| The IMS Security Team | ![]() |
|
Menu Home About Us Vulnerabilities |
You are here: nexGIN RC → IMS Security Team → Vulnerabilities OpenSBC (INVITE of Death)Advisory Draft Date: 2nd Feburary, 2009. Release Date: 16th Feburary, 2009.
BackgroundOpenSBC is an ongoing attempt to create an open-source Session Border Controller that is fully compliant with the mandates of RFC 3261. OpenSBC can be used as a SIP router, media anchor for farend NAT traversal, SIP egress and ingress trunking among others. More information about the server can be found at http://opensipstack.org/ OverviewThe INVITE of Death vulnerability in OpenSBC server allows the attacker to crash the server causing remote Denial of Service (DOS). The problem specifically exists in OpenSBC version 1.1.5-25 in the handling of “Via” field caused from maliciously crafted SIP packet. Proof of ConceptThe proof of concept code can be downloaded from here: OpenSBC.pl. INVITE sip:bob@open-ims.test SIP/2.0 Work AroundThe OpenSBC devolpment team has been reported about the vulnerability. Below is the E-mail exchange content between our research team and the CTO of Solegey Systems: CreditsThe vulnerability was discovered by Zubair Rafique and Sohail Aziz from the IMS security research project team. ContactM. Zubair Rafique M. Ali Akbar DisclaimerThe contents of this advisory are copyright (c) 2009 nexGIN RC , and may be distributed freely provided that no fee is charged for this distribution and proper credit is given. |