<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://evangelyze.net/cs/utility/FeedStylesheets/atom.xsl" media="screen"?><feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en"><title type="html">Tony&amp;#39;s Blog</title><subtitle type="html">Securing Your Microsoft Unified Communications Environment</subtitle><id>http://evangelyze.net/cs/blogs/tony/atom.aspx</id><link rel="alternate" type="text/html" href="http://evangelyze.net/cs/blogs/tony/default.aspx" /><link rel="self" type="application/atom+xml" href="http://evangelyze.net/cs/blogs/tony/atom.aspx" /><generator uri="http://communityserver.org" version="4.1.40407.4157">Community Server</generator><updated>2009-02-22T21:29:00Z</updated><entry><title>IMI-TechTalk: Business Continuity and Cost Cutting with Unified Communications</title><link rel="alternate" type="text/html" href="/cs/blogs/tony/archive/2009/06/17/imi-techtalk-business-continuity-and-cost-cutting-with-unified-communications.aspx" /><link rel="enclosure" type="audio/mpeg" length="24337622" href="http://www.evangelyze.net/media/audiocasts/TechTalk061409.mp3" /><id>/cs/blogs/tony/archive/2009/06/17/imi-techtalk-business-continuity-and-cost-cutting-with-unified-communications.aspx</id><published>2009-06-17T16:37:00Z</published><updated>2009-06-17T16:37:00Z</updated><content type="html">&lt;p&gt;There was some time zone confusion with the scheduled guest of the &lt;a href="http://blog.imitechtalk.com/2009/06/june-14-week-in-review.html"&gt;IMI-TechTalk radio show&lt;/a&gt; this past Sunday. I received a phone call in the middle of the show while Tom was live on the air asking me to step in and do the live show impromptu. So, I jumped on the air and&amp;nbsp;host Tom D&amp;#39;Auria and I proceeded to discuss unified communications. Specifically, we talked about how unified communications pays for itself and can help companies save money, as well as how it fits into business continuity plans and preventing or responding to a pandemic outbreak or any other disaster.&amp;nbsp; &lt;/p&gt;
&lt;p&gt;TechTalk is broadcast on &lt;a href="http://www.1100kfnx.com/index.php?/"&gt;&lt;span style="color:#3366cc;"&gt;KFNX AM 1100&lt;/span&gt;&lt;/a&gt; out of Phoenix, AZ, but you can also listen to a &lt;a href="http://www.1100kfnx.com/"&gt;&lt;span style="color:#3366cc;"&gt;live stream&lt;/span&gt;&lt;/a&gt; of the show via the Web. Tune in at 6pm Eastern / 5pm Central to listen on the show live. If you miss the live show, you can check back on the &lt;a href="http://blog.imitechtalk.com/"&gt;&lt;span style="color:#003399;"&gt;IMI-TechTalk blog&lt;/span&gt;&lt;/a&gt; and find a link to the recorded MP3 to download after the fact. &lt;/p&gt;
&lt;p&gt;Click on the &amp;#39;&lt;a href="http://www.evangelyze.net/media/audiocasts/TechTalk061409.mp3"&gt;&lt;span style="color:#003399;"&gt;attachment&lt;/span&gt;&lt;/a&gt;&amp;#39;&amp;nbsp;link below to listen to the June 14 IMI-TechTalk show on cost savings and business continuity with unified communications.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;a href="http://twitter.com/tonys3kur3"&gt;&lt;span style="color:#003399;"&gt;Follow me on Twitter&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://evangelyze.net/cs/aggbug.aspx?PostID=400" width="1" height="1"&gt;</content><author><name>tony</name><uri>http://evangelyze.net/cs/members/tony/default.aspx</uri></author><category term="unified communications" scheme="http://evangelyze.net/cs/blogs/tony/archive/tags/unified+communications/default.aspx" /><category term="IMI-TechTalk" scheme="http://evangelyze.net/cs/blogs/tony/archive/tags/IMI-TechTalk/default.aspx" /><category term="roi" scheme="http://evangelyze.net/cs/blogs/tony/archive/tags/roi/default.aspx" /><category term="cost savings" scheme="http://evangelyze.net/cs/blogs/tony/archive/tags/cost+savings/default.aspx" /><category term="business continuity" scheme="http://evangelyze.net/cs/blogs/tony/archive/tags/business+continuity/default.aspx" /><category term="travel" scheme="http://evangelyze.net/cs/blogs/tony/archive/tags/travel/default.aspx" /><category term="pandemic" scheme="http://evangelyze.net/cs/blogs/tony/archive/tags/pandemic/default.aspx" /></entry><entry><title>Researchers Hack Skype and Google Voice VoIP Calls</title><link rel="alternate" type="text/html" href="/cs/blogs/tony/archive/2009/04/12/researchers-hack-skype-and-google-voice-voip-calls.aspx" /><id>/cs/blogs/tony/archive/2009/04/12/researchers-hack-skype-and-google-voice-voip-calls.aspx</id><published>2009-04-13T02:44:00Z</published><updated>2009-04-13T02:44:00Z</updated><content type="html">&lt;p&gt;VoIP is a hot technology for enterprise communications, but it is also a hot communications technology for consumers. Vonage has been around for years. Most cable TV providers have added both broadband Internet service and VoIP phone service to their product inventory and offer bundled pricing that make it more cost effective for consumers to purchase all three from the one provider.&lt;/p&gt;
&lt;p&gt;Of course, free is good too. Skype was one of the first to emerge as a free voice over IP communication tool. Over the years it has evolved and actually provides a pseudo-unified communications and pseudo-social networking experience in addition to the voice communication. In fact, for some small and medium organizations Skype has been embraced as a communications tool in the enterprise as well. Google got into the game more recently with Google Voice. By virtue of being Google, their product has become somewhat of an instant success as well. &lt;/p&gt;
&lt;p&gt;Recently a researchers at Secure Science demonstrated methods they have discovered that allow them to listen to or hijack Skype and Google Voice calls. The attacks could be used to launch a &amp;#39;botnet&amp;#39; style VoIP attack, harnessing thousands of compromised VoIP accounts to make spam telemarketing calls that can&amp;#39;t be traced. An attacker might also be able to lure a user into surrendering sensitive information such as credit card or social security numbers. The attacks are different for Skype and Google Voice. You can learn more about the details &lt;a href="http://www.pcworld.com/businesscenter/article/162976/voip_services_are_vulnerable_to_botnets_security_researchers_say.html"&gt;from this PC World article&lt;/a&gt;. &lt;/p&gt;
&lt;p&gt;Google responded quickly and worked with the researchers to address the weaknesses in their system and improve their authentication process to prevent the attack. Kudos to Google. The attacks spotlight some of the issues with VoIP though. I know it seems sort of &amp;#39;broken record&amp;#39; but consumers and enterprises alike are adopting VoIP for all of the benefits it can provide with no regard for the security concerns that come with it. They take for granted the relative security that traditional phone communications have enjoyed and forget that when you move voice communications onto the data network it becomes subject to many of the same risks and threats while also creating whole new risks and threats that didn&amp;#39;t previously exist. &lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://evangelyze.net/cs/aggbug.aspx?PostID=317" width="1" height="1"&gt;</content><author><name>tony</name><uri>http://evangelyze.net/cs/members/tony/default.aspx</uri></author><category term="VoIP security" scheme="http://evangelyze.net/cs/blogs/tony/archive/tags/VoIP+security/default.aspx" /><category term="Skype" scheme="http://evangelyze.net/cs/blogs/tony/archive/tags/Skype/default.aspx" /><category term="VoIP fraud" scheme="http://evangelyze.net/cs/blogs/tony/archive/tags/VoIP+fraud/default.aspx" /><category term="attack" scheme="http://evangelyze.net/cs/blogs/tony/archive/tags/attack/default.aspx" /><category term="Google Voice" scheme="http://evangelyze.net/cs/blogs/tony/archive/tags/Google+Voice/default.aspx" /><category term="Secure Science" scheme="http://evangelyze.net/cs/blogs/tony/archive/tags/Secure+Science/default.aspx" /></entry><entry><title>What to Expect from Windows 7</title><link rel="alternate" type="text/html" href="/cs/blogs/tony/archive/2009/04/03/what-to-expect-from-windows-7.aspx" /><link rel="enclosure" type="audio/mpeg" length="16036029" href="http://www.evangelyze.net/media/audiocasts/TechTalk032909.mp3" /><id>/cs/blogs/tony/archive/2009/04/03/what-to-expect-from-windows-7.aspx</id><published>2009-04-04T00:52:00Z</published><updated>2009-04-04T00:52:00Z</updated><content type="html">&lt;p&gt;On March 29, 2009 I &lt;a href="http://www.garageband.com/mp3cat/.UZCMbCqB5a6u/01_TechTalk___Windows_7_03_29_09.mp3"&gt;&lt;span style="color:#003399;"&gt;appeared as a guest&lt;/span&gt;&lt;/a&gt; on the &lt;a href="http://techtalk.imi-us.com/"&gt;&lt;span style="color:#003399;"&gt;IMI-TechTalk radio show&lt;/span&gt;&lt;/a&gt;. Tom D&amp;#39;Auria, CEO of Information Methods Incorporated (IMI), and I talked about Microsoft&amp;#39;s new desktop operating system, Windows 7.&amp;nbsp;We talked about what users can expect from the new operating system and some of the new features that users can look forward to. We also talked about when the new operating system is expected to be released and the various versions of Windows 7 that will be available. IMI-TechTalk is broadcast by &lt;a href="http://www.1100kfnx.com/"&gt;&lt;span style="color:#003399;"&gt;KFNX AM 1100&lt;/span&gt;&lt;/a&gt; out of Phoenix, AZ every Sunday. It is also available as streaming audio via the Web so you can listen to the show no matter how far you are from Phoenix. &lt;/p&gt;
&lt;p&gt;Click on the &amp;#39;&lt;span style="color:#3366cc;"&gt;&lt;a href="http://www.evangelyze.net/media/audiocasts/TechTalk032909.mp3"&gt;attachment&lt;/a&gt;&lt;/span&gt;&amp;#39;&amp;nbsp;link below to listen to the Microsoft&amp;nbsp;Windows 7&amp;nbsp;show from&amp;nbsp;March 29, 2009.&lt;/p&gt;
&lt;p&gt;&lt;a href="http://twitter.com/tonys3kur3"&gt;Follow me on Twitter&lt;/a&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://evangelyze.net/cs/aggbug.aspx?PostID=273" width="1" height="1"&gt;</content><author><name>tony</name><uri>http://evangelyze.net/cs/members/tony/default.aspx</uri></author><category term="KFNX AM 1100" scheme="http://evangelyze.net/cs/blogs/tony/archive/tags/KFNX+AM+1100/default.aspx" /><category term="IMI-TechTalk" scheme="http://evangelyze.net/cs/blogs/tony/archive/tags/IMI-TechTalk/default.aspx" /><category term="Windows 7" scheme="http://evangelyze.net/cs/blogs/tony/archive/tags/Windows+7/default.aspx" /><category term="radio show" scheme="http://evangelyze.net/cs/blogs/tony/archive/tags/radio+show/default.aspx" /></entry><entry><title>Attack Capable of Capturing SIP Device Password</title><link rel="alternate" type="text/html" href="/cs/blogs/tony/archive/2009/03/27/attack-capable-of-capturing-sip-device-password.aspx" /><id>/cs/blogs/tony/archive/2009/03/27/attack-capable-of-capturing-sip-device-password.aspx</id><published>2009-03-27T13:03:00Z</published><updated>2009-03-27T13:03:00Z</updated><content type="html">&lt;p&gt;A pair of VoIP security researchers claims to have&amp;nbsp;&lt;a href="http://www.usken.no/2009/03/26/get-the-password-from-any-sip-device-its-fully-possible/"&gt;discovered a method for acquiring the password from a SIP device&lt;/a&gt;. The attack seems to take advantage of a weakness in SIP security controls and authentication. When a call is being terminated, the SIP UserAgent sends a &amp;#39;BYE&amp;#39; message. Normally this would terminate the call, but with this attack a response is sent to the device of &amp;#39;407 Proxy Authorization Required&amp;#39; and the SIP UserAgent responds by transmitting the password for the SIP device (encrypted with MD5 hash).&lt;/p&gt;
&lt;p&gt;For this attack to work demonstrates a weakness in SIP authentication. The SIP protocol should not respond to such requests from external or untrusted sources. The SIP protocol itself should be coded to ignore or drop authentication requests from unauthorized sources. VoIP vendors and organizations using vulnerable SIP devices may be able to configure security controls to mitigate the threat by blocking or dropping requests like this without allowing them through to the SIP device. &lt;/p&gt;
&lt;p&gt;A successful attack could reveal the password for the targeted SIP device, allowing the attacker to impersonate that device. Given the IP address and password of the SIP device, the attacker could attach a rogue SIP device which the VoIP network would recognize. There may be other potential attacks that result from the ability to impersonate an authorized SIP device, but the most prevalent would be simply VoIP call fraud. Attackers can use the hijacked SIP device to place calls around the world. If that happens, the organization might be shocked when they get the next bill from their VoIP provider.&lt;/p&gt;
&lt;p&gt;According to &lt;a href="http://www.usken.no/2009/03/26/get-the-password-from-any-sip-device-its-fully-possible/"&gt;their blog post&lt;/a&gt;, the attackers feel confident they can get the password from any SIP device using this method. That is because the flaw is&amp;nbsp;with the SIP protocol itself and not with any particular device.&amp;nbsp;What are your thoughts? Is this a big deal or just hype? Who bears the burden to address the issue- the SIP device&amp;nbsp;vendors, or should the SIP protocol itself be modified to protect the authentication and authorization exchanges?&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;a href="http://twitter.com/tonys3kur3"&gt;Follow me on Twitter&lt;/a&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://evangelyze.net/cs/aggbug.aspx?PostID=259" width="1" height="1"&gt;</content><author><name>tony</name><uri>http://evangelyze.net/cs/members/tony/default.aspx</uri></author><category term="VoIP security" scheme="http://evangelyze.net/cs/blogs/tony/archive/tags/VoIP+security/default.aspx" /><category term="VoIP fraud" scheme="http://evangelyze.net/cs/blogs/tony/archive/tags/VoIP+fraud/default.aspx" /><category term="attack" scheme="http://evangelyze.net/cs/blogs/tony/archive/tags/attack/default.aspx" /><category term="SIP device" scheme="http://evangelyze.net/cs/blogs/tony/archive/tags/SIP+device/default.aspx" /><category term="password" scheme="http://evangelyze.net/cs/blogs/tony/archive/tags/password/default.aspx" /></entry><entry><title>Reality Check: Should you invest in IP PBX now, later or not at all?</title><link rel="alternate" type="text/html" href="/cs/blogs/tony/archive/2009/03/25/reality-check-should-you-invest-in-ip-pbx-now-later-or-not-at-all.aspx" /><link rel="enclosure" type="audio/mpeg" length="7278934" href="http://ehg-techtarget.hitbox.com/redirector.mp3?hb=DM54102503VE83EN3;DM5212204PCA83EN3&amp;amp;cv.c4=DL|PODCAST_031809_realitycheck_EH.mp3&amp;amp;cd=1&amp;amp;n=/podcast=&amp;amp;vcon=/searchUnifiedCommunications/podcasts&amp;amp;hec=0&amp;amp;vjs=HBX0200u&amp;amp;fn=http://media.techtarget.com/audioCast/NETWORKING/031809_realitycheck_EH.mp3&amp;amp;target=http://media.techtarget.com/audioCast/NETWORKING/031809_realitycheck_EH.mp3" /><id>/cs/blogs/tony/archive/2009/03/25/reality-check-should-you-invest-in-ip-pbx-now-later-or-not-at-all.aspx</id><published>2009-03-25T16:40:00Z</published><updated>2009-03-25T16:40:00Z</updated><content type="html">&lt;p&gt;Each month TechTarget&amp;#39;s &lt;a href="http://searchunifiedcommunications.techtarget.com/"&gt;&lt;span style="color:#003399;"&gt;SearchUnifiedCommunications&lt;/span&gt;&lt;/a&gt; site does a podcast on a unified communications topic titled Reality Check. I appeared as a guest on this month&amp;#39;s podcast and was interviewed by SearchUnifiedCommunications Associate Editor Elaine Hom. We focused our discussion this month around the PBX. We talked about whether the PBX is still relevant and whether or not organizations that are implementing unified communications need to invest in a PBX or IP PBX. We also talked about the different approaches&amp;nbsp;that some of the major unified communications&amp;nbsp;vendors take&amp;nbsp;and how their core competency in part dictates the focus of their&amp;nbsp;unified communications initiatives, as well as&amp;nbsp;some&amp;nbsp;best practices for&amp;nbsp;how to tackle implementing unified communications.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;You can listen to the podcast by &lt;span style="color:#3366cc;"&gt;&lt;a href="http://ehg-techtarget.hitbox.com/redirector.mp3?hb=DM54102503VE83EN3;DM5212204PCA83EN3&amp;amp;cv.c4=DL|PODCAST_031809_realitycheck_EH.mp3&amp;amp;cd=1&amp;amp;n=/podcast=&amp;amp;vcon=/searchUnifiedCommunications/podcasts&amp;amp;hec=0&amp;amp;vjs=HBX0200u&amp;amp;fn=http://media.techtarget.com/audioCast/NETWORKING/031809_realitycheck_EH.mp3&amp;amp;target=http://media.techtarget.com/audioCast/NETWORKING/031809_realitycheck_EH.mp3"&gt;clicking here&lt;/a&gt;&lt;/span&gt;.&lt;/p&gt;
&lt;p&gt;&lt;a href="http://twitter.com/tonys3kur3"&gt;Follow me on Twitter&lt;/a&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://evangelyze.net/cs/aggbug.aspx?PostID=253" width="1" height="1"&gt;</content><author><name>tony</name><uri>http://evangelyze.net/cs/members/tony/default.aspx</uri></author><category term="VoIP" scheme="http://evangelyze.net/cs/blogs/tony/archive/tags/VoIP/default.aspx" /><category term="unified communications" scheme="http://evangelyze.net/cs/blogs/tony/archive/tags/unified+communications/default.aspx" /><category term="PBX" scheme="http://evangelyze.net/cs/blogs/tony/archive/tags/PBX/default.aspx" /><category term="podcast" scheme="http://evangelyze.net/cs/blogs/tony/archive/tags/podcast/default.aspx" /><category term="Reality Check" scheme="http://evangelyze.net/cs/blogs/tony/archive/tags/Reality+Check/default.aspx" /><category term="IP PBX" scheme="http://evangelyze.net/cs/blogs/tony/archive/tags/IP+PBX/default.aspx" /><category term="searchunifiedcommunications" scheme="http://evangelyze.net/cs/blogs/tony/archive/tags/searchunifiedcommunications/default.aspx" /></entry><entry><title>Talking Windows 7 on TechTalk Radio Show</title><link rel="alternate" type="text/html" href="/cs/blogs/tony/archive/2009/03/21/guest-on-imi-techtalk-radio-show.aspx" /><id>/cs/blogs/tony/archive/2009/03/21/guest-on-imi-techtalk-radio-show.aspx</id><published>2009-03-22T01:49:00Z</published><updated>2009-03-22T01:49:00Z</updated><content type="html">&lt;p&gt;I will be joining host Tom D&amp;#39;Auria live on the &lt;a href="http://blog.imitechtalk.com/2009/03/march-22-whats-new-with-windows-7.html"&gt;IMI-TechTalk radio show&lt;/a&gt; this Sunday. Our topic this week will be Windows 7. We will talk about what you can expect from the upcoming new desktop operating system from Microsoft. We will also focus on some of the issues that Microsoft has had in the past when rolling out a new operating system- Vista being a recent and poignant example of those issues, as well as some of the compelling new features that could be game changers for some organizations. &lt;/p&gt;
&lt;p&gt;TechTalk is broadcast on &lt;a href="http://www.1100kfnx.com/index.php?/"&gt;KFNX AM 1100&lt;/a&gt; out of Phoenix, AZ, but you can also listen to a &lt;a href="http://www.1100kfnx.com/"&gt;live stream&lt;/a&gt; of the show via the Web. Tune in at 6pm Eastern / 5pm Central to listen on the show live. If you miss the live show, you can check back on the &lt;a href="http://blog.imitechtalk.com/"&gt;IMI-TechTalk blog&lt;/a&gt; and find a link to the recorded MP3 to download after the fact. &lt;/p&gt;
&lt;p&gt;&lt;a href="http://twitter.com/tonys3kur3"&gt;Follow me on Twitter&lt;/a&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://evangelyze.net/cs/aggbug.aspx?PostID=241" width="1" height="1"&gt;</content><author><name>tony</name><uri>http://evangelyze.net/cs/members/tony/default.aspx</uri></author><category term="KFNX AM 1100" scheme="http://evangelyze.net/cs/blogs/tony/archive/tags/KFNX+AM+1100/default.aspx" /><category term="IMI-TechTalk" scheme="http://evangelyze.net/cs/blogs/tony/archive/tags/IMI-TechTalk/default.aspx" /><category term="Windows 7" scheme="http://evangelyze.net/cs/blogs/tony/archive/tags/Windows+7/default.aspx" /><category term="radio show" scheme="http://evangelyze.net/cs/blogs/tony/archive/tags/radio+show/default.aspx" /></entry><entry><title>The State of PCI Compliance</title><link rel="alternate" type="text/html" href="/cs/blogs/tony/archive/2009/03/18/the-state-of-pci-compliance.aspx" /><id>/cs/blogs/tony/archive/2009/03/18/the-state-of-pci-compliance.aspx</id><published>2009-03-18T19:38:00Z</published><updated>2009-03-18T19:38:00Z</updated><content type="html">&lt;p&gt;As Director of Security for Evangelyze Communications my primary focus is on the security implications of VoIP and unified communications and helping our customers to understand the risks and implement effective security controls to protect their unified communications infrastructure. Another aspect of that security however is the issue of compliance. Organizations fall under a variety of regulatory mandates and industry guidelines and those compliance requirements often overlap into monitoring and retaining communications data. &lt;/p&gt;
&lt;p&gt;Organizations need to be familiar with the mandates they are obligated to follow, whether it is SOX (Sarbanes-Oxley), HIPAA (Health Insurance Portability and Accountability Act), GLBA (Gramm-Leach-Bliley Act), PCI DSS (Payment Card Industry Data Security Standard), or others. Some organizations must comply with two or more of these depending on the industry they are in and the types of business they engage in. To achieve and maintain compliance, organizations need to understand what the requirements are for compliance regarding&amp;nbsp; their communications. As it relates to unified communications, organizations have to grasp the implications of the converged communications channels.&amp;nbsp;With instant messaging conversations&amp;nbsp;archived&amp;nbsp;in Outlook, and voicemail messages sent as file attachments via email, and email being able to be read over the phone by Microsoft Exchange using Outlook Voice Access, the lines are blurred between the types of communication and organizations have to be aware of this and put the appropriate controls in place to be compliant.&lt;/p&gt;
&lt;p&gt;PCI Compliance has been a particular focus of mine. I was the lead author and tech editor of &lt;a href="http://www.amazon.com/PCI-Compliance-Understand-Implement-Effective/dp/1597491659/ref=pd_bbs_sr_1?ie=UTF8&amp;amp;s=books&amp;amp;qid=1237405996&amp;amp;sr=8-1"&gt;PCI Compliance: Understand and Implement Effective PCI Data Security Standard Compliance&lt;/a&gt; published by Syngress in 2007. Dr. Anton Chuvakin and I are co-authoring a 2nd edition of the book to be published later this year which will contain updated information related to revisions in the PCI DSS guidelines themselves as well as reflecting new information regarding the various breaches and issues that have occurred over the past couple of years. It will also have more real-world case studies and how-to guidance to provide more actionable material for the reader rather than just a theoretical description of the PCI DSS guidelines.&lt;/p&gt;
&lt;p&gt;This week I was the guest on a podcast recorded for BankInfoSecurity.com&amp;nbsp;titled &amp;#39;&lt;a href="http://www.bankinfosecurity.com/podcasts.php?podcastID=209"&gt;The State of PCI Compliance&lt;/a&gt;&amp;#39;. You can listen to the &lt;a href="http://www.bankinfosecurity.com/showPodcast.php?podcastID=209"&gt;streaming audio by clicking here&lt;/a&gt;. &lt;/p&gt;
&lt;p&gt;&lt;a href="http://twitter.com/tonys3kur3"&gt;&lt;span style="color:#003399;"&gt;Follow me on Twitter&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://evangelyze.net/cs/aggbug.aspx?PostID=235" width="1" height="1"&gt;</content><author><name>tony</name><uri>http://evangelyze.net/cs/members/tony/default.aspx</uri></author><category term="security" scheme="http://evangelyze.net/cs/blogs/tony/archive/tags/security/default.aspx" /><category term="VoIP" scheme="http://evangelyze.net/cs/blogs/tony/archive/tags/VoIP/default.aspx" /><category term="unified communications" scheme="http://evangelyze.net/cs/blogs/tony/archive/tags/unified+communications/default.aspx" /><category term="unified communications security" scheme="http://evangelyze.net/cs/blogs/tony/archive/tags/unified+communications+security/default.aspx" /><category term="podcast" scheme="http://evangelyze.net/cs/blogs/tony/archive/tags/podcast/default.aspx" /><category term="PCI compliance" scheme="http://evangelyze.net/cs/blogs/tony/archive/tags/PCI+compliance/default.aspx" /><category term="PCI DSS" scheme="http://evangelyze.net/cs/blogs/tony/archive/tags/PCI+DSS/default.aspx" /><category term="compliance" scheme="http://evangelyze.net/cs/blogs/tony/archive/tags/compliance/default.aspx" /></entry><entry><title>Forefront Security for OCS Finally Reaches RTM</title><link rel="alternate" type="text/html" href="/cs/blogs/tony/archive/2009/03/18/forefront-security-for-ocs-finally-reaches-rtm.aspx" /><id>/cs/blogs/tony/archive/2009/03/18/forefront-security-for-ocs-finally-reaches-rtm.aspx</id><published>2009-03-18T16:06:00Z</published><updated>2009-03-18T16:06:00Z</updated><content type="html">&lt;p&gt;&lt;a href="http://www.microsoft.com/Forefront/clientsecurity/en/us/default.aspx"&gt;Forefront Client Security&lt;/a&gt; and other &lt;a href="http://www.microsoft.com/forefront/serversecurity/en/us/default.aspx"&gt;Forefront Server Security&lt;/a&gt; products, such as &lt;a href="http://www.microsoft.com/forefront/serversecurity/exchange/en/us/default.aspx"&gt;Forefront Security for Exchange Server&lt;/a&gt; and &lt;a href="http://www.microsoft.com/forefront/serversecurity/sharepoint/en/us/default.aspx"&gt;Forefront Security for Sharepoint&lt;/a&gt;, have been around for some time now. Microsoft&amp;#39;s &lt;a href="http://www.microsoft.com/forefront/serversecurity/ocs/en/us/default.aspx"&gt;Forefront&amp;nbsp;Security for Office Communications Server&lt;/a&gt; seems to have taken a painstakingly long time to get developed, make it through Beta testing, and finally now &lt;a href="http://redmondmag.com/news/article.asp?EditorialsID=10691"&gt;released to manufacturing (RTM)&lt;/a&gt;. But, that day has finally arrived.&lt;/p&gt;
&lt;p&gt;Forefront for OCS delivers valuable protection for the unified communications platform. Aside from protecting OCS 2007 and OCS 2007 R2 from malware using as many as five simultaneous antivirus scanning engines, Forefront Security for Office Communications Server also provides keyword and content filtering for instant messaging communications. Using Forefront Security for OCS, organizations can block sensitive or confidential information from being communicated via instant messaging, and certain file types- for example EXE files- can be blocked as instant messaging file attachments. Microsoft Forefront Security for Office Communications Server looks at the actual file content so it is also smart enough not to be circumvented by simply renaming the file extension. &lt;/p&gt;
&lt;p&gt;I will be writing more about how to install, configure, and administer &lt;a href="http://www.microsoft.com/forefront/serversecurity/ocs/en/us/default.aspx"&gt;Forefront Security for Office Communications Server&lt;/a&gt; in the coming weeks. Check back to learn more about the product, how it works, and issues you may expect to encounter. Feel free to comment here or drop me an email if you have specific questions or run into problems that you would like me to explore.&lt;/p&gt;
&lt;p&gt;&lt;a href="http://twitter.com/tonys3kur3"&gt;&lt;span style="color:#003399;"&gt;Follow me on Twitter&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://evangelyze.net/cs/aggbug.aspx?PostID=233" width="1" height="1"&gt;</content><author><name>tony</name><uri>http://evangelyze.net/cs/members/tony/default.aspx</uri></author><category term="OCS 2007" scheme="http://evangelyze.net/cs/blogs/tony/archive/tags/OCS+2007/default.aspx" /><category term="Forefront Security for Office Communications Server" scheme="http://evangelyze.net/cs/blogs/tony/archive/tags/Forefront+Security+for+Office+Communications+Server/default.aspx" /><category term="Forefront Security" scheme="http://evangelyze.net/cs/blogs/tony/archive/tags/Forefront+Security/default.aspx" /><category term="OCS 2007 R2" scheme="http://evangelyze.net/cs/blogs/tony/archive/tags/OCS+2007+R2/default.aspx" /><category term="malware" scheme="http://evangelyze.net/cs/blogs/tony/archive/tags/malware/default.aspx" /><category term="content filtering" scheme="http://evangelyze.net/cs/blogs/tony/archive/tags/content+filtering/default.aspx" /></entry><entry><title>INVITE of Death</title><link rel="alternate" type="text/html" href="/cs/blogs/tony/archive/2009/03/15/invite-of-death.aspx" /><id>/cs/blogs/tony/archive/2009/03/15/invite-of-death.aspx</id><published>2009-03-16T00:51:00Z</published><updated>2009-03-16T00:51:00Z</updated><content type="html">&lt;p&gt;Pretty cool name, huh? If you&amp;#39;re going to create a new VoIP or unified communications attack, you want to have one with panache and it is hard to get a name with more impact than the &amp;#39;INVITE of Death&amp;#39;.&lt;/p&gt;
&lt;p&gt;That said, the attack itself is not nearly as impressive as the name. SIP is one of the prevalent protocols for VoIP and unified communications. The INVITE request is a function of SIP (Session Initiation Protocol). When a call is placed, the INVITE request is sent to the device being contacted. The receiving device can respond that it is TRYING, or that it is RINGING, or with OK and establish the communications session as a few examples.&lt;/p&gt;
&lt;p&gt;The &lt;a href="http://ims-bisf.nexginrc.org/OpenSBC-vul.html"&gt;INVITE of Death attack&lt;/a&gt; is simply a denial-of-service (DoS) attack and it only works against one particular open source product- OpenSBC. Directing a malformed INVITE request to a vulnerable&amp;nbsp;OpenSBC server will cause the OpenSBC server to crash. &lt;/p&gt;
&lt;p&gt;In this case, simply stripping out erroneous characters- specifically leading or trailing colons- solves the problem and protects the OpenSBC server from the INVITE of Death DoS attack. The INVITE of Death won&amp;#39;t be bringing VoIP to its knees, but it does demonstrate the similarities between SIP and HTTP and illustrates that SIP&amp;nbsp;can be&amp;nbsp;vulnerable to the same types of malformed packet attacks that have plagued standard network data and Web servers for years. &lt;/p&gt;
&lt;p&gt;&lt;a href="http://twitter.com/tonys3kur3"&gt;&lt;span style="color:#003399;"&gt;Follow me on Twitter&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://evangelyze.net/cs/aggbug.aspx?PostID=230" width="1" height="1"&gt;</content><author><name>tony</name><uri>http://evangelyze.net/cs/members/tony/default.aspx</uri></author><category term="VoIP" scheme="http://evangelyze.net/cs/blogs/tony/archive/tags/VoIP/default.aspx" /><category term="VoIP security" scheme="http://evangelyze.net/cs/blogs/tony/archive/tags/VoIP+security/default.aspx" /><category term="SIP" scheme="http://evangelyze.net/cs/blogs/tony/archive/tags/SIP/default.aspx" /><category term="INVITE" scheme="http://evangelyze.net/cs/blogs/tony/archive/tags/INVITE/default.aspx" /><category term="denial-of-service" scheme="http://evangelyze.net/cs/blogs/tony/archive/tags/denial-of-service/default.aspx" /><category term="OpenSBC" scheme="http://evangelyze.net/cs/blogs/tony/archive/tags/OpenSBC/default.aspx" /><category term="DoS" scheme="http://evangelyze.net/cs/blogs/tony/archive/tags/DoS/default.aspx" /><category term="INVITE of Death" scheme="http://evangelyze.net/cs/blogs/tony/archive/tags/INVITE+of+Death/default.aspx" /></entry><entry><title>Securing SIP Trunks</title><link rel="alternate" type="text/html" href="/cs/blogs/tony/archive/2009/03/08/securing-sip-trunks.aspx" /><link rel="enclosure" type="application/pdf" length="2193753" href="http://evangelyze.net/cs/cfs-file.ashx/__key/CommunityServer.Components.PostAttachments/00.00.00.01.69/Securing_5F00_SIP_5F00_Trunks.pdf" /><id>/cs/blogs/tony/archive/2009/03/08/securing-sip-trunks.aspx</id><published>2009-03-08T17:57:00Z</published><updated>2009-03-08T17:57:00Z</updated><content type="html">&lt;p&gt;SIP trunking provides organizations with a cost-effective, reliable method of connecting the internal network and telephony systems with external VoIP and traditional phone systems over the IP network. SIP tunking is quickly replacing traditional PRI and analog circuits for enterprise communications. Typically, SIP trunking involves an IP PBX, however Microsoft Office Communications Server 2007 R2 introduced the ability to do direct SIP trunking to the OCS 2007 environment and eliminate the IP PBX. Microsoft only provides direct SIP trunking with two VoIP providers, but Evangelyze Communications developed &lt;a href="http://evangelyze.net/products.asp#SMARTSIP"&gt;SmartSIP&lt;/a&gt; which lets organizations leverage their existing telephony hardware and employ direct SIP trunking with virtually any VoIP provider.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;SIP trunking has many business benefits, but also introduces some additional security concerns. Internal security policies and controls will most likely differ from the security policies and controls of the SIP trunk provider. Connecting with the SIP trunk provider may involve opening ports though the firewall or NAT device, modifying the IP PBX (if present), changing private IP addressing or numbering plans, or other changes to the unified communications infrastructure.&amp;nbsp;The organization must also maintain control over signaling and media secuity as well as call-routing policies.&lt;/p&gt;
&lt;p&gt;Organizations have to understand the risks and implement appropriate security measures to ensure the availability of their unified communications network, the integrity and confidentiality of voice and data communications, and the overall compliance with regulatory requirements the organization might be subject to. Read &lt;a href="http://www.evangelyze.net/cs/cfs-file.ashx/__key/CommunityServer.Components.PostAttachments/00.00.00.01.69/Securing_5F00_SIP_5F00_Trunks.pdf"&gt;Securing SIP Trunks&lt;/a&gt; to learn more about the security issues and how Evangelyze Communications, by partnering with Sipera Systems, can work with organizations to implement SIP trunking securely. &lt;/p&gt;
&lt;p&gt;&lt;a href="http://twitter.com/tonys3kur3"&gt;Follow me on Twitter&lt;/a&gt;&lt;/p&gt;
&lt;p align="left"&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;　&lt;/p&gt;
&lt;p&gt;&lt;span style="font-family:TradeGothic,TradeGothic;font-size:xx-small;"&gt;&lt;span style="font-family:TradeGothic,TradeGothic;font-size:xx-small;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://evangelyze.net/cs/aggbug.aspx?PostID=169" width="1" height="1"&gt;</content><author><name>tony</name><uri>http://evangelyze.net/cs/members/tony/default.aspx</uri></author><category term="security" scheme="http://evangelyze.net/cs/blogs/tony/archive/tags/security/default.aspx" /><category term="VoIP security" scheme="http://evangelyze.net/cs/blogs/tony/archive/tags/VoIP+security/default.aspx" /><category term="unified communications" scheme="http://evangelyze.net/cs/blogs/tony/archive/tags/unified+communications/default.aspx" /><category term="unified communications security" scheme="http://evangelyze.net/cs/blogs/tony/archive/tags/unified+communications+security/default.aspx" /><category term="UC" scheme="http://evangelyze.net/cs/blogs/tony/archive/tags/UC/default.aspx" /><category term="smartsip" scheme="http://evangelyze.net/cs/blogs/tony/archive/tags/smartsip/default.aspx" /><category term="sipera systems" scheme="http://evangelyze.net/cs/blogs/tony/archive/tags/sipera+systems/default.aspx" /><category term="sip trunks" scheme="http://evangelyze.net/cs/blogs/tony/archive/tags/sip+trunks/default.aspx" /></entry><entry><title>Metasploit Founder Introduces WarVOX Suite for Voice Penetration Testing</title><link rel="alternate" type="text/html" href="/cs/blogs/tony/archive/2009/03/07/metasploit-introduces-warvox-suite-for-voice-penetration-testing.aspx" /><id>/cs/blogs/tony/archive/2009/03/07/metasploit-introduces-warvox-suite-for-voice-penetration-testing.aspx</id><published>2009-03-08T04:18:00Z</published><updated>2009-03-08T04:18:00Z</updated><content type="html">&lt;p&gt;The founder of &lt;a href="http://metasploit.org/"&gt;Metasploit&lt;/a&gt;, HD Moore, has released a new set of tools for voice security research and penetration testing- &lt;a href="http://www.warvox.org/index.html"&gt;WarVOX&lt;/a&gt;. Metasploit&amp;nbsp;has been around for a few years and has offered security administrators and researchers a powerful and comprehensive exploit generation and penetration testing platform that is freely available. Now, HD Moore has taken that same concept or basic goal and delivered the WarVOX suite of security tools for exploring, classifying, and auditing telephone systems. &lt;/p&gt;
&lt;p&gt;WarVOX can be used to conduct reconnaisance and penetration testing of voice networks. It is a war-dialing tool, among other things, but a war-dialing tool with a broader approach. According to the WarVOX site &amp;quot;Unlike normal wardialing tools, WarVOX works with the actual audio from each call and does not use a modem directly. This model allows WarVOX to find and classify a wide range of interesting lines, including modems, faxes, voice mail boxes, PBXs, loops, dial tones, IVRs, and forwarders. WarVOX provides the unique ability to classify all telephone lines in a given range, not just those connected to modems, allowing for a comprehensive audit of a telephone system.&amp;quot;&lt;/p&gt;
&lt;p&gt;I have &lt;a href="http://www.warvox.org/install.html"&gt;downloaded the WarVOX installation&lt;/a&gt; and plan to play around with it. Metasploit has earned a great deal of respect in the general security research arena, so I expect good things from WarVOX as well. You can check out &lt;a href="http://warvox.org/media/warvox-1.0.0.pdf"&gt;this presentation&lt;/a&gt; to learn more about WarVOX and how and why it was developed.&lt;/p&gt;
&lt;p&gt;&lt;a href="http://twitter.com/tonys3kur3"&gt;Follow me on Twitter&lt;/a&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;a href="http://twitter.com/tonys3kur3"&gt;&lt;span style="font-family:comic sans ms,sans-serif;font-size:small;"&gt;&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://evangelyze.net/cs/aggbug.aspx?PostID=168" width="1" height="1"&gt;</content><author><name>tony</name><uri>http://evangelyze.net/cs/members/tony/default.aspx</uri></author><category term="VoIP security" scheme="http://evangelyze.net/cs/blogs/tony/archive/tags/VoIP+security/default.aspx" /><category term="VoIP security assessment" scheme="http://evangelyze.net/cs/blogs/tony/archive/tags/VoIP+security+assessment/default.aspx" /><category term="MetaSploit" scheme="http://evangelyze.net/cs/blogs/tony/archive/tags/MetaSploit/default.aspx" /><category term="penetration testing" scheme="http://evangelyze.net/cs/blogs/tony/archive/tags/penetration+testing/default.aspx" /><category term="WarVOX" scheme="http://evangelyze.net/cs/blogs/tony/archive/tags/WarVOX/default.aspx" /><category term="exploit generation" scheme="http://evangelyze.net/cs/blogs/tony/archive/tags/exploit+generation/default.aspx" /><category term="war-dialing" scheme="http://evangelyze.net/cs/blogs/tony/archive/tags/war-dialing/default.aspx" /></entry><entry><title>Reality Check: Can you have UC without VoIP/IP PBX?</title><link rel="alternate" type="text/html" href="/cs/blogs/tony/archive/2009/02/25/reality-check-can-you-have-uc-without-voip-ip-pbx.aspx" /><link rel="enclosure" type="audio/mpeg" length="8128209" href="http://ehg-techtarget.hitbox.com/redirector.mp3?hb=DM54102503VE83EN3;DM5212204PCA83EN3&amp;amp;cv.c4=DL|PODCAST_021609_realitycheck_EH.mp3&amp;amp;cd=1&amp;amp;n=/podcast=&amp;amp;vcon=/searchUnifiedCommunications/podcasts&amp;amp;hec=0&amp;amp;vjs=HBX0200u&amp;amp;fn=http://media.techtarget.com/audioCast/NETWORKING/021609_realitycheck_EH.mp3&amp;amp;target=http://media.techtarget.com/audioCast/NETWORKING/021609_realitycheck_EH.mp3" /><id>/cs/blogs/tony/archive/2009/02/25/reality-check-can-you-have-uc-without-voip-ip-pbx.aspx</id><published>2009-02-25T21:21:00Z</published><updated>2009-02-25T21:21:00Z</updated><content type="html">&lt;p&gt;Each month TechTarget&amp;#39;s &lt;a href="http://searchunifiedcommunications.techtarget.com/"&gt;SearchUnifiedCommunications&lt;/a&gt; site does a podcast on a unified communications topic titled Reality Check. I appeared as a guest on this month&amp;#39;s podcast and was interviewed by SearchUnifiedCommunications Associate Editor Elaine Hom. We talked about the general concept of unified communications, and we dove deeper into whether or not VoIP is a requirement of unified communications, as well as the recently released Office Communications Server 2007 R2 and whether or not organizations really need to have an IP PBX any longer.&lt;/p&gt;
&lt;p&gt;You can listen to the podcast by &lt;a href="http://ehg-techtarget.hitbox.com/redirector.mp3?hb=DM54102503VE83EN3;DM5212204PCA83EN3&amp;amp;cv.c4=DL|PODCAST_021609_realitycheck_EH.mp3&amp;amp;cd=1&amp;amp;n=/podcast=&amp;amp;vcon=/searchUnifiedCommunications/podcasts&amp;amp;hec=0&amp;amp;vjs=HBX0200u&amp;amp;fn=http://media.techtarget.com/audioCast/NETWORKING/021609_realitycheck_EH.mp3&amp;amp;target=http://media.techtarget.com/audioCast/NETWORKING/021609_realitycheck_EH.mp3"&gt;clicking here&lt;/a&gt;.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://evangelyze.net/cs/aggbug.aspx?PostID=163" width="1" height="1"&gt;</content><author><name>tony</name><uri>http://evangelyze.net/cs/members/tony/default.aspx</uri></author><category term="VoIP" scheme="http://evangelyze.net/cs/blogs/tony/archive/tags/VoIP/default.aspx" /><category term="unified communications" scheme="http://evangelyze.net/cs/blogs/tony/archive/tags/unified+communications/default.aspx" /><category term="PBX" scheme="http://evangelyze.net/cs/blogs/tony/archive/tags/PBX/default.aspx" /><category term="podcast" scheme="http://evangelyze.net/cs/blogs/tony/archive/tags/podcast/default.aspx" /><category term="Reality Check" scheme="http://evangelyze.net/cs/blogs/tony/archive/tags/Reality+Check/default.aspx" /><category term="IP PBX" scheme="http://evangelyze.net/cs/blogs/tony/archive/tags/IP+PBX/default.aspx" /><category term="searchunifiedcommunications" scheme="http://evangelyze.net/cs/blogs/tony/archive/tags/searchunifiedcommunications/default.aspx" /></entry><entry><title>Microsoft Voice and Unified Communications</title><link rel="alternate" type="text/html" href="/cs/blogs/tony/archive/2009/02/22/microsoft-voice-and-unified-communications.aspx" /><link rel="enclosure" type="audio/mpeg" length="9902384" href="http://www.informit.com/content/podcasts/8/Joe_Schurman.mp3" /><id>/cs/blogs/tony/archive/2009/02/22/microsoft-voice-and-unified-communications.aspx</id><published>2009-02-23T04:39:00Z</published><updated>2009-02-23T04:39:00Z</updated><content type="html">&lt;p&gt;Joe Schurman, my friend and the Founder and CEO of &lt;a href="http://evangelyze.net/"&gt;Evangelyze Communications&lt;/a&gt;, wrote a book which just hit the shelves this week: &lt;a href="http://www.whatdouc.com/"&gt;Microsoft Voice and Unified Communications&lt;/a&gt;. The book is an excellent primer on unified communications combined with visionary insight on the direction and future of unified communications from someone who has been in the VoIP / unified communications trenches since they were first dug. I did a more in depth review of the book which &lt;a href="http://itknowledgeexchange.techtarget.com/connectivity/book-review-microsoft-voice-and-unified-communications/"&gt;you can read here&lt;/a&gt;. &lt;/p&gt;
&lt;p&gt;There is a &lt;a href="http://www.whatdouc.com/Chapter_1.pdf"&gt;sample chapter&lt;/a&gt; available for download from &lt;a href="http://www.whatdouc.com/"&gt;WhatDoUC.com&lt;/a&gt;. I also highly recommend that you listen to the &lt;a href="http://www.informit.com/content/podcasts/8/Joe_Schurman.mp3"&gt;podcast interview&lt;/a&gt; Joe did with &lt;a href="http://blogs.technet.com/eileen_brown/"&gt;Eileen Brown&lt;/a&gt; for &lt;a href="http://www.informit.com/podcasts/channel.aspx?c=3761c00b-ef8f-4385-9b08-a6e1c7a9a35f"&gt;OnMicrosoft&lt;/a&gt;. &lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://evangelyze.net/cs/aggbug.aspx?PostID=162" width="1" height="1"&gt;</content><author><name>tony</name><uri>http://evangelyze.net/cs/members/tony/default.aspx</uri></author><category term="podcast" scheme="http://evangelyze.net/cs/blogs/tony/archive/tags/podcast/default.aspx" /><category term="Microsoft Voice and Unified Communications" scheme="http://evangelyze.net/cs/blogs/tony/archive/tags/Microsoft+Voice+and+Unified+Communications/default.aspx" /><category term="Joe Schurman" scheme="http://evangelyze.net/cs/blogs/tony/archive/tags/Joe+Schurman/default.aspx" /><category term="Eileen Brown" scheme="http://evangelyze.net/cs/blogs/tony/archive/tags/Eileen+Brown/default.aspx" /><category term="whatdouc.com" scheme="http://evangelyze.net/cs/blogs/tony/archive/tags/whatdouc.com/default.aspx" /><category term="OnMicrosoft" scheme="http://evangelyze.net/cs/blogs/tony/archive/tags/OnMicrosoft/default.aspx" /></entry><entry><title>The Future of Unified Communications</title><link rel="alternate" type="text/html" href="/cs/blogs/tony/archive/2009/02/22/the-future-of-unified-communications.aspx" /><link rel="enclosure" type="audio/mpeg" length="57637377" href="http://www.evangelyze.net/media/audiocasts/TechTalk011809.mp3" /><id>/cs/blogs/tony/archive/2009/02/22/the-future-of-unified-communications.aspx</id><published>2009-02-23T03:54:00Z</published><updated>2009-02-23T03:54:00Z</updated><content type="html">&lt;p&gt;On&amp;nbsp;January 18, 2009&amp;nbsp;I &lt;a href="http://techtalk.imi-us.com/Archives/2008/20080210/"&gt;&lt;span style="color:#003399;"&gt;appeared as a guest&lt;/span&gt;&lt;/a&gt; on the &lt;a href="http://techtalk.imi-us.com/"&gt;&lt;span style="color:#003399;"&gt;IMI-TechTalk radio show&lt;/span&gt;&lt;/a&gt;. Tom D&amp;#39;Auria, CEO of Information Methods Incorporated (IMI), and I talked about the&amp;nbsp;future of &lt;a href="http://www.microsoft.com/uc/Default.mspx"&gt;Unified Communications&lt;/a&gt;.&amp;nbsp;I provided a brief overview of what unified communications is and what the current market looks like. We then talked about whether or not companies still need to have a PBX and some of the advantages and benefits that software-powered voice delivers. We wrapped up by talking about where unified communications is heading and discussing some of the &lt;a href="http://evangelyze.net/products.asp"&gt;innovative tools&lt;/a&gt; that &lt;a href="http://evangelyze.net/index.asp"&gt;Evangelyze Communications&lt;/a&gt; has developed to extend the functionality of Microsoft Office Communications Server.&amp;nbsp;IMI-TechTalk is broadcast by &lt;a href="http://www.1100kfnx.com/"&gt;&lt;span style="color:#003399;"&gt;KFNX AM 1100&lt;/span&gt;&lt;/a&gt; out of Phoenix, AZ every Sunday. It is also available as streaming audio via the Web so you can listen to the show no matter how far you are from Phoenix. &lt;/p&gt;
&lt;p&gt;Click on the &amp;#39;&lt;a href="http://www.evangelyze.net/media/audiocasts/TechTalk011809.mp3"&gt;&lt;span style="color:#003399;"&gt;attachment&lt;/span&gt;&lt;/a&gt;&amp;#39;&amp;nbsp;link below to listen to the Microsoft&amp;nbsp;Response Point&amp;nbsp;show from&amp;nbsp;January of 2009.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://evangelyze.net/cs/aggbug.aspx?PostID=161" width="1" height="1"&gt;</content><author><name>tony</name><uri>http://evangelyze.net/cs/members/tony/default.aspx</uri></author><category term="unified communications" scheme="http://evangelyze.net/cs/blogs/tony/archive/tags/unified+communications/default.aspx" /><category term="Tom D'Auria" scheme="http://evangelyze.net/cs/blogs/tony/archive/tags/Tom+D_2700_Auria/default.aspx" /><category term="KFNX AM 1100" scheme="http://evangelyze.net/cs/blogs/tony/archive/tags/KFNX+AM+1100/default.aspx" /><category term="IMI-TechTalk" scheme="http://evangelyze.net/cs/blogs/tony/archive/tags/IMI-TechTalk/default.aspx" /><category term="Microsoft" scheme="http://evangelyze.net/cs/blogs/tony/archive/tags/Microsoft/default.aspx" /><category term="software-powered voice" scheme="http://evangelyze.net/cs/blogs/tony/archive/tags/software-powered+voice/default.aspx" /><category term="PBX" scheme="http://evangelyze.net/cs/blogs/tony/archive/tags/PBX/default.aspx" /></entry><entry><title>Microsoft Response Point</title><link rel="alternate" type="text/html" href="/cs/blogs/tony/archive/2009/02/22/microsoft-response-point.aspx" /><link rel="enclosure" type="audio/mpeg" length="48070980" href="http://www.evangelyze.net/media/audiocasts/TechTalk042708.mp3" /><id>/cs/blogs/tony/archive/2009/02/22/microsoft-response-point.aspx</id><published>2009-02-23T03:29:00Z</published><updated>2009-02-23T03:29:00Z</updated><content type="html">&lt;p&gt;On&amp;nbsp;April 27, 2008 I &lt;a href="http://techtalk.imi-us.com/Archives/2008/20080210/"&gt;&lt;span style="color:#003399;"&gt;appeared as a guest&lt;/span&gt;&lt;/a&gt; on the &lt;a href="http://techtalk.imi-us.com/"&gt;&lt;span style="color:#003399;"&gt;IMI-TechTalk radio show&lt;/span&gt;&lt;/a&gt;. Tom D&amp;#39;Auria, CEO of Information Methods Incorporated (IMI), and I talked about the &lt;a href="http://www.microsoft.com/responsepoint/default.aspx"&gt;Microsoft Response Point&lt;/a&gt; phone system.&amp;nbsp;I provided an overview of what Microsoft Response Point is and how it enables small and medium businesses to get enterprise-class communications and features on an SMB budget.&amp;nbsp;IMI-TechTalk is broadcast by &lt;a href="http://www.1100kfnx.com/"&gt;&lt;span style="color:#003399;"&gt;KFNX AM 1100&lt;/span&gt;&lt;/a&gt; out of Phoenix, AZ every Sunday. It is also available as streaming audio via the Web so you can listen to the show no matter how far you are from Phoenix. &lt;/p&gt;
&lt;p&gt;Click on the &amp;#39;&lt;a href="http://www.evangelyze.net/media/audiocasts/TechTalk042708.mp3"&gt;&lt;span style="color:#003399;"&gt;attachment&lt;/span&gt;&lt;/a&gt;&amp;#39;&amp;nbsp;link below to listen to the Microsoft&amp;nbsp;Response Point&amp;nbsp;show from&amp;nbsp;April of 2008.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://evangelyze.net/cs/aggbug.aspx?PostID=160" width="1" height="1"&gt;</content><author><name>tony</name><uri>http://evangelyze.net/cs/members/tony/default.aspx</uri></author><category term="unified communications" scheme="http://evangelyze.net/cs/blogs/tony/archive/tags/unified+communications/default.aspx" /><category term="Tom D'Auria" scheme="http://evangelyze.net/cs/blogs/tony/archive/tags/Tom+D_2700_Auria/default.aspx" /><category term="KFNX AM 1100" scheme="http://evangelyze.net/cs/blogs/tony/archive/tags/KFNX+AM+1100/default.aspx" /><category term="IMI-TechTalk" scheme="http://evangelyze.net/cs/blogs/tony/archive/tags/IMI-TechTalk/default.aspx" /><category term="Microsoft" scheme="http://evangelyze.net/cs/blogs/tony/archive/tags/Microsoft/default.aspx" /><category term="Response Point" scheme="http://evangelyze.net/cs/blogs/tony/archive/tags/Response+Point/default.aspx" /></entry></feed>