Strange Log entry - any valid reason for this?
IP removed in case it is just an operator error ;-).
Oct 9 13:52:29 kiwisdr kiwid: 08:06:12.948 0... ** attempt to save kiwi config with auth_admin == FALSE! IP X.X.X.X
Oct 9 13:52:29 kiwisdr kiwid: 08:06:12.952 0... ** attempt to save kiwi config with auth_admin == FALSE! IP X.X.X.X
Oct 9 13:52:29 kiwisdr kiwid: 08:06:12.961 0... ** attempt to save kiwi config with auth_admin == FALSE! IP X.X.X.X
Oct 9 13:52:29 kiwisdr kiwid: 08:06:12.964 0... ** attempt to save kiwi config with auth_admin == FALSE! IP X.X.X.X
Oct 9 13:52:29 kiwisdr kiwid: 08:06:12.970 0... ** attempt to save kiwi config with auth_admin == FALSE! IP X.X.X.X
Oct 9 13:52:39 kiwisdr kiwid: 08:06:23.029 0... 0 7020.00 kHz lsb z0 "X.X.X.X" Guangzhou, China (ARRIVED)
Oct 9 13:54:07 kiwisdr kiwid: 08:07:50.571 .... 0 1000.00 kHz am z4 "X.X.X.X" Guangzhou, China (LEAVING after 0:01:39)
From experience elsewhere I'd lock down your public interface to trusted IP's when setting up new devices.
Oct 9 13:52:29 kiwisdr kiwid: 08:06:12.948 0... ** attempt to save kiwi config with auth_admin == FALSE! IP X.X.X.X
Oct 9 13:52:29 kiwisdr kiwid: 08:06:12.952 0... ** attempt to save kiwi config with auth_admin == FALSE! IP X.X.X.X
Oct 9 13:52:29 kiwisdr kiwid: 08:06:12.961 0... ** attempt to save kiwi config with auth_admin == FALSE! IP X.X.X.X
Oct 9 13:52:29 kiwisdr kiwid: 08:06:12.964 0... ** attempt to save kiwi config with auth_admin == FALSE! IP X.X.X.X
Oct 9 13:52:29 kiwisdr kiwid: 08:06:12.970 0... ** attempt to save kiwi config with auth_admin == FALSE! IP X.X.X.X
Oct 9 13:52:39 kiwisdr kiwid: 08:06:23.029 0... 0 7020.00 kHz lsb z0 "X.X.X.X" Guangzhou, China (ARRIVED)
Oct 9 13:54:07 kiwisdr kiwid: 08:07:50.571 .... 0 1000.00 kHz am z4 "X.X.X.X" Guangzhou, China (LEAVING after 0:01:39)
From experience elsewhere I'd lock down your public interface to trusted IP's when setting up new devices.
Comments
I look after a small FTP server for work and we must have got on some BOT list as we'd see a pattern of malicious brute force connections hitting through the day, I ended up blocking large geographical ranges and China was No.1.
Not saying the bad actors were from China but attacks relayed mainly from those IP ranges (and a specific insecure CMS for about 70% of the sources).
I checked this IP on abuseipdb.com and it was not found.