SIP: type=friend

General discussions about Asterisk.

Moderators: Moderator, Support

SIP: type=friend

Postby thor » Sun Jun 12, 2011 2:33 pm

Does anyone have an example when using type=friend in a SIP device definition would be necessary ?
thor
Oldsterisk
 
Posts: 238
Joined: Thu Mar 18, 2010 12:19 pm

Re: SIP: type=friend

Postby cmendes0101 » Wed Jun 22, 2011 2:05 am

The type friend is both user and peer type.

Found this somewhere:

* peer: A SIP entity to which Asterisk sends calls (a SIP provider for example). If you want a user (extension) to have multiple phones, define an extension that calls two SIP peers. The peer authenticates at registration.
* user: A SIP entity which places calls through Asterisk (A phone which can place calls only). Users authenticate to reach services with their context.
* friend: An entity which is both a user and a peer. This make sense for most desk handsets and other devices. Asterisk will create two objects, one peer and one user, with the same name.
cmendes0101
Newsterisk
 
Posts: 39
Joined: Wed Apr 06, 2011 4:07 pm

Re: SIP: type=friend

Postby thor » Wed Jun 22, 2011 9:25 am

This is jibberish.

Why would you want to have both user+peer for the same device when peer only is sufficient ?

I am really looking for a real life example.
Show me a config where type=peer does not work, but type friend does.
thor
Oldsterisk
 
Posts: 238
Joined: Thu Mar 18, 2010 12:19 pm

Re: SIP: type=friend

Postby thor » Wed Jul 06, 2011 11:07 am

Another argument against using type=friend has been just posted.

Using type=friend not only allows your "extensions" to be enumerated: viewtopic.php?t=78538

The enumeration attack does not produce any meaningful entries in asterisk logs, so it is undetectable by log scanning tools like fail2ban : viewtopic.php?t=78988
thor
Oldsterisk
 
Posts: 238
Joined: Thu Mar 18, 2010 12:19 pm

Re: SIP: type=friend

Postby malcolmd » Wed Jul 06, 2011 11:46 am

Is the enumeration still present given:

http://downloads.asterisk.org/pub/secur ... 1-011.html

?
Malcolm Davenport
Digium, Inc. | Senior Product Manager
malcolmd
Moves Like Spencer
 
Posts: 3019
Joined: Wed Aug 03, 2005 3:53 pm
Location: Huntsville, AL, US

Re: SIP: type=friend

Postby thor » Wed Jul 06, 2011 12:25 pm

Okay, compiled 1.8.4.4 and it is gone. That was quick. Now you need to upgrade the rest of the world.
It was not clear from the advisory what exactly was fixed as the CVE entry is stil not updated.


Can you find me now a sample config with type=friend in it ? It has been a month since I asked and no one came forward.
thor
Oldsterisk
 
Posts: 238
Joined: Thu Mar 18, 2010 12:19 pm


Return to Asterisk General

Who is online

Users browsing this forum: No registered users and 1 guest