ALERT Edgewater Hacking

Stewart

Guru
Joined
Sep 16, 2009
Messages
603
Reaction score
6
On Friday we just worked through a hack on a client's Edgewater that caught us off-guard. The techs over at Bandwidth.com did a great job of helping us out. It seems that even if you reset the password in the GUI interface, it doesn't reset the SSH password. When setting it up over a year ago we went into both to look around and make the configurations. Once we were done we reset the GUI password and thought we were done. We never shut off the SSH and it left us vulnerable since that password must be reset via the command line. It's all closed up now and we've corrected the vulnerability at our other clients using the hardware but I thought I'd let everyone know what happened. Luckily we had international calling turned off and so no damage was done. The technician at Bandwidth informed us that they are seeing a rash of these and that he personally was seeing this 2-3 times a week. Good luck!
 

Members online

Forum statistics

Threads
25,825
Messages
167,849
Members
19,250
Latest member
mark-curtis
Get 3CX - Absolutely Free!

Link up your team and customers Phone System Live Chat Video Conferencing

Hosted or Self-managed. Up to 10 users free forever. No credit card. Try risk free.

3CX
A 3CX Account with that email already exists. You will be redirected to the Customer Portal to sign in or reset your password if you've forgotten it.
Top