Enable Security GmbH published findings from coturn's August advisory batch, including DTLS state exhaustion worse than reported, source spoofing unnecessary, and one host doing it.
Published
Signal category
Research & Knowledge
Quote
“What we found reproducing coturn's August advisory batch. The DTLS state exhaustion is worse than its report suggested, since source spoofing turns out to be unnecessary and one host can do it.”
— Enable Security GmbH team
Company
Enable Security GmbH
Offensive security tools and quality penetration testing to help protect your real-time communications systems.
- Industry
- Information Technology & Services
- Location
- Passau, DE
- Company size
- 2 employees
Enable Security provides offensive security tools and services, including Penetration Testing, to help clients create secure Real-time Communications (RTC) systems. Our clients are able to measure the robustness of their RTC security consistently and observe significant improvement in the robustness of their system. Founded back in 2008 by Sandro Gauci, Enable Security has been providing high quality security testing and penetration testing services covering phone systems, web applications, network infrastructure, wireless and various other attack targets. Enable Security GmbH was incorporated in December 2015, with its head-quarters based in Germany from where it operates as a distributed, remote company. The team at Enable Security takes a creative, manual approach, building their own security tools and taking the course of thinking like an attacker. This gives Enable Security the cutting edge in discovering and reporting vulnerabilities that conventional scanning tools or generic pentesting cannot find. The team behind Enable Security has extensive industry experience and expertise in the field of IT security. It now focuses its efforts in the area that its team is most passionate about: Real-Time Communications (RTC) security, including VoIP and WebRTC infrastructure. Follow our blog at https://www.rtcsec.com
Founded 2008