Digium rolls out new IAX security- what you should know
Friday, September 11, 2009 at 8:03AM
This past week Digium rolled out new versions of asterisk for all currently supported branches (1.2.x, 1.4.x, & 1.6.x), with a security addition to combat IAX's DOS vulnerabilities that arise from the protocols use of a single port. The new releases introduce token authentication for IAX devices and trunks, and have methods to put a limit on the number of unathenticated IAX connections. Disclosure of the new security methods and how to use them can be found here, http://downloads.asterisk.org/pub/security/IAX2-security.html.
