Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Vista
Two attacks against VoIP
Peter Thermos

"We are more secure than a regular phone line."

Comments Mode:
Two attacks against VoIP 2006-04-06
Tobias Glemser (3 replies)
Re: Two attacks against VoIP 2006-04-06
Author (2 replies)
Re: Re: Two attacks against VoIP 2006-04-12
Tobias Glemser
"The comment "This is also false if we discuss an actual SIP-Proxy implementation." is based on ONE implementation which you have configured and tested in an isolated environment compared to testing 4 different commercial implementations in carrier and enterprise environments respectively."

Nope :) I've seen about 30 different implementations of various sizes all in productive environment. Only one has been very easy to break in using only a username, since no password was requested.

I agree, that there are implementations as you describe, but I don't know any _actual_ product, no matter if OS or commercial, which doesn't use "www-authentication". If there is one, you shouldn't download/buy :)

"The point is that in certain cases VoIP implementations should use encryption. Do you prefer using telnet to administer your environment or ssh, even if it is switched?"

Of course SSH. Of course I really would like to use SIP/S or RTP/s. But always when talking about an unsecure LAN environment or if crossing network borders.

But what about securing your LAN completely on Layer 2 and 3??

This would mean: Implement security one time and use you automatically would use it for any IP service!

[ reply ]

Link to this comment: http://www.securityfocus.com/comments/infocus/1862/529#529
Re: Re: Two attacks against VoIP 2006-04-16
Anonymous
Re: Two attacks against VoIP 2006-04-06
Anonymous (1 replies)
Re: Re: Two attacks against VoIP 2006-04-12
Tobias Glemser
Re: Two attacks against VoIP 2006-04-07
Roger (1 replies)
Re: Re: Two attacks against VoIP 2006-09-25
VoIP_Hacker
Two attacks against VoIP 2006-04-06
Greg (1 replies)
Re: Two attacks against VoIP 2006-10-24
Wireless_VOIP
Two attacks against VoIP 2006-04-07
Peter Thermos
Two attacks against VoIP 2006-04-10
Anonymous
Two attacks against VoIP 2006-04-11
MidNet
Two attacks against VoIP 2006-11-09
Anonymous







 

Privacy Statement
Copyright 2008, SecurityFocus