• On MovieTome: See the villain of IRON MAN 2!
September 26, 2008 3:12 PM PDT

VoIP system users can be targeted in attacks

by Robert Vamosi

Jason Ostrom of VoIP Hopper on Saturday plans to release his next-generation VoIP sniffer at Toorcon in San Diego to help raise awareness of the type of vulnerabilities businesses face as they adopt unified communications (UC) technology.

He told CNET News that the tool, UCSniff, has two settings. One is a learning mode, sniffing all the IP traffic then mapping telephone extensions to specific addresses. By default, it is capturing all the calls and saving them to wave files.

The other setting is a bit more creepy: targeting conversations. After learning the IP addresses of the phone system, someone using UCSniff can listen to all the VoIP, or voice over Internet Protocol, conversations made by a specific user, say the CEO. That's user mode. A second mode, conversation mode, allows someone to monitor calls made exclusively between two extensions, say only when the CEO calls the CFO.

"So it's like dynamic ARP poisoning," Ostrom explained, referring to Address Resolution Protocol spoofing. "The tool, on the fly, figures out how to do the ARP poisoning for you so you're not intercepting the traffic of phones that you do not want to intercept."

Ostrom, who now works for Sipera Systems, said the flaw, if any, is within the structure of the system and not specific to any platform, such as that of Cisco Systems. Two other, related tools are also set to be released by Ostrom on Saturday. Combined, the tools can allow one to create a man-in-the-middle attack on VoIP networks in an enterprise.

Some of the pieces are already available on the Internet, he said. However, UCSniff "brings together what is lacking, what is needed to be the most effective and secure VoIP security assessment tool available."

Ostrom's talk will be followed with a discussion of best practices for enterprises. "You can apply security controls to mitigate this vulnerability within your infrastructure and in how you design your network," he said.

As CNET's resident security expert, Robert Vamosi has been interviewed on the BBC, CNN, MSNBC, and other outlets to share his knowledge about the latest online threats and to offer advice on personal and corporate security. Listen to his podcast at securitybites.cnet.com or e-mail Robert with your questions and comments.
advertisement
Click here!
Recent posts from Security
Microsoft to fix holes in Windows, Office
Google privacy controls: Most people won't care
Zero-day flaw found in Web encryption
Mac Game: Art project or malware?
Corporate bank accounts targeted in online fraud
Hacker breaks into jailbroken iPhones, asks for $7
Malwarebytes accuses rival of software theft
Security firm M86 acquires Finjan
Add a Comment (Log in or register)
by 42istheanswer September 27, 2008 6:00 AM PDT
Whatever. If little weenies like this have nothing else better to do then I guess more power to them. Get a life, nerds. Can't you do anything more useful, like help old ladies across the road?
Reply to this comment
by pdombowsky September 27, 2008 3:44 PM PDT
This is nothing new - everyone knows that enterprise VoIP systems are insecure. And there has already been a tool (VoIPaudit) available for over two years now that does complete vulnerability assessments of enterprise Voice over IP networks including penetration testing, discovery and looks for vendor specific issues. It is available as a free download from VoIPshield.
Reply to this comment
advertisement

FAQ: Buying the right Windows 7 upgrade

Readers still have lots of questions on just which version of the software they need to buy in order to upgrade their PC. CNET News tries to offer some answers.

N.Y. lawsuit details Intel's 'largesse' toward Dell

Attorney General Andrew Cuomo's federal antitrust case filed Wednesday alleges a longstanding symbiotic relationship between Intel and Dell.

About Security

Online security is threatened by more than hacking and phishing attempts. Check here for the latest updates on software vulnerabilities, data leaks, and rapidly spreading viruses--and learn how to protect your systems.

Add this feed to your online news reader

Security topics

advertisement
advertisement

Inside CNET News

Scroll Left Scroll Right