On 23/04/11 8:45 AM, Tzafrir Cohen wrote:
So here's a mini poll:
Do you have a manager interface user that does not have all the read and
write permissions? If so: how have you managed to do so?
* Reading documentation / source
* An existing sample
* Trial and Error
Trial and Error - removed
On Thu, Apr 21, 2011 at 04:40:39PM -0500, Asterisk Security Team wrote:
>Asterisk Project Security Advisory - AST-2011-006
>
> ProductAsterisk
> SummaryAsterisk Manager User Shell Access
Asterisk Project Security Advisory - AST-2011-006
ProductAsterisk
SummaryAsterisk Manager User Shell Access
Nature of Advisory Permission Escalation