Vonage and Others were Warned about SIP ID Theft, Eavesdropping and Other Exploits

Source: snapvoip.blogspot.com

Sipera, the VoIP security firm that I saw first at BlackHat 2007 has warned VoIP firms before disclosing the vulnerabilities. There are multiple vulnerabilities, advisories and they are listed here.

The tests focused specifically of residential and SMB VoIP service and equipment. I was surprised to find strong authentication, signaling security, and media encryption were lacking, looks like everybody is following Microsoft. Get it Out there first and then we fix it as troubles jump up.

So what does these vulnerabilities do to users? spoofing, eavesdropping, and remote exploits are some of the possibilities.

I will write later today about what you should be looking in VoIP Security.

Following is the news release by Sipera;


Richardson, TX, October 23, 2007 – Sipera VIPER™ Lab, operated by Sipera Systems, the leader in comprehensive VoIP/UC security solutions, today disclosed multiple threat advisories for users of VoIP services and equipment from Vonage, Globe7 and Grandstream. Among other threats, unwitting VoIP users face eavesdropping, spam, spoofing and denial-of-service (DoS) attacks. Full details on these vulnerabilities are posted as an educational security service to Sipera’s customers and the general public at http://www.sipera.com/viper.

Sipera VIPER Lab determined the Vonage VoIP Motorola Phone Adapter (VT 2142-VD) and Vonage service implementations leave users vulnerable to a form of VoIP identity theft, allowing hackers to take over a user’s phone service with a “registration replay attack,” then make and receive calls while impersonating the victim. Incomplete security practices, such as not encrypting traffic, open Vonage users to eavesdropping on private voice and video communications. Hackers can also send multiple SIP INVITE messages to a user, an Internet version of “ringing the phone off the hook” which creates a DoS attack. Leveraging these vulnerabilities, remote attackers can also send malicious messages directly to Vonage users, subjecting them to spam, social engineering and VoIP scams.

“These vulnerabilities create serious privacy and service availability issues for users,” said Krishna Kurapati, Sipera founder/CTO and head of Sipera VIPER Lab. “Vonage, Globe7 and Grandstream customers can no longer assume that their VoIP providers are automatically securing their services, but they should demand best security practices be followed as a condition of becoming a customer. Sipera VIPER Lab will continue to proactively identify VoIP threats and assist VoIP providers to implement best security practices before attacks occur.”

Sipera VIPER Lab also found issues with European provider Globe7’s online account access, as a result of utilizing unsecured connections and employing a weak encryption scheme. This allows hackers to access confidential name, password and account balance data, as well as steal VoIP service to make and receive calls, masked as a legitimate Globe7 user. Likewise, Sipera VIPER Lab established the Grandstream HandyTone-488 PSTN-to-VoIP adapter is vulnerable to buffer overflows and fragmented packet attacks. By sending a specially crafted SIP INVITE message to public IP addresses, attackers can disconnect legitimate Grandstream users.

Sipera VIPER Lab is comprised of experienced VoIP security researchers operating globally 24/7/365. Since its inception in 2003, Sipera VIPER Lab has identified thousands of vulnerabilities and security threats which include fuzzing, floods and distributed floods, spoofing, stealth attacks and spam. VIPER Lab research is used to continuously improve the Sipera IPCS products that protect, control and enable real-time unified communications for enterprises and service providers. Sipera VIPER Lab also recently launched a blog to discuss ongoing VoIP attacks and VoIP/UC vulnerabilities at http://www.sipera.com/viper/blog.

Share and Enjoy: These icons link to social bookmarking sites where readers can share and discover new web pages.
  • Digg
  • del.icio.us
  • blinkbits
  • BlinkList
  • Blue Dot
  • Fark
  • Fleck
  • Furl
  • Netscape
  • NewsVine
  • Reddit
  • Shadows
  • Slashdot
  • SphereIt
  • Spurl
  • StumbleUpon
  • Technorati
  • YahooMyWeb





Last 20 posts tagged "Vonage"

Vonage Releases Third Quarter Results

Source: www.voip-news.com

p-news.comVonage Holdings Corp. has announced its third quarter results. Revenue grew by seven percent over the previous year to $226 million.
“We reported our fourth consecutive quarter of …

Published on November 7th, 2008 under , , , , , ,

Vonage Has a New Patent

Source: www.voip-news.com

p-news.comVonage has a new patent. It’s for something called “Method and Apparatus for Enhanced Internet Telephony.” According to the company, “The invention, which was filed for patent …

Published on October 23rd, 2008 under , , , , ,

Friday Links: Vonage, Skype and more

Source: www.voip-news.com

p-news.comIke Elliot of Telecosm is taking a long-term hiatus from blogging due to taking a job with Level3. Apparently he and the company think that blogging then becomes a conflict of interest …

Published on October 10th, 2008 under , , , , ,

Wednesday Links: Did Vonage Screw Up?

Source: www.voip-news.com

p-news.comVoIP Watch wonders if Vonage just screwed up when Verizon sued it. After all, Cox won the lawsuit that Verizon filed against its company. Read it here.
Smith on VoIP has some speculative …

Published on October 9th, 2008 under , , , , ,

Friday Links: Collaboration, Vonage

Source: www.voip-news.com

p-news.comI was speaking with a woman this week about her phone service. It seems that she has been having trouble with the clarity of her Vonage. She’d been perfectly happy with it until it …

Published on August 16th, 2008 under , , , , ,

Vonage’s New Vonage Pro

Source: www.voip-news.com

p-news.comVonage has introduced a new option for its service. Vonage Pro revamps its options to offer more to customers. The service includes Vonage Digital Voice, Vonage Companion, Vonage Visual …

Published on August 1st, 2008 under , , ,

Vonage Has a New CEO

Source: www.voip-news.com

p-news.comWell, that didn’t take long. Vonage announced that they were letting interim CEO Jeffrey Citron go last week. Today, they announced that Marc Lefar has been named chief executive …

Published on July 31st, 2008 under , , , ,

911 Law Pleases Vonage

Source: www.voip-news.com

p-news.comAww, isn’t that cute?
Vonages is pleased to bits about the New and Emerging Technologies 911 Improvement Act of 2008 that President George W. Bush signed into law this week.
Of course …

Published on July 25th, 2008 under , , , , ,

Comcast To Work With Vonage

Source: www.voip-news.com

p-news.comComcast, Comcast, Comcast.
The television and internet provider is at it again — blocking VoIP traffic. Do they ever learn?
Now, they are saying they will work with Vonage to ensure …

Published on July 11th, 2008 under , , , , ,

Did Comcast Just Admit to Vonage Traffic-shaping?

Source: gigaom.com

I received an emailed press release from Comcast this morning about their plans to work with Vonage to address “the reasonable network management of Internet services” that left me a tad …

Published on July 9th, 2008 under , , , ,

No More AT&T Callvantage?

Source: gigaom.com

AT&T, long before it merged with SBC had made a half-hearted attempt at getting into consumer VoIP by selling a service called, CallVantage. It was surprisingly good, especially its call …

Published on July 4th, 2008 under , , , , ,

Wednesday Links: Vonage, Fax over IP

Source: www.voip-news.com

p-news.comWhat could a company want with a memory stick that turns any PC into a VoIP phone? What could they want with it so much that they would spend $6.5 billion to get it? Interesting stuff. …

Published on June 4th, 2008 under , , , , , , ,

Vonage Won’t Comment About Reliabiity…Does Anyone Wonder Why?

Source: andyabramson.blogs.com

Vonage has a problem and its getting worse. Long ridiculed for poor customer service and lousy quality now they’ve chosen to take the non-comment approach when they get asked about that …

Published on May 31st, 2008 under , , , , , ,

Thanks to Cable, VoIP in the U.S. Is Booming

Source: gigaom.com

Despite all the troubles with VoIP service providers such as SunRocket and Vonage, VoIP as a technology seems to be doing quite well in the U.S., according to data from Telegeography. As of …

Published on May 19th, 2008 under , , , , , , , , ,

Vonage Put Under The Ikeroscope

Source: andyabramson.blogs.com

I happen to always enjoy reading Ike Elliott’s analysis of companies in the VoIP space that are publicly traded. God does his microscopic analysis remind me of what we used to see from …

Published on May 17th, 2008 under , , , , ,

Now Vonage Will Also Sell Broadband

Source: gigaom.com

After a really rough 2007, Vonage (VG), the independent voice-over-IP service provider, seems to be having a better 2008. This morning the company reported its first-quarter 2008 financial results, …

Published on May 8th, 2008 under , , , , ,

Vonage To Use Social Media To Communicate

Source: andyabramson.blogs.com

It looks like Vonage is gearing up for some efforts in the media if I read the tea leaves properly.
They hired a new PR firm and one of the things they plan on doing is deploying a social media …

Published on May 2nd, 2008 under , , , , , , ,

Vonage, Connecticut Reach $70K Settlement

Source: www.voip-news.com

p-news.comVonage and the state of Connecticut have reached a settlement deal in the May 2005 lawsuit in which the state claimed that Vonage didn’t inform customers of 911’s deficiency on …

Published on March 26th, 2008 under , , , , , ,

March 5, 2008: Vonage’s Cranky Creditors

Source: gigaom.com

SAI: Google StreetView Competitor Everyscape Gets $7M
News.com: In Tech Support Obama Beats Clinton
BusinessWeek: Clearwire and Sprint: Squeezed Together?
Fortune: Yahoo! Playing for Time in

Published on March 5th, 2008 under , , , , , , , , , , , , , , ,

Comcast and Vonage Compared

Source: andyabramson.blogs.com

A few weeks back Ike Elliott wrote about the differences in growth and momentum between Comcast and Vonage.
Here’s my take:
1) Vonage churn is one, if not the highest in the telco industry. …

Published on February 24th, 2008 under , , , , ,

Member of "Hype Media! Network"