- Joined
- Oct 17, 2018
- Messages
- 71
- Reaction score
- 88
Hi all,
It seems like many people have their Neptune Apex exposed over the Internet. See this Shodan Report: https://www.shodan.io/search?query="Server:+AquaController"
This is a security risk since many services like Shodan and Censys are search engines for "machines" instead of websites. An attacker can trivially get a list of most controllers exposed to the internet. Then a brute force attack can be tried to guess the username/password or another exploit can be discovered to bypass authentication.
It seems like many people have their Neptune Apex exposed over the Internet. See this Shodan Report: https://www.shodan.io/search?query="Server:+AquaController"
This is a security risk since many services like Shodan and Censys are search engines for "machines" instead of websites. An attacker can trivially get a list of most controllers exposed to the internet. Then a brute force attack can be tried to guess the username/password or another exploit can be discovered to bypass authentication.

