Sjur Usken

Views on new technologies and business opportunities from Sjur Usken

Category Archives: VoIP

We demand the authority to free the free sprectrum!!


Inspired by this talk at Ecomm 2009 by Michael Calabrese. It’s time to let the intelligent wireless units utilize the available spectrum! Why allocate all the frequencies static, when you can divide them both in time, location, height (on ground, in planes..) and dynamically back-off channles in use.

If I had done the same spectrum scan in down-town Oslo, I would have found that the 900 and 1800 MHz channels for GSM and UMTS is utilized, while 2.4GHz is pretty crowded. There would also be some TV channels. But what about the rest??? Why not use it?

Demand a GPS in the senders, where they every 24 hours download what they are allowed to transmit and which frequencies. Just do something…. because the static allocation of frequencies are out of date and we need more (unlicensed) mobile bandwidth!

VoIP used for social engineering hacking


Direct VoIP attacks are escalating, but even as scary is using a hacked VoIP system to extend your social engineering in a firm. This can be done automatically by using hacked PBXes to make the call, to direct attacks towards a (larger) institution where you first hack their VoIP phone central, and then use real accounts on this system for social engineering.

More info about it from The Standard and the FTC “prank” about Vishing.

Take VoIP security more seriously!


I’m glad when people are taking VoIP security more seriously. VoIP will become an even more important service, integrated into everyday life on the Internet.

Ben in the Australian Honeynet Project is now on his third article about VoIP frauds. It is for the general audience and gives you a insight of what drives the hackers to get access to your VoIP system.

Lance Spitzner and I was interviewed for an article in the Norwegian Computerworld edition. Here I argued that it is not necessarily insecure systems with bugs, but rather configuration errors done by the administrators and installers.

Then it’s nice to see people making YuoTube videos of how to make your Asterisk more secure:

httpv://www.youtube.com/watch?v=tkHkWn8ZTXQ

[ad]

Article about the Honeynet Project


Computerworld in Norway published an article about The Honeynet Project and the Norwegian Honeynet Chapter. This is one of the main tools to learn the tools of how attackers abuse VoIP targets. Her is the Norwegian and English version.

Will SIP TLS be the solution to SIP Security?


SIP is now mostly run over UDP. This is scalable but unsecure. Microsoft uses only TCP and encrypted TLS. But TLS has its own flaws as shown by this webpage.

There are three general attacks against HTTPS discussed here, each with slightly different characteristics, all of which yield the same result: the attacker is able to execute an HTTP transaction of his choice, authenticated by a legitimate user (the victim of the MITM attack). Some attacks result in the attacker-supplied request generating a response document which is then presented to the client without any certificate warning or other indication to the user. Other techniques allow the attacker to forward or re-purpose client certificate authentication credentials.

They use HTTPS, but it could most likely also be done in SIP as well. When everybody is using SIP TLS, there will still be security issues….

More info in here.

[ad]

Patch Tuesday will take down your phonesystem…


Its a while since patch Tuesday has taken down any communication system. For those who can’t remember, Skype went down because of this. Now it is Microsoft to learn a lesson. The patch KB974571 “Vulnerabilities in CryptoAPI could allow spoofing” will actually render your Microsoft Office Communications Server useless. It will think that you will just have a demo license and then stop. Luckily it should only be to uninstall the patch and you are up and running again. Tom Keating has more on the topic.
[ad]

Stupid Chinese fraud guy trying to sell a "Vedio phone"!


There is a lot of people trying to make money illegal. Some are good at it, some are not that good. Like this guy “Tony” trying to sell “Vedio Phone”. He sent a word document with cut’n’paste pictures and spec’s from several very different SIP Video phones as a reply to my account at www.alibaba.com. There were several strange issues. The high-end phones were 1/20 of the normal price and mostly the same price.

The e-mail was first sent to Julan Wang, e-mail jiayifeng20090909@yahoo.cn, then forwarded to another e- mail fengfeng20090703@yahoo.cn and then to royyang1986@yahoo.cn where “Tony” answered.

He used a company which I found out was in the textile industry, definley not in the VoIP business.

I asked for a quote to check out what this really was, and got another word document with nice “stamp” on and I was promised free shipping (great for a fraud…!). I got tired of playing around and told him I needed more information about his business for suspicion of fraud. I never heard any more…

If you want to check up who this actually is, here is where the “performa” invoice (another great spelling!) was supposed to be paid to:

Payee : Zhihao Wang
Account NO : 495282020014901
Beneficiary Institution : BANK OF CHINA  ANHUI BRANCH
Beneficiary’s Address: NO.313 CHANGJIANG MIDDLE ROAD, HEFEI, CHINA .
SWIFT CODE : BKCHCNBJ780

Confirmed: At least four IP PBXes in Norway part of the attack


The SIP attack yesterday hit several Norwegian IP addresses, where several insecure IP PBXes were located. The attacker managed to several of these ringing the Citibank number. I have confirmed from different sources that minimum four PBXes were abused the last 24 hours. These were Cisco and Asterisk PBXes, but configured insecure. There were no abuse of security holes or similar, only totally insecure configuration.

I will recommend all IP PBX owners and VoIP Service Providers to check if it is tried calling to the Citibank number (+442075005000). The attacker has tried different prefixes in front, so search for the digits “%442075005000”.

Also check my previous blog about how to secure your VoIP equipment.
[ad]

Citibank UK number was target for a "lawnmower" telephone attack today!


Citibank is or has been under a telephone calling attack latest 12 hours. Here I will explain the attack and how it was done.

Have you seen the movie “lawnmower man”, when in the end, all phones rings in the who city? This was the aim for todays attack on Citibank in UK. The attack was simple, but probably effective when it was active. Send SIP INVITE to open SIP gateways and PBXs, who then will actually use the traditional phonesystem (POTS) to call the target. Suddenly you need DoS protection on your traditional POTS lines….

The SIP INVITE looks like this.

INVITE sip:00442075005000@x SIP/2.0
Via: SIP/2.0/UDP 217.23.7.47:58585;branch=z9hG4bKaergjerugroijrgrg
To: <sip:x>
From: <sip:217.23.7.47:58585>;tag=Zerogij34
Call-ID: 213948958-34384780214-384748@217.23.7.47
CSeq: 1 INVITE
Max-Forwards: 69
Contact: <sip:sip@217.23.7.47:58585;transport=udp>
Allow: INVITE,ACK,OPTIONS,BYE,CANCEL,NOTIFY,REFER,MESSAGE
Content-Type: application/sdp
Content-Length: 520
Session-Expires: 3600;
Allow-Events: refer..
       v=0
       o=sip 2147483647 1 IN IP4 1.1.1.1
       s=sip
       c=IN IP4 1.1.1.1
       t=0 0
       m=audio 29784 RTP/AVP 8 0 4 18 18 18 18 96 3 98
       a=rtpmap:96 telephone-event/8000
       a=sendrecva=ptime:20
       a=rtpmap:18 G729AB/8000
       a=rtpmap:18 G729B/8000
       a=rtpmap:18 G729A/8000
       a=rtpmap:18 G729/8000
       a=rtpmap:4 G723

Lets walk through the SIP packet and see what info we can get from it:

A quick google search on the tag: Zerogij34  reveals that this attack has been around since at least 6th of August.

The IP (217.23.7.47)from this packet should be located in Portugal but the other attacks originate from both UK and Netherlands.
There is no User-Agent listed, so the packet is very likely crafted from tools like sipsak or sipp.
The codec list seems real, but they use an obscure address (1.1.1.1) for the RTP. If they would use their own IP address, it could case a small DoS with RTP traffic for every successful call. The port 29784 is within the range of Cisco units (26 000-32 000)

The other INVITES reveals that the attacker is trying to figure the extension to get a dial-tone:

  • INVITE sip:00442075005000@67.170.104.216 SIP/2.0
  • INVITE sip:011442075005000@67.170.104.216 SIP/2.0
  • INVITE sip:0442075005000@67.170.104.216 SIP/2.0
  • INVITE sip:0000442075005000@67.170.104.216 SIP/2.0
  • INVITE sip:0011442075005000@67.170.104.216 SIP/2.0
  • INVITE sip:900442075005000@67.170.104.216 SIP/2.0
  • INVITE sip:9011442075005000@67.170.104.216 SIP/2.0
  • INVITE sip:90442075005000@67.170.104.216 SIP/2.0
  • INVITE sip:442075005000@67.170.104.216 SIP/2.0
  • and several more…

But is this a DoS attack on Citibank? I doubt it. Why call the Citibank on a Sunday 5 a.m.? This is more likely that Citibank has lots of lines and therefore the SIP INVITES does not generate an error (busy or others). The attacker does not hear any ringtone, but he/she should see the 180 Ringing / 180 Session in Progress. Then he or she knows that he could actually get through to the PSTN on this SIP proxy. If it would be a ringing attack, why does the attacker just send one single SIP INVITE through each gateway that actually calls this destination?

The machines with the attacking IP addresses should be put under surveillance to see who connects to these. They are probably just some bots in a larger network, but they need to relay back which gateways actually responded successfully.

Sad to say, but I believe this is only the small beginning….
[ad]

Copy everything…. the Planet UMG-2000 and Cisco UC500


I’m a gadget person and I like cool technologies. I get a lot of e-mails with new products and I let my mind spin around this product how it can be used the best way and in which situations.

I do notice that there is a lot of copy products. All from an iPhone with dual SIM and a lot of other features not on the regular one, to one special that caught my eye, the Planet Unified Office Gateway (which IMHO is a UC500 copy…)

Some background:
Cisco is trying to capture the SMB market (In US it is probably just called the Small Business Market) with their Cisco Unified Communications 500 series. This product has everything in one unit and can be quite complex to sell and install, but gives the buyer (the business) most services in one unit.

Planet has then launced their own version of this “all-in-a-box” solution with their UMG-2000. It has a lot of the same features as well, but I haven’t seen the interface for admin or what firmware it is running on. But as in most cases, you get what you pay for. Wish both Planet and Cisco good luck!

Design a site like this with WordPress.com
Get started