bar top left
bar top right
left curve
right curve
Welcome, Guest
Go to bottom
Post Reply
Post New Topic
Page: 12
TOPIC: SYSTEM HACKED
#54825
SYSTEM HACKED 1 Year, 10 Months ago Karma: 0
My system sits on a private network behind cisco router with public IP. Yet still I was the a victim of hacking. An hacker took over one of my extensions and made a massive amount of calls for the past three days depleting all my credit with VoIP provider.

Is there a command I can run to find the IP's where these calls came from, and any extra advise on how to totally lock down server would be appreciated

Thanks
Enter code here   
Please note: although no board code and smiley buttons are shown, they are still usable.
jmorrison26
Fresh Boarder
Posts: 26
graphgraph
User Offline Click here to see the profile of this user
Reply Quote
 
#54827
Re:SYSTEM HACKED 1 Year, 10 Months ago Karma: 130
Hi.
You could protect you with iptable, and fail2ban.
There's lots of posts about that on this forum.

Try to look at the asterisk logs : /var/log/asterisk/full

Good luck

Regards.
Enter code here   
Please note: although no board code and smiley buttons are shown, they are still usable.
danardf
Administrator
Posts: 5422
graph
User Offline Click here to see the profile of this user
Gender: Male Location: France - Trans sur Erdre Birthday: 12/31

Links hidden for unregistered users. Login or register Here - Links hidden for unregistered users. Login or register Here - Franck Danard - franckd@agmp.org
Reply Quote
 
#54830
Re:SYSTEM HACKED 1 Year, 10 Months ago Karma: 33
were your extensions using easy passwords?
Did you not limit your extensions to only LAN registration?

I would suggest that you read the security forum and all the good advices that are written in detail there. As Franck wrote the minimum to every system:

-use real password for extensions.
-use the permit/deny adapted to each extension use
-install fail2ban
-change all passwords (freepbx, elastix, mysql, fop, manager, ....)

you can add some others like
-use prepaid on your trunk provider to limit your losses in case of hack
You will find some really good articles on all these issues.
Enter code here   
Please note: although no board code and smiley buttons are shown, they are still usable.
Patrick_elx
Gold Boarder
Posts: 1112
graphgraph
User Offline Click here to see the profile of this user
Gender: Male Location: Florida, USA
Reply Quote
 
#54847
Re:SYSTEM HACKED 1 Year, 10 Months ago Karma: 0
I will try these methods immediately.

Also is there such a tool that can encrypted extension passwords, passwords are written in plain text then converted to hexadecimal.
Enter code here   
Please note: although no board code and smiley buttons are shown, they are still usable.
jmorrison26
Fresh Boarder
Posts: 26
graphgraph
User Offline Click here to see the profile of this user
Reply Quote
 
#54850
Re:SYSTEM HACKED 1 Year, 10 Months ago Karma: 130
Like md5sum

Yes, of course, you could use the encoded digest md5.
Example:
Code:

echo -n "100:asterisk:passwd" | md5sum


Regards
Enter code here   
Please note: although no board code and smiley buttons are shown, they are still usable.
danardf
Administrator
Posts: 5422
graph
User Offline Click here to see the profile of this user
Gender: Male Location: France - Trans sur Erdre Birthday: 12/31

Links hidden for unregistered users. Login or register Here - Links hidden for unregistered users. Login or register Here - Franck Danard - franckd@agmp.org
Reply Quote
 
#55140
Re:SYSTEM HACKED 1 Year, 10 Months ago Karma: 0
danardf wrote:
Like md5sum

Yes, of course, you could use the encoded digest md5.
Example:
Code:

echo -n "100:asterisk:passwd" | md5sum


Regards



Is there any other software that can be downloaded and used to encrypt passwords
Enter code here   
Please note: although no board code and smiley buttons are shown, they are still usable.
jmorrison26
Fresh Boarder
Posts: 26
graphgraph
User Offline Click here to see the profile of this user
Reply Quote
 
#55162
Re:SYSTEM HACKED 1 Year, 10 Months ago Karma: 130
Hmmm. I don't know.
I always use this to encrypt the password.
Maybe that yes.
Enter code here   
Please note: although no board code and smiley buttons are shown, they are still usable.
danardf
Administrator
Posts: 5422
graph
User Offline Click here to see the profile of this user
Gender: Male Location: France - Trans sur Erdre Birthday: 12/31

Links hidden for unregistered users. Login or register Here - Links hidden for unregistered users. Login or register Here - Franck Danard - franckd@agmp.org
Reply Quote
 
#55164
Re:SYSTEM HACKED 1 Year, 10 Months ago Karma: 130
Hmmm. I don't know.
I always use this to encrypt the password.
Maybe that yes.
Enter code here   
Please note: although no board code and smiley buttons are shown, they are still usable.
danardf
Administrator
Posts: 5422
graph
User Offline Click here to see the profile of this user
Gender: Male Location: France - Trans sur Erdre Birthday: 12/31

Links hidden for unregistered users. Login or register Here - Links hidden for unregistered users. Login or register Here - Franck Danard - franckd@agmp.org
Reply Quote
 
#55165
Re:SYSTEM HACKED 1 Year, 10 Months ago Karma: 130
Hmmm. I don't know.
I always use this to encrypt the password.
Maybe that yes.
Enter code here   
Please note: although no board code and smiley buttons are shown, they are still usable.
danardf
Administrator
Posts: 5422
graph
User Offline Click here to see the profile of this user
Gender: Male Location: France - Trans sur Erdre Birthday: 12/31

Links hidden for unregistered users. Login or register Here - Links hidden for unregistered users. Login or register Here - Franck Danard - franckd@agmp.org
Reply Quote
 
#55166
Re:SYSTEM HACKED 1 Year, 10 Months ago Karma: 156
Hello Franck

comment ca va? Argentina ou Brasil ?, pour moi c'est Brasil.


My opinion is if you need to protect your passwords with md5 (which is a good idea but not easily supported in FreePBX) then you have assumed that your system can be compromised, i.e. they have access to to your sip*.conf files

This is not acceptable and jmorrison26 MUST change ALL authorities he uses, with the extensions and the providers, setting every extension to use md5auth will be a real PITA in FreePBX and every extension he adds. I suggest a complete RESET, assume it is totally fucked up and just redo it with careful consideration, and reasonable security (use strong Eff$%%^^YF passwords) add fail2ban, CSF, rkhunter . . . whatever floats your boat.

JM2CWAE


dicko
Enter code here   
Please note: although no board code and smiley buttons are shown, they are still usable.
dicko
Ethically, I no longer support PaloSanto, Sorry.
Platinum Boarder
Posts: 4100
graphgraph
User Offline Click here to see the profile of this user
Gender: Male Location: Not available Birthday: 01/21
There are other solutions!!
Reply Quote
 
Go to top
Post Reply
Post New Topic
Page: 12
Moderators: Bob, jgutierrez
Protected by Spam Fighter