SIP trunks security alert

Alex728

Guru
Joined
Dec 22, 2007
Messages
416
Reaction score
1
Judging from my recent experience, at least one North American SIP trunk provider has not understood the importance of SIP authentication.
While working on a customer’s VoIP system, I noticed that SIP messages sent from their PBX to their SIP trunk provider were triggering an immediate response, without the usual authentication challenge.
This meant that the trunk was not bothering to authenticate call requests, leaving the system open to a toll fraud and other attacks.
http://www.itproportal.com/security/news/article/2009/2/19/sip-trunk-authentication-who-needs-it/
 
incidentally though I appeciate the article writer probably can't disclose the carrier with the hold for fear of causing more problems/being sued, maybe its worth someone showing people how to check that the carrier is authorisiing logins properly?

a minor point - I didn't intentionally select a smiley as the thread icon - this is of course nothing to smile about - did try to edit it to the warning sign icon but I know from being a mod on two other vbulletin forums that maybe only mods/admins can edit a thread subject (including icon)

edit: I think one of the mods appears to have changed it to a sad face which makes a bit more sense in the context..
 

Members online

No members online now.

Forum statistics

Threads
26,687
Messages
174,410
Members
20,257
Latest member
Dempan
Get 3CX - Absolutely Free!

Link up your team and customers Phone System Live Chat Video Conferencing

Hosted or Self-managed. Up to 10 users free forever. No credit card. Try risk free.

3CX
A 3CX Account with that email already exists. You will be redirected to the Customer Portal to sign in or reset your password if you've forgotten it.
Back
Top