[asterisk-users] Tipping Point IPS blocking Asterisk SIP quaility
messages
Edwin Groothuis
edwin at mavetju.org
Tue Feb 20 14:02:49 MST 2007
Hi guys,
Just wanted to give you a heads up, so you don't end up chasing
strange issues...
Since early this morning, our Tipping Point IPS is blocking the
Asterisk generated SIP Quality messages (the ones which tell you
how good or badly reachably a remote SIP server is)
Rule 5051: SIP: PROTOS Test Suite INVITE Test Case
This filter detects a test case from the PROTOS SIP testing
suite. PROTOS test suites are designed to "fizz" popular
protocols to discover weaknesses in particular implementation.
The PROTOS SIP test suite fuzzes SIP INVITE messages by sending
several thousand combinations of illegal, abnormal, and overlong
values for a variety of SIP INVITE message parameters. The
results of these results range from unexpected responses to
denial of service conditions to classic buffer overvlow error
conditions.
Vendor Site:
http://wwww.eee.oulu.fi/research/ouspq/protos/
It seems to be "default to block", which will cause a couple of
issues for people today :-)
Edwin
--
Edwin Groothuis | Personal website: http://www.mavetju.org
edwin at mavetju.org | Weblog: http://weblog.barnet.com.au/edwin/
More information about the asterisk-users
mailing list