<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: acme]]></title>
    <link>http://securityratty.com/tag/acme</link>
    <description></description>
    <pubDate>Wed, 03 Oct 2007 02:00:00 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[Insider Threats: the biggest Information Security risk]]></title>
      <link>http://securityratty.com/article/94738166477b3697ee3d387b7722021b</link>
      <guid>http://securityratty.com/article/94738166477b3697ee3d387b7722021b</guid>
      <description><![CDATA[It's a fact that most crimes are committed by people known to their victims. Similarly, businesses are most at risk from former and current employees. Most commonly when thinking about information...]]></description>
      <content:encoded><![CDATA[
      It's a fact that most crimes are committed by people known to their victims. Similarly, businesses are most at risk from former and current employees. Most commonly when thinking about information security we consider how to prevent intrusion into our business from the outside. The facts and statistics tell a different story. 62% of large businesses in the UK (source: DTI/PWC Insider Threat Report 2006) have dealt with a security incident instigated by a current or former employee.

I've been writing up some of my research into insider threats in the form of a paper describing the risks posed to a fictional multinational company, Acme Widgets plc. 

You can download the paper for free <a href="http://www.computerweekly.com/blogs/stuart_king/StuartKing_InsiderThreatRisk_0508.pdf">here</a>. If you'd like to leave me feedback or would like more information about insider threats, write to the email address within the digital signature at the end of the document.

If you'd like to make a donation in return for downloading the paper, please give to <a href="http://www.bbc.co.uk/pudsey/donate/">Children in Need</a>.

      
   ]]></content:encoded>
      <pubDate>Sat, 10 May 2008 11:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/insider threats">insider threats</category>
      <category domain="http://securityratty.com/tag/information">information</category>
      <category domain="http://securityratty.com/tag/information security">information security</category>
      <category domain="http://securityratty.com/tag/current">current</category>
      <category domain="http://securityratty.com/tag/paper">paper</category>
      <category domain="http://securityratty.com/tag/fictional multinational company">fictional multinational company</category>
      <category domain="http://securityratty.com/tag/acme widgets plc">acme widgets plc</category>
      <category domain="http://securityratty.com/tag/current employees">current employees</category>
      <category domain="http://securityratty.com/tag/risks posed">risks posed</category>
      <source url="http://www.computerweekly.com/blogs/stuart_king/2008/05/insider-threats-the-biggest-in.html">Insider Threats: the biggest Information Security risk</source>
    </item>
    <item>
      <title><![CDATA[Blue Box #71: VLAN Hopping, SIP Digest vulnerability, VoIP security hype, Skype security, Google's latest moves, listener comments and much more...]]></title>
      <link>http://securityratty.com/article/898c5592d3ded3cdf3767c9f5304b294</link>
      <guid>http://securityratty.com/article/898c5592d3ded3cdf3767c9f5304b294</guid>
      <description><![CDATA[Synopsis: Blue Box #71: VLAN Hopping, SIP Digest vulnerability, VoIP security hype, Skype security, Google's latest moves, listener comments and much more
Welcome to Blue Box: The VoIP Security...]]></description>
      <content:encoded><![CDATA[
<div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Synopsis:</strong> Blue Box #71: VLAN Hopping, SIP Digest vulnerability, VoIP security hype, Skype security, Google's latest moves, listener comments and much more...

</p><hr /><p>Welcome to <strong>Blue Box: The VoIP Security Podcast</strong> #71, a 51-minute podcast&nbsp; from Dan York and Jonathan Zar covering VoIP security news, comments and opinions.&nbsp; &nbsp; </p>

<p><a rel="enclosure" href="http://ripple.radiotail.com/409/BBP-071-2007-11-08.mp3">Download the show here</a> (MP3, 21MB) or <a href="http://feeds.feedburner.com/BlueBox">subscribe to the RSS feed</a> to download the show automatically.&nbsp; </p> 

<p>You may also listen to this podcast right now:</p> 

<p><object width="200" height="20" data="http://www.blueboxpodcast.com/dewplayer.swf?son=http://ripple.radiotail.com/409/BBP-071-2007-11-08.mp3" type="application/x-shockwave-flash"><param value="http://www.blueboxpodcast.com/dewplayer.swf?son=http://ripple.radiotail.com/409/BBP-071-2007-11-08.mp3&amp;bgcolor=#FFFFFF" name="movie" /></object> </p> 

<p><em>NOTE: This show was recorded on November 8, 2007.</em></p>
<p><strong>Show Content:</strong></p> 
 

<ul> <li>00:20 - Intro to the show, contact information and how to provide comments.&nbsp; Welcome to all the new listeners - and to all those listeners who have been here for so long!&nbsp; </li>

<li><a href="http://voipsa.org/pipermail/voipsec_voipsa.org/2007-November/002475.html">SIP Digest Access Authentication <span class="caps">RELAY</span>-ATTACK for Toll-Fraud</a></li>
<li>VoiceCon ENews: <a href="http://www.voicecon.com/enews/2007/10/30/issue-199-voip-security-update/">VoIP Security Update</a> (about my talk at Interop)</li>
		<li><a href="http://www.thevoicereport.com/TelecomJunkiesArchive-VoIPHacking2">Telecom Junkies episode about <span class="caps">VLAN </span>Hopping</a></li>
		<li>Network World: <a href="http://www.networkworld.com/newsletters/converg/2007/1105converge1.html">VoIP security notices show security remains a multi-vendor issue</a> – also <a href="http://blogs.techrepublic.com.com/wireless/?p=149">TechRepublic article about VoIP Hopper</a></li>
		<li>Network World: <a href="http://www.networkworld.com/columnists/2007/110607-jericho-forum.html">VoIP security industry: Guilty as charged</a> (Plus, 10 nasty questions to ask your VoIP supplier)</li>
		<li>VoIP-News.com: <a href="http://www.voip-news.com/feature/vonage-security-problems-103107/">Vonage Security Problems May Be Just the Start</a></li>
		<li>The Ethical Hacker Network: <a href="http://www.ethicalhacker.net/content/view/127/24/">Fun with Online VoIP Hacking</a></li>
		<li>SearchVoIP: <a href="http://www.searchvoip.com.au/topics/article.asp?DocID=1280884">Unified communications security vulnerabilities</a></li>
		<li>SecurityPark: <a href="http://www.securitypark.co.uk/security_article260054.html">Seeing through the VoIP security hype</a></li>
		<li>The Guardian: <a href="http://www.guardian.co.uk/technology/2007/nov/01/news.hacking">Why VoIP is the next target for spammers</a></li>
		<li>Skype Blog: <a href="http://share.skype.com/sites/en/2007/11/skype_for_mac_on_leopard.html">Skype for Mac on Leopard</a> (note comments about embracing security)</li>
		<li>Voice of <span class="caps">VOIPSA</span>: <a href="http://voipsa.org/blog/2007/10/24/isolation-vs-integration/">Isolation vs. Integration</a> (Dustin Trammell)</li>
		<li>Converge!Network Digest: <a href="http://www.convergedigest.com/bp/bp1.asp?ID=497&amp;ctgy=2">The Future IC/UC Net Will Be Federated</a> (by Acme Packet)</li>
		<li><span class="caps">TMC</span>Net: <a href="http://ipcommunications.tmcnet.com/hot-topics/gateway/articles/14107-telecom-italia-sparkle-enhances-voip-services-with-acme.htm">Telecom Italia Sparke Enhances VoIP Services with Acme Packet</a></li>
		<li>Mark Collier: <a href="http://voipsecurityblog.typepad.com/marks_voip_security_blog/2007/11/voip-training-c.html">VoIP Training Courses</a> – he also has made available <a href="http://voipsecurityblog.typepad.com/marks_voip_security_blog/2007/11/presented-at-th.html">his presentation on security</a> that he recently gave at AT&amp;T’s Focus Conference.</li>
<li>InfoWorld: <a href="http://weblog.infoworld.com/realitycheck/archives/2007/11/vetting_the_qua.html?source=rss">Vetting the quality of VoIP</a> (follow-on to <a href="http://weblog.infoworld.com/realitycheck/archives/2007/10/the_lie_that_is.html?source=rss">The lie that is Voice over IP</a> )</li>
<li>Comment (email) from Matt Hillman about <a href="http://www.podcastersmeetup.com/">http://www.podcastersmeetup.com/</a> at ShmooCon Feb 15-17 in DC</li>
		<li>Comment (audio) from Mohammad Halawah</li>
		<li>Comment (email) from Frank Leonhardt</li>
		<li>Comment (email) from Josef Janitor</li>
<li>- Review of the last week's traffic on the <a href="http://www.voipsa.org/VOIPSEC/">VOIPSEC </a>public mailing list&nbsp; </li>
<li>- Wrap-up of the show </li>
<li> - End of show&nbsp; </li></ul> <p>Comments, suggestions and feedback are welcome either as replies to this post&nbsp; or via e-mail to <a href="mailto:blueboxpodcast@gmail.com">blueboxpodcast@gmail.com</a>.&nbsp; Audio comments sent as attached MP3 files are definitely welcome and will be played in future shows.&nbsp; You may also call the listener comment line at either +1-206-350-7280 or via SIP to '<a href="sip:bluebox@voipuser.org">bluebox@voipuser.org</a>' to leave a comment there.&nbsp; </p> <p>Thank you for listening and please do let us know what you think of the show. </p></div>

<p><a href="http://feeds.feedburner.com/~a/BlueBox?a=LLruHs"><img src="http://feeds.feedburner.com/~a/BlueBox?i=LLruHs" border="0"></img></a></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/BlueBox?a=0y5zYZC"><img src="http://feeds.feedburner.com/~f/BlueBox?i=0y5zYZC" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/BlueBox?a=p7bjuvC"><img src="http://feeds.feedburner.com/~f/BlueBox?i=p7bjuvC" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/BlueBox?a=uQ1bXGC"><img src="http://feeds.feedburner.com/~f/BlueBox?i=uQ1bXGC" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/BlueBox?a=kncAzvC"><img src="http://feeds.feedburner.com/~f/BlueBox?i=kncAzvC" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/BlueBox?a=NWuDqYc"><img src="http://feeds.feedburner.com/~f/BlueBox?i=NWuDqYc" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/BlueBox?a=DCZ31oC"><img src="http://feeds.feedburner.com/~f/BlueBox?i=DCZ31oC" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/BlueBox/~4/193983052" height="1" width="1"/>]]></content:encoded>
      <pubDate>Mon, 17 Dec 2007 16:59:44 +0000</pubDate>
      <category domain="http://securityratty.com/tag/voip">voip</category>
      <category domain="http://securityratty.com/tag/voip security hype">voip security hype</category>
      <category domain="http://securityratty.com/tag/online voip">online voip</category>
      <category domain="http://securityratty.com/tag/voip supplier">voip supplier</category>
      <category domain="http://securityratty.com/tag/voip-news">voip-news</category>
      <category domain="http://securityratty.com/tag/voip security news">voip security news</category>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/voip security industry">voip security industry</category>
      <category domain="http://securityratty.com/tag/skype security">skype security</category>
      <source url="http://feeds.feedburner.com/~r/BlueBox/~3/193983052/blue-box-71-vla.html">Blue Box #71: VLAN Hopping, SIP Digest vulnerability, VoIP security hype, Skype security, Google's latest moves, listener comments and much more...</source>
    </item>
    <item>
      <title><![CDATA[Blue Box #71: VLAN Hopping, SIP Digest vulnerability, VoIP security hype, Skype security, Google's latest moves, listener comments and much more...]]></title>
      <link>http://securityratty.com/article/824c395b19126f8f64906d1bf0c6233d</link>
      <guid>http://securityratty.com/article/824c395b19126f8f64906d1bf0c6233d</guid>
      <description><![CDATA[Synopsis: Blue Box #71: VLAN Hopping, SIP Digest vulnerability, VoIP security hype, Skype security, Google's latest moves, listener comments and much more
Welcome to Blue Box: The VoIP Security...]]></description>
      <content:encoded><![CDATA[
<div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Synopsis:</strong> Blue Box #71: VLAN Hopping, SIP Digest vulnerability, VoIP security hype, Skype security, Google's latest moves, listener comments and much more...

</p><hr /><p>Welcome to <strong>Blue Box: The VoIP Security Podcast</strong> #71, a 51-minute podcast&nbsp; from Dan York and Jonathan Zar covering VoIP security news, comments and opinions.&nbsp; &nbsp; </p>

<p><a rel="enclosure" href="http://ripple.radiotail.com/409/BBP-071-2007-11-08.mp3">Download the show here</a> (MP3, 21MB) or <a href="http://feeds.feedburner.com/BlueBox">subscribe to the RSS feed</a> to download the show automatically.&nbsp; </p> 

<p>You may also listen to this podcast right now:</p> 

<p><object width="200" height="20" data="http://www.blueboxpodcast.com/dewplayer.swf?son=http://ripple.radiotail.com/409/BBP-071-2007-11-08.mp3" type="application/x-shockwave-flash"><param value="http://www.blueboxpodcast.com/dewplayer.swf?son=http://ripple.radiotail.com/409/BBP-071-2007-11-08.mp3&amp;bgcolor=#FFFFFF" name="movie" /></object> </p> 

<p><em>NOTE: This show was recorded on November 8, 2007.</em></p>
<p><strong>Show Content:</strong></p> 
 

<ul> <li>00:20 - Intro to the show, contact information and how to provide comments.&nbsp; Welcome to all the new listeners - and to all those listeners who have been here for so long!&nbsp; </li>

<li><a href="http://voipsa.org/pipermail/voipsec_voipsa.org/2007-November/002475.html">SIP Digest Access Authentication <span class="caps">RELAY</span>-ATTACK for Toll-Fraud</a></li>
<li>VoiceCon ENews: <a href="http://www.voicecon.com/enews/2007/10/30/issue-199-voip-security-update/">VoIP Security Update</a> (about my talk at Interop)</li>
		<li><a href="http://www.thevoicereport.com/TelecomJunkiesArchive-VoIPHacking2">Telecom Junkies episode about <span class="caps">VLAN </span>Hopping</a></li>
		<li>Network World: <a href="http://www.networkworld.com/newsletters/converg/2007/1105converge1.html">VoIP security notices show security remains a multi-vendor issue</a> ??? also <a href="http://blogs.techrepublic.com.com/wireless/?p=149">TechRepublic article about VoIP Hopper</a></li>
		<li>Network World: <a href="http://www.networkworld.com/columnists/2007/110607-jericho-forum.html">VoIP security industry: Guilty as charged</a> (Plus, 10 nasty questions to ask your VoIP supplier)</li>
		<li>VoIP-News.com: <a href="http://www.voip-news.com/feature/vonage-security-problems-103107/">Vonage Security Problems May Be Just the Start</a></li>
		<li>The Ethical Hacker Network: <a href="http://www.ethicalhacker.net/content/view/127/24/">Fun with Online VoIP Hacking</a></li>
		<li>SearchVoIP: <a href="http://www.searchvoip.com.au/topics/article.asp?DocID=1280884">Unified communications security vulnerabilities</a></li>
		<li>SecurityPark: <a href="http://www.securitypark.co.uk/security_article260054.html">Seeing through the VoIP security hype</a></li>
		<li>The Guardian: <a href="http://www.guardian.co.uk/technology/2007/nov/01/news.hacking">Why VoIP is the next target for spammers</a></li>
		<li>Skype Blog: <a href="http://share.skype.com/sites/en/2007/11/skype_for_mac_on_leopard.html">Skype for Mac on Leopard</a> (note comments about embracing security)</li>
		<li>Voice of <span class="caps">VOIPSA</span>: <a href="http://voipsa.org/blog/2007/10/24/isolation-vs-integration/">Isolation vs. Integration</a> (Dustin Trammell)</li>
		<li>Converge!Network Digest: <a href="http://www.convergedigest.com/bp/bp1.asp?ID=497&amp;ctgy=2">The Future IC/UC Net Will Be Federated</a> (by Acme Packet)</li>
		<li><span class="caps">TMC</span>Net: <a href="http://ipcommunications.tmcnet.com/hot-topics/gateway/articles/14107-telecom-italia-sparkle-enhances-voip-services-with-acme.htm">Telecom Italia Sparke Enhances VoIP Services with Acme Packet</a></li>
		<li>Mark Collier: <a href="http://voipsecurityblog.typepad.com/marks_voip_security_blog/2007/11/voip-training-c.html">VoIP Training Courses</a> ??? he also has made available <a href="http://voipsecurityblog.typepad.com/marks_voip_security_blog/2007/11/presented-at-th.html">his presentation on security</a> that he recently gave at AT&amp;T???s Focus Conference.</li>
<li>InfoWorld: <a href="http://weblog.infoworld.com/realitycheck/archives/2007/11/vetting_the_qua.html?source=rss">Vetting the quality of VoIP</a> (follow-on to <a href="http://weblog.infoworld.com/realitycheck/archives/2007/10/the_lie_that_is.html?source=rss">The lie that is Voice over IP</a> )</li>
<li>Comment (email) from Matt Hillman about <a href="http://www.podcastersmeetup.com/">http://www.podcastersmeetup.com/</a> at ShmooCon Feb 15-17 in DC</li>
		<li>Comment (audio) from Mohammad Halawah</li>
		<li>Comment (email) from Frank Leonhardt</li>
		<li>Comment (email) from Josef Janitor</li>
<li>- Review of the last week's traffic on the <a href="http://www.voipsa.org/VOIPSEC/">VOIPSEC </a>public mailing list&nbsp; </li>
<li>- Wrap-up of the show </li>
<li> - End of show&nbsp; </li></ul> <p>Comments, suggestions and feedback are welcome either as replies to this post&nbsp; or via e-mail to <a href="mailto:blueboxpodcast@gmail.com">blueboxpodcast@gmail.com</a>.&nbsp; Audio comments sent as attached MP3 files are definitely welcome and will be played in future shows.&nbsp; You may also call the listener comment line at either +1-206-350-7280 or via SIP to '<a href="sip:bluebox@voipuser.org">bluebox@voipuser.org</a>' to leave a comment there.&nbsp; </p> <p>Thank you for listening and please do let us know what you think of the show. </p></div>
]]></content:encoded>
      <pubDate>Sun, 02 Dec 2007 10:58:15 +0000</pubDate>
      <category domain="http://securityratty.com/tag/voip">voip</category>
      <category domain="http://securityratty.com/tag/voip security hype">voip security hype</category>
      <category domain="http://securityratty.com/tag/online voip">online voip</category>
      <category domain="http://securityratty.com/tag/voip supplier">voip supplier</category>
      <category domain="http://securityratty.com/tag/voip-news">voip-news</category>
      <category domain="http://securityratty.com/tag/voip security news">voip security news</category>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/voip security industry">voip security industry</category>
      <category domain="http://securityratty.com/tag/skype security">skype security</category>
      <source url="http://www.blueboxpodcast.com/2007/12/blue-box-71-vla.html">Blue Box #71: VLAN Hopping, SIP Digest vulnerability, VoIP security hype, Skype security, Google's latest moves, listener comments and much more...</source>
    </item>
    <item>
      <title><![CDATA[Blue Box #68: Top 14 VoIP Vulnerabilities, Asterisk security, VoIP hacker, IMS, P2P, Skype, industry moves, VoIP security news, listener comments and ]]></title>
      <link>http://securityratty.com/article/865f0d1c531f4167af2702f1fd1e0d94</link>
      <guid>http://securityratty.com/article/865f0d1c531f4167af2702f1fd1e0d94</guid>
      <description><![CDATA[Synopsis: Blue Box #68: Top 14 VoIP Vulnerabilities, Asterisk security, VoIP hacker, IMS, P2P, Skype, industry moves, VoIP security news, listener comments and more
Welcome to Blue Box: The VoIP...]]></description>
      <content:encoded><![CDATA[
<div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Synopsis:</strong>Blue Box #68: Top 14 VoIP Vulnerabilities, Asterisk security, VoIP hacker, IMS, P2P, Skype, industry moves, VoIP security news, listener comments and more...  

<hr /><p>Welcome to <strong>Blue Box: The VoIP Security Podcast</strong> #68, a 46-minute podcast&nbsp; from Dan York and Jonathan Zar covering VoIP security news, comments and opinions.&nbsp; &nbsp; </p>

<p><a href="http://ripple.radiotail.com/409/BBP-068-2007-10-03.mp3" rel="enclosure">Download the show here</a> (MP3, 21MB) or <a href="http://feeds.feedburner.com/BlueBox">subscribe to the RSS feed</a> to download the show automatically.&nbsp; </p> 

<p>You may also listen to this podcast right now:</p> 

<p>
<p><object width="200" height="20" type="application/x-shockwave-flash" data="http://www.blueboxpodcast.com/dewplayer.swf?son=http://ripple.radiotail.com/409/BBP-068-2007-10-03.mp3"><param name="movie" value="http://www.blueboxpodcast.com/dewplayer.swf?son=http://ripple.radiotail.com/409/BBP-068-2007-10-03.mp3&amp;bgcolor=#FFFFFF" /></object> </p> <p><strong>Show Content:</strong></p> 
<p><strong>Show Content:</strong></p> 

<p>	<ul> <li>00:20 - Intro to the show, contact information and how to provide comments.&nbsp; Welcome to all the new listeners - and to all those listeners who have been here for so long!&nbsp; </li><br />
<li>01:03 - Programming notes:<br />
<ul><li>New comment line &#8211; 206-350-7280</li><br />
<li>Slight web site changes</li><br />
<li>Books from Peter Thermos and Ari Takanen &#8211; anniversary show promotion</li></ul><br />
<li>03:27 - NetworkWorld: <a href="http://www.networkworld.com/news/2007/100107-voip-top-vulnerabilities.html">Top 14 VoIP Vulnerabilities</a> &#8211; and also <a href="http://www.networkworld.com/community/node/20120">this comment in reply</a></li><br />
<li>07:08 - blog.spywareguide.com: <a href="http://blog.spywareguide.com/2007/09/bubblesfor_kids.html">Bubbles&#8230; for Kids!</a>  (spyware that propagates via Skype IM)</li><br />
<li>09:25 - Voice of VoIPSA: <a href="http://voipsa.org/blog/2007/09/25/asterisk-what-would-your-security-roadmap-for-asterisk-be/">What would your security roadmap for Asterisk be?</a> and <a href="http://www.disruptivetelephony.com/2007/10/the-audacity-of.html">3Com to sell/support Asterisk</a></li><br />
<li>18:11 - Voice of <span class="caps">VOIPSA</span>: <a href="http://voipsa.org/blog/2007/09/28/voip-hacker-goes-to-jail/">VoIP Hacker Goes to Jail</a> pointing to <a href="http://www.informationweek.com/news/showArticle.jhtml?articleID=202101781">Information Week interview with Robert Moore</a> which is similar to the <a href="http://www.thevoicereport.com/TelecomJunkiesArchive-VoIPHacker.html">Telecom Junkies interview</a> I did earlier with Robert Moore.</li><br />
<li>19:14 - Converge!Digest: <a href="http://www.convergedigest.com/bp/bp1.asp?ID=489&#38;ctgy=2">Defending the <span class="caps">IMS </span>Core</a> (sponsored by Sonus)</li><br />
<li>20:56 - Processor: <a href="http://www.processor.com/editorial/article.asp?article=articles/P2939/21p39/21p39.asp&#38;guid">Getting Tough with <span class="caps">P2P</span></a>= which relates to <a href="http://www.disruptivetelephony.com/2007/09/how-using-skype.html">Dan&#8217;s recent issues with using Skype at a hotel</a></li><br />
<li>26:36 - <span class="caps">PC </span>World: <a href="http://www.pcworld.com/businesscenter/article/137797/attack_of_the_killer_bots.html">Attack of the Killer Bots</a></li><br />
<li>28:57 - News Releases<ul><li><a href="http://www.prnewswire.com/cgi-bin/stories.pl?ACCT=104&#38;STORY=/www/story/10-02-2007/0004674099&#38;EDATE">Sipera Secures $10 Million to Further Advance VoIP/UC Security</a>=</li><br />
<li><a href="http://home.businesswire.com/portal/site/google/index.jsp?ndmViewId=news_view&#38;newsId=20071001005948&#38;newsLang=en">Bandwidth.com Bands with Acme Packet</a> (finally, security for <span class="caps">SIP</span> trunking!)</li><br />
<li><a href="http://money.cnn.com/news/newsfeeds/articles/prnewswire/LNM00101102007-1.htm">Radware Unveils Industry First Behavioral Server Protections as Part of its Full Spectrum Protection Technology</a></li><br />
<li><a href="http://home.businesswire.com/portal/site/google/index.jsp?ndmViewId=news_view&#38;newsId=20071001005119&#38;newsLang=en">Alcatel-Lucent Bolsters its Security Solutions in Worldwide Reseller Agreement with CloudShield Technologies</a></li><br />
<li><a href="http://www.tmcnet.com/comsol/articles/11625-clavister-announces-new-version-its-ip-based-security.htm">Clavister Announces New Version of its IP-Based Security Operating System</a>  (see also <a href="http://www.kauppalehti.fi/4/i/eng/releases/press_release.jsp?selected=other&#38;oid=20070901/11909837707310&#38;lang=EN">press release</a> )</li><br />
<li><a href="http://www.sourcewire.com/releases/rel_display.php?relid=34083&#38;hilite">ForeScout Continues Innovation Leadership with Latest Network Access Control Offering</a>=</li><br />
</ul><br />
<li>32:24 - <a href="http://www.crn.com/networking/202102837">3Com bought by Bain Capital, Huawei</a> </li><br />
<li>34:58 - <a href="http://www.disruptivetelephony.com/2007/10/ebay-pays-530-m.html">Skype <span class="caps">CEO</span> out, eBay takes $1.4 million charge</a></li><br />
<li>37:08 - <a href="http://news.google.com/news?hl=en&#38;ned=us&#38;q=nokia+navteq&#38;btnG=Search+News">Nokia to buy Navteq</a></li><br />
<li>38:26 - Vonage loses patent trial<br /></li><br />
<li>39:29 - Upcoming shows:<br /><ul> <br />
<li>Oct 24-25, New York, USA, <a href="http://www.interop.net/">Interop</a><br />
<li>Oct 29-Nov 1, Boston, <span class="caps">USA</span>, <a href="http://www.von.com/2007/fall_boston/">Fall 2007 <span class="caps">VON</span></a></li></ul> </li><br />
<li>39:58 - Comment (email) from Peter Thermos</li><br />
<li>42:15 - Comment (email) from Frank Leonhardt about Skype malware</li><br />
<li>42:24 - Comments (blog) <a href="http://www.blueboxpodcast.com/2007/08/blue-box-video-.html#comments">about video edition #1</a></li><br />
<li>42:51 - Brief commentary from Dan about using TalkPlus to call a <span class="caps">SIP URI</span> from a cell phone</li><br />
<li>45:39 - Review of the last week's traffic on the <a href="http://www.voipsa.org/VOIPSEC/">VOIPSEC </a>public mailing list&nbsp; </li><br />
<li>46:00 - Wrap-up of the show <br /></li><br />
<li>46:51 - End of show&nbsp; </li></ul> <p>Comments, suggestions and feedback are welcome either as replies to this post&nbsp; or via e-mail to <a href="mailto:blueboxpodcast@gmail.com">blueboxpodcast@gmail.com</a>.&nbsp; Audio comments sent as attached MP3 files are definitely welcome and will be played in future shows.&nbsp; You may also call the listener comment line at either +1-206-350-7280 or via SIP to '<a href="sip:bluebox@voipuser.org">bluebox@voipuser.org</a>' to leave a comment there.&nbsp; </p> <p>Thank you for listening and please do let us know what you think of the show. </p></p></div>

<p><a href="http://feeds.feedburner.com/~a/BlueBox?a=Uda19a"><img src="http://feeds.feedburner.com/~a/BlueBox?i=Uda19a" border="0"></img></a></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/BlueBox?a=JGxhshf4"><img src="http://feeds.feedburner.com/~f/BlueBox?i=JGxhshf4" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/BlueBox?a=dnbU2EeA"><img src="http://feeds.feedburner.com/~f/BlueBox?i=dnbU2EeA" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/BlueBox?a=2bL8868d"><img src="http://feeds.feedburner.com/~f/BlueBox?i=2bL8868d" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/BlueBox?a=2zPj6l7R"><img src="http://feeds.feedburner.com/~f/BlueBox?i=2zPj6l7R" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/BlueBox?a=P6SgLmEN"><img src="http://feeds.feedburner.com/~f/BlueBox?i=P6SgLmEN" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/BlueBox?a=Lj18nyY3"><img src="http://feeds.feedburner.com/~f/BlueBox?i=Lj18nyY3" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/BlueBox/~4/164629784" height="1" width="1"/>]]></content:encoded>
      <pubDate>Sat, 27 Oct 2007 10:33:10 +0000</pubDate>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/voip security news">voip security news</category>
      <category domain="http://securityratty.com/tag/asterisk">asterisk</category>
      <category domain="http://securityratty.com/tag/asterisk security">asterisk security</category>
      <category domain="http://securityratty.com/tag/comments">comments</category>
      <category domain="http://securityratty.com/tag/sellsupport asterisk">sellsupport asterisk</category>
      <category domain="http://securityratty.com/tag/skype">skype</category>
      <category domain="http://securityratty.com/tag/listener comments">listener comments</category>
      <category domain="http://securityratty.com/tag/listener comment line">listener comment line</category>
      <source url="http://feeds.feedburner.com/~r/BlueBox/~3/164629784/synopsisblue-bo.html">Blue Box #68: Top 14 VoIP Vulnerabilities, Asterisk security, VoIP hacker, IMS, P2P, Skype, industry moves, VoIP security news, listener comments and </source>
    </item>
    <item>
      <title><![CDATA[Blue Box #68: Top 14 VoIP Vulnerabilities, Asterisk security, VoIP hacker, IMS, P2P, Skype, industry moves, VoIP security news, listener comments and ]]></title>
      <link>http://securityratty.com/article/dcb75f646e79c7aff03810543af541c8</link>
      <guid>http://securityratty.com/article/dcb75f646e79c7aff03810543af541c8</guid>
      <description><![CDATA[Synopsis: Blue Box #68: Top 14 VoIP Vulnerabilities, Asterisk security, VoIP hacker, IMS, P2P, Skype, industry moves, VoIP security news, listener comments and more
Welcome to Blue Box: The VoIP...]]></description>
      <content:encoded><![CDATA[
<div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Synopsis:</strong>Blue Box #68: Top 14 VoIP Vulnerabilities, Asterisk security, VoIP hacker, IMS, P2P, Skype, industry moves, VoIP security news, listener comments and more...  

<hr /><p>Welcome to <strong>Blue Box: The VoIP Security Podcast</strong> #68, a 46-minute podcast&nbsp; from Dan York and Jonathan Zar covering VoIP security news, comments and opinions.&nbsp; &nbsp; </p>

<p><a href="http://ripple.radiotail.com/409/BBP-068-2007-10-03.mp3" rel="enclosure">Download the show here</a> (MP3, 21MB) or <a href="http://feeds.feedburner.com/BlueBox">subscribe to the RSS feed</a> to download the show automatically.&nbsp; </p> 

<p>You may also listen to this podcast right now:</p> 

<p>
<p><object width="200" height="20" type="application/x-shockwave-flash" data="http://www.blueboxpodcast.com/dewplayer.swf?son=http://ripple.radiotail.com/409/BBP-068-2007-10-03.mp3"><param name="movie" value="http://www.blueboxpodcast.com/dewplayer.swf?son=http://ripple.radiotail.com/409/BBP-068-2007-10-03.mp3&amp;bgcolor=#FFFFFF" /></object> </p> <p><strong>Show Content:</strong></p> 
<p><strong>Show Content:</strong></p> 

<p>	<ul> <li>00:20 - Intro to the show, contact information and how to provide comments.&nbsp; Welcome to all the new listeners - and to all those listeners who have been here for so long!&nbsp; </li><br />
<li>01:03 - Programming notes:<br />
<ul><li>New comment line &#8211; 206-350-7280</li><br />
<li>Slight web site changes</li><br />
<li>Books from Peter Thermos and Ari Takanen &#8211; anniversary show promotion</li></ul><br />
<li>03:27 - NetworkWorld: <a href="http://www.networkworld.com/news/2007/100107-voip-top-vulnerabilities.html">Top 14 VoIP Vulnerabilities</a> &#8211; and also <a href="http://www.networkworld.com/community/node/20120">this comment in reply</a></li><br />
<li>07:08 - blog.spywareguide.com: <a href="http://blog.spywareguide.com/2007/09/bubblesfor_kids.html">Bubbles&#8230; for Kids!</a>  (spyware that propagates via Skype IM)</li><br />
<li>09:25 - Voice of VoIPSA: <a href="http://voipsa.org/blog/2007/09/25/asterisk-what-would-your-security-roadmap-for-asterisk-be/">What would your security roadmap for Asterisk be?</a> and <a href="http://www.disruptivetelephony.com/2007/10/the-audacity-of.html">3Com to sell/support Asterisk</a></li><br />
<li>18:11 - Voice of <span class="caps">VOIPSA</span>: <a href="http://voipsa.org/blog/2007/09/28/voip-hacker-goes-to-jail/">VoIP Hacker Goes to Jail</a> pointing to <a href="http://www.informationweek.com/news/showArticle.jhtml?articleID=202101781">Information Week interview with Robert Moore</a> which is similar to the <a href="http://www.thevoicereport.com/TelecomJunkiesArchive-VoIPHacker.html">Telecom Junkies interview</a> I did earlier with Robert Moore.</li><br />
<li>19:14 - Converge!Digest: <a href="http://www.convergedigest.com/bp/bp1.asp?ID=489&#38;ctgy=2">Defending the <span class="caps">IMS </span>Core</a> (sponsored by Sonus)</li><br />
<li>20:56 - Processor: <a href="http://www.processor.com/editorial/article.asp?article=articles/P2939/21p39/21p39.asp&#38;guid">Getting Tough with <span class="caps">P2P</span></a>= which relates to <a href="http://www.disruptivetelephony.com/2007/09/how-using-skype.html">Dan&#8217;s recent issues with using Skype at a hotel</a></li><br />
<li>26:36 - <span class="caps">PC </span>World: <a href="http://www.pcworld.com/businesscenter/article/137797/attack_of_the_killer_bots.html">Attack of the Killer Bots</a></li><br />
<li>28:57 - News Releases<ul><li><a href="http://www.prnewswire.com/cgi-bin/stories.pl?ACCT=104&#38;STORY=/www/story/10-02-2007/0004674099&#38;EDATE">Sipera Secures $10 Million to Further Advance VoIP/UC Security</a>=</li><br />
<li><a href="http://home.businesswire.com/portal/site/google/index.jsp?ndmViewId=news_view&#38;newsId=20071001005948&#38;newsLang=en">Bandwidth.com Bands with Acme Packet</a> (finally, security for <span class="caps">SIP</span> trunking!)</li><br />
<li><a href="http://money.cnn.com/news/newsfeeds/articles/prnewswire/LNM00101102007-1.htm">Radware Unveils Industry First Behavioral Server Protections as Part of its Full Spectrum Protection Technology</a></li><br />
<li><a href="http://home.businesswire.com/portal/site/google/index.jsp?ndmViewId=news_view&#38;newsId=20071001005119&#38;newsLang=en">Alcatel-Lucent Bolsters its Security Solutions in Worldwide Reseller Agreement with CloudShield Technologies</a></li><br />
<li><a href="http://www.tmcnet.com/comsol/articles/11625-clavister-announces-new-version-its-ip-based-security.htm">Clavister Announces New Version of its IP-Based Security Operating System</a>  (see also <a href="http://www.kauppalehti.fi/4/i/eng/releases/press_release.jsp?selected=other&#38;oid=20070901/11909837707310&#38;lang=EN">press release</a> )</li><br />
<li><a href="http://www.sourcewire.com/releases/rel_display.php?relid=34083&#38;hilite">ForeScout Continues Innovation Leadership with Latest Network Access Control Offering</a>=</li><br />
</ul><br />
<li>32:24 - <a href="http://www.crn.com/networking/202102837">3Com bought by Bain Capital, Huawei</a> </li><br />
<li>34:58 - <a href="http://www.disruptivetelephony.com/2007/10/ebay-pays-530-m.html">Skype <span class="caps">CEO</span> out, eBay takes $1.4 million charge</a></li><br />
<li>37:08 - <a href="http://news.google.com/news?hl=en&#38;ned=us&#38;q=nokia+navteq&#38;btnG=Search+News">Nokia to buy Navteq</a></li><br />
<li>38:26 - Vonage loses patent trial<br /></li><br />
<li>39:29 - Upcoming shows:<br /><ul> <br />
<li>Oct 24-25, New York, USA, <a href="http://www.interop.net/">Interop</a><br />
<li>Oct 29-Nov 1, Boston, <span class="caps">USA</span>, <a href="http://www.von.com/2007/fall_boston/">Fall 2007 <span class="caps">VON</span></a></li></ul> </li><br />
<li>39:58 - Comment (email) from Peter Thermos</li><br />
<li>42:15 - Comment (email) from Frank Leonhardt about Skype malware</li><br />
<li>42:24 - Comments (blog) <a href="http://www.blueboxpodcast.com/2007/08/blue-box-video-.html#comments">about video edition #1</a></li><br />
<li>42:51 - Brief commentary from Dan about using TalkPlus to call a <span class="caps">SIP URI</span> from a cell phone</li><br />
<li>45:39 - Review of the last week's traffic on the <a href="http://www.voipsa.org/VOIPSEC/">VOIPSEC </a>public mailing list&nbsp; </li><br />
<li>46:00 - Wrap-up of the show <br /></li><br />
<li>46:51 - End of show&nbsp; </li></ul> <p>Comments, suggestions and feedback are welcome either as replies to this post&nbsp; or via e-mail to <a href="mailto:blueboxpodcast@gmail.com">blueboxpodcast@gmail.com</a>.&nbsp; Audio comments sent as attached MP3 files are definitely welcome and will be played in future shows.&nbsp; You may also call the listener comment line at either +1-206-350-7280 or via SIP to '<a href="sip:bluebox@voipuser.org">bluebox@voipuser.org</a>' to leave a comment there.&nbsp; </p> <p>Thank you for listening and please do let us know what you think of the show. </p></p></div>
]]></content:encoded>
      <pubDate>Wed, 03 Oct 2007 02:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/voip security news">voip security news</category>
      <category domain="http://securityratty.com/tag/asterisk">asterisk</category>
      <category domain="http://securityratty.com/tag/asterisk security">asterisk security</category>
      <category domain="http://securityratty.com/tag/comments">comments</category>
      <category domain="http://securityratty.com/tag/sellsupport asterisk">sellsupport asterisk</category>
      <category domain="http://securityratty.com/tag/skype">skype</category>
      <category domain="http://securityratty.com/tag/listener comments">listener comments</category>
      <category domain="http://securityratty.com/tag/listener comment line">listener comment line</category>
      <source url="http://www.blueboxpodcast.com/2007/10/synopsisblue-bo.html">Blue Box #68: Top 14 VoIP Vulnerabilities, Asterisk security, VoIP hacker, IMS, P2P, Skype, industry moves, VoIP security news, listener comments and </source>
    </item>
  </channel>
</rss>
