SHARE
Follow this article on Twitter Facebook LinkedIn Bookmark and Share
Home >> Voice, Data, and IP >> Protocols and Standards

VoIP vulnerabilities

VoIP vulnerabilities

By:  Leon Erlanger  On: 02 Mar 2006 For: Network World Canada Creator

Is enterprise VoIP (voice over IP) due for a security wakeup call or are the threats mostly exaggerated? It depends on who’s talking.

Also potentially menacing are man-in-the-middle attacks (hackers masquerading as a SIP proxy and logging all call activity) and trust exploitation (hacking into a data server that has a trust relationship with VoIP servers to gain access to the latter).

To these, add toll fraud, which is accomplished by hacking into a voice gateway and making international calls at the company’s expense. Then there’s eavesdropping: Users with access to the network and two free, easily available tools called tcpdump and Vomit (Voice over Misconfigured Internet Telephones) can reassemble and convert a voice conversation over IP to a standard WAV file.

Further, VoIP systems often depend on vulnerable applications to function properly. “SQL Slammer attacked Microsoft SQL Server, but because Cisco Call Manager telephony servers depend on SQL server, it disrupted many of them, as well,” Collier says.

QuickLink: 069113










Sign up for our Newsletters












Print |  Views: 709   |   Rating:offoffoffoffoff  (0 votes)
Rate this article on a scale of
1 to 5 stars,5 being the best.




Leon Erlanger Leon Erlanger is a contributor to the International Data Group (IDG) News Service, which publishes global technology stories from bureaus around the world to more than 300 publications in more than 60 countries.

Related Content

6 things to consider when installing IP telephony
6 things to consider when installing IP telephonyA speaker at IT360 gave some tips on security, quality of service, power over Ethernet, staffing, data networks and redundancy. Find out what analyst Matthias Machowinski has to say and how the Phybridge Uniphyer works
1.3 million DNS servers still vulnerable to cache-poisoning
1.3 million DNS servers still vulnerable to cache-poisoning At least one in 10 servers is still susceptible to domain name systems attack despite fixes being made available more than four months ago
Six quizzical VoIP issues
Six quizzical VoIP issuesCanadian governments and other public sector agencies have identified VoIP as one of the most useful technologies to help them meet the high expectation for citizen service. VoIP may be hot, but all that heat can raise some issues. We resolve to answer some of the more pressing questions you might be facing.
Voice Mobility announces new migration tool for Avaya servers
vancouver-based unified communication solutions company voice mobility released a new migration tool today called virtual silver suitcase (vss). designed sp
blog comments powered by Disqus