Over 100 Vulnerabilities in Leading Enterprise VoIP Systems Uncovered By VoIPshield

Source: snapvoip.blogspot.com

It was unbelievably shocking to see the vulnerability database and so many of them. Ignorance is a bliss until something bad happens to someone. Follow the link below to see the database of vulnerabilities and related equipment. Yours might be there. At VoIPshield, you can also download a copy of VoIPauditLite.VoIPauditLiteTM is a basic version of the award winning VoIPauditTM Enterprise. It provides the same vulnerability assessment and penetration testing functions, and is intended to give the prospective VoIPaudit Enterprise purchaser a no cost introduction to the product. VoIPauditLite is a single-user license, includes vulnerabilities for a single vendor, and scans up to 128 targets on a single network.

Ottawa, Ontario (April 2, 2008) – VoIPshield Laboratories, the research division of VoIPshield Systems Inc., today announced it has discovered over 100 security vulnerabilities in Voice over IP systems marketed by Avaya, Cisco and Nortel.A vulnerability is a design or implementation flaw in a VoIP system that can be exploited by a hacker with malicious intentions, including extortion through service outage threats, industrial espionage through call recording, or identity theft through the stealing of sensitive customer information.

VoIPshield notified the vendors of its findings earlier this year. Under the terms of its Responsible Disclosure Policy, VoIPshield works with the vendors to help them recreate the vulnerabilities in their own test labs, and offers its services to assist the vendors in determining the best remediation approach.

“It is important that companies understand the security risks associated with their VoIP systems”, said Rick Dalmazzi, president and CEO of VoIPshield. “Now is the time to start planning a protection strategy, while the hacking community is still learning about VoIP, not after the attacks begin.”

The vulnerabilities are cataloged and presented on the company’s website at www.voipshield.com/research .Each vulnerability is categorized based on an exploit’s most likely malicious intent:unauthorized access, code execution, denial of service or information harvesting. Each is also given a severity rating based on a modified industry standard index. Vendor responses are also included, indicating what action if any the vendor has indicated they will take to remediate the vulnerability, and when.

“The limited number of high-profile attacks against IP telephony has lulled most chief information security officers and voice/data managers into a false sense of security, with the result that most do not have adequate protection for their converged networks,” said Lawrence Orans, research director for networking and communications equipment at Gartner Research. “As IP telephony continues to gain momentum, targeted attacks — and possibly broad-based attacks — will surface and gain greater visibility, highlighting vulnerabilities and the overall lack of focus on IP telephony security.”

The database marks the first of ongoing announcements that VoIPshield Labs will make as it continues its research into these and other vendors’ products. Avaya, Cisco and Nortel were chosen for the initial round of research because of their popularity in the North American market.Microsoft has recently announced its entry into the enterprise VoIP market.

Just this month, communications research firm In-Stat revealed that while 80% of companies said they’d deployed some type of VoIP solution, more than 40% do not have specific plans for securing them. This finding, based on a survey of U.S. companies conducted in September 2007, was published in a report titled U.S. Businesses Lag in Securing VoIP. “Regardless of the VoIP solution that is in place or planned, security should be an integral part of an implementation from the beginning,” the report summarized.

The vulnerabilities discovered are used by VoIPshield to create signatures for its enterprise VoIP security solutions:VoIPauditTM, a VoIP Vulnerability Assessment system, and VoIPguardTM, a VoIP Intrusion Prevention System (VIPS).Users are protected against attacks attempting to exploit the known vulnerabilities. VoIPshield products are regularly updated with new signatures through the VoIPshield UpdateTM subscription service.

"Digital video and voice enabled by Voice over IP technologies are vital to commerce and are substantially at risk", said Jonathan Zar, chairman of the threat taxonomy committee of the Voice over IP Security Alliance (VoIPSA). It is important that products be developed that are specifically designed to protect VoIP systems. VoIPSA encourages all research leading to such products."

For more information about the vulnerabilities database and VoIPshield’s products visit www.voipshield.com/research.

Published on April 3rd, 2008 under


Last 20 posts tagged "VoIP Security"

Over 100 Vulnerabilities in Leading Enterprise VoIP Systems Uncovered By VoIPshield

Source: snapvoip.blogspot.com

It was unbelievably shocking to see the vulnerability database and so many of them. Ignorance is a bliss until something bad happens to someone. Follow the link below to see the database of…

Published on April 3rd, 2008 under

Secure Skype IM With FaceTime Communications’ Greynet Enterprise Manager

Source: snapvoip.blogspot.com

BELMONT, CALIFORNIA - FaceTime Communications, the leading provider of solutions that control Internet and unified communications (UC) in [...]…

Published on March 27th, 2008 under ,

FBI VoIP Surveillance Docs

Source: snapvoip.blogspot.com

Slashdot has discussion on VoIP Surveillance focusing on FBI Electronic Surveillance Needs for Carrier-Grade Voice over Packet (CGVoP) Service. The 88 paged document, which is part of the CALEA…

Published on March 16th, 2008 under ,

Who Is Listening To Your VoIP Calls? (Unknown To You!)

Source: snapvoip.blogspot.com

quot;Who Might Be Spying on Your Communications? (Hint — It’s Not Just the NSA)", when I saw the title, I imagined a list of other government institutions and some phone companies…

Published on March 13th, 2008 under

VoIP News Tells You How To Secure Your VoIP Call

Source: snapvoip.blogspot.com

VoIP News has a "feature article" on VoIP Security. There are many VoIP Solutions for making VoIP calls but security that people used to get with (did we really?) is certainly diminished…

Published on February 24th, 2008 under ,

UM Labs Offering VoIP Security Launched By Peter Cox.

Source: snapvoip.blogspot.com

The creator of Proof of concept tool for VoIP Security that I wrote about a while ago, Peter Cox, together with Stuart Morrice has launched a new company UM Labs, to provide effective security…

Published on February 11th, 2008 under , ,

Vishing Attacks Are On The Rise, FBI Warns

Source: snapvoip.blogspot.com

The U.S. Federal Bureau of Investigation (FBI)’s Internet Crime Complaint Center (IC3) has issued a warning yesterday that so-called "vishing" attacks are on the rise. Vishing…

Published on January 18th, 2008 under ,

Top Five VoIP IP Telephony Vulnerabilities According To Sipera Viper Lab

Source: snapvoip.blogspot.com

Sipera VIPER Lab determined the Top 5 VoIP Vulnerabilities for 2007 were:
1) Remote eavesdropping of VoIP phone calls, a practice that is exponentially easier in VoIP than with traditional PSTN…

Published on December 12th, 2007 under

Secure Computing’s Sidewinder to Protect VoIP Communications At TeleCents Communications

Source: snapvoip.blogspot.com

Secure Computing Corporation (NASDAQ: SCUR), a leading enterprise gateway security company, today announced that TeleCents Communications has deployed Secure Computing Sidewinder® to provid…

Published on December 11th, 2007 under

Eavesdropping Is Possible On Cisco IP Phones

Source: snapvoip.blogspot.com

Cisco confirms that an attacker with valid Extension Mobility authentication credentials could cause a Cisco Unified IP Phone configured to use the Extension Mobility feature to transmit or receiv…

Published on November 30th, 2007 under

VoIP Security Education at ITEXPO East 2008

Source: snapvoip.blogspot.com

I have written about 100 posts related to VoIP Security. The latest (last week) being SIPtap (A Proof of Concept Tool), Taps into SIP Based VoIP Calls Records Them.A lot of sites have written…

Published on November 26th, 2007 under

SIPtap (A Proof of Concept Tool), Taps into SIP Based VoIP Calls Records Them.

Source: snapvoip.blogspot.com

I have mentioned security issues involving VoIP IP Telephony as close as few weeks ago as well as two years ago!Today I hear and see another side of it. Proof of concept of wire tapping and recording…

Published on November 22nd, 2007 under

VoIP Security Vulnerabilities to rise in 2008: McAfee

Source: snapvoip.blogspot.com

In McAfee’s predictions for 2008, McAfee Avert Labs Top 10 Threat Predictions for 2008has valuable information regarding over all security. Two of them relate to our industry and I hav…

Published on November 19th, 2007 under

Securing VoIP One More Way

Source: snapvoip.blogspot.com

From the article "Are VoIP systems prepared for attacks?" on SC magazine, I snipped the last of it, the advise. Although seems to be repeating the process of securing a any data network,…

Published on November 16th, 2007 under

VOIPSA: SIP Digest Access Authentication RELAY-ATTACK for Toll-Fraud

Source: snapvoip.blogspot.com

VOIPSA has posted a message on its VOIPSEC mailing list about "Breaking SIP for fun and toll fraud".From the mailing list;"In this post, we would like to inform abouta potentia…

Published on November 4th, 2007 under

VoIP and UC Best Practices Webinar

Source: snapvoip.blogspot.com

Security and managing threats are the last thing you want to consider when you are bringing up a Unified Communications (UC) project or Enterprise wide VoIP deployment. Because you would think…

Published on October 30th, 2007 under

Vonage and Others were Warned about SIP ID Theft, Eavesdropping and Other Exploits

Source: snapvoip.blogspot.com

Sipera, the VoIP security firm that I saw first at BlackHat 2007 has warned VoIP firms before disclosing the vulnerabilities. There are multiple vulnerabilities, advisories and they are listed…

Published on October 26th, 2007 under

SIP XSS attacks and Spam Over Skype (SOS), they come in pairs.

Source: snapvoip.blogspot.com

There are many a ways that hackers (Malicious ones) used to get on your PC or PCs. Now they have one more way to get on your PC and steal valuable information.
There are two warnings by two…

Published on October 19th, 2007 under

Watch out! Drive by Pharming targets Broadband users.

Source: snapvoip.blogspot.com

Geemodo reports about a new threat to broadband users. Drive by Pharming is the word!Geemodo: Drive by Pharming targets Broadband users…

Published on October 19th, 2007 under ,

Not so bright VoIP Hacker goes to Prison

Source: snapvoip.blogspot.com

Convicted hacker Robert Moore, who is set to go to federal prison this week, says breaking into 15 telecommunications companies and hundreds of businesses worldwide was incredibly easy becaus…

Published on September 27th, 2007 under
Member of "Hype Media! Network"