<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	
	>
<channel>
	<title>
	Comments on: FreePBX Backdoor Passwords Pose Asterisk Security Threat	</title>
	<atom:link href="https://nerdvittles.com/freepbx-backdoor-passwords-pose-asterisk-security-threat/feed/" rel="self" type="application/rss+xml" />
	<link>https://nerdvittles.com/freepbx-backdoor-passwords-pose-asterisk-security-threat/</link>
	<description>Ward Mundy&#039;s Technobabblelog</description>
	<lastBuildDate>Tue, 08 Dec 2015 15:39:07 +0000</lastBuildDate>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	
	<item>
		<title>
		By: Karmena		</title>
		<link>https://nerdvittles.com/freepbx-backdoor-passwords-pose-asterisk-security-threat/comment-page-1/#comment-14597</link>

		<dc:creator><![CDATA[Karmena]]></dc:creator>
		<pubDate>Fri, 20 May 2011 00:53:57 +0000</pubDate>
		<guid isPermaLink="false">http://nerdvittles.com/?p=737#comment-14597</guid>

					<description><![CDATA[Thank you for putting this post out, but I really don&#039;t understand. So you&#039;re saying, just by re-formating my system, and changing the default password, extension passwords, etc, I&#039;ll be safe? How do I get rid of the default usernames and passwords? Does the latest FreePBX have that taken care of, or is it still there? So if I&#039;ve been using FreePBX for years, and have been updating, making sure my passwords are secure etc., how should I go ahead and REFORMAT YEARS WORTH OF STUFF? I&#039;m really confused, since that means my business goes down for about a week or more! I know security is important, but so is feeding my children. And saying that I should use another product, instead of what I have built and customized and put my sweat and blood into... I mean if someone who was able to get into their server with the backdoor read this... they&#039;ll think its a doomsday message, &quot;my life is finished!&quot;, &quot;all my hard work goes down the drain!&quot; &quot;all is lost!&quot; Is there a way to recover and start over, without having downtime? I&#039;m just scard for those who read this, and don&#039;t know what to know what to do after the system has been compromised in such a cruel fashion]]></description>
			<content:encoded><![CDATA[<p>Thank you for putting this post out, but I really don&#8217;t understand. So you&#8217;re saying, just by re-formating my system, and changing the default password, extension passwords, etc, I&#8217;ll be safe? How do I get rid of the default usernames and passwords? Does the latest FreePBX have that taken care of, or is it still there? So if I&#8217;ve been using FreePBX for years, and have been updating, making sure my passwords are secure etc., how should I go ahead and REFORMAT YEARS WORTH OF STUFF? I&#8217;m really confused, since that means my business goes down for about a week or more! I know security is important, but so is feeding my children. And saying that I should use another product, instead of what I have built and customized and put my sweat and blood into&#8230; I mean if someone who was able to get into their server with the backdoor read this&#8230; they&#8217;ll think its a doomsday message, "my life is finished!", "all my hard work goes down the drain!" "all is lost!" Is there a way to recover and start over, without having downtime? I&#8217;m just scard for those who read this, and don&#8217;t know what to know what to do after the system has been compromised in such a cruel fashion</p>
]]></content:encoded>
		
			</item>
		<item>
		<title>
		By: Trousle Undrhil		</title>
		<link>https://nerdvittles.com/freepbx-backdoor-passwords-pose-asterisk-security-threat/comment-page-1/#comment-14168</link>

		<dc:creator><![CDATA[Trousle Undrhil]]></dc:creator>
		<pubDate>Thu, 28 Apr 2011 20:48:53 +0000</pubDate>
		<guid isPermaLink="false">http://nerdvittles.com/?p=737#comment-14168</guid>

					<description><![CDATA[While this might sound like a dumb question, I follow the camp of &quot;There is no such thing as a dumb question.&quot;  So, here it goes:

What is considered a weak password?  Something that I can guess on my own in a few hours?  Something that a hacker with the latest CPU and cracking software can guess in a few hours?  How many digits should be the minimum for a password?  Should there be a maximum number of digits?

&lt;i&gt;[WM: Six to eight alphanumeric characters with a couple of uppercase letters thrown in is virtually impossible to crack.]&lt;/i&gt;]]></description>
			<content:encoded><![CDATA[<p>While this might sound like a dumb question, I follow the camp of "There is no such thing as a dumb question."  So, here it goes:</p>
<p>What is considered a weak password?  Something that I can guess on my own in a few hours?  Something that a hacker with the latest CPU and cracking software can guess in a few hours?  How many digits should be the minimum for a password?  Should there be a maximum number of digits?</p>
<p><i>[WM: Six to eight alphanumeric characters with a couple of uppercase letters thrown in is virtually impossible to crack.]</i></p>
]]></content:encoded>
		
			</item>
		<item>
		<title>
		By: Kerry  Garrison		</title>
		<link>https://nerdvittles.com/freepbx-backdoor-passwords-pose-asterisk-security-threat/comment-page-1/#comment-14039</link>

		<dc:creator><![CDATA[Kerry  Garrison]]></dc:creator>
		<pubDate>Mon, 18 Apr 2011 18:53:32 +0000</pubDate>
		<guid isPermaLink="false">http://nerdvittles.com/?p=737#comment-14039</guid>

					<description><![CDATA[Excellent roundup of password issues. People think their phone system is safe and it is often the worst protected system on their network. I have heard many many times &quot;its secure because its Linux&quot;, anyone saying that shouldn&#039;t be installing these systems. A weak password is almost an open invitation to get hacked.]]></description>
			<content:encoded><![CDATA[<p>Excellent roundup of password issues. People think their phone system is safe and it is often the worst protected system on their network. I have heard many many times "its secure because its Linux", anyone saying that shouldn&#8217;t be installing these systems. A weak password is almost an open invitation to get hacked.</p>
]]></content:encoded>
		
			</item>
		<item>
		<title>
		By: Tony		</title>
		<link>https://nerdvittles.com/freepbx-backdoor-passwords-pose-asterisk-security-threat/comment-page-1/#comment-14017</link>

		<dc:creator><![CDATA[Tony]]></dc:creator>
		<pubDate>Fri, 15 Apr 2011 23:21:58 +0000</pubDate>
		<guid isPermaLink="false">http://nerdvittles.com/?p=737#comment-14017</guid>

					<description><![CDATA[Another reason people should move to FreePBX 2.9 as soon as it is final.  We added a option in Advanced Setting to disable the backdoor MySQL username and password login and the default setting of this is to disable the backdoor.  These were all things added to FreePBX as we started building a FreePBX Distro and focused on making sure it was secure, hence why we random generate MySQL and AMI username and password for each system and make you setup your own FreePBX admin page the first time you attempt to log in.  Default password are dangerous and most people never change them.]]></description>
			<content:encoded><![CDATA[<p>Another reason people should move to FreePBX 2.9 as soon as it is final.  We added a option in Advanced Setting to disable the backdoor MySQL username and password login and the default setting of this is to disable the backdoor.  These were all things added to FreePBX as we started building a FreePBX Distro and focused on making sure it was secure, hence why we random generate MySQL and AMI username and password for each system and make you setup your own FreePBX admin page the first time you attempt to log in.  Default password are dangerous and most people never change them.</p>
]]></content:encoded>
		
			</item>
		<item>
		<title>
		By: Rafael Cortes		</title>
		<link>https://nerdvittles.com/freepbx-backdoor-passwords-pose-asterisk-security-threat/comment-page-1/#comment-14011</link>

		<dc:creator><![CDATA[Rafael Cortes]]></dc:creator>
		<pubDate>Fri, 15 Apr 2011 15:48:45 +0000</pubDate>
		<guid isPermaLink="false">http://nerdvittles.com/?p=737#comment-14011</guid>

					<description><![CDATA[Besides changing the password, and following all the security tips that Ward provides, it is a good idea to talk to your sysadmin, or hire an external one that knows how to block and filter outgoing communications in your firewall. That usually stops bots, and &quot;phone home&quot; types of attacks, even from the &quot;authorized&quot; services (Like Trixbox did back in the day when they got aquired). 

The PBX should not begin any outgoing request except for specific ones to your providers, and the update server if so you wish, everything else SHOULD be blocked, and even the authorized ones should be filtered and monitored.

...just my 2 cents.

(Ward, greetings from Puerto Rico)]]></description>
			<content:encoded><![CDATA[<p>Besides changing the password, and following all the security tips that Ward provides, it is a good idea to talk to your sysadmin, or hire an external one that knows how to block and filter outgoing communications in your firewall. That usually stops bots, and "phone home" types of attacks, even from the "authorized" services (Like Trixbox did back in the day when they got aquired). </p>
<p>The PBX should not begin any outgoing request except for specific ones to your providers, and the update server if so you wish, everything else SHOULD be blocked, and even the authorized ones should be filtered and monitored.</p>
<p>&#8230;just my 2 cents.</p>
<p>(Ward, greetings from Puerto Rico)</p>
]]></content:encoded>
		
			</item>
		<item>
		<title>
		By: David		</title>
		<link>https://nerdvittles.com/freepbx-backdoor-passwords-pose-asterisk-security-threat/comment-page-1/#comment-14008</link>

		<dc:creator><![CDATA[David]]></dc:creator>
		<pubDate>Fri, 15 Apr 2011 12:36:53 +0000</pubDate>
		<guid isPermaLink="false">http://nerdvittles.com/?p=737#comment-14008</guid>

					<description><![CDATA[Thanks Ward.  Yet again, our two systems are still sleeping safe at night while others didn&#039;t know their kitchen window was left wide open.]]></description>
			<content:encoded><![CDATA[<p>Thanks Ward.  Yet again, our two systems are still sleeping safe at night while others didn&#8217;t know their kitchen window was left wide open.</p>
]]></content:encoded>
		
			</item>
		<item>
		<title>
		By: Andrew		</title>
		<link>https://nerdvittles.com/freepbx-backdoor-passwords-pose-asterisk-security-threat/comment-page-1/#comment-14007</link>

		<dc:creator><![CDATA[Andrew]]></dc:creator>
		<pubDate>Fri, 15 Apr 2011 12:24:29 +0000</pubDate>
		<guid isPermaLink="false">http://nerdvittles.com/?p=737#comment-14007</guid>

					<description><![CDATA[Yet another reason I&#039;m glad that I&#039;ve been using PBX in a Flash. Your focus on security in a niche market that often neglects security is very much appreciated.]]></description>
			<content:encoded><![CDATA[<p>Yet another reason I&#8217;m glad that I&#8217;ve been using PBX in a Flash. Your focus on security in a niche market that often neglects security is very much appreciated.</p>
]]></content:encoded>
		
			</item>
	</channel>
</rss>
