<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>VoIP Tech Chat &#187; SIP</title>
	<atom:link href="http://www.voiptechchat.com/tag/sip/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.voiptechchat.com</link>
	<description>Patrick and Fred Chat... sometimes about VoIP</description>
	<lastBuildDate>Fri, 30 Dec 2011 01:34:47 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>Explaining SIP Brute Force Attacks to Non-techs</title>
		<link>http://www.voiptechchat.com/voip/688/explaining-sip-brute-force-attacks-to-non-techs/</link>
		<comments>http://www.voiptechchat.com/voip/688/explaining-sip-brute-force-attacks-to-non-techs/#comments</comments>
		<pubDate>Fri, 11 Mar 2011 04:57:12 +0000</pubDate>
		<dc:creator>Fred</dc:creator>
				<category><![CDATA[tech]]></category>
		<category><![CDATA[VoIP]]></category>
		<category><![CDATA[asterisk]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[SIP]]></category>

		<guid isPermaLink="false">http://www.voiptechchat.com/?p=688</guid>
		<description><![CDATA[Check out this article from TEAM FORREST about explaining SIP Brute Force Attacks in plain English.]]></description>
			<content:encoded><![CDATA[<p>Check out <a href="http://www.teamforrest.com/blog/196/explaining-sip-brute-force-attacks/" onclick="pageTracker._trackPageview('/outgoing/www.teamforrest.com/blog/196/explaining-sip-brute-force-attacks/?referer=');">this article</a> from TEAM FORREST about explaining SIP Brute Force Attacks in plain English.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.voiptechchat.com/voip/688/explaining-sip-brute-force-attacks-to-non-techs/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Kamailio releases Version 3.1</title>
		<link>http://www.voiptechchat.com/voip/652/kamailio-openser-31/</link>
		<comments>http://www.voiptechchat.com/voip/652/kamailio-openser-31/#comments</comments>
		<pubDate>Sun, 10 Oct 2010 12:25:22 +0000</pubDate>
		<dc:creator>Fred</dc:creator>
				<category><![CDATA[VoIP]]></category>
		<category><![CDATA[Kamailio]]></category>
		<category><![CDATA[OpenSER]]></category>
		<category><![CDATA[SER]]></category>
		<category><![CDATA[SIP]]></category>

		<guid isPermaLink="false">http://www.voiptechchat.com/?p=652</guid>
		<description><![CDATA[Kamailio, formerly OpenSER, released version 3.1.0 on October 6th. Packed with some amazing features, the new version of Kamailio represents continued integration with the Sip Express Router (SER) software. New features from 3.1 include: asynchronous TLS embedded LUA, HTTP server, &#8230; <a href="http://www.voiptechchat.com/voip/652/kamailio-openser-31/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.kamailio.org" onclick="pageTracker._trackPageview('/outgoing/www.kamailio.org?referer=');">Kamailio</a>, formerly OpenSER, released <a href="http://www.kamailio.org/w/kamailio-openser-v3.1.0-release-notes/" onclick="pageTracker._trackPageview('/outgoing/www.kamailio.org/w/kamailio-openser-v3.1.0-release-notes/?referer=');">version 3.1.0</a> on October 6th. Packed with some amazing features, the new version of Kamailio represents continued integration with the Sip Express Router (SER) software.</p>
<p>New features from 3.1 include:</p>
<ul>
<li><a href="http://by-miconda.blogspot.com/2010/10/best-of-new-in-kamailio-310-6.html" onclick="pageTracker._trackPageview('/outgoing/by-miconda.blogspot.com/2010/10/best-of-new-in-kamailio-310-6.html?referer=');">asynchronous TLS</a></li>
<li>embedded LUA, HTTP server, Python, XCAP (and more)</li>
<li>SIP Registration to remote servers<span id="more-652"></span></li>
<li>new DoS preventions</li>
</ul>
<p>From Kamailio:</p>
<blockquote><p>Since last major release, version 3.0.0 (which was out in January 10, 2010),  the two SIP servers are practically the same application, the name making the difference regarding the database structure and the extensions used for certain features, such as user database based authentication or location service. Therefore another development direction was towards smooth integration of Kamailio and SER extensions, previously duplicated modules such as auth, sl, ratelimit or sms were merged during this development cycle.</p></blockquote>
<p>For more information, please visit <a href="http://www.kamailio.org" onclick="pageTracker._trackPageview('/outgoing/www.kamailio.org?referer=');">www.kamailio.org</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.voiptechchat.com/voip/652/kamailio-openser-31/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>VoIP Users Conference SIP Hacks Discussion Brings the Heat</title>
		<link>http://www.voiptechchat.com/voip/548/voip-users-conference-sip-hacks-discussion-brings-the-heat/</link>
		<comments>http://www.voiptechchat.com/voip/548/voip-users-conference-sip-hacks-discussion-brings-the-heat/#comments</comments>
		<pubDate>Mon, 24 May 2010 12:45:22 +0000</pubDate>
		<dc:creator>Fred</dc:creator>
				<category><![CDATA[VoIP]]></category>
		<category><![CDATA[hack]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[SIP]]></category>
		<category><![CDATA[vuc]]></category>

		<guid isPermaLink="false">http://www.voiptechchat.com/?p=548</guid>
		<description><![CDATA[The VoIP Users Conference provides an open-to-all weekly conference call where anyone can engage in discussions related to, well, VoIP. Sometimes the conversations discuss new technologies / products. Sometimes discussions center around implementation. And lately, conversations may focus on security. &#8230; <a href="http://www.voiptechchat.com/voip/548/voip-users-conference-sip-hacks-discussion-brings-the-heat/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.voiptechchat.com/wp-content/uploads/2010/05/argument.jpeg"><img class="alignright size-medium wp-image-549" title="argument" src="http://www.voiptechchat.com/wp-content/uploads/2010/05/argument-300x239.jpg" alt="" width="300" height="239" /></a>The VoIP Users Conference provides an open-to-all weekly conference call where anyone can engage in discussions related to, well, VoIP. Sometimes the conversations discuss new technologies / products. Sometimes discussions center around implementation. And lately, conversations may focus on security.</p>
<p>Last week, Ward Mundy, Tim Panton, Karl Fife, Leif Madsen, Yours Truly, and many other regulars <a href="http://www.voipusersconference.org/2010/sip-hack-callerid-stuffing/" onclick="pageTracker._trackPageview('/outgoing/www.voipusersconference.org/2010/sip-hack-callerid-stuffing/?referer=');">discussed a SIP Caller ID Injection Hack</a>. As in all conversations, opinions differ. My position about where to best filter this injection differed than Ward Mundy&#8217;s thoughts&#8230; and, courtesy of the VoIP Users Conference, you can listen to the conversation and form your own opinions.</p>
<p>Although, next time&#8230; maybe you&#8217;d enjoy actively participating in our conversations rather than listening to the replay. <img src='http://www.voiptechchat.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<p><strong>→ </strong><a href="http://www.voipusersconference.org/2010/sip-hack-callerid-stuffing/" onclick="pageTracker._trackPageview('/outgoing/www.voipusersconference.org/2010/sip-hack-callerid-stuffing/?referer=');"><strong>SIP Hacks: who should filter what, where?</strong></a><strong> (VoIP Users Conference)</strong></p>
<p>(The VoIP Users Conference provides weekly live discussion about VoIP, SIP, Asterisk and all kinds of telephony-related topics every Friday at 12pm EST. For more information, please visit <a href="http://vuc.me" onclick="pageTracker._trackPageview('/outgoing/vuc.me?referer=');">http://vuc.me</a>.)</p>
]]></content:encoded>
			<wfw:commentRss>http://www.voiptechchat.com/voip/548/voip-users-conference-sip-hacks-discussion-brings-the-heat/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>SIP Attacks From Amazon EC2 Cloud Continue</title>
		<link>http://www.voiptechchat.com/voip/538/sip-attacks-from-amazon-ec2-cloud-continue/</link>
		<comments>http://www.voiptechchat.com/voip/538/sip-attacks-from-amazon-ec2-cloud-continue/#comments</comments>
		<pubDate>Sun, 16 May 2010 22:11:02 +0000</pubDate>
		<dc:creator>Fred</dc:creator>
				<category><![CDATA[tech]]></category>
		<category><![CDATA[VoIP]]></category>
		<category><![CDATA[amazon ec2]]></category>
		<category><![CDATA[brute force]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[SIP]]></category>

		<guid isPermaLink="false">http://www.voiptechchat.com/?p=538</guid>
		<description><![CDATA[Just over a month ago, we reported that SIP attacks from the Amazon EC2 cloud were on the rise. While the attacks we received last month were limited to &#8220;extension only&#8221; registration attempts, one of the attacks we received this &#8230; <a href="http://www.voiptechchat.com/voip/538/sip-attacks-from-amazon-ec2-cloud-continue/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<div id="attachment_458" class="wp-caption alignright" style="width: 174px"><a href="http://www.voiptechchat.com/wp-content/uploads/2010/04/aws.gif"><img class="size-full wp-image-458" title="aws" src="http://www.voiptechchat.com/wp-content/uploads/2010/04/aws.gif" alt="" width="164" height="60" /></a><p class="wp-caption-text">Attacks from the cloud.</p></div>
<p>Just over a month ago, we reported that SIP attacks from the Amazon EC2 cloud <a href="http://www.voiptechchat.com/voip/457/amazon-ec2-sip-brute-force-attacks-on-rise/">were on the rise</a>. While the attacks we received last month were limited to &#8220;extension only&#8221; registration attempts, one of the attacks we received this morning included what we assume was a standard dictionary attack.</p>
<p>The first attack came from 204.236.245.101. In less than 60 seconds, this IP attempted more than 11,500 registrations against our server. Most of these were 4 digit extensions (<a href="http://www.voiptechchat.com/20100516-204ec2.txt.zip">download the log (zipped) here</a>). The second attack came from 184.73.4.183. In less than 90 seconds, this IP attempted more than 21,000 registrations against our server; including what we think is a standard dictionary attack complete with root, postmaster, pixadmin, etc. (<a href="http://www.voiptechchat.com/20100516-184ec2.txt.zip">download the log (zipped) here</a>).</p>
<p><span id="more-538"></span>From past experience, Amazon will simply not do anything about these attacks. The only way to contact Amazon to report abuse is through their web form, which results with Amazon either completely ignoring you or sending a delayed response asking for the exact information you have already sent (and then ignoring you).</p>
<p>So, I’m looking for more ideas from the community on how we can get Amazon to help us stop their network from leveraging a very powerful attack against little ol’ SIP servers.</p>
<p>We are currently deploying a custom perl script to block these attackers via iptables (which is why the attacks registration attempts “stopped”).</p>
<p>Thanks for reading and we’ll be updating this as soon as more information comes in!</p>
<p class="note">Update #1</p>
<p>The first response from Amazon:</p>
<blockquote><p>Thank you for submitting your abuse report.</p>
<p>We have completed an initial investigation of the issue and learned that the IP address you reported did indeed belong an Amazon EC2 instance. These intrusion attempts that you report were not, however, initiated by Amazon.</p>
<p>One of the biggest advantages of Amazon EC2 is that developers are given complete control of their instances. While the IPs may indicate that the network is Amazon&#8217;s, our developer customers are the ones controlling the instances. You may learn more about EC2 at http://aws.amazon.com/ec2</p>
<p>That said, we do take reports of unauthorized network activity from our environment very seriously. It is specifically forbidden in our terms of use. We&#8217;ve already contacted the Amazon EC2 customer who controlled the instance in question and informed them that they are required to terminate their unauthorized interaction with your network, failing which we will terminate their instance. In cases of egregious abuse or as we otherwise deem appropriate, we will immediately terminate all their instances and suspend their account.</p>
<p>If you have blocked this address range, please be aware that usage on the address range is transient and new users may soon be operating from those addresses and may not be able to reach you; once you have confirmed that the activity has been ceased by our customer, you should open your filters to re-allow traffic.</p>
<p>Thanks again for alerting us to this issue.</p>
<p>Original report:</p>
<p>* Source IPs: 204.236.245.101<br />
* Abuse Time: Sun May 16 08:53:00 UTC 2010<br />
* NTP: Y</p>
<p><strong>How can I send a message to the EC2 customer?</strong><br />
Complete and submit the web form <a href="https://www.amazon.com/gp/html-forms-controller/AWSAbuseReporter" onclick="pageTracker._trackPageview('/outgoing/www.amazon.com/gp/html-forms-controller/AWSAbuseReporter?referer=');">here</a>.</p>
<p><strong>How can I contact a member of the Amazon EC2 abuse team?</strong><br />
Send an e-mail to ec2-abuse@amazon.com to contact a member of the Amazon EC2 abuse team.</p>
<p>Please note: This e-mail message was sent from a notification-only address that cannot accept incoming e-mail. Please do not reply to this message.</p>
<p><a href="http://www.amazon.com/aws" onclick="pageTracker._trackPageview('/outgoing/www.amazon.com/aws?referer=');">Amazon Web Services</a></p>
<p>If you feel you are receiving this email in error and do not wish to receive further notifications, send an e-mail to ec2-abuse@amazon.com.</p>
<p>Amazon Web Services LLC is a subsidiary of Amazon.com, Inc. Amazon.com is a registered trademark of Amazon.com, Inc. This message produced and distributed by Amazon Web Services, LLC, 1200 12th Ave South, Seattle, WA 98144.</p></blockquote>
<p>I really don&#8217;t need a sales pitch in my abuse response.</p>
<h4>Additional Information:</h4>
<ul>
<li><a href="http://www.teamforrest.com/blog/171/asterisk-no-matching-peer-found-block/" onclick="pageTracker._trackPageview('/outgoing/www.teamforrest.com/blog/171/asterisk-no-matching-peer-found-block/?referer=');">Automatically Block Failed SIP Peer Registrations</a> (Team Forrest)</li>
<li><a href="http://www.voiptechchat.com/voip/457/amazon-ec2-sip-brute-force-attacks-on-rise/">Amazon EC2 SIP Brute Force Attacks on Rise</a> (VoIP Tech Chat)</li>
<li><a href="http://www.stuartsheldon.org/blog/2010/04/sip-brute-force-attack-originating-from-amazon-ec2-hosts/" onclick="pageTracker._trackPageview('/outgoing/www.stuartsheldon.org/blog/2010/04/sip-brute-force-attack-originating-from-amazon-ec2-hosts/?referer=');">SIP Brute Force Attack Originating From Amazon EC2 Hosts</a> (Building The Net)</li>
<li><a href="http://jcs.org/notaweblog/2010/04/11/properly_stopping_a_sip_flood/" onclick="pageTracker._trackPageview('/outgoing/jcs.org/notaweblog/2010/04/11/properly_stopping_a_sip_flood/?referer=');">Properly stopping a SIP flood</a> (joshua stein)</li>
</ul>
]]></content:encoded>
			<wfw:commentRss>http://www.voiptechchat.com/voip/538/sip-attacks-from-amazon-ec2-cloud-continue/feed/</wfw:commentRss>
		<slash:comments>20</slash:comments>
		</item>
		<item>
		<title>Amazon EC2 SIP Brute Force Attacks on Rise</title>
		<link>http://www.voiptechchat.com/voip/457/amazon-ec2-sip-brute-force-attacks-on-rise/</link>
		<comments>http://www.voiptechchat.com/voip/457/amazon-ec2-sip-brute-force-attacks-on-rise/#comments</comments>
		<pubDate>Sun, 11 Apr 2010 21:14:51 +0000</pubDate>
		<dc:creator>Fred</dc:creator>
				<category><![CDATA[VoIP]]></category>
		<category><![CDATA[amazon ec2]]></category>
		<category><![CDATA[brute force]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[SIP]]></category>

		<guid isPermaLink="false">http://www.voiptechchat.com/?p=457</guid>
		<description><![CDATA[Update #1: 12 APR 2010. Amazon NOC&#8217;s response. Update #2: 12 APR 2010. Amazon Statement. Update #3: 13 APR 2010. Amazon Response. Complaints of rampant SIP Brute Force Attacks coming from servers with Amazon EC2 IP Addresses cause many admins &#8230; <a href="http://www.voiptechchat.com/voip/457/amazon-ec2-sip-brute-force-attacks-on-rise/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<div id="attachment_458" class="wp-caption alignright" style="width: 174px"><a href="http://www.voiptechchat.com/wp-content/uploads/2010/04/aws.gif"><img class="size-full wp-image-458" title="aws" src="http://www.voiptechchat.com/wp-content/uploads/2010/04/aws.gif" alt="" width="164" height="60" /></a><p class="wp-caption-text">Attacks from the cloud.</p></div>
<p><strong>Update #1: 12 APR 2010. Amazon NOC&#8217;s response.<br />
Update #2: 12 APR 2010. Amazon Statement.<br />
Update #3: 13 APR 2010. Amazon Response. </strong></p>
<p>Complaints of rampant SIP Brute Force Attacks coming from servers with Amazon EC2 IP Addresses cause many admins to simply drop all Amazon EC2 traffic. Generally, SIP brute force attacks attempt to register various peer names to a system and/or attempt to guess passwords of known/guesses peers or endpoints.</p>
<p>The complaints mentioned this weekend show an excessive amount of traffic; with some providers claiming 6GB of traffic dedicated to such attacks. Since we ourselves received an attack from an Amazon hosted server, we also reported and complained to the Amazon NOC/Abuse depts. <del datetime="2010-04-12T12:15:37+00:00">As of this posting, no response or acknowledgement has been received from Amazon.</del> The response from Amazon is below. <span id="more-457"></span></p>
<p>There are various techniques to assist with minimizing DDoS and Brute Force attacks, such as limiting access via the public internet, using strong passwords, not mapping extension name to peer/endpoint name, limiting simultaneous calls, and aggressively monitoring usage. Automatic blocking of abusive IP&#8217;s (fail2ban, blockhosts, etc.) can also assist with minimizing damage.</p>
<p class="note">Update #1: 12 APR 2010. &#8220;Response&#8221; from Amazon&#8217;s NOC</p>
<p>So when this happened, I submitted a report to Amazon complaining of the attack. The report was sent to their abuse and noc mails and contained the standard abuse report, including their host, my host, the protocol, ports, and description of activity; as well as a sample log.</p>
<p>About 48 hours later, they sent this as a response:</p>
<blockquote><p>From: 	Amazon.com &lt;ec2-abuse@amazon.com&gt;<br />
Subject: 	Your Amazon EC2 Inquiry<br />
Date: 	April 12, 2010 7:31:59 AM EDT<br />
To:	Fred Posner</p>
<p>Hello.</p>
<p>Thank you for contacting Amazon Web Services. We take reports of unauthorized network activity from our environment very seriously. It is specifically forbidden in our terms of use.</p>
<p>Because Amazon EC2 Public IP addresses may change ownership frequently, without additional information we will be unable to identify the correct owner of the IP address for the period of time in question.</p>
<p>So that we can process your report and identify the actual customer in question, we require the following information. Please note that we will not open attachments under any circumstance</p>
<ul>
<li>Source IP</li>
<li>Destination IP (your IP)</li>
<li>Destination Port and Protocol</li>
<li>Accurate Date, Time and *Time Zone* of activity</li>
<li>Intensity and frequency of activity in short log extracts, no larger than 4KB</li>
<li>Your contact details (phone and email)</li>
</ul>
<p>For a faster response, please file your report using the AWS Abuse form at the link below:</p>
<p><a href="https://www.amazon.com/gp/html-forms-controller/AWSAbuse/" onclick="pageTracker._trackPageview('/outgoing/www.amazon.com/gp/html-forms-controller/AWSAbuse/?referer=');">https://www.amazon.com/gp/html-forms-controller/AWSAbuse/</a></p>
<p>We appreciate your help in providing the necessary information requested.</p>
<p>Best regards,</p>
<p>-EC2 Abuse Team</p></blockquote>
<p>So, their laziness aside (since the report to them included ALL the information requested), I filled out the form&#8211; which of course failed with an unknown error. (below)</p>
<p>For people interested in moving to Amazon&#8217;s cloud, this is a good example of the quality of people conducting your network administration. I&#8217;ve sent another response by email. Others have blocked the entire EC2 IP range and have requested their upstream providers do the same.</p>
<p><strong>So my question to you&#8230; What would </strong><em><strong>your </strong></em><strong>next step be?</strong></p>
<p class="note">Update #2: 12 APR 2010. Amazon Statement.</p>
<p>Following a request for interview/statement, VoIP Tech Chat received the following communication from Amazon&#8217;s Public Relations Manager:</p>
<blockquote><p>Hello Fred and thank you for contacting us.  Over the weekend, we received a report of a suspicious account and began an investigation.  Our normal process is to connect the two involved parties to give them an opportunity to talk in case the abuse is not malicious but is simply heavy traffic from a legitimate customer.  If that is not successful, we then move to isolate the traffic from the abusing party.  Normally this process works quite well for situations our customers have encountered, however this incident has highlighted the need for an escalation process to address potentially malicious attacks more quickly.  Additionally, we are working on quickly putting better protections and processes in place to better guard against unwanted SIP traffic.  We take the security of our customers and our quality of service very seriously, and will  continue to work to improve our processes and services for customers.</p>
<p>Thanks</p>
<p>Kay Kinton<br />
Public Relations Manager<br />
Amazon Web Services</p></blockquote>
<p>I&#8217;ve replied to again ask for an interview and will update if a response is received. The statement states this was over a weekend, however doesn&#8217;t address that the attacks continued today. It also states a &#8220;report&#8221; was received, but there were many reports submitted. That being said, at least they responded.</p>
<p class="note">Update #3: 13 APR 2010. Amazon Response. Decline of Interview.</p>
<p>After Kay Kinton&#8217;s statement, I asked her for a phone interview.</p>
<blockquote><p>Sent: Monday, April 12, 2010 2:00 PM<br />
To: Kinton, Kay<br />
Subject: Re: Amazon Web Services</p>
<p>Kay,</p>
<p>Thank you for your statement. I would like to interview you about this for VoIP Tech Chat&#8230; it would be an over-the-phone interview and would be for 5 minutes or however much longer you would like.</p>
<p>&#8212;fred</p></blockquote>
<p>Kay&#8217;s response was quick, and to the point:</p>
<blockquote><p>What else can I tell you Fred?</p></blockquote>
<p>I truly dislike email for interviews for no other reason that not getting the tone of that response. Did Kay mean that as &#8220;Sure, great! What else can I help you with?&#8221; Or, was it more along the lines of, &#8220;I answered you. What now?&#8221;</p>
<p>Giving her the benefit of the doubt, I replied:</p>
<blockquote><p>Date: April 12, 2010 5:24:14 PM EDT<br />
To: &#8220;Kinton, Kay&#8221;<br />
Subject: Re: Amazon Web Services</p>
<p>We would like to interview on this. I thank you for the statement, however I have additional questions:</p>
<p>I know of 12 complaints since Saturday (from different reporters) that were submitted regarding SIP attacks from EC2 to outside systems. How many complaints did you receive since Saturday?</p>
<p>I know attacks continued today and may even be ongoing. There were attacks as of 1pm EST hitting systems with over 640K of data. Are you still seeing attacks? How many hosts were identified?</p>
<p>Were the attacks submitted from one customer/client of yours or many?</p>
<p>Those are my initial questions, however I do request a phone interview rather than email. I find them much easier to exchange information as well as generally a better expressive forum for an interview.</p>
<p>&#8212;fred</p></blockquote>
<p>Good thing I didn&#8217;t hold my breath. The next day, after not receiving a response, I called Kay several times and emailed her for an update. Her response via email:</p>
<blockquote><p>Hello Fred. We believe that we&#8217;ve identified and shut down the illegal activity and are closing the loop with customers.  We&#8217;d certainly be interested in hearing of the cases you refer to below so we can follow up.</p></blockquote>
<p>I tried reaching out to her but have not had responses. Which leaves me with this&#8230;</p>
<p>Her response did not answer my question and I certainly have no basis to believe that Amazon is currently taking any interest in this matter. They&#8217;ve told us prior that they cannot pinpoint IP to timeframe as well as that during an attack, they&#8217;d try to mediate between parties rather than actually stopping the attack in progress (to give them an opportunity to talk). Sadly&#8230; when I&#8217;m being flooded, I want the flood to stop. Afterwards, I&#8217;ll be glad to talk. But I digress&#8230;</p>
<p>Since Kay did not answer any of the additional questions we asked, but did state that she&#8217;d be interested in hearing about the other cases, we will encourage anyone with information or feelings about this issue to contact Kay Kinton directly:</p>
<p style="padding-left: 30px;">Kay Kinton<br />
<strong><a href="mailto:kinton@amazon.com">kinton@amazon.com</a></strong><br />
Public Relations Manager<br />
Amazon Web Services<br />
<strong>Phone:  206-266-8387</strong></p>
<div class="topsy_widget_data" style="float: right; margin-left: 0.75em;"><script type="text/javascript">// <![CDATA[
   topsyWidgetPreload({ "url": "http://www.voiptechchat.com/voip/457/amazon-ec2-sip-brute-force-attacks-on-rise/", "title": "Amazon EC2 SIP Brute Force Attacks on Rise", "theme": "blue","style": "big", "nick": "fredposner" });
// ]]&gt;</script></div>
<p><strong>For More Information:</strong></p>
<ul>
<li><a href="http://lists.digium.com/pipermail/asterisk-users/2010-April/thread.html#247094" onclick="pageTracker._trackPageview('/outgoing/lists.digium.com/pipermail/asterisk-users/2010-April/thread.html_247094?referer=');">Asterisk User&#8217;s Mailing List Archives</a></li>
<li><a href="http://blogs.digium.com/2009/03/28/sip-security/" onclick="pageTracker._trackPageview('/outgoing/blogs.digium.com/2009/03/28/sip-security/?referer=');">7 Steps to Better SIP Security</a> (Digium)</li>
<li><a href="http://www.aczoom.com/cms/blockhosts" onclick="pageTracker._trackPageview('/outgoing/www.aczoom.com/cms/blockhosts?referer=');">Blockhosts</a></li>
<li><a href="http://www.voipsa.org/" onclick="pageTracker._trackPageview('/outgoing/www.voipsa.org/?referer=');">Voice over IP Security Alliance</a> (VOIPSA)</li>
<li><a href="http://www.stuartsheldon.org/blog/2010/04/sip-brute-force-attack-originating-from-amazon-ec2-hosts/" onclick="pageTracker._trackPageview('/outgoing/www.stuartsheldon.org/blog/2010/04/sip-brute-force-attack-originating-from-amazon-ec2-hosts/?referer=');">SIP Brute Force Attack Originating From Amazon EC2 Hosts</a> (Building The Net)</li>
<li><a href="http://jcs.org/notaweblog/2010/04/11/properly_stopping_a_sip_flood/" onclick="pageTracker._trackPageview('/outgoing/jcs.org/notaweblog/2010/04/11/properly_stopping_a_sip_flood/?referer=');">Properly stopping a SIP flood</a> (joshua stein)</li>
<li><a href="http://www.teamforrest.com/blog/171/asterisk-no-matching-peer-found-block/" onclick="pageTracker._trackPageview('/outgoing/www.teamforrest.com/blog/171/asterisk-no-matching-peer-found-block/?referer=');">Automatically Block Failed SIP Peer Registrations</a> (Team Forrest)</li>
</ul>
<div id="attachment_462" class="wp-caption aligncenter" style="width: 310px"><a href="http://www.voiptechchat.com/wp-content/uploads/2010/04/amazon-ec2-noc.png"><img class="size-medium wp-image-462" title="amazon-ec2-noc" src="http://www.voiptechchat.com/wp-content/uploads/2010/04/amazon-ec2-noc-300x207.png" alt="" width="300" height="207" /></a><p class="wp-caption-text">Report your error with our form. Fail.</p></div>
]]></content:encoded>
			<wfw:commentRss>http://www.voiptechchat.com/voip/457/amazon-ec2-sip-brute-force-attacks-on-rise/feed/</wfw:commentRss>
		<slash:comments>53</slash:comments>
		</item>
		<item>
		<title>Cisco SIP Denial of Service Vulnerabilities</title>
		<link>http://www.voiptechchat.com/voip/416/cisco-sip-denial-of-service-vulnerabilities/</link>
		<comments>http://www.voiptechchat.com/voip/416/cisco-sip-denial-of-service-vulnerabilities/#comments</comments>
		<pubDate>Thu, 25 Mar 2010 13:05:58 +0000</pubDate>
		<dc:creator>Fred</dc:creator>
				<category><![CDATA[tech]]></category>
		<category><![CDATA[VoIP]]></category>
		<category><![CDATA[Cisco]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[SIP]]></category>
		<category><![CDATA[vulnerability]]></category>

		<guid isPermaLink="false">http://www.voiptechchat.com/?p=416</guid>
		<description><![CDATA[Cisco recently announced a Denial of Service vulnerability within the SIP implementation of the Cisco IOS Software. Cisco devices running affected Cisco IOS Software versions that are configured to process SIP messages are affected. The vulnerability allows a remote attacker &#8230; <a href="http://www.voiptechchat.com/voip/416/cisco-sip-denial-of-service-vulnerabilities/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p><img class="alignright size-full wp-image-418" title="cisco" src="http://www.voiptechchat.com/wp-content/uploads/2010/03/cisco.gif" alt="" width="110" height="73" />Cisco recently <a href="http://www.cisco.com/en/US/products/products_security_advisory09186a0080b20f32.shtml" onclick="pageTracker._trackPageview('/outgoing/www.cisco.com/en/US/products/products_security_advisory09186a0080b20f32.shtml?referer=');">announced</a> a Denial of Service vulnerability within the SIP implementation of the Cisco IOS Software. Cisco devices running affected Cisco IOS Software  versions that are 	 configured to process SIP messages are affected. The vulnerability allows a remote attacker to reload a device and/or execute remote code.</p>
<p>Cisco recommends removing SIP support unless needed. &#8220;If the affected Cisco IOS device requires SIP for  VoIP services, SIP 	 cannot be disabled, and no workarounds are available. Users are  advised to 	 apply mitigation techniques to help limit exposure to the  vulnerabilities. 	 Mitigation consists of allowing only legitimate devices to connect to  affected 	 devices. To increase effectiveness, the mitigation must be coupled  with 	 anti-spoofing measures on the network edge. This action is required  because SIP 	 can use UDP as the transport protocol.&#8221;</p>
<p>The full advisory is reprinted below: <span id="more-416"></span></p>
<blockquote>
<h3>Cisco Security Advisory: Cisco IOS Software Session Initiation Protocol Denial of Service Vulnerabilities</h3>
<p>* Cisco Security Advisory: Cisco IOS Software Session Initiation Protocol Denial of Service Vulnerabilities</p>
<p>Document ID: 111448</p>
<h5>Advisory ID: cisco-sa-20100324-sip</p>
<p>http://www.cisco.com/warp/public/707/cisco-sa-20100324-sip.shtml</p>
<p>Revision 1.0<br />
For Public Release 2010 March 24 1600 UTC (GMT)</h5>
<p><strong>Summary</strong></p>
<p>Multiple vulnerabilities exist in the Session Initiation Protocol (SIP) implementation in Cisco IOS Software that could allow an unauthenticated, remote attacker to cause a reload of an affected device when SIP operation is enabled. Remote code execution may also be possible.</p>
<p>Cisco has released free software updates that address these vulnerabilities. For devices that must run SIP there are no workarounds; however, mitigations are available to limit exposure of the vulnerabilities.</p>
<p>This advisory is posted at http://www.cisco.com/warp/public/707/cisco-sa-20100324-sip.shtml.</p>
<p>Note: The March 24, 2010, Cisco IOS Software Security Advisory bundled publication includes seven Security Advisories. All the advisories address vulnerabilities in Cisco IOS Software. Each advisory lists the releases that correct the vulnerability or vulnerabilities detailed in the advisory. The table at the following URL lists releases that correct all Cisco IOS Software vulnerabilities that have been published on March 24, 2010, or earlier:</p>
<p>http://www.cisco.com/warp/public/707/cisco-sa-20100324-bundle.shtml</p>
<p>Individual publication links are in &#8220;Cisco Event Response: Semiannual Cisco IOS Software Security Advisory Bundled Publication&#8221; at the following link:</p>
<p>http://www.cisco.com/web/about/security/intelligence/Cisco_ERP_mar10.html</p>
<h3>Affected Products</h3>
<p>These vulnerabilities only affect devices running Cisco IOS  Software with SIP voice services enabled.</p>
<h3>Impact</h3>
<p>Successful exploitation of the vulnerabilities in this advisory may result in a reload of the device. Repeated exploitation could result in a sustained denial of service condition. There is a potential to execute arbitrary code. In the event of successful remote code execution,  device integrity could be completely compromised.</p></blockquote>
<h2>Related Links / Suggested Readings</h2>
<ul>
<li><a href="http://www.cisco.com/en/US/products/products_security_advisory09186a0080b20f32.shtml" onclick="pageTracker._trackPageview('/outgoing/www.cisco.com/en/US/products/products_security_advisory09186a0080b20f32.shtml?referer=');">Cisco Security Advisory: Cisco IOS Software Session Initiation Protocol Denial of Service Vulnerabilities</a></li>
<li><a href="http://www.teamforrest.com/blog/162/vulnerability-assessment-and-scans/" onclick="pageTracker._trackPageview('/outgoing/www.teamforrest.com/blog/162/vulnerability-assessment-and-scans/?referer=');">Vulnerability Scans and Assessments</a></li>
</ul>
]]></content:encoded>
			<wfw:commentRss>http://www.voiptechchat.com/voip/416/cisco-sip-denial-of-service-vulnerabilities/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Verizon Announces SMB VoIP Package</title>
		<link>http://www.voiptechchat.com/voip/393/verizon-announces-smb-voip-package/</link>
		<comments>http://www.voiptechchat.com/voip/393/verizon-announces-smb-voip-package/#comments</comments>
		<pubDate>Mon, 15 Mar 2010 18:42:10 +0000</pubDate>
		<dc:creator>Fred</dc:creator>
				<category><![CDATA[tech]]></category>
		<category><![CDATA[VoIP]]></category>
		<category><![CDATA[business]]></category>
		<category><![CDATA[SIP]]></category>
		<category><![CDATA[verizon]]></category>

		<guid isPermaLink="false">http://www.voiptechchat.com/?p=393</guid>
		<description><![CDATA[Verizon recently issued a press release where they introduced two new &#8220;packages&#8221; aimed to help small to medium sized businesses through &#8220;rough economic times.&#8221; Although the packages are detailed and named in the press release (reprinted below), the release and &#8230; <a href="http://www.voiptechchat.com/voip/393/verizon-announces-smb-voip-package/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p><img class="alignright size-full wp-image-396" title="verizon" src="http://www.voiptechchat.com/wp-content/uploads/2010/03/verizon.gif" alt="" width="152" height="55" />Verizon recently<a href="http://www.verizonbusiness.com/us/about/news/pr-25480-en-Small+and+Medium+Sized+Business+Options+Are+Focus+of+Verizon+Global+Wholesale+Offers.xml" onclick="pageTracker._trackPageview('/outgoing/www.verizonbusiness.com/us/about/news/pr-25480-en-Small+and+Medium+Sized+Business+Options+Are+Focus+of+Verizon+Global+Wholesale+Offers.xml?referer=');"> issued a press release</a> where they introduced two new &#8220;packages&#8221; aimed to help small to medium sized businesses through &#8220;rough economic times.&#8221; Although the packages are detailed and named in the press release (reprinted below), the release and website are a little lacking for information regarding costs and fees. If Verizon will be making it easier (and cost effective) to get SIP Trunks to end users, this may open a great window for PBX systems such as Asterisk, SwitchVox, FreeSWITCH, and more.</p>
<p>The press release follows:</p>
<blockquote>
<h2>Small and Medium-Sized Business Options Are Focus of Verizon Global Wholesale Offers</h2>
<h4>Voice Over IP and Powerful Internet Access Packages Bolster Business Success In Rough Economic Times</h4>
<p>March 15, 2010</p>
<p><strong>NEW YORK</strong> &#8211; At a time when small and medium-sized businesses look for every technological advantage to help them continue as the fundamental economic growth engine in the U.S., Verizon is providing support with three new voice-over-IP and Internet packages available through the Verizon Global Wholesale division.<span id="more-393"></span></p>
<p>The offers are designed to respond to the rapid growth of voice over IP (VoIP) in the small and medium business realm and the resulting demand for powerful high-speed Internet connections. In addition, the offers support Verizon Global Wholesale customers&#8217; marketing efforts to small and medium sized businesses.</p>
<p>&#8220;By creating new VoIP and Internet packages that include both services and hardware, we&#8217;re giving our wholesale customers new ways to support their small- and medium-sized business customers in a time when every nickel and every efficiency counts toward success,&#8221; said Quintin Lew, senior vice president of marketing for Verizon Global Wholesale. &#8220;Our goal continues to be to arm our wholesale customers with the tools that help them to help small and medium-sized businesses succeed.&#8221;</p>
<p>(For more information about the benefits Verizon Global Wholesale offers its wholesale customers who support the small and medium business market, click <a href="http://www.verizonbusiness.com/resources/media/index.xml?urlid=130677" onclick="pageTracker._trackPageview('/outgoing/www.verizonbusiness.com/resources/media/index.xml?urlid=130677&amp;referer=');">here</a>.)</p>
<h3>NEC IP PBX and SIP Gateway Solution</h3>
<p>The first new package combines Verizon&#8217;s SIP (session initiation protocol) Gateway Service with associated router hardware. SIP Gateway Service transports VoIP traffic between packet-based IP networks and the traditional telephone network, allowing Verizon Global Wholesale&#8217;s customers to give small and medium-sized businesses a quick and easy way to get into the VoIP world.</p>
<p>In addition to providing access to Verizon&#8217;s expansive IP local network and its telephone number inventory, wholesale customers can offer small and medium-sized businesses a new NEC UNIVERGE SV8100 IP PBX and its associated installation and maintenance bundle at a discount, simplifying the setup and lowering the cost of entry into the IP market. This enables small and medium-sized businesses to work with a single vendor, receive one bill, and gain access to a feature-rich VoIP solution that delivers cost reductions and the promise of increased productivity.</p>
<p>Both the SIP connection and the NEC UNIVERGE SV8100 PBX are priced at a discount with this new simple, feature-rich package. The service and hardware discounts expire on June 30.</p>
<h3>Internet Dedicated T1 Package</h3>
<p>The second new package, Internet Dedicated T1, also combines discounted service and hardware. It provides a high-capacity connection for 30 or more users and is designed for transmitting high-volume e-mail traffic, transferring large files, or hosting Web sites from virtually anywhere.</p>
<p>The package, based on T1 technology, combines 24 channels of broadband signal into a 1.544 megabit per second (Mbps) service, with customer equipment available to enable the service. Quality of service (QoS) assurance is offered as an option, at an additional cost. QoS is important for businesses that consolidate voice, video and key business applications onto a converged IP network.</p>
<p>The equipment offered in this package is either a Samsung Ubigate iBG 1000 for data-only applications or a model 1003 for data and voice services combined. The discounts on service and equipment expire on March 31, 2011.</p>
<p>For small and medium-sized businesses with a larger appetite for Internet access, a third new promotional offer features Internet access with an Ethernet connection at either 5 Mbps or 10 Mbps. This Internet Dedicated Ethernet service is discounted and bundled with a Samsung iBG1000 router, the cost of which is credited back over the initial year of service.</p>
<p>Targeted at businesses that intend to consolidate voice, video and key business applications onto a converged IP network, this offer delivers a single-vendor solution that end-user customers can leverage to fit their business model. The Ethernet service discount and the monthly credit offer for the cost of the router are scheduled to expire on March 31, 2011.</p>
<p>&#8220;Small businesses need their carriers to go beyond a one-size-fits-all solution,&#8221; Lew said. &#8220;These Internet offers cover the key speeds and features that growing small and medium-sized enterprises require to solve modern connection issues and engage the world in new and aggressive ways.&#8221;</p>
<p>Verizon Communications Inc. (NYSE, NASDAQ:VZ), headquartered in New York, is a global leader in delivering broadband and other wireless and wireline communications services to mass market, business, government and wholesale customers. Verizon Wireless operates America&#8217;s most reliable wireless network, serving more than 91 million customers nationwide. Verizon also provides converged communications, information and entertainment services over America&#8217;s most advanced fiber-optic network, and delivers innovative, seamless business solutions to customers around the world. A Dow 30 company, Verizon employs a diverse workforce of approximately 222,900 and last year generated consolidated revenues of more than $107 billion. For more information, visit <a href="http://www.verizon.com" onclick="pageTracker._trackPageview('/outgoing/www.verizon.com?referer=');">www.verizon.com</a>.</p>
<p>VERIZON&#8217;S ONLINE NEWS CENTER: Verizon news releases, executive speeches and biographies, media contacts, high-quality video and images, and other information are available at Verizon&#8217;s News Center on the World Wide Web at <a href="http://www.verizon.com/news" onclick="pageTracker._trackPageview('/outgoing/www.verizon.com/news?referer=');">www.verizon.com/news</a>. To receive news releases by e-mail, visit the News Center and register for customized automatic delivery of Verizon news releases.</p>
<h4>Media Contacts:</h4>
<p>Lynn Staggs<br />
+1-918-590-2403<br />
lynn.staggs@verizonbusiness.com</p>
<p>Jim Smith<br />
Verizon<br />
201-618-3346<br />
james.albert.smith@verizon.com</p></blockquote>
<h4>Suggested Reading:</h4>
<ul>
<li><a href="http://www.mgraves.org/voip/2010/03/sip-trunks-don’t-exist-there’s-no-such-thing" onclick="pageTracker._trackPageview('/outgoing/www.mgraves.org/voip/2010/03/sip-trunks-don_t-exist-there_s-no-such-thing?referer=');">Graves On SOHO VoIP — SIP Trunks don&#8217;t exist.</a></li>
<li><a href="http://www.verizonwireless.com" onclick="pageTracker._trackPageview('/outgoing/www.verizonwireless.com?referer=');">Verizon Wireless</a></li>
</ul>
]]></content:encoded>
			<wfw:commentRss>http://www.voiptechchat.com/voip/393/verizon-announces-smb-voip-package/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>VoicePulse Minimum Usage Requirement</title>
		<link>http://www.voiptechchat.com/voip/375/voicepulse-minimum-usage-requirement/</link>
		<comments>http://www.voiptechchat.com/voip/375/voicepulse-minimum-usage-requirement/#comments</comments>
		<pubDate>Tue, 09 Mar 2010 16:20:23 +0000</pubDate>
		<dc:creator>Fred</dc:creator>
				<category><![CDATA[VoIP]]></category>
		<category><![CDATA[SIP]]></category>
		<category><![CDATA[voicepulse]]></category>

		<guid isPermaLink="false">http://www.voiptechchat.com/?p=375</guid>
		<description><![CDATA[VoicePulse announced today in an email that Business and Wholesale accounts will be required to meet a minimum usage of $10/month. They also advised that their Terms of Service had been updated to reflect the change. The company targeting users &#8230; <a href="http://www.voiptechchat.com/voip/375/voicepulse-minimum-usage-requirement/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.voicepulse.com" onclick="pageTracker._trackPageview('/outgoing/www.voicepulse.com?referer=');">VoicePulse</a> announced today in an email that Business and Wholesale accounts will be required to meet a minimum usage of $10/month. They also advised that their Terms of Service had been updated to reflect the change. The company targeting users utilizing the service as a backup provider encouraged account holders to contact a representative to discuss becoming the &#8220;Primary&#8221; provider.</p>
<p>The email follows: <span id="more-375"></span></p>
<blockquote><p>Beginning on your next monthly bill cycle (3/27/2010 12:00:00 AM), your VoicePulse for Business and Wholesale account will be required to meet a minimum usage of $10 per month. The minimum usage requirement can be met by any combination of phone numbers, channels, features, outbound minutes, inbound toll-free minutes, etc.  Our Terms of Service has been updated to reflect above mentioned changes and we advise all customers to review the updated Terms of Service available within your account center.</p>
<p>Make VoicePulse Your Primary Provider</p>
<p>If you are using VoicePulse service as a backup provider and do not meet this minimum usage each month, our customer service representatives are ready to work with you on pricing so that we can become your primary provider.</p>
<p>Inactive Accounts</p>
<p>If you are not using your VoicePulse service and have no intention of doing so in the future, our customer service representatives will be responsive, courteous and expeditious in canceling your account, at your request.  However, if you are using another provider for your VoIP services and have had a good experience with VoicePulse in the past, we are ready to take whatever steps necessary to win back your business and offer you savings that exceed or eliminate this fee altogether</p>
<p>We appreciate your continued support and we look forward to serving you in the years to come. As always, our representatives are available by phone at +1-732-339-5100 M-F 9am-5pm ET and email at contact@voicepulse.com.</p></blockquote>
]]></content:encoded>
			<wfw:commentRss>http://www.voiptechchat.com/voip/375/voicepulse-minimum-usage-requirement/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Asterisk Security Release Announced</title>
		<link>http://www.voiptechchat.com/voip/366/asterisk-security-release-announced/</link>
		<comments>http://www.voiptechchat.com/voip/366/asterisk-security-release-announced/#comments</comments>
		<pubDate>Fri, 19 Feb 2010 12:22:18 +0000</pubDate>
		<dc:creator>Fred</dc:creator>
				<category><![CDATA[VoIP]]></category>
		<category><![CDATA[asterisk]]></category>
		<category><![CDATA[Digium]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[SIP]]></category>

		<guid isPermaLink="false">http://www.voiptechchat.com/?p=366</guid>
		<description><![CDATA[The Asterisk team of Digium announced new versions of Asterisk in reference to a potential security issue. The release highlights best practices and hopes to raise awareness of some potential security issues and injection statments. The announcement follows: The Asterisk &#8230; <a href="http://www.voiptechchat.com/voip/366/asterisk-security-release-announced/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p>The <a href="http://www.asterisk.org" onclick="pageTracker._trackPageview('/outgoing/www.asterisk.org?referer=');">Asterisk</a> team of <a href="http://www.digium.com" onclick="pageTracker._trackPageview('/outgoing/www.digium.com?referer=');">Digium</a> announced new versions of Asterisk in reference to a potential security issue. The release highlights best practices and hopes to raise awareness of some potential security issues and injection statments. The announcement follows:</p>
<blockquote><p>The Asterisk Development Team has announced security releases for the following<br />
versions of Asterisk:<span id="more-366"></span></p>
<p>* 1.2.40<br />
* 1.4.29.1<br />
* 1.6.0.24<br />
* 1.6.1.16<br />
* 1.6.2.4</p>
<p>These releases are available for immediate download at<br />
<a href="http://downloads.asterisk.org/pub/telephony/asterisk/" onclick="pageTracker._trackPageview('/outgoing/downloads.asterisk.org/pub/telephony/asterisk/?referer=');">http://downloads.asterisk.org/pub/telephony/asterisk/</a></p>
<p>The releases of Asterisk 1.2.40, 1.4.29.1, 1.6.0.24, 1.6.1.16, and 1.6.2.4<br />
include documention describing a possible dialplan string injection with common<br />
usage of the ${EXTEN} (and other expansion variables). The issue and resolution<br />
are described in the AST-2010-002 security advisory.</p>
<p>If you have a channel technology which can accept characters other than numbers<br />
and letters (such as SIP) it may be possible to craft an INVITE which sends data<br />
such as 300&amp;Zap/g1/4165551212 which would create an additional outgoing channel<br />
leg that was not originally intended by the dialplan programmer.</p>
<p>Please note that this is not limited to an specific protocol or the Dial()<br />
application.</p>
<p>The expansion of variables into programmatically-interpreted strings is a common<br />
behavior in many script or script-like languages, Asterisk included. The ability<br />
for a variable to directly replace components of a command is a feature, not a<br />
bug &#8211; that is the entire point of string expansion.</p>
<p>However, it is often the case due to expediency or design misunderstanding that<br />
a developer will not examine and filter string data from external sources before<br />
passing it into potentially harmful areas of their dialplan.</p>
<p>With the flexibility of the design of Asterisk come these risks if the dialplan<br />
designer is not suitably cautious as to how foreign data is allowed to enter the<br />
system unchecked.</p>
<p>This security release is intended to raise awareness of how it is possible to<br />
insert malicious strings into dialplans, and to advise developers to read the<br />
best practices documents so that they may easily avoid these dangers.</p>
<p>For more information about the details of this vulnerability, please read the<br />
security advisory AST-2010-002, which was released at the same time as this<br />
announcement.</p>
<p>Asterisk 1.2.40 also contains a backported dialplan function called FILTER() in<br />
order to allow the filtering of strings as described in the best practices<br />
document.</p>
<p>It should also be noted that the 1.6.x series of Asterisk had release candidates<br />
available as versions 1.6.0.23-rc2, 1.6.1.15-rc2, and 1.6.2.3-rc2. These will<br />
either be released as 1.6.0.25, 1.6.1.17, and 1.6.2.5, or if another round of<br />
RC changes is necessary, those versions numbers will be used with -rc1 appended.</p>
<p>For a full list of changes in the current releases, please see the ChangeLog:</p>
<p><a href="http://downloads.asterisk.org/pub/telephony/asterisk/" onclick="pageTracker._trackPageview('/outgoing/downloads.asterisk.org/pub/telephony/asterisk/?referer=');">http://downloads.asterisk.org/pub/telephony/asterisk/ChangeLog-1.2.40</a><br />
<a href="http://downloads.asterisk.org/pub/telephony/asterisk/ChangeLog-1.4.29.1" onclick="pageTracker._trackPageview('/outgoing/downloads.asterisk.org/pub/telephony/asterisk/ChangeLog-1.4.29.1?referer=');">http://downloads.asterisk.org/pub/telephony/asterisk/ChangeLog-1.4.29.1</a><br />
<a href="http://downloads.asterisk.org/pub/telephony/asterisk/ChangeLog-1.6.0.24" onclick="pageTracker._trackPageview('/outgoing/downloads.asterisk.org/pub/telephony/asterisk/ChangeLog-1.6.0.24?referer=');">http://downloads.asterisk.org/pub/telephony/asterisk/ChangeLog-1.6.0.24</a><br />
<a href="http://downloads.asterisk.org/pub/telephony/asterisk/ChangeLog-1.6.1.16" onclick="pageTracker._trackPageview('/outgoing/downloads.asterisk.org/pub/telephony/asterisk/ChangeLog-1.6.1.16?referer=');">http://downloads.asterisk.org/pub/telephony/asterisk/ChangeLog-1.6.1.16</a><br />
<a href="http://downloads.asterisk.org/pub/telephony/asterisk/ChangeLog-1.6.2.4" onclick="pageTracker._trackPageview('/outgoing/downloads.asterisk.org/pub/telephony/asterisk/ChangeLog-1.6.2.4?referer=');">http://downloads.asterisk.org/pub/telephony/asterisk/ChangeLog-1.6.2.4</a></p>
<p>Security advisory AST-2010-002 is available at:</p>
<p><a href="http://downloads.asterisk.org/pub/security/AST-2010-002.pdf" onclick="pageTracker._trackPageview('/outgoing/downloads.asterisk.org/pub/security/AST-2010-002.pdf?referer=');">http://downloads.asterisk.org/pub/security/AST-2010-002.pdf</a></p>
<p>The README-SERIOUSLY.bestpractices.txt document is available in the top-level<br />
directory of your Asterisk sources, or available in all Asterisk branches from<br />
1.2 and up.</p>
<p><a href="http://svn.asterisk.org/svn/asterisk/trunk/README-SERIOUSLY.bestpractices.txt" onclick="pageTracker._trackPageview('/outgoing/svn.asterisk.org/svn/asterisk/trunk/README-SERIOUSLY.bestpractices.txt?referer=');">http://svn.asterisk.org/svn/asterisk/trunk/README-SERIOUSLY.bestpractices.txt</a></p>
<p>Thank you for your continued support of Asterisk!</p></blockquote>
]]></content:encoded>
			<wfw:commentRss>http://www.voiptechchat.com/voip/366/asterisk-security-release-announced/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Skype for Asterisk Beta Limited Time Offer</title>
		<link>http://www.voiptechchat.com/voip/303/skype-for-asterisk-beta-limited-time-offer/</link>
		<comments>http://www.voiptechchat.com/voip/303/skype-for-asterisk-beta-limited-time-offer/#comments</comments>
		<pubDate>Thu, 30 Jul 2009 18:58:20 +0000</pubDate>
		<dc:creator>Fred</dc:creator>
				<category><![CDATA[VoIP]]></category>
		<category><![CDATA[asterisk]]></category>
		<category><![CDATA[Digium]]></category>
		<category><![CDATA[SIP]]></category>
		<category><![CDATA[skype]]></category>

		<guid isPermaLink="false">http://www.voiptechchat.com/?p=303</guid>
		<description><![CDATA[Hi, VoIP Tech Chat here introducing a BRAND NEW download from Digium, the company bringing you Asterisk. Are your Skype calls limiting you to sitting in front of your computer? Do you ever forget to plug in your microphone and &#8230; <a href="http://www.voiptechchat.com/voip/303/skype-for-asterisk-beta-limited-time-offer/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p>Hi, VoIP Tech Chat here introducing a <strong>BRAND NEW</strong> download from <a href="http://www.digium.com" onclick="pageTracker._trackPageview('/outgoing/www.digium.com?referer=');">Digium</a>, the company bringing you <a href="http://www.asterisk.org" onclick="pageTracker._trackPageview('/outgoing/www.asterisk.org?referer=');">Asterisk</a>. Are your Skype calls limiting you to sitting in front of your computer? Do you ever forget to plug in your microphone and lose audio? Well, Digium has the perfect product for you!</p>
<p>Skype for Asterisk Beta is a download that lets you <strong>integrate your Asterisk system with the Skype network</strong>.</p>
<p>With Skype for Asterisk, you can:<span id="more-303"></span></p>
<ul>
<li>Make Skype to Skype calls</li>
<li>Call landlines, cellphones, <em>even grandma!</em></li>
<li>Receive SkypeIn calls</li>
<li>Make multiple Skype calls simultaneously using the same Skype account</li>
<li>Read Skype profile fields</li>
<li>Support DTMF</li>
<li>Set and retrieve online status</li>
<li>Handle incoming Skype calls using your dialplan</li>
<li>Use the Asterisk PBX for voice and the Desktop for IM</li>
<li>And much more!</li>
</ul>
<p><strong>And you can do this all from your Asterisk PBX!</strong></p>
<p>Ordinary Skype is a mess. You need your desktop and some sort of sound equipment just to make a call. <em>Crazy</em>. Skype for Asterisk Beta has the <strong>muscle</strong> to use your phone system <strong>directly with the Skype network</strong>. Use Skype for Asterisk Beta to provide an IVR or Sales portal for your company. You can use Skype for Asterisk Beta at home while watching TV. You can even use Skype for Asterisk Beta to send your Skype calls to one central voicemail.</p>
<p>Whether your Skype needs are large or small, Skype for Asterisk Beta can handle it all. Skype for Asterisk Beta is free, so it pays for itself.</p>
<p>Through Digium’s exclusive Beta offer you can download Skype for Asterisk Beta at the very low price of Free.</p>
<h3>But wait, there’s more!</h3>
<p>Skype for Asterisk Beta is a <strong>limited time offer</strong>. You have to <strong>act now</strong> to download and register the software. Skype for Asterisk Beta can only be downloaded until August 7th and used until August 31st. And of course, being beta, there’s some betaness to contend with.</p>
<p>So <strong>act now</strong> and <strong><a href="http://store.digium.com/productview.php?product_code=804-00019" onclick="pageTracker._trackPageview('/outgoing/store.digium.com/productview.php?product_code=804-00019&amp;referer=');">download the Skype for Asterisk Beta software today</a></strong> directly from Digium.</p>
<p>(In case you hadn’t guessed, this is also our homage to Billy Mays.)</p>
<p>Here&#8217;s what Digium&#8217;s John Todd posted:</p>
<blockquote><p>I know many of you have been waiting for this for a while, so I&#8217;ll  keep this short:  The Skype for Asterisk Public Beta is now available on the Digium store.</p>
<p>We are pleased to announce the open beta of Skype For Asterisk is ready to begin and we look forward to you participation. To obtain your copy of the software, please visit Digium’s web store and purchase (for zero dollars) the Skype For Asterisk product. The web store does require a Digium.com account, which can be set up during the purchase process if you don’t already have one. Once the web store process is complete, you will be e-mailed your license key and directions on where to download Skype For Asterisk beta software.</p>
<p>This is a &#8220;time-expiring&#8221; beta &#8211; the software will stop working on August 31.  The download is also currently time-limited &#8211; it will be available until August 7 on our website.  After the 31st, you would need to have purchased a license for the SfA software (sorry, no pricing that I can give you right now &#8211; that will be a separate announcement.  I&#8217;m just the community guy &#8211; I have no idea about pricing or commercial contracts or the like, so please wait until that&#8217;s been announced as I will find out about the same time as you do. <img src='http://www.voiptechchat.com/wp-includes/images/smilies/icon_smile.gif' alt=':-)' class='wp-smiley' /> </p>
<p>Trial &#8220;purchase&#8221; page:<br />
<a href="http://store.digium.com/productview.php?product_code=804-00019" onclick="pageTracker._trackPageview('/outgoing/store.digium.com/productview.php?product_code=804-00019&amp;referer=');">http://store.digium.com/productview.php?product_code=804-00019</a></p>
<p>JT</p></blockquote>
<p>While you&#8217;re downloading Skype for Asterisk, read <a href="http://www.mgraves.org/voip/2009/07/skype-for-asterisk-open-beta-now-available" onclick="pageTracker._trackPageview('/outgoing/www.mgraves.org/voip/2009/07/skype-for-asterisk-open-beta-now-available?referer=');">Michael Grave&#8217;s post</a> over at Graves On SOHO VoIP.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.voiptechchat.com/voip/303/skype-for-asterisk-beta-limited-time-offer/feed/</wfw:commentRss>
		<slash:comments>5</slash:comments>
		</item>
	</channel>
</rss>

<!-- Dynamic Page Served (once) in 0.911 seconds -->

