Cron and Test and One can have ENTIRE SERVER ACCESS ?

General and Support topics relating to ViciDialNow and GoAutoDial ISO installers

Moderators: enjay, williamconley, Op3r, Staydog, gardo, mflorell, MJCoate, mcargile, Kumba, s0lid

Cron and Test and One can have ENTIRE SERVER ACCESS ?

Postby gmcust3 » Wed Aug 31, 2011 8:06 am

If I know someone IP , I can login to any dialer using cron credential and can roam around in the server ?

I tried it and I Can !!

Gardo , cant we block it while installing GoautoDial 2.1 ELSE SECURITY is HIGHLY COMPROMISED ?
GoAutoDial CE
VERSION: 2.4-309a
BUILD: 110430-1642
No other software installed on the box.
I've read the manager manual.
gmcust3
 
Posts: 1148
Joined: Sat Oct 24, 2009 1:15 pm

Postby williamconley » Wed Aug 31, 2011 1:20 pm

vicidial's new admin "1st login" will change default passwords ... but not the Cron yet. Would certainly be a good feature request. Just adding the cron pass to the mix would be good ... honesly, though, since cron is fully automated it almost makes more sense for "install.pl" to create a random pass for cron and install it. (no human ever needs to KNOW the cron pass, but it is visible in the system if you actually needed it for something ... just making it different on every machine would suffice)
Vicidial Installation and Repair, plus Hosting and Colocation
Newest Product: Vicidial Agent Only Beep - Beta
http://www.PoundTeam.com # 352-269-0000 # +44(203) 769-2294
williamconley
 
Posts: 20258
Joined: Wed Oct 31, 2007 4:17 pm
Location: Davenport, FL (By Disney!)


Return to ViciDialNow - GoAutoDial

Who is online

Users browsing this forum: No registered users and 71 guests