Synopsis: Blue Box #66: Cisco/Grandstream/Thomson VoIP security vulnerabilities, Skype outage, VoiceCon coverage, VoIP security news, listener comments and more..
Welcome to Blue Box: The VoIP Security Podcast #66, a 56-minute podcast from Dan York and Jonathan Zar covering VoIP security news, comments and opinions.
Download the show here (MP3, 21MB) or subscribe to the RSS feed to download the show automatically.
You may also listen to this podcast right now:
Show Content:
Show Content:
- 00:20 - Intro to the show, contact information and how to provide comments. Welcome to all the new listeners - and to all those listeners who have been here for so long!
- 03:00 - Programming notes
- First Blue Box video – what did you all think? Should we do more of these? (Anyone interested in helping?)
- Upcoming interviews: excellent SIP security session with Cullen Jennings, update interview with Dave Endler/Mark Collier, contribution from Brenno deWinter of a Phil Zimmermann interview
- Apologies if any of you had a problem downloading shows last week. Our hosting provider, LibSyn had a DNS configuration issue and people couldn’t get to the site.
- 07:55 - 3 messages SIP Remote DOS on Cisco 7940 SIP Phone – and Cisco response
- 12:17 - SIP remote attack on Grandstream SIP Phone GXV-3000
- 16:45 -Remote DOS on Thomson SIP phone ST 2030 using the VIA header and Remote DOS on Thomson SIP phone ST 2030 using the TO header
- 19:55 - Cisco: Voice Vulnerabilities in Cisco IOS and Cisco Unified Communications Manager
- 21:55 - Asterisk AST-2007-021 – Crash from invalid/corrupted MIME bodies when using voicemail with IMAP storage (note the move away from “ASA” which Avaya had been using)
- 24:30 - Sipera softphone issue – still working with the vendor
- 25:20 - Skype outage:
- Voice of VOIPSA: It’s official – Skype blames the outage on Microsoft
- Skype responds The Microsoft connection clarified and Dan’s commentary
- 33:51 - ZDNet: Sipera introduces new enterprise VoIP security toolset
- 34:32 - Voice of VoIPSA VoiceCon coverage: SIP Security and IP Telephony Security Threats and Countermeasures
- 35:36 - VoIPNews: Hacking VoIP Exposed (interview with Mark Collier)
- 37:03 - eWeek Channel Insider: VOIP Security Requires Layered Approach, Experts Say and a blog reaction
- 37:23 - Computerworld: VoIP requires attention to security best practices
- 38:30 - Network World: VoIP hacker talks: Service provider nets easy pickings based on Telecom Junkies podcast: Interview with a VoIP Hacker - also tricityherald.com: Spokane man heads to prison for hacking
- 39:14 - IEEE Digital Library: Service Provider Implementations of SIP Regarding Security
- 40:32 - News Releases:
- Enterasys secures enterprise VoIP
- Fortinet Adds UTM for Small Offices (mention of VoIP and 3G)
- ResearchAndMarkets releases a new report on VoIP security
- Raketu Realizes Over 50% Jump in Service Subscribers in Wake of Skype Outage
- 42:50 - Upcoming shows:
- Sept 10-12, Los Angeles, CA, USA ITEXPO West 2007
- Oct 29-Nov 1, Boston, USA, Fall 2007 VON
- 43:44 - comment (email) from Rhodri Davies about PSTN being more secure
- 48:12 - comment (email) from Atilla asking about slides for SE 19
- 49:01 - comment (email) from Jose Luis about OCS
- 52:46 - comment (email) from Sachin Joglekar about video
- 54:31 - Review of the last week's traffic on the VOIPSEC public mailing list
- 55:09 - Wrap-up of the show
- Jonathan mentions that Jaxtr received $10million in VC funding.
- 56:15 - End of show
Comments, suggestions and feedback are welcome either as replies to this post or via e-mail to [email protected]. Audio comments sent as attached MP3 files are definitely welcome and will be played in future shows. You may also call the listener comment line at either +1-206-350-2583 or via SIP to '[email protected]' to leave a comment there.
Thank you for listening and please do let us know what you think of the show.
Comments