Re: Pbx testing



Hey,

On Tue, 13 Jun 2006, Grizzly wrote:

Hi list,
have someone any idea about general pbx testing (assessment, pentest)?
Thanks!

First of all, if you haven't done it yet, i strongly suggest you to read
the excellent NIST Special Publication titled "PBX Vulnerability Analysis:
Finding Holes in Your PBX Before Someone Else Does" (sp800-24pbx.pdf).

Even though it's slightly outdated (written in 2000), it's still a great
resource for security auditors and network administrators. Take also a
look at OSSTMM (http://www.isecom.org/) and ISSAF (http://www.oisg.org/)
-- but don't expect to find too much in both of them about this topic.

Google, vendors documentation and the archives of this mailing list may
ideed help as well;)

Here's a quick audit checklist off the top of my head:

1) Administrative access: default and easily-guessable passwords, console
access, remote maintenance, feature access, etc.
2) System configuration and operating system patchlevel
3) Vendor-specific issues
4) Configuration-specific issues: station, trunking, call privileges, call
routing, other specific features, etc.
5) Audit trails and logs review
6) Mailbox audit
7) Wardialing: scan the extensions hunting for modems
8) YMMV

Moreover, if the PBX you're testing speaks also TCP/IP, all the usual IP
networks vulnerabilities may also apply, so be sure to check them all --
but since usually these kind of TCP/IP stacks aren't very robust, beware
of not DoS'ing it, specially if it's a production PBX!

Finally, if it's a VoIP PBX, you should check a whole other range of
possible security issues. As a side note, i'm currently working on a
complete VoIP security testing methodology for ISECOM's OSSTMM: you'll see
the results of my research in the near future.

Cheers,

--
Marco Ivaldi
Antifork Research, Inc. http://0xdeadbeef.info/
3B05 C9C5 A2DE C3D7 4233 0394 EF85 2008 DBFD B707


------------------------------------------------------------------------------
This List Sponsored by: Cenzic

Concerned about Web Application Security?
Why not go with the #1 solution - Cenzic, the only one to win the Analyst's
Choice Award from eWeek. As attacks through web applications continue to rise,
you need to proactively protect your applications from hackers. Cenzic has the
most comprehensive solutions to meet your application security penetration
testing and vulnerability management needs. You have an option to go with a
managed service (Cenzic ClickToSecure) or an enterprise software
(Cenzic Hailstorm). Download FREE whitepaper on how a managed service can
help you: http://www.cenzic.com/news_events/wpappsec.php
And, now for a limited time we can do a FREE audit for you to confirm your
results from other product. Contact us at request@xxxxxxxxxx for details.
------------------------------------------------------------------------------



Relevant Pages

  • RE: PBX Security
    ... Well unfortunately I'm seeing PBX security not that easily handled. ... is not just enough to restrict source IP addresses and control access to ... the management of the box. ...
    (Pen-Test)
  • RE: PBX Security
    ... networks, and toll fraud is always an issue. ... Enterprise Security Practice. ... Subject: PBX Security ... is not just enough to restrict source IP addresses and control access to ...
    (Pen-Test)
  • PBX Security
    ... I return with the reasons I freaked when I saw what a PBX ... ANY extension, and not just any user can do that, with proper ... cryptographic controls on software updates for a PBX. ... relevant and enforced security policy, security conscious users, etc and ...
    (Pen-Test)
  • RE: PBX Security
    ... the access controls are, if the dial-up modem for remote admin of the PBX ... Software updates are rather hard to patch in transit, ... > Subject: PBX Security ...
    (Pen-Test)
  • RE: detecting wardialing
    ... The biggest issues with SandTrap is that it is not in-line with a PBX, ... Protection against wardialing can be easily accomplished by ... Better Management for Network Security ...
    (Security-Basics)

Loading