"We are more secure than a regular phone line."
Expand all |
Post comment
Two attacks against VoIP
2006-04-06
Tobias Glemser (3 replies)
Tobias Glemser (3 replies)
|
Two attacks against VoIP
"We are more secure than a regular phone line."
Expand all |
Post comment
Two attacks against VoIP
2006-04-06 Tobias Glemser (3 replies) |
|
|
Privacy Statement |
The comment "This is also false if we discuss an actual SIP-Proxy implementation." is based on ONE implementation which you have configured and tested in an isolated environment compared to testing 4 different commercial implementations in carrier and enterprise environments respectively. Vulnerabilities vary from one environment to the other. The attacks mentioned in this article have been demonstrated in production environments (including message replay of registrations).
The comment on "BUT: Any other service using IP is also "vulnerable"! This is NOT a VoIP-Problem in the first row if ARP-Poisoning is possible. This is a problem of your LAN-implementation."
The point is that in certain cases VoIP implementations should use encryption. Do you prefer using telnet to administer your environment or ssh, even if it is switched?
PS:
I appreciate that you took the time to read the article and provide feedback.
[ reply ]
Link to this comment: http://www.securityfocus.com/comments/infocus/1862/509#509