河南商丘网警近日发现某学校校园网络存在严重安全隐患[1]。该校存储人脸信息及进出轨迹数据的服务器开放了高危端口,并开启了Telnet服务,致使敏感数据暴露在互联网中[1]。公安机关经查证发现,该校防护措施缺失、网络日志缺位、高危服务暴露等多个问题,依据《中华人民共和国网络安全法》相关规定对其进行了行政处罚,并责令限期改正[1]。
高危端口是指容易被利用进行网络攻击的服务端口[1]。常见的高危端口包括:21端口(FTP)、23端口(Telnet)、445端口(SMB)、3389端口(RDP)、1433和3306端口(数据库)[1]。网络日志留存时间不得少于六个月[1]。该案例提醒教育机构,校园网络系统涉及学生隐私和安全,必须重视网络安全防护。
Henan Shangqiu cyber police discovered that a local school's campus network server had exposed high-risk ports and was subjected to cyberattacks [1]. The server storing facial recognition data and entry-exit tracking information was directly exposed to the internet [1]. The school had failed to implement adequate protective measures, lacked network logging systems, and left high-risk services undefended [1].
Following an investigation, public security authorities imposed administrative penalties on the school in accordance with the Cybersecurity Law of the People's Republic of China and ordered the institution to make corrections within a specified timeframe [1]. Among the identified vulnerabilities, the server had opened a Telnet service on port 23, one of several commonly exploited high-risk ports [1]. Network logs must be retained for no less than six months to ensure proper security auditing and incident response [1].
High-risk ports typically include FTP on port 21, Telnet on port 23, SMB on port 445, RDP on port 3389, and database services on ports 1433 and 3306 [1].