Summary: | ASTERISK-16564: allowguest should be off by default in sip.conf | ||
Reporter: | Ruchir Brahmbhatt (ruchirb) | Labels: | |
Date Opened: | 2010-08-13 09:09:59 | Date Closed: | 2010-08-13 11:03:51 |
Priority: | Major | Regression? | No |
Status: | Closed/Complete | Components: | Addons/General |
Versions: | Frequency of Occurrence | ||
Related Issues: | |||
Environment: | Attachments: | ||
Description: | By default allowguest is set to yes in sip.conf. This should be turned off by default to prevent security issues on new deployments. Hackers are getting smarter and exploiting various flows. We recently had attack which exploited device forwarding flow and made lots of calls. | ||
Comments: | By: Jason Parker (jparker) 2010-08-13 11:03:51 Please follow this in the duplicated issue (ASTERISK-14122). |