<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>usken.no - VoIP news! &#187; asterisk</title>
	<atom:link href="http://www.usken.no/tag/asterisk/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.usken.no</link>
	<description>VoIP news for VoIP people!</description>
	<lastBuildDate>Mon, 06 Sep 2010 10:34:20 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.1</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Asterisk vulnerabilites can be abused</title>
		<link>http://www.usken.no/2008/12/asterisk-vulnerabilites-can-be-abused/</link>
		<comments>http://www.usken.no/2008/12/asterisk-vulnerabilites-can-be-abused/#comments</comments>
		<pubDate>Sat, 06 Dec 2008 12:39:40 +0000</pubDate>
		<dc:creator>sjur</dc:creator>
				<category><![CDATA[VoIP]]></category>
		<category><![CDATA[asterisk]]></category>
		<category><![CDATA[fbi]]></category>
		<category><![CDATA[fraud]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://www.usken.no/?p=117</guid>
		<description><![CDATA[I remember in the old times when Cisco was running the Call Manager on a Windows 2000 system. The Call Manager servers were always six months behind with patches and updates, and had to be protected at all costs. Caution has to be taken as always when enabling new services, and especially when it can [...]]]></description>
			<content:encoded><![CDATA[<p>I remember in the old times when <a href="www.cisco.com">Cisco</a> was running the Call Manager on a Windows 2000 system. The Call Manager servers were always six months behind with patches and updates, and had to be protected at all costs. Caution has to be taken as always when enabling new services, and especially when it can hurt financially. PC World reports that &#8220;yes, you can abuse Asterisk with a bug for a time ago&#8221; in this <a href="http://www.pcworld.com/businesscenter/article/155074/fbi_criminals_autodialing_with_hacked_voip_systems.html">article. </a> They sited the <a href="http://www.ic3.gov">IC3s</a> <a href="http://www.ic3.gov/media/2008/081205-2.aspx">article</a> about VoIP fraud.</p>
<p>Do we need another firewall for all new services? There are several Media specialized firewalls, often called <a href="http://en.wikipedia.org/wiki/Session_border_controller">Session Border Controller</a> that does this, but is this the way to do it? Probably not. IMHO it is to have a good security audit and overview of your own infrastructure, take control! Don&#8217;t buy yourself out of the current biggest threats, there will be new! Take control with <a href="http://en.wikipedia.org/wiki/Intrusion_detection_system">IDS</a> and even <a href="http://en.wikipedia.org/wiki/Intrusion-prevention_system">IPS,</a> and have backup plans in case serious bugs and flaws makes your services vulnerable!</p>
<p>And good there is several other people talking about security, like <a href="http://voipsecurityblog.typepad.com/">Mark Collier</a> and the folks behind the <a href="http://www.blueboxpodcast.com/">bluebox security podcast!</a> Good job!</p>
<p><script type="text/javascript"><!--
google_ad_client = "pub-1177893919351833";
google_ad_slot = "0971638747";
google_ad_width = 468;
google_ad_height = 60;
//--></script>
<script type="text/javascript" src="http://pagead2.googlesyndication.com/pagead/show_ads.js"></script>
</p>
]]></content:encoded>
			<wfw:commentRss>http://www.usken.no/2008/12/asterisk-vulnerabilites-can-be-abused/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
