Image
 
linkedin_logo.png rss_logo.jpg
twitter_logo.png youtube_logo.jpg
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 51 guests online
 
Advertisement

You are here: Home arrow Ethical Hacking Discussions and Related Certificationsarrow Otherarrow Fun with VoIP devices
EH-Net
May 18, 2013, 06:54:22 AM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: Go back to The Ethical Hacker Network Online Magazine Home Page
 
   Home   Help Calendar Login Register  
Pages: [1]   Go Down
  Print  
Author Topic: Fun with VoIP devices  (Read 3152 times)
0 Members and 1 Guest are viewing this topic.
sil
Hero Member
*****
Offline Offline

Posts: 549



View Profile WWW
« on: April 20, 2012, 12:56:37 PM »


I was bored earlier in the week and was on a conference call so I began messing around with the web interface of one of the conference phones I have. Lo and behold, stupidity ensued

www.infiltrated.net/konftel/

Enjoy the 4 minute walkthrough. Sent the vendor a quick email, but alas fell on deaf ears. *shrugs* If you have to ask what can you do against this in a test environment, I suggest you read the PTES and OSSTMM documentation over and over again. Title explained the gist of it though

Logged

lorddicranius
Sr. Member
****
Offline Offline

Posts: 447



View Profile WWW
« Reply #1 on: April 20, 2012, 01:23:35 PM »

Nicely done, and thx for the vid Smiley

What track is that playing during the vid?
Logged

GSEC, eCPPT, Sec+
sil
Hero Member
*****
Offline Offline

Posts: 549



View Profile WWW
« Reply #2 on: April 20, 2012, 01:29:11 PM »

Vinny Paz "Death Messiah 2012"
Logged

lorddicranius
Sr. Member
****
Offline Offline

Posts: 447



View Profile WWW
« Reply #3 on: April 21, 2012, 01:17:15 AM »

I'm going to have to check out more of this Vinny Paz, thanks!
Logged

GSEC, eCPPT, Sec+
alucian
Full Member
***
Offline Offline

Posts: 225



View Profile
« Reply #4 on: April 21, 2012, 08:32:06 AM »

Very interesting.

I imagine that because you already are the admin, you knew the profile, and all the other data sent when you authenticate as admin.

I hope that they'll fix it as soon as possible, but event if they'll provide a firmware upgrade, some users very rarely are updating their VoIP devices. For them they are Black Box devices they don't touch. I saw some SLAs where the vendor said that if the customer will touch the device the warranty will be void. Probably a temporary bandage will be to put them in a separate VLAN, but this is tricky and if not properly done will create a false sense of protection.

Thanks for the video!
Logged

CISSP ISSAP, CISM/A, GWAPT, GCIH, eCPPT, OSWP
knwminus
Full Member
***
Offline Offline

Posts: 100



View Profile WWW
« Reply #5 on: April 24, 2012, 11:54:25 AM »

Nice track and nice video.
Logged

A+ N+ CCNA CCNA:S CNSS 4011 Security+

Next Up: CCNP CCNP:S
Pages: [1]   Go Up
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.18 | SMF © 2013, Simple Machines
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.052 seconds with 22 queries.
 
Exclusive Deal

sansfire13_245x90_cw90.jpg
SANSFIRE 2013
June 15 - 22

5% Off w/ Code: EHN_5

SANS Deals 4 EH-Netters
5% OFF Any SANS Course in Any Format!
Coupon Code: EHN_5 Including SANS Rocky Mountain 2013 & SANS Boston 2013
Polls
Compared to this year, 2013 will be:
 
Recent Forum Topics
EH-Net News Feeds
Latest Additions
 
         
Advertisement

© 2013 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.