Re: Pbx testing

From: Marco Ivaldi (raptor@0xdeadbeef.info)
Date: Tue Jun 27 2006 - 12:11:48 EDT


Hey,

On Tue, 13 Jun 2006, Grizzly wrote:

> Hi list,
> have someone any idea about general pbx testing (assessment, pentest)?
> Thanks!

First of all, if you haven't done it yet, i strongly suggest you to read
the excellent NIST Special Publication titled "PBX Vulnerability Analysis:
Finding Holes in Your PBX Before Someone Else Does" (sp800-24pbx.pdf).

Even though it's slightly outdated (written in 2000), it's still a great
resource for security auditors and network administrators. Take also a
look at OSSTMM (http://www.isecom.org/) and ISSAF (http://www.oisg.org/)
-- but don't expect to find too much in both of them about this topic.

Google, vendors documentation and the archives of this mailing list may
ideed help as well;)

Here's a quick audit checklist off the top of my head:

1) Administrative access: default and easily-guessable passwords, console
   access, remote maintenance, feature access, etc.
2) System configuration and operating system patchlevel
3) Vendor-specific issues
4) Configuration-specific issues: station, trunking, call privileges, call
   routing, other specific features, etc.
5) Audit trails and logs review
6) Mailbox audit
7) Wardialing: scan the extensions hunting for modems
8) YMMV

Moreover, if the PBX you're testing speaks also TCP/IP, all the usual IP
networks vulnerabilities may also apply, so be sure to check them all --
but since usually these kind of TCP/IP stacks aren't very robust, beware
of not DoS'ing it, specially if it's a production PBX!

Finally, if it's a VoIP PBX, you should check a whole other range of
possible security issues. As a side note, i'm currently working on a
complete VoIP security testing methodology for ISECOM's OSSTMM: you'll see
the results of my research in the near future.

Cheers,

-- 
Marco Ivaldi
Antifork Research, Inc.   http://0xdeadbeef.info/
3B05 C9C5 A2DE C3D7 4233  0394 EF85 2008 DBFD B707
------------------------------------------------------------------------------
This List Sponsored by: Cenzic
Concerned about Web Application Security? 
Why not go with the #1 solution - Cenzic, the only one to win the Analyst's 
Choice Award from eWeek. As attacks through web applications continue to rise, 
you need to proactively protect your applications from hackers. Cenzic has the 
most comprehensive solutions to meet your application security penetration 
testing and vulnerability management needs. You have an option to go with a 
managed service (Cenzic ClickToSecure) or an enterprise software 
(Cenzic Hailstorm). Download FREE whitepaper on how a managed service can 
help you: http://www.cenzic.com/news_events/wpappsec.php 
And, now for a limited time we can do a FREE audit for you to confirm your 
results from other product. Contact us at request@cenzic.com for details.
------------------------------------------------------------------------------


This archive was generated by hypermail 2.1.7 : Sat Apr 12 2008 - 10:56:11 EDT