Re: SIP Dialog Match

aayush bhatnagar <[email protected]>
Newsgroups gmane.ietf.sip
Message-ID <[email protected]>
It is possible..and is standardized. 'C' can 'logically' Join an existing
dialog between 'A' (UAC) and 'B' (UAS), by including a Join header in the
INVITE request.
It may be a security concern to allow C to Join the existing dialog, but it
can be a way to implement a call screening server (call tapping) for lawful
interception services.

For more details look here: http://www.rfc-editor.org/rfc/rfc3911.txt
<http://www.rfc-editor.org/rfc/rfc3911.txt>

On Thu, Jul 30, 2009 at 09:28, Karunesh Sharma <
[email protected]> wrote:

>  List:
>
>
>
> I am having a question about SIP dialog validation using src/dst ip. If
> there is established sip dialog between ‘A’ & ‘B’ then can ‘C’ who is not
> party to existing dialog and who somehow knows all sip dialog identifiers
> (Call-ID, To/From Tags) of the dialog between ‘A’ & ‘B’, sends target
> refresh request with its own IP in contact. This is a typical call hijacking
> case. If this is valid how to avoid that? Is Authentication is only way out
> or do we have other alternate as well?
>
>
>
> I didn’t find anything on this in 3261 or other related RFCs.
>
>
>
> Thanks
>
>
>
> K$
>
> _______________________
>
>
>
> _______________________________________________
> Sip mailing list  https://www.ietf.org/mailman/listinfo/sip
> This list is for NEW development of the core SIP Protocol
> Use [email protected] for questions on current sip
> Use [email protected] for new developments on the application of sip
>



-- 
aayush
----------------------------------------------------
"A philosopher always knows what to do...until it happens to him"

_______________________________________________
Sip mailing list  https://www.ietf.org/mailman/listinfo/sip
This list is for NEW development of the core SIP Protocol
Use [email protected] for questions on current sip
Use [email protected] for new developments on the application of sip
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.