exploit the possibilities
Home Files News &[SERVICES_TAB]About Contact Add New

asterisk-1.2.13.txt

asterisk-1.2.13.txt
Posted Oct 30, 2006
Authored by Jesus Oquendo | Site infiltrated.net

Asterisk Open Source PBX versions prior to 1.2.13 are vulnerable to local and remote denial of service attacks via a sequence of malformed packets.

tags | advisory, remote, denial of service, local
SHA-256 | 2b0be2f77b87a8b5e9ce286060248fb1dbf05ea28f09a44a6813660999d9e6f6

asterisk-1.2.13.txt

Change Mirror Download
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1


Product: Asterisk Open Source PBX
Impact: Multiple Local and Remote Denials of Service
Version(s): All versions prior to 1.2.13
Author: Jesus Oquendo
echo @infiltrated|sed 's/^/sil/g;s/$/.net/g'


I. BACKGROUND
Asterisk is an Open Source PBX which runs on Linux, BSD, Solaris and MacOSX that provides all of
the features in a standard PBX. Asterisk does voice over IP and can interoperate with almost all
telephony equipment.

II. DESCRIPTION
A sequence of malformed (pre-defined) packets can cause different denial of services on Asterisk.
The attack is both local and remote. These denial of services can range from the Asterisk server
shutting down, channels being opened and filling up queues. Log file denials of service by filling
space with errors and ranDumb messages. Voicemail space allocation being filled, and ICMP denials
of service.

III SOLUTION
Versions 1.2.13 and greater are no longer vulnerable to the attack and users are urged to update
to 1.2.13 or better.

IV. SOURCE
http://www.infiltrated.net/asteroid/asteroidv1.tar.gz

V. POSSIBILITIES
While the initial packet creation tool was tested on Asterisk, it was not targeted towards Asterisk
but at the SIP protocol. Asterisk was used merely for Wireshark packet captures in order to re-create
newer packets. The Asteroid SIP denial of service tool could also affect other products that run the
SIP protocol including soft phones, other PBX's, etc.

VI. MENTIONS
Thanks to Kevin P. Flemming and the guys at Asterisk fixing this promptly. Dan York for getting people
to pay attention. Tim Donahue for his Perl pointers, vgersh99 (aka vlad) for nawk pointers, PHV,
Annihilannic, p5wizard, Anthony LaMantia, Tzafir Cohen, and the others on the Asterisk-Dev list.

VII. TESTBED
Tested on Solaris, FreeBSD, Linux (SuSE, CentOS, Gentoo, Debian) distributions running various versions
Asterisk.

VIII. CHECKSUMS

$ md5 asteroidv1.tar.gz
MD5 (asteroidv1.tar.gz) = b32c56ab4004d2a75eeee109d9e8d824

$ sha1 asteroidv1.tar.gz
SHA1 (asteroidv1.tar.gz) = 0345fc7e423bddb8d9aa5fae431c0715db70a879



=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+
J. Oquendo
echo @infiltrated|sed 's/^/sil/g;s/$/.net/g'
http://pgp.mit.edu:11371/pks/lookup?op=get&search=0x1383A743

"How a man plays the game shows something of his
character - how he loses shows all" - Mr. Luckey

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.3 (FreeBSD)

iD8DBQFFRnM0h3J3NhODp0MRAu0NAJsFLdCKJgRqtjLs35GtXxRKNYNaLgCg8xxI
zZUQr4YWe0BE8RHpvEYTyEI=
=TLzd
-----END PGP SIGNATURE-----

Login or Register to add favorites

File Archive:

August 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Aug 1st
    15 Files
  • 2
    Aug 2nd
    22 Files
  • 3
    Aug 3rd
    0 Files
  • 4
    Aug 4th
    0 Files
  • 5
    Aug 5th
    15 Files
  • 6
    Aug 6th
    11 Files
  • 7
    Aug 7th
    43 Files
  • 8
    Aug 8th
    42 Files
  • 9
    Aug 9th
    36 Files
  • 10
    Aug 10th
    0 Files
  • 11
    Aug 11th
    0 Files
  • 12
    Aug 12th
    0 Files
  • 13
    Aug 13th
    0 Files
  • 14
    Aug 14th
    0 Files
  • 15
    Aug 15th
    0 Files
  • 16
    Aug 16th
    0 Files
  • 17
    Aug 17th
    0 Files
  • 18
    Aug 18th
    0 Files
  • 19
    Aug 19th
    0 Files
  • 20
    Aug 20th
    0 Files
  • 21
    Aug 21st
    0 Files
  • 22
    Aug 22nd
    0 Files
  • 23
    Aug 23rd
    0 Files
  • 24
    Aug 24th
    0 Files
  • 25
    Aug 25th
    0 Files
  • 26
    Aug 26th
    0 Files
  • 27
    Aug 27th
    0 Files
  • 28
    Aug 28th
    0 Files
  • 29
    Aug 29th
    0 Files
  • 30
    Aug 30th
    0 Files
  • 31
    Aug 31st
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2022 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close