From my colleague Tim Greene on a story Layer 8 ran over the weekend: The FBI is toning down its warning about security flaws in Asterisk IP PBX software and is acknowledging that the company that markets the software already found the problem and fixed it back in March. What is new, according to an FBI spokesman, is that it found an exploit of the vulnerability in a real-world case of vishing — using VoIP to spoof caller ID numbers so victims will believe they are talking to legitimate businesses and give up valuable personal information.
The initial warning issued by the FBI’s Internet Crimes Complaint Center (IC3) Friday indicated that the exploit was not only new but that it represented a new vishing technique. “It’s an old vulnerability, but we’re seeing criminals exploit it,” the spokesman said in a voice mail message. He could not be reached to say the number of cases the FBI found in the wild. The bug the FBI was talking about was identified by a researcher for Digium, the business that sells a commercial version of and support for Asterisk, who was performing routine code and security audit.
The problem affects Asterisk Version 1.2 and 1.4, says John Todd, the director of Asterisk’s open source community. The most current version is 1.6.0.3.
The two vulnerable versions cannot be exploited if users follow fairly standard best practices for deploying PBXs, Todd says. For the exploit to work, the IP PBX software has to be configured to allow users classified as guests to dial to the public phone network, he says. “They really have to have botched their configuration to make this bug exploitable,” he says.
It would be possible for an Asterisk IP PBX that was hijacked by this exploit to call victims with messages that attempt to extract valuable information from them such as credit card and bank account numbers, Todd says. The caller ID associated with the calls could be spoofed so they add credence to the vishing message, but many carriers block caller IDs other than those officially assigned to their business customers when they set up their direct inward dialing accounts, he says.
Todd says it was odd that IC3 didn’t contact Digium before issuing its warning, which has been the practice with other FBI divisions. In general, industry practice is to notify a business when security flaws are found in its products so it can correct them before they are announced. This limits the extent of any potential exploits.
Digium got more response to its own announcement about the bug back in March than it has since the IC3 intelligence note was issued, he says. He also says he hopes better communication with the FBI can avoid similar warnings in the future.
Layer 8 in a box
More hot stories:
DARPA: developing the wild, the wacky and wicked cool for 50 years
FBI: Wacky nicknames nab bank robbers; Pony Tail bandit on the run
Data centers explore novel ways to cut energy use
Microsoft Research inventions are wacky and useful
High-Tech Comedy Police Force coming to a theatre near you




