Graves On SOHO VoIP

End User Perspective On IP Telephony In The Home Office
  • rss
  • Home
  • About
    • Contact
    • Disclosure
  • Guides & How-To’s
  • Product Reviews
  • Raves
  • Personal Blog

Put Down The Telephone and Noone Gets Hurt!

mjgraves | December 8, 2008

asterisk icon 94x96 Put Down The Telephone and Noone Gets Hurt!The FBI release last Friday about vishing & Asterisk touched off a bit of a fury. It now appears that they have restated their warning acknowledging Digium’s original response to the matter in question (AST-2008-003) That being, all current v1.2 and 1.4 Asterisk systems will have been patched already. Asterisk v1.6 was never effected. Digium provides further clarification as well.

As always, keep your systems current!

Comments
1 Comment »
Categories
Asterisk, VoIP
Tags
Asterisk, digium, FBI, John Todd, security, vishing
Comments rss Comments rss
Trackback Trackback

Asterisk Implicated In FBI Security Warning

mjgraves | December 7, 2008

asterisk icon 94x96 Asterisk Implicated In FBI Security WarningThe FBI’s Internet Crime Complaint Center has issues a warning with respect to the use of Asterisk to create vishing attacks. According to a post at Slashdot someone from PCWorld checked with Digium who was puzzled about the matter. Digium’s own John Todd responds with a blog post this morning.

The FBI alert is extremely vague, making only a non-specific reference as follows:

The FBI has received information concerning a new technique used to conduct vishingi attacks. The recent attacks were conducted by hackers exploiting a security vulnerability in Asterisk software. Asterisk is free and widely used software developed to integrate PBXii systems with Voice over Internet Protocol (VoIP), digital Internet voice calling services; however, early versions of the Asterisk software are known to have a vulnerability. The vulnerability can be exploited by cyber criminals to use the system as an auto dialer, generating thousands of vishing telephone calls to consumers within one hour.

It must be really challenging for the FBI to get their heads around how to deal with something like Asterisk. It’s a telecom & networking toolkit to build whatever you like. It’s a major enabling mechanism for anyone in the telecom space, and for whatever purpose.

Security is one of the next big issues in VoIP. It remains largely unaddressed in the residential / SOHO space. IMHO the question is not if we’ll address it, but more simply when. For those with an interest in the matter may I suggest reading at www.voipsa.org especially their excellent blog and mailing list. Also, the Bluebox Security Podcast by Dan York and Jonathan Zar.

Update: Here a link to the PCWorld article on the matter.

Update2: Digium’s Bill Miller offers a clarification that Digium was only contacted after the FBI warning was issued and the PC World article was already published.

So it appears that we have before us a classic example of brilliant government in action supported by a comparably skilled press. That Digium was the singular reference source that should have been contacted should have been patently obvious to everyone involved.

Comments
2 Comments »
Categories
Asterisk
Tags
Asterisk, digium, FBI, John Todd, security, VoIP
Comments rss Comments rss
Trackback Trackback

Search Me?

My Tweets

  • If I didn't know better I'd say that today was Monday. Such a blur.
  • Mossberg & Jobs On The iPad: I wasn’t going to post this…but what the heck. It’s just too funny…and true to life. http://bit.ly/bVpTlB
  • @DaveMichels Time to cut & run...
  • OK, that last tweet proves that I have my Twitter RSS feed flowing into an HD graphics system and crawling on-air in less than a minute.
  • This is simply a test, had this been a real tweet I'd have come up with something much more interesting. #fb

Recent Posts

  • Android In Desktop Phones From MSI
  • Point-CounterPoint: Hosted Voice vs. CPE
  • Point-Counterpoint: An Introduction
  • ONSIP Becomes First Hosted PBX Service Provider to Support HD Voice for All On Network And Conference Bridge Calls
  • USB Audio Interfaces: Mac vs PC Applications

Recent Comments

  • qwe on Gigaset News: New Beta Firmware Release
  • qwe on Gigaset News: New Beta Firmware Release
  • Neal Gilbert on Point-CounterPoint: Hosted Voice vs. CPE
  • Matt on Gigaset News: New Beta Firmware Release
  • mjgraves on Point-CounterPoint: Hosted Voice vs. CPE

Series: Making Use of HDVoice Right Now!

  • Series Introduction
  • HDVoice Using Skype
  • HDVoice Using Gizmo5
  • HDVoice Using SIPGate
  • HDVoice Using OnSIP

Make a difference.


Change a life.

VoIP Users Conference

Think About It

RSS From My Personal Blog

  • The Who’s Baba O’Reilly Performed On Gear From ThinkGeek
  • What’s in a name or a title?
  • We Now Have Vacancy
  • Just A Thought
  • Knowing Your Limits

RSS mgraves' shared items in Google Reader

  • Speaking of the Hosted vs. Premises Debate
  • Save the Date!
  • The Secret Origin of Windows
  • FreeSWITCH In Action: Handling Thousands of IVR Calls
  • BMW pulls off an old tablecloth trick
  • SKY to Demonstrate 3D Service

Tags

Asterisk Astlinux astricon Audio blog Broadband cell cellular codec conference cordless DECT digium DSL FWD G.722 gateway Gigaset gsm HD hdvoice headset hp ip M3 music onsip phone polycom QoS router siemens sip skype SNOM soft phone Squeezebox technology USB Video VoIP VUC wideband wifi zipdx

Archives

  • March 2010
  • February 2010
  • January 2010
  • December 2009
  • November 2009
  • October 2009
  • September 2009
  • August 2009
  • July 2009
  • June 2009
  • May 2009
  • April 2009
  • March 2009
  • February 2009
  • January 2009
  • December 2008
  • November 2008
  • October 2008
  • September 2008
  • August 2008
  • July 2008
  • June 2008
  • May 2008
  • April 2008
  • March 2008
  • February 2008
  • January 2008
  • December 2007
  • November 2007
  • October 2007

Meta

  • Register
  • Log in
  • Entries RSS
  • Comments RSS
  • WordPress.org
rss Comments rss valid xhtml 1.1