<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: listener]]></title>
    <link>http://securityratty.com/tag/listener</link>
    <description></description>
    <pubDate>Tue, 29 Apr 2008 09:56:50 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[Speaking of Security Podcast #110]]></title>
      <link>http://securityratty.com/article/21502f9ef22320ee774fb83d712b5764</link>
      <guid>http://securityratty.com/article/21502f9ef22320ee774fb83d712b5764</guid>
      <description><![CDATA[Click to Download/Listen (12:39
Both Gartner and Forrester , two of the leading independent technology and market research firms, recently evaluated data loss prevention (or DLP) vendors in their...]]></description>
      <content:encoded><![CDATA[<br /><a href="http://www.rsa.com/blog/blog_entry.aspx?id=1293">Click to Download/Listen</a> (12:39)<br>
<br clear="all" />
Both <a href="http://rsa.com/press_release.aspx?id=9448">Gartner</a> and <a href="http://www.rsa.com/blog/blog_entry.aspx?id=1289">Forrester</a>, two of the leading independent technology and market research firms, recently evaluated  data loss prevention (or DLP) vendors in their annual reports on this market. <a href="http://rsa.com/node.aspx?id=3426" target="_blank">RSA's Data Loss Prevention Suite</a> was named as a leader by both of these firms. Paul Joyal talks about these reports with Tom Corn, Vice President of Products for RSA's Data Security Group. <strong>And we continue with another giveaway for Podcast Listener Appreciation Month for all responders to our <a href="http://www.zipsurvey.com/LaunchSurvey.aspx?suid=30142&key=C8500AE4" target="_blank">Authentication Poll</a>!</strong> Listen to this week's podcast for the secret word!<br /><br />]]></content:encoded>
      <pubDate>Sun, 22 Jun 2008 20:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/firms">firms</category>
      <category domain="http://securityratty.com/tag/market research firms">market research firms</category>
      <category domain="http://securityratty.com/tag/market">market</category>
      <category domain="http://securityratty.com/tag/annual reports">annual reports</category>
      <category domain="http://securityratty.com/tag/reports">reports</category>
      <category domain="http://securityratty.com/tag/data loss prevention">data loss prevention</category>
      <category domain="http://securityratty.com/tag/paul joyal talks">paul joyal talks</category>
      <category domain="http://securityratty.com/tag/vice president">vice president</category>
      <category domain="http://securityratty.com/tag/authentication poll">authentication poll</category>
      <source url="http://www.rsa.com/blog/blog_entry.aspx?id=1293">Speaking of Security Podcast #110</source>
    </item>
    <item>
      <title><![CDATA[Speaking of Security Podcast #109]]></title>
      <link>http://securityratty.com/article/360cdb67ff4eefe61368c7375512e616</link>
      <guid>http://securityratty.com/article/360cdb67ff4eefe61368c7375512e616</guid>
      <description><![CDATA[Click to Download/Listen (05:48
Last week's headline: &quot; RSA, The Security Division of EMC, Expands Identity Assurance Portfolio with Flexible Card-Shaped Authenticator to Provide Convenient Online...]]></description>
      <content:encoded><![CDATA[<a href="http://www.rsa.com/blog/blog_entry.aspx?id=1291">Click to Download/Listen</a> (05:48)<br>
<br clear="all" />
Last week's headline: &quot;<a href="http://rsa.com/press_release.aspx?id=9425" target="_blank">RSA, The Security Division of EMC, Expands Identity Assurance Portfolio with   Flexible Card-Shaped Authenticator to Provide Convenient Online Security</a>&quot; is the topic of this week's interview with RSA's Rachael Stockton.<strong> And we continue  with another giveaway for Podcast Listener Appreciation Month for all responders to our <a href="http://www.zipsurvey.com/LaunchSurvey.aspx?suid=30142&amp;key=C8500AE4" target="_blank">Authentication Poll</a>!</strong> Listen to this week's podcast for the secret word!<br><br>]]></content:encoded>
      <pubDate>Sun, 15 Jun 2008 20:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/week">week</category>
      <category domain="http://securityratty.com/tag/rachael stockton">rachael stockton</category>
      <category domain="http://securityratty.com/tag/authentication poll">authentication poll</category>
      <category domain="http://securityratty.com/tag/security division">security division</category>
      <category domain="http://securityratty.com/tag/rsa">rsa</category>
      <category domain="http://securityratty.com/tag/secret word">secret word</category>
      <category domain="http://securityratty.com/tag/podcast">podcast</category>
      <category domain="http://securityratty.com/tag/emc">emc</category>
      <category domain="http://securityratty.com/tag/giveaway">giveaway</category>
      <source url="http://www.rsa.com/blog/blog_entry.aspx?id=1291">Speaking of Security Podcast #109</source>
    </item>
    <item>
      <title><![CDATA[Blue Box SE#025 - An interview with Eric Hernaez about Solegy and the OpenSBC Project]]></title>
      <link>http://securityratty.com/article/68cc0edd9defde9601e764783f55b503</link>
      <guid>http://securityratty.com/article/68cc0edd9defde9601e764783f55b503</guid>
      <description><![CDATA[Synopsis: Blue Box Special Edition #25: An interview with Eric Hernaez, CEO of Solegy, about the OpenSBC project
Welcome to Blue Box: The VoIP Security Podcast Special Edition #25, a 13-minute podcast...]]></description>
      <content:encoded><![CDATA[
<div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Synopsis:</strong>&nbsp; Blue Box Special Edition #25: An interview with Eric Hernaez, CEO of Solegy, about <a href="http://www.opensourcesip.org:8080/clearspacex/index.jspa">the OpenSBC project</a></p><hr /><p>Welcome to <strong>Blue Box: The VoIP Security Podcast</strong> Special Edition #25, a 13-minute podcast&nbsp; from Dan York and Jonathan Zar covering VoIP security news, comments and opinions.&nbsp; &nbsp; </p>

<p><a href="http://media.libsyn.com/media/lodestar/BBP-SE025-SolegyOpenSBC.mp3" rel="enclosure">Download the show here</a> (MP3, 6MB) or <a href="http://feeds.feedburner.com/BlueBox">subscribe to the RSS feed</a> to download the show automatically.&nbsp; </p>

<p>You may also listen to this podcast right now:</p> 

<p><object width="200" height="20" type="application/x-shockwave-flash" data="http://www.blueboxpodcast.com/dewplayer.swf?son=http://media.libsyn.com/media/lodestar/BBP-SE025-SolegyOpenSBC.mp3"><param name="movie" value="http://www.blueboxpodcast.com/dewplayer.swf?son=http://media.libsyn.com/media/lodestar/BBP-SE025-SolegyOpenSBC.mp3&amp;bgcolor=#FFFFFF" /></object> </p> 

<p><strong>Show Content:</strong></p> 
<p><img width="222" height="87" border="0" align="right" alt="solegylogo.jpg" src="http://www.blueboxpodcast.com/images/solegylogo.jpg" />In this interview, I sat down with Eric Hernaez, CEO of <a href="http://www.solegy.com/">Solegy</a>, to talk about<a href="http://www.opensourcesip.org:8080/clearspacex/index.jspa"> the OpenSBC Project</a> and how it provides an open source implementation of a session border controller (SBC).&nbsp; We talked about how OpenSBC came about, who is using it, how scalable it is and where users can learn more.&nbsp; We also discussed <a href="http://www.solegy.com/">Solegy,</a> the company supporting the open source OpenSBC project and what they are doing. It was an enjoyable talk that really came about randomly when I met Eric near the press room at IT Expo in Los Angeles back in September 2007. We had been wanting to learn more about the OpenSBC project so I put my recorder on a table and we started talking.</p>

<p>More information about the OpenSBC project and other open source SIP-related projects can be found at <a href="http://www.opensourcesip.org">opensourcesip.org</a>.</p>

<p>Production assistance on this Special Edition was provided by Sergio Meinardi.

</p>

<p>Comments, suggestions and feedback are welcome either as replies to this post&nbsp; or via e-mail to <a href="mailto:blueboxpodcast@gmail.com">blueboxpodcast@gmail.com</a>.&nbsp; Audio comments sent as attached MP3 files are definitely welcome and will be played in future shows.&nbsp; You may also call the listener comment line at either +1-415-830-5439 or via SIP to '<a href="sip:bluebox@voipuser.org">bluebox@voipuser.org</a>' to leave a comment there.&nbsp; </p> <p>Thank you for listening and please do let us know what you think of the show. </p></div>
]]></content:encoded>
      <pubDate>Tue, 10 Jun 2008 18:53:28 +0000</pubDate>
      <category domain="http://securityratty.com/tag/opensbc">opensbc</category>
      <category domain="http://securityratty.com/tag/source opensbc project">source opensbc project</category>
      <category domain="http://securityratty.com/tag/opensbc project">opensbc project</category>
      <category domain="http://securityratty.com/tag/source">source</category>
      <category domain="http://securityratty.com/tag/eric hernaez">eric hernaez</category>
      <category domain="http://securityratty.com/tag/eric">eric</category>
      <category domain="http://securityratty.com/tag/solegy">solegy</category>
      <category domain="http://securityratty.com/tag/comments">comments</category>
      <category domain="http://securityratty.com/tag/audio comments">audio comments</category>
      <source url="http://www.blueboxpodcast.com/2008/06/blue-box-se025.html">Blue Box SE#025 - An interview with Eric Hernaez about Solegy and the OpenSBC Project</source>
    </item>
    <item>
      <title><![CDATA[Blue Box SE#025 - An interview with Eric Hernaez about Solegy and the OpenSBC Project]]></title>
      <link>http://securityratty.com/article/9cd229af930b928b9597a5a6ecba0b01</link>
      <guid>http://securityratty.com/article/9cd229af930b928b9597a5a6ecba0b01</guid>
      <description><![CDATA[Synopsis: Blue Box Special Edition #25: An interview with Eric Hernaez, CEO of Solegy, about the OpenSBC project
Welcome to Blue Box: The VoIP Security Podcast Special Edition #25, a 13-minute podcast...]]></description>
      <content:encoded><![CDATA[
<div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Synopsis:</strong>&nbsp; Blue Box Special Edition #25: An interview with Eric Hernaez, CEO of Solegy, about <a href="http://www.opensourcesip.org:8080/clearspacex/index.jspa">the OpenSBC project</a></p><hr /><p>Welcome to <strong>Blue Box: The VoIP Security Podcast</strong> Special Edition #25, a 13-minute podcast&nbsp; from Dan York and Jonathan Zar covering VoIP security news, comments and opinions.&nbsp; &nbsp; </p>

<p><a href="http://media.libsyn.com/media/lodestar/BBP-SE025-SolegyOpenSBC.mp3" rel="enclosure">Download the show here</a> (MP3, 6MB) or <a href="http://feeds.feedburner.com/BlueBox">subscribe to the RSS feed</a> to download the show automatically.&nbsp; </p>

<p>You may also listen to this podcast right now:</p> 

<p><object width="200" height="20" type="application/x-shockwave-flash" data="http://www.blueboxpodcast.com/dewplayer.swf?son=http://media.libsyn.com/media/lodestar/BBP-SE025-SolegyOpenSBC.mp3"><param name="movie" value="http://www.blueboxpodcast.com/dewplayer.swf?son=http://media.libsyn.com/media/lodestar/BBP-SE025-SolegyOpenSBC.mp3&amp;bgcolor=#FFFFFF" /></object> </p> 

<p><strong>Show Content:</strong></p> 
<p><img width="222" height="87" border="0" align="right" alt="solegylogo.jpg" src="http://www.blueboxpodcast.com/images/solegylogo.jpg" />In this interview, I sat down with Eric Hernaez, CEO of <a href="http://www.solegy.com/">Solegy</a>, to talk about<a href="http://www.opensourcesip.org:8080/clearspacex/index.jspa"> the OpenSBC Project</a> and how it provides an open source implementation of a session border controller (SBC).&nbsp; We talked about how OpenSBC came about, who is using it, how scalable it is and where users can learn more.&nbsp; We also discussed <a href="http://www.solegy.com/">Solegy,</a> the company supporting the open source OpenSBC project and what they are doing. It was an enjoyable talk that really came about randomly when I met Eric near the press room at IT Expo in Los Angeles back in September 2007. We had been wanting to learn more about the OpenSBC project so I put my recorder on a table and we started talking.</p>

<p>More information about the OpenSBC project and other open source SIP-related projects can be found at <a href="http://www.opensourcesip.org">opensourcesip.org</a>.</p>

<p>Production assistance on this Special Edition was provided by Sergio Meinardi.

</p>

<p>Comments, suggestions and feedback are welcome either as replies to this post&nbsp; or via e-mail to <a href="mailto:blueboxpodcast@gmail.com">blueboxpodcast@gmail.com</a>.&nbsp; Audio comments sent as attached MP3 files are definitely welcome and will be played in future shows.&nbsp; You may also call the listener comment line at either +1-415-830-5439 or via SIP to '<a href="sip:bluebox@voipuser.org">bluebox@voipuser.org</a>' to leave a comment there.&nbsp; </p> <p>Thank you for listening and please do let us know what you think of the show. </p></div>

<p><a href="http://feeds.feedburner.com/~a/BlueBox?a=EpTKwo"><img src="http://feeds.feedburner.com/~a/BlueBox?i=EpTKwo" border="0"></img></a></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/BlueBox?a=5UpepI"><img src="http://feeds.feedburner.com/~f/BlueBox?i=5UpepI" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/BlueBox?a=7EQicI"><img src="http://feeds.feedburner.com/~f/BlueBox?i=7EQicI" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/BlueBox?a=7bNNsI"><img src="http://feeds.feedburner.com/~f/BlueBox?i=7bNNsI" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/BlueBox?a=2fp6ZI"><img src="http://feeds.feedburner.com/~f/BlueBox?i=2fp6ZI" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/BlueBox?a=hx2yui"><img src="http://feeds.feedburner.com/~f/BlueBox?i=hx2yui" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/BlueBox?a=gImhuI"><img src="http://feeds.feedburner.com/~f/BlueBox?i=gImhuI" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/BlueBox/~4/309295183" height="1" width="1"/>]]></content:encoded>
      <pubDate>Tue, 10 Jun 2008 18:02:51 +0000</pubDate>
      <category domain="http://securityratty.com/tag/opensbc">opensbc</category>
      <category domain="http://securityratty.com/tag/source opensbc project">source opensbc project</category>
      <category domain="http://securityratty.com/tag/opensbc project">opensbc project</category>
      <category domain="http://securityratty.com/tag/source">source</category>
      <category domain="http://securityratty.com/tag/eric hernaez">eric hernaez</category>
      <category domain="http://securityratty.com/tag/eric">eric</category>
      <category domain="http://securityratty.com/tag/solegy">solegy</category>
      <category domain="http://securityratty.com/tag/comments">comments</category>
      <category domain="http://securityratty.com/tag/audio comments">audio comments</category>
      <source url="http://feeds.feedburner.com/~r/BlueBox/~3/309295183/blue-box-se025.html">Blue Box SE#025 - An interview with Eric Hernaez about Solegy and the OpenSBC Project</source>
    </item>
    <item>
      <title><![CDATA[Blue Box #79: Asterisk vulnerabilities, VoiceCon/VON coverage, eavesdropping, FBI, ZFone, P2P, VoIP security news and more]]></title>
      <link>http://securityratty.com/article/12a646d6f75cd20c5bdf249647b13de5</link>
      <guid>http://securityratty.com/article/12a646d6f75cd20c5bdf249647b13de5</guid>
      <description><![CDATA[Synopsis: Blue Box #79: Asterisk vulnerabilities, VoiceCon/VON coverage, eavesdropping, FBI, ZFone, P2P, VoIP security news and more
Welcome to Blue Box: The VoIP Security Podcast #78, a 32-minute...]]></description>
      <content:encoded><![CDATA[
<div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Synopsis:</strong>&nbsp; Blue Box #79: Asterisk vulnerabilities, VoiceCon/VON coverage, eavesdropping, FBI, ZFone, P2P, VoIP security news and more</p><hr /><p>Welcome to <strong>Blue Box: The VoIP Security Podcast</strong> #78, a 32-minute podcast&nbsp; from Dan York and Jonathan Zar covering VoIP security news, comments and opinions.&nbsp; &nbsp; </p>

<p><a rel="enclosure" href="http://media.libsyn.com/media/lodestar/BBP-079-2008-03-27.mp3">Download the show here</a> (MP3, 15MB) or <a href="http://feeds.feedburner.com/BlueBox">subscribe to the RSS feed</a> to download the show automatically.&nbsp; </p>

<p><strong>NOTE: </strong><em>This show was originally recorded on March 27, 2008. Yes, that was over two months ago... we know...</em></p> 

<p>You may also listen to this podcast right now:</p> 

<p><object width="200" height="20" data="http://www.blueboxpodcast.com/dewplayer.swf?son=http://media.libsyn.com/media/lodestar/BBP-079-2008-03-27.mp3" type="application/x-shockwave-flash"><param value="http://www.blueboxpodcast.com/dewplayer.swf?son=http://media.libsyn.com/media/lodestar/BBP-079-2008-03-27.mp3&amp;bgcolor=#FFFFFF" name="movie" /></object> </p> 

<p><strong>Show Content:</strong></p> 
 

<ul> <li>00:20 - Intro to the show, contact information and how to provide comments.&nbsp; Welcome to all the new listeners - and to all those listeners who have been here for so long!&nbsp; </li>

<p><li><span class="caps">MANY</span> thanks for all the offers of audio production assistance</li><br />
		<li>Dan met with Craig Bowser down at VoiceCon, also David Endler, Mark Collier, etc.</li><br />
		<li>Jonathan met with Dean Elwood, Martyn Davies, etc.</li><br />
		<li><a href="http://voipsa.org/blog/2008/03/21/four-new-security-vulnerabilities-in-asterisk-time-to-upgrade/">Four Asterisk vulnerabilities</a></li><br />
<li>The Economist: <a href="http://www.economist.com/printedition/displaystory.cfm?story_id=10789393">Bugging The Cloud</a></li><br />
<li>Forbes: <a href="http://www.forbes.com/technology/2008/03/18/zimmerman-hacking-voip-tech-security-cx_ag_0318voip.html">How to Make Your Phone Untappable</a></li><br />
<li>VoIP News: <a href="http://www.voip-news.com/feature/voip-spying-031308/">VoIP: Who Might Be Spying on Your Communications? (Hint &#8211; It&#8217;s Not Just the <span class="caps">NSA</span></a></li><br />
		<li>VoIP News: <a href="http://www.voip-news.com/feature/17-wiretap-signs-031908/">Listen Up: 17 Signs That You Are Being Wiretapped</a></li><br />
<li>eChannelLine: <a href="http://www.echannelline.com/usa/brief.cfm?item=15198">Businesses lagging in securing VoIP</a> (also <a href="http://www.computerweekly.com/Articles/2008/03/25/229961/security-being-ignored-as-voip-deployments-increase.htm">ComputerWeekly.com</a> and <a href="http://www.businesswire.com/portal/site/google/?ndmViewId=news_view&#38;newsId=20080324005525&#38;newsLang=en">news release</a> )</li><br />
		<li>eChannelLine: <a href="http://www.echannelline.com/usa/story.cfm?item=23076">Ingate launches enhanced security for VoIP and <span class="caps">SIP</span></a> (also <a href="http://www.voipplanet.com/solutions/article.php/3735601">Enterprise VoIPPlanet</a> )</li><br />
<li>Voice of <span class="caps">VOIPSA</span>: <a href="http://voipsa.org/blog/2008/03/24/hacking-zyxel-gateways/">Hacking Zyxel Gateways</a></li><br />
		<li>Voice of <span class="caps">VOIPSA</span>: <a href="http://voipsa.org/blog/2008/03/17/vishing-attacks/">Vishing Attacks</a></li><br />
		<li>Voice of <span class="caps">VOIPSA</span>: <a href="http://voipsa.org/blog/2008/03/19/fbi-voip-surveillance-requirements-leaked/">FBI VoIP Surveillance Requirements Leaked</a> (also in <a href="http://www.fiercevoip.com/story/fbi-voip-docs-leaked-again/2008-03-17">FierceVoIP</a> and <a href="http://yro.slashdot.org/article.pl?sid=08/03/15/2021257">Slashdot</a> )</li><br />
		<li>Voice of <span class="caps">VOIPSA</span>: <a href="http://voipsa.org/blog/2008/03/20/hackers-send-thousands-of-fake-calls-to-deaf-people/">Hackers Send Thousands of Fake Calls to Deaf People</a></li><br />
<li>SnapVoIP: <a href="http://snapvoip.blogspot.com/2008/03/unified-communications-in-virtual.html">Unified Communications in Virtual Worlds to Solve &#8216;Tower of Babel&#8217; for Intelligence Agencies</a></li><br />
		<li><a href="http://www.textually.org/textually/archives/2008/03/019464.htm">Israeli-made Cryptophone attracts world spy agencies</a> pointing to <a href="http://www.tikalnetworks.com/voip/index.php?cid=29">product site</a></li><br />
<li>BlogInfoSec.com: <a href="http://www.bloginfosec.com/2008/03/25/save-the-whales/">Save The Whales</a> (about a new form of phishing)</li><br />
<li>Network Computing: <a href="http://www.networkcomputing.com/immersion/dataprivacy/showArticle.jhtml?articleID=206904104">Your Data and the <span class="caps">P2P </span>Peril</a></li><br />
<li>NetQoS: <a href="http://www.networkperformancedaily.com/2008/03/voip_monitor_v11_released_and_1.html">VoIP Monitor 1.1 released</a></li><br />
<li><span class="caps">PC </span>World: <a href="http://www.pcworld.com/article/id,143810-c,webservices/article.html">FaceTime Security Product Scans Skype&#8217;s Encrypted IM</a> and <a href="http://www.earthtimes.org/articles/show/facetime-provides-unmatched-malware-prevention-for-leading-voip-and-chat-software,322357.shtml">news release</a></li><br />
		<li><a href="http://www.earthtimes.org/articles/show/sipera-ipcs-solution-for-teleworkers-rated-avaya-compliant,318456.shtml">Sipera <span class="caps">IPCS </span>Solution for Teleworkers Rated &#8216;Avaya Compliant&#8217;</a></li><br />
		<li><a href="http://www.earthtimes.org/articles/show/extreme-networks-boosts-security-for-converged-voice-and-data-networks,317382.shtml">Extreme Networks Boosts Security for Converged Voice and Data Networks with New Tools</a></li></p>

<p><li>Review of the last week's traffic on the <a href="http://www.voipsa.org/VOIPSEC/">VOIPSEC </a>public mailing list&nbsp; </li><br />
<li>Wrap-up of the show </li><br />
<li>32:27 - End of show&nbsp; </li></ul> <p>Comments, suggestions and feedback are welcome either as replies to this post&nbsp; or via e-mail to <a href="mailto:blueboxpodcast@gmail.com">blueboxpodcast@gmail.com</a>.&nbsp; Audio comments sent as attached MP3 files are definitely welcome and will be played in future shows.&nbsp; You may also call the listener comment line at either +1-415-830-5439 or via SIP to '<a href="sip:bluebox@voipuser.org">bluebox@voipuser.org</a>' to leave a comment there.&nbsp; </p> <p>Thank you for listening and please do let us know what you think of the show. </p></p></div>
]]></content:encoded>
      <pubDate>Mon, 09 Jun 2008 12:30:57 +0000</pubDate>
      <category domain="http://securityratty.com/tag/voip">voip</category>
      <category domain="http://securityratty.com/tag/voip security news">voip security news</category>
      <category domain="http://securityratty.com/tag/voip monitor">voip monitor</category>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/voip news">voip news</category>
      <category domain="http://securityratty.com/tag/asterisk vulnerabilities">asterisk vulnerabilities</category>
      <category domain="http://securityratty.com/tag/voip security podcast">voip security podcast</category>
      <category domain="http://securityratty.com/tag/blue box">blue box</category>
      <category domain="http://securityratty.com/tag/podcast">podcast</category>
      <source url="http://www.blueboxpodcast.com/2008/06/blue-box-79-ast.html">Blue Box #79: Asterisk vulnerabilities, VoiceCon/VON coverage, eavesdropping, FBI, ZFone, P2P, VoIP security news and more</source>
    </item>
    <item>
      <title><![CDATA[Blue Box #79: Asterisk vulnerabilities, VoiceCon/VON coverage, eavesdropping, FBI, ZFone, P2P, VoIP security news and more]]></title>
      <link>http://securityratty.com/article/6ff472aef8df8c39ce9d47bf4fe36d51</link>
      <guid>http://securityratty.com/article/6ff472aef8df8c39ce9d47bf4fe36d51</guid>
      <description><![CDATA[Synopsis: Blue Box #79: Asterisk vulnerabilities, VoiceCon/VON coverage, eavesdropping, FBI, ZFone, P2P, VoIP security news and more
Welcome to Blue Box: The VoIP Security Podcast #78, a 32-minute...]]></description>
      <content:encoded><![CDATA[
<div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Synopsis:</strong>&nbsp; Blue Box #79: Asterisk vulnerabilities, VoiceCon/VON coverage, eavesdropping, FBI, ZFone, P2P, VoIP security news and more</p><hr /><p>Welcome to <strong>Blue Box: The VoIP Security Podcast</strong> #78, a 32-minute podcast&nbsp; from Dan York and Jonathan Zar covering VoIP security news, comments and opinions.&nbsp; &nbsp; </p>

<p><a rel="enclosure" href="http://media.libsyn.com/media/lodestar/BBP-079-2008-03-27.mp3">Download the show here</a> (MP3, 15MB) or <a href="http://feeds.feedburner.com/BlueBox">subscribe to the RSS feed</a> to download the show automatically.&nbsp; </p>

<p><strong>NOTE: </strong><em>This show was originally recorded on March 27, 2008. Yes, that was over two months ago... we know...</em></p> 

<p>You may also listen to this podcast right now:</p> 

<p><object width="200" height="20" data="http://www.blueboxpodcast.com/dewplayer.swf?son=http://media.libsyn.com/media/lodestar/BBP-079-2008-03-27.mp3" type="application/x-shockwave-flash"><param value="http://www.blueboxpodcast.com/dewplayer.swf?son=http://media.libsyn.com/media/lodestar/BBP-079-2008-03-27.mp3&amp;bgcolor=#FFFFFF" name="movie" /></object> </p> 

<p><strong>Show Content:</strong></p> 
 

<ul> <li>00:20 - Intro to the show, contact information and how to provide comments.&nbsp; Welcome to all the new listeners - and to all those listeners who have been here for so long!&nbsp; </li>

<p><li><span class="caps">MANY</span> thanks for all the offers of audio production assistance</li><br />
		<li>Dan met with Craig Bowser down at VoiceCon, also David Endler, Mark Collier, etc.</li><br />
		<li>Jonathan met with Dean Elwood, Martyn Davies, etc.</li><br />
		<li><a href="http://voipsa.org/blog/2008/03/21/four-new-security-vulnerabilities-in-asterisk-time-to-upgrade/">Four Asterisk vulnerabilities</a></li><br />
<li>The Economist: <a href="http://www.economist.com/printedition/displaystory.cfm?story_id=10789393">Bugging The Cloud</a></li><br />
<li>Forbes: <a href="http://www.forbes.com/technology/2008/03/18/zimmerman-hacking-voip-tech-security-cx_ag_0318voip.html">How to Make Your Phone Untappable</a></li><br />
<li>VoIP News: <a href="http://www.voip-news.com/feature/voip-spying-031308/">VoIP: Who Might Be Spying on Your Communications? (Hint &#8211; It&#8217;s Not Just the <span class="caps">NSA</span></a></li><br />
		<li>VoIP News: <a href="http://www.voip-news.com/feature/17-wiretap-signs-031908/">Listen Up: 17 Signs That You Are Being Wiretapped</a></li><br />
<li>eChannelLine: <a href="http://www.echannelline.com/usa/brief.cfm?item=15198">Businesses lagging in securing VoIP</a> (also <a href="http://www.computerweekly.com/Articles/2008/03/25/229961/security-being-ignored-as-voip-deployments-increase.htm">ComputerWeekly.com</a> and <a href="http://www.businesswire.com/portal/site/google/?ndmViewId=news_view&#38;newsId=20080324005525&#38;newsLang=en">news release</a> )</li><br />
		<li>eChannelLine: <a href="http://www.echannelline.com/usa/story.cfm?item=23076">Ingate launches enhanced security for VoIP and <span class="caps">SIP</span></a> (also <a href="http://www.voipplanet.com/solutions/article.php/3735601">Enterprise VoIPPlanet</a> )</li><br />
<li>Voice of <span class="caps">VOIPSA</span>: <a href="http://voipsa.org/blog/2008/03/24/hacking-zyxel-gateways/">Hacking Zyxel Gateways</a></li><br />
		<li>Voice of <span class="caps">VOIPSA</span>: <a href="http://voipsa.org/blog/2008/03/17/vishing-attacks/">Vishing Attacks</a></li><br />
		<li>Voice of <span class="caps">VOIPSA</span>: <a href="http://voipsa.org/blog/2008/03/19/fbi-voip-surveillance-requirements-leaked/">FBI VoIP Surveillance Requirements Leaked</a> (also in <a href="http://www.fiercevoip.com/story/fbi-voip-docs-leaked-again/2008-03-17">FierceVoIP</a> and <a href="http://yro.slashdot.org/article.pl?sid=08/03/15/2021257">Slashdot</a> )</li><br />
		<li>Voice of <span class="caps">VOIPSA</span>: <a href="http://voipsa.org/blog/2008/03/20/hackers-send-thousands-of-fake-calls-to-deaf-people/">Hackers Send Thousands of Fake Calls to Deaf People</a></li><br />
<li>SnapVoIP: <a href="http://snapvoip.blogspot.com/2008/03/unified-communications-in-virtual.html">Unified Communications in Virtual Worlds to Solve &#8216;Tower of Babel&#8217; for Intelligence Agencies</a></li><br />
		<li><a href="http://www.textually.org/textually/archives/2008/03/019464.htm">Israeli-made Cryptophone attracts world spy agencies</a> pointing to <a href="http://www.tikalnetworks.com/voip/index.php?cid=29">product site</a></li><br />
<li>BlogInfoSec.com: <a href="http://www.bloginfosec.com/2008/03/25/save-the-whales/">Save The Whales</a> (about a new form of phishing)</li><br />
<li>Network Computing: <a href="http://www.networkcomputing.com/immersion/dataprivacy/showArticle.jhtml?articleID=206904104">Your Data and the <span class="caps">P2P </span>Peril</a></li><br />
<li>NetQoS: <a href="http://www.networkperformancedaily.com/2008/03/voip_monitor_v11_released_and_1.html">VoIP Monitor 1.1 released</a></li><br />
<li><span class="caps">PC </span>World: <a href="http://www.pcworld.com/article/id,143810-c,webservices/article.html">FaceTime Security Product Scans Skype&#8217;s Encrypted IM</a> and <a href="http://www.earthtimes.org/articles/show/facetime-provides-unmatched-malware-prevention-for-leading-voip-and-chat-software,322357.shtml">news release</a></li><br />
		<li><a href="http://www.earthtimes.org/articles/show/sipera-ipcs-solution-for-teleworkers-rated-avaya-compliant,318456.shtml">Sipera <span class="caps">IPCS </span>Solution for Teleworkers Rated &#8216;Avaya Compliant&#8217;</a></li><br />
		<li><a href="http://www.earthtimes.org/articles/show/extreme-networks-boosts-security-for-converged-voice-and-data-networks,317382.shtml">Extreme Networks Boosts Security for Converged Voice and Data Networks with New Tools</a></li></p>

<p><li>Review of the last week's traffic on the <a href="http://www.voipsa.org/VOIPSEC/">VOIPSEC </a>public mailing list&nbsp; </li><br />
<li>Wrap-up of the show </li><br />
<li>32:27 - End of show&nbsp; </li></ul> <p>Comments, suggestions and feedback are welcome either as replies to this post&nbsp; or via e-mail to <a href="mailto:blueboxpodcast@gmail.com">blueboxpodcast@gmail.com</a>.&nbsp; Audio comments sent as attached MP3 files are definitely welcome and will be played in future shows.&nbsp; You may also call the listener comment line at either +1-415-830-5439 or via SIP to '<a href="sip:bluebox@voipuser.org">bluebox@voipuser.org</a>' to leave a comment there.&nbsp; </p> <p>Thank you for listening and please do let us know what you think of the show. </p></p></div>

<p><a href="http://feeds.feedburner.com/~a/BlueBox?a=i1mO1B"><img src="http://feeds.feedburner.com/~a/BlueBox?i=i1mO1B" border="0"></img></a></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/BlueBox?a=YWUw1I"><img src="http://feeds.feedburner.com/~f/BlueBox?i=YWUw1I" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/BlueBox?a=74RvnI"><img src="http://feeds.feedburner.com/~f/BlueBox?i=74RvnI" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/BlueBox?a=c8gwAI"><img src="http://feeds.feedburner.com/~f/BlueBox?i=c8gwAI" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/BlueBox?a=HpdUtI"><img src="http://feeds.feedburner.com/~f/BlueBox?i=HpdUtI" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/BlueBox?a=p9H2li"><img src="http://feeds.feedburner.com/~f/BlueBox?i=p9H2li" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/BlueBox?a=oUodVI"><img src="http://feeds.feedburner.com/~f/BlueBox?i=oUodVI" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/BlueBox/~4/308280975" height="1" width="1"/>]]></content:encoded>
      <pubDate>Mon, 09 Jun 2008 11:30:58 +0000</pubDate>
      <category domain="http://securityratty.com/tag/voip">voip</category>
      <category domain="http://securityratty.com/tag/voip security news">voip security news</category>
      <category domain="http://securityratty.com/tag/voip monitor">voip monitor</category>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/voip news">voip news</category>
      <category domain="http://securityratty.com/tag/asterisk vulnerabilities">asterisk vulnerabilities</category>
      <category domain="http://securityratty.com/tag/voip security podcast">voip security podcast</category>
      <category domain="http://securityratty.com/tag/blue box">blue box</category>
      <category domain="http://securityratty.com/tag/podcast">podcast</category>
      <source url="http://feeds.feedburner.com/~r/BlueBox/~3/308280975/blue-box-79-ast.html">Blue Box #79: Asterisk vulnerabilities, VoiceCon/VON coverage, eavesdropping, FBI, ZFone, P2P, VoIP security news and more</source>
    </item>
    <item>
      <title><![CDATA[Speaking of Security Podcast #108]]></title>
      <link>http://securityratty.com/article/af5b4d749fe62264798a80a2037fc1e3</link>
      <guid>http://securityratty.com/article/af5b4d749fe62264798a80a2037fc1e3</guid>
      <description><![CDATA[Click to Dowload/Listen (08:24
We continue June with another giveaway for Podcast Listener Appreciation Month! Listen all month long for chances to WIN fabulous prizes... Details are in the podcast...]]></description>
      <content:encoded><![CDATA[<a href="http://www.rsa.com/blog/blog_entry.aspx?id=1290">Click to Dowload/Listen</a> (08:24)<br><br clear="all" /><strong>We continue June with another giveaway for Podcast Listener Appreciation Month!</strong> Listen all month long for chances to WIN fabulous prizes... Details are in the podcast for this week's contest. In this episode, Matt Buckley interviews one of our new Speaking of Security Bloggers, Paul Stamp, formerly of Forrester Research who is now a Senior Manager, Product Marketing, in RSA's <a href="http://rsa.com/node.aspx?id=3182" target="_blank">Information and Event Management Group</a>.  Speaking of SIEM, <a href="http://rsa.com/press_release.aspx?id=9388" target="_blank">RSA is positioned in the Leaders quadrant within Gartner's Q12008 Magic Quadrant for SIEM</a>.<br><br>]]></content:encoded>
      <pubDate>Sun, 08 Jun 2008 20:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/matt buckley interviews">matt buckley interviews</category>
      <category domain="http://securityratty.com/tag/q12008 magic quadrant">q12008 magic quadrant</category>
      <category domain="http://securityratty.com/tag/win fabulous">win fabulous</category>
      <category domain="http://securityratty.com/tag/senior manager">senior manager</category>
      <category domain="http://securityratty.com/tag/siem">siem</category>
      <category domain="http://securityratty.com/tag/event management">event management</category>
      <category domain="http://securityratty.com/tag/leaders quadrant">leaders quadrant</category>
      <category domain="http://securityratty.com/tag/forrester research">forrester research</category>
      <category domain="http://securityratty.com/tag/paul stamp">paul stamp</category>
      <source url="http://www.rsa.com/blog/blog_entry.aspx?id=1290">Speaking of Security Podcast #108</source>
    </item>
    <item>
      <title><![CDATA[Speaking of Security Podcast #107]]></title>
      <link>http://securityratty.com/article/01d7fee030bdeca7746c7688ca35852c</link>
      <guid>http://securityratty.com/article/01d7fee030bdeca7746c7688ca35852c</guid>
      <description><![CDATA[Click to Dowload/Listen (08:24
June is Podcast Listener Appreciation Month! Listen all month long for chances to WIN fabulous prizes... Details are in the podcast for this week's contest. This episode...]]></description>
      <content:encoded><![CDATA[<a href="http://www.rsa.com/blog/blog_entry.aspx?id=1287">Click to Dowload/Listen</a> (08:24)<br>
<br clear="all" />
  <strong>June is Podcast Listener Appreciation Month!</strong> Listen all month long for chances to WIN fabulous prizes... Details are in the podcast for this week's contest. This episode also includes an encryption Q&amp;A with Rich Mogull, founder of <a href="http://www.securosis.com" target="_blank">Securosis.com</a> and formerly of Gartner. Earlier this week he presented &quot;How Encryption and Key Management Solutions Fit into an Overall Information Risk Management Strategy&quot; during part 1 of a 2-part RSA web seminar series on encryption. <a href="https://www.livemeeting.com/cc/emc/view?id=Event_W_DSG_Encryption-1_Q208&role=attend&pw=jht3AN2633z&fmt=lmm&cn=blog" target="_blank">Watch the full replay here</a> and/or sign up for <a href="http://info.rsasecurity.com/2008Am/webcast/080603DSS/online_RSAweb.html" target="_blank">next week's part 2 here</a>.<br>]]></content:encoded>
      <pubDate>Sun, 01 Jun 2008 20:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/week">week</category>
      <category domain="http://securityratty.com/tag/encryption">encryption</category>
      <category domain="http://securityratty.com/tag/win fabulous">win fabulous</category>
      <category domain="http://securityratty.com/tag/rich mogull">rich mogull</category>
      <category domain="http://securityratty.com/tag/andor sign">andor sign</category>
      <category domain="http://securityratty.com/tag/podcast">podcast</category>
      <category domain="http://securityratty.com/tag/month">month</category>
      <category domain="http://securityratty.com/tag/gartner">gartner</category>
      <category domain="http://securityratty.com/tag/founder">founder</category>
      <source url="http://www.rsa.com/blog/blog_entry.aspx?id=1287">Speaking of Security Podcast #107</source>
    </item>
    <item>
      <title><![CDATA[Blue Box #78: Cisco IP phone vulnerabilties, WiFi handset insecurity, IETF security-related news, VoIP security news, listener comments and more]]></title>
      <link>http://securityratty.com/article/d47e0757b7a447223299541c460a193c</link>
      <guid>http://securityratty.com/article/d47e0757b7a447223299541c460a193c</guid>
      <description><![CDATA[Synopsis: Blue Box #78: Cisco IP phone vulnerabilties, WiFi handset insecurity, IETF security-related news, VoIP security news, listener comments and more
Welcome to Blue Box: The VoIP Security...]]></description>
      <content:encoded><![CDATA[
<div xmlns="http://www.w3.org/1999/xhtml">
<p><strong>Synopsis:</strong>&nbsp; Blue Box #78: Cisco IP phone vulnerabilties, WiFi handset insecurity, IETF security-related news, VoIP security news, listener comments and more</p><hr /><p>Welcome to <strong>Blue Box: The VoIP Security Podcast</strong> #78, a 40-minute podcast&nbsp; from Dan York and Jonathan Zar covering VoIP security news, comments and opinions.&nbsp; &nbsp; </p>

<p><a rel="enclosure" href="http://media.libsyn.com/media/lodestar/BBP-078-2008-02-25.mp3">Download the show here</a> (MP3, 17MB) or <a href="http://feeds.feedburner.com/BlueBox">subscribe to the RSS feed</a> to download the show automatically.&nbsp; </p>

<p><strong>NOTE: </strong><em>This show was originally recorded on February 25, 2008. Yes, that was two months ago... we know!</em></p> 

<p>You may also listen to this podcast right now:</p> 

<p><object width="200" height="20" data="http://www.blueboxpodcast.com/dewplayer.swf?son=http://media.libsyn.com/media/lodestar/BBP-078-2008-02-25.mp3" type="application/x-shockwave-flash"><param value="http://www.blueboxpodcast.com/dewplayer.swf?son=http://media.libsyn.com/media/lodestar/BBP-078-2008-02-25.mp3&amp;bgcolor=#FFFFFF" name="movie" /></object> </p> 

<p><strong>Show Content:</strong></p> 
 

<ul> <li>00:20 - Intro to the show, contact information and how to provide comments.&nbsp; Welcome to all the new listeners - and to all those listeners who have been here for so long!&nbsp; </li>

<li><a href="http://www.blueboxpodcast.com/2007/12/new-audio-comme.html">new comment line +1-415-830-5439</a></li>
	<li><a href="http://www.blueboxpodcast.com/2008/02/blue-box-se023.html">Special Edition #23</a> with Sonus Networks</li>
	<li><a href="http://saunderslog.com/2008/02/25/squawk-box-february-25-the-voice-phishing-call/">Squawk Box podcast about voice phishing</a> ??? also this article <a href="http://www.bmighty.com/security/showArticle.jhtml?articleID=206800660">Vishing: The Latest, and Greatest, Security Concern</a></li>
<li>Cisco: <a href="http://www.cisco.com/warp/public/707/cisco-sa-20080213-phone.shtml">Cisco Unified <span class="caps">IP </span>Phone Overflow and DoS Vulnerabilities</a> and <a href="http://voipsa.org/blog/2008/02/14/ciscos-slew-of-vulnerabilities/">Dustin Trammell???s coverage</a></li>
		<li>ZDNet: <a href="http://blogs.zdnet.com/security/?p=896">Design flaw in wireless VoIP handsets endanger the enterprise</a> followed by <a href="http://blogs.zdnet.com/security/?p=901">Cisco confirms vulnerability in 7921 WiFi IP phone</a></li>
<li>Voice of <span class="caps">VOIPSA</span>: <a href="http://voipsa.org/blog/2008/02/20/slides-about-peer-to-peer-sip-p2psip-security-now-available/">Slides about <span class="caps">P2PSIP</span> security new available</a></li>
		<li>Voice of <span class="caps">VOIPSA</span>: <a href="http://voipsa.org/blog/2008/02/15/join-the-new-rucus-mailing-list-if-you-want-to-look-at-ways-to-end-spit/">RUCUS mailing list &amp; <span class="caps">BOF</span></a></li>
		<li>Voice of <span class="caps">VOIPSA</span>: <a href="http://voipsa.org/blog/2008/02/11/end-to-end-voip-security-using-dtls-srtp-a-new-proposal/">End-to-end VoIP security using <span class="caps">DTLS</span>-SRTP</a></li>
		<li>Also a whole bunch on <span class="caps">SIP </span>Identity</li>
		<li><a href="http://blogs.voxeo.com/speakingofstandards/2008/02/12/sip-torture-tests-for-ipv6-now-out-in-rfc-5118/">SIP Torture Tests for IPv6 now out in <span class="caps">RFC 5118</span></a></li>
		<li><a href="http://tools.ietf.org/rfcmarkup?doc=draft-york-spit-similarity-scenarios">SIP Usage Scenarios Similar to <span class="caps">SPIT</span></a></li>
		<li><a href="http://www.ietf.org/internet-drafts/draft-niccolini-speermint-voipthreats-03.txt">SPEERMINT Security BCPs</a></li>
		<li><a href="http://tools.ietf.org/rfcmarkup?doc=draft-kaplan-sip-baiting-attack">SIP Identity Baiting Attack</a></li>
		<li><a href="http://www.ietf.org/internet-drafts/draft-rosenberg-sip-rfc4474-concerns-00.txt">Concerns around Applicability of <span class="caps">RFC 4474</span></a></li>
<li><a href="http://www.securityfocus.com/archive/101/488311/30/30/threaded">VoIP Hopper 0.9.9 released</a> (<a href="http://voiphopper.sourceforge.net/">site</a> ) ??? Thanks to Frank Leonhardt for the info.</li>
		<li>VoIP News: <a href="http://www.voip-news.com/feature/is-someone-listening-022208/">Is Someone Listening to Your VoIP Calls?</a> (linked to from <a href="http://blogs.zdnet.com/ip-telephony/?p=3294">ZDNet</a> )</li>
		<li>ZDNet: <a href="http://blogs.zdnet.com/security/?p=895">Cracking <span class="caps">GSM</span></a></li>
		<li>TMCnet- <a href="http://internetcommunications.tmcnet.com/topics/sip/articles/21394-ocs-exposed-practicing-safe-ocs.htm">Practicing Safe <span class="caps">OCS</span></a></li>
		<li>TMCnet- <a href="http://sip.tmcnet.com/topics/sip-and-open-standards/articles/21397-security-attack-the-day.htm">Security Attack of the Day</a> (Tom Cross starts blogging for TMCnet)</li>
		<li>Speaking of Tom, <a href="http://sip.tmcnet.com/topics/featured-articles/articles/21137-techtionarycom-releases-sip-security-checklist.htm">Techtionary.com Releases <span class="caps">SIP </span>Security Checklist</a></li>
	<li>Voice of <span class="caps">VOIPSA</span>: <a href="http://voipsa.org/blog/2008/02/21/siptap-author-forms-voip-security-company/">SIPTap Author forms VoIP Security Company</a> (by Craig Bowser!)</li>
		<li>Voice of <span class="caps">VOIPSA</span>: <a href="http://voipsa.org/blog/2008/02/21/underpowered-hardware/">Underpowered Hardware</a></li>
	<li><a href="http://www.projectspider.org/">Project Spider</a> ??? about <span class="caps">SPIT</span></li>
	<li><span class="caps">CBC</span>: <a href="http://www.cbc.ca/technology/story/2008/02/12/bell.html?ref=rss">Bell recovers stolen data on 3.4 million customers</a></li>
<li>Comment (email) from Larry Farmer</li>
		<li>Comment (email) from Shlomo Dubrowin</li>
		<li>Comment (email) about <span class="caps">SE </span>#23</li>
<li>Review of the last week's traffic on the <a href="http://www.voipsa.org/VOIPSEC/">VOIPSEC </a>public mailing list&nbsp; </li>
<li>Wrap-up of the show </li>
<li>40:01 - End of show&nbsp; </li></ul> <p>Comments, suggestions and feedback are welcome either as replies to this post&nbsp; or via e-mail to <a href="mailto:blueboxpodcast@gmail.com">blueboxpodcast@gmail.com</a>.&nbsp; Audio comments sent as attached MP3 files are definitely welcome and will be played in future shows.&nbsp; You may also call the listener comment line at either +1-415-830-5439 or via SIP to '<a href="sip:bluebox@voipuser.org">bluebox@voipuser.org</a>' to leave a comment there.&nbsp; </p> <p>Thank you for listening and please do let us know what you think of the show. </p></div>
]]></content:encoded>
      <pubDate>Tue, 29 Apr 2008 10:56:49 +0000</pubDate>
      <category domain="http://securityratty.com/tag/voip security news">voip security news</category>
      <category domain="http://securityratty.com/tag/news">news</category>
      <category domain="http://securityratty.com/tag/listener comment line">listener comment line</category>
      <category domain="http://securityratty.com/tag/comments">comments</category>
      <category domain="http://securityratty.com/tag/listener comments">listener comments</category>
      <category domain="http://securityratty.com/tag/comment line">comment line</category>
      <category domain="http://securityratty.com/tag/cisco">cisco</category>
      <category domain="http://securityratty.com/tag/phone">phone</category>
      <category domain="http://securityratty.com/tag/podcast">podcast</category>
      <source url="http://www.blueboxpodcast.com/2008/04/blue-box-78-cis.html">Blue Box #78: Cisco IP phone vulnerabilties, WiFi handset insecurity, IETF security-related news, VoIP security news, listener comments and more</source>
    </item>
    <item>
      <title><![CDATA[Blue Box #78: Cisco IP phone vulnerabilties, WiFi handset insecurity, IETF security-related news, VoIP security news, listener comments and more]]></title>
      <link>http://securityratty.com/article/5012fddf567c518c66082afa468b2250</link>
      <guid>http://securityratty.com/article/5012fddf567c518c66082afa468b2250</guid>
      <description><![CDATA[Synopsis: Blue Box #78: Cisco IP phone vulnerabilties, WiFi handset insecurity, IETF security-related news, VoIP security news, listener comments and more
Welcome to Blue Box: The VoIP Security...]]></description>
      <content:encoded><![CDATA[
<div xmlns="http://www.w3.org/1999/xhtml">

<p><strong>Synopsis:</strong>&nbsp; Blue Box #78: Cisco IP phone vulnerabilties, WiFi handset insecurity, IETF security-related news, VoIP security news, listener comments and more</p><hr /><p>Welcome to <strong>Blue Box: The VoIP Security Podcast</strong> #78, a 40-minute podcast&nbsp; from Dan York and Jonathan Zar covering VoIP security news, comments and opinions.&nbsp; &nbsp; </p>

<p><a rel="enclosure" href="http://ripple.radiotail.com/409/BBP-078-2008-02-25.mp3">Download the show here</a> (MP3, 17MB) or <a href="http://feeds.feedburner.com/BlueBox">subscribe to the RSS feed</a> to download the show automatically.&nbsp; </p>

<p><strong>NOTE: </strong><em>This show was originally recorded on February 25, 2008. Yes, that was two months ago... we know!</em></p> 

<p>You may also listen to this podcast right now:</p> 

<p><object width="200" height="20" data="http://www.blueboxpodcast.com/dewplayer.swf?son=http://ripple.radiotail.com/409/BBP-078-2008-02-25.mp3" type="application/x-shockwave-flash"><param value="http://www.blueboxpodcast.com/dewplayer.swf?son=http://ripple.radiotail.com/409/BBP-078-2008-02-25.mp3&amp;bgcolor=#FFFFFF" name="movie" /></object> </p> 

<p><strong>Show Content:</strong></p> 
 

<ul> <li>00:20 - Intro to the show, contact information and how to provide comments.&nbsp; Welcome to all the new listeners - and to all those listeners who have been here for so long!&nbsp; </li>

<li><a href="http://www.blueboxpodcast.com/2007/12/new-audio-comme.html">new comment line +1-415-830-5439</a></li>
	<li><a href="http://www.blueboxpodcast.com/2008/02/blue-box-se023.html">Special Edition #23</a> with Sonus Networks</li>
	<li><a href="http://saunderslog.com/2008/02/25/squawk-box-february-25-the-voice-phishing-call/">Squawk Box podcast about voice phishing</a> – also this article <a href="http://www.bmighty.com/security/showArticle.jhtml?articleID=206800660">Vishing: The Latest, and Greatest, Security Concern</a></li>
<li>Cisco: <a href="http://www.cisco.com/warp/public/707/cisco-sa-20080213-phone.shtml">Cisco Unified <span class="caps">IP </span>Phone Overflow and DoS Vulnerabilities</a> and <a href="http://voipsa.org/blog/2008/02/14/ciscos-slew-of-vulnerabilities/">Dustin Trammell’s coverage</a></li>
		<li>ZDNet: <a href="http://blogs.zdnet.com/security/?p=896">Design flaw in wireless VoIP handsets endanger the enterprise</a> followed by <a href="http://blogs.zdnet.com/security/?p=901">Cisco confirms vulnerability in 7921 WiFi IP phone</a></li>
<li>Voice of <span class="caps">VOIPSA</span>: <a href="http://voipsa.org/blog/2008/02/20/slides-about-peer-to-peer-sip-p2psip-security-now-available/">Slides about <span class="caps">P2PSIP</span> security new available</a></li>
		<li>Voice of <span class="caps">VOIPSA</span>: <a href="http://voipsa.org/blog/2008/02/15/join-the-new-rucus-mailing-list-if-you-want-to-look-at-ways-to-end-spit/">RUCUS mailing list &amp; <span class="caps">BOF</span></a></li>
		<li>Voice of <span class="caps">VOIPSA</span>: <a href="http://voipsa.org/blog/2008/02/11/end-to-end-voip-security-using-dtls-srtp-a-new-proposal/">End-to-end VoIP security using <span class="caps">DTLS</span>-SRTP</a></li>
		<li>Also a whole bunch on <span class="caps">SIP </span>Identity</li>
		<li><a href="http://blogs.voxeo.com/speakingofstandards/2008/02/12/sip-torture-tests-for-ipv6-now-out-in-rfc-5118/">SIP Torture Tests for IPv6 now out in <span class="caps">RFC 5118</span></a></li>
		<li><a href="http://tools.ietf.org/rfcmarkup?doc=draft-york-spit-similarity-scenarios">SIP Usage Scenarios Similar to <span class="caps">SPIT</span></a></li>
		<li><a href="http://www.ietf.org/internet-drafts/draft-niccolini-speermint-voipthreats-03.txt">SPEERMINT Security BCPs</a></li>
		<li><a href="http://tools.ietf.org/rfcmarkup?doc=draft-kaplan-sip-baiting-attack">SIP Identity Baiting Attack</a></li>
		<li><a href="http://www.ietf.org/internet-drafts/draft-rosenberg-sip-rfc4474-concerns-00.txt">Concerns around Applicability of <span class="caps">RFC 4474</span></a></li>
<li><a href="http://www.securityfocus.com/archive/101/488311/30/30/threaded">VoIP Hopper 0.9.9 released</a> (<a href="http://voiphopper.sourceforge.net/">site</a> ) – Thanks to Frank Leonhardt for the info.</li>
		<li>VoIP News: <a href="http://www.voip-news.com/feature/is-someone-listening-022208/">Is Someone Listening to Your VoIP Calls?</a> (linked to from <a href="http://blogs.zdnet.com/ip-telephony/?p=3294">ZDNet</a> )</li>
		<li>ZDNet: <a href="http://blogs.zdnet.com/security/?p=895">Cracking <span class="caps">GSM</span></a></li>
		<li>TMCnet- <a href="http://internetcommunications.tmcnet.com/topics/sip/articles/21394-ocs-exposed-practicing-safe-ocs.htm">Practicing Safe <span class="caps">OCS</span></a></li>
		<li>TMCnet- <a href="http://sip.tmcnet.com/topics/sip-and-open-standards/articles/21397-security-attack-the-day.htm">Security Attack of the Day</a> (Tom Cross starts blogging for TMCnet)</li>
		<li>Speaking of Tom, <a href="http://sip.tmcnet.com/topics/featured-articles/articles/21137-techtionarycom-releases-sip-security-checklist.htm">Techtionary.com Releases <span class="caps">SIP </span>Security Checklist</a></li>
	<li>Voice of <span class="caps">VOIPSA</span>: <a href="http://voipsa.org/blog/2008/02/21/siptap-author-forms-voip-security-company/">SIPTap Author forms VoIP Security Company</a> (by Craig Bowser!)</li>
		<li>Voice of <span class="caps">VOIPSA</span>: <a href="http://voipsa.org/blog/2008/02/21/underpowered-hardware/">Underpowered Hardware</a></li>
	<li><a href="http://www.projectspider.org/">Project Spider</a> – about <span class="caps">SPIT</span></li>
	<li><span class="caps">CBC</span>: <a href="http://www.cbc.ca/technology/story/2008/02/12/bell.html?ref=rss">Bell recovers stolen data on 3.4 million customers</a></li>
<li>Comment (email) from Larry Farmer</li>
		<li>Comment (email) from Shlomo Dubrowin</li>
		<li>Comment (email) about <span class="caps">SE </span>#23</li>
<li>Review of the last week's traffic on the <a href="http://www.voipsa.org/VOIPSEC/">VOIPSEC </a>public mailing list&nbsp; </li>
<li>Wrap-up of the show </li>
<li>40:01 - End of show&nbsp; </li></ul> <p>Comments, suggestions and feedback are welcome either as replies to this post&nbsp; or via e-mail to <a href="mailto:blueboxpodcast@gmail.com">blueboxpodcast@gmail.com</a>.&nbsp; Audio comments sent as attached MP3 files are definitely welcome and will be played in future shows.&nbsp; You may also call the listener comment line at either +1-415-830-5439 or via SIP to '<a href="sip:bluebox@voipuser.org">bluebox@voipuser.org</a>' to leave a comment there.&nbsp; </p> <p>Thank you for listening and please do let us know what you think of the show. </p></div>

<p><a href="http://feeds.feedburner.com/~a/BlueBox?a=GdoBf2"><img src="http://feeds.feedburner.com/~a/BlueBox?i=GdoBf2" border="0"></img></a></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/BlueBox?a=U5qKBG"><img src="http://feeds.feedburner.com/~f/BlueBox?i=U5qKBG" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/BlueBox?a=8JxrSG"><img src="http://feeds.feedburner.com/~f/BlueBox?i=8JxrSG" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/BlueBox?a=xn2j5G"><img src="http://feeds.feedburner.com/~f/BlueBox?i=xn2j5G" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/BlueBox?a=TusLiG"><img src="http://feeds.feedburner.com/~f/BlueBox?i=TusLiG" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/BlueBox?a=nuIcBg"><img src="http://feeds.feedburner.com/~f/BlueBox?i=nuIcBg" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/BlueBox?a=ohLq5G"><img src="http://feeds.feedburner.com/~f/BlueBox?i=ohLq5G" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/BlueBox/~4/280262754" height="1" width="1"/>]]></content:encoded>
      <pubDate>Tue, 29 Apr 2008 09:56:50 +0000</pubDate>
      <category domain="http://securityratty.com/tag/voip security news">voip security news</category>
      <category domain="http://securityratty.com/tag/news">news</category>
      <category domain="http://securityratty.com/tag/listener comment line">listener comment line</category>
      <category domain="http://securityratty.com/tag/comments">comments</category>
      <category domain="http://securityratty.com/tag/listener comments">listener comments</category>
      <category domain="http://securityratty.com/tag/comment line">comment line</category>
      <category domain="http://securityratty.com/tag/cisco">cisco</category>
      <category domain="http://securityratty.com/tag/phone">phone</category>
      <category domain="http://securityratty.com/tag/podcast">podcast</category>
      <source url="http://feeds.feedburner.com/~r/BlueBox/~3/280262754/blue-box-78-cis.html">Blue Box #78: Cisco IP phone vulnerabilties, WiFi handset insecurity, IETF security-related news, VoIP security news, listener comments and more</source>
    </item>
  </channel>
</rss>
