[Asterisk-Dev] Re: SIP SECURITY WARNING: v1-0 (cvs today) sip
context in general section ignored goes to default instead -
allowing unauthorized sip devices to place calls in default context
Rich Adamson
radamson at routers.com
Sat Dec 4 08:18:45 MST 2004
> > What do you do to protect the truly stupid, lazy, or the wonderful
> > combination of both?
>
> You set up the default configuration files to accept all incoming
> requests into a context that, regardless of the attempted extension,
> answers by reading a voice message that explains that you need to
> follow the instructions in sip.conf and extensions.conf, telling you
> how to create a safe installation that will actually handle calls.
>
> In sip.conf, there could be a comment, in the [general] section,
> explaining that the active "context=initial" setting is what gives
> this behavior, and naming a couple of other preconfigured contexts
> you can name instead to enable more functionality.
Or, just something very simple like John Todd's sample:
context = bogon-calls ; Send SIP callers that we don't know about here
and the same for iax.
More information about the asterisk-dev
mailing list