
Hi, I'm transferring the bodies of the first message in each technical thread from the old yahoo site to this group. ### Any of you running Sansay SPXs as you SBCs better make sure you don't have telnet, SSH, or FTP open to the world. Several, including two of mine, have now been hit with what I believe is going to turn out to be a standard script kiddie vs. linux default accounts attack. No operational impact at this time, but they were owned, the people who left the ports open beaten to a bloody pulp, and the new units will come in via courier tomorrow. Should be a no downtime replacement. ### This message and any attachments are intended only for the use of the addressee and may contain information that is privileged and confidential. If the reader of the message is not the intended recipient or an authorized representative of the intended recipient, you are hereby notified that any dissemination of this communication is strictly prohibited. If you have received this communication in error, please notify us immediately by e-mail and delete the message and any attachments from your system.

This ended up being a "standard" linux box exploit, because of bad default passwords and FTP configurations. All has been resolved by the vendor at this point.
participants (2)
-
daryl@introspect.net
-
David_Hiers@adp.com