Seven Steps to Better SIP Security with Asterisk

In case any of you were wondering why there has been a fairly notable upswing in the attacks happening on SIP endpoints, the answer is “script kiddies.” In the last few months, a number of new tools have made it easy for knuckle-draggers to attack and defraud SIP endpoints, Asterisk-based systems included. There are easily-available tools that scan networks looking for SIP hosts, and then scan hosts looking for valid extensions, and then scan valid extensions looking for passwords.


You can take steps, NOW, to eliminate many of these problems. I think the community is interested in coming up with an integrated Asterisk-based solution that is much wider in scope for dynamic protection (community-shared blacklists is the current thinking) but that doesn’t mean you should wait for some new tool to defend your systems. You can IMMEDIATELY take fairly common-sense measures to protect your Asterisk server from the bulk of the scans and attacks that are on the increase. The methods and tools for protection already exists – just apply them, and you’ll be able to sleep more soundly at night.

Seven Easy Steps to Better SIP Security on Asterisk:

1) Don’t accept SIP authentication requests from all IP addresses. Use the “permit=” and “deny=” lines in sip.conf to only allow a reasonable subset of IP addresess to reach each listed extension/user in your sip.conf file. Even if you accept inbound calls from “anywhere” (via [default]) don’t let those users reach authenticated elements! Contiued …

Related Posts

How to install Takeoff Launcher on Fedora 16 KDE Takeoff Launcher is one of my favorite menu styles and I consider it one of 2 cool reasons to use the K Desktop Environment. Though it is not in Fedor...
How to install AppMenu-QML on Fedora 16 KDE There are several menu styles available for users of the K Desktop Environment. Virtually all, should be familiar with the Classic menu, the Kickoff m...
Install Jitsi 1.0 in Debian, Linux Mint and Ubuntu Jitsi is a multi-protocol, multi-platform voice and video instant messenger client. It is mostly implemented in Java, and is Free/Open Source software...
How to customize Linux Mint 12 KDE Linux Mint 12 KDE is the latest release of Linux Mint KDE, a distribution based on Ubuntu Desktop. It has already being reviewed on this website (see ...
How to make DuckDuckGo the default search engine in Chromium The folks behind DuckDuckGo have been deftly positioning the search engine as one you should be using, if you are tired or want to avoid snooping by G...
Linux Mint 12 LXDE review Linux Mint LXDE is the edition of Linux Mint, a distribution based on Ubuntu Desktop, that uses the Lightweight X11 Desktop Environment (LXDE), which,...

We Recommend These Vendors

Launch an SSD VPS in Europe, USA, Asia & Australia on Vultr's KVM-based Cloud platform starting at $5:00/month (15 GB SSD, 768 MB of RAM).

Deploy an SSD Cloud server in 55 seconds on DigitalOcean. Built for developers and starting at $5:00/month (20 GB SSD, 512 MB of RAM).


Leave a Comment

Your email address will not be published. Required fields are marked *

*