New VoIP Security Problem

Tom Keating alerted to me a new phone hack which is for now targeting SNOM IP phones.

The big hack involves the ability of some VoIP phones to make phone calls from the Web interface using a simple web POST request. The Snom 32x supports this feature which along with some security vulnerabilities is what GNUCitizen exploited to have some real fun, like ya know, making an outbound call using a spoofed CallerID.

Hackers will need the IP address of the phone being targeted to launch the attack, but using a simple scanner they can use a cross-site scripting attack to hack the phone’s built-in management interface.

Illegal stuff a hacker can do:
  •  Steal the phone history from the logs including any other details attached to the calls via XHR.
  •  Poison the address book with a persistent XSS - the name is encoded correctly but not the phone number.
  • Inject a JavaScript worm to gain total control over the user by changing the visible output by performing XHR-CSRF attack.
  • Change the settings of registered phones, including the displayed text on the phone’s display.
But the scariest problem is that a hacker can monitor the victim by making a phone call to the attacker’s number who in turn will accept the call and record the incoming sound. Worst of all, the phone doesn’t give any noticeable feedback (ring tones, etc) while the victim is under surveillance and the victim pays for the call!

Over the years, the SNOM team has been quite innovative and their technology has always been solid. I would imagine the fix for this problem should be pretty easy to write and now they need to roll it out quickly to all the phones on the market.
| 0 Comments | 0 TrackBacks

Listed below are links to sites that reference New VoIP Security Problem:

0 TrackBacks

New VoIP Security Problem TrackBack URL : http://blog.tmcnet.com/mt/mt-tb.cgi/35092

Leave comment to New VoIP Security Problem article

Subscribe to Blog

October 2008

Sun Mon Tue Wed Thu Fri Sat
      1 2 3 4
5 6 7 8 9 10 11
12 13 14 15 16 17 18
19 20 21 22 23 24 25
26 27 28 29 30 31  

About this Entry

This page contains a single entry by Rich Tehrani published on February 12, 2008 4:32 PM.

What Caused the Blackberry Outage was the previous entry in this blog.

VoIP Inc. May Sue You Soon is the next entry in this blog.

Find recent content on the main index or look in the archives to find all content.

Yearly Archives

'04 '05 '06 '07 '08
  Jan Jan Jan Jan
  Feb Feb Feb Feb
  Mar Mar Mar Mar
Apr Apr Apr Apr Apr
May May May May May
Jun Jun Jun Jun Jun
Jul Jul Jul Jul Jul
Aug Aug Aug Aug Aug
Sep Sep Sep Sep Sep
Oct Oct Oct Oct Oct
Nov Nov Nov Nov  
Dec Dec Dec Dec  

Around TMCnet Blogs

Latest Whitepapers