Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs
Two attacks against VoIP
Peter Thermos

"We are more secure than a regular phone line."

Submit Comment Mode:
Name:
Subject:
Message:
 
  Enter the characters that appear above
 
Re: Two attacks against VoIP 2006-04-07
Roger
" using a response value which is normally a MD5 Hash consisting of Username, Password, nonce, HTTP Request Method and Request URI.

This prevents the describend attacks."

Since the hash does not bind to any of the registration information, this offers no protection at all against a MITM attack...

[ more ]  





 

Privacy Statement
Copyright 2009, SecurityFocus