Get a Pentest and security assessment of your IT network.

Advisories

Asterisk Project Security Advisory – AST-2009-008

Asterisk Project Security Advisory – It is possible to determine if a peer with a specific name is configured in Asterisk by sending a specially crafted REGISTER message twice. The username that is to be checked is put in the user portion of the URI in the To header. A bogus non-matching value is put into the username portion of the Digest in the Authorization header. If the peer does exist the second REGISTER will receive a response of “403 Authentication user name does not match account name”. If the peer does not exist the response will be “404 Not Found” if alwaysauthreject is disabled and “401 Unauthorized” if alwaysauthreject is enabled.

 

You can download this advisory from the following link: https://packetstormsecurity.com/files/download/82467/AST-2009-008.txt

Source: https://packetstormsecurity.com/files/82467/Asterisk-Project-Security-Advisory-AST-2009-008.html

Related posts
Advisories

crossZone.txt

Advisories

Secunia Security Advisory 16900

Advisories

Secunia Security Advisory 19793

Advisories

Secunia Security Advisory 22534