Image
 
linkedin_logo.png rss_logo.jpg
twitter_logo.png youtube_logo.jpg
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 52 guests and 1 member online
 
Advertisement

You are here: Home arrow Ethical Hacking Discussions and Related Certificationsarrow Network Pen Testingarrow VOIP Security
EH-Net
May 23, 2013, 11:00:12 PM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: Go back to The Ethical Hacker Network Online Magazine Home Page
 
   Home   Help Calendar Login Register  
Pages: [1]   Go Down
  Print  
Author Topic: VOIP Security  (Read 3217 times)
0 Members and 1 Guest are viewing this topic.
g00d_4sh
Sr. Member
****
Offline Offline

Posts: 394



View Profile
« on: January 31, 2008, 02:46:08 PM »

Alright, I'm doing some 'footwork' myself, to gather and glean information, but I would definately appreciate any links, experience, or advice and opinions from those of you who know on this issue.  We're going over our VOIP system right now, and considering the security of it in general.  We are of course in a switched network, and have the VOIP traffic running over it's own VLAN. 

My question is... security wise how would that be looking?  We're a Cisco house, using Cisco VOIP phones, etc.  I was under the impression that ARP poisoning, and man in the middle attacks, combined with Cain and Abel or another sniffer/translator program would make listening into the VOIP system rather easy.  I just recently in my search came accross a Cisco white paper saying that having the phones on a different VLAN (even though the computers hook into the phones) negates man in the middle attacks. 

So, please any thoughts, opinions, insights, or solutions would be highly appreciated.
Logged

"Bad.. Good?  I'm the guy with the gun"
rance
Full Member
***
Offline Offline

Posts: 212


<censored>


View Profile
« Reply #1 on: January 31, 2008, 02:59:36 PM »

Alright, I'm doing some 'footwork' myself, to gather and glean information, but I would definately appreciate any links, experience, or advice and opinions from those of you who know on this issue.  We're going over our VOIP system right now, and considering the security of it in general.  We are of course in a switched network, and have the VOIP traffic running over it's own VLAN. 

My question is... security wise how would that be looking?  We're a Cisco house, using Cisco VOIP phones, etc.  I was under the impression that ARP poisoning, and man in the middle attacks, combined with Cain and Abel or another sniffer/translator program would make listening into the VOIP system rather easy.  I just recently in my search came accross a Cisco white paper saying that having the phones on a different VLAN (even though the computers hook into the phones) negates man in the middle attacks. 

So, please any thoughts, opinions, insights, or solutions would be highly appreciated.

A snipped I gleaned from here: http://www.roboguys.com/index.php?option=com_content&task=view&id=57&Itemid=47

Quote
Dividing your broadcast domains in your network up can limit the effectiveness of an ARP based attack. Traffic for a machine not on the same broadcast domain as the attacker cannot be redirected due to the nature of ARP; it's a broadcast protocol. Dividing your important servers into a separate network can provide a layer of security against this type of attack and follows good industry design standards.

One additional method of defending against this attack is to hardcode each IP address to each MAC address on vulnerable systems. Naturally, this has a high level of administrative overhead and can be cumbersome and fraught with problems in some situations. Implementing a solution such as this is only practical for a limited number of servers and devices in most cases, but is probably one of the more effective methods of actually stopping ARP spoofing attacks.

So, if your VoIP devices are on a separate VLAN, they should be protected from simple attacks by residing on a separate broadcast domain.  Now, if you were able to sneak a machine on you VoIP VLAN, I don't know what would stop someone from being able to perform a MITM attack, unless of course, you are utilizing Static MAC address configuration on your switches (which, with my limited exposure to VoIP may be happening as part of normal device deployment/configuration).

It'd be fun to test... so... get testing! Smiley
Logged

Poking at security since 1986.  +++ATH
g00d_4sh
Sr. Member
****
Offline Offline

Posts: 394



View Profile
« Reply #2 on: January 31, 2008, 03:37:04 PM »

Well we are not doing port security on the switches, nor static mac mapping.  Our VOIP phones are such that they can be freely moved around the organization, and retain the phone number/ID we assign them via the Cisco manager.  We also plug our computers into the phones.  Honestly I'm a tad intrigued on how that works, since our computer sends the info into the phone, which then forwards it to the POE switches.  Though the VOIP is on it's own VOIP VLAN, i'm assuming it strips off the phone MAC and replaces it with the comp MAC for forwarding purposes?  As to the VOIP phones being on another VLAN, for a MITM attack... couldn't a computer 'call' the target phone number via software, and disassemble the packets to get the target phone's MAC since all switch ports allow both the data and VOIP streams?
Logged

"Bad.. Good?  I'm the guy with the gun"
Pages: [1]   Go Up
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.18 | SMF © 2013, Simple Machines
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.05 seconds with 23 queries.
 
Exclusive Deal

sansfire13_245x90_cw90.jpg
SANSFIRE 2013
June 15 - 22

5% Off w/ Code: EHN_5

SANS Deals 4 EH-Netters
5% OFF Any SANS Course in Any Format!
Coupon Code: EHN_5 Including SANS Rocky Mountain 2013 & SANS Boston 2013
Polls
Compared to this year, 2013 will be:
 
Recent Forum Topics
EH-Net News Feeds
Latest Additions
 
         
Advertisement

© 2013 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.