Security flaw - FreePBX - Please update 2.2!!

Status
Not open for further replies.

Bob1

Forum User
Joined
Nov 4, 2007
Messages
2,400
Reaction score
1
Security Advice :

A major security vulnerability has been discovered.

Information on FreePBX flaw : http://seclists.org/fulldisclosure/2012/Mar/234

Elastix Specific Information on Exploit : http://www.exploit-db.com/exploits/18650/

Elastix versions fixed : 2.2

Elastix fix : Elastix has released a new FreePBX package (freePBX-2.8.1-12).

How to apply : yum update freePBX (note the uppercase PBX)

When asked to press Y to proceed check that this is the package that it is updating

Updating:
freePBX noarch 2.8.1-12 elastix-updates
 
Sir Bob,

I see that you say "Elastix Versions Fixed: 2.2", Dumb question but does this mean that if I have 2.2.0.23 that I don't need to worry about this update or that Versions fixed means this is a patch for all 2.2 ?

We sometime read things differently here in the U S.

Can this update be done from "PBX" - "Tools" Asterisk CL"?

Amphibian
 
Amphibian

Do a yum check-update and see if the version of freepbx is up to date.

If you have CSF firewall running the security hole will not affect you,the same goes for any further security holes found
 
Sir Dave,

I just ran the "Version" list and it showed freepbx release 10 not 12.

Can this be done by asterisk CLI under tools or from terminal window?

And yes I have CSF Running. I really don't fully understand why I need FreePBX anyways, I don't use it and haven't found a reason why I would need to use it.

Are yoou in the U S?


Thanks

Amphibian
 
Amphibian

From root in the console type in " yum check-update " without quotation marks and it will show what updates are available.

To install that update you want type " yum update module name as it shows "

I prefer Freepbx as it has more settings available that aren't in the Elastix gui
 
Thank you sir.



Amphibian
 
Amphibian,

DaveD lives in the best country in the world, Australia :laugh:

But to answer your question, you need to have Freepbx. Even the embedded version of Freepbx in Elastix uses/wraps the code which is part of Freepbx. This is why the menu options on the whole look the same...

The embedded version just lessens a new users brain explosion in terms of options, and in fact many people utilise the embedded version only, especially for day to day changes.

Regards

Bob
 
Sir Bob,

I got ur Australia.....lol

As to FreePBX, I understand its cause now better. That's the problem when you start getting older, sometimes you just have to grab me by the hand and lead away. For day to day I really haven't seen the "easier" way over Elastix but there again I'm new at this so maybe eventually I'll get it.

Sir Dave says that since I'm using CSF I really don't need to worry about it but would you suggest updating it anyway? And have you seen any problems after update?


Thank


Amphibian
 
Amphibian

I have quite a few systems that have the security hole in them, I am not concerned with CSF running, as the boxes are running perfect and have been for a long time I tend not to update anything while all is good.

But saying that each person needs to make their own security decisions regarding what they think is best practice, and mine is while all is well leave alone I have that much confidence in CSF.

Bob summed it up well below....

Dave
 
Amphibian,

I write this post not just for you but anyone else who needs to update.

Naturally, if you are using CSF or any other firewall, or your Network firewall is protecting anyone from accessing http(s) on your Elastix system, then there is not a great urgency.

However, just because there is firewall there, doesn't necessarily mean that someone on the local network, cannot access the system.

If you can imagine someone who is disgruntled with the company that they are working for, there is nothing to stop him/her performing this "attack" while still working for the company, and is something he can do via the company vpn. After he leaves, he posts the details on the Internet for all to use (if he has compromised the system). Most would not try to use it themselves. The larger the company, the more likely this is to happen.

There is the possibility that some could write a trojan that proxys a http connection, that ends up on one of the Local Network machines, same concern.

However, the likelihood of these happening are slim against the likelihood of an anonymous attack coming from the Internet (but it can happen).

However, imagine the possibility that the firewall settings are compromised on your firewall whether it be through corruption, human error or other reasons, it is always better to have that next layer, which in this case is removing the "flaw" so you have two layers of security.

But like most of the security flaws that are and will be posted, the main topic will be to do with Web based services. If you don't have these available to the Internet, then the panic is not there. But it would be "wrong" of me to say you don't need to patch it, as I don't control your system, I don't know your system, and generally its bad advice with any security flaw.

Hope I have not made it to unclear...

Regards

Bob
 
DaveD,

Must be a lazy (but cold) Sunday afternoon in Australia....both posting at the same time..

Regards

Bob
 
Lol Bob went to go for a longboard surf.......but alas no surf
 
Sir Bob,
Sir Bob says" Hope I have not made it to unclear..."


I would say you made it very clear. Sorry I crapped in your frootloops.

The first part of:
"Sir Dave says that since I'm using CSF I really don't need to worry about it but would you suggest updating it anyway? And have you seen any problems after update?" was beyond doubt a really stupid statement and please accept my apologies for that (realised it after hitting the submit button that I had inadvertently included that in my post) . I have enough mentality to know that, I wasn't trying to pit you and Sir Dave, I was more after the last part of that statement about issues after updating. That's what I get for working, playing and posting at the same time --- things sometimes just don't come out right, even with the help of virtual paper.

Anyway, the update was done and that's what really matters. It's Sunday here, lunch time, and I'm going fishing.


Thanks


Amphibian
 
Amphibian,

Love the term "crapped in your Frootloops" :laugh:

I was concerned that I had made the subject/answer unclear as I flip-flopped on the answer.

I could see that you were bouncing for the answers, which is totally the correct thing to do.

Security can be a very subjective and opinionated topic, and unlike many other areas of IT, it is not the sort of that you can perform a "monkey see, monkey do" approach. You need to have an understanding of the principles in relation to security, which also means you have to take an interest in it, which is exactly what you were doing. For that I applaud you.

Also no-one has all the answers, and even if they feel that they do, whether the answers are right or wrong is another matter. Unless you work in cyber security, day in and day out, living and breathing it, you can only know the basic principles and a few areas that take your interest.

It still gets to the point, like protecting a house, you can spend as much as you like. If they are that determined, they will get in, no matter how much you spend. Its securing the system to cover for those 99% of intruders, because covering for that 1% will cost you exponentially what it cost you for covering the 99%.

A simple high level slideshow will give you an idea...
http://www.slideshare.net/elastixorg/el ... monitoring

Regards

Bob
 
Status
Not open for further replies.

Forum statistics

Threads
111,858
Messages
589,427
Members
164,698
Latest member
RRusev