SlideShare a Scribd company logo
1 of 243
The Black Bag Security  Review Dan York, CISSP Emerging Telephony 2007
The Story of SysAdmin Steve ,[object Object]
Once upon a time...
big company
smaller company
promotion
IT
phones, too!
new VoIP system
net head
V
Voice
SIP
open standard
Security Isn’t Possible
education
IP-PBX SIP Service Provider LAN Internet PSTN
cheap
merged
quit
?
new IT staff
Juvenile Joe
BOFH
read e-mail
monitor
comment
playground
exploit chaos
fun
ultimate truism
voice = packets
packets = bits
bits can be manipulated
“ VoIP security tools”
tools, tools, tools
voipsa.org
hackingvoip.com
sectools.org
tools, tools, tools
good
evil
test/defend
attack
perspective
white hat
black hat
wireshark ,[object Object]
 
cain & abel
RTP
WAV
MP3s
iPod
2-hour commute
corporate conversations
personal iPod
corporate conversations
personal iPod
(scared yet?)
conversations
PIN
voicemail PINs
banking PINs
DTMF decoder
(fun stuff, eh?)
Teleworker Ted
envy
grudge
hang up Ted
cell phone
devious
mix in new background
amusement park
screaming kids
dog
Ted’s dog
endless barking
no clue
Process Paul
new rules
worked late
wife
female
no clue
???
insecure firewall
family
SIP softphone
free long distance
(toll fraud)
Board conf calls
revenues in the tank
acquisition
only hope
IT outsourced
job
(Uh-oh)
war
SIP trunk
unencrypted
sniff CID
lawyers
CFO
SIP Redirect
random extension
shipping
HR
labs
kitchen
?
acquire?
@#$@?%$!
SysAdmin Steve
fix it
DoS
BYE
hang up CEO
set reload
erase SIP registration
busy
packet flood
degrade
cell phones
acquire?
@#$@?%$!
SysAdmin Steve
fix it
3 strikes
investigation
truth
discovered
heart attack
SIP trunk
unencrypted
corporate conversations
public Internet
clear
call records
public Internet
cleartext
(not good)
plan
Fire Joe!
defense in depth
layers
encryption
voice
call control
LAN
SIP trunk
clueless
new provider
call accounting
IP network
VLANs
IDS/IPS
monitoring
rate throttling
secure perimeter
firewall traversal
firmware
o/s patches
disable services
die, default passwords, die, die, die
layers
secure VoIP
caveat
internal
disgruntled
x%?
compromised servers
spyware
unsecured WiFi
(checked your parking lot lately?)
offline analysis
SIP trunk
$$$
security
(differentiator?)
Botnet Bob
zombies
fun
profit
Criminal Chris
espionage
identity theft
human replay attack
Spammer Sue
SPIT
1,000s of calls
“ significant event”
Congressman
mistress
public official
porn line
identity theft
13-yr-old
podcast
Wall Street Journal
“ VOIP IS INSECURE!”
moral
VoIP *can* be secure
work
plan
questions
education
good news
voipsa.org
VOIPSA Threat Taxonomy
VOIPSA  Best Practices
VOIPSEC  mailing list
blueboxpodcast.com
 
(if you’re not reading them, be aware the attackers ARE!)
defense in depth
layers and layers
voice
call control
SIP trunks
management interfaces / APIs
PSTN interfaces
PSTN
voip = IP + PSTN
it’s the network, stupid
IP network
voice = packets
packets = bits
bits can be manipulated
VoIP *can* be secure
work
plan
SysAdmin Steve?
happily ever after?
acquisition?
job?
CIO?
another story
To be continued...
The End ,[object Object]
Please practice safe VoIP!
Q&eh? ,[object Object]
Thank you ,[object Object]

More Related Content

Viewers also liked

Open source enterprise search and retrieval platform
Open source enterprise search and retrieval platformOpen source enterprise search and retrieval platform
Open source enterprise search and retrieval platform
mteutelink
 
54. Euskal Soziometroa -Bakea eta Bizikidetza / Sociometro Vasco 54 -Paz y Co...
54. Euskal Soziometroa -Bakea eta Bizikidetza / Sociometro Vasco 54 -Paz y Co...54. Euskal Soziometroa -Bakea eta Bizikidetza / Sociometro Vasco 54 -Paz y Co...
54. Euskal Soziometroa -Bakea eta Bizikidetza / Sociometro Vasco 54 -Paz y Co...
Irekia - EJGV
 
Edisi nasional1710
Edisi nasional1710Edisi nasional1710
Edisi nasional1710
epaperwol
 
Sobre el planeta del principito
Sobre el planeta del principitoSobre el planeta del principito
Sobre el planeta del principito
CRA LUMPIAQUE
 
HorizonsVol20Iss1_Online_spreads
HorizonsVol20Iss1_Online_spreadsHorizonsVol20Iss1_Online_spreads
HorizonsVol20Iss1_Online_spreads
Matt Corkery
 

Viewers also liked (18)

Historia infor iri
Historia infor iriHistoria infor iri
Historia infor iri
 
Programa. Foro para la igualdad 2014 - octubre
Programa. Foro para la igualdad 2014 - octubrePrograma. Foro para la igualdad 2014 - octubre
Programa. Foro para la igualdad 2014 - octubre
 
Open source enterprise search and retrieval platform
Open source enterprise search and retrieval platformOpen source enterprise search and retrieval platform
Open source enterprise search and retrieval platform
 
Oscar david toro
Oscar david toroOscar david toro
Oscar david toro
 
Rafael Carranza: La Batalla de Yungay. 1939.
Rafael Carranza: La Batalla de Yungay. 1939.Rafael Carranza: La Batalla de Yungay. 1939.
Rafael Carranza: La Batalla de Yungay. 1939.
 
54. Euskal Soziometroa -Bakea eta Bizikidetza / Sociometro Vasco 54 -Paz y Co...
54. Euskal Soziometroa -Bakea eta Bizikidetza / Sociometro Vasco 54 -Paz y Co...54. Euskal Soziometroa -Bakea eta Bizikidetza / Sociometro Vasco 54 -Paz y Co...
54. Euskal Soziometroa -Bakea eta Bizikidetza / Sociometro Vasco 54 -Paz y Co...
 
Precios reducidos
Precios reducidos Precios reducidos
Precios reducidos
 
Edisi nasional1710
Edisi nasional1710Edisi nasional1710
Edisi nasional1710
 
Quién da mas
Quién da masQuién da mas
Quién da mas
 
Sommerbuchtipps Ihrer Buchhandlung - Nordbuch Marketing
Sommerbuchtipps Ihrer Buchhandlung - Nordbuch MarketingSommerbuchtipps Ihrer Buchhandlung - Nordbuch Marketing
Sommerbuchtipps Ihrer Buchhandlung - Nordbuch Marketing
 
Guidebook+for+erasmus.doc
Guidebook+for+erasmus.docGuidebook+for+erasmus.doc
Guidebook+for+erasmus.doc
 
Sobre el planeta del principito
Sobre el planeta del principitoSobre el planeta del principito
Sobre el planeta del principito
 
fiesta del albariño maria sofia sp
fiesta del albariño maria sofia spfiesta del albariño maria sofia sp
fiesta del albariño maria sofia sp
 
HorizonsVol20Iss1_Online_spreads
HorizonsVol20Iss1_Online_spreadsHorizonsVol20Iss1_Online_spreads
HorizonsVol20Iss1_Online_spreads
 
Presentacion Plan de Unidad
Presentacion Plan de UnidadPresentacion Plan de Unidad
Presentacion Plan de Unidad
 
Rsgn 2128-2014-minedu
Rsgn 2128-2014-mineduRsgn 2128-2014-minedu
Rsgn 2128-2014-minedu
 
Inc29 13-i
Inc29 13-iInc29 13-i
Inc29 13-i
 
Reports on Fairness aware and privacy preserving friend matching protocol in ...
Reports on Fairness aware and privacy preserving friend matching protocol in ...Reports on Fairness aware and privacy preserving friend matching protocol in ...
Reports on Fairness aware and privacy preserving friend matching protocol in ...
 

Similar to ETel2007: The Black Bag Security Review (VoIP Security)

Ethical hacking by chandra prakash upadhyay
Ethical hacking by chandra prakash upadhyayEthical hacking by chandra prakash upadhyay
Ethical hacking by chandra prakash upadhyay
Chandra Prakash
 
It’s time to boost VoIP network security
It’s time to boost VoIP network securityIt’s time to boost VoIP network security
It’s time to boost VoIP network security
Bev Robb
 
Deconstructing Presence
Deconstructing PresenceDeconstructing Presence
Deconstructing Presence
Phil Wolff
 
Dave Troy's Presentation at eComm 2008
Dave Troy's Presentation at eComm 2008Dave Troy's Presentation at eComm 2008
Dave Troy's Presentation at eComm 2008
eComm2008
 

Similar to ETel2007: The Black Bag Security Review (VoIP Security) (20)

E Tel2007 Black Bag Session - VoIP Security Threats, Tools and Best Practices
E Tel2007 Black Bag Session - VoIP Security Threats, Tools and Best PracticesE Tel2007 Black Bag Session - VoIP Security Threats, Tools and Best Practices
E Tel2007 Black Bag Session - VoIP Security Threats, Tools and Best Practices
 
Ethical hacking by chandra prakash upadhyay
Ethical hacking by chandra prakash upadhyayEthical hacking by chandra prakash upadhyay
Ethical hacking by chandra prakash upadhyay
 
Weaponizing the Nokia N900 -- TakeDownCon, Dallas, 2011
Weaponizing the Nokia N900 -- TakeDownCon, Dallas, 2011Weaponizing the Nokia N900 -- TakeDownCon, Dallas, 2011
Weaponizing the Nokia N900 -- TakeDownCon, Dallas, 2011
 
Information Security - A Discussion
Information Security  - A DiscussionInformation Security  - A Discussion
Information Security - A Discussion
 
Top Five Internal Security Vulnerabilities
Top Five Internal Security VulnerabilitiesTop Five Internal Security Vulnerabilities
Top Five Internal Security Vulnerabilities
 
Amy mania - Put Words In My Mouth - DC2711 2019
Amy mania - Put Words In My Mouth - DC2711 2019Amy mania - Put Words In My Mouth - DC2711 2019
Amy mania - Put Words In My Mouth - DC2711 2019
 
Presence and the Real-Time Internet
Presence and the Real-Time InternetPresence and the Real-Time Internet
Presence and the Real-Time Internet
 
It’s time to boost VoIP network security
It’s time to boost VoIP network securityIt’s time to boost VoIP network security
It’s time to boost VoIP network security
 
Deconstructing Presence
Deconstructing PresenceDeconstructing Presence
Deconstructing Presence
 
Dave Troy's Presentation at eComm 2008
Dave Troy's Presentation at eComm 2008Dave Troy's Presentation at eComm 2008
Dave Troy's Presentation at eComm 2008
 
Protect your IPPBX against VOIP attacks
Protect your IPPBX against VOIP attacksProtect your IPPBX against VOIP attacks
Protect your IPPBX against VOIP attacks
 
Core Values Decision Sept
Core Values Decision SeptCore Values Decision Sept
Core Values Decision Sept
 
It security &_ethical_hacking
It security &_ethical_hackingIt security &_ethical_hacking
It security &_ethical_hacking
 
Technology Safety Practices
Technology Safety PracticesTechnology Safety Practices
Technology Safety Practices
 
VoIP Security 101 what you need to know
VoIP Security 101   what you need to knowVoIP Security 101   what you need to know
VoIP Security 101 what you need to know
 
Network Security
Network SecurityNetwork Security
Network Security
 
Cybercrime and IT ACT
Cybercrime and IT ACTCybercrime and IT ACT
Cybercrime and IT ACT
 
Lecture about network and host security to NII students
Lecture about network and host security to NII studentsLecture about network and host security to NII students
Lecture about network and host security to NII students
 
Hacking 1224807880385377-9
Hacking 1224807880385377-9Hacking 1224807880385377-9
Hacking 1224807880385377-9
 
Emerging Threats to Infrastructure
Emerging Threats to InfrastructureEmerging Threats to Infrastructure
Emerging Threats to Infrastructure
 

More from Dan York

Open Source and The Global Disruption Of Telecom: What Choices Will We Make?
Open Source and The Global Disruption Of Telecom: What Choices Will We Make?Open Source and The Global Disruption Of Telecom: What Choices Will We Make?
Open Source and The Global Disruption Of Telecom: What Choices Will We Make?
Dan York
 

More from Dan York (16)

Yes, IPv6 is Real! How To Make Your Apps Work (And Be As Fast As Possible)
Yes, IPv6 is Real! How To Make Your Apps Work (And Be As Fast As Possible) Yes, IPv6 is Real! How To Make Your Apps Work (And Be As Fast As Possible)
Yes, IPv6 is Real! How To Make Your Apps Work (And Be As Fast As Possible)
 
SIPNOC 2014 - Is It Time For TLS for SIP?
SIPNOC 2014 - Is It Time For TLS for SIP?SIPNOC 2014 - Is It Time For TLS for SIP?
SIPNOC 2014 - Is It Time For TLS for SIP?
 
A Choice Of Internet Futures: Will Nonprofits Be Stuck In The Slow Lane?
A Choice Of Internet Futures: Will Nonprofits Be Stuck In The Slow Lane?A Choice Of Internet Futures: Will Nonprofits Be Stuck In The Slow Lane?
A Choice Of Internet Futures: Will Nonprofits Be Stuck In The Slow Lane?
 
Open Source and The Global Disruption Of Telecom: What Choices Will We Make?
Open Source and The Global Disruption Of Telecom: What Choices Will We Make?Open Source and The Global Disruption Of Telecom: What Choices Will We Make?
Open Source and The Global Disruption Of Telecom: What Choices Will We Make?
 
DNS / DNSSEC / DANE / DPRIVE Results at IETF93 Hackathon
DNS / DNSSEC / DANE / DPRIVE Results at IETF93 HackathonDNS / DNSSEC / DANE / DPRIVE Results at IETF93 Hackathon
DNS / DNSSEC / DANE / DPRIVE Results at IETF93 Hackathon
 
Deploying New DNSSEC Algorithms (IEPG@IETF93 - July 2015)
Deploying New DNSSEC Algorithms (IEPG@IETF93 - July 2015)Deploying New DNSSEC Algorithms (IEPG@IETF93 - July 2015)
Deploying New DNSSEC Algorithms (IEPG@IETF93 - July 2015)
 
The State of VoIP Security, a.k.a. “Does Anyone Really Give A _____ About VoI...
The State of VoIP Security, a.k.a. “Does Anyone Really Give A _____ About VoI...The State of VoIP Security, a.k.a. “Does Anyone Really Give A _____ About VoI...
The State of VoIP Security, a.k.a. “Does Anyone Really Give A _____ About VoI...
 
How IPv6 Will Kill Telecom - And What We Need To Do About It
How IPv6 Will Kill Telecom - And What We Need To Do About ItHow IPv6 Will Kill Telecom - And What We Need To Do About It
How IPv6 Will Kill Telecom - And What We Need To Do About It
 
SIP, Unified Communications (UC) and Security
SIP, Unified Communications (UC) and SecuritySIP, Unified Communications (UC) and Security
SIP, Unified Communications (UC) and Security
 
ClueCon2009: The Security Saga of SysAdmin Steve
ClueCon2009: The Security Saga of SysAdmin SteveClueCon2009: The Security Saga of SysAdmin Steve
ClueCon2009: The Security Saga of SysAdmin Steve
 
SIP Trunking & Security in an Enterprise Network
SIP Trunking & Security  in an Enterprise NetworkSIP Trunking & Security  in an Enterprise Network
SIP Trunking & Security in an Enterprise Network
 
OSCON 2008: Mashing Up Voice and the Web Using Open Source and XML
OSCON 2008: Mashing Up Voice and the Web Using Open Source and XMLOSCON 2008: Mashing Up Voice and the Web Using Open Source and XML
OSCON 2008: Mashing Up Voice and the Web Using Open Source and XML
 
IP Telephony Security 101
IP Telephony Security 101IP Telephony Security 101
IP Telephony Security 101
 
Recording Remote Hosts/Interviews with VoIP/Skype
Recording Remote Hosts/Interviews with VoIP/SkypeRecording Remote Hosts/Interviews with VoIP/Skype
Recording Remote Hosts/Interviews with VoIP/Skype
 
Hacking and Attacking VoIP Systems - What You Need To Know
Hacking and Attacking VoIP Systems - What You Need To KnowHacking and Attacking VoIP Systems - What You Need To Know
Hacking and Attacking VoIP Systems - What You Need To Know
 
BLISS Problem Statement and Motivation
BLISS Problem Statement and MotivationBLISS Problem Statement and Motivation
BLISS Problem Statement and Motivation
 

Recently uploaded

Histor y of HAM Radio presentation slide
Histor y of HAM Radio presentation slideHistor y of HAM Radio presentation slide
Histor y of HAM Radio presentation slide
vu2urc
 
CNv6 Instructor Chapter 6 Quality of Service
CNv6 Instructor Chapter 6 Quality of ServiceCNv6 Instructor Chapter 6 Quality of Service
CNv6 Instructor Chapter 6 Quality of Service
giselly40
 
EIS-Webinar-Prompt-Knowledge-Eng-2024-04-08.pptx
EIS-Webinar-Prompt-Knowledge-Eng-2024-04-08.pptxEIS-Webinar-Prompt-Knowledge-Eng-2024-04-08.pptx
EIS-Webinar-Prompt-Knowledge-Eng-2024-04-08.pptx
Earley Information Science
 

Recently uploaded (20)

Boost Fertility New Invention Ups Success Rates.pdf
Boost Fertility New Invention Ups Success Rates.pdfBoost Fertility New Invention Ups Success Rates.pdf
Boost Fertility New Invention Ups Success Rates.pdf
 
The 7 Things I Know About Cyber Security After 25 Years | April 2024
The 7 Things I Know About Cyber Security After 25 Years | April 2024The 7 Things I Know About Cyber Security After 25 Years | April 2024
The 7 Things I Know About Cyber Security After 25 Years | April 2024
 
Histor y of HAM Radio presentation slide
Histor y of HAM Radio presentation slideHistor y of HAM Radio presentation slide
Histor y of HAM Radio presentation slide
 
Data Cloud, More than a CDP by Matt Robison
Data Cloud, More than a CDP by Matt RobisonData Cloud, More than a CDP by Matt Robison
Data Cloud, More than a CDP by Matt Robison
 
From Event to Action: Accelerate Your Decision Making with Real-Time Automation
From Event to Action: Accelerate Your Decision Making with Real-Time AutomationFrom Event to Action: Accelerate Your Decision Making with Real-Time Automation
From Event to Action: Accelerate Your Decision Making with Real-Time Automation
 
Presentation on how to chat with PDF using ChatGPT code interpreter
Presentation on how to chat with PDF using ChatGPT code interpreterPresentation on how to chat with PDF using ChatGPT code interpreter
Presentation on how to chat with PDF using ChatGPT code interpreter
 
Bajaj Allianz Life Insurance Company - Insurer Innovation Award 2024
Bajaj Allianz Life Insurance Company - Insurer Innovation Award 2024Bajaj Allianz Life Insurance Company - Insurer Innovation Award 2024
Bajaj Allianz Life Insurance Company - Insurer Innovation Award 2024
 
04-2024-HHUG-Sales-and-Marketing-Alignment.pptx
04-2024-HHUG-Sales-and-Marketing-Alignment.pptx04-2024-HHUG-Sales-and-Marketing-Alignment.pptx
04-2024-HHUG-Sales-and-Marketing-Alignment.pptx
 
Boost PC performance: How more available memory can improve productivity
Boost PC performance: How more available memory can improve productivityBoost PC performance: How more available memory can improve productivity
Boost PC performance: How more available memory can improve productivity
 
Slack Application Development 101 Slides
Slack Application Development 101 SlidesSlack Application Development 101 Slides
Slack Application Development 101 Slides
 
08448380779 Call Girls In Greater Kailash - I Women Seeking Men
08448380779 Call Girls In Greater Kailash - I Women Seeking Men08448380779 Call Girls In Greater Kailash - I Women Seeking Men
08448380779 Call Girls In Greater Kailash - I Women Seeking Men
 
Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...
Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...
Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...
 
CNv6 Instructor Chapter 6 Quality of Service
CNv6 Instructor Chapter 6 Quality of ServiceCNv6 Instructor Chapter 6 Quality of Service
CNv6 Instructor Chapter 6 Quality of Service
 
TrustArc Webinar - Stay Ahead of US State Data Privacy Law Developments
TrustArc Webinar - Stay Ahead of US State Data Privacy Law DevelopmentsTrustArc Webinar - Stay Ahead of US State Data Privacy Law Developments
TrustArc Webinar - Stay Ahead of US State Data Privacy Law Developments
 
Driving Behavioral Change for Information Management through Data-Driven Gree...
Driving Behavioral Change for Information Management through Data-Driven Gree...Driving Behavioral Change for Information Management through Data-Driven Gree...
Driving Behavioral Change for Information Management through Data-Driven Gree...
 
Understanding Discord NSFW Servers A Guide for Responsible Users.pdf
Understanding Discord NSFW Servers A Guide for Responsible Users.pdfUnderstanding Discord NSFW Servers A Guide for Responsible Users.pdf
Understanding Discord NSFW Servers A Guide for Responsible Users.pdf
 
A Domino Admins Adventures (Engage 2024)
A Domino Admins Adventures (Engage 2024)A Domino Admins Adventures (Engage 2024)
A Domino Admins Adventures (Engage 2024)
 
The Codex of Business Writing Software for Real-World Solutions 2.pptx
The Codex of Business Writing Software for Real-World Solutions 2.pptxThe Codex of Business Writing Software for Real-World Solutions 2.pptx
The Codex of Business Writing Software for Real-World Solutions 2.pptx
 
EIS-Webinar-Prompt-Knowledge-Eng-2024-04-08.pptx
EIS-Webinar-Prompt-Knowledge-Eng-2024-04-08.pptxEIS-Webinar-Prompt-Knowledge-Eng-2024-04-08.pptx
EIS-Webinar-Prompt-Knowledge-Eng-2024-04-08.pptx
 
Finology Group – Insurtech Innovation Award 2024
Finology Group – Insurtech Innovation Award 2024Finology Group – Insurtech Innovation Award 2024
Finology Group – Insurtech Innovation Award 2024
 

ETel2007: The Black Bag Security Review (VoIP Security)