SPIT and Spam DDoS - Fact or Fiction?

Spit and SpamI've written about SPIT or "Spam over Internet Telephony" a few times in the past. Well, now I have a story to share that Dan York shared with me about SPIT leveraging DDoS (Distributed Denial of Service) attacks to bring down a competitor.

The story begins...
ZZZ Telemarketing (not a real name) is locked in a heated fight with their bitter rival, YYY Telemarketing (also not a real name), to win a very large lead generation contract with Customer X. Customer X has decided to run a test pitting the two companies against each other for a week to see who can generate the most leads. The ZZZ CEO has said to his staff that it is “do or die” for the company. If they fail to win the contract, they will have to shut down - they need to do “whatever it takes” to win over YYY. A ZZZ staffer discovers that part of why YYY has consistently underbid them is because they are using SIP trunks to reduce their PSTN connection costs. But the staffer also discovers that YYY is using very cheap voice service providers who run over the public Internet with no security. continued...

Let me give you the Cliff Notes on the rest of the story.
- Bots on tens of thousands of zombie PCs are instructed to start slamming the SIP servers at YYY and its providers with enormous numbers of bogus SIP messages
- This "VoIP botnet" attacks and paralyzes YYY’s SIP server preventing calls from going though.
- Company ZZZ wins the contract since Company YYY was unable to make calls.

Fact or fiction?

According to Dan York, an expert on VoIP security, it's FACT. I didn't include the full story that appears on Dan's website, since I didn't want to steal his thunder, but go read it. It's an excellent and thought-provoking read.

Just as scary, Dan told me, "The sample code actually works well... I ran it on a Windows PC connected out to an IRC chat room and then issued commands."

Welcome to the era of "SPIT and Spam DDoS" to bring down your competitors!
| 0 Comments | 0 TrackBacks

Listed below are links to sites that reference SPIT and Spam DDoS - Fact or Fiction?:

SPIT and Spam DDoS - Fact or Fiction? TrackBack URL : http://blog.tmcnet.com/mt/mt-tb.cgi/32462

Leave a comment

Recent Activity

Saturday

  • Tom Keating tweeted, "Spending 4th of July with in-laws on their lake-side house. Coming soon - fireworks!"

Friday

  • Tom Keating queued Star Trek
  • Tom Keating queued Stardust
  • Tom Keating queued The Fountain

Thursday

More...

Recent Comments

  • ctjames: Yes , I've tried several times by using Cydia installed read more
  • http://openid.aol.com/drdaraban: Yes, I confirm antonioj's comment, both skype and the app read more
  • cmytroops: I was browsing the net and cam across a great read more
  • mike: Sorry if this is off topic but I’m thinking of read more
  • @NumberGarage: Our military service men and women should be driving new read more
  • https://www.google.com/accounts/o8/id?id=AItOawlacBYIyCFI8mz5HS_pdsnSDV1wLz6Vgc8: We have implemented over 50 VoIP systems in the last read more
  • Theo Barton: Its a good phone. I have had a lot of read more
  • https://me.yahoo.com/a/ea7WMvNu2Mlud7dBwQPAAus9JCfo9qE-#27391: I don't want to go through all the problems, I read more
  • Claudio G.: I contacted these folks via e-mail recently (June 2009)and they read more
  • Kinjudah De- Morgan: I am using a strong satelite receiver and a Gateway read more

Subscribe to Blog

    View my Microsoft MVP Profile:

Blogroll

Entry Archives

Around TMCnet Blogs

  • Communications and Technology Blog - Tehrani.com:
    Problems at Joost
  • On Rad's Radar?:
    USF and Rural Reform
  • VoIP & Gadgets Blog:
    Worst Google News Headline Ever! - No public viewing
  • Communications and Technology Blog - Tehrani.com:
    Heading to Rhode Island
  • First Coffee:
    SugarCRM Studied, Broadband 'Crucial,' EGain, OOCOSPI, NetSuite's Zander
  • On Rad's Radar?:
    Bells Giving Up on Landlines?
  • The Readerboard:
    Tougher Actions To Save Telemarketing
  • VoIP & Gadgets Blog:
    eBuddy for iPhone Supports Push Notifications
  • Latest Whitepapers

    TMCnet Videos