Přístupnostní navigace
E-application
Search Search Close
Bachelor's Thesis
Author of thesis: Bc. Kryštof Vyplel
Acad. year: 2025/2026
Supervisor: doc. Ing. Pavel Šilhavý, Ph.D.
Reviewer: Ing. Radim Číž, Ph.D.
This bachelor thesis deals with security threats in open-source PBX systems, with a focus on PBX Asterisk. The aim of the thesis is to analyse security-relevant network-accessible parts of PBX Asterisk, propose a procedure for security testing of a VoIP PBX, and implement selected laboratory scenarios in an isolated environment. The theoretical part defines the security aspects of VoIP and PBX systems, especially from the perspective of confidentiality, integrity, and availability. It also describes the network-accessible parts of Asterisk, the importance of SIP/PJSIP and IAX2 protocols, and the role of the dialplan, configuration, endpoints, and management interfaces. The practical part focuses on the design of a laboratory environment, the selection of suitable tools, the reconnaissance of available services, the analysis of a vulnerability database, and the implementation of five scenarios related to service availability, access control, identity spoofing, and the processing of non-standard inputs. The result of the thesis is a practically oriented procedure for security verification of PBX Asterisk, a categorisation of vulnerabilities based on their impacts and methods of exploitation, and a laboratory assignment composed of five scenarios suitable for teaching cybersecurity and computer networking.
PBX Asterisk; VoIP; security threats; penetration testing; SIP/PJSIP; IAX2; vulnerabilities; service availability; identity spoofing; laboratory scenarios
Date of defence
16.06.2026
Result of the defence
Defended (thesis was successfully defended)
Grading
C
Process of defence
Otázky oponenta: Ve scénáři SC 02 popisujete zranitelnost CVE-2024-35190, kdy je neautorizovaný požadavek chybně přiřazen k důvěryhodnému endpointu local_asterisk. Vysvětlete mechanismus, jakým k tomuto chybnému ztotožnění dochází, a jaké konkrétní konfigurační parametry v PJSIP by měly být nastaveny, aby se tomuto riziku v produkci předešlo. Scénář SC 04 demonstruje pád systému při zpracování SIP hlavičky funkcí PJSIP_HEADER. Jakým způsobem by měl tvůrce dialplanu správně ošetřovat a validovat proměnné přebírané z vnější signalizace, aby eliminoval riziko paměťových chyb u zranitelných verzí systému? Student prezentoval výsledky své práce a komise byla seznámena s posudky. Student obhájil bakalářskou práci s výhradami a odpověděl na otázky členů komise a oponenta.
Language of thesis
Czech
Faculty
Fakulta elektrotechniky a komunikačních technologií
Department
Department of Telecommunications
Study programme
Information Security (BPC-IBE)
Composition of Committee
doc. Ing. Jiří Hošek, Ph.D. (předseda) doc. Ing. Petr Sysel, Ph.D. (místopředseda) Mgr. Andrej Krištofík, Ph.D. (člen) Ing. Martin Štůsek, Ph.D. (člen) Ing. Radek Možný, Ph.D. (člen) Ing. Michal Lares, Ph.D. (člen) Ing. Patrik Dobiáš (člen)
Supervisor’s reportdoc. Ing. Pavel Šilhavý, Ph.D.
Grade proposed by supervisor: C
Reviewer’s reportIng. Radim Číž, Ph.D.
Grade proposed by reviewer: C
Responsibility: Mgr. et Mgr. Hana Odstrčilová