Re: [fw-wiz] VOIP versus PBX

From: Marcus J. Ranum (mjr_at_ranum.com)
Date: 07/21/05

  • Next message: Paul Melson: "RE: [fw-wiz] Forwarding traffic to an active IDS/Firewall"
    To: "Yehuda Goldenberg" <Yehuda@nj.essutton.com>, <firewall-wizards@honor.icsalabs.com>
    Date: Thu, 21 Jul 2005 11:25:53 -0400
    
    

    Yehuda Goldenberg wrote:
    >What else do I have to worry about with VOIP?

    We don't know much about the security of VOIP PBXes but since they were
    largely developed by "phone guys" I'm comfortable assuming that there is little
    or none. So you have the issue of accidental or deliberate denial-of-service
    against desktop phones, but also the potential that the PBX can be attacked
    over the in-band network that's used to manage it. Because you *KNOW*
    that whoever manages the PBX will want to access it from their desktop
    workstation not a workstation on a separate VLAN.

    The protocols used for VOIP are "problematic" let us say. "Designed by
    people who ignored security" might be a less tactful way to say it.
    "Moronic" also comes to mind. That said, there appear to be so many of
    them that it's hard to nail down whether you'll have a problem or not; it
    depends on what you wind up using and where/how. The situation is
    comparable to wireless - getting it all working in default mode is easy.
    Getting it all working safely is hard and may be impossible.

    Lastly, inevitably, someone will want to do VOIP with the outside world.
    For cost saving reasons, or whatever (but really so they can talk to their
    kid in college for "free") so there will be a move to let the VOIP through
    your firewall. Then you will discover VOIP-spam. Of course the guys
    who designed VOIP systems didn't take that into account, either.

    Like every other "new widget technology" VOIP will eventually mature
    just around the time that it's being replaced by some cool new new
    widget technology that didn't take into account any lessons learned
    from the last new widget technology. But there will be loads of vendors
    with a $15,000 1-U rack-mount appliance that offers a complete solution
    that fixes all those problems.

    mjr.

    _______________________________________________
    firewall-wizards mailing list
    firewall-wizards@honor.icsalabs.com
    http://honor.icsalabs.com/mailman/listinfo/firewall-wizards


  • Next message: Paul Melson: "RE: [fw-wiz] Forwarding traffic to an active IDS/Firewall"

    Relevant Pages

    • RE: Converged Network Assessment - VoIP Security
      ... VoIP Conference 2006 participants requirements: ... CPD Network Security Technologies ... Converged Network Assessment - VoIP Security ... convergence is going to have a lot to do with integrating VoIP ...
      (Pen-Test)
    • Risks Digest 24.32
      ... Report on security risks of applying CALEA to VoIP ...
      (comp.risks)
    • SQL Voice Over IP Exposed!
      ... VOIP can Lower telecom costs and help with network ... consolidation -- and cause security problems if not handled right. ... "The idiosyncrasies of voice data may strain your security system to ...
      (comp.dcom.telecom)
    • RE: VOIP: RTP vs SRTP
      ... There's no question that VoIP Security is a BIG issue. ... vulnerability management needs. ... Download FREE whitepaper on how a managed service can help you: ...
      (Pen-Test)
    • RE: Question on VoIP security
      ... > I am currently facing an Intranet VoIP project (will be restricted to ... > 1 organization's Intranet, geographically disperse), from the security ... network, but treat the security side of it as you would any data port. ... just got a little easier as the phones are all going to have the same ...
      (Security-Basics)