<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/xsl" media="screen" href="/~d/styles/atom10full.xsl"?><?xml-stylesheet type="text/css" media="screen" href="http://feeds.feedburner.com/~d/styles/itemcontent.css"?><feed xmlns="http://www.w3.org/2005/Atom" xmlns:openSearch="http://a9.com/-/spec/opensearchrss/1.0/" xmlns:georss="http://www.georss.org/georss" xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0"><id>tag:blogger.com,1999:blog-6965515748199796807</id><updated>2009-07-02T17:40:30.755-07:00</updated><title type="text">SIPVicious</title><subtitle type="html" /><link rel="alternate" type="text/html" href="http://sipvicious.org/blog/" /><link rel="next" type="application/atom+xml" href="http://www.blogger.com/feeds/6965515748199796807/posts/default?start-index=26&amp;max-results=25" /><link rel="http://schemas.google.com/g/2005#feed" type="application/atom+xml" href="http://feeds.feedburner.com/Sipvicious" /><author><name>sandro</name><email>noreply@blogger.com</email></author><generator version="7.00" uri="http://www.blogger.com">Blogger</generator><openSearch:totalResults>81</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>25</openSearch:itemsPerPage><link rel="license" type="text/html" href="http://creativecommons.org/licenses/by-nc/2.0/" /><logo>http://creativecommons.org/images/public/somerights20.gif</logo><link rel="self" href="http://feeds.feedburner.com/Sipvicious" type="application/atom+xml" /><feedburner:emailServiceId>Sipvicious</feedburner:emailServiceId><feedburner:feedburnerHostname>http://feedburner.google.com</feedburner:feedburnerHostname><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="hub" href="http://pubsubhubbub.appspot.com" /><entry><id>tag:blogger.com,1999:blog-6965515748199796807.post-265272120812230377</id><published>2009-05-10T20:23:00.000-07:00</published><updated>2009-05-10T20:42:04.368-07:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="krakow" /><category scheme="http://www.blogger.com/atom/ns#" term="confidence 2009" /><category scheme="http://www.blogger.com/atom/ns#" term="sip iax2" /><category scheme="http://www.blogger.com/atom/ns#" term="voip presentation" /><category scheme="http://www.blogger.com/atom/ns#" term="poland" /><title type="text">Scanning the Intertubes for VoIP at CONFidence</title><content type="html">As I'm writing, plans are being made for my trip to Krakow, Poland for &lt;a href="https://www.owasp.org/index.php/AppSecEU09"&gt;AppSecEU09&lt;/a&gt; (OWASP) and &lt;a href="http://2009.confidence.org.pl/"&gt;CONFidence&lt;/a&gt;. Will be presenting at &lt;a href="http://2009.confidence.org.pl/"&gt;CONFidence&lt;/a&gt; on VoIP security and how it translates to the Internet. It will consist of a sample of the threats that exist out there and are or may be exploited by would be criminals.&lt;br /&gt;&lt;br /&gt;What this means is that I'll be describing a healthy dose of SIP and IAX2 abuse together with various live and recorded demos. As usual my &lt;a href="http://twitter.com/sandrogauci"&gt;Twitter&lt;/a&gt; account will be getting some updates as long as I'm conscious and my laptop battery still has some juice left ;-)&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://sipvicious.org/blog/uploaded_images/logo_conf_na_czarne-744892.gif"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 320px; height: 273px;" src="http://sipvicious.org/blog/uploaded_images/logo_conf_na_czarne-744891.gif" alt="" border="0" /&gt;&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6965515748199796807-265272120812230377?l=sipvicious.org%2Fblog'/&gt;&lt;/div&gt;</content><link rel="replies" type="application/atom+xml" href="http://www.blogger.com/feeds/6965515748199796807/265272120812230377/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="https://www.blogger.com/comment.g?blogID=6965515748199796807&amp;postID=265272120812230377" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/6965515748199796807/posts/default/265272120812230377" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/6965515748199796807/posts/default/265272120812230377" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/Sipvicious/~3/FQM3-PNg7vU/scanning-intertubes-for-voip-at.html" title="Scanning the Intertubes for VoIP at CONFidence" /><author><name>sandro</name><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd="http://schemas.google.com/g/2005" name="OpenSocialUserId" value="01651987283704076907" /></author><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://sipvicious.org/blog/2009/05/scanning-intertubes-for-voip-at.html</feedburner:origLink></entry><entry><id>tag:blogger.com,1999:blog-6965515748199796807.post-8585407038291664104</id><published>2009-04-15T07:18:00.000-07:00</published><updated>2009-04-15T07:30:20.304-07:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="munich" /><category scheme="http://www.blogger.com/atom/ns#" term="beer" /><category scheme="http://www.blogger.com/atom/ns#" term="troopers09" /><category scheme="http://www.blogger.com/atom/ns#" term="twitter security" /><category scheme="http://www.blogger.com/atom/ns#" term="iax2autohack" /><title type="text">Troopers09 &amp; IAX2 support</title><content type="html">I will be co-presenting in Munich together with Wendel on Web Application Firewall insecurities and dropping some new tools. If any readers are going to be around the area for &lt;a href="http://troopers09.org/content/e3/index_eng.html"&gt;Troopers09&lt;/a&gt; next week, drop me a &lt;a href="mailto:sandro@enablesecurity.com"&gt;note&lt;/a&gt;. &lt;span style="font-weight: bold;"&gt;Beer is mostly welcome. &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;My &lt;a href="http://www.twitter.com/sandrogauci"&gt;Twitter&lt;/a&gt; account will probably be getting a few updates ;-)&lt;br /&gt;&lt;br /&gt;As a sidenote.. &lt;a href="http://enablesecurity.com/2009/04/15/voippack-for-april-adds-asterisk-scanning/"&gt;VOIPPACK now gets IAX2 support&lt;/a&gt;, with 3 additional tools. Most notable is IAX2autohack which is very similar to sipautohack but for the Asterisk protocol. The video demo can be found over &lt;a href="http://vimeo.com/4162693"&gt;here.&lt;/a&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://sipvicious.org/blog/uploaded_images/troopers_burning_safe_small-771271.jpg"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 320px; height: 269px;" src="http://sipvicious.org/blog/uploaded_images/troopers_burning_safe_small-771269.jpg" alt="" border="0" /&gt;&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6965515748199796807-8585407038291664104?l=sipvicious.org%2Fblog'/&gt;&lt;/div&gt;</content><link rel="replies" type="application/atom+xml" href="http://www.blogger.com/feeds/6965515748199796807/8585407038291664104/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="https://www.blogger.com/comment.g?blogID=6965515748199796807&amp;postID=8585407038291664104" title="2 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/6965515748199796807/posts/default/8585407038291664104" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/6965515748199796807/posts/default/8585407038291664104" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/Sipvicious/~3/R6virFsEcHU/troopers09-iax2-support.html" title="Troopers09 &amp;amp; IAX2 support" /><author><name>sandro</name><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd="http://schemas.google.com/g/2005" name="OpenSocialUserId" value="01651987283704076907" /></author><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">2</thr:total><feedburner:origLink>http://sipvicious.org/blog/2009/04/troopers09-iax2-support.html</feedburner:origLink></entry><entry><id>tag:blogger.com,1999:blog-6965515748199796807.post-7131402950371767994</id><published>2009-04-07T05:47:00.000-07:00</published><updated>2009-04-07T05:53:52.635-07:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="voipscanner" /><title type="text">SaaS VoIP Security Scanning with VOIPSCANNER.com</title><content type="html">&lt;a href="http://beta.voipscanner.com/voipscanner/default/apply"&gt;Apply for a beta code&lt;/a&gt; now while its still hot!&lt;br /&gt;&lt;br /&gt;&lt;h3&gt;What is VOIPSCANNER.com?&lt;/h3&gt;         &lt;p&gt; VOIPSCANNER.COM makes scanning your public facing IP PBX for security holes easier than ever. No need for desktop applications or any software installation, just enter the IP address of your IP PBX and you will receive a report of what attackers out there might find about your IP PBX.&lt;br /&gt;&lt;/p&gt;&lt;p&gt;&lt;br /&gt;&lt;/p&gt;&lt;br /&gt;&lt;br /&gt;&lt;object width="400" height="314"&gt;&lt;param name="allowfullscreen" value="true" /&gt;&lt;param name="allowscriptaccess" value="always" /&gt;&lt;param name="movie" value="http://vimeo.com/moogaloop.swf?clip_id=3984490&amp;amp;server=vimeo.com&amp;amp;show_title=1&amp;amp;show_byline=1&amp;amp;show_portrait=0&amp;amp;color=00ADEF&amp;amp;fullscreen=1" /&gt;&lt;embed src="http://vimeo.com/moogaloop.swf?clip_id=3984490&amp;amp;server=vimeo.com&amp;amp;show_title=1&amp;amp;show_byline=1&amp;amp;show_portrait=0&amp;amp;color=00ADEF&amp;amp;fullscreen=1" type="application/x-shockwave-flash" allowfullscreen="true" allowscriptaccess="always" width="400" height="314"&gt;&lt;/embed&gt;&lt;/object&gt;&lt;br /&gt;&lt;a href="http://vimeo.com/3984490"&gt;beta.voipscanner.com demo&lt;/a&gt; from &lt;a href="http://vimeo.com/enablesecurity"&gt;Sandro Gauci&lt;/a&gt; on &lt;a href="http://vimeo.com"&gt;Vimeo&lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6965515748199796807-7131402950371767994?l=sipvicious.org%2Fblog'/&gt;&lt;/div&gt;</content><link rel="replies" type="application/atom+xml" href="http://www.blogger.com/feeds/6965515748199796807/7131402950371767994/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="https://www.blogger.com/comment.g?blogID=6965515748199796807&amp;postID=7131402950371767994" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/6965515748199796807/posts/default/7131402950371767994" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/6965515748199796807/posts/default/7131402950371767994" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/Sipvicious/~3/Ws8xol5pzqQ/saas-voip-security-scanning-with.html" title="SaaS VoIP Security Scanning with VOIPSCANNER.com" /><author><name>sandro</name><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd="http://schemas.google.com/g/2005" name="OpenSocialUserId" value="01651987283704076907" /></author><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://sipvicious.org/blog/2009/04/saas-voip-security-scanning-with.html</feedburner:origLink></entry><entry><id>tag:blogger.com,1999:blog-6965515748199796807.post-316571975072210689</id><published>2009-04-01T03:50:00.000-07:00</published><updated>2009-04-01T04:02:35.817-07:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="digest authentication" /><category scheme="http://www.blogger.com/atom/ns#" term="sip scan" /><category scheme="http://www.blogger.com/atom/ns#" term="ip phone hack" /><category scheme="http://www.blogger.com/atom/ns#" term="digest leak" /><title type="text">VoIPScanner, SIP Digest Leak tutorial and more!</title><content type="html">&lt;a style="font-weight: bold;" href="http://enablesecurity.com/resources/how-to-exploit-the-sip-digest-leak-vulnerability-by-using-voippack/"&gt;Check out the tutorial&lt;/a&gt;. This security flaw has been getting a bit of attention so I thought of preparing a tutorial on how to use VOIPPACK to demo it. There's &lt;a href="http://vimeo.com/3642600"&gt;the video&lt;/a&gt; that I posted earlier on which shows the attack in action. In the tutorial I explain how to do this step by step on a softphone and a hardphone as well.&lt;br /&gt;&lt;br /&gt;&lt;object height="250" width="400"&gt;&lt;param name="allowfullscreen" value="true"&gt;&lt;param name="allowscriptaccess" value="always"&gt;&lt;param name="movie" value="http://vimeo.com/moogaloop.swf?clip_id=3642600&amp;amp;server=vimeo.com&amp;amp;show_title=1&amp;amp;show_byline=1&amp;amp;show_portrait=1&amp;amp;color=00ADEF&amp;amp;fullscreen=1"&gt;&lt;embed src="http://vimeo.com/moogaloop.swf?clip_id=3642600&amp;amp;server=vimeo.com&amp;amp;show_title=1&amp;amp;show_byline=1&amp;amp;show_portrait=1&amp;amp;color=00ADEF&amp;amp;fullscreen=1" type="application/x-shockwave-flash" allowfullscreen="true" allowscriptaccess="always" height="250" width="400"&gt;&lt;/embed&gt;&lt;/object&gt;&lt;br /&gt;&lt;a href="http://vimeo.com/3642600"&gt;SIP Digest Leak&lt;/a&gt; from &lt;a href="http://vimeo.com/enablesecurity"&gt;Sandro Gauci&lt;/a&gt; on &lt;a href="http://vimeo.com/"&gt;Vimeo&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;Also started a new project called &lt;a href="http://voipscanner.com/"&gt;voipscanner.com&lt;/a&gt; which is currently in private beta. If you have an internet facing IP PBX that you'd like to scan, give &lt;a href="http://enablesecurity.com/contact"&gt;me a ping&lt;/a&gt; ;-) You might just about qualify for the private beta. Public beta will  be available later this week or earlier next week.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6965515748199796807-316571975072210689?l=sipvicious.org%2Fblog'/&gt;&lt;/div&gt;</content><link rel="replies" type="application/atom+xml" href="http://www.blogger.com/feeds/6965515748199796807/316571975072210689/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="https://www.blogger.com/comment.g?blogID=6965515748199796807&amp;postID=316571975072210689" title="2 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/6965515748199796807/posts/default/316571975072210689" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/6965515748199796807/posts/default/316571975072210689" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/Sipvicious/~3/tHFsCX5Edn4/voipscanner-sip-digest-leak-tutorial.html" title="VoIPScanner, SIP Digest Leak tutorial and more!" /><author><name>sandro</name><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd="http://schemas.google.com/g/2005" name="OpenSocialUserId" value="01651987283704076907" /></author><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">2</thr:total><feedburner:origLink>http://sipvicious.org/blog/2009/04/voipscanner-sip-digest-leak-tutorial.html</feedburner:origLink></entry><entry><id>tag:blogger.com,1999:blog-6965515748199796807.post-3101396130764054721</id><published>2009-03-24T07:11:00.000-07:00</published><updated>2009-03-24T07:21:45.251-07:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="voip lab" /><category scheme="http://www.blogger.com/atom/ns#" term="tutorial" /><title type="text">How to set up a VoIP lab</title><content type="html">Just published a tutorial called &lt;a href="http://enablesecurity.com/resources/how-to-set-up-a-voip-lab-on-a-shoe-string/"&gt;“How to set up a VoIP lab”&lt;/a&gt; which provides easy step-by-step instructions on how to get a VoIP lab up and running. Abstract:&lt;br /&gt;&lt;em&gt;&lt;/em&gt;&lt;blockquote&gt;&lt;em&gt;Have you been wondering about what sort of security vulnerabilities apply to the VoIP network that’s coming up in your next assignment but have no equipment to test on yet? &lt;/em&gt;&lt;br /&gt;Truth is that most of the times there is no need for a lot of expensive hardware to setup a basic lab for testing VoIP security.&lt;/blockquote&gt;&lt;em&gt;&lt;a href="http://resources.enablesecurity.com/resources/voiplab.pdf"&gt;Download the PDF version&lt;/a&gt;&lt;br /&gt;&lt;/em&gt;Hope this helps!&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6965515748199796807-3101396130764054721?l=sipvicious.org%2Fblog'/&gt;&lt;/div&gt;</content><link rel="replies" type="application/atom+xml" href="http://www.blogger.com/feeds/6965515748199796807/3101396130764054721/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="https://www.blogger.com/comment.g?blogID=6965515748199796807&amp;postID=3101396130764054721" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/6965515748199796807/posts/default/3101396130764054721" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/6965515748199796807/posts/default/3101396130764054721" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/Sipvicious/~3/dRp1jnZ6_vs/how-to-set-up-voip-lab.html" title="How to set up a VoIP lab" /><author><name>sandro</name><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd="http://schemas.google.com/g/2005" name="OpenSocialUserId" value="01651987283704076907" /></author><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://sipvicious.org/blog/2009/03/how-to-set-up-voip-lab.html</feedburner:origLink></entry><entry><id>tag:blogger.com,1999:blog-6965515748199796807.post-3726488513261622326</id><published>2009-03-17T10:17:00.001-07:00</published><updated>2009-03-17T10:31:40.395-07:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="fingerprinting sip" /><category scheme="http://www.blogger.com/atom/ns#" term="ghostcall" /><category scheme="http://www.blogger.com/atom/ns#" term="ip phone" /><category scheme="http://www.blogger.com/atom/ns#" term="digest leak" /><category scheme="http://www.blogger.com/atom/ns#" term="voippack" /><title type="text">Late March updates</title><content type="html">It's about time that we look at SIPVicious again. If you're making use of the SVN version, please update to the latest svn commit which includes some fixes for bugs that were creating unnecessary traffic.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;I'm currently planning on a major update of SIPVicious - &lt;a href="mailto:sandro@enablesecurity.com"&gt;email me&lt;/a&gt; with your suggestions and VoIP needs please ;-)&lt;/span&gt; Cleaner and extensible code guaranteed.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;VOIPPACK&lt;/span&gt; gets to target IP Phones this month, with 2 major new modules that highlight what can be done to both hardphones and softphones: Ghostcall and "SIP Digest Leak".&lt;br /&gt;&lt;br /&gt;Ghostcall might remind some people of the movie "The Omega Man" where all phones ring at the same time. Of course, the phones in the movie are most probably not VoIP phones but could very well be.&lt;br /&gt;&lt;br /&gt;Then there's "SIP Digest Leak" that highlights a vulnerability that affects many IP Phones. This tool allows penetration testers and other security dudes to force IP Phones to reveal the digest credentials and possibly recover the password used to access a PBX or a VoIP provider.&lt;br /&gt;&lt;br /&gt;More information about these tools was posted the &lt;a href="http://enablesecurity.com/2009/03/17/march-voippack-update-brings-ip-phone-attacks/"&gt;EnableSecurity blog&lt;/a&gt;. Actual demonstration videos on the &lt;a href="http://vimeo.com/album/48814"&gt;Vimeo account&lt;/a&gt;. And here's a clip from "The Omega Man" showing a 70's version of Ghostcall:&lt;br /&gt;&lt;br /&gt;&lt;object height="344" width="425"&gt;&lt;param name="movie" value="http://www.youtube.com/v/evdQL5RFLec&amp;amp;hl=en&amp;amp;fs=1"&gt;&lt;param name="allowFullScreen" value="true"&gt;&lt;param name="allowscriptaccess" value="always"&gt;&lt;embed src="http://www.youtube.com/v/evdQL5RFLec&amp;amp;hl=en&amp;amp;fs=1" type="application/x-shockwave-flash" allowscriptaccess="always" allowfullscreen="true" height="344" width="425"&gt;&lt;/embed&gt;&lt;/object&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6965515748199796807-3726488513261622326?l=sipvicious.org%2Fblog'/&gt;&lt;/div&gt;</content><link rel="replies" type="application/atom+xml" href="http://www.blogger.com/feeds/6965515748199796807/3726488513261622326/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="https://www.blogger.com/comment.g?blogID=6965515748199796807&amp;postID=3726488513261622326" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/6965515748199796807/posts/default/3726488513261622326" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/6965515748199796807/posts/default/3726488513261622326" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/Sipvicious/~3/ZdQJpwgvrfc/late-march-updates.html" title="Late March updates" /><author><name>sandro</name><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd="http://schemas.google.com/g/2005" name="OpenSocialUserId" value="01651987283704076907" /></author><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://sipvicious.org/blog/2009/03/late-march-updates.html</feedburner:origLink></entry><entry><id>tag:blogger.com,1999:blog-6965515748199796807.post-4018455245189396127</id><published>2009-02-18T06:11:00.000-08:00</published><updated>2009-02-18T06:17:43.654-08:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="mosdef" /><category scheme="http://www.blogger.com/atom/ns#" term="asterisk security" /><category scheme="http://www.blogger.com/atom/ns#" term="voippack" /><title type="text">How to identify Asterisk servers and upload MOSDEF on AsteriskNOW</title><content type="html">Originally posted this on &lt;a href="http://enablesecurity.com/blog"&gt;EnableSecurity's blog&lt;/a&gt; but cross posting since not everyone is subscribed.&lt;br /&gt;&lt;br /&gt;&lt;object height="225" width="400"&gt;&lt;param name="allowfullscreen" value="true"&gt;&lt;param name="allowscriptaccess" value="always"&gt;&lt;param name="movie" value="http://vimeo.com/moogaloop.swf?clip_id=3162761&amp;amp;server=vimeo.com&amp;amp;show_title=1&amp;amp;show_byline=1&amp;amp;show_portrait=0&amp;amp;color=&amp;amp;fullscreen=1"&gt;&lt;embed src="http://vimeo.com/moogaloop.swf?clip_id=3162761&amp;amp;server=vimeo.com&amp;amp;show_title=1&amp;amp;show_byline=1&amp;amp;show_portrait=0&amp;amp;color=&amp;amp;fullscreen=1" type="application/x-shockwave-flash" allowfullscreen="true" allowscriptaccess="always" height="225" width="400"&gt;&lt;/embed&gt;&lt;/object&gt;&lt;br /&gt;&lt;a href="http://vimeo.com/3162761"&gt;IAX2Scan and AsteriskNOW_Exec - security testing for Asterisk&lt;/a&gt; from &lt;a href="http://vimeo.com/enablesecurity"&gt;Sandro Gauci&lt;/a&gt; on &lt;a href="http://vimeo.com/"&gt;Vimeo&lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6965515748199796807-4018455245189396127?l=sipvicious.org%2Fblog'/&gt;&lt;/div&gt;</content><link rel="replies" type="application/atom+xml" href="http://www.blogger.com/feeds/6965515748199796807/4018455245189396127/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="https://www.blogger.com/comment.g?blogID=6965515748199796807&amp;postID=4018455245189396127" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/6965515748199796807/posts/default/4018455245189396127" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/6965515748199796807/posts/default/4018455245189396127" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/Sipvicious/~3/6DeM7TO0-E8/how-to-identify-asterisk-servers-and.html" title="How to identify Asterisk servers and upload MOSDEF on AsteriskNOW" /><author><name>sandro</name><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd="http://schemas.google.com/g/2005" name="OpenSocialUserId" value="01651987283704076907" /></author><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://sipvicious.org/blog/2009/02/how-to-identify-asterisk-servers-and.html</feedburner:origLink></entry><entry><id>tag:blogger.com,1999:blog-6965515748199796807.post-8441867792866327044</id><published>2009-01-21T10:59:00.000-08:00</published><updated>2009-01-21T11:20:03.082-08:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="pbx phreak" /><category scheme="http://www.blogger.com/atom/ns#" term="call forwarding" /><category scheme="http://www.blogger.com/atom/ns#" term="free phone calls" /><category scheme="http://www.blogger.com/atom/ns#" term="phone phreak" /><category scheme="http://www.blogger.com/atom/ns#" term="pbx hacked" /><title type="text">Phone phreaks are now using call forwarding features to make free phonecalls!</title><content type="html">&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://blog.wired.com/photos/uncategorized/2007/11/19/dougtv.jpg"&gt;&lt;img style="margin: 0pt 0pt 10px 10px; float: right; cursor: pointer; width: 248px; height: 179px;" src="http://blog.wired.com/photos/uncategorized/2007/11/19/dougtv.jpg" alt="" border="0" /&gt;&lt;/a&gt;Actually, they have been doing that for quite a while; say a couple of years. Yet it still works, and  we only hear about it when some organization is hit with a hefty phone bill because their PBX server has been abused.&lt;br /&gt;&lt;br /&gt;The West Australian is &lt;a href="http://www.thewest.com.au/default.aspx?MenuID=77&amp;amp;ContentID=119462"&gt;running a feature article&lt;/a&gt; on various (undisclosed) cases where PBX systems, some traditional while others are IP-based (and exposed on the Internet) were abused to make phonecalls to foreign countries.&lt;br /&gt;&lt;br /&gt;While looking for more information, &lt;a href="http://www.riskmanagementmagazine.com.au/articles/F4/0C038BF4.asp?Type=124&amp;amp;Category=1240"&gt;an article from 2005 showed up&lt;/a&gt; which describes what happened to a couple of organizations (hospitals and businesses). The telco companies tend to ask the victim organizations to pay up the phone bill for calls that the phone phreaks made.&lt;br /&gt;&lt;br /&gt;But now things are moving more towards the Internet, where attackers can be anywhere in the world and the cost of a packet is much less than that of a phonecall!&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6965515748199796807-8441867792866327044?l=sipvicious.org%2Fblog'/&gt;&lt;/div&gt;</content><link rel="replies" type="application/atom+xml" href="http://www.blogger.com/feeds/6965515748199796807/8441867792866327044/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="https://www.blogger.com/comment.g?blogID=6965515748199796807&amp;postID=8441867792866327044" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/6965515748199796807/posts/default/8441867792866327044" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/6965515748199796807/posts/default/8441867792866327044" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/Sipvicious/~3/_YIXshecKdM/phone-phreaks-are-now-using-call.html" title="Phone phreaks are now using call forwarding features to make free phonecalls!" /><author><name>sandro</name><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd="http://schemas.google.com/g/2005" name="OpenSocialUserId" value="01651987283704076907" /></author><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://sipvicious.org/blog/2009/01/phone-phreaks-are-now-using-call.html</feedburner:origLink></entry><entry><id>tag:blogger.com,1999:blog-6965515748199796807.post-8956057751277574585</id><published>2009-01-06T14:39:00.000-08:00</published><updated>2009-01-06T14:45:56.829-08:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="sipautohack" /><category scheme="http://www.blogger.com/atom/ns#" term="immunity" /><category scheme="http://www.blogger.com/atom/ns#" term="canvas" /><category scheme="http://www.blogger.com/atom/ns#" term="voippack" /><title type="text">VOIPPACK released</title><content type="html">Yep its out! Check out the &lt;a href="http://enablesecurity.com/2009/01/05/voippack-now-available/"&gt;announcement on EnableSecurity&lt;/a&gt;. For more information about VOIPPACK refer to the &lt;a href="http://enablesecurity.com/products/enablesecurity-voippack/"&gt;products page&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;This video is a demo of sipautohack in action (looks and sounds better than the previous):&lt;br /&gt;&lt;br /&gt;&lt;object height="250" width="400"&gt;&lt;param name="allowfullscreen" value="true"&gt;&lt;param name="allowscriptaccess" value="always"&gt;&lt;param name="movie" value="http://vimeo.com/moogaloop.swf?clip_id=2524735&amp;amp;server=vimeo.com&amp;amp;show_title=1&amp;amp;show_byline=1&amp;amp;show_portrait=1&amp;amp;color=00ADEF&amp;amp;fullscreen=1"&gt;&lt;embed src="http://vimeo.com/moogaloop.swf?clip_id=2524735&amp;amp;server=vimeo.com&amp;amp;show_title=1&amp;amp;show_byline=1&amp;amp;show_portrait=1&amp;amp;color=00ADEF&amp;amp;fullscreen=1" type="application/x-shockwave-flash" allowfullscreen="true" allowscriptaccess="always" height="250" width="400"&gt;&lt;/embed&gt;&lt;/object&gt;&lt;br /&gt;&lt;a href="http://vimeo.com/2524735"&gt;Demonstrating sipautohack&lt;/a&gt; from &lt;a href="http://vimeo.com/user665968"&gt;Sandro Gauci&lt;/a&gt; on &lt;a href="http://vimeo.com/"&gt;Vimeo&lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6965515748199796807-8956057751277574585?l=sipvicious.org%2Fblog'/&gt;&lt;/div&gt;</content><link rel="replies" type="application/atom+xml" href="http://www.blogger.com/feeds/6965515748199796807/8956057751277574585/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="https://www.blogger.com/comment.g?blogID=6965515748199796807&amp;postID=8956057751277574585" title="1 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/6965515748199796807/posts/default/8956057751277574585" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/6965515748199796807/posts/default/8956057751277574585" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/Sipvicious/~3/LfJOZ2WkR4M/voippack-released.html" title="VOIPPACK released" /><author><name>sandro</name><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd="http://schemas.google.com/g/2005" name="OpenSocialUserId" value="01651987283704076907" /></author><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">1</thr:total><feedburner:origLink>http://sipvicious.org/blog/2009/01/voippack-released.html</feedburner:origLink></entry><entry><id>tag:blogger.com,1999:blog-6965515748199796807.post-6293809571499285953</id><published>2009-01-06T13:34:00.000-08:00</published><updated>2009-01-06T14:34:43.919-08:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="port 5060" /><category scheme="http://www.blogger.com/atom/ns#" term="sip scan" /><category scheme="http://www.blogger.com/atom/ns#" term="scans" /><category scheme="http://www.blogger.com/atom/ns#" term="voip scanning" /><category scheme="http://www.blogger.com/atom/ns#" term="sipvicious" /><category scheme="http://www.blogger.com/atom/ns#" term="voip security" /><title type="text">VOIP Scanning on the increase</title><content type="html">Various service providers and vendors have noticed an increase in VoIP scanning traffic. &lt;a href="http://www.fiercevoip.com/story/arbor-networks-voip-ipv6-emerging-security-threats/2008-11-11?utm_medium=rss&amp;amp;utm_source=rss&amp;amp;cmp-id=OTC-RSS-FV0"&gt;Arbor Networks mentioned VoIP attacks&lt;/a&gt; as one of their increasing concerns. &lt;a href="http://www.honeynor.no/2008/10/19/voip-attacks-are-escalating/"&gt;A Norwegian honeynet detected&lt;/a&gt; various INVITE requests trying to get VoIP systems on the internet to dial specific numbers. This scan is for open VOIP relays. VoIP attacks are nothing new really and some people in the telco-fraud business seem to have been around for quite a while. What is new is that they are getting detected more and more (and I'm getting more emails about this) which probably means that the scans are on the increase.&lt;br /&gt;&lt;br /&gt;Some traffic is borne from custom tools, probably designed from stage one to conduct fraud. Other traffic is generated by publicly available tools such as SIPVicious. My suggestion is to scan your network with SIPVicious, remove any SIP devices that should not be exposed to the internet. If the VoIP system needs to be exposed, at least make sure the the user extension passwords are not predictable (use svcrack to test this).&lt;br /&gt;&lt;br /&gt;Here's some blogs and articles that mentioned SIPVicious scans:&lt;br /&gt;&lt;ul&gt;&lt;li&gt;&lt;a href="http://belsec.skynetblogs.be/post/6598075/belgian-network-security-notes-from-arbor-net"&gt;&lt;span class="post_title"&gt;Belgian network security notes from Arbor networks&lt;/span&gt;&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="http://blogs.technet.com/mmpc/archive/2008/10/28/whats-travelling-on-the-wire-part-2.aspx"&gt;&lt;span class="post_title"&gt;Microsoft: &lt;/span&gt;What’s Travelling on the Wire (part 2)&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;If you came across any such scans or related stories &lt;a href="mailto:sandro@enablesecurity.com"&gt;drop me an email&lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6965515748199796807-6293809571499285953?l=sipvicious.org%2Fblog'/&gt;&lt;/div&gt;</content><link rel="replies" type="application/atom+xml" href="http://www.blogger.com/feeds/6965515748199796807/6293809571499285953/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="https://www.blogger.com/comment.g?blogID=6965515748199796807&amp;postID=6293809571499285953" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/6965515748199796807/posts/default/6293809571499285953" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/6965515748199796807/posts/default/6293809571499285953" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/Sipvicious/~3/QSkn5v93POo/voip-scanning-on-increase.html" title="VOIP Scanning on the increase" /><author><name>sandro</name><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd="http://schemas.google.com/g/2005" name="OpenSocialUserId" value="01651987283704076907" /></author><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://sipvicious.org/blog/2009/01/voip-scanning-on-increase.html</feedburner:origLink></entry><entry><id>tag:blogger.com,1999:blog-6965515748199796807.post-6298814104971298048</id><published>2008-12-13T01:34:00.000-08:00</published><updated>2008-12-13T01:44:13.906-08:00</updated><title type="text">Introducing EnableSecurity VoIPPack</title><content type="html">&lt;p&gt;&lt;a href="http://enablesecurity.com/products/enablesecurity-voippack/"&gt;EnableSecurity VoIPPack&lt;/a&gt; is a pack or addon for &lt;a href="http://www.immunitysec.com/products-canvas.shtml" target="_blank"&gt;Immunity CANVAS&lt;/a&gt; that complements this tool with commercial-grade VoIP scanning capabilities. Probably the most intruiguing module currently is sipautohack. &lt;/p&gt; &lt;p&gt;The following is a taster showing sipautohack scanning a target network, identifying PBX server, enumerating the extensions intelligently and finally cracking the password for each extension on the PBX. More demos &lt;a href="http://enablesecurity.com/products/enablesecurity-voippack"&gt;here&lt;/a&gt;.&lt;br /&gt;&lt;object width="400" height="311"&gt;&lt;param name="allowfullscreen" value="true" /&gt;&lt;param name="allowscriptaccess" value="always" /&gt;&lt;param name="movie" value="http://vimeo.com/moogaloop.swf?clip_id=2426478&amp;amp;server=vimeo.com&amp;amp;show_title=1&amp;amp;show_byline=1&amp;amp;show_portrait=0&amp;amp;color=&amp;amp;fullscreen=1" /&gt;&lt;embed src="http://vimeo.com/moogaloop.swf?clip_id=2426478&amp;amp;server=vimeo.com&amp;amp;show_title=1&amp;amp;show_byline=1&amp;amp;show_portrait=0&amp;amp;color=&amp;amp;fullscreen=1" type="application/x-shockwave-flash" allowfullscreen="true" allowscriptaccess="always" width="400" height="311"&gt;&lt;/embed&gt;&lt;/object&gt;&lt;br /&gt;.&lt;/p&gt;&lt;p&gt;&lt;br /&gt;&lt;/p&gt;&lt;p&gt;For more information about VoIPPack take a look at &lt;a href="http://enablesecurity.com/products/enablesecurity-voippack"&gt;the product page&lt;/a&gt;. EnableSecurity is currently running a private beta. &lt;a href="mailto:voippackbeta@enablesecurity.com"&gt;Apply as a beta tester&lt;/a&gt;.&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6965515748199796807-6298814104971298048?l=sipvicious.org%2Fblog'/&gt;&lt;/div&gt;</content><link rel="replies" type="application/atom+xml" href="http://www.blogger.com/feeds/6965515748199796807/6298814104971298048/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="https://www.blogger.com/comment.g?blogID=6965515748199796807&amp;postID=6298814104971298048" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/6965515748199796807/posts/default/6298814104971298048" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/6965515748199796807/posts/default/6298814104971298048" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/Sipvicious/~3/0hQ5EuGQGYQ/introducing-enablesecurity-voippack.html" title="Introducing EnableSecurity VoIPPack" /><author><name>sandro</name><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd="http://schemas.google.com/g/2005" name="OpenSocialUserId" value="01651987283704076907" /></author><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://sipvicious.org/blog/2008/12/introducing-enablesecurity-voippack.html</feedburner:origLink></entry><entry><id>tag:blogger.com,1999:blog-6965515748199796807.post-787127627444853952</id><published>2008-10-26T03:47:00.001-07:00</published><updated>2008-10-26T04:23:21.435-07:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="rsa europe 2008" /><title type="text">Off to RSA Europe 2008</title><content type="html">&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://sipvicious.org/blog/uploaded_images/rsa-europe-786852.jpg"&gt;&lt;img style="margin: 0pt 0pt 10px 10px; float: right; cursor: pointer; width: 231px; height: 79px;" src="http://sipvicious.org/blog/uploaded_images/rsa-europe-786847.jpg" alt="" border="0" /&gt;&lt;/a&gt;I'll be in the UK for the next few days to visit &lt;a href="http://www.rsaconference.com/2008/Europe/Home.aspx"&gt;RSA Europe&lt;/a&gt;. Will probably be twittering on &lt;a href="http://twitter.com/sandrogauci"&gt;twitter.com/sandrogauci&lt;/a&gt; and updating the &lt;a href="http://enablesecurity.com/blog"&gt;sister blog at EnableSecurity&lt;/a&gt; where I'll post the list of talks that I'm interested in visiting as soon as I get a chance. And of course - if any readers are around drop me a message ;-)&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6965515748199796807-787127627444853952?l=sipvicious.org%2Fblog'/&gt;&lt;/div&gt;</content><link rel="replies" type="application/atom+xml" href="http://www.blogger.com/feeds/6965515748199796807/787127627444853952/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="https://www.blogger.com/comment.g?blogID=6965515748199796807&amp;postID=787127627444853952" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/6965515748199796807/posts/default/787127627444853952" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/6965515748199796807/posts/default/787127627444853952" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/Sipvicious/~3/R6uj9f90908/off-to-rsa-europe-2008.html" title="Off to RSA Europe 2008" /><author><name>sandro</name><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd="http://schemas.google.com/g/2005" name="OpenSocialUserId" value="01651987283704076907" /></author><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://sipvicious.org/blog/2008/10/off-to-rsa-europe-2008.html</feedburner:origLink></entry><entry><id>tag:blogger.com,1999:blog-6965515748199796807.post-9200882108368488657</id><published>2008-10-24T00:06:00.000-07:00</published><updated>2008-10-24T00:11:44.451-07:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="voip attack" /><category scheme="http://www.blogger.com/atom/ns#" term="voip spam" /><title type="text">Analysis of a VoIP Attack</title><content type="html">Klaus Darilion published an interesting paper explaining what happened to German VoIP users and how to mitigate. I suggest that you read &lt;a href="http://www.ipcom.at/fileadmin/public/2008-10-22_Analysis_of_a_VoIP_Attack.pdf"&gt;this one&lt;/a&gt;. Looks like attacks are becoming more and more widespread / mainstream.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6965515748199796807-9200882108368488657?l=sipvicious.org%2Fblog'/&gt;&lt;/div&gt;</content><link rel="replies" type="application/atom+xml" href="http://www.blogger.com/feeds/6965515748199796807/9200882108368488657/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="https://www.blogger.com/comment.g?blogID=6965515748199796807&amp;postID=9200882108368488657" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/6965515748199796807/posts/default/9200882108368488657" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/6965515748199796807/posts/default/9200882108368488657" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/Sipvicious/~3/fagO9J7scwI/analysis-of-voip-attack.html" title="Analysis of a VoIP Attack" /><author><name>sandro</name><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd="http://schemas.google.com/g/2005" name="OpenSocialUserId" value="01651987283704076907" /></author><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://sipvicious.org/blog/2008/10/analysis-of-voip-attack.html</feedburner:origLink></entry><entry><id>tag:blogger.com,1999:blog-6965515748199796807.post-3372871941463677216</id><published>2008-09-09T22:24:00.000-07:00</published><updated>2008-09-09T22:44:00.336-07:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="svwar" /><category scheme="http://www.blogger.com/atom/ns#" term="pbx" /><category scheme="http://www.blogger.com/atom/ns#" term="extension" /><category scheme="http://www.blogger.com/atom/ns#" term="update" /><category scheme="http://www.blogger.com/atom/ns#" term="sipvicious tools" /><title type="text">Upcoming changes in SIPVicious</title><content type="html">The following are two updates for the next version of SIPVicious's PBX extension enumeration tool svwar:&lt;br /&gt;&lt;ol&gt;&lt;li&gt;svwar now tries to guess common numbers by default. It scans for the following ranges: 1000,2000... 9000, 1001, 2001..9001, 1111,2222... 9999, 11111,22222...99999, 100-999, 1234,2345 ..7890 and so on. This feature has a tendency to identify extensions on many PBX configurations. If you would like to disable it simply pass the --disabledefaults option to svwar.&lt;br /&gt;&lt;/li&gt;&lt;li&gt;svwar now sends ACK responses to SIP responses with code 200 because some PBXes keep sending packets until they receive an acknowledge.&lt;br /&gt;&lt;/li&gt;&lt;/ol&gt;That's it for now. Please &lt;a href="mailto:sandro@enablesecurity.com"&gt;let me know&lt;/a&gt; about your experience with the new features. To give the code a try simply run svn update from the sipvicious directory, or gte the latest by running the following:&lt;br /&gt;&lt;blockquote&gt;  &lt;tt&gt;svn checkout &lt;strong&gt;&lt;em&gt;http&lt;/em&gt;&lt;/strong&gt;://sipvicious.googlecode.com/svn/trunk/ sipvicious-read-only&lt;/tt&gt;&lt;/blockquote&gt;&lt;br /&gt;Have fun!&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6965515748199796807-3372871941463677216?l=sipvicious.org%2Fblog'/&gt;&lt;/div&gt;</content><link rel="replies" type="application/atom+xml" href="http://www.blogger.com/feeds/6965515748199796807/3372871941463677216/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="https://www.blogger.com/comment.g?blogID=6965515748199796807&amp;postID=3372871941463677216" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/6965515748199796807/posts/default/3372871941463677216" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/6965515748199796807/posts/default/3372871941463677216" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/Sipvicious/~3/CSrcPKGf7zk/upcoming-changes-in-sipvicious.html" title="Upcoming changes in SIPVicious" /><author><name>sandro</name><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd="http://schemas.google.com/g/2005" name="OpenSocialUserId" value="01651987283704076907" /></author><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://sipvicious.org/blog/2008/09/upcoming-changes-in-sipvicious.html</feedburner:origLink></entry><entry><id>tag:blogger.com,1999:blog-6965515748199796807.post-858677885135196734</id><published>2008-08-21T07:21:00.001-07:00</published><updated>2008-08-21T11:19:48.117-07:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="homeland security" /><category scheme="http://www.blogger.com/atom/ns#" term="voip hacker" /><category scheme="http://www.blogger.com/atom/ns#" term="hacked" /><title type="text">Homeland Security Dept's PBX hacked?</title><content type="html">Ouch! ZDNet have &lt;a href="http://blogs.zdnet.com/security/?p=1765"&gt;a short article&lt;/a&gt; about a misconfigured PBX making 400 calls to some of the hottest countries around: Afghanistan, India, Yemen and Saudi Arabia. Very ugly .. hope that the details emerge. If anyone has more details email me or post here.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Promotional message: &lt;a href="http://code.google.com/p/sipvicious/downloads/list"&gt;SIPVicious is free&lt;/a&gt; - test your SIP based PBX before someone else does ;-)&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;span&gt;Update:&lt;/span&gt;&lt;span&gt; Apparently it &lt;a href="http://ca.news.yahoo.com/s/capress/080820/world/fema_phones_hacked"&gt;consisted of voicemail hacking&lt;/a&gt; - you know that thing from the 90s.&lt;span style="font-weight: bold;"&gt; &lt;/span&gt;So no VoIP or SIP involved, just plain old school default pin cracking.&lt;/span&gt;&lt;span style="font-weight: bold;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6965515748199796807-858677885135196734?l=sipvicious.org%2Fblog'/&gt;&lt;/div&gt;</content><link rel="replies" type="application/atom+xml" href="http://www.blogger.com/feeds/6965515748199796807/858677885135196734/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="https://www.blogger.com/comment.g?blogID=6965515748199796807&amp;postID=858677885135196734" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/6965515748199796807/posts/default/858677885135196734" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/6965515748199796807/posts/default/858677885135196734" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/Sipvicious/~3/oA7frwx011M/homeland-security-depts-pbx-hacked.html" title="Homeland Security Dept's PBX hacked?" /><author><name>sandro</name><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd="http://schemas.google.com/g/2005" name="OpenSocialUserId" value="01651987283704076907" /></author><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://sipvicious.org/blog/2008/08/homeland-security-depts-pbx-hacked.html</feedburner:origLink></entry><entry><id>tag:blogger.com,1999:blog-6965515748199796807.post-1939092227617685064</id><published>2008-08-11T04:07:00.000-07:00</published><updated>2008-08-11T04:13:20.080-07:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="cookies" /><category scheme="http://www.blogger.com/atom/ns#" term="enablesecurity" /><title type="text">Surf Jack - HTTPS will not save you</title><content type="html">Alert: this is not a VoIP security post. Just a repost from EnableSecurity.&lt;br /&gt;&lt;br /&gt;I just released &lt;a href="http://resources.enablesecurity.com/resources/Surf%20Jacking.pdf"&gt;a new paper &lt;/a&gt;and tool on the subject of web application security.&lt;br /&gt;&lt;br /&gt;Check out the &lt;a href="http://enablesecurity.com/2008/08/11/surf-jack-https-will-not-save-you/"&gt;blog post&lt;/a&gt; (which includes the &lt;a href="http://www.vimeo.com/1507697"&gt;bonus video&lt;/a&gt; everyone loves), and the &lt;a href="http://surfjack.googlecode.com"&gt;proof of concept tool&lt;/a&gt; itself.&lt;br /&gt;&lt;br /&gt;And if you did not do it already, please subscribe to my other site, &lt;a href="http://enablesecurity.com/rss"&gt;EnableSecurity's RSS feed&lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6965515748199796807-1939092227617685064?l=sipvicious.org%2Fblog'/&gt;&lt;/div&gt;</content><link rel="replies" type="application/atom+xml" href="http://www.blogger.com/feeds/6965515748199796807/1939092227617685064/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="https://www.blogger.com/comment.g?blogID=6965515748199796807&amp;postID=1939092227617685064" title="1 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/6965515748199796807/posts/default/1939092227617685064" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/6965515748199796807/posts/default/1939092227617685064" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/Sipvicious/~3/zyc4t1yYq-0/surf-jack-https-will-not-save-you.html" title="Surf Jack - HTTPS will not save you" /><author><name>sandro</name><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd="http://schemas.google.com/g/2005" name="OpenSocialUserId" value="01651987283704076907" /></author><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">1</thr:total><feedburner:origLink>http://sipvicious.org/blog/2008/08/surf-jack-https-will-not-save-you.html</feedburner:origLink></entry><entry><id>tag:blogger.com,1999:blog-6965515748199796807.post-5689131896539341992</id><published>2008-08-10T09:32:00.000-07:00</published><updated>2008-08-10T09:41:16.037-07:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="sipvicious tools" /><category scheme="http://www.blogger.com/atom/ns#" term="sipvicious" /><category scheme="http://www.blogger.com/atom/ns#" term="voip security" /><title type="text">New SIPVicious release  0.2.4</title><content type="html">Just updated the release of SIPVicious to 0.2.4 to include a couple of bug fixes in svwar and a new feature. The new "--template" parameter allows you to make use of format strings to create more flexible ranges. Some examples include scanning prefixes or suffixes.. which apparently can be quite useful with certain environments ;-)&lt;br /&gt;&lt;br /&gt;Many thanks to &lt;a href="http://web1.egvrn.net/tokata/"&gt;Teodor Georgiev&lt;/a&gt; for his patience and help in making SIPVicious more robust and reliable!&lt;br /&gt;&lt;br /&gt;Here's a link to the full &lt;a href="http://code.google.com/p/sipvicious/wiki/ChangeLog"&gt;Changelog&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;Grab the &lt;a href="http://sipvicious.googlecode.com/files/sipvicious-0.2.4.tar.gz"&gt;tarball&lt;/a&gt; or the &lt;a href="http://sipvicious.googlecode.com/files/sipvicious-0.2.4.zip"&gt;zip file&lt;/a&gt;.&lt;br /&gt;To upgrade to the svn version simply run "svn update" as usual - enjoy&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6965515748199796807-5689131896539341992?l=sipvicious.org%2Fblog'/&gt;&lt;/div&gt;</content><link rel="replies" type="application/atom+xml" href="http://www.blogger.com/feeds/6965515748199796807/5689131896539341992/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="https://www.blogger.com/comment.g?blogID=6965515748199796807&amp;postID=5689131896539341992" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/6965515748199796807/posts/default/5689131896539341992" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/6965515748199796807/posts/default/5689131896539341992" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/Sipvicious/~3/KwFwMD_doDc/new-sipvicious-release-024.html" title="New SIPVicious release  0.2.4" /><author><name>sandro</name><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd="http://schemas.google.com/g/2005" name="OpenSocialUserId" value="01651987283704076907" /></author><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://sipvicious.org/blog/2008/08/new-sipvicious-release-024.html</feedburner:origLink></entry><entry><id>tag:blogger.com,1999:blog-6965515748199796807.post-9128440051819751619</id><published>2008-06-20T05:40:00.000-07:00</published><updated>2008-06-20T07:06:29.883-07:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="backtrack 3" /><category scheme="http://www.blogger.com/atom/ns#" term="backtrack" /><title type="text">Backtrack 3 out - with VoIP security tools</title><content type="html">The final &lt;a href="http://www.remote-exploit.org/backtrack.html"&gt;Backtrack&lt;/a&gt; 3 is out and it features some VoIP tools in the /pentest directory:&lt;br /&gt;&lt;ul&gt;&lt;li&gt;&lt;a href="http://sipvicious.googlecode.com/"&gt;SIPVicious&lt;/a&gt; (guess you know by now what this is about :)&lt;/li&gt;&lt;li&gt;&lt;a href="http://sourceforge.net/projects/voiper"&gt;Voiper&lt;/a&gt; - a SIP fuzzing toolkit which aims at identifying flaws in VoIP products that do SIP and SDP.&lt;/li&gt;&lt;li&gt;&lt;a href="http://metalinkltd.com/downloads.php"&gt;Sipbomber&lt;/a&gt; - a SIP testing tool which has test cases that are run against SIP enabled software / devices&lt;/li&gt;&lt;li&gt;&lt;a href="http://hackingvoipexposed.wordpress.com/2007/01/23/new-tool-released-sip-rogue/"&gt;SIP Rogue&lt;/a&gt; - allows application level man in the middle (MITM) attacks on SIP devices.&lt;/li&gt;&lt;/ul&gt;In the $PATH one can find:&lt;br /&gt;&lt;ul&gt;&lt;li&gt;&lt;a href="http://voiphopper.sourceforge.net/"&gt;VoIP Hopper&lt;/a&gt; - allows one to hop between VLANS.&lt;/li&gt;&lt;li&gt;&lt;a href="http://www.enderunix.org/voipong/"&gt;VOIPONG&lt;/a&gt; - a Voice over IP sniffer - will record any phone calls that it sees.&lt;br /&gt;&lt;/li&gt;&lt;li&gt;sipdump / sipcrack - an offline password cracker for the digest authentication used by SIP&lt;/li&gt;&lt;/ul&gt;Tools that were previously found in Backtrack 2 are described on the &lt;a href="http://backtrack.offensive-security.com/index.php?title=Tools#VOIP_.26_Telephony_Analysis"&gt;tools page&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;Grab Backtrack from the &lt;a href="http://www.remote-exploit.org/backtrack.html"&gt;official&lt;/a&gt; site.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6965515748199796807-9128440051819751619?l=sipvicious.org%2Fblog'/&gt;&lt;/div&gt;</content><link rel="replies" type="application/atom+xml" href="http://www.blogger.com/feeds/6965515748199796807/9128440051819751619/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="https://www.blogger.com/comment.g?blogID=6965515748199796807&amp;postID=9128440051819751619" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/6965515748199796807/posts/default/9128440051819751619" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/6965515748199796807/posts/default/9128440051819751619" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/Sipvicious/~3/zwxsgiZTZio/backtrack-3-out-with-voip-security.html" title="Backtrack 3 out - with VoIP security tools" /><author><name>sandro</name><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd="http://schemas.google.com/g/2005" name="OpenSocialUserId" value="01651987283704076907" /></author><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://sipvicious.org/blog/2008/06/backtrack-3-out-with-voip-security.html</feedburner:origLink></entry><entry><id>tag:blogger.com,1999:blog-6965515748199796807.post-1528995122113702086</id><published>2008-06-17T01:10:00.000-07:00</published><updated>2008-06-17T01:16:10.932-07:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="wireless security" /><category scheme="http://www.blogger.com/atom/ns#" term="research and design" /><category scheme="http://www.blogger.com/atom/ns#" term="independent research" /><category scheme="http://www.blogger.com/atom/ns#" term="reverse engineering" /><category scheme="http://www.blogger.com/atom/ns#" term="enablesecurity" /><category scheme="http://www.blogger.com/atom/ns#" term="voip security" /><category scheme="http://www.blogger.com/atom/ns#" term="web application security" /><category scheme="http://www.blogger.com/atom/ns#" term="security consultancy X security vulnerability" /><title type="text">Ladies and Gentlemen please welcome..</title><content type="html">&lt;a href="http://enablesecurity.com/"&gt;EnableSecurity&lt;/a&gt;! I will be publishing my security research and rants as well as providing Security Consultancy, Research and Design. A brief "who am I" can be seen at the &lt;a href="http://www.linkedin.com/in/sandrogauci" target="_blank"&gt;Linkedin Profile&lt;/a&gt; page, while Google has &lt;a href="http://www.google.com/?q=" target="_blank"&gt;further details&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;So what sort of things am I doing? &lt;ul&gt;&lt;li&gt;Wireless security auditing&lt;/li&gt; &lt;li&gt;Web Application Security&lt;/li&gt; &lt;li&gt;VoIP security research&lt;/li&gt; &lt;li&gt;Reverse Engineering&lt;/li&gt;&lt;br /&gt;&lt;/ul&gt;I'll continue developing &lt;a href="http://sipvicious.googlecode.com/" target="_blank"&gt;SIPVicious&lt;/a&gt; and &lt;a href="http://enablesecurity.com/resources/"&gt;publish additional tools&lt;/a&gt; to help security professionals get the job done.&lt;br /&gt;&lt;br /&gt;And one more thing - I suggest that you subscribe to the &lt;a mce_href="http://enablesecurity.com/feed/" href="http://enablesecurity.com/feed/"&gt;RSS&lt;/a&gt; as I shall be releasing some research later on this week.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6965515748199796807-1528995122113702086?l=sipvicious.org%2Fblog'/&gt;&lt;/div&gt;</content><link rel="replies" type="application/atom+xml" href="http://www.blogger.com/feeds/6965515748199796807/1528995122113702086/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="https://www.blogger.com/comment.g?blogID=6965515748199796807&amp;postID=1528995122113702086" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/6965515748199796807/posts/default/1528995122113702086" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/6965515748199796807/posts/default/1528995122113702086" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/Sipvicious/~3/6XLvG9mvaQM/ladies-and-gentlemen-please-welcome.html" title="Ladies and Gentlemen please welcome.." /><author><name>sandro</name><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd="http://schemas.google.com/g/2005" name="OpenSocialUserId" value="01651987283704076907" /></author><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://sipvicious.org/blog/2008/06/ladies-and-gentlemen-please-welcome.html</feedburner:origLink></entry><entry><id>tag:blogger.com,1999:blog-6965515748199796807.post-6449063928438822475</id><published>2008-06-11T08:06:00.000-07:00</published><updated>2008-06-11T08:10:53.448-07:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="sipvicious tools" /><category scheme="http://www.blogger.com/atom/ns#" term="sipvicious" /><category scheme="http://www.blogger.com/atom/ns#" term="security tools" /><title type="text">SIPVicious tools roadmap</title><content type="html">I'm looking at &lt;span style="font-weight: bold;"&gt;improving&lt;/span&gt; SIPVicious and would appreciate your input for new features or any possible bug fixes. Send me &lt;a href="mailto:sandrogauc@gmail.com"&gt;an email&lt;/a&gt; with ideas, or simply leave a comment.&lt;br /&gt;&lt;br /&gt;Check my current "to do" list &lt;a href="http://code.google.com/p/sipvicious/wiki/TodoList"&gt;here&lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6965515748199796807-6449063928438822475?l=sipvicious.org%2Fblog'/&gt;&lt;/div&gt;</content><link rel="replies" type="application/atom+xml" href="http://www.blogger.com/feeds/6965515748199796807/6449063928438822475/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="https://www.blogger.com/comment.g?blogID=6965515748199796807&amp;postID=6449063928438822475" title="2 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/6965515748199796807/posts/default/6449063928438822475" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/6965515748199796807/posts/default/6449063928438822475" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/Sipvicious/~3/z3JE6OLbDQs/sipvicious-tools-roadmap.html" title="SIPVicious tools roadmap" /><author><name>sandro</name><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd="http://schemas.google.com/g/2005" name="OpenSocialUserId" value="01651987283704076907" /></author><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">2</thr:total><feedburner:origLink>http://sipvicious.org/blog/2008/06/sipvicious-tools-roadmap.html</feedburner:origLink></entry><entry><id>tag:blogger.com,1999:blog-6965515748199796807.post-5556321526709745575</id><published>2008-06-03T05:37:00.000-07:00</published><updated>2008-06-03T05:55:31.189-07:00</updated><title type="text">SIPVicious version 0.2.3 with fingerprinting and dns goodies</title><content type="html">Just posted a new version of SIPVicious v0.2.3. This includes some new features as well as bug fixes. However be warned - bugs have been invariably introduced in the course of adding these new features, so please help me test it out ;-)&lt;br /&gt;&lt;br /&gt;&lt;a href="http://sipvicious.googlecode.com/files/sipvicious-0.2.3.tar.gz"&gt;Here's the link&lt;/a&gt; you've been looking for.&lt;br /&gt;&lt;br /&gt;From the Changelog:&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;v0.2.3&lt;/span&gt;&lt;br /&gt;&lt;ul&gt;&lt;li&gt;Feature:  Fingerprinting support for svmap. Included fphelper.py and 3 databases used for fingerprinting. &lt;/li&gt;&lt;li&gt;Feature:  Added svlearnfp.py which allows one to add new signatures to db and send them to the author.&lt;/li&gt;&lt;li&gt;Feature:  Added DNS SRV check to svmap. Use ./svmap.py --srv domainname.com to give it a try&lt;br /&gt;&lt;/li&gt;&lt;/ul&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;v0.2.svn&lt;/span&gt;&lt;br /&gt;&lt;ul&gt;&lt;li&gt;Feature:  added the ability for svreport to count results when doing a list&lt;/li&gt;&lt;li&gt;Bug fix:  fixed a bug related to resuming a scan which does not have an extension&lt;br /&gt;&lt;/li&gt;&lt;/ul&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6965515748199796807-5556321526709745575?l=sipvicious.org%2Fblog'/&gt;&lt;/div&gt;</content><link rel="replies" type="application/atom+xml" href="http://www.blogger.com/feeds/6965515748199796807/5556321526709745575/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="https://www.blogger.com/comment.g?blogID=6965515748199796807&amp;postID=5556321526709745575" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/6965515748199796807/posts/default/5556321526709745575" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/6965515748199796807/posts/default/5556321526709745575" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/Sipvicious/~3/dfoq767z9vY/sipvicious-version-023-with.html" title="SIPVicious version 0.2.3 with fingerprinting and dns goodies" /><author><name>sandro</name><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd="http://schemas.google.com/g/2005" name="OpenSocialUserId" value="01651987283704076907" /></author><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://sipvicious.org/blog/2008/06/sipvicious-version-023-with.html</feedburner:origLink></entry><entry><id>tag:blogger.com,1999:blog-6965515748199796807.post-7806630862129539275</id><published>2008-05-15T02:37:00.000-07:00</published><updated>2008-05-15T06:36:14.340-07:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="underground" /><category scheme="http://www.blogger.com/atom/ns#" term="hacking" /><title type="text">VoIP and identity fraud on the BBC</title><content type="html">The BBC News is running &lt;a href="http://news.bbc.co.uk/2/hi/technology/7398676.stm"&gt;an article&lt;/a&gt; highlighting one of the most basic vulnerabilities in the majority of current VoIP providers - the lack of encryption. Indeed, this is a problem since SIP passes an md5 hash of the password as clear text and therefore anyone watching the traffic can perform an offline attack and quickly recover the credentials. The attack has been described in countless blogs, articles and papers by now and some tools are very efficient in demonstrating this issue.&lt;br /&gt;&lt;br /&gt;What caught my eye is the mention of VoIP credentials being sold on  the underground 17$ a piece. So I emailed Mr Gladwin who was quoted in the article. This is a summary of our email conversations:&lt;br /&gt;&lt;ul&gt;&lt;li&gt;There is no indication that stolen VoIP details were harvested because of the lack of encryption&lt;br /&gt;&lt;/li&gt;&lt;li&gt;If anyone comes across &lt;span style="font-style: italic;"&gt;underground&lt;/span&gt; forums / sites / resources which have prices please let me know. Unfortunately Dave Gladwin was not able to provide me with a reference (until now)&lt;br /&gt;&lt;/li&gt;&lt;li&gt;There was no indication as to the size or volume of the VoIP credentials trading&lt;/li&gt;&lt;/ul&gt;Skype took the chance to remind us that this is not an issue for then (since they make use of a proprietary protocol which has encryption built-in).&lt;br /&gt;&lt;br /&gt;I'm interested in learning which method is being used to steal credentials. Take your pick:&lt;br /&gt;&lt;ul&gt;&lt;li&gt;Sniffing at WiFi internet cafe's / hacked service providers etc and offline password attacks &lt;/li&gt;&lt;li&gt;Active password attacks (such as those supported by &lt;a href="http://sipvicious.googlecode.com/"&gt;SIPVicious svcrack&lt;/a&gt;). Such attacks have been previously &lt;a href="http://sipvicious.org/blog/2007/08/interview-with-voip-hacker.html"&gt;used by Robert Moore&lt;/a&gt; and obviously others which were not caught ;-)&lt;/li&gt;&lt;li&gt;Hacked VoIP service providers or end users&lt;/li&gt;&lt;li&gt;Phishing attacks&lt;/li&gt;&lt;/ul&gt;My feeling is that active password attacks will give you the best results when the target is simply "the Internet". But in the end, what matters is what's being currently abused and how we can prevent and mitigate.&lt;br /&gt;&lt;br /&gt;Update: Dave Gladwin updated the &lt;a href="http://blog.newport-networks.com/newport_networks_blog/2008/05/bbc-web-site-it.html"&gt;Newport Networks Blog&lt;/a&gt; to provide more details on the subject.&lt;br /&gt;&lt;br /&gt;&lt;div style="text-align: center;"&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://sipvicious.org/blog/uploaded_images/caveman-727967.gif"&gt;&lt;img style="cursor: pointer;" src="http://sipvicious.org/blog/uploaded_images/caveman-727887.gif" alt="" border="0" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6965515748199796807-7806630862129539275?l=sipvicious.org%2Fblog'/&gt;&lt;/div&gt;</content><link rel="replies" type="application/atom+xml" href="http://www.blogger.com/feeds/6965515748199796807/7806630862129539275/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="https://www.blogger.com/comment.g?blogID=6965515748199796807&amp;postID=7806630862129539275" title="1 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/6965515748199796807/posts/default/7806630862129539275" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/6965515748199796807/posts/default/7806630862129539275" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/Sipvicious/~3/i0qD4WvTmWw/voip-and-identity-fraud-on-bbc.html" title="VoIP and identity fraud on the BBC" /><author><name>sandro</name><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd="http://schemas.google.com/g/2005" name="OpenSocialUserId" value="01651987283704076907" /></author><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">1</thr:total><feedburner:origLink>http://sipvicious.org/blog/2008/05/voip-and-identity-fraud-on-bbc.html</feedburner:origLink></entry><entry><id>tag:blogger.com,1999:blog-6965515748199796807.post-3162255266204568938</id><published>2008-05-02T10:13:00.000-07:00</published><updated>2008-05-02T10:21:08.054-07:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="defcon 15" /><title type="text">Defcon 15 videos - VoIP related talks</title><content type="html">Just in case anyone missed Defcon 15 (like I did), here's two talks of interest with relation to VoIP:&lt;br /&gt;&lt;ul&gt;&lt;li&gt;&lt;a href="http://video.google.com/videoplay?docid=-7314424420458150454&amp;amp;hl=en"&gt;T210: INTERSTATE: A Stateful Protocol Fuzzer for SIP&lt;/a&gt; by Ian G. Harris&lt;/li&gt;&lt;li&gt;&lt;a href="http://video.google.com/videoplay?docid=-4247694999570610113&amp;amp;hl=en"&gt;T442: Real-time Steganography with RTP&lt;/a&gt; by |)ruid&lt;/li&gt;&lt;/ul&gt;For the rest of the videos check out &lt;a href="http://www.catonmat.net/blog/videos-from-defcon-15-hacker-conference/"&gt;this list&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;Thanks for &lt;a href="http://ironguard.net/"&gt;Anthony of Iron::Guard&lt;/a&gt; for the pointer.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;div style="text-align: center;"&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://sipvicious.org/blog/uploaded_images/Snapshot-2008-05-02-19-15-41-775779.jpg"&gt;&lt;img style="cursor: pointer;" src="http://sipvicious.org/blog/uploaded_images/Snapshot-2008-05-02-19-15-41-775774.jpg" alt="" border="0" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6965515748199796807-3162255266204568938?l=sipvicious.org%2Fblog'/&gt;&lt;/div&gt;</content><link rel="replies" type="application/atom+xml" href="http://www.blogger.com/feeds/6965515748199796807/3162255266204568938/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="https://www.blogger.com/comment.g?blogID=6965515748199796807&amp;postID=3162255266204568938" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/6965515748199796807/posts/default/3162255266204568938" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/6965515748199796807/posts/default/3162255266204568938" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/Sipvicious/~3/zpDXIeZ9K1A/defcon-15-videos-voip-related-talks.html" title="Defcon 15 videos - VoIP related talks" /><author><name>sandro</name><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd="http://schemas.google.com/g/2005" name="OpenSocialUserId" value="01651987283704076907" /></author><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://sipvicious.org/blog/2008/05/defcon-15-videos-voip-related-talks.html</feedburner:origLink></entry><entry><id>tag:blogger.com,1999:blog-6965515748199796807.post-1830706474395902011</id><published>2008-05-02T01:05:00.000-07:00</published><updated>2008-05-02T01:10:03.323-07:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="hids" /><category scheme="http://www.blogger.com/atom/ns#" term="ossec" /><category scheme="http://www.blogger.com/atom/ns#" term="asterisk" /><title type="text">OSSEC v1.5 now has builtin Asterisk rules</title><content type="html">A &lt;a href="http://www.ossec.net/dcid/?p=133"&gt;new OSSEC version&lt;/a&gt; has been released. Along with a number of updates, OSSEC now includes the Asterisk rules that were first published in &lt;a href="http://enablesecurity.com/resources/22_29_storming_sip.pdf"&gt;my hakin9 article&lt;/a&gt; and then &lt;a href="http://sipvicious.org/blog/2008/03/using-ossec-to-detect-attacks-on.html"&gt;here&lt;/a&gt;. The rest of the updates are described in the &lt;a href="http://www.ossec.net/announcements/v1.5-2008-05-02.txt"&gt;Changelog&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.ossec.net/main/downloads"&gt;Grab it now.&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6965515748199796807-1830706474395902011?l=sipvicious.org%2Fblog'/&gt;&lt;/div&gt;</content><link rel="replies" type="application/atom+xml" href="http://www.blogger.com/feeds/6965515748199796807/1830706474395902011/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="https://www.blogger.com/comment.g?blogID=6965515748199796807&amp;postID=1830706474395902011" title="1 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/6965515748199796807/posts/default/1830706474395902011" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/6965515748199796807/posts/default/1830706474395902011" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/Sipvicious/~3/wz2YvNivinY/ossec-v15-now-has-builtin-asterisk.html" title="OSSEC v1.5 now has builtin Asterisk rules" /><author><name>sandro</name><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd="http://schemas.google.com/g/2005" name="OpenSocialUserId" value="01651987283704076907" /></author><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">1</thr:total><feedburner:origLink>http://sipvicious.org/blog/2008/05/ossec-v15-now-has-builtin-asterisk.html</feedburner:origLink></entry><entry><id>tag:blogger.com,1999:blog-6965515748199796807.post-5606267929186107580</id><published>2008-04-22T07:03:00.000-07:00</published><updated>2008-04-22T07:17:35.687-07:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="infosec europe" /><title type="text">Infosec Europe 2008</title><content type="html">If anyone's going to be at &lt;a href="http://infosec.co.uk"&gt;Infosec Europe&lt;/a&gt; tomorrow or the next day and would like to have a chat (and maybe offer a beer), &lt;a href="mailto:sandro-at-enablesecurity-dot-com"&gt;contact me.&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Time to update &lt;a href="http://www.twitter.com/sandrogauci"&gt;twitter&lt;/a&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://sipvicious.org/blog/uploaded_images/infosec08_header_logo-719891.gif"&gt;&lt;img style="cursor: pointer;" src="http://sipvicious.org/blog/uploaded_images/infosec08_header_logo-719887.gif" alt="" border="0" /&gt;&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6965515748199796807-5606267929186107580?l=sipvicious.org%2Fblog'/&gt;&lt;/div&gt;</content><link rel="replies" type="application/atom+xml" href="http://www.blogger.com/feeds/6965515748199796807/5606267929186107580/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="https://www.blogger.com/comment.g?blogID=6965515748199796807&amp;postID=5606267929186107580" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/6965515748199796807/posts/default/5606267929186107580" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/6965515748199796807/posts/default/5606267929186107580" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/Sipvicious/~3/d1Tb1hAsnVE/infosec-europe-2008.html" title="Infosec Europe 2008" /><author><name>sandro</name><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd="http://schemas.google.com/g/2005" name="OpenSocialUserId" value="01651987283704076907" /></author><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://sipvicious.org/blog/2008/04/infosec-europe-2008.html</feedburner:origLink></entry></feed>
