Image
 
linkedin_logo.png rss_logo.jpg
twitter_logo.png youtube_logo.jpg
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 19 guests online
 
Advertisement

You are here: Home arrow Ethical Hacking Discussions and Related Certificationsarrow Otherarrow VoIP Abuse Project
EH-Net
May 25, 2013, 09:36:15 PM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: Go back to The Ethical Hacker Network Online Magazine Home Page
 
   Home   Help Calendar Login Register  
Pages: [1]   Go Down
  Print  
Author Topic: VoIP Abuse Project  (Read 8734 times)
0 Members and 1 Guest are viewing this topic.
sil
Hero Member
*****
Offline Offline

Posts: 549



View Profile WWW
« on: September 21, 2010, 08:13:34 PM »

For those whose company deals with Voice Over IP and for those wanting to get a birds eye into incident response, analytics, attack trends, etc.:

http://www.infiltrated.net/voipabuse/
http://www.infiltrated.net/voipabuse/honeypot/

I will eventually clean it up, add to it, etc.
Logged

hayabusa
Hero Member
*****
Offline Offline

Posts: 1633



View Profile
« Reply #1 on: September 21, 2010, 08:44:39 PM »

Nice sil!  Bookmarked... thanks!
Logged

~ hayabusa ~ 

"All men can see these tactics whereby I conquer, but what none can see is the strategy out of which victory is evolved." - Sun Tzu, 'The Art of War'


OSCE, OSCP , GPEN, C|EH
sil
Hero Member
*****
Offline Offline

Posts: 549



View Profile WWW
« Reply #2 on: October 04, 2010, 12:05:14 PM »

Alright, been really busy with this project. For more info on what brought it about, etc. including a blogradio interview see:

Intro
http://voipsa.org/blog/2010/09/28/voip-abuse-project/

Analysis
http://voipsa.org/blog/2010/09/29/voip-attackers-sometimes-they-come-back/

Listen (episode 275)
http://www.talkshoe.com/talkshoe/web/talkCast.jsp?masterId=22622&cmd=tc

Intro to above show
http://www.voipusersconference.org/2010/voip-abuse-project/
Logged

sil
Hero Member
*****
Offline Offline

Posts: 549



View Profile WWW
« Reply #3 on: October 04, 2010, 12:06:51 PM »

Durf...

Interview with Dark Reading
http://www.darkreading.com/insiderthreat/security/attacks/showArticle.jhtml?articleID=227500994
Logged

ajohnson
Recruiters
Hero Member
*
Offline Offline

Posts: 1060


aka dynamik


View Profile WWW
« Reply #4 on: October 04, 2010, 01:42:34 PM »

Great stuff!
Logged

WIP: GCFA | www.infosiege.net | @infosiege

The day you stop learning is the day you start becoming obsolete.
sil
Hero Member
*****
Offline Offline

Posts: 549



View Profile WWW
« Reply #5 on: October 04, 2010, 02:23:09 PM »

It actually got "re-interesting" this weekend. I will follow up @ the end of the month as I watch the trends. I've been trying to find a way to easily pull from all my servers, parse from all of them, sort them out uniquely, upload them, script out the html for them, update the pages automatically and use curl to POST to twitter. Sad S'a pain. Never enough time in the day

@dynamik my WIP: RWSP @ TechnoForensics Wink End of this month
Logged

ajohnson
Recruiters
Hero Member
*
Offline Offline

Posts: 1060


aka dynamik


View Profile WWW
« Reply #6 on: October 04, 2010, 02:52:04 PM »

@dynamik my WIP: RWSP @ TechnoForensics Wink End of this month

That's awesome. I probably won't get a shot at that until 2012 (mostly because of weak skills Embarrassed), but it looks amazing. I'm eagerly anticipating the review (and the pass) Wink

While we're on the subject of VOIP, do you have any recommendations for getting started? It seems like Trixbox is a popular system to get up and running quickly. I just don't know what else I need in terms of hardware, software, etc. It's a major shortcoming of mine that I need to remedy.
Logged

WIP: GCFA | www.infosiege.net | @infosiege

The day you stop learning is the day you start becoming obsolete.
sil
Hero Member
*****
Offline Offline

Posts: 549



View Profile WWW
« Reply #7 on: October 04, 2010, 03:55:05 PM »

It depends Wink ProPBX? As in for work or home/fiddling. Pro small to midsized office I would go for pbxnsip for its easy of use/functionality. Home (ab)use, Asterisk all the way. Trixbox is "eh" a lot of holes. Depending on which version of Asterisk you use, stay away from 1.8 for now.

Logged

ajohnson
Recruiters
Hero Member
*
Offline Offline

Posts: 1060


aka dynamik


View Profile WWW
« Reply #8 on: October 04, 2010, 04:19:09 PM »

Oh, I just want something to break in lab. It looks like there are free soft phone packages for Asterisk. That should be enough to get me started.
Logged

WIP: GCFA | www.infosiege.net | @infosiege

The day you stop learning is the day you start becoming obsolete.
sil
Hero Member
*****
Offline Offline

Posts: 549



View Profile WWW
« Reply #9 on: October 04, 2010, 07:58:38 PM »

For breaking, I would start with Asterisk definitely. A vast majority of open source products have their roots in some shape form or fashion in Asterisk. Don't forget to also tinker with OpenSER (or OpenSIP whichever the stubborn-developers re-forked it as).

I go back and forth with Asterisk, Call Manager Express, pbxnsip for most of my testing/abuse. At the end of the day, SIP is SIP is SIP is ... I priced out Juniper SBC blade for an mx240 (http://www.juniper.net/customers/support/products/mx240.jsp) lo and behold was out of my budget Sad So I got stuck ordering an mx80 with Acme Packets for SBC's etc...

For the most part, you could use Trixbox although at the end of the day, knowing Asterisk, how its configured, how it works will give you more bang for your buck. For softphones I use mainly Snom's softphone client or XLite
Logged

tturner
Sr. Member
****
Offline Offline

Posts: 432


View Profile WWW
« Reply #10 on: October 05, 2010, 06:16:42 AM »

My preference has always been Asterisk and the CLI as a learning tool or for low resource builds and http://pbxinaflash.net/ for builds where a non-techie needs to manage the box. And as always http://www.voip-info.org/ is your friend. If you really want to get you feet wet, I highly recommend the http://www.digium.com/en/training/courses/#advanced course. I took it a couple years ago with Jared Smith who was one of the authors of Asterisk: The Future of Telephony http://cdn.oreilly.com/books/9780596510480.pdf and Digium's lead trainer. It was a great course and i would highly recommend it for anyone interested in learning more about Asterisk. You get a "free" Polycom hardphone (I got a SP330) and a T1 card (I really only use as a timing source since I use IAX trunks to my ITSP) and an analog telephony card with 1FXO/FXS port with room for expansion using additional daughter cards. Both cards were of course Digium branded.
Logged

Certifications:
CISSP, CISA, GPEN, GWAPT, GAWN, GCIA, GCIH, GSEC, OPSE, CSWAE, CSTP, VCP

WIP: OSWP, GSSP-JAVA, GXPN

Udacity on hold, again. I suck.

http://sentinel24.com/blog  @tonylturner http://bsidesorlando.org
Pages: [1]   Go Up
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.18 | SMF © 2013, Simple Machines
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.071 seconds with 23 queries.
 
Exclusive Deal

sansfire13_245x90_cw90.jpg
SANSFIRE 2013
June 15 - 22

5% Off w/ Code: EHN_5

SANS Deals 4 EH-Netters
5% OFF Any SANS Course in Any Format!
Coupon Code: EHN_5 Including SANS Rocky Mountain 2013 & SANS Boston 2013
Polls
Compared to this year, 2013 will be:
 
Recent Forum Topics
EH-Net News Feeds
Latest Additions
 
         
Advertisement

© 2013 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.