Snom VoIP vulnerability resolved

Snom 320After my Snom VoIP phone hacked article, I received a response from snom indicating that the vulnerability had more to do with a user not setting a password on the IP phone than any sort of bug or vulnerability in the snom firmware itself. Well that's certainly good news. I guess users or IT administrators that don't set passwords on the IP phones have only themselves to blame if their phones are hacked.

This direct from Snom...

CVE-2008-1248:
Yes, you can send an HTTP-POST to the phone and let it dial a number. But you can protect your phone by setting a password. If you set a password then nobody can post an HTTP request to dial a number. The statement in the referred web site that Snom phone don't support passwords is wrong. You can set a password to protect your phone. And you should do it if your phone is connected to the Internet directly.

Our next firmware release will warn the user that no password is set and that his phone is vulnerable.

This is not a real vulnerability, so we can't say a particular firmware is affected, since you can avoid it by setting a password

CVE-2008-1249:
Yes, this is possible right now when the flash plugin is enabled. But the flash plugin is not enabled by default in current firmwares. So a phone is not vulnerable unless you enable the flash plugin. But you can protect your phone by setting a password like for CVE-2008-1248.

Our next firmware release will warn the user that no password is set and that his phone is vulnerable.

Our release after the next will change the flash plugin so that this isn't possible any more.

This is not a real vulnerability, so we can't say a particular firmware is affected, since you can avoid it by setting a password

CVS-2008-1250:
Yes, Snom phone are vulnerable to cross-site request forgery (CSRF). All firmware up to V7.1.30 are affected.

We have changed our web frontend. It uses tokens and html-encoding for values entered in input fields now. Our next firmware release will not be vulnerable to CSRF any more.

CVS-2008-1251:
Yes, Snom phone are vulnerable to Cross-site scripting (XSS). All firmware up to V7.1.30 are affected.

We have changed our web frontend. It uses tokens and html-encoding for values entered in input fields now. Our next firmware release will not be vulnerable to XSS any more.

We also created a website:
http://www.snom.com/javascriptsecurity.html
| 2 Comments | 0 TrackBacks

Listed below are links to sites that reference Snom VoIP vulnerability resolved:

Snom VoIP vulnerability resolved TrackBack URL : http://blog.tmcnet.com/mt/mt-tb.cgi/35648

2 Comments

Yes, of course setting the password protects the phones from getting hacked. Its good to have passwords especially for the phones having snom VoIP. This should be done carefully.

It is a necessary to set passwords to your IP because if not they can be hacked and we face lots of problems.

Leave a comment

Recent Activity

Today

  • Tom Keating queued The Blind Side

Sunday

Sunday

  • Tom Keating tweeted, "Moving a Data Center: Moving a data center can be fun. Yes, if you enjoy being up from 6am (Friday) to 2am (Satur... http://bit.ly/cX6L0j"
  • Tom Keating posted Moving a Data Center

Friday

  • Tom Keating tweeted, "Tearing down TMC's entire network infrastructure. My sweet beautiful network! [sniff] [sniff]"

Thursday

  • Tom Keating tweeted, "why the heck am I still awake when I have an all-nighter tomorrow moving the entire #TMCNet data center? (www.tmcnet.com) fun fun!"
  • Tom Keating tweeted, "No, Gremlins Didn't Eat TMCNet's Web Servers: Starting tomorrow around 7am, TMC will be shutting down its entire d... http://bit.ly/bS3OOn"

More...

Recent Comments

  • Peter Radizeski: I'm not certain that is accurate. The staff for VON read more
  • טכנאי מחשבים: Fast, organized, thorough, non-intrusive, and free! THANKS AVG. read more
  • SomeGuy: I've had sipgate setup for less than 24 hours on read more
  • Uverse instaler: Being a uverse installer in the StL area, I can read more
  • Roger: Dan did you find out what the music is?? I read more
  • VoIP Spear: I don't think this site is active anymore. You can read more
  • Mamrez: Hi guys , I'm looking for cracked MOBILELOG for iphone read more
  • Symplicity: Works amazing thanks :) read more
  • wirefly customer: I got my phone from wirefly and it turned out read more
  • Maher: Dear Sir, I am looking for a slim credit card read more

Subscribe to Blog

Recent Entry Images

  • apple-ipad.jpg
  • google-nexus-one.jpg
  • freetalk-connect.jpg
  • freetalk-connect.jpg
  • calliflower-skype.jpg
  • itexpo-logo.jpg

Entry Archives

Around TMCnet Blogs

  • Communications and Technology Blog - Tehrani.com:
    Apple Antitrust Issues
  • On Rad's Radar?:
    Endstream Plans
  • VoIP & Gadgets Blog:
    Moving a Data Center
  • Communications and Technology Blog - Tehrani.com:
    IfByPhone Interview ITEXPO East 2010 Miami
  • First Coffee:
    Frost & Sullivan Webcast, LCEC and ENERGYprism, IDC for
  • On Rad's Radar?:
    Freeside's new CEO
  • The Readerboard:
    Tune In, Call in (And Donate), 'Hope for Haiti
  • VoIP & Gadgets Blog:
    No, Gremlins Didn't Eat TMCNet's Web Servers
  • Latest Whitepapers

    TMCnet Videos