I had a MAS that got hacked a few months ago. I think there was external Remote Desktop access through the firewall and the password was still default. The device that it replaces was a Win 2K ACD system that had no RDP built in.

Default passwords are about as just a little better then as no passwords. It would seem that on the surface the LUCA would be more secure, whith it's Linux OS and a password that is not just "password". I guess it could still be guess with a dictionary attck or if somone knew that system.

we have a lot of customers that still have the default passwords on their system. For the most part they do not have exposure to the outside world (except an IES or the ICX that could have dialup access). I do try to add more security when the systems have access to them from outside the firewall.

Did you have the SSH or Web ports forwarded theough the firewall? I am just curious how someone could get into that system.