Found a bug - Dial without registering softphone

General and Support topics relating to ViciDialNow and GoAutoDial ISO installers

Moderators: enjay, williamconley, Op3r, Staydog, gardo, mflorell, MJCoate, mcargile, Kumba, s0lid

Found a bug - Dial without registering softphone

Postby knotbeerdan » Mon Aug 08, 2011 10:45 am

Over the weekend one of my co workers found a bug in goautodial. I am unsure if it is because of the way we configured the system or if it is a bug.

He found out that we are able to dial through the softphone (counterpath eyebeam) without entering valid phone credentials and registering the softphone first.

Can anyone reproduce this issue?
GoAutoDial 2.1CE - standard install | Asterisk: 1.4.27.1-1 | Vicidial: 2.4-309a | Build: 110430-1642| Telephony cards: none
knotbeerdan
 
Posts: 40
Joined: Thu May 05, 2011 4:31 pm
Location: Phoenix, AZ

Postby williamconley » Mon Aug 08, 2011 11:04 pm

That's not a bug.

That's a feature.

It can be turned off in sip.conf (Kumba put out a security notice for Vicibox on this a couple months back).
Code: Select all
;allowguest=no                  ; Allow or reject guest calls (default is yes)


Oh! And THANKS for posting your specs! I love it when you guys do that. 8-)
Vicidial Installation and Repair, plus Hosting and Colocation
Newest Product: Vicidial Agent Only Beep - Beta
http://www.PoundTeam.com # 352-269-0000 # +44(203) 769-2294
williamconley
 
Posts: 20258
Joined: Wed Oct 31, 2007 4:17 pm
Location: Davenport, FL (By Disney!)

Postby knotbeerdan » Tue Aug 09, 2011 11:26 am

Thanks for the response... This may be a dumb question but isnt this a security risk for anyone who is using vicidial in production?

And although I do have my specs I must change them since we are running goautodial in a Citrix virtual environment. (which works pretty well by the way, just cant install the Xenserver tools or run the dialers in PVM mode :( )
GoAutoDial 2.1CE - standard install | Asterisk: 1.4.27.1-1 | Vicidial: 2.4-309a | Build: 110430-1642| Telephony cards: none
knotbeerdan
 
Posts: 40
Joined: Thu May 05, 2011 4:31 pm
Location: Phoenix, AZ

Postby williamconley » Tue Aug 09, 2011 11:33 am

OK, now you have my attention. My recollection of Citrix was "remote access" not "virtual environment", so please enlighten me there a bit if you will.

And YES that's a security risk, which is why Kumba issued a Security Alert on the Vicibox Board to fix it.

In theory, the trunkinbound context should be where all sip calls land ... BUT "unauthenicated" (ie: guest) will use the default context instead: the default context in sip.conf is set to "default" instead of "trunkinbound".

Changing that could have an unknown effect on the rest of the system, so it is easier to require authentication for all inbound calls. If all sip.conf contexts require user/pass (with hard-to-crack user/pass!) or have specified host IPs ... then turning off guest will point all sip calls to the contexts specified in each sip peer's "context=" value. Since agents are in "default" but have user/pass, they are assumed safe. All carriers should be assigned "trunkinbound" so they are safe because "trunkinbound" will ONLY go to the agi for inbound calls in Vicidial (no way out).
Vicidial Installation and Repair, plus Hosting and Colocation
Newest Product: Vicidial Agent Only Beep - Beta
http://www.PoundTeam.com # 352-269-0000 # +44(203) 769-2294
williamconley
 
Posts: 20258
Joined: Wed Oct 31, 2007 4:17 pm
Location: Davenport, FL (By Disney!)

Re: Found a bug - Dial without registering softphone

Postby gardo » Tue Aug 09, 2011 4:39 pm

Can you list down the steps to be able to dial out without authentication? We'll try to replicate it in a default GoAutoDial install.

knotbeerdan wrote:Over the weekend one of my co workers found a bug in goautodial. I am unsure if it is because of the way we configured the system or if it is a bug.

He found out that we are able to dial through the softphone (counterpath eyebeam) without entering valid phone credentials and registering the softphone first.

Can anyone reproduce this issue?
http://goautodial.com
Empowering the next generation contact centers
gardo
 
Posts: 1926
Joined: Fri Sep 15, 2006 10:24 am
Location: Manila, 1004

Postby williamconley » Tue Aug 09, 2011 6:17 pm

Dialout isn't the issue: the "guest" user in SIP allows inbound calls ... and if the default context is set to "default" ... then the guest account will execute dialplan in "default" which is where vicidial keeps its dialplan. Solution: turn off guest. Require authentication (ie: user/pass or valid IP address matching a "host" entry in a sip context).
Vicidial Installation and Repair, plus Hosting and Colocation
Newest Product: Vicidial Agent Only Beep - Beta
http://www.PoundTeam.com # 352-269-0000 # +44(203) 769-2294
williamconley
 
Posts: 20258
Joined: Wed Oct 31, 2007 4:17 pm
Location: Davenport, FL (By Disney!)


Return to ViciDialNow - GoAutoDial

Who is online

Users browsing this forum: No registered users and 53 guests