Graves On SOHO VoIP

End User Perspective On IP Telephony In The Home Office
  • rss
  • Home
  • About
    • Contact
    • Disclosure
  • Guides & How-To’s
  • Product Reviews
  • Raves
  • Personal Blog

Asterisk Implicated In FBI Security Warning

mjgraves | December 7, 2008

asterisk icon 94x96 Asterisk Implicated In FBI Security WarningThe FBI’s Internet Crime Complaint Center has issues a warning with respect to the use of Asterisk to create vishing attacks. According to a post at Slashdot someone from PCWorld checked with Digium who was puzzled about the matter. Digium’s own John Todd responds with a blog post this morning.

The FBI alert is extremely vague, making only a non-specific reference as follows:

The FBI has received information concerning a new technique used to conduct vishingi attacks. The recent attacks were conducted by hackers exploiting a security vulnerability in Asterisk software. Asterisk is free and widely used software developed to integrate PBXii systems with Voice over Internet Protocol (VoIP), digital Internet voice calling services; however, early versions of the Asterisk software are known to have a vulnerability. The vulnerability can be exploited by cyber criminals to use the system as an auto dialer, generating thousands of vishing telephone calls to consumers within one hour.

It must be really challenging for the FBI to get their heads around how to deal with something like Asterisk. It’s a telecom & networking toolkit to build whatever you like. It’s a major enabling mechanism for anyone in the telecom space, and for whatever purpose.

Security is one of the next big issues in VoIP. It remains largely unaddressed in the residential / SOHO space. IMHO the question is not if we’ll address it, but more simply when. For those with an interest in the matter may I suggest reading at www.voipsa.org especially their excellent blog and mailing list. Also, the Bluebox Security Podcast by Dan York and Jonathan Zar.

Update: Here a link to the PCWorld article on the matter.

Update2: Digium’s Bill Miller offers a clarification that Digium was only contacted after the FBI warning was issued and the PC World article was already published.

So it appears that we have before us a classic example of brilliant government in action supported by a comparably skilled press. That Digium was the singular reference source that should have been contacted should have been patently obvious to everyone involved.

Categories
Asterisk
Tags
Asterisk, digium, FBI, John Todd, security, VoIP
Comments rss
Comments rss
Trackback
Trackback

« Adding A Cellular Trunk To A Home Office VOIP System: Part 2 Jazinga Review Online At Small Net Builder »

2 Responses to “Asterisk Implicated In FBI Security Warning”

  1. 1
    FBI Security Warnings and VoIP | Voip Tech Chat says:
    December 8, 2008 at 11:48 am

    [...] Graves on SOHO VoIP — Always smart to read this blog [...]

    Reply
  2. 2
    FBI and Asterisk Security? Relax, Breathe, and Read - Team Forrest says:
    December 8, 2008 at 2:03 pm

    [...] Michael Graves discusses the Recent FBI Warning [...]

    Reply

Leave a Reply

Click here to cancel reply.

Search Me?

My Tweets

  • No public Twitter messages.

Recent Posts

  • A Tale Of Wonky Wifi Part 1: Netgear & Cisco
  • Thinking Outside The Box: SIP Hard Phone + External Speakerphone
  • Review: Yamaha PSG-01s Personal USB Speakerphone
  • Pondering The Plantronics Savi Go…Further, Please.
  • Polycom Display Sizes Compared

Recent Comments

  • Jan1973 on Gigaset Firmware Update Released
  • Jan1973 on Gigaset Firmware Update Released
  • Kim Callis on A Tale Of Wonky Wifi Part 1: Netgear & Cisco
  • Ottone on A Tale Of Wonky Wifi Part 1: Netgear & Cisco
  • David Cook on A Tale Of Wonky Wifi Part 1: Netgear & Cisco

Series: Making Use of HDVoice Right Now!

  • Series Introduction
  • HDVoice Using Skype
  • HDVoice Using Gizmo5
  • HDVoice Using SIPGate
  • HDVoice Using OnSIP

Make a difference.


Change a life.

VoIP Users Conference

RSS From My Personal Blog

  • Just A Thought
  • Knowing Your Limits
  • Funny Stuff: Learning To Speak Teabag
  • TV Is An Evil Plot to Control Our Minds
  • Fred Posner On TSA

Say What?

This message transmitted on 100% recycled electrons.

Tags

Asterisk Astlinux astricon Audio blog Broadband cell cellular codec conference cordless DECT digium DSL FWD G.722 gateway Gigaset gsm HD hdvoice headset hp ip M3 music onsip phone polycom QoS router siemens sip skype SNOM soft phone Squeezebox technology USB Video VoIP VUC wideband wifi zipdx

Archives

  • February 2010
  • January 2010
  • December 2009
  • November 2009
  • October 2009
  • September 2009
  • August 2009
  • July 2009
  • June 2009
  • May 2009
  • April 2009
  • March 2009
  • February 2009
  • January 2009
  • December 2008
  • November 2008
  • October 2008
  • September 2008
  • August 2008
  • July 2008
  • June 2008
  • May 2008
  • April 2008
  • March 2008
  • February 2008
  • January 2008
  • December 2007
  • November 2007
  • October 2007

Meta

  • Register
  • Log in
  • Entries RSS
  • Comments RSS
  • WordPress.org
rss Comments rss valid xhtml 1.1