Re: security bug in cvs2.07

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



Hello ZM,

It certainly is a case of restarting the gateway after putting in additional
alias/dialeddigits. On re-registration, it appears that the reg table
already has the first alias and hence assumes that the new RRQ is just a
normal re-poll. This possibly generates a CDR without the necessary
attributes and hence does not qualify as a full CDR if it is ever generated.

As it is a live system, it will take a while before I can simulate it and
when I do, I will send you the logs - possibly in a couple of days.

Regards,
Ap.Muthu
apmuthu@usa.net

>----- Original Message ----- 
>From: "Zygmuntowicz Michal" <m.zygmuntowicz@onet.pl>
>To: <openh323gk-users@lists.sourceforge.net>
>Subject: Re:  security bug in cvs2.07
>Date: Wed, 7 Jan 2004 19:11:52 +0100
>Reply-To: openh323gk-users@lists.sourceforge.net

>Do you mean incremental registration with additional aliases?
>Why the CDR is not generated? Or it is generated, but contains
>some wrong data.

>Maybe you could provide me with the log file?

>----- Original Original Message ----- 
>From: "Ap.Muthu" <apmuthu@usa.net>
>Sent: Wednesday, January 07, 2004 5:19 PM


>> Just discovered that when a gateway registers with the GNUgk 2.07cvs with
>> an alias(or dialeddigits) and then gets an additional alias(or
dialeddigits)
>> and re-registers, the original registration endpoint id is issued and the
>> endpoint table seems to have allow calls to the new alias but the cdrs do
>> not appear for calls made or attempted to the new alias (or
dialeddigits).
>>
>> This way a participating gateway can fool the GK into allowing calls to
the
>> additional alias without getting it CDRed.






-------------------------------------------------------
This SF.net email is sponsored by: Perforce Software.
Perforce is the Fast Software Configuration Management System offering
advanced branching capabilities and atomic changes on 50+ platforms.
Free Eval! http://www.perforce.com/perforce/loadprog.html
_______________________________________________
List: Openh323gk-users@lists.sourceforge.net
Archive: http://sourceforge.net/mailarchive/forum.php?forum_id=8549
Homepage: http://www.gnugk.org/

[Index of Archives]     [SIP]     [Open H.323]     [Gnu Gatekeeper]     [Asterisk PBX]     [ISDN Cause Codes]     [Yosemite News]

  Powered by Linux