I just tried to submit a support ticket (https://www.connectwise.com/services/support) about the security bulletin "ConnectWise Control Host Header Injection". where I wanted to know when a secure version will be available for us, their Linux customers but I get a "403 Forbidden" when clicking the Submit button! What's the best way to contact them beside phone?
The “Initial” bug report about this
problem has been created almost a year ago
Back in December
ConnectWise released a security bulletin concerning a vulnerability
Since the fix is in version 20.13 and the Linux version is way way
behind, it seems we are stuck with a vulnerable version!
think we have been very patient. Like you asked, bug reports have
been filled but it seems the resolution of the problem is going at a
crawling speed! As
a Product Manager for ConnectWise, you
shouldn’t let us in the dark by giving us
the silent treatment! Please be more
pro-active and keep us informed about the progress (if any) and be
honest with us!
I followed your guide but when I tried to start Screen
Connect, the service would not start in the background. Usually the
service takes between 15 to 25 seconds to start. After 2 minutes, I
stopped the command and the log was already 200KB!
Should I wait longer? Do you want a log?
high Cpu utilization on my linux server. With version
19.4.25759.7247, I had a Cpu utilization around 1%. When it was
released, I installed version 19.6.27027.7360 where the Cpu
utilization reach a constant 30%. I also installed the latest version
(20.1.27036.7360). The cpu utilization is almost as high with 27%.
Below you can see the jump in Cpu utilization after installing version 19.6.27027.7360 and the little reduction after installing version 20.1.27036.736
Steve Moring, did you
try the latest version (20.1.27036.7360)?
Do you experience high Cpu utilization?
I have the same problem with ScreenConnector. I run ScreenConnect on an Ubuntu server behind a Nginx reverse proxy.
I get the message "Unable to connect to the remote server". After reading Zinc's bug report, I decided to check the ip and remote port that ScreenConnector is trying to use. The IP is the right one (WebServerAddressableUri) but the port is 8040 which is the non proxy port (WebServerListenUri).
Here are the keys from my web.config
Zinc, since you are also behind a reverse proxy, does the "External Accessibility Check" Passed or Failed on your setup? On mine, I get "Unrecognized server. Not ScreenConnect Web Server." for the Web Server.
Customer support service by UserEcho