At a glance
Many cyber incidents do not begin with sophisticated attacks or previously unknown vulnerabilities. Instead, they start with outdated services that remain exposed to the internet long after safer alternatives became available.
Services such as Telnet, FTP and SMBv1 can provide an easy pathway into your network if they are not properly managed.
This blog explains why legacy services remain a risk and outlines practical steps organisations can take to reduce their exposure.
Legacy services are still creating opportunities for attackers
When people think about cyber security incidents, they often imagine highly skilled threat actors exploiting advanced vulnerabilities.
However, many cyber compromises do not begin with sophisticated attacks. They often start with legacy services that remain exposed to the internet long after safer alternatives became available or are inadvertently re-exposed to the internet due to an update or undocumented change. If attackers can find these services, they will investigate them for weaknesses.
Across Australian networks, we continue to see organisations exposing legacy services to the public internet.
In many cases, these services were designed long before modern cyber security threats became commonplace.
Some transmit information without encryption. Others rely on outdated authentication methods. Many have well-known vulnerabilities that have been publicly documented for years.
We understand that some legacy systems still support important business functions. This is especially common in operational technology environments. Replacing them may require significant planning, investment and operational change.
The concern is when legacy services are left exposed to the internet without appropriate security controls or ongoing risk management.
Threat actors actively scan the internet looking for exposed services. If they can see an open service, they can scan it. If they can scan it, they will try to exploit it.
When a service transmits information without encryption, in clear text, or relies on outdated security controls, it is much easier to compromise it.
Why attackers continue to target legacy services
Attackers are often opportunistic.
They do not always need sophisticated techniques when older technologies continue to provide easier pathways into networks.
Legacy services remain attractive because they can allow malicious actors to:
- exploit known vulnerabilities
- capture usernames and passwords sent without encryption
- gain unauthorised access to systems
- execute malicious code on vulnerable devices
- move laterally through a network after an initial compromise
- automate attacks using freely available tools and exploit kits.
Many of the weaknesses associated with these services are already well understood.
Unfortunately, that also means they are well understood by attackers.
A protocol developed decades ago may still function as intended today. That does not mean it was designed to defend against modern threats.
Services worth reviewing
Organisations should maintain visibility of all internet-facing services and regularly review whether they are still required.
Examples of legacy services and protocols that warrant particular attention include:
- Telnet (port 23)
- File Transfer Protocol (FTP) (ports 20 and 21)
- Unencrypted web management panels (HTTP) (port 80)
- Server Message Block version 1 (SMBv1) (ports 139 and 445)
- Rlogin and Remote Shell (Rsh) (ports 512-514)
- Simple Network Management Protocol version 1 and 2c (SNMPv1/2c) (ports 161 and 162).
These services may still exist within environments for historical, operational or compatibility reasons. However, many have more secure modern alternatives available.
Even if a service remains necessary, it should not automatically be directly accessible from the internet.
Restricting access to trusted networks and implementing appropriate security controls can significantly reduce risk.
Small changes can reduce your attack surface
Reducing exposure to legacy services does not always require a large-scale technology refresh.
Often, the most effective improvements start with fundamental cyber security practices.
Consider the following actions:
- Identify all internet-facing services and protocols.
- Remove services that are no longer required.
- Replace outdated services with supported alternatives where possible.
- Confine high-risk or essential services to internal or trusted networks.
- Apply network segmentation to limit access between systems.
- Implement strong access controls and authentication measures.
- Review firewall rules and network configurations regularly.
- Monitor for legacy services reappearing after upgrades, migrations or system changes.
These actions help reduce your attack surface and make it harder for malicious actors to establish an initial foothold within your environment.
Legacy technology does not have to become a security incident
Most organisations accumulate some form of legacy technology over time. That is not unusual. What matters is understanding where that technology exists, what risks it introduces and whether appropriate controls are in place.
Legacy systems may continue to support important business activities. Exposed legacy services, however, often create unnecessary opportunities for attackers.
The good news is that this is a problem organisations can address.
By identifying outdated services, restricting unnecessary exposure and replacing legacy protocols where possible, you can significantly improve your cyber security posture.
Cyber security is often strongest when organisations focus on the basics. Reviewing internet-facing services is one of those fundamentals.
The technology may be old, but the risks remain very real.
Further information
Amanda L