
Nov. 11, 2009
3:49 p.m.
Lee Riemer wrote:
What's wrong with authenticating BYEs and CANCELs? I see them as just as important as an INVITE. Anyone can some around, sniff the dialog and spoof a BYE or CANCEL.
They'd have to spoof a Call-ID, From and To tags, correct CSeqs, any loose-routing parameters present in the Route and/or Record-Route headers, and the Route header itself. I suppose it *could* be done... but... -- Alex Balashov - Principal Evariste Systems Web : http://www.evaristesys.com/ Tel : (+1) (678) 954-0670 Direct : (+1) (678) 954-0671