Mmmm. Coming up in my logs quite regularly, and the router has been showing all sorts of weirdness lately
Code:
Dec 31 21:11:54 ripshod HTTPD: [LOGIN][https][Web] successed (12.190.146.90)
Dec 31 21:12:07 ripshod rc_service: httpds 3791:notify_rc start_uiScribeLogFileInfoList
Dec 31 21:12:07 ripshod custom_script: Running /jffs/scripts/service-event (args: start uiScribeLogFileInfoList)
**edit** Blocked that IP in skynet, and now seeing a new IP
Code:
Jan 1 10:49:04 ripshod HTTPD: [LOGIN][https][Web] failed (96.211.88.94)
Jan 1 10:49:08 ripshod HTTPD: [LOGIN][https][Web] successed (96.211.88.94)
Jan 1 10:55:40 ripshod HTTPD: [LOGIN][https][Web] successed (96.211.88.94)
Needless to say that IP is blocked too now. Also have a zero byte file in the root, ".init_enable_core" that I never noticed before.
Both private IPs. The first is AT&T, the second Comcast. Like being hacked from the USA.
To confirm. Web access from WAN is disabled.
@RMerlin any concerns?