VoIP Providers
advertise with voip providers
VoIP Articles
Cisco VoIP bug poses eavesdropping risk 2007-11-30
A bug involving 7900 Series IP phones from Cisco creates a means for hackers to eavesdrop on calls.

The flaw stems from security shortcomings in the Extension Mobility feature of the phones, which allows users to configure a Cisco IP phone as their own. The feature is disabled by support, which is just as well because when enabled the feature fails to encrypt signalling communications between a device and an internal web server. This, in turn, creates a means for miscreants to sniff out authentication credentials. These credentials might subsequently be misused to cut off users or eavesdrop on streaming media connections associated with calls.

However, an attack along these lines will only succeed in cases where would-be hackers are already in possession of valid Extension Mobility authentication credentials. Attackers would also need to have access to a targeted network. Although remote hacking is theoretically possible, a bigger danger would appear to stem from internal attacks.

In a throwback to the early days of wiretapping, successful attacks based on the vulnerability leave a tell-tale noise on the wire.

"Internal testing by Cisco also revealed that the described attack produced static noise on the IP phone while it was under attack," Cisco said in an advisory that explains the issue and details possible workarounds.

The network giant credits researcher Joffrey Czarney of Telindus with discovering the flaw. Czarney presented a paper on his research at the recent Hack.Lu 2007 security conference, which was held last month in Luxembourg.

By John Leyden
VoIP Providers List Information
If you have any constructive thoughts, creative ideas, or reasonable offers, please, contact us.
Send Email to Helen O'Neill if you have any questions either about this website, or about VoIP providers, or VoIP in general.
Send Email to our technical support if you have any technical queries.
About VoIP Providers List
VoIP Providers List services save time for companies searching both for information and interconnection partners, interested in voice minutes exchange, i.e. VoIP minutes termination and origination, as well as hardware and software trade. We provide information on interconnection services, VoIP hardware solutions and VoIP software , as well as overall situation in the VoIP industry.
VoIP Providers List is constantly moderated, and thus we can guarantee that any VoIP provider published in the web-based company catalogue has provided accurate details on its services and operations.
We are constantly working on improvement and development of our services. Your comments and proposals regarding the services are highly welcome. Please, do not hesitate to contact us providing with your ideas, opinion, and feed-back. We will be grateful for any information and useful links on Voice over IP, VoIP hardware, VoIP software, and VoIP Providers.
 
VoIP Providers Statistics
Providers in database: 3315
Users Online: 254
VoIP Articles
Getting Real About VoIP
Getting Real About VoIP
VOIP Service: Sign Up And Save
VOIP Service: Sign Up And Save
VoIP Providers The Top 7
VoIP Providers The Top 7
Power-Intensive VoIP Equipment Requires Proper Power Precautions
Power-Intensive VoIP Equipment Requires Proper Power Precautions
Google Talk Creates Universally Available VOiP Service
Google Talk Creates Universally Available VOiP Service
Read more articles
Newest VoIP Providers
1. Perusat [Peru] 2. Heswick [Switzerland] 3. OpenIP [France] 4. Acacia Voiceline [Belize] 5. SC Eurofon Srl [Romania] 6. NICnet [Philippines] 7. Trombatel co Ltd [Thailand] 8. Capratel Inc. [USA] 9. AJ-TEL Communications Network [Mexico] 10. Todoservicio [Colombia]