Sjur Usken

Views on new technologies and business opportunities from Sjur Usken

Category Archives: VoIP

The new Fritz!box 7270


I was lucky and getting my hands on the newest router from AVM, the Fritz!Box Fon WLAN 7270 (puuuhh, easy name).

When I first heard about the Fritz!Box, the exceptional thing was the ISDN interface. I’m living in Norway, and ISDN has been a great success here since the incumbent waited with DSL investments until most of us had gotten ISDN to dial-up the Internet.

The Fritz!Box has added up on it’s cool features, mentioning, ISDN (capable of either TE or NT mode), 2 analog ports, one analog port to connect to a phone line, DECT, USB 2.0 and WLAN (802.11 a/b/g/n (!!!)) running on its respective 2,4 and 5Ghz. No wonder AVM is starting to call it a “home server”!

I’m starting with the most important, VoIP. It is capable of three concurrent calls either direction and with several technologies. You can connect up to 8 ISDN phones in the ISDN port, several phones in both the analogue ports, and associate up to 6 DECT phones to the internal DECT base statin. But remember, only three calls at the same time, whatever technology used.

The Fritz!Box has built-in answering machine, built-in soft fax which sends the fax as a PDF in your e-mail. It lets you get rid of that fax machine and paper, thank you!

On the IP interfaces, It has ADSL2+, four (4) 10/100Mbit ports (why not 1000Mbit???). If you have cable modem or fiber connection, you can use the LAN1 port for Internet access instead of the built-in ADSL2+ port. It supports all protocols (like PPPoE, PPPoA, RFC1483 and more) needed for connecting up to an ISP.

What I really fancy, is the daily reports telling me how good my calls has been.

Internet Telephony Voice Transmission
This table shows detailed information about voice transmission during Internet telephony.
Duration (*) Remote Site Coding Packets (**) Lost Delay Jitter Burst Other
0:19 (300 ms) >| G.711 54921 (-) 0.0 % 14 ms 0 ms (0 %)

The web interface is even better. It has some really good and informative overviews of the different technologies. Here is the DECT overview:

Monitor the DECT system in the Fritz unit

Monitor the DECT system in the Fritz unit

The Fritz!box has a USB 2.0 USB host port. Just plug a USB harddrive into it, and you are ready. Set a (good!) password on the share and you can access it as an FTP server from all over the Internet. AVM had also added a new Samba Server feature, [delete – with a small program installed,] so you have direct access to the USB port as a network share from all of your PCs. This is excellent for a small firm that needs to share a scanner or printer.

All in all, the Fritz!box is full of technologies, enabling it to fit most of an advance home or a small firm!
I love it!
[ad]

Asterisk vulnerabilites can be abused


I remember in the old times when Cisco was running the Call Manager on a Windows 2000 system. The Call Manager servers were always six months behind with patches and updates, and had to be protected at all costs. Caution has to be taken as always when enabling new services, and especially when it can hurt financially. PC World reports that “yes, you can abuse Asterisk with a bug for a time ago” in this article. They sited the IC3s article about VoIP fraud.

Do we need another firewall for all new services? There are several Media specialized firewalls, often called Session Border Controller that does this, but is this the way to do it? Probably not. IMHO it is to have a good security audit and overview of your own infrastructure, take control! Don’t buy yourself out of the current biggest threats, there will be new! Take control with IDS and even IPS, and have backup plans in case serious bugs and flaws makes your services vulnerable!

And good there is several other people talking about security, like Mark Collier and the folks behind the bluebox security podcast! Good job!

[ad]

VoIP system abused in an English bank service company…


I’ve had several responses to my previous article about VoIP attacks, and people are approaching the Honeynet organisation for help to figure out what they to do after being abused. This is both good and bad. Good that they seek help, bad that they do not have a IT security plan.

IT hacking costs money, and when implementing mis configured VoIP it shows up on the telephony bill as well. Previously it was costs that were not that obvious, down-time for the firm, stolen documents used against them in business competitions or just abuse of their Internet bandwidth to hurt others. How would the world been if all the security faults a firm had would show up on their monthly Internet bill? “Your computers have been participating in a DDoS attacking costing a firm 5 million, this is your cost”

The companies need to take security more serious. It is a war going on on the Internet where the strongest one will survive. And the war has begun for a long time ago…
[ad]

VoIP attacks are escalating


There has been numerous VoIP attacks from very different sources the latest months. In this article we will go through attacks towards two different companies in Norway. I will explain how they did it and how you can protect yourself against it.

Who was the attackers?

The attackers IP adresses:

  • 124.217.230.238
  • 124.217.230.225
  • 213.130.74.70
  • 213.130.74.72

The first two IP adresses belongs to “Piradius” network in Malaysia.

The second two IP addresses belongs to a VoIP company in Bulgaria, www.iconnectbg.net. These people has not been successful with their actions, but they had about 1000 SIP INVITES while trying to get through.

There was also some port scannings on port 5060 from an American IP, so we contacted the firm and it was most likely a break-in on the local servers.

The attackers business models

There seems to have been to way to make money. One way was to directly use it as an outbound gateway. This is quite risky since you have an existing business to protect.

The other way was to sell these minutes to another provider. One company specializing in discovering and making the gateway ready, then selling this access to prepaid phone card providers.

There are several others, like calling expensive numbers in other countries and then charging the terminating fees.

How did they find the VoIP gateways

The Piradius network (or the people hiring place in this network) did their port scanning from 124.217.252.238. First they search just for open ports, port 5060 (UDP and TCP!) and 1720 (h323). If you have a Cisco PSTN gateway, remember that the Cisco gateways can do both SIP UDP/TCP and H323. The first machine tried all different numbers similar to this.525551690000.

Example:

  • 00525551690000
  • 000=23525551690000
  • 00100525551690000

They tried a lot of different variations of this, and after a while they went over to a brute force way, just counting their way upwards

  • 26100525551690000
  • 26200525551690000
  • 26300525551690000
  • 26400525551690000

The always used caller ID 5199362832664 on all calls. They probably had an Asterisk on the other phone number, noticing when it rang and which gateway that then had been used.

What was configured wrong?

One of the customers with an Asterisk had included the “outbound” context to the SIP provider within the reach for the inbound context. Calls coming in and there were no matching numbers internally was routed out to the SIP provider. This is such a bad idea…

Another customer had a Cisco gateway. Cisco gateways just routes VoIP traffic the same as IP based on the dial-peers. It was configured properly with dial-peers but not with the correct access lists. The Cisco just needs 1 dial-peer configured to bounce traffic like this.

The motives

These two attacks were directed to get free calling. The calls were going to expensive countries like Cuba and Jamaica. There has been no directly breach on the system with username/passwords to gain access and get information. The objectives were to send free telephony traffic through the unsecured PBXs.

How to protect your VoIP equipment

  • Always have a firewall or session border controller (SBC is just a specialized VoIP firewall) between you and the Internet.
  • Limit your access to your VoIP servers from the rest of the world
  • Do not let inbound contexts in Asterisk have access to outbound.
  • Be careful with dial-in features and get a new dial-tone based on a password.
  • Update the software regularly.
  • Use VPN tunnels to protect the VoIP traffic going over the Internet
  • Use SIP TLS and SRTP if possible (we are waiting on hardware manufacturers here as well)
  • Shutdown all services on equipment that is not in use. Example H323 on a Cisco gateway used only for SIP

[ad]

VoIP News


[ad]

LinksysONE


My company just aquired a company with a Linksys ONE platform. I have gotten the pleasure to learn the whole platform in just a few days, and it is very elegant.

It is more of a provisioning platform than switching, but interesting! It also embraces Cisco‘s Unified Communiction 500 products with very easy setup.

It saves money for companies having a solution that is fully remote configured. It was about 20 000 lightning yesterday in Oslo and one of the customers on this platform got their LinksysONE router broken. It was a call-centre, so quite urgent to get it running again. We sent a new unit with a courier and they installed it themselves. We had several backups from the last week and one of those was loaded on to it.

The clue is to make “one-stop-shop” for your telephony needs, and make it EASY! My assumption was that the old PBX vendors kept the interface as cryptic as possible, so their agents could make money configure these proprietary units. Even just to move a phone would result at least in an hour or two of work.

VoIP companies will not win on the call cost, but on the total cost of ownership (TCO) and features! When companies realizes this, they will demand VoIP systems!

[ad]

[ad#midtbanner]

The quarterly VoIP vulnerability list


The VoIPSA blog released a quarterly overview of VoIP vulnerabilites for Q1 2008. Yes, it is a little old at the moment, but still interesting. The Cisco phones are on top when it comes to number of vulnerabilities. It is slightly more scary that a VoIP expert, InGate, also has errors on their equipment. It was an easy to exploit Denial-of-Service(DoS) bug, critical for those relying on InGate to protect them from DoS attacks.
[ad]

Review of Polycom 6000 and 7000 conference phones


Just had two phones landing on my desk, the new conference phones from Polycom. The Polycom 7000 looks great and stylish, but the 6000 is rather dull. Both have the same great codecs, so there should not be a big difference on the sound quality.

Features

The 7000 does have extra input like USB and micro-jack (2,5mm) for mobile phones.
It also seems the 7000 is the only one supporting Power over Ethernet (PoE). There were no power to it at all in the box, only a network cable. Luckily I had lots of single PoEs laying around…

Setup
There gotta be a bug in the setup through the web interface. I could not make it set a authorization name/number. I also saw it in the SIP code that it did not send any authorization user in the digest authentication. I tried several times through the web interface, but ended up a day later putting it directly into the phone through the built in screen. Then it worked…. I did read the manual, but this is missing the middle part. It is good on user behavior (volume up and down) and good on setting up an automatic provisioning system (APS). But I was just going to put in one single account.

Finally, the usage

Great microphones! It picked up sound from all over the room. We had music playing, others discussing nearby but could still carry out the conversation! Say goodbye to lousy ISDN quality!! I really wonder how they actually make it work in full duplex, we were chatting in both directions with no problems. I have now wrapped up the 6000 (the ugly one..) and shipping it 2000 kilometers north to our support center. We have regular meetings, so that will be a good test. We used a Linksys 942 with loud speaker last time, and it was dreadful sound. The one we normally use is the Grandstream GXV-3000 with video, this works excellent as long as you have an extra conference “head-set”.

I would absolutely go for the Polycom 7000, but then I haven’t heard the price yet….

[ad]

OpenSBC and other nice projects


The Session BorderController is a VoIP specific transformer. It is really a mock up to handle the differences between vendors and bad implementations of VoIP protocols. Some SBCs also do transcoding and SIP to H323 conversion, which is functional. But in my opinion a SBC is unnecessary in a perfect world.

You can argue that a firewall has a SBC built in, which is correct. SBC can be called a protocol specific firewall. And that costs money! I have checked prices on Covergence, Juniper, InGate and lots of others. One thing in common, it costs! It costs to be an early VoIP adopter, paying extra to get everything to work together! So actually paying for lousy work done by others implementing the SIP stack….

Then it is nice with OpenSBC, FreeSwitch and similar projects. They provide means to get the different vendors to work together, making you able to choose between different vendors. I wish the open source community all the best! Let’s make this great togehter!
[ad]

Let the phones do it themselves!


Finally some “out-of-the-box” thinking. Avaya has launced their Quick Edition phones. When the individual devices are getting more and more memory and CPU, why not let them also do the job?

It is as easy as genius. If you need more phones, just add more. No central PBX needed. All the phones are stand-alone and manage themselves through some sort of local P2P. And you get quite a bit of functionality as well. Some of the features (from Avaya.com )

  • Voicemail Backup
  • Greetings and Prompts
  • Message Waiting Indicator
  • Redirect to Specified Extension
  • Telephone User Interface
  • Visual Voicemail
  • Message Monitoring
  • Message Sorting
  • Callback from Message
  • Administration

What will be the next big thing? We’ll just have to create it ourselves!

[ad]

Design a site like this with WordPress.com
Get started