Hacker News new | ask | show | jobs
by DownGoat 2873 days ago
It is because dropbear is very common in embedded systems. They are commonly riddled with vulnerabilities, so they are getting hacked almost as soon as they are publicly reachable. This is not because of dropbear, but because they are typically configured with weak credentials that are newer changed. I guess IRC servers see a lot of spam from such devices, so they just drop all systems which has dropbear.
1 comments

It's probably also because of dropbear since embedded devices often run old versions and dropbear seemed to be vulnerable to severe vulnerabilities in the past:

https://www.cvedetails.com/vulnerability-list/vendor_id-1580...