I have a pi2 with Jessie.
Also on my router a port forward on a none obvious port.
Logged on this morning and it said last login was two days ago at a time I knew I would not login.
Looked like and external address.
History showed some weird commands I don't think I issued.
Will investigate further but currently pi switched off and port forward deleted.
As I remember commands were wget from some external IP. and IP tables commands.
Questions
I guess a port scanner could find the port but how do they get passed the root password ?
Should I disable root login from IP ?
Anyone seen this ?
Thanks
Jim