Author | Topic |
Location: Brisbane
Registered: February 2003
|
Re: Any RTP/Firewall Experts?
|
Mon, 17 October 2005 07:35
|
|
From the IT but has been paraphrased for liablity | ...I got a feeling enabling it for the entire workplace would open the organisation to potential attacks from some crafted SIP or H.323 packets
|
this is just a neater way of saying "I vaguely recall reading a slashdot story about using video conferencing to attack a ...".
If they know where the traffic's coming from, who it's going to, then you should be able to impliment some kind of authenticated (not just 'trusted') access.
Sure it's a sane approach to network security (deny everything, allow what you know) but that doesn't preclude learning.
This simple search found a number of references to the exploit - but it seems to be a DoS attack, not door opener.
|
|
|