[aklug] Re: OT(?): Remote Access VPN

From: Jeremy Austin <jhaustin@gmail.com>
Date: Fri Oct 23 2015 - 16:54:33 AKDT

On Fri, Oct 23, 2015 at 4:13 PM, JP <jp@jptechnical.com> wrote:

> This should go without saying, but be sure you change the admin password
> on that. The ubiquities I have had experience with (end points specifically
> in this case) have SSH on and default password. Didn't realize it and
> didn't reset the password right away. By the time I reset the password it
> had been compromised and was poisoning DNS and other nasty stuff, and I am
> only talking a couple days.
>

This unfortunately does go without saying, too often. More recent UBNT
firmwares flash a banner at you until you change the default password. I
always provision separately before ever connecting to a public inbound IP.

Even after changing default passwords: if you aren't doing rate limiting
and blacklisting on brute force ssh attacks, you probably should.

jermudgeon

---------
To unsubscribe, send email to <aklug-request@aklug.org>
with 'unsubscribe' in the message body.
Received on Fri Oct 23 16:55:15 2015

This archive was generated by hypermail 2.1.8 : Fri Oct 23 2015 - 16:55:15 AKDT