TB Rootkit Exploit Found

TheShniz

Guru
Joined
Nov 15, 2007
Messages
560
Reaction score
2
I admittedly try to avoid any & all things green, and only know about the most recent occurences through other forums/articles/etc... so I took a quick scan of their Open Discussion, and found at the top:

The Beginning of the End
http://www.trixbox.org/forums/trixbox-forums/open-discussion/begining-end-ce

Suprisingly, many of the same people I knew & loved are still there, all in various stages of having given up. I understand 'the mob' aka 'the masses' can be dumb as sheep, but these guys are the ones 'that know' and are intimately aware. I suppose things become self-evident to people at different levels of obviousness, lol.

A very long, but interesting read... nothing different than what so many were saying this time last year I suppose.
 

kevinfvc

Member
Joined
Apr 11, 2008
Messages
132
Reaction score
2
A user on the trixbox forums has found a rootkit exploit on his server. :crazy:

Simple test:

Code:
ls -all /sbin/init.zk

the trixbox link returns a page not found error for me...

For hacks, rootkits, ect, how much is truly the blame of fonality platform vs. poor network security (operator fault)? Is there something inherently more insecure in trixbox vs PiaF, Elastix, Switchvox, ect???

PiaF has done a good job being proactive on adding security features like fail2ban and setting IP Tables into the distribution, but if an operator choses to turn these features off, the system is as vulnerable as the next. Right?
 

wardmundy

Nerd Uno
Joined
Oct 12, 2007
Messages
19,202
Reaction score
5,224
Interesting. It appears the thread was deleted about the time California got to work this morning. That's one way to handle security threats, I suppose. Here's what's left of it on Google...

Rootkit Found on my Trixbox Server | trixbox

Jan 26, 2009 ... A quick Google turned up many hints that this was rootkit related. I ran rootkit hunter, but this turned up nothing. ...
www.trixbox.org/forums/trixbox-forums/open-discussion/rootkit-found-my-trixbox-server - 4 hours ago - Similar pages -

Rootkit Found on my Trixbox Server | trixbox

- 3:22pmJan 26, 2009 ... On further checking, I found evidence of the zk rootkit - eg: an init.zk file in /sbin. At this point I just started a reinstall - which took all of about 30 mins, including a config restore. Now, this server is behind a hardware firewall with no general access and the only ports open are those for SIP, RTP and IAX2. ...
www.trixbox.org/forums/trixbox-forums/open-discussion/rootkit-found-my-trixbox-server - 5 hours ago

Rootkit Found on my Trixbox Server | trixbox

- 3:22pmJan 26, 2009 ... So I get in via this and get root via vmsplice and then suddenly Bob's your uncle and the box isn't yours anymore. ...
www.trixbox.org/forums/trixbox-forums/open-discussion/rootkit-found-my-trixbox-server - 5 hours ago

Rootkit Found on my Trixbox Server | trixbox

- 3:22pmJan 26, 2009 ... SIP and IAX2 exploits are from 2007, there has been an information disclosure weakness in IAX2 too, which has been announced some days ago. ...
www.trixbox.org/forums/trixbox-forums/open-discussion/rootkit-found-my-trixbox-server - 5 hours ago

Rootkit Found on my Trixbox Server | trixbox

- 3:22pmJan 26, 2009 ... The vmsplice 'exploit' requires user rights to execute code on the box, that requires access either locally or remotely. ... aka "Skyking".
www.trixbox.org/forums/trixbox-forums/open-discussion/rootkit-found-my-trixbox-server - 5 hours ago


And then there's this result from donbusca.com:
 

jmullinix

Guru
Joined
Oct 21, 2007
Messages
1,263
Reaction score
7
The pure presence of a rootkit on a user's machine should not be worthy of deleting the thread. Therefore one could only assume that the root kit got in through a known security flaw.
 

Members online

Forum statistics

Threads
25,814
Messages
167,783
Members
19,245
Latest member
rahee
Get 3CX - Absolutely Free!

Link up your team and customers Phone System Live Chat Video Conferencing

Hosted or Self-managed. Up to 10 users free forever. No credit card. Try risk free.

3CX
A 3CX Account with that email already exists. You will be redirected to the Customer Portal to sign in or reset your password if you've forgotten it.
Top