Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Vista
VoIP hacks gut Caller I.D.
Kevin Poulsen, SecurityFocus 2004-07-06

Implementation quirks in Voice over IP are making it easy for hackers to spoof Caller I.D., and to unmask blocked numbers.

Comments Mode:
VoIP hacks gut Caller I.D. 2004-07-07
Anonymous (9 replies)
VoIP hacks gut Caller I.D. 2004-07-07
Anonymous
VoIP hacks gut Caller I.D. 2004-07-07
Anonymous
VoIP hacks gut Caller I.D. 2004-07-07
Anonymous
VoIP hacks gut Caller I.D. 2004-07-08
GuidoZ
VoIP hacks gut Caller I.D. 2004-07-08
Anonymous
VoIP hacks gut Caller I.D. 2004-07-10
Anonymous
VoIP hacks gut Caller I.D. 2004-07-12
Anonymous
VoIP hacks gut Caller I.D. 2004-07-12
Anonymous
VoIP hacks gut Caller I.D. 2004-07-07
Anonymous (12 replies)
VoIP hacks gut Caller I.D. 2004-07-07
Anonymous
VoIP hacks gut Caller I.D. 2004-07-07
Anonymous
VoIP hacks gut Caller I.D. 2004-07-07
Natas
VoIP hacks gut Caller I.D. 2004-07-07
Anonymous
VoIP hacks gut Caller I.D. 2004-07-07
Anonymous
VoIP hacks gut Caller I.D. 2004-07-07
Anonymous
VoIP hacks gut Caller I.D. 2004-07-08
Anonymous
VoIP hacks gut Caller I.D. 2004-07-08
Anonymous
VoicePulse and many other providers choose to do business by administratively locking down the configuration of the device used to get onto their network. The subscriber does not get to see the credentials; only pieces of it may be determined by doing a packet sniff, but digest authentication is used, so they cannot be determined directly (challenge/response). At least in the VoicePulse case (I'm a subscriber), the subscriber's PSTN DN does not figure into it at all; the userID is an opaque string. While I can't say with 100% certainty, I would say it's up to VP's Asterisk boxen to provide my CPN data to the PSTN based on my userID (a database lookup most likely). AFAIK, one cannot get onto VP's network unless one authenticates so. Therefore I'm not sure if it's even possible, unless there is some sort of buffer overflow or similar exploit in Asterisk that could be used to fake my CPN data.

As to whether private numbers are revealed to me, I can't readily determine. I do know that part of their service offering is to block anonymous callers. An optional subfeature of this is for their Asterisk to solicit and then pass on 10 digits entered by such callers. At that point of course they can tone in anything they'd like without any sort of validation.

[ reply ]

Link to this comment: http://www.securityfocus.com/comments/articles/9061/27412#27412
VoIP hacks gut Caller I.D. 2004-07-12
Anonymous
VoIP hacks gut Caller I.D. 2004-07-12
Anonymous
VoIP hacks gut Caller I.D. 2004-07-13
Anonymous
VoIP hacks gut Caller I.D. 2004-07-07
Anonymous
Carrier's Fault 2004-07-07
B Vincent (1 replies)
Re: Carrier's Fault 2006-04-19
Anonymous
VoIP hacks gut Caller I.D. 2004-07-07
Anonymous
VoIP hacks gut Caller I.D. 2004-07-07
Anonymous
VoIP hacks gut Caller I.D. 2004-07-07
Anonymous
VoIP hacks gut Caller I.D. 2004-07-07
Anonymous
VoIP hacks gut Caller I.D. 2004-07-07
Anonymous
VoIP hacks gut Caller I.D. 2004-07-08
Anonymous
VoIP hacks gut Caller I.D. 2004-07-08
Anonymous
VoIP hacks gut Caller I.D. 2004-07-08
Anonymous
VoIP hacks gut Caller I.D. 2004-07-09
Synfoe
VoIP hacks gut Caller I.D. 2004-07-09
Anonymous
VoIP hacks gut Caller I.D. 2004-07-09
Mr.Asus
VoIP hacks gut Caller I.D. 2004-07-09
Anonymous
Asterisk 2004-07-09
Anonymous
Caller id spoofing overview 2004-07-10
Anonymous
VoIP hacks gut Caller I.D. 2004-07-11
natas
VoIP hacks gut Caller I.D. 2004-07-11
a god of logic
VoIP hacks gut Caller I.D. 2004-07-13
Anonymous







 

Privacy Statement
Copyright 2007, SecurityFocus