<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>usken.no - VoIP news! &#187; Uncategorized</title>
	<atom:link href="http://www.usken.no/category/uncategorized/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.usken.no</link>
	<description>VoIP news for VoIP people!</description>
	<lastBuildDate>Mon, 06 Sep 2010 10:34:20 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.1</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Another VoIP hacking in Norway</title>
		<link>http://www.usken.no/2010/07/another-voip-hacking-in-norway/</link>
		<comments>http://www.usken.no/2010/07/another-voip-hacking-in-norway/#comments</comments>
		<pubDate>Wed, 28 Jul 2010 08:46:09 +0000</pubDate>
		<dc:creator>sjur</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[abuse]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[VoIP]]></category>

		<guid isPermaLink="false">http://www.usken.no/?p=359</guid>
		<description><![CDATA[The latest month of scanning has seemed valuable for the hackers. A Norwegian municipality has been hacked and their PBX has been calling Somalia and a lot of others destinations we have picked up on our VoIP honeypots during the last month.
If you have an unsecure IP PBX on the net, now it will only [...]]]></description>
			<content:encoded><![CDATA[<p>The latest month of scanning has seemed valuable for the hackers. A Norwegian municipality has been hacked and their PBX has been calling Somalia and a lot of others destinations we have picked up on our VoIP honeypots during the last month.</p>
<p>If you have an unsecure IP PBX on the net, now it will only take hours before it will be detected. Most normal cause for this is misconfiguration. The people setting up the IP PBX has not taken security seriously and the IP PBX is wide open for calling.</p>
<p>The simplest ways is that inbound calls is routed out again if no local destination is found.  A little harder is to just brute-force the password on extensions. I can only say, there will be more like this!</p>
<p><a href="http://www.nettavisen.no/it/article2952472.ece">Norwegian version</a></p>
<p><a href="http://translate.google.com/translate?js=y&amp;prev=_t&amp;hl=no&amp;ie=UTF-8&amp;layout=1&amp;eotf=1&amp;u=http%3A%2F%2Fwww.nettavisen.no%2Fit%2Farticle2952472.ece&amp;sl=no&amp;tl=en" target="_blank">English version</a></p>
<p>The hacker can sell this &#8220;gateway&#8221; to a third party dealing with calling cards. I have investigated frauds in Norway where they managed to send 1,2 million NOK (approx 200 000 USD) within 10 days. This was a Cisco installation, but misconfigured Asterisk installations are also abused a lot.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.usken.no/2010/07/another-voip-hacking-in-norway/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Using botnets to do SIP scanning</title>
		<link>http://www.usken.no/2010/07/using-botnets-to-do-sip-scanning/</link>
		<comments>http://www.usken.no/2010/07/using-botnets-to-do-sip-scanning/#comments</comments>
		<pubDate>Sun, 11 Jul 2010 10:40:53 +0000</pubDate>
		<dc:creator>sjur</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[scanning]]></category>
		<category><![CDATA[sipvicous]]></category>
		<category><![CDATA[VoIP]]></category>

		<guid isPermaLink="false">http://www.usken.no/?p=356</guid>
		<description><![CDATA[The lastest week there has been a tremendous SIP scanning from IPs all over the world latest week. The scannings are coming from a lot of IPs but the same signature, so it is probably only one person/firm behind this.
The scanning is this:
OPTIONS sip:100@X.X.X.X SIP/2.0
Via: SIP/2.0/UDP 192.168.1.9:5060;branch=
z9hG4bK-31055767;rport
Content-Length: 0
From: &#8220;sipsscuser&#8221;&#60;sip:100@192.168.1.9&#62;;  tag=01669016334862887007103185718785156498385702949
Accept: application/sdp
User-Agent: sundayddr
To: &#8220;sipssc&#8221;&#60;sip:100@192.168.1.9&#62;
Contact: sip:100@192.168.1.9:5060
CSeq: [...]]]></description>
			<content:encoded><![CDATA[<p>The lastest week there has been a tremendous SIP scanning from IPs all over the world latest week. The scannings are coming from a lot of IPs but the same signature, so it is probably only one person/firm behind this.</p>
<p>The scanning is this:</p>
<blockquote><p>OPTIONS sip:100@X.X.X.X SIP/2.0<br />
Via: SIP/2.0/UDP 192.168.1.9:5060;branch=</p>
<div id=":xl">z9hG4bK-31055767;rport<br />
Content-Length: 0<br />
From: &#8220;sipsscuser&#8221;&lt;sip:100@192.168.1.9&gt;;  tag=01669016334862887007103185718785156498385702949</p>
<div>Accept: application/sdp<br />
User-Agent: sundayddr<br />
To: &#8220;sipssc&#8221;&lt;sip:100@192.168.1.9&gt;<br />
Contact: sip:100@192.168.1.9:5060<br />
CSeq: 1 OPTIONS</div>
</div>
<div id=":xl">Call-ID: 022827170099429274868738305<br />
Max-Forwards: 70</div>
<div></div>
</blockquote>
<div>The lay-out of the OPTIONS messages is the same as in <a href="http://blog.sipvicious.org/" target="_blank">SIPVicious </a>scannings, so the author has taken this python code and just changed the User-Agent.</div>
<div></div>
<div>And this is just the beginning&#8230;.</div>
]]></content:encoded>
			<wfw:commentRss>http://www.usken.no/2010/07/using-botnets-to-do-sip-scanning/feed/</wfw:commentRss>
		<slash:comments>6</slash:comments>
		</item>
		<item>
		<title>Test your VoIP skills!</title>
		<link>http://www.usken.no/2010/06/test-your-voip-skills/</link>
		<comments>http://www.usken.no/2010/06/test-your-voip-skills/#comments</comments>
		<pubDate>Tue, 01 Jun 2010 08:09:22 +0000</pubDate>
		<dc:creator>sjur</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://www.usken.no/?p=350</guid>
		<description><![CDATA[The Honeynet project released VoIP challenge of the month. ]]></description>
			<content:encoded><![CDATA[<p>The Honeynet Project has released a real VoIP attack challenge! It is real data and YOU must find out how the hacker does the attack! Are you up for it? You will learn more about VoIP and get an understanding of the current VoIP attack methods! Go for <a href="https://honeynet.org/challenges/2010_4_voip" target="_blank">it here</a>! Deadline in 3 weeks!</p>
<p>The Chinese speaking members of the Honeynet Project has translated it even to simplified Chinese! Have fun and learn a lot!</p>
]]></content:encoded>
			<wfw:commentRss>http://www.usken.no/2010/06/test-your-voip-skills/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Extreme SIP scanning latest week</title>
		<link>http://www.usken.no/2010/04/extreme-sip-scanning-latest-week/</link>
		<comments>http://www.usken.no/2010/04/extreme-sip-scanning-latest-week/#comments</comments>
		<pubDate>Wed, 14 Apr 2010 16:17:37 +0000</pubDate>
		<dc:creator>sjur</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[amazon]]></category>
		<category><![CDATA[attack]]></category>
		<category><![CDATA[ec2]]></category>
		<category><![CDATA[VoIP]]></category>

		<guid isPermaLink="false">http://www.usken.no/?p=347</guid>
		<description><![CDATA[There have never been so many SIP scannings in so short time for all my VoIP honeypots.They have tried all types, INVITES, REGISTER, SUBSCRIBES and OPTIONS.  A short list of some of the attackes latest 48 hours. Normally just doing a couple hundred extensions and passwords, some of these IPs trying up to 10 000 [...]]]></description>
			<content:encoded><![CDATA[<p>There have never been so many SIP scannings in so short time for all my VoIP honeypots.They have tried all types, INVITES, REGISTER, SUBSCRIBES and OPTIONS.  A short list of some of the attackes latest 48 hours. Normally just doing a couple hundred extensions and passwords, some of these IPs trying up to 10 000 different extensions/passwords.</p>
<p>IP addresses [User-agent] Provider</p>
<p>119.147.116.157    [Asterisk]<br />
193.47.153.14         [SIPVicious]<br />
86.47.46.147          [First SIPVicious, then SIPPER for PhonerLite]<br />
174.143.245.120  [SIPVicious]<br />
174.129.52.240    [SIPVicious]     Amazone EC2<br />
24.190.38.4            [SIPVicious]</p>
<p>So keep your systems ready for the flood to come! This is just the start.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.usken.no/2010/04/extreme-sip-scanning-latest-week/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>A great challenge awaits you!</title>
		<link>http://www.usken.no/2010/01/a-great-challenge-awaits-you/</link>
		<comments>http://www.usken.no/2010/01/a-great-challenge-awaits-you/#comments</comments>
		<pubDate>Mon, 18 Jan 2010 07:40:18 +0000</pubDate>
		<dc:creator>sjur</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[challenge]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[honeynet]]></category>
		<category><![CDATA[sotm]]></category>

		<guid isPermaLink="false">http://www.usken.no/?p=323</guid>
		<description><![CDATA[Slightly interested in security?
Do you want to learn more about investigating attacks?
Here is your challenge!
The Honeynet Project has released this years first Scan of the Month challenge! It has many levels and now you can test if you are up to it!



]]></description>
			<content:encoded><![CDATA[<p>Slightly interested in security?</p>
<p>Do you want to learn more about investigating attacks?</p>
<p><a href="https://honeynet.org/node/504">Here </a>is your challenge!</p>
<p><a href="http://www.honeynet.org">The Honeynet Project</a> has released this years first <a href="https://honeynet.org/node/504">Scan of the Mont</a>h challenge! It has many levels and now you can test if you are up to it!</p>
<p><script type="text/javascript"><!--
google_ad_client = "pub-1177893919351833";
google_ad_slot = "0971638747";
google_ad_width = 468;
google_ad_height = 60;
//--></script>
<script type="text/javascript" src="http://pagead2.googlesyndication.com/pagead/show_ads.js"></script>
</p>
]]></content:encoded>
			<wfw:commentRss>http://www.usken.no/2010/01/a-great-challenge-awaits-you/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Article about the Honeynet Project</title>
		<link>http://www.usken.no/2009/11/article-about-the-honeynet-project/</link>
		<comments>http://www.usken.no/2009/11/article-about-the-honeynet-project/#comments</comments>
		<pubDate>Tue, 24 Nov 2009 09:28:23 +0000</pubDate>
		<dc:creator>sjur</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[VoIP]]></category>
		<category><![CDATA[honeynet]]></category>

		<guid isPermaLink="false">http://www.usken.no/?p=266</guid>
		<description><![CDATA[Computerworld in Norway published an article about The Honeynet Project and the Norwegian Honeynet Chapter. This is one of the main tools to learn the tools of how attackers abuse VoIP targets. Her is the Norwegian and English version.
]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.idg.no/computerworld/tema/sikkerhet/article151029.ece">Computerworld</a> in Norway published an article about <a href="http://www.honeynet.org">The Honeynet Project</a> and the <a href="http://www.honeynor.no">Norwegian Honeynet Chapter</a>. This is one of the main tools to learn the tools of how attackers abuse VoIP targets. Her is the <a href="http://www.idg.no/computerworld/tema/sikkerhet/article151029.ece" target="_blank">Norwegian</a> and <a href="http://translate.google.com/translate?hl=en&amp;sl=no&amp;tl=en&amp;u=http%3A%2F%2Fwww.idg.no%2Fcomputerworld%2Ftema%2Fsikkerhet%2Farticle151029.ece" target="_blank">English</a> version.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.usken.no/2009/11/article-about-the-honeynet-project/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Another day, another (VoIP) fraud&#8230;</title>
		<link>http://www.usken.no/2009/10/another-day-another-voip-fraud/</link>
		<comments>http://www.usken.no/2009/10/another-day-another-voip-fraud/#comments</comments>
		<pubDate>Wed, 21 Oct 2009 17:32:35 +0000</pubDate>
		<dc:creator>sjur</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://www.usken.no/?p=260</guid>
		<description><![CDATA[What the heck is the customers Asterisk calling Guatemala about quarter to five in the morning? 1000 calls to Guatemala, but very few actually went through or had any long duration. This was around 11 o&#8217;clock in the evening for Guatemala. What was the purpose of this abuse?
It would have been nice to have a [...]]]></description>
			<content:encoded><![CDATA[<p>What the heck is the customers <a href="http://www.asterisk.org">Asterisk</a> calling Guatemala about quarter to five in the morning? 1000 calls to Guatemala, but very few actually went through or had any long duration. This was around 11 o&#8217;clock in the evening for Guatemala. What was the purpose of this abuse?</p>
<p>It would have been nice to have a tap into this unsecure <a href="http://www.asterisk.or">Asterisk</a> and listen in on the abuse calls. Was this open PBX sold as a gateway to a cash calling card company, or was it used to just free calling for the hacker itself? Ideas and comments are appreciated!</p>
<p><script type="text/javascript"><!--
google_ad_client = "pub-1177893919351833";
google_ad_slot = "0971638747";
google_ad_width = 468;
google_ad_height = 60;
//--></script>
<script type="text/javascript" src="http://pagead2.googlesyndication.com/pagead/show_ads.js"></script>
</p>
]]></content:encoded>
			<wfw:commentRss>http://www.usken.no/2009/10/another-day-another-voip-fraud/feed/</wfw:commentRss>
		<slash:comments>11</slash:comments>
		</item>
		<item>
		<title>Embarrasing with the Norwegian Police website&#8230;</title>
		<link>http://www.usken.no/2009/09/embarrasing-with-the-norwegian-police-website/</link>
		<comments>http://www.usken.no/2009/09/embarrasing-with-the-norwegian-police-website/#comments</comments>
		<pubDate>Tue, 01 Sep 2009 15:00:34 +0000</pubDate>
		<dc:creator>sjur</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://www.usken.no/?p=215</guid>
		<description><![CDATA[The Norwegian Police are limping after web 2.0 and finally made a website where you can report a crime (only if your wallet, bicycle or mobile phone is stolen). The only stupid thing is that it results in an e-mail sent to another system. But hey, they promise to send a letter in your (snail) [...]]]></description>
			<content:encoded><![CDATA[<p>The Norwegian Police are limping after web 2.0 and finally made a website where you can report a crime (only if your wallet, bicycle or mobile phone is stolen). The only stupid thing is that it results in an e-mail sent to another system. But hey, they promise to send a letter in your (snail) mail within 14 days after the report. Great promise when you know only 3% of bicycle thefts are solved.</p>
<p>I think it is great that the police are trying to make it easier for you and me. The only problem is when they also make it easy for the bad guys. The Norwegian police is using the URL to point to graphics and then it is open for you and me to write whatever we want ourselves&#8230; great&#8230; no wonder this hits the front page on the largest tabloid <a href="http://www.vg.no/teknologi/artikkel.php?artid=578201" target="_blank">newspaper</a> (Link in Norwegian).</p>
]]></content:encoded>
			<wfw:commentRss>http://www.usken.no/2009/09/embarrasing-with-the-norwegian-police-website/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>The Linux Media Center Solution! Awesome!</title>
		<link>http://www.usken.no/2009/05/the-linux-media-center-solution-awesome/</link>
		<comments>http://www.usken.no/2009/05/the-linux-media-center-solution-awesome/#comments</comments>
		<pubDate>Sun, 10 May 2009 15:05:18 +0000</pubDate>
		<dc:creator>sjur</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://www.usken.no/?p=205</guid>
		<description><![CDATA[Browsed through the Internet for the Freedom Fone Project and came over the LinuxMCE. I have been dreaming about a project like this, and was really amazed about the possibilities included already.
They have done a smart thing dividing it up in two parts;

 one powerful core server for doing encoding of incoming media
one or more [...]]]></description>
			<content:encoded><![CDATA[<p>Browsed through the Internet for the Freedom Fone Project and came over the <a href="http://www.linuxmce.org" target="_blank">LinuxMCE</a>. I have been dreaming about a project like this, and was really amazed about the possibilities included already.<br />
They have done a smart thing dividing it up in two parts;</p>
<ul>
<li> one powerful core server for doing encoding of incoming media</li>
<li>one or more clients connected to each screen around in the house.</li>
</ul>
<p>Some of the features:</p>
<ul>
<li>Surveillance camera</li>
<li>Intrusion alarm</li>
<li>Heat/Cooling control</li>
<li>Lightning control</li>
<li>Full media center functionality</li>
<li>Telephone central</li>
</ul>
<p>All these features are knit together into a nice user interface where you only need a remote with three (3) buttons  (+ OK and cancel) to operate. And it&#8217;s even cooler with a gyro remote control (anyone played with the Nintendo wii??)</p>
<p>What I&#8217;m missing for my immediate use:</p>
<ul>
<li>heat control for radiators (a small motor to turn the knob..)</li>
<li>interface to my proprietary doorphone. (can probably be done with a Cisco/Linksys SPA3100 ATA)</li>
</ul>
<p>I have already e-mailed several of my friends who are looking for this and will definely spread the word!</p>
<p>When it is also running on the <a href="http://no.asus.com/products.aspx?l1=24&amp;l2=169&amp;l3=0&amp;l4=0&amp;model=2290&amp;modelmenu=1" target="_blank">Asus EEE Top</a> (15,6&#8243; touch screen and can do full HD video) it will be great! Or the even better <a href="http://www.msi.com/index.php?func=prodpage2&amp;maincat_no=654&amp;cat2_no=666" target="_blank">MSI Wind Top EA 1900</a> (who makes these names by the way&#8230;)</p>
<p>Keep up the good work! The future will be fantastic!<br />
<script type="text/javascript"><!--
google_ad_client = "pub-1177893919351833";
google_ad_slot = "0971638747";
google_ad_width = 468;
google_ad_height = 60;
//--></script>
<script type="text/javascript" src="http://pagead2.googlesyndication.com/pagead/show_ads.js"></script>
</p>
]]></content:encoded>
			<wfw:commentRss>http://www.usken.no/2009/05/the-linux-media-center-solution-awesome/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>The Freedom Fone Project for Africa!</title>
		<link>http://www.usken.no/2009/05/the-freedom-fone-project-for-africa/</link>
		<comments>http://www.usken.no/2009/05/the-freedom-fone-project-for-africa/#comments</comments>
		<pubDate>Sun, 10 May 2009 11:26:55 +0000</pubDate>
		<dc:creator>sjur</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://www.usken.no/?p=202</guid>
		<description><![CDATA[There are not much publicity about this project, so I wanted to explain what it&#8217;s all about.The ultimate goal is to make it easy to spread information e.g. people send a SMS and get a call informing them about HIV/AIDS or the weather.
The Freedom Fone is a universal media conveyor, it should take most media [...]]]></description>
			<content:encoded><![CDATA[<p>There are not much publicity about this project, so I wanted to explain what it&#8217;s all about.The ultimate goal is to make it easy to spread information e.g. people send a SMS and get a call informing them about HIV/AIDS or the weather.</p>
<p>The Freedom Fone is a universal media conveyor, it should take most media input from people (mobile, skype, web, e-mail) and generate output (sms, call, radio, web) in the best possible way.</p>
<p>The limitations are the usual one in Africa. No power, little or no Internet connection, few people to run it, harsh environmental conditions, etc&#8230;</p>
<p>Our solution seems easy, but there is some work behind it. Take a standard netbook (asus preferred) and plug in a USB to cellphone (mobigater). Install Ubuntu with Freeswitch and several other tools. Glue it all together with a lot of customization, and BINGO! We have a Freedom Fone Server!</p>
<p><strong>Usage scenarios</strong></p>
<p>An organization wants to spread information about specific topics. We create a SMS word people can send to be called back and informed.</p>
<p>Farmers want to know about the weather and subscribes on a daily or weekly weather forecast.</p>
<p>Ex.pats living abroad wants to help out and makes an informative radio program. This is aired on the local radio station</p>
<p>Others? Please comment!<br />
<script type="text/javascript"><!--
google_ad_client = "pub-1177893919351833";
google_ad_slot = "0971638747";
google_ad_width = 468;
google_ad_height = 60;
//--></script>
<script type="text/javascript" src="http://pagead2.googlesyndication.com/pagead/show_ads.js"></script>
</p>
]]></content:encoded>
			<wfw:commentRss>http://www.usken.no/2009/05/the-freedom-fone-project-for-africa/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
