<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: sipera]]></title>
    <link>http://securityratty.com/tag/sipera</link>
    <description></description>
    <pubDate>Wed, 07 Nov 2007 19:52:27 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[Blue Box #82: Asterisk & Skype security vulnerabilities, new VoIP security tools, VoIP steganography, VoIP security news and much, much more...]]></title>
      <link>http://securityratty.com/article/ab8e0e22ebb1851ff664c3be0a3baa7d</link>
      <guid>http://securityratty.com/article/ab8e0e22ebb1851ff664c3be0a3baa7d</guid>
      <description><![CDATA[Synopsis: Blue Box #82: Asterisk &amp; Skype security vulnerabilities, new VoIP security tools, VoIP steganography, VoIP security news and much, much more
Welcome to Blue Box: The VoIP Security Podcast...]]></description>
      <content:encoded><![CDATA[
<div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Synopsis:</strong>&nbsp; Blue Box #82: Asterisk & Skype security vulnerabilities, new VoIP security tools, VoIP steganography, VoIP security news and much, much more...</p><hr /><p>Welcome to <strong>Blue Box: The VoIP Security Podcast</strong> #82, a 47-minute podcast&nbsp; from Dan York and Jonathan Zar covering VoIP security news, comments and opinions.&nbsp; &nbsp; </p>

<p><a rel="enclosure" href="http://media.libsyn.com/media/lodestar/BBP-082-2008-06-21.mp3">Download the show here</a> (MP3, 21MB) or <a href="http://feeds.feedburner.com/BlueBox">subscribe to the RSS feed</a> to download the show automatically.&nbsp; </p>

<p><strong>NOTE: </strong><em>This show was originally recorded on June 21, 2008. </em></p> 

<p>You may also listen to this podcast right now:</p> 

<p><object width="200" height="20" data="http://www.blueboxpodcast.com/dewplayer.swf?son=http://media.libsyn.com/media/lodestar/BBP-082-2008-06-21.mp3" type="application/x-shockwave-flash"><param value="http://www.blueboxpodcast.com/dewplayer.swf?son=http://media.libsyn.com/media/lodestar/BBP-082-2008-06-21.mp3&amp;bgcolor=#FFFFFF" name="movie" /></object> </p> 

<p><strong>Show Content:</strong></p> 
 

<ul> <li>00:20 - Intro to the show, contact information and how to provide comments.&nbsp; Welcome to all the new listeners - and to all those listeners who have been here for so long!</li>
<li>Programming notes:
	<ul>
	<li>Note about the production team &#8211; new special editions coming soon.</li>
		<li>Note about URLs for the media files</li>
	</ul>
<li><a href="http://downloads.digium.com/pub/security/AST-2008-008.html">AST-2008-008 &#8211; Remote Crash Vulnerability in <span class="caps">SIP</span> channel driver when run in pedantic mode</a></li>
		<li><a href="http://downloads.digium.com/pub/security/AST-2008-009.html">AST-2008-009 &#8211; Remote crash vulnerability in ooh323 channel driver</a></li>
		<li><a href="http://www.skype.com/security/skype-sb-2008-003.html">Skype-SB-2008-003 &#8211; Skype File <span class="caps">URI </span>Security Bypass Code Execution Vulnerability</a></li>

<p><li><a href="http://voipsa.org/pipermail/voipsec_voipsa.org/2008-June/002677.html">New version of SIPvicious</a></li><br />
		<li><a href="http://code.google.com/p/sipflanker/">Sipflanker &#8211; tool to find <span class="caps">SIP</span> devices with web GUIs</a></li><br />
<ul><br />
	<li><a href="http://voipsa.org/pipermail/voipsec_voipsa.org/2008-June/002678.html">Discussion about VoIP Steganography</a> (pointed to by Craig Bowser)</li><br />
		<li>Geeks Are Sexy: <a href="http://www.geeksaresexy.net/2008/06/02/new-technology-hides-messages-in-internet-phone-calls/">New Technology Hides Messages in Internet Phone Calls</a> &#8211; and Switched: <a href="http://www.switched.com/2008/06/03/spies-to-use-skype-to-send-secret-messages/">Spies to Use Skype to Send Secret Messages?</a> &#8211; and <a href="http://www.theregister.co.uk/2008/06/03/voip_steganography/">The Register</a></li><br />
	<li>FierceVoIP: <a href="http://www.fiercevoip.com/story/voip-security-and-circle-trust/2008-05-06">VoIP Security and the Circle of Trust</a> pointing to Government Computer News: <a href="http://www.gcn.com/print/27_10/46209-1.html">Careful with the call</a></li><br />
	<br />
	<li>The Register: <a href="http://www.theregister.co.uk/2008/06/03/low_tech_phishing_scams/">&#8216;Untraceable&#8217; phone fraudsters eye your credit card</a></li><br />
	<br />
	<li>SearchUnifiedCommunications: <a href="http://searchunifiedcommunications.techtarget.com/news/article/0,289142,sid186_gci1315878,00.html">Disaster and recovery in the VoIP/IPT <span class="caps">RFP</span></a></li><br />
	<br />
	<li>Secure Computing: <a href="http://www.securecomputing.net.au/News/114221,voice-tools-under-enemy-fire.aspx">Voice tools under enemy fire</a></li><br />
	<br />
	<li>VNUnet: <a href="http://www.vnunet.com/computing/analysis/2217608/voip-application-worth-paying-4021945">A good VoIP application is worth paying for</a></li><br />
	<br />
	<li><a href="http://www.ofcom.org.uk/media/news/2007/12/nr_22071205">Ofcom confirms VoIP providers must provide access to 999 and 112</a></li><br />
	<br />
	<li><a href="http://blog.voipshield.com/">Bogdan Materna&#8217;s blog is live</a></li></p>

<p><li>Realtime Community: <a href="http://www.realtime-websecurity.com/ESMWSv3.asp">The Essentials Series:<br />Messaging and Web Security<br />Volume <span class="caps">III</span></a></li><br />
		<li>Global Knowledge: <a href="http://images.globalknowledge.com/wwwimages/seminars/voipsec/player.html">On-Demand Webinar on VoIP Security</a> (hat tip to <a href="http://tfl09.blogspot.com/2008/06/voip-security-web-seminar.html">Thomas Lee</a> )</li><br />
		<li>SearchSecurity: <a href="http://searchsecurity.techtarget.com.au/articles/24883-The-threats-to-telcos-and-how-they-can-repel-them">The threats to telcos and how they can repel them</a></li><br />
		<li>TMCnet: <a href="http://www.tmcnet.com/news/2008/06/02/3476832.htm">Balancing Issues in World of Telepresence</a></li><br />
		<li>Network World: <a href="http://www.networkworld.com/buyersguides/guide.php?cat=898361">VoIP Security Buying Guide</a></li></p>

<p><li><a href="http://www.fiercewireless.com/press-releases/nortel-and-securelogix-team-deliver-voice-security-and-management-solutions-worldwide">Nortel and SecureLogix Team to Deliver Voice Security and Management Solutions to Worldwide Enterprise Market</a> (see also <a href="http://www.fiercevoip.com/story/nortel-adds-voip-security-thru-securelogix/2008-06-02?utm_medium=rss&#38;utm_source=rss&#38;cmp-id=OTC-RSS-FV0">this analysis</a> )</li><br />
		<li><a href="http://www.earthtimes.org/articles/show/sipera-partner-network-arms-resellers-with-comprehensive-uc-and-voip-security,428703.shtml">Sipera Partner Network Arms Resellers With Comprehensive UC and VoIP Security</a></li><br />
		<li><a href="http://www.webitpr.com/release_detail.asp?ReleaseID=8791">VIVOphone Deploys Paradial RealTunnel?? to Solve <span class="caps">NAT </span>Traversal Challenges for VoIP Services</a></li><br />
		<li><a href="http://www.networkworld.com/newsletters/converg/2008/061608converge1.html">Audiocodes joins the ranks of <span class="caps">SBC</span> vendors</a></li><br />
<li>SearchSecurity: <a href="http://searchnetworking.techtarget.com.au/articles/24906-Securing-the-new-network">Securing the new network</a> (interesting because it shows the layers of a defense in depth)</li><br />
<li>The Hindu Business News: <a href="http://www.thehindubusinessline.com/ew/2008/06/16/stories/2008061650050201.htm">Serious about Security</a></li><br />
<li>Shows:<br />
<ul><br />
	<li><a href="http://www.iptelephonyuniversity.com/home.html">IP Telephony University</a> &#8211; June 23-24, Alexandria, VA</li><br />
		<li><a href="http://voipsa.org/pipermail/voipsec_voipsa.org/2008-June/002675.html">IPTComm 2008</a> &#8211; July 1-2, Heidelberg, Germany</li><br />
		<li><a href="http://www.thelasthope.org/index.php">The Last H.O.P.E.</a> &#8211; July 18-20, New York</li><br />
		<li><a href="http://www.speechtek.com/">SpeechTek</a> &#8211; August 18-20, New York</li><br />
	</ul><br />
<li><a href="http://article.gmane.org/gmane.comp.voip.security.voipsa/2562">Call for papers for Hack-in-the-box Malaysia</a> ends June 30th</li><br />
	<br />
	<li><a href="http://www.room362.com/archives/192-ShmooCon-2008-Videos-Hit-the-Shelves.html">SchmooCon 2008 videos available &#8211; several dealing with VoIP</a></li></p>

<p><li>No comments this week.<br />
<li>Review of the last week's traffic on the <a href="http://www.voipsa.org/VOIPSEC/">VOIPSEC </a>public mailing list&nbsp; </li><br />
<li>Wrap-up of the show </li><br />
<li>47:09 - End of show&nbsp; </li></ul> <p>Comments, suggestions and feedback are welcome either as replies to this post&nbsp; or via e-mail to <a href="mailto:blueboxpodcast@gmail.com">blueboxpodcast@gmail.com</a>.&nbsp; Audio comments sent as attached MP3 files are definitely welcome and will be played in future shows.&nbsp; You may also call the listener comment line at either +1-415-830-5439 or via SIP to '<a href="sip:bluebox@voipuser.org">bluebox@voipuser.org</a>' to leave a comment there.&nbsp; </p> <p>Thank you for listening and please do let us know what you think of the show. </p></p></div>
]]></content:encoded>
      <pubDate>Wed, 27 Aug 2008 16:53:17 +0000</pubDate>
      <category domain="http://securityratty.com/tag/voip security">voip security</category>
      <category domain="http://securityratty.com/tag/voip security news">voip security news</category>
      <category domain="http://securityratty.com/tag/voip">voip</category>
      <category domain="http://securityratty.com/tag/voip security tools">voip security tools</category>
      <category domain="http://securityratty.com/tag/voip steganography">voip steganography</category>
      <category domain="http://securityratty.com/tag/voip services">voip services</category>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/skype security vulnerabilities">skype security vulnerabilities</category>
      <category domain="http://securityratty.com/tag/voip security podcast">voip security podcast</category>
      <source url="http://www.blueboxpodcast.com/2008/08/blue-box-82-ast.html">Blue Box #82: Asterisk &amp; Skype security vulnerabilities, new VoIP security tools, VoIP steganography, VoIP security news and much, much more...</source>
    </item>
    <item>
      <title><![CDATA[Blue Box #82: Asterisk & Skype security vulnerabilities, new VoIP security tools, VoIP steganography, VoIP security news and much, much more...]]></title>
      <link>http://securityratty.com/article/48c1a58b9d39348008877ad191ffcfea</link>
      <guid>http://securityratty.com/article/48c1a58b9d39348008877ad191ffcfea</guid>
      <description><![CDATA[Synopsis: Blue Box #82: Asterisk &amp; Skype security vulnerabilities, new VoIP security tools, VoIP steganography, VoIP security news and much, much more
Welcome to Blue Box: The VoIP Security Podcast...]]></description>
      <content:encoded><![CDATA[
<div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Synopsis:</strong>&nbsp; Blue Box #82: Asterisk & Skype security vulnerabilities, new VoIP security tools, VoIP steganography, VoIP security news and much, much more...</p><hr /><p>Welcome to <strong>Blue Box: The VoIP Security Podcast</strong> #82, a 47-minute podcast&nbsp; from Dan York and Jonathan Zar covering VoIP security news, comments and opinions.&nbsp; &nbsp; </p>

<p><a rel="enclosure" href="http://media.libsyn.com/media/lodestar/BBP-082-2008-06-21.mp3">Download the show here</a> (MP3, 21MB) or <a href="http://feeds.feedburner.com/BlueBox">subscribe to the RSS feed</a> to download the show automatically.&nbsp; </p>

<p><strong>NOTE: </strong><em>This show was originally recorded on June 21, 2008. </em></p> 

<p>You may also listen to this podcast right now:</p> 

<p><object width="200" height="20" data="http://www.blueboxpodcast.com/dewplayer.swf?son=http://media.libsyn.com/media/lodestar/BBP-082-2008-06-21.mp3" type="application/x-shockwave-flash"><param value="http://www.blueboxpodcast.com/dewplayer.swf?son=http://media.libsyn.com/media/lodestar/BBP-082-2008-06-21.mp3&amp;bgcolor=#FFFFFF" name="movie" /></object> </p> 

<p><strong>Show Content:</strong></p> 
 

<ul> <li>00:20 - Intro to the show, contact information and how to provide comments.&nbsp; Welcome to all the new listeners - and to all those listeners who have been here for so long!</li>
<li>Programming notes:
	<ul>
	<li>Note about the production team &#8211; new special editions coming soon.</li>
		<li>Note about URLs for the media files</li>
	</ul>
<li><a href="http://downloads.digium.com/pub/security/AST-2008-008.html">AST-2008-008 &#8211; Remote Crash Vulnerability in <span class="caps">SIP</span> channel driver when run in pedantic mode</a></li>
		<li><a href="http://downloads.digium.com/pub/security/AST-2008-009.html">AST-2008-009 &#8211; Remote crash vulnerability in ooh323 channel driver</a></li>
		<li><a href="http://www.skype.com/security/skype-sb-2008-003.html">Skype-SB-2008-003 &#8211; Skype File <span class="caps">URI </span>Security Bypass Code Execution Vulnerability</a></li>

<p><li><a href="http://voipsa.org/pipermail/voipsec_voipsa.org/2008-June/002677.html">New version of SIPvicious</a></li><br />
		<li><a href="http://code.google.com/p/sipflanker/">Sipflanker &#8211; tool to find <span class="caps">SIP</span> devices with web GUIs</a></li><br />
<ul><br />
	<li><a href="http://voipsa.org/pipermail/voipsec_voipsa.org/2008-June/002678.html">Discussion about VoIP Steganography</a> (pointed to by Craig Bowser)</li><br />
		<li>Geeks Are Sexy: <a href="http://www.geeksaresexy.net/2008/06/02/new-technology-hides-messages-in-internet-phone-calls/">New Technology Hides Messages in Internet Phone Calls</a> &#8211; and Switched: <a href="http://www.switched.com/2008/06/03/spies-to-use-skype-to-send-secret-messages/">Spies to Use Skype to Send Secret Messages?</a> &#8211; and <a href="http://www.theregister.co.uk/2008/06/03/voip_steganography/">The Register</a></li><br />
	<li>FierceVoIP: <a href="http://www.fiercevoip.com/story/voip-security-and-circle-trust/2008-05-06">VoIP Security and the Circle of Trust</a> pointing to Government Computer News: <a href="http://www.gcn.com/print/27_10/46209-1.html">Careful with the call</a></li><br />
	<br />
	<li>The Register: <a href="http://www.theregister.co.uk/2008/06/03/low_tech_phishing_scams/">&#8216;Untraceable&#8217; phone fraudsters eye your credit card</a></li><br />
	<br />
	<li>SearchUnifiedCommunications: <a href="http://searchunifiedcommunications.techtarget.com/news/article/0,289142,sid186_gci1315878,00.html">Disaster and recovery in the VoIP/IPT <span class="caps">RFP</span></a></li><br />
	<br />
	<li>Secure Computing: <a href="http://www.securecomputing.net.au/News/114221,voice-tools-under-enemy-fire.aspx">Voice tools under enemy fire</a></li><br />
	<br />
	<li>VNUnet: <a href="http://www.vnunet.com/computing/analysis/2217608/voip-application-worth-paying-4021945">A good VoIP application is worth paying for</a></li><br />
	<br />
	<li><a href="http://www.ofcom.org.uk/media/news/2007/12/nr_22071205">Ofcom confirms VoIP providers must provide access to 999 and 112</a></li><br />
	<br />
	<li><a href="http://blog.voipshield.com/">Bogdan Materna&#8217;s blog is live</a></li></p>

<p><li>Realtime Community: <a href="http://www.realtime-websecurity.com/ESMWSv3.asp">The Essentials Series:<br />Messaging and Web Security<br />Volume <span class="caps">III</span></a></li><br />
		<li>Global Knowledge: <a href="http://images.globalknowledge.com/wwwimages/seminars/voipsec/player.html">On-Demand Webinar on VoIP Security</a> (hat tip to <a href="http://tfl09.blogspot.com/2008/06/voip-security-web-seminar.html">Thomas Lee</a> )</li><br />
		<li>SearchSecurity: <a href="http://searchsecurity.techtarget.com.au/articles/24883-The-threats-to-telcos-and-how-they-can-repel-them">The threats to telcos and how they can repel them</a></li><br />
		<li>TMCnet: <a href="http://www.tmcnet.com/news/2008/06/02/3476832.htm">Balancing Issues in World of Telepresence</a></li><br />
		<li>Network World: <a href="http://www.networkworld.com/buyersguides/guide.php?cat=898361">VoIP Security Buying Guide</a></li></p>

<p><li><a href="http://www.fiercewireless.com/press-releases/nortel-and-securelogix-team-deliver-voice-security-and-management-solutions-worldwide">Nortel and SecureLogix Team to Deliver Voice Security and Management Solutions to Worldwide Enterprise Market</a> (see also <a href="http://www.fiercevoip.com/story/nortel-adds-voip-security-thru-securelogix/2008-06-02?utm_medium=rss&#38;utm_source=rss&#38;cmp-id=OTC-RSS-FV0">this analysis</a> )</li><br />
		<li><a href="http://www.earthtimes.org/articles/show/sipera-partner-network-arms-resellers-with-comprehensive-uc-and-voip-security,428703.shtml">Sipera Partner Network Arms Resellers With Comprehensive UC and VoIP Security</a></li><br />
		<li><a href="http://www.webitpr.com/release_detail.asp?ReleaseID=8791">VIVOphone Deploys Paradial RealTunnel® to Solve <span class="caps">NAT </span>Traversal Challenges for VoIP Services</a></li><br />
		<li><a href="http://www.networkworld.com/newsletters/converg/2008/061608converge1.html">Audiocodes joins the ranks of <span class="caps">SBC</span> vendors</a></li><br />
<li>SearchSecurity: <a href="http://searchnetworking.techtarget.com.au/articles/24906-Securing-the-new-network">Securing the new network</a> (interesting because it shows the layers of a defense in depth)</li><br />
<li>The Hindu Business News: <a href="http://www.thehindubusinessline.com/ew/2008/06/16/stories/2008061650050201.htm">Serious about Security</a></li><br />
<li>Shows:<br />
<ul><br />
	<li><a href="http://www.iptelephonyuniversity.com/home.html">IP Telephony University</a> &#8211; June 23-24, Alexandria, VA</li><br />
		<li><a href="http://voipsa.org/pipermail/voipsec_voipsa.org/2008-June/002675.html">IPTComm 2008</a> &#8211; July 1-2, Heidelberg, Germany</li><br />
		<li><a href="http://www.thelasthope.org/index.php">The Last H.O.P.E.</a> &#8211; July 18-20, New York</li><br />
		<li><a href="http://www.speechtek.com/">SpeechTek</a> &#8211; August 18-20, New York</li><br />
	</ul><br />
<li><a href="http://article.gmane.org/gmane.comp.voip.security.voipsa/2562">Call for papers for Hack-in-the-box Malaysia</a> ends June 30th</li><br />
	<br />
	<li><a href="http://www.room362.com/archives/192-ShmooCon-2008-Videos-Hit-the-Shelves.html">SchmooCon 2008 videos available &#8211; several dealing with VoIP</a></li></p>

<p><li>No comments this week.<br />
<li>Review of the last week's traffic on the <a href="http://www.voipsa.org/VOIPSEC/">VOIPSEC </a>public mailing list&nbsp; </li><br />
<li>Wrap-up of the show </li><br />
<li>47:09 - End of show&nbsp; </li></ul> <p>Comments, suggestions and feedback are welcome either as replies to this post&nbsp; or via e-mail to <a href="mailto:blueboxpodcast@gmail.com">blueboxpodcast@gmail.com</a>.&nbsp; Audio comments sent as attached MP3 files are definitely welcome and will be played in future shows.&nbsp; You may also call the listener comment line at either +1-415-830-5439 or via SIP to '<a href="sip:bluebox@voipuser.org">bluebox@voipuser.org</a>' to leave a comment there.&nbsp; </p> <p>Thank you for listening and please do let us know what you think of the show. </p></p></div>

<p><a href="http://feeds.feedburner.com/~a/BlueBox?a=lWcQZE"><img src="http://feeds.feedburner.com/~a/BlueBox?i=lWcQZE" border="0"></img></a></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/BlueBox?a=pYLEpK"><img src="http://feeds.feedburner.com/~f/BlueBox?i=pYLEpK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/BlueBox?a=rcmyeK"><img src="http://feeds.feedburner.com/~f/BlueBox?i=rcmyeK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/BlueBox?a=FcteyK"><img src="http://feeds.feedburner.com/~f/BlueBox?i=FcteyK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/BlueBox?a=g4KpjK"><img src="http://feeds.feedburner.com/~f/BlueBox?i=g4KpjK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/BlueBox?a=XvHGuk"><img src="http://feeds.feedburner.com/~f/BlueBox?i=XvHGuk" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/BlueBox?a=WQc3oK"><img src="http://feeds.feedburner.com/~f/BlueBox?i=WQc3oK" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/BlueBox/~4/376657116" height="1" width="1"/>]]></content:encoded>
      <pubDate>Wed, 27 Aug 2008 15:53:18 +0000</pubDate>
      <category domain="http://securityratty.com/tag/voip security">voip security</category>
      <category domain="http://securityratty.com/tag/voip security news">voip security news</category>
      <category domain="http://securityratty.com/tag/voip">voip</category>
      <category domain="http://securityratty.com/tag/voip security tools">voip security tools</category>
      <category domain="http://securityratty.com/tag/voip steganography">voip steganography</category>
      <category domain="http://securityratty.com/tag/voip services">voip services</category>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/skype security vulnerabilities">skype security vulnerabilities</category>
      <category domain="http://securityratty.com/tag/voip security podcast">voip security podcast</category>
      <source url="http://feeds.feedburner.com/~r/BlueBox/~3/376657116/blue-box-82-ast.html">Blue Box #82: Asterisk &amp; Skype security vulnerabilities, new VoIP security tools, VoIP steganography, VoIP security news and much, much more...</source>
    </item>
    <item>
      <title><![CDATA[Blue Box #79: Asterisk vulnerabilities, VoiceCon/VON coverage, eavesdropping, FBI, ZFone, P2P, VoIP security news and more]]></title>
      <link>http://securityratty.com/article/12a646d6f75cd20c5bdf249647b13de5</link>
      <guid>http://securityratty.com/article/12a646d6f75cd20c5bdf249647b13de5</guid>
      <description><![CDATA[Synopsis: Blue Box #79: Asterisk vulnerabilities, VoiceCon/VON coverage, eavesdropping, FBI, ZFone, P2P, VoIP security news and more
Welcome to Blue Box: The VoIP Security Podcast #78, a 32-minute...]]></description>
      <content:encoded><![CDATA[
<div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Synopsis:</strong>&nbsp; Blue Box #79: Asterisk vulnerabilities, VoiceCon/VON coverage, eavesdropping, FBI, ZFone, P2P, VoIP security news and more</p><hr /><p>Welcome to <strong>Blue Box: The VoIP Security Podcast</strong> #78, a 32-minute podcast&nbsp; from Dan York and Jonathan Zar covering VoIP security news, comments and opinions.&nbsp; &nbsp; </p>

<p><a rel="enclosure" href="http://media.libsyn.com/media/lodestar/BBP-079-2008-03-27.mp3">Download the show here</a> (MP3, 15MB) or <a href="http://feeds.feedburner.com/BlueBox">subscribe to the RSS feed</a> to download the show automatically.&nbsp; </p>

<p><strong>NOTE: </strong><em>This show was originally recorded on March 27, 2008. Yes, that was over two months ago... we know...</em></p> 

<p>You may also listen to this podcast right now:</p> 

<p><object width="200" height="20" data="http://www.blueboxpodcast.com/dewplayer.swf?son=http://media.libsyn.com/media/lodestar/BBP-079-2008-03-27.mp3" type="application/x-shockwave-flash"><param value="http://www.blueboxpodcast.com/dewplayer.swf?son=http://media.libsyn.com/media/lodestar/BBP-079-2008-03-27.mp3&amp;bgcolor=#FFFFFF" name="movie" /></object> </p> 

<p><strong>Show Content:</strong></p> 
 

<ul> <li>00:20 - Intro to the show, contact information and how to provide comments.&nbsp; Welcome to all the new listeners - and to all those listeners who have been here for so long!&nbsp; </li>

<p><li><span class="caps">MANY</span> thanks for all the offers of audio production assistance</li><br />
		<li>Dan met with Craig Bowser down at VoiceCon, also David Endler, Mark Collier, etc.</li><br />
		<li>Jonathan met with Dean Elwood, Martyn Davies, etc.</li><br />
		<li><a href="http://voipsa.org/blog/2008/03/21/four-new-security-vulnerabilities-in-asterisk-time-to-upgrade/">Four Asterisk vulnerabilities</a></li><br />
<li>The Economist: <a href="http://www.economist.com/printedition/displaystory.cfm?story_id=10789393">Bugging The Cloud</a></li><br />
<li>Forbes: <a href="http://www.forbes.com/technology/2008/03/18/zimmerman-hacking-voip-tech-security-cx_ag_0318voip.html">How to Make Your Phone Untappable</a></li><br />
<li>VoIP News: <a href="http://www.voip-news.com/feature/voip-spying-031308/">VoIP: Who Might Be Spying on Your Communications? (Hint &#8211; It&#8217;s Not Just the <span class="caps">NSA</span></a></li><br />
		<li>VoIP News: <a href="http://www.voip-news.com/feature/17-wiretap-signs-031908/">Listen Up: 17 Signs That You Are Being Wiretapped</a></li><br />
<li>eChannelLine: <a href="http://www.echannelline.com/usa/brief.cfm?item=15198">Businesses lagging in securing VoIP</a> (also <a href="http://www.computerweekly.com/Articles/2008/03/25/229961/security-being-ignored-as-voip-deployments-increase.htm">ComputerWeekly.com</a> and <a href="http://www.businesswire.com/portal/site/google/?ndmViewId=news_view&#38;newsId=20080324005525&#38;newsLang=en">news release</a> )</li><br />
		<li>eChannelLine: <a href="http://www.echannelline.com/usa/story.cfm?item=23076">Ingate launches enhanced security for VoIP and <span class="caps">SIP</span></a> (also <a href="http://www.voipplanet.com/solutions/article.php/3735601">Enterprise VoIPPlanet</a> )</li><br />
<li>Voice of <span class="caps">VOIPSA</span>: <a href="http://voipsa.org/blog/2008/03/24/hacking-zyxel-gateways/">Hacking Zyxel Gateways</a></li><br />
		<li>Voice of <span class="caps">VOIPSA</span>: <a href="http://voipsa.org/blog/2008/03/17/vishing-attacks/">Vishing Attacks</a></li><br />
		<li>Voice of <span class="caps">VOIPSA</span>: <a href="http://voipsa.org/blog/2008/03/19/fbi-voip-surveillance-requirements-leaked/">FBI VoIP Surveillance Requirements Leaked</a> (also in <a href="http://www.fiercevoip.com/story/fbi-voip-docs-leaked-again/2008-03-17">FierceVoIP</a> and <a href="http://yro.slashdot.org/article.pl?sid=08/03/15/2021257">Slashdot</a> )</li><br />
		<li>Voice of <span class="caps">VOIPSA</span>: <a href="http://voipsa.org/blog/2008/03/20/hackers-send-thousands-of-fake-calls-to-deaf-people/">Hackers Send Thousands of Fake Calls to Deaf People</a></li><br />
<li>SnapVoIP: <a href="http://snapvoip.blogspot.com/2008/03/unified-communications-in-virtual.html">Unified Communications in Virtual Worlds to Solve &#8216;Tower of Babel&#8217; for Intelligence Agencies</a></li><br />
		<li><a href="http://www.textually.org/textually/archives/2008/03/019464.htm">Israeli-made Cryptophone attracts world spy agencies</a> pointing to <a href="http://www.tikalnetworks.com/voip/index.php?cid=29">product site</a></li><br />
<li>BlogInfoSec.com: <a href="http://www.bloginfosec.com/2008/03/25/save-the-whales/">Save The Whales</a> (about a new form of phishing)</li><br />
<li>Network Computing: <a href="http://www.networkcomputing.com/immersion/dataprivacy/showArticle.jhtml?articleID=206904104">Your Data and the <span class="caps">P2P </span>Peril</a></li><br />
<li>NetQoS: <a href="http://www.networkperformancedaily.com/2008/03/voip_monitor_v11_released_and_1.html">VoIP Monitor 1.1 released</a></li><br />
<li><span class="caps">PC </span>World: <a href="http://www.pcworld.com/article/id,143810-c,webservices/article.html">FaceTime Security Product Scans Skype&#8217;s Encrypted IM</a> and <a href="http://www.earthtimes.org/articles/show/facetime-provides-unmatched-malware-prevention-for-leading-voip-and-chat-software,322357.shtml">news release</a></li><br />
		<li><a href="http://www.earthtimes.org/articles/show/sipera-ipcs-solution-for-teleworkers-rated-avaya-compliant,318456.shtml">Sipera <span class="caps">IPCS </span>Solution for Teleworkers Rated &#8216;Avaya Compliant&#8217;</a></li><br />
		<li><a href="http://www.earthtimes.org/articles/show/extreme-networks-boosts-security-for-converged-voice-and-data-networks,317382.shtml">Extreme Networks Boosts Security for Converged Voice and Data Networks with New Tools</a></li></p>

<p><li>Review of the last week's traffic on the <a href="http://www.voipsa.org/VOIPSEC/">VOIPSEC </a>public mailing list&nbsp; </li><br />
<li>Wrap-up of the show </li><br />
<li>32:27 - End of show&nbsp; </li></ul> <p>Comments, suggestions and feedback are welcome either as replies to this post&nbsp; or via e-mail to <a href="mailto:blueboxpodcast@gmail.com">blueboxpodcast@gmail.com</a>.&nbsp; Audio comments sent as attached MP3 files are definitely welcome and will be played in future shows.&nbsp; You may also call the listener comment line at either +1-415-830-5439 or via SIP to '<a href="sip:bluebox@voipuser.org">bluebox@voipuser.org</a>' to leave a comment there.&nbsp; </p> <p>Thank you for listening and please do let us know what you think of the show. </p></p></div>
]]></content:encoded>
      <pubDate>Mon, 09 Jun 2008 12:30:57 +0000</pubDate>
      <category domain="http://securityratty.com/tag/voip">voip</category>
      <category domain="http://securityratty.com/tag/voip security news">voip security news</category>
      <category domain="http://securityratty.com/tag/voip monitor">voip monitor</category>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/voip news">voip news</category>
      <category domain="http://securityratty.com/tag/asterisk vulnerabilities">asterisk vulnerabilities</category>
      <category domain="http://securityratty.com/tag/voip security podcast">voip security podcast</category>
      <category domain="http://securityratty.com/tag/blue box">blue box</category>
      <category domain="http://securityratty.com/tag/podcast">podcast</category>
      <source url="http://www.blueboxpodcast.com/2008/06/blue-box-79-ast.html">Blue Box #79: Asterisk vulnerabilities, VoiceCon/VON coverage, eavesdropping, FBI, ZFone, P2P, VoIP security news and more</source>
    </item>
    <item>
      <title><![CDATA[Blue Box #79: Asterisk vulnerabilities, VoiceCon/VON coverage, eavesdropping, FBI, ZFone, P2P, VoIP security news and more]]></title>
      <link>http://securityratty.com/article/6ff472aef8df8c39ce9d47bf4fe36d51</link>
      <guid>http://securityratty.com/article/6ff472aef8df8c39ce9d47bf4fe36d51</guid>
      <description><![CDATA[Synopsis: Blue Box #79: Asterisk vulnerabilities, VoiceCon/VON coverage, eavesdropping, FBI, ZFone, P2P, VoIP security news and more
Welcome to Blue Box: The VoIP Security Podcast #78, a 32-minute...]]></description>
      <content:encoded><![CDATA[
<div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Synopsis:</strong>&nbsp; Blue Box #79: Asterisk vulnerabilities, VoiceCon/VON coverage, eavesdropping, FBI, ZFone, P2P, VoIP security news and more</p><hr /><p>Welcome to <strong>Blue Box: The VoIP Security Podcast</strong> #78, a 32-minute podcast&nbsp; from Dan York and Jonathan Zar covering VoIP security news, comments and opinions.&nbsp; &nbsp; </p>

<p><a rel="enclosure" href="http://media.libsyn.com/media/lodestar/BBP-079-2008-03-27.mp3">Download the show here</a> (MP3, 15MB) or <a href="http://feeds.feedburner.com/BlueBox">subscribe to the RSS feed</a> to download the show automatically.&nbsp; </p>

<p><strong>NOTE: </strong><em>This show was originally recorded on March 27, 2008. Yes, that was over two months ago... we know...</em></p> 

<p>You may also listen to this podcast right now:</p> 

<p><object width="200" height="20" data="http://www.blueboxpodcast.com/dewplayer.swf?son=http://media.libsyn.com/media/lodestar/BBP-079-2008-03-27.mp3" type="application/x-shockwave-flash"><param value="http://www.blueboxpodcast.com/dewplayer.swf?son=http://media.libsyn.com/media/lodestar/BBP-079-2008-03-27.mp3&amp;bgcolor=#FFFFFF" name="movie" /></object> </p> 

<p><strong>Show Content:</strong></p> 
 

<ul> <li>00:20 - Intro to the show, contact information and how to provide comments.&nbsp; Welcome to all the new listeners - and to all those listeners who have been here for so long!&nbsp; </li>

<p><li><span class="caps">MANY</span> thanks for all the offers of audio production assistance</li><br />
		<li>Dan met with Craig Bowser down at VoiceCon, also David Endler, Mark Collier, etc.</li><br />
		<li>Jonathan met with Dean Elwood, Martyn Davies, etc.</li><br />
		<li><a href="http://voipsa.org/blog/2008/03/21/four-new-security-vulnerabilities-in-asterisk-time-to-upgrade/">Four Asterisk vulnerabilities</a></li><br />
<li>The Economist: <a href="http://www.economist.com/printedition/displaystory.cfm?story_id=10789393">Bugging The Cloud</a></li><br />
<li>Forbes: <a href="http://www.forbes.com/technology/2008/03/18/zimmerman-hacking-voip-tech-security-cx_ag_0318voip.html">How to Make Your Phone Untappable</a></li><br />
<li>VoIP News: <a href="http://www.voip-news.com/feature/voip-spying-031308/">VoIP: Who Might Be Spying on Your Communications? (Hint &#8211; It&#8217;s Not Just the <span class="caps">NSA</span></a></li><br />
		<li>VoIP News: <a href="http://www.voip-news.com/feature/17-wiretap-signs-031908/">Listen Up: 17 Signs That You Are Being Wiretapped</a></li><br />
<li>eChannelLine: <a href="http://www.echannelline.com/usa/brief.cfm?item=15198">Businesses lagging in securing VoIP</a> (also <a href="http://www.computerweekly.com/Articles/2008/03/25/229961/security-being-ignored-as-voip-deployments-increase.htm">ComputerWeekly.com</a> and <a href="http://www.businesswire.com/portal/site/google/?ndmViewId=news_view&#38;newsId=20080324005525&#38;newsLang=en">news release</a> )</li><br />
		<li>eChannelLine: <a href="http://www.echannelline.com/usa/story.cfm?item=23076">Ingate launches enhanced security for VoIP and <span class="caps">SIP</span></a> (also <a href="http://www.voipplanet.com/solutions/article.php/3735601">Enterprise VoIPPlanet</a> )</li><br />
<li>Voice of <span class="caps">VOIPSA</span>: <a href="http://voipsa.org/blog/2008/03/24/hacking-zyxel-gateways/">Hacking Zyxel Gateways</a></li><br />
		<li>Voice of <span class="caps">VOIPSA</span>: <a href="http://voipsa.org/blog/2008/03/17/vishing-attacks/">Vishing Attacks</a></li><br />
		<li>Voice of <span class="caps">VOIPSA</span>: <a href="http://voipsa.org/blog/2008/03/19/fbi-voip-surveillance-requirements-leaked/">FBI VoIP Surveillance Requirements Leaked</a> (also in <a href="http://www.fiercevoip.com/story/fbi-voip-docs-leaked-again/2008-03-17">FierceVoIP</a> and <a href="http://yro.slashdot.org/article.pl?sid=08/03/15/2021257">Slashdot</a> )</li><br />
		<li>Voice of <span class="caps">VOIPSA</span>: <a href="http://voipsa.org/blog/2008/03/20/hackers-send-thousands-of-fake-calls-to-deaf-people/">Hackers Send Thousands of Fake Calls to Deaf People</a></li><br />
<li>SnapVoIP: <a href="http://snapvoip.blogspot.com/2008/03/unified-communications-in-virtual.html">Unified Communications in Virtual Worlds to Solve &#8216;Tower of Babel&#8217; for Intelligence Agencies</a></li><br />
		<li><a href="http://www.textually.org/textually/archives/2008/03/019464.htm">Israeli-made Cryptophone attracts world spy agencies</a> pointing to <a href="http://www.tikalnetworks.com/voip/index.php?cid=29">product site</a></li><br />
<li>BlogInfoSec.com: <a href="http://www.bloginfosec.com/2008/03/25/save-the-whales/">Save The Whales</a> (about a new form of phishing)</li><br />
<li>Network Computing: <a href="http://www.networkcomputing.com/immersion/dataprivacy/showArticle.jhtml?articleID=206904104">Your Data and the <span class="caps">P2P </span>Peril</a></li><br />
<li>NetQoS: <a href="http://www.networkperformancedaily.com/2008/03/voip_monitor_v11_released_and_1.html">VoIP Monitor 1.1 released</a></li><br />
<li><span class="caps">PC </span>World: <a href="http://www.pcworld.com/article/id,143810-c,webservices/article.html">FaceTime Security Product Scans Skype&#8217;s Encrypted IM</a> and <a href="http://www.earthtimes.org/articles/show/facetime-provides-unmatched-malware-prevention-for-leading-voip-and-chat-software,322357.shtml">news release</a></li><br />
		<li><a href="http://www.earthtimes.org/articles/show/sipera-ipcs-solution-for-teleworkers-rated-avaya-compliant,318456.shtml">Sipera <span class="caps">IPCS </span>Solution for Teleworkers Rated &#8216;Avaya Compliant&#8217;</a></li><br />
		<li><a href="http://www.earthtimes.org/articles/show/extreme-networks-boosts-security-for-converged-voice-and-data-networks,317382.shtml">Extreme Networks Boosts Security for Converged Voice and Data Networks with New Tools</a></li></p>

<p><li>Review of the last week's traffic on the <a href="http://www.voipsa.org/VOIPSEC/">VOIPSEC </a>public mailing list&nbsp; </li><br />
<li>Wrap-up of the show </li><br />
<li>32:27 - End of show&nbsp; </li></ul> <p>Comments, suggestions and feedback are welcome either as replies to this post&nbsp; or via e-mail to <a href="mailto:blueboxpodcast@gmail.com">blueboxpodcast@gmail.com</a>.&nbsp; Audio comments sent as attached MP3 files are definitely welcome and will be played in future shows.&nbsp; You may also call the listener comment line at either +1-415-830-5439 or via SIP to '<a href="sip:bluebox@voipuser.org">bluebox@voipuser.org</a>' to leave a comment there.&nbsp; </p> <p>Thank you for listening and please do let us know what you think of the show. </p></p></div>

<p><a href="http://feeds.feedburner.com/~a/BlueBox?a=i1mO1B"><img src="http://feeds.feedburner.com/~a/BlueBox?i=i1mO1B" border="0"></img></a></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/BlueBox?a=YWUw1I"><img src="http://feeds.feedburner.com/~f/BlueBox?i=YWUw1I" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/BlueBox?a=74RvnI"><img src="http://feeds.feedburner.com/~f/BlueBox?i=74RvnI" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/BlueBox?a=c8gwAI"><img src="http://feeds.feedburner.com/~f/BlueBox?i=c8gwAI" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/BlueBox?a=HpdUtI"><img src="http://feeds.feedburner.com/~f/BlueBox?i=HpdUtI" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/BlueBox?a=p9H2li"><img src="http://feeds.feedburner.com/~f/BlueBox?i=p9H2li" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/BlueBox?a=oUodVI"><img src="http://feeds.feedburner.com/~f/BlueBox?i=oUodVI" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/BlueBox/~4/308280975" height="1" width="1"/>]]></content:encoded>
      <pubDate>Mon, 09 Jun 2008 11:30:58 +0000</pubDate>
      <category domain="http://securityratty.com/tag/voip">voip</category>
      <category domain="http://securityratty.com/tag/voip security news">voip security news</category>
      <category domain="http://securityratty.com/tag/voip monitor">voip monitor</category>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/voip news">voip news</category>
      <category domain="http://securityratty.com/tag/asterisk vulnerabilities">asterisk vulnerabilities</category>
      <category domain="http://securityratty.com/tag/voip security podcast">voip security podcast</category>
      <category domain="http://securityratty.com/tag/blue box">blue box</category>
      <category domain="http://securityratty.com/tag/podcast">podcast</category>
      <source url="http://feeds.feedburner.com/~r/BlueBox/~3/308280975/blue-box-79-ast.html">Blue Box #79: Asterisk vulnerabilities, VoiceCon/VON coverage, eavesdropping, FBI, ZFone, P2P, VoIP security news and more</source>
    </item>
    <item>
      <title><![CDATA[Blue Box #76: Cisco, Skype and BT vulnerabilities, when SIP looks like SPIT, VoIP security threat predictions and the FBI forgets to pay their bills, ]]></title>
      <link>http://securityratty.com/article/7c8d62985159e1b742a937909b0b64c5</link>
      <guid>http://securityratty.com/article/7c8d62985159e1b742a937909b0b64c5</guid>
      <description><![CDATA[Synopsis: Blue Box #76: Cisco, Skype and BT vulnerabilities, when SIP looks like SPIT, VoIP security threat predictions and the FBI forgets to pay their bills, plus listener comments and more
Welcome...]]></description>
      <content:encoded><![CDATA[
<div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Synopsis:</strong> Blue Box #76: Cisco, Skype and BT vulnerabilities, when SIP looks like SPIT, VoIP security threat predictions and the FBI forgets to pay their bills, plus listener comments and more... 
</p><hr /><p>Welcome to <strong>Blue Box: The VoIP Security Podcast</strong> #76, a 38-minute podcast&nbsp; from Dan York and Jonathan Zar covering VoIP security news, comments and opinions.&nbsp; &nbsp; </p>

<p><a href="http://ripple.radiotail.com/409/BBP-076-2008-01-22.mp3" rel="enclosure">Download the show here</a> (MP3, 17MB) or <a href="http://feeds.feedburner.com/BlueBox">subscribe to the RSS feed</a> to download the show automatically.&nbsp; </p> 

<p>You may also listen to this podcast right now:</p> 

<p><object width="200" height="20" type="application/x-shockwave-flash" data="http://www.blueboxpodcast.com/dewplayer.swf?son=http://ripple.radiotail.com/409/BBP-076-2008-01-22.mp3"><param name="movie" value="http://www.blueboxpodcast.com/dewplayer.swf?son=http://ripple.radiotail.com/409/BBP-076-2008-01-22.mp3&amp;bgcolor=#FFFFFF" /></object> </p> 

<p><strong>Show Content:</strong></p> 
 

<ul> <li>00:20 - Intro to the show, contact information and how to provide comments.&nbsp; Welcome to all the new listeners - and to all those listeners who have been here for so long!&nbsp; </li>

<li><a href="http://www.blueboxpodcast.com/2007/12/new-audio-comme.html">new comment line +1-415-830-5439</a></li>
<li>Cisco: <a href="http://www.cisco.com/en/US/products/products_security_advisory09186a0080932c61.shtml">Cisco Unified Communications Manager <span class="caps">CTL </span>Provider Heap Overflow</a></li>
		<li>Skype: <a href="http://skype.com/security/skype-sb-2008-001.html">SKYPE-SB/2008-001: Skype Cross Zone Scripting Vulnerability</a> ??? coverage in <a href="http://share.skype.com/sites/security/2008/01/skype_cross_zone_scripting_vul.html">Skype blog</a> and <a href="http://www.computerworld.com/action/article.do?command=viewArticleBasic&amp;articleId=9057778&amp;intsrc=news_ts_head">ComputerWorld article</a></li>
		<li>GNUcitizen: <a href="http://www.gnucitizen.org/blog/call-jacking">BT Home Call Jacking</a> also mentioned in <a href="http://voipsa.org/pipermail/voipsec_voipsa.org/2008-January/002565.html">VOIPSEC message</a> ??? coverage in <a href="http://www.pcworld.com/article/id,141587-c,onlinesecurity/article.html">PC World</a> and <a href="http://www.theregister.co.uk/2008/01/21/bt_home_hub_voip_hijacking/">The Register</a></li>
<li>Voice of <span class="caps">VOIPSA</span>: <a href="http://voipsa.org/blog/2008/01/16/an-excellent-overview-of-sip-security-issues-at-the-3rd-etsi-security-workshop/">SIP Security slides at <span class="caps">ETSI</span> event</a></li>
		<li>Voice of <span class="caps">VOIPSA</span>: <a href="http://voipsa.org/blog/2008/01/17/can-legitimate-sip-traffic-be-mistaken-for-spit-how-do-you-differentiate/">How do you differentiate between legitimate <span class="caps">SIP</span> usage and <span class="caps">SPIT</span>?</a> pointing to <a href="http://www.ietf.org/internet-drafts/draft-york-spit-similarity-scenarios-00.txt">Dan???s Internet-Draft document</a></li>
		<li><a href="http://tools.ietf.org/html/rfc5039">RFC 5039</a> on <span class="caps">SIP</span> and Spam</li>
<li>Sipera ???news release on <a href="http://www.sipera.com/index.php?action=company,press_release&amp;id=399">Top 5 VoIP Threat Predictions of 2008</a> ??? coverage in The Register: <a href="http://www.theregister.co.uk/2008/01/17/voip_security_2008/">2008 ??? the year VoIP gets hacked?</a> and <span class="caps">IT </span>Business Edge: <a href="http://www.itbusinessedge.com/blogs/top/?p=260">VoIP Security Still Falling Short</a></li>
		<li>SearchSecurity.com: <a href="http://searchsecurity.techtarget.com/tip/0,289483,sid14_gci1293693,00.html">Enterprise security in 2008: Addressing emerging threats like VoIP and virtualization</a></li>
<li>C|Net blogs: <a href="http://www.cnet.com/surveillance-state/8301-13739_1-9851587-46.html">Can terrorists use the Net to avoid wiretaps?</a></li>
<p><a href="http://apnews.myway.com/article/20080110/D8U35C500.html">FBI Wiretaps dropped due to unpaid bills</a>
		</p>

<li><a href="http://www.telegeography.com/cu/article.php?article_id=21245&amp;email=html">CityCell joins rivals forced to pay up for VoIP infringements</a></li>
<li>Comment (email) from someone looking for VoIP security professional in Connecticut</li>
		<li>Comment (email) from Shlomo Dubrowin</li><li>Review of the last week's traffic on the <a href="http://www.voipsa.org/VOIPSEC/">VOIPSEC </a>public mailing list&nbsp; </li>
<li>Wrap-up of the show </li>
<li> 38:09 - End of show&nbsp; </li></ul> <p>Comments, suggestions and feedback are welcome either as replies to this post&nbsp; or via e-mail to <a href="mailto:blueboxpodcast@gmail.com">blueboxpodcast@gmail.com</a>.&nbsp; Audio comments sent as attached MP3 files are definitely welcome and will be played in future shows.&nbsp; You may also call the listener comment line at either +1-415-830-5439 or via SIP to '<a href="sip:bluebox@voipuser.org">bluebox@voipuser.org</a>' to leave a comment there.&nbsp; </p> <p>Thank you for listening and please do let us know what you think of the show. </p></div>
]]></content:encoded>
      <pubDate>Thu, 14 Feb 2008 16:37:49 +0000</pubDate>
      <category domain="http://securityratty.com/tag/voip">voip</category>
      <category domain="http://securityratty.com/tag/voip infringements">voip infringements</category>
      <category domain="http://securityratty.com/tag/voip security professional">voip security professional</category>
      <category domain="http://securityratty.com/tag/voip threat predictions">voip threat predictions</category>
      <category domain="http://securityratty.com/tag/voip security news">voip security news</category>
      <category domain="http://securityratty.com/tag/voip security">voip security</category>
      <category domain="http://securityratty.com/tag/voip security podcast">voip security podcast</category>
      <category domain="http://securityratty.com/tag/comments">comments</category>
      <category domain="http://securityratty.com/tag/sip">sip</category>
      <source url="http://www.blueboxpodcast.com/2008/02/blue-box-76-cis.html">Blue Box #76: Cisco, Skype and BT vulnerabilities, when SIP looks like SPIT, VoIP security threat predictions and the FBI forgets to pay their bills, </source>
    </item>
    <item>
      <title><![CDATA[Blue Box #76: Cisco, Skype and BT vulnerabilities, when SIP looks like SPIT, VoIP security threat predictions and the FBI forgets to pay their bills, ]]></title>
      <link>http://securityratty.com/article/b00b1b75e564b40517a1a73ddcf6657b</link>
      <guid>http://securityratty.com/article/b00b1b75e564b40517a1a73ddcf6657b</guid>
      <description><![CDATA[Synopsis: Blue Box #76: Cisco, Skype and BT vulnerabilities, when SIP looks like SPIT, VoIP security threat predictions and the FBI forgets to pay their bills, plus listener comments and more
Welcome...]]></description>
      <content:encoded><![CDATA[
<div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Synopsis:</strong> Blue Box #76: Cisco, Skype and BT vulnerabilities, when SIP looks like SPIT, VoIP security threat predictions and the FBI forgets to pay their bills, plus listener comments and more... 
</p><hr /><p>Welcome to <strong>Blue Box: The VoIP Security Podcast</strong> #76, a 38-minute podcast&nbsp; from Dan York and Jonathan Zar covering VoIP security news, comments and opinions.&nbsp; &nbsp; </p>

<p><a href="http://ripple.radiotail.com/409/BBP-076-2008-01-22.mp3" rel="enclosure">Download the show here</a> (MP3, 17MB) or <a href="http://feeds.feedburner.com/BlueBox">subscribe to the RSS feed</a> to download the show automatically.&nbsp; </p> 

<p>You may also listen to this podcast right now:</p> 

<p><object width="200" height="20" type="application/x-shockwave-flash" data="http://www.blueboxpodcast.com/dewplayer.swf?son=http://ripple.radiotail.com/409/BBP-076-2008-01-22.mp3"><param name="movie" value="http://www.blueboxpodcast.com/dewplayer.swf?son=http://ripple.radiotail.com/409/BBP-076-2008-01-22.mp3&amp;bgcolor=#FFFFFF" /></object> </p> 

<p><strong>Show Content:</strong></p> 
 

<ul> <li>00:20 - Intro to the show, contact information and how to provide comments.&nbsp; Welcome to all the new listeners - and to all those listeners who have been here for so long!&nbsp; </li>

<li><a href="http://www.blueboxpodcast.com/2007/12/new-audio-comme.html">new comment line +1-415-830-5439</a></li>
<li>Cisco: <a href="http://www.cisco.com/en/US/products/products_security_advisory09186a0080932c61.shtml">Cisco Unified Communications Manager <span class="caps">CTL </span>Provider Heap Overflow</a></li>
		<li>Skype: <a href="http://skype.com/security/skype-sb-2008-001.html">SKYPE-SB/2008-001: Skype Cross Zone Scripting Vulnerability</a> – coverage in <a href="http://share.skype.com/sites/security/2008/01/skype_cross_zone_scripting_vul.html">Skype blog</a> and <a href="http://www.computerworld.com/action/article.do?command=viewArticleBasic&amp;articleId=9057778&amp;intsrc=news_ts_head">ComputerWorld article</a></li>
		<li>GNUcitizen: <a href="http://www.gnucitizen.org/blog/call-jacking">BT Home Call Jacking</a> also mentioned in <a href="http://voipsa.org/pipermail/voipsec_voipsa.org/2008-January/002565.html">VOIPSEC message</a> – coverage in <a href="http://www.pcworld.com/article/id,141587-c,onlinesecurity/article.html">PC World</a> and <a href="http://www.theregister.co.uk/2008/01/21/bt_home_hub_voip_hijacking/">The Register</a></li>
<li>Voice of <span class="caps">VOIPSA</span>: <a href="http://voipsa.org/blog/2008/01/16/an-excellent-overview-of-sip-security-issues-at-the-3rd-etsi-security-workshop/">SIP Security slides at <span class="caps">ETSI</span> event</a></li>
		<li>Voice of <span class="caps">VOIPSA</span>: <a href="http://voipsa.org/blog/2008/01/17/can-legitimate-sip-traffic-be-mistaken-for-spit-how-do-you-differentiate/">How do you differentiate between legitimate <span class="caps">SIP</span> usage and <span class="caps">SPIT</span>?</a> pointing to <a href="http://www.ietf.org/internet-drafts/draft-york-spit-similarity-scenarios-00.txt">Dan’s Internet-Draft document</a></li>
		<li><a href="http://tools.ietf.org/html/rfc5039">RFC 5039</a> on <span class="caps">SIP</span> and Spam</li>
<li>Sipera “news release on <a href="http://www.sipera.com/index.php?action=company,press_release&amp;id=399">Top 5 VoIP Threat Predictions of 2008</a> – coverage in The Register: <a href="http://www.theregister.co.uk/2008/01/17/voip_security_2008/">2008 – the year VoIP gets hacked?</a> and <span class="caps">IT </span>Business Edge: <a href="http://www.itbusinessedge.com/blogs/top/?p=260">VoIP Security Still Falling Short</a></li>
		<li>SearchSecurity.com: <a href="http://searchsecurity.techtarget.com/tip/0,289483,sid14_gci1293693,00.html">Enterprise security in 2008: Addressing emerging threats like VoIP and virtualization</a></li>
<li>C|Net blogs: <a href="http://www.cnet.com/surveillance-state/8301-13739_1-9851587-46.html">Can terrorists use the Net to avoid wiretaps?</a></li>
<p><a href="http://apnews.myway.com/article/20080110/D8U35C500.html">FBI Wiretaps dropped due to unpaid bills</a>
		</p>

<li><a href="http://www.telegeography.com/cu/article.php?article_id=21245&amp;email=html">CityCell joins rivals forced to pay up for VoIP infringements</a></li>
<li>Comment (email) from someone looking for VoIP security professional in Connecticut</li>
		<li>Comment (email) from Shlomo Dubrowin</li><li>Review of the last week's traffic on the <a href="http://www.voipsa.org/VOIPSEC/">VOIPSEC </a>public mailing list&nbsp; </li>
<li>Wrap-up of the show </li>
<li> 38:09 - End of show&nbsp; </li></ul> <p>Comments, suggestions and feedback are welcome either as replies to this post&nbsp; or via e-mail to <a href="mailto:blueboxpodcast@gmail.com">blueboxpodcast@gmail.com</a>.&nbsp; Audio comments sent as attached MP3 files are definitely welcome and will be played in future shows.&nbsp; You may also call the listener comment line at either +1-415-830-5439 or via SIP to '<a href="sip:bluebox@voipuser.org">bluebox@voipuser.org</a>' to leave a comment there.&nbsp; </p> <p>Thank you for listening and please do let us know what you think of the show. </p></div>

<p><a href="http://feeds.feedburner.com/~a/BlueBox?a=W9kI7J"><img src="http://feeds.feedburner.com/~a/BlueBox?i=W9kI7J" border="0"></img></a></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/BlueBox?a=SUDPe7E"><img src="http://feeds.feedburner.com/~f/BlueBox?i=SUDPe7E" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/BlueBox?a=lOe0BeE"><img src="http://feeds.feedburner.com/~f/BlueBox?i=lOe0BeE" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/BlueBox?a=S8181ZE"><img src="http://feeds.feedburner.com/~f/BlueBox?i=S8181ZE" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/BlueBox?a=j5PzJJE"><img src="http://feeds.feedburner.com/~f/BlueBox?i=j5PzJJE" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/BlueBox?a=N4yapKe"><img src="http://feeds.feedburner.com/~f/BlueBox?i=N4yapKe" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/BlueBox?a=IOPW57E"><img src="http://feeds.feedburner.com/~f/BlueBox?i=IOPW57E" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/BlueBox/~4/235261257" height="1" width="1"/>]]></content:encoded>
      <pubDate>Thu, 14 Feb 2008 15:37:50 +0000</pubDate>
      <category domain="http://securityratty.com/tag/voip">voip</category>
      <category domain="http://securityratty.com/tag/voip infringements">voip infringements</category>
      <category domain="http://securityratty.com/tag/voip security professional">voip security professional</category>
      <category domain="http://securityratty.com/tag/voip threat predictions">voip threat predictions</category>
      <category domain="http://securityratty.com/tag/voip security news">voip security news</category>
      <category domain="http://securityratty.com/tag/voip security">voip security</category>
      <category domain="http://securityratty.com/tag/voip security podcast">voip security podcast</category>
      <category domain="http://securityratty.com/tag/comments">comments</category>
      <category domain="http://securityratty.com/tag/sip">sip</category>
      <source url="http://feeds.feedburner.com/~r/BlueBox/~3/235261257/blue-box-76-cis.html">Blue Box #76: Cisco, Skype and BT vulnerabilities, when SIP looks like SPIT, VoIP security threat predictions and the FBI forgets to pay their bills, </source>
    </item>
    <item>
      <title><![CDATA[Blue Box #74: 2008 Crystal Ball Edition, Asterisk and Trixbox vulnerabilities, top 10 lists, VoIP security trends for 2008 and more....]]></title>
      <link>http://securityratty.com/article/c0914c73b0c753bea48c9000c9d04ea9</link>
      <guid>http://securityratty.com/article/c0914c73b0c753bea48c9000c9d04ea9</guid>
      <description><![CDATA[Synopsis: Blue Box #74: 2008 Crystal Ball Edition, Asterisk and Trixbox vulnerabilities, top 10 lists, VoIP security trends for 2008 and more
Welcome to Blue Box: The VoIP Security Podcast #74, a...]]></description>
      <content:encoded><![CDATA[
<div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Synopsis:</strong> Blue Box #74: 2008 Crystal Ball Edition, Asterisk and Trixbox vulnerabilities, top 10 lists, VoIP security trends for 2008 and more....
</p><hr /><p>Welcome to <strong>Blue Box: The VoIP Security Podcast</strong> #74, a 44-minute podcast&nbsp; from Dan York and Jonathan Zar covering VoIP security news, comments and opinions.&nbsp; &nbsp; </p>

<p><a rel="enclosure" href="http://ripple.radiotail.com/409/BBP-074-2007-12-20.mp3">Download the show here</a> (MP3, 20MB) or <a href="http://feeds.feedburner.com/BlueBox">subscribe to the RSS feed</a> to download the show automatically.&nbsp; </p> 

<p>You may also listen to this podcast right now:</p> 

<p><object width="200" height="20" data="http://www.blueboxpodcast.com/dewplayer.swf?son=http://ripple.radiotail.com/409/BBP-074-2007-12-20.mp3" type="application/x-shockwave-flash"><param value="http://www.blueboxpodcast.com/dewplayer.swf?son=http://ripple.radiotail.com/409/BBP-074-2007-12-20.mp3&amp;bgcolor=#FFFFFF" name="movie" /></object> </p> 

<p><strong>Show Content:</strong></p> 
 

<ul> <li>00:20 - Intro to the show, contact information and how to provide comments.&nbsp; Welcome to all the new listeners - and to all those listeners who have been here for so long!&nbsp; </li>

<li><a href="http://www.blueboxpodcast.com/2007/12/new-audio-comme.html">new comment line +1-415-830-5439</a></li>
		<li><a href="http://www.blueboxpodcast.com/2007/12/blue-box-se022.html">SE 22 with Jonathan Rosenberg</a></li>
<li><a href="http://downloads.digium.com/pub/security/AST-2007-027.html">Asterisk <span class="caps">AST</span>-2007-027: Database matching order permits host-based authentication to be ignored</a></li>
		<li>Voice of <span class="caps">VOIPSA</span>: <a href="http://voipsa.org/blog/2007/12/17/trixbox-contains-phone-home-code-to-retrieve-arbitrary-commands-to-execute/">Trixbox contains &#8216;phone home&#8217; code to retrieve arbitrary commands to execute</a></li>
		<li><a href="http://www.trixbox.org/trixbox-ce-audit-tool-official-statement-and-fixes">trixbox CE audit tool official statement and fixes</a></li>
		<li><a href="http://www.trixbox.org/audit-tool-change-plan">Audit Tool Change Plan</a></li>
		<li><a href="http://www.trixbox.org/audit-tool-fix-being-pushed-out-tonight">Audit tool &#8216;fix&#8217; being pushed out tonight</a></li>

<li>ComputerWorld: <a href="http://www.computerworld.com/action/article.do?command=viewArticleBasic&#38;articleId=9053452&#38;source=rss_news50">VoIP vulnerabilities increasing, but not exploits</a></li>
		<li><span class="caps">CRN</span>: <a href="http://www.crn.com/networking/205100204">Top 9 VoIP Threats and Vulnerabilities</a> (Sipera PR strikes again) &#8211; points to <span class="caps">CRN</span> article: <a href="http://www.crn.com/networking/204805527">VoIP Threats, Vulnerabilities Abound</a> which is based on press release <a href="http://www.techweb.com/showPressRelease.jhtml?articleID=X661245">Sipera <span class="caps">VIPER </span>Lab Reveals Top 5 VoIP Vulnerabilities in 2007</a></li>
		<li>Voice of <span class="caps">VOIPSA</span>: <a href="http://voipsa.org/blog/2007/12/12/pointers-to-any-audit-methodology-for-forensic-analysis-of-voip-systems/">Pointers to any audi methodology for forensic analysis of VoIP systems?</a></li>
		<li><span class="caps">TMC</span>.net: <a href="http://sip.tmcnet.com/topics/sip-and-open-standards/articles/16548-sip-security-just-it-right.htm">SIP and Security: Just Do It Right!</a></li>

<li><a href="http://money.cnn.com/news/newsfeeds/articles/prnewswire/NYW006A19122007-1.htm">PAETEC, Alcatel-Lucent Deploy Industry Leading Disaster Recovery VoIP Solution</a></li>

<li>Feature:  top stories of 2007 and trends for 2008</li>



<li>No comments this week.</li>
<li>Review of the last week's traffic on the <a href="http://www.voipsa.org/VOIPSEC/">VOIPSEC </a>public mailing list&nbsp; </li>
<li>Wrap-up of the show </li>
<li> 43:57 - End of show&nbsp; </li></ul> <p>Comments, suggestions and feedback are welcome either as replies to this post&nbsp; or via e-mail to <a href="mailto:blueboxpodcast@gmail.com">blueboxpodcast@gmail.com</a>.&nbsp; Audio comments sent as attached MP3 files are definitely welcome and will be played in future shows.&nbsp; You may also call the listener comment line at either +1-415-830-5439 or via SIP to '<a href="sip:bluebox@voipuser.org">bluebox@voipuser.org</a>' to leave a comment there.&nbsp; </p> <p>Thank you for listening and please do let us know what you think of the show. </p></div>
]]></content:encoded>
      <pubDate>Tue, 08 Jan 2008 14:42:39 +0000</pubDate>
      <category domain="http://securityratty.com/tag/trends">trends</category>
      <category domain="http://securityratty.com/tag/vulnerabilities">vulnerabilities</category>
      <category domain="http://securityratty.com/tag/voip security trends">voip security trends</category>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/trixbox vulnerabilities">trixbox vulnerabilities</category>
      <category domain="http://securityratty.com/tag/voip vulnerabilities">voip vulnerabilities</category>
      <category domain="http://securityratty.com/tag/listener comment line">listener comment line</category>
      <category domain="http://securityratty.com/tag/comment line">comment line</category>
      <category domain="http://securityratty.com/tag/top">top</category>
      <source url="http://www.blueboxpodcast.com/2008/01/blue-box-74-200.html">Blue Box #74: 2008 Crystal Ball Edition, Asterisk and Trixbox vulnerabilities, top 10 lists, VoIP security trends for 2008 and more....</source>
    </item>
    <item>
      <title><![CDATA[Blue Box #74: 2008 Crystal Ball Edition, Asterisk and Trixbox vulnerabilities, top 10 lists, VoIP security trends for 2008 and more....]]></title>
      <link>http://securityratty.com/article/8076404175c339d862777d2e464a59e5</link>
      <guid>http://securityratty.com/article/8076404175c339d862777d2e464a59e5</guid>
      <description><![CDATA[Synopsis: Blue Box #74: 2008 Crystal Ball Edition, Asterisk and Trixbox vulnerabilities, top 10 lists, VoIP security trends for 2008 and more
Welcome to Blue Box: The VoIP Security Podcast #74, a...]]></description>
      <content:encoded><![CDATA[
<div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Synopsis:</strong> Blue Box #74: 2008 Crystal Ball Edition, Asterisk and Trixbox vulnerabilities, top 10 lists, VoIP security trends for 2008 and more....
</p><hr /><p>Welcome to <strong>Blue Box: The VoIP Security Podcast</strong> #74, a 44-minute podcast&nbsp; from Dan York and Jonathan Zar covering VoIP security news, comments and opinions.&nbsp; &nbsp; </p>

<p><a rel="enclosure" href="http://ripple.radiotail.com/409/BBP-074-2007-12-20.mp3">Download the show here</a> (MP3, 20MB) or <a href="http://feeds.feedburner.com/BlueBox">subscribe to the RSS feed</a> to download the show automatically.&nbsp; </p> 

<p>You may also listen to this podcast right now:</p> 

<p><object width="200" height="20" data="http://www.blueboxpodcast.com/dewplayer.swf?son=http://ripple.radiotail.com/409/BBP-074-2007-12-20.mp3" type="application/x-shockwave-flash"><param value="http://www.blueboxpodcast.com/dewplayer.swf?son=http://ripple.radiotail.com/409/BBP-074-2007-12-20.mp3&amp;bgcolor=#FFFFFF" name="movie" /></object> </p> 

<p><strong>Show Content:</strong></p> 
 

<ul> <li>00:20 - Intro to the show, contact information and how to provide comments.&nbsp; Welcome to all the new listeners - and to all those listeners who have been here for so long!&nbsp; </li>

<li><a href="http://www.blueboxpodcast.com/2007/12/new-audio-comme.html">new comment line +1-415-830-5439</a></li>
		<li><a href="http://www.blueboxpodcast.com/2007/12/blue-box-se022.html">SE 22 with Jonathan Rosenberg</a></li>
<li><a href="http://downloads.digium.com/pub/security/AST-2007-027.html">Asterisk <span class="caps">AST</span>-2007-027: Database matching order permits host-based authentication to be ignored</a></li>
		<li>Voice of <span class="caps">VOIPSA</span>: <a href="http://voipsa.org/blog/2007/12/17/trixbox-contains-phone-home-code-to-retrieve-arbitrary-commands-to-execute/">Trixbox contains &#8216;phone home&#8217; code to retrieve arbitrary commands to execute</a></li>
		<li><a href="http://www.trixbox.org/trixbox-ce-audit-tool-official-statement-and-fixes">trixbox CE audit tool official statement and fixes</a></li>
		<li><a href="http://www.trixbox.org/audit-tool-change-plan">Audit Tool Change Plan</a></li>
		<li><a href="http://www.trixbox.org/audit-tool-fix-being-pushed-out-tonight">Audit tool &#8216;fix&#8217; being pushed out tonight</a></li>

<li>ComputerWorld: <a href="http://www.computerworld.com/action/article.do?command=viewArticleBasic&#38;articleId=9053452&#38;source=rss_news50">VoIP vulnerabilities increasing, but not exploits</a></li>
		<li><span class="caps">CRN</span>: <a href="http://www.crn.com/networking/205100204">Top 9 VoIP Threats and Vulnerabilities</a> (Sipera PR strikes again) &#8211; points to <span class="caps">CRN</span> article: <a href="http://www.crn.com/networking/204805527">VoIP Threats, Vulnerabilities Abound</a> which is based on press release <a href="http://www.techweb.com/showPressRelease.jhtml?articleID=X661245">Sipera <span class="caps">VIPER </span>Lab Reveals Top 5 VoIP Vulnerabilities in 2007</a></li>
		<li>Voice of <span class="caps">VOIPSA</span>: <a href="http://voipsa.org/blog/2007/12/12/pointers-to-any-audit-methodology-for-forensic-analysis-of-voip-systems/">Pointers to any audi methodology for forensic analysis of VoIP systems?</a></li>
		<li><span class="caps">TMC</span>.net: <a href="http://sip.tmcnet.com/topics/sip-and-open-standards/articles/16548-sip-security-just-it-right.htm">SIP and Security: Just Do It Right!</a></li>

<li><a href="http://money.cnn.com/news/newsfeeds/articles/prnewswire/NYW006A19122007-1.htm">PAETEC, Alcatel-Lucent Deploy Industry Leading Disaster Recovery VoIP Solution</a></li>

<li>Feature:  top stories of 2007 and trends for 2008</li>



<li>No comments this week.</li>
<li>Review of the last week's traffic on the <a href="http://www.voipsa.org/VOIPSEC/">VOIPSEC </a>public mailing list&nbsp; </li>
<li>Wrap-up of the show </li>
<li> 43:57 - End of show&nbsp; </li></ul> <p>Comments, suggestions and feedback are welcome either as replies to this post&nbsp; or via e-mail to <a href="mailto:blueboxpodcast@gmail.com">blueboxpodcast@gmail.com</a>.&nbsp; Audio comments sent as attached MP3 files are definitely welcome and will be played in future shows.&nbsp; You may also call the listener comment line at either +1-415-830-5439 or via SIP to '<a href="sip:bluebox@voipuser.org">bluebox@voipuser.org</a>' to leave a comment there.&nbsp; </p> <p>Thank you for listening and please do let us know what you think of the show. </p></div>

<p><a href="http://feeds.feedburner.com/~a/BlueBox?a=KVZkW6"><img src="http://feeds.feedburner.com/~a/BlueBox?i=KVZkW6" border="0"></img></a></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/BlueBox?a=xlJ8KzD"><img src="http://feeds.feedburner.com/~f/BlueBox?i=xlJ8KzD" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/BlueBox?a=9ad3x1D"><img src="http://feeds.feedburner.com/~f/BlueBox?i=9ad3x1D" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/BlueBox?a=bCFmBuD"><img src="http://feeds.feedburner.com/~f/BlueBox?i=bCFmBuD" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/BlueBox?a=MjMbHMD"><img src="http://feeds.feedburner.com/~f/BlueBox?i=MjMbHMD" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/BlueBox?a=AFX6Htd"><img src="http://feeds.feedburner.com/~f/BlueBox?i=AFX6Htd" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/BlueBox?a=nuf0RmD"><img src="http://feeds.feedburner.com/~f/BlueBox?i=nuf0RmD" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/BlueBox/~4/213446795" height="1" width="1"/>]]></content:encoded>
      <pubDate>Tue, 08 Jan 2008 13:42:40 +0000</pubDate>
      <category domain="http://securityratty.com/tag/trends">trends</category>
      <category domain="http://securityratty.com/tag/vulnerabilities">vulnerabilities</category>
      <category domain="http://securityratty.com/tag/voip security trends">voip security trends</category>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/trixbox vulnerabilities">trixbox vulnerabilities</category>
      <category domain="http://securityratty.com/tag/voip vulnerabilities">voip vulnerabilities</category>
      <category domain="http://securityratty.com/tag/listener comment line">listener comment line</category>
      <category domain="http://securityratty.com/tag/comment line">comment line</category>
      <category domain="http://securityratty.com/tag/top">top</category>
      <source url="http://feeds.feedburner.com/~r/BlueBox/~3/213446795/blue-box-74-200.html">Blue Box #74: 2008 Crystal Ball Edition, Asterisk and Trixbox vulnerabilities, top 10 lists, VoIP security trends for 2008 and more....</source>
    </item>
    <item>
      <title><![CDATA[Security World: Top 5 VoIP vulnerabilities in 2007]]></title>
      <link>http://securityratty.com/article/f7cb21e8ec7fa464a1a6470729819dff</link>
      <guid>http://securityratty.com/article/f7cb21e8ec7fa464a1a6470729819dff</guid>
      <description><![CDATA[Sipera VIPER Lab revealed the Top 5 VoIP Vulnerabilities in 2007. In assembling this list, the Sipera VIPER team reviewed 2007 vendor and media reports of known vulnerabilities and estimated the...]]></description>
      <content:encoded><![CDATA[Sipera VIPER Lab revealed the Top 5 VoIP Vulnerabilities in 2007. In assembling this list, the Sipera VIPER team reviewed 2007 vendor and media reports of known vulnerabilities and estimated the impac...]]></content:encoded>
      <pubDate>Thu, 13 Dec 2007 22:50:02 +0000</pubDate>
      <category domain="http://securityratty.com/tag/vulnerabilities">vulnerabilities</category>
      <category domain="http://securityratty.com/tag/voip vulnerabilities">voip vulnerabilities</category>
      <category domain="http://securityratty.com/tag/sipera viper team">sipera viper team</category>
      <category domain="http://securityratty.com/tag/sipera viper lab">sipera viper lab</category>
      <category domain="http://securityratty.com/tag/media reports">media reports</category>
      <category domain="http://securityratty.com/tag/top">top</category>
      <category domain="http://securityratty.com/tag/impac">impac</category>
      <category domain="http://securityratty.com/tag/list">list</category>
      <category domain="http://securityratty.com/tag/vendor">vendor</category>
      <source url="http://feeds.feedburner.com/~r/HelpNetSecurity/~3/200290756/secworld.php">Security World: Top 5 VoIP vulnerabilities in 2007</source>
    </item>
    <item>
      <title><![CDATA[Blue Box #70: 2-yr Anniversary show, VoIP security vulnerabilities, Vonage, Comcast, phishing, listener comments and much, much more... ]]></title>
      <link>http://securityratty.com/article/000fe05beb7be31948ee3c35b723296d</link>
      <guid>http://securityratty.com/article/000fe05beb7be31948ee3c35b723296d</guid>
      <description><![CDATA[Synopsis: Blue Box #70: 2-yr Anniversary show, VoIP security vulnerabilities, Vonage, Comcast, phishing, listener comments and much, much more
Welcome to Blue Box: The VoIP Security Podcast #70, a...]]></description>
      <content:encoded><![CDATA[
<div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Synopsis:</strong>Blue Box #70: 2-yr Anniversary show, VoIP security vulnerabilities, Vonage, Comcast, phishing, listener comments and much, much more... 

</p><hr /><p>Welcome to <strong>Blue Box: The VoIP Security Podcast</strong> #70, a 51-minute podcast&nbsp; from Dan York and Jonathan Zar covering VoIP security news, comments and opinions.&nbsp; &nbsp; </p>

<p><a rel="enclosure" href="http://ripple.radiotail.com/409/BBP-070-2007-10-25.mp3">Download the show here</a> (MP3, 21MB) or <a href="http://feeds.feedburner.com/BlueBox">subscribe to the RSS feed</a> to download the show automatically.&nbsp; </p> 

<p>You may also listen to this podcast right now:</p> 

<p><object width="200" height="20" data="http://www.blueboxpodcast.com/dewplayer.swf?son=http://ripple.radiotail.com/409/BBP-070-2007-10-25.mp3" type="application/x-shockwave-flash"><param value="http://www.blueboxpodcast.com/dewplayer.swf?son=http://ripple.radiotail.com/409/BBP-070-2007-10-25.mp3&amp;bgcolor=#FFFFFF" name="movie" /></object> </p> 

<p><em>NOTE: This show was recorded on October 25, 2007.</em></p>
<p><strong>Show Content:</strong></p> 
 

<ul> <li>00:20 - Intro to the show, contact information and how to provide comments.&nbsp; Welcome to all the new listeners - and to all those listeners who have been here for so long!&nbsp; </li>
<li>Programming notes:</li>


	<ul>
		<li>Dan???s <a href="http://www.disruptivetelephony.com/2007/10/my-new-employer.html">new employment with Voxeo</a></li>
		<li>Dan at <span class="caps">VON</span> next week ??? Dean Elwood is doing a VoIPUser dinner ??? perhaps a Blue Box dinner as well?</li>
		<li>We hope you enjoyed <a href="http://www.blueboxpodcast.com/2007/10/blue-box-se021-.html">Blue Box <span class="caps">SE 21</span> with Phil Zimmermann</a> ??? many thanks to Martyn Davies for helping with that.</li>
		<li>Reporters for some of the spring shows?&nbsp; (we can probably get you press credentials??? if you are there)</li>
	</ul>

	<li><a href="http://voipsa.org/pipermail/voipsec_voipsa.org/2007-October/002466.html">XSS attack and <span class="caps">SQL</span> injection via <span class="caps">SIP</span> against Asterisk</a></li>
		<li>The <a href="http://voipsa.org/pipermail/voipsec_voipsa.org/2007-October/002452.html">XSS attack against Linksys <span class="caps">SPA</span>-941</a> we discussed last week was <a href="http://packetstormsecurity.org/0710-exploits/sip-pwn.txt">picked up by Secure Computing</a> which resulted in this SearchSecurity.com article: <a href="http://searchsecurity.techtarget.com/originalContent/0,289142,sid14_gci1277386,00.html?track=NL-102">New Attack Methods Target Web 2.0, VoIP</a> (last link sent to us by Rhodri Davies)</li>
		<li>Sipera released <a href="http://www.sipera.com/index.php?action=resources,threat_advisory&amp;all=Specific">a range of vulnerabilities</a> related to Vonage, Grandstream and more ??? note that the Vonage thread has been picked up by <a href="http://blogs.zdnet.com/ip-telephony/?p=2652">ZDNet???s Russell Shaw</a></li>


	<li>Wired: <a href="http://blog.wired.com/27bstroke6/2007/10/phones-arent-sa.html">Phones Aren???t Safe Either, Hackers Say</a> ??? also discussed in <a href="http://www.networkworld.com/community/node/20894">Network World</a> and Russell Shaw <a href="http://blogs.zdnet.com/ip-telephony/?p=2619">We???ve toasted so many of these (VoIP) networks???</a> and <a href="http://dtrammell.wordpress.com/2007/10/23/toorcon-9/">Dustin Trammell???s blog</a> (in the list of sessions he attended)</li>
		<li><span class="caps">SANS</span>: <a href="http://isc.sans.org/diary.html?storyid=3486&amp;rss">Vishing, Skype, and VoIP-Based Fraud</a> (sent in by Craig Bowser)</li>
		<li><span class="caps">CXO </span>Today: <a href="http://www.cxotoday.com/India/Editors_Speak/The_Phishing_Epidemic/551-83964-904.html">The Phishing Epidemic</a></li>
		<li>PCWorld.CA: <a href="http://www.pcworld.ca//news/column/b4251b280a01040800986975dc486390/pg1.htm">The eight most dangerous consumer technologies</a> (Skype and consumer VoIP are #6 on <a href="http://www.pcworld.ca/news/column/b43cf5a90a010408009869754af04cd1/pg0.htm">page 2</a> )</li>
		<li><span class="caps">TMC </span>Net: <a href="http://sip.tmcnet.com/topics/service-provider-solutions/articles/12981-voip-peering-search-a-viable-interconnect-business-model.htm">VoIP Peering in Search of a Viable Interconnect Business Model</a> (note the comments about security toward the bottom)</li>
		<li>Cisco TechWise podcasts <a href="http://www.cisco.com/en/US/netsol/ns752/networking_solutions_packages_list.html">Session Initiation Protocol and Security</a> (it???s on the page??? came out 10/18/07 )</li>
		<li>TechRepublic: <a href="http://blogs.techrepublic.com.com/hiner/?p=559">Sanity check: Will Microsoft be your next phone company?</a> (nice roundup of the MS announcements??? some of the comments are also interesting)</li>
	


	<li>Comcast</li>


	<ul>
	<li>AP: <a href="http://ap.google.com/article/ALeqM5gxRiQSVfgK4sLbVRE_X4MOlM9q0AD8SCASPG0">Comcast blocks some Internet traffic</a></li>
		<li><a href="http://www.edbrill.com/ebrill/edbrill.nsf/dx/associated-press-comcast-blocks-some-internet-traffic">Ed Brill notes the impact on Notes/Domino traffic</a></li>
		<li><a href="http://www.news.com/8301-13578_3-9800629-38.html">cnet post</a></li>
		<li>TorrentFreak: <a href="http://torrentfreak.com/comcast-throttles-bittorrent-traffic-seeding-impossible/">Comcast Throttles BitTorrent Traffic, Seeding Impossible</a></li>
		<li><span class="caps">P2P</span>Net: <a href="http://www.p2pnet.net/story/13717">Comcast impedes hi-speed file sharing</a></li>

	<li><a href="http://www.earthtimes.org/articles/show/news_press_release,204000.shtml">Carnegie Mellon???s CyLab and Nortel Combine Efforts to Research Leading Security Technologies</a></li>
		<li>SearchVoIP.au: <a href="http://www.searchvoip.com.au/papers/paper.asp?DocID=20239">Avaya white paper: VoIP Security for Dummies</a></li></ul>

<li>- Upcoming shows:<br /><ul> <br />
<li>Oct 24-25, New York, USA, <a href="http://www.interop.net/">Interop</a><br />
</li>

<li>Oct 29-Nov 1, Boston, <span class="caps">USA</span>, <a href="http://www.von.com/2007/fall_boston/">Fall 2007 <span class="caps">VON</span></a></li></ul> </li>





	<li>Comment (email) from Dan Wing about episode 69 and the potential DDoS attack</li>
		<li>Comment (email) from Raul Siles about episode 66</li>
		<li>Comment (email) from Raul Siles about <span class="caps">SANS </span>VoIP Security course</li>

<li>Two-year-anniversary:


	<ul>
	<li>Comment (audio) from Martyn Davies</li>
		<li>Comment (audio) from Dean Elwood</li>
		<li>Comment (audio) from Mike Wallace</li>
		<li>Comment (audio) from Raul Siles (with Matrix inclusion)</li>
		<li>Comment (audio) from Carsten Helmuth (cut off)</li>
		<li>Comment (email) from Scott Tanner</li>
		<li>Comment (email) from Shlomo Dubrowin</li>
	</ul>

</li>

<li>- Drawing for the book

</li>

<li>- Review of the last week's traffic on the <a href="http://www.voipsa.org/VOIPSEC/">VOIPSEC </a>public mailing list&nbsp; </li><br />
<li>- Wrap-up of the show </li><br />
<li>51:14 - End of show&nbsp; </li></ul> <p>Comments, suggestions and feedback are welcome either as replies to this post&nbsp; or via e-mail to <a href="mailto:blueboxpodcast@gmail.com">blueboxpodcast@gmail.com</a>.&nbsp; Audio comments sent as attached MP3 files are definitely welcome and will be played in future shows.&nbsp; You may also call the listener comment line at either +1-206-350-7280 or via SIP to '<a href="sip:bluebox@voipuser.org">bluebox@voipuser.org</a>' to leave a comment there.&nbsp; </p> <p>Thank you for listening and please do let us know what you think of the show. </p></div>
]]></content:encoded>
      <pubDate>Wed, 07 Nov 2007 19:52:27 +0000</pubDate>
      <category domain="http://securityratty.com/tag/voip security">voip security</category>
      <category domain="http://securityratty.com/tag/voip security vulnerabilities">voip security vulnerabilities</category>
      <category domain="http://securityratty.com/tag/voip security news">voip security news</category>
      <category domain="http://securityratty.com/tag/voip">voip</category>
      <category domain="http://securityratty.com/tag/voip security podcast">voip security podcast</category>
      <category domain="http://securityratty.com/tag/consumer voip">consumer voip</category>
      <category domain="http://securityratty.com/tag/vulnerabilities">vulnerabilities</category>
      <category domain="http://securityratty.com/tag/sans voip security">sans voip security</category>
      <category domain="http://securityratty.com/tag/sans">sans</category>
      <source url="http://www.blueboxpodcast.com/2007/11/blue-box-70-2-y.html">Blue Box #70: 2-yr Anniversary show, VoIP security vulnerabilities, Vonage, Comcast, phishing, listener comments and much, much more... </source>
    </item>
  </channel>
</rss>
