Uploaded image for project: 'FreePBX'
  1. FreePBX
  2. FREEPBX-5100

Security: type=friend allows extensions to be enumerated

    XMLWordPrintable

    Details

    • ToDo:

      Description

      As reported in this thread http://www.freepbx.org/forum/freepbx/general-help/security-enumerating-extensions using type=friend for extensions results in extension enumeration vulnerability. There is really no point in using type=friend for extensions. Extensions should use type=peer by default. The circumstances where type=friend would be needed are unclear, given the fact the extensions are supposed to register. More info in this post from 2005: http://www.voip-info.org/wiki/view/Asterisk+SIP+user+vs+peer

        Gliffy Diagrams

          Attachments

            Issue Links

              Activity

                People

                • Assignee:
                  Unassigned
                  Reporter:
                  obelisk obelisk (Inactive)
                • Votes:
                  0 Vote for this issue
                  Watchers:
                  1 Start watching this issue

                  Dates

                  • Created:
                    Updated:
                    Resolved:

                    NextupJiraPlusStatus

                    Error rendering 'slack.nextup.jira:nextup-jira-plus-status'. Please contact your Jira administrators.