Category Archives: advisories

Asterisk SIP vulnerability

I found a security hole in the Asterisk SIP implementation last week. I was happy to hear that it has already been patched and released. The vulnerability allows an attacker to determine whether a given username is valid or not. With knowledge of existing usernames a more efficient password guessing attack can be mounted against the system.

The full advisory can be read here:
http://downloads.asterisk.org/pub/security/AST-2009-008.html

I have been working on some very basic VoIP tools lately which amongst other things have this attack implemented. I’ll hopefully get to releasing it in the near future.