General and Support topics relating to ViciDialNow and GoAutoDial ISO installers
Moderators: enjay, williamconley, Op3r, Staydog, gardo, mflorell, MJCoate, mcargile, Kumba, s0lid
by ctc_olsen » Tue Dec 31, 2013 11:14 am
Happy New Year guys! Sad to say I'm still working. Sighs*
We found a rootkit on or VICI
Using rkhunter:
Rootkit checks...
Rootkits checked : 321
Possible rootkits: 3
Rootkit names : SHV4 Rootkit, SHV5 Rootkit, Sniffer
We immediately wiped it out. I would like to ask if anyone here have any suggestions on what entries to add at iptables or which ports we need to block in order to prevent this from happening again.
I have browsed around but I couldn't really find an exact article on what I am looking for. Please help.
VERSION: 2.4-309a BUILD: 110430-1642 (Upgrade from CE 2.0,ISO) | Asterisk 1.4.27.1-1 | VmWare vCenter Server Ver 4.1.0| No additional software | No Digium/Sangoma Hardware
-
ctc_olsen
-
- Posts: 65
- Joined: Tue Jul 24, 2012 7:34 am
by Vince-0 » Thu Jan 02, 2014 2:39 am
Root kits can be installed using a number of attack vectors. You should install and use the latest versions of Vicidial (astguiclient from SVN trunk) and the latest Vicidial ISO and keep those up to date because there could be SQL injection, cross-site scripting, PHP or Asterisk vulnerabilities that can lead to root permissions escalation. If your server is hosted on the Internet then you can do IP white-lists to limit access to each of these sub-systems.
Any services directly exposed to the Internet need constant updating and vulnerability checks. I hope you wiped out the entire OS installation after finding root-kits.
Vin.
-
Vince-0
-
- Posts: 272
- Joined: Fri Mar 02, 2012 4:27 pm
- Location: South Africa
by williamconley » Thu Jan 02, 2014 11:29 pm
Vicidial Installation and Repair, plus Hosting and Colocation
Newest Product: Vicidial Agent Only Beep - Beta
http://www.PoundTeam.com # 352-269-0000 # +44(203) 769-2294
-
williamconley
-
- Posts: 20253
- Joined: Wed Oct 31, 2007 4:17 pm
- Location: Davenport, FL (By Disney!)
-
Return to ViciDialNow - GoAutoDial
Who is online
Users browsing this forum: No registered users and 96 guests