Is the SBC vulnerable to attacks in known ports?
Hello everybody,
Hope you're doing allright,
Recently a customer asked if the SBC, with a sip-interface listening SIP in the 80 TCP port, would be vulnerable to non-sip related attacks in such interface or if the sbc would be capable of blocking/ignoring these unwanted interactions from maliscious sources.
Do you guys believe the SD would block or this could be a potential threat (e.g. potentential cpu impact)?
I don't think that setting up a known port for a sip-interface would be the best idea and wouldn't recommend it.
Regarding the non sip attacks, I would say that the sbc would not respond to this traffic in the application layer, but I'm not sure abut the transport layer, I mean, it's still TCP the protocol (and the port) the SBC is using and so is the potential attack. Is the SBC capable of ignore this traffic at this level (transport)?,