<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0" xml:base="http://www.fiercevoip.com" xmlns:dc="http://purl.org/dc/elements/1.1/">
<channel>
 <title>Last Hope</title>
 <link>http://www.fiercevoip.com/tags/last-hope</link>
 <description></description>
 <language>en</language>
<item>
 <title>The sky is (not) falling (this summer)</title>
 <link>http://www.fiercevoip.com/story/sky-not-falling-summer/2008-07-23?utm_medium=rss&amp;utm_source=rss&amp;cmp-id=OTC-RSS-FV0</link>
 <description>&lt;p&gt;&lt;img src=&quot;http://static.fiercemarkets.com/public/headshots/doug100.jpg&quot; alt=&quot;&quot; align=&quot;right&quot; /&gt;Last weekend, The Last HOPE conference kicked off hacker awareness month. Between now and mid-August, prepare to hear about plenty of scary security stuff that may or may not affect you in the slightest.&lt;/p&gt;
&lt;p&gt;VoIP and voice security seem to be almost pass&amp;eacute; for the corporate-focused Black Hat conference in Las   Vegas (No session on VoIP) and its irregular weekend party/knowledgefest DEFCON (one session). Compare that to three VoIP sessions at Last HOPE, plus Kevin Mitnick&#039;s quickie workaround to crack Caller ID blocking and it&#039;s very quiet when compared to dramatic announcements at previous events in past years.&lt;/p&gt;
&lt;p&gt;The sole VoIP attack session at DEFCON discusses VoIPER, a toolkit to automatically and extensively test VoIP devices. VoIPER has been thrown at IP desk sets, softphones, and servers to find vulnerabilities. It&#039;s open source and you can take a look at the code at &lt;a href=&quot;http://sourceforge.net/projects/voiper&quot;&gt;http://sourceforge.net/projects/voiper&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;Is the quiet a good thing? I&#039;m not sure if this means VoIP security has become seriously boring or if there&#039;s a lot of behind-the-scenes activity we&#039;ll hear about in a more dramatic fashion next year. Certainly there&#039;s bound to be some UC security activity to be discussed in the months ahead.&lt;/p&gt;
&lt;p&gt;But for now, I&#039;d say that it&#039;s a good time to enjoy the rest of the summer--unless you have to worry about all the other security headaches bound to be pouring out of Black Hat and DEFCON in a couple of weeks.&lt;/p&gt;
&lt;p&gt;- &lt;a href=&quot;mailto:doug@fiercemarkets.com&quot;&gt;Doug&lt;/a&gt;&lt;/p&gt;</description>
 <comments>http://www.fiercevoip.com/story/sky-not-falling-summer/2008-07-23#comments</comments>
 <category domain="http://www.fiercevoip.com/tags/black-hat">Black Hat</category>
 <category domain="http://www.fiercevoip.com/tags/defcon">Defcon</category>
 <category domain="http://www.fiercevoip.com/tags/last-hope">Last Hope</category>
 <category domain="http://www.fiercevoip.com/tags/last-hope-0">the last hope</category>
 <category domain="http://www.fiercevoip.com/tags/voip-security">VoIP Security</category>
 <pubDate>Wed, 23 Jul 2008 16:14:13 -0400</pubDate>
 <dc:creator>Doug Mohney</dc:creator>
 <guid isPermaLink="false">2628 at http://www.fiercevoip.com</guid>
</item>
<item>
 <title>Digium CTO parses unblocked Caller ID hack</title>
 <link>http://www.fiercevoip.com/story/digium-cto-parses-unblocked-caller-id-hack/2008-07-22?utm_medium=rss&amp;utm_source=rss&amp;cmp-id=OTC-RSS-FV0</link>
 <description>&lt;p&gt;Normally, punching *67 should block Caller ID information
being passed through to a receiving caller. But, as security consultant Kevin Mitnick has demonstrated and Digium
CTO Mark Spencer explains, it&#039;s not 100 percent foolproof.&lt;/p&gt;
&lt;p&gt;At The Last HOPE hacker conference over the weekend, Mitnick
demonstrated how an appropriately configured Asterisk box and a suitable SIP
trunking service can be used to deliver Caller ID information even on inbound
calls that have a &quot;Private&quot; flag set.&lt;/p&gt;
&lt;p&gt;&quot;There are legitimate reasons why you need to set the Caller
ID to normal [and carry that information forward,]&quot; said Digium CTO Mark
Spencer. &quot;If, for example, I&#039;m in an enterprise environment and I want to have
calls forwarded [from my office number] to my cell phone, [the PBX] needs that
information.&quot;&lt;/p&gt;
&lt;p&gt;Mitnick used the &quot;enterprise class&quot; VoIP/SIP trunking
provider FlowRoute to get a phone number (DID) and service that would deliver
all of the call information to an Asterisk server.&amp;nbsp; The Asterisk server is simply setup/scripted
to pass along all Caller ID information for inbound calls regardless of the
setting of the privacy flag on the call.&lt;/p&gt;
&lt;p&gt;Spencer also noted that Caller ID information is also
carried along and recorded for &quot;private&quot; calls to toll free numbers; the
information is necessary for proper billing.&lt;/p&gt;
&lt;p&gt;Mark is not happy with the use of Asterisk for questionable
uses, but since it is open source, there is little he can do about it. &quot;I hate to say it, but the same reasons why
Asterisk is attractive to a lot of businesses, it&#039;s low cost, it can be easily
tweaked, it&#039;s more flexible, make it easy for using it for an illegitimate
purpose,&quot; said Spencer. &quot;It&#039;s a very powerful platform. I&#039;m not thrilled about
it being used for fraud and I&#039;m not thrilled with companies who build products
on it in competition with Digium, but there&#039;s not a lot I can do about it.&quot;&lt;/p&gt;
&lt;p&gt;For more:&lt;br /&gt;- Engadget snags &lt;a href=&quot;http://www.engadget.com/2008/07/21/how-to-reveal-blocked-caller-id-info-a-video-guide-to-risky-beh/&quot;&gt;Mitnick
demo video&lt;/a&gt; from The Last HOPE conference&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Related articles:&lt;/strong&gt;&lt;br /&gt; Last Hope Launches &lt;a href=&quot;http://www.fiercevoip.com/story/last-hope-launches-security-season/2008-07-20?utm_medium=rss&amp;amp;utm_source=rss&amp;amp;cmp-id=OTC-RSS-FV0&quot;&gt;Security
Season&lt;/a&gt;&lt;br /&gt; VoIP Security and the &lt;a href=&quot;http://www.fiercevoip.com/story/voip-security-and-circle-trust/2008-05-06&quot;&gt;Circle
of Trust&lt;/a&gt;&lt;/p&gt;</description>
 <comments>http://www.fiercevoip.com/story/digium-cto-parses-unblocked-caller-id-hack/2008-07-22#comments</comments>
 <category domain="http://www.fiercevoip.com/tags/caller-id">Caller Id</category>
 <category domain="http://www.fiercevoip.com/tags/digium">digium</category>
 <category domain="http://www.fiercevoip.com/tags/kevin-mitnick">Kevin Mitnick</category>
 <category domain="http://www.fiercevoip.com/tags/last-hope">Last Hope</category>
 <category domain="http://www.fiercevoip.com/tags/mark-spencer">Mark Spencer</category>
 <category domain="http://www.fiercevoip.com/tags/sip">SIP</category>
 <category domain="http://www.fiercevoip.com/tags/voip-security">VoIP Security</category>
 <pubDate>Tue, 22 Jul 2008 12:05:53 -0400</pubDate>
 <dc:creator>Doug Mohney</dc:creator>
 <guid isPermaLink="false">2624 at http://www.fiercevoip.com</guid>
</item>
<item>
 <title>Last Hope Launches Security Season</title>
 <link>http://www.fiercevoip.com/story/last-hope-launches-security-season/2008-07-20?utm_medium=rss&amp;utm_source=rss&amp;cmp-id=OTC-RSS-FV0</link>
 <description>&lt;p&gt;Over the weekend, 2600&#039;s The Last HOPE (Hackers On Planet
Earth) conference launched what this reporter dubs &quot;Security Season.&quot;
Be prepared for an onslaught of computer security stories featuring
oh-so-clever hackers between now and the wrap-up of DEFCON 16 in mid-August.&lt;/p&gt;
&lt;p&gt;At the conference, hacker celebrity Kevin Mitnick appeared
to plug his coming tell-all book and demonstrated a script for Digium&#039;s
Asterisk IP PBX to show Caller ID information for someone calling even if the
phone&#039;s Caller ID is set to &quot;private.&quot;&lt;/p&gt;
&lt;p&gt;Other presentations at the conference went much deeper into
VoIP security. Blake Cornell and Jeremy McNamara discussed how a number of
foreign governments and ISPs are blocking VoIP services in attempt to protect a
telephone monopoly and/or to censor information. The duo will release a pair of
tools to determine if an ISP is blocking SIP and to scan entire netblocks to
determine if any Asterisk IAX2 services are available. Details were also provided as to how Asterisk
and VoIP providers who support IAX2 can provide virtually un-blockable VoIP
services in a country that is actively blocking SIP-based VoIP services.&lt;/p&gt;
&lt;p&gt;Sessions also touched upon the ability to use VoIP as a low
cost method to probe phone networks around the world and incidents last year
where a group of Italian VoIP hackers exploited VoIP vulnerabilities.&lt;/p&gt;
&lt;p&gt;For more:&lt;br /&gt;- Silicon Valley Insider spots &lt;a href=&quot;http://www.alleyinsider.com/2008/7/uber-hacker-kevin-mitnick-signs-tell-all-book-deal-&quot;&gt;Mitnick
hacking Asterisk&lt;/a&gt;&lt;br /&gt;- The &lt;a href=&quot;http://www.thelasthope.org/&quot;&gt;Last Hope&lt;/a&gt; website&lt;br /&gt;- Jeremy McNamara&#039;s &lt;a href=&quot;http://www.jeremy-mcnamara.com/&quot;&gt;VoIP/Asterisk
blog&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Related articles:&lt;/strong&gt;&lt;br /&gt; Newport
Networks Riles Up &lt;a href=&quot;http://www.fiercevoip.com/story/newport-networks-riles-voip-security-fears/2008-05-18&quot;&gt;VoIP
Security Fears&lt;/a&gt;&lt;br /&gt; VoIP Security and the &lt;a href=&quot;http://www.fiercevoip.com/story/voip-security-and-circle-trust/2008-05-06&quot;&gt;Circle
of Trust&lt;/a&gt;&lt;/p&gt;</description>
 <comments>http://www.fiercevoip.com/story/last-hope-launches-security-season/2008-07-20#comments</comments>
 <category domain="http://www.fiercevoip.com/tags/asterisk">Asterisk</category>
 <category domain="http://www.fiercevoip.com/tags/computer-security">Computer Security</category>
 <category domain="http://www.fiercevoip.com/tags/defcon">Defcon</category>
 <category domain="http://www.fiercevoip.com/tags/digium">digium</category>
 <category domain="http://www.fiercevoip.com/tags/hope-website">Hope Website</category>
 <category domain="http://www.fiercevoip.com/tags/kevin-mitnick">Kevin Mitnick</category>
 <category domain="http://www.fiercevoip.com/tags/last-hope">Last Hope</category>
 <category domain="http://www.fiercevoip.com/tags/voip-security">VoIP Security</category>
 <category domain="http://www.fiercevoip.com/tags/vulnerabilities-0">Vulnerabilities</category>
 <pubDate>Sun, 20 Jul 2008 16:26:58 -0400</pubDate>
 <dc:creator>Doug Mohney</dc:creator>
 <guid isPermaLink="false">2618 at http://www.fiercevoip.com</guid>
</item>
</channel>
</rss>
