Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Vista
Two attacks against VoIP
Peter Thermos

"We are more secure than a regular phone line."

Comments Mode:
Two attacks against VoIP 2006-04-06
Tobias Glemser (3 replies)
Re: Two attacks against VoIP 2006-04-06
Author (2 replies)
The two fundamental messages of the article are the fact that there are VoIP Service providers who misconceive VoIP security and the fact that there is a gap between the standards and products when it comes to supporting certain security features.

The comment "This is also false if we discuss an actual SIP-Proxy implementation." is based on ONE implementation which you have configured and tested in an isolated environment compared to testing 4 different commercial implementations in carrier and enterprise environments respectively. Vulnerabilities vary from one environment to the other. The attacks mentioned in this article have been demonstrated in production environments (including message replay of registrations).

The comment on "BUT: Any other service using IP is also "vulnerable"! This is NOT a VoIP-Problem in the first row if ARP-Poisoning is possible. This is a problem of your LAN-implementation."

The point is that in certain cases VoIP implementations should use encryption. Do you prefer using telnet to administer your environment or ssh, even if it is switched?

PS:

I appreciate that you took the time to read the article and provide feedback.

[ reply ]

Link to this comment: http://www.securityfocus.com/comments/infocus/1862/509#509
Re: Re: Two attacks against VoIP 2006-04-12
Tobias Glemser
Re: Re: Two attacks against VoIP 2006-04-16
Anonymous
Re: Two attacks against VoIP 2006-04-06
Anonymous (1 replies)
Re: Re: Two attacks against VoIP 2006-04-12
Tobias Glemser
Re: Two attacks against VoIP 2006-04-07
Roger (1 replies)
Re: Re: Two attacks against VoIP 2006-09-25
VoIP_Hacker
Two attacks against VoIP 2006-04-06
Greg (1 replies)
Re: Two attacks against VoIP 2006-10-24
Wireless_VOIP
Two attacks against VoIP 2006-04-07
Peter Thermos
Two attacks against VoIP 2006-04-10
Anonymous
Two attacks against VoIP 2006-04-11
MidNet
Two attacks against VoIP 2006-11-09
Anonymous







 

Privacy Statement
Copyright 2008, SecurityFocus