Skip Links

Network World

  • Social Web 
  • Email 
  • Close

Asterisk VoIP platform open to DDoS attacks, security firm says

By Phil Hochmuth , NetworkWorld.com , 07/17/2006
  • Share/Email
  • Comment
  • Print

A flaw in the Asterisk IP PBX platform reported last week could result in a denial-of-service attack that would disrupt a business' VoIP or VoIP-to-PSTN gateway service.

Asterisk is an open-source IP telephony and messaging platform that runs on Linux, BSD and Mac OSX servers, and can be used as a complete office phone system, or to add IP-enabled services - such as messaging or gateways - to a mixed TDM/IP phone network. A vulnerability in the Inter-Asterisk eXchange protocol version 2 (IAX2) - used by Asterisk servers to set up and manage calls - could be used to flood an Asterisk IP PBX with bogus calls and make the phone system unavailable, according to the Internet Security Systems (ISS) X-Force Threat Analysis Service, which discovered the bug.

Using a method which ISS calls "somewhat analogous to a SYN flood," an attacker, with knowledge of a valid user name on an Asterisk system, could generate enough unauthenticated call requests to overwhelm the Asterisk IP PBX, ISS says. A remote attacker could do this from a single PC or server, the security company says. Networks that use Asterisk boxes as gateways between a TDM and VoIP network could also be attacked via this method.

ISS says there is a setting in the Asterisk software which can limit the number of simultaneous unauthenticated call requests the Asterisk server will try to handle and resolve. Changing this setting to the lowest number of unauthenticated calls will fix the vulnerability, ISS says.

A fixed version of the software is also available from asterisk.org, which maintains the open-source platform, as well as from Digium, a company which sells service and support for Asterisk-based phone systems.

  • Share/Email
  • Comment
  • Print
Partner Content

Brilliantly simple security and control solutions for email, web and endpoint

www.sophos.com

Stopping data leakage

Learn how to exploit your current security investment to control the information that flows into, through and out of your network.

Download the white paper.

Why detection rates aren't enough

Evaluating endpoint security products is a time-consuming and daunting task. Learn the six critical questions you need to ask prospective vendors to get the right endpoint solution.

Download the white paper.

Applications: taking back control

Employees installing unauthorized applications is a growing threat to business security and productivity. Cost-effectively reduce this threat by integrating control into your malware protection.

Learn more today.

Comment
Login
Forgot your account info?
Add comment
Anonymous comments subject to approval. Register here for member benefits.
Have a NetworkWorld account? Log in here. Register now for a free account.

Videos

rssRss Feed
Get instant email notification when white papers, webcasts, executive guides are added to our library. Stay informed and up-to-date with the latest on IT Technologies with Network World's Resource Alerts.
Network World,to go. Wherever you are. Breaking news delivered to your mobile device. Select the hottest topics in networking and start receiving Network World on your mobile device today.