SHARE
Follow this article on Twitter Facebook LinkedIn Bookmark and Share
Home >> Information Architecture >> Identity Management

Ottawa firm warns of Microsoft OCS VoIP threat

Ottawa firm warns of Microsoft OCS VoIP threat

By:  Briony Smith  On: 13 Nov 2008 For: ComputerWorld Canada Creator

VoIPshield Systems says media stream attacks could affect Office Communications Server as well as Office Communicator and Windows Live Messager. And this time, the PBX isn't involved

An Ottawa firm that tracks security vulnerabilities in VoIP and unified communications systems has warned of a new threat IT managers should be on the lookout for, particularly if they use Microsoft Office Communications Server.

Standardized packet format media stream protocols (including real-time protocols) are now a target for security breaches, according to VoIPshield Systems Inc. CEO Rick Dalmazzi. This opens up a whole new realm of possible threats based on media stream attacks. “This new category sees things coming through the media stream, and actually through the packets voice call,” he said. “Up to now, all of our announced exploits involved attacking the IP PBX. These new attacks do not go through the PBX. They go directly from user to user.”

More in Network World Canada

VoIP trends and developments

While the new issue also affects industry heavyweights like Cisco, Nortel, and Avaya (companies whose flaws have been pointed out by VoIPshield Systems before), Microsoft is yet another point of entry for the possible security bug, according to VoIPshield.

The Microsoft flaw affects Office Communications Server 2007, Office Communicator, and Windows Live Messenger products, which provide VoIP, presence, and instant messaging, and conferencing, VoIPshield said. The attacks would most likely be based on denial of service.

There could be added hiccups with solving a breach of this kind, as media packets often travel between peers, making it harder to keep track of. Dalmazzi gave an example of how this could happen: “If you and I were communicating by Microsoft Live Messenger, and I used the VoIP feature to call you, I could cause your entire computer to freeze up and necessitate a reboot.”

Mohammad Akif, security and privacy lead for Microsoft Canada, said that, after hearing about this breach (from Network World Canada) that he had raised it with his service team. “We are not aware of any attacks of this kind that customers have reported,” he said. “We are investigating this claim to verify it, and if it is true, the appropriate action to protect our customers.”

If there was a vulnerability, said Akif, it would be included and mentioned in the monthly patch release. A more serious flaw would merit an out-of-cycle update and general announcement.

This burgeoning trend is far from critical mass, according to Info-Tech Research Group research analyst Jayanth Angl. He said that there have been few reported attacks of hackers taking information out of VoIP or unified communications systems, as the few that do happen tend to be around denial of service still.


Sign up for our Newsletters












Print |  Views: 1637   |   Rating:offoffoffoffoff  (0 votes)
Rate this article on a scale of
1 to 5 stars,5 being the best.




Briony Smith Briony Smith is a contributor to the International Data Group (IDG) News Service, which publishes global technology stories from bureaus around the world to more than 300 publications in more than 60 countries.

Related Content

How women can pick up the skills shortage slack
How women can pick up the skills shortage slackExecutives from Microsoft, IBM, CIPS and York University discuss strategies to attract more female recruits, family-friendly work environments and the challenges for internationally educated professionals
Windows flaw enables theft of online game login info
Windows flaw enables theft of online game login infoSecurity experts say a glitch in Vista and other Microsoft Corp. software products enables cyber crooks to steal online game log-in signatures
Security barriers to VoIP and how to handle them
Security barriers to VoIP and how to handle them While VoIP is susceptible to the same threats as other network applications, there are some potential VoIP-specific attacks, says David Endler, chairman and founder of the VoIP Security Alliance.
BlackHat USA 2008 - Day 2 Review
today was the second and final day of the blackhat usa briefings. a lot of great content was presented today. much like yesterday we’ve included some highlevel comments on the various presentations that tadd and i attended. we will be attending defcon over the weekend and tying that into one final posting next week. what follows is our summary.

Comments (0)

No Comments!
Name: (required) eMail: (optional)

Your email address will not appear online and will be used only if the editor wishes to contact you personally for additional comments.