Asterisk

Post Reply
German

Asterisk

Post by German »

Hi Team :

There is a new risk with the open vulnerabilities for PBX systems, please check http://labs.musecurity.com/advisories/MU-200608-01.txt , Does this issue represents a threat to Alcatel architecture ?

Thanks in advanced
User avatar
frank
Alcatel Unleashed Certified Guru
Alcatel Unleashed Certified Guru
Posts: 3386
Joined: 06 Jul 2004 00:18
Location: New York
Contact:

Post by frank »

If you can remote exploit, you might be able to become root.
If you become root, then you can look / change the configuration.

If you only have an IP trunk or analog or T1 trunk with Alcatel, I am pretty sure there are no risk.
Code Free Or Die
German

Asterisk

Post by German »

OK,

That means taking care with the password of root user, but as the other hand how do i know this feature has been installed and Is it in service into my pBX system ? How can I troubleshoot it to reach with this goal?

Thanks for your reply again.

German Medina
+511-9662-8500
User avatar
frank
Alcatel Unleashed Certified Guru
Alcatel Unleashed Certified Guru
Posts: 3386
Joined: 06 Jul 2004 00:18
Location: New York
Contact:

Post by frank »

Did you do the PBX configuration ?
Do a trkvisu all it will tell you if you have IP trunk
Code Free Or Die
German

Asterisk(*)

Post by German »

Last login: Thu Aug 24 16:09:58 from srv4760

Alcatel OmniPCX Enterprise
standard installation last performed: 31-Dec-2005 00:20:00



# The role of the CPU is MAIN
Application software identity

R6.1.1-f2.502-5-pe-c7

Business identification: R6.1.1

Release:
DELIVERY f2.502
Patch identification: 5
Dynamic patch identification: none

Country: pe
Cpu: c7

ACD VERSION
release : 6
bug_fixing : 1
protocol_id : 90
version_dy_hr_stat : 11

(101)xa001001> trkvisu all
output of all Trunk_Groups and Links
-------------------------------------------------------------------
Numb | Name | Type | Var. | Node | Pfx
-------------------------------------------------------------------
TG 0 | ISDN-OUT | T2 | ISDN | 1 => local | #100 or #9 or #*0 or #*9
TG 1 | ISDN-IN | T2 | ISDN | 1 => local | #*8
TG 3 | 4310093 | BCA | | 1 => local | #*23
TG 4 | 4314648 | BCA | | 1 => local | #*24
TG 5 | 4249975 | BCA | | 1 => local | #*25
TG 6 | Libre | BCA | | 1 => local | #*26
TG 7 | 4310358 | BCA | | 1 => local | #*27
TG 8 | PAAG | BCA | | 1 => local | #108 or #*28
TG 9 | 4238189 | BCA | | 1 => local | #*29
TG 10 | Claro | BCA | | 1 => local | #110 or #*30
TG 11 | Libre | BCA | | 1 => local | #*31
TG 12 | Telmex | T2 | ISDN | 1 => local | #112
TG 13 | PAAG-OUT | LIA | | 1 => local | #7
TG 14 | Libre | BCA | | 1 => local | No pfx
TG 15 | Movistar | BCA | | 1 => local | #115
TG 20 | L_Sur | LIA | | 1 => local | #120
TG 21 | Callao | LIA | | 1 => local | #121
TG 22 | L_Norte | LIA | | 1 => local | #122
TG 23 | L_Ciudad | LIA | | 1 => local | #123
TG 24 | L_Este | LIA | | 1 => local | #124
TG 26 | Hospitales | MIXTE | | 1 => local | #126
TG 27 | LaLibertad | LIA | | 1 => local | #127
TG 28 | Cuzco | LIA | | 1 => local | #128
TG 29 | Ayacucho | LIA | | 1 => local | #129
TG 30 | SanMartin | LIA | | 1 => local | #130
TG 31 | Junin | LIA | | 1 => local | #131
TG 32 | Lambayeque | LIA | | 1 => local | #132
TG 33 | Ica | LIA | | 1 => local | #133
TG 34 | Arequipa | LIA | | 1 => local | #134
TG 35 | PAAG-IN | LIA | | 1 => local | No pfx
TG 40 | ISDN-OUT2 | T2 | ISDN | 1 => local | #140
TG 41 | ISDN-OUT3 | T2 | ISDN | 1 => local | #141
-------------------------------------------------------------------
-------------------------------------------------------------------
(101)xa001001>
User avatar
frank
Alcatel Unleashed Certified Guru
Alcatel Unleashed Certified Guru
Posts: 3386
Joined: 06 Jul 2004 00:18
Location: New York
Contact:

Post by frank »

looks like you don t have on ..
under type, you should see T2-IP if you had one
Code Free Or Die
cavagnaro

Post by cavagnaro »

Hola German,

Te saluda Jorge Cornejo de eBD Perú, ustedes no cuentan con licencias para troncales IP. Que pruebas estas o deseas realizar?

A customer :D
German

asterisk(*)

Post by German »

Is there an aditional command to check : .. see T2-IP (type) ?

Thanks in advanced again,
cavagnaro

Post by cavagnaro »

You can check your licenses using spadmin under the command line.
German

asterisk(*)

Post by German »

Thanks Team for your assistant and the overall questions related with the issue.

See you the next topics

German Medina
9662-8500
Post Reply

Return to “GENERAL”