BREAKING: Discover How A Slacker Makes $100,000 A Year!

WEBMASTERS! Get Your Website To The Top Of Google


Confirmed: Ability to spy on remote calls with VoIP


Monday, December 3rd, 2007

In October, two security experts at hacker conference ToorCon9 in San Diego hacked into their hotel’s corporate network using a Cisco VoIP phone

By Linda Leung Framingham

Cisco confirmed it is possible to eavesdrop on remote conversations using Cisco VoIP phones. In its security response, Cisco says: “an attacker with valid Extension Mobility authentication credentials could cause a Cisco Unified IP Phone configured to use the Extension Mobility feature to transmit or receive a Real-Time Transport Protocol (RTP) audio stream.”

Cisco adds that Extension Mobility authentication credentials are not tied to individual IP phones and that “any Extension Mobility account configured on an IP phone’s Cisco Unified Communications Manager/CallManager (CUCM) server can be used to perform an eavesdropping attack.”

The technique was described by Telindus researcher Joffrey Czarny at HACK.LU 2007 in Luxembourg in October.

Cisco has published some workarounds to this problem in its security response.

Also in October, two security experts at hacker conference ToorCon9 in San Diego hacked into their hotel’s corporate network using a Cisco VoIP phone.

The hackers, John Kindervag and Jason Ostrom said they were able to access the hotel’s financial and corporate network and recorded other phone calls, according to a blog on Wired.com.

The hackers used penetration tests propounded by a tool called VoIP Hopper, which mimics the Cisco data packets sent at three minute intervals and then trades a new Ethernet interface, getting the PC — which the hackers switched in place of the hotel phone — into the network running the VoIP, according to the blog post.

The Avaya configuration is superior to Cisco, according to the hackers, because you have to send requests beyond a sniffer. Although it can be breached the same way, by replacing the phone with a PC.


Related News

This entry was posted on Monday, December 3rd, 2007 at 11:10 am and is filed under Science & Technology News, Surveillance, Civil Liberties & Human Rights News . You can follow any responses to this entry through the RSS 2.0 feed. You can leave a response, or trackback from your own site.
Translate: Translate to EnglishÜbersetzen Sie zum Deutsch/GermanПереведите к русскому/RussianΜεταφράστε στα ελληνικά/GreekVertaal aan het Nederlands/Dutchترجمة الى العربية/Arabic中文翻译/Chinese Traditional中文翻译/Chinese Simplified한국어에게 번역하십시오/Korean日本語に翻訳しなさい /JapaneseTraduza ao Português/PortugueseTraduca ad Italiano/ItalianTraduisez au Français/FrenchTraduzca al Español/Spanish


ALSO SEE
Instant Download
RINF Exclusives
RINF Classified Ads
Get to the top of Google

Forum

Network This Report

These icons link to social bookmarking sites where readers can share and discover new web pages.
  • del.icio.us
  • Technorati
  • Digg
  • StumbleUpon
  • Slashdot
  • Reddit
  • YahooMyWeb
  • Fark
  • Netscape
  • Furl

Email This Page To A Friend


Breaking Headlines
Stay Informed
RINF News Archives


Small Business Support
In light of the current financial climate, RINF has decided to support small & home based businesses. Give your support...
Hotels Morecambe
Web Hosting Reviews
Log Splitter
Home based business opportunities
Find Office Chairs
WoW guide reviews
Get Ghillie Suits
Best weight loss pills
Online Dating
Site Maps: 2003 - 2005 Archives | 2005 - 2007 Archives | 2007 - 2008 Archives | Current Archives | Alternative News Media
Usage of this document is covered by the Creative Commons Attribution-Non-Commercial-No Derivative Works License
Privacy Policy | © Copyright RINF NEWS - All Rights Reserved