[asterisk-users] Tipping Point IPS blocking Asterisk SIP quaility messages

Edwin Groothuis edwin at mavetju.org
Tue Feb 20 14:02:49 MST 2007


Hi guys,

Just wanted to give you a heads up, so you don't end up chasing
strange issues...

Since early this morning, our Tipping Point IPS is blocking the
Asterisk generated SIP Quality messages (the ones which tell you
how good or badly reachably a remote SIP server is)

Rule 5051: SIP: PROTOS Test Suite INVITE Test Case

    This filter detects a test case from the PROTOS SIP testing
    suite.  PROTOS test suites are designed to "fizz" popular
    protocols to discover weaknesses in particular implementation.

    The PROTOS SIP test suite fuzzes SIP INVITE messages by sending
    several thousand combinations of illegal, abnormal, and overlong
    values for a variety of SIP INVITE message parameters. The
    results of these results range from unexpected responses to
    denial of service conditions to classic buffer overvlow error
    conditions.

    Vendor Site:
    http://wwww.eee.oulu.fi/research/ouspq/protos/

It seems to be "default to block", which will cause a couple of
issues for people today :-)

Edwin

-- 
Edwin Groothuis      |            Personal website: http://www.mavetju.org
edwin at mavetju.org    |          Weblog: http://weblog.barnet.com.au/edwin/


More information about the asterisk-users mailing list