Alohatone wrote:
that script is a barebones model to get it going
Use basic linux security concepts.
enable iptables and lock that server down
install fail2ban
if you ban everything and then just allow only what you want through (ports / source ips) the server can be very secure with minimal effort.
The problem is that this thing comes up with mysql and web open to the internet with default passwords. Sure I can secure it after it's up and check the logs but how can I be sure it's not too late then?
This stackscript would be improved by setting a user provided web password and a random database password. I've no idea how to do that though, this is the first time I've ever used a stackscript.
I'd never use fail2ban BTW. I don't really think it improves security.
EDIT: Security paranoia not withstanding asterix/freepbx work like a dream. I had a phone number working and forwarded to a SIP phone in about 2 minutes.