Asterisk SIP Server, From “Info” to “Ouch”
ID: 09afb059-ae9d-52bb-b665-c08094dda108
STIX ID: report--09afb059-ae9d-52bb-b665-c08094dda108
Feed Name: Black Hills Infosec Blog
Threat Score
A security researcher investigated an "Asterisk Detection" informational finding from Nessus and discovered an IPitomy web interface exposing employee names and extensions, non-administrative accounts using default credentials (username=password equal to extension), and no account lockout, allowing rapid brute-force discovery of valid accounts and access to voicemail and call settings.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
