Here is the list (incomplete) of ways your trixbox can be hacked. Given most of the people use default passwords, exploiting most of these is trivial.
It is also amazing fonality continues to distribute the product with so many security holes enabled.
1. UDP port 5060.
Opening this port may allow internet users to place calls through your box.
You should almost never open this port.
2. TCP port 5038
This allows remote access to the manager interface ( read: full access to your asterisk instance, call origination, etc .... )
3. TCP/UDP port 11211
Access to memcached allows stealing your session credentials and login as maint user if access to your web interface is allowed.
Given the fact this port falls in the range of the default RTP ports (10000-20000) most users will have it enabled.
Memcached SHOULD NOT be used on trixbox.
4. TCP port 3306
This is the mysql port. You can modify the content of the database, read extensions/user credentials, create custom extensions, etc ....
5. TCP port 4445
FOP server - call management, etc ...
6. Port 80 and 443
Access to the admin web interface.
Additional info:
http://fonality.com/trixbox/forums/trixbox-forums/open-discussion...
http://fonality.com/trixbox/forums/trixbox-forums/open-discussion...
http://fonality.com/trixbox/forums/trixbox-forums/open-discussion...
http://fonality.com/trixbox/forums/trixbox-forums/open-discussion...
http://fonality.com/trixbox/forums/trixbox-forums/open-discussion...



Member Since:
2010-03-14