Security: Credentials disclosure via <withheld>

6 posts / 0 new
Last post
obelisk
obelisk's picture
Security: Credentials disclosure via <withheld>

This is not the same as http://www.freepbx.org/forum/freepbx/development/security-gen-amp-conf-php

The ISO used to install - http://downloads.freepbxdistro.org/ISO/FreePBX-Distro-Net-32bit-1.88.210.57.iso - the latest as of 2/15/2012.

The details will be posted here on 2/22/2012

tonyclewis
tonyclewis's picture
well not giving us any

well not giving us any details on what the issue is does no good. You are running all over talking about security but not offering any details, solutions or how to re-create it. Feel free to send me a PM on the issue and I can look at it but these types of threads are useless and scare people without giving us any information.

Tony Lewis
Schmooze Com, Inc.
FreePBX Developer

obelisk
obelisk's picture
I would be happy to use the

I would be happy to use the official channel for reporting security issues to FPBX if there was one.
Does

work ?

BTW: I thinkI posted enough details for you to recreate the problem.
Check the other thread in the dev forum.

tonyclewis
tonyclewis's picture
I see nothing in that

I see nothing in that thread. Please contact me direct as I oversee the Distro part of FreePBX. You can also email

if you want and I and Philippe both get that email

Tony Lewis
Schmooze Com, Inc.
FreePBX Developer

tonyclewis
tonyclewis's picture
Ok so what was referring to

Ok so what was referring to is in this bug report. http://www.freepbx.org/trac/ticket/5585

The ARI Admin Username and Password was exposed in the /recordings directory without being logged into the ARI. This was not exposed anywhere else and was not disclosing the Admin Username and Password as was stated in other forumns but the ARI admin username and password. This was introduced 3 days ago by a mistake and has been corrected in the latest ARI Framework module.

Please note this only effect 2.10 Beta customers and only people who updated the ARI module in the past 3 days.

Tony Lewis
Schmooze Com, Inc.
FreePBX Developer

p_lindheimer
p_lindheimer's picture
obelisk, yes

obelisk,

yes

should work. Did you have issues with it, if so I will check it out.

philippe