Sign in

Sandro Gauci

@sandrogauci.bsky.social
34 followers 8 following 5 posts

Offensive VoIP/WebRTC security; mostly harmless Offensive VoIP/WebRTC security; mostly harmless enablesecurity.com/blog Chief Mischief Officer @enablesecurity savvycal.com/sandrogauci/pub

PostsRepliesMedia
Sandro Gauci @sandrogauci.bsky.social · 27/03/2026
Something we've wanted to build for a long time. VoIP/WebRTC security practice has needed a DVWA equivalent. DVRTC is our attempt at that. pbx1.dvrtc.net is live now. enablesecurity.com/blog/introducing-dvrtc-damn-vulnerable-real-time-communications/
pbx1.dvrtc.net
DVRTC - Damn Vulnerable Real-Time Communications
000
Sandro Gauci @sandrogauci.bsky.social · 25/02/2026
Published the "how to fix it" guides for TURN server security. Copy-paste coturn configs included. Also talking about this on WebRTC Live today: webrtc.ventures/webrtc-live/ enablesecurity.com/blog/turn-security-best-practices/
webrtc.ventures
WebRTC Live
Decision-makers and developers from around the world tune into WebRTC.ventures' monthly WebRTC Live broadcasts to learn about the latest use cases and technical updates for WebRTC and real-time commun...
012
Sandro Gauci @sandrogauci.bsky.social · 12/02/2026
Wrote up our RTCon 2025 talk on TURN security threats. www.enablesecurity.com/blog/turn-se...
enablesecurity.com
TURN Security Threats: A Hacker's View
TURN servers are powerful proxies abused for internal network access, C2 operations, and DDoS attacks. Threat analysis from years of research and pentesting.
022
Reposted by Sandro Gauci
enablesecurity.bsky.social @enablesecurity.bsky.social · 12/02/2026
TURN servers are meant to relay WebRTC media. To an attacker, they're just proxies. We wrote up the threats we've been finding since 2017: relay abuse, DoS amplification, and software vulns. www.enablesecurity.com/blog/turn-se...
enablesecurity.com
TURN Security Threats: A Hacker's View
TURN servers are powerful proxies abused for internal network access, C2 operations, and DDoS attacks. Threat analysis from years of research and pentesting.
023
Reposted by Sandro Gauci
Fred Posner @fred.tel · 30/11/2025
I know those of us in the US have had out minds focused on all things Turkey... but now it's time to remember that there are those that read what @sandrogauci.bsky.social / @enablesecurity.bsky.social writes, and those who wish they had. #security #rtc #voip www.enablesecurity.com/newsletter/2...
enablesecurity.com
November 2025: VoIP and WebRTC vulnerability roundup
November 2025 RTCSec newsletter: Cisco UCCX critical RCE, FreePBX command injection, Firefox WebRTC use-after-free, Jitsi OAuth hijacking, PJSIP buffer overflow, AudioCodes EOL vulnerabilities, and Mi...
021
Reposted by Sandro Gauci
Fred Posner @fred.tel · 31/10/2025
Monthly reminder that there are those who read what @sandrogauci.bsky.social / @enablesecurity.bsky.social writes, and those who wish they had. #security #rtc #voip www.enablesecurity.com/newsletter/2...
enablesecurity.com
October 2025: RTP attacks, Cisco VoIP phones, satellite leaks, and nation-state breaches
October 2025 RTCSec newsletter: RTP Bleed and Inject discussions, critical Cisco VoIP phone vulnerabilities, satellite communication leaks, Ribbon Communications breach, and comprehensive security upd...
011
Reposted by Sandro Gauci
enablesecurity.bsky.social @enablesecurity.bsky.social · 01/10/2025
Thanks @fred.tel ! This one covers: FreePBX troubles and fixes (CVE-2025-57819 + more) Voice-AI meets toll fraud 📞💸 RTP Bleed clarifications for DTLS-SRTP TURN security deep-dive + Qualcomm & Chrome WebRTC vulns
022
Reposted by Sandro Gauci
Fred Posner @fred.tel · 30/09/2025
End of the month which means it's time for me to link the @enablesecurity.bsky.social newsletter and say... "There are those who read what @sandrogauci.bsky.social writes... and those who wish they had." www.enablesecurity.com/newsletter/2...
enablesecurity.com
September 2025: more RTP, FreePBX and Voice AI vulnerabilities this time
September 2025 RTCSec newsletter: more RTP, FreePBX and Voice AI vulnerabilities this time
021
Reposted by Sandro Gauci
Fred Posner @fred.tel · 29/05/2025
The latest newsletter from @enablesecurity.bsky.social is out and as I always say... There are those who read what @sandrogauci.bsky.social writes, and those who wish they had. www.enablesecurity.com/newsletter/ (subscribe link right at the top) #voip #webrtc #sip #security #kamailio
enablesecurity.com
RTCSec Newsletter - a monthly newsletter about VoIP and WebRTC security
Curated VoIP and WebRTC security news, research and updates by Enable Security.
042
Reposted by Sandro Gauci
Fred Posner @fred.tel · 12/05/2025
There are those who listen to @sandrogauci.bsky.social / @enablesecurity.bsky.social and those that wish they had. #kamailioworld
011
Sandro Gauci @sandrogauci.bsky.social · 30/04/2025
Anyone who should subscribe, its here: www.enablesecurity.com/subscribe/
enablesecurity.com
Subscribe to RTCSec Newsletter & Updates
Subscribe to our monthly RTCSec Newsletter for curated VoIP and WebRTC security news, plus get notifications about new blog posts and research.
000