Re: [SR-Users] Security hygiene for Kamailio

2014-02-03 Thread davy
Hi! I was just testing the digest replay possibilities against Kamailio. (findings: http://www.kamailio.org/wiki/tutorials/security/kamailio-security#digest_authentication) It looks that by default (the typical default configs), a SIP replay attack can be done during 300 seconds (?) . Now I t

Re: [SR-Users] Security hygiene for Kamailio

2014-01-29 Thread davy van de moere
I started the pages, to be found : http://www.kamailio.org/wiki/tutorials/security/security-threats http://www.kamailio.org/wiki/tutorials/security/kamailio-security They are a long from being complete, but it's a start, feel free to modify/correct/add content! 2013-12-18 davy > ACK > > :) >

Re: [SR-Users] Security hygiene for Kamailio

2013-12-18 Thread davy
ACK :) Op 18-dec.-2013, om 15:30 heeft Daniel-Constantin Mierla het volgende geschreven: > Hello, > > On 18/12/13 10:53, davy wrote: >> Cool, I'll spend some time this weekend to have a first stake in the ground >> on the wiki ! > > great! Just use namespaces when creating new pages, to hav

Re: [SR-Users] Security hygiene for Kamailio

2013-12-18 Thread Daniel-Constantin Mierla
Hello, On 18/12/13 10:53, davy wrote: Cool, I'll spend some time this weekend to have a first stake in the ground on the wiki ! great! Just use namespaces when creating new pages, to have a good structure of the wiki. It can be something under tutorials, such as: tutorials:security:TITLE

Re: [SR-Users] Security hygiene for Kamailio

2013-12-18 Thread Alex Balashov
On 12/18/2013 06:11 AM, davy wrote: But I think two aspects might be very handy. A first would be to list all the attacks on VoIP networks known to man, and how Kamailio can help defending on this, with e.g. config snippets, … A second which I personally find very interesting, is how we can hav

Re: [SR-Users] Security hygiene for Kamailio

2013-12-18 Thread davy
Alex, Thx for your prompt feedback! We could conclude that stating something like "This config is the best way to secure your Kamailio", is a contradictio in terminis ;) But I think two aspects might be very handy. A first would be to list all the attacks on VoIP networks known to man, and ho

Re: [SR-Users] Security hygiene for Kamailio

2013-12-18 Thread Alex Balashov
Davy, I would also weigh on the side of saying that Kamailio security, even in a best-practical, common denominator kind of way, is inextricably bound up in the specificity of how Kamailio is being used, the role it's playing as a network element, the topology in which it is participating, et

Re: [SR-Users] Security hygiene for Kamailio

2013-12-18 Thread davy
Awesome :) Op 18-dec.-2013, om 11:02 heeft "Olle E. Johansson" het volgende geschreven: > > On 18 Dec 2013, at 10:53, davy wrote: > >> Cool, I'll spend some time this weekend to have a first stake in the ground >> on the wiki ! >> >> It's better to have our security measures being checked

Re: [SR-Users] Security hygiene for Kamailio

2013-12-18 Thread Olle E. Johansson
On 18 Dec 2013, at 10:53, davy wrote: > Cool, I'll spend some time this weekend to have a first stake in the ground > on the wiki ! > > It's better to have our security measures being checked by peers than by > hackers ;) Thank you, Davy! When you've got a template, ping me. I can send out i

Re: [SR-Users] Security hygiene for Kamailio

2013-12-18 Thread davy
Cool, I'll spend some time this weekend to have a first stake in the ground on the wiki ! It's better to have our security measures being checked by peers than by hackers ;) Op 18-dec.-2013, om 09:33 heeft Daniel-Constantin Mierla het volgende geschreven: > Hello, > > On 17/12/13 17:27, d

Re: [SR-Users] Security hygiene for Kamailio

2013-12-18 Thread Daniel-Constantin Mierla
Hello, On 17/12/13 17:27, davy wrote: Hi all, we all enjoy our FAIL2BAN and snippets of our Kamailio config when we see it successfully fight off the "friendly-scanner", and multiple futile attempts to fool our systems. But it got me thinking… What is a sufficient level of security on our Ka

[SR-Users] Security hygiene for Kamailio

2013-12-17 Thread davy
Hi all, we all enjoy our FAIL2BAN and snippets of our Kamailio config when we see it successfully fight off the "friendly-scanner", and multiple futile attempts to fool our systems. But it got me thinking… What is a sufficient level of security on our Kamailio machinery… ? Are we all just doin