<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0" xml:base="http://www.fiercevoip.com" xmlns:dc="http://purl.org/dc/elements/1.1/">
<channel>
 <title>VoIP Security</title>
 <link>http://www.fiercevoip.com/tags/voip-security</link>
 <description></description>
 <language>en</language>
<item>
 <title>VoIP and tech&#039;s murky role in Mumbai attacks</title>
 <link>http://www.fiercevoip.com/story/voip-and-techs-murky-role-mumbai-attacks/2008-12-03?utm_medium=rss&amp;utm_source=rss&amp;cmp-id=OTC-RSS-FV0</link>
 <description>&lt;p&gt;Reports out of Mumbai&amp;nbsp;claim the 10 member Lashker-e-Taiba terrorist attack group was steeped in off-the-shelf consumer technology.&amp;nbsp; The FBI is reportedly assisting Indian intelligence agencies in deciphering &quot;Internet telephony signatures&quot; originating in Pakistan.&lt;/p&gt;
&lt;p&gt;Terrorist controllers/handlers in Pakistan used VoIP to communicate with the Mumbai attack cell, with calls flowing out of Pakistan to satellite phones carried by the group. Conducting traffic analysis - number of calls, type of calls, frequency, and length - on the communications stream between Pakistan and Mumbai seems to have occurred, but it is not clear if Indian authorities have access to any media streams - the actual verbal conversations -- of calls.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;The FBI is apparently providing support to trace back when calls started coming in to the cell phone. While not being publicly discussed, it is likely that a United States National Security Agency &quot;vacuum cleaner&quot; system sucked up the broadcasted satellite phone conversations in some form; it is unknown if the communications were encrypted end-to-end, but if they were, it would provide an additional complication to learning the substance of the communications between Lashker-e-Taiba and its Mumbai cell.&lt;/p&gt;
&lt;p&gt;Players on both sides of the terrorist equation - both attackers and defenders - are aware of the use and application of off-the-shelf technologies for attacks.&amp;nbsp;In October, a short report by the U.S. Army 304th Military Intelligence open source intelligence team examined the potential use and application of mobile phone and VoIP technologies by terrorist groups.&amp;nbsp;While the media generally obsessed over the application of Twitter, the report also highlighted the use of GPS, software to change voices in conjunction with VoIP calls, and Google Maps.&lt;/p&gt;
&lt;p&gt;For more:&lt;br /&gt;- The Economic Times of India briefly &lt;a href=&quot;http://economictimes.indiatimes.com/News/PoliticsNation/FBI_files_case_in_Mumbai_terror_attacks/articleshow/3784976.cms&quot;&gt;discusses&lt;/a&gt; FBI involvement in VoIP cracking.&lt;br /&gt;- Ars Technica and the media &lt;a href=&quot;http://arstechnica.com/news.ars/post/20081027-tweets-of-terror-army-microblogs-potential-terrorist-tool.html&quot;&gt;fetished on Twitter&lt;/a&gt; as a terrorist tool, but the U.S. Army report highlights &lt;a href=&quot;http://www.fas.org/irp/eprint/mobile.pdf&quot;&gt;other technologies&lt;/a&gt; as well.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Related articles&lt;a href=&quot;http://www.fiercevoip.com/story/taliban-voip-calls/2008-09-15&quot;&gt;&lt;br /&gt;&lt;/a&gt;&lt;/strong&gt;&lt;a href=&quot;http://www.fiercevoip.com/story/taliban-voip-calls/2008-09-15&quot;&gt;Taliban VoIP calls - FierceVoIP&lt;/a&gt;&lt;br /&gt;&lt;a href=&quot;http://www.fierceonlinevideo.com/story/youtube-take-down-terrorist-videos/2008-09-19&quot;&gt;YouTube to take down terrorist videos - FierceOnlineVideo&lt;/a&gt;&lt;/p&gt;</description>
 <comments>http://www.fiercevoip.com/story/voip-and-techs-murky-role-mumbai-attacks/2008-12-03#comments</comments>
 <category domain="http://www.fiercevoip.com/tags/lawful-intercept">Lawful Intercept</category>
 <category domain="http://www.fiercevoip.com/tags/mumbai">mumbai</category>
 <category domain="http://www.fiercevoip.com/tags/terrorist">terrorist</category>
 <category domain="http://www.fiercevoip.com/tags/terrorist-attack">terrorist attack</category>
 <category domain="http://www.fiercevoip.com/tags/voip-0">VoIP</category>
 <category domain="http://www.fiercevoip.com/tags/voip-security">VoIP Security</category>
 <category domain="http://www.fiercevoip.com/tags/voip-technologies">Voip Technologies</category>
 <category domain="http://www.fiercevoip.com/tags/voip-technology">VoIP Technology</category>
 <pubDate>Wed, 03 Dec 2008 11:38:30 -0500</pubDate>
 <dc:creator>Doug Mohney</dc:creator>
 <guid isPermaLink="false">3013 at http://www.fiercevoip.com</guid>
</item>
<item>
 <title>SPOTLIGHT: Hacking VoIP gets reviewed</title>
 <link>http://www.fiercevoip.com/story/spotlight-hacking-voip-gets-reviewed/2008-11-23?utm_medium=rss&amp;utm_source=rss&amp;cmp-id=OTC-RSS-FV0</link>
 <description>&lt;p&gt;The recently released &quot;Hacking VoIP&quot; has received a quick review via desicritics.org. Targeted to VoIP administrators and other IT personnel working with VoIP on a daily basis, the book goes through a series of discussions and exercises discussing SIP signaling and H.323, as well as media-layer issues via RTP and IAX issues in signaling and media.&amp;nbsp;There&#039;s the usual tour of free tools and a wrap at the end with countermeasures and auditing. No Starch Press is listing the 232 page tome at $44.95, but Amazon.com is offering it for $29.67 with free shipping.&lt;/p&gt;
&lt;p&gt;For more:&lt;br /&gt;- Desicritics.org book review. &lt;a href=&quot;http://desicritics.org/2008/11/23/123748.php&quot;&gt;Post&lt;/a&gt;. &lt;br /&gt;- Dr. Dobb&#039;s CodeTalk also &lt;a href=&quot;http://dobbscodetalk.com/index.php?option=com_myblog&amp;amp;show=Hacking-VoIP-Book-Review.html&amp;amp;Itemid=29&quot;&gt;reviews&lt;/a&gt; &lt;u&gt;Hacking VoIP&lt;/u&gt;&lt;/p&gt;</description>
 <comments>http://www.fiercevoip.com/story/spotlight-hacking-voip-gets-reviewed/2008-11-23#comments</comments>
 <category domain="http://www.fiercevoip.com/tags/h-323">H.323</category>
 <category domain="http://www.fiercevoip.com/tags/hacking-voip">Hacking VoIP</category>
 <category domain="http://www.fiercevoip.com/tags/no-starch-publishing">No Starch Publishing</category>
 <category domain="http://www.fiercevoip.com/tags/rtp">Rtp</category>
 <category domain="http://www.fiercevoip.com/tags/sip">SIP</category>
 <category domain="http://www.fiercevoip.com/tags/voip-0">VoIP</category>
 <category domain="http://www.fiercevoip.com/tags/voip-security">VoIP Security</category>
 <pubDate>Sun, 23 Nov 2008 21:54:49 -0500</pubDate>
 <dc:creator>Doug Mohney</dc:creator>
 <guid isPermaLink="false">2991 at http://www.fiercevoip.com</guid>
</item>
<item>
 <title>Thinking about Vishing VoIP security</title>
 <link>http://www.fiercevoip.com/story/thinking-about-vishing-voip-security/2008-11-19?utm_medium=rss&amp;utm_source=rss&amp;cmp-id=OTC-RSS-FV0</link>
 <description>&lt;p&gt;How do you avoid being phished over VoIP? No, we&#039;re not talking about a Ben and Jerry&#039;s flavor, we&#039;re discussing the tactic of being called up over the phone and being socially engineered into disclosing confidential information. &amp;nbsp;&lt;/p&gt;
&lt;p&gt;Phishing is now a widespread tactic, with bogus emails spammed out on a daily basis. Initial attacks were mostly for-profit in nature, with an inbox letter posing as a bank or the IRS requesting security and personal information. The information would then be utilized by the attacker for either a simple credit card exploit or a more elaborate identity theft exploit.&amp;nbsp;Varients such as Spear Phising and Vishing are now in vogue, but phishing attacks can be broken down into four parts: Redirect, Disclosure, Impersonation and Unauthorized Usage.&lt;/p&gt;
&lt;p&gt;Vishing is a faster way to gain information if the attacker feels confident in his or her social engineering skills. In the days before computers, this was known as &quot;The art of the con.&quot; &amp;nbsp;Regardless, we still have to wonder if J. Michael Straczynski understood he was writing a double-entendre when he penned the line, &quot;&lt;a href=&quot;http://www.imdb.com/title/tt0149437/&quot;&gt;Who do you serve? And who do you trust?&lt;/a&gt;&quot; A look at the general practices of phishing can help in the development of strategies against vishing.&lt;/p&gt;
&lt;p&gt;For more:&lt;br /&gt;- TopTechNews breaks down Phishing and Vishing. &lt;a href=&quot;http://www.toptechnews.com/news/Phishing--Don-t-Be-Catch-of-the-Day/story.xhtml?story_id=10300BJQT59U&amp;amp;full_skip=1&quot;&gt;Article&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Related articles&lt;/strong&gt;&lt;br /&gt;&lt;a href=&quot;http://www.fiercevoip.com/story/trend-vishing-voip-phishing-on-the-rise/2006-08-01&quot;&gt;Trend: &quot;Vishing,&quot; VoIP phishing on the rise - FierceVoIP&lt;/a&gt;&lt;br /&gt;&lt;a href=&quot;http://www.fiercevoip.com/story/voip-security-and-circle-trust/2008-05-06?utm_medium=rss&amp;amp;utm_source=voip_Smtp&amp;amp;cmp-id=OTC-RSS-FV0&quot;&gt;VoIP Security and the Circle of Trust - FierceVoIP&lt;/a&gt;&lt;/p&gt;</description>
 <comments>http://www.fiercevoip.com/story/thinking-about-vishing-voip-security/2008-11-19#comments</comments>
 <category domain="http://www.fiercevoip.com/tags/attacker">Attacker</category>
 <category domain="http://www.fiercevoip.com/tags/exploit">Exploit</category>
 <category domain="http://www.fiercevoip.com/tags/phishing">phishing</category>
 <category domain="http://www.fiercevoip.com/tags/phishing-attacks">Phishing Attacks</category>
 <category domain="http://www.fiercevoip.com/tags/social-engineering">Social Engineering</category>
 <category domain="http://www.fiercevoip.com/tags/vishing">vishing</category>
 <category domain="http://www.fiercevoip.com/tags/voip-0">VoIP</category>
 <category domain="http://www.fiercevoip.com/tags/voip-security">VoIP Security</category>
 <pubDate>Wed, 19 Nov 2008 19:00:21 -0500</pubDate>
 <dc:creator>Doug Mohney</dc:creator>
 <guid isPermaLink="false">2986 at http://www.fiercevoip.com</guid>
</item>
<item>
 <title>SPOTLIGHT: UCSniff VoIP security tool officially unveiled</title>
 <link>http://www.fiercevoip.com/story/spotlight-ucsniff-voip-security-tool-officially-unveiled/2008-11-14?utm_medium=rss&amp;utm_source=rss&amp;cmp-id=OTC-RSS-FV0</link>
 <description>&lt;p&gt;If you haven&#039;t worried enough about VoIP security, UCSniff has been&amp;nbsp;released officially by the Sipera Viper Lab.&lt;/p&gt;
&lt;p&gt;First unveiled at the Toorcon security conference in late September, UCSniff allows you to target users based on corporate directory and/or extensions, record entire voice conversations, discover and hope VLANs, perform man-in-the-middle (MitM) redirection and plenty more. Sipera has now made the tool available for public download, so, if you want to really torque off your security and IT people, you could record and email them a couple of their phone calls.&lt;/p&gt;
&lt;p&gt;If you want really scary/really paranoid thoughts, since UCSniff (and of course, a lot of other security tools) are written in C and available for Linux systems, an attacker could buy a $300 Netbook, install it in a phone closet somewhere, and with a little hackwork, record and email your conversations outside the office.&lt;/p&gt;
&lt;p&gt;Hmm, maybe its time to re-install the old key system...&lt;/p&gt;
&lt;p&gt;For more:&lt;br /&gt;- Read the quick blog &lt;a href=&quot;http://www.darkreading.com/blog/archives/2008/11/new_tool_makes.html&quot;&gt;post&lt;/a&gt; at Dark Reading.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Related articles&lt;br /&gt;&lt;/strong&gt;&lt;a href=&quot;http://www.fiercevoip.com/story/ucsniff-targets-voip-uc-and-inside-job/2008-09-28&quot;&gt;UCSniff targets VoIP, UC, and the inside job - FierceVoIP&lt;/a&gt;&lt;br /&gt;&lt;a href=&quot;http://www.fiercevoip.com/special-reports/sipera-systems-top-voip-company-2008-fiercevoip-fierce-15&quot;&gt;Sipera Systems, Top VoIP Company 2008: FierceVoIP, Fierce 15 ...&lt;/a&gt;&lt;/p&gt;</description>
 <comments>http://www.fiercevoip.com/story/spotlight-ucsniff-voip-security-tool-officially-unveiled/2008-11-14#comments</comments>
 <category domain="http://www.fiercevoip.com/tags/attacker">Attacker</category>
 <category domain="http://www.fiercevoip.com/tags/security-tools">Security Tools</category>
 <category domain="http://www.fiercevoip.com/tags/sipera-systems">Sipera Systems</category>
 <category domain="http://www.fiercevoip.com/tags/voice-conversations">Voice Conversations</category>
 <category domain="http://www.fiercevoip.com/tags/voip-0">VoIP</category>
 <category domain="http://www.fiercevoip.com/tags/voip-2008-fierce-15">VoIP 2008 Fierce 15</category>
 <category domain="http://www.fiercevoip.com/tags/voip-security">VoIP Security</category>
 <pubDate>Fri, 14 Nov 2008 16:19:09 -0500</pubDate>
 <dc:creator>Doug Mohney</dc:creator>
 <guid isPermaLink="false">2957 at http://www.fiercevoip.com</guid>
</item>
<item>
 <title>VoIPShield says Microsoft OCS vulnerable to attacks</title>
 <link>http://www.fiercevoip.com/story/voipshield-says-microsoft-ocs-vulnerable-attacks/2008-11-14?utm_medium=rss&amp;utm_source=rss&amp;cmp-id=OTC-RSS-FV0</link>
 <description>&lt;p&gt;Media stream attacks could affect Micrsofot Office Communications Server (OCS) as well as Office Communicator and Windows Messenger, says VoIPshield Systems. Microsoft is looking into the report.&lt;/p&gt;
&lt;p&gt;VoIPshield says the vulnerabilities affect applications using protocols like RTP and, if exploited, could cause a denial of service (DOS) attack against not only the stated applications, but against the whole desktop. The company is not publicly disclosing details of the vulnerabilities, but says it confidentially discloses full details to affected vendors.&lt;/p&gt;
&lt;p&gt;A spokesperson for VoIPshield Labs said the company is currently validating new research that shows an attacker can gain unauthorized access to an unsuspecting user&#039;s laptop by manipulating the packets of a VoIP phone call - an attack that might even be able to traverse a PSTN gateway. If possible, this attack would be a far more subtle and serious threat than a DoS attack since there would be no warning.&lt;/p&gt;
&lt;p&gt;Microsoft is&amp;nbsp;investigating the finding and recommends both&amp;nbsp;managing patches and keeping all software up to date.&lt;/p&gt;
&lt;p&gt;For more:&lt;br /&gt;- Read the details of the alleged vulnerability.&amp;nbsp; &lt;a href=&quot;http://www.itworldcanada.com/a/News/3304fbfc-492f-42ca-b1a5-080833c1c96b.html&quot;&gt;Article&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Related articles&lt;/strong&gt;&lt;br /&gt;&lt;a href=&quot;http://www.fiercevoip.com/story/arbor-networks-voip-ipv6-emerging-security-threats/2008-11-11?utm_medium=rss&amp;amp;utm_source=rss&amp;amp;cmp-id=OTC-RSS-FV0&quot;&gt;Arbor Networks: VoIP, IPv6 emerging security threats - FierceVoIP&lt;/a&gt;&lt;br /&gt;&lt;a href=&quot;http://www.fiercevoip.com/story/voip-security-and-circle-trust/2008-05-06&quot;&gt;VoIP Security and the Circle of Trust - FierceVoIP&lt;/a&gt;&lt;/p&gt;</description>
 <comments>http://www.fiercevoip.com/story/voipshield-says-microsoft-ocs-vulnerable-attacks/2008-11-14#comments</comments>
 <category domain="http://www.fiercevoip.com/tags/denial-service">Denial Of Service</category>
 <category domain="http://www.fiercevoip.com/tags/denial-service-dos">Denial Of Service Dos</category>
 <category domain="http://www.fiercevoip.com/tags/rtp">Rtp</category>
 <category domain="http://www.fiercevoip.com/tags/security-threats">Security Threats</category>
 <category domain="http://www.fiercevoip.com/tags/unauthorized-access">Unauthorized Access</category>
 <category domain="http://www.fiercevoip.com/tags/voip-0">VoIP</category>
 <category domain="http://www.fiercevoip.com/tags/voip-security">VoIP Security</category>
 <category domain="http://www.fiercevoip.com/tags/voipshield">VoIPShield</category>
 <category domain="http://www.fiercevoip.com/tags/vulnerabilities-0">Vulnerabilities</category>
 <category domain="http://www.fiercevoip.com/tags/vulnerability">Vulnerability</category>
 <pubDate>Fri, 14 Nov 2008 15:56:05 -0500</pubDate>
 <dc:creator>Doug Mohney</dc:creator>
 <guid isPermaLink="false">2956 at http://www.fiercevoip.com</guid>
</item>
<item>
 <title>Arbor Networks: VoIP, IPv6 emerging security threats</title>
 <link>http://www.fiercevoip.com/story/arbor-networks-voip-ipv6-emerging-security-threats/2008-11-11?utm_medium=rss&amp;utm_source=rss&amp;cmp-id=OTC-RSS-FV0</link>
 <description>&lt;p&gt;Summing up responses from &quot;nearly 70&quot; IP network operators around the globe, Arbor Networks issued a gloomy report on worldwide infrastructure security.&amp;nbsp;Malicious attacks (are there any friendly attacks?) continued to grow at &quot;an alarming rate&quot; over the past year, with VoIP and IPv6 labeled as emerging threats.&lt;/p&gt;
&lt;p&gt;Only 21 percent of respondents said they had the tools in place to detect threats against VoIP infrastructure or services, but those that do are prepared with solutions to mitigate threats against VoIP infrastructure and services.&amp;nbsp;The report doesn&#039;t specifically break out VoIP-specific attacks into a unique category, but at least one operator noted &quot;Heavy VoIP scans on the increase recently.&quot;&lt;/p&gt;
&lt;p&gt;Chasing new reviews means that ISPs are increasingly deploying more complex infrastructure to deliver VoIP, video and IP services.&amp;nbsp; Adding more complex infrastructure also adds more opportunities for an attacker because everything gets so much more complicated.&lt;/p&gt;
&lt;p&gt;Arbor says providers need to have deep application insight into IP services and apps - can we say DPI and an Arbor Networks sales brochure? &amp;nbsp;On the other hand,&amp;nbsp;any sarcasm is tampered by reports of DDoS attacks as large as 40 gigabits, with the largest sustained attacks of 24 and 17 Gbps respectively.&amp;nbsp;When you stop to consider that all but the largest carriers run at about 10 Gbps or so, life gets very ugly.&lt;/p&gt;
&lt;p&gt;For more:&lt;br /&gt;- Arbor Networks summarizes its fourth annual infrastructure security report. &lt;a href=&quot;http://www.arbornetworks.com/en/arbor-networks-publishes-fourth-annual-worldwide-worldwide-infrastructure-security-report-2.html&quot;&gt;Release&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Related articles&lt;/strong&gt;&lt;br /&gt;&lt;a href=&quot;http://www.fiercetelecom.com/story/what-dpi-needs-most/2008-07-21&quot;&gt;What DPI needs most - FierceTelecom&lt;/a&gt;&lt;br /&gt;&lt;a href=&quot;http://www.fiercetelecom.com/story/broadband-traffic-cops-are-patrol/2008-06-10&quot;&gt;Broadband traffic cops are on patrol - FierceTelecom&lt;/a&gt;&lt;/p&gt;</description>
 <comments>http://www.fiercevoip.com/story/arbor-networks-voip-ipv6-emerging-security-threats/2008-11-11#comments</comments>
 <category domain="http://www.fiercevoip.com/tags/arbor-networks">Arbor Networks</category>
 <category domain="http://www.fiercevoip.com/tags/ddos-attacks">Ddos Attacks</category>
 <category domain="http://www.fiercevoip.com/tags/infrastructure-security">Infrastructure Security</category>
 <category domain="http://www.fiercevoip.com/tags/internet-service-provider">internet service provider</category>
 <category domain="http://www.fiercevoip.com/tags/ipv6">Ipv6</category>
 <category domain="http://www.fiercevoip.com/tags/isp">ISP</category>
 <category domain="http://www.fiercevoip.com/tags/itsp">Itsp</category>
 <category domain="http://www.fiercevoip.com/tags/malicious-attacks">Malicious Attacks</category>
 <category domain="http://www.fiercevoip.com/tags/voip-0">VoIP</category>
 <category domain="http://www.fiercevoip.com/tags/voip-security">VoIP Security</category>
 <pubDate>Tue, 11 Nov 2008 21:25:05 -0500</pubDate>
 <dc:creator>Doug Mohney</dc:creator>
 <guid isPermaLink="false">2938 at http://www.fiercevoip.com</guid>
</item>
<item>
 <title>Acme Packet reports slight slowdown in 3Q results</title>
 <link>http://www.fiercevoip.com/story/acme-packet-reports-slight-slowdown-3q-results/2008-11-07-1?utm_medium=rss&amp;utm_source=rss&amp;cmp-id=OTC-RSS-FV0</link>
 <description>&lt;p&gt;Acme Packet, the Burlington, Mass.-based session border controller manufacturer, announced fiscal third quarter results showing revenues were up 11 percent sequentially from the second quarter of 2008 and down year-over-year.&lt;/p&gt;
&lt;p&gt;Acme Packet reported $28.4 million in revenue for the third quarter 2008, and $85.7 million in year-to-date revenue. Acme Packet slipped slightly in trading yesterday, down to $3.80 per share from its opening price of $4.20 per share.&lt;/p&gt;
&lt;p&gt;A company spokesperson cited the economic slowdown as a cause of the slightly lower revenues, but maintained that the company&#039;s gross margin was still strong and capex was being managed prudently through the soft economic period.&lt;/p&gt;
&lt;p&gt;The company slightly adjusted guidance for the rest of the fiscal year, bringing the high end of its revenue forecast down to $118 million from $119 million, and adjusted its expected revenue from interest up to between $3.4 and 3.6 million from its previous estimate of $3 million.&lt;/p&gt;
&lt;p&gt;Acme Packet also announced it has repurchased 6.3 million shares of its common stock for an aggregate price of $35.8 million through Nov. 5, 2008.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;For more:&lt;br /&gt;- see the company release &lt;a href=&quot;http://www.ir.acmepacket.com/phoenix.zhtml?c=200804&amp;amp;p=irol-newsArticle&amp;amp;ID=1223449&amp;amp;highlight=&quot;&gt;here&lt;/a&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Related articles&lt;br /&gt;&lt;/strong&gt;&lt;a href=&quot;http://www.fiercevoip.com/story/acme-packet-canary-voip-coal-mine/2008-07-08&quot;&gt;Acme Packet&lt;/a&gt;: Canary in the (VoIP) Coal Mine?&lt;br /&gt;&lt;a href=&quot;http://www.fiercevoip.com/story/acme-packet-new-net-net-product-offering/2008-09-16&quot;&gt;Acme Packet&lt;/a&gt; new Net-Net product offering&lt;br /&gt;&lt;a href=&quot;http://www.fiercevoip.com/story/andy-ory-ceo-acmepacket/2008-08-25&quot;&gt;FierceVoIP Leaders: Andy Ory&lt;/a&gt;, President, CEO, and Co-founder, Acme Packet&lt;/p&gt;</description>
 <comments>http://www.fiercevoip.com/story/acme-packet-reports-slight-slowdown-3q-results/2008-11-07-1#comments</comments>
 <category domain="http://www.fiercevoip.com/tags/acme-packet">Acme Packet</category>
 <category domain="http://www.fiercevoip.com/tags/sbc-0">Sbc</category>
 <category domain="http://www.fiercevoip.com/tags/session-border-control">Session Border Control</category>
 <category domain="http://www.fiercevoip.com/tags/telecommunications-equipment-manufacturer">Telecommunications Equipment Manufacturer</category>
 <category domain="http://www.fiercevoip.com/tags/third-quarter-results">Third Quarter Results</category>
 <category domain="http://www.fiercevoip.com/tags/voip-companies">voip companies</category>
 <category domain="http://www.fiercevoip.com/tags/voip-security">VoIP Security</category>
 <category domain="http://www.fiercevoip.com/tags/voip-technology">VoIP Technology</category>
 <pubDate>Fri, 07 Nov 2008 09:46:08 -0500</pubDate>
 <dc:creator>Pete Wylie</dc:creator>
 <guid isPermaLink="false">2928 at http://www.fiercevoip.com</guid>
</item>
<item>
 <title>Sipera Systems, Top VoIP Company 2008: FierceVoIP, Fierce 15</title>
 <link>http://www.fiercevoip.com/special-reports/sipera-systems-top-voip-company-2008-fiercevoip-fierce-15?utm_medium=rss&amp;utm_source=rss&amp;cmp-id=OTC-RSS-FV0</link>
 <description>&lt;p&gt;&lt;strong&gt;&lt;img src=&quot;http://assets.fiercemarkets.com/files/voip/fierceimages/fierce15-sml-logo.gif&quot; alt=&quot;&quot; width=&quot;91&quot; height=&quot;86&quot; align=&quot;right&quot; /&gt;Sipera Systems&lt;/strong&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Where it&#039;s based: &lt;/strong&gt;Richardson, Texas&lt;br /&gt;&lt;strong&gt;When it was founded: &lt;/strong&gt;2003&lt;br /&gt;&lt;strong&gt;Website: &lt;/strong&gt;&lt;a href=&quot;http://www.sipera.com&quot;&gt;www.sipera.com&lt;/a&gt;&lt;strong&gt;&amp;nbsp;&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Why it&#039;s Fierce: &lt;/strong&gt;&amp;nbsp;Proactive VoIP security testing and vulnerability assessment is something Fierce to our professionally paranoid hearts, so Sipera would win consideration simply for its in-house VIPER lab.&amp;nbsp; However, Sipera has moved beyond simply flogging the latest VoIP threats to incorporate unified communications into its assessments and security appliances. Its latest product release offers advanced security for SIP trunking, better integration into SIP trunk provider services and adding additional SBC functionality.&amp;nbsp; We expect to see more out of Sipera in the months to come.&lt;/p&gt;</description>
 <category domain="http://www.fiercevoip.com/tags/sip">SIP</category>
 <category domain="http://www.fiercevoip.com/tags/sipera-systems">Sipera Systems</category>
 <category domain="http://www.fiercevoip.com/tags/unified-communications">Unified Communications</category>
 <category domain="http://www.fiercevoip.com/tags/voip-security">VoIP Security</category>
 <category domain="http://www.fiercevoip.com/tags/voip-testing">voip testing</category>
 <pubDate>Tue, 04 Nov 2008 14:44:55 -0500</pubDate>
 <dc:creator />
 <guid isPermaLink="false">2915 at http://www.fiercevoip.com</guid>
</item>
<item>
 <title>SPOTLIGHT: Implementation headaches for VoIP &amp; UC</title>
 <link>http://www.fiercevoip.com/story/spotlight-implementation-headaches-voip-uc/2008-11-02?utm_medium=rss&amp;utm_source=rss&amp;cmp-id=OTC-RSS-FV0</link>
 <description>&lt;p&gt;Adding the latest and greatest in voice and UC to your network can generate five different types of problems, says Processor.com.&lt;/p&gt;
&lt;p&gt;Adding or migrating voice to an existing network can result in problems if a careful assessment of existing resources isn&#039;t taken. Care must be taken to provide priority to voice packets over data and to make sure there&#039;s enough bandwidth to support voice in the first place.&amp;nbsp;Older equipment, even old Ethernet switches and shared hubs -- not to mention first generation WiFi devices - weren&#039;t built to support QoS.&lt;/p&gt;
&lt;p&gt;Shifting to VoIP also brings security and continuity of service considerations you just don&#039;t find in the POTS world.&lt;/p&gt;
&lt;p&gt;For more:&lt;br /&gt;- Processor.com gives advice on tackling VoIP and UC trouble. &lt;a href=&quot;http://www.processor.com/editorial/article.asp?article=articles/P3044/21p44/21p44/21p44.asp&amp;amp;guid=&quot;&gt;Article&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Related articles&lt;/strong&gt;&lt;br /&gt;&lt;a href=&quot;http://www.fiercevoip.com/story/spotlight-how-to-troubleshoot-your-voip-phone-setup/2008-04-21&quot;&gt;SPOTLIGHT: How to troubleshoot your VoIP phone setup - FierceVoIP&lt;/a&gt;&lt;br /&gt;&lt;a href=&quot;http://www.fiercevoip.com/story/ucsniff-targets-voip-uc-and-inside-job/2008-09-28&quot;&gt;UCSniff targets VoIP, UC, and the inside job - FierceVoIP&lt;/a&gt;&lt;/p&gt;</description>
 <comments>http://www.fiercevoip.com/story/spotlight-implementation-headaches-voip-uc/2008-11-02#comments</comments>
 <category domain="http://www.fiercevoip.com/tags/pots">POTS</category>
 <category domain="http://www.fiercevoip.com/tags/uc">UC</category>
 <category domain="http://www.fiercevoip.com/tags/unified-communications">Unified Communications</category>
 <category domain="http://www.fiercevoip.com/tags/voip-0">VoIP</category>
 <category domain="http://www.fiercevoip.com/tags/voip-installation">voip installation</category>
 <category domain="http://www.fiercevoip.com/tags/voip-security">VoIP Security</category>
 <category domain="http://www.fiercevoip.com/tags/voip-technology">VoIP Technology</category>
 <pubDate>Sun, 02 Nov 2008 17:36:59 -0500</pubDate>
 <dc:creator>Doug Mohney</dc:creator>
 <guid isPermaLink="false">2895 at http://www.fiercevoip.com</guid>
</item>
<item>
 <title>Skype responds to security breach</title>
 <link>http://www.fiercevoip.com/story/skype-responds-security-breach/2008-10-03?utm_medium=rss&amp;utm_source=rss&amp;cmp-id=OTC-RSS-FV0</link>
 <description>&lt;p&gt;Josh Silverman, president of Skype, responded in his blog Thursday to media reports about unauthorized storage of text messages and user data by Skype&#039;s Chinese partner TOM Online. Silverman explains that Skype considered the possibility of texts not going through because of Chinese censorship standards that TOM had to meet in order to operate in the country. He stressed that TOM had to ensure Chinese government access to the communications to operate at all, but that Skype leadership was assured any &quot;offensive&quot; communications would simply be deleted.&lt;/p&gt;
&lt;p&gt;&quot;Breaching Trust,&quot; the report that sparked Silverman&#039;s response, found a security breach on the servers where &quot;offensive&quot; communications are stored that enabled public access to the information. Silverman assured Skype users that TOM remedied the security breach after Skype made them aware of it. He also noted that Skype was working with TOM on the storage of the &quot;offensive&quot; text conversations and accompanying user data.&lt;/p&gt;
&lt;p&gt;Silverman also stressed that the compromised communications only affected text conversations in which at least one of the users was using TOM, and that Skype-Skype communications are completely secure and safe.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;For more:&lt;br /&gt;- see Silverman&#039;s blog post &lt;a href=&quot;http://share.skype.com/sites/en/2008/10/skype_president_addresses_chin.html&quot;&gt;here&lt;/a&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Related Articles&lt;br /&gt;&lt;/strong&gt;&lt;a href=&quot;http://www.fiercevoip.com/story/china-monitoring-skype-calls/2008-10-02&quot;&gt;Is China monitoring Skype calls?&lt;/a&gt;&lt;br /&gt;&lt;a href=&quot;http://www.fiercevoip.com/story/skype-voip-dead/2008-09-17&quot;&gt;Skype: VoIP is dead&lt;/a&gt;&lt;br /&gt;&lt;a href=&quot;http://www.fiercevoip.com/story/fiercevoip-leaders-jonathan-christensen-gm-audio-and-video-skype/2008-09-11&quot;&gt;FierceVoIP Leaders: Jonathan Christensen, GM of audio and video for Skype&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;&amp;nbsp;&lt;/strong&gt;&lt;/p&gt;</description>
 <comments>http://www.fiercevoip.com/story/skype-responds-security-breach/2008-10-03#comments</comments>
 <category domain="http://www.fiercevoip.com/tags/china-0">china</category>
 <category domain="http://www.fiercevoip.com/tags/chinese-censorship">Chinese Censorship</category>
 <category domain="http://www.fiercevoip.com/tags/chinese-monitoring">chinese monitoring</category>
 <category domain="http://www.fiercevoip.com/tags/chinese-skype-censorship">Chinese Skype Censorship</category>
 <category domain="http://www.fiercevoip.com/tags/josh-silverman">Josh Silverman</category>
 <category domain="http://www.fiercevoip.com/tags/skype">Skype</category>
 <category domain="http://www.fiercevoip.com/tags/voip-0">VoIP</category>
 <category domain="http://www.fiercevoip.com/tags/voip-security">VoIP Security</category>
 <category domain="http://www.fiercevoip.com/tags/voip-technology">VoIP Technology</category>
 <pubDate>Fri, 03 Oct 2008 14:55:58 -0400</pubDate>
 <dc:creator>Pete Wylie</dc:creator>
 <guid isPermaLink="false">2819 at http://www.fiercevoip.com</guid>
</item>
<item>
 <title>UCSniff targets VoIP, UC, and the inside job</title>
 <link>http://www.fiercevoip.com/story/ucsniff-targets-voip-uc-and-inside-job/2008-09-28?utm_medium=rss&amp;utm_source=rss&amp;cmp-id=OTC-RSS-FV0</link>
 <description>&lt;p&gt;Over the weekend, the Toorcon security conference in San Diego showcased a next-generation VoIP sniffer. Trust no one, and that goes double if they are on your side of the firewall.&lt;/p&gt;
&lt;p&gt;The UCSniff tool, created by VoIP Hopper author and director of Sipera&#039;s VIPER VoIP vulnerabilities lab Jason Ostrom, has two settings for mischief. One is a learning mode that sniffs IP traffic and maps phone extensions to specific IP addresses. By default, it captures all the calls and saves them to .WAV files, says CNET news.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;Once you have a map of phones to IP addresses, an attacker could use UCSniff to listen to all the VoIP conversations made by a specific mode.&amp;nbsp; If that&#039;s not exciting enough, a second model allows for monitoring calls made exclusively between two extensions.&lt;/p&gt;
&lt;p&gt;Readers should note that Ostrom&#039;s presentation outlines scenarios for the &quot;trusted insider&quot; within the corporation that has access to an organization&#039;s VoIP infrastructure and calls for consideration of internal controls and best practices to prevent VoIP eavesdropping.&lt;/p&gt;
&lt;p&gt;For more:&lt;br /&gt;- CNet blogs about Toorcon VoIP security session. &lt;a href=&quot;http://news.cnet.com/8301-1009_3-10052393-83.html&quot;&gt;Posting&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Related articles&lt;/strong&gt;&lt;a href=&quot;http://www.fiercevoip.com/story/voip-security-and-circle-trust/2008-05-06&quot;&gt;&lt;br /&gt;VoIP Security and the Circle of Trust&lt;/a&gt;&lt;a href=&quot;http://www.fiercevoip.com/story/last-hope-launches-security-season/2008-07-20?utm_medium=rss&amp;amp;utm_source=rss&amp;amp;cmp-id=OTC-RSS-FV0&quot;&gt;&lt;br /&gt;Last Hope Launches Security Season&lt;/a&gt;&lt;/p&gt;</description>
 <comments>http://www.fiercevoip.com/story/ucsniff-targets-voip-uc-and-inside-job/2008-09-28#comments</comments>
 <category domain="http://www.fiercevoip.com/tags/best-practices">Best Practices</category>
 <category domain="http://www.fiercevoip.com/tags/security-conference">Security Conference</category>
 <category domain="http://www.fiercevoip.com/tags/sipera">Sipera</category>
 <category domain="http://www.fiercevoip.com/tags/toorcon">toorcon</category>
 <category domain="http://www.fiercevoip.com/tags/viper-lab">VIPER lab</category>
 <category domain="http://www.fiercevoip.com/tags/voip-0">VoIP</category>
 <category domain="http://www.fiercevoip.com/tags/voip-security">VoIP Security</category>
 <category domain="http://www.fiercevoip.com/tags/voip-technology">VoIP Technology</category>
 <category domain="http://www.fiercevoip.com/tags/vulnerabilities-0">Vulnerabilities</category>
 <pubDate>Sun, 28 Sep 2008 22:16:27 -0400</pubDate>
 <dc:creator>Doug Mohney</dc:creator>
 <guid isPermaLink="false">2803 at http://www.fiercevoip.com</guid>
</item>
<item>
 <title>SPOTLIGHT: Skype - The other birthday</title>
 <link>http://www.fiercevoip.com/story/spotlight-skype-other-birthday/2008-09-09?utm_medium=rss&amp;utm_source=rss&amp;cmp-id=OTC-RSS-FV0</link>
 <description>&lt;p&gt;As Google celebrates 10 years of world domination, er, operation, Skype wants you to know that the peer-to-peer VoIP/IM/video client is celebrating its fifth birthday.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;Skype&#039;s PR firm has sent out a pretty folder containing a time line of accomplishments over the past 5 years, a &quot;Five Fun Facts&quot; sheet, a couple of tear-jerker case studies on how people use the software, a voucher for three months of unlimited service and a cookie (Iced, a bit dry). From April to June 2008, Skype added nearly 29 million users and clocked 1.9 billion SkypeOut minutes.&amp;nbsp; &amp;nbsp;&lt;/p&gt;
&lt;p&gt;Taking&amp;nbsp;a different tack, ITWire chimes in with some of Skype&#039;s product and company stumbles, but misses three grade-A headaches for the company.&amp;nbsp;First among these was a multi-day crash of Skype in August 2007 attributed to a set of Windows Update patches. Can government entities conduct lawful intercept activities on Skype? Some say there&#039;s a back door which leads to Skype&#039;s third faux pas - an utter lack of transparency and a &quot;black box&quot; closed system which makes security experts nervous and leaves open source developers frustrated.&lt;/p&gt;
&lt;p&gt;For more:&lt;br /&gt;- ITWire talks about Skype&#039;s lower moments. &lt;a href=&quot;http://www.itwire.com/content/view/20496/1103/1/1/&quot;&gt;Article&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Related articles&lt;/strong&gt;&lt;a href=&quot;http://www.fiercevoip.com/story/skype-wiretap-nuances/2008-06-10&quot;&gt;&lt;br /&gt;Skype Wiretap Nuances - FierceVoIP&lt;/a&gt;&lt;br /&gt;&lt;a href=&quot;http://www.fiercevoip.com/story/skype-back-door/2008-07-25&quot;&gt;A Skype Back Door? - FierceVoIP&lt;/a&gt;&lt;/p&gt;</description>
 <comments>http://www.fiercevoip.com/story/spotlight-skype-other-birthday/2008-09-09#comments</comments>
 <category domain="http://www.fiercevoip.com/tags/lawful-intercept">Lawful Intercept</category>
 <category domain="http://www.fiercevoip.com/tags/skype">Skype</category>
 <category domain="http://www.fiercevoip.com/tags/voip-0">VoIP</category>
 <category domain="http://www.fiercevoip.com/tags/voip-security">VoIP Security</category>
 <category domain="http://www.fiercevoip.com/tags/voip-technology">VoIP Technology</category>
 <pubDate>Tue, 09 Sep 2008 15:00:15 -0400</pubDate>
 <dc:creator>Doug Mohney</dc:creator>
 <guid isPermaLink="false">2746 at http://www.fiercevoip.com</guid>
</item>
<item>
 <title>VoIP drives broadband service growth</title>
 <link>http://www.fiercevoip.com/story/voip-drives-broadband-service-growth/2008-09-03?utm_medium=rss&amp;utm_source=rss&amp;cmp-id=OTC-RSS-FV0</link>
 <description>&lt;p&gt;Broadband value-added services reaped $25.7 billion worldwide in 2007, an increase of 62 percent from 2006, according to Point-Topic research. VoIP and security made up the largest percentage of this gross as well, accounting for 56 percent of the service revenue, or more than $14 billion.&lt;/p&gt;
&lt;p&gt;&quot;Value added services are growing strongly and are increasingly significant in overall revenue terms,&quot; said John Bosnell, senior analyst at Point-Topic. &quot;The success story of 2007 has been VOIP.&amp;nbsp; Overall revenue has very nearly doubled, average revenue per user (ARPU) is up and take-up in major markets, particularly North America and Western Europe is growing quickly.&quot;&lt;/p&gt;
&lt;p&gt;Bosnell predicted continued rapid growth in both components of the VoIP business, IP telephony and Internet telephony. He said market saturation is not imminent, but could occur in the future.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;For more:&lt;br /&gt;- read the rest of the rosy Point-Topic forecast &lt;a href=&quot;http://point-topic.com/content/dslanalysis/bbacbvas08.htm&quot;&gt;here&lt;/a&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Related Articles&lt;br /&gt;&lt;/strong&gt;&lt;a href=&quot;http://www.fiercevoip.com/story/voip-service-revenues-52-07/2008-08-13?utm_medium=rss&amp;amp;utm_source=rss&amp;amp;cmp-id=OTC-RSS-FV0&quot;&gt;VoIP service revenues up 52% in &#039;07&lt;/a&gt;&lt;br /&gt;&lt;a href=&quot;http://www.fiercevoip.com/story/spotlight-clearwire-credits-better-revenues-voip/2008-08-10?utm_medium=rss&amp;amp;utm_source=rss&amp;amp;cmp-id=OTC-RSS-FV0&quot;&gt;SPOTLIGHT: Clearwire Credits Better Revenues to VoIP&lt;/a&gt;&lt;/p&gt;</description>
 <comments>http://www.fiercevoip.com/story/voip-drives-broadband-service-growth/2008-09-03#comments</comments>
 <category domain="http://www.fiercevoip.com/tags/broadband-services">Broadband Services</category>
 <category domain="http://www.fiercevoip.com/tags/service-revenues">Service Revenues</category>
 <category domain="http://www.fiercevoip.com/tags/voip-industry-news">voip industry news</category>
 <category domain="http://www.fiercevoip.com/tags/voip-security">VoIP Security</category>
 <pubDate>Wed, 03 Sep 2008 11:46:27 -0400</pubDate>
 <dc:creator>Pete Wylie</dc:creator>
 <guid isPermaLink="false">2731 at http://www.fiercevoip.com</guid>
</item>
<item>
 <title>SPOTLIGHT: The Menace of Hannah Montana</title>
 <link>http://www.fiercevoip.com/story/spotlight-menace-hannah-montana/2008-08-04?utm_medium=rss&amp;utm_source=rss&amp;cmp-id=OTC-RSS-FV0</link>
 <description>&lt;p&gt;Disney&#039;s &quot;Hannah Montana Wake-Up Call&quot; has apparently been overwhelmed with bad people abusing the power of VoIP.&lt;/p&gt;
&lt;p&gt;The service allows you to enter in a phone number on a website to deliver a special pre-recorded message from Miley Cyrus for a wake up call or activity reminder. There&#039;s no sender authentication and no opt-out mechanism or audit trail, so people are doing whatever they want and the system is apparently swamped with some individuals scheduled to receive up to five calls already. Not to mention the potential to game the system for calls to be made at early hours of the morning.&lt;/p&gt;
&lt;p&gt;For more:&lt;br /&gt;- Gigaom warns us about Hanna Montana&#039;s &lt;a href=&quot;http://gigaom.com/2008/08/04/hannah-montana-crank-calls-voip-mischief/&quot;&gt;bad VoIP habit&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Related articles:&lt;/strong&gt;&lt;br /&gt; Last HOPE &lt;a href=&quot;http://www.fiercevoip.com/story/last-hope-launches-security-season/2008-07-20?utm_medium=rss&amp;amp;utm_source=rss&amp;amp;cmp-id=OTC-RSS-FV0&quot;&gt;Launches Security Season&lt;/a&gt;&lt;br /&gt; VoIP Security and the &lt;a href=&quot;http://www.fiercevoip.com/story/voip-security-and-circle-trust/2008-05-06&quot;&gt;Circle of Trust&lt;/a&gt;&lt;/p&gt;</description>
 <comments>http://www.fiercevoip.com/story/spotlight-menace-hannah-montana/2008-08-04#comments</comments>
 <category domain="http://www.fiercevoip.com/tags/disney">Disney</category>
 <category domain="http://www.fiercevoip.com/tags/hannah-montana">Hannah Montana</category>
 <category domain="http://www.fiercevoip.com/tags/recorded-message">Recorded Message</category>
 <category domain="http://www.fiercevoip.com/tags/voip-security">VoIP Security</category>
 <category domain="http://www.fiercevoip.com/tags/voip-technology">VoIP Technology</category>
 <pubDate>Mon, 04 Aug 2008 16:07:04 -0400</pubDate>
 <dc:creator>Doug Mohney</dc:creator>
 <guid isPermaLink="false">2656 at http://www.fiercevoip.com</guid>
</item>
<item>
 <title>The Ease of Hacking VoIP</title>
 <link>http://www.fiercevoip.com/story/ease-hacking-voip/2008-08-03?utm_medium=rss&amp;utm_source=rss&amp;cmp-id=OTC-RSS-FV0</link>
 <description>&lt;p&gt;Most of the 300,000 privately owned IP PBX systems throughout the U.S. are &quot;wide open&quot; to anyone that wants to hack them, says ChannelWeb. Compounding matters are a lack of regulatory interest and failure of vendors to disclose vulnerabilities.&lt;/p&gt;
&lt;p&gt;With VoIP systems being implemented on data LANs and blended with other software for unified communications solutions, the potential for mischief can get very large very quickly. VoIPshield has been posting and demonstrating publicly documented (i.e. available through The Google) hacks. While Cisco Call Manager gets a workout on how easy it is to exploit, the real problem lies in companies not updating their VoIP and IP PBX software with the latest security patches and fixes like they do all with all their other software.&lt;/p&gt;
&lt;p&gt;If you&#039;re not worried yet, there&#039;s a free utility called VoIPhopper to jump between voice and data VLANs so one can easily bypass firewalls and nearly all the IDS software for sale today.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;For more:&lt;br /&gt;- &lt;a href=&quot;http://www.crn.com/security/209900949&quot;&gt;Hacking VoIP is easy&lt;/a&gt;, reports ChannelWeb&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Related articles:&lt;/strong&gt;&lt;br /&gt; Last HOPE Launches &lt;a href=&quot;http://www.fiercevoip.com/story/last-hope-launches-security-season/2008-07-20?utm_medium=rss&amp;amp;utm_source=rss&amp;amp;cmp-id=OTC-RSS-FV0&quot;&gt;Security Season&lt;/a&gt;&lt;br /&gt; SPOTLIGHT: Survey: &lt;a href=&quot;http://www.fiercetelecom.com/story/spotlight-survey-u.s.-firms-lax-about-voip-security/2008-03-27&quot;&gt;U.S. firms lax&lt;/a&gt; about VoIP security&lt;/p&gt;</description>
 <comments>http://www.fiercevoip.com/story/ease-hacking-voip/2008-08-03#comments</comments>
 <category domain="http://www.fiercevoip.com/tags/cisco">Cisco</category>
 <category domain="http://www.fiercevoip.com/tags/security-patches">Security Patches</category>
 <category domain="http://www.fiercevoip.com/tags/voip-security">VoIP Security</category>
 <category domain="http://www.fiercevoip.com/tags/voip-technology">VoIP Technology</category>
 <category domain="http://www.fiercevoip.com/tags/voipshield">VoIPShield</category>
 <category domain="http://www.fiercevoip.com/tags/vulnerabilities-0">Vulnerabilities</category>
 <pubDate>Sun, 03 Aug 2008 21:54:14 -0400</pubDate>
 <dc:creator>Doug Mohney</dc:creator>
 <guid isPermaLink="false">2655 at http://www.fiercevoip.com</guid>
</item>
<item>
 <title>A Skype Back Door? </title>
 <link>http://www.fiercevoip.com/story/skype-back-door/2008-07-25?utm_medium=rss&amp;utm_source=rss&amp;cmp-id=OTC-RSS-FV0</link>
 <description>&lt;p&gt;High-ranking officials at the Austrian interior ministry have said it isn&#039;t a problem to listen into Skype conversations, implying that there is a back door built into the program.&lt;/p&gt;
&lt;p&gt;Heise online has talked to a number of parties present at a June 25 meeting between ISP representatives and the Austrian regulator on lawful intercept of IP services who confirm the report. Skype has declined comment on if the software has a back door or if there is a specific key for decrypting data streams.&lt;/p&gt;
&lt;p&gt;Rumors have been floating around on Skype selling a special listening device to interested governments and there has long been speculation about a back door to the program.&amp;nbsp; Because Skype&#039;s code and protocols are both proprietary and closed, security experts have long wondered what Skype is capable of and what risks may arise in deploying the software in an enterprise environment.&lt;/p&gt;
&lt;p&gt;Austrian officials have demanded that ISP allow the interior ministry to install network bridges and Linux servers in their network centers to copy and filter data traffic. If they don&#039;t, officials will work to enforce more expensive European ETSI lawful intercept standards.&lt;/p&gt;
&lt;p&gt;For more:&lt;br /&gt; - Heise Online reports on the potential for a &lt;a href=&quot;http://www.heise-online.co.uk/security/Speculation-over-back-door-in-Skype--/news/111170&quot;&gt;Skype backdoor&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Related articles:&lt;/strong&gt;&lt;br /&gt; &lt;a href=&quot;http://www.fiercevoip.com/story/skype-wiretap-nuances/2008-06-10&quot;&gt;Skype Wiretap Nuances&lt;/a&gt;&lt;br /&gt; Skype resists &lt;a href=&quot;http://www.fiercevoip.com/story/skype-resists-inter-operability/2008-01-17&quot;&gt;inter-operability&lt;/a&gt;&lt;/p&gt;</description>
 <comments>http://www.fiercevoip.com/story/skype-back-door/2008-07-25#comments</comments>
 <category domain="http://www.fiercevoip.com/tags/back-door">Back Door</category>
 <category domain="http://www.fiercevoip.com/tags/lawful-intercept">Lawful Intercept</category>
 <category domain="http://www.fiercevoip.com/tags/security-experts">Security Experts</category>
 <category domain="http://www.fiercevoip.com/tags/skype">Skype</category>
 <category domain="http://www.fiercevoip.com/tags/voip-0">VoIP</category>
 <category domain="http://www.fiercevoip.com/tags/voip-security">VoIP Security</category>
 <pubDate>Fri, 25 Jul 2008 15:28:40 -0400</pubDate>
 <dc:creator>Doug Mohney</dc:creator>
 <guid isPermaLink="false">2632 at http://www.fiercevoip.com</guid>
</item>
<item>
 <title>The sky is (not) falling (this summer)</title>
 <link>http://www.fiercevoip.com/story/sky-not-falling-summer/2008-07-23?utm_medium=rss&amp;utm_source=rss&amp;cmp-id=OTC-RSS-FV0</link>
 <description>&lt;p&gt;&lt;img src=&quot;http://static.fiercemarkets.com/public/headshots/doug100.jpg&quot; alt=&quot;&quot; align=&quot;right&quot; /&gt;Last weekend, The Last HOPE conference kicked off hacker awareness month. Between now and mid-August, prepare to hear about plenty of scary security stuff that may or may not affect you in the slightest.&lt;/p&gt;
&lt;p&gt;VoIP and voice security seem to be almost pass&amp;eacute; for the corporate-focused Black Hat conference in Las   Vegas (No session on VoIP) and its irregular weekend party/knowledgefest DEFCON (one session). Compare that to three VoIP sessions at Last HOPE, plus Kevin Mitnick&#039;s quickie workaround to crack Caller ID blocking and it&#039;s very quiet when compared to dramatic announcements at previous events in past years.&lt;/p&gt;
&lt;p&gt;The sole VoIP attack session at DEFCON discusses VoIPER, a toolkit to automatically and extensively test VoIP devices. VoIPER has been thrown at IP desk sets, softphones, and servers to find vulnerabilities. It&#039;s open source and you can take a look at the code at &lt;a href=&quot;http://sourceforge.net/projects/voiper&quot;&gt;http://sourceforge.net/projects/voiper&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;Is the quiet a good thing? I&#039;m not sure if this means VoIP security has become seriously boring or if there&#039;s a lot of behind-the-scenes activity we&#039;ll hear about in a more dramatic fashion next year. Certainly there&#039;s bound to be some UC security activity to be discussed in the months ahead.&lt;/p&gt;
&lt;p&gt;But for now, I&#039;d say that it&#039;s a good time to enjoy the rest of the summer--unless you have to worry about all the other security headaches bound to be pouring out of Black Hat and DEFCON in a couple of weeks.&lt;/p&gt;
&lt;p&gt;- &lt;a href=&quot;mailto:doug@fiercemarkets.com&quot;&gt;Doug&lt;/a&gt;&lt;/p&gt;</description>
 <comments>http://www.fiercevoip.com/story/sky-not-falling-summer/2008-07-23#comments</comments>
 <category domain="http://www.fiercevoip.com/tags/black-hat">Black Hat</category>
 <category domain="http://www.fiercevoip.com/tags/defcon">Defcon</category>
 <category domain="http://www.fiercevoip.com/tags/last-hope">Last Hope</category>
 <category domain="http://www.fiercevoip.com/tags/last-hope-0">the last hope</category>
 <category domain="http://www.fiercevoip.com/tags/voip-security">VoIP Security</category>
 <pubDate>Wed, 23 Jul 2008 16:14:13 -0400</pubDate>
 <dc:creator>Doug Mohney</dc:creator>
 <guid isPermaLink="false">2628 at http://www.fiercevoip.com</guid>
</item>
<item>
 <title>Digium CTO parses unblocked Caller ID hack</title>
 <link>http://www.fiercevoip.com/story/digium-cto-parses-unblocked-caller-id-hack/2008-07-22?utm_medium=rss&amp;utm_source=rss&amp;cmp-id=OTC-RSS-FV0</link>
 <description>&lt;p&gt;Normally, punching *67 should block Caller ID information
being passed through to a receiving caller. But, as security consultant Kevin Mitnick has demonstrated and Digium
CTO Mark Spencer explains, it&#039;s not 100 percent foolproof.&lt;/p&gt;
&lt;p&gt;At The Last HOPE hacker conference over the weekend, Mitnick
demonstrated how an appropriately configured Asterisk box and a suitable SIP
trunking service can be used to deliver Caller ID information even on inbound
calls that have a &quot;Private&quot; flag set.&lt;/p&gt;
&lt;p&gt;&quot;There are legitimate reasons why you need to set the Caller
ID to normal [and carry that information forward,]&quot; said Digium CTO Mark
Spencer. &quot;If, for example, I&#039;m in an enterprise environment and I want to have
calls forwarded [from my office number] to my cell phone, [the PBX] needs that
information.&quot;&lt;/p&gt;
&lt;p&gt;Mitnick used the &quot;enterprise class&quot; VoIP/SIP trunking
provider FlowRoute to get a phone number (DID) and service that would deliver
all of the call information to an Asterisk server.&amp;nbsp; The Asterisk server is simply setup/scripted
to pass along all Caller ID information for inbound calls regardless of the
setting of the privacy flag on the call.&lt;/p&gt;
&lt;p&gt;Spencer also noted that Caller ID information is also
carried along and recorded for &quot;private&quot; calls to toll free numbers; the
information is necessary for proper billing.&lt;/p&gt;
&lt;p&gt;Mark is not happy with the use of Asterisk for questionable
uses, but since it is open source, there is little he can do about it. &quot;I hate to say it, but the same reasons why
Asterisk is attractive to a lot of businesses, it&#039;s low cost, it can be easily
tweaked, it&#039;s more flexible, make it easy for using it for an illegitimate
purpose,&quot; said Spencer. &quot;It&#039;s a very powerful platform. I&#039;m not thrilled about
it being used for fraud and I&#039;m not thrilled with companies who build products
on it in competition with Digium, but there&#039;s not a lot I can do about it.&quot;&lt;/p&gt;
&lt;p&gt;For more:&lt;br /&gt;- Engadget snags &lt;a href=&quot;http://www.engadget.com/2008/07/21/how-to-reveal-blocked-caller-id-info-a-video-guide-to-risky-beh/&quot;&gt;Mitnick
demo video&lt;/a&gt; from The Last HOPE conference&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Related articles:&lt;/strong&gt;&lt;br /&gt; Last Hope Launches &lt;a href=&quot;http://www.fiercevoip.com/story/last-hope-launches-security-season/2008-07-20?utm_medium=rss&amp;amp;utm_source=rss&amp;amp;cmp-id=OTC-RSS-FV0&quot;&gt;Security
Season&lt;/a&gt;&lt;br /&gt; VoIP Security and the &lt;a href=&quot;http://www.fiercevoip.com/story/voip-security-and-circle-trust/2008-05-06&quot;&gt;Circle
of Trust&lt;/a&gt;&lt;/p&gt;</description>
 <comments>http://www.fiercevoip.com/story/digium-cto-parses-unblocked-caller-id-hack/2008-07-22#comments</comments>
 <category domain="http://www.fiercevoip.com/tags/caller-id">Caller Id</category>
 <category domain="http://www.fiercevoip.com/tags/digium">digium</category>
 <category domain="http://www.fiercevoip.com/tags/kevin-mitnick">Kevin Mitnick</category>
 <category domain="http://www.fiercevoip.com/tags/last-hope">Last Hope</category>
 <category domain="http://www.fiercevoip.com/tags/mark-spencer">Mark Spencer</category>
 <category domain="http://www.fiercevoip.com/tags/sip">SIP</category>
 <category domain="http://www.fiercevoip.com/tags/voip-security">VoIP Security</category>
 <pubDate>Tue, 22 Jul 2008 12:05:53 -0400</pubDate>
 <dc:creator>Doug Mohney</dc:creator>
 <guid isPermaLink="false">2624 at http://www.fiercevoip.com</guid>
</item>
<item>
 <title>Last Hope Launches Security Season</title>
 <link>http://www.fiercevoip.com/story/last-hope-launches-security-season/2008-07-20?utm_medium=rss&amp;utm_source=rss&amp;cmp-id=OTC-RSS-FV0</link>
 <description>&lt;p&gt;Over the weekend, 2600&#039;s The Last HOPE (Hackers On Planet
Earth) conference launched what this reporter dubs &quot;Security Season.&quot;
Be prepared for an onslaught of computer security stories featuring
oh-so-clever hackers between now and the wrap-up of DEFCON 16 in mid-August.&lt;/p&gt;
&lt;p&gt;At the conference, hacker celebrity Kevin Mitnick appeared
to plug his coming tell-all book and demonstrated a script for Digium&#039;s
Asterisk IP PBX to show Caller ID information for someone calling even if the
phone&#039;s Caller ID is set to &quot;private.&quot;&lt;/p&gt;
&lt;p&gt;Other presentations at the conference went much deeper into
VoIP security. Blake Cornell and Jeremy McNamara discussed how a number of
foreign governments and ISPs are blocking VoIP services in attempt to protect a
telephone monopoly and/or to censor information. The duo will release a pair of
tools to determine if an ISP is blocking SIP and to scan entire netblocks to
determine if any Asterisk IAX2 services are available. Details were also provided as to how Asterisk
and VoIP providers who support IAX2 can provide virtually un-blockable VoIP
services in a country that is actively blocking SIP-based VoIP services.&lt;/p&gt;
&lt;p&gt;Sessions also touched upon the ability to use VoIP as a low
cost method to probe phone networks around the world and incidents last year
where a group of Italian VoIP hackers exploited VoIP vulnerabilities.&lt;/p&gt;
&lt;p&gt;For more:&lt;br /&gt;- Silicon Valley Insider spots &lt;a href=&quot;http://www.alleyinsider.com/2008/7/uber-hacker-kevin-mitnick-signs-tell-all-book-deal-&quot;&gt;Mitnick
hacking Asterisk&lt;/a&gt;&lt;br /&gt;- The &lt;a href=&quot;http://www.thelasthope.org/&quot;&gt;Last Hope&lt;/a&gt; website&lt;br /&gt;- Jeremy McNamara&#039;s &lt;a href=&quot;http://www.jeremy-mcnamara.com/&quot;&gt;VoIP/Asterisk
blog&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Related articles:&lt;/strong&gt;&lt;br /&gt; Newport
Networks Riles Up &lt;a href=&quot;http://www.fiercevoip.com/story/newport-networks-riles-voip-security-fears/2008-05-18&quot;&gt;VoIP
Security Fears&lt;/a&gt;&lt;br /&gt; VoIP Security and the &lt;a href=&quot;http://www.fiercevoip.com/story/voip-security-and-circle-trust/2008-05-06&quot;&gt;Circle
of Trust&lt;/a&gt;&lt;/p&gt;</description>
 <comments>http://www.fiercevoip.com/story/last-hope-launches-security-season/2008-07-20#comments</comments>
 <category domain="http://www.fiercevoip.com/tags/asterisk">Asterisk</category>
 <category domain="http://www.fiercevoip.com/tags/computer-security">Computer Security</category>
 <category domain="http://www.fiercevoip.com/tags/defcon">Defcon</category>
 <category domain="http://www.fiercevoip.com/tags/digium">digium</category>
 <category domain="http://www.fiercevoip.com/tags/hope-website">Hope Website</category>
 <category domain="http://www.fiercevoip.com/tags/kevin-mitnick">Kevin Mitnick</category>
 <category domain="http://www.fiercevoip.com/tags/last-hope">Last Hope</category>
 <category domain="http://www.fiercevoip.com/tags/voip-security">VoIP Security</category>
 <category domain="http://www.fiercevoip.com/tags/vulnerabilities-0">Vulnerabilities</category>
 <pubDate>Sun, 20 Jul 2008 16:26:58 -0400</pubDate>
 <dc:creator>Doug Mohney</dc:creator>
 <guid isPermaLink="false">2618 at http://www.fiercevoip.com</guid>
</item>
<item>
 <title>UC Data Leakage Dangers</title>
 <link>http://www.fiercevoip.com/story/uc-data-leakage-dangers/2008-07-19?utm_medium=rss&amp;utm_source=rss&amp;cmp-id=OTC-RSS-FV0</link>
 <description>&lt;p&gt;It&#039;s not just &lt;em&gt;&lt;a href=&quot;http://www.fiercevoip.com/story/uc-insecurity/2008-07-19&quot;&gt;Light Reading&lt;/a&gt;&lt;/em&gt; that&#039;s talking about UC security this week. Osterman Research has conducted a
survey polling enterprises on their security thoughts and features about UC.&lt;/p&gt;
&lt;p&gt;Companies are starting to understand that UC is a good
thing, but it creates even more opportunities for data leaks. Nearly 50 percent of respondents are
concerned about information leak prevention in their current or planned UC
implementation with 23 percent viewing leak prevention as a top priority, said
109 mid- to large-IT organizations in North America.&lt;/p&gt;
&lt;p&gt;IT shops are worried that attackers get a menu of choices by
putting all communications traffic onto one common data network. An attacker
can intercept VoIP, IM and other traffic or choose to inflict a
denial-of-service attack by using VoIP to flood systems with session requests.&lt;/p&gt;
&lt;p&gt;Outsider attacks, however, pale in comparison to insider
threats from either unintentional or accidental leaks, with 48 percent of
respondents worried about such a problem compared to 31 percent who worry
about data loss from malicious software.&lt;/p&gt;
&lt;p&gt;For more:&lt;br /&gt; - SearchSecurity.com reports on the &lt;a href=&quot;http://searchsecurity.techtarget.com/news/article/0,289142,sid14_gci1321656,00.html&quot;&gt;UC
security survey&lt;/a&gt; by Osterman Research&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Related articles:&lt;/strong&gt;&lt;br /&gt; &lt;a href=&quot;http://www.fiercevoip.com/story/uc-insecurity/2008-07-19&quot;&gt;UC
Insecurity&lt;/a&gt;&lt;br /&gt; UC security &lt;a href=&quot;http://www.fiercevoip.com/story/uc-security-urgent-priority/2008-01-31&quot;&gt;urgent
priority&lt;/a&gt;&lt;/p&gt;</description>
 <comments>http://www.fiercevoip.com/story/uc-data-leakage-dangers/2008-07-19#comments</comments>
 <category domain="http://www.fiercevoip.com/tags/denial-service-attack">Denial Of Service Attack</category>
 <category domain="http://www.fiercevoip.com/tags/enterprise-voip">Enterprise VoIP</category>
 <category domain="http://www.fiercevoip.com/tags/leak-prevention">Leak Prevention</category>
 <category domain="http://www.fiercevoip.com/tags/unified-communications">Unified Communications</category>
 <category domain="http://www.fiercevoip.com/tags/voip-security">VoIP Security</category>
 <pubDate>Sat, 19 Jul 2008 20:40:51 -0400</pubDate>
 <dc:creator>Doug Mohney</dc:creator>
 <guid isPermaLink="false">2617 at http://www.fiercevoip.com</guid>
</item>
</channel>
</rss>
