Hacker News new | past | comments | ask | show | jobs | submit login
Current 0-day vulnerability on FreePBX (freepbx.org)
40 points by kimi on Dec 22, 2021 | hide | past | favorite | 7 comments



I've got a FreePBX 2.8 server (yes, 11 years old) that's been running my home phones for the last decade+. It runs CentOS 5.5, on a fanless Intel Atom CPU with 1GB of RAM.

I've hacked on it quite a bit, customizing some bits here and there. Learned a lot about SIP, UDP, Asterisk, a bit of PHP, Linux, apache, etc over the years. Been a lot of fun! Along the way at some point I swapped an SSD in to make it fully solid state.

I know one day I should "upgrade" it but the damn thing is so reliable. It will probably outlive me if I had to wager.


Please patch your software. Running exploitable services is a breeding ground for worms, DDoS, mail spam, etc. It put your data, your network at risk. It makes the internet less safe for everyone else.


> FreePBX . . . gives users the tools to build a phone system tailored to their needs.

For anyone wondering, like I was.


My first job was to tailor a FreePBX system to our users' "needs". Management decided that our sales team's "needs" are to get email reminders after each client call to keep the SalesForce log up to date.

The sales team did not agree with that, but it was fun to build anyway!


What linux to unix is what FreePBX TO PBX. Basically think it as an open source google voice. Any one interested in SMS, VoIP then this the project to take a look.


It's basically a pre configured Asterisk server with very, very many gui setings and lots of paid extensions.


That can basically do anything you can think of and then more.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: