VoIP Security

VoIP Security

The need for increased security awareness in small to medium business in 2010.

Posted January 8th, 2010 by admin

56
vote

The holidays are over, time to focus on the new year ahead. For some the holidays provide a little more time – as others are busy preparing for the holidays – to research, review and ‘catch up’ on security news and trends from around the industry.
I have always been an advocate for security awareness in the small to medium business (SMB) space. Working in this field I have come to understand the balance between equipment and resources cost and the margins which SMB’s operate within to remain viable. Calls for increasing security can appear to negatively impact this balance. Unfortunately the SMB space is becoming an increasingly popular target for internet criminals as witnessed by these two recent articles.

http://www.krebsonsecurity.com/2010/01/fbi-investigating-theft-of-500000...

http://www.wired.com/threatlevel/2009/12/feds-warn-small-businesses/

Asterisk Security Advisory – RTP Remote Crash Vulnerability

Posted December 4th, 2009 by admin

61
vote

asterisklogo.jpgEarlier this week, the security team at Digium released Asterisk Projects Security Advisory AST-2009-010 identifying an interesting attack where an attacker can send a malformed RTP packet within the RTP stream and crash the Asterisk system. The fix identified is to upgrade to the latest version of Asterisk.

My one bit of feedback to the folks at Digium would be that their advisories do not provide any information about mitigating circumstances. (Would be great if they could add such a section.)

Sipera SLiC Delivers Smartphone Security for 'Business Ready' Mobile VoIP and Unified Communications

Posted October 26th, 2009 by admin

39
vote

sipera_logo.jpg Sipera
Systems
announces availability of the Sipera Secure Live Communications (SLiC)
mobility solution. Delivering breakthrough enterprise-class communications privacy
and security for VoIP and UC on smartphones, Sipera SLiC makes smartphone VoIP and
UC "business ready."

Sipera SLiC is the industry's first security solution enabling enterprises to "tame"
the smartphone, permitting employees to use VoIP, UC, cloud telephony, and other low-cost
and feature-rich communications applications on mobile devices with complete security
and privacy. In an important industry first, Sipera SLiC enables smartphone VoIP to
include smart-card card authentication for accessing enterprise resources, providing

Slides: SIP Trunking and Security in an Enterprise Network

Posted September 30th, 2008 by admin

77
vote

Earlier this month out at ITEXPO in Los Angeles, I participated in the Ingate SIP Trunking seminars as I have been doing for the last year or so. My talk was ?SIP Trunking and Security in an Enterprise Network?. The slides are available for viewing or download from my SlideShare account and I?ll also embed them here in this post.

I did record the presentation in both audio and video and hope to be making that available as a Blue Box podcast some time soon. I?ll then sync the slides to the audio. Meanwhile? enjoy the slides!

VoIPshield announces discovery of over 100 vulnerabilities in Cisco, Avaya, Nortel VoIP systems

Posted April 2nd, 2008 by admin

94
vote

Extreme Networks Boosts Security for IP Telephony and VoIP

Posted March 17th, 2008 by admin

85
vote

Extreme Networks made enhancements to its network solutions that provide behavior-based rules to protect IP Telephony and VoIP traffic. These security rules help mitigate the threat of malicious users and hackers who are actively trying to exploit vulnerabilities and breach the IP communications network. Based on these rules, users or devices that demonstrate destructive behavior when entering the network can rapidly be addressed to preserve the quality of voice communications.

New Features Added to VoIPAlarm 2

Posted January 8th, 2008 by admin

81
vote

NextAlarm announces two major new security features for its VoIPAlarm 2 IP alarm signal transmission platform. VoIPAlarm 2 is centered around the VoIPAlarm ABN adapter, an IP communicator which connects to any Contact ID compatible alarm system. Signals from the alarm system are received by VoIPAlarm over broadband Internet, and retransmitted over PSTN phone lines or IP to the central station of the alarm installer's choice.

Oops? Skype failed to mention this wee minor security update?

Posted December 11th, 2007 by admin

Toasting VoIP Phones with Targa3

Posted December 2nd, 2007 by admin

112
vote

With all of the VoIP tools available it?s easy to forget to test the IP stack of your VoIP phone for stability from classic attacks. With that in mind, a good tool for accomplishing this basic vetting is called Targa3. Written way back in 1999, Targa3 encompasses several attacks such as Jolt, Nestea, etc. to ?generate attacks using invalid fragmentation, protocol, packet size, header values, options, offsets, tcp segments, routing flags, and other unknown/unexpected packet values.?

Blue Box #69: Linksys SPA-941 vulnerability, SIP DDoS, New release of SIPVicious, Asterisk security roadmap, other VoIP security

Posted October 11th, 2007 by admin

109
vote

Blue Box Podcast #69 is now available for download.

Syndicate content