Syndicate

VoIP in the News
NSA-Funded 'Cauldron' Tool Goes Commercial NSA tool 2009.05.27 Vulnerability Tool
Vulnerabilities in Microsoft Exchange Could Allow Remote Code Execution Critical flaws in Microsoft VoIP 2009.02.10 Vulnerability News
Hacked Business Owner Stuck With $52k Phone Bill. Business owner hacked 2008.12.19 Various Attacks
FBI warns of flawed Asterisk, Criminals exploiting. FBI warns of flawed Asterisk 2008.12.08 Security
FEMA phones hacked; calls made to Mideast, Asia FEMA hacked 2008.08.20 Various Attacks
Cyber Attack Hits Georgian President’s Phone Call with CNN Cyber Attack Hits Georgian President’s Phone Call 2008.08.11 Toll Fraud
IDC's latest study says that 30.9 million IP telephony lines shipped in 2007 IDC's annual update on VoIP market 2008.07.14 General News
Network World reports on VoIP vulnerability disclosures More VoIP Vulnerabilities disclosed 2008.06.26 Security
VoIP over Flash. Groundbreaking. Peer to peer from your browser, no longer some primitive applet proxying via a call server. VoIP over Flash 2008.05.18 General News
EDS Deploys 100,000 Cisco Unified IP Phones For Bank of America 100,000 Cisco IP Phones deployed 2008.05.15 General News
Cisco, Microsoft locked in battle for unified communications market Cisco vs. Microsoft No.2 2008.04.28 General News
Disaster recovery bug hangs up Cisco comms kit Cisco DRF has big issues 2008.04.07 Security

The Word: Cisco DRF is big deal.
THe DRF sub-system in the Cisco portfolio is a critical pice of the puzzle, the workaround for the solution absent the real patch is as follows: "Administrators can mitigate this vulnerability by disabling the DRF Master service. However, administrators should exercise caution when disabling the DRF Master service, as system backups will not occur while the service is stopped. Administrators are encouraged to perform a complete system backup before employing this workaround and use care when making configuration changes until the DRF Master service can be safely re-enabled." That is not really that feasible, thus patching should be immediate if not critical priority for any organization.


 
Wall Street Journal reports on VoIP vulnerability disclosures VoIP Vulnerabilities disclosed 2008.04.02 Security
Social Security Confirms Nortel Government Solutions for World’s Largest VoIP Nortel chosen by U.S. Social Security 2008.03.18 General News
Enterprise telephony market tops $9.6 billion in 2007 VoIP sales up in 2007 2008.02.28 General News
Researchers from GNUCitizen have released a proof-of-concept for hakcing into a phone via a web-interface and doing some nasty things. Total surveillance made easy with VoIP phones 2008.02.11 Hijacking, Eavesdropping Attack
Researchers from GNUCitizen have released a proof-of-concept for call-jacking via a BT Home Hub user's router. New VOIP 'Call-Jacking' Hack Unleashed 2008.01.23 Hijacking attack
Clearwire will be deploying Nortel's Application Server 5200 and Communication Server 2000 into its data centers to make itself VOIP capable. Clearwire breaks into VoIP market 2008.01.22 Service Providers
IETF is seeking comments on this document about requirements related to Session Border Controller (SBC) deployments SIP SBC Requirements 2007.12.21 RFC
Excellent Podcast about SIP NAT traversal SIP NAT traversal 2007.12.19 Podcast Interview
Microsoft vs. Cisco VoIP cold war 2007.12.17 General News

The Word: Microsft and Cisco are poised to go head-to-head in the coming years as the Unified communications market expands.
I personally think that Microsoft's approach offers many benefits over what Cisco can provide today. However, Microsoft is nowhere near ready to go head-to-head - yet. The question remains whether Cisco can quickly adapt to offset these advantages. As soon as Live Communicator becomes embedded with Vista Service Pack whatever, it is game over.


 
VoIP activity on the rise VoIP moving forward 2007.12.12 General News
Top 5 VoIP vulnerabilities of 2007 Sipera announces Top 5 2007.12.12 Security
VoIP on the iPod touch VoIP on iPod touch 2007.12.10 Consumer
Predicting Security threats for 2008 McAfee Cyber Crime 2007 Report 2007.11.30 Security
Wiretapping Just the Start of VoIP's Security Woes Wiretapping 2007.11.30 Security
VoIP is, in essence, a time bomb, poised for a massive exploit Time Bomb 2007.11.20 Security
Why VoIP is the next target for spammers SPIT is coming 2007.10.05 SPIT

Interview With A Convicted Hacker: Robert Moore Tells How He Broke Into Routers And Stole VoIP Services Interview with Roger Moore 2007.09.27 Hacker Interview

The Word: A clever hacker gets put into jail for exposing the irresponsability and ineptness of security at major service providers.
It is shamefull that Robert Moore, thee technical prime on the operation gets two years in jail; a sentence comparable to much greater crimes as we've seen. Ban the kid from the computers, keep the jail fro real criminals; his only crime to me is that he's exposed the irresponsability of service providers to protect their own infrastructure.
As Moore re-iterates, the absense of default password configured routers ans VoIP servers, the majority of their plan could not come to fruition. If the secuirty "gurus" at these service providers had any brains, they would have solved this problem in the pre-deployment network phase. Default password can be picked up with most opensourfce and commercial VoIP and data Vulnerability Assessement products. Let's just hope this turns on some lights in the security NOC's at the affected service providers. 


 
VoIP Hopping: A Method of Testing VoIP security or Voice VLANs SecurityFocus 2007.09.10 VoIP Hopping Attack

The Word: Simple yet elegant attack that easily breaks the "mighty" VLAN apart. People hide behind these VLAN's as if they are going to fix all their problems - bug mistake! VLAN's are only as strong as the weakest link in the overall infrastructure.
The VLAN hopping attack shows how a very simple exploit of the unauthenticated nature of Layer 2 protocols allows hackers to easily inject packets which are able to reach a forbidden section of the IP space in an enterprise. Amplifying the problme was the fact that a DHCP server was willingly giving out IP addresses to parties on the targetted corpsroate network, a secure solution would have defintiely implemtned static IP's with ACL's or an EAP authentication strategy if DHCP was a must.
In general, alot can be learned from this event: that VLAN's are only as strong as their configruation, that DHCP is dangerous if not properly managed and that hotel networks are no more safe than the next enteprrise network.
I congratulate the parties that publshied thier attack., howver it should be noted that this type of attack has been around for some time and proof of concept have been here even 5 years ago, bottom line is that this is not new! It is not some system ridden with holes because of its lack of maturity; VLAN technolgoy and security solutions built around them have been around for long time, security should be default - it is not. I strongly recommend anyone in charge of security of their Voice networks goes out and tries to hack them, do omsehting malicious and then show your complacents bosses the world of trouble they could be in with auditors.


 
Jericho Forum voices concerns over VoIP security ZDNet 2007.08.29 Eavesdropping Attack
IPhone Flaw Lets Hackers Take Over, Security Firm Says NY Times 2007.07.23 Hijacking Attack
Hackers stealing PBX phone minutes to on-sell cheap Computerworld 2007.07.18 Fraud Attack
Hacker Taps Cell Phone to Stalk Family FOXNews 2007.06.24 Hijacking, Eavesdropping Attack
Attackers get chatty on VoIP Infoworld 2007.05.30 Worms

VoIP-IRC bot VoIP-IRC bot 2007.05.08 DoS, VoIP Spam Attack

The Word: Easy to use bot that allows you to easily send SPIT, run DoS attacks and crack SIP suthentication passwords.
Using freely available java libraries, one could create similar and more complex bot type applications. What is most frightening is the fact that IRC is an underground haven for hackers and freelance "maeler's", the talent pool is exreme and most of these folks are very ambitious and take pride in their hacking endeavours. All this is good, but the main question remains how can we protect legitimate networks from these bots? I would suggest active VoIP specific protection products that are good at mitigating SPIT, DoS and VoIP specific vulnerabilities - data products would be higly unlikely to have any effect against VoIP bots.


 
New Trojan Calls On Skype Network World 2007.03.23 Virus
VoIP phreakers establish thriving black market The Register 2007.03.22 Fraud Attack
Spam Hits Video Sites Wall Street Journal 2007.03.15 Spam Attack
VoIP threats to watch out for Silicon.com 2007.03.09 Various Attacks
How to protect your business from VoIP threats SC Magazine 2007.02.19 Various Attacks
VoIP threat as crims seek out soft targets AustralianIT 2007.02.13 Various Attacks
Voice over IP under threat IT Observer 2007.01.05 Various Attacks
VOIP More Vulnerable Dark Reading 2006.12.21 Various Attacks
VOIP Risks Take Center Stage in 2007 Dark Reading 2006.12.20 Various Attacks
Worm may be spreading via Skype chat Infoworld 2006.12.19 Worm
Hackers ‘can eavesdrop on 70% of web calls’ Greatreporter.com 2006.12.17 Eavesdropping Attack
Ovum: Reduce VoIP Security Risks Before Further Deployment New Telephony 2006.11.15 Various Attacks
Unknown Threat, Real Risk: VoIP Security CXOtoday.com 2006.11.13 Various Attacks
PABX hackers rack up $9000 phone bill m-net 2006.10.18 Fraud Attacks
New VoIP threats to listen for Malaysia Star 2006.09.07 DoS, Hijacking, Eavesdropping Attacks
Possible Cisco Zero-day Exploit Revealed at Black Hat SearchSecurity.com/Information Security 2006.08.08 Black Hat Briefing
Another Look at VoIP Security Risks Top Tech News 2006.08.03 Black Hat Briefing
VOIP: With functionality comes risk GCN 2006.08.03 Black Hat Briefing
New tools test VoIP security ZDNet 2006.08.02 Black Hat Briefing
ISS Finds Bugs in Asterisk VoIP Software CIO 2006.07.17 DoS, DDoS Attack
Cisco Details New VoIP, Router Vulnerabilities InternetWeek 2006.07.12 DoS Attack
Keeping Hackers Off VoIP TheStreet.com 2006.06.26 Spam, Spoofing, DoS, DDoS Attack
Vodafone, Ericsson Get Hung Up In Greece's Phone-Tap Scandal Wall Street Journal 2006.06.21 Eavesdropping Attack
Cisco Call Manager Flaw Could Invite Hackers InformationWeek 2006.06.19 Hijacking Attack
Is Your VoIP Phone Vulnerable? Business Week 2006.06.13 Spam Attack
Big Security Flaws Found In Asterix PBX, IAX VoIP Client Networking Pipeline 2006.06.13 DoS Attack

Hacker cracked Net phone networks for gain, feds say TMCnet/York Times 2006.06.08 Reconnaisance, Spoofing Attack

The Word: Two hackers gain access to multiple service providers VoIP networks and re-selling 10 million dollars equivalent of VoIP service.
Not only does this event demonstrate how irresonsable the security "gurus" at the supposedly invincible ISP's are, it highlights the complacency of a large population of network security administrators who rely on technolgies such a firewall's to address VoIP security. Perimter defense is dead; firewall's provide little or no protection against the real bad guys; DoS attacks, SPIT, worms, trojans, etc. These type of attacks require application level aware devices which have expertise in VoIP protocols, behaviour and anomolies.
Technology is only half the battle, there has to be an effective human element that complements these products. Unfortunately, as we have seen theere is still much too learn inside the ISP NOC's. I suggest that they abandon they "we are big, we are smart, we cannot be hacked" mentaily and focus on the rapid changing landscape of VoIP security and its direction into the future.


 





Digg!Del.icio.us!Google!Facebook!Technorati!Newsvine!Free social bookmarking plugins and extensions for Joomla! websites!