Support A2Billing :

provided by Star2Billing S.L.

Support A2Billing :
It is currently Wed Apr 24, 2024 10:30 pm
VoIP Billing solution


All times are UTC




Post new topic Reply to topic  [ 11 posts ] 
Author Message
 Post subject: Securing the server
PostPosted: Tue Mar 13, 2007 10:01 pm 
Offline

Joined: Thu Feb 01, 2007 6:13 pm
Posts: 67
Hello

I have A2Billing installed and I'm using DMZ on the router with no firewall. Is there any security risks without a firewall?


Thank You


Top
 Profile  
 
 Post subject:
PostPosted: Wed Mar 14, 2007 1:24 am 
Offline

Joined: Wed Dec 13, 2006 9:06 pm
Posts: 94
maybe a DOS attack on your sip ports from an unhappy customer?


Top
 Profile  
 
 Post subject:
PostPosted: Wed Mar 14, 2007 6:10 pm 
Offline
User avatar

Joined: Thu Jan 18, 2007 5:37 pm
Posts: 131
Location: Mallorca / Spain
i think the best way is using iptables.

if possible use suse 10.1 or 10.2 because of the apparmor.

just open port 80 (HTTP), 443 (HTTPS), 5060 (SIP), 4569 (IAX2) and the ports you need for SSH (do NOT use standard port 22) and maybe webmin (do NOT use standard port 10000).

then you can also install Suhosin -http://www.hardened-php.net/suhosin/index.html


Top
 Profile  
 
 Post subject:
PostPosted: Wed Mar 14, 2007 9:46 pm 
Offline

Joined: Thu Aug 10, 2006 10:47 pm
Posts: 145
Location: LA,CA,USA
Yes, if u are running trixbox there are quite a few security holes (the trixbox teams acknowledges this), however rightly so....their platform is designed to be deployed as a PBX which sites FULLY protected behind a firewall of some type....


Top
 Profile  
 
 Post subject:
PostPosted: Wed Mar 14, 2007 9:49 pm 
Offline
User avatar

Joined: Thu Jan 18, 2007 5:37 pm
Posts: 131
Location: Mallorca / Spain
hello crshman :D

can we hire you for a big project ? ;-)


Top
 Profile  
 
 Post subject:
PostPosted: Wed Mar 14, 2007 9:52 pm 
Offline

Joined: Thu Aug 10, 2006 10:47 pm
Posts: 145
Location: LA,CA,USA
Haha.....unfortunately i've been busy with stuff of my own lately (hence my lack of activity)...my latest task has been trying to integrate OpenSER and A2Billing seamlessly


Top
 Profile  
 
 Post subject:
PostPosted: Wed Mar 14, 2007 10:27 pm 
Offline

Joined: Thu Oct 19, 2006 9:56 am
Posts: 300
Location: Athens, Greece
crshman wrote:
..FULLY protected behind a firewall of some type....


I disagree.. You couldn't possibly fully protect (by blocking) some box until you actually pulled the network plug completely. Indeed, asterisk 1.4.0 suffered some SIP problem (security related - I won't go into details here)..
So any firewalls IMHO are useless: if you need some service, open its port, if not, just don't run the service! (some may also be configured only to listen on local interfaces/addresses)

Security comes when you carefully set up the linux box, you audit it and keep everything simple (so that it's easier to check). Then, you make sure you apply any patches once they come out.


Top
 Profile  
 
 Post subject:
PostPosted: Wed Mar 14, 2007 10:56 pm 
Offline

Joined: Thu Aug 10, 2006 10:47 pm
Posts: 145
Location: LA,CA,USA
By fully protected i meant from the big bad internet....any competent systems administrator would not have the need to firewall boxes on the corporate lan.....


Top
 Profile  
 
 Post subject: suhosin
PostPosted: Tue Apr 01, 2008 10:48 am 
Offline
User avatar

Joined: Tue Dec 04, 2007 12:05 am
Posts: 295
microcosmic wrote:
i think the best way is using iptables.

if possible use suse 10.1 or 10.2 because of the apparmor.

just open port 80 (HTTP), 443 (HTTPS), 5060 (SIP), 4569 (IAX2) and the ports you need for SSH (do NOT use standard port 22) and maybe webmin (do NOT use standard port 10000).

then you can also install Suhosin -http://www.hardened-php.net/suhosin/index.html



Hi now I am writing one manual for how to make the perfect centos and a2billing

and is very help full is you give me the correct setup for Suhosin and a2billing

thanks in advance


Top
 Profile  
 
 Post subject:
PostPosted: Sat Sep 06, 2008 6:45 pm 
Offline

Joined: Sun Aug 17, 2008 1:52 pm
Posts: 93
hi,

have you written the guide for perfect centos?

Can I know where to read it ?

thanks


Top
 Profile  
 
 Post subject:
PostPosted: Fri Feb 13, 2009 2:12 am 
Offline

Joined: Thu Aug 02, 2007 2:02 pm
Posts: 26
Yes sounds interesting


Top
 Profile  
 
Display posts from previous:  Sort by  
Post new topic Reply to topic  [ 11 posts ] 
Hosted Voice Broadcast


All times are UTC


Who is online

Users browsing this forum: No registered users and 21 guests


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum

Search for:
Jump to:  
cron
Powered by phpBB © 2000, 2002, 2005, 2007 phpBB Group