Dont see any lists and can not control dialing? HACKED

All installation and configuration problems and questions

Moderators: gerski, enjay, williamconley, Op3r, Staydog, gardo, mflorell, MJCoate, mcargile, Kumba, Michael_N

Dont see any lists and can not control dialing? HACKED

Postby carpenox » Mon Sep 16, 2024 11:59 am

Yes, so this new exploit is affecting a lot of people and I woke up this morning to more messages than ever about people in our community's campaigns not showing any way to dial and lists area of menu area totally gone. I am working on a remediation plan to release to the public, but for now, do these things.

1. Run this command in linux cli: mysql asterisk -u cron -p1234 -e "update system_settings set outbound_autodial_active='1'"
This will turn dialing and lists back on, you can also just go into admin > system settings and go down to "outbound autodial" and change it to 1

2. If you are not using VERM or chat, rename those directories because this is the way they are getting in, and even those of you who did update your servers, it can still cause you headaches with your 6666 user getting locked out from hack attempts. (copy 6666 user to another name and delete 6666 user) If you are using them, make sure you update your SVN to latest.

3. Close HTTP/HTTPS to your trusted zone only. Only the dynamic portal port should be open on public zone.

Here are some current articles that will help you better understand and fix your systems. New article for remediation plan of action coming this week.

About this exploit - https://dialer.one/august-2024-vicidial ... ty-update/

Secure your system correctly - https://dialer.one/how-to-secure-vicidi ... ly-part-1/

Using the dynamic portal - https://dialer.one/how-to-use-the-built ... r-vicibox/

How to update your SVN - https://dialer.one/how-to-update-your-v ... ubversion/

Hope this helps

Chris
Alma Linux 9.4 | SVN Version: 3889 | DB Schema Version: 1721 | Asterisk 18.21.1 | PHP8
www.dialer.one -:- 1-833-DIALER-1 -:- https://linktr.ee/CyburDial -:- WA: +19549477572
GC: https://join.skype.com/ujkQ7i5lV78O | DC: https://discord.gg/DVktk6smbh
carpenox
 
Posts: 2418
Joined: Wed Apr 08, 2020 2:02 am
Location: St Petersburg, FL

Re: Dont see any lists and can not control dialing? HACKED

Postby Acidshock » Tue Sep 17, 2024 12:54 am

Yeah just dealt with 3 servers today that had this issue. Also heard from other people having the same issue too.
VERSION: 2.14-698a | BUILD: 190207-2301 | Asterisk:13.24.1-vici | Vicibox 8.1.2
Acidshock
 
Posts: 430
Joined: Wed Mar 03, 2010 3:19 pm

Re: Dont see any lists and can not control dialing? HACKED

Postby JakeBelieve » Tue Sep 24, 2024 9:28 am

Thanks for the input, this is something I'm still currently dealing with. They got in twice. Once yesterday and once on Sept 16th. I was trying to figure out how a strict whitelist wasn't working or who I had let do this. I appreciate the post and any updates on methods to completely eradicate.
Version: 1.4.21.2/2.14-928a | BUILD: 240826-0918 | SVN: 3875 | Asterisk: 16.30.0-vici |Schema | 1718 - Cluster
JakeBelieve
 
Posts: 4
Joined: Tue Feb 28, 2017 9:33 pm

Re: Dont see any lists and can not control dialing? HACKED

Postby carpenox » Tue Sep 24, 2024 11:36 am

if you have updated to the latest SVN, it should not be happening, make sure to update all servers if its a cluster. You can also just remove the VERM folder altogether, msot people do not use this feature anyways and thats how the enumeration process is gaining hackers access. As far as whitelist goes, not leaving http/https open to the public zone will eliminate all hacker possibilities for these exploits. Feel free to join my skype group for additional questions if you'd like.
Alma Linux 9.4 | SVN Version: 3889 | DB Schema Version: 1721 | Asterisk 18.21.1 | PHP8
www.dialer.one -:- 1-833-DIALER-1 -:- https://linktr.ee/CyburDial -:- WA: +19549477572
GC: https://join.skype.com/ujkQ7i5lV78O | DC: https://discord.gg/DVktk6smbh
carpenox
 
Posts: 2418
Joined: Wed Apr 08, 2020 2:02 am
Location: St Petersburg, FL

Re: Dont see any lists and can not control dialing? HACKED

Postby williamconley » Fri Sep 27, 2024 9:06 pm

JakeBelieve wrote:Thanks for the input, this is something I'm still currently dealing with. They got in twice. Once yesterday and once on Sept 16th. I was trying to figure out how a strict whitelist wasn't working or who I had let do this. I appreciate the post and any updates on methods to completely eradicate.


Whitelist always works unless: You allow the hacker inside your firewall or leave something open. One of those two must be true.

Check logs, find the IP of the hacker. Be sure they're not allowed.

And be sure mysql credentials are ALL IP locked (not "%"/any ip entries)
Vicidial Installation and Repair, plus Hosting and Colocation
Newest Product: Vicidial Agent Only Beep - Beta
http://www.PoundTeam.com # 352-269-0000 # +44(203) 769-2294
williamconley
 
Posts: 20253
Joined: Wed Oct 31, 2007 4:17 pm
Location: Davenport, FL (By Disney!)


Return to Support

Who is online

Users browsing this forum: No registered users and 95 guests