[asterisk-dev] Dialstring injection - security advisory release?

Atis Lezdins atis at iq-labs.net
Tue Feb 23 07:18:50 CST 2010


>> This was already suggested by several other people, but not yet
>> implemented :-(

My apologies for missing that :( So, I hope to see patches soon.

>  Please also don't forget, that now we have two pattern matchers, i.e.
> ".", which collects digits, and "!", which triggers as soon as the match is
> complete, so we need TWO new symbols for their "safe" equivalents.

Of course, above was just example for illustrating :)

Regards,
Atis

-- 
Atis Lezdins,
VoIP Project Manager / Developer,
IQ Labs Inc,
atis at iq-labs.net
Skype: atis.lezdins
Cell Phone: +371 28806004
Cell Phone: +1 800 7300689
Work phone: +1 800 7502835



More information about the asterisk-dev mailing list