<?xml version="1.0" encoding="UTF-8"?>
<feed xmlns="http://www.w3.org/2005/Atom" 
      xmlns:thr="http://purl.org/syndication/thread/1.0">
  <link rel="alternate" type="text/html" href="http://blog.tmcnet.com/blog/tom-keating/voip/snom-voip-vulnerability-resolved.asp" />
  <link rel="self" type="application/atom+xml" href="http://blog.tmcnet.com/blog/tom-keating/atom.xml" />
  <id>tag:blog.tmcnet.com,2016:/blog/tom-keating//4/tag:blog.tmcnet.com,2008:/blog/tom-keating//4.35750-</id>
  <updated>2016-03-16T17:59:03Z</updated>
  <title>Comments for Snom VoIP vulnerability resolved</title>
  <subtitle>VoIP &amp; Gadgets blog - Latest news in VoIP &amp; gadgets, wireless, mobile phones, reviews, &amp; opinions</subtitle>
  <generator uri="http://www.sixapart.com/movabletype/">Movable Type 4.38</generator>
  <entry>
    <id>tag:blog.tmcnet.com,2008:/blog/tom-keating//4.35750</id>
    <link rel="alternate" type="text/html" href="http://blog.tmcnet.com/blog/tom-keating/voip/snom-voip-vulnerability-resolved.asp" />
    <link rel="service.edit" type="application/atom+xml" href="http://blog.tmcnet.com/mt/mt-atom.cgi/weblog/blog_id=4/entry_id=35750" title="Snom VoIP vulnerability resolved" />
    <published>2008-03-31T15:13:36Z</published>
    <updated>2008-04-10T21:35:08Z</updated>
    <title>Snom VoIP vulnerability resolved</title>
    <summary>After my Snom VoIP phone hacked article, I received a response from snom indicating that the vulnerability had more to do with a user not setting a password on the IP phone than any sort of bug or vulnerability in...</summary>
    <author>
      <name>Tom Keating</name>
      <uri>http://blog.tmcnet.com/blog/tom-keating/</uri>
    </author>
    
    <category term="SIP" />
    
    <category term="TMCnet" />
    
    <category term="VoIP" />
    
    <content type="html" xml:lang="en" xml:base="http://blog.tmcnet.com/blog/tom-keating/">
      <![CDATA[<img align="right" src="http://blog.tmcnet.com/blog/tom-keating/images/snom-320.jpg" alt="Snom 320" />After my <a href="http://blog.tmcnet.com/blog/tom-keating/voip/snom-voip-phone-hacked.asp">Snom VoIP phone hacked article</a>, I received a response from snom indicating that the vulnerability had more to do with a user <strong>not setting a password</strong> on the IP phone than any sort of bug or vulnerability in the snom firmware itself. Well that's certainly good news. I guess users or IT administrators that <strong>don't set passwords</strong> on the IP phones have only themselves to blame if their phones are hacked.<br />
<br />
This direct from Snom...<br />
<br />
CVE-2008-1248:<br />
Yes, you can send an HTTP-POST to the phone and let it dial a number. But you can protect your phone by setting a password. If you set a password then nobody can post an HTTP request to dial a number. The statement in the referred web site that Snom phone don't support passwords is wrong. You can set a password to protect your phone. And you should do it if your phone is connected to the Internet directly.<br />
<br />
Our next firmware release will warn the user that no password is set and that his phone is vulnerable.<br />
<br />
This is not a real vulnerability, so we can't say a particular firmware is affected, since you can avoid it by setting a password<br />
<br />
CVE-2008-1249:<br />
Yes, this is possible right now when the flash plugin is enabled. But the flash plugin is not enabled by default in current firmwares. So a phone is not vulnerable unless you enable the flash plugin. But you can protect your phone by setting a password like for CVE-2008-1248.<br />
<br />
Our next firmware release will warn the user that no password is set and that his phone is vulnerable.<br />
<br />
Our release after the next will change the flash plugin so that this isn't possible any more.<br />
<br />
This is not a real vulnerability, so we can't say a particular firmware is affected, since you can avoid it by setting a password<br />
<br />
CVS-2008-1250:<br />
Yes, Snom phone are vulnerable to cross-site request forgery (CSRF). All firmware up to V7.1.30 are affected.<br />
<br />
We have changed our web frontend. It uses tokens and html-encoding for values entered in input fields now. Our next firmware release will not be vulnerable to CSRF any more.<br />
<br />
CVS-2008-1251:<br />
Yes, Snom phone are vulnerable to Cross-site scripting (XSS).  All firmware up to V7.1.30 are affected.<br />
<br />
We have changed our web frontend. It uses tokens and html-encoding for values entered in input fields now. Our next firmware release will not be vulnerable to XSS any more.<br />
<br />
We also created a website:<br />
<a href="http://www.snom.com/javascriptsecurity.html">http://www.snom.com/javascriptsecurity.html</a>]]>
      
    </content>
  </entry>

  <entry>
    <id>tag:blog.tmcnet.com,2008:/blog/tom-keating//4.35750-comment:35395</id>
    <thr:in-reply-to ref="tag:blog.tmcnet.com,2008:/blog/tom-keating//4.35750" type="text/html" href="http://blog.tmcnet.com/blog/tom-keating/voip/snom-voip-vulnerability-resolved.asp"/>
    <link rel="alternate" type="text/html" href="http://blog.tmcnet.com/blog/tom-keating/voip/snom-voip-vulnerability-resolved.asp#c35395" />
    <title>Comment from Mike on 2008-03-31</title>
    <author>
        <name>Mike</name>
        <uri>http://voip-services.topchoicereviews.com/</uri>
    </author>
    <content type="html" xml:lang="en" xml:base="http://voip-services.topchoicereviews.com/">
        <![CDATA[<p>Yes, of course setting the password protects the phones from getting hacked. Its good to have passwords especially for the phones having snom VoIP. This should be done carefully.</p>]]>
    </content>
    <published>2008-03-31T16:41:06Z</published>
  </entry>

  <entry>
    <id>tag:blog.tmcnet.com,2008:/blog/tom-keating//4.35750-comment:35437</id>
    <thr:in-reply-to ref="tag:blog.tmcnet.com,2008:/blog/tom-keating//4.35750" type="text/html" href="http://blog.tmcnet.com/blog/tom-keating/voip/snom-voip-vulnerability-resolved.asp"/>
    <link rel="alternate" type="text/html" href="http://blog.tmcnet.com/blog/tom-keating/voip/snom-voip-vulnerability-resolved.asp#c35437" />
    <title>Comment from Mike on 2008-04-01</title>
    <author>
        <name>Mike</name>
        <uri>http://voip-services.topchoicereviews.com/</uri>
    </author>
    <content type="html" xml:lang="en" xml:base="http://voip-services.topchoicereviews.com/">
        <![CDATA[<p>It is a necessary to set passwords to your IP because if not they can be hacked and we face lots of problems.</p>]]>
    </content>
    <published>2008-04-01T15:24:49Z</published>
  </entry>

</feed>
