<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>$words[rand()] &#187; VoIP</title>
	<atom:link href="http://seanharlow.info/category/work/voip/feed/" rel="self" type="application/rss+xml" />
	<link>http://seanharlow.info</link>
	<description>Programming, politics, and pissed off rants...</description>
	<lastBuildDate>Mon, 14 Jun 2010 21:21:58 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0</generator>
<xhtml:meta xmlns:xhtml="http://www.w3.org/1999/xhtml" name="robots" content="noindex" />
		<item>
		<title>Potentially serious vulnerability in a number of SIP endpoints</title>
		<link>http://seanharlow.info/2009/04/11/potentially-serious-vulnerability-in-a-number-of-sip-endpoints/</link>
		<comments>http://seanharlow.info/2009/04/11/potentially-serious-vulnerability-in-a-number-of-sip-endpoints/#comments</comments>
		<pubDate>Sat, 11 Apr 2009 16:16:11 +0000</pubDate>
		<dc:creator>wolrah</dc:creator>
				<category><![CDATA[Geekery]]></category>
		<category><![CDATA[Networking]]></category>
		<category><![CDATA[Tech]]></category>
		<category><![CDATA[VoIP]]></category>
		<category><![CDATA[Work]]></category>

		<guid isPermaLink="false">http://seanharlow.info/?p=123</guid>
		<description><![CDATA[Sjur Usken and Sandro Gauci have discovered a major flaw in the SIP implementations on a wide range of IP phones. The short explanation is that the phones do not verify where a proxy authentication request is coming from and happily return the SIP authentication information. It is hashed and salted, but the salt is [...]]]></description>
			<content:encoded><![CDATA[<img style='float: left; margin-right: 10px; border: none;' src='http://www.gravatar.com/avatar.php?gravatar_id=b74ece40b0ed98a2f2a63f3437d93547&amp;default=http://use.perl.org/images/pix.gif' alt='No Gravatar' width=40 height=40/><p><a href="http://www.usken.no/">Sjur Usken</a> and <a href="http://enablesecurity.com/blog/">Sandro Gauci</a> have discovered a major flaw in the SIP implementations on a wide range of IP phones.  The short explanation is that the phones do not verify where a proxy authentication request is coming from and happily return the SIP authentication information.  It is hashed and salted, but the salt is chosen by the attacker, so a set of rainbow tables would make cracking it trivial.  For full details, check out <a href="http://www.usken.no/2009/03/26/get-the-password-from-any-sip-device-its-fully-possible/">Sjur’s blog post</a> (which spread fairly rapidly around the VoIP world) and his <a href="http://www.usken.no/2009/04/11/and-the-cisc-7940-phones-leaks-its-password-hash/">latest post</a> showing the trace as he attacked a Cisco 7940 I set up for this purpose.</p>
<p>Until the phone vendors release fixed firmware (if they do) the only way to defend yourself from this is to not have phones exposed on public IP addresses.  If they have to be for some reason (we all know SIP and NAT really don’t get along, and proper SIP aware NAT devices cost a fair bit) set firewall rules that prevent the phones from speaking SIP to any IPs that aren’t part of your VoIP system.  Alternatively, in the event that every single phone on your system is statically addressed, the reverse could be done at the registrar side.  It wouldn’t stop the attackers from finding the password, but it would prevent them from using it in any way.</p>
<p>The implications of an attacker gaining the SIP authentication information are of course severe, once they have that they can imitate the attacked phone and make calls to any number of regions potentially costing thousands of dollars in the course of a single night. </p>
]]></content:encoded>
			<wfw:commentRss>http://seanharlow.info/2009/04/11/potentially-serious-vulnerability-in-a-number-of-sip-endpoints/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Damn, it’s been a while…</title>
		<link>http://seanharlow.info/2008/05/11/damn-its-been-a-while/</link>
		<comments>http://seanharlow.info/2008/05/11/damn-its-been-a-while/#comments</comments>
		<pubDate>Mon, 12 May 2008 01:09:50 +0000</pubDate>
		<dc:creator>wolrah</dc:creator>
				<category><![CDATA[325i]]></category>
		<category><![CDATA[Boredom Killers]]></category>
		<category><![CDATA[Cars]]></category>
		<category><![CDATA[Probe]]></category>
		<category><![CDATA[VoIP]]></category>
		<category><![CDATA[Work]]></category>

		<guid isPermaLink="false">http://www.seanharlow.info/2008/05/11/damn-its-been-a-while/</guid>
		<description><![CDATA[It’s been quite some time since I last posted… Here’s a quick summary of what’s gone on in my life: The bastard Probe is still in the garage, status really unchanged since August. I got bored after doing an install in Columbus and wandered in to a used car dealer.Â  Somehow I drove home in [...]]]></description>
			<content:encoded><![CDATA[<img style='float: left; margin-right: 10px; border: none;' src='http://www.gravatar.com/avatar.php?gravatar_id=b74ece40b0ed98a2f2a63f3437d93547&amp;default=http://use.perl.org/images/pix.gif' alt='No Gravatar' width=40 height=40/><p>It’s been quite some time since I last posted…</p>
<p>Here’s a quick summary of what’s gone on in my life:</p>
<ul>
<li>The bastard Probe is still in the garage, status really unchanged since August.</li>
<li>I got bored after doing an install in Columbus and wandered in to a used car dealer.Â  Somehow I drove home in a 2002 BMW 325i…</li>
<li>Charlie and Mary both quit at MV (this was over the course of a few months, not at the same time), which threw me in to a situation I really did not want to be in.Â  I kinda paniced and nearly quit to do contract work.Â  Fortunately, when I went to discuss my 2 weeks the boss offered me a significant raise, and after sleeping on it I decided sticking with what I knew and continuing to ride out the bad towards the good (which seems to be getting closer) was the better plan.</li>
<li>My parents moved to Virginia, making me the primary “support” for my brother when he’s in Toledo at school.</li>
</ul>
<p>I might go in to detail on some of those later.Â  Anyways, what I came to post follows:</p>
<p>I’ve been getting in to a few blogs recently, and this one I just discovered today.Â  All I’ve read so far is interesting and well written, here’s a few favorites in no particular order…</p>
<p><a href="http://www.violentacres.com/archives/319/just-say-no-to-bastard-children">http://www.violentacres.com/archives/319/just-say-no-to-bastard-children</a></p>
<p><a href="http://www.violentacres.com/archives/59/two-phrases-that-destroyed-american-culture">http://www.violentacres.com/archives/59/two-phrases-that-destroyed-american-culture</a></p>
<p><a href="http://www.violentacres.com/archives/48/four-rookie-mistakes-people-make-that-keep-them-poor">http://www.violentacres.com/archives/48/four-rookie-mistakes-people-make-that-keep-them-poor</a></p>
<p><a href="http://www.violentacres.com/archives/250/the-pentecostal-church-and-the-holy-ghost-want-you-to-wear-pig-panties">http://www.violentacres.com/archives/250/the-pentecostal-church-and-the-holy-ghost-want-you-to-wear-pig-panties</a></p>
<p><a href="http://www.violentacres.com/archives/279/a-pedophile-lurking-behind-every-dark-corner">http://www.violentacres.com/archives/279/a-pedophile-lurking-behind-every-dark-corner</a></p>
<p><em>edited for linkification…stupid wordpress, what else does it think i might want when I post a URL?</em></p>
]]></content:encoded>
			<wfw:commentRss>http://seanharlow.info/2008/05/11/damn-its-been-a-while/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
