Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs
Two attacks against VoIP
Peter Thermos

"We are more secure than a regular phone line."

Comments Mode:
Two attacks against VoIP 2006-04-06
Tobias Glemser (3 replies)
Re: Two attacks against VoIP 2006-04-06
Author (2 replies)
Re: Re: Two attacks against VoIP 2006-04-12
Tobias Glemser
Re: Re: Two attacks against VoIP 2006-04-16
Anonymous
Re: Two attacks against VoIP 2006-04-06
Anonymous (1 replies)
Re: Re: Two attacks against VoIP 2006-04-12
Tobias Glemser
Re: Two attacks against VoIP 2006-04-07
Roger (1 replies)
Re: Re: Two attacks against VoIP 2006-09-25
VoIP_Hacker
Two attacks against VoIP 2006-04-06
Greg (2 replies)
Re: Two attacks against VoIP 2006-10-24
Wireless_VOIP
Re: Two attacks against VoIP 2009-01-19
Anonymous
Two attacks against VoIP 2006-04-07
Peter Thermos
The underlying message of article wasn't really about the attacks. The desription of the attacks serve as an introductory reference for readers that don't share the same background as some of us do, especially in VoIP Security. There are many more issues associated with NGN/VoIP (and generaly Internet Multimedia Applications) security that don't fit a 3 page write up.

The two underlying messages are :

a) There is a gap between IETF standards and product implementations when it comes to security controls. But vendors and service providers choose not to implement them.

b) VoIP Service providers (there is a hint for one in this paper) don't seem to understand the security issues associated with VoIP. The quote "we are more secure than a phone line" is based on an official response from a VoIP service provider's "Tier 2" support ! In fact their CEO stated the same thing on a news announcement a few months ago.

Furthermore the attacks are from actual deployments (notice the plural) not an isolated custom Asterisk installation in a lab.

Regards,

Peter

[ reply ]

Link to this comment: http://www.securityfocus.com/comments/infocus/1862/519#519
Two attacks against VoIP 2006-04-10
Anonymous
Two attacks against VoIP 2006-04-11
MidNet
Two attacks against VoIP 2006-11-09
Anonymous







 

Privacy Statement
Copyright 2009, SecurityFocus