Digium Responds to FBI Vhishing Security Warning about Asterisk

fbi-ic3.jpgA few days ago the FBI's Internet Crimes Complaint Center (IC3) issued an unclear warning that says versions of Asterisk software are vulnerable to vhishing (voice phishing) attacks, but didn't say which versions, but causing a flurry of news activity on VoIP news sites, tech sites, and blogs.

It all started with this warning from the IC3:
New Technique Utilizing Private Branch Exchange (PBX) Systems To Conduct Vishing Attacks

The FBI has received information concerning a new technique used to conduct vishing attacks. The recent attacks were conducted by hackers exploiting a security vulnerability in Asterisk software.
My esteemed colleagues Rich Tehrani and Greg Galitzine did some research to find out what the story was, including contacting Digium's John Todd.

Here's Rich's take:

Before commenting I waited to hear back from Digium's John Todd who explained that there were some methodology and editorial process issues in this alert - basically no one checked with Digium before going public. As it turns out, after checking with Digium, the FBI quickly revised their statement and everything is fine.

The details are that there was a bug which Digium found in March of 2008 and subsequently patched in version 1.2 and 1.4. Version 1.6 is not affected. Besides, according to Todd, the security issue would arise if system administrators basically disregarded logical security measures like using numerals in passwords.

Read more...

Greg Galitzine also writes about the FBI's warning about Asterisk in an article titled Digium Defends Asterisk Against Fed Warning: "Tempest in a Teapot"

In it, Greg writes:

Todd writes in a blog entry titled SIP Security and Asterisk:

That bug allowed in some cases unauthorized callers to make calls through an unprotected "context" in Asterisk. Due to the nature of the bug there was fairly limited exposure - it would have required a fairly unusual set of configurations to permit fraud, and there was both a simple config file change that would provide protection, as well as an actual patch to the code which we have every reason to believe has been widely implemented by the very proactive Open-Source community using Asterisk in production environments. The bug didn't allow arbitrary setting of caller ID, and would only work in a limited set of circumstances that personally I think would be unusual, though possible.

Early on, Todd had a sense that this might just be a misunderstanding: Sorry for the fuss, and I suspect this is just a tempest in a teapot. Use good passwords, keep your packet filters up, and I'll update things here as we hear more.

Digium's John Todd wrote an excellent blog post describing what happened after he was able to contact the FBI in charge of the security warning. While there was indeed a security vulnerability in Asterisk, it was patched in 1.2 and 1.4 and doesn't exist in 1.6. Thus, someone would have to be using a very old version of Asterisk. And as for the security vulnerability itself which seemed to enable vhishing attacks, John indicates that it was a relatively obscure exploit and "an administrator would have to consciously configure their system in what I believe to be an extremely unusual way in order to be victimized by this particular vulnerability." So indeed in John's own words, it seems to be a tempest in a teapot after all.

John Todd wrote:
As we had surmised, the warning from the IC3/FBI on Friday was just a re-hash of a bug that was fixed back in March of this year.  I was in touch with the agent in charge of this release this morning (after contact attempts on Friday failed) and he understood quickly that the wording was lacking in ways that created questions in the minds of readers, and this was being amplified by bloggers who more clearly outlined the set of questions raised by the advisory/release.  To his credit, the IC3 agent quickly pushed through a set of changes today to the posting which more specifically describes the issue, which indeed is the AST-2008-003 SIP guest permissions problem.

 

John Todd also wrote:
This bug was discovered and patched for 1.2 and 1.4 versions of the software, and 1.6 releases were not vulnerable.  Simple changes to site-specific configurations typically would be all that would be required even on systems that did not get patched or upgraded.  The bug that is described is relatively obscure, and was found by Jason Parker here at Digium.  We didn't know of any "in the wild" exploits back then, though of course there may be some now.  I'm still somewhat surprised that anyone has been able to use this bug to the extent that they were able to mount "vishing" attacks.  While I won't get into the details of configuration specifics, I would say that an administrator would have to consciously configure their system in what I believe to be an extremely unusual way in order to be victimized by this particular vulnerability.
John Todd complains about the "vagueness" of the warning but in an update after speaking to the IC3 agemt, John Todd says "To his credit, the IC3 agent quickly pushed through a set of changes today to the posting which more specifically describes the issue, which indeed is the AST-2008-003 SIP guest permissions problem." (an old issue)

So my Asterisk-loving friends. If you are indeed running patched 1.2/1.4 Asterisk or v1.6 you have nothing to worry about. And if you aren't running these versions, what the heck is wrong with you? And you call yourself an Asterisk fan. Per shame!

P.S. As Rich said, "I am sure by the time Asterisk World rolls around in a few months in Miami, we will all be laughing about this incident and marveling at the opportunity that is open source communications."
| 1 Comment | 0 TrackBacks

Listed below are links to sites that reference Digium Responds to FBI Vhishing Security Warning about Asterisk:

Digium Responds to FBI Vhishing Security Warning about Asterisk TrackBack URL : http://blog.tmcnet.com/mt/mt-tb.cgi/38412

1 Comment

This makes me feel good about the fact that I am running the newer versions of the software. I was really terrified following the press release from the FBI, but your blog really talked me down from the ledge. Thanks for your level-headed approach!

Leave a comment

Recent Activity

Today

  • Tom Keating queued The Blind Side

Sunday

Sunday

  • Tom Keating tweeted, "Moving a Data Center: Moving a data center can be fun. Yes, if you enjoy being up from 6am (Friday) to 2am (Satur... http://bit.ly/cX6L0j"
  • Tom Keating posted Moving a Data Center

Friday

  • Tom Keating tweeted, "Tearing down TMC's entire network infrastructure. My sweet beautiful network! [sniff] [sniff]"

Thursday

  • Tom Keating tweeted, "why the heck am I still awake when I have an all-nighter tomorrow moving the entire #TMCNet data center? (www.tmcnet.com) fun fun!"
  • Tom Keating tweeted, "No, Gremlins Didn't Eat TMCNet's Web Servers: Starting tomorrow around 7am, TMC will be shutting down its entire d... http://bit.ly/bS3OOn"

More...

Recent Comments

  • Peter Radizeski: I'm not certain that is accurate. The staff for VON read more
  • טכנאי מחשבים: Fast, organized, thorough, non-intrusive, and free! THANKS AVG. read more
  • SomeGuy: I've had sipgate setup for less than 24 hours on read more
  • Uverse instaler: Being a uverse installer in the StL area, I can read more
  • Roger: Dan did you find out what the music is?? I read more
  • VoIP Spear: I don't think this site is active anymore. You can read more
  • Mamrez: Hi guys , I'm looking for cracked MOBILELOG for iphone read more
  • Symplicity: Works amazing thanks :) read more
  • wirefly customer: I got my phone from wirefly and it turned out read more
  • Maher: Dear Sir, I am looking for a slim credit card read more

Subscribe to Blog

Recent Entry Images

  • river-park-800-connecticut-avenue.jpg
  • river-park-800-connecticut-avenue.jpg
  • apple-ipad.jpg
  • google-nexus-one.jpg
  • freetalk-connect.jpg
  • freetalk-connect.jpg
  • calliflower-skype.jpg

Entry Archives

Around TMCnet Blogs

  • Communications and Technology Blog - Tehrani.com:
    Apple Antitrust Issues
  • On Rad's Radar?:
    Endstream Plans
  • VoIP & Gadgets Blog:
    Moving a Data Center
  • Communications and Technology Blog - Tehrani.com:
    IfByPhone Interview ITEXPO East 2010 Miami
  • First Coffee:
    Frost & Sullivan Webcast, LCEC and ENERGYprism, IDC for
  • On Rad's Radar?:
    Freeside's new CEO
  • The Readerboard:
    Tune In, Call in (And Donate), 'Hope for Haiti
  • VoIP & Gadgets Blog:
    No, Gremlins Didn't Eat TMCNet's Web Servers
  • Latest Whitepapers

    TMCnet Videos