[Kamailio-Users] SIP Digest Access Authentication RELAY survey

Victor Pascual Ávila victor.pascual.avila at gmail.com
Wed Jan 14 17:58:23 CET 2009


On Wed, Jan 14, 2009 at 5:16 PM, Daniel-Constantin Mierla
<miconda at gmail.com> wrote:
> Hello,
>
> On 01/14/2009 05:49 PM, Victor Pascual Ávila wrote:
>>
>> Hi,
>> excuse me if this message is not directly related to Kamailio.
>>
>
> such debates are welcome all the time.
>>
>> I'm just wondering if folks could share with me if (and how) they have
>> prevented the "SIP Digest Access Authentication RELAY" in their
>> networks (and what worked for them or not).
>>
>
> To be sure we talk about the same thing, is this the issue described at:
> http://madynes.loria.fr/TeamMembers/Abdelnur/madynes-security-advisory-sip-digest-access-authentication-relay-attack-for-toll-fraud

Right. The attack is also described here:
http://kif.gforge.inria.fr/advisory/relay_attack.pdf
-- 
Victor Pascual Ávila


More information about the Users mailing list