[Asterisk-Users] Asterisk security problem: authorized SIP users can fake any callerid!

Tom Samplonius tom.samplonius at gmail.com
Sat Mar 12 01:00:58 MST 2005


On Fri, 11 Mar 2005 14:41:37 -0500, C F <shmaltz at gmail.com> wrote:
> Welcome to SIP, this is how SIP works, thats why ppl use IAX.

  It is a combination of chan_sip and the particular sip.conf actually.

  Sane SIP servers will challenge all INVITEs, and apply user
identification from the user database, not what the UA choose to
supply.  But if you configre Asterisk to accept anything from anyone,
well you should expect this.

Tom



More information about the asterisk-users mailing list