Hacking and Attacking VoIP Systems - What You Need To Know

Loading...

Flash Player 9 (or above) is needed to view presentations.
We have detected that you do not have it on your computer. To install it, go here.

0 comments

Post a comment

    Post a comment
    Embed Video
    Edit your comment Cancel

    5 Favorites

    Hacking and Attacking VoIP Systems - What You Need To Know - Presentation Transcript

    1. Hacking and Attacking VoIP Systems What You Need To Worry About Dan York, CISSP VOIPSA Best Practices Chair September 27, 2007
    2. Privacy Availability Compliance Confidence Mobility Cost Avoidance Business Continuity © 2007 VOIPSA and Owners as Marked p.
    3. © 2007 VOIPSA and Owners as Marked p.
    4. © 2007 VOIPSA and Owners as Marked p.
    5. © 2007 VOIPSA and Owners as Marked p.
    6. TDM security is relatively simple... PSTN Gateways TDM Switch Physical Wiring Voicemail © 2007 VOIPSA and Owners as Marked p.
    7. VoIP security is more complex Desktop Operating PSTN E-mail PCs Systems Gateways Systems Network Web Firewalls Switches Servers Standards PDAs Voice over Wireless IP Devices Instant Messaging Directories Internet Databases Physical Voicemail Wiring © 2007 VOIPSA and Owners as Marked p.
    8. What is the Industry Doing to Help? Security Vendors VoIP Vendors “The Sky Is Falling!” “Don’t Worry, Trust Us!” (Buy our products!) (Buy our products!) © 2007 VOIPSA and Owners as Marked p.
    9. Voice Over IP Security Alliance (VOIPSA) • www.voipsa.org – 100 members from VoIP and security industries • VOIPSEC mailing list – www.voipsa.org/VOIPSEC/ • “Voice of VOIPSA” Blog – www.voipsa.org/blog • Blue Box: The VoIP Security Podcast – www.blueboxpodcast.com • VoIP Security Threat Taxonomy • Best Practices Project underway now Security Research Market and Social Classification Best Practices Outreach Objectives and Taxonomy of for VoIP Communication Constraints Security Threats Security of Findings Security System Testing Published Active Now Ongoing LEGEND © 2007 VOIPSA and Owners as Marked p.
    10. VoIP Security
    11. Security concerns in telephony are not new… Image courtesy of the Computer History Museum © 2007 VOIPSA and Owners as Marked p.
    12. Nor are our attempts to protect against threats… Image courtesy of Mike Sandman – http://www.sandman.com/ © 2007 VOIPSA and Owners as Marked p.
    13. Security Aspects of IP Telephony Media / Voice Manage TCP/IP Call ment Network Control PSTN Policy © 2007 VOIPSA and Owners as Marked p.
    14. Media Eavesdropping Degraded Voice Quality Encryption Virtual LANs (VLANs) Packet Filtering © 2007 VOIPSA and Owners as Marked p.
    15. Signaling Denial of Service Impersonation Toll Fraud Encryption Encrypted Phone Software Proper Programming © 2007 VOIPSA and Owners as Marked p.
    16. Management Web Interfaces APIs! Phones! Encryption Change Default Passwords! Patches? We don’t need... © 2007 VOIPSA and Owners as Marked p.
    17. PSTN © 2007 VOIPSA and Owners as Marked p.
    18. LAN Internet © 2007 VOIPSA and Owners as Marked p.
    19. What about SPIT? (“SPam over Internet Telephony”) • Makes for great headlines, but not yet a significant threat • Fear is script/tool that: –Iterates through calling SIP addresses: • 111@sip.company.com, 112@sip.company.com, … • Opens an audio stream if call is answered (by person or voicemail) –Steals VoIP credentials and uses account to make calls SPAM • Reality is that today such direct connections are generally not allowed • This will change as companies make greater use of SIP trunking and/or directly connect IP-PBX systems to the Internet (and allow incoming calls from any other IP endpoint) • Until that time, Telemarketers have to initiate unsolicited calls through the PSTN to reach their primary market: slows them down and adds cost © 2007 VOIPSA and Owners as Marked p.
    20. The Challenge of SIP Trunking PSTN SIP Service Provider Internet IP-PBX LAN © 2007 VOIPSA and Owners as Marked p.
    21. VoIP Security Tools
    22. www.voipsa.org/Resources/tools.php www.hackingvoip.com © 2007 VOIPSA and Owners as Marked p.
    23. © 2007 VOIPSA and Owners as Marked p.
    24. Tools, tools, tools... • UDP Flooder • Asteroid • IAX Flooder • enumIAX • IAX Enumerator • iWar • ohrwurm RTP Fuzzer • StegRTP • RTP Flooder • VoiPong • INVITE Flooder • Web Interface for SIP Trace • AuthTool • SIPScan • BYE Teardown • SIPCrack • Redirect Poison • SiVuS • Registration Hijacker • SIPVicious Tool Suite • Registration Eraser • SIPBomber • RTP InsertSound • SIPsak • RTP MixSound • SIP bot • SPITTER © 2007 VOIPSA and Owners as Marked p.
    25. Asterisk & Security
    26. www.asterisk.org/security © 2007 VOIPSA and Owners as Marked p.
    27. Security Suggestions for Asterisk 1. TLS-encrypted SIP • needs SIP over TCP first... 2. Secure RTP (SRTP) • there’s a patch 3. SRTP Key Exchange • sdescriptions now, DTLS or potentially ZRTP in the future If Asterisk is configured to use 4. Figure out the phone configuration mess IMAP as its backend storage for • so that the web servers on the phones can be disabled voicemail, then an e-mail sent to a • auto configuration is a start, but how secure are the config files? user with an invalid/corrupted MIME body will cause Asterisk to crash 5. Identity when the user listens to their • RFC 4474 (SIP Identity) voicemail using the phone. 6. Watch out for the APIs and the apps • always fun when a rolodex app can crash your phone system! 7. Toll fraud?? 8. Testing with tools? © 2007 VOIPSA and Owners as Marked p.
    28. Resources
    29. Security Links • VoIP Security Alliance - http://www.voipsa.org/ –Threat Taxonomy - http://www.voipsa.org/Activities/taxonomy.php –VOIPSEC email list - http://www.voipsa.org/VOIPSEC/ –Weblog - http://www.voipsa.org/blog/ –Security Tools list - http://www.voipsa.org/Resources/tools.php –Blue Box: The VoIP Security Podcast - http://www.blueboxpodcast.com • NIST SP800-58, “Security Considerations for VoIP Systems” – http://csrc.nist.gov/publications/nistpubs/800-58/SP800-58-final.pdf • Network Security Tools – http://sectools.org/ • Hacking Exposed VoIP site and tools – http://www.hackingvoip.com/ © 2007 VOIPSA and Owners as Marked p.
    30. Q&eh? www.voipsa.org
    31. Speaker Introduction – Dan York Dan York, CISSP, is the Best Practices Chair for the VOIP Security Alliance where he leads the project to develop and document a concise set of industry-wide best practices for security VoIP systems. He is also heading up VOIPSA's move into \"social media\" with the launch of the Voice of VOIPSA group weblog. Additionally, York is the producer of Blue Box: The VoIP Security Podcast where each week he and co-host Jonathan Zar discuss VoIP security news and interview people involved in the field. Most recently he served as Director of IP Technology reporting to the CTO of Mitel Corporation and focused on emerging VoIP technology and VoIP security. As chair of Mitel's Product Security Team, he coordinates the efforts of a cross-functional group to communicate both externally and internally on VoIP security issues, respond to customer inquiries related to security, investigate security vulnerability reports, and monitor security standards and trends. Previously, York served in Mitel Product Management bringing multiple products to market including Mitel's secure VoIP Teleworker Solution in 2003. His writing can also be found online at his weblog, Disruptive Telephony. © 2007 VOIPSA and Owners as Marked p.
    32. Other Best Practices Media / Voice TCP/IP Manage Call Network • Network ment Control Policy PSTN –Networks should be evaluated for readiness to carry VoIP traffic. –Secure mechanisms should be used for traversal of firewalls. • Phone Sets –Set software loads should be encrypted and tamper-proof. –Sets should run the minimum of services required. –Connection of a set to the system must require an initial authentication and authorization. • Servers –Servers should be incorporated into appropriate patch management and anti-virus systems. –Sufficient backup power should be available to maintain operation of telephony devices (and necessary network infrastructure) in the event of a power failure. • Wireless –All wireless devices should implement WPA and/or WPA2 versus WEP. © 2007 VOIPSA and Owners as Marked p.

    + Dan YorkDan York, 2 years ago

    custom

    5075 views, 5 favs, 10 embeds more stats

    Presentation by Dan York at AstriCon 2007 about how more

    More info about this document

    CC Attribution-NonCommercial-NoDerivs LicenseCC Attribution-NonCommercial-NoDerivs LicenseCC Attribution-NonCommercial-NoDerivs License

    Go to text version

    • Total Views 5075
      • 4652 on SlideShare
      • 423 from embeds
    • Comments 0
    • Favorites 5
    • Downloads 360
    Most viewed embeds
    • 234 views on http://voipsa.org
    • 133 views on http://www.blueboxpodcast.com
    • 48 views on http://leblogtoipvoip.blogspot.com
    • 2 views on http://www.arcanesecurity.net
    • 1 views on http://www.voipsa.org

    more

    All embeds
    • 234 views on http://voipsa.org
    • 133 views on http://www.blueboxpodcast.com
    • 48 views on http://leblogtoipvoip.blogspot.com
    • 2 views on http://www.arcanesecurity.net
    • 1 views on http://www.voipsa.org
    • 1 views on http://www.typepad.com
    • 1 views on http://66.102.9.104
    • 1 views on http://static.slideshare.net
    • 1 views on http://www.blogger.com
    • 1 views on http://translate.googleusercontent.com

    less

    Flagged as inappropriate Flag as inappropriate
    Flag as inappropriate

    Select your reason for flagging this presentation as inappropriate. If needed, use the feedback form to let us know more details.

    Cancel
    File a copyright complaint
    Having problems? Go to our helpdesk?

    Categories