PBX Vulnerability Analysis: Finding Holes in Your PBX Before Someone Else Does (NIST SP 800-24 Aug 2000)
This publication is issued by the National Institute of Standards and Technology as part of its program to promulgate security standards for information systems as well as standards for test procedures for assessing the level of conformance to these standards. This document is intended for use primarily by system administrators of PBX systems, but may also be useful for security evaluators. Where possible, countermeasures are described that can be applied by system administrators. In some cases vulnerabilities may be discovered that require software patches from the manufacturer.
Download the NIST SP 800-24 here.



