problem in voip environment

From: Pasquiet Loic (M.) (Loic.Pasquiet_at_Polytechnique.fr)
Date: 09/11/04

  • Next message: David S. Miller: "Re: Linux 2.4.27 SECURITY BUG - TCP Local (probable Remote) Denial of Service"
    Date: Sat, 11 Sep 2004 22:53:44 +0200
    To: <bugtraq@securityfocus.com>
    
    

    1. Topic
    Security issues have been identified that allows an attacker to
    compromise ip phones.

    2. Description

    We are testing voip solutions and here's what we've found :

    take a layer 2 switch, here, an avaya cajun switch like P33xT or
    P334T-ML (layer 2).

    configure 2 ports like it's recommended in voip, like this :

    a vlan id x on port 1 and a vlan-static-bindig id y for telephony (x is
    the pvid is or native vlan or default vlan)
    a vlan id x on port 2 and a vlan-static-bindig id y for telephony
    we are in mode access so ports are not 802.1q or in trunk mode ...
    plug an ip phone on port 1 in 10.10.10.10/24
    plug a PC on port 2 in 10.10.10.11/24 (the pc doesn't tag his frames)
    (if you plug the PC behind another ip phone, the result is the same)

    try to ping the ip phone ... it's ok.
    You can now easily flood all ip phones on the same switch or the entire
    stack !

    3. Affected products

    Avaya Cajun P33xT , P33xT-ML and more ?

    4.Solution

    Actually in the product house for Avaya.

    With other switch, we know that you can bypass this hole by activate a
    'untagpvidonly' command on the ports 1 et 2
    or something equivalent according to constructors ...

    In trunk mode or in full 802.1q mode, we can do the 'same' thing by
    simply tagging frames from your PC.
    So, you are in telephony vlan ...

    We are also interesting in deployment experience and the response about
    fully tagging ports or not ...

    thanks,
    loic

     


  • Next message: David S. Miller: "Re: Linux 2.4.27 SECURITY BUG - TCP Local (probable Remote) Denial of Service"

    Relevant Pages

    • Re: Configuring Cisco IPS High Bandwidth Using EtherChannel Load Balancing
      ... "If the paired interfaces are connected to the same switch, ... VLANs for the two ports. ... IPS is able to track traffic per-VLAN, ... VLAN Pair mode uses one interface only and this is the only supported ...
      (Focus-IDS)
    • RE: ID sensors on a Cisco Catalyst 6509 switch
      ... ID sensors on a Cisco Catalyst 6509 switch ... capability using the VLAN ACLs. ... We'll use ports 1-4 on the 10/100 mod. ...
      (Focus-IDS)
    • Re: Creating VLANS on 6500 IOS 12.2
      ... How do you just create a basic VLAN for a few ports so the devices in ... so they want me to give them two ports of the ... On a Cisco layer-3 capable switch running IOS there are two ways to ... configure a layer 3 interface. ...
      (comp.dcom.sys.cisco)
    • Re: 470-48T switches can I do this?
      ... My fibers are going into the core, one is on the 172.16.x.x vlan while ... those that are used on the core switch. ... set the ports or MLT on ES470 and core switch as trunk port. ...
      (comp.dcom.sys.nortel)
    • RE: ID sensors on a Cisco Catalyst 6509 switch
      ... ID sensors on a Cisco Catalyst 6509 switch ... capability using the VLAN ACLs. ... We'll use ports 1-4 on the 10/100 mod. ... selection of capture ports. ...
      (Focus-IDS)