I'm familiar with WHOIS, and I could have changed the port, or even used
iptables to firewall the port.  Or since there are no valid SIP peers on
this setup, I could just not care, and probably nothing bad would happen.

Then again, Asterisk runs as root, and its possible there are security
flaws.  The point was, others might have the same issue, and not know it. 
I raise the concern for the good of the network as a whole.  If you're not
using SIP, you might consider adding noload=chan_sip.so to modules.conf. 
I am also suggesting this be part of the standard portal-based and/or
stock ACID configuration.

Security by obscurity works as long as what you're securing against isn't
bothering to port-scan, and is just trying well-known ports, but that
isn't going to defend you against the Chinese government.  Take SSH --
change it to port 222, and nearly all of the password attacks go away, but
that doesn't mean you shouldn't also use strong passwords, and maybe
consider disabling root logins entirely (create a separate user-account,
log in as that user, and then su to root).


