Gagan Posted September 9, 2020 Report Posted September 9, 2020 IS anyone else facing same issue in kazoo cluster? kazoo Kamilio Module is crashing after being hit by malicious SIP messages , which is causing kamailio to crash and dump core files. root@d1k1 ~]# ls -lh /tmp total 2.4G -rw-------. 1 kamailio daemon 1.4G Sep 9 09:18 core.4419 -rw-------. 1 kamailio daemon 1.4G Sep 9 08:39 core.4422 -rw-------. 1 kamailio daemon 216M Sep 9 10:29 core.4426 Even a single malicious attempt is crashing module. Dumps are being created, which ultimately fills disk space. when one kamailio module fails, other in cluster also fail in matter of seconds.
Administrators Darren Schreiber Posted September 9, 2020 Administrators Report Posted September 9, 2020 This sounds like a very old bug in an old version of Kamailio. We haven't had this in a long time. What is the version number?
Administrators Darren Schreiber Posted September 9, 2020 Administrators Report Posted September 9, 2020 What Kamailio version though?
Gagan Posted September 9, 2020 Author Report Posted September 9, 2020 nstalled Packages Name : kazoo-kamailio Arch : noarch Version : 4.3 Release : 25.el7.centos Size : 0.0 Repo : installed From repo : kazoo4 [root@d1k1 ~]# kamailio -version version: kamailio 5.1.9-rc1 (x86_64/linux)
Administrators Darren Schreiber Posted September 9, 2020 Administrators Report Posted September 9, 2020 I would make sure you are on latest 4.3.x kazoo-kamailio-configs altogether. There was an exploit in the wild causing these crashes which we patched some time ago.
Gagan Posted September 10, 2020 Author Report Posted September 10, 2020 yes, we had similar issue earlier, but once we updated to 4.3.58 , issue was gone, now it seems to have hit back.
Recommended Posts