Gagan Posted September 9, 2020 Report Share Posted September 9, 2020 IS anyone else facing same issue in kazoo cluster? kazoo Kamilio Module is crashing after being hit by malicious SIP messages , which is causing kamailio to crash and dump core files. root@d1k1 ~]# ls -lh /tmp total 2.4G -rw-------. 1 kamailio daemon 1.4G Sep 9 09:18 core.4419 -rw-------. 1 kamailio daemon 1.4G Sep 9 08:39 core.4422 -rw-------. 1 kamailio daemon 216M Sep 9 10:29 core.4426 Even a single malicious attempt is crashing module. Dumps are being created, which ultimately fills disk space. when one kamailio module fails, other in cluster also fail in matter of seconds. Quote Link to comment Share on other sites More sharing options...
Darren Schreiber Posted September 9, 2020 Report Share Posted September 9, 2020 This sounds like a very old bug in an old version of Kamailio. We haven't had this in a long time. What is the version number? Quote Link to comment Share on other sites More sharing options...
Gagan Posted September 9, 2020 Author Report Share Posted September 9, 2020 4.3 version (4.3.58) Quote Link to comment Share on other sites More sharing options...
Darren Schreiber Posted September 9, 2020 Report Share Posted September 9, 2020 What Kamailio version though? Quote Link to comment Share on other sites More sharing options...
Gagan Posted September 9, 2020 Author Report Share Posted September 9, 2020 nstalled Packages Name : kazoo-kamailio Arch : noarch Version : 4.3 Release : 25.el7.centos Size : 0.0 Repo : installed From repo : kazoo4 [root@d1k1 ~]# kamailio -version version: kamailio 5.1.9-rc1 (x86_64/linux) Quote Link to comment Share on other sites More sharing options...
Darren Schreiber Posted September 9, 2020 Report Share Posted September 9, 2020 I would make sure you are on latest 4.3.x kazoo-kamailio-configs altogether. There was an exploit in the wild causing these crashes which we patched some time ago. Quote Link to comment Share on other sites More sharing options...
Gagan Posted September 10, 2020 Author Report Share Posted September 10, 2020 yes, we had similar issue earlier, but once we updated to 4.3.58 , issue was gone, now it seems to have hit back. Quote Link to comment Share on other sites More sharing options...
Recommended Posts
Join the conversation
You can post now and register later. If you have an account, sign in now to post with your account.