<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://evangelyze.net/cs/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Tony's Blog : vulnerabilities</title><link>http://evangelyze.net/cs/blogs/tony/archive/tags/vulnerabilities/default.aspx</link><description>Tags: vulnerabilities</description><dc:language>en</dc:language><generator>CommunityServer 2008.5 SP2 (Debug Build: 40407.4157)</generator><item><title>VoIP Service Theft Fugitive Captured</title><link>http://evangelyze.net/cs/blogs/tony/archive/2009/02/11/voip-service-theft-fugitive-captured.aspx</link><pubDate>Wed, 11 Feb 2009 20:26:00 GMT</pubDate><guid isPermaLink="false">e99d0b66-7c3d-48f6-a7f8-df8f414b967b:151</guid><dc:creator>tony</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://evangelyze.net/cs/blogs/tony/rsscomments.aspx?PostID=151</wfw:commentRss><comments>http://evangelyze.net/cs/blogs/tony/archive/2009/02/11/voip-service-theft-fugitive-captured.aspx#comments</comments><description>&lt;p&gt;Edward Pena was arrested in Mexico yesterday. Pena was originally charged in 2006 with computer fraud and wire fraud for &lt;a href="http://www.computerworld.com/action/article.do?command=viewArticleBasic&amp;amp;taxonomyName=security&amp;amp;articleId=9127718"&gt;selling stolen VoIP service&lt;/a&gt;. Working with his partner Robert Moore, the two scanned networks to find open or poorly secured VoIP systems. Moore would deliver the information to Pena and Pena in turn used the information to sell more than 10 million stolen minutes of VoIP service from 15 different VoIP providers.&lt;/p&gt;
&lt;p&gt;Pena&amp;#39;s lucrative criminal enterprise netted him more than $1 million, enabling him to live a lavish lifestyle. Pena purchased real estate in Miami, a 40-foot Sea Ray Mercruiser boat, and a BMW M3 among other things with his ill-gotten gains.&lt;/p&gt;
&lt;p&gt;Pena has been on the run for the past couple of years. Now that he has been apprehended he faces up to 25 years in prison. In this case justice will apparently be served. I am not sure however if any of the 15 victimized entities will be able to recover any of the income they lost in paying for the 10 million stolen minutes of VoIP service. &lt;/p&gt;
&lt;p&gt;It is important that organizations understand the threats that exist to VoIP systems, and the security best practices necessary to protect against them. Performing a VoIP security assessment is the first step to ensuring that your VoIP system isn&amp;#39;t targeted by the next &amp;#39;Pena&amp;#39; that comes along.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://evangelyze.net/cs/aggbug.aspx?PostID=151" width="1" height="1"&gt;</description><category domain="http://evangelyze.net/cs/blogs/tony/archive/tags/VoIP/default.aspx">VoIP</category><category domain="http://evangelyze.net/cs/blogs/tony/archive/tags/VoIP+security/default.aspx">VoIP security</category><category domain="http://evangelyze.net/cs/blogs/tony/archive/tags/vulnerabilities/default.aspx">vulnerabilities</category><category domain="http://evangelyze.net/cs/blogs/tony/archive/tags/best+practices/default.aspx">best practices</category><category domain="http://evangelyze.net/cs/blogs/tony/archive/tags/VoIP+security+assessment/default.aspx">VoIP security assessment</category><category domain="http://evangelyze.net/cs/blogs/tony/archive/tags/threats/default.aspx">threats</category><category domain="http://evangelyze.net/cs/blogs/tony/archive/tags/theft/default.aspx">theft</category></item><item><title>IBM Reports Increase in VoIP Vulnerabilities</title><link>http://evangelyze.net/cs/blogs/tony/archive/2009/02/06/ibm-reports-increase-in-voip-vulnerabilities.aspx</link><pubDate>Fri, 06 Feb 2009 14:36:00 GMT</pubDate><guid isPermaLink="false">e99d0b66-7c3d-48f6-a7f8-df8f414b967b:148</guid><dc:creator>tony</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://evangelyze.net/cs/blogs/tony/rsscomments.aspx?PostID=148</wfw:commentRss><comments>http://evangelyze.net/cs/blogs/tony/archive/2009/02/06/ibm-reports-increase-in-voip-vulnerabilities.aspx#comments</comments><description>&lt;p&gt;The most recent &lt;a href="http://arstechnica.com/security/news/2009/02/malware-economics-web-security-major-issues-in-2008.ars"&gt;IBM X-Force report&lt;/a&gt; provides a lot of insight into the state of network security and malware, including some bad news for VoIP (Voice over IP). The report which summarizes IBM&amp;#39;s findings from 2008 and illustrates some trends and predictions of what to expect for 2009 is a valuable source of information. Among other tidbits (like an overall increase of 13.5% in discovered vulnerabilities, but a 50% drop in &amp;#39;Critical&amp;#39; vulnerabilities from 2007) is the news that IBM reported a 49% increase in client-side vulnerabilities for VoIP.&lt;/p&gt;
&lt;p&gt;The report states &amp;quot;As we mentioned, client-side vulnerabilities trended downwards in 2008, though VOIP clients were a notable exception; the total number of VOIP client flaws rose 49 percent over the past 12 months.&amp;quot; &lt;/p&gt;
&lt;p&gt;Take a look at the complete &lt;a href="http://www-935.ibm.com/services/us/iss/xforce/trendreports/xforce-2008-annual-report.pdf"&gt;IBM Internet Security Systems X-Force 2008 Trend &amp;amp; Risk Report&lt;/a&gt; to learn more about what 2008 looked like and what the trends are for 2009. In particular though, pay attention to the trends for VoIP and unified communications security. VoIP and UC are reaching that critical mass where attackers are&amp;nbsp;going to find&amp;nbsp;them to be increasingly attractive targets. Once attackers come up with a solid model for generating revenue from VoIP and UC exploits (aside from toll fraud), many companies are going to find that their VoIP and UC security measures are not adequate to protect them.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://evangelyze.net/cs/aggbug.aspx?PostID=148" width="1" height="1"&gt;</description><category domain="http://evangelyze.net/cs/blogs/tony/archive/tags/VoIP/default.aspx">VoIP</category><category domain="http://evangelyze.net/cs/blogs/tony/archive/tags/VoIP+security/default.aspx">VoIP security</category><category domain="http://evangelyze.net/cs/blogs/tony/archive/tags/unified+communications/default.aspx">unified communications</category><category domain="http://evangelyze.net/cs/blogs/tony/archive/tags/unified+communications+security/default.aspx">unified communications security</category><category domain="http://evangelyze.net/cs/blogs/tony/archive/tags/vulnerabilities/default.aspx">vulnerabilities</category><category domain="http://evangelyze.net/cs/blogs/tony/archive/tags/UC/default.aspx">UC</category><category domain="http://evangelyze.net/cs/blogs/tony/archive/tags/IBM+X-Force+report/default.aspx">IBM X-Force report</category></item><item><title>VoIP Security: The Basics</title><link>http://evangelyze.net/cs/blogs/tony/archive/2009/02/05/voip-security-the-basics.aspx</link><pubDate>Thu, 05 Feb 2009 19:34:00 GMT</pubDate><guid isPermaLink="false">e99d0b66-7c3d-48f6-a7f8-df8f414b967b:145</guid><dc:creator>tony</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://evangelyze.net/cs/blogs/tony/rsscomments.aspx?PostID=145</wfw:commentRss><comments>http://evangelyze.net/cs/blogs/tony/archive/2009/02/05/voip-security-the-basics.aspx#comments</comments><description>&lt;p&gt;It is no secret that VoIP is a popular and growing technology. VoIP, and its bigger, more converged, and feature-rich brother, unified communications, represent a significant shift in communications technology and a quantum evolution in how businesses leverage communications to improve productivity and increase efficiency. Bottom line- businesses that don&amp;#39;t have it now will have it soon and new tools and technologies will continue to drive the adoption of VoIP and unified communications.&lt;/p&gt;
&lt;p&gt;VoIP security is frequently talked about, but it is rare to hear of actual VoIP attacks. From both a theoretical and practical point of view there are a number of vulnerabilities and weaknesses in various VoIP implementations, but I think that the attackers are still working out their &amp;#39;business model&amp;#39; and examining how to go from exploit to income. So far it seems like the most prevalent attacks are &lt;a href="http://www.evangelyze.net/cs/blogs/tony/archive/2009/01/25/voip-attack-rings-up-120-000-phone-bill.aspx"&gt;old-fashioned toll fraud attacks&lt;/a&gt; against VoIP systems. Without a strategy to monetize the attack, there is little incentive to execute one. Once the Internet criminals of the world figure out how to make money from VoIP exploits the gloves will be off. &lt;/p&gt;
&lt;p&gt;A &lt;a href="http://www.csoonline.com/article/478577/VoIP_Security_The_Basics?page=3"&gt;recent article in CSOOnline.com by Bob Bradley&lt;/a&gt; (Excellent last name! He must know what he is talking about), spells out some of the most prevalent security issues with VoIP, and some recommendations and best practices to guard against them. There are plenty of resources available, and a growing number of vendors and consulting companies dedicated to providing VoIP and unified communications security. It is the responsibility of CSO&amp;#39;s, CIO&amp;#39;s, and other IT mangement and security individuals to be informed about the threats and aware of the available mitigations and countermeasures to enure that their VoIP and unified communications environments are adequately protected.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://evangelyze.net/cs/aggbug.aspx?PostID=145" width="1" height="1"&gt;</description><category domain="http://evangelyze.net/cs/blogs/tony/archive/tags/VoIP/default.aspx">VoIP</category><category domain="http://evangelyze.net/cs/blogs/tony/archive/tags/VoIP+security/default.aspx">VoIP security</category><category domain="http://evangelyze.net/cs/blogs/tony/archive/tags/toll+fraud/default.aspx">toll fraud</category><category domain="http://evangelyze.net/cs/blogs/tony/archive/tags/unified+communications+security/default.aspx">unified communications security</category><category domain="http://evangelyze.net/cs/blogs/tony/archive/tags/vulnerabilities/default.aspx">vulnerabilities</category><category domain="http://evangelyze.net/cs/blogs/tony/archive/tags/best+practices/default.aspx">best practices</category><category domain="http://evangelyze.net/cs/blogs/tony/archive/tags/mitigation/default.aspx">mitigation</category></item></channel></rss>