FREEPBX VULNERABILITY!
I'm getting many reports of compromised FreePBX servers, apparently, there is a bug in the Commercial Endpoint Manager (Commercial RestApps have been compromised twice)
No details yet on how this vulnerability works. Sangoma released a patch for 16 & 17.
But wait! There's more!
Remember @xrobau? It looks like he's working on something super cool!
I'm not sure if this is part of TangoPBX, or completely independent.
Regardless, I really hope he succeeds.
Thread: π§΅
I AM EXCITED!
New kid(s) on the block? (Plural? See all tweets)
Over the weekend, a new Community Forums emerged, run by @clearly_ip.
https://t.co/BTNsie8qjc
TangoPBX? We all know Tango. But will this be a fork from FreePBX or a complete ground-up-build? See my other thread.
In the meantime, you can engage in the forums, follow https://t.co/bguLlCpILX on @GitHub.
Follow @crosstalksol on @TikTok
It looks like the future is bright!
I AM EXCITED!
New kid(s) on the block? (Plural? See all tweets)
Over the weekend, a new Community Forums emerged, run by @clearly_ip.
https://t.co/BTNsie8qjc
Asterisk v22.1.0 has been released!
Some of these features are not in older versions.
Worth noting that v22 is an LTS release, get your v18 servers to v22!
https://t.co/htAjlO25LM
Sad to see the community getting destroyed.
We need to bring back the https://t.co/2OaAmUeNxP (VoIP User Conference) to revive the OSS community.
https://t.co/1CcnVqAqLB
We, the community, deserve some answers from @Sangoma!
According to the researcher, he attempted to reach out to Sangoma several times and even after they "patched" it, it was still possible to bypass the patch.
"Sangoma did not properly communicate:
π¨π¨π¨
PATCH YOUR FREEPBX SERVERS TODAY!
@Sangoma has released two patches addressing the @FreePBX CVE-2023-41903 vulnerability in Endpoint Manager and in Rest Apps.
Official Security Notice: https://t.co/CT3UZBbS9M