Some discussions about SIP security [thanks to the heroes participating in the discussion]

xiaoxiao2021-03-06  64

********* (IoKe) 10:21:34

Discuss a technical issue

********* (IoKe) 10:22:03

SIP as a data transmitted by the coded code, isn't it afraid of being eavesdropped?

******* (You are smart and ask me) 10:10:28

What data do you mean?

********* (IoKe) 10:23:27

I think it's easy to eavesdrop, intercepting the SIP protocol on the Internet, it is easy to get the RTP port and route, and then easily make eavesdropping through a specific mode.

******* (Ivan) 10:11:54

You can add SDP encryption in RTP

********* (IoKe) 10:24:39

I can easily realize the protocols of all POP3 in our LAN, including passwords, can be intercepted.

******* (golgo) 10:06

Does MD5 do?

********* (Ioke) 10:25:05

Transmission encryption?

******* (golgo) 10:12:32

********* (Ioke) 10:25:23

MD5 is just useless in your downloaded file check is not changed

******* (golgo) 10:12:54

Only this role?

********* (IoKE) 10:25:43

Can't guarantee your transmission being listened

********* (Ioke) 10:25:53

seems like it

******* (golgo) 10:13:20

That's another MD6.

********* (Ioke) 10:26:52

Do you talk about how can I encrypt the SIP protocol? So can SIP GATEWAY know if the SIP protocol is added?

******** (Ioke) 10:27:10

Does SIP are transmitted by SSL?

********* (IoKe) 10:27:29

MD7 does not guarantee that your transmission is not listening.

********* (IoKE) 10:27:47

Why, why don't everyone are not interested?

******* (golgo) 10:15:44

Have

******* (golgo) 10:15:47

SSL

******* (Golgo) 10:15:53

OpenSSL

******* (You are smart and ask me) 10:15:57

Not interested, SIP has not played well.

********* (IoKE) 10:29:10

Not that I said that there is no provision for SSL transmission in the SIP protocol.

********* (IoKe) 10:29:27

Have you achieved SSL SIP transmission channels?

********* (IoKE) 10:32:28

Follow, discuss the topic, all speechless ~~

******* (Ivan) 10:20:52

Leoo, ask a question, RTP and SIP are not coupled together.

******* (Ivan) 10:21:07

Is the RTP get the other party's IP via SIP? ******* (You are smart and ask me) 10:21:20

Not

******* (You are smart and ask me) 10:21:38

IP and ports of RTP in SIP

********* (IoKe) 10:34:46

Is not coupled together

******* (You are smart and ask me) 10:22:16

Mainly indicated in SDP

******* (Ivan) 10:22:23

Is there a IP and port in the SIP? Use

XXXX @ xxxx method

********* (IoKE) 10:35:09

But the routing of the audio that can be taken by SIP

********* (IoKe) 10:35:35

Specified, if not specified, how to communicate

******* (Ivan) 10:22:53

Do you mean that IP and Port in SDP?

******* (You are smart and ask me) 10:22:54

Indicated SDP

********* (IoKe) 10:35:55

SDP encryption?

******* (You are smart and ask me) 10:23:21

Tell the opponent you open RTP port and address

********* (IoKe) 10:37:08

This way I can easily put the RTP package, restore the RTP package in the process of their transmission.

******* (You are smart and ask me) 10:24:53

of course

******* (golgo) 10:25:08

RTP, good complex problem

********* (IoKe) 10:38:07

Will RTP will encrypt the package?

******* (You are smart and ask me) 10:25:30

If the SIP package is sent, some people have destroyed in the agent it passed.

********* (IoKe) 10:38:50

I am not in the agent.

******* (You are smart and ask me) 10:26:02

Then we have to negotiate an encryption algorithm in both parties.

********* (IoKe) 10:39:07

I capture the transfer package in the network.

******* (You are smart and ask me) 10:26:47

How do you catch it?

********* (IoKE) 10:39:35

Then I can simulate the caller to initiate a call, or listen

********* (IoKe) 10:39:59

Simply speaking, talk about the implementation in the LAN

******* (golgo) 10:27:22

********* (Ioke) 10:40:29

I can set the NIC to a mixed mode, so my network card can receive all the packages transmitted in the local area.

********* (IoKe) 10:41:02

Now I analyze SDP in the SIP package, get RTP IP and port

******* (You are smart and ask me) 10:28:38

Local area network

********* (IoKe) 10:41:46

Then there is all RTP packs of this IP in the network, then restore voice

********* (IoKe) 10:41:52

Is it very ok?

********* (Ioke) 10:42:35

If it is a wide area network, it can also be implemented, but it is not easy as the LAN

******* (You are smart and ask me) 10:30:02

It seems that hub is copying each passing thereof and then sent it over again, so you can receive any packages in the local area.

********* (IoKe) 10:43:25

Haha, have you seen five types of lines listening calipers

********* (IoKe) 10:44:02

Put the caliper card on your network cable, do not destroy your transmission, all the data is easy to capture

******* (You are smart and ask me) 10:31:31

Is there such a Dongdong?

********* (IoKe) 10:44:33

In WAN can also be implemented by ARP

********* (Ioke) 10:44:39

Haven't seen it.

********* (IoKe) 10:45:08

What is the network cable transmission data? Carrier, do the carrier caught?

********* (Ioke) 10:45:19

I am afraid it is better

******* (golgo) 10:32:46

******* (You are smart and ask me) 10:32:49

Oh, it can catch all SIP signaling through this line.

********* (IoKe) 10:45:44

Sure enough, smart

转载请注明原文地址:https://www.9cbs.com/read-85556.html

New Post(0)