• Home
  • About
  • Tech
  • Projects
  • Contact
TjWallas.DevOps().Labs>

#DEFCON 19: Attacking the Network through VoIP

31/10/2011

 
Speaker: Jason Ostrom Sipera VIPER Lab

This presentation is about the security of VoIP deployed in hotel guest rooms. What it is, why it benefits administrators and users, and how easily it can be broken. The hospitality industry is widely deploying VoIP. Since 2008, we've seen an increase of these rollouts along with Admin awareness of applying the required security controls in order to mitigate this potential backdoor into a company's mission critical data and systems — their Crown Jewels. The method is simple: through VoIP, a malicious hotel guest may gain access into corporate data resources such as a company's sensitive financial or HR systems. This talk will present updated research with a new case study: A Hotel VoIP infrastructure that had security applied. We will explore the missing pieces. How has this risk changed for permitting a hotel guest unauthorized network access, and who should be concerned? An old VLAN attack will be re-visited, with a new twist: how the VLAN attack applies to recent production VoIP infrastructure deployments, and how it can be combined with a new physical method. A new version of the free VoIP Hopper security tool will be demonstrated live, showcasing this new feature. In addition, we will investigate an alternative to CDP for device discovery and inventory control: LLDP-MED (Link Layer Device Discovery - Media Endpoint Discovery). A case study penetration test of a client infrastructure that used LLDP-MED follows , with a comparison to CDP. VoIP Hopper will demonstrate the first security assessment tool features for this advancing protocol. Mitigation recommendations will follow.

Via: Christian008

Related articles
  • Audio and video VoIP sniffed (powersthatbeat.wordpress.com)
  • Virtual Pbx Introduces Virtual PBX Complete with VoIP Anywhere for iPhones, Android Phones and Computers (virtualpbx.com)

Comments are closed.
Powered by Create your own unique website with customizable templates.