7 Steps to Better SIP Security on Asterisk by JT

John Todd is an Asterisk evangelist and works for Digium. VoIP Users Conference reposted John's 7 steps to better SIP Security on Asterik (here). The reason for the 7 steps now?
"In the last few months, a number of new tools have made it easy for knuckle-draggers to attack and defraud SIP endpoints, Asterisk-based systems included. There are easily-available tools that scan networks looking for SIP hosts, and then scan hosts looking for valid extensions, and then scan valid extensions looking for passwords. You can take steps, NOW, to eliminate many of these problems."
It's not just Asterisk either. There are holes in every PBX and softswitch. There is long distance fraud, especially in International calling. You should be checking your CDR's at least daily - or run a script to pick up anomalies.

Security in entirety will become extremely important this year. New tools; a tanking world economy; criminals will be looking for every lever to make money or get something free.  So will disgruntled employees, so network admins need to be on top of any changes in human resources.
The opinions and views expressed in comments, blogs, etc. are those of the authors alone and not necessarily those of TMC, TMCnet, or its editors. TMCnet reserves the right to edit, delete, or otherwise make changes to the content that appears on these pages at its own discretion and as it deems necessary.
| 0 Comments | 0 TrackBacks

Listed below are links to sites that reference 7 Steps to Better SIP Security on Asterisk by JT:

7 Steps to Better SIP Security on Asterisk by JT TrackBack URL : http://blog.tmcnet.com/mt/mt-tb.cgi/39664

Leave a comment

Subscribe to Blog

Blogroll

Recent Entry Images

  • tmc-woo-leg.jpg

Around TMCnet Blogs

Latest Whitepapers

TMCnet Videos