[cisco-voip] CUCM6 linux distro

A.L.M.Buxey at lboro.ac.uk A.L.M.Buxey at lboro.ac.uk
Thu Aug 28 04:35:49 EDT 2008


Hi,
> Database is informix. Distro is RHEL.
> Why does it matter what they are. It is an appliance and the give you the
> tools t

security would be the obvious answer.  is the distro and packages
up to date - what services does it run, are they listening
on any ports, is there a firewall used to protect listening
ports or are services carefully configured to negate this.
are default or known username/passwords on the system..hardcoded
dbadmin/dbpass, for example.  in 'ye olde days' when an applicance
was coded for its purpose..didnt matter as much. now, when appliances
are based on Linux, Windows (or OSX!) these things are of a major 
concern...you have a fully operational system that, if compromised
would/could give enhanced access to the network and other systems..
but also then be subverted for free trunk calls to south asia
or greenland etc.

alan


More information about the cisco-voip mailing list