[asterisk-users] Removing mailbox and password prompt for voicemail

Nabeel nabeelshikder at gmail.com
Mon Aug 1 03:08:36 CDT 2016


>
> But did you understand every line and what it was doing?
>

They are quite self-explanatory, so of-course I understand them.


> Too much information missing.  Perhaps instead of asking how to
> implement the solution that you have already decided on you should
> instead tell us what problem you are trying to solve.  Are you really
> trying to make your voicemail available to anyone who calls you or are
> you limiting it to just the registered phone?  How are you accessing VM


I am using ODBC realtime storage with Asterisk. Currently, with no password
set, a user can dial the voicemail number to retrieve their own voicemail,
without needing to enter a password (without hearing the password prompt).
However, there is still a 'mailbox' prompt played, and if a different
mailbox number is entered after this prompt, then a password can be entered
(if set) which intrudes into the other person's mailbox. I want to remove
this 'mailbox' prompt so that users won't have this opportunity to access
another person's mailbox.

That's exactly what I mean.  That's why you need to password protect
> it.


I am yet to test this behaviour in Asterisk during the Unavailable/Busy
message. However, if this is the case, then this seems to be an illogical
security hole in Asterisk's design. Why does Asterisk allow accessing
another person's mailbox by pressing the '*' key, while listening to *the
other person's* unavailable message?

Nabeel
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.digium.com/pipermail/asterisk-users/attachments/20160801/e037172e/attachment.html>


More information about the asterisk-users mailing list