Re: VoIP pentest ?

From: Ofir Arkin (ofir_at_sys-security.com)
Date: 10/30/04

  • Next message: jwoloz: "Re: Re: An idiot question"
    Date: Sat, 30 Oct 2004 11:09:48 +0200
    To: Frederic Charpentier <fcharpen@xmcopartners.com>
    
    

    Frederic,

    You might wish to read:
    Security Risk Factors with IP Telephony based Networks

    Found at:
    http://www.sys-security.com/html/projects/VoIP.html

    Although it is not targeting H.323, it speaks about the generic risk
    factors to VoIP.
    Yours,

    Ofir Arkin
    Founder,
    The Sys-Security Group
    http://www.sys-security.com

    On Oct 27, 2004, at 11:28 AM, Frederic Charpentier wrote:

    > Hi all,
    > does anyone have experiences or papers on VoIP pentest/assessment ?
    > Expecting classic OS/Network audits and H323/ASN.1 flaws, I can't find
    > any documentations or papers about flaws in VoIP architecture.
    >
    > Fred.
    >
    >
    >
    >
    >
    > -----------------------------------------------------------------------
    > -------
    > Internet Security Systems. - Keeping You Ahead of the Threat
    >
    > When business losses are measured in seconds, Internet threats must be
    > stopped before they impact your network. To learn how Internet
    > Security Systems keeps organizations ahead of the threat with
    > preemptive intrusion prevention, download the new whitepaper, Defining
    > the Rules of Preemptive Protection, and end your reliance on reactive
    > security technology.
    > http://www.securityfocus.com/sponsor/ISS_pen-test_041001
    > -----------------------------------------------------------------------
    > --------
    >


  • Next message: jwoloz: "Re: Re: An idiot question"

    Relevant Pages

    • Re: Hiding IP in E-Mail..
      ... >>to get around having your IP show, use a web mail service and a proxy to ... >>header for good reason, you shouldn't try and get around this. ... It's only a security risk if your system or network is at risk. ...
      (Security-Basics)
    • Re: Update
      ... First what was the security risk in the first place. ... Second if you use the openSUSE updates, as soon as Novell has done the ... This update fixes three memory corruptions within the X server which ...
      (alt.os.linux.suse)
    • Re: Help in WMI in ASP.net application
      ... WMI is supposed to be Microsoft's implementation of WBEM, ... the only way to achieve this is by hacking and damaging security. ... can't pass it to a second server. ... Using plain text passwords in a COMponent (security risk) ...
      (microsoft.public.scripting.wsh)
    • Re: where are you microsoft? why still no wifi activesync 4??
      ... all i can find for reason to disable network syncing ... over activesync to regular pcs is "security" reasons. ... of a security risk here than a bunch of open TCP ports... ...
      (microsoft.public.pocketpc)
    • Re: [PHP] Parse error?
      ... Thanks for the help, and pointing out the security risk, Chris & David! ... Subject: [PHP] Parse error? ...
      (php.general)