White hats expose VoIP security threat

Daily Newsletters

Sign up to ZDNet UK's daily newsletter.

NEWS

Penetration testers have demonstrated a way of compromising computers by subverting VoIP software clients.

The testers, who are from VoIP security firm Sipera, claim that they have found similar vulnerabilities in several vendors' enterprise VoIP software clients. Sipera would not reveal the identity of the affected vendors, because they have not yet brought out patches.

The testers demonstrated a proof-of-concept exploit for one of the VoIP clients at the Black Hat security conference in Las Vegas on Wednesday. On a laptop running Windows XP SP2 with a Windows firewall, running McAfee antivirus, Sipera product manager Sachin Joglekar demonstrated a vulnerability that allows a hacker to cause a buffer-overflow condition.

This allows a small script to be inserted on the victim's laptop, which then enables the hacker to take control of the laptop and view directories, delete them, and steal files and data, Sipera claimed.

"Very specialised, small shell code, just bits and bytes, is inserted into a SIP message," Joglekar said. "As soon as the phone gets the malformed message, the shell code is executed on the laptop and opens a connection that allows an attacker to open a connection and steal files and data."

Joglekar claimed this was "very significant" because data could be smuggled "under the radar from the VoIP side", and that data security vendors were currently "not serious about VoIP".

"Previously there have been no threats to confidential data from softphones. Now there is a bridge built between the two islands," he said.

However, Jon Collins, service director with analyst firm Freeform Dynamics, said that, as few companies have yet rolled out VoIP, a more pressing security concern was "protecting employees from themselves" through education about social-engineering attacks, as working practices evolve.

"I'm not suggesting that finding VoIP or IM client holes isn't an issue, but there are 500 different ways of getting onto someone's laptop. Companies should be concentrating on protecting employees from themselves rather than worrying about external threats. Companies are trying to enable corporate employees to work from home. Corporate data is leaving the company — this is a major area of concern," said Collins.

Read this

Feature
Tutorial: Creating a secure and reliable VoIP solution

Increasingly widespread, it is important to be aware of measures which can increase VoIP's security and reliability...

Read more +

Joglekar claimed that VoIP protocol subversion was an unrecognised problem in many vendor products. "We found vulnerabilities allowing shell-code execution in multiple vendor VoIP products and software," said Joglekar. "As different modes of communication like VoIP and IM are unified, privacy, security and compliance issues become [more significant]."

He said that most security products would be circumvented by VoIP client-exploit code, because finding anomalies required deep packet inspection and an understanding of VoIP user and client behaviour.

McAfee said that its antivirus software had not picked up the hack in the demonstration because the hack was proof-of-concept. "Both our consumer and enterprise generic products monitor the top 20 buffer-overflow methods," said McAfee analyst Greg Day. "If this is seen in the real world, we could create an antivirus signature, and would do that if it became common in the outside world."

Day said that behaviour-blocking in McAfee antivirus software would not stop this exploit because behaviour-blocking is "designed around a common threat rather than a proof-of-concept hacking technique". He added that McAfee had host and network intrusion-prevention products designed to stop this type of exploit.

Microsoft could offer no comment at the time of writing on how the researchers had managed to evade the Windows firewall.

Post your comment

In order to post a comment you need to be registered and logged in.

You can also log in with Facebook. Log in or create your ZDNet UK account below

  • Login

Will not be displayed with your comment

By signing up for this service, you indicate that you agree to our Terms and Conditions and have read and understood our Privacy Policy. Questions about membership? Find the answers in the Community FAQ

Get ZDNet UK's daily newsletter

Enter your email address to sign up

ZDNet UK Live

SPM

The 2 million number quoted is shipments not sales, an exact repeat of last year's dire sales of WP7. Sales to customers are likely to number only...

3 hours ago by SPM on Nokia earnings fail to shine despite Lumia
apexwm

It sounds like this is just another variable in the complex equation of Microsoft licensing, which often results in customers overpaying as it is....

5 hours ago by apexwm on UK customers to lose out in Microsoft licensing change
chonzchor

I am really thankful to you for this nice and beautiful information.I really like this. cable ties

6 hours ago by chonzchor on Currys £16.99 USB cable rip-off.
Brian Jones

What would be nice would be if Microsoft practiced consistent pricing between the US and Europe.

11 hours ago by Brian Jones via Facebook on UK customers to lose out in Microsoft licensing change
Karen Friar

@Scott Deagan: Ofcom dedicated a section to upload speeds - see page 19 onward of its full report:...

11 hours ago by Karen Friar on UK broadband speed climbs 22 percent
EUDataProtection

The EU proposals can all be read in full on the reform website: http://ec.europa.eu/justice/data-protection/minisite/index.html

12 hours ago by EUDataProtection on Firms face tough new EU fines for data breaches
Jake Rayson

Found out that Taskwarrior stores all data in plain text files: "Task writes all pending tasks to the file ~/.task/pending.data and all completed...

14 hours ago by Jake Rayson on Taskwarrior: command line task manager
ians1

"...based 6,000 miles away..." Indeed, so who do you complain to when things go wrong? I would not buy shares in Faecebook even if I could...

15 hours ago by ians1 on Facebook plans to raise $5bn via share launch
servermanagement

These are really very useful tips of backing up the system. Each tips are important and essential to prevent loosing all the data that we have....

17 hours ago by servermanagement on Ten ways to take the sting out of IT disasters
Scott Deagan

Why is the upstream never discussed? I'd like to see Ofcom explain to Internet users why people in the UK can only get a maximum of 10Mb/s upstream...

1 day ago by Scott Deagan via Facebook on UK broadband speed climbs 22 percent
Moley

Seemingly a very strange decision, even perverse. Mind you, the basis of the decision is hardly explained here or in Cnet. Perhaps we will hear...

1 day ago by Moley on Free Maps costs Google £400K in damages in France
Jake Rayson

@OccupyACAT: I had heard mention of the Emacs extension but not the Ubiquity project. Interesting to see an idea spread almost simultaneously! Re....

1 day ago by Jake Rayson on Ubuntu HUD Intenterface? Sublime already there!
markhumphryes

With no Flash support on LoveFilm, mobile devices running Android will not be able to use it - I presume - I tried a trial via my Galaxy Tab 10.1...

1 day ago by markhumphryes on Lovefilm drops Flash, kills Linux support
manek

And people wonder why there is caution about doing business with large, consumer-focused technology companies, most of which are based 6,000 miles...

2 days ago by manek on Facebook plans to raise $5bn via share launch
manek

Yes, frameworks and smarter compilers - but I suspect a lot of the code will have to be written with parallel processing as one of its fundamental...

2 days ago by manek on Parallel computing takes a step forward
Simon Bisson and Mary Branscombe

Well, this is why I'm both fascinated and slightly worried; parallel computing and concurrency and complex architectures don't seem to be something...

2 days ago by Simon Bisson and Mary Branscombe on Parallel computing takes a step forward
ians1

Let's hope that they take more notice of their shareholders than they do of their poor customers! I have never experienced customer service as bad...

2 days ago by ians1 on Facebook plans to raise $5bn via share launch
servermanagement

Thanks for the heads up. Will definitely check this HUD Intenterface.

2 days ago by servermanagement on Linux Minterface
Will A

Some more observations by an extremely frustrated user in Canada (apparently every country has a different set of "issues"): The web interfaces...

2 days ago by Will A on Cambridge researchers knock Verified by Visa
Jake Rayson

@zdnetukuser: I hope there's more conciliation and less bitterness in the graphical shell camps, I'd like to Ubuntu to succeed, I *want* to have a...

2 days ago by Jake Rayson on Linux Minterface