Re: [SR-Users] Why is the To URI the default in save()?

2017-05-16 Thread Daniel Tryba
On Mon, May 15, 2017 at 03:06:38PM +0200, Daniel-Constantin Mierla wrote: > > This opens the door to hijacking incoming calls to other users on the > > same kamailio registrar if one knows/guesses other usernames and use > > those in the To header. > SIP allows third party registrations. From heade

Re: [SR-Users] Why is the To URI the default in save()?

2017-05-15 Thread Daniel-Constantin Mierla
On 15.05.17 14:14, Daniel Tryba wrote: > The save function from the registrar module uses the To header to disect > and store the username for the location table according to observations > and documentation > http://www.kamailio.org/docs/modules/stable/modules/registrar.html#registrar.f.save > >

Re: [SR-Users] Why is the To URI the default in save()?

2017-05-15 Thread Alex Balashov
Hello, RFC 3261 ยง 10.2.1 says: The address-of-record is included in the To header field of the REGISTER request. -- Alex -- Alex Balashov | Principal | Evariste Systems LLC Tel: +1-706-510-6800 / +1-800-250-5920 (toll-free) Web: http://www.evaristesys.com/, http://www.csrpswitch.com/

[SR-Users] Why is the To URI the default in save()?

2017-05-15 Thread Daniel Tryba
The save function from the registrar module uses the To header to disect and store the username for the location table according to observations and documentation http://www.kamailio.org/docs/modules/stable/modules/registrar.html#registrar.f.save After troubleshooting a ticket from an enduser unab