logo

AppleTV & nmap -sV

ID: 55c6df68-e091-5d14-9538-c397e24e661d

STIX ID: report--55c6df68-e091-5d14-9538-c397e24e661d

Feed Name: Black Hills Infosec Blog

Threat Score
25/100

Date Published: 2016-10-11

Date Updated: 2026-04-27

Author: BHIS

...
...

A researcher observed that an Apple TV (tvOS 9.2.2) can be woken from the network by a minimal HTTP GET to port 3689. Using tcpdump, Wireshark, and netcat, the author traced the wake event to a generic GET sent during an nmap version scan and demonstrates that the service responds even when the device appears “off,” implying exposed functionality on that port that may not require authentication.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.