-
Website
http://www.matasano.com/log -
Original page
http://www.matasano.com/log/1117/the-wild-world-of-voip/ -
Subscribe
All Comments -
Community
-
Top Commenters
-
Press Controls
3 comments · 2 points
-
ChrisMtso
12 comments · 1 points
-
Eric Monti
11 comments · 1 points
-
StatlerAndWaldorf
12 comments · 3 points
-
Dave G.
7 comments · 1 points
-
-
Popular Threads
One of the prime vendors for this telco actually, when asked to help design a solution for a particular VoIP problem turned over a set of documentation (very thorough and long) for the solution... They forgot to search/replace the competitors name in the documentation, they also couldn't be bothered to understand that in the original specifications there were large flashing notes about: "This will be deployed on the public network". Most of the docs, when they danced around 'security' would say: "and this must be deployed on a private network or behind a sip aware firewall", fine... got any firewalls that have ATM/oc-12 interfaces?
Security isn't even a 'feature' for the vendors, and the operators rarely care about anything other than 'fraud' issues... 'Jane calls Joe, Joe tells the SIP gateway that the call ends prior to the 1min mark, since the media goes peer-to-peer jane/joe talk for a month for free on an open line, giant-telco loses 1mon of call time charges, boo!' No current production telco (and even enterprises rarely do this) voip system does p2p media, they all push everything through an SBC so that CALEA and other 'features' can be enabled on calls.
ugh... voip-security-hotbutton.
And the marketing of such devices seem to be as a magical bandaid, much like firewalls. And they're priced accordingly, in the hundreds of thousands of dollars.
In any case, great to have Matasano back, although I hate this commenting system and the new look and feel. Posting comments off-site to disqus forums is creeping me out. And the flash is double-creeping me out. Kthx.
I'm curious if there are any libraries or component frameworks out there to help VoIP implementers. I know you speak of Wireshark as a guideline, but I was thinking of something more commercial, such as Coverity Extend (particularly for embedded devices). Or maybe something in between. I guess asterisk with PaX/GRSec wouldn't be a poor implementation choice, but I'm looking for something with a bit more assurance.
Good question. My slant on things has mainly been from the perspective of attacking existing VoIP implementations. Apparently there are VoIP implementations out there, such as Trolltech's Qtopia -- http://osdir.com/Article7982.phtml -- but I can't attest to their security, as I've never looked at this particular implementation.
Most of the freely available implementations are oriented towards being a client, rather than being a VoIP switch and router. Perhaps there's a market here!