Gateways usage security
Forum » WikiPBX / General » Gateways usage security
Started by: leddaledda
On: 1276695443|%e %b %Y, %H:%M %Z|agohover
Number of posts: 3
rss icon RSS: New posts
Summary:
using gateways of other accounts
Gateways usage security
leddaledda 1276695443|%e %b %Y, %H:%M %Z|agohover

While adding extension, in picklist you can choose "gateway dialout"

It configures extensions with the line like this:
<action application="bridge" data="sofia/gateway/myprovider.com/$1"/>

After that it's possible to edit this line and specify another gateway (e.g. gateway of another account)

Is there any control that every account can use only his own gateways and not gateways of other accounts?

Reply  |  Options
Unfold Gateways usage security by leddaledda, 1276695443|%e %b %Y, %H:%M %Z|agohover
Re: Gateways usage security
stas_shtinstas_shtin 1276710948|%e %b %Y, %H:%M %Z|agohover

Just checking it would probably be easier than asking… Anyway, there is a security check that happens when freeswitch requests dialplan that looks for this particular issue. User shouldn't be able to use gateways belonging to others.

However, there must be other less obvious ways for malicious user to exploit freeswitch server as he has direct access to generated dialplan. We plan to have a WYSIWYG interface for editing dialplan extensions in the future that would let user to use only safe commands.

Reply  |  Options
Unfold Re: Gateways usage security by stas_shtinstas_shtin, 1276710948|%e %b %Y, %H:%M %Z|agohover
Re: Gateways usage security
leddaledda 1276781243|%e %b %Y, %H:%M %Z|agohover

Thanks for pointing on this check. I've found it.

Reply  |  Options
Unfold Re: Gateways usage security by leddaledda, 1276781243|%e %b %Y, %H:%M %Z|agohover
New Post
page_revision: 0, last_edited: 1226259295|%e %b %Y, %H:%M %Z (%O ago)
Unless otherwise stated, the content of this page is licensed under Creative Commons Attribution-ShareAlike 3.0 License