Enable Security

280 posts

Enable Security banner
Enable Security

Enable Security

@enablesecurity

We talk about Offensive Real-Time Communications / VoIP and WebRTC Security Blog: https://t.co/7b16xzphm2 Newsletter: https://t.co/SBo5FEGFFv

Germany Katılım Mayıs 2016
174 Takip Edilen357 Takipçiler
Enable Security
Enable Security@enablesecurity·
4/ I'll be presenting DVRTC at @opensips Summit (Bucharest, Apr 28), Kamailio World (Berlin, May 8), and CommCon (Dusseldorf, June 9-11). Three conferences, three different VoIP/WebRTC attack scenarios.
English
1
0
0
50
Enable Security
Enable Security@enablesecurity·
That last one is especially fun: the injection point is the called SIP URI itself. We'll cover it in a dedicated post with a video demo soon.
English
1
0
0
29
Enable Security
Enable Security@enablesecurity·
DVRTC, our intentionally vulnerable VoIP/WebRTC lab, now has a second scenario. v0.2.0 adds pbx2: OpenSIPS, FreeSWITCH, and rtpproxy. It joins pbx1 (Kamailio, Asterisk, rtpengine, coturn), so DVRTC now covers two different VoIP stacks to practice against. enablesecurity.com/blog/dvrtc-v0-…
English
1
0
8
583
Enable Security
Enable Security@enablesecurity·
svcrack cracks SIP passwords online. The default range (100-999) wasn't enough, but --enabledefaults found the password in under a second.
English
1
0
0
35
Enable Security
Enable Security@enablesecurity·
The bottleneck has already shifted from finding vulnerabilities to handling them. Carlini has several hundred unvalidated Linux kernel crashes. Most RTC projects are not ready for this volume of valid, reproducible findings.
English
1
0
0
32
Enable Security
Enable Security@enablesecurity·
Nicholas Carlini at Anthropic showed the methodology: loop Claude through each source file, prompt it like a CTF. 500+ high-severity findings, 22 Firefox vulnerabilities in two weeks, a Linux kernel bug from 2003 that required two cooperating adversarial clients.
Enable Security@enablesecurity

AI agents are now autonomously finding zero-days in large C codebases. RTC infrastructure (Kamailio, Asterisk, pjsip, rtpengine, coturn) is directly in the path. We wrote about why, and what project maintainers can do about it: enablesecurity.com/blog/ai-coming…

English
2
0
3
150