Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Vista
Two attacks against VoIP
Peter Thermos

"We are more secure than a regular phone line."

Comments Mode:
Two attacks against VoIP 2006-04-06
Tobias Glemser (3 replies)
Re: Two attacks against VoIP 2006-04-06
Author (2 replies)
Re: Re: Two attacks against VoIP 2006-04-12
Tobias Glemser
Re: Re: Two attacks against VoIP 2006-04-16
Anonymous
Re: Two attacks against VoIP 2006-04-06
Anonymous (1 replies)
Re: Re: Two attacks against VoIP 2006-04-12
Tobias Glemser
Re: Two attacks against VoIP 2006-04-07
Roger (1 replies)
Re: Re: Two attacks against VoIP 2006-09-25
VoIP_Hacker
You are exactly correct on all accounts ...... MITM is an easy hack. I do it daily in hacking and product demonstrations.

One other note on VLAN's, they are for anything but security. It is a broadcast domain. There are many hacks out there to traverse VLAN's. Yersinia (a hacking app) allows you to hack layer 2 protocols. Pentration testing with this app allows VLAN hacking and VLAN hopping. Download and test app here: http://sourceforge.net/projects/yersinia

Furthermore, VLAN's do not protect against the many potential vulnerabilities introduced by the deployment of soft phones, which reside on the data VLAN, or other potential DoS attacks like floods related to the misconfiguration of hard phones or malicious attacks from inside the network. The significant security concerns for this type of deployment are mainly SIP/SCCP/H.323 call control and application level attacks including: DoS attacks from infected soft clients, Application level floods, Spoofing and impersonation, Theft of service, and Call state machine violations.

THe only way to protect VoIP is to properly authenticate and encrypt the protocols. The best solution is to scrub the data inline with a IPS device. That is what Sipera does -- The Sipera boxes are located in-line with the enterprise IP PBX, thus functioning as a gateway for each call server by monitoring all signaling traffic exchanged in the network. Since the majority of the concerns originate from soft clients running on PCs, Sipera also sit at the intersection of the VoIP and Data VLAN and monitor all signaling and media traffic as it passes between the two. Specific Sipera features that protect the network and end-users include: Source limiting for application level floods, Policy and signature-based filtering, Fingerprinting, Protocol anomaly filtering, and Behavior learning-based filtering. Sipera can be purchased at http://www.sipera.com.

[ reply ]

Link to this comment: http://www.securityfocus.com/comments/infocus/1862/693#693
Two attacks against VoIP 2006-04-06
Greg (1 replies)
Re: Two attacks against VoIP 2006-10-24
Wireless_VOIP
Two attacks against VoIP 2006-04-07
Peter Thermos
Two attacks against VoIP 2006-04-10
Anonymous
Two attacks against VoIP 2006-04-11
MidNet
Two attacks against VoIP 2006-11-09
Anonymous







 

Privacy Statement
Copyright 2008, SecurityFocus