No subject


Thu Jul 12 09:23:04 CDT 2007


CDRs for attended transfers are now correct which is fantastic. For
blind transfers the CDR for the first call leg is still incorrect with
the duration only being recorded up until the point the transfer
occurs.

For people on the list following this bug my company got stung by this
in the last week so there now appear to be some people out there
actively looking for Asterisk systems to exploit. The incident for us
was a user using attended transfers to place free calls through a 1.2
system. In the past we have had normal users stumble across the
problem but in this case it was a directed attempt. So if like us you
are a provider and use Asterisk and are required to support transfers
it would be highly advisable to keep a close eye on things!

Regards,

Greyman.



More information about the asterisk-users mailing list