Login, change your address, subscribe to new or manage current magazines or e-newsletter subscriptions
Computerworld Publication PageNetworkWorld Publication PageCIO Canada Publication PageITJobUniverse.ca
- The Information, Communication and Technology (ICT) Job Board
Advanced Search
Knowledge Centres
Content Types
Featured White Papers
Gartner Research Note "Boost SharePoint Performance with an Application Delivery Network"Gartner Research Note "Boost SharePoint Performance with an Application Delivery Network" read more
From fear to value: CIO strategies for propelling business through the economic crisisFrom fear to value: CIO strategies for propelling business through the economic crisis read more
Reaping the rewards of your service-oriented architecture infrastructureReaping the rewards of your service-oriented architecture infrastructure read more
Yuk it Up
Featured White Papers
Download the Network Barometer Report, which aggregates findings from secure network infrastructure assessments conducted for more than 150 organisations around the world. It provides some surprising stats on the state of network (un)readiness prevalent today; the reasons why organisations are failing at remediating known vulnerabilities; recommendations on assessing your own infrastructure, and on ways to improve your state of readiness to support the business; and more.
Early-generation server load-balancing technology has proven to be an invaluable asset, especially for organizations hosting widely utilized Web applications. But business requirements evolve, as do the processes and technologies used to fulfill them. The many changes and trends that have taken hold since SLBs were first introduced expose the need for enterprises to step up from a simple load-balancing solution to a more comprehensive application delivery solution . This paper is intended to serve as a guide for organizations looking to replace their early-generation SLBs, providing details on the top eight criteria to use during an evaluation process.
Featured Spotlight
Keep up on who's hiring, who's downsizing and how the government is helping. News, job opportunities, recruiters and employment lawyers are all available.
Sign-Up for
Enterprise Infrastructure
eNewsletter Delivered Weekly
Click here
Page 1 of 1

Digg it Twitter

IP telephony potential security risk for businesses

COMMENT ON THIS ARTICLE

Enterprises have been warned to avoid IP telephony for staff engaged in teleworking.

While tweaking firewalls for premium VoIP (Voice over Internet Protocol) traffic allows easier remote access in a telework environment, it can also create a potential security hole putting the network at risk.

Security firm Assurance Pty Ltd.'s Assurance.com.au Director Neil Wise said hackers can access a network by locating the address of VoIP Web servers on Google Inc. or by scanning for commonalities in mail server protection lists.

"If users fail to change default settings, hackers can access a hole into the network by locating the VoIP Web server [on Google] and could find usernames and passwords in installation documentation from the vendor's Web site," Wise said.

"Many second-tier Australian telcos ship VoIP phones preconfigured. Installation wizards are designed to have minimal user input to make the technology attractive and to reduce support costs but this makes users vulnerable to a very real attack."

"Hackers could also use IP phones with packet-capture to record conversations, depending on the type of encryption used. For example SIP 1.0 [session initiated protocol] could be easily decoded, while SIP 2.0 is much harder."

Gibson Quai - AAS Pty Ltd.'s Telsyte Director Warren Chaisatien said hackers can leverage the vulnerability to access other Web applications such as online banking.

"While hackers could gain access to networks and steal user accounts to make phone calls, they would cause the most damage in gaining online banking details by monitoring keystrokes," Chaisatien said.

"VoIP phones are subject to these network vulnerabilities because they are an IP application. Users need to realize this and must be very careful and use the same precautions they would for online banking."

User who leave default answering messages are similarly vulnerable, according to 3Com Corp.'s Tipping Point Director of Security Research David Endler because it allows hackers to identify the phones' make and model.

"Vendors' default voicemail answering messages are unique, so calling the system and listening to the message can tell hackers what brand IP phone system is being used and they can tailor their reconnaissance and attacks accordingly," Endler said.

"Firewall scans reveal open ports and tools can map likely protocols; however, VoIP-aware firewalls close these ports so they are only open when they need to carry calls."

Both Wise and Endler said the solution is to disable VoIP Web servers, change default usernames, passwords and voicemail greetings.

COMMENT ON THIS ARTICLE

Page 1 of 1
Send to a Friend  Rate This Page  Print This PageAdd a new comment
Bookmark this article on:
del.icio.us| Digg it| Furl| Google| Technorati| StumbleIt| Yahoo!

Have something to say about this article? Add a new comment

If you find a comment inappropriate, You can notify the moderator by clicking the Report an innapropriate comment icon.
studentReply to this commentReport an innapropriate comment
hi how are you doing today holp you are fine i like to contact you personlly plz send me email with this addtress uchmndy@yahoo.com i could have give you my number but i lost my cellpone i waitting for your respon thanks GOD bless you as you do?
Written by: uche, from benin
ADD A COMMENT
Name:*Your email address will not appear online and will be used only in the event that the editor wishes to contact you personally for additional comment.
City:
Email:
Title:*
Comment:*
* required fields



Related Content
Articles

Events

Book Reviews

Featured Content
Improving business through smart energy and environment policy
Businesses and public entities today face increasing pressure to develop policies that are both good for the planet and good for business. A framework developed by IBM offers businesses and other organizations a comprehensive approach to energy and environmental issues. The framework helps identify and prioritize environmental efforts by breaking down problems and opportunities into seven distinct business areas, which can then be segmented into manageable projects.
E-mail a Friend