[Serusers] hijack another account

Andreas Granig a.granig at inode.at
Thu Dec 2 14:58:33 CET 2004


kcassidy at kakelma.mine.nu wrote:
>   This only checks the REGISTER method.  I think we need something to 
> check the URI in the INVITE method whether it's fake or not.  Just my 2 
> cents.

if(method == "INVITE" && proxy_authorize(...))
{
   if(!check_from())
   {
     # from-user != authorized user
   }
   # proceed as usual here...
}

should do it.

Andy




More information about the sr-users mailing list