Re: [asterisk-users] The S word: Asterisk security

2008-07-09 Thread Tzafrir Cohen
On Tue, Jul 08, 2008 at 09:34:44PM -0700, Trevor Peirce wrote: Steve Totaro wrote: For security, how about an authentication retry setting in the sip configuration? After X amounts of failed auth or registration attempts, block IP for Y amount of time. It would seem fairly easy to do

Re: [asterisk-users] The S word: Asterisk security

2008-07-09 Thread Trevor Peirce
Tzafrir Cohen wrote: On Tue, Jul 08, 2008 at 09:34:44PM -0700, Trevor Peirce wrote: I was recently introduced to fail2ban. It's a nice tool that will watch log files and when it notices too many failed authentication attempts (SSH, FTP, Password protected web sites, asterisk) it will run

Re: [asterisk-users] The S word: Asterisk security

2008-07-08 Thread Trevor Peirce
Steve Totaro wrote: For security, how about an authentication retry setting in the sip configuration? After X amounts of failed auth or registration attempts, block IP for Y amount of time. It would seem fairly easy to do using realtime with DB entries for IP blocks and expiration. Then a

Re: [asterisk-users] The S word: Asterisk security

2008-07-05 Thread randulo
On Fri, Jul 4, 2008 at 10:06 PM, Michael Graves [EMAIL PROTECTED] wrote: All the VUC calls are recorded and available via http://voipusersconference.org/ning/. The post-call session is often not recorded, but the main body of the call is available for download. I recorded yesterday's post

Re: [asterisk-users] The S word: Asterisk security

2008-07-04 Thread randulo
Aside from the 5g phone that will come out as soon as you plunk down $300 for the 3g ($800 if you calculate your 2 year contract obligation), don't forget to join us today for The S Word: Security Most of you on this list will be more qualified than I am to discuss or even list the issues

Re: [asterisk-users] The S word: Asterisk security

2008-07-04 Thread randulo
Hope you get some beach time in today! Thanks for being a part of what I consider to be a gathering of friends with a common interest. I'm always happy to see you :) Best, Randy On Tue, Jul 1, 2008 at 5:56 PM, Kristian Kielhofner [EMAIL PROTECTED] wrote: On 7/1/08, randulo [EMAIL PROTECTED]

Re: [asterisk-users] The S word: Asterisk security

2008-07-04 Thread Steve Totaro
Randy, Do you record these sessions? Thanks, Steve T On Fri, Jul 4, 2008 at 2:31 AM, randulo [EMAIL PROTECTED] wrote: Aside from the 5g phone that will come out as soon as you plunk down $300 for the 3g ($800 if you calculate your 2 year contract obligation), don't forget to join us today

Re: [asterisk-users] The S word: Asterisk security

2008-07-04 Thread Michael Graves
On Fri, 4 Jul 2008 14:21:59 -0400, Steve Totaro wrote: Randy, Do you record these sessions? Thanks, Steve T All the VUC calls are recorded and available via http://voipusersconference.org/ning/. The post-call session is often not recorded, but the main body of the call is available for

[asterisk-users] The S word: Asterisk security

2008-07-01 Thread randulo
Hi all, As I mentioned briefly in the SIP takeover thread, I'd like to try to talk about security this coming Friday. I realize it is a holiday in the USA, but do geeks ever take a day off, especially security-conscious geeks? Mark Spencer once said The Bug Tracker is never on vacation!. We will

Re: [asterisk-users] The S word: Asterisk security

2008-07-01 Thread Kristian Kielhofner
On 7/1/08, randulo [EMAIL PROTECTED] wrote: Hi all, As I mentioned briefly in the SIP takeover thread, I'd like to try to talk about security this coming Friday. I realize it is a holiday in the USA, but do geeks ever take a day off, especially security-conscious geeks? Mark Spencer once

Re: [asterisk-users] The S word: Asterisk security

2008-07-01 Thread mgraves
FWD 54245 Original Message Subject: Re: [asterisk-users] The S word: Asterisk security From: Kristian Kielhofner [EMAIL PROTECTED] Date: Tue, July 01, 2008 10:56 am To: Asterisk Users Mailing List - Non-Commercial Discussionasterisk-users@lists.digium.com On 7/1/08

Re: [asterisk-users] The S word: Asterisk security

2008-07-01 Thread randulo
On Tue, Jul 1, 2008 at 5:56 PM, Kristian Kielhofner [EMAIL PROTECTED] wrote: I'd love to participate as long as no one minds me calling in from the beach... :) Why, do they care that I'm often naked? Hopefully, no one knew. PS, I did wear shorts for the Allison Smith sessions. r

Re: [asterisk-users] The S word: Asterisk security

2008-07-01 Thread Steve Totaro
On Tue, Jul 1, 2008 at 11:56 AM, Kristian Kielhofner [EMAIL PROTECTED] wrote: On 7/1/08, randulo [EMAIL PROTECTED] wrote: Hi all, As I mentioned briefly in the SIP takeover thread, I'd like to try to talk about security this coming Friday. I realize it is a holiday in the USA, but do

Re: [asterisk-users] The S word: Asterisk security

2008-07-01 Thread Fred Posner
On Jul 1, 2008, at 11:29 AM, randulo wrote: Hi all, As I mentioned briefly in the SIP takeover thread, I'd like to try to talk about security this coming Friday. I realize it is a holiday in the USA, but do geeks ever take a day off, especially security-conscious geeks? Mark Spencer once said

Re: [asterisk-users] The S word: Asterisk security

2008-07-01 Thread mgraves
Headset mic? Drive safe ;-) Michael Graves mgraves at mstvp.com o(713) 861-4005 c(713) 201-1262 sip:[EMAIL PROTECTED] skype mjgraves FWD 54245 Original Message Subject: Re: [asterisk-users] The S word: Asterisk security From: Fred Posner [EMAIL PROTECTED] Date: Tue, July

Re: [asterisk-users] The S word: Asterisk security

2008-07-01 Thread randulo
On Tue, Jul 1, 2008 at 7:30 PM, Fred Posner [EMAIL PROTECTED] wrote: a 2000 mile motorcycle ride :) I'll Where to where? What Michael said. ___ -- Bandwidth and Colocation Provided by http://www.api-digital.com -- AstriCon 2008 - September 22 - 25

Re: [asterisk-users] The S word: Asterisk security

2008-07-01 Thread Kristian Kielhofner
On 7/1/08, Steve Totaro [EMAIL PROTECTED] wrote: NOT sent from my iPhone or Blackberry very funny, you could add the typed with my thumbs line too. :) I know, although it looks like I'll be waiting in line in a couple of weeks for iPhone 2.0/3G... I just need to remember to update my

Re: [asterisk-users] The S word: Asterisk security

2008-07-01 Thread Fred Posner
On Tue, Jul 1, 2008 at 7:30 PM, Fred Posner [EMAIL PROTECTED] wrote: a 2000 mile motorcycle ride :) I'll Where to where? Gainesville, FL to Ann Arbor, MI to Gainesville, FL What Michael said. I had a blueant bluetooth, which was awesome on the motorcycle. Clear