Graves On SOHO VoIP

End User Perspective On IP Telephony In The Home Office
  • rss
  • Home
  • About
  • Guides & Reviews
  • Raves
  • Personal Blog

Asterisk Implicated In FBI Security Warning

mjgraves | December 7, 2008

asterisk icon 94x96 Asterisk Implicated In FBI Security WarningThe FBI’s Internet Crime Complaint Center has issues a warning with respect to the use of Asterisk to create vishing attacks. According to a post at Slashdot someone from PCWorld checked with Digium who was puzzled about the matter. Digium’s own John Todd responds with a blog post this morning.

The FBI alert is extremely vague, making only a non-specific reference as follows:

The FBI has received information concerning a new technique used to conduct vishingi attacks. The recent attacks were conducted by hackers exploiting a security vulnerability in Asterisk software. Asterisk is free and widely used software developed to integrate PBXii systems with Voice over Internet Protocol (VoIP), digital Internet voice calling services; however, early versions of the Asterisk software are known to have a vulnerability. The vulnerability can be exploited by cyber criminals to use the system as an auto dialer, generating thousands of vishing telephone calls to consumers within one hour.

It must be really challenging for the FBI to get their heads around how to deal with something like Asterisk. It’s a telecom & networking toolkit to build whatever you like. It’s a major enabling mechanism for anyone in the telecom space, and for whatever purpose.

Security is one of the next big issues in VoIP. It remains largely unaddressed in the residential / SOHO space. IMHO the question is not if we’ll address it, but more simply when. For those with an interest in the matter may I suggest reading at www.voipsa.org especially their excellent blog and mailing list. Also, the Bluebox Security Podcast by Dan York and Jonathan Zar.

Update: Here a link to the PCWorld article on the matter.

Update2: Digium’s Bill Miller offers a clarification that Digium was only contacted after the FBI warning was issued and the PC World article was already published.

So it appears that we have before us a classic example of brilliant government in action supported by a comparably skilled press. That Digium was the singular reference source that should have been contacted should have been patently obvious to everyone involved.

Categories
Asterisk
Tags
Asterisk, digium, FBI, John Todd, security, VoIP
Comments rss
Comments rss
Trackback
Trackback

« Adding A Cellular Trunk To A Home Office VOIP System: Part 2 Jazinga Review Online At Small Net Builder »

2 responses

[...] Graves on SOHO VoIP — Always smart to read

FBI Security Warnings and VoIP | Voip Tech Chat | December 8, 2008

[...] Graves on SOHO VoIP — Always smart to read this blog [...]

[...] Michael Graves discusses the Recent FBI Warning [...]

FBI and Asterisk Security? Relax, Breathe, and Read - Team Forrest | December 8, 2008

[...] Michael Graves discusses the Recent FBI Warning [...]

Leave a comment

You can use these tags : <a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <strike> <strong>

My Tweets

  • It's 100+ degrees yet again. There's only one answer. Mas margarita's por favor! Frozen with salt!
  • This weeks VUC call was interesting. Might drive me to roll up my sleeves and get into some code, first time in a long while. http://vuc.me
  • @e4VoIP The Konfetel device arrived. Many thanks. Hoping that it makes my UK guys happy. At very least I get to give it a try in depth.
  • Stella made blueberry muffins this morning. Going down nicely with fresh coffee. Yum!
  • @maximCH what does the reverse hold script do? Does it monitor a call for a change in media the ring back to me? That'd be cool.

Recent Comments

  • mjgraves on Gigaset Gear Starting To Hit US Retailers
  • Jason on Gigaset Gear Starting To Hit US Retailers
  • mjgraves on Making Use of Wideband Voice Right Now!: SIPGate
  • Florian on Making Use of Wideband Voice Right Now!: SIPGate
  • Chris Melville on DECT Wars: snom m3 vs Siemens S685IP

Recent Posts

  • New Jabra Headsets
  • HD Connect Gets Rolling
  • David Rowe On Royalty Free Codecs
  • Gigaset Gear Starting To Hit US Retailers
  • Making Use of Wideband Voice Right Now!: SIPGate

Gallery

jazinga-wifi-mac-filter.png

Make a difference.


Change a life.

VoIP Users Conference

RSS From My Personal Blog

  • Pixel Power On The Cover Of Broadcast Engineering Magazine…sorta
  • Three Geeks In Pictures
  • Office Renovation Underway
  • A Great Overview Of Social Media For Geeks
  • Kites At TED: Saul Griffith

Say What?

The question of whether a computer can think is no more interesting than the question of whether a submarine can swim. — Edgar W. Dijkstra

Tags

Asterisk Astlinux Audio blog Broadband cell cellular conference cordless DECT DSL firmware FWD G.722 gateway gsm HD hdvoice home Houston hp ip m0n0wall M3 music onsip phone polycom QoS review router siemens sip skype SNOM soft phone Squeezebox T5700 technology Traffic Shaping Video VoIP VUC wideband wifi

Archives

  • July 2009
  • June 2009
  • May 2009
  • April 2009
  • March 2009
  • February 2009
  • January 2009
  • December 2008
  • November 2008
  • October 2008
  • September 2008
  • August 2008
  • July 2008
  • June 2008
  • May 2008
  • April 2008
  • March 2008
  • February 2008
  • January 2008
  • December 2007
  • November 2007
  • October 2007

Meta

  • Register
  • Log in
  • Entries RSS
  • Comments RSS
  • WordPress.org
rss Comments rss valid xhtml 1.1 design by jide powered by Wordpress get firefox

All content © copyright 2009 Michael Graves