New Official Allstar Distribution Released
A new official Allstar Link Distribution is now available. It is called "DIAL" (Debian Install (for) Allstar Link). It is based on 'Debian Jessie', and supports a number of modern motherboards and other hardware configurations, of which the "Old Standard" (ACID) distro sadly fell short. It runs a VERY modern 3.X Linux kernel and DAHDI (as opposed to Zaptel, as was in the ACID distro). The ISO (installation) image may be downloaded at: http://dl.allstarlink.org/dial/dial-allstar-netinstall.iso Download the image, "burn" it to a CD or USB stick, install it, let it do its "installation stuff" (it reboots once or twice), and then, finally log in as 'root' with the password 'debian'. You will be taken through a script with a few questions, and then it will be ready to use. This is a result of a great deal of diligent work by Steve Zingman, N4IRS and Mike Zingman, N4IRR, without whom this would have not been possible. Please express your gratitude to them for making this possible. Jim, WB6NIL
As Jim himself would say, "Thanks, Dudes!" N5ZUA On 10/4/2015 10:00 PM, Jim Duuuude wrote:
A new official Allstar Link Distribution is now available. Please express your gratitude to them for making this possible. Jim, WB6NIL
_______________________________________________
I am very excited to try this out... in the next few days - Thanks! "Got Root?" How many software engineers does it take to change a light bulb? *None. It's a hardware problem.* Unix is user friendly. It's just very particular about who it's friends are. WINDOWS: Will Install Needless Data On Whole System MICROSOFT: Most Intelligent Customers Realize Our Software Only Fools Teenagers. A ntennas P oorly P laced L acks E ngineering The best way to accelerate a computer running Windows is at 9.81 m/s². *"I get paid to support Windows, I use Linux to get work done."* On Sun, Oct 4, 2015 at 8:24 PM, Steve Agee <n5zua@earthlink.net> wrote:
As Jim himself would say, "Thanks, Dudes!"
N5ZUA
On 10/4/2015 10:00 PM, Jim Duuuude wrote:
A new official Allstar Link Distribution is now available. Please express your gratitude to them for making this possible. Jim, WB6NIL
_______________________________________________
_______________________________________________ App_rpt-users mailing list App_rpt-users@ohnosec.org http://ohnosec.org/cgi-bin/mailman/listinfo/app_rpt-users
To unsubscribe from this list please visit http://ohnosec.org/cgi-bin/mailman/listinfo/app_rpt-users and scroll down to the bottom of the page. Enter your email address and press the "Unsubscribe or edit options button" You do not need a password to unsubscribe, you can do it via email confirmation. If you have trouble unsubscribing, please send a message to the list detailing the problem.
A Big thank you!! Loren Tedford (KC9ZHV) Email: lorentedford@gmail.com Main Line:1-631-686-8878 Option 1 for Loren. Fax Line 1:1-618-551-2755 Fax Line 2:1-631-686-8892 (New Fax line) Cell: 618-553-0806 http://www.lorentedford.com http://www.kc9zhv.com http://hub.kc9zhv.com On Sun, Oct 4, 2015 at 10:00 PM, Jim Duuuude <telesistant@hotmail.com> wrote:
A new official Allstar Link Distribution is now available.
It is called "DIAL" (Debian Install (for) Allstar Link).
It is based on 'Debian Jessie', and supports a number of modern motherboards and other hardware configurations, of which the "Old Standard" (ACID) distro sadly fell short.
It runs a VERY modern 3.X Linux kernel and DAHDI (as opposed to Zaptel, as was in the ACID distro).
The ISO (installation) image may be downloaded at:
<http://dl.allstarlink.org/dial/dial-allstar-netinstall.iso> http://dl.allstarlink.org/dial/dial-allstar-netinstall.iso
Download the image, "burn" it to a CD or USB stick, install it, let it do its "installation stuff" (it reboots once or twice), and then, finally log in as 'root' with the password 'debian'. You will be taken through a script with a few questions, and then it will be ready to use.
This is a result of a great deal of diligent work by Steve Zingman, N4IRS and Mike Zingman, N4IRR, without whom this would have not been possible.
Please express your gratitude to them for making this possible.
Jim, WB6NIL
_______________________________________________ App_rpt-users mailing list App_rpt-users@ohnosec.org http://ohnosec.org/cgi-bin/mailman/listinfo/app_rpt-users
To unsubscribe from this list please visit http://ohnosec.org/cgi-bin/mailman/listinfo/app_rpt-users and scroll down to the bottom of the page. Enter your email address and press the "Unsubscribe or edit options button" You do not need a password to unsubscribe, you can do it via email confirmation. If you have trouble unsubscribing, please send a message to the list detailing the problem.
A BIG thank you for this nice release. I am firing this in a VM machine today to check it.. cant wait ;-) Sent from my iPad
On Oct 4, 2015, at 11:00 PM, Jim Duuuude <telesistant@hotmail.com> wrote:
A new official Allstar Link Distribution is now available.
It is called "DIAL" (Debian Install (for) Allstar Link).
It is based on 'Debian Jessie', and supports a number of modern motherboards and other hardware configurations, of which the "Old Standard" (ACID) distro sadly fell short.
It runs a VERY modern 3.X Linux kernel and DAHDI (as opposed to Zaptel, as was in the ACID distro).
The ISO (installation) image may be downloaded at:
http://dl.allstarlink.org/dial/dial-allstar-netinstall.iso
Download the image, "burn" it to a CD or USB stick, install it, let it do its "installation stuff" (it reboots once or twice), and then, finally log in as 'root' with the password 'debian'. You will be taken through a script with a few questions, and then it will be ready to use.
This is a result of a great deal of diligent work by Steve Zingman, N4IRS and Mike Zingman, N4IRR, without whom this would have not been possible.
Please express your gratitude to them for making this possible.
Jim, WB6NIL
_______________________________________________ App_rpt-users mailing list App_rpt-users@ohnosec.org http://ohnosec.org/cgi-bin/mailman/listinfo/app_rpt-users
To unsubscribe from this list please visit http://ohnosec.org/cgi-bin/mailman/listinfo/app_rpt-users and scroll down to the bottom of the page. Enter your email address and press the "Unsubscribe or edit options button" You do not need a password to unsubscribe, you can do it via email confirmation. If you have trouble unsubscribing, please send a message to the list detailing the problem.
_______________________________________________ App_rpt-users mailing list App_rpt-users@ohnosec.org http://ohnosec.org/cgi-bin/mailman/listinfo/app_rpt-users To unsubscribe from this list please visit http://ohnosec.org/cgi-bin/mailman/listinfo/app_rpt-users and scroll down to the bottom of the page. Enter your email address and press the "Unsubscribe or edit options button" You do not need a password to unsubscribe, you can do it via email confirmation. If you have trouble unsubscribing, please send a message to the list detailing the problem.
I have been running this for a few months now with no issues at all. Very stable and it uses much less memory. Thanks for all the hard work from both Steve n4irs and the dude for making all this possible! Sent from my iPhone
On Oct 5, 2015, at 7:35 AM, pete M <petem001@hotmail.com> wrote:
A BIG thank you for this nice release.
I am firing this in a VM machine today to check it.. cant wait ;-)
Sent from my iPad
On Oct 4, 2015, at 11:00 PM, Jim Duuuude <telesistant@hotmail.com> wrote:
A new official Allstar Link Distribution is now available.
It is called "DIAL" (Debian Install (for) Allstar Link).
It is based on 'Debian Jessie', and supports a number of modern motherboards and other hardware configurations, of which the "Old Standard" (ACID) distro sadly fell short.
It runs a VERY modern 3.X Linux kernel and DAHDI (as opposed to Zaptel, as was in the ACID distro).
The ISO (installation) image may be downloaded at:
http://dl.allstarlink.org/dial/dial-allstar-netinstall.iso
Download the image, "burn" it to a CD or USB stick, install it, let it do its "installation stuff" (it reboots once or twice), and then, finally log in as 'root' with the password 'debian'. You will be taken through a script with a few questions, and then it will be ready to use.
This is a result of a great deal of diligent work by Steve Zingman, N4IRS and Mike Zingman, N4IRR, without whom this would have not been possible.
Please express your gratitude to them for making this possible.
Jim, WB6NIL
_______________________________________________ App_rpt-users mailing list App_rpt-users@ohnosec.org http://ohnosec.org/cgi-bin/mailman/listinfo/app_rpt-users
To unsubscribe from this list please visit http://ohnosec.org/cgi-bin/mailman/listinfo/app_rpt-users and scroll down to the bottom of the page. Enter your email address and press the "Unsubscribe or edit options button" You do not need a password to unsubscribe, you can do it via email confirmation. If you have trouble unsubscribing, please send a message to the list detailing the problem.
App_rpt-users mailing list App_rpt-users@ohnosec.org http://ohnosec.org/cgi-bin/mailman/listinfo/app_rpt-users
To unsubscribe from this list please visit http://ohnosec.org/cgi-bin/mailman/listinfo/app_rpt-users and scroll down to the bottom of the page. Enter your email address and press the "Unsubscribe or edit options button" You do not need a password to unsubscribe, you can do it via email confirmation. If you have trouble unsubscribing, please send a message to the list detailing the problem.
Is DIAL the official version based on Steves N4IRS' Bare Metal install polished?? If so, great. The last version of the Bare Metal install worked well for me. Sounds good! Will give it a shot. Like the USB install option!! Jon VA3RQ On 10/5/2015 7:43 AM, Corey Dean wrote:
I have been running this for a few months now with no issues at all. Very stable and it uses much less memory.
Thanks for all the hard work from both Steve n4irs and the dude for making all this possible!
Sent from my iPhone
On Oct 5, 2015, at 7:35 AM, pete M <petem001@hotmail.com <mailto:petem001@hotmail.com>> wrote:
A BIG thank you for this nice release.
I am firing this in a VM machine today to check it.. cant wait ;-)
Sent from my iPad
On Oct 4, 2015, at 11:00 PM, Jim Duuuude <telesistant@hotmail.com <mailto:telesistant@hotmail.com>> wrote:
A new official Allstar Link Distribution is now available.
It is called "DIAL" (Debian Install (for) Allstar Link).
It is based on 'Debian Jessie', and supports a number of modern motherboards and other hardware configurations, of which the "Old Standard" (ACID) distro sadly fell short.
It runs a VERY modern 3.X Linux kernel and DAHDI (as opposed to Zaptel, as was in the ACID distro).
The ISO (installation) image may be downloaded at:
http://dl.allstarlink.org/dial/dial-allstar-netinstall.iso
Download the image, "burn" it to a CD or USB stick, install it, let it do its "installation stuff" (it reboots once or twice), and then, finally log in as 'root' with the password 'debian'. You will be taken through a script with a few questions, and then it will be ready to use.
This is a result of a great deal of diligent work by Steve Zingman, N4IRS and Mike Zingman, N4IRR, without whom this would have not been possible.
Please express your gratitude to them for making this possible.
Jim, WB6NIL
_______________________________________________ App_rpt-users mailing list App_rpt-users@ohnosec.org <mailto:App_rpt-users@ohnosec.org> http://ohnosec.org/cgi-bin/mailman/listinfo/app_rpt-users
To unsubscribe from this list please visit http://ohnosec.org/cgi-bin/mailman/listinfo/app_rpt-users and scroll down to the bottom of the page. Enter your email address and press the "Unsubscribe or edit options button" You do not need a password to unsubscribe, you can do it via email confirmation. If you have trouble unsubscribing, please send a message to the list detailing the problem.
App_rpt-users mailing list App_rpt-users@ohnosec.org <mailto:App_rpt-users@ohnosec.org> http://ohnosec.org/cgi-bin/mailman/listinfo/app_rpt-users
To unsubscribe from this list please visit http://ohnosec.org/cgi-bin/mailman/listinfo/app_rpt-users and scroll down to the bottom of the page. Enter your email address and press the "Unsubscribe or edit options button" You do not need a password to unsubscribe, you can do it via email confirmation. If you have trouble unsubscribing, please send a message to the list detailing the problem.
_______________________________________________ App_rpt-users mailing list App_rpt-users@ohnosec.org http://ohnosec.org/cgi-bin/mailman/listinfo/app_rpt-users
To unsubscribe from this list please visit http://ohnosec.org/cgi-bin/mailman/listinfo/app_rpt-users and scroll down to the bottom of the page. Enter your email address and press the "Unsubscribe or edit options button" You do not need a password to unsubscribe, you can do it via email confirmation. If you have trouble unsubscribing, please send a message to the list detailing the problem.
Jon, It's version 1.0 with all that implies. It's better in some areas under the hood. The node setup scripts are now included along with more information to the user during install. root login via SSH is now allowed. SSH is listening on port 222. I still expect bugs and will squash them as quickly as possible. I also still want to hear from users with ideas. The same concepts used on the x86 will be applied to future platforms and SBC systems, some of them already in testing . 73, Steve N4IRS On 10/5/2015 8:29 AM, Jon Rorke wrote:
Is DIAL the official version based on Steves N4IRS' Bare Metal install polished??
If so, great. The last version of the Bare Metal install worked well for me.
Sounds good! Will give it a shot. Like the USB install option!!
Jon VA3RQ
On 10/5/2015 7:43 AM, Corey Dean wrote:
I have been running this for a few months now with no issues at all. Very stable and it uses much less memory.
Thanks for all the hard work from both Steve n4irs and the dude for making all this possible!
Sent from my iPhone
On Oct 5, 2015, at 7:35 AM, pete M <petem001@hotmail.com <mailto:petem001@hotmail.com>> wrote:
A BIG thank you for this nice release.
I am firing this in a VM machine today to check it.. cant wait ;-)
Sent from my iPad
On Oct 4, 2015, at 11:00 PM, Jim Duuuude <telesistant@hotmail.com> wrote:
A new official Allstar Link Distribution is now available.
It is called "DIAL" (Debian Install (for) Allstar Link).
It is based on 'Debian Jessie', and supports a number of modern motherboards and other hardware configurations, of which the "Old Standard" (ACID) distro sadly fell short.
It runs a VERY modern 3.X Linux kernel and DAHDI (as opposed to Zaptel, as was in the ACID distro).
The ISO (installation) image may be downloaded at:
http://dl.allstarlink.org/dial/dial-allstar-netinstall.iso
Download the image, "burn" it to a CD or USB stick, install it, let it do its "installation stuff" (it reboots once or twice), and then, finally log in as 'root' with the password 'debian'. You will be taken through a script with a few questions, and then it will be ready to use.
This is a result of a great deal of diligent work by Steve Zingman, N4IRS and Mike Zingman, N4IRR, without whom this would have not been possible.
Please express your gratitude to them for making this possible.
Jim, WB6NIL
_______________________________________________ App_rpt-users mailing list App_rpt-users@ohnosec.org <mailto:App_rpt-users@ohnosec.org> http://ohnosec.org/cgi-bin/mailman/listinfo/app_rpt-users
To unsubscribe from this list please visit http://ohnosec.org/cgi-bin/mailman/listinfo/app_rpt-users and scroll down to the bottom of the page. Enter your email address and press the "Unsubscribe or edit options button" You do not need a password to unsubscribe, you can do it via email confirmation. If you have trouble unsubscribing, please send a message to the list detailing the problem.
App_rpt-users mailing list App_rpt-users@ohnosec.org <mailto:App_rpt-users@ohnosec.org> http://ohnosec.org/cgi-bin/mailman/listinfo/app_rpt-users
To unsubscribe from this list please visit http://ohnosec.org/cgi-bin/mailman/listinfo/app_rpt-users and scroll down to the bottom of the page. Enter your email address and press the "Unsubscribe or edit options button" You do not need a password to unsubscribe, you can do it via email confirmation. If you have trouble unsubscribing, please send a message to the list detailing the problem.
_______________________________________________ App_rpt-users mailing list App_rpt-users@ohnosec.org http://ohnosec.org/cgi-bin/mailman/listinfo/app_rpt-users
To unsubscribe from this list please visithttp://ohnosec.org/cgi-bin/mailman/listinfo/app_rpt-users and scroll down to the bottom of the page. Enter your email address and press the "Unsubscribe or edit options button" You do not need a password to unsubscribe, you can do it via email confirmation. If you have trouble unsubscribing, please send a message to the list detailing the problem.
_______________________________________________ App_rpt-users mailing list App_rpt-users@ohnosec.org http://ohnosec.org/cgi-bin/mailman/listinfo/app_rpt-users
To unsubscribe from this list please visit http://ohnosec.org/cgi-bin/mailman/listinfo/app_rpt-users and scroll down to the bottom of the page. Enter your email address and press the "Unsubscribe or edit options button" You do not need a password to unsubscribe, you can do it via email confirmation. If you have trouble unsubscribing, please send a message to the list detailing the problem.
Thanks for all of your efforts! Dave N --- This email has been checked for viruses by Avast antivirus software. https://www.avast.com/antivirus
On 10/5/15 8:40 AM, Steve Zingman wrote:
It's version 1.0 with all that implies. It's better in some areas under the hood. The node setup scripts are now included along with more information to the user during install. root login via SSH is now allowed.
Cool, Is the rolling your own still supported? most of the reason I rolled my own was to run on Debian in the first place. Also, root login supported :( that's just a bad idea. Thanks for the awesome work. I know I've asked about the progress being made, if any, to get app_rpt back into mainline asterisk in the past. Has anything been happening on this front? 73's -- Bryan Fields 727-409-1194 - Voice 727-214-2508 - Fax http://bryanfields.net
Bryan, app_rpt.c and associated programs do not work with the newer versions of asterisk. The last release of asterisk that included app_rpt.c was 1.8.11.1, and while it compiles and loads, it is pretty outdated and doesn't work. Looking at the code (app_rpt.c and asterisk itself), and reading the forums that the asterisk developers post to, and considering that DAHDI needs to have some patches applied to it for it to work with app_rpt.c under asterisk, I can understand why Jim et all decided to fork the distro. -Stacy KG7QIN On 10/05/2015 11:56 AM, Bryan Fields wrote:
On 10/5/15 8:40 AM, Steve Zingman wrote:
It's version 1.0 with all that implies. It's better in some areas under the hood. The node setup scripts are now included along with more information to the user during install. root login via SSH is now allowed. Cool, Is the rolling your own still supported? most of the reason I rolled my own was to run on Debian in the first place.
Also, root login supported :( that's just a bad idea.
Thanks for the awesome work. I know I've asked about the progress being made, if any, to get app_rpt back into mainline asterisk in the past. Has anything been happening on this front?
73's
I agree with Stacy here. I use asterisk only as a platform for app rpt. I have not felt the need to use features in later versions for a repeater controller remote base or ROIP endpoint. I'm sure others will disagree, I only speak for myself. If there are security issues that need to be addressed, we need to find them and squash them if they cause a real concern. I have to go for the joke here, put a fork in it it's done. ;) 73, Steve N4IRS On 10/05/2015 03:44 PM, Stacy wrote:
Bryan, app_rpt.c and associated programs do not work with the newer versions of asterisk. The last release of asterisk that included app_rpt.c was 1.8.11.1, and while it compiles and loads, it is pretty outdated and doesn't work.
Looking at the code (app_rpt.c and asterisk itself), and reading the forums that the asterisk developers post to, and considering that DAHDI needs to have some patches applied to it for it to work with app_rpt.c under asterisk, I can understand why Jim et all decided to fork the distro.
-Stacy KG7QIN
On 10/05/2015 11:56 AM, Bryan Fields wrote:
On 10/5/15 8:40 AM, Steve Zingman wrote:
It's version 1.0 with all that implies. It's better in some areas under the hood. The node setup scripts are now included along with more information to the user during install. root login via SSH is now allowed. Cool, Is the rolling your own still supported? most of the reason I rolled my own was to run on Debian in the first place.
Also, root login supported :( that's just a bad idea.
Thanks for the awesome work. I know I've asked about the progress being made, if any, to get app_rpt back into mainline asterisk in the past. Has anything been happening on this front?
73's
App_rpt-users mailing list App_rpt-users@ohnosec.org http://ohnosec.org/cgi-bin/mailman/listinfo/app_rpt-users
To unsubscribe from this list please visit http://ohnosec.org/cgi-bin/mailman/listinfo/app_rpt-users and scroll down to the bottom of the page. Enter your email address and press the "Unsubscribe or edit options button" You do not need a password to unsubscribe, you can do it via email confirmation. If you have trouble unsubscribing, please send a message to the list detailing the problem.
-- "Anything is possible if you don't know what you are talking about." 1st Law of Logic
I would like to see new versions of Asterisk supported for one reason... webRTC. That would allow us to replace the crappy Java Webtransceiver with modern web apps, built into Allmon for example. On Mon, Oct 5, 2015 at 1:10 PM, Steve Zingman <szingman@msgstor.com> wrote:
I agree with Stacy here. I use asterisk only as a platform for app rpt. I have not felt the need to use features in later versions for a repeater controller remote base or ROIP endpoint. I'm sure others will disagree, I only speak for myself. If there are security issues that need to be addressed, we need to find them and squash them if they cause a real concern.
I have to go for the joke here, put a fork in it it's done. ;)
73, Steve N4IRS
On 10/05/2015 03:44 PM, Stacy wrote:
Bryan, app_rpt.c and associated programs do not work with the newer versions of asterisk. The last release of asterisk that included app_rpt.c was 1.8.11.1, and while it compiles and loads, it is pretty outdated and doesn't work.
Looking at the code (app_rpt.c and asterisk itself), and reading the forums that the asterisk developers post to, and considering that DAHDI needs to have some patches applied to it for it to work with app_rpt.c under asterisk, I can understand why Jim et all decided to fork the distro.
-Stacy KG7QIN
On 10/05/2015 11:56 AM, Bryan Fields wrote:
On 10/5/15 8:40 AM, Steve Zingman wrote:
It's version 1.0 with all that implies. It's better in some areas under the hood. The node setup scripts are now included along with more information to the user during install. root login via SSH is now allowed.
Cool, Is the rolling your own still supported? most of the reason I rolled my own was to run on Debian in the first place.
Also, root login supported :( that's just a bad idea.
Thanks for the awesome work. I know I've asked about the progress being made, if any, to get app_rpt back into mainline asterisk in the past. Has anything been happening on this front?
73's
_______________________________________________ App_rpt-users mailing list App_rpt-users@ohnosec.org http://ohnosec.org/cgi-bin/mailman/listinfo/app_rpt-users
To unsubscribe from this list please visit http://ohnosec.org/cgi-bin/mailman/listinfo/app_rpt-users and scroll down to the bottom of the page. Enter your email address and press the "Unsubscribe or edit options button" You do not need a password to unsubscribe, you can do it via email confirmation. If you have trouble unsubscribing, please send a message to the list detailing the problem.
-- "Anything is possible if you don't know what you are talking about." 1st Law of Logic
_______________________________________________ App_rpt-users mailing list App_rpt-users@ohnosec.org http://ohnosec.org/cgi-bin/mailman/listinfo/app_rpt-users
To unsubscribe from this list please visit http://ohnosec.org/cgi-bin/mailman/listinfo/app_rpt-users and scroll down to the bottom of the page. Enter your email address and press the "Unsubscribe or edit options button" You do not need a password to unsubscribe, you can do it via email confirmation. If you have trouble unsubscribing, please send a message to the list detailing the problem.
-- -- Tim
Bryan, Yes, rolling you own is still supported. I will continue to provide scripts and patches to install AllStar Asterisk on Debian. My scripts and patches will remain at <https://github.com/N4IRS/AllStar> DIAL is a really a Debian netinstall that sets up to download and install asterisk on first boot. It makes a number of assumptions of how a bare metal machine should be configured and downloads the source to DAHDI and Asterisk (From the SVN) to build a functional node. The decision to support root login has it's pluses and minuses. To retain compatibility with ACID it is enabled by default. During the testing of the image I had quite a few people needing help to login and edit files using tools like WinSCP. As you well know, it's trivial to turn off and I may add a question to the node setup scripts to make it easy to swap. My plate is quite full right now with 1.0 of DIAL, A brand new Android IAX client and preparations to update the PiStar and other SBC Debian images to mirror DIAL. If someone wants to tackle getting current Asterisk working with app_rpt I'll provide whatever I can. I know in the past it has been said it is not possible . 73, Steve N4IRS On 10/05/2015 02:56 PM, Bryan Fields wrote:
On 10/5/15 8:40 AM, Steve Zingman wrote:
It's version 1.0 with all that implies. It's better in some areas under the hood. The node setup scripts are now included along with more information to the user during install. root login via SSH is now allowed. Cool, Is the rolling your own still supported? most of the reason I rolled my own was to run on Debian in the first place.
Also, root login supported :( that's just a bad idea.
Thanks for the awesome work. I know I've asked about the progress being made, if any, to get app_rpt back into mainline asterisk in the past. Has anything been happening on this front?
73's
-- "Anything is possible if you don't know what you are talking about." 1st Law of Logic
Steve, I didn't want to say anything (since I haven't had a chance to call Jim yet), but since people are asking-- I've already started the port of the latest app_rpt.c (0.325) from the repository to asterisk 1.8-currenr (1.8.32.3), which is why I made the comment earlier. So far, having hacked back in some code that was removed from asterisk, I've been able to get app_rpt.c to answer, send telemetry, etc. What it doesn't do, and I haven't worked on this in several days, is be able to "dial" other systems and connect people once someone has connected to it. The program times out before detecting that the other end has responded and reports a connection failure. I've narrowed down the code that does the connection, processes the call and reports the failure. I have some ideas on what is causing it, but won't be able to look until a few more days. -Stacy KG7QIN On 10/05/2015 01:00 PM, Steve Zingman wrote:
Bryan, Yes, rolling you own is still supported. I will continue to provide scripts and patches to install AllStar Asterisk on Debian. My scripts and patches will remain at <https://github.com/N4IRS/AllStar>
DIAL is a really a Debian netinstall that sets up to download and install asterisk on first boot. It makes a number of assumptions of how a bare metal machine should be configured and downloads the source to DAHDI and Asterisk (From the SVN) to build a functional node.
The decision to support root login has it's pluses and minuses. To retain compatibility with ACID it is enabled by default. During the testing of the image I had quite a few people needing help to login and edit files using tools like WinSCP. As you well know, it's trivial to turn off and I may add a question to the node setup scripts to make it easy to swap.
My plate is quite full right now with 1.0 of DIAL, A brand new Android IAX client and preparations to update the PiStar and other SBC Debian images to mirror DIAL. If someone wants to tackle getting current Asterisk working with app_rpt I'll provide whatever I can. I know in the past it has been said it is not possible .
73, Steve N4IRS
On 10/05/2015 02:56 PM, Bryan Fields wrote:
On 10/5/15 8:40 AM, Steve Zingman wrote:
It's version 1.0 with all that implies. It's better in some areas under the hood. The node setup scripts are now included along with more information to the user during install. root login via SSH is now allowed. Cool, Is the rolling your own still supported? most of the reason I rolled my own was to run on Debian in the first place.
Also, root login supported :( that's just a bad idea.
Thanks for the awesome work. I know I've asked about the progress being made, if any, to get app_rpt back into mainline asterisk in the past. Has anything been happening on this front?
73's
Dave, Let's say I agree with you. And I well may. On most internet exposed machines, I don't even allow ssh unless I trust your address or require a VPN. I agree is common practice to not allow it. Now the question is why? As John McLaughlin would say, DISCUSS! On 10/05/2015 08:40 AM, Steve Zingman wrote:
/root login via SSH is now allowed / This is a bad idea. Root should *never* be allowed to login to a system remotely. It's better to log in as a normal user and then become root via su, sudo, etc.
- Dave
-- "Anything is possible if you don't know what you are talking about." 1st Law of Logic
Direct root login being disallowed IF there were no other way to get full root privileges (not the case here) was considered best practice. However in almost every case there is a user (on Raspbian user pi) that can simply login, sudo -s and do whatever they want. Yes it puts up a small hurdle but I don't see it as a serious one. In short, there is almost no setup that will allow you to completely lock out root with the exception of a few well designed appliances. And that means someone is out there doing support to get things resolved. This system is not of that flavor and root is necessary for many things so frankly adding a hurdle or two really doesn't appreciably make the system more secure. Require a long pass phrase (say 20 mixed characters or so) and this whole thing is moot... And BTW - putting sshd on port 222 (or anything except 22) is security by obscurity - many tools can find standard protocols on non-standard ports :-) (I know, I wrote one) The best bet is to not allow ssh at all. If that is not feasible then do the su or sudo thing and/or set up an intermediate system such that you access a non-privileged account on system A, then ssh to system B and system B will ONLY accept ssh from system A. Still can be beaten but it is a bit harder... And BTW - I have done infosec for about 20 years so I am allowed to have an opinion on this topic :-) Steven Donegan KK6IVC General Class FCC License Silver State Car #86 www.sscc.us From: Steve Zingman <szingman@msgstor.com> To: "app_rpt-users@ohnosec.org" <app_rpt-users@ohnosec.org> Sent: Monday, October 5, 2015 2:24 PM Subject: [App_rpt-users] New Official Allstar Distribution Released (DIAL) Dave, Let's say I agree with you. And I well may. On most internet exposed machines, I don't even allow ssh unless I trust your address or require a VPN. I agree is common practice to not allow it. Now the question is why? As John McLaughlin would say, DISCUSS! On 10/05/2015 08:40 AM, Steve Zingman wrote:
root login via SSH is now allowed
This is a bad idea. Root should *never* be allowed to login to a system remotely. It's better to log in as a normal user and then become root via su, sudo, etc.
- Dave
-- "Anything is possible if you don't know what you are talking about." 1st Law of Logic _______________________________________________ App_rpt-users mailing list App_rpt-users@ohnosec.org http://ohnosec.org/cgi-bin/mailman/listinfo/app_rpt-users To unsubscribe from this list please visit http://ohnosec.org/cgi-bin/mailman/listinfo/app_rpt-users and scroll down to the bottom of the page. Enter your email address and press the "Unsubscribe or edit options button" You do not need a password to unsubscribe, you can do it via email confirmation. If you have trouble unsubscribing, please send a message to the list detailing the problem.
Using a jump box as you describe is one way...not allowing SSH from the outside adds a layer; setting up a secue VDI capability to the jumpbox over a vpn is yet a third way...;). my rule: if it's exposed to the net, it's potentially vulnerable. Just turn on your SIP port and pop some popcorn to see...;) -- Bryan Sent from my iPhone 5...No electrons were harmed in the sending of this message.
On Oct 5, 2015, at 17:39, Steven Donegan <donegan@donegan.org> wrote:
Direct root login being disallowed IF there were no other way to get full root privileges (not the case here) was considered best practice. However in almost every case there is a user (on Raspbian user pi) that can simply login, sudo -s and do whatever they want. Yes it puts up a small hurdle but I don't see it as a serious one.
In short, there is almost no setup that will allow you to completely lock out root with the exception of a few well designed appliances. And that means someone is out there doing support to get things resolved. This system is not of that flavor and root is necessary for many things so frankly adding a hurdle or two really doesn't appreciably make the system more secure.
Require a long pass phrase (say 20 mixed characters or so) and this whole thing is moot...
And BTW - putting sshd on port 222 (or anything except 22) is security by obscurity - many tools can find standard protocols on non-standard ports :-) (I know, I wrote one)
The best bet is to not allow ssh at all. If that is not feasible then do the su or sudo thing and/or set up an intermediate system such that you access a non-privileged account on system A, then ssh to system B and system B will ONLY accept ssh from system A. Still can be beaten but it is a bit harder...
And BTW - I have done infosec for about 20 years so I am allowed to have an opinion on this topic :-)
Steven Donegan KK6IVC General Class FCC License Silver State Car #86 www.sscc.us
From: Steve Zingman <szingman@msgstor.com> To: "app_rpt-users@ohnosec.org" <app_rpt-users@ohnosec.org> Sent: Monday, October 5, 2015 2:24 PM Subject: [App_rpt-users] New Official Allstar Distribution Released (DIAL)
Dave, Let's say I agree with you. And I well may. On most internet exposed machines, I don't even allow ssh unless I trust your address or require a VPN. I agree is common practice to not allow it. Now the question is why?
As John McLaughlin would say, DISCUSS!
On 10/05/2015 08:40 AM, Steve Zingman wrote:
root login via SSH is now allowed
This is a bad idea. Root should *never* be allowed to login to a system remotely. It's better to log in as a normal user and then become root via su, sudo, etc.
- Dave
-- "Anything is possible if you don't know what you are talking about." 1st Law of Logic
_______________________________________________ App_rpt-users mailing list App_rpt-users@ohnosec.org http://ohnosec.org/cgi-bin/mailman/listinfo/app_rpt-users
To unsubscribe from this list please visit http://ohnosec.org/cgi-bin/mailman/listinfo/app_rpt-users and scroll down to the bottom of the page. Enter your email address and press the "Unsubscribe or edit options button" You do not need a password to unsubscribe, you can do it via email confirmation. If you have trouble unsubscribing, please send a message to the list detailing the problem.
_______________________________________________ App_rpt-users mailing list App_rpt-users@ohnosec.org http://ohnosec.org/cgi-bin/mailman/listinfo/app_rpt-users
To unsubscribe from this list please visit http://ohnosec.org/cgi-bin/mailman/listinfo/app_rpt-users and scroll down to the bottom of the page. Enter your email address and press the "Unsubscribe or edit options button" You do not need a password to unsubscribe, you can do it via email confirmation. If you have trouble unsubscribing, please send a message to the list detailing the problem.
Using certificates for ssh is yet another method :-) Steven Donegan KK6IVC General Class FCC License Silver State Car #86 www.sscc.us From: Bryan D. Boyle <bdboyle@bdboyle.com> To: Steven Donegan <donegan@donegan.org> Cc: Steve Zingman <szingman@msgstor.com>; "app_rpt-users@ohnosec.org" <app_rpt-users@ohnosec.org> Sent: Monday, October 5, 2015 2:49 PM Subject: Re: [App_rpt-users] New Official Allstar Distribution Released (DIAL) Using a jump box as you describe is one way...not allowing SSH from the outside adds a layer; setting up a secue VDI capability to the jumpbox over a vpn is yet a third way...;). my rule: if it's exposed to the net, it's potentially vulnerable. Just turn on your SIP port and pop some popcorn to see...;) --BryanSent from my iPhone 5...No electrons were harmed in the sending of this message. On Oct 5, 2015, at 17:39, Steven Donegan <donegan@donegan.org> wrote: Direct root login being disallowed IF there were no other way to get full root privileges (not the case here) was considered best practice. However in almost every case there is a user (on Raspbian user pi) that can simply login, sudo -s and do whatever they want. Yes it puts up a small hurdle but I don't see it as a serious one. In short, there is almost no setup that will allow you to completely lock out root with the exception of a few well designed appliances. And that means someone is out there doing support to get things resolved. This system is not of that flavor and root is necessary for many things so frankly adding a hurdle or two really doesn't appreciably make the system more secure. Require a long pass phrase (say 20 mixed characters or so) and this whole thing is moot... And BTW - putting sshd on port 222 (or anything except 22) is security by obscurity - many tools can find standard protocols on non-standard ports :-) (I know, I wrote one) The best bet is to not allow ssh at all. If that is not feasible then do the su or sudo thing and/or set up an intermediate system such that you access a non-privileged account on system A, then ssh to system B and system B will ONLY accept ssh from system A. Still can be beaten but it is a bit harder... And BTW - I have done infosec for about 20 years so I am allowed to have an opinion on this topic :-) Steven Donegan KK6IVC General Class FCC License Silver State Car #86 www.sscc.us From: Steve Zingman <szingman@msgstor.com> To: "app_rpt-users@ohnosec.org" <app_rpt-users@ohnosec.org> Sent: Monday, October 5, 2015 2:24 PM Subject: [App_rpt-users] New Official Allstar Distribution Released (DIAL) Dave, Let's say I agree with you. And I well may. On most internet exposed machines, I don't even allow ssh unless I trust your address or require a VPN. I agree is common practice to not allow it. Now the question is why? As John McLaughlin would say, DISCUSS! On 10/05/2015 08:40 AM, Steve Zingman wrote:
root login via SSH is now allowed
This is a bad idea. Root should *never* be allowed to login to a system remotely. It's better to log in as a normal user and then become root via su, sudo, etc.
- Dave
-- "Anything is possible if you don't know what you are talking about." 1st Law of Logic _______________________________________________ App_rpt-users mailing list App_rpt-users@ohnosec.org http://ohnosec.org/cgi-bin/mailman/listinfo/app_rpt-users To unsubscribe from this list please visit http://ohnosec.org/cgi-bin/mailman/listinfo/app_rpt-users and scroll down to the bottom of the page. Enter your email address and press the "Unsubscribe or edit options button" You do not need a password to unsubscribe, you can do it via email confirmation. If you have trouble unsubscribing, please send a message to the list detailing the problem. _______________________________________________ App_rpt-users mailing list App_rpt-users@ohnosec.org http://ohnosec.org/cgi-bin/mailman/listinfo/app_rpt-users To unsubscribe from this list please visit http://ohnosec.org/cgi-bin/mailman/listinfo/app_rpt-users and scroll down to the bottom of the page. Enter your email address and press the "Unsubscribe or edit options button" You do not need a password to unsubscribe, you can do it via email confirmation. If you have trouble unsubscribing, please send a message to the list detailing the problem.
Yep - disallowing keyboard-interactive and accepting only certificates. I turn off PermitRootLogin and only allow certificates. Barring some kind of exploit in sshd, that ought to be secure enough. Steven Donegan wrote:
Using certificates for ssh is yet another method :-) Steven Donegan KK6IVC General Class FCC License Silver State Car #86 www.sscc.us
------------------------------------------------------------------------ *From:* Bryan D. Boyle <bdboyle@bdboyle.com> *To:* Steven Donegan <donegan@donegan.org> *Cc:* Steve Zingman <szingman@msgstor.com>; "app_rpt-users@ohnosec.org" <app_rpt-users@ohnosec.org> *Sent:* Monday, October 5, 2015 2:49 PM *Subject:* Re: [App_rpt-users] New Official Allstar Distribution Released (DIAL)
Using a jump box as you describe is one way...not allowing SSH from the outside adds a layer; setting up a secue VDI capability to the jumpbox over a vpn is yet a third way...;).
my rule: if it's exposed to the net, it's potentially vulnerable. Just turn on your SIP port and pop some popcorn to see...;)
-- Bryan Sent from my iPhone 5...No electrons were harmed in the sending of this message.
On Oct 5, 2015, at 17:39, Steven Donegan <donegan@donegan.org <mailto:donegan@donegan.org>> wrote:
Direct root login being disallowed IF there were no other way to get full root privileges (not the case here) was considered best practice. However in almost every case there is a user (on Raspbian user pi) that can simply login, sudo -s and do whatever they want. Yes it puts up a small hurdle but I don't see it as a serious one.
In short, there is almost no setup that will allow you to completely lock out root with the exception of a few well designed appliances. And that means someone is out there doing support to get things resolved. This system is not of that flavor and root is necessary for many things so frankly adding a hurdle or two really doesn't appreciably make the system more secure.
Require a long pass phrase (say 20 mixed characters or so) and this whole thing is moot...
And BTW - putting sshd on port 222 (or anything except 22) is security by obscurity - many tools can find standard protocols on non-standard ports :-) (I know, I wrote one)
The best bet is to not allow ssh at all. If that is not feasible then do the su or sudo thing and/or set up an intermediate system such that you access a non-privileged account on system A, then ssh to system B and system B will ONLY accept ssh from system A. Still can be beaten but it is a bit harder...
And BTW - I have done infosec for about 20 years so I am allowed to have an opinion on this topic :-) Steven Donegan KK6IVC General Class FCC License Silver State Car #86 www.sscc.us <http://www.sscc.us/>
------------------------------------------------------------------------ *From:* Steve Zingman <szingman@msgstor.com <mailto:szingman@msgstor.com>> *To:* "app_rpt-users@ohnosec.org <mailto:app_rpt-users@ohnosec.org>" <app_rpt-users@ohnosec.org <mailto:app_rpt-users@ohnosec.org>> *Sent:* Monday, October 5, 2015 2:24 PM *Subject:* [App_rpt-users] New Official Allstar Distribution Released (DIAL)
Dave, Let's say I agree with you. And I well may. On most internet exposed machines, I don't even allow ssh unless I trust your address or require a VPN. I agree is common practice to not allow it. Now the question is why?
As John McLaughlin would say, DISCUSS!
On 10/05/2015 08:40 AM, Steve Zingman wrote:
/ root login via SSH is now allowed / This is a bad idea. Root should *never* be allowed to login to a system remotely. It's better to log in as a normal user and then become root via su, sudo, etc.
- Dave
-- "Anything is possible if you don't know what you are talking about." 1st Law of Logic
_______________________________________________ App_rpt-users mailing list App_rpt-users@ohnosec.org <mailto:App_rpt-users@ohnosec.org> http://ohnosec.org/cgi-bin/mailman/listinfo/app_rpt-users
To unsubscribe from this list please visit http://ohnosec.org/cgi-bin/mailman/listinfo/app_rpt-users <http://ohnosec.org/cgi-bin/mailman/listinfo/app_rpt-users>and scroll down to the bottom of the page. Enter your email address and press the "Unsubscribe or edit options button" You do not need a password to unsubscribe, you can do it via email confirmation. If you have trouble unsubscribing, please send a message to the list detailing the problem.
_______________________________________________ App_rpt-users mailing list App_rpt-users@ohnosec.org <mailto:App_rpt-users@ohnosec.org> http://ohnosec.org/cgi-bin/mailman/listinfo/app_rpt-users
To unsubscribe from this list please visit http://ohnosec.org/cgi-bin/mailman/listinfo/app_rpt-users and scroll down to the bottom of the page. Enter your email address and press the "Unsubscribe or edit options button" You do not need a password to unsubscribe, you can do it via email confirmation. If you have trouble unsubscribing, please send a message to the list detailing the problem.
_______________________________________________ App_rpt-users mailing list App_rpt-users@ohnosec.org http://ohnosec.org/cgi-bin/mailman/listinfo/app_rpt-users
To unsubscribe from this list please visit http://ohnosec.org/cgi-bin/mailman/listinfo/app_rpt-users and scroll down to the bottom of the page. Enter your email address and press the "Unsubscribe or edit options button" You do not need a password to unsubscribe, you can do it via email confirmation. If you have trouble unsubscribing, please send a message to the list detailing the problem.
BTW - I have a script to make a *NIX box a CA and generate certificates - that could easily be added to the DIAL/Pi/etc releases - let me see if I can scrounge it up :-) Assuming anyone would want that ability and Steve is OK with it :-) Steven Donegan KK6IVC General Class FCC License Silver State Car #86 www.sscc.us From: David Andrzejewski <david@davidandrzejewski.com> To: Steven Donegan <donegan@donegan.org> Cc: Bryan D. Boyle <bdboyle@bdboyle.com>; "app_rpt-users@ohnosec.org" <app_rpt-users@ohnosec.org> Sent: Monday, October 5, 2015 3:50 PM Subject: Re: [App_rpt-users] New Official Allstar Distribution Released (DIAL) Yep - disallowing keyboard-interactive and accepting only certificates. I turn off PermitRootLogin and only allow certificates. Barring some kind of exploit in sshd, that ought to be secure enough. Steven Donegan wrote: Using certificates for ssh is yet another method :-) Steven Donegan KK6IVC General Class FCC License Silver State Car #86 www.sscc.us From: Bryan D. Boyle <bdboyle@bdboyle.com> To: Steven Donegan <donegan@donegan.org> Cc: Steve Zingman <szingman@msgstor.com>; "app_rpt-users@ohnosec.org" <app_rpt-users@ohnosec.org> Sent: Monday, October 5, 2015 2:49 PM Subject: Re: [App_rpt-users] New Official Allstar Distribution Released (DIAL) Using a jump box as you describe is one way...not allowing SSH from the outside adds a layer; setting up a secue VDI capability to the jumpbox over a vpn is yet a third way...;). my rule: if it's exposed to the net, it's potentially vulnerable. Just turn on your SIP port and pop some popcorn to see...;) --BryanSent from my iPhone 5...No electrons were harmed in the sending of this message. On Oct 5, 2015, at 17:39, Steven Donegan <donegan@donegan.org> wrote: Direct root login being disallowed IF there were no other way to get full root privileges (not the case here) was considered best practice. However in almost every case there is a user (on Raspbian user pi) that can simply login, sudo -s and do whatever they want. Yes it puts up a small hurdle but I don't see it as a serious one. In short, there is almost no setup that will allow you to completely lock out root with the exception of a few well designed appliances. And that means someone is out there doing support to get things resolved. This system is not of that flavor and root is necessary for many things so frankly adding a hurdle or two really doesn't appreciably make the system more secure. Require a long pass phrase (say 20 mixed characters or so) and this whole thing is moot... And BTW - putting sshd on port 222 (or anything except 22) is security by obscurity - many tools can find standard protocols on non-standard ports :-) (I know, I wrote one) The best bet is to not allow ssh at all. If that is not feasible then do the su or sudo thing and/or set up an intermediate system such that you access a non-privileged account on system A, then ssh to system B and system B will ONLY accept ssh from system A. Still can be beaten but it is a bit harder... And BTW - I have done infosec for about 20 years so I am allowed to have an opinion on this topic :-) Steven Donegan KK6IVC General Class FCC License Silver State Car #86 www.sscc.us From: Steve Zingman <szingman@msgstor.com> To: "app_rpt-users@ohnosec.org" <app_rpt-users@ohnosec.org> Sent: Monday, October 5, 2015 2:24 PM Subject: [App_rpt-users] New Official Allstar Distribution Released (DIAL) Dave, Let's say I agree with you. And I well may. On most internet exposed machines, I don't even allow ssh unless I trust your address or require a VPN. I agree is common practice to not allow it. Now the question is why? As John McLaughlin would say, DISCUSS! On 10/05/2015 08:40 AM, Steve Zingman wrote:
root login via SSH is now allowed
This is a bad idea. Root should *never* be allowed to login to a system remotely. It's better to log in as a normal user and then become root via su, sudo, etc.
- Dave
-- "Anything is possible if you don't know what you are talking about." 1st Law of Logic _______________________________________________ App_rpt-users mailing list App_rpt-users@ohnosec.org http://ohnosec.org/cgi-bin/mailman/listinfo/app_rpt-users To unsubscribe from this list please visit http://ohnosec.org/cgi-bin/mailman/listinfo/app_rpt-users and scroll down to the bottom of the page. Enter your email address and press the "Unsubscribe or edit options button" You do not need a password to unsubscribe, you can do it via email confirmation. If you have trouble unsubscribing, please send a message to the list detailing the problem. _______________________________________________ App_rpt-users mailing list App_rpt-users@ohnosec.org http://ohnosec.org/cgi-bin/mailman/listinfo/app_rpt-users To unsubscribe from this list please visit http://ohnosec.org/cgi-bin/mailman/listinfo/app_rpt-users and scroll down to the bottom of the page. Enter your email address and press the "Unsubscribe or edit options button" You do not need a password to unsubscribe, you can do it via email confirmation. If you have trouble unsubscribing, please send a message to the list detailing the problem. _______________________________________________ App_rpt-users mailing list App_rpt-users@ohnosec.org http://ohnosec.org/cgi-bin/mailman/listinfo/app_rpt-users To unsubscribe from this list please visit http://ohnosec.org/cgi-bin/mailman/listinfo/app_rpt-users and scroll down to the bottom of the page. Enter your email address and press the "Unsubscribe or edit options button" You do not need a password to unsubscribe, you can do it via email confirmation. If you have trouble unsubscribing, please send a message to the list detailing the problem.
Sure, I think a hardening script might be in order (and optional). On 10/05/2015 06:55 PM, Steven Donegan wrote:
BTW - I have a script to make a *NIX box a CA and generate certificates - that could easily be added to the DIAL/Pi/etc releases - let me see if I can scrounge it up :-) Assuming anyone would want that ability and Steve is OK with it :-) Steven Donegan KK6IVC General Class FCC License Silver State Car #86 www.sscc.us
------------------------------------------------------------------------ *From:* David Andrzejewski <david@davidandrzejewski.com> *To:* Steven Donegan <donegan@donegan.org> *Cc:* Bryan D. Boyle <bdboyle@bdboyle.com>; "app_rpt-users@ohnosec.org" <app_rpt-users@ohnosec.org> *Sent:* Monday, October 5, 2015 3:50 PM *Subject:* Re: [App_rpt-users] New Official Allstar Distribution Released (DIAL)
Yep - disallowing keyboard-interactive and accepting only certificates. I turn off PermitRootLogin and only allow certificates. Barring some kind of exploit in sshd, that ought to be secure enough.
Steven Donegan wrote:
Using certificates for ssh is yet another method :-) Steven Donegan KK6IVC General Class FCC License Silver State Car #86 www.sscc.us <http://www.sscc.us/>
------------------------------------------------------------------------ *From:* Bryan D. Boyle <bdboyle@bdboyle.com> <mailto:bdboyle@bdboyle.com> *To:* Steven Donegan <donegan@donegan.org> <mailto:donegan@donegan.org> *Cc:* Steve Zingman <szingman@msgstor.com> <mailto:szingman@msgstor.com>; "app_rpt-users@ohnosec.org" <mailto:app_rpt-users@ohnosec.org> <app_rpt-users@ohnosec.org> <mailto:app_rpt-users@ohnosec.org> *Sent:* Monday, October 5, 2015 2:49 PM *Subject:* Re: [App_rpt-users] New Official Allstar Distribution Released (DIAL)
Using a jump box as you describe is one way...not allowing SSH from the outside adds a layer; setting up a secue VDI capability to the jumpbox over a vpn is yet a third way...;).
my rule: if it's exposed to the net, it's potentially vulnerable. Just turn on your SIP port and pop some popcorn to see...;)
-- Bryan Sent from my iPhone 5...No electrons were harmed in the sending of this message.
On Oct 5, 2015, at 17:39, Steven Donegan <donegan@donegan.org <mailto:donegan@donegan.org>> wrote:
Direct root login being disallowed IF there were no other way to get full root privileges (not the case here) was considered best practice. However in almost every case there is a user (on Raspbian user pi) that can simply login, sudo -s and do whatever they want. Yes it puts up a small hurdle but I don't see it as a serious one.
In short, there is almost no setup that will allow you to completely lock out root with the exception of a few well designed appliances. And that means someone is out there doing support to get things resolved. This system is not of that flavor and root is necessary for many things so frankly adding a hurdle or two really doesn't appreciably make the system more secure.
Require a long pass phrase (say 20 mixed characters or so) and this whole thing is moot...
And BTW - putting sshd on port 222 (or anything except 22) is security by obscurity - many tools can find standard protocols on non-standard ports :-) (I know, I wrote one)
The best bet is to not allow ssh at all. If that is not feasible then do the su or sudo thing and/or set up an intermediate system such that you access a non-privileged account on system A, then ssh to system B and system B will ONLY accept ssh from system A. Still can be beaten but it is a bit harder...
And BTW - I have done infosec for about 20 years so I am allowed to have an opinion on this topic :-) Steven Donegan KK6IVC General Class FCC License Silver State Car #86 www.sscc.us <http://www.sscc.us/>
------------------------------------------------------------------------ *From:* Steve Zingman <szingman@msgstor.com <mailto:szingman@msgstor.com>> *To:* "app_rpt-users@ohnosec.org <mailto:app_rpt-users@ohnosec.org>" <app_rpt-users@ohnosec.org <mailto:app_rpt-users@ohnosec.org>> *Sent:* Monday, October 5, 2015 2:24 PM *Subject:* [App_rpt-users] New Official Allstar Distribution Released (DIAL)
Dave, Let's say I agree with you. And I well may. On most internet exposed machines, I don't even allow ssh unless I trust your address or require a VPN. I agree is common practice to not allow it. Now the question is why?
As John McLaughlin would say, DISCUSS!
On 10/05/2015 08:40 AM, Steve Zingman wrote:
/root login via SSH is now allowed / This is a bad idea. Root should *never* be allowed to login to a system remotely. It's better to log in as a normal user and then become root via su, sudo, etc.
- Dave
-- "Anything is possible if you don't know what you are talking about." 1st Law of Logic
_______________________________________________ App_rpt-users mailing list App_rpt-users@ohnosec.org <mailto:App_rpt-users@ohnosec.org> http://ohnosec.org/cgi-bin/mailman/listinfo/app_rpt-users
To unsubscribe from this list please visit http://ohnosec.org/cgi-bin/mailman/listinfo/app_rpt-users and scroll down to the bottom of the page. Enter your email address and press the "Unsubscribe or edit options button" You do not need a password to unsubscribe, you can do it via email confirmation. If you have trouble unsubscribing, please send a message to the list detailing the problem.
_______________________________________________ App_rpt-users mailing list App_rpt-users@ohnosec.org <mailto:App_rpt-users@ohnosec.org> http://ohnosec.org/cgi-bin/mailman/listinfo/app_rpt-users
To unsubscribe from this list please visit http://ohnosec.org/cgi-bin/mailman/listinfo/app_rpt-users and scroll down to the bottom of the page. Enter your email address and press the "Unsubscribe or edit options button" You do not need a password to unsubscribe, you can do it via email confirmation. If you have trouble unsubscribing, please send a message to the list detailing the problem.
_______________________________________________ App_rpt-users mailing list App_rpt-users@ohnosec.org <mailto:App_rpt-users@ohnosec.org> http://ohnosec.org/cgi-bin/mailman/listinfo/app_rpt-users
To unsubscribe from this list please visithttp://ohnosec.org/cgi-bin/mailman/listinfo/app_rpt-users and scroll down to the bottom of the page. Enter your email address and press the "Unsubscribe or edit options button" You do not need a password to unsubscribe, you can do it via email confirmation. If you have trouble unsubscribing, please send a message to the list detailing the problem.
_______________________________________________ App_rpt-users mailing list App_rpt-users@ohnosec.org http://ohnosec.org/cgi-bin/mailman/listinfo/app_rpt-users
To unsubscribe from this list please visit http://ohnosec.org/cgi-bin/mailman/listinfo/app_rpt-users and scroll down to the bottom of the page. Enter your email address and press the "Unsubscribe or edit options button" You do not need a password to unsubscribe, you can do it via email confirmation. If you have trouble unsubscribing, please send a message to the list detailing the problem.
-- "Anything is possible if you don't know what you are talking about." 1st Law of Logic
Lets remember the root access is only enabled by default, and when you have you node configured then disable root access. Other roip/voip systems recommend this. I agree its a good idea to not expose the servers to the throbbing viruses waiting to attack us out side our routers. But lets not make it so locked down that us non-linux gurus cant get in. And if you do, please make a howto for us leser types so we can continue to enjoy or Allstar nodes! Thanks for the efforts! Jon VA3RQ On 10/5/2015 7:04 PM, Steve Zingman wrote:
Sure, I think a hardening script might be in order (and optional).
On 10/05/2015 06:55 PM, Steven Donegan wrote:
BTW - I have a script to make a *NIX box a CA and generate certificates - that could easily be added to the DIAL/Pi/etc releases - let me see if I can scrounge it up :-) Assuming anyone would want that ability and Steve is OK with it :-) Steven Donegan KK6IVC General Class FCC License Silver State Car #86 www.sscc.us
------------------------------------------------------------------------ *From:* David Andrzejewski <david@davidandrzejewski.com> *To:* Steven Donegan <donegan@donegan.org> *Cc:* Bryan D. Boyle <bdboyle@bdboyle.com>; "app_rpt-users@ohnosec.org" <app_rpt-users@ohnosec.org> *Sent:* Monday, October 5, 2015 3:50 PM *Subject:* Re: [App_rpt-users] New Official Allstar Distribution Released (DIAL)
Yep - disallowing keyboard-interactive and accepting only certificates. I turn off PermitRootLogin and only allow certificates. Barring some kind of exploit in sshd, that ought to be secure enough.
Steven Donegan wrote:
Using certificates for ssh is yet another method :-) Steven Donegan KK6IVC General Class FCC License Silver State Car #86 www.sscc.us <http://www.sscc.us/>
------------------------------------------------------------------------ *From:* Bryan D. Boyle <bdboyle@bdboyle.com> *To:* Steven Donegan <donegan@donegan.org> *Cc:* Steve Zingman <szingman@msgstor.com> <mailto:szingman@msgstor.com>; "app_rpt-users@ohnosec.org" <mailto:app_rpt-users@ohnosec.org> <app_rpt-users@ohnosec.org> <mailto:app_rpt-users@ohnosec.org> *Sent:* Monday, October 5, 2015 2:49 PM *Subject:* Re: [App_rpt-users] New Official Allstar Distribution Released (DIAL)
Using a jump box as you describe is one way...not allowing SSH from the outside adds a layer; setting up a secue VDI capability to the jumpbox over a vpn is yet a third way...;).
my rule: if it's exposed to the net, it's potentially vulnerable. Just turn on your SIP port and pop some popcorn to see...;)
-- Bryan Sent from my iPhone 5...No electrons were harmed in the sending of this message.
On Oct 5, 2015, at 17:39, Steven Donegan <donegan@donegan.org> wrote:
Direct root login being disallowed IF there were no other way to get full root privileges (not the case here) was considered best practice. However in almost every case there is a user (on Raspbian user pi) that can simply login, sudo -s and do whatever they want. Yes it puts up a small hurdle but I don't see it as a serious one.
In short, there is almost no setup that will allow you to completely lock out root with the exception of a few well designed appliances. And that means someone is out there doing support to get things resolved. This system is not of that flavor and root is necessary for many things so frankly adding a hurdle or two really doesn't appreciably make the system more secure.
Require a long pass phrase (say 20 mixed characters or so) and this whole thing is moot...
And BTW - putting sshd on port 222 (or anything except 22) is security by obscurity - many tools can find standard protocols on non-standard ports :-) (I know, I wrote one)
The best bet is to not allow ssh at all. If that is not feasible then do the su or sudo thing and/or set up an intermediate system such that you access a non-privileged account on system A, then ssh to system B and system B will ONLY accept ssh from system A. Still can be beaten but it is a bit harder...
And BTW - I have done infosec for about 20 years so I am allowed to have an opinion on this topic :-) Steven Donegan KK6IVC General Class FCC License Silver State Car #86 www.sscc.us <http://www.sscc.us/>
------------------------------------------------------------------------ *From:* Steve Zingman <szingman@msgstor.com> *To:* "app_rpt-users@ohnosec.org" <app_rpt-users@ohnosec.org> *Sent:* Monday, October 5, 2015 2:24 PM *Subject:* [App_rpt-users] New Official Allstar Distribution Released (DIAL)
Dave, Let's say I agree with you. And I well may. On most internet exposed machines, I don't even allow ssh unless I trust your address or require a VPN. I agree is common practice to not allow it. Now the question is why?
As John McLaughlin would say, DISCUSS!
On 10/05/2015 08:40 AM, Steve Zingman wrote:
/ root login via SSH is now allowed / This is a bad idea. Root should *never* be allowed to login to a system remotely. It's better to log in as a normal user and then become root via su, sudo, etc.
- Dave
-- "Anything is possible if you don't know what you are talking about." 1st Law of Logic
_______________________________________________ App_rpt-users mailing list App_rpt-users@ohnosec.org http://ohnosec.org/cgi-bin/mailman/listinfo/app_rpt-users
To unsubscribe from this list please visit http://ohnosec.org/cgi-bin/mailman/listinfo/app_rpt-users and scroll down to the bottom of the page. Enter your email address and press the "Unsubscribe or edit options button" You do not need a password to unsubscribe, you can do it via email confirmation. If you have trouble unsubscribing, please send a message to the list detailing the problem.
_______________________________________________ App_rpt-users mailing list App_rpt-users@ohnosec.org <mailto:App_rpt-users@ohnosec.org> http://ohnosec.org/cgi-bin/mailman/listinfo/app_rpt-users
To unsubscribe from this list please visit http://ohnosec.org/cgi-bin/mailman/listinfo/app_rpt-users and scroll down to the bottom of the page. Enter your email address and press the "Unsubscribe or edit options button" You do not need a password to unsubscribe, you can do it via email confirmation. If you have trouble unsubscribing, please send a message to the list detailing the problem.
_______________________________________________ App_rpt-users mailing list App_rpt-users@ohnosec.org <mailto:App_rpt-users@ohnosec.org> http://ohnosec.org/cgi-bin/mailman/listinfo/app_rpt-users
To unsubscribe from this list please visithttp://ohnosec.org/cgi-bin/mailman/listinfo/app_rpt-users and scroll down to the bottom of the page. Enter your email address and press the "Unsubscribe or edit options button" You do not need a password to unsubscribe, you can do it via email confirmation. If you have trouble unsubscribing, please send a message to the list detailing the problem.
_______________________________________________ App_rpt-users mailing list App_rpt-users@ohnosec.org http://ohnosec.org/cgi-bin/mailman/listinfo/app_rpt-users
To unsubscribe from this list please visithttp://ohnosec.org/cgi-bin/mailman/listinfo/app_rpt-users and scroll down to the bottom of the page. Enter your email address and press the "Unsubscribe or edit options button" You do not need a password to unsubscribe, you can do it via email confirmation. If you have trouble unsubscribing, please send a message to the list detailing the problem.
-- "Anything is possible if you don't know what you are talking about." 1st Law of Logic
_______________________________________________ App_rpt-users mailing list App_rpt-users@ohnosec.org http://ohnosec.org/cgi-bin/mailman/listinfo/app_rpt-users
To unsubscribe from this list please visit http://ohnosec.org/cgi-bin/mailman/listinfo/app_rpt-users and scroll down to the bottom of the page. Enter your email address and press the "Unsubscribe or edit options button" You do not need a password to unsubscribe, you can do it via email confirmation. If you have trouble unsubscribing, please send a message to the list detailing the problem.
Let me spin up one of the DIAL setups - may take me a day - then see what is enabled by default and hardening will be 'easy' (no processes/ports active not absolutely required). Adding the CA stuff will be easy as well if desired. Whatever the overall direction is I can do security stuff :-) Steven Donegan KK6IVC General Class FCC License Silver State Car #86 www.sscc.us From: Steve Zingman <szingman@msgstor.com> To: Steven Donegan <donegan@donegan.org>; David Andrzejewski <david@davidandrzejewski.com> Cc: "app_rpt-users@ohnosec.org" <app_rpt-users@ohnosec.org> Sent: Monday, October 5, 2015 4:04 PM Subject: Re: [App_rpt-users] New Official Allstar Distribution Released (DIAL) Sure, I think a hardening script might be in order (and optional). On 10/05/2015 06:55 PM, Steven Donegan wrote: BTW - I have a script to make a *NIX box a CA and generate certificates - that could easily be added to the DIAL/Pi/etc releases - let me see if I can scrounge it up :-) Assuming anyone would want that ability and Steve is OK with it :-) Steven Donegan KK6IVC General Class FCC License Silver State Car #86 www.sscc.us From: David Andrzejewski <david@davidandrzejewski.com> To: Steven Donegan <donegan@donegan.org> Cc: Bryan D. Boyle <bdboyle@bdboyle.com>; "app_rpt-users@ohnosec.org" <app_rpt-users@ohnosec.org> Sent: Monday, October 5, 2015 3:50 PM Subject: Re: [App_rpt-users] New Official Allstar Distribution Released (DIAL) Yep - disallowing keyboard-interactive and accepting only certificates. I turn off PermitRootLogin and only allow certificates. Barring some kind of exploit in sshd, that ought to be secure enough. Steven Donegan wrote: Using certificates for ssh is yet another method :-) Steven Donegan KK6IVC General Class FCC License Silver State Car #86 www.sscc.us From: Bryan D. Boyle <bdboyle@bdboyle.com> To: Steven Donegan <donegan@donegan.org> Cc: Steve Zingman <szingman@msgstor.com>; "app_rpt-users@ohnosec.org" <app_rpt-users@ohnosec.org> Sent: Monday, October 5, 2015 2:49 PM Subject: Re: [App_rpt-users] New Official Allstar Distribution Released (DIAL) Using a jump box as you describe is one way...not allowing SSH from the outside adds a layer; setting up a secue VDI capability to the jumpbox over a vpn is yet a third way...;). my rule: if it's exposed to the net, it's potentially vulnerable. Just turn on your SIP port and pop some popcorn to see...;) -- Bryan Sent from my iPhone 5...No electrons were harmed in the sending of this message. On Oct 5, 2015, at 17:39, Steven Donegan <donegan@donegan.org> wrote: Direct root login being disallowed IF there were no other way to get full root privileges (not the case here) was considered best practice. However in almost every case there is a user (on Raspbian user pi) that can simply login, sudo -s and do whatever they want. Yes it puts up a small hurdle but I don't see it as a serious one. In short, there is almost no setup that will allow you to completely lock out root with the exception of a few well designed appliances. And that means someone is out there doing support to get things resolved. This system is not of that flavor and root is necessary for many things so frankly adding a hurdle or two really doesn't appreciably make the system more secure. Require a long pass phrase (say 20 mixed characters or so) and this whole thing is moot... And BTW - putting sshd on port 222 (or anything except 22) is security by obscurity - many tools can find standard protocols on non-standard ports :-) (I know, I wrote one) The best bet is to not allow ssh at all. If that is not feasible then do the su or sudo thing and/or set up an intermediate system such that you access a non-privileged account on system A, then ssh to system B and system B will ONLY accept ssh from system A. Still can be beaten but it is a bit harder... And BTW - I have done infosec for about 20 years so I am allowed to have an opinion on this topic :-) Steven Donegan KK6IVC General Class FCC License Silver State Car #86 www.sscc.us From: Steve Zingman <szingman@msgstor.com> To: "app_rpt-users@ohnosec.org" <app_rpt-users@ohnosec.org> Sent: Monday, October 5, 2015 2:24 PM Subject: [App_rpt-users] New Official Allstar Distribution Released (DIAL) Dave, Let's say I agree with you. And I well may. On most internet exposed machines, I don't even allow ssh unless I trust your address or require a VPN. I agree is common practice to not allow it. Now the question is why? As John McLaughlin would say, DISCUSS! On 10/05/2015 08:40 AM, Steve Zingman wrote:
root login via SSH is now allowed
This is a bad idea. Root should *never* be allowed to login to a system remotely. It's better to log in as a normal user and then become root via su, sudo, etc.
- Dave
-- "Anything is possible if you don't know what you are talking about." 1st Law of Logic _______________________________________________ App_rpt-users mailing list App_rpt-users@ohnosec.org http://ohnosec.org/cgi-bin/mailman/listinfo/app_rpt-users To unsubscribe from this list please visit http://ohnosec.org/cgi-bin/mailman/listinfo/app_rpt-users and scroll down to the bottom of the page. Enter your email address and press the "Unsubscribe or edit options button" You do not need a password to unsubscribe, you can do it via email confirmation. If you have trouble unsubscribing, please send a message to the list detailing the problem. _______________________________________________ App_rpt-users mailing list App_rpt-users@ohnosec.org http://ohnosec.org/cgi-bin/mailman/listinfo/app_rpt-users To unsubscribe from this list please visit http://ohnosec.org/cgi-bin/mailman/listinfo/app_rpt-users and scroll down to the bottom of the page. Enter your email address and press the "Unsubscribe or edit options button" You do not need a password to unsubscribe, you can do it via email confirmation. If you have trouble unsubscribing, please send a message to the list detailing the problem. _______________________________________________ App_rpt-users mailing list App_rpt-users@ohnosec.org http://ohnosec.org/cgi-bin/mailman/listinfo/app_rpt-users To unsubscribe from this list please visit http://ohnosec.org/cgi-bin/mailman/listinfo/app_rpt-users and scroll down to the bottom of the page. Enter your email address and press the "Unsubscribe or edit options button" You do not need a password to unsubscribe, you can do it via email confirmation. If you have trouble unsubscribing, please send a message to the list detailing the problem. _______________________________________________ App_rpt-users mailing list App_rpt-users@ohnosec.org http://ohnosec.org/cgi-bin/mailman/listinfo/app_rpt-users To unsubscribe from this list please visit http://ohnosec.org/cgi-bin/mailman/listinfo/app_rpt-users and scroll down to the bottom of the page. Enter your email address and press the "Unsubscribe or edit options button" You do not need a password to unsubscribe, you can do it via email confirmation. If you have trouble unsubscribing, please send a message to the list detailing the problem. -- "Anything is possible if you don't know what you are talking about." 1st Law of Logic
As of right now it's listening to 222 and 5038 on 127.0.0.1 TCP and 4569 on UDP. That's all. On 10/05/2015 07:15 PM, Steven Donegan wrote:
Let me spin up one of the DIAL setups - may take me a day - then see what is enabled by default and hardening will be 'easy' (no processes/ports active not absolutely required). Adding the CA stuff will be easy as well if desired. Whatever the overall direction is I can do security stuff :-) Steven Donegan KK6IVC General Class FCC License Silver State Car #86 www.sscc.us
------------------------------------------------------------------------ *From:* Steve Zingman <szingman@msgstor.com> *To:* Steven Donegan <donegan@donegan.org>; David Andrzejewski <david@davidandrzejewski.com> *Cc:* "app_rpt-users@ohnosec.org" <app_rpt-users@ohnosec.org> *Sent:* Monday, October 5, 2015 4:04 PM *Subject:* Re: [App_rpt-users] New Official Allstar Distribution Released (DIAL)
Sure, I think a hardening script might be in order (and optional).
On 10/05/2015 06:55 PM, Steven Donegan wrote:
BTW - I have a script to make a *NIX box a CA and generate certificates - that could easily be added to the DIAL/Pi/etc releases - let me see if I can scrounge it up :-) Assuming anyone would want that ability and Steve is OK with it :-) Steven Donegan KK6IVC General Class FCC License Silver State Car #86 www.sscc.us <http://www.sscc.us/>
------------------------------------------------------------------------ *From:* David Andrzejewski <david@davidandrzejewski.com> <mailto:david@davidandrzejewski.com> *To:* Steven Donegan <donegan@donegan.org> <mailto:donegan@donegan.org> *Cc:* Bryan D. Boyle <bdboyle@bdboyle.com> <mailto:bdboyle@bdboyle.com>; "app_rpt-users@ohnosec.org" <mailto:app_rpt-users@ohnosec.org> <app_rpt-users@ohnosec.org> <mailto:app_rpt-users@ohnosec.org> *Sent:* Monday, October 5, 2015 3:50 PM *Subject:* Re: [App_rpt-users] New Official Allstar Distribution Released (DIAL)
Yep - disallowing keyboard-interactive and accepting only certificates. I turn off PermitRootLogin and only allow certificates. Barring some kind of exploit in sshd, that ought to be secure enough.
Steven Donegan wrote:
Using certificates for ssh is yet another method :-) Steven Donegan KK6IVC General Class FCC License Silver State Car #86 www.sscc.us <http://www.sscc.us/>
------------------------------------------------------------------------ *From:* Bryan D. Boyle <bdboyle@bdboyle.com> <mailto:bdboyle@bdboyle.com> *To:* Steven Donegan <donegan@donegan.org> <mailto:donegan@donegan.org> *Cc:* Steve Zingman <szingman@msgstor.com> <mailto:szingman@msgstor.com>; "app_rpt-users@ohnosec.org" <mailto:app_rpt-users@ohnosec.org> <app_rpt-users@ohnosec.org> <mailto:app_rpt-users@ohnosec.org> *Sent:* Monday, October 5, 2015 2:49 PM *Subject:* Re: [App_rpt-users] New Official Allstar Distribution Released (DIAL)
Using a jump box as you describe is one way...not allowing SSH from the outside adds a layer; setting up a secue VDI capability to the jumpbox over a vpn is yet a third way...;).
my rule: if it's exposed to the net, it's potentially vulnerable. Just turn on your SIP port and pop some popcorn to see...;)
-- Bryan Sent from my iPhone 5...No electrons were harmed in the sending of this message.
On Oct 5, 2015, at 17:39, Steven Donegan <donegan@donegan.org <mailto:donegan@donegan.org>> wrote:
Direct root login being disallowed IF there were no other way to get full root privileges (not the case here) was considered best practice. However in almost every case there is a user (on Raspbian user pi) that can simply login, sudo -s and do whatever they want. Yes it puts up a small hurdle but I don't see it as a serious one.
In short, there is almost no setup that will allow you to completely lock out root with the exception of a few well designed appliances. And that means someone is out there doing support to get things resolved. This system is not of that flavor and root is necessary for many things so frankly adding a hurdle or two really doesn't appreciably make the system more secure.
Require a long pass phrase (say 20 mixed characters or so) and this whole thing is moot...
And BTW - putting sshd on port 222 (or anything except 22) is security by obscurity - many tools can find standard protocols on non-standard ports :-) (I know, I wrote one)
The best bet is to not allow ssh at all. If that is not feasible then do the su or sudo thing and/or set up an intermediate system such that you access a non-privileged account on system A, then ssh to system B and system B will ONLY accept ssh from system A. Still can be beaten but it is a bit harder...
And BTW - I have done infosec for about 20 years so I am allowed to have an opinion on this topic :-) Steven Donegan KK6IVC General Class FCC License Silver State Car #86 www.sscc.us <http://www.sscc.us/>
------------------------------------------------------------------------ *From:* Steve Zingman <szingman@msgstor.com <mailto:szingman@msgstor.com>> *To:* "app_rpt-users@ohnosec.org <mailto:app_rpt-users@ohnosec.org>" <app_rpt-users@ohnosec.org <mailto:app_rpt-users@ohnosec.org>> *Sent:* Monday, October 5, 2015 2:24 PM *Subject:* [App_rpt-users] New Official Allstar Distribution Released (DIAL)
Dave, Let's say I agree with you. And I well may. On most internet exposed machines, I don't even allow ssh unless I trust your address or require a VPN. I agree is common practice to not allow it. Now the question is why?
As John McLaughlin would say, DISCUSS!
On 10/05/2015 08:40 AM, Steve Zingman wrote:
/root login via SSH is now allowed / This is a bad idea. Root should *never* be allowed to login to a system remotely. It's better to log in as a normal user and then become root via su, sudo, etc.
- Dave
-- "Anything is possible if you don't know what you are talking about." 1st Law of Logic
_______________________________________________ App_rpt-users mailing list App_rpt-users@ohnosec.org <mailto:App_rpt-users@ohnosec.org> http://ohnosec.org/cgi-bin/mailman/listinfo/app_rpt-users
To unsubscribe from this list please visit http://ohnosec.org/cgi-bin/mailman/listinfo/app_rpt-users and scroll down to the bottom of the page. Enter your email address and press the "Unsubscribe or edit options button" You do not need a password to unsubscribe, you can do it via email confirmation. If you have trouble unsubscribing, please send a message to the list detailing the problem.
_______________________________________________ App_rpt-users mailing list App_rpt-users@ohnosec.org <mailto:App_rpt-users@ohnosec.org> http://ohnosec.org/cgi-bin/mailman/listinfo/app_rpt-users
To unsubscribe from this list please visit http://ohnosec.org/cgi-bin/mailman/listinfo/app_rpt-users and scroll down to the bottom of the page. Enter your email address and press the "Unsubscribe or edit options button" You do not need a password to unsubscribe, you can do it via email confirmation. If you have trouble unsubscribing, please send a message to the list detailing the problem.
_______________________________________________ App_rpt-users mailing list App_rpt-users@ohnosec.org <mailto:App_rpt-users@ohnosec.org> http://ohnosec.org/cgi-bin/mailman/listinfo/app_rpt-users
To unsubscribe from this list please visithttp://ohnosec.org/cgi-bin/mailman/listinfo/app_rpt-users and scroll down to the bottom of the page. Enter your email address and press the "Unsubscribe or edit options button" You do not need a password to unsubscribe, you can do it via email confirmation. If you have trouble unsubscribing, please send a message to the list detailing the problem.
_______________________________________________ App_rpt-users mailing list App_rpt-users@ohnosec.org <mailto:App_rpt-users@ohnosec.org> http://ohnosec.org/cgi-bin/mailman/listinfo/app_rpt-users
To unsubscribe from this list please visithttp://ohnosec.org/cgi-bin/mailman/listinfo/app_rpt-users and scroll down to the bottom of the page. Enter your email address and press the "Unsubscribe or edit options button" You do not need a password to unsubscribe, you can do it via email confirmation. If you have trouble unsubscribing, please send a message to the list detailing the problem.
-- "Anything is possible if you don't know what you are talking about." 1st Law of Logic
-- "Anything is possible if you don't know what you are talking about." 1st Law of Logic
5038 is asterisk management port - I would suggest for hardening that 222 (whatever port is selected for ssh) and 4569 be firewalled tightly and 5038 kept totally local. But this is all food for further discussion :-) Not having a currently running Debian system handy - does it use iptables or firewalld? I have set up both in a scripted fashion before. Steven Donegan KK6IVC General Class FCC License Silver State Car #86 www.sscc.us From: Steve Zingman <szingman@msgstor.com> To: Steven Donegan <donegan@donegan.org> Cc: "app_rpt-users@ohnosec.org" <app_rpt-users@ohnosec.org> Sent: Monday, October 5, 2015 4:38 PM Subject: Node security As of right now it's listening to 222 and 5038 on 127.0.0.1 TCP and 4569 on UDP. That's all. On 10/05/2015 07:15 PM, Steven Donegan wrote: Let me spin up one of the DIAL setups - may take me a day - then see what is enabled by default and hardening will be 'easy' (no processes/ports active not absolutely required). Adding the CA stuff will be easy as well if desired. Whatever the overall direction is I can do security stuff :-) Steven Donegan KK6IVC General Class FCC License Silver State Car #86 www.sscc.us From: Steve Zingman <szingman@msgstor.com> To: Steven Donegan <donegan@donegan.org>; David Andrzejewski <david@davidandrzejewski.com> Cc: "app_rpt-users@ohnosec.org" <app_rpt-users@ohnosec.org> Sent: Monday, October 5, 2015 4:04 PM Subject: Re: [App_rpt-users] New Official Allstar Distribution Released (DIAL) Sure, I think a hardening script might be in order (and optional). On 10/05/2015 06:55 PM, Steven Donegan wrote: BTW - I have a script to make a *NIX box a CA and generate certificates - that could easily be added to the DIAL/Pi/etc releases - let me see if I can scrounge it up :-) Assuming anyone would want that ability and Steve is OK with it :-) Steven Donegan KK6IVC General Class FCC License Silver State Car #86 www.sscc.us From: David Andrzejewski <david@davidandrzejewski.com> To: Steven Donegan <donegan@donegan.org> Cc: Bryan D. Boyle <bdboyle@bdboyle.com>; "app_rpt-users@ohnosec.org" <app_rpt-users@ohnosec.org> Sent: Monday, October 5, 2015 3:50 PM Subject: Re: [App_rpt-users] New Official Allstar Distribution Released (DIAL) Yep - disallowing keyboard-interactive and accepting only certificates. I turn off PermitRootLogin and only allow certificates. Barring some kind of exploit in sshd, that ought to be secure enough. Steven Donegan wrote: Using certificates for ssh is yet another method :-) Steven Donegan KK6IVC General Class FCC License Silver State Car #86 www.sscc.us From: Bryan D. Boyle <bdboyle@bdboyle.com> To: Steven Donegan <donegan@donegan.org> Cc: Steve Zingman <szingman@msgstor.com>; "app_rpt-users@ohnosec.org" <app_rpt-users@ohnosec.org> Sent: Monday, October 5, 2015 2:49 PM Subject: Re: [App_rpt-users] New Official Allstar Distribution Released (DIAL) Using a jump box as you describe is one way...not allowing SSH from the outside adds a layer; setting up a secue VDI capability to the jumpbox over a vpn is yet a third way...;). my rule: if it's exposed to the net, it's potentially vulnerable. Just turn on your SIP port and pop some popcorn to see...;) -- Bryan Sent from my iPhone 5...No electrons were harmed in the sending of this message. On Oct 5, 2015, at 17:39, Steven Donegan <donegan@donegan.org> wrote: Direct root login being disallowed IF there were no other way to get full root privileges (not the case here) was considered best practice. However in almost every case there is a user (on Raspbian user pi) that can simply login, sudo -s and do whatever they want. Yes it puts up a small hurdle but I don't see it as a serious one. In short, there is almost no setup that will allow you to completely lock out root with the exception of a few well designed appliances. And that means someone is out there doing support to get things resolved. This system is not of that flavor and root is necessary for many things so frankly adding a hurdle or two really doesn't appreciably make the system more secure. Require a long pass phrase (say 20 mixed characters or so) and this whole thing is moot... And BTW - putting sshd on port 222 (or anything except 22) is security by obscurity - many tools can find standard protocols on non-standard ports :-) (I know, I wrote one) The best bet is to not allow ssh at all. If that is not feasible then do the su or sudo thing and/or set up an intermediate system such that you access a non-privileged account on system A, then ssh to system B and system B will ONLY accept ssh from system A. Still can be beaten but it is a bit harder... And BTW - I have done infosec for about 20 years so I am allowed to have an opinion on this topic :-) Steven Donegan KK6IVC General Class FCC License Silver State Car #86 www.sscc.us From: Steve Zingman <szingman@msgstor.com> To: "app_rpt-users@ohnosec.org" <app_rpt-users@ohnosec.org> Sent: Monday, October 5, 2015 2:24 PM Subject: [App_rpt-users] New Official Allstar Distribution Released (DIAL) Dave, Let's say I agree with you. And I well may. On most internet exposed machines, I don't even allow ssh unless I trust your address or require a VPN. I agree is common practice to not allow it. Now the question is why? As John McLaughlin would say, DISCUSS! On 10/05/2015 08:40 AM, Steve Zingman wrote:
root login via SSH is now allowed
This is a bad idea. Root should *never* be allowed to login to a system remotely. It's better to log in as a normal user and then become root via su, sudo, etc.
- Dave
-- "Anything is possible if you don't know what you are talking about." 1st Law of Logic _______________________________________________ App_rpt-users mailing list App_rpt-users@ohnosec.org http://ohnosec.org/cgi-bin/mailman/listinfo/app_rpt-users To unsubscribe from this list please visit http://ohnosec.org/cgi-bin/mailman/listinfo/app_rpt-users and scroll down to the bottom of the page. Enter your email address and press the "Unsubscribe or edit options button" You do not need a password to unsubscribe, you can do it via email confirmation. If you have trouble unsubscribing, please send a message to the list detailing the problem. _______________________________________________ App_rpt-users mailing list App_rpt-users@ohnosec.org http://ohnosec.org/cgi-bin/mailman/listinfo/app_rpt-users To unsubscribe from this list please visit http://ohnosec.org/cgi-bin/mailman/listinfo/app_rpt-users and scroll down to the bottom of the page. Enter your email address and press the "Unsubscribe or edit options button" You do not need a password to unsubscribe, you can do it via email confirmation. If you have trouble unsubscribing, please send a message to the list detailing the problem. _______________________________________________ App_rpt-users mailing list App_rpt-users@ohnosec.org http://ohnosec.org/cgi-bin/mailman/listinfo/app_rpt-users To unsubscribe from this list please visit http://ohnosec.org/cgi-bin/mailman/listinfo/app_rpt-users and scroll down to the bottom of the page. Enter your email address and press the "Unsubscribe or edit options button" You do not need a password to unsubscribe, you can do it via email confirmation. If you have trouble unsubscribing, please send a message to the list detailing the problem. _______________________________________________ App_rpt-users mailing list App_rpt-users@ohnosec.org http://ohnosec.org/cgi-bin/mailman/listinfo/app_rpt-users To unsubscribe from this list please visit http://ohnosec.org/cgi-bin/mailman/listinfo/app_rpt-users and scroll down to the bottom of the page. Enter your email address and press the "Unsubscribe or edit options button" You do not need a password to unsubscribe, you can do it via email confirmation. If you have trouble unsubscribing, please send a message to the list detailing the problem. -- "Anything is possible if you don't know what you are talking about." 1st Law of Logic -- "Anything is possible if you don't know what you are talking about." 1st Law of Logic
5038 is used by Allmon to display a HTML base management console. It's not bad and can be installed locally. Since it's only listening to local host by default I'm OK with it. If you are going to firewall IAX (4569) you are going to need to read the allstar node list to create allow rules. Debian uses iptables. I use Shorewall as a front end to make it more user friendly. On 10/05/2015 07:43 PM, Steven Donegan wrote:
5038 is asterisk management port - I would suggest for hardening that 222 (whatever port is selected for ssh) and 4569 be firewalled tightly and 5038 kept totally local. But this is all food for further discussion :-)
Not having a currently running Debian system handy - does it use iptables or firewalld? I have set up both in a scripted fashion before. Steven Donegan KK6IVC General Class FCC License Silver State Car #86 www.sscc.us
------------------------------------------------------------------------ *From:* Steve Zingman <szingman@msgstor.com> *To:* Steven Donegan <donegan@donegan.org> *Cc:* "app_rpt-users@ohnosec.org" <app_rpt-users@ohnosec.org> *Sent:* Monday, October 5, 2015 4:38 PM *Subject:* Node security
As of right now it's listening to 222 and 5038 on 127.0.0.1 TCP and 4569 on UDP.
That's all.
On 10/05/2015 07:15 PM, Steven Donegan wrote:
Let me spin up one of the DIAL setups - may take me a day - then see what is enabled by default and hardening will be 'easy' (no processes/ports active not absolutely required). Adding the CA stuff will be easy as well if desired. Whatever the overall direction is I can do security stuff :-) Steven Donegan KK6IVC General Class FCC License Silver State Car #86 www.sscc.us <http://www.sscc.us/>
------------------------------------------------------------------------ *From:* Steve Zingman <szingman@msgstor.com> <mailto:szingman@msgstor.com> *To:* Steven Donegan <donegan@donegan.org>; David Andrzejewski <david@davidandrzejewski.com> *Cc:* "app_rpt-users@ohnosec.org" <mailto:app_rpt-users@ohnosec.org> <app_rpt-users@ohnosec.org> <mailto:app_rpt-users@ohnosec.org> *Sent:* Monday, October 5, 2015 4:04 PM *Subject:* Re: [App_rpt-users] New Official Allstar Distribution Released (DIAL)
Sure, I think a hardening script might be in order (and optional).
On 10/05/2015 06:55 PM, Steven Donegan wrote:
BTW - I have a script to make a *NIX box a CA and generate certificates - that could easily be added to the DIAL/Pi/etc releases - let me see if I can scrounge it up :-) Assuming anyone would want that ability and Steve is OK with it :-) Steven Donegan KK6IVC General Class FCC License Silver State Car #86 www.sscc.us <http://www.sscc.us/>
------------------------------------------------------------------------ *From:* David Andrzejewski <david@davidandrzejewski.com> *To:* Steven Donegan <donegan@donegan.org> *Cc:* Bryan D. Boyle <bdboyle@bdboyle.com>; "app_rpt-users@ohnosec.org" <app_rpt-users@ohnosec.org> *Sent:* Monday, October 5, 2015 3:50 PM *Subject:* Re: [App_rpt-users] New Official Allstar Distribution Released (DIAL)
Yep - disallowing keyboard-interactive and accepting only certificates. I turn off PermitRootLogin and only allow certificates. Barring some kind of exploit in sshd, that ought to be secure enough.
Steven Donegan wrote:
Using certificates for ssh is yet another method :-) Steven Donegan KK6IVC General Class FCC License Silver State Car #86 www.sscc.us
------------------------------------------------------------------------ *From:* Bryan D. Boyle <bdboyle@bdboyle.com> *To:* Steven Donegan <donegan@donegan.org> *Cc:* Steve Zingman <szingman@msgstor.com>; "app_rpt-users@ohnosec.org" <app_rpt-users@ohnosec.org> *Sent:* Monday, October 5, 2015 2:49 PM *Subject:* Re: [App_rpt-users] New Official Allstar Distribution Released (DIAL)
Using a jump box as you describe is one way...not allowing SSH from the outside adds a layer; setting up a secue VDI capability to the jumpbox over a vpn is yet a third way...;).
my rule: if it's exposed to the net, it's potentially vulnerable. Just turn on your SIP port and pop some popcorn to see...;)
-- Bryan Sent from my iPhone 5...No electrons were harmed in the sending of this message.
On Oct 5, 2015, at 17:39, Steven Donegan <donegan@donegan.org> wrote:
Direct root login being disallowed IF there were no other way to get full root privileges (not the case here) was considered best practice. However in almost every case there is a user (on Raspbian user pi) that can simply login, sudo -s and do whatever they want. Yes it puts up a small hurdle but I don't see it as a serious one.
In short, there is almost no setup that will allow you to completely lock out root with the exception of a few well designed appliances. And that means someone is out there doing support to get things resolved. This system is not of that flavor and root is necessary for many things so frankly adding a hurdle or two really doesn't appreciably make the system more secure.
Require a long pass phrase (say 20 mixed characters or so) and this whole thing is moot...
And BTW - putting sshd on port 222 (or anything except 22) is security by obscurity - many tools can find standard protocols on non-standard ports :-) (I know, I wrote one)
The best bet is to not allow ssh at all. If that is not feasible then do the su or sudo thing and/or set up an intermediate system such that you access a non-privileged account on system A, then ssh to system B and system B will ONLY accept ssh from system A. Still can be beaten but it is a bit harder...
And BTW - I have done infosec for about 20 years so I am allowed to have an opinion on this topic :-) Steven Donegan KK6IVC General Class FCC License Silver State Car #86 www.sscc.us
------------------------------------------------------------------------ *From:* Steve Zingman <szingman@msgstor.com> *To:* "app_rpt-users@ohnosec.org" <app_rpt-users@ohnosec.org> *Sent:* Monday, October 5, 2015 2:24 PM *Subject:* [App_rpt-users] New Official Allstar Distribution Released (DIAL)
Dave, Let's say I agree with you. And I well may. On most internet exposed machines, I don't even allow ssh unless I trust your address or require a VPN. I agree is common practice to not allow it. Now the question is why?
As John McLaughlin would say, DISCUSS!
On 10/05/2015 08:40 AM, Steve Zingman wrote:
/root login via SSH is now allowed / This is a bad idea. Root should *never* be allowed to login to a system remotely. It's better to log in as a normal user and then become root via su, sudo, etc.
- Dave
-- "Anything is possible if you don't know what you are talking about." 1st Law of Logic
_______________________________________________ App_rpt-users mailing list App_rpt-users@ohnosec.org http://ohnosec.org/cgi-bin/mailman/listinfo/app_rpt-users
To unsubscribe from this list please visit http://ohnosec.org/cgi-bin/mailman/listinfo/app_rpt-users and scroll down to the bottom of the page. Enter your email address and press the "Unsubscribe or edit options button" You do not need a password to unsubscribe, you can do it via email confirmation. If you have trouble unsubscribing, please send a message to the list detailing the problem.
_______________________________________________ App_rpt-users mailing list App_rpt-users@ohnosec.org http://ohnosec.org/cgi-bin/mailman/listinfo/app_rpt-users
To unsubscribe from this list please visit http://ohnosec.org/cgi-bin/mailman/listinfo/app_rpt-users and scroll down to the bottom of the page. Enter your email address and press the "Unsubscribe or edit options button" You do not need a password to unsubscribe, you can do it via email confirmation. If you have trouble unsubscribing, please send a message to the list detailing the problem.
_______________________________________________ App_rpt-users mailing list App_rpt-users@ohnosec.org <mailto:App_rpt-users@ohnosec.org> http://ohnosec.org/cgi-bin/mailman/listinfo/app_rpt-users
To unsubscribe from this list please visithttp://ohnosec.org/cgi-bin/mailman/listinfo/app_rpt-users and scroll down to the bottom of the page. Enter your email address and press the "Unsubscribe or edit options button" You do not need a password to unsubscribe, you can do it via email confirmation. If you have trouble unsubscribing, please send a message to the list detailing the problem.
_______________________________________________ App_rpt-users mailing list App_rpt-users@ohnosec.org <mailto:App_rpt-users@ohnosec.org> http://ohnosec.org/cgi-bin/mailman/listinfo/app_rpt-users
To unsubscribe from this list please visithttp://ohnosec.org/cgi-bin/mailman/listinfo/app_rpt-users and scroll down to the bottom of the page. Enter your email address and press the "Unsubscribe or edit options button" You do not need a password to unsubscribe, you can do it via email confirmation. If you have trouble unsubscribing, please send a message to the list detailing the problem.
-- "Anything is possible if you don't know what you are talking about." 1st Law of Logic
-- "Anything is possible if you don't know what you are talking about." 1st Law of Logic
-- "Anything is possible if you don't know what you are talking about." 1st Law of Logic
https://www.sans.org/critical-security-controls Follow the link above for a good place to start at securing your systems/networks. #12 is relevant in this case. :) -Stacy KG7QIN On 10/05/2015 04:15 PM, Steven Donegan wrote:
Let me spin up one of the DIAL setups - may take me a day - then see what is enabled by default and hardening will be 'easy' (no processes/ports active not absolutely required). Adding the CA stuff will be easy as well if desired. Whatever the overall direction is I can do security stuff :-)
Steven Donegan KK6IVC General Class FCC License Silver State Car #86 www.sscc.us
------------------------------------------------------------------------ *From:* Steve Zingman <szingman@msgstor.com> *To:* Steven Donegan <donegan@donegan.org>; David Andrzejewski <david@davidandrzejewski.com> *Cc:* "app_rpt-users@ohnosec.org" <app_rpt-users@ohnosec.org> *Sent:* Monday, October 5, 2015 4:04 PM *Subject:* Re: [App_rpt-users] New Official Allstar Distribution Released (DIAL)
Sure, I think a hardening script might be in order (and optional).
On 10/05/2015 06:55 PM, Steven Donegan wrote:
BTW - I have a script to make a *NIX box a CA and generate certificates - that could easily be added to the DIAL/Pi/etc releases - let me see if I can scrounge it up :-) Assuming anyone would want that ability and Steve is OK with it :-)
Steven Donegan KK6IVC General Class FCC License Silver State Car #86 www.sscc.us <http://www.sscc.us/>
------------------------------------------------------------------------ *From:* David Andrzejewski <david@davidandrzejewski.com> <mailto:david@davidandrzejewski.com> *To:* Steven Donegan <donegan@donegan.org> <mailto:donegan@donegan.org> *Cc:* Bryan D. Boyle <bdboyle@bdboyle.com> <mailto:bdboyle@bdboyle.com>; "app_rpt-users@ohnosec.org" <mailto:app_rpt-users@ohnosec.org> <app_rpt-users@ohnosec.org> <mailto:app_rpt-users@ohnosec.org> *Sent:* Monday, October 5, 2015 3:50 PM *Subject:* Re: [App_rpt-users] New Official Allstar Distribution Released (DIAL)
Yep - disallowing keyboard-interactive and accepting only certificates. I turn off PermitRootLogin and only allow certificates. Barring some kind of exploit in sshd, that ought to be secure enough.
Steven Donegan wrote:
Using certificates for ssh is yet another method :-)
Steven Donegan KK6IVC General Class FCC License Silver State Car #86 www.sscc.us <http://www.sscc.us/>
------------------------------------------------------------------------ *From:* Bryan D. Boyle <bdboyle@bdboyle.com> <mailto:bdboyle@bdboyle.com> *To:* Steven Donegan <donegan@donegan.org> <mailto:donegan@donegan.org> *Cc:* Steve Zingman <szingman@msgstor.com> <mailto:szingman@msgstor.com>; "app_rpt-users@ohnosec.org" <mailto:app_rpt-users@ohnosec.org> <app_rpt-users@ohnosec.org> <mailto:app_rpt-users@ohnosec.org> *Sent:* Monday, October 5, 2015 2:49 PM *Subject:* Re: [App_rpt-users] New Official Allstar Distribution Released (DIAL)
Using a jump box as you describe is one way...not allowing SSH from the outside adds a layer; setting up a secue VDI capability to the jumpbox over a vpn is yet a third way...;).
my rule: if it's exposed to the net, it's potentially vulnerable. Just turn on your SIP port and pop some popcorn to see...;)
-- Bryan Sent from my iPhone 5...No electrons were harmed in the sending of this message.
On Oct 5, 2015, at 17:39, Steven Donegan <donegan@donegan.org <mailto:donegan@donegan.org>> wrote:
Direct root login being disallowed IF there were no other way to get full root privileges (not the case here) was considered best practice. However in almost every case there is a user (on Raspbian user pi) that can simply login, sudo -s and do whatever they want. Yes it puts up a small hurdle but I don't see it as a serious one.
In short, there is almost no setup that will allow you to completely lock out root with the exception of a few well designed appliances. And that means someone is out there doing support to get things resolved. This system is not of that flavor and root is necessary for many things so frankly adding a hurdle or two really doesn't appreciably make the system more secure.
Require a long pass phrase (say 20 mixed characters or so) and this whole thing is moot...
And BTW - putting sshd on port 222 (or anything except 22) is security by obscurity - many tools can find standard protocols on non-standard ports :-) (I know, I wrote one)
The best bet is to not allow ssh at all. If that is not feasible then do the su or sudo thing and/or set up an intermediate system such that you access a non-privileged account on system A, then ssh to system B and system B will ONLY accept ssh from system A. Still can be beaten but it is a bit harder...
And BTW - I have done infosec for about 20 years so I am allowed to have an opinion on this topic :-)
Steven Donegan KK6IVC General Class FCC License Silver State Car #86 www.sscc.us <http://www.sscc.us/>
------------------------------------------------------------------------ *From:* Steve Zingman <szingman@msgstor.com <mailto:szingman@msgstor.com>> *To:* "app_rpt-users@ohnosec.org <mailto:app_rpt-users@ohnosec.org>" <app_rpt-users@ohnosec.org <mailto:app_rpt-users@ohnosec.org>> *Sent:* Monday, October 5, 2015 2:24 PM *Subject:* [App_rpt-users] New Official Allstar Distribution Released (DIAL)
Dave, Let's say I agree with you. And I well may. On most internet exposed machines, I don't even allow ssh unless I trust your address or require a VPN. I agree is common practice to not allow it. Now the question is why?
As John McLaughlin would say, DISCUSS!
On 10/05/2015 08:40 AM, Steve Zingman wrote:
/root login via SSH is now allowed / This is a bad idea. Root should *never* be allowed to login to a system remotely. It's better to log in as a normal user and then become root via su, sudo, etc.
- Dave
-- "Anything is possible if you don't know what you are talking about." 1st Law of Logic
_______________________________________________ App_rpt-users mailing list App_rpt-users@ohnosec.org <mailto:App_rpt-users@ohnosec.org> http://ohnosec.org/cgi-bin/mailman/listinfo/app_rpt-users
To unsubscribe from this list please visit http://ohnosec.org/cgi-bin/mailman/listinfo/app_rpt-users and scroll down to the bottom of the page. Enter your email address and press the "Unsubscribe or edit options button" You do not need a password to unsubscribe, you can do it via email confirmation. If you have trouble unsubscribing, please send a message to the list detailing the problem.
_______________________________________________ App_rpt-users mailing list App_rpt-users@ohnosec.org <mailto:App_rpt-users@ohnosec.org> http://ohnosec.org/cgi-bin/mailman/listinfo/app_rpt-users
To unsubscribe from this list please visit http://ohnosec.org/cgi-bin/mailman/listinfo/app_rpt-users and scroll down to the bottom of the page. Enter your email address and press the "Unsubscribe or edit options button" You do not need a password to unsubscribe, you can do it via email confirmation. If you have trouble unsubscribing, please send a message to the list detailing the problem.
_______________________________________________ App_rpt-users mailing list App_rpt-users@ohnosec.org <mailto:App_rpt-users@ohnosec.org> http://ohnosec.org/cgi-bin/mailman/listinfo/app_rpt-users
To unsubscribe from this list please visit http://ohnosec.org/cgi-bin/mailman/listinfo/app_rpt-users and scroll down to the bottom of the page. Enter your email address and press the "Unsubscribe or edit options button" You do not need a password to unsubscribe, you can do it via email confirmation. If you have trouble unsubscribing, please send a message to the list detailing the problem.
_______________________________________________ App_rpt-users mailing list App_rpt-users@ohnosec.org <mailto:App_rpt-users@ohnosec.org> http://ohnosec.org/cgi-bin/mailman/listinfo/app_rpt-users
To unsubscribe from this list please visit http://ohnosec.org/cgi-bin/mailman/listinfo/app_rpt-users and scroll down to the bottom of the page. Enter your email address and press the "Unsubscribe or edit options button" You do not need a password to unsubscribe, you can do it via email confirmation. If you have trouble unsubscribing, please send a message to the list detailing the problem.
-- "Anything is possible if you don't know what you are talking about." 1st Law of Logic
_______________________________________________ App_rpt-users mailing list App_rpt-users@ohnosec.org http://ohnosec.org/cgi-bin/mailman/listinfo/app_rpt-users
To unsubscribe from this list please visit http://ohnosec.org/cgi-bin/mailman/listinfo/app_rpt-users and scroll down to the bottom of the page. Enter your email address and press the "Unsubscribe or edit options button" You do not need a password to unsubscribe, you can do it via email confirmation. If you have trouble unsubscribing, please send a message to the list detailing the problem.
Stacy, You are correct. As pretty much everyone that has weighed in. DIAL sets up a node so it can be configured by most users either using Linux tools or tools on other systems (WinSCP) Before a node is deployed it should be locked down. This is a given. Right now my plate is full getting versions for other processors. So I'm going to ask the security people in the group to create a lock down or deploy script. Take the existing DIAL deployment and lock it down. I'll take your work make sure it fits with the x86 DIAL and the other processors. I suggest you use the list so others can participate. 73, Steve N4IRS On 10/08/2015 06:31 PM, Stacy wrote:
https://www.sans.org/critical-security-controls
Follow the link above for a good place to start at securing your systems/networks. #12 is relevant in this case. :)
-Stacy KG7QIN
On 10/05/2015 04:15 PM, Steven Donegan wrote:
Let me spin up one of the DIAL setups - may take me a day - then see what is enabled by default and hardening will be 'easy' (no processes/ports active not absolutely required). Adding the CA stuff will be easy as well if desired. Whatever the overall direction is I can do security stuff :-) Steven Donegan KK6IVC General Class FCC License Silver State Car #86 www.sscc.us
------------------------------------------------------------------------ *From:* Steve Zingman <szingman@msgstor.com> *To:* Steven Donegan <donegan@donegan.org>; David Andrzejewski <david@davidandrzejewski.com> *Cc:* "app_rpt-users@ohnosec.org" <app_rpt-users@ohnosec.org> *Sent:* Monday, October 5, 2015 4:04 PM *Subject:* Re: [App_rpt-users] New Official Allstar Distribution Released (DIAL)
Sure, I think a hardening script might be in order (and optional).
On 10/05/2015 06:55 PM, Steven Donegan wrote:
BTW - I have a script to make a *NIX box a CA and generate certificates - that could easily be added to the DIAL/Pi/etc releases - let me see if I can scrounge it up :-) Assuming anyone would want that ability and Steve is OK with it :-) Steven Donegan KK6IVC General Class FCC License Silver State Car #86 www.sscc.us <http://www.sscc.us/>
------------------------------------------------------------------------ *From:* David Andrzejewski <david@davidandrzejewski.com> *To:* Steven Donegan <donegan@donegan.org> *Cc:* Bryan D. Boyle <bdboyle@bdboyle.com>; "app_rpt-users@ohnosec.org" <mailto:app_rpt-users@ohnosec.org> <app_rpt-users@ohnosec.org> <mailto:app_rpt-users@ohnosec.org> *Sent:* Monday, October 5, 2015 3:50 PM *Subject:* Re: [App_rpt-users] New Official Allstar Distribution Released (DIAL)
Yep - disallowing keyboard-interactive and accepting only certificates. I turn off PermitRootLogin and only allow certificates. Barring some kind of exploit in sshd, that ought to be secure enough.
Steven Donegan wrote:
Using certificates for ssh is yet another method :-) Steven Donegan KK6IVC General Class FCC License Silver State Car #86 www.sscc.us <http://www.sscc.us/>
------------------------------------------------------------------------ *From:* Bryan D. Boyle <bdboyle@bdboyle.com> *To:* Steven Donegan <donegan@donegan.org> *Cc:* Steve Zingman <szingman@msgstor.com>; "app_rpt-users@ohnosec.org" <app_rpt-users@ohnosec.org> *Sent:* Monday, October 5, 2015 2:49 PM *Subject:* Re: [App_rpt-users] New Official Allstar Distribution Released (DIAL)
Using a jump box as you describe is one way...not allowing SSH from the outside adds a layer; setting up a secue VDI capability to the jumpbox over a vpn is yet a third way...;).
my rule: if it's exposed to the net, it's potentially vulnerable. Just turn on your SIP port and pop some popcorn to see...;)
-- Bryan Sent from my iPhone 5...No electrons were harmed in the sending of this message.
On Oct 5, 2015, at 17:39, Steven Donegan <donegan@donegan.org> wrote:
Direct root login being disallowed IF there were no other way to get full root privileges (not the case here) was considered best practice. However in almost every case there is a user (on Raspbian user pi) that can simply login, sudo -s and do whatever they want. Yes it puts up a small hurdle but I don't see it as a serious one.
In short, there is almost no setup that will allow you to completely lock out root with the exception of a few well designed appliances. And that means someone is out there doing support to get things resolved. This system is not of that flavor and root is necessary for many things so frankly adding a hurdle or two really doesn't appreciably make the system more secure.
Require a long pass phrase (say 20 mixed characters or so) and this whole thing is moot...
And BTW - putting sshd on port 222 (or anything except 22) is security by obscurity - many tools can find standard protocols on non-standard ports :-) (I know, I wrote one)
The best bet is to not allow ssh at all. If that is not feasible then do the su or sudo thing and/or set up an intermediate system such that you access a non-privileged account on system A, then ssh to system B and system B will ONLY accept ssh from system A. Still can be beaten but it is a bit harder...
And BTW - I have done infosec for about 20 years so I am allowed to have an opinion on this topic :-) Steven Donegan KK6IVC General Class FCC License Silver State Car #86 www.sscc.us
------------------------------------------------------------------------ *From:* Steve Zingman <szingman@msgstor.com> *To:* "app_rpt-users@ohnosec.org" <app_rpt-users@ohnosec.org> *Sent:* Monday, October 5, 2015 2:24 PM *Subject:* [App_rpt-users] New Official Allstar Distribution Released (DIAL)
Dave, Let's say I agree with you. And I well may. On most internet exposed machines, I don't even allow ssh unless I trust your address or require a VPN. I agree is common practice to not allow it. Now the question is why?
As John McLaughlin would say, DISCUSS!
On 10/05/2015 08:40 AM, Steve Zingman wrote:
/root login via SSH is now allowed / This is a bad idea. Root should *never* be allowed to login to a system remotely. It's better to log in as a normal user and then become root via su, sudo, etc.
- Dave
-- "Anything is possible if you don't know what you are talking about." 1st Law of Logic
_______________________________________________ App_rpt-users mailing list App_rpt-users@ohnosec.org http://ohnosec.org/cgi-bin/mailman/listinfo/app_rpt-users
To unsubscribe from this list please visit http://ohnosec.org/cgi-bin/mailman/listinfo/app_rpt-users and scroll down to the bottom of the page. Enter your email address and press the "Unsubscribe or edit options button" You do not need a password to unsubscribe, you can do it via email confirmation. If you have trouble unsubscribing, please send a message to the list detailing the problem.
_______________________________________________ App_rpt-users mailing list App_rpt-users@ohnosec.org http://ohnosec.org/cgi-bin/mailman/listinfo/app_rpt-users
To unsubscribe from this list please visit http://ohnosec.org/cgi-bin/mailman/listinfo/app_rpt-users and scroll down to the bottom of the page. Enter your email address and press the "Unsubscribe or edit options button" You do not need a password to unsubscribe, you can do it via email confirmation. If you have trouble unsubscribing, please send a message to the list detailing the problem.
_______________________________________________ App_rpt-users mailing list App_rpt-users@ohnosec.org <mailto:App_rpt-users@ohnosec.org> http://ohnosec.org/cgi-bin/mailman/listinfo/app_rpt-users
To unsubscribe from this list please visithttp://ohnosec.org/cgi-bin/mailman/listinfo/app_rpt-users and scroll down to the bottom of the page. Enter your email address and press the "Unsubscribe or edit options button" You do not need a password to unsubscribe, you can do it via email confirmation. If you have trouble unsubscribing, please send a message to the list detailing the problem.
_______________________________________________ App_rpt-users mailing list App_rpt-users@ohnosec.org <mailto:App_rpt-users@ohnosec.org> http://ohnosec.org/cgi-bin/mailman/listinfo/app_rpt-users
To unsubscribe from this list please visithttp://ohnosec.org/cgi-bin/mailman/listinfo/app_rpt-users and scroll down to the bottom of the page. Enter your email address and press the "Unsubscribe or edit options button" You do not need a password to unsubscribe, you can do it via email confirmation. If you have trouble unsubscribing, please send a message to the list detailing the problem.
-- "Anything is possible if you don't know what you are talking about." 1st Law of Logic
_______________________________________________ App_rpt-users mailing list App_rpt-users@ohnosec.org http://ohnosec.org/cgi-bin/mailman/listinfo/app_rpt-users
To unsubscribe from this list please visithttp://ohnosec.org/cgi-bin/mailman/listinfo/app_rpt-users and scroll down to the bottom of the page. Enter your email address and press the "Unsubscribe or edit options button" You do not need a password to unsubscribe, you can do it via email confirmation. If you have trouble unsubscribing, please send a message to the list detailing the problem.
-- "Anything is possible if you don't know what you are talking about." 1st Law of Logic
Certificates, two-factor authentication and something like ssh-guard set to block on the first three attempts with a really really long block threshold. Stacy KG7QIN On 10/05/2015 02:57 PM, Steven Donegan wrote:
Using certificates for ssh is yet another method :-)
Steven Donegan KK6IVC General Class FCC License Silver State Car #86 www.sscc.us
------------------------------------------------------------------------ *From:* Bryan D. Boyle <bdboyle@bdboyle.com> *To:* Steven Donegan <donegan@donegan.org> *Cc:* Steve Zingman <szingman@msgstor.com>; "app_rpt-users@ohnosec.org" <app_rpt-users@ohnosec.org> *Sent:* Monday, October 5, 2015 2:49 PM *Subject:* Re: [App_rpt-users] New Official Allstar Distribution Released (DIAL)
Using a jump box as you describe is one way...not allowing SSH from the outside adds a layer; setting up a secue VDI capability to the jumpbox over a vpn is yet a third way...;).
my rule: if it's exposed to the net, it's potentially vulnerable. Just turn on your SIP port and pop some popcorn to see...;)
-- Bryan Sent from my iPhone 5...No electrons were harmed in the sending of this message.
On Oct 5, 2015, at 17:39, Steven Donegan <donegan@donegan.org <mailto:donegan@donegan.org>> wrote:
Direct root login being disallowed IF there were no other way to get full root privileges (not the case here) was considered best practice. However in almost every case there is a user (on Raspbian user pi) that can simply login, sudo -s and do whatever they want. Yes it puts up a small hurdle but I don't see it as a serious one.
In short, there is almost no setup that will allow you to completely lock out root with the exception of a few well designed appliances. And that means someone is out there doing support to get things resolved. This system is not of that flavor and root is necessary for many things so frankly adding a hurdle or two really doesn't appreciably make the system more secure.
Require a long pass phrase (say 20 mixed characters or so) and this whole thing is moot...
And BTW - putting sshd on port 222 (or anything except 22) is security by obscurity - many tools can find standard protocols on non-standard ports :-) (I know, I wrote one)
The best bet is to not allow ssh at all. If that is not feasible then do the su or sudo thing and/or set up an intermediate system such that you access a non-privileged account on system A, then ssh to system B and system B will ONLY accept ssh from system A. Still can be beaten but it is a bit harder...
And BTW - I have done infosec for about 20 years so I am allowed to have an opinion on this topic :-)
Steven Donegan KK6IVC General Class FCC License Silver State Car #86 www.sscc.us <http://www.sscc.us/>
------------------------------------------------------------------------ *From:* Steve Zingman <szingman@msgstor.com <mailto:szingman@msgstor.com>> *To:* "app_rpt-users@ohnosec.org <mailto:app_rpt-users@ohnosec.org>" <app_rpt-users@ohnosec.org <mailto:app_rpt-users@ohnosec.org>> *Sent:* Monday, October 5, 2015 2:24 PM *Subject:* [App_rpt-users] New Official Allstar Distribution Released (DIAL)
Dave, Let's say I agree with you. And I well may. On most internet exposed machines, I don't even allow ssh unless I trust your address or require a VPN. I agree is common practice to not allow it. Now the question is why?
As John McLaughlin would say, DISCUSS!
On 10/05/2015 08:40 AM, Steve Zingman wrote:
/root login via SSH is now allowed / This is a bad idea. Root should *never* be allowed to login to a system remotely. It's better to log in as a normal user and then become root via su, sudo, etc.
- Dave
-- "Anything is possible if you don't know what you are talking about." 1st Law of Logic
_______________________________________________ App_rpt-users mailing list App_rpt-users@ohnosec.org <mailto:App_rpt-users@ohnosec.org> http://ohnosec.org/cgi-bin/mailman/listinfo/app_rpt-users
To unsubscribe from this list please visit http://ohnosec.org/cgi-bin/mailman/listinfo/app_rpt-users and scroll down to the bottom of the page. Enter your email address and press the "Unsubscribe or edit options button" You do not need a password to unsubscribe, you can do it via email confirmation. If you have trouble unsubscribing, please send a message to the list detailing the problem.
_______________________________________________ App_rpt-users mailing list App_rpt-users@ohnosec.org <mailto:App_rpt-users@ohnosec.org> http://ohnosec.org/cgi-bin/mailman/listinfo/app_rpt-users
To unsubscribe from this list please visit http://ohnosec.org/cgi-bin/mailman/listinfo/app_rpt-users and scroll down to the bottom of the page. Enter your email address and press the "Unsubscribe or edit options button" You do not need a password to unsubscribe, you can do it via email confirmation. If you have trouble unsubscribing, please send a message to the list detailing the problem.
_______________________________________________ App_rpt-users mailing list App_rpt-users@ohnosec.org http://ohnosec.org/cgi-bin/mailman/listinfo/app_rpt-users
To unsubscribe from this list please visit http://ohnosec.org/cgi-bin/mailman/listinfo/app_rpt-users and scroll down to the bottom of the page. Enter your email address and press the "Unsubscribe or edit options button" You do not need a password to unsubscribe, you can do it via email confirmation. If you have trouble unsubscribing, please send a message to the list detailing the problem.
Personally I use Fail2ban Loren Tedford (KC9ZHV) Email: lorentedford@gmail.com Main Line:1-631-686-8878 Option 1 for Loren. Fax Line 1:1-618-551-2755 Fax Line 2:1-631-686-8892 (New Fax line) Cell: 618-553-0806 http://www.lorentedford.com http://www.kc9zhv.com http://hub.kc9zhv.com On Mon, Oct 5, 2015 at 9:06 PM, Stacy <kg7qin@arrl.net> wrote:
Certificates, two-factor authentication and something like ssh-guard set to block on the first three attempts with a really really long block threshold.
Stacy KG7QIN
On 10/05/2015 02:57 PM, Steven Donegan wrote:
Using certificates for ssh is yet another method :-)
Steven Donegan KK6IVC General Class FCC License Silver State Car #86 www.sscc.us
------------------------------ *From:* Bryan D. Boyle <bdboyle@bdboyle.com> <bdboyle@bdboyle.com> *To:* Steven Donegan <donegan@donegan.org> <donegan@donegan.org> *Cc:* Steve Zingman <szingman@msgstor.com> <szingman@msgstor.com>; "app_rpt-users@ohnosec.org" <app_rpt-users@ohnosec.org> <app_rpt-users@ohnosec.org> <app_rpt-users@ohnosec.org> *Sent:* Monday, October 5, 2015 2:49 PM *Subject:* Re: [App_rpt-users] New Official Allstar Distribution Released (DIAL)
Using a jump box as you describe is one way...not allowing SSH from the outside adds a layer; setting up a secue VDI capability to the jumpbox over a vpn is yet a third way...;).
my rule: if it's exposed to the net, it's potentially vulnerable. Just turn on your SIP port and pop some popcorn to see...;)
-- Bryan Sent from my iPhone 5...No electrons were harmed in the sending of this message.
On Oct 5, 2015, at 17:39, Steven Donegan < <donegan@donegan.org> donegan@donegan.org> wrote:
Direct root login being disallowed IF there were no other way to get full root privileges (not the case here) was considered best practice. However in almost every case there is a user (on Raspbian user pi) that can simply login, sudo -s and do whatever they want. Yes it puts up a small hurdle but I don't see it as a serious one.
In short, there is almost no setup that will allow you to completely lock out root with the exception of a few well designed appliances. And that means someone is out there doing support to get things resolved. This system is not of that flavor and root is necessary for many things so frankly adding a hurdle or two really doesn't appreciably make the system more secure.
Require a long pass phrase (say 20 mixed characters or so) and this whole thing is moot...
And BTW - putting sshd on port 222 (or anything except 22) is security by obscurity - many tools can find standard protocols on non-standard ports :-) (I know, I wrote one)
The best bet is to not allow ssh at all. If that is not feasible then do the su or sudo thing and/or set up an intermediate system such that you access a non-privileged account on system A, then ssh to system B and system B will ONLY accept ssh from system A. Still can be beaten but it is a bit harder...
And BTW - I have done infosec for about 20 years so I am allowed to have an opinion on this topic :-)
Steven Donegan KK6IVC General Class FCC License Silver State Car #86 www.sscc.us
------------------------------ *From:* Steve Zingman < <szingman@msgstor.com>szingman@msgstor.com> *To:* "app_rpt-users@ohnosec.org" <app_rpt-users@ohnosec.org> *Sent:* Monday, October 5, 2015 2:24 PM *Subject:* [App_rpt-users] New Official Allstar Distribution Released (DIAL)
Dave, Let's say I agree with you. And I well may. On most internet exposed machines, I don't even allow ssh unless I trust your address or require a VPN. I agree is common practice to not allow it. Now the question is why?
As John McLaughlin would say, DISCUSS!
* root login via SSH is now allowed
On 10/05/2015 08:40 AM, Steve Zingman wrote: *
This is a bad idea. Root should *never* be allowed to login to a system remotely. It's better to log in as a normal user and then become root via su, sudo, etc.
- Dave
-- "Anything is possible if you don't know what you are talking about." 1st Law of Logic
_______________________________________________ App_rpt-users mailing list App_rpt-users@ohnosec.org http://ohnosec.org/cgi-bin/mailman/listinfo/app_rpt-users
To unsubscribe from this list please visit http://ohnosec.org/cgi-bin/mailman/listinfo/app_rpt-users and scroll down to the bottom of the page. Enter your email address and press the "Unsubscribe or edit options button" You do not need a password to unsubscribe, you can do it via email confirmation. If you have trouble unsubscribing, please send a message to the list detailing the problem.
_______________________________________________ App_rpt-users mailing list App_rpt-users@ohnosec.org http://ohnosec.org/cgi-bin/mailman/listinfo/app_rpt-users
To unsubscribe from this list please visit <http://ohnosec.org/cgi-bin/mailman/listinfo/app_rpt-users> http://ohnosec.org/cgi-bin/mailman/listinfo/app_rpt-users and scroll down to the bottom of the page. Enter your email address and press the "Unsubscribe or edit options button" You do not need a password to unsubscribe, you can do it via email confirmation. If you have trouble unsubscribing, please send a message to the list detailing the problem.
_______________________________________________ App_rpt-users mailing listApp_rpt-users@ohnosec.orghttp://ohnosec.org/cgi-bin/mailman/listinfo/app_rpt-users
To unsubscribe from this list please visit http://ohnosec.org/cgi-bin/mailman/listinfo/app_rpt-users and scroll down to the bottom of the page. Enter your email address and press the "Unsubscribe or edit options button" You do not need a password to unsubscribe, you can do it via email confirmation. If you have trouble unsubscribing, please send a message to the list detailing the problem.
_______________________________________________ App_rpt-users mailing list App_rpt-users@ohnosec.org http://ohnosec.org/cgi-bin/mailman/listinfo/app_rpt-users
To unsubscribe from this list please visit http://ohnosec.org/cgi-bin/mailman/listinfo/app_rpt-users and scroll down to the bottom of the page. Enter your email address and press the "Unsubscribe or edit options button" You do not need a password to unsubscribe, you can do it via email confirmation. If you have trouble unsubscribing, please send a message to the list detailing the problem.
Same difference. :) On 10/05/2015 07:30 PM, Loren Tedford wrote:
Personally I use Fail2ban
Loren Tedford (KC9ZHV) Email: lorentedford@gmail.com <mailto:lorentedford@gmail.com> Main Line:1-631-686-8878 Option 1 for Loren. Fax Line 1:1-618-551-2755 Fax Line 2:1-631-686-8892 (New Fax line) Cell: 618-553-0806 http://www.lorentedford.com <http://www.lorentedford.com/> http://www.kc9zhv.com http://hub.kc9zhv.com
On Mon, Oct 5, 2015 at 9:06 PM, Stacy <kg7qin@arrl.net <mailto:kg7qin@arrl.net>> wrote:
Certificates, two-factor authentication and something like ssh-guard set to block on the first three attempts with a really really long block threshold.
Stacy KG7QIN
On 10/05/2015 02:57 PM, Steven Donegan wrote:
Using certificates for ssh is yet another method :-)
Steven Donegan KK6IVC General Class FCC License Silver State Car #86 www.sscc.us <http://www.sscc.us>
------------------------------------------------------------------------ *From:* Bryan D. Boyle <bdboyle@bdboyle.com> <mailto:bdboyle@bdboyle.com> *To:* Steven Donegan <donegan@donegan.org> <mailto:donegan@donegan.org> *Cc:* Steve Zingman <szingman@msgstor.com> <mailto:szingman@msgstor.com>; "app_rpt-users@ohnosec.org" <mailto:app_rpt-users@ohnosec.org> <app_rpt-users@ohnosec.org> <mailto:app_rpt-users@ohnosec.org> *Sent:* Monday, October 5, 2015 2:49 PM *Subject:* Re: [App_rpt-users] New Official Allstar Distribution Released (DIAL)
Using a jump box as you describe is one way...not allowing SSH from the outside adds a layer; setting up a secue VDI capability to the jumpbox over a vpn is yet a third way...;).
my rule: if it's exposed to the net, it's potentially vulnerable. Just turn on your SIP port and pop some popcorn to see...;)
-- Bryan Sent from my iPhone 5...No electrons were harmed in the sending of this message.
On Oct 5, 2015, at 17:39, Steven Donegan <donegan@donegan.org <mailto:donegan@donegan.org>> wrote:
Direct root login being disallowed IF there were no other way to get full root privileges (not the case here) was considered best practice. However in almost every case there is a user (on Raspbian user pi) that can simply login, sudo -s and do whatever they want. Yes it puts up a small hurdle but I don't see it as a serious one.
In short, there is almost no setup that will allow you to completely lock out root with the exception of a few well designed appliances. And that means someone is out there doing support to get things resolved. This system is not of that flavor and root is necessary for many things so frankly adding a hurdle or two really doesn't appreciably make the system more secure.
Require a long pass phrase (say 20 mixed characters or so) and this whole thing is moot...
And BTW - putting sshd on port 222 (or anything except 22) is security by obscurity - many tools can find standard protocols on non-standard ports :-) (I know, I wrote one)
The best bet is to not allow ssh at all. If that is not feasible then do the su or sudo thing and/or set up an intermediate system such that you access a non-privileged account on system A, then ssh to system B and system B will ONLY accept ssh from system A. Still can be beaten but it is a bit harder...
And BTW - I have done infosec for about 20 years so I am allowed to have an opinion on this topic :-)
Steven Donegan KK6IVC General Class FCC License Silver State Car #86 www.sscc.us <http://www.sscc.us/>
------------------------------------------------------------------------ *From:* Steve Zingman <szingman@msgstor.com <mailto:szingman@msgstor.com>> *To:* "app_rpt-users@ohnosec.org <mailto:app_rpt-users@ohnosec.org>" <app_rpt-users@ohnosec.org <mailto:app_rpt-users@ohnosec.org>> *Sent:* Monday, October 5, 2015 2:24 PM *Subject:* [App_rpt-users] New Official Allstar Distribution Released (DIAL)
Dave, Let's say I agree with you. And I well may. On most internet exposed machines, I don't even allow ssh unless I trust your address or require a VPN. I agree is common practice to not allow it. Now the question is why?
As John McLaughlin would say, DISCUSS!
On 10/05/2015 08:40 AM, Steve Zingman wrote: >/root login via SSH is now allowed / > This is a bad idea. Root should *never* be allowed to login to a system > remotely. It's better to log in as a normal user and then become root > via su, sudo, etc.
> - Dave
-- "Anything is possible if you don't know what you are talking about." 1st Law of Logic
_______________________________________________ App_rpt-users mailing list App_rpt-users@ohnosec.org <mailto:App_rpt-users@ohnosec.org> http://ohnosec.org/cgi-bin/mailman/listinfo/app_rpt-users
To unsubscribe from this list please visit http://ohnosec.org/cgi-bin/mailman/listinfo/app_rpt-users and scroll down to the bottom of the page. Enter your email address and press the "Unsubscribe or edit options button" You do not need a password to unsubscribe, you can do it via email confirmation. If you have trouble unsubscribing, please send a message to the list detailing the problem.
_______________________________________________ App_rpt-users mailing list App_rpt-users@ohnosec.org <mailto:App_rpt-users@ohnosec.org> http://ohnosec.org/cgi-bin/mailman/listinfo/app_rpt-users
To unsubscribe from this list please visit http://ohnosec.org/cgi-bin/mailman/listinfo/app_rpt-users and scroll down to the bottom of the page. Enter your email address and press the "Unsubscribe or edit options button" You do not need a password to unsubscribe, you can do it via email confirmation. If you have trouble unsubscribing, please send a message to the list detailing the problem.
_______________________________________________ App_rpt-users mailing list App_rpt-users@ohnosec.org <mailto:App_rpt-users@ohnosec.org> http://ohnosec.org/cgi-bin/mailman/listinfo/app_rpt-users
To unsubscribe from this list please visit http://ohnosec.org/cgi-bin/mailman/listinfo/app_rpt-users and scroll down to the bottom of the page. Enter your email address and press the "Unsubscribe or edit options button" You do not need a password to unsubscribe, you can do it via email confirmation. If you have trouble unsubscribing, please send a message to the list detailing the problem.
_______________________________________________ App_rpt-users mailing list App_rpt-users@ohnosec.org <mailto:App_rpt-users@ohnosec.org> http://ohnosec.org/cgi-bin/mailman/listinfo/app_rpt-users
To unsubscribe from this list please visit http://ohnosec.org/cgi-bin/mailman/listinfo/app_rpt-users and scroll down to the bottom of the page. Enter your email address and press the "Unsubscribe or edit options button" You do not need a password to unsubscribe, you can do it via email confirmation. If you have trouble unsubscribing, please send a message to the list detailing the problem.
This discussion sounds like discussions 20 years go regarding PL on a repeater, it's too hard to solder in a pl board. Even the basic security books on Unix long before Linux discuss root and security. Root should never be exposed to the outside world, you also have to do as much to protect it from the inside as many exploits come from someone getting inside user credentials. basic security says.. 1) don't expose anything you don't absolutely have to 2) keep your software up to date, especially the system. 3) anyone running a server should be trained. Fail to ban... "just means attack slowly" exposing 22 "says please try me" putting ssh on another port simply "says scan me", scripts do this all the time. it goes on and on.. I personally use tunnels from my machine to my server, and tunnels are restricted not only by certificates, they are also restricted to IP address's they can come from. Ports open to critical applications should be run at a minimum in a chroot environment. The basic asterisk installation needs more work than just spinning up the disk to get it securely installed. It is not possible to logon to any one of my servers with a password. We even have developers who say if you are behind a fire wall at your house you should be secure.. pure poppycock.. So any system that intentionally exposes root, or you can't easily update the base system is "broken by design" kinda like Windows stuff (not just my oppinion) The internet is not a friendly place, it was 30 years ago, but has not been friendly for the last 25+ years ago.. anyone who just plugs in to the internet with an unprotected server is adding to the problem. Bad server security is worse than the worst repeater curchunker cause the exploit is silent, you don't know it is happening unless YOU know what you are doing, watching logs etc.. you are keeping spammers in business... Some think they are secure because the only thing their server runs is asterisk, till someone gets root, installs a mail server, and spams the world for years.. or they change ssh.conf and allow ssh out, (which is open by default and should be closed on installation) so now they are using your server or small Raspberry Pi to attack the rest of the internet using your IP address.. it happens all the time guys.. In fact one of the biggest security exploits going today is getting someone to plug in a Pi from unknown origin into someone's internal network.. read "Penetration Testing with Raspberry Pi" by Muntz & Lakhani. Bad buys are sending out Pi's by the hundreds to large companies, hoping someone will plug it into the local network to see what it is.. it's then game over for many small companies without knowledgeable sysadmins. If you don't want to learn basic security, it's your machine, it's your problem, basic security is not hard to learn, but doesn't come from an installation disk any more than understanding ham radio comes from memorizing the test. Don't ask developers to keep it easy for you just because you don't want learn basic security, if developers do it for you, they are bad developers, shame on them. My .02 cents... with a constant internet connection since 1978.. Fred On 10/5/15 10:36 PM, Stacy wrote:
Same difference. :)
On 10/05/2015 07:30 PM, Loren Tedford wrote:
Personally I use Fail2ban
Loren Tedford (KC9ZHV) Email: lorentedford@gmail.com <mailto:lorentedford@gmail.com> Main Line:1-631-686-8878 Option 1 for Loren. Fax Line 1:1-618-551-2755 Fax Line 2:1-631-686-8892 (New Fax line) Cell: 618-553-0806 http://www.lorentedford.com http://www.kc9zhv.com http://hub.kc9zhv.com
On Mon, Oct 5, 2015 at 9:06 PM, Stacy <kg7qin@arrl.net <mailto:kg7qin@arrl.net>> wrote:
Certificates, two-factor authentication and something like ssh-guard set to block on the first three attempts with a really really long block threshold.
Stacy KG7QIN
On 10/05/2015 02:57 PM, Steven Donegan wrote:
Using certificates for ssh is yet another method :-)
Steven Donegan KK6IVC General Class FCC License Silver State Car #86 www.sscc.us <http://www.sscc.us>
------------------------------------------------------------------------ *From:* Bryan D. Boyle <bdboyle@bdboyle.com> <mailto:bdboyle@bdboyle.com> *To:* Steven Donegan <donegan@donegan.org> <mailto:donegan@donegan.org> *Cc:* Steve Zingman <szingman@msgstor.com> <mailto:szingman@msgstor.com>; "app_rpt-users@ohnosec.org" <mailto:app_rpt-users@ohnosec.org> <app_rpt-users@ohnosec.org> <mailto:app_rpt-users@ohnosec.org> *Sent:* Monday, October 5, 2015 2:49 PM *Subject:* Re: [App_rpt-users] New Official Allstar Distribution Released (DIAL)
Using a jump box as you describe is one way...not allowing SSH from the outside adds a layer; setting up a secue VDI capability to the jumpbox over a vpn is yet a third way...;).
my rule: if it's exposed to the net, it's potentially vulnerable. Just turn on your SIP port and pop some popcorn to see...;)
-- Bryan Sent from my iPhone 5...No electrons were harmed in the sending of this message.
On Oct 5, 2015, at 17:39, Steven Donegan <donegan@donegan.org> wrote:
Direct root login being disallowed IF there were no other way to get full root privileges (not the case here) was considered best practice. However in almost every case there is a user (on Raspbian user pi) that can simply login, sudo -s and do whatever they want. Yes it puts up a small hurdle but I don't see it as a serious one.
In short, there is almost no setup that will allow you to completely lock out root with the exception of a few well designed appliances. And that means someone is out there doing support to get things resolved. This system is not of that flavor and root is necessary for many things so frankly adding a hurdle or two really doesn't appreciably make the system more secure.
Require a long pass phrase (say 20 mixed characters or so) and this whole thing is moot...
And BTW - putting sshd on port 222 (or anything except 22) is security by obscurity - many tools can find standard protocols on non-standard ports :-) (I know, I wrote one)
The best bet is to not allow ssh at all. If that is not feasible then do the su or sudo thing and/or set up an intermediate system such that you access a non-privileged account on system A, then ssh to system B and system B will ONLY accept ssh from system A. Still can be beaten but it is a bit harder...
And BTW - I have done infosec for about 20 years so I am allowed to have an opinion on this topic :-)
Steven Donegan KK6IVC General Class FCC License Silver State Car #86 www.sscc.us <http://www.sscc.us/>
------------------------------------------------------------------------ *From:* Steve Zingman <szingman@msgstor.com> *To:* "app_rpt-users@ohnosec.org" <app_rpt-users@ohnosec.org> *Sent:* Monday, October 5, 2015 2:24 PM *Subject:* [App_rpt-users] New Official Allstar Distribution Released (DIAL)
Dave, Let's say I agree with you. And I well may. On most internet exposed machines, I don't even allow ssh unless I trust your address or require a VPN. I agree is common practice to not allow it. Now the question is why?
As John McLaughlin would say, DISCUSS!
On 10/05/2015 08:40 AM, Steve Zingman wrote: >/root login via SSH is now allowed / > This is a bad idea. Root should *never* be allowed to login to a system > remotely. It's better to log in as a normal user and then become root > via su, sudo, etc.
> - Dave
-- "Anything is possible if you don't know what you are talking about." 1st Law of Logic
_______________________________________________ App_rpt-users mailing list App_rpt-users@ohnosec.org http://ohnosec.org/cgi-bin/mailman/listinfo/app_rpt-users
To unsubscribe from this list please visit http://ohnosec.org/cgi-bin/mailman/listinfo/app_rpt-users and scroll down to the bottom of the page. Enter your email address and press the "Unsubscribe or edit options button" You do not need a password to unsubscribe, you can do it via email confirmation. If you have trouble unsubscribing, please send a message to the list detailing the problem.
_______________________________________________ App_rpt-users mailing list App_rpt-users@ohnosec.org <mailto:App_rpt-users@ohnosec.org> http://ohnosec.org/cgi-bin/mailman/listinfo/app_rpt-users
To unsubscribe from this list please visit http://ohnosec.org/cgi-bin/mailman/listinfo/app_rpt-users and scroll down to the bottom of the page. Enter your email address and press the "Unsubscribe or edit options button" You do not need a password to unsubscribe, you can do it via email confirmation. If you have trouble unsubscribing, please send a message to the list detailing the problem.
_______________________________________________ App_rpt-users mailing list App_rpt-users@ohnosec.org <mailto:App_rpt-users@ohnosec.org> http://ohnosec.org/cgi-bin/mailman/listinfo/app_rpt-users
To unsubscribe from this list please visit http://ohnosec.org/cgi-bin/mailman/listinfo/app_rpt-users and scroll down to the bottom of the page. Enter your email address and press the "Unsubscribe or edit options button" You do not need a password to unsubscribe, you can do it via email confirmation. If you have trouble unsubscribing, please send a message to the list detailing the problem.
_______________________________________________ App_rpt-users mailing list App_rpt-users@ohnosec.org <mailto:App_rpt-users@ohnosec.org> http://ohnosec.org/cgi-bin/mailman/listinfo/app_rpt-users
To unsubscribe from this list please visit http://ohnosec.org/cgi-bin/mailman/listinfo/app_rpt-users and scroll down to the bottom of the page. Enter your email address and press the "Unsubscribe or edit options button" You do not need a password to unsubscribe, you can do it via email confirmation. If you have trouble unsubscribing, please send a message to the list detailing the problem.
-- This message has been scanned for viruses and dangerous content by *MailScanner* <http://www.mailscanner.info/>, and is believed to be clean.
_______________________________________________ App_rpt-users mailing list App_rpt-users@ohnosec.org http://ohnosec.org/cgi-bin/mailman/listinfo/app_rpt-users
To unsubscribe from this list please visit http://ohnosec.org/cgi-bin/mailman/listinfo/app_rpt-users and scroll down to the bottom of the page. Enter your email address and press the "Unsubscribe or edit options button" You do not need a password to unsubscribe, you can do it via email confirmation. If you have trouble unsubscribing, please send a message to the list detailing the problem.
-- Fred Moore email: fred@fmeco.com fred@safes.com phone: 321-217-8699
I am having a issue with an ACID box running radio usb connected to a modified audio FOB. however when I plug the modified audio fob into my raspberry pi using simpleusb channel driver it works perfectly. so I have two questions 1. what issues are there using radio usb under simplex mode? Does the acid upgrade to simple usb channel driver solve these bugs? What channel driver does DIAL support? it also appears that radio channel driver works fine with a DMK Engineering URI running under the same ACID box. The main question is WHY DOES IT WORK WITH A DMK URI BUT NOT THE MODIFIED AUDIO FOB UNDER ACID? EITHER ONE (DMK URI OR MY MODIFIED AUDIO FOB) BOTH WORK FINE WHEN DRIVEN BY A RASPBERRY PI! PLEASE HELP A VERY CONFUSSED GUY Thanks 73 Neil Sablatzky K8IT Allstar Node 41838 KITLINK Allstar Node 42087 KITLINK HUB IRLP Node exp0068 Echolink K8IT-L WIRES-X K8IT 11479 Room 21479 --------------------------------------------------
Neil, DIAL supports chan_usbradio and chan_simpleusb and all other channel drivers chan_usrp etc. All the same channel drivers supported under ACID ort on a RPi 73, Steve N4IRS On 10/06/2015 07:59 PM, Neil k8it wrote:
I am having a issue with an ACID box running radio usb connected to a modified audio FOB. however when I plug the modified audio fob into my raspberry pi using simpleusb channel driver it works perfectly. so I have two questions 1. what issues are there using radio usb under simplex mode? Does the acid upgrade to simple usb channel driver solve these bugs? What channel driver does DIAL support?
it also appears that radio channel driver works fine with a DMK Engineering URI running under the same ACID box.
The main question is WHY DOES IT WORK WITH A DMK URI BUT NOT THE MODIFIED AUDIO FOB UNDER ACID? EITHER ONE (DMK URI OR MY MODIFIED AUDIO FOB) BOTH WORK FINE WHEN DRIVEN BY A RASPBERRY PI! PLEASE HELP A VERY CONFUSSED GUY
Thanks 73 Neil Sablatzky K8IT Allstar Node 41838 KITLINK Allstar Node 42087 KITLINK HUB IRLP Node exp0068 Echolink K8IT-L WIRES-X K8IT 11479 Room 21479
--------------------------------------------------
-- "Anything is possible if you don't know what you are talking about." 1st Law of Logic
Neil, How old is the ACID install? I'm wondering if the ACID install is older. What is the result of lsusb? 73, Steve N4IRS On 10/06/2015 07:59 PM, Neil k8it wrote:
I am having a issue with an ACID box running radio usb connected to a modified audio FOB. however when I plug the modified audio fob into my raspberry pi using simpleusb channel driver it works perfectly. so I have two questions 1. what issues are there using radio usb under simplex mode? Does the acid upgrade to simple usb channel driver solve these bugs? What channel driver does DIAL support?
it also appears that radio channel driver works fine with a DMK Engineering URI running under the same ACID box.
The main question is WHY DOES IT WORK WITH A DMK URI BUT NOT THE MODIFIED AUDIO FOB UNDER ACID? EITHER ONE (DMK URI OR MY MODIFIED AUDIO FOB) BOTH WORK FINE WHEN DRIVEN BY A RASPBERRY PI! PLEASE HELP A VERY CONFUSSED GUY
Thanks 73 Neil Sablatzky K8IT Allstar Node 41838 KITLINK Allstar Node 42087 KITLINK HUB IRLP Node exp0068 Echolink K8IT-L WIRES-X K8IT 11479 Room 21479
--------------------------------------------------
-- "Anything is possible if you don't know what you are talking about." 1st Law of Logic
This is the response from lsusb on the ACID box with the latest ACID distribution off of the allstarlink.org site. and using a DMK URI which seems to work [root@test ~]# lsusb Bus 001 Device 001: ID 0000:0000 Bus 007 Device 001: ID 0000:0000 Bus 003 Device 001: ID 0000:0000 Bus 005 Device 001: ID 0000:0000 Bus 006 Device 001: ID 0000:0000 Bus 008 Device 007: ID 0d8c:013a C-Media Electronics, Inc. Bus 008 Device 002: ID 0403:6001 Future Technology Devices International, Ltd FT232 USB-Serial (UART) IC Bus 008 Device 001: ID 0000:0000 Bus 002 Device 001: ID 0000:0000 Bus 004 Device 001: ID 0000:0000 [root@test ~]# This is the lsusb ouput from the same ACID box but connected to a modified audio FOB. This will not send transmit audio but keys the ptt and receives cos corectly. Both the DMK URI and the modified audio FOB work great on my raspberry pi. the radio used in both cases are the same, and no changes to audio levels where done. s 007 Device 001: ID 0000:0000 Bus 003 Device 001: ID 0000:0000 Bus 005 Device 001: ID 0000:0000 Bus 006 Device 001: ID 0000:0000 Bus 008 Device 008: ID 0d8c:000c C-Media Electronics, Inc. Audio Adapter Bus 008 Device 002: ID 0403:6001 Future Technology Devices International, Ltd FT232 USB-Serial (UART) IC Bus 008 Device 001: ID 0000:0000 Bus 002 Device 001: ID 0000:0000 Bus 004 Device 001: ID 0000:0000 [root@test ~]# [ro Any thoughts on how I can solve this issue? Thanks 73 Neil Sablatzky K8IT Allstar Node 41838 KITLINK Allstar Node 42087 KITLINK HUB IRLP Node exp0068 Echolink K8IT-L WIRES-X K8IT 11479 Room 21479 -------------------------------------------------- From: "Steve Zingman" <szingman@msgstor.com> Sent: Tuesday, October 06, 2015 8:26 PM To: "Neil k8it" <k8it@cac.net>; "Bryan Fields" <Bryan@bryanfields.net> Cc: <app_rpt-users@ohnosec.org> Subject: Re: simpleusb channel driver
Neil, How old is the ACID install? I'm wondering if the ACID install is older. What is the result of lsusb?
73, Steve N4IRS
On 10/06/2015 07:59 PM, Neil k8it wrote:
I am having a issue with an ACID box running radio usb connected to a modified audio FOB. however when I plug the modified audio fob into my raspberry pi using simpleusb channel driver it works perfectly. so I have two questions 1. what issues are there using radio usb under simplex mode? Does the acid upgrade to simple usb channel driver solve these bugs? What channel driver does DIAL support?
it also appears that radio channel driver works fine with a DMK Engineering URI running under the same ACID box.
The main question is WHY DOES IT WORK WITH A DMK URI BUT NOT THE MODIFIED AUDIO FOB UNDER ACID? EITHER ONE (DMK URI OR MY MODIFIED AUDIO FOB) BOTH WORK FINE WHEN DRIVEN BY A RASPBERRY PI! PLEASE HELP A VERY CONFUSSED GUY
Thanks 73 Neil Sablatzky K8IT Allstar Node 41838 KITLINK Allstar Node 42087 KITLINK HUB IRLP Node exp0068 Echolink K8IT-L WIRES-X K8IT 11479 Room 21479
--------------------------------------------------
-- "Anything is possible if you don't know what you are talking about." 1st Law of Logic
----- No virus found in this message. Checked by AVG - www.avg.com Version: 2015.0.6140 / Virus Database: 4435/10771 - Release Date: 10/06/15
Neil, With the modified FOB plugged in and asterisk running. Run radio-tune-menu F) Flash (Toggle PTT and Tone output several times) P) Print Current Parameter Values T) Toggle Transmit Test Tone/Keying (currently Disabled) Please send the output of P) Print Current Parameter Values Press T to toggle test tone Press F to Toggle PTT and Tone output Do you get any audio out of the transmitter? Thanks, Steve N4IRS On 10/07/2015 12:15 AM, Neil k8it wrote:
This is the response from lsusb on the ACID box with the latest ACID distribution off of the allstarlink.org site. and using a DMK URI which seems to work
[root@test ~]# lsusb Bus 001 Device 001: ID 0000:0000 Bus 007 Device 001: ID 0000:0000 Bus 003 Device 001: ID 0000:0000 Bus 005 Device 001: ID 0000:0000 Bus 006 Device 001: ID 0000:0000 Bus 008 Device 007: ID 0d8c:013a C-Media Electronics, Inc. Bus 008 Device 002: ID 0403:6001 Future Technology Devices International, Ltd FT232 USB-Serial (UART) IC Bus 008 Device 001: ID 0000:0000 Bus 002 Device 001: ID 0000:0000 Bus 004 Device 001: ID 0000:0000 [root@test ~]#
This is the lsusb ouput from the same ACID box but connected to a modified audio FOB. This will not send transmit audio but keys the ptt and receives cos corectly.
Both the DMK URI and the modified audio FOB work great on my raspberry pi. the radio used in both cases are the same, and no changes to audio levels where done. s 007 Device 001: ID 0000:0000 Bus 003 Device 001: ID 0000:0000 Bus 005 Device 001: ID 0000:0000 Bus 006 Device 001: ID 0000:0000 Bus 008 Device 008: ID 0d8c:000c C-Media Electronics, Inc. Audio Adapter Bus 008 Device 002: ID 0403:6001 Future Technology Devices International, Ltd FT232 USB-Serial (UART) IC Bus 008 Device 001: ID 0000:0000 Bus 002 Device 001: ID 0000:0000 Bus 004 Device 001: ID 0000:0000 [root@test ~]# [ro
Any thoughts on how I can solve this issue? Thanks 73 Neil Sablatzky K8IT Allstar Node 41838 KITLINK Allstar Node 42087 KITLINK HUB IRLP Node exp0068 Echolink K8IT-L WIRES-X K8IT 11479 Room 21479
-------------------------------------------------- From: "Steve Zingman" <szingman@msgstor.com> Sent: Tuesday, October 06, 2015 8:26 PM To: "Neil k8it" <k8it@cac.net>; "Bryan Fields" <Bryan@bryanfields.net> Cc: <app_rpt-users@ohnosec.org> Subject: Re: simpleusb channel driver
Neil, How old is the ACID install? I'm wondering if the ACID install is older. What is the result of lsusb?
73, Steve N4IRS
On 10/06/2015 07:59 PM, Neil k8it wrote:
I am having a issue with an ACID box running radio usb connected to a modified audio FOB. however when I plug the modified audio fob into my raspberry pi using simpleusb channel driver it works perfectly. so I have two questions 1. what issues are there using radio usb under simplex mode? Does the acid upgrade to simple usb channel driver solve these bugs? What channel driver does DIAL support?
it also appears that radio channel driver works fine with a DMK Engineering URI running under the same ACID box.
The main question is WHY DOES IT WORK WITH A DMK URI BUT NOT THE MODIFIED AUDIO FOB UNDER ACID? EITHER ONE (DMK URI OR MY MODIFIED AUDIO FOB) BOTH WORK FINE WHEN DRIVEN BY A RASPBERRY PI! PLEASE HELP A VERY CONFUSSED GUY
Thanks 73 Neil Sablatzky K8IT Allstar Node 41838 KITLINK Allstar Node 42087 KITLINK HUB IRLP Node exp0068 Echolink K8IT-L WIRES-X K8IT 11479 Room 21479
--------------------------------------------------
-- "Anything is possible if you don't know what you are talking about." 1st Law of Logic
----- No virus found in this message. Checked by AVG - www.avg.com Version: 2015.0.6140 / Virus Database: 4435/10771 - Release Date: 10/06/15
-- "Anything is possible if you don't know what you are talking about." 1st Law of Logic
On 10/05/2015 08:40 AM, Steve Zingman wrote:
root login via SSH is now allowed
This is a bad idea. Root should *never* be allowed to login to a system remotely. It's better to log in as a normal user and then become root via su, sudo, etc. - Dave -- David Andrzejewski - KD8TWG Assistant Emergency Coordinator - Geauga County, Ohio Technical Specialist - Ohio Section ARRL - The National Association for Amateur Radio™ david@kd8twg.net http://qrz.com/db/kd8twg
On 10/5/15 4:56 PM, David Andrzejewski wrote:
This is a bad idea. Root should *never* be allowed to login to a system remotely. It's better to log in as a normal user and then become root via su, sudo, etc. meh, it's more of a local policy thing. I'd prefer it's not enabled by default, but there are some reasons I could see for enabling it.
-- Bryan Fields 727-409-1194 - Voice 727-214-2508 - Fax http://bryanfields.net
If I can throw in my $0.02 from someone who has worked at a service provider doing managed services (routers and firewalls) you want to heed NerdUno (Ward Mundy's) words to never expose Asterisk to the internet, and especially since this is old ASterisk. You want some sort of firewall appliance in front of it. I personally prefer VPN tunnels coming back in but you can get crafty and do port forwards with unknown ports to like 22 and 80 but there's always that risk of someone catching on. Tunnels are the safest way to get back inside. You only want to expose only the ports specifically necessary to do the job. 73 leon wa4zlw On 10/5/2015 6:17 PM, Bryan Fields wrote:
On 10/5/15 4:56 PM, David AIf I can throw inndrzejewski wrote:
This is a bad idea. Root should*never* be allowed to login to a system remotely. It's better to log in as a normal user and then become root via su, sudo, etc. meh, it's more of a local policy thing. I'd prefer it's not enabled by default, but there are some reasons I could see for enabling it.
-- Bryan Fields
727-409-1194 - Voice 727-214-2508 - Fax http://bryanfields.net
_______________________________________________ App_rpt-users mailing list App_rpt-users@ohnosec.org http://ohnosec.org/cgi-bin/mailman/listinfo/app_rpt-users
To unsubscribe from this list please visit http://ohnosec.org/cgi-bin/mailman/listinfo/app_rpt-users and scroll down to the bottom of the page. Enter your email address and press the "Unsubscribe or edit options button" You do not need a password to unsubscribe, you can do it via email confirmation. If you have trouble unsubscribing, please send a message to the list detailing the problem.
Leon, I've heard this before about old Asterisk. Any notes you can point to detailing security issues in 1.4? 73, Steve N4IRS On 10/05/2015 06:43 PM, Leon Zetekoff wrote:
If I can throw in my $0.02
from someone who has worked at a service provider doing managed services (routers and firewalls) you want to heed NerdUno (Ward Mundy's) words to never expose Asterisk to the internet, and especially since this is old ASterisk. You want some sort of firewall appliance in front of it.
I personally prefer VPN tunnels coming back in but you can get crafty and do port forwards with unknown ports to like 22 and 80 but there's always that risk of someone catching on. Tunnels are the safest way to get back inside. You only want to expose only the ports specifically necessary to do the job.
73 leon wa4zlw
On 10/5/2015 6:17 PM, Bryan Fields wrote:
On 10/5/15 4:56 PM, David AIf I can throw inndrzejewski wrote:
This is a bad idea. Root should*never* be allowed to login to a system remotely. It's better to log in as a normal user and then become root via su, sudo, etc. meh, it's more of a local policy thing. I'd prefer it's not enabled by default, but there are some reasons I could see for enabling it.
-- Bryan Fields
727-409-1194 - Voice 727-214-2508 - Fax http://bryanfields.net
_______________________________________________ App_rpt-users mailing list App_rpt-users@ohnosec.org http://ohnosec.org/cgi-bin/mailman/listinfo/app_rpt-users
To unsubscribe from this list please visithttp://ohnosec.org/cgi-bin/mailman/listinfo/app_rpt-users and scroll down to the bottom of the page. Enter your email address and press the "Unsubscribe or edit options button" You do not need a password to unsubscribe, you can do it via email confirmation. If you have trouble unsubscribing, please send a message to the list detailing the problem.
_______________________________________________ App_rpt-users mailing list App_rpt-users@ohnosec.org http://ohnosec.org/cgi-bin/mailman/listinfo/app_rpt-users
To unsubscribe from this list please visit http://ohnosec.org/cgi-bin/mailman/listinfo/app_rpt-users and scroll down to the bottom of the page. Enter your email address and press the "Unsubscribe or edit options button" You do not need a password to unsubscribe, you can do it via email confirmation. If you have trouble unsubscribing, please send a message to the list detailing the problem.
-- "Anything is possible if you don't know what you are talking about." 1st Law of Logic
Take a look at the Digium website. The advisories are there. IAX2 has one (if I remember correctly it eats up all the channel's resources causing a denial of service). http://www.asterisk.org/downloads/security-advisories -Stacy KG7QIN On 10/05/2015 04:40 PM, Steve Zingman wrote:
Leon, I've heard this before about old Asterisk. Any notes you can point to detailing security issues in 1.4?
73, Steve N4IRS
On 10/05/2015 06:43 PM, Leon Zetekoff wrote:
If I can throw in my $0.02
from someone who has worked at a service provider doing managed services (routers and firewalls) you want to heed NerdUno (Ward Mundy's) words to never expose Asterisk to the internet, and especially since this is old ASterisk. You want some sort of firewall appliance in front of it.
I personally prefer VPN tunnels coming back in but you can get crafty and do port forwards with unknown ports to like 22 and 80 but there's always that risk of someone catching on. Tunnels are the safest way to get back inside. You only want to expose only the ports specifically necessary to do the job.
73 leon wa4zlw
On 10/5/2015 6:17 PM, Bryan Fields wrote:
On 10/5/15 4:56 PM, David AIf I can throw inndrzejewski wrote:
This is a bad idea. Root should *never* be allowed to login to a system remotely. It's better to log in as a normal user and then become root via su, sudo, etc. meh, it's more of a local policy thing. I'd prefer it's not enabled by default, but there are some reasons I could see for enabling it.
-- Bryan Fields
727-409-1194 - Voice 727-214-2508 - Fax http://bryanfields.net
_______________________________________________ App_rpt-users mailing list App_rpt-users@ohnosec.org http://ohnosec.org/cgi-bin/mailman/listinfo/app_rpt-users
To unsubscribe from this list please visit http://ohnosec.org/cgi-bin/mailman/listinfo/app_rpt-users and scroll down to the bottom of the page. Enter your email address and press the "Unsubscribe or edit options button" You do not need a password to unsubscribe, you can do it via email confirmation. If you have trouble unsubscribing, please send a message to the list detailing the problem.
_______________________________________________ App_rpt-users mailing list App_rpt-users@ohnosec.org http://ohnosec.org/cgi-bin/mailman/listinfo/app_rpt-users
To unsubscribe from this list please visit http://ohnosec.org/cgi-bin/mailman/listinfo/app_rpt-users and scroll down to the bottom of the page. Enter your email address and press the "Unsubscribe or edit options button" You do not need a password to unsubscribe, you can do it via email confirmation. If you have trouble unsubscribing, please send a message to the list detailing the problem.
-- "Anything is possible if you don't know what you are talking about." 1st Law of Logic
_______________________________________________ App_rpt-users mailing list App_rpt-users@ohnosec.org http://ohnosec.org/cgi-bin/mailman/listinfo/app_rpt-users
To unsubscribe from this list please visit http://ohnosec.org/cgi-bin/mailman/listinfo/app_rpt-users and scroll down to the bottom of the page. Enter your email address and press the "Unsubscribe or edit options button" You do not need a password to unsubscribe, you can do it via email confirmation. If you have trouble unsubscribing, please send a message to the list detailing the problem.
For IAX2: http://downloads.asterisk.org/pub/security/AST-2009-006.pdf "IAX2 Call Number Resource Exhaustion" There are others. This particular advisory is on the LAST page as the LAST one. :) -Stacy KG7QIN On 10/05/2015 07:09 PM, Stacy wrote:
Take a look at the Digium website. The advisories are there.
IAX2 has one (if I remember correctly it eats up all the channel's resources causing a denial of service).
http://www.asterisk.org/downloads/security-advisories
-Stacy KG7QIN
On 10/05/2015 04:40 PM, Steve Zingman wrote:
Leon, I've heard this before about old Asterisk. Any notes you can point to detailing security issues in 1.4?
73, Steve N4IRS
On 10/05/2015 06:43 PM, Leon Zetekoff wrote:
If I can throw in my $0.02
from someone who has worked at a service provider doing managed services (routers and firewalls) you want to heed NerdUno (Ward Mundy's) words to never expose Asterisk to the internet, and especially since this is old ASterisk. You want some sort of firewall appliance in front of it.
I personally prefer VPN tunnels coming back in but you can get crafty and do port forwards with unknown ports to like 22 and 80 but there's always that risk of someone catching on. Tunnels are the safest way to get back inside. You only want to expose only the ports specifically necessary to do the job.
73 leon wa4zlw
On 10/5/2015 6:17 PM, Bryan Fields wrote:
On 10/5/15 4:56 PM, David AIf I can throw inndrzejewski wrote:
This is a bad idea. Root should *never* be allowed to login to a system remotely. It's better to log in as a normal user and then become root via su, sudo, etc. meh, it's more of a local policy thing. I'd prefer it's not enabled by default, but there are some reasons I could see for enabling it.
-- Bryan Fields
727-409-1194 - Voice 727-214-2508 - Fax http://bryanfields.net
_______________________________________________ App_rpt-users mailing list App_rpt-users@ohnosec.org http://ohnosec.org/cgi-bin/mailman/listinfo/app_rpt-users
To unsubscribe from this list please visit http://ohnosec.org/cgi-bin/mailman/listinfo/app_rpt-users and scroll down to the bottom of the page. Enter your email address and press the "Unsubscribe or edit options button" You do not need a password to unsubscribe, you can do it via email confirmation. If you have trouble unsubscribing, please send a message to the list detailing the problem.
_______________________________________________ App_rpt-users mailing list App_rpt-users@ohnosec.org http://ohnosec.org/cgi-bin/mailman/listinfo/app_rpt-users
To unsubscribe from this list please visit http://ohnosec.org/cgi-bin/mailman/listinfo/app_rpt-users and scroll down to the bottom of the page. Enter your email address and press the "Unsubscribe or edit options button" You do not need a password to unsubscribe, you can do it via email confirmation. If you have trouble unsubscribing, please send a message to the list detailing the problem.
-- "Anything is possible if you don't know what you are talking about." 1st Law of Logic
_______________________________________________ App_rpt-users mailing list App_rpt-users@ohnosec.org http://ohnosec.org/cgi-bin/mailman/listinfo/app_rpt-users
To unsubscribe from this list please visit http://ohnosec.org/cgi-bin/mailman/listinfo/app_rpt-users and scroll down to the bottom of the page. Enter your email address and press the "Unsubscribe or edit options button" You do not need a password to unsubscribe, you can do it via email confirmation. If you have trouble unsubscribing, please send a message to the list detailing the problem.
_______________________________________________ App_rpt-users mailing list App_rpt-users@ohnosec.org http://ohnosec.org/cgi-bin/mailman/listinfo/app_rpt-users
To unsubscribe from this list please visit http://ohnosec.org/cgi-bin/mailman/listinfo/app_rpt-users and scroll down to the bottom of the page. Enter your email address and press the "Unsubscribe or edit options button" You do not need a password to unsubscribe, you can do it via email confirmation. If you have trouble unsubscribing, please send a message to the list detailing the problem.
There are going to be quite a few items to read. In the case of AST-2009-006.pdf If I read this right the fix is Call token validation. Looking at the source on the SVN I see around line 300 support for the token. Lots more to read, one step at a time... On 10/05/2015 10:09 PM, Stacy wrote:
Take a look at the Digium website. The advisories are there.
IAX2 has one (if I remember correctly it eats up all the channel's resources causing a denial of service).
http://www.asterisk.org/downloads/security-advisories
-Stacy KG7QIN
On 10/05/2015 04:40 PM, Steve Zingman wrote:
Leon, I've heard this before about old Asterisk. Any notes you can point to detailing security issues in 1.4?
73, Steve N4IRS
On 10/05/2015 06:43 PM, Leon Zetekoff wrote:
If I can throw in my $0.02
from someone who has worked at a service provider doing managed services (routers and firewalls) you want to heed NerdUno (Ward Mundy's) words to never expose Asterisk to the internet, and especially since this is old ASterisk. You want some sort of firewall appliance in front of it.
I personally prefer VPN tunnels coming back in but you can get crafty and do port forwards with unknown ports to like 22 and 80 but there's always that risk of someone catching on. Tunnels are the safest way to get back inside. You only want to expose only the ports specifically necessary to do the job.
73 leon wa4zlw
On 10/5/2015 6:17 PM, Bryan Fields wrote:
On 10/5/15 4:56 PM, David AIf I can throw inndrzejewski wrote:
This is a bad idea. Root should*never* be allowed to login to a system remotely. It's better to log in as a normal user and then become root via su, sudo, etc. meh, it's more of a local policy thing. I'd prefer it's not enabled by default, but there are some reasons I could see for enabling it.
-- Bryan Fields
727-409-1194 - Voice 727-214-2508 - Fax http://bryanfields.net
_______________________________________________ App_rpt-users mailing list App_rpt-users@ohnosec.org http://ohnosec.org/cgi-bin/mailman/listinfo/app_rpt-users
To unsubscribe from this list please visithttp://ohnosec.org/cgi-bin/mailman/listinfo/app_rpt-users and scroll down to the bottom of the page. Enter your email address and press the "Unsubscribe or edit options button" You do not need a password to unsubscribe, you can do it via email confirmation. If you have trouble unsubscribing, please send a message to the list detailing the problem.
_______________________________________________ App_rpt-users mailing list App_rpt-users@ohnosec.org http://ohnosec.org/cgi-bin/mailman/listinfo/app_rpt-users
To unsubscribe from this list please visithttp://ohnosec.org/cgi-bin/mailman/listinfo/app_rpt-users and scroll down to the bottom of the page. Enter your email address and press the "Unsubscribe or edit options button" You do not need a password to unsubscribe, you can do it via email confirmation. If you have trouble unsubscribing, please send a message to the list detailing the problem.
-- "Anything is possible if you don't know what you are talking about." 1st Law of Logic
_______________________________________________ App_rpt-users mailing list App_rpt-users@ohnosec.org http://ohnosec.org/cgi-bin/mailman/listinfo/app_rpt-users
To unsubscribe from this list please visithttp://ohnosec.org/cgi-bin/mailman/listinfo/app_rpt-users and scroll down to the bottom of the page. Enter your email address and press the "Unsubscribe or edit options button" You do not need a password to unsubscribe, you can do it via email confirmation. If you have trouble unsubscribing, please send a message to the list detailing the problem.
-- "Anything is possible if you don't know what you are talking about." 1st Law of Logic
True, there is a lot to read. I haven't looked at the iax2 code to see what Jim's added in. If I remember correctly, he's done an update to it for various things. -Stacy KG7QIN On 10/05/2015 07:23 PM, Steve Zingman wrote:
There are going to be quite a few items to read. In the case of AST-2009-006.pdf If I read this right the fix is Call token validation. Looking at the source on the SVN I see around line 300 support for the token. Lots more to read, one step at a time...
On 10/05/2015 10:09 PM, Stacy wrote:
Take a look at the Digium website. The advisories are there.
IAX2 has one (if I remember correctly it eats up all the channel's resources causing a denial of service).
http://www.asterisk.org/downloads/security-advisories
-Stacy KG7QIN
On 10/05/2015 04:40 PM, Steve Zingman wrote:
Leon, I've heard this before about old Asterisk. Any notes you can point to detailing security issues in 1.4?
73, Steve N4IRS
On 10/05/2015 06:43 PM, Leon Zetekoff wrote:
If I can throw in my $0.02
from someone who has worked at a service provider doing managed services (routers and firewalls) you want to heed NerdUno (Ward Mundy's) words to never expose Asterisk to the internet, and especially since this is old ASterisk. You want some sort of firewall appliance in front of it.
I personally prefer VPN tunnels coming back in but you can get crafty and do port forwards with unknown ports to like 22 and 80 but there's always that risk of someone catching on. Tunnels are the safest way to get back inside. You only want to expose only the ports specifically necessary to do the job.
73 leon wa4zlw
On 10/5/2015 6:17 PM, Bryan Fields wrote:
On 10/5/15 4:56 PM, David AIf I can throw inndrzejewski wrote:
This is a bad idea. Root should *never* be allowed to login to a system remotely. It's better to log in as a normal user and then become root via su, sudo, etc. meh, it's more of a local policy thing. I'd prefer it's not enabled by default, but there are some reasons I could see for enabling it.
-- Bryan Fields
727-409-1194 - Voice 727-214-2508 - Fax http://bryanfields.net
_______________________________________________ App_rpt-users mailing list App_rpt-users@ohnosec.org http://ohnosec.org/cgi-bin/mailman/listinfo/app_rpt-users
To unsubscribe from this list please visit http://ohnosec.org/cgi-bin/mailman/listinfo/app_rpt-users and scroll down to the bottom of the page. Enter your email address and press the "Unsubscribe or edit options button" You do not need a password to unsubscribe, you can do it via email confirmation. If you have trouble unsubscribing, please send a message to the list detailing the problem.
_______________________________________________ App_rpt-users mailing list App_rpt-users@ohnosec.org http://ohnosec.org/cgi-bin/mailman/listinfo/app_rpt-users
To unsubscribe from this list please visit http://ohnosec.org/cgi-bin/mailman/listinfo/app_rpt-users and scroll down to the bottom of the page. Enter your email address and press the "Unsubscribe or edit options button" You do not need a password to unsubscribe, you can do it via email confirmation. If you have trouble unsubscribing, please send a message to the list detailing the problem.
-- "Anything is possible if you don't know what you are talking about." 1st Law of Logic
_______________________________________________ App_rpt-users mailing list App_rpt-users@ohnosec.org http://ohnosec.org/cgi-bin/mailman/listinfo/app_rpt-users
To unsubscribe from this list please visit http://ohnosec.org/cgi-bin/mailman/listinfo/app_rpt-users and scroll down to the bottom of the page. Enter your email address and press the "Unsubscribe or edit options button" You do not need a password to unsubscribe, you can do it via email confirmation. If you have trouble unsubscribing, please send a message to the list detailing the problem.
-- "Anything is possible if you don't know what you are talking about." 1st Law of Logic
participants (19)
-
Bryan D. Boyle -
Bryan Fields -
Corey Dean -
Dave Newmyer -
David Andrzejewski -
Fred Moore -
Jim Duuuude -
Jon Rorke -
Leon Zetekoff -
Loren Tedford -
Mark Johnston -
Neil k8it -
pete M -
REDBUTTON_CTRL -
Stacy -
Steve Agee -
Steve Zingman -
Steven Donegan -
Tim Sawyer