Penetration Testing mailing list archives
Re: Pbx testing
From: Marco Ivaldi <raptor () 0xdeadbeef info>
Date: Tue, 27 Jun 2006 18:11:48 +0200 (CEST)
Hey, On Tue, 13 Jun 2006, Grizzly wrote:
Hi list, have someone any idea about general pbx testing (assessment, pentest)? Thanks!
First of all, if you haven't done it yet, i strongly suggest you to read the excellent NIST Special Publication titled "PBX Vulnerability Analysis: Finding Holes in Your PBX Before Someone Else Does" (sp800-24pbx.pdf). Even though it's slightly outdated (written in 2000), it's still a great resource for security auditors and network administrators. Take also a look at OSSTMM (http://www.isecom.org/) and ISSAF (http://www.oisg.org/) -- but don't expect to find too much in both of them about this topic. Google, vendors documentation and the archives of this mailing list may ideed help as well;) Here's a quick audit checklist off the top of my head: 1) Administrative access: default and easily-guessable passwords, console access, remote maintenance, feature access, etc. 2) System configuration and operating system patchlevel 3) Vendor-specific issues 4) Configuration-specific issues: station, trunking, call privileges, call routing, other specific features, etc. 5) Audit trails and logs review 6) Mailbox audit 7) Wardialing: scan the extensions hunting for modems 8) YMMV Moreover, if the PBX you're testing speaks also TCP/IP, all the usual IP networks vulnerabilities may also apply, so be sure to check them all -- but since usually these kind of TCP/IP stacks aren't very robust, beware of not DoS'ing it, specially if it's a production PBX! Finally, if it's a VoIP PBX, you should check a whole other range of possible security issues. As a side note, i'm currently working on a complete VoIP security testing methodology for ISECOM's OSSTMM: you'll see the results of my research in the near future. Cheers, -- Marco Ivaldi Antifork Research, Inc. http://0xdeadbeef.info/ 3B05 C9C5 A2DE C3D7 4233 0394 EF85 2008 DBFD B707 ------------------------------------------------------------------------------ This List Sponsored by: Cenzic Concerned about Web Application Security? Why not go with the #1 solution - Cenzic, the only one to win the Analyst's Choice Award from eWeek. As attacks through web applications continue to rise, you need to proactively protect your applications from hackers. Cenzic has the most comprehensive solutions to meet your application security penetration testing and vulnerability management needs. You have an option to go with a managed service (Cenzic ClickToSecure) or an enterprise software (Cenzic Hailstorm). Download FREE whitepaper on how a managed service can help you: http://www.cenzic.com/news_events/wpappsec.php And, now for a limited time we can do a FREE audit for you to confirm your results from other product. Contact us at request () cenzic com for details. ------------------------------------------------------------------------------
Current thread:
- Pbx testing Grizzly (Jun 13)
- Re: Pbx testing lion nagar (Jun 14)
- <Possible follow-ups>
- Re: Pbx testing Marco Ivaldi (Jun 27)