<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>security &#8211; Nerd Vittles</title>
	<atom:link href="https://nerdvittles.com/tag/security/feed/" rel="self" type="application/rss+xml" />
	<link>https://nerdvittles.com</link>
	<description>Ward Mundy&#039;s Technobabblelog</description>
	<lastBuildDate>Fri, 20 Oct 2023 12:20:14 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	

<image>
	<url>https://nerdvittles.com/wp-content/uploads/nerdvittles.png</url>
	<title>security &#8211; Nerd Vittles</title>
	<link>https://nerdvittles.com</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>Zero-Day Vulnerabilities Compromise All FreePBX Systems</title>
		<link>https://nerdvittles.com/zero-day-vulnerabilities-compromise-all-freepbx-systems/</link>
					<comments>https://nerdvittles.com/zero-day-vulnerabilities-compromise-all-freepbx-systems/#comments</comments>
		
		<dc:creator><![CDATA[ward]]></dc:creator>
		<pubDate>Sun, 17 Sep 2023 12:58:03 +0000</pubDate>
				<category><![CDATA[CentOS/SL Platform]]></category>
		<category><![CDATA[Incredible PBX]]></category>
		<category><![CDATA[Raspberry Pi]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Smartphones]]></category>
		<category><![CDATA[Technology]]></category>
		<category><![CDATA[Telephony]]></category>
		<category><![CDATA[Ubuntu/Debian]]></category>
		<category><![CDATA[asterisk]]></category>
		<category><![CDATA[freepbx]]></category>
		<category><![CDATA[IncrediblePBX]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[virtualization]]></category>
		<category><![CDATA[voip]]></category>
		<guid isPermaLink="false">https://nerdvittles.com/?p=37167</guid>

					<description><![CDATA[If you&#8217;re a user of Asterisk&#174; and FreePBX&#174;, the DEFCON 31 Conference in Las Vegas did not disappoint this year. It exposed not one but three critical, unpatched vulnerabilities in affected FreePBX-based platforms that can compromise your servers in under a minute. I would hasten to add that all of these vulnerabilities were disclosed to Sangoma&#174; months ago and remain unaddressed for months. What this meant was a hacker could easily get administrator privileges on your server with a blank&#8230; <a class="read-more" href="https://nerdvittles.com/zero-day-vulnerabilities-compromise-all-freepbx-systems/">Read More &#8250;</a>]]></description>
		
					<wfw:commentRss>https://nerdvittles.com/zero-day-vulnerabilities-compromise-all-freepbx-systems/feed/</wfw:commentRss>
			<slash:comments>2</slash:comments>
		
		
			</item>
		<item>
		<title>Sangoma Beefs Up FreePBX Security&#8230; For a Price</title>
		<link>https://nerdvittles.com/sangoma-beefs-up-freepbx-security-for-a-price/</link>
		
		<dc:creator><![CDATA[ward]]></dc:creator>
		<pubDate>Mon, 05 Dec 2022 14:19:23 +0000</pubDate>
				<category><![CDATA[CentOS/SL Platform]]></category>
		<category><![CDATA[Incredible PBX]]></category>
		<category><![CDATA[Raspberry Pi]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Technology]]></category>
		<category><![CDATA[Telephony]]></category>
		<category><![CDATA[Ubuntu/Debian]]></category>
		<category><![CDATA[asterisk]]></category>
		<category><![CDATA[freepbx]]></category>
		<category><![CDATA[IncrediblePBX]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[voip]]></category>
		<guid isPermaLink="false">https://nerdvittles.com/?p=36088</guid>

					<description><![CDATA[We&#8217;ve lost count of the number of FreePBX&#174; security breaches that were directly attributable to vulnerabilities in the FreePBX web interface. Suffice it to say, it was the reason that PBX in a Flash and Incredible PBX instituted the Travelin&#8217; Man 3 firewall a decade ago hiding the FreePBX GUI from everyone except those on a whitelist controlled by the PBX administrator. More than a decade later, Sangoma&#174; finally introduces Multi-Factor Authentication (MFA) with two major gotchas. First, you have&#8230; <a class="read-more" href="https://nerdvittles.com/sangoma-beefs-up-freepbx-security-for-a-price/">Read More &#8250;</a>]]></description>
		
		
		
			</item>
		<item>
		<title>Some Further Thoughts &#038; Solutions Regarding DDoS Attacks</title>
		<link>https://nerdvittles.com/some-further-thoughts-solutions-regarding-ddos-attacks/</link>
					<comments>https://nerdvittles.com/some-further-thoughts-solutions-regarding-ddos-attacks/#comments</comments>
		
		<dc:creator><![CDATA[ward]]></dc:creator>
		<pubDate>Mon, 27 Sep 2021 14:00:27 +0000</pubDate>
				<category><![CDATA[CentOS/SL Platform]]></category>
		<category><![CDATA[Cloud Computing]]></category>
		<category><![CDATA[Incredible PBX]]></category>
		<category><![CDATA[Raspberry Pi]]></category>
		<category><![CDATA[Technology]]></category>
		<category><![CDATA[Telephony]]></category>
		<category><![CDATA[Ubuntu/Debian]]></category>
		<category><![CDATA[asterisk]]></category>
		<category><![CDATA[freepbx]]></category>
		<category><![CDATA[FreeSWITCH]]></category>
		<category><![CDATA[IncrediblePBX]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[voip]]></category>
		<guid isPermaLink="false">https://nerdvittles.com/?p=34917</guid>

					<description><![CDATA[This month&#8217;s DDoS attacks on SIP infrastructure in the VoIP community should give us all pause to reflect upon what each of us can do to lessen the impact of these attacks in our Internet-centric community. Suffice it to say, DDoS attacks can be directed toward carriers (last week it was Bandwidth.com), VoIP providers (last week it was VoIP.ms), and VoIP servers (that would be your PBX). While they may not like it, carriers and many VoIP providers have the&#8230; <a class="read-more" href="https://nerdvittles.com/some-further-thoughts-solutions-regarding-ddos-attacks/">Read More &#8250;</a>]]></description>
		
					<wfw:commentRss>https://nerdvittles.com/some-further-thoughts-solutions-regarding-ddos-attacks/feed/</wfw:commentRss>
			<slash:comments>4</slash:comments>
		
		
			</item>
		<item>
		<title>Is SIP Trunking Safe &#038; Reliable in the DDoS World?</title>
		<link>https://nerdvittles.com/is-sip-trunking-safe-reliable-in-the-ddos-world/</link>
		
		<dc:creator><![CDATA[ward]]></dc:creator>
		<pubDate>Mon, 20 Sep 2021 19:00:11 +0000</pubDate>
				<category><![CDATA[Cellular Services]]></category>
		<category><![CDATA[CentOS/SL Platform]]></category>
		<category><![CDATA[Cloud Computing]]></category>
		<category><![CDATA[Google Voice & Svcs]]></category>
		<category><![CDATA[Incredible PBX]]></category>
		<category><![CDATA[Networking]]></category>
		<category><![CDATA[Raspberry Pi]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Technology]]></category>
		<category><![CDATA[Telephony]]></category>
		<category><![CDATA[Ubuntu/Debian]]></category>
		<category><![CDATA[asterisk]]></category>
		<category><![CDATA[freepbx]]></category>
		<category><![CDATA[FreeSWITCH]]></category>
		<category><![CDATA[IncrediblePBX]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[voip]]></category>
		<guid isPermaLink="false">http://nerdvittles.com/?p=34895</guid>

					<description><![CDATA[Since last Thursday when VoIP.ms suffered (and continues to suffer) one of the worst Distributed Denial of Service (DDOS) attacks in the VoIP era, we&#8217;ve been asked a thousand times whether any SIP trunking provider can provide a safe and reliable platform under circumstances similar to the VoIP.ms outage. We obviously cannot vouch for every trunking provider but, based upon our discussions with two of the major carriers that support Incredible PBX, we are confident that either of them could&#8230; <a class="read-more" href="https://nerdvittles.com/is-sip-trunking-safe-reliable-in-the-ddos-world/">Read More &#8250;</a>]]></description>
		
		
		
			</item>
		<item>
		<title>Blink Cameras: The Travelin&#8217; Man&#8217;s Dream Come True</title>
		<link>https://nerdvittles.com/blink-cameras-the-travelin-mans-dream-come-true/</link>
					<comments>https://nerdvittles.com/blink-cameras-the-travelin-mans-dream-come-true/#comments</comments>
		
		<dc:creator><![CDATA[ward]]></dc:creator>
		<pubDate>Mon, 12 Jul 2021 07:00:25 +0000</pubDate>
				<category><![CDATA[Home Automation]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Smartphones]]></category>
		<category><![CDATA[Streaming Devices]]></category>
		<category><![CDATA[Technology]]></category>
		<category><![CDATA[Video]]></category>
		<category><![CDATA[cloud computing]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[Wi-Fi]]></category>
		<category><![CDATA[WiFi]]></category>
		<guid isPermaLink="false">https://nerdvittles.com/?p=34676</guid>

					<description><![CDATA[Okay, I&#8217;ll admit it. Our family has morphed into a band of traveling gypsies. We&#8217;re spreading our time between four cities and four "homes." Not many folks are that crazy, but many of you have vacation homes thanks to Covid. And one of the first things that pops up on your to-do list is how to secure your residences when you&#8217;re not at home. Yes, you can pay a monitoring service in every location a hefty monthly fee to do&#8230; <a class="read-more" href="https://nerdvittles.com/blink-cameras-the-travelin-mans-dream-come-true/">Read More &#8250;</a>]]></description>
		
					<wfw:commentRss>https://nerdvittles.com/blink-cameras-the-travelin-mans-dream-come-true/feed/</wfw:commentRss>
			<slash:comments>3</slash:comments>
		
		
			</item>
		<item>
		<title>Mastering the Incredible PBX 16-15 Feature Set with Raspbian</title>
		<link>https://nerdvittles.com/mastering-the-incredible-pbx-16-15-feature-set-with-raspbian/</link>
		
		<dc:creator><![CDATA[ward]]></dc:creator>
		<pubDate>Wed, 28 Aug 2019 14:00:51 +0000</pubDate>
				<category><![CDATA[Incredible PBX]]></category>
		<category><![CDATA[Raspberry Pi]]></category>
		<category><![CDATA[Technology]]></category>
		<category><![CDATA[Telephony]]></category>
		<category><![CDATA[asterisk]]></category>
		<category><![CDATA[disa]]></category>
		<category><![CDATA[firewall]]></category>
		<category><![CDATA[IncrediblePBX]]></category>
		<category><![CDATA[raspberrypi]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[sip]]></category>
		<category><![CDATA[stt]]></category>
		<category><![CDATA[tts]]></category>
		<category><![CDATA[voip]]></category>
		<guid isPermaLink="false">http://nerdvittles.com/?p=30538</guid>

					<description><![CDATA[This week we&#8217;ll finish up our introduction of Incredible PBX&#174; 16-15 for the Raspberry Pi with a quick look at some of the additional features that are offered on this new platform and that were not covered in our first and second articles. These include text-to-speech apps for news, weather, and today in history as well as the sample ODBC apps for speed dialing and employee data base lookups. We&#8217;ll also walk you through the conferencing setup and document the&#8230; <a class="read-more" href="https://nerdvittles.com/mastering-the-incredible-pbx-16-15-feature-set-with-raspbian/">Read More &#8250;</a>]]></description>
		
		
		
			</item>
		<item>
		<title>Game Changer: Hooking Up Facebook with Incredible PBX</title>
		<link>https://nerdvittles.com/the-perfect-pair-facebook-hooks-up-with-incredible-pbx/</link>
		
		<dc:creator><![CDATA[ward]]></dc:creator>
		<pubDate>Mon, 02 Oct 2017 07:00:37 +0000</pubDate>
				<category><![CDATA[CentOS/SL Platform]]></category>
		<category><![CDATA[Cloud Computing]]></category>
		<category><![CDATA[Google Voice & Svcs]]></category>
		<category><![CDATA[Incredible PBX]]></category>
		<category><![CDATA[Internet/Web]]></category>
		<category><![CDATA[Networking]]></category>
		<category><![CDATA[Technology]]></category>
		<category><![CDATA[Telephony]]></category>
		<category><![CDATA[Wazo & XiVO]]></category>
		<category><![CDATA[android]]></category>
		<category><![CDATA[asterisk]]></category>
		<category><![CDATA[google voice]]></category>
		<category><![CDATA[gvoice]]></category>
		<category><![CDATA[IncrediblePBX]]></category>
		<category><![CDATA[iphone]]></category>
		<category><![CDATA[issabel]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[SMS]]></category>
		<category><![CDATA[voip]]></category>
		<category><![CDATA[Wazo]]></category>
		<guid isPermaLink="false">http://nerdvittles.com/?p=23469</guid>

					<description><![CDATA[There aren&#8217;t many VoIP discoveries that get us this excited about the future of telecom. But merging with 1.5 billion users plus Facebook&#8217;s enormous talent pool and technology resources is definitely something worthy of your attention. What a Facebook marriage with the VoIP platform could mean for the future of telecommunications is nothing short of earth-shattering. Few people still have home phones. Almost everyone has a Facebook account and a cellphone. If VoIP solutions for businesses fail to take those&#8230; <a class="read-more" href="https://nerdvittles.com/the-perfect-pair-facebook-hooks-up-with-incredible-pbx/">Read More &#8250;</a>]]></description>
		
		
		
			</item>
		<item>
		<title>VoIP Security: Installing SSL Certificates with Incredible PBX</title>
		<link>https://nerdvittles.com/voip-security-installing-ssl-certificates-with-incredible-pbx/</link>
					<comments>https://nerdvittles.com/voip-security-installing-ssl-certificates-with-incredible-pbx/#comments</comments>
		
		<dc:creator><![CDATA[ward]]></dc:creator>
		<pubDate>Mon, 25 Sep 2017 07:00:46 +0000</pubDate>
				<category><![CDATA[CentOS/SL Platform]]></category>
		<category><![CDATA[Incredible PBX]]></category>
		<category><![CDATA[Internet/Web]]></category>
		<category><![CDATA[Networking]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Technology]]></category>
		<category><![CDATA[Telephony]]></category>
		<category><![CDATA[Ubuntu/Debian]]></category>
		<category><![CDATA[Wazo & XiVO]]></category>
		<category><![CDATA[asterisk]]></category>
		<category><![CDATA[IncrediblePBX]]></category>
		<category><![CDATA[issabel]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[Wazo]]></category>
		<guid isPermaLink="false">http://nerdvittles.com/?p=23520</guid>

					<description><![CDATA[We&#8217;ve got some revolutionary VoIP projects coming your way over the next several weeks, but I&#8217;m sorry to say the hardest part of them is getting your server configured to use secure and encrypted web communications via HTTPS. This is quickly becoming a universal requirement of most of the major technology players. So what might not be the most glamorous VoIP topic for a Monday morning is not only necessary but long overdue. The good news is that obtaining, installing,&#8230; <a class="read-more" href="https://nerdvittles.com/voip-security-installing-ssl-certificates-with-incredible-pbx/">Read More &#8250;</a>]]></description>
		
					<wfw:commentRss>https://nerdvittles.com/voip-security-installing-ssl-certificates-with-incredible-pbx/feed/</wfw:commentRss>
			<slash:comments>1</slash:comments>
		
		
			</item>
		<item>
		<title>RTPbleed Security Alert: Asterisk Calls Can Be Intercepted</title>
		<link>https://nerdvittles.com/rtpbleed-security-alert-asterisk-calls-can-be-intercepted/</link>
					<comments>https://nerdvittles.com/rtpbleed-security-alert-asterisk-calls-can-be-intercepted/#comments</comments>
		
		<dc:creator><![CDATA[ward]]></dc:creator>
		<pubDate>Fri, 08 Sep 2017 07:00:23 +0000</pubDate>
				<category><![CDATA[CentOS/SL Platform]]></category>
		<category><![CDATA[Cloud Computing]]></category>
		<category><![CDATA[Incredible PBX]]></category>
		<category><![CDATA[Raspberry Pi]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Streaming Devices]]></category>
		<category><![CDATA[Technology]]></category>
		<category><![CDATA[Telephony]]></category>
		<category><![CDATA[Ubuntu/Debian]]></category>
		<category><![CDATA[Wazo & XiVO]]></category>
		<category><![CDATA[asterisk]]></category>
		<category><![CDATA[freepbx]]></category>
		<category><![CDATA[iptables]]></category>
		<category><![CDATA[issabel]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[sip]]></category>
		<category><![CDATA[Wazo]]></category>
		<guid isPermaLink="false">http://nerdvittles.com/?p=23361</guid>

					<description><![CDATA[If you&#8217;ve installed Asterisk&#174; during the past 4½ years, your server has a MAJOR security problem. If you didn&#8217;t already know, with Asterisk, your VoIP conversations actually are carried over a random UDP port using the Real Time Protocol (RTP), not the SIP port (UDP 5060) which handles the setup and teardown of your VoIP connections. It turns out that, since March 2013, all of that RTP traffic and thus your conversations could be intercepted and redirected by anyone on&#8230; <a class="read-more" href="https://nerdvittles.com/rtpbleed-security-alert-asterisk-calls-can-be-intercepted/">Read More &#8250;</a>]]></description>
		
					<wfw:commentRss>https://nerdvittles.com/rtpbleed-security-alert-asterisk-calls-can-be-intercepted/feed/</wfw:commentRss>
			<slash:comments>5</slash:comments>
		
		
			</item>
		<item>
		<title>3CX in the Cloud: 8 Great Ways to Secure Your Server</title>
		<link>https://nerdvittles.com/3cx-in-the-cloud-8-great-ways-to-secure-your-server/</link>
		
		<dc:creator><![CDATA[ward]]></dc:creator>
		<pubDate>Fri, 23 Jun 2017 12:00:52 +0000</pubDate>
				<category><![CDATA[Cloud Computing]]></category>
		<category><![CDATA[Incredible PBX]]></category>
		<category><![CDATA[Networking]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Technology]]></category>
		<category><![CDATA[Telephony]]></category>
		<category><![CDATA[cloud computing]]></category>
		<category><![CDATA[firewall]]></category>
		<category><![CDATA[IncrediblePBX]]></category>
		<category><![CDATA[pbx]]></category>
		<category><![CDATA[piaf]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[sip]]></category>
		<category><![CDATA[voip]]></category>
		<guid isPermaLink="false">http://nerdvittles.com/?p=22469</guid>

					<description><![CDATA[Now that many of you have taken advantage of the opportunity to deploy a free 3CX server, it seemed like an opportune time to share what we&#8217;ve learned while deploying 3CX on hosted platforms in the cloud. If you&#8217;ve followed our Nerd Vittles adventures over the years, you already know that our number one consideration with any PBX deployment is security. Without that, you&#8217;re just paying somebody else&#8217;s phone bill. While 3CX is extremely secure as delivered, once you choose&#8230; <a class="read-more" href="https://nerdvittles.com/3cx-in-the-cloud-8-great-ways-to-secure-your-server/">Read More &#8250;</a>]]></description>
		
		
		
			</item>
		<item>
		<title>Twofer Tuesday: 2 Cloud Servers for the Price of a RasPi</title>
		<link>https://nerdvittles.com/2-sandboxes-in-the-cloud-for-life-same-35-price-as-a-raspberry-pi/</link>
					<comments>https://nerdvittles.com/2-sandboxes-in-the-cloud-for-life-same-35-price-as-a-raspberry-pi/#comments</comments>
		
		<dc:creator><![CDATA[ward]]></dc:creator>
		<pubDate>Tue, 28 Feb 2017 07:00:27 +0000</pubDate>
				<category><![CDATA[Blogs]]></category>
		<category><![CDATA[CentOS/SL Platform]]></category>
		<category><![CDATA[Cloud Computing]]></category>
		<category><![CDATA[Google Voice & Svcs]]></category>
		<category><![CDATA[Internet/Web]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Technology]]></category>
		<category><![CDATA[Telephony]]></category>
		<category><![CDATA[cloud computing]]></category>
		<category><![CDATA[fail2ban]]></category>
		<category><![CDATA[firewall]]></category>
		<category><![CDATA[gpl]]></category>
		<category><![CDATA[iptables]]></category>
		<category><![CDATA[open source]]></category>
		<category><![CDATA[raspberrypi]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[virtualization]]></category>
		<category><![CDATA[vm]]></category>
		<category><![CDATA[wordpress]]></category>
		<guid isPermaLink="false">http://nerdvittles.com/?p=21392</guid>

					<description><![CDATA[It&#8217;s been more than a year since we last chatted about Cloud At Cost. Because they&#8217;re in the midst of yet another 50% off Fire Sale and to close out February with a bang, it seemed like a good time to take a fresh look at a terrific way to get started with Linux. For today&#8217;s $35 cloud project, we&#8217;re going to build a free WordPress server and a free commercial PBX compliments of 3CX. For what it&#8217;s worth, we&#8217;ve&#8230; <a class="read-more" href="https://nerdvittles.com/2-sandboxes-in-the-cloud-for-life-same-35-price-as-a-raspberry-pi/">Read More &#8250;</a>]]></description>
		
					<wfw:commentRss>https://nerdvittles.com/2-sandboxes-in-the-cloud-for-life-same-35-price-as-a-raspberry-pi/feed/</wfw:commentRss>
			<slash:comments>1</slash:comments>
		
		
			</item>
		<item>
		<title>Introducing a New WhiteList Security Model for Wazo</title>
		<link>https://nerdvittles.com/introducing-a-new-whitelist-security-model-for-wazo/</link>
					<comments>https://nerdvittles.com/introducing-a-new-whitelist-security-model-for-wazo/#comments</comments>
		
		<dc:creator><![CDATA[ward]]></dc:creator>
		<pubDate>Mon, 20 Feb 2017 15:30:30 +0000</pubDate>
				<category><![CDATA[Incredible PBX]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Technology]]></category>
		<category><![CDATA[Telephony]]></category>
		<category><![CDATA[Wazo & XiVO]]></category>
		<category><![CDATA[asterisk]]></category>
		<category><![CDATA[firewall]]></category>
		<category><![CDATA[IncrediblePBX]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[Wazo]]></category>
		<guid isPermaLink="false">http://nerdvittles.com/?p=21349</guid>

					<description><![CDATA[Today we&#8217;re pleased to introduce a new state-of-the-art Travelin&#8217; Man 3 firewall implementation for 2017. Five years ago, we developed a new security model for Asterisk&#174; servers that whitelisted those needing access while blocking everyone else. The design was simple. You can&#8217;t attack what you can&#8217;t see. Three years ago, we made Travelin&#8217; Man 3 more flexible for remote users with the addition of PortKnocker, a terrific tool providing temporary remote server access using a random three-number code. Today&#8217;s release&#8230; <a class="read-more" href="https://nerdvittles.com/introducing-a-new-whitelist-security-model-for-wazo/">Read More &#8250;</a>]]></description>
		
					<wfw:commentRss>https://nerdvittles.com/introducing-a-new-whitelist-security-model-for-wazo/feed/</wfw:commentRss>
			<slash:comments>1</slash:comments>
		
		
			</item>
		<item>
		<title>Integrating SIP URIs into XiVO for Free Worldwide Calling</title>
		<link>https://nerdvittles.com/integrating-sip-uris-into-xivo-for-free-worldwide-calling/</link>
		
		<dc:creator><![CDATA[ward]]></dc:creator>
		<pubDate>Mon, 26 Sep 2016 07:00:19 +0000</pubDate>
				<category><![CDATA[Incredible PBX]]></category>
		<category><![CDATA[Technology]]></category>
		<category><![CDATA[Telephony]]></category>
		<category><![CDATA[Wazo & XiVO]]></category>
		<category><![CDATA[asterisk]]></category>
		<category><![CDATA[IncrediblePBX]]></category>
		<category><![CDATA[inum]]></category>
		<category><![CDATA[pbx]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[sip]]></category>
		<category><![CDATA[sip phone]]></category>
		<category><![CDATA[voip]]></category>
		<category><![CDATA[XiVO]]></category>
		<guid isPermaLink="false">http://nerdvittles.com/?p=19578</guid>

					<description><![CDATA[It&#8217;s been a while since we&#8217;ve explored SIP URIs and all of the advantages that SIP URI calling brings to your PBX. Number one on that list is FREE calling to and from anyone on the planet so long as both of you have an Internet connection with a SIP phone or a VoIP server such as Incredible PBX for XiVO. SIP URIs are the fundamental building blocks for VoIP technology. Consider this. If everyone in the world had a&#8230; <a class="read-more" href="https://nerdvittles.com/integrating-sip-uris-into-xivo-for-free-worldwide-calling/">Read More &#8250;</a>]]></description>
		
		
		
			</item>
		<item>
		<title>Security 101: A Fresh Look at Incredible PBX Security Audit Methodology</title>
		<link>https://nerdvittles.com/security-101-a-fresh-look-at-incredible-pbx-security-audit-methodology/</link>
		
		<dc:creator><![CDATA[ward]]></dc:creator>
		<pubDate>Tue, 09 Aug 2016 13:13:41 +0000</pubDate>
				<category><![CDATA[Incredible PBX]]></category>
		<category><![CDATA[Networking]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Technology]]></category>
		<category><![CDATA[Telephony]]></category>
		<category><![CDATA[asterisk]]></category>
		<category><![CDATA[firewall]]></category>
		<category><![CDATA[freepbx]]></category>
		<category><![CDATA[google voice]]></category>
		<category><![CDATA[gvoice]]></category>
		<category><![CDATA[IncrediblePBX]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[XiVO]]></category>
		<guid isPermaLink="false">http://nerdvittles.com/?p=19099</guid>

					<description><![CDATA[Embed from Getty Images Incredible PBX remains one of the most secure VoIP server platforms on the planet for one simple reason. We always deploy a preconfigured Linux IPtables firewall with a whitelist that hides your server from everyone except you and trusted VoIP providers. IPtables is automatically configured and deployed as part of every initial install of Incredible PBX regardless of your platform. This includes XiVO with Debian 8 as well as CentOS 6 and 7, Ubuntu 14.04, Raspbian&#8230; <a class="read-more" href="https://nerdvittles.com/security-101-a-fresh-look-at-incredible-pbx-security-audit-methodology/">Read More &#8250;</a>]]></description>
		
		
		
			</item>
		<item>
		<title>Taking a Fresh Look at the Asterisk, FreePBX, and Incredible PBX Security Models</title>
		<link>https://nerdvittles.com/taking-a-fresh-look-at-the-asterisk-freepbx-and-incredible-pbx-security-models/</link>
		
		<dc:creator><![CDATA[ward]]></dc:creator>
		<pubDate>Mon, 18 Apr 2016 07:00:42 +0000</pubDate>
				<category><![CDATA[CentOS/SL Platform]]></category>
		<category><![CDATA[Cloud Computing]]></category>
		<category><![CDATA[Incredible PBX]]></category>
		<category><![CDATA[Networking]]></category>
		<category><![CDATA[Raspberry Pi]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Technology]]></category>
		<category><![CDATA[Telephony]]></category>
		<category><![CDATA[Ubuntu/Debian]]></category>
		<category><![CDATA[Wazo & XiVO]]></category>
		<category><![CDATA[asterisk]]></category>
		<category><![CDATA[firewall]]></category>
		<category><![CDATA[freepbx]]></category>
		<category><![CDATA[IncrediblePBX]]></category>
		<category><![CDATA[security]]></category>
		<guid isPermaLink="false">http://nerdvittles.com/?p=17710</guid>

					<description><![CDATA[Embed from Getty Images About once a year, we try to shine the spotlight on Asterisk&#174; security in hopes of saving lots of organizations and individuals a little bit (or a lot) of money. In light of last week&#8217;s major security lapse in the Asterisk&#174; dialplan of those using FreePBX&#174; since the Asterisk@Home days, now seemed like a good time for a review. As we&#8217;ve noted before, the problem with open source phone systems is they&#8217;re open source phone systems.&#8230; <a class="read-more" href="https://nerdvittles.com/taking-a-fresh-look-at-the-asterisk-freepbx-and-incredible-pbx-security-models/">Read More &#8250;</a>]]></description>
		
		
		
			</item>
		<item>
		<title>It&#8217;s Back: $10.50 Buys an Incredible PBX in the Cloud For Life&#8230; If You Hurry</title>
		<link>https://nerdvittles.com/the-ultimate-voip-sandbox-in-the-cloud-for-less-than-a-35-raspberry-pi-2/</link>
					<comments>https://nerdvittles.com/the-ultimate-voip-sandbox-in-the-cloud-for-less-than-a-35-raspberry-pi-2/#comments</comments>
		
		<dc:creator><![CDATA[ward]]></dc:creator>
		<pubDate>Mon, 14 Mar 2016 07:00:01 +0000</pubDate>
				<category><![CDATA[CentOS/SL Platform]]></category>
		<category><![CDATA[Cloud Computing]]></category>
		<category><![CDATA[Incredible PBX]]></category>
		<category><![CDATA[Internet/Web]]></category>
		<category><![CDATA[Networking]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Technology]]></category>
		<category><![CDATA[Telephony]]></category>
		<category><![CDATA[Ubuntu/Debian]]></category>
		<category><![CDATA[asterisk]]></category>
		<category><![CDATA[cloud computing]]></category>
		<category><![CDATA[fail2ban]]></category>
		<category><![CDATA[firewall]]></category>
		<category><![CDATA[freepbx]]></category>
		<category><![CDATA[gpl]]></category>
		<category><![CDATA[IncrediblePBX]]></category>
		<category><![CDATA[iptables]]></category>
		<category><![CDATA[open source]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[virtualization]]></category>
		<category><![CDATA[vm]]></category>
		<guid isPermaLink="false">http://nerdvittles.com/?p=16791</guid>

					<description><![CDATA[Embed from Getty Images In January, we began our new series on Cloud Computing by documenting how to build an awesome LAMP server in the Cloud using Linux. Today we&#8217;re again going to show you how to use the same Cloud platform and take advantage of the $10.50 coupon code TAKE70 to build an Incredible PBX in the Cloud FOR LIFE. When you&#8217;re finished, you&#8217;ll have a state-of-the-art Incredible PBX 13 server with hundreds of PBX features including free calling&#8230; <a class="read-more" href="https://nerdvittles.com/the-ultimate-voip-sandbox-in-the-cloud-for-less-than-a-35-raspberry-pi-2/">Read More &#8250;</a>]]></description>
		
					<wfw:commentRss>https://nerdvittles.com/the-ultimate-voip-sandbox-in-the-cloud-for-less-than-a-35-raspberry-pi-2/feed/</wfw:commentRss>
			<slash:comments>1</slash:comments>
		
		
			</item>
		<item>
		<title>The Ultimate Linux Sandbox in the Cloud for Less Than a $35 Raspberry Pi 2</title>
		<link>https://nerdvittles.com/the-ultimate-linux-sandbox-in-the-cloud-for-less-than-a-35-raspberry-pi/</link>
		
		<dc:creator><![CDATA[ward]]></dc:creator>
		<pubDate>Mon, 25 Jan 2016 07:00:10 +0000</pubDate>
				<category><![CDATA[CentOS/SL Platform]]></category>
		<category><![CDATA[Cloud Computing]]></category>
		<category><![CDATA[Incredible PBX]]></category>
		<category><![CDATA[Internet/Web]]></category>
		<category><![CDATA[Networking]]></category>
		<category><![CDATA[Technology]]></category>
		<category><![CDATA[Ubuntu/Debian]]></category>
		<category><![CDATA[cloud computing]]></category>
		<category><![CDATA[fail2ban]]></category>
		<category><![CDATA[firewall]]></category>
		<category><![CDATA[gpl]]></category>
		<category><![CDATA[iptables]]></category>
		<category><![CDATA[open source]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[virtualization]]></category>
		<category><![CDATA[vm]]></category>
		<category><![CDATA[wordpress]]></category>
		<guid isPermaLink="false">http://nerdvittles.com/?p=16630</guid>

					<description><![CDATA[Every few years we like to drop back and take a fresh look at the best way to get started with Linux. For those coming from the Windows World, it can be a painful process. Learning with a Cloud-based server can be especially dangerous because of the security risks. And then there&#8217;s the cost factor. Not everyone has several hundred dollars to buy hardware and, frankly, learning about Linux on a $35 Raspberry Pi can drive most newbies to drink.&#8230; <a class="read-more" href="https://nerdvittles.com/the-ultimate-linux-sandbox-in-the-cloud-for-less-than-a-35-raspberry-pi/">Read More &#8250;</a>]]></description>
		
		
		
			</item>
		<item>
		<title>Introducing the FUD-Free Firewall for FreePBX Distro and AsteriskNOW</title>
		<link>https://nerdvittles.com/firewalls-101-introducing-travelin-man-3-for-the-freepbx-distro-asterisknow/</link>
		
		<dc:creator><![CDATA[ward]]></dc:creator>
		<pubDate>Mon, 10 Aug 2015 10:00:12 +0000</pubDate>
				<category><![CDATA[Google Voice & Svcs]]></category>
		<category><![CDATA[Incredible PBX]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Technology]]></category>
		<category><![CDATA[Telephony]]></category>
		<category><![CDATA[asterisk]]></category>
		<category><![CDATA[firewall]]></category>
		<category><![CDATA[freepbx]]></category>
		<category><![CDATA[gpl]]></category>
		<category><![CDATA[IncrediblePBX]]></category>
		<category><![CDATA[security]]></category>
		<guid isPermaLink="false">http://nerdvittles.com/?p=14416</guid>

					<description><![CDATA[View image &#124; gettyimages.com After frequent complaints from our FreePBX&#174; users, we introduced a firewall application for the PBX in a Flash™ and Incredible PBX™ platforms that protected FreePBX resources. That was over 5 years ago. The product became Travelin&#8217; Man™ 3, an IPtables-based WhiteList that totally eliminated access to your Asterisk&#174; server unless a WhiteList entry had been authorized by the administrator. The application was further embellished over the years to facilitate access by remote users. First, we introduced&#8230; <a class="read-more" href="https://nerdvittles.com/firewalls-101-introducing-travelin-man-3-for-the-freepbx-distro-asterisknow/">Read More &#8250;</a>]]></description>
		
		
		
			</item>
		<item>
		<title>Firewalls 101: Why Every Asterisk Server Should Have a Functioning Firewall</title>
		<link>https://nerdvittles.com/firewalls-101-why-every-asterisk-server-should-have-a-functioning-firewall/</link>
					<comments>https://nerdvittles.com/firewalls-101-why-every-asterisk-server-should-have-a-functioning-firewall/#comments</comments>
		
		<dc:creator><![CDATA[ward]]></dc:creator>
		<pubDate>Mon, 03 Aug 2015 07:00:10 +0000</pubDate>
				<category><![CDATA[Incredible PBX]]></category>
		<category><![CDATA[Networking]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Technology]]></category>
		<category><![CDATA[Telephony]]></category>
		<category><![CDATA[asterisk]]></category>
		<category><![CDATA[firewall]]></category>
		<category><![CDATA[freepbx]]></category>
		<category><![CDATA[Internet/Web]]></category>
		<category><![CDATA[security]]></category>
		<guid isPermaLink="false">http://nerdvittles.com/?p=14349</guid>

					<description><![CDATA[View image &#124; gettyimages.com Part of our fundamental disagreement with the FreePBX&#174; design can be summed up in one word: FIREWALL or the lack of a functioning firewall in the FreePBX Distro and in the functionally identical Digium product, AsteriskNOW&#174;.1 Most of the other design choices including the controversial, non-GPL compliant Module Signature Checking mechanism are touted as failsafe ways to detect altered systems even though changes in FreePBX MySQL tables and Asterisk config files can be modified easily without&#8230; <a class="read-more" href="https://nerdvittles.com/firewalls-101-why-every-asterisk-server-should-have-a-functioning-firewall/">Read More &#8250;</a>]]></description>
		
					<wfw:commentRss>https://nerdvittles.com/firewalls-101-why-every-asterisk-server-should-have-a-functioning-firewall/feed/</wfw:commentRss>
			<slash:comments>1</slash:comments>
		
		
			</item>
		<item>
		<title>Firewalls and Internet Security: Separating FUD and Fiction in the VoIP World</title>
		<link>https://nerdvittles.com/firewalls-and-internet-security-separating-fud-and-fiction-in-the-voip-world/</link>
		
		<dc:creator><![CDATA[ward]]></dc:creator>
		<pubDate>Thu, 23 Apr 2015 13:20:55 +0000</pubDate>
				<category><![CDATA[Internet/Web]]></category>
		<category><![CDATA[Networking]]></category>
		<category><![CDATA[Technology]]></category>
		<category><![CDATA[Telephony]]></category>
		<category><![CDATA[asterisk]]></category>
		<category><![CDATA[firewall]]></category>
		<category><![CDATA[freepbx]]></category>
		<category><![CDATA[IncrediblePBX]]></category>
		<category><![CDATA[piaf]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[sip]]></category>
		<guid isPermaLink="false">http://nerdvittles.com/?p=12966</guid>

					<description><![CDATA[Some of us have spent years developing secure VoIP solutions for Asterisk&#174; that protect your phone bill while bringing Cloud-based solutions within reach of virtually anyone. So it&#8217;s particularly disappointing when a hardware manufacturer spreads fear, uncertainty, and doubt in order to peddle their hardware. In this case, it happens to be Session Border Controllers (SBCs). We want you to watch this latest "infomercial" for yourself: https://youtu.be/Bp_7m64k_ko To hear Sangoma tell it, every VoIP server protected by merely a firewall&#8230; <a class="read-more" href="https://nerdvittles.com/firewalls-and-internet-security-separating-fud-and-fiction-in-the-voip-world/">Read More &#8250;</a>]]></description>
		
		
		
			</item>
		<item>
		<title>Midnight Madness: Introducing Incredible PBX 12 with Asterisk 12 and FreePBX</title>
		<link>https://nerdvittles.com/midnight-madness-introducing-incredible-pbx-12-with-asterisk-12-and-freepbx/</link>
					<comments>https://nerdvittles.com/midnight-madness-introducing-incredible-pbx-12-with-asterisk-12-and-freepbx/#comments</comments>
		
		<dc:creator><![CDATA[ward]]></dc:creator>
		<pubDate>Mon, 01 Dec 2014 09:01:40 +0000</pubDate>
				<category><![CDATA[Technology]]></category>
		<category><![CDATA[Telephony]]></category>
		<category><![CDATA[asterisk]]></category>
		<category><![CDATA[fax]]></category>
		<category><![CDATA[freepbx]]></category>
		<category><![CDATA[iax]]></category>
		<category><![CDATA[IncrediblePBX]]></category>
		<category><![CDATA[iptables]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[sip]]></category>
		<guid isPermaLink="false">http://nerdvittles.com/?p=11041</guid>

					<description><![CDATA[[iframe-popup id="4&#8243;] The number "12&#8243; always has held mystical prominence in our culture and so it is with Asterisk&#174;. Just over 12 months ago, Digium first introduced Asterisk 12 at AstriCon in Atlanta and heralded a major change in the direction of the product. It was more than a wholesale revamping of the Asterisk feature set. There was a revolutionary new development methodology thanks to the untiring efforts of Matt Jordan and his incredibly talented development team. Unlike Asterisk releases&#8230; <a class="read-more" href="https://nerdvittles.com/midnight-madness-introducing-incredible-pbx-12-with-asterisk-12-and-freepbx/">Read More &#8250;</a>]]></description>
		
					<wfw:commentRss>https://nerdvittles.com/midnight-madness-introducing-incredible-pbx-12-with-asterisk-12-and-freepbx/feed/</wfw:commentRss>
			<slash:comments>4</slash:comments>
		
		
			</item>
		<item>
		<title>A Firsthand Look at Disaster Recovery: Tethering and IAX  with Asterisk</title>
		<link>https://nerdvittles.com/a-firsthand-look-at-disaster-recovery-tethering-and-iax-with-asterisk/</link>
					<comments>https://nerdvittles.com/a-firsthand-look-at-disaster-recovery-tethering-and-iax-with-asterisk/#comments</comments>
		
		<dc:creator><![CDATA[ward]]></dc:creator>
		<pubDate>Mon, 20 Oct 2014 12:16:35 +0000</pubDate>
				<category><![CDATA[Networking]]></category>
		<category><![CDATA[Smartphones]]></category>
		<category><![CDATA[Technology]]></category>
		<category><![CDATA[Telephony]]></category>
		<category><![CDATA[Wi-Fi]]></category>
		<category><![CDATA[asterisk]]></category>
		<category><![CDATA[google voice]]></category>
		<category><![CDATA[gvoice]]></category>
		<category><![CDATA[IncrediblePBX]]></category>
		<category><![CDATA[piaf]]></category>
		<category><![CDATA[security]]></category>
		<guid isPermaLink="false">http://nerdvittles.com/?p=10940</guid>

					<description><![CDATA[One of the exciting challenges of building a swimming pool is knowing that it&#8217;s just a matter of time until your Internet connection dies. As you might imagine, swimming pools are major construction and involve a lot of digging. And digging usually means some oops moments when cables get cut. In our case, we had watched the folks digging the trenches for all of the pool plumbing to be sure they didn&#8217;t accidentally whack one of three coax cables coming&#8230; <a class="read-more" href="https://nerdvittles.com/a-firsthand-look-at-disaster-recovery-tethering-and-iax-with-asterisk/">Read More &#8250;</a>]]></description>
		
					<wfw:commentRss>https://nerdvittles.com/a-firsthand-look-at-disaster-recovery-tethering-and-iax-with-asterisk/feed/</wfw:commentRss>
			<slash:comments>3</slash:comments>
		
		
			</item>
		<item>
		<title>Zero Day Vulnerability Protection and More: Introducing Cover Your Asterisk</title>
		<link>https://nerdvittles.com/zero-day-vulnerability-protection-and-more-introducing-cover-your-assterisk/</link>
		
		<dc:creator><![CDATA[ward]]></dc:creator>
		<pubDate>Mon, 06 Oct 2014 14:37:40 +0000</pubDate>
				<category><![CDATA[Technology]]></category>
		<category><![CDATA[Telephony]]></category>
		<category><![CDATA[asterisk]]></category>
		<category><![CDATA[firewall]]></category>
		<category><![CDATA[freepbx]]></category>
		<category><![CDATA[IncrediblePBX]]></category>
		<category><![CDATA[piaf]]></category>
		<category><![CDATA[security]]></category>
		<guid isPermaLink="false">http://nerdvittles.com/?p=10835</guid>

					<description><![CDATA[It&#8217;s been a difficult couple of weeks for the Linux&#174; and Asterisk&#174; communities with the back-to-back disclosures of the BASH Shellshock bug and then the FreePBX&#174; Asterisk Recording Interface (ARI) bug a few days later. Both of these vulnerabilities have been circulating in the wild for years. We won&#8217;t repeat Wikipedia&#8217;s Zero Day Attack analysis other than to note that what makes these particular bugs so scary is not only the fact that both went undetected and unpatched for years&#8230; <a class="read-more" href="https://nerdvittles.com/zero-day-vulnerability-protection-and-more-introducing-cover-your-assterisk/">Read More &#8250;</a>]]></description>
		
		
		
			</item>
		<item>
		<title>Hold On to Your Wallet: Another Huge VoIP Phone Bill May Be Lurking</title>
		<link>https://nerdvittles.com/hold-on-to-your-wallet-another-huge-voip-phone-bill-may-be-lurking/</link>
					<comments>https://nerdvittles.com/hold-on-to-your-wallet-another-huge-voip-phone-bill-may-be-lurking/#comments</comments>
		
		<dc:creator><![CDATA[ward]]></dc:creator>
		<pubDate>Wed, 01 Oct 2014 18:08:29 +0000</pubDate>
				<category><![CDATA[Technology]]></category>
		<category><![CDATA[Telephony]]></category>
		<category><![CDATA[asterisk]]></category>
		<category><![CDATA[freepbx]]></category>
		<category><![CDATA[IncrediblePBX]]></category>
		<category><![CDATA[piaf]]></category>
		<category><![CDATA[security]]></category>
		<guid isPermaLink="false">http://nerdvittles.com/?p=10779</guid>

					<description><![CDATA[View image &#124; gettyimages.com We interrupt our regularly scheduled content to bring you an urgent security alert. A couple days ago, a FreePBX&#174; user reported unusual call activity. He traced the calls to a System Admin Dashboard module that was linked back to an IP address in the Netherlands. When the problem was reported, the FreePBX Community Manager quite accurately noted that it wasn&#8217;t FreePBX code. When a second user reported the exact same exploit, alarm bells apparently went off.&#8230; <a class="read-more" href="https://nerdvittles.com/hold-on-to-your-wallet-another-huge-voip-phone-bill-may-be-lurking/">Read More &#8250;</a>]]></description>
		
					<wfw:commentRss>https://nerdvittles.com/hold-on-to-your-wallet-another-huge-voip-phone-bill-may-be-lurking/feed/</wfw:commentRss>
			<slash:comments>1</slash:comments>
		
		
			</item>
	</channel>
</rss>
