LWN.net Logo

"Vishing" advisory targets Asterisk

"Vishing" advisory targets Asterisk

Posted Dec 18, 2008 10:51 UTC (Thu) by tzafrir (subscriber, #11501)
Parent article: "Vishing" advisory targets Asterisk

Direct link: http://downloads.digium.com/pub/asa/AST-2008-003.html

Even for those not able to apply the source patch, an effective configuration workaround is mentioned there.

Many of the less-maintained Asterisk systems have a configuration built with the FreePBX system. In the standard configuration of the FreePBX system the default context from the general section is sent to a context that hangs up immediately, and hence would not allow any relayed calls.

And there are other issues to worry about, as stated in the discussion that followed. For instance, there are now more and more remote VoIP extensions. Those normally authenticate by password (technically: a challenge-response protocol. At least in SIP. So passwords are not sent in the clear). Naturally some of them have weak passwords and attackers try to guess such passwords.


(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds