FW: [AusNOG] Heads up: Super awful FreePBX RCE

"Mark Foster" <[email protected]> Wed, 20 Nov 2019 18:19:02 +1300
Newsgroups gmane.org.operators.nznog
Message-ID <[email protected]>
This is a multipart message in MIME format.

------=_NextPart_000_00DB_01D59FCE.FD392E00
Content-Type: multipart/alternative;
	boundary="----=_NextPart_001_00DC_01D59FCE.FD392E00"


------=_NextPart_001_00DC_01D59FCE.FD392E00
Content-Type: text/plain;
	charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

NZNOG=E2=80=99s been a bit quiet lately!

=20

This might be of interest or relevance to NZ Operators, so FYI=E2=80=A6

=20

Cheers

Mark.

=20

=20

From: AusNOG <[email protected]> On Behalf Of Rob Thomas
Sent: Wednesday, 20 November 2019 4:24 pm
To: <[email protected]> <[email protected]>
Subject: [AusNOG] Heads up: Super awful FreePBX RCE

=20

If you have any FreePBX machines floating around, now is the time to =
make sure they're up to date, ESPECIALLY if they're visible from the =
interwebs.

=20

https://www.reddit.com/r/VOIP/comments/dypp36/20191119_critical_freepbx_s=
ecurity_vulnerability/=20

=20

I backdated it for those yanks who are living in the past, but it was =
discovered this morning.

=20

The quick summary is it's a trivial exploit, with the ability to =
escalate to a root shell - which means a pwned machine, all the attacker =
needs is unauthenticated visibility to any of the admin pages.

=20

Feel free to hit me up offlist if you need any more info.  And yes, it =
was my code that was vulnerable, but in my defence it was 12 year old =
code, and the vulnerability was only just discovered now 8)

=20

--Rob

=20

=20

=20


------=_NextPart_001_00DC_01D59FCE.FD392E00
Content-Type: text/html;
	charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

<html xmlns:v=3D"urn:schemas-microsoft-com:vml" =
xmlns:o=3D"urn:schemas-microsoft-com:office:office" =
xmlns:w=3D"urn:schemas-microsoft-com:office:word" =
xmlns:m=3D"http://schemas.microsoft.com/office/2004/12/omml" =
xmlns=3D"http://www.w3.org/TR/REC-html40"><head><meta =
http-equiv=3DContent-Type content=3D"text/html; charset=3Dutf-8"><meta =
name=3DGenerator content=3D"Microsoft Word 15 (filtered =
medium)"><style><!--
/* Font Definitions */
@font-face
	{font-family:"Cambria Math";
	panose-1:2 4 5 3 5 4 6 3 2 4;}
@font-face
	{font-family:Calibri;
	panose-1:2 15 5 2 2 2 4 3 2 4;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
	{margin:0cm;
	margin-bottom:.0001pt;
	font-size:11.0pt;
	font-family:"Calibri",sans-serif;}
a:link, span.MsoHyperlink
	{mso-style-priority:99;
	color:blue;
	text-decoration:underline;}
a:visited, span.MsoHyperlinkFollowed
	{mso-style-priority:99;
	color:purple;
	text-decoration:underline;}
p.msonormal0, li.msonormal0, div.msonormal0
	{mso-style-name:msonormal;
	mso-margin-top-alt:auto;
	margin-right:0cm;
	mso-margin-bottom-alt:auto;
	margin-left:0cm;
	font-size:11.0pt;
	font-family:"Calibri",sans-serif;}
span.EmailStyle18
	{mso-style-type:personal-reply;
	font-family:"Calibri",sans-serif;
	color:windowtext;}
.MsoChpDefault
	{mso-style-type:export-only;
	font-size:10.0pt;
	font-family:"Calibri",sans-serif;
	mso-fareast-language:EN-US;}
@page WordSection1
	{size:612.0pt 792.0pt;
	margin:72.0pt 72.0pt 72.0pt 72.0pt;}
div.WordSection1
	{page:WordSection1;}
--></style><!--[if gte mso 9]><xml>
<o:shapedefaults v:ext=3D"edit" spidmax=3D"1026" />
</xml><![endif]--><!--[if gte mso 9]><xml>
<o:shapelayout v:ext=3D"edit">
<o:idmap v:ext=3D"edit" data=3D"1" />
</o:shapelayout></xml><![endif]--></head><body lang=3DEN-NZ link=3Dblue =
vlink=3Dpurple><div class=3DWordSection1><p class=3DMsoNormal><span =
style=3D'mso-fareast-language:EN-US'>NZNOG=E2=80=99s been a bit quiet =
lately!<o:p></o:p></span></p><p class=3DMsoNormal><span =
style=3D'mso-fareast-language:EN-US'><o:p>&nbsp;</o:p></span></p><p =
class=3DMsoNormal><span style=3D'mso-fareast-language:EN-US'>This might =
be of interest or relevance to NZ Operators, so =
FYI=E2=80=A6<o:p></o:p></span></p><p class=3DMsoNormal><span =
style=3D'mso-fareast-language:EN-US'><o:p>&nbsp;</o:p></span></p><p =
class=3DMsoNormal><span =
style=3D'mso-fareast-language:EN-US'>Cheers<o:p></o:p></span></p><p =
class=3DMsoNormal><span =
style=3D'mso-fareast-language:EN-US'>Mark.<o:p></o:p></span></p><p =
class=3DMsoNormal><span =
style=3D'mso-fareast-language:EN-US'><o:p>&nbsp;</o:p></span></p><p =
class=3DMsoNormal><span =
style=3D'mso-fareast-language:EN-US'><o:p>&nbsp;</o:p></span></p><p =
class=3DMsoNormal><b><span lang=3DEN-US>From:</span></b><span =
lang=3DEN-US> AusNOG &lt;[email protected]&gt; <b>On =
Behalf Of </b>Rob Thomas<br><b>Sent:</b> Wednesday, 20 November 2019 =
4:24 pm<br><b>To:</b> &lt;[email protected]&gt; =
&lt;[email protected]&gt;<br><b>Subject:</b> [AusNOG] Heads up: =
Super awful FreePBX RCE<o:p></o:p></span></p><p =
class=3DMsoNormal><o:p>&nbsp;</o:p></p><div><p class=3DMsoNormal>If you =
have any FreePBX machines floating around, now is the time to make sure =
they're up to date, ESPECIALLY if they're visible from the =
interwebs.<o:p></o:p></p><div><p =
class=3DMsoNormal><o:p>&nbsp;</o:p></p></div><div><p =
class=3DMsoNormal><a =
href=3D"https://www.reddit.com/r/VOIP/comments/dypp36/20191119_critical_f=
reepbx_security_vulnerability/">https://www.reddit.com/r/VOIP/comments/dy=
pp36/20191119_critical_freepbx_security_vulnerability/</a>&nbsp;<o:p></o:=
p></p></div><div><p class=3DMsoNormal><o:p>&nbsp;</o:p></p></div><div><p =
class=3DMsoNormal>I backdated it for those yanks who are living in the =
past, but it was discovered this morning.<o:p></o:p></p></div><div><p =
class=3DMsoNormal><o:p>&nbsp;</o:p></p></div><div><p =
class=3DMsoNormal>The quick summary is it's a trivial exploit, with the =
ability to escalate to a root shell - which means a pwned machine, all =
the attacker needs is unauthenticated visibility to any of the admin =
pages.<o:p></o:p></p></div><div><p =
class=3DMsoNormal><o:p>&nbsp;</o:p></p></div><div><p =
class=3DMsoNormal>Feel free to hit me up offlist if you need any more =
info.&nbsp; And yes, it was my code that was vulnerable, but in my =
defence it was 12 year old code, and the vulnerability was only just =
discovered now 8)<o:p></o:p></p></div><div><p =
class=3DMsoNormal><o:p>&nbsp;</o:p></p></div><div><p =
class=3DMsoNormal>--Rob<o:p></o:p></p></div><div><p =
class=3DMsoNormal><o:p>&nbsp;</o:p></p></div><div><p =
class=3DMsoNormal><o:p>&nbsp;</o:p></p></div><div><p =
class=3DMsoNormal>&nbsp;<o:p></o:p></p></div></div></div></body></html>
------=_NextPart_001_00DC_01D59FCE.FD392E00--

------=_NextPart_000_00DB_01D59FCE.FD392E00
Content-Type: text/plain;
	name="Untitled attachment 00145.txt"
Content-Transfer-Encoding: 7bit
Content-Disposition: attachment;
	filename="Untitled attachment 00145.txt"

_______________________________________________
AusNOG mailing list
[email protected]
http://lists.ausnog.net/mailman/listinfo/ausnog

------=_NextPart_000_00DB_01D59FCE.FD392E00
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

_______________________________________________
NZNOG mailing list -- [email protected]
To unsubscribe send an email to [email protected]

------=_NextPart_000_00DB_01D59FCE.FD392E00--