[Freeswitch-users] multiple registerations coudln't worked correctly!

Samira Mh saami_mh at ymail.com
Thu Jun 28 20:00:22 MSD 2012


thanks alot for great reply,
using sip-to-host , ip, domain  on realtime directory we found out who steal account informations,because we only serve this servive for users who have ADSL account of our ISP compay...so restict on the range of ip-addresses
but i think there is not any soltion for implement limit only one user login,
thanks so much


________________________________
 From: Michael Collins <msc at freeswitch.org>
To: FreeSWITCH Users Help <freeswitch-users at lists.freeswitch.org> 
Sent: Thursday, June 28, 2012 8:16 PM
Subject: Re: [Freeswitch-users] multiple registerations coudln't worked correctly!
 

This is probably the wrong way to handle the situation. There are definitely drawbacks. It sounds like you're wanting a "first come, first served" scenario. The problem is that if the thief gets userA's information then all he would have to do is disconnect the real userA's phone, thereby making that registration go away, then he could register his bogus "userA" and no one would know any better. The only symptom would be that the real userA would not be able to register, but by the time you found out about that the thief could have made all sorts of calls while pretending to be userA.

I believe you need to rethink your security strategy. If the real issue is that someone can steal user account information and use it nefariously then you need to solve THAT problem, or at least mitigate it. For example, just how did the thief steal the credentials? 

I get the feeling that trying to do this "I'm first, so no one else can register" thing is a poor way to make things secure. It's kind of like leaving the front door unlocked and then super gluing all your stuff to the floor so no one can walk in and take it.

-MC


On Thu, Jun 28, 2012 at 8:21 AM, Samira Mh <saami_mh at ymail.com> wrote:

suppose we have account with the following information:
>
>extension=1000
>secret=12345
>callerid=userA
>--------------------------
>now the user(B,C,D ..) -NOT IMPORTANT who?- stolen  the account informations of userA and want to login using userA account
>
>while the userA is now connect to server,but at the same time userB register on sip phone using userA iformations(extesion=1000,secret=12345,...)
>and by set multi_registering=false the userA is not connected now, and userB is now connected because only one user able to register
>but i don't want this situation appear,i want to set if userA is now connected the other user couldn't connect using same informations 
>thanksss
>
>
>
>
>
>
>
>________________________________
> From: Peter Olsson <peter.olsson at visionutveckling.se>
>To: 'FreeSWITCH Users Help' <freeswitch-users at lists.freeswitch.org> 
>Sent: Thursday, June 28, 2012 6:51 PM
>Subject: Re: [Freeswitch-users] multiple registerations coudln't worked correctly!
> 
>
>I still don’t understand.. :) How could UserA use UserB’s account? Aren’t you using different passwords for the user?
> 
>/Peter
> 
>Från:freeswitch-users-bounces at lists.freeswitch.org [mailto:freeswitch-users-bounces at lists.freeswitch.org] För Samira Mh
>Skickat: den 28 juni 2012 10:05
>Till: FreeSWITCH Users Help
>Ämne: Re: [Freeswitch-users] multiple registerations coudln't worked correctly!
> 
>i have implemented VODSL service using freeswitch,and create accounts for user on the server,but i don't want the userA use the account of userB,
>i want to restrict each user only use her/his account not able to use each other account that don't belong to his/her...
>also i don't want to restrict this using ip addresses ,want to limit using account
> 
>
>________________________________
> 
>From:Peter Olsson <peter.olsson at visionutveckling.se>
>To: FreeSWITCH Users Help <freeswitch-users at lists.freeswitch.org> 
>Sent: Thursday, June 28, 2012 9:44 AM
>Subject: Re: [Freeswitch-users] multiple registerations coudln't worked correctly!
>
>The option is to enable multiple-registrations, which will make both registrations work simultaneously.
>
>Why is this even a problem, what problem are you trying to solve?
>
>/Peter
>
>28 jun 2012 kl. 06:21 skrev "Samira Mh" <saami_mh at ymail.com<mailto:saami_mh at ymail.com>>:
>
>is there any solutions for the second registration couldn't overwrite the first one registeration ?
>
>
>________________________________
>From: Peter Olsson <peter.olsson at visionutveckling.se<mailto:peter.olsson at visionutveckling.se>>
>To: FreeSWITCH Users Help <freeswitch-users at lists.freeswitch.org<mailto:freeswitch-users at lists.freeswitch.org>>
>Sent: Wednesday, June 27, 2012 11:46 PM
>Subject: Re: [Freeswitch-users] multiple registerations coudln't worked correctly!
>
>If they end up with only one registration within FS it's just normal. Since the second registration will overwrite the first.
>
>/Peter
>________________________________
>Från: freeswitch-users-bounces at lists.freeswitch.org<mailto:freeswitch-users-bounces at lists.freeswitch.org> [freeswitch-users-bounces at lists.freeswitch.org<mailto:freeswitch-users-bounces at lists.freeswitch.org>] för Samira Mh [saami_mh at ymail.com<mailto:saami_mh at ymail.com>]
>Skickat: den 27 juni 2012 21:05
>Till: Free SWITCH Users Help
>Ämne: [Freeswitch-users] multiple registerations coudln't worked correctly!
>
>
>hi,
>i have set <param name="multiple-registrations" value="false"/> on internal.xml  and switch.conf.xml then
>restart freeswitch
>but I  could register 2 sip phones using the same extension number at the same time!
>but i want to only one extension could be register using the same extensions
>plz help
>
>
>_________________________________________________________________________
>Professional FreeSWITCH Consulting Services:
>consulting at freeswitch.org<mailto:consulting at freeswitch.org>
>http://www.freeswitchsolutions.com
>
>
>
>
>Official FreeSWITCH Sites
>http://www.freeswitch.org
>http://wiki.freeswitch.org
>http://www.cluecon.com
>
>Join Us At ClueCon - Aug 7-9, 2012
>
>FreeSWITCH-users mailing list
>FreeSWITCH-users at lists.freeswitch.org<mailto:FreeSWITCH-users at lists.freeswitch.org>
>http://lists.freeswitch.org/mailman/listinfo/freeswitch-users
>UNSUBSCRIBE:http://lists.freeswitch.org/mailman/options/freeswitch-users
>http://www.freeswitch.org<http://www.freeswitch.org/>
>
>
>
>_________________________________________________________________________
>Professional FreeSWITCH Consulting Services:
>consulting at freeswitch.org<mailto:consulting at freeswitch.org>
>http://www.freeswitchsolutions.com
>
>
>
>
>Official FreeSWITCH Sites
>http://www.freeswitch.org
>http://wiki.freeswitch.org
>http://www.cluecon.com
>
>Join Us At ClueCon - Aug 7-9, 2012
>
>FreeSWITCH-users mailing list
>FreeSWITCH-users at lists.freeswitch.org<mailto:FreeSWITCH-users at lists.freeswitch.org>
>http://lists.freeswitch.org/mailman/listinfo/freeswitch-users
>UNSUBSCRIBE:http://lists.freeswitch.org/mailman/options/freeswitch-users
>http://www.freeswitch.org
>
>
>!DSPAM:4febd86932764854317000!
>
>_________________________________________________________________________
>Professional FreeSWITCH Consulting Services:
>consulting at freeswitch.org
>http://www.freeswitchsolutions.com
>
>
>
>
>Official FreeSWITCH Sites
>http://www.freeswitch.org
>http://wiki.freeswitch.org
>http://www.cluecon.com
>
>Join Us At ClueCon - Aug 7-9, 2012
>
>FreeSWITCH-users mailing list
>FreeSWITCH-users at lists.freeswitch.org
>http://lists.freeswitch.org/mailman/listinfo/freeswitch-users
>UNSUBSCRIBE:http://lists.freeswitch.org/mailman/options/freeswitch-users
>http://www.freeswitch.org
>
>
>!DSPAM:4fec0eac32768939220457! 
>_________________________________________________________________________
>Professional FreeSWITCH Consulting Services:
>consulting at freeswitch.org
>http://www.freeswitchsolutions.com
>
>
>
>
>Official FreeSWITCH Sites
>http://www.freeswitch.org
>http://wiki.freeswitch.org
>http://www.cluecon.com
>
>Join Us At ClueCon - Aug 7-9, 2012
>
>FreeSWITCH-users mailing list
>FreeSWITCH-users at lists.freeswitch.org
>http://lists.freeswitch.org/mailman/listinfo/freeswitch-users
>UNSUBSCRIBE:http://lists.freeswitch.org/mailman/options/freeswitch-users
>http://www.freeswitch.org
>
>
>
>_________________________________________________________________________
>Professional FreeSWITCH Consulting Services:
>consulting at freeswitch.org
>http://www.freeswitchsolutions.com
>
>
>
>
>Official FreeSWITCH Sites
>http://www.freeswitch.org
>http://wiki.freeswitch.org
>http://www.cluecon.com
>
>Join Us At ClueCon - Aug 7-9, 2012
>
>FreeSWITCH-users mailing list
>FreeSWITCH-users at lists.freeswitch.org
>http://lists.freeswitch.org/mailman/listinfo/freeswitch-users
>UNSUBSCRIBE:http://lists.freeswitch.org/mailman/options/freeswitch-users
>http://www.freeswitch.org
>
>

_________________________________________________________________________
Professional FreeSWITCH Consulting Services:
consulting at freeswitch.org
http://www.freeswitchsolutions.com




Official FreeSWITCH Sites
http://www.freeswitch.org
http://wiki.freeswitch.org
http://www.cluecon.com

Join Us At ClueCon - Aug 7-9, 2012

FreeSWITCH-users mailing list
FreeSWITCH-users at lists.freeswitch.org
http://lists.freeswitch.org/mailman/listinfo/freeswitch-users
UNSUBSCRIBE:http://lists.freeswitch.org/mailman/options/freeswitch-users
http://www.freeswitch.org
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://lists.freeswitch.org/pipermail/freeswitch-users/attachments/20120628/07584303/attachment-0001.html 


Join us at ClueCon 2011 Aug 9-11, 2011
More information about the FreeSWITCH-users mailing list