<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0" xml:base="http://www.fiercevoip.com" xmlns:dc="http://purl.org/dc/elements/1.1/">
<channel>
 <title>VoIPShield</title>
 <link>http://www.fiercevoip.com/tags/voipshield</link>
 <description></description>
 <language>en</language>
<item>
 <title>VoIPShield says Microsoft OCS vulnerable to attacks</title>
 <link>http://www.fiercevoip.com/story/voipshield-says-microsoft-ocs-vulnerable-attacks/2008-11-14?utm_medium=rss&amp;utm_source=rss&amp;cmp-id=OTC-RSS-FV0</link>
 <description>&lt;p&gt;Media stream attacks could affect Micrsofot Office Communications Server (OCS) as well as Office Communicator and Windows Messenger, says VoIPshield Systems. Microsoft is looking into the report.&lt;/p&gt;
&lt;p&gt;VoIPshield says the vulnerabilities affect applications using protocols like RTP and, if exploited, could cause a denial of service (DOS) attack against not only the stated applications, but against the whole desktop. The company is not publicly disclosing details of the vulnerabilities, but says it confidentially discloses full details to affected vendors.&lt;/p&gt;
&lt;p&gt;A spokesperson for VoIPshield Labs said the company is currently validating new research that shows an attacker can gain unauthorized access to an unsuspecting user&#039;s laptop by manipulating the packets of a VoIP phone call - an attack that might even be able to traverse a PSTN gateway. If possible, this attack would be a far more subtle and serious threat than a DoS attack since there would be no warning.&lt;/p&gt;
&lt;p&gt;Microsoft is&amp;nbsp;investigating the finding and recommends both&amp;nbsp;managing patches and keeping all software up to date.&lt;/p&gt;
&lt;p&gt;For more:&lt;br /&gt;- Read the details of the alleged vulnerability.&amp;nbsp; &lt;a href=&quot;http://www.itworldcanada.com/a/News/3304fbfc-492f-42ca-b1a5-080833c1c96b.html&quot;&gt;Article&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Related articles&lt;/strong&gt;&lt;br /&gt;&lt;a href=&quot;http://www.fiercevoip.com/story/arbor-networks-voip-ipv6-emerging-security-threats/2008-11-11?utm_medium=rss&amp;amp;utm_source=rss&amp;amp;cmp-id=OTC-RSS-FV0&quot;&gt;Arbor Networks: VoIP, IPv6 emerging security threats - FierceVoIP&lt;/a&gt;&lt;br /&gt;&lt;a href=&quot;http://www.fiercevoip.com/story/voip-security-and-circle-trust/2008-05-06&quot;&gt;VoIP Security and the Circle of Trust - FierceVoIP&lt;/a&gt;&lt;/p&gt;</description>
 <comments>http://www.fiercevoip.com/story/voipshield-says-microsoft-ocs-vulnerable-attacks/2008-11-14#comments</comments>
 <category domain="http://www.fiercevoip.com/tags/denial-service">Denial Of Service</category>
 <category domain="http://www.fiercevoip.com/tags/denial-service-dos">Denial Of Service Dos</category>
 <category domain="http://www.fiercevoip.com/tags/rtp">Rtp</category>
 <category domain="http://www.fiercevoip.com/tags/security-threats">Security Threats</category>
 <category domain="http://www.fiercevoip.com/tags/unauthorized-access">Unauthorized Access</category>
 <category domain="http://www.fiercevoip.com/tags/voip-0">VoIP</category>
 <category domain="http://www.fiercevoip.com/tags/voip-security">VoIP Security</category>
 <category domain="http://www.fiercevoip.com/tags/voipshield">VoIPShield</category>
 <category domain="http://www.fiercevoip.com/tags/vulnerabilities-0">Vulnerabilities</category>
 <category domain="http://www.fiercevoip.com/tags/vulnerability">Vulnerability</category>
 <pubDate>Fri, 14 Nov 2008 15:56:05 -0500</pubDate>
 <dc:creator>Doug Mohney</dc:creator>
 <guid isPermaLink="false">2956 at http://www.fiercevoip.com</guid>
</item>
<item>
 <title>The Ease of Hacking VoIP</title>
 <link>http://www.fiercevoip.com/story/ease-hacking-voip/2008-08-03?utm_medium=rss&amp;utm_source=rss&amp;cmp-id=OTC-RSS-FV0</link>
 <description>&lt;p&gt;Most of the 300,000 privately owned IP PBX systems throughout the U.S. are &quot;wide open&quot; to anyone that wants to hack them, says ChannelWeb. Compounding matters are a lack of regulatory interest and failure of vendors to disclose vulnerabilities.&lt;/p&gt;
&lt;p&gt;With VoIP systems being implemented on data LANs and blended with other software for unified communications solutions, the potential for mischief can get very large very quickly. VoIPshield has been posting and demonstrating publicly documented (i.e. available through The Google) hacks. While Cisco Call Manager gets a workout on how easy it is to exploit, the real problem lies in companies not updating their VoIP and IP PBX software with the latest security patches and fixes like they do all with all their other software.&lt;/p&gt;
&lt;p&gt;If you&#039;re not worried yet, there&#039;s a free utility called VoIPhopper to jump between voice and data VLANs so one can easily bypass firewalls and nearly all the IDS software for sale today.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;For more:&lt;br /&gt;- &lt;a href=&quot;http://www.crn.com/security/209900949&quot;&gt;Hacking VoIP is easy&lt;/a&gt;, reports ChannelWeb&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Related articles:&lt;/strong&gt;&lt;br /&gt; Last HOPE Launches &lt;a href=&quot;http://www.fiercevoip.com/story/last-hope-launches-security-season/2008-07-20?utm_medium=rss&amp;amp;utm_source=rss&amp;amp;cmp-id=OTC-RSS-FV0&quot;&gt;Security Season&lt;/a&gt;&lt;br /&gt; SPOTLIGHT: Survey: &lt;a href=&quot;http://www.fiercetelecom.com/story/spotlight-survey-u.s.-firms-lax-about-voip-security/2008-03-27&quot;&gt;U.S. firms lax&lt;/a&gt; about VoIP security&lt;/p&gt;</description>
 <comments>http://www.fiercevoip.com/story/ease-hacking-voip/2008-08-03#comments</comments>
 <category domain="http://www.fiercevoip.com/tags/cisco">Cisco</category>
 <category domain="http://www.fiercevoip.com/tags/security-patches">Security Patches</category>
 <category domain="http://www.fiercevoip.com/tags/voip-security">VoIP Security</category>
 <category domain="http://www.fiercevoip.com/tags/voip-technology">VoIP Technology</category>
 <category domain="http://www.fiercevoip.com/tags/voipshield">VoIPShield</category>
 <category domain="http://www.fiercevoip.com/tags/vulnerabilities-0">Vulnerabilities</category>
 <pubDate>Sun, 03 Aug 2008 21:54:14 -0400</pubDate>
 <dc:creator>Doug Mohney</dc:creator>
 <guid isPermaLink="false">2655 at http://www.fiercevoip.com</guid>
</item>
<item>
 <title>Avaya, Cisco and Nortel Patching VoIP ASAP</title>
 <link>http://www.fiercevoip.com/story/avaya-cisco-and-nortel-patching-voip-asap/2008-06-24?utm_medium=rss&amp;utm_source=rss&amp;cmp-id=OTC-RSS-FV0</link>
 <description>&lt;p&gt;VoIP customers of Avaya, Cisco and Nortel should be on the
lookout for patches today by 12 p.m. EDT to correct security vulnerabilities
discovered by VoIPshield Laboratories.&lt;/p&gt;
&lt;p&gt;According to &lt;em&gt;Network
World&lt;/em&gt;, VoIPShield earlier found and quietly reported the problems to the
three vendors to give them time to develop patches for the flaws. Details of
the vulnerabilities and vendor fixes are scheduled to be released in a
simultaneous announcement between the three VoIP vendors and the security
company. Two of the three vendors are
expected to issue patches with the third to issue an advisory.&lt;/p&gt;
&lt;p&gt;Vulnerabilities found affect VoIP PBXes and softphone
software. If exploited, consequences could include remote code execution, unauthorized
access, denial of service, and information harvesting.&lt;/p&gt;
&lt;p&gt;Avaya, Cisco and Nortel were chosen by VoIPshield for
testing because they represent the bulk of IP PBX sales in North
 America. Microsoft has been
included in the next round of testing with results expected to be announced in
about four months.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;For more&lt;br /&gt; - Network World reports Avaya, Cisco and Nortel &lt;a href=&quot;http://www.networkworld.com/news/2008/062408-voip-vulnerabilities.html&quot;&gt;VoIP
vulnerabilities&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Related articles:&lt;/strong&gt;&lt;br /&gt; Newport Networks Riles Up &lt;a href=&quot;http://www.fiercevoip.com/story/newport-networks-riles-voip-security-fears/2008-05-18&quot;&gt;VoIP
Security Fears&lt;/a&gt;&lt;br /&gt; Circle the wagons, &lt;a href=&quot;http://www.fiercevoip.com/story/circle-the-wagons-enterprise-voip-is-under-attack/2008-04-03&quot;&gt;enterprise
VoIP is under attack&lt;/a&gt;&lt;br /&gt; &lt;a href=&quot;http://www.fiercevoip.com/story/nortel-adds-voip-security-thru-securelogix/2008-06-02&quot;&gt;Nortel
Adds VoIP Security&lt;/a&gt; Thru SecureLogix&lt;/p&gt;</description>
 <comments>http://www.fiercevoip.com/story/avaya-cisco-and-nortel-patching-voip-asap/2008-06-24#comments</comments>
 <category domain="http://www.fiercevoip.com/tags/avaya">Avaya</category>
 <category domain="http://www.fiercevoip.com/tags/cisco">Cisco</category>
 <category domain="http://www.fiercevoip.com/tags/nortel">Nortel</category>
 <category domain="http://www.fiercevoip.com/tags/patches">Patches</category>
 <category domain="http://www.fiercevoip.com/tags/security-company">Security Company</category>
 <category domain="http://www.fiercevoip.com/tags/security-vulnerabilities">Security Vulnerabilities</category>
 <category domain="http://www.fiercevoip.com/tags/voip-security">VoIP Security</category>
 <category domain="http://www.fiercevoip.com/tags/voipshield">VoIPShield</category>
 <pubDate>Tue, 24 Jun 2008 22:48:49 -0400</pubDate>
 <dc:creator>Doug Mohney</dc:creator>
 <guid isPermaLink="false">2557 at http://www.fiercevoip.com</guid>
</item>
</channel>
</rss>
