Re: [asterisk-users] Saving "admins" from themselves

2023-09-05 Thread Mark Murawski
Hi Dovid, There is no default manager.conf in the 'make basic-pbx' config build.  But there is however the sample manager.conf.sample which would get installed with 'make samples' config which has a giant security warning at the top of the file.  By default manager has enabled=no, and has a

[asterisk-users] Saving "admins" from themselves

2023-09-04 Thread Dovid Bender
Hi, We recently had a customer that set up Asterisk with port 5038 open to the world with standard configs for the AMI (by that I mean they copied and pasted configs that they saw online). Digging around a bit it seems the attacker used the AMI action "pjsip show auths" followed by "pjsip show