- What does Cisco have against Quebec?
- Attrition.org nails another nitwit
- Diary of a deliberately spammed housewife
- Seven cloud-computing security risks
- 20 great Windows open source projects
News | Newsletters | Podcasts | Chats | Opinions | RSS Feeds | This Week In Print | IT Careers | Community | Reports | Downloads | Slideshows | New Data Center
Partner Sites:App Performance | On Demand Security | Networking Solution | SOA | Value of WDS
New exploits against VoIP continue to emerge, but experts say these demonstrations reveal the need for vigilant security and are not fatal flaws to the technology.
At Black Hat this month researchers released hacking tools against VoIP signaling protocols H.323 and AIX as well as tools to insert audio into VoIP calls. At Defcon, a tool that automatically probes the Session Initiation Protocol for vulnerabilities was released to enable the covert piggy-backing of data over VoIP streams.
|
The problem lies not in VoIP technology but in its implementation, says Barrie Dempster, a senior security consultant for Next Generation Security Software. “If you apply traditional network security logic to VoIP you can make it as secure as any other protocol,” he says.
VoIP notoriety
Much of the notoriety of VoIP vulnerabilities come because the technology is relatively new and its code wasn’t necessarily written with security in mind — a problem that plagues many new technologies.
Dempster cites ways to exploit Asterisk, the open source PBX, including buffer overflows. He says this and other weaknesses can be dealt with by removing the code for unused features and performing security audits on the features that are used. “The problem is not the specific vulnerabilities themselves. It’s the maturity of the software. There hasn’t been enough security review yet,” he says.
The problem is well recognized, and known exploits are publicized to help develop defenses against them. For example, the industry group VoIP Security Alliance publishes a set of hacking tools on its site that it promotes as security tools to test that VoIP gear can withstand real-world attacks.
IBM spent all that money on a mass rollout of PGP Whole Disk Encryption, just when its discovered that...- Anonymous
Comments (1)
RE: VoIP requires strict attention to security best practicesBy ranganath on August 18, 2007, 11:03 amthat was a good update
Reply | Read entire comment
View all comments