Microsoft and VoIP Vulnerabilities

Source: www.voip-news.com

VoIPshield Laboratories says that there are some serious security vulnerabilities in VoIP and Unified Communications (UC) systems that affect applications using media stream protocols like RTP (Real-time Transport Protocol). Among the impacted products are Microsoft Office Communications Server 2007, Office Communicator and Windows Live Messenger.

“Most of the attention in enterprise VoIP/UC security has been paid to the control channel, where SIP and other signaling protocols are used,” said Ken Kousky, CEO of CISSP certification training company IP3 Inc. and adviser to the VoIP Lab at Illinois Institute of Technology. “Until now, the media stream has been largely ignored by the security community as a source of malicious activity. But attacks from these vectors have the potential to be dangerously persistent and widespread.”

If exploited, the vulnerabilities if exploited would cause a Denial of Service (DoS) condition against the entire desktop environment.

“Today’s announcements are just the tip of the iceberg,” said Andriy Markov, director of VoIPshield Labs. “Although they are specific to Microsoft’s applications, similar flaws exist in other VoIP vendors’ products. And many other media stream attacks exist that have more severe implications than service availability. We’re presently validating new research that shows an attacker can gain unauthorized access to an unsuspecting user’s laptop by manipulating the packets of a VoIP phone call. We believe that these attacks can even be made to traverse a PSTN gateway.”

According to VoIPshield:

Effective immediately, customers of VoIPshield’s VoIPguard(TM) VoIP/UC Intrusion Prevention System can download the new signatures using the VoIPshield Update(TM) subscription service. VoIPguard contains over 500 VoIP/UC specific signatures to detect and prevent malicious signalling and media traffic.

Share and Enjoy: These icons link to social bookmarking sites where readers can share and discover new web pages.
  • Digg
  • del.icio.us
  • blinkbits
  • BlinkList
  • Blue Dot
  • Fark
  • Fleck
  • Furl
  • Netscape
  • NewsVine
  • Reddit
  • Shadows
  • Slashdot
  • SphereIt
  • Spurl
  • StumbleUpon
  • Technorati
  • YahooMyWeb
Published on November 13th, 2008 under , , , , , ,





Last 20 posts tagged "VoIP Vulnerabilities"

Microsoft and VoIP Vulnerabilities

Source: www.voip-news.com

p-news.comVoIPshield Laboratories says that there are some serious security vulnerabilities in VoIP and Unified Communications (UC) systems that affect applications using media stream protocols …

Published on November 13th, 2008 under , , , , , ,

Top 5 VoIP Threat Predictions for 2008

Source: snapvoip.blogspot.com

Sipera Lab which is always chasing behind VoIP vulnerabilities and security threats have released a list of threat predictions for 2008. I saw their demo at the Blackhat2007 last year. Following …

Published on January 16th, 2008 under ,

Vonage and Others were Warned about SIP ID Theft, Eavesdropping and Other Exploits

Source: snapvoip.blogspot.com

Sipera, the VoIP security firm that I saw first at BlackHat 2007 has warned VoIP firms before disclosing the vulnerabilities. There are multiple vulnerabilities, advisories and they are listed …


Member of "Hype Media! Network"