Graves On SOHO VoIP

End User Perspective On IP Telephony In The Home Office
  • rss
  • Home
  • About
    • Contact
    • Disclosure
  • Guides & How-To’s
  • Product Reviews
  • Raves
  • Personal Blog

Put Down The Telephone and Noone Gets Hurt!

mjgraves | December 8, 2008

asterisk icon 94x96 Put Down The Telephone and Noone Gets Hurt!The FBI release last Friday about vishing & Asterisk touched off a bit of a fury. It now appears that they have restated their warning acknowledging Digium’s original response to the matter in question (AST-2008-003) That being, all current v1.2 and 1.4 Asterisk systems will have been patched already. Asterisk v1.6 was never effected. Digium provides further clarification as well.

As always, keep your systems current!

Comments
1 Comment »
Categories
Asterisk, VoIP
Tags
Asterisk, digium, FBI, John Todd, security, vishing
Comments rss Comments rss
Trackback Trackback

Asterisk Implicated In FBI Security Warning

mjgraves | December 7, 2008

asterisk icon 94x96 Asterisk Implicated In FBI Security WarningThe FBI’s Internet Crime Complaint Center has issues a warning with respect to the use of Asterisk to create vishing attacks. According to a post at Slashdot someone from PCWorld checked with Digium who was puzzled about the matter. Digium’s own John Todd responds with a blog post this morning.

The FBI alert is extremely vague, making only a non-specific reference as follows:

The FBI has received information concerning a new technique used to conduct vishingi attacks. The recent attacks were conducted by hackers exploiting a security vulnerability in Asterisk software. Asterisk is free and widely used software developed to integrate PBXii systems with Voice over Internet Protocol (VoIP), digital Internet voice calling services; however, early versions of the Asterisk software are known to have a vulnerability. The vulnerability can be exploited by cyber criminals to use the system as an auto dialer, generating thousands of vishing telephone calls to consumers within one hour.

It must be really challenging for the FBI to get their heads around how to deal with something like Asterisk. It’s a telecom & networking toolkit to build whatever you like. It’s a major enabling mechanism for anyone in the telecom space, and for whatever purpose.

Security is one of the next big issues in VoIP. It remains largely unaddressed in the residential / SOHO space. IMHO the question is not if we’ll address it, but more simply when. For those with an interest in the matter may I suggest reading at www.voipsa.org especially their excellent blog and mailing list. Also, the Bluebox Security Podcast by Dan York and Jonathan Zar.

Update: Here a link to the PCWorld article on the matter.

Update2: Digium’s Bill Miller offers a clarification that Digium was only contacted after the FBI warning was issued and the PC World article was already published.

So it appears that we have before us a classic example of brilliant government in action supported by a comparably skilled press. That Digium was the singular reference source that should have been contacted should have been patently obvious to everyone involved.

Comments
2 Comments »
Categories
Asterisk
Tags
Asterisk, digium, FBI, John Todd, security, VoIP
Comments rss Comments rss
Trackback Trackback

Search Me?

My Tweets

  • @wolrah Happy to be of assistance. I'm a new world man.
  • RT @DaveMichels: Google Voice Problems. Online help only indicates lots of folks have this problem and no support from Google.
  • At YYZ en route to YAM. No my folks don't follow my tweets so the surprise is safe.
  • @PhoneBoy that just sounds bad. So very bad. Remember that pain is reduced when shared & joy enhanced.
  • RT @steely_glint: UAE TRA legalizes VoIP but still bans Skype. Protectionism at work. http://bit.ly/cnQVwP

Recent Posts

  • SIP Trunks don’t exist. There’s no such thing.
  • Video How-To: Calling the VUC Using PhonerLite on Windows
  • Making Use of Wideband Voice Right Now!: IdeaSIP
  • The Inventor Of The Cell Phone Interviewed On C-SPAN
  • OpenPeak Tablet At Mobile World Congress

Recent Comments

  • Greg on Gigaset News: New Beta Firmware Release
  • qwe on Gigaset News: New Beta Firmware Release
  • Venturello on Review: The Gigaset A580IP SIP/DECT Cordless Phone System
  • Catalonia on Gigaset News: New Beta Firmware Release
  • Catalonia on Gigaset News: New Beta Firmware Release

Series: Making Use of HDVoice Right Now!

  • Series Introduction
  • HDVoice Using Skype
  • HDVoice Using Gizmo5
  • HDVoice Using SIPGate
  • HDVoice Using OnSIP
  • HDVoice Using IdeaSIP

Make a difference.


Change a life.

VoIP Users Conference

Think About It

RSS From My Personal Blog

  • Mossberg & Jobs On The iPad
  • The Who’s Baba O’Reilly Performed On Gear From ThinkGeek
  • What’s in a name or a title?
  • We Now Have Vacancy
  • Just A Thought

RSS Google Reader Shared Stories

  • Let the Spectrum Reallocation Games Begin
  • Niue #4: License?! We Don't Need No Stinkin' License!
  • AudioCodes Debuts OCS-SIP Phone Interoperability Product
  • Verizon Announces SMB VoIP Package
  • Covad Nationwide Ethernet Service Launches on Tax Day
  • Niue Episode 3: Linking the Site
  • Verizon responds to ARRA in a predictable way
  • Tesla switches gears, plans to keep Roadster till 2012
  • [PBX] Hosted PBX service
  • Niue Episode 2: Site Prep

Tags

Asterisk Astlinux astricon Audio blog Broadband cell cellular codec conference cordless DECT digium DSL FWD G.722 gateway Gigaset gsm HD hdvoice headset hp M3 music onsip phone polycom QoS router siemens sip skype SNOM soft phone Squeezebox technology uri USB Video VoIP VUC wideband wifi zipdx

Archives

  • March 2010
  • February 2010
  • January 2010
  • December 2009
  • November 2009
  • October 2009
  • September 2009
  • August 2009
  • July 2009
  • June 2009
  • May 2009
  • April 2009
  • March 2009
  • February 2009
  • January 2009
  • December 2008
  • November 2008
  • October 2008
  • September 2008
  • August 2008
  • July 2008
  • June 2008
  • May 2008
  • April 2008
  • March 2008
  • February 2008
  • January 2008
  • December 2007
  • November 2007
  • October 2007

Meta

  • Register
  • Log in
  • Entries RSS
  • Comments RSS
  • WordPress.org
rss Comments rss valid xhtml 1.1