<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: trixbox]]></title>
    <link>http://securityratty.com/tag/trixbox</link>
    <description></description>
    <pubDate>Tue, 08 Jan 2008 13:42:40 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[Blue Box #74: 2008 Crystal Ball Edition, Asterisk and Trixbox vulnerabilities, top 10 lists, VoIP security trends for 2008 and more....]]></title>
      <link>http://securityratty.com/article/c0914c73b0c753bea48c9000c9d04ea9</link>
      <guid>http://securityratty.com/article/c0914c73b0c753bea48c9000c9d04ea9</guid>
      <description><![CDATA[Synopsis: Blue Box #74: 2008 Crystal Ball Edition, Asterisk and Trixbox vulnerabilities, top 10 lists, VoIP security trends for 2008 and more
Welcome to Blue Box: The VoIP Security Podcast #74, a...]]></description>
      <content:encoded><![CDATA[
<div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Synopsis:</strong> Blue Box #74: 2008 Crystal Ball Edition, Asterisk and Trixbox vulnerabilities, top 10 lists, VoIP security trends for 2008 and more....
</p><hr /><p>Welcome to <strong>Blue Box: The VoIP Security Podcast</strong> #74, a 44-minute podcast&nbsp; from Dan York and Jonathan Zar covering VoIP security news, comments and opinions.&nbsp; &nbsp; </p>

<p><a rel="enclosure" href="http://ripple.radiotail.com/409/BBP-074-2007-12-20.mp3">Download the show here</a> (MP3, 20MB) or <a href="http://feeds.feedburner.com/BlueBox">subscribe to the RSS feed</a> to download the show automatically.&nbsp; </p> 

<p>You may also listen to this podcast right now:</p> 

<p><object width="200" height="20" data="http://www.blueboxpodcast.com/dewplayer.swf?son=http://ripple.radiotail.com/409/BBP-074-2007-12-20.mp3" type="application/x-shockwave-flash"><param value="http://www.blueboxpodcast.com/dewplayer.swf?son=http://ripple.radiotail.com/409/BBP-074-2007-12-20.mp3&amp;bgcolor=#FFFFFF" name="movie" /></object> </p> 

<p><strong>Show Content:</strong></p> 
 

<ul> <li>00:20 - Intro to the show, contact information and how to provide comments.&nbsp; Welcome to all the new listeners - and to all those listeners who have been here for so long!&nbsp; </li>

<li><a href="http://www.blueboxpodcast.com/2007/12/new-audio-comme.html">new comment line +1-415-830-5439</a></li>
		<li><a href="http://www.blueboxpodcast.com/2007/12/blue-box-se022.html">SE 22 with Jonathan Rosenberg</a></li>
<li><a href="http://downloads.digium.com/pub/security/AST-2007-027.html">Asterisk <span class="caps">AST</span>-2007-027: Database matching order permits host-based authentication to be ignored</a></li>
		<li>Voice of <span class="caps">VOIPSA</span>: <a href="http://voipsa.org/blog/2007/12/17/trixbox-contains-phone-home-code-to-retrieve-arbitrary-commands-to-execute/">Trixbox contains &#8216;phone home&#8217; code to retrieve arbitrary commands to execute</a></li>
		<li><a href="http://www.trixbox.org/trixbox-ce-audit-tool-official-statement-and-fixes">trixbox CE audit tool official statement and fixes</a></li>
		<li><a href="http://www.trixbox.org/audit-tool-change-plan">Audit Tool Change Plan</a></li>
		<li><a href="http://www.trixbox.org/audit-tool-fix-being-pushed-out-tonight">Audit tool &#8216;fix&#8217; being pushed out tonight</a></li>

<li>ComputerWorld: <a href="http://www.computerworld.com/action/article.do?command=viewArticleBasic&#38;articleId=9053452&#38;source=rss_news50">VoIP vulnerabilities increasing, but not exploits</a></li>
		<li><span class="caps">CRN</span>: <a href="http://www.crn.com/networking/205100204">Top 9 VoIP Threats and Vulnerabilities</a> (Sipera PR strikes again) &#8211; points to <span class="caps">CRN</span> article: <a href="http://www.crn.com/networking/204805527">VoIP Threats, Vulnerabilities Abound</a> which is based on press release <a href="http://www.techweb.com/showPressRelease.jhtml?articleID=X661245">Sipera <span class="caps">VIPER </span>Lab Reveals Top 5 VoIP Vulnerabilities in 2007</a></li>
		<li>Voice of <span class="caps">VOIPSA</span>: <a href="http://voipsa.org/blog/2007/12/12/pointers-to-any-audit-methodology-for-forensic-analysis-of-voip-systems/">Pointers to any audi methodology for forensic analysis of VoIP systems?</a></li>
		<li><span class="caps">TMC</span>.net: <a href="http://sip.tmcnet.com/topics/sip-and-open-standards/articles/16548-sip-security-just-it-right.htm">SIP and Security: Just Do It Right!</a></li>

<li><a href="http://money.cnn.com/news/newsfeeds/articles/prnewswire/NYW006A19122007-1.htm">PAETEC, Alcatel-Lucent Deploy Industry Leading Disaster Recovery VoIP Solution</a></li>

<li>Feature:  top stories of 2007 and trends for 2008</li>



<li>No comments this week.</li>
<li>Review of the last week's traffic on the <a href="http://www.voipsa.org/VOIPSEC/">VOIPSEC </a>public mailing list&nbsp; </li>
<li>Wrap-up of the show </li>
<li> 43:57 - End of show&nbsp; </li></ul> <p>Comments, suggestions and feedback are welcome either as replies to this post&nbsp; or via e-mail to <a href="mailto:blueboxpodcast@gmail.com">blueboxpodcast@gmail.com</a>.&nbsp; Audio comments sent as attached MP3 files are definitely welcome and will be played in future shows.&nbsp; You may also call the listener comment line at either +1-415-830-5439 or via SIP to '<a href="sip:bluebox@voipuser.org">bluebox@voipuser.org</a>' to leave a comment there.&nbsp; </p> <p>Thank you for listening and please do let us know what you think of the show. </p></div>
]]></content:encoded>
      <pubDate>Tue, 08 Jan 2008 14:42:39 +0000</pubDate>
      <category domain="http://securityratty.com/tag/trends">trends</category>
      <category domain="http://securityratty.com/tag/vulnerabilities">vulnerabilities</category>
      <category domain="http://securityratty.com/tag/voip security trends">voip security trends</category>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/trixbox vulnerabilities">trixbox vulnerabilities</category>
      <category domain="http://securityratty.com/tag/voip vulnerabilities">voip vulnerabilities</category>
      <category domain="http://securityratty.com/tag/listener comment line">listener comment line</category>
      <category domain="http://securityratty.com/tag/comment line">comment line</category>
      <category domain="http://securityratty.com/tag/top">top</category>
      <source url="http://www.blueboxpodcast.com/2008/01/blue-box-74-200.html">Blue Box #74: 2008 Crystal Ball Edition, Asterisk and Trixbox vulnerabilities, top 10 lists, VoIP security trends for 2008 and more....</source>
    </item>
    <item>
      <title><![CDATA[Blue Box #74: 2008 Crystal Ball Edition, Asterisk and Trixbox vulnerabilities, top 10 lists, VoIP security trends for 2008 and more....]]></title>
      <link>http://securityratty.com/article/8076404175c339d862777d2e464a59e5</link>
      <guid>http://securityratty.com/article/8076404175c339d862777d2e464a59e5</guid>
      <description><![CDATA[Synopsis: Blue Box #74: 2008 Crystal Ball Edition, Asterisk and Trixbox vulnerabilities, top 10 lists, VoIP security trends for 2008 and more
Welcome to Blue Box: The VoIP Security Podcast #74, a...]]></description>
      <content:encoded><![CDATA[
<div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Synopsis:</strong> Blue Box #74: 2008 Crystal Ball Edition, Asterisk and Trixbox vulnerabilities, top 10 lists, VoIP security trends for 2008 and more....
</p><hr /><p>Welcome to <strong>Blue Box: The VoIP Security Podcast</strong> #74, a 44-minute podcast&nbsp; from Dan York and Jonathan Zar covering VoIP security news, comments and opinions.&nbsp; &nbsp; </p>

<p><a rel="enclosure" href="http://ripple.radiotail.com/409/BBP-074-2007-12-20.mp3">Download the show here</a> (MP3, 20MB) or <a href="http://feeds.feedburner.com/BlueBox">subscribe to the RSS feed</a> to download the show automatically.&nbsp; </p> 

<p>You may also listen to this podcast right now:</p> 

<p><object width="200" height="20" data="http://www.blueboxpodcast.com/dewplayer.swf?son=http://ripple.radiotail.com/409/BBP-074-2007-12-20.mp3" type="application/x-shockwave-flash"><param value="http://www.blueboxpodcast.com/dewplayer.swf?son=http://ripple.radiotail.com/409/BBP-074-2007-12-20.mp3&amp;bgcolor=#FFFFFF" name="movie" /></object> </p> 

<p><strong>Show Content:</strong></p> 
 

<ul> <li>00:20 - Intro to the show, contact information and how to provide comments.&nbsp; Welcome to all the new listeners - and to all those listeners who have been here for so long!&nbsp; </li>

<li><a href="http://www.blueboxpodcast.com/2007/12/new-audio-comme.html">new comment line +1-415-830-5439</a></li>
		<li><a href="http://www.blueboxpodcast.com/2007/12/blue-box-se022.html">SE 22 with Jonathan Rosenberg</a></li>
<li><a href="http://downloads.digium.com/pub/security/AST-2007-027.html">Asterisk <span class="caps">AST</span>-2007-027: Database matching order permits host-based authentication to be ignored</a></li>
		<li>Voice of <span class="caps">VOIPSA</span>: <a href="http://voipsa.org/blog/2007/12/17/trixbox-contains-phone-home-code-to-retrieve-arbitrary-commands-to-execute/">Trixbox contains &#8216;phone home&#8217; code to retrieve arbitrary commands to execute</a></li>
		<li><a href="http://www.trixbox.org/trixbox-ce-audit-tool-official-statement-and-fixes">trixbox CE audit tool official statement and fixes</a></li>
		<li><a href="http://www.trixbox.org/audit-tool-change-plan">Audit Tool Change Plan</a></li>
		<li><a href="http://www.trixbox.org/audit-tool-fix-being-pushed-out-tonight">Audit tool &#8216;fix&#8217; being pushed out tonight</a></li>

<li>ComputerWorld: <a href="http://www.computerworld.com/action/article.do?command=viewArticleBasic&#38;articleId=9053452&#38;source=rss_news50">VoIP vulnerabilities increasing, but not exploits</a></li>
		<li><span class="caps">CRN</span>: <a href="http://www.crn.com/networking/205100204">Top 9 VoIP Threats and Vulnerabilities</a> (Sipera PR strikes again) &#8211; points to <span class="caps">CRN</span> article: <a href="http://www.crn.com/networking/204805527">VoIP Threats, Vulnerabilities Abound</a> which is based on press release <a href="http://www.techweb.com/showPressRelease.jhtml?articleID=X661245">Sipera <span class="caps">VIPER </span>Lab Reveals Top 5 VoIP Vulnerabilities in 2007</a></li>
		<li>Voice of <span class="caps">VOIPSA</span>: <a href="http://voipsa.org/blog/2007/12/12/pointers-to-any-audit-methodology-for-forensic-analysis-of-voip-systems/">Pointers to any audi methodology for forensic analysis of VoIP systems?</a></li>
		<li><span class="caps">TMC</span>.net: <a href="http://sip.tmcnet.com/topics/sip-and-open-standards/articles/16548-sip-security-just-it-right.htm">SIP and Security: Just Do It Right!</a></li>

<li><a href="http://money.cnn.com/news/newsfeeds/articles/prnewswire/NYW006A19122007-1.htm">PAETEC, Alcatel-Lucent Deploy Industry Leading Disaster Recovery VoIP Solution</a></li>

<li>Feature:  top stories of 2007 and trends for 2008</li>



<li>No comments this week.</li>
<li>Review of the last week's traffic on the <a href="http://www.voipsa.org/VOIPSEC/">VOIPSEC </a>public mailing list&nbsp; </li>
<li>Wrap-up of the show </li>
<li> 43:57 - End of show&nbsp; </li></ul> <p>Comments, suggestions and feedback are welcome either as replies to this post&nbsp; or via e-mail to <a href="mailto:blueboxpodcast@gmail.com">blueboxpodcast@gmail.com</a>.&nbsp; Audio comments sent as attached MP3 files are definitely welcome and will be played in future shows.&nbsp; You may also call the listener comment line at either +1-415-830-5439 or via SIP to '<a href="sip:bluebox@voipuser.org">bluebox@voipuser.org</a>' to leave a comment there.&nbsp; </p> <p>Thank you for listening and please do let us know what you think of the show. </p></div>

<p><a href="http://feeds.feedburner.com/~a/BlueBox?a=KVZkW6"><img src="http://feeds.feedburner.com/~a/BlueBox?i=KVZkW6" border="0"></img></a></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/BlueBox?a=xlJ8KzD"><img src="http://feeds.feedburner.com/~f/BlueBox?i=xlJ8KzD" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/BlueBox?a=9ad3x1D"><img src="http://feeds.feedburner.com/~f/BlueBox?i=9ad3x1D" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/BlueBox?a=bCFmBuD"><img src="http://feeds.feedburner.com/~f/BlueBox?i=bCFmBuD" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/BlueBox?a=MjMbHMD"><img src="http://feeds.feedburner.com/~f/BlueBox?i=MjMbHMD" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/BlueBox?a=AFX6Htd"><img src="http://feeds.feedburner.com/~f/BlueBox?i=AFX6Htd" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/BlueBox?a=nuf0RmD"><img src="http://feeds.feedburner.com/~f/BlueBox?i=nuf0RmD" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/BlueBox/~4/213446795" height="1" width="1"/>]]></content:encoded>
      <pubDate>Tue, 08 Jan 2008 13:42:40 +0000</pubDate>
      <category domain="http://securityratty.com/tag/trends">trends</category>
      <category domain="http://securityratty.com/tag/vulnerabilities">vulnerabilities</category>
      <category domain="http://securityratty.com/tag/voip security trends">voip security trends</category>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/trixbox vulnerabilities">trixbox vulnerabilities</category>
      <category domain="http://securityratty.com/tag/voip vulnerabilities">voip vulnerabilities</category>
      <category domain="http://securityratty.com/tag/listener comment line">listener comment line</category>
      <category domain="http://securityratty.com/tag/comment line">comment line</category>
      <category domain="http://securityratty.com/tag/top">top</category>
      <source url="http://feeds.feedburner.com/~r/BlueBox/~3/213446795/blue-box-74-200.html">Blue Box #74: 2008 Crystal Ball Edition, Asterisk and Trixbox vulnerabilities, top 10 lists, VoIP security trends for 2008 and more....</source>
    </item>
  </channel>
</rss>
