[Asterisk-Dev] SIP SECURITY WARNING: v1-0 (cvs today) sip context
in general section ignored goes to default instead -
allowing unauthorized sip devices to place calls in default context
Olle E. Johansson
oej at edvina.net
Mon Dec 6 02:11:04 MST 2004
Andy Reinke wrote:
> SIP SECURITY WARNING
>
>
> [general]
>
> contex=sip-unauthorized
>
If you spell this right, all calls from unknown SIP devices will be sent to the
context you set here. If you do not set a context in the general section of
sip.conf, "default" will be used.
This is the way you configure how to receive calls from unknown users, not
really a security hole. Everything you define in the [general] context= context
will be rechable by anyone.
/Olle
More information about the asterisk-dev
mailing list