Opened 3 years ago

Closed 2 years ago

#673 closed defect (fixed)

log of sent DTMF tones, AT+VTS=

Reported by: gurucubano Owned by: morphis
Priority: minor Milestone: cornucopia-0.11
Component: cornucopia/fsogsm Version: 0.9
Keywords: +VTS, security Cc:

Description

I was testing something and used a toll free number of my local bank
(because it is free and there is a voice and DTMF System menu to play
around)... I was suprised seeing lines like this in
/var/log/fsogsmd.log:

2012-04-08T11:49:59.395616Z [INFO] libfsotransport <0710:2>: SRC: "+VTS=#" -> [
+"OK" ]

The value of +VTS=x is the DTMF tone to send; the value x should not be logged,
at least not in the INFO level; keep in mind that such DTMF tones often
are used to send credentials, PIN or other secret information to the
other side of a call. While it is technically nearly imposible to
intercept them in the call, it is prety much easy to read them out of
the log files of a (stolen or lost) phone.

See also: http://trac.shr-project.org/trac/ticket/1922

Change History (5)

comment:1 Changed 3 years ago by morphis

  • Milestone set to 0.10
  • Version milestone5.5 deleted

comment:2 Changed 3 years ago by morphis

  • Version set to 0.9

comment:3 Changed 3 years ago by morphis

  • Milestone changed from 0.10 to 0.11

comment:4 Changed 3 years ago by morphis

  • Owner changed from mickey to morphis
  • Status changed from new to accepted

comment:5 Changed 2 years ago by morphis

  • Resolution set to fixed
  • Status changed from accepted to closed

Tested this and with todays libfsotransport everything is only printed in DEBUG log level. See below.

2012-05-04T12:17:24.469384Z [DEBUG] PhonesimModem <>: Created mediator FsoGsmCallSendDtmf
2012-05-04T12:17:24.469441Z [DEBUG] libfsotransport <127.0.0.1:3001 (fd 7)>: Attemping to write next command to transport; we have 1 commands pending!
2012-05-04T12:17:24.469466Z [DEBUG] libfsotransport <127.0.0.1:3001 (fd 7)>: Wrote '+VTS=1;+VTS=2;+VTS=3;+VTS=4'. Waiting (5s) for answer...
2012-05-04T12:17:24.469489Z [DEBUG] libfsotransport <127.0.0.1:3001 (fd 7)>: WriteCallback called with 31 bytes in buffer
2012-05-04T12:17:24.469536Z [DEBUG] libfsotransport <127.0.0.1:3001 (fd 7)>: WriteCallback wrote 31 bytes
2012-05-04T12:17:24.475257Z [DEBUG] libfsotransport <127.0.0.1:3001 (fd 7)>: SRC: "+VTS=1;+VTS=2;+VTS=3;+VTS=4" -> [ "OK" ]
Last edited 2 years ago by morphis (previous) (diff)
Note: See TracTickets for help on using tickets.