16 Jun
2017
16 Jun
'17
3:42 a.m.
On 6/15/17 11:22 PM, Jeremy Utley wrote:
Most likely, I would suspect it's an older install without the "debian" or "pi" user secured, and they logged into the node that way.
Bingo. Tim documented this on the docs site, but many (most) people forgot to secure it/didn't read the docs. There is now a allstarlinux "hack" in a popular hacking/scanning toolkit. The more blackhat toolkits automate scanning/hacking this. 44/8 has seen a bunch of traffic for this. 73's -- Bryan Fields 727-409-1194 - Voice http://bryanfields.net