asterisk resource exhaustion

September 24

Asterisk Remote Denial of Service - IAX Control New

Posted by jj
Filed under Asterisk, Digium, vulnerability | No Comments

Here we go again…  There is now exploit code circulating for yet another remote Denial of Service attack against Asterisk.
The asterisk resource exhaustion attack is against the IAX2 VoIP signaling protocol using the IAX Control New packet.  The exploit affects all versions of Asterisk.
Digium was notified of this discovery on August 17th, 2008 and again […]

July 23

IAX Poke Resource Exhaustion

Posted by jj
Filed under Asterisk, iax2, vulnerability | 2 Comments

While preparing for The Last HOPE, Blake Cornell discovered the fact that given a flood of IAX ‘POKE’ requests one could affect the operation of Asterisk.
The moment Blake informed me and I was able to replicate the sitaution, I promptly informed Digium via a quick IRC-based private discussion with multiple Digium employees. However my non-standard […]