<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>WireChatter.com &#187; Security</title>
	<atom:link href="http://www.wirechatter.com/category/security/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.wirechatter.com</link>
	<description>All you wanted to know about VoIP, SIP trunks and more</description>
	<lastBuildDate>Tue, 31 Jan 2012 00:21:43 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>VoIP Security &#8211; Dan York, The Black Bag Security Review</title>
		<link>http://www.wirechatter.com/voip-security-dan-york-the-black-bag-security-review/</link>
		<comments>http://www.wirechatter.com/voip-security-dan-york-the-black-bag-security-review/#comments</comments>
		<pubDate>Mon, 02 Mar 2009 14:00:50 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[VoIP]]></category>
		<category><![CDATA[Black Bag Security Review]]></category>
		<category><![CDATA[Dan York]]></category>

		<guid isPermaLink="false">http://www.wirechatter.com/?p=17</guid>
		<description><![CDATA[Dan York gives a great Podcast (delivered here in a powerpoint presentation) about VoIP Security. It is an enjoyable anecdotal talk, where he sets up a story and tells the pitfalls that can begall an unsuspecting &#8216;sysadmin steve&#8217; who inherits a VoIP system. Really, the intent here is that there are a number of potential <a href='http://www.wirechatter.com/voip-security-dan-york-the-black-bag-security-review/'>[...]</a>]]></description>
			<content:encoded><![CDATA[<p>Dan York gives a great Podcast (delivered here in a powerpoint presentation) about <a class="zem_slink" title="Voice over Internet Protocol" rel="wikipedia" href="http://en.wikipedia.org/wiki/Voice_over_Internet_Protocol">VoIP</a> Security. It is an enjoyable anecdotal talk, where he sets up a story and tells the pitfalls that can begall an unsuspecting &#8216;sysadmin steve&#8217; who inherits a VoIP system. Really, the intent here is that there are a number of potential security holes in VoIP that at the very least you need to be aware of. If your phone calls and what  you say don&#8217;t need to be &#8216;private&#8217; then you probably don&#8217;t need to worry too much! <img src='http://www.wirechatter.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<div id="__ss_27314" style="width: 425px; text-align: left;"><object width="425" height="355" data="http://static.slideshare.net/swf/ssplayer2.swf?doc=etel2007-the-black-bag-security-review-voip-security-22929" type="application/x-shockwave-flash"><param name="allowFullScreen" value="true" /><param name="allowScriptAccess" value="always" /><param name="src" value="http://static.slideshare.net/swf/ssplayer2.swf?doc=etel2007-the-black-bag-security-review-voip-security-22929" /><param name="allowfullscreen" value="true" /></object> </p>
<div style="font-size: 11px; font-family: tahoma,arial; height: 26px; padding-top: 2px;"><a href="http://www.slideshare.net/?src=embed"><img style="border:0px none;margin-bottom:-5px" src="http://static.slideshare.net/swf/logo_embd.png" alt="SlideShare" /></a> | <a title="View this slideshow on SlideShare" href="undefined">View</a> | <a href="http://www.slideshare.net/upload">Upload your own</a></div>
</div>
<div class="zemanta-pixie" style="margin-top: 10px; height: 15px;"><a class="zemanta-pixie-a" title="Zemified by Zemanta" href="http://reblog.zemanta.com/zemified/9b61a569-db26-4ac1-b0e8-e1aa8b9acfbb/"><img class="zemanta-pixie-img" style="border: none; float: right;" src="http://img.zemanta.com/reblog_e.png?x-id=9b61a569-db26-4ac1-b0e8-e1aa8b9acfbb" alt="Reblog this post [with Zemanta]" /></a><span class="zem-script more-related"><script src="http://static.zemanta.com/readside/loader.js" type="text/javascript"></script></span></div>
]]></content:encoded>
			<wfw:commentRss>http://www.wirechatter.com/voip-security-dan-york-the-black-bag-security-review/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Basic VoIP security threat tutorial, ARP poisoning</title>
		<link>http://www.wirechatter.com/basic-voip-security-threat-tutorial-arp-poisoning/</link>
		<comments>http://www.wirechatter.com/basic-voip-security-threat-tutorial-arp-poisoning/#comments</comments>
		<pubDate>Mon, 23 Jun 2008 19:49:43 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[VoIP]]></category>
		<category><![CDATA[arp poisoning]]></category>
		<category><![CDATA[tutorial]]></category>
		<category><![CDATA[video]]></category>

		<guid isPermaLink="false">http://www.wirechatter.com/?p=19</guid>
		<description><![CDATA[Image via Wikipedia A very basic tutorial from techcentric.org on how to STOP VoIP security threats , CAIN, ARP and MITM attacks. Explains that an ARP Poisoning attack is a man in the middle attack (intercepting data in this case VoIP packets). They recommend that you use SKYPE instead of SIP to avoid man in the <a href='http://www.wirechatter.com/basic-voip-security-threat-tutorial-arp-poisoning/'>[...]</a>]]></description>
			<content:encoded><![CDATA[<div class="zemanta-img" style="margin: 1em; float: right; display: block;"><a href="http://en.wikipedia.org/wiki/Image:SIP_signaling.png"><img style="border: medium none; display: block;" src="http://upload.wikimedia.org/wikipedia/en/thumb/9/9b/SIP_signaling.png/202px-SIP_signaling.png" alt="Session Initiation Protocol" /></a></p>
<p class="zemanta-img-attribution">Image via <a href="http://en.wikipedia.org/wiki/Image:SIP_signaling.png" target="_blank">Wikipedia</a></p>
</div>
<p>A very basic tutorial from techcentric.org on how to STOP VoIP security threats , CAIN, <a class="zem_slink" title="Address Resolution Protocol" rel="wikipedia" href="http://en.wikipedia.org/wiki/Address_Resolution_Protocol">ARP</a> and MITM attacks. Explains that an <a class="zem_slink" title="ARP spoofing" rel="wikipedia" href="http://en.wikipedia.org/wiki/ARP_spoofing">ARP Poisoning</a> attack is a <a class="zem_slink" title="Man-in-the-middle attack" rel="wikipedia" href="http://en.wikipedia.org/wiki/Man-in-the-middle_attack">man in the middle attack</a> (intercepting data in this case VoIP packets).</p>
<p>They recommend that you use SKYPE instead of SIP to avoid man in the middle attacks; or download ZPhone, it works with most SIP clients, or put your VoIP calls on VPN.</p>
<p>See the SIP protocol diagram (right)more information on what is happening during a SIP based VoIP call</p>
<p>Not the most insightful tutorial and a few people have commented that there were a few inaccuracies or that it was too basic, I thought it was a great tutorial for a &#8216;first timer&#8217; trying to get a handle of what is going on with VoIP security threats. I would definitely need more details from here though.</p>
<p><object classid="clsid:d27cdb6e-ae6d-11cf-96b8-444553540000" width="425" height="355" codebase="http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab#version=6,0,40,0"><param name="wmode" value="transparent" /><param name="src" value="http://www.youtube.com/v/qt3LaZhGRoQ&amp;hl=en" /><embed type="application/x-shockwave-flash" width="425" height="355" src="http://www.youtube.com/v/qt3LaZhGRoQ&amp;hl=en" wmode="transparent"></embed></object></p>
<fieldset class="zemanta-related">
<legend>Related articles</legend>
<ul class="zemanta-article-ul">
<li class="zemanta-article-ul-li"><a title="Open in new window" href="http://www.hackaday.com/2008/06/04/arp-poisoning-is-still-a-problem/">ARP poisoning is still a problem</a> [via Zemanta]</li>
</ul>
</fieldset>
<div class="zemanta-pixie" style="margin-top: 10px; height: 15px;"><a class="zemanta-pixie-a" title="Zemified by Zemanta" href="http://reblog.zemanta.com/zemified/3eb0d053-1481-4869-845c-46242f168c48/"><img class="zemanta-pixie-img" style="border: medium none; float: right;" src="http://img.zemanta.com/reblog_a.png?x-id=3eb0d053-1481-4869-845c-46242f168c48" alt="Zemanta Pixie" /></a></div>
]]></content:encoded>
			<wfw:commentRss>http://www.wirechatter.com/basic-voip-security-threat-tutorial-arp-poisoning/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>VoIP Security Threats &#8211; Video, Peter Cox</title>
		<link>http://www.wirechatter.com/voip-security-threats-video/</link>
		<comments>http://www.wirechatter.com/voip-security-threats-video/#comments</comments>
		<pubDate>Fri, 02 May 2008 05:50:10 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[SIP Trunks]]></category>
		<category><![CDATA[VoIP]]></category>
		<category><![CDATA[video]]></category>

		<guid isPermaLink="false">http://www.wirechatter.com/?p=18</guid>
		<description><![CDATA[Peter Cox(?) a security consultant specializing in VoIP security has a great Podcast primer on VoIP security examples. He states that there are really three categories of VoIP Security Threats: IP level Threats &#8211; shared with the web and email and others, common knowledge to many people already Protocol and application specific threats, based on <a href='http://www.wirechatter.com/voip-security-threats-video/'>[...]</a>]]></description>
			<content:encoded><![CDATA[<p>Peter Cox(?) a security consultant specializing in VoIP security has a great Podcast primer on VoIP security examples. He states that there are really three categories of VoIP Security Threats:</p>
<ol>
<li>IP level Threats &#8211; shared with the web and email and others, common knowledge to many people already</li>
<li>Protocol and application specific threats, based on the way the SIP protocol is designed and is implemented, these VoIP security vulnerabilities can result in misdirected calls, terminated calls, and general call disruption</li>
<li>Content related VoIP Security threats, the interfere with the media stream (the voice or video call)</li>
</ol>
<div>The most serious is a application level flooding attack, the works by running a script that sends a bunch of calls to an extension in rapid succession and hangs up once answered. It would make a phone unusable, no effective calls in or out.</div>
<div>Imagine also that the attacker injected content into a call, ring the phone and then play a recorded message &#8211; Telephone or VoIP SPAM! the last thing we need </div>
<div>Another set of threats revolve around the need of SIP phones to register with an IP/PBX. these kind of VoIP attacks can come in and de-register phones and extensions and render people unable to receive calls</div>
<p><object classid="clsid:d27cdb6e-ae6d-11cf-96b8-444553540000" width="425" height="355" codebase="http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab#version=6,0,40,0"><param name="wmode" value="transparent" /><param name="src" value="http://www.youtube.com/v/UA1quyLOTdg&amp;hl=en" /><embed type="application/x-shockwave-flash" width="425" height="355" src="http://www.youtube.com/v/UA1quyLOTdg&amp;hl=en" wmode="transparent"></embed></object></p>
]]></content:encoded>
			<wfw:commentRss>http://www.wirechatter.com/voip-security-threats-video/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>VOIP Security Concerns</title>
		<link>http://www.wirechatter.com/voip-security-concerns/</link>
		<comments>http://www.wirechatter.com/voip-security-concerns/#comments</comments>
		<pubDate>Tue, 15 Apr 2008 18:05:56 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Credit card]]></category>
		<category><![CDATA[Denial-of-service attack]]></category>
		<category><![CDATA[DOS]]></category>
		<category><![CDATA[Firewall]]></category>
		<category><![CDATA[Telecommunications]]></category>
		<category><![CDATA[Virtual LAN]]></category>
		<category><![CDATA[Voice over Internet Protocol]]></category>
		<category><![CDATA[VoIP]]></category>

		<guid isPermaLink="false">http://66.249.31.108/~wirechat/?p=8</guid>
		<description><![CDATA[VoIP uses the Internet for sending and retrieving VoIP data. This makes it vulnerable to hackers. For individuals who use VoIP this may not be a problem, but businesses don’t want their information to leak. For this reason VoIP services are dedicated to making their service as secure as possible. Hackers may ty to tap <a href='http://www.wirechatter.com/voip-security-concerns/'>[...]</a>]]></description>
			<content:encoded><![CDATA[<p><!--StartFragment-->VoIP uses the Internet for sending and retrieving VoIP data. This makes it vulnerable to hackers. For individuals who use VoIP this may not be a problem, but businesses don’t want their information to leak. For this reason VoIP services are dedicated to making their service as secure as possible.</p>
<p>Hackers may ty to tap your call and retrieve all sorts of information. They can retrieve conversations, but also VoIP phone numbers or user identities. When they retrieve this information, they can use your VoIP to make calls themselves. Some hackers may even record your call and use your voice to make calls.</p>
<p>There are a few ways to avoid these security problems. The first is encryption. Encryption works in the same way as when sending credit card information. The data is sent over a safe connection. Another way of averting security issues is by separating VoIP data and other Internet data by using a so-called VLAN (Virtual Local Area Network). The call quality may suffer under these measures. But both methods are an option if calls are to be kept secret.</p>
<p>Viruses sent with VoIP data could also be a risk factor, although this threat hasn’t been seen yet. Viruses don’t only overload the network, but they also reduce the quality of calls.</p>
<p>Another issue is SPIT – Spam over Internet Telephony. Instead of receiving e-mails you receive calls from companies that try to sell you their services and products.</p>
<p><strong> How secure is my VoIP?</strong> Certain services maintain security through encryption or the use of a VLAN (Virtual Local Area Network). There are certain things consumers can do themselves.</p>
<ol>
<li>A firewall will protect your computer from malicious attacks. </li>
<li>All downloads should also be checked for viruses or other threats. </li>
</ol>
<div class="zemanta-img zemanta-action-dragged" style="margin: 1em; display: block;">
<div>
<dl class="wp-caption alignright" style="width: 212px;">
<dt class="wp-caption-dt"><a href="http://commons.wikipedia.org/wiki/Image:Stachledraht_DDos_Attack.svg"><img title="Diagram of a Stachledraht DDos Attack" src="http://upload.wikimedia.org/wikipedia/commons/thumb/3/3f/Stachledraht_DDos_Attack.svg/202px-Stachledraht_DDos_Attack.svg.png" alt="Diagram of a Stachledraht DDos Attack" width="202" height="286" /></a></dt>
<dd class="wp-caption-dd zemanta-img-attribution" style="font-size: 0.8em;">Image via <a href="http://commons.wikipedia.org/wiki/Image:Stachledraht_DDos_Attack.svg">Wikipedia</a></dd>
</dl>
</div>
</div>
<p>VoIP hardware on the other hand can be unstabilized or shut down if it receives certain types of data. <br />
Certain Internet phones are sensitive to data piracy.  <span>For individuals these security issues may not be of importance. But businesses have sensitive conversations over the Internet. They have their own gateways and equipment, which makes them an easy prey for DOS attacks (Denial of Service) and other assailments.</span> </p>
<div class="zemanta-pixie" style="margin-top: 10px; height: 15px;"><a class="zemanta-pixie-a" title="Zemified by Zemanta" href="http://reblog.zemanta.com/zemified/4765d951-fe9d-44be-9e75-65b34ebde892/"><img class="zemanta-pixie-img" style="border: none; float: right;" src="http://img.zemanta.com/reblog_e.png?x-id=4765d951-fe9d-44be-9e75-65b34ebde892" alt="Reblog this post [with Zemanta]" /></a><span class="zem-script more-related"><script src="http://static.zemanta.com/readside/loader.js" type="text/javascript"></script></span></div>
]]></content:encoded>
			<wfw:commentRss>http://www.wirechatter.com/voip-security-concerns/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

