Vonage and Others were Warned about SIP ID Theft, Eavesdropping and Other Exploits

Source: snapvoip.blogspot.com

Sipera, the VoIP security firm that I saw first at BlackHat 2007 has warned VoIP firms before disclosing the vulnerabilities. There are multiple vulnerabilities, advisories and they are listed here.

The tests focused specifically of residential and SMB VoIP service and equipment. I was surprised to find strong authentication, signaling security, and media encryption were lacking, looks like everybody is following Microsoft. Get it Out there first and then we fix it as troubles jump up.

So what does these vulnerabilities do to users? spoofing, eavesdropping, and remote exploits are some of the possibilities.

I will write later today about what you should be looking in VoIP Security.

Following is the news release by Sipera;


Richardson, TX, October 23, 2007 – Sipera VIPER™ Lab, operated by Sipera Systems, the leader in comprehensive VoIP/UC security solutions, today disclosed multiple threat advisories for users of VoIP services and equipment from Vonage, Globe7 and Grandstream. Among other threats, unwitting VoIP users face eavesdropping, spam, spoofing and denial-of-service (DoS) attacks. Full details on these vulnerabilities are posted as an educational security service to Sipera’s customers and the general public at http://www.sipera.com/viper.

Sipera VIPER Lab determined the Vonage VoIP Motorola Phone Adapter (VT 2142-VD) and Vonage service implementations leave users vulnerable to a form of VoIP identity theft, allowing hackers to take over a user’s phone service with a “registration replay attack,” then make and receive calls while impersonating the victim. Incomplete security practices, such as not encrypting traffic, open Vonage users to eavesdropping on private voice and video communications. Hackers can also send multiple SIP INVITE messages to a user, an Internet version of “ringing the phone off the hook” which creates a DoS attack. Leveraging these vulnerabilities, remote attackers can also send malicious messages directly to Vonage users, subjecting them to spam, social engineering and VoIP scams.

“These vulnerabilities create serious privacy and service availability issues for users,” said Krishna Kurapati, Sipera founder/CTO and head of Sipera VIPER Lab. “Vonage, Globe7 and Grandstream customers can no longer assume that their VoIP providers are automatically securing their services, but they should demand best security practices be followed as a condition of becoming a customer. Sipera VIPER Lab will continue to proactively identify VoIP threats and assist VoIP providers to implement best security practices before attacks occur.”

Sipera VIPER Lab also found issues with European provider Globe7’s online account access, as a result of utilizing unsecured connections and employing a weak encryption scheme. This allows hackers to access confidential name, password and account balance data, as well as steal VoIP service to make and receive calls, masked as a legitimate Globe7 user. Likewise, Sipera VIPER Lab established the Grandstream HandyTone-488 PSTN-to-VoIP adapter is vulnerable to buffer overflows and fragmented packet attacks. By sending a specially crafted SIP INVITE message to public IP addresses, attackers can disconnect legitimate Grandstream users.

Sipera VIPER Lab is comprised of experienced VoIP security researchers operating globally 24/7/365. Since its inception in 2003, Sipera VIPER Lab has identified thousands of vulnerabilities and security threats which include fuzzing, floods and distributed floods, spoofing, stealth attacks and spam. VIPER Lab research is used to continuously improve the Sipera IPCS products that protect, control and enable real-time unified communications for enterprises and service providers. Sipera VIPER Lab also recently launched a blog to discuss ongoing VoIP attacks and VoIP/UC vulnerabilities at http://www.sipera.com/viper/blog.

Published on October 26th, 2007 under


Last 20 posts tagged "VoIP Security"

VoIP Security Examined

Source: www.voip-news.com

Do you remember when anti-virus was a sometimes thing, when people didn’t worry about impending hackings and attempts to steal or corrupt critical data? That’s sort of like VoIP’s stat…

Published on May 19th, 2008 under , , , , ,

The Dish on VoIP Security

Source: www.voip-news.com

Researchers are investigating the extent of the vulnerability of VoIP. Could voice spam be inserted? How can it be exploited?
PC World has a handy guide to security up. Here’s a snippet:
New…

Published on May 14th, 2008 under , , , ,

Over 100 Vulnerabilities in Leading Enterprise VoIP Systems Uncovered By VoIPshield

Source: snapvoip.blogspot.com

It was unbelievably shocking to see the vulnerability database and so many of them. Ignorance is a bliss until something bad happens to someone. Follow the link below to see the database of…

Published on April 3rd, 2008 under

New York Times Takes on VoIP Security

Source: www.voip-news.com

Ahhh, finally. I knew it had to happen sometime: the New York Times talking about VoIP (or more specifically, VoIP security).
So, what do they have to say about VoIP? Well, for starters, it is…

Published on April 3rd, 2008 under , , , , ,

Secure Skype IM With FaceTime Communications’ Greynet Enterprise Manager

Source: snapvoip.blogspot.com

BELMONT, CALIFORNIA - FaceTime Communications, the leading provider of solutions that control Internet and unified communications (UC) in [...]…

Published on March 27th, 2008 under ,

FBI VoIP Surveillance Docs

Source: snapvoip.blogspot.com

Slashdot has discussion on VoIP Surveillance focusing on FBI Electronic Surveillance Needs for Carrier-Grade Voice over Packet (CGVoP) Service. The 88 paged document, which is part of the CALEA…

Published on March 16th, 2008 under ,

Who Is Listening To Your VoIP Calls? (Unknown To You!)

Source: snapvoip.blogspot.com

quot;Who Might Be Spying on Your Communications? (Hint — It’s Not Just the NSA)", when I saw the title, I imagined a list of other government institutions and some phone companies…

Published on March 13th, 2008 under

VoIP News Tells You How To Secure Your VoIP Call

Source: snapvoip.blogspot.com

VoIP News has a "feature article" on VoIP Security. There are many VoIP Solutions for making VoIP calls but security that people used to get with (did we really?) is certainly diminished…

Published on February 24th, 2008 under ,

UM Labs Offering VoIP Security Launched By Peter Cox.

Source: snapvoip.blogspot.com

The creator of Proof of concept tool for VoIP Security that I wrote about a while ago, Peter Cox, together with Stuart Morrice has launched a new company UM Labs, to provide effective security…

Published on February 11th, 2008 under , ,

Vishing Attacks Are On The Rise, FBI Warns

Source: snapvoip.blogspot.com

The U.S. Federal Bureau of Investigation (FBI)’s Internet Crime Complaint Center (IC3) has issued a warning yesterday that so-called "vishing" attacks are on the rise. Vishing…

Published on January 18th, 2008 under ,

Top Five VoIP IP Telephony Vulnerabilities According To Sipera Viper Lab

Source: snapvoip.blogspot.com

Sipera VIPER Lab determined the Top 5 VoIP Vulnerabilities for 2007 were:
1) Remote eavesdropping of VoIP phone calls, a practice that is exponentially easier in VoIP than with traditional PSTN…

Published on December 12th, 2007 under

Secure Computing’s Sidewinder to Protect VoIP Communications At TeleCents Communications

Source: snapvoip.blogspot.com

Secure Computing Corporation (NASDAQ: SCUR), a leading enterprise gateway security company, today announced that TeleCents Communications has deployed Secure Computing Sidewinder® to provid…

Published on December 11th, 2007 under

Eavesdropping Is Possible On Cisco IP Phones

Source: snapvoip.blogspot.com

Cisco confirms that an attacker with valid Extension Mobility authentication credentials could cause a Cisco Unified IP Phone configured to use the Extension Mobility feature to transmit or receiv…

Published on November 30th, 2007 under

VoIP Security Education at ITEXPO East 2008

Source: snapvoip.blogspot.com

I have written about 100 posts related to VoIP Security. The latest (last week) being SIPtap (A Proof of Concept Tool), Taps into SIP Based VoIP Calls Records Them.A lot of sites have written…

Published on November 26th, 2007 under

SIPtap (A Proof of Concept Tool), Taps into SIP Based VoIP Calls Records Them.

Source: snapvoip.blogspot.com

I have mentioned security issues involving VoIP IP Telephony as close as few weeks ago as well as two years ago!Today I hear and see another side of it. Proof of concept of wire tapping and recording…

Published on November 22nd, 2007 under

VoIP Security Vulnerabilities to rise in 2008: McAfee

Source: snapvoip.blogspot.com

In McAfee’s predictions for 2008, McAfee Avert Labs Top 10 Threat Predictions for 2008has valuable information regarding over all security. Two of them relate to our industry and I hav…

Published on November 19th, 2007 under

Securing VoIP One More Way

Source: snapvoip.blogspot.com

From the article "Are VoIP systems prepared for attacks?" on SC magazine, I snipped the last of it, the advise. Although seems to be repeating the process of securing a any data network,…

Published on November 16th, 2007 under

VOIPSA: SIP Digest Access Authentication RELAY-ATTACK for Toll-Fraud

Source: snapvoip.blogspot.com

VOIPSA has posted a message on its VOIPSEC mailing list about "Breaking SIP for fun and toll fraud".From the mailing list;"In this post, we would like to inform abouta potentia…

Published on November 4th, 2007 under

VoIP and UC Best Practices Webinar

Source: snapvoip.blogspot.com

Security and managing threats are the last thing you want to consider when you are bringing up a Unified Communications (UC) project or Enterprise wide VoIP deployment. Because you would think…

Published on October 30th, 2007 under

Vonage and Others were Warned about SIP ID Theft, Eavesdropping and Other Exploits

Source: snapvoip.blogspot.com

Sipera, the VoIP security firm that I saw first at BlackHat 2007 has warned VoIP firms before disclosing the vulnerabilities. There are multiple vulnerabilities, advisories and they are listed…

Published on October 26th, 2007 under
Member of "Hype Media! Network"