Archive for the ‘opensips’ Category

SiVuS: un escáner de vulnerabilidad para las redes VoIP

October 12, 2008

SiVuS es un escáner de vulnerabilidad para las redes VoIP que utilizan el protocolo SIP. Este escáner proporciona varias características para verificar la robustez y para asegurar la implementación de una red VoIP segura.

Las características de este escáner son las siguientes:

Generador de mensajes SIP: puede ser utilizado para enviar varios tipos de mensajes a un componente del SIP incluyendo contenido del SDP. Esta característica se puede utilizar para probar ediciones específicas del SIP o para generar varios ataques, como por ejemplo un ataque de denegación de servicios.

Explorador de componentes del SIP: explora una gama de direcciones IP para identificar los anfitriones que utilizan el protocolo SIP y se puedan utilizar como blancos para el análisis adicional. Es una opción del explorador que permite el descubrimiento preliminar de blancos antes de una exploración real.

Explorador de la vulnerabilidad del SIP: El explorador proporciona la configuración flexible de varias opciones que se puedan utilizar, para verificar la robustez y la seguridad de una implementación del protocolo SIP. Se realizan chequeos como: análisis de las cabeceras de mensajes del protocolo SIP para identificar vulnerabilidades tales como desbordamientos del buffer o ataques de denegación de servicio, autentificación de mensajes que identifican componentes del SIP, autentificación de las peticiones del registro, inspección para las comunicaciones seguras (SIPS) y verificación de las capacidades de cifrado.

Componente de log: posee un completo sistema de log en HTML que permite omitir mensajes de error para hacer logs mas fáciles de comprender, también posee base de datos para históricos.

Ayuda del SIP: el interfaz de SiVuS proporciona ayuda rápida en los aspectos más comunes sobre SIP que pueden ser útiles a un usuario mientras que realizan SiVuS. La ayuda del SIP proporciona información sobre última versión del estándar RFC 3261 (SIP), muestra también ayuda a un usuario para construir mensajes del SIP a través del generador.

Descarga Sivus 1.09:
http://www.vopsecurity.org/sivus-1.09.exe

Manual Sivus 1.09:
http://www.vopsec.net/SiVuS-User-Doc.pdf

Seguridad en VoIP a través del protocolo ZRTP.
http://vtroger.blogspot.com/2007/10/seguridad-en-voip-travs-del-protocolo.html

Herramienta de test de penetración para VoIP:
http://vtroger.blogspot.com/2007/10/herramienta-de-test-de-penetra

Algunos clientes IMS

August 15, 2008

Con la maqueta de open ims core funcionando aparece la necesidad de conseguir clientes IMS y sip con los cuales podamos probar:


There are several IMS clients out there recently, which can be used with the Open IMS Core.

  • FOKUS’ OpenIC (Open IMS Client) is available only commercially (Contact: info@open-ims.org). Yet, there is also a free binary OpenIC_Lite version available right here
  • The UCT IMS Client which is available under the GPL
  • The IMS Communicator, also under the GPL

Instale el ultimo y lo estoy probando a ver que tal, hasta el momento veo que tiene una pinta bastente fea pero hace lo que tiene que hacer…pero como siempre digo este tema esta evolucionando a una velocidad vertiginosa, conasulten siempre las fuentes: http://www.openimscore.org/node/72

Openser, OpenIMS Core, kamailio, linux, asterisk……

Using MS Windows Messenger with a custom SIP Server

August 13, 2008

De hecho no solo windows messenger puede perfectamente trabajar con openser, opensips, openimscore, sino tambien gaim y otros clientes que ya mencionaremos.

Con MS Windows tenemos los siguientes features:

Supported protocols: SIP 2.0., UDP/TCP/IP/TLS, SIMPLE

Voice codecs: G.723.1, G.722.1, GSM6.10, G.711 (que malo no tiene el G729)

Features: local buddy list, presence, audio and video, instant messaging

Using MS Windows Messenger with a custom SIP Server (obtenido de: http://www.voice-system.ro/docs/sip-ms-msg/ar01s03.html#id2472711

Although MS provides its own SIP server, known as MS Live Communications Server, this article is based on experiences during the usage of MS Windows Messengers with SIP Express Router (SER).

In your real configuration, you have to replace the addresses presented in this document with the proper values for your SIP service. So, in the next examples we will use “sip-server.net” as the address of the SIP server (registrar and proxy), “3333@sip-server.net” as the SIP address of local user and “4444@sip-server.net” as the SIP address of the remote user.

3.1. Configure MS Windows Messenger

Make sure the version of MS Windows Messenger is 4.6, 4.7 or 5.0+.

3.1.1. Start MS Windows Messenger

- Start -> Programs -> Windows Messenger

3.1.2. Go to Options

- from menu, select “Tools” -> “Options…

3.1.3. Go to Accounts

- select “Accounts” tab

- select “Communications Service

- in the “Communications Service Account” section, fill in the “Sign-in name” field with the address of your SIP account, e.g., “3333@sip-server.net”.

3.1.4. Advanced Option

- click on “Advanced…” button

- select “Configure Settings

- outbound proxy: to enable outbound proxy fill in the “Server name or IP address” with the address of your SIP server, e.g., “sip-server.net:5060

- communication protocol: select an option from “Connect Using” list, e.g., “UDP” — this is the most recommended protocol for SIP

- click OK

- click OK in Options window

3.1.5. Register with your SIP server

- click on “Click here to sign in

3.1.6. Authentication

- if the SIP server requires user authentication

- fill the “Sign-in name” field with your SIP address, e.g., “3333@sip-server.net

- fill the “Username Name” field with the user name of your SIP account, e.g., “3333

- fill the “Password” field with the password of your SIP account (chosen by you or given by your SIP provider during the subscription to SIP service)

- press “OK” button

3.1.7. Online

- you can start voice sessions or send instant messages

3.2. Use MS Windows Messenger

Once you are online, you can start chatting or talking with your friends using Windows Messenger, or, if you have a webcam, you can have a video conference.

3.2.1. Start a chat session

- click “Send a instant message” from “I want to…” list

- select “Other

- enter the address of destination in “e-mail address” field

- choose “Communication Service” in “Service” select box

- click “OK

- type the message in the new window

- press “Enter” or click on “Send” button

3.2.2. Start a voice conversation

- click “Start a voice conversation” from “I want to…” list

- select “Other

- enter the address of destination in “e-mail address” field

- choose “Communication Service” in “Service” select box

- click “OK

- wait until the remote party accepts your call

- you can send also instant messages while talking by typing the message in the input field in the bottom of the new window and pressing “Send” button.

Openwengo

OpenWengo is a community of enthusiasts and developers, creating free software products related to communication over IP. The flagship product of the OpenWengo project is a softphone which allows you to make free PC to PC video and voice calls, and to integrate all your IM contacts in one place.

OpenWengo was started and is supported by the french VoIP provider Wengo . Through our partnership with Wengo, we also offer very cheap PC to telephone and SMS rates. OpenWengo is an active community – come join us.

To get started, download the software and let us know what you think.

WengoPhone 2.1 (OpenWengo 2.1.2)
For Windows (other platforms)

Compilando opensips con soporte mysql y configuracion

August 12, 2008

1.- Habilitar soporte para mysql:

Para habilitar el soporte de MySQL editamos el fichero Makefile y localizamos esta sección:

exclude_modules?= jabber cpl-c pa mysql postgres osp unixodbc \
avp_radius auth_radius group_radius uri_radius xmpp \
presence pua pua_mi pua_usrloc \
mi_xmlrpc perl snmpstats

y eliminamos “mysql”, dejándolo así:

exclude_modules?= jabber cpl-c pa postgres osp unixodbc \
avp_radius auth_radius group_radius uri_radius xmpp \
presence pua pua_mi pua_usrloc \
mi_xmlrpc perl snmpstats

Mismo procedime¡iento que con openser.

2.- Cambio de password de mysql:
The default user is root and the password is, as they say blank for default.

You can set the root password by typing this:

CODE
# mysqladmin -u root password ‘new-password’

You can then login by typing this:

CODE
# mysql -u root –p


Then you’ll be prompted to provide the password you specified earlier.

You also might want to delete the anonymous user in the User’s table. The default configuration of MySQL allows any user access to the system without
providing a username or password.

Delete the user by typing this:

CODE

# mysql -u root –p
mysql> use mysql
mysql> delete from user where User=”;
mysql> quit

Framp:

Try stopping the mysql daemon

CODE
/etc/init.d/mysql stop


Run

CODE
mysqld_safe –skip-grant-tables &


Enter as root

CODE
mysql -u root -p

To change root password

CODE
mysql client – mysql -u root


and write

CODE

use mysql
update user set password=PASSWORD(”NEW-ROOT-PASSWORD”) where User=’root’;

3.- Resetear el password MySQL (por si se le olvido cual era el anterior):

# /etc/init.d/mysql stop
# echo SET PASSWORD FOR ‘root’@'localhost’ = PASSWORD\(‘NuevoPassword’\)\; >reset_pass
# mysqld_safe –init-file=reset_pass
# rm reset_pass
# /etc/init.d/mysql start

4.- Habilitar el DBENGINE como mysql:

All files containing openserctl in the name should be downloaded. Then place the files on the local file system as follows:

openserctl => /usr/local/sbin/
openserctlrc => /usr/local/etc/openser/
openserctl.{base,sqlbase,ctlbase,fifo,unixsock,mysql,pgsql} => /usr/local/lib/openser/opensectl/

Edit now /usr/local/etc/openserctrc and add:
DBENGINE=MYSQL
CTLENGINE=FIFO

Do: chmod +x /usr/local/sbin/openserctl

Also, you can set the database parameters – the comments in /usr/local/etc/openserctrc give you more details.


5.- Creando la base de datos opensips:

opensipsdbctl create opensips

6.- Agregando suscriptores:

opensipsctl add user password email

rm para borrar

7.- Revisar estructura de la base de datos de mysql:

mysql -u root

show databases;

use opensips;

show tables;

select * from suscriber;

Openser ahora se llama opensips

August 10, 2008

El proyecto openser se llama ahora opensips.

OpenSIPS (Open SIP Server) is a mature Open Source implementation of a SIP server. OpenSIPS is more than a SIP proxy/router as it includes application-level functionalities. OpenSIPS, as a SIP server, is the core component of any SIP-based VoIP solution. With a very flexible and customizable routing engine, OpenSIPS ‘unifies voice, video, IM and presence services in a highly efficient way, thanks to its scalable (modular) design.
What OpenSIPS has to offer, comes in a reliable and high-performance flavour – OpenSIPS is one of the fastest SIP servers, with a throughput that confirms it as a solution up to enterprise or carrier-grade class.

Notas sobre instalacion, compilacion, configuracion: (copia del archivo de texto que viene cuando nos bajamos el paquete de la pagina):

$Id: INSTALL 4555 2008-08-03 03:41:05Z dan_pascu $

===========================================

OpenSIPS Installation Notes

http://www.opensips.org/

===========================================

This memo gives you hints how to set up OpenSIPS quickly. To
understand how OpenSIPS works and how to configure it properly,
read admin’s guide available from OpenSIPS website. We also
urge you to read latest ISSUES (available from OpenSIPS website
too) and check for potential problems in this release.
Users of previous releases are encouraged to read NEWS to
learn how to move to this new OpenSIPS version.

TOC

1. Supported Architectures and Requirements
2. Howto Build opensips From Source Distribution
3. Quick-Start Installation Guide
A) Getting Help
B) Disclaimers
C) Quick Start
D) opensips with Persistent Data Storage
4. Troubleshooting

1. Supported Architectures and Requirements
——————————————-

Supported architectures: Linux/i386, Linux/armv4l, FreeBSD/i386, OpenBSD/i386
Solaris/sparc64, NetBSD/sparc64
(for other architectures the Makefiles might need to be edited)

There are various configuration options defined in the Makefile.

Requirements:

- gcc / suncc / icc : gcc >= 2.9x; 4.[012] recommended (it will work with
older version but it might require some options tweaking for best
performance)
- bison or yacc (Berkley yacc)
- flex
- GNU make (on Linux this is the standard “make”, on FreeBSD and Solaris is
called “gmake”) version >= 3.79.
- sed and tr (used in the makefiles)
- GNU tar (“gtar” on Solaris) and gzip if you want “make tar” to work
- GNU install or BSD install (on Solaris “ginstall”) if you want “make
install”, “make bin”, “make sunpkg” to work
- openssl if you want to compile the TLS support
- libsctp if you want to compile the SCTP support
- libmysqlclient & libz (zlib) -libs and devel headers- if you want mysql DB
support (the db_mysql module)
- libpq / postgresql -libs and devel headers- if you want postgres DB
support (the db_postgres module)
- unixodbc -libs and devel headers- if you want unixodbc DB
support (the db_unixodbc module)
- libexpat if you want the jabber gateway support (the jabber module) or the
XMPP gateway support
- libxml2 if you want to use the cpl-c (Call Processing Language) or
the presence modules (presence and pua*)
- libradius-ng -libs and devel headers- if you want to use functionalities
with radius support – authentication, accounting, group support, etc
- unixodbc – libs and devel headers – if you want UNIXODBC support as
DB underlayer
- libxmlrpc-c3 – libs and devel headers – if you want to have XML-RPC support
for the Management interface (MI)
- libperl – libs and devel headers – if you want PERL connector to support
perl scripting from you config file (perl module)
- libsnmp9 – libs and devel headers – if you want SNMP client functionality
(SNMP AgentX subagent) for opensips
- libldap libs and devel headers v2.1 or greater – if you want LDAP support
- libconfuse and devel headers – if you want to compile the carrierroute
module

OS Notes:

- FreeBSD/OpenBSD/NetBSD: make sure gmake, bison or yacc & flex are installed
- Solaris: as above; you can use Solaris’s yacc instead of bison. You might
need also gtar and ginstall.

2. Howto Build opensips From Source Distribution
——————————————-

(NOTE: if make doesn’t work try gmake instead)

- compile with default options (TLS support is enabled by “TLS=1″; SCTP
support is enabled by “SCTP=1″):

make #builds only opensips core, equivalent to make opensips
make modules

or make all #builds everything

-compile debug mode version

make mode=debug all

-compile only the textops module

make modules=modules/textops modules

-compile all the “default” modules except textops and db_mysql

make skip_modules=”textops db_mysql” modules

-compile all default modules and include uri_radius (not compiled by default):

make include_modules=”uri_radius” modules

-compile all the modules from the modules subdirectory (even the one excluded
by default):

make exclude_modules=”" modules

-compile all the modules from the modules subdirectory excluding exec:

make exclude_modules=exec modules
or
make exclude_modules=”" skip_modules=exec modules

-generate README file for textops module

make modules=modules/textops modules-readme

-compile with gcc-3.2 instead of gcc

make CC=gcc-3.2 all

or

CC=gcc-3.2 make all

Make targets:

Clean:

make clean (clean the modules too)
make proper (clean also the dependencies)
make distclean (the same as proper)
make mantainer-clean (clean everything, including auto generated files,
tags, *.dbg a.s.o)

Compile:

make proper
make
(or gmake on non-Linux systems)
make modules
or make modules exclude_modules=”exec” etc.

Make tags:

make TAGS

Create a tar.gz with the sources (in ../):

make tar

Create a tar.gz with the binary distribution (in ../):

make bin

Create a gzipped solaris package (in ../):

make sunpkg

Create debian packages (in ../):

make deb

or

dpkg-buildpackage

Install:

make prefix=/usr/local install

Note: If you use prefix parameter in make install then you also need
to use this parameter in previous make commands, i.e. make, make modules,
or make all. If you fail to do this then OpenSIPS will look for the default
configuration file in a wrong directory, because the directory of the
default configuration file is hard coded into opensips during compile time.
When you use a different prefix parameter when installing then the
directory hard coded in opensips and the directory in which the file will be
installed by make install will not match. (You can specify exact location
of the configuration file using -f parameter of opensips).

For example, if you do the following:
make all
make prefix=/ install

Then the installation will put the default configuration file into
/etc/opensips/opensips.cfg (because prefix is /), but opensips will look for the
file in /usr/local/etc/opensips/opensips.cfg (because there was no prefix
parameter in make all and /usr/local is the default value of prefix).

Workaround is trivial, use the same parameters in all make commands:
make prefix=/ all
make prefix=/ install

That applies to other make parameters as well (for example parameters
“modules” or “excluded_modules”).

3. Quick-Start Installation Guide
———————————————-

A) Getting Help

This guide gives you instructions on how to quickly set up OpenSIPS
on your box. In case the default configuration does not fly, check
documentation at opensips site
http://www.opensips.org/
to learn how to configure OpenSIPS for your site.

If the documentation does not resolve your problem you may try contacting
our user forum by E-mail at users@opensips.org — that is the mailing list
of opensips community. To participate in the mailing list, subscribe at the
following web address:
http://www.opensips.org/cgi-bin/mailman/listinfo/users

B) Disclaimers

Note well the default “quick-start” configuration is very simple in order
to be easily installable. It provides minimum features. Particularly,
authentication is by default disabled, which means anyone can register using
any name with the server. (This is on purpose to avoid installation
dependencies on MySQL which is needed for storing user credentials.)

C) Quick Start

The following step-by step guide gives you instructions how to install the
sql-free distribution of opensips. If you need persistence and authentication,
then you have to install additional MySql support — proceed to section D)
after you are finished with C).

1) Download an RPM or debian package from our site
http://opensips.org/pub/opensips/latest/packages/
If you don’t use an rpm or debian based distribution, see if corresponding
packages are available or try our tar.gz’ed binaries.
If you use Gentoo Linux you do not have to download a package.
For debian, packages are available via the Debian official repositories for
testing and unstable. For stable, use the project’s repository at:
deb http://www.opensips.org/debian stable main

2) install the package
RPM:
rpm -i
debian:
dpkg -i
or if APT repository is used:
apt-get install
gentoo:
emerge opensips
(or if use only stable packets: ACCEPT_KEYWORDS=”~x86″ emerge opensips)
tar.gz:
cd /; tar zxvf _os_arch.tar.gz
(it will install in /usr/local/, and the configuration file in
/usr/local/etc/opensips/opensips.cfg)
Solaris:
gunzip .gz ; pkgadd -d
*BSD:
pkg_add package_name
Note that the OpenSIPS package is in the FreeBSD package tree included,
but is not present in the OpenBSD and NetBSD repository. You’ll probably
have more luck trying to build directly from the source with the tar.gz,
as the package files for this systems are somewhat out of date at the
moment.

3) start the server
RPM + gentoo:
/etc/init.d/opensips start
debian:
opensips is started automatically after the install
(in case something fails you can start it with /etc/init.d/opensips start)
tar.gz:
the tar.gz does not include an init.d script, you’ll have to create one of
your own or adapt one from the source distribution (debian/init.d,
rpm/opensips.init.*, gentoo/opensips.init)
You can start opensips directly with /usr/local/sbin/opensips.
Solaris:
see tar.gz.

4) optionally, watch server’s health using the opensipsctl utility
– to do so, first set the environment variable SIP_DOMAIN to your domain
name, e.g., in Bourne shell, call
export SIP_DOMAIN=”myserver.foobar.com”
– if you are using other than ‘localhost’ mysql server for maintaining
subscriber database, change the variable ‘SQL_HOST’ to the proper
host name in the opensipsctl script
– run the opensipsctl utility
/usr/sbin/opensipsctl moni
or
/usr/local/sbin/opensipsserctl moni (if you installed from a tar.gz
or solaris package)
– you can create a resource file for opensipsctl, name it .opensipsctlrc
and place it in your home directory. You can set there the values for
opensipsctl variables (e.g., SIP_DOMAIN, SQL_HOST, SQL_USER, SQL_DB …)

5) Register with the server using your favourite SIP User Agent.
For example, users of Windows Messenger need to set
in Tools->Options->Accounts the following values:
Sign-in Name: @
Advanced->Configure Settings (on)
Advanced->Server:
Connect Using: UDP

D) opensips with Persistent Data Storage

The default configuration is very simple and features many simplifications.
In particular, it does not authenticate users and loses User Location database
on reboot. To provide persistence, keep user credentials and remember users’
locations across reboots, opensips can be configured to use MySQL. Before you
proceed, you need to make sure MySQL is installed on your box.

1) Download the package containing mysql support for opensips from:
http://www.opensips.org/pub/opensips/
(rpm and deb provided, most of the binary tar.gz distributions and the
solaris package include it; if it is not present you’ll have to rebuild
from the source).
For gentoo please include ‘mysql’ to your USE variable in /etc/make.conf
or give it as variable to the emerge command.
2) install the package
RPM based:
rpm -i
DEB based:
dpkg -i
or if APT repository is used
apt-get install
Gentoo Linux:
emerge opensips
(if do not want to put ‘mysql’ into your USE variable you can type:
USE=”mysql” emerge opensips)
3) create SQL tables
You must specify your database type in the /etc/opensipsctlrc file, e.g.
MySQL. See section 7 for an explanation of further possible parameters.
– if you have a previously installed OpenSIPS on your system, use
/usr/sbin/opensipsdbctl migrate
to convert your OpenSIPS database into new structures
NOTE: “migrate” is available only for mysql DBs
– otherwise, if this is your very first installation, use
/usr/sbin/opensipsdbctl create
to create OpenSIPS database structures
(you will be prompted for password of MySQL “root” user)

4) configure opensips to use SQL
uncomment all lines in configuration file opensips.cfg which are related to
authentication:
– loadmodule “/usr/lib/opensips/modules/db_mysql.so”
– loadmodule “/usr/lib/opensips/modules/auth.so”
– loadmodule “/usr/lib/opensips/modules/auth_db.so”
– modparam(“usrloc”, “db_mode”, 2)
– modparam(“auth”, “calculate_ha1″, yes)
– modparam(“auth_db”, “password_column”, “password”)
– if (!www_authorize(“sip.org”, “subscriber”)) {
www_challenge(“sip.org”, “0″);
break;
};
5) be sure to replace realm, the first parameter in www_* actions,
with name of your server; some broken UAC implementations don’t
authenticate otherwise; the authentication command in your
configuration script should look then like this:
if (!www_authorize(“myserver.foobar.com”, “subscriber”)) {
www_challenge(“myserver.foobar.com”, “0″);
break;
}
6) restart the server
/etc/init.d/opensips restart
7) you can now start managing the server using the opensipsctl utility;
you need to first set the environment variable SIP_DOMAIN to your
local SIP realm, e.g.,
export SIP_DOMAIN=”myserver.foobar.com”
or you can configure via the resource file for opensipsctlrc. The default
file is installed in the etc/ directory of your installation (along with the
OpenSIPS config file). For per user configuration, create .opensipsctlrc
in your home directory.
You can set there the values for opensipsctl variables like:
SIP_DOMAIN – your SIP domain
DBENGINE – database type: MYSQL, PGSQL or DBTEXT by default none is loaded
DBHOST – database host
DBNAME – database name
DBRWUSER – database read/write user
DBROUSER – database read only user
DBROPW – password for database read only user
DBROOTUSER – database super user
ALIASES_TYPE – type of aliases used:
DB – database aliases
UL – usrloc aliases
default none
CTLENGINE – control engine: FIFO or UNIXSOCK
OSIPS_FIFO – path to FIFO file
VERBOSE – verbose – debug purposes – default ’0′

a) watch the server status using ‘opensipsctl moni’
b) try to login with your SIP client as user ‘admin’ with
password ‘opensipsrw’
c) try adding new users using
‘opensipsctl add ‘

8) default values (database url, users and passwords) are:
– DEFAULT_DB_URL=”mysql://opensips:opensipsrw@localhost/opensips”
– r/w user: opensips ; passwd: opensipsrw
– r/o user: opensipsro ; passwd: opensipsro
VERY IMPORTANT NOTE: for security reasons, do change the values of
passwords after installation

4. Troubleshooting
——————

Q: SIP requests are replied by opensips with “483 Too Many Hops” or
“513 Message Too Large”

A: In both cases, the reason is probably an error in request routing script
which caused an infinite loop. You can easily verify whether this happens
by watching SIP traffic on loopback interface. A typical reason for
misrouting is a failure to match local domain correctly. If a server fails
to recognize a request for itself, it will try to forward it to current URI
in believe it would forward them to a foreign domain. Alas, it forwards the
request to itself again. This continues to happen until value of
max_forwards header field reaches zero or the request grows too big.
Solutions is easy: make sure that domain matching
is correctly configured. A quick way to achieve that is to introduce a config
option to opensips.cfg: alias=domainname, where domainname shall be replaced
with name of domain, which you wish to server and which appears in
request-URIs.


Follow

Get every new post delivered to your Inbox.