VoIP Wars : Return of the SIP
|
|
|
- Elmer Reeves
- 10 years ago
- Views:
Transcription
1 VoIP Wars : Return of the SIP Fatih Özavcı Security Sense of Security (Australia)
2 # whois Security Sense of Security (Australia) 10+ Years Experience in Penetration Testing 800+ Penetration Tests, 40+ Focused on NGN/VoIP SIP/NGN/VoIP Systems Penetration Testing Mobile Application Penetration Testing IPTV Penetration Testing Regular Stuff (Network Inf., Web, SOAP, Exploitation...) Author of Viproy VoIP Penetration Testing Kit Author of Hacking Trust Relationships Between SIP Gateways Blackhat Arsenal USA 2013 Viproy VoIP Pen-Test Kit So, that's me 2
3 Viproy in Action
4 # traceroute VoIP Networks are Insecure, but Why? Basic Attacks Discovery, Footprinting, Brute Force Initiating a Call, Spoofing, CDR and Billing Bypass SIP Proxy Bounce Attack Fake Services and MITM Fuzzing Servers and Clients, Collecting Credentials (Distributed) Denial of Service Attacking SIP Soft Switches and SIP Clients, SIP Amplification Attack Hacking Trust Relationships of SIP Gateways Attacking SIP Clients via SIP Trust Relationships Fuzzing in Advance Out of Scope RTP Services and Network Tests, Management Additional Services XML/JSON Based Soap Services 4
5 # info SIP Session Initiation Protocol Only Signalling, not for Call Transporting Extended with Session Discovery Protocol NGN Next Generation Network Forget TDM and PSTN SIP, H.248 / Megaco, RTP, MSAN/MGW Smart Customer Modems & Phones Easy Management Security is NOT a Concern?! Next Generation! Because We Said So! 5
6 # SIP Services : Internal IP Telephony Support Servers Factory/Campus SIP over VPN SIP Clients INTERNET Commercial Gateways SIP Server Analog/Digital PBX 6
7 # SIP Services : Commercial Services Customers VAS, CDR, DB Servers MSAN/MGW PSTN/ISDN Distributed MPLS SDP Servers Soft Switch INTERNET (SIP Server) Mobile RTP, Proxy Servers 3rd Party Gateways 7
8 # Administrators Think... Root Doesn't! Their VoIP Network Isolated Abusing VoIP Requires Knowledge Open Physical Access, Weak VPN or MPLS With Viproy, That's No Longer The Case! Most Attacks are Network Based or Toll Fraud DOS, DDOS, Attacking Mobile Clients, Spying Phishing, Surveliance, Abusing VAS Services VoIP Devices are Well-Configured Weak Passwords, Old Software, Vulnerable Protocols 8
9 # Viproy What? Viproy is a Vulcan-ish Word that means "Call" Viproy VoIP Penetration and Exploitation Kit Testing Modules for Metasploit, MSF License Old Techniques, New Approach SIP Library for New Module Development Custom Header Support, Authentication Support New Stuff for Testing: Trust Analyzer, Bounce Scan, Proxy etc Modules Options, Register, Invite, Message Brute Forcers, Enumerator SIP Trust Analyzer, Service Scanner SIP Proxy, Fake Service, DDOS Tester 9
10 # Basic Attacks We are looking for... Finding and Identifying SIP Services and Purposes Discovering Available Methods and Features Discovering SIP Software and Vulnerabilities Identifying Valid Target Numbers, Users, Realm Unauthenticated Registration (Trunk, VAS, Gateway) Brute Forcing Valid Accounts and Passwords Invite Without Registration Direct Invite from Special Trunk (IP Based) Invite Spoofing (After or Before Registration, Via Trunk) Viproy Pen-Testing Kit Could Automate Discovery 10
11 # Basic Attacks Discovery OPTIONS / REGISTER / INVITE / SUBSCRIBE 100 Trying 200 OK 401 Unauthorized 403 Forbidden 404 Not Found 500 Internal Server Error Clients Gateways Collecting Information from Response Headers User-Agent Server Realm Call-ID Record-Route Warning P-Asserted-Identity P-Called-Party-ID P-Preferred-Identity P-Charging-Vector Soft Switch (SIP Server) 11
12 # Basic Attacks Register REGISTER / SUBSCRIBE (From, To, Credentials) 200 OK 401 Unauthorized 403 Forbidden 404 Not Found 500 Internal Server Error RESPONSE Depends on Informations in REQUEST Type of Request (REGISTER, SUBSCRIBE) FROM, TO, Credentials with Realm Via Actions/Tests Depends on RESPONSE Brute Force (FROM, TO, Credentials) Detecting/Enumerating Special TOs, FROMs or Trunks Detecting/Enumerating Accounts With Weak or Null Passwords. Clients Gateways Soft Switch (SIP Server) 12
13 # Basic Attacks this isn't the call you're looking for We are attacking for... Free Calling, Call Spoofing Free VAS Services, Free International Calling Breaking Call Barriers Spoofing with... Via Field, From Field P-Asserted-Identity, P-Called-Party-ID, P-Preferred-Identity ISDN Calling Party Number, Remote-Party-ID Bypass with... P-Charging-Vector (Spoofing, Manipulating) Re-Invite, Update (Without/With P-Charging-Vector) Viproy Pen-Testing Kit Supports Custom Headers 13
14 # Basic Attacks Invite, CDR and Billing Tests INVITE/ACK/RE-INVITE/UPDATE (From, To, Credentials, VIA...) 100 Trying 183 Session Progress 180 Ringing 200 OK 401 Unauthorized 403 Forbidden 404 Not Found 500 Internal Server Error RESPONSE Depends on Informations in INVITE REQUEST FROM, TO, Credentials with Realm, FROM <>, TO <> Via, Record-Route Direct INVITE from Specific IP:PORT (IP Based Trunks) Actions/Tests Depends on RESPONSE Brute Force (FROM&TO) for VAS and Gateways Testing Call Limits, Unauthenticated Calls, CDR Management INVITE Spoofing for Restriction Bypass, Spying, Invoice. Clients Gateways Soft Switch (SIP Server) 14
15 # SIP Proxy Bounce Attack SIP Proxies Redirect Requests to Other SIP Servers We Can Access Them via SIP Proxy then We Can Scan We Can Scan Inaccessible Servers URI Field is Useful for This Scan Viproy Pen-Testing Kit Has a UDP Port Scan Module 15
16 # SIP Proxy Bounce Attack Izmir Production SIP Service The Wall White Walker How Can We Use It? Ankara Adana SIP Trust Relationship Attacks Attacking Inaccessible Servers Attacking SIP Software Software Version, Type 16
17 # Fake Services and MITM We Need a Fake Service Adding a Feature to Regular SIP Client Collecting Credentials Redirecting Calls Manipulating CDR or Billing Features Fuzzing Servers and Clients for Vulnerabilities Fake Service Should be Semi-Automated Communication Sequence Should be Defined Sending Bogus Request/Result to Client/Server Viproy Pen-Testing Kit Has a SIP Proxy and Fake Service Fuzzing Support of Fake Service is in Development Stage 17
18 # Fake Services and MITM Usage of Proxy & Fake Server Features Soft Switch (SIP Server) Clients Use ARP Spoof & VLAN Hopping & Manual Config Collect Credentials, Hashes, Information Change Client's Request to Add a Feature (Spoofing etc) Change the SDP Features to Redirect Calls Add a Proxy Header to Bypass Billing & CDR Manipulate Request at Runtime to find BOF Vulnerabilities 18
19 # DOS It's Not Service, It's Money Locking All Customer Phones and Services for Blackmail Denial of Service Vulnerabilities of SIP Services Many Responses for Bogus Requests DDOS Concurrent Registered User/Call Limits Voice Message Box, CDR, VAS based DOS Attacks Bye And Cancel Tests for Call Drop Locking All Accounts if Account Locking is Active for Multiple Fails Multiple Invite (After or Before Registration, Via Trunk) Calling All Numbers at Same Time Overloading SIP Server's Call Limits Calling Expensive Gateways,Targets or VAS From Customers Viproy Pen-Testing Kit Has a few DOS Features 19
20 # DDOS All Your SIP Gateways Belong to Us! SIP Amplification Attack + SIP Servers Send Errors Many Times (10+) + We Can Send IP Spoofed Packets + SIP Servers Send Responses to Victim => 1 packet for 10+ Packets, ICMP Errors (Bonus) Viproy Pen-Testing Kit Has a PoC DDOS Module Can we use SIP Server's Trust? -wait for it20
21 # DDOS All Your SIP Gateways Belong to Us! Izmir Production SIP Service The Wall IP Spoofed Call Request Ankara Production SIP Service White Walker The Wall Adana Production SIP Service Citadel 21
22 # Hacking SIP Trust Relationships NGN SIP Services Trust Each Other Authentication and TCP are Slow, They Need Speed IP and Port Based Trust are Most Effective Way What We Need Target Number to Call (Cell Phone if Service is Public) Tech Magazine, Web Site Information, News Baby Steps Finding Trusted SIP Networks (Mostly B Class) Sending IP Spoofed Requests from Each IP:Port Each Call Should Contain IP:Port in "From" Section If We Have a Call, We Have The Trusted SIP Gateway IP and Port Brace Yourselves The Call is Coming 22
23 # Hacking SIP Trust Relationships Slow Motion Izmir Production SIP Service The Wall t es om u eq n Fr R l l ta i a d C rt Da e f oo :Po p S IP IP ins nta o C Ankara White Walker Istanbul International Trusted Operator 23
24 # Hacking SIP Trust Relationships Brace Yourselves, The Call is Coming Izmir Production SIP Service The Wall White Walker st e qu rom e ll R in F a d C own e f Fr oo y Kn p om d S IP ebo Ci m tad o S el Come Again? Ankara Istanbul International Trusted Operator Billing? CDR? Log? 24
25 # Hacking SIP Trust Relationships Business Impact Denial of Service Short Message Service and Billing Calling All Numbers at Same Time Overloading SIP Server's Call Limits Overloading VAS Service or International Limits Overloading CDR Records with Spoofed Calls Attacking a Server Software Crashing/Exploiting Inaccesible Features Call Redirection (working on it, not yet :/) Attacking a Client? Next Slide! 25
26 # Attacking a Client via SIP Trust Relationships SIP Server Redirects a few Fields to Client FROM, FROM NAME, Contact Other Fields Depend on Server (SDP, MIME etc) Clients Have Buffer Overflow in FROM? Send 2000 Chars to Test it! Crash it or Execute your Command if Available Clients Trust SIP Servers and Trust is UDP Based This module can be used for Trust Between Client and Server Viproy Pen-Testing Kit SIP Trust Module Simple Fuzz Support (FROM=FUZZ 2000) You Can Modify it for Further Attacks 26
27 # Attacking a Client via SIP Trust Relationships Brace Yourselves 550 Chars are Coming Izmir Production SIP Service The Wall White Walker Ankara Istanbul t es u eq R The Wall m l l o a r d C s in F e f Bo oo har p C S g IP 550 Re us In qu vit es e t CRASSSSH! International Trusted Operator Command? Why Not! AdorePhone Iphone App 27
28 # Fuzz Me Maybe Fuzzing as a SIP Client SIP Server Proxy MITM SIP Server Software SIP Clients Hardware Devices, IP Phones, Video Conference Systems Desktop Application or Web Based Software Mobile Software Special SIP Devices/Software SIP Firewalls, ACL Devices, Proxies Connected SIP Trunks, 3rd Party Gateways MSAN/MGW Logging Software (Indirect) Special Products: Cisco, Alcatel, Avaya, Huawei, ZTE... 28
29 # Old School Fuzzing Request Fuzzing SDP Features MIME Type Fuzzing Response Fuzzing Authentication, Bogus Messages, Redirection Static vs Stateful How about Smart Fuzzing Missing State Features (ACK,PHRACK,RE-INVITE,UPDATE) Fuzzing After Authentication (Double Account, Self-Call) Response Fuzzing (Before or After Authentication) Missing SIP Features (IP Spoofing for SIP Trunks, Proxy Headers) Numeric Fuzzing for Services is NOT Memory Corruption Dial Plan Fuzzing, VAS Fuzzing 29
30 # How Viproy Pen-Testing Kit Helps Fuzzing Tests Skeleton for Feature Fuzzing, NOT Only SIP Protocol Multiple SIP Service Initiation Call Fuzzing in Many States, Response Fuzzing Integration With Other Metasploit Features Fuzzers, Encoding Support, Auxiliaries, Immortality etc. Custom Header Support Future Compliance, Vendor Specific Extensions, VAS Raw Data Send Support (Useful with External Static Tools) Authentication Support Authentication Fuzzing, Custom Fuzzing with Authentication Less Code, Custom Fuzzing, State Checks Some Features (Fuzz Library, SDP) are Coming Soon 30
31 # Fuzzing SIP Services Request Based OPTIONS/REGISTER/SUBSCRIBE/INVITE/ACK/RE-INVITE/UPDATE Trying 183 Session Progress 180 Ringing 200 OK Fuzzing Targets, REQUEST Fields 401 Unauthorized 403 Forbidden 404 Not Found 500 Internal Server Error Request Type, Protocol, Description Via, Branch, Call-ID, From, To, Cseq, Contact, Record-Route Proxy Headers, P-*-* (P-Asserted-Identity, P-Charging-Vector...) Authentication in Various Requests (User, Pass, Realm, Nonce) Content-Type, Content-Lenth SDP Information Fields ISUP Fields Clients Gateways Soft Switch (SIP Server) 31
32 # Fuzzing SIP Services Response Based OPTIONS MALICOUS RESPONSE Clients INVITE Myself / INVITE I'm Proxy INVITE/ACK Gateways MALICOUS RESPONSE Potential RESPONSE Types for Fuzzing 100 Trying 183 Session Progress 180 Ringing 200 OK 401 Unauthorized 403 Forbidden 404 Not Found 500 Internal Server Error Soft Switch (SIP Server) 32
33 SIP Bounce Attack, Hacking SIP Trust, Attacking Mobile Apps
34 References Viproy VoIP Penetration and Exploitation Kit Author : Homepage : Github : Attacking SIP Servers Using Viproy VoIP Kit (50 mins) Hacking Trust Relationships Between SIP Gateways (PDF) VoIP Pen-Test Environment VulnVoIP 34
35 Special Thanks to... Special Ones Konca Ozavci Kadir Altan Anil Pazvant Suggestions & Guidelines & Support Paul Henry Mark Collier Jason Olstrom Jesus Perez Rubio 35
36 Q?
37 Thanks
VoIP Wars : Return of the SIP
VoIP Wars : Return of the SIP Fatih Özavcı Information Security Researcher & Consultant fatih.ozavci at viproy.com viproy.com/fozavci # whois Information Security Consultant @ Viproy / Turkey 10+ Years
Hacking SIP Services Like a Boss. Fatih Özavcı Information Security Researcher & Consultant
Hacking SIP Services Like a Boss Fatih Özavcı Information Security Researcher & Consultant fatih.ozavci at viproy.com viproy.com/fozavci #direngezi 2 #direngezi 3 #direngezi 4 About Me Information Security
VoIP Wars: Attack of the Cisco Phones
VoIP Wars: Attack of the Cisco Phones Compliance, Protection & Business Confidence Sense of Security Pty Ltd Sydney Level 8, 66 King Street Melbourne Level 10, 401 Docklands Drv T: 1300 922 923 T: +61
VoIP Wars: Attack of the Cisco Phones
VoIP Wars: Attack of the Cisco Phones Compliance, Protection & Business Confidence Sense of Security Pty Ltd Sydney Level 8, 66 King Street Melbourne Level 10, 401 Docklands Drv T: 1300 922 923 T: +61
Hacking Trust Relationships of SIP Gateways
Hacking Trust Relationships of SIP Gateways Author : Fatih Özavcı Homepage : gamasec.net/fozavci SIP Project Page : github.com/fozavci/gamasec-sipmodules Version : 0.9 Hacking Trust Relationship Between
Practical VoIP Hacking with Viproy
Practical VoIP Hacking with Viproy 9 December 2014 Compliance, Protection & Business Confidence Sense of Security Pty Ltd Sydney Level 8, 66 King Street Sydney NSW 2000 Australia Melbourne Level 10, 401
Viproy Reloaded 2.0. Compliance, Protection & Business Confidence. Melbourne Level 10, 401 Docklands Drv
Viproy Reloaded 2.0 Compliance, Protection & Business Confidence Sense of Security Pty Ltd Sydney Level 8, 66 King Street Melbourne Level 10, 401 Docklands Drv T: 1300 922 923 T: +61 (0) 2 9290 4444 [email protected]
Penetration Testing SIP Services
Penetration Testing SIP Services Using Metasploit Framework Writer Version : 0.2 : Fatih Özavcı (fatih.ozavci at viproy.com) Introduction Viproy VoIP Penetration Testing Kit Sayfa 2 Table of Contents 1
VoIP Wars: Destroying Jar Jar Lync
VoIP Wars: Destroying Jar Jar Lync Fatih Ozavci 25 October 2015 Compliance, Protection & Business Confidence Sense of Security Pty Ltd Sydney Melbourne T: 1300 922 923 [email protected] Level
How to make free phone calls and influence people by the grugq
VoIPhreaking How to make free phone calls and influence people by the grugq Agenda Introduction VoIP Overview Security Conclusion Voice over IP (VoIP) Good News Other News Cheap phone calls Explosive growth
Protect Yourself Against VoIP Hacking. Mark D. Collier Chief Technology Officer SecureLogix Corporation
Protect Yourself Against VoIP Hacking Mark D. Collier Chief Technology Officer SecureLogix Corporation What Will Be Covered How to assess the security of your IPT network: In house/external and ground
VOIP WARS: THE PHREAKERS AWAKEN. Fatih Ozavci @fozavci Managing Consultant Context Information Security
VOIP WARS: THE PHREAKERS AWAKEN Fatih Ozavci @fozavci Managing Consultant Context Information Security Fatih Ozavci, Managing Consultant VoIP & phreaking Mobile applications and devices Network infrastructure
Conducting an IP Telephony Security Assessment
Conducting an IP Telephony Security Assessment Mark D. Collier Chief Technology Officer [email protected] www.securelogix.com Presentation Outline Ground rules and scope Discovery Security policy
The Trivial Cisco IP Phones Compromise
Security analysis of the implications of deploying Cisco Systems SIP-based IP Phones model 7960 Ofir Arkin Founder The Sys-Security Group [email protected] http://www.sys-security.com September 2002
AV@ANZA Formación en Tecnologías Avanzadas
SISTEMAS DE SEÑALIZACION SIP I & II (@-SIP1&2) Contenido 1. Why SIP? Gain an understanding of why SIP is a valuable protocol despite competing technologies like ISDN, SS7, H.323, MEGACO, SGCP, MGCP, and
Sense of Security VoIP Security Testing Training
Sense of Security VoIP Security Testing Training Fatih Ozavci Christos Archimandritis 8 August 2015 Compliance, Protection & Business Confidence Sense of Security Pty Ltd Sydney Level 8, 66 King Street
Basic Vulnerability Issues for SIP Security
Introduction Basic Vulnerability Issues for SIP Security By Mark Collier Chief Technology Officer SecureLogix Corporation [email protected] The Session Initiation Protocol (SIP) is the future
10 Key Things Your VoIP Firewall Should Do. When voice joins applications and data on your network
10 Key Things Your Firewall Should Do When voice joins applications and data on your network Table of Contents Making the Move to 3 10 Key Things 1 Security is More Than Physical 4 2 Priority Means Clarity
A Brief Security Analysis of Microsoft Skype for Business
A Whitepaper Prepared by Sense of Security A Brief Security Analysis of Microsoft Skype for Business Version No: 1.0 Document No: SFB-Tech-1215 Author: Fatih Ozavci 17 December 2015 Sense of Security is
SIP Essentials Training
SIP Essentials Training 5 Day Course Lecture & Labs COURSE DESCRIPTION Learn Session Initiation Protocol and important protocols related to SIP implementations. Thoroughly study the SIP protocol through
An outline of the security threats that face SIP based VoIP and other real-time applications
A Taxonomy of VoIP Security Threats An outline of the security threats that face SIP based VoIP and other real-time applications Peter Cox CTO Borderware Technologies Inc VoIP Security Threats VoIP Applications
The #1 Issue on VoIP, Fraud!
Know your enemy Sun Tzu's The Art of War The #1 Issue on VoIP, Fraud! How to identify, prevent and reduce damages caused by fraud Flavio E. Goncalves About me Author of the book Building Telephony Systems
Sense of Security VoIP Security Testing Training
Sense of Security VoIP Security Testing Training Fatih Ozavci Christos Archimandritis 8 August 2015 Compliance, Protection & Business Confidence Sense of Security Pty Ltd Sydney Level 8, 66 King Street
NAT TCP SIP ALG Support
The feature allows embedded messages of the Session Initiation Protocol (SIP) passing through a device that is configured with Network Address Translation (NAT) to be translated and encoded back to the
PENTEST. Pentest Services. VoIP & Web. www.novacybersecurity.com
PENTEST VoIP & Web Pentest Services VoIP & WEB Penetration Testing The Experinced and National VoIP/Unified Communications R&D organization, NETAŞ NOVA Pentest Services test the applications, infrastructure
SIP : Session Initiation Protocol
: Session Initiation Protocol EFORT http://www.efort.com (Session Initiation Protocol) as defined in IETF RFC 3261 is a multimedia signaling protocol used for multimedia session establishment, modification
Session Initiation Protocol (SIP) Vulnerabilities. Mark D. Collier Chief Technology Officer SecureLogix Corporation
Session Initiation Protocol (SIP) Vulnerabilities Mark D. Collier Chief Technology Officer SecureLogix Corporation What Will Be Covered Introduction to SIP General SIP security SIP vulnerabilities and
VoIP Security regarding the Open Source Software Asterisk
Cybernetics and Information Technologies, Systems and Applications (CITSA) 2008 VoIP Security regarding the Open Source Software Asterisk Prof. Dr.-Ing. Kai-Oliver Detken Company: DECOIT GmbH URL: http://www.decoit.de
Voice Over IP (VoIP) Denial of Service (DoS)
Introduction Voice Over IP (VoIP) Denial of Service (DoS) By Mark Collier Chief Technology Officer SecureLogix Corporation [email protected] Denial of Service (DoS) is an issue for any IP network-based
EE4607 Session Initiation Protocol
EE4607 Session Initiation Protocol Michael Barry [email protected] [email protected] Outline of Lecture IP Telephony the need for SIP Session Initiation Protocol Addressing SIP Methods/Responses Functional
Recommended IP Telephony Architecture
Report Number: I332-009R-2006 Recommended IP Telephony Architecture Systems and Network Attack Center (SNAC) Updated: 1 May 2006 Version 1.0 [email protected] This Page Intentionally Left Blank ii Warnings
https://elearn.zdresearch.com https://training.zdresearch.com/course/pentesting
https://elearn.zdresearch.com https://training.zdresearch.com/course/pentesting Chapter 1 1. Introducing Penetration Testing 1.1 What is penetration testing 1.2 Different types of test 1.2.1 External Tests
Securing SIP Trunks APPLICATION NOTE. www.sipera.com
APPLICATION NOTE Securing SIP Trunks SIP Trunks are offered by Internet Telephony Service Providers (ITSPs) to connect an enterprise s IP PBX to the traditional Public Switched Telephone Network (PSTN)
SIP Trunking. Service Guide. www.megapath.com. Learn More: Call us at 877.634.2728.
Service Guide Learn More: Call us at 877.634.2728. www.megapath.com What is MegaPath SIP Trunking? SIP Trunking enables your business to reduce costs and simplify IT management by combining voice and Internet
Enumerating and Breaking VoIP
Enumerating and Breaking VoIP Introduction Voice over Internet Protocol (VoIP) has seen rapid implementation over the past few years. Most of the organizations which have implemented VoIP are either unaware
Online course syllabus. MAB: Voice over IP
Illuminating Technology Course aim: Online course syllabus MAB: Voice over IP This course introduces the principles and operation of telephony services that operate over Internet Protocol (IP) networks
Anat Bremler-Barr Ronit Halachmi-Bekel Jussi Kangasharju Interdisciplinary center Herzliya Darmstadt University of Technology
Unregister Attack in SIP Anat Bremler-Barr Ronit Halachmi-Bekel Jussi Kangasharju Interdisciplinary center Herzliya Darmstadt University of Technology Unregister Attack We present a new VoIP Denial Of
TSIN02 - Internetworking
TSIN02 - Internetworking Lecture 9: SIP and H323 Literature: Understand the basics of SIP and it's architecture Understand H.323 and how it compares to SIP Understand MGCP (MEGACO/H.248) SIP: Protocol
VoIP some threats, security attacks and security mechanisms. Lars Strand RiskNet Open Workshop Oslo, 24. June 2009
VoIP some threats, security attacks and security mechanisms Lars Strand RiskNet Open Workshop Oslo, 24. June 2009 "It's appalling how much worse VoIP is compared to the PSTN. If these problems aren't fixed,
Vulnerability Assessment and Penetration Testing
Vulnerability Assessment and Penetration Testing Module 1: Vulnerability Assessment & Penetration Testing: Introduction 1.1 Brief Introduction of Linux 1.2 About Vulnerability Assessment and Penetration
Session Initiation Protocol (SIP) The Emerging System in IP Telephony
Session Initiation Protocol (SIP) The Emerging System in IP Telephony Introduction Session Initiation Protocol (SIP) is an application layer control protocol that can establish, modify and terminate multimedia
Learn Ethical Hacking, Become a Pentester
Learn Ethical Hacking, Become a Pentester Course Syllabus & Certification Program DOCUMENT CLASSIFICATION: PUBLIC Copyrighted Material No part of this publication, in whole or in part, may be reproduced,
The SIP School- 'Mitel Style'
The SIP School- 'Mitel Style' Course Objectives This course will take delegates through the basics of SIP into some very technical areas and is suited to people who will be installing and supporting SIP
The VoIP Vulnerability Scanner
SiVuS (SiP Vulnerability Scanner) The VoIP Vulnerability Scanner User Guide v1.07 www.vopsecurity.org Contents 1 INTRODUCTION... 3 2 SIVUS FEATURES AND FUNCTIONALITY... 4 3 INSTALLATION... 5 4 OPERATION...
Storming SIP Security
Attack Sandro Gauci Difficulty VoIP is a hot and steadily gaining market share in the phone business. As people constantly seek to make long distance calls cheaper, they are moving away from relying on
Ron Shuck, CISSP, CISM, CISA, GCIA Infrastructure Security Architect Spirit AeroSystems
Ron Shuck, CISSP, CISM, CISA, GCIA Infrastructure Security Architect Spirit AeroSystems VOIP Components Common Threats How Threats are Used Future Trends Provides basic network connectivity and transport
COPYRIGHTED MATERIAL. Contents. Foreword. Acknowledgments
Contents Foreword Preface Acknowledgments 1 Introduction 1 1.1 Motivation for Network Convergence 1 1.2 The Core Network 2 1.3 Legacy Service Requirements 4 1.4 New Service Requirements 5 1.5 Architectures
SIP PBX TRUNKING WITH SIP-DDI 1.0
Documentation on SIP PBX trunking with SIP-DDI 1.0 and the related QSC product IPfonie extended Version 1.1, date: september 15th, 2011 page 1/22 List of references Author Document Roland Hänel "Technical
CS5008: Internet Computing
CS5008: Internet Computing Lecture 22: Internet Security A. O Riordan, 2009, latest revision 2015 Internet Security When a computer connects to the Internet and begins communicating with others, it is
Analysis of a VoIP Attack
IPCom Gesellschaft für internetbasierte Kommunikationsdienste mbh Analysis of a VoIP Attack Klaus Darilion, IPCom GmbH, [email protected] Abstract: Recently, several IT news websites reported VoIP
IP-Telephony SIP & MEGACO
IP-Telephony SIP & MEGACO Bernard Hammer Siemens AG, Munich Siemens AG 2001 1 Presentation Outline Session Initiation Protocol Introduction Examples Media Gateway Decomposition Protocol 2 IETF Standard
Security of IPv6 and DNSSEC for penetration testers
Security of IPv6 and DNSSEC for penetration testers Vesselin Hadjitodorov Master education System and Network Engineering June 30, 2011 Agenda Introduction DNSSEC security IPv6 security Conclusion Questions
VoIP Security Methodology and Results. NGS Software Ltd
VoIP Security Methodology and Results NGS Software Ltd Barrie Dempster Senior Security Consultant [email protected] Agenda VoIP Security Issues Assessment Methodology Case Study: Asterisk VoIP Security
SS7 & LTE Stack Attack
SS7 & LTE Stack Attack Ankit Gupta Black Hat USA 2013 [email protected] Introduction With the evolution of IP network, Telecom Industries are using it as their core mode of communication for their network
SIP Trunking and Voice over IP
SIP Trunking and Voice over IP Agenda What is SIP Trunking? SIP Signaling How is Voice encoded and transported? What are the Voice over IP Impairments? How is Voice Quality measured? VoIP Technology Confidential
A Novel Approach for Evaluating and Detecting Low Rate SIP Flooding Attack
A Novel Approach for Evaluating and Detecting Low Rate SIP Flooding Attack Abhishek Kumar Department of Computer Science and Engineering-Information Security NITK Surathkal-575025, India Dr. P. Santhi
How To Set Up An Ip Firewall On Linux With Iptables (For Ubuntu) And Iptable (For Windows)
Security principles Firewalls and NAT These materials are licensed under the Creative Commons Attribution-Noncommercial 3.0 Unported license (http://creativecommons.org/licenses/by-nc/3.0/) Host vs Network
VoIP Security. Title: Something Old (H.323), Something New (IAX), Something Hallow (Security), & Something Blue (VoIP Administrators)
VoIP Security Title: Something Old (H.323), Something New (IAX), Something Hallow (Security), & Something Blue (VoIP Administrators) BlackHat 2007 Presented by: Himanshu Dwivedi ([email protected])
SIP A Technology Deep Dive
SIP A Technology Deep Dive Anshu Prasad Product Line Manager, Mitel June 2010 Laith Zalzalah Director, Mitel NetSolutions What is SIP? Session Initiation Protocol (SIP) is a signaling protocol for establishing
Penetration Testing with Kali Linux
Penetration Testing with Kali Linux PWK Copyright 2014 Offensive Security Ltd. All rights reserved. Page 1 of 11 All rights reserved to Offensive Security, 2014 No part of this publication, in whole or
6.40A AudioCodes Mediant 800 MSBG
AudioCodes Mediant 800 MSBG Page 1 of 66 6.40A AudioCodes Mediant 800 MSBG 1. Important Notes Check the SIP 3 rd Party Validation Website for current validation status. The SIP 3 rd party Validation Website
The SIP School- 'Mitel Style'
The SIP School- 'Mitel Style' Course Objectives This course will take delegates through the basics of SIP into some very technical areas and is suited to people who will be installing and supporting SIP
Black Box Analysis and Attacks of Nortel VoIP Implementations
Black Box Analysis and Attacks of Nortel VoIP Implementations Richard Gowman, CISSP Eldon Sprickerhoff, CISSP CISA www.esentire.com Copyright 2007 esentire, Inc. Who we are... esentire, Inc. Based out
Application Note. Onsight Connect Network Requirements V6.1
Application Note Onsight Connect Network Requirements V6.1 1 ONSIGHT CONNECT SERVICE NETWORK REQUIREMENTS... 3 1.1 Onsight Connect Overview... 3 1.2 Onsight Connect Servers... 4 Onsight Connect Network
DoS/DDoS Attacks and Protection on VoIP/UC
DoS/DDoS Attacks and Protection on VoIP/UC Presented by: Sipera Systems Agenda What are DoS and DDoS Attacks? VoIP/UC is different Impact of DoS attacks on VoIP Protection techniques 2 UC Security Requirements
Avaya IP Office 8.1 Configuration Guide
Avaya IP Office 8.1 Configuration Guide Performed By tekvizion PVS, Inc. Contact: 214-242-5900 www.tekvizion.com Revision: 1.1 Date: 10/14/2013 Copyright 2013 by tekvizion PVS, Inc. All Rights Reserved.
ARCHITECTURES TO SUPPORT PSTN SIP VOIP INTERCONNECTION
ARCHITECTURES TO SUPPORT PSTN SIP VOIP INTERCONNECTION 10 April 2009 Gömbös Attila, Horváth Géza About SIP-to-PSTN connectivity 2 Providing a voice over IP solution that will scale to PSTN call volumes,
VoIP Trunking with Session Border Controllers
VoIP Trunking with Session Border Controllers By Chris Mackall Submitted to the Faculty of the Information Technology Program in Partial Fulfillment of the Requirements for the Degree of Bachelor of Science
Best Practices for Securing IP Telephony
Best Practices for Securing IP Telephony Irwin Lazar, CISSP Senior Analyst Burton Group Agenda VoIP overview VoIP risks Mitigation strategies Recommendations VoIP Overview Hosted by VoIP Functional Diagram
Vulnerabilities in SOHO VoIP Gateways
Vulnerabilities in SOHO VoIP Gateways Is grandma safe? Peter Thermos [email protected] [email protected] 1 Purpose of the study VoIP subscription is growing and therefore security
Unregister Attacks in SIP
Unregister Attacks in SIP Anat Bremler-Barr Ronit Halachmi-Bekel Interdisciplinary Center Herzliya Email: {bremler,halachmi.ronit}@idc.ac.il Jussi Kangasharju Darmstadt University of Technology [email protected]
Threats to be considered (1) ERSTE GROUP
VoIP-Implementation Lessons Learned Philipp Schaumann Erste Group Bank AG Group IT-Security [email protected] http://sicherheitskultur.at/ Seite 1 Threats to be considered (1) Eavesdropping
SIP Trunking with Microsoft Office Communication Server 2007 R2
SIP Trunking with Microsoft Office Communication Server 2007 R2 A Dell Technical White Paper By Farrukh Noman Dell Product Group - Enterprise THIS WHITE PAPER IS FOR INFORMATIONAL PURPOSES ONLY, AND MAY
Transparent weaknesses in VoIP
Transparent weaknesses in VoIP Peter Thermos [email protected] 2007 Palindrome Technologies, All Rights Reserved 1 of 56 Speaker Background Consulting Government and commercial organizations,
TECHNICAL CHALLENGES OF VoIP BYPASS
TECHNICAL CHALLENGES OF VoIP BYPASS Presented by Monica Cultrera VP Software Development Bitek International Inc 23 rd TELELCOMMUNICATION CONFERENCE Agenda 1. Defining VoIP What is VoIP? How to establish
Voice over IP Security
Voice over IP Security Patrick Park Cisco Press Cisco Press 800 East 96th Street Indianapolis, Indiana 46240 USA vii Contents Introduction xvii Part I VoIP Security Fundamentals 3 Chapter 1 Working with
VoIP Phreaking Introduction to SIP Hacking. Hendrik Scholz [email protected] http://www.wormulon.net/ 22C3, 2005 12 27 Berlin, Germany
VoIP Phreaking Introduction to SIP Hacking Hendrik Scholz [email protected] http://www.wormulon.net/ 22C3, 2005 12 27 Berlin, Germany Agenda What is Voice Over IP? Infrastucture Protocols SIP attacks
The use of IP networks, namely the LAN and WAN, to carry voice. Voice was originally carried over circuit switched networks
Voice over IP Introduction VoIP Voice over IP The use of IP networks, namely the LAN and WAN, to carry voice Voice was originally carried over circuit switched networks PSTN (Public Switch Telephone Network)
Avaya Aura SIP Trunking Training
Avaya Aura SIP Trunking Training 5 Day Course Lecture & Demo WHO NEEDS TO ATTEND This class is suited to those who are new to administering Avaya systems and would like to know more about the SIP protocol.
SIP Trunking Steps to Success, Part One: Key Lessons from IT Managers Who ve Been There
SIP Trunking Steps to Success, Part One: Key Lessons from IT Managers Who ve Been There Q&A Session Date: Wednesday, April 13, 2011 Q: You have to partner with a provider in order to do SIP trunking, correct?
How to Configure the Avaya IP Office 6.1 for use with Integra Telecom SIP Solutions
How to Configure the Avaya IP Office 6.1 for use with Integra Telecom SIP Solutions Overview This document provides a reference for configuration of the Avaya IP Office to connect to Integra Telecom SIP
iscsi Security (Insecure SCSI) Presenter: Himanshu Dwivedi
iscsi Security (Insecure SCSI) Presenter: Himanshu Dwivedi Agenda Introduction iscsi Attacks Enumeration Authorization Authentication iscsi Defenses Information Security Partners (isec) isec Partners Independent
Convergence Technologies Professional (CTP) Course 1: Data Networking
Convergence Technologies Professional (CTP) Course 1: Data Networking The Data Networking course teaches you the fundamentals of networking. Through hands-on training, you will learn the vendor-independent
MODELLING OF INTELLIGENCE IN INTERNET TELEPHONE SYSTEM
MODELLING OF INTELLIGENCE IN INTERNET TELEPHONE SYSTEM Evelina Nicolova Pencheva, Vessela Liubomirova Georgieva Department of telecommunications, Technical University of Sofia, 7 Kliment Ohridski St.,
Cconducted at the Cisco facility and Miercom lab. Specific areas examined
Lab Testing Summary Report July 2009 Report 090708 Product Category: Unified Communications Vendor Tested: Key findings and conclusions: Cisco Unified Communications solution uses multilayered security
Configuration Notes 283
Mediatrix 4400 Digital Gateway VoIP Trunking with a Legacy PBX June 21, 2011 Proprietary 2011 Media5 Corporation Table of Contents Table of Contents... 2 Introduction... 3 Mediatrix 4400 Digital Gateway
Voice over IP Fundamentals
Voice over IP Fundamentals Duration: 5 Days Course Code: GK3277 Overview: The aim of this course is for delegates to gain essential data networking and Voice over IP (VoIP) knowledge in a single, week-long
Integration of GSM Module with PC Mother Board (GSM Trunking) WHITE/Technical PAPER. Author: Srinivasa Rao Bommana (srinivasrao.bommana@wipro.
(GSM Trunking) WHITE/Technical PAPER Author: Srinivasa Rao Bommana ([email protected]) Table of Contents 1. ABSTRACT... 3 2. INTRODUCTION... 3 3. PROPOSED SYSTEM... 4 4. SOLUTION DESCRIPTION...
Ingate Firewall/SIParator SIP Security for the Enterprise
Ingate Firewall/SIParator SIP Security for the Enterprise Ingate Systems February, 2013 Ingate Systems AB (publ) Tel: +46 8 600 77 50 BACKGROUND... 1 1 NETWORK SECURITY... 2 2 WHY IS VOIP SECURITY IMPORTANT?...
Mediatrix 3000 with Asterisk June 22, 2011
Mediatrix 3000 with Asterisk June 22, 2011 Proprietary 2011 Media5 Corporation Table of Contents Introduction... 3 Network Topology... 3 Equipment Detail... 3 Configuration of the Fax Extension... 4 Configuration
Media Gateway Controller RTP
1 Softswitch Architecture Interdomain protocols Application Server Media Gateway Controller SIP, Parlay, Jain Application specific Application Server Media Gateway Controller Signaling Gateway Sigtran
White paper. SIP An introduction
White paper An introduction Table of contents 1 Introducing 3 2 How does it work? 3 3 Inside a normal call 4 4 DTMF sending commands in sip calls 6 5 Complex environments and higher security 6 6 Summary
Vega 100G and Vega 200G Gamma Config Guide
Vega 100G and Vega 200G Gamma Config Guide This document aims to go through the steps necessary to configure the Vega SBC to be used with a Gamma SIP Trunk. When a SIP trunk is provisioned by Gamma a list
Firewall Support for SIP
Firewall Support for SIP The Firewall Support for SIP feature integrates Cisco IOS firewalls, Voice over IP (VoIP) protocol, and Session Initiation Protocol (SIP) within a Cisco IOS-based platform, enabling
