NEWS FLASH Proprietary Distro Gets Proprietary Firewall... finally

wardmundy

Nerd Uno
Joined
Oct 12, 2007
Messages
19,206
Reaction score
5,229
Now ask yourself how a vulnerability in a FreePBX module can morph into a root vulnerability, and you'll better appreciate why isolating your firewall from FreePBX is a very good idea.
 

hecatae

resident hecatae
Joined
Feb 7, 2014
Messages
769
Reaction score
202
Now ask yourself how a vulnerability in a FreePBX module can morph into a root vulnerability, and you'll better appreciate why isolating your firewall from FreePBX is a very good idea.


is the sysadmin module on github, can we look at the source, as the sysadmin module still has root access as far as I understand?
 

wardmundy

Nerd Uno
Joined
Oct 12, 2007
Messages
19,206
Reaction score
5,229
Heh. Even the "Free" version is a Commercial (encrypted) Module and, based upon the capabilities and method of installation, root access appears to be a "hidden feature." That would certainly explain the latest vulnerability.

images
 

billsimon

Well-Known Member
Joined
Jan 2, 2011
Messages
1,540
Reaction score
729
It was a shell command injection exploit (similar to DB injection if you are familiar). The patch does a more strict check of parameters.
 

Members online

Forum statistics

Threads
25,825
Messages
167,856
Members
19,250
Latest member
mark-curtis
Get 3CX - Absolutely Free!

Link up your team and customers Phone System Live Chat Video Conferencing

Hosted or Self-managed. Up to 10 users free forever. No credit card. Try risk free.

3CX
A 3CX Account with that email already exists. You will be redirected to the Customer Portal to sign in or reset your password if you've forgotten it.
Top