[asterisk-users] Hack

Steven Howes steve-lists at geekinter.net
Fri Oct 18 03:29:53 CDT 2013


On 18 Oct 2013, at 04:06, John T. Bittner <john at xaccel.net> wrote:
> Today I was hacked but caught it very quickly. This is the weird part, they hacked an IP Auth based account by simply knowing the account name.
> 
> How is this possible? I am running Asterisk 11.5.0. Now it’s my fault I used a dictionary based account name but how did they bypass the set ip I had under the account for this host.

Did the IP show under sip show peer xxx? If it's realtime it's possible to set it and need to prune it / sip reload.

Steve
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.digium.com/pipermail/asterisk-users/attachments/20131018/cf20c595/attachment.html>


More information about the asterisk-users mailing list