... should be a crime to not change the default credentials.
... should be a crime to not change the default credentials.
The default credentials on every bit of UBNT hardware that I've used grant access to both the web UI and admin SSH access. So, the access attempts that WillieStevenson has noticed coming from that IP are most likely coming from the router itself.
I can't see any reasonable reason for redacting the IPs that are making those access attempts, and I see no reason at all for redacting static, factory default usernames and passwords.
Actually that particular IP attacked me more than 170 times. It may be useful to others to keep this address on their "naughty" list of hosts to ban.
Interestingly, the IP address of that router is _not_ present in either the base (attacks within the past 360 days) list or the delisted (manually removed from the base list by the person in question) list.
It's almost like no single list is terribly likely to be complete, and that publishing collation of a master list is required for completeness. :)
No. Some random sysadmin stood up some business-tier gear and failed to change the factory default, static username and password. He then also failed to restrict access to the built-in web server and SSH server to only a trusted set of machines.