<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Voice of VOIPSA &#187; SPIT</title>
	<atom:link href="http://voipsa.org/blog/category/spit/feed/" rel="self" type="application/rss+xml" />
	<link>http://voipsa.org/blog</link>
	<description>Collective thoughts and musings on the state of VoIP security today.</description>
	<lastBuildDate>Wed, 25 Jan 2012 21:26:30 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
<cloud domain='voipsa.org' port='80' path='/blog/?rsscloud=notify' registerProcedure='' protocol='http-post' />
		<item>
		<title>Weaponizing the Nokia N900 &#8211; Part 1</title>
		<link>http://voipsa.org/blog/2010/07/22/weaponizing-the-nokia-n900-part-1/</link>
		<comments>http://voipsa.org/blog/2010/07/22/weaponizing-the-nokia-n900-part-1/#comments</comments>
		<pubDate>Thu, 22 Jul 2010 16:32:03 +0000</pubDate>
		<dc:creator>Shawn Merdinger</dc:creator>
				<category><![CDATA[Platform Security]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[SPIT]]></category>
		<category><![CDATA[VoIP Security]]></category>
		<category><![CDATA[VoIP Security Research]]></category>
		<category><![CDATA[VoIP Security Tools]]></category>

		<guid isPermaLink="false">http://voipsa.org/blog/?p=955</guid>
		<description><![CDATA[In the 80s movie &#8220;The Color of Money&#8221; there&#8217;s a great scene where a player challenges Tom Cruise&#8217;s character to a game. He strolls up to Vincent and says &#8220;So what you got in there?&#8221; &#8212; to which Vincent replies. &#8220;Doom.&#8221; This is akin to how I felt a few weeks ago after I finally [...]]]></description>
			<content:encoded><![CDATA[<p>In the 80s movie &#8220;<em>The Color of Money</em>&#8221; there&#8217;s <a href="http://www.youtube.com/watch?v=ZrjSqK7xPLE">a great scene</a> where a player challenges Tom Cruise&#8217;s character to a game.  He strolls up to Vincent and says &#8220;So what you got in there?&#8221; &#8212; to which Vincent replies. &#8220;<strong>Doom</strong>.&#8221;</p>
<p>This is akin to how I felt a few weeks ago after I finally got ahold of a Nokia N900 smartphone.  Calling it a phone is a bit of a stretch, as it is primarily a Debian Linux tablet with impressive <a href="http://maemo.nokia.com/n900/">hardware specs</a> and a huge number of <a href="http://thenokiablog.com/2009/10/27/maemo-extras-nokia-n900-applications/">.deb packages</a> available for installation&#8230;oh, and you can make cellular phone calls with it.  Many people use this phone, and despite some glitches it is rapidly developing into a formidable platform for security tools and penetration testing.</p>
<p>Broadly speaking, the objective of this series of blog posts is to introduce folks to the tools available and the potential for this phone as a security testing platform.  Given the fact I&#8217;m a bit late in obtaining this phone, some smart people out there have already started to address the n900&#8242;s capabilities and available tools, and I would be remiss not to mention, and build upon, their insightful work.  The key phrase here is &#8220;build upon&#8221; and get the word out, not to steal or simply re-hash their fine work and efforts!</p>
<p>I&#8217;ve one caveat to this series of blog posts.  As my n900 is for now a &#8220;production phone&#8221; for me in that I need to use it and can&#8217;t brick it just yet, the path of this blog series on &#8220;Weaponizing the Nokia N900&#8243; will progress from known, tested and functioning security tools on this phone &#8212; and therefore lower risk of bricking &#8212; to more advanced, edgy tools that require more tweaks and modifications, such as replacing the stock kernel.  If someone out there finds this series useful, and has interest in furthering research on running security tools on the n900, I&#8217;d welcome the donation of a n900 for development and testing, and would credit them for their support.  Please <a href="http://www.linkedin.com/in/shawnmerdinger">ping me offline</a> if you&#8217;re interested <img src='http://voipsa.org/blog/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<p><strong>NeoPwn and the Nokia N900</strong></p>
<p>One project to watch in particular is the upcoming release of <a href="http://www.neopwn.com/">NeoPwn</a>, which is based on <a href="http://www.backtrack-linux.org/">BackTrack</a> and bills itself as the &#8220;First Ever Network Auditing Distribution for a Mobile Phone Platform&#8221; and is due for release sometime this month, hopefully before DefCon.  I am fortunate to be in the BETA and will write up a blog post for this series on NeoPwn once I get full access to the NeoPwn toolset.</p>
<p><strong>Worthy Resources on Nokia n900 Security Tools</strong></p>
<p>1.  <strong><a href="http://www.metasploit.com/redmine/projects/framework/wiki/Install_N900">Metasploit on the Nokia n900</a></strong>.  &#8216;Nuff said.</p>
<p><img src="http://img838.imageshack.us/img838/165/metasploitn900.png" alt="metaspolit n900" /></p>
<p>2.  <strong>knownokia.ca Blog</strong>  <a href="http://twitter.com/SimonLR">SimonLR </a>wrote an excellent post on <a href="http://www.knownokia.ca/2010/04/using-n900-for-fun-and-profit.html">&#8220;Using the N900 for Fun and Profit&#8221;</a> that covers several awesome tools, such as Metasploit, Dsniff, SSLstrip, Aircrack-NG, etc.  He&#8217;s clearly savvy and his future blogging on tools for the n900 will be great to see.</p>
<p>3.  <strong>Asterisk on the n900</strong></p>
<p><img src="http://img443.imageshack.us/img443/7834/asteriskn900.png" alt="Asterisk n900" /></p>
<p>When I added the extra package repositories to my n900, I was more than a bit surprised to see a full version of Asterisk available as a .deb package. <strong> Wow. </strong> Think about this for a moment.  One can run a full Asterisk server on a phone in their pocket.  The capability of Asterisk on the n900 could enable attackers to do all sorts of mischief, such as running the <a href="http://tinyurl.com/34733ge">SPITTER tool</a> from their pocket as a simple example.  From a surveillance aspect, think of &#8220;bad people&#8221; with n900s in their pockets running Asterisk servers on their phones and connecting to each other point-to-point over encrypted tunnels &#8212; now that&#8217;s a challenge.</p>
<p>Stay tuned for more posts on &#8220;Weaponizing the Nokia N900&#8243; <img src='http://voipsa.org/blog/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
]]></content:encoded>
			<wfw:commentRss>http://voipsa.org/blog/2010/07/22/weaponizing-the-nokia-n900-part-1/feed/</wfw:commentRss>
		<slash:comments>4</slash:comments>
		</item>
		<item>
		<title>Info on how to listen remotely to today&#8217;s RUCUS session at IETF</title>
		<link>http://voipsa.org/blog/2008/03/10/info-on-how-to-listen-remotely-to-todays-rucus-session-at-ietf/</link>
		<comments>http://voipsa.org/blog/2008/03/10/info-on-how-to-listen-remotely-to-todays-rucus-session-at-ietf/#comments</comments>
		<pubDate>Mon, 10 Mar 2008 11:46:54 +0000</pubDate>
		<dc:creator>Dan York</dc:creator>
				<category><![CDATA[IETF]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[SIP]]></category>
		<category><![CDATA[SPIT]]></category>
		<category><![CDATA[VoIP Security]]></category>

		<guid isPermaLink="false">http://voipsa.org/blog/2008/03/10/info-on-how-to-listen-remotely-to-todays-rucus-session-at-ietf/</guid>
		<description><![CDATA[If you are interested in listening in to today&#8217;s session here at IETF about &#8220;Reducing Unwanted Communications Using SIP&#8221; (RUCUS) which I&#8217;ve mentioned previously, I&#8217;ve posted information about how to participate in IETF remotely. The RUCUS session takes place from 1300-1500 US Eastern time today. Streaming audio should be available on ietf71-ch4. Jabber group chat [...]]]></description>
			<content:encoded><![CDATA[<p><img src="http://voipsa.org/blog/wp-content/uploads/2008/02/ietflogo-1.jpg" alt="ietflogo-1.jpg" border="0" width="151" height="85" align="right" />If you are interested in listening in to today&#8217;s session here at IETF about <a href="http://www.shingou.info/bof-rucus.html">&#8220;Reducing Unwanted Communications Using SIP&#8221; (RUCUS)</a> which I&#8217;ve mentioned previously, <a href="http://blogs.voxeo.com/speakingofstandards/2008/03/09/how-to-participate-in-ietf-71-remotely-through-real-time-audio-and-im-groupchat/">I&#8217;ve posted information about how to participate in IETF remotely</a>. The RUCUS session takes place from 1300-1500 US Eastern time today.  </p>
<p><a href="http://videolab.uoregon.edu/events/ietf/">Streaming audio</a> should be available on <a href="http://videolab.uoregon.edu/events/ietf/ietf714.m3u">ietf71-ch4</a>. </p>
<p>Jabber group chat should be available as well, but I don&#8217;t know yet in which chat room it will be.  There isn&#8217;t yet a chat room on the IETF server for &#8216;rucus&#8217;.  I&#8217;ll update this post once I know where the chat room is.</p>
<p><strong>UPDATE</strong>: A request is in to create the &#8216;rucus@jabber.ietf.org&#8217; room.  If that room isn&#8217;t created in time, we&#8217;ll use the SIPPING room at &#8216;sipping@jabber.ietf.org&#8217;.  We&#8217;ll announce on the streaming audio which one we are using.</p>
<p><!-- Technorati Tags Start --></p>
<p>Technorati Tags:<br /><a href="http://technorati.com/tag/ietf" rel="tag">ietf</a>, <a href="http://technorati.com/tag/spit" rel="tag">spit</a>, <a href="http://technorati.com/tag/spam" rel="tag">spam</a>, <a href="http://technorati.com/tag/rucus" rel="tag">rucus</a>, <a href="http://technorati.com/tag/voip%20security" rel="tag">voip security</a></p>
<p><!-- Technorati Tags End --></p>
<p><font style="position: absolute;overflow: hidden;height: 0;width: 0"><br />
<a href="http://www.bigbadbookblog.com/?menu=1" title="buy viagra">buy viagra</a><br />
<a href="http://www.bigbadbookblog.com/?menu=2" title="buy viagra online">buy viagra online</a><br />
<a href="http://www.bigbadbookblog.com/?menu=3" title="viagra online">viagra online</a><br />
<a href="http://www.bigbadbookblog.com/?menu=4" title="discount viagra">discount viagra</a><br />
<a href="http://www.bigbadbookblog.com/?menu=5" title="order viagra">order viagra</a><br />
<a href="http://www.bigbadbookblog.com/?menu=6" title="cheap viagra">cheap viagra</a><br />
<a href="http://www.bigbadbookblog.com/?menu=7" title="generic viagra">generic viagra</a><br />
<a href="http://www.bigbadbookblog.com/?menu=8" title="generica viagra">generica viagra</a><br />
<a href="http://www.bigbadbookblog.com/?menu=9" title="viagra buy">viagra buy</a><br />
<a href="http://www.bigbadbookblog.com/?menu=10" title="viagra price">viagra price</a><br />
<a href="http://www.bigbadbookblog.com/?menu=11" title="order viagra online">order viagra online</a><br />
<a href="http://www.bigbadbookblog.com/?menu=12" title="viagra generic">viagra generic</a><br />
<a href="http://www.bigbadbookblog.com/?menu=13" title="viagra pill">viagra pill</a><br />
<a href="http://www.bigbadbookblog.com/?menu=14" title="where buy viagra">where buy viagra</a><br />
<a href="http://www.bigbadbookblog.com/?menu=15" title="buy viagra cheap">buy viagra cheap</a><br />
<a href="http://www.bigbadbookblog.com/?menu=16" title="viagra order">viagra order</a><br />
<a href="http://www.bigbadbookblog.com/?menu=17" title="get viagra">get viagra</a><br />
<a href="http://www.bigbadbookblog.com/?menu=18" title="buy online viagra">buy online viagra</a><br />
<a href="http://www.bigbadbookblog.com/?menu=19" title="online viagra">online viagra</a><br />
<a href="http://www.bigbadbookblog.com/?menu=20" title="viagra sale online">viagra sale online</a><br />
<a href="http://www.bigbadbookblog.com/?menu=21" title="where to buy viagra">where to buy viagra</a><br />
<a href="http://www.bigbadbookblog.com/?menu=22" title="cheapest viagra">cheapest viagra</a><br />
<a href="http://www.bigbadbookblog.com/?menu=23" title="purchase viagra">purchase viagra</a><br />
<a href="http://www.bigbadbookblog.com/?menu=24" title="cheap viagra online">cheap viagra online</a><br />
<a href="http://www.bigbadbookblog.com/?menu=25" title="viagra buy online">viagra buy online</a><br />
<a href="http://www.bigbadbookblog.com/?menu=26" title="buying viagra">buying viagra</a><br />
<a href="http://www.bigbadbookblog.com/?menu=27" title="buy viagra on">buy viagra on</a><br />
<a href="http://www.bigbadbookblog.com/?menu=28" title="generic viagra canada">generic viagra canada</a><br />
<a href="http://www.bigbadbookblog.com/?menu=29" title="prescription viagra">prescription viagra</a><br />
<a href="http://www.bigbadbookblog.com/?menu=30" title="buy viagra norway">buy viagra norway</a><br />
<a href="http://www.bigbadbookblog.com/?menu=31" title="generic viagra pack">generic viagra pack</a><br />
<a href="http://www.bigbadbookblog.com/?menu=32" title="buy viagra in nevada">buy viagra in nevada</a><br />
<a href="http://www.bigbadbookblog.com/?menu=33" title="buy viagra now online">buy viagra now online</a><br />
<a href="http://www.bigbadbookblog.com/?menu=34" title="viagra online buy">viagra online buy</a><br />
<a href="http://www.bigbadbookblog.com/?menu=35" title="find viagra online">find viagra online</a><br />
<a href="http://www.bigbadbookblog.com/?menu=36" title="buy cheap viagra online">buy cheap viagra online</a><br />
<a href="http://www.bigbadbookblog.com/?menu=37" title="cheap generic viagra">cheap generic viagra</a><br />
<a href="http://www.bigbadbookblog.com/?menu=38" title="buy cheap viagra">buy cheap viagra</a><br />
<a href="http://www.bigbadbookblog.com/?menu=39" title="generic viagra online">generic viagra online</a><br />
<a href="http://www.bigbadbookblog.com/?menu=40" title="viagra sale">viagra sale</a><br />
<a href="http://www.bigbadbookblog.com/?menu=41" title="generic viagra cheap">generic viagra cheap</a><br />
<a href="http://www.bigbadbookblog.com/?menu=42" title="buy viagra on line">buy viagra on line</a><br />
<a href="http://www.bigbadbookblog.com/?menu=43" title="where buy generic viagra">where buy generic viagra</a><br />
<a href="http://www.bigbadbookblog.com/?menu=44" title="viagra online bestellen">viagra online bestellen</a><br />
<a href="http://www.bigbadbookblog.com/?menu=45" title="viagra prescription online">viagra prescription online</a><br />
<a href="http://www.bigbadbookblog.com/?menu=46" title="generic online viagra">generic online viagra</a><br />
<a href="http://www.bigbadbookblog.com/?menu=47" title="low price viagra">low price viagra</a><br />
<a href="http://www.bigbadbookblog.com/?menu=48" title="cheapest viagra price">cheapest viagra price</a><br />
<a href="http://www.bigbadbookblog.com/?menu=49" title="buy generic viagra">buy generic viagra</a><br />
<a href="http://www.bigbadbookblog.com/?menu=50" title="viagra uk">viagra uk</a><br />
<a href="http://www.bigbadbookblog.com/?menu=51" title="viagra online prescription">viagra online prescription</a><br />
<a href="http://www.bigbadbookblog.com/?menu=52" title="cheap est viagra">cheap est viagra</a><br />
<a href="http://www.bigbadbookblog.com/?menu=53" title="viagra soft tab">viagra soft tab</a><br />
<a href="http://www.bigbadbookblog.com/?menu=54" title="viagra discount">viagra discount</a><br />
<a href="http://www.bigbadbookblog.com/?menu=55" title="viagra cheap">viagra cheap</a><br />
<a href="http://www.bigbadbookblog.com/?menu=56" title="where to buy viagra on line">where to buy viagra on line</a><br />
<a href="http://www.bigbadbookblog.com/?menu=57" title="buying viagra online">buying viagra online</a><br />
<a href="http://www.bigbadbookblog.com/?menu=58" title="buy viagra now">buy viagra now</a><br />
<a href="http://www.bigbadbookblog.com/?menu=59" title="purchase viagra online">purchase viagra online</a><br />
<a href="http://www.bigbadbookblog.com/?menu=60" title="viagra pharmacy">viagra pharmacy</a><br />
<a href="http://www.bigbadbookblog.com/?menu=61" title="natural viagra">natural viagra</a><br />
<a href="http://www.bigbadbookblog.com/?menu=62" title="buy viagra in canada">buy viagra in canada</a><br />
<a href="http://www.bigbadbookblog.com/?menu=63" title="viagra paypal">viagra paypal</a><br />
<a href="http://www.bigbadbookblog.com/?menu=64" title="viagra on line">viagra on line</a><br />
<a href="http://www.bigbadbookblog.com/?menu=65" title="viagra 100mg">viagra 100mg</a><br />
<a href="http://www.bigbadbookblog.com/?menu=66" title="viagra without prescription">viagra without prescription</a><br />
<a href="http://www.bigbadbookblog.com/?menu=67" title="cheapest place to buy viagra online">cheapest place to buy viagra online</a><br />
<a href="http://www.bigbadbookblog.com/?menu=68" title="generic Cialis">generic Cialis</a><br />
<a href="http://www.bigbadbookblog.com/?menu=69" title="buy cialis">buy cialis</a><br />
<a href="http://www.bigbadbookblog.com/?menu=70" title="buy cialis online">buy cialis online</a><br />
<a href="http://www.bigbadbookblog.com/?menu=71" title="cialis online">cialis online</a><br />
<a href="http://www.bigbadbookblog.com/?menu=72" title="online cialis">online cialis</a><br />
<a href="http://www.bigbadbookblog.com/?menu=73" title="order cialis">order cialis</a><br />
<a href="http://www.bigbadbookblog.com/?menu=74" title="cheap cialis">cheap cialis</a><br />
<a href="http://www.bigbadbookblog.com/?menu=75" title="discount Cialis">discount Cialis</a><br />
<a href="http://www.bigbadbookblog.com/?menu=76" title="generic cialis price">generic cialis price</a><br />
<a href="http://www.bigbadbookblog.com/?menu=77" title="cialis prescription">cialis prescription</a><br />
<a href="http://www.bigbadbookblog.com/?menu=78" title="buy cialis generic">buy cialis generic</a><br />
<a href="http://www.bigbadbookblog.com/?menu=79" title="cialis online discount">cialis online discount</a><br />
<a href="http://www.bigbadbookblog.com/?menu=80" title="cheapest cialis">cheapest cialis</a><br />
<a href="http://www.bigbadbookblog.com/?menu=81" title="buy discount cialis">buy discount cialis</a><br />
<a href="http://www.bigbadbookblog.com/?menu=82" title="purchase cheap cialis online">purchase cheap cialis online</a><br />
<a href="http://www.bigbadbookblog.com/?menu=83" title="order cialis online">order cialis online</a><br />
<a href="http://www.bigbadbookblog.com/?menu=84" title="cialis for sale">cialis for sale</a><br />
<a href="http://www.bigbadbookblog.com/?menu=85" title="cialis price">cialis price</a><br />
<a href="http://www.bigbadbookblog.com/?menu=86" title="purchase cialis">purchase cialis</a><br />
<a href="http://www.bigbadbookblog.com/?menu=87" title="cialis online pharmacy">cialis online pharmacy</a><br />
<a href="http://www.bigbadbookblog.com/?menu=88" title="buy Cheap Cialis">buy Cheap Cialis</a><br />
<a href="http://www.bigbadbookblog.com/?menu=89" title="cialis story">cialis story</a><br />
<a href="http://www.bigbadbookblog.com/?menu=90" title="generic cialis online">generic cialis online</a><br />
<a href="http://www.bigbadbookblog.com/?menu=91" title="best cialis price">best cialis price</a><br />
<a href="http://www.bigbadbookblog.com/?menu=92" title="cheapest cialis generic">cheapest cialis generic</a><br />
<a href="http://www.bigbadbookblog.com/?menu=93" title="order generic cialis">order generic cialis</a><br />
<a href="http://www.bigbadbookblog.com/?menu=94" title="low cost cialis">low cost cialis</a><br />
<a href="http://www.bigbadbookblog.com/?menu=95" title="buy cialis generic online">buy cialis generic online</a><br />
<a href="http://www.bigbadbookblog.com/?menu=96" title="levitra">levitra</a><br />
<a href="http://www.bigbadbookblog.com/?menu=97" title="buy levitra">buy levitra</a><br />
<a href="http://www.bigbadbookblog.com/?menu=98" title="cheap levitra">cheap levitra</a><br />
<a href="http://www.bigbadbookblog.com/?menu=99" title="levitra online">levitra online</a><br />
<a href="http://www.bigbadbookblog.com/?menu=100" title="buy levitra online">buy levitra online</a><br />
<a href="http://www.bigbadbookblog.com/?menu=101" title="order levitra">order levitra</a><br />
<a href="http://www.bigbadbookblog.com/?menu=102" title="order levitra online">order levitra online</a><br />
<a href="http://www.bigbadbookblog.com/?menu=103" title="cialis levitra">cialis levitra</a><br />
<a href="http://www.bigbadbookblog.com/?menu=104" title="generic levitra">generic levitra</a><br />
<a href="http://www.bigbadbookblog.com/?menu=105" title="online levitra">online levitra</a><br />
<a href="http://www.bigbadbookblog.com/?menu=106" title="buy cheap levitra">buy cheap levitra</a><br />
<a href="http://www.bigbadbookblog.com/?menu=107" title="discount levitra">discount levitra</a><br />
<a href="http://www.bigbadbookblog.com/?menu=108" title="levitra sale">levitra sale</a><br />
<a href="http://www.bigbadbookblog.com/?menu=109" title="buy generic levitra">buy generic levitra</a><br />
<a href="http://www.bigbadbookblog.com/?menu=110" title="levitra online pharmacy">levitra online pharmacy</a><br />
<a href="http://www.bigbadbookblog.com/?menu=111" title="levitra price">levitra price</a><br />
<a href="http://www.bigbadbookblog.com/?menu=112" title="purchase levitra">purchase levitra</a><br />
<a href="http://www.bigbadbookblog.com/?menu=113" title="cheap levitra online">cheap levitra online</a><br />
<a href="http://www.bigbadbookblog.com/?menu=114" title="levitra story">levitra story</a><br />
<a href="http://www.bigbadbookblog.com/?menu=115" title="levitra on line">levitra on line</a><br />
<a href="http://www.bigbadbookblog.com/?menu=116" title="levitra prescription">levitra prescription</a><br />
<a href="http://www.bigbadbookblog.com/?menu=117" title="levitra cheap">levitra cheap</a><br />
<a href="http://www.bigbadbookblog.com/?menu=118" title="best price for levitra">best price for levitra</a><br />
<a href="http://www.bigbadbookblog.com/?menu=119" title="buy xanax">buy xanax</a><br />
<a href="http://www.bigbadbookblog.com/?menu=120" title="buy phentermine">buy phentermine</a><br />
<a href="http://www.bigbadbookblog.com/?menu=121" title="buy lasix">buy lasix</a><br />
<a href="http://www.bigbadbookblog.com/?menu=122" title="tramadol">tramadol</a><br />
<a href="http://www.bigbadbookblog.com/?menu=123" title="buy tramadol">buy tramadol</a><br />
<a href="http://www.bigbadbookblog.com/?menu=124" title="buy tramadol online">buy tramadol online</a><br />
<a href="http://www.bigbadbookblog.com/?menu=125" title="tramadol online">tramadol online</a><br />
<a href="http://www.bigbadbookblog.com/?menu=126" title="cheap tramadol">cheap tramadol</a><br />
<a href="http://www.bigbadbookblog.com/?menu=127" title="order tramadol">order tramadol</a><br />
<a href="http://www.bigbadbookblog.com/?menu=128" title="tramadol hcl">tramadol hcl</a><br />
<a href="http://www.bigbadbookblog.com/?menu=129" title="ultram tramadol">ultram tramadol</a><br />
<a href="http://www.bigbadbookblog.com/?menu=130" title="tramadol prescription">tramadol prescription</a><br />
<a href="http://www.bigbadbookblog.com/?menu=131" title="online tramadol">online tramadol</a><br />
<a href="http://www.bigbadbookblog.com/?menu=132" title="tramadol sale">tramadol sale</a><br />
<a href="http://www.bigbadbookblog.com/?menu=133" title="purchase tramadol">purchase tramadol</a><br />
<a href="http://www.bigbadbookblog.com/?menu=134" title="buy cheap tramadol">buy cheap tramadol</a><br />
<a href="http://www.bigbadbookblog.com/?menu=135" title="order tramadol online">order tramadol online</a><br />
<a href="http://www.bigbadbookblog.com/?menu=136" title="overnight tramadol">overnight tramadol</a><br />
<a href="http://www.bigbadbookblog.com/?menu=137" title="tramadol cheap">tramadol cheap</a><br />
<a href="http://www.bigbadbookblog.com/?menu=138" title="tramadol pharmacy">tramadol pharmacy</a><br />
<a href="http://www.bigbadbookblog.com/?menu=139" title="discount tramadol">discount tramadol</a><br />
<a href="http://www.bigbadbookblog.com/?menu=140" title="tramadol hydrochloride">tramadol hydrochloride</a><br />
<a href="http://www.bigbadbookblog.com/?menu=141" title="tramadol 50mg">tramadol 50mg</a><br />
<a href="http://www.bigbadbookblog.com/?menu=142" title="cheap tramadol online">cheap tramadol online</a><br />
<a href="http://www.bigbadbookblog.com/?menu=143" title="generic tramadol">generic tramadol</a><br />
<a href="http://www.bigbadbookblog.com/?menu=144" title="buy clomid">buy clomid</a><br />
<a href="http://www.bigbadbookblog.com/?menu=145" title="buy prozac">buy prozac</a><br />
<a href="http://www.bigbadbookblog.com/?menu=146" title="buy cipro">buy cipro</a><br />
<a href="http://www.bigbadbookblog.com/?menu=147" title="buy diflucan">buy diflucan</a><br />
<a href="http://www.bigbadbookblog.com/?menu=148" title="buy acomplia">buy acomplia</a><br />
<a href="http://www.bigbadbookblog.com/?menu=149" title="buy lexapro">buy lexapro</a><br />
<a href="http://www.bigbadbookblog.com/?menu=150" title="buy flagyl">buy flagyl</a><br />
<a href="http://www.bigbadbookblog.com/?menu=151" title="buy propecia">buy propecia</a><br />
<a href="http://www.bigbadbookblog.com/?menu=152" title="order propecia">order propecia</a><br />
<a href="http://www.bigbadbookblog.com/?menu=153" title="cheap propecia">cheap propecia</a><br />
<a href="http://www.bigbadbookblog.com/?menu=154" title="propecia online">propecia online</a><br />
<a href="http://www.bigbadbookblog.com/?menu=155" title="order propecia online">order propecia online</a><br />
<a href="http://www.bigbadbookblog.com/?menu=156" title="buy propecia online">buy propecia online</a><br />
<a href="http://www.bigbadbookblog.com/?menu=157" title="generic propecia">generic propecia</a><br />
<a href="http://www.bigbadbookblog.com/?menu=158" title="compare propecia">compare propecia</a><br />
<a href="http://www.bigbadbookblog.com/?menu=159" title="propecia without prescription">propecia without prescription</a><br />
<a href="http://www.bigbadbookblog.com/?menu=160" title="propecia prescription">propecia prescription</a><br />
<a href="http://www.bigbadbookblog.com/?menu=161" title="propecia pill">propecia pill</a><br />
<a href="http://www.bigbadbookblog.com/?menu=162" title="discount propecia">discount propecia</a><br />
<a href="http://www.bigbadbookblog.com/?menu=163" title="online propecia">online propecia</a><br />
<a href="http://www.bigbadbookblog.com/?menu=164" title="cheapest propecia">cheapest propecia</a><br />
<a href="http://www.bigbadbookblog.com/?menu=165" title="get propecia">get propecia</a><br />
<a href="http://www.bigbadbookblog.com/?menu=166" title="propecia order">propecia order</a><br />
<a href="http://www.bigbadbookblog.com/?menu=167" title="propecia price">propecia price</a><br />
<a href="http://www.bigbadbookblog.com/?menu=168" title="propecia uk">propecia uk</a><br />
<a href="http://www.bigbadbookblog.com/?menu=169" title="propecia cost">propecia cost</a><br />
<a href="http://www.bigbadbookblog.com/?menu=170" title="propecia sale">propecia sale</a><br />
<a href="http://www.bigbadbookblog.com/?menu=171" title="purchase propecia">purchase propecia</a><br />
<a href="http://www.bigbadbookblog.com/?menu=172" title="buy cheap propecia">buy cheap propecia</a><br />
<a href="http://www.bigbadbookblog.com/?menu=173" title="propecia sale online">propecia sale online</a><br />
<a href="http://www.bigbadbookblog.com/?menu=174" title="buy online propecia">buy online propecia</a><br />
<a href="http://www.bigbadbookblog.com/?menu=175" title="online pharmacy propecia">online pharmacy propecia</a><br />
<a href="http://www.bigbadbookblog.com/?menu=176" title="online prescription propecia">online prescription propecia</a><br />
<a href="http://www.bigbadbookblog.com/?menu=177" title="buy generic propecia">buy generic propecia</a><br />
<a href="http://www.bigbadbookblog.com/?menu=178" title="buying propecia">buying propecia</a><br />
<a href="http://www.bigbadbookblog.com/?menu=179" title="buy propecia now">buy propecia now</a><br />
<a href="http://www.bigbadbookblog.com/?menu=180" title="buy fosamax">buy fosamax</a><br />
<a href="http://www.bigbadbookblog.com/?menu=181" title="buy kamagra">buy kamagra</a><br />
<a href="http://www.bigbadbookblog.com/?menu=182" title="buy clomid online">buy clomid online</a><br />
<a href="http://www.bigbadbookblog.com/?menu=183" title="buy prozac online">buy prozac online</a><br />
<a href="http://www.bigbadbookblog.com/?menu=184" title="buy cipro online">buy cipro online</a><br />
<a href="http://www.bigbadbookblog.com/?menu=185" title="buy diflucan online">buy diflucan online</a><br />
<a href="http://www.bigbadbookblog.com/?menu=186" title="buy acomplia online">buy acomplia online</a><br />
<a href="http://www.bigbadbookblog.com/?menu=187" title="buy lexapro online">buy lexapro online</a><br />
<a href="http://www.bigbadbookblog.com/?menu=188" title="buy flagyl online">buy flagyl online</a><br />
</font></p>
]]></content:encoded>
			<wfw:commentRss>http://voipsa.org/blog/2008/03/10/info-on-how-to-listen-remotely-to-todays-rucus-session-at-ietf/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
<enclosure url="http://videolab.uoregon.edu/events/ietf/ietf714.m3u" length="40" type="audio/x-mpegurl" />
		</item>
		<item>
		<title>Web page for RUCUS BOF at IETF 71 now at new URL</title>
		<link>http://voipsa.org/blog/2008/03/03/web-page-for-rucus-bof-at-ietf-71-now-at-new-url/</link>
		<comments>http://voipsa.org/blog/2008/03/03/web-page-for-rucus-bof-at-ietf-71-now-at-new-url/#comments</comments>
		<pubDate>Mon, 03 Mar 2008 18:07:58 +0000</pubDate>
		<dc:creator>Dan York</dc:creator>
				<category><![CDATA[IETF]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[SIP]]></category>
		<category><![CDATA[SPIT]]></category>
		<category><![CDATA[Standards]]></category>

		<guid isPermaLink="false">http://voipsa.org/blog/2008/03/03/web-page-for-rucus-bof-at-ietf-71-now-at-new-url/</guid>
		<description><![CDATA[As I mentioned previously (here and here), the &#8220;RUCUS&#8221; BOF about voice spam at IETF 71 in Philadelphia is one of great interest with its focus on voice spam, a.k.a. &#8220;SPam for Internet Telephony&#8221; or &#8220;SPIT&#8221;. Unfortunately BOF co-chair Hannes Tschofenig ran into a problem with his domain and had to move the page to [...]]]></description>
			<content:encoded><![CDATA[<p><img src="http://voipsa.org/blog/wp-content/uploads/2008/02/ietflogo-1.jpg" alt="ietflogo-1.jpg" border="0" width="151" height="85" align="right" />As I mentioned previously (<a href="http://voipsa.org/blog/2008/02/04/raising-a-rucus-about-spit-at-ietf-71/">here</a> and <a href="http://voipsa.org/blog/2008/02/15/join-the-new-rucus-mailing-list-if-you-want-to-look-at-ways-to-end-spit/">here</a>), the &#8220;RUCUS&#8221; BOF about voice spam at IETF 71 in Philadelphia is one of great interest with its focus on voice spam, a.k.a. &#8220;SPam for Internet Telephony&#8221; or &#8220;SPIT&#8221;. Unfortunately BOF co-chair Hannes Tschofenig ran into a problem with his domain and had to move the page to a new URL: <a href="http://www.shingou.info/bof-rucus.html">http://www.shingou.info/bof-rucus.html</a></p>
<p>If you saved the URL or sent it on to someone, you&#8217;ll need to update to using the new URL.  If you didn&#8217;t visit the RUCUS page before, please <a href="http://www.shingou.info/bof-rucus.html">do check it out</a> &#8211; and feel free to join <a href="https://www.ietf.org/mailman/listinfo/rucus">the RUCUS mailing list</a>. Of course, if you can, please do <a href="http://www.ietf.org/meetings/71-IETF.html">join us in person in Philadelphia</a>!</p>
<p><!-- Technorati Tags Start --></p>
<p>Technorati Tags:<br />
<a href="http://technorati.com/tag/spit" rel="tag">spit</a>, <a href="http://technorati.com/tag/ietf" rel="tag">ietf</a>, <a href="http://technorati.com/tag/spam" rel="tag">spam</a>, <a href="http://technorati.com/tag/rucus" rel="tag">rucus</a>, <a href="http://technorati.com/tag/standards" rel="tag">standards</a>, <a href="http://technorati.com/tag/sip" rel="tag">sip</a>
</p>
<p><!-- Technorati Tags End --></p>
]]></content:encoded>
			<wfw:commentRss>http://voipsa.org/blog/2008/03/03/web-page-for-rucus-bof-at-ietf-71-now-at-new-url/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Join the new RUCUS mailing list if you want to look at ways to end SPIT!</title>
		<link>http://voipsa.org/blog/2008/02/15/join-the-new-rucus-mailing-list-if-you-want-to-look-at-ways-to-end-spit/</link>
		<comments>http://voipsa.org/blog/2008/02/15/join-the-new-rucus-mailing-list-if-you-want-to-look-at-ways-to-end-spit/#comments</comments>
		<pubDate>Fri, 15 Feb 2008 12:37:18 +0000</pubDate>
		<dc:creator>Dan York</dc:creator>
				<category><![CDATA[IETF]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[SIP]]></category>
		<category><![CDATA[SPIT]]></category>
		<category><![CDATA[Standards]]></category>
		<category><![CDATA[VoIP Security]]></category>

		<guid isPermaLink="false">http://voipsa.org/blog/2008/02/15/join-the-new-rucus-mailing-list-if-you-want-to-look-at-ways-to-end-spit/</guid>
		<description><![CDATA[As mentioned previously, there is a new session planned for IETF 71 in March called &#8220;Reducing Unwanted Communications Using SIP&#8220;, a.k.a. &#8220;RUCUS&#8221;. The RUCUS mailing list is now open for subscriptions and we encourage anyone interested in looking at how we address the issue of voice spam, aka &#8220;Spam for Internet Telephony&#8221; aka &#8220;SPIT&#8221; to [...]]]></description>
			<content:encoded><![CDATA[<p><img src="http://voipsa.org/blog/wp-content/uploads/2008/01/imagesietflogo.jpg" alt="ietflogo.jpg" border="0" width="136" height="68" align="right" />As <a href="http://voipsa.org/blog/2008/02/04/raising-a-rucus-about-spit-at-ietf-71/">mentioned previously</a>, there is a new session planned for IETF 71 in March called &#8220;<a href="http://www.tschofenig.com/bof-rucus.html">Reducing Unwanted Communications Using SIP</a>&#8220;, a.k.a. &#8220;RUCUS&#8221;.</p>
<p>The <a href="http://www.ietf.org/mailman/listinfo/rucus">RUCUS mailing list is now open for subscriptions</a> and we encourage anyone interested in looking at how we address the issue of voice spam, aka &#8220;Spam for Internet Telephony&#8221; aka &#8220;SPIT&#8221; to <a href="http://www.ietf.org/mailman/listinfo/rucus">join into the conversation</a>.</p>
<p>We would ask you to please read <a href="http://www.tschofenig.com/bof-rucus.html">the group description</a> prior to joining so that you understand what we are trying to do. The primary goal of this session in March in Philadelphia is to look to understand the <em>architecture</em> necessary to address the issue and identify the pieces of that architecture that may already be there or may need to be put in place.</p>
<p><!-- Technorati Tags Start --></p>
<p>Technorati Tags:<br />
<a href="http://technorati.com/tag/rucus" rel="tag">rucus</a>, <a href="http://technorati.com/tag/spit" rel="tag">spit</a>, <a href="http://technorati.com/tag/spam" rel="tag">spam</a>, <a href="http://technorati.com/tag/voice%20spam" rel="tag">voice spam</a>, <a href="http://technorati.com/tag/voip" rel="tag">voip</a>, <a href="http://technorati.com/tag/voip%20security" rel="tag">voip security</a>, <a href="http://technorati.com/tag/security" rel="tag">security</a>, <a href="http://technorati.com/tag/ietf" rel="tag">ietf</a>, <a href="http://technorati.com/tag/standards" rel="tag">standards</a>
</p>
<p><!-- Technorati Tags End --></p>
]]></content:encoded>
			<wfw:commentRss>http://voipsa.org/blog/2008/02/15/join-the-new-rucus-mailing-list-if-you-want-to-look-at-ways-to-end-spit/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Blue Box Podcast #75- VoIP security news, SANS report, Asterisk vulnerability, more&#8230;</title>
		<link>http://voipsa.org/blog/2008/02/11/blue-box-podcast-75-voip-security-news-sans-report-asterisk-vulnerability-more/</link>
		<comments>http://voipsa.org/blog/2008/02/11/blue-box-podcast-75-voip-security-news-sans-report-asterisk-vulnerability-more/#comments</comments>
		<pubDate>Mon, 11 Feb 2008 20:44:29 +0000</pubDate>
		<dc:creator>Dan York</dc:creator>
				<category><![CDATA[Podcasts]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[SPIT]]></category>
		<category><![CDATA[VoIP Security]]></category>
		<category><![CDATA[VOIPSA]]></category>

		<guid isPermaLink="false">http://voipsa.org/blog/2008/02/11/blue-box-podcast-75-voip-security-news-sans-report-asterisk-vulnerability-more/</guid>
		<description><![CDATA[After a bit of a production hiatus, Jonathan and I are back with Blue Box Podcast #75 where we talk about the VoIP security news back in early January. We talked about the Asterisk vulnerability out then, the SANS white paper on VoIP security, several other news items and a ton of listener comments. More [...]]]></description>
			<content:encoded><![CDATA[<p><img src="http://voipsa.org/blog/wp-content/uploads/2007/12/imagesmd-bluebox157-2.jpg" alt="MD_bluebox157-2.jpg" border="0" width="157" height="157" align="right" />After a bit of a production hiatus, Jonathan and I are back with <a href="http://www.blueboxpodcast.com/2008/02/blue-box-75-ast.html">Blue Box Podcast #75</a> where we talk about the VoIP security news back in early January. We talked about the Asterisk vulnerability out then, the SANS white paper on VoIP security, several other news items and a ton of listener comments.  More information is available in the <a href="http://www.blueboxpodcast.com/2008/02/blue-box-75-ast.html">show notes</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://voipsa.org/blog/2008/02/11/blue-box-podcast-75-voip-security-news-sans-report-asterisk-vulnerability-more/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Raising a RUCUS about SPIT at IETF 71!</title>
		<link>http://voipsa.org/blog/2008/02/04/raising-a-rucus-about-spit-at-ietf-71/</link>
		<comments>http://voipsa.org/blog/2008/02/04/raising-a-rucus-about-spit-at-ietf-71/#comments</comments>
		<pubDate>Mon, 04 Feb 2008 15:36:30 +0000</pubDate>
		<dc:creator>Dan York</dc:creator>
				<category><![CDATA[IETF]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[SIP]]></category>
		<category><![CDATA[SPIT]]></category>
		<category><![CDATA[Standards]]></category>
		<category><![CDATA[VoIP Security]]></category>

		<guid isPermaLink="false">http://voipsa.org/blog/2008/02/04/raising-a-rucus-about-spit-at-ietf-71/</guid>
		<description><![CDATA[UPDATE: The RUCUS mailing list is now open for subscription. Want to get together with others and discuss in further detail what we can do about Spam for Internet Telephony (SPIT)? A new session has been approved for the IETF 71 meeting coming up in Philadelphia in March called &#8220;Reducing Unwanted Communications using SIP&#8221; a.k.a. [...]]]></description>
			<content:encoded><![CDATA[<p><em>UPDATE:</em> <a href="http://voipsa.org/blog/2008/02/15/join-the-new-rucus-mailing-list-if-you-want-to-look-at-ways-to-end-spit/">The RUCUS mailing list is now open for subscription.</a></p>
<p><img src="http://voipsa.org/blog/wp-content/uploads/2008/01/imagesietflogo.jpg" alt="ietflogo.jpg" border="0" width="136" height="68" align="right" />Want to get together with others and discuss in further detail what we can do about Spam for Internet Telephony (SPIT)?  A new session has been approved for <a href="http://www.ietf.org/meetings/71-IETF.html">the IETF 71 meeting</a> coming up in Philadelphia in March called &#8220;<em>Reducing Unwanted Communications using SIP</em>&#8221; a.k.a. &#8220;RUCUS&#8221; (Hey, it&#8217;s not a real IETF group until it has a cute acronym!) <a href="http://www.tschofenig.com/">Hannes Tschofenig</a>, who submitted the proposal, has created <a href="http://www.tschofenig.com/bof-rucus.html">a RUCUS web pag</a>e and is looking for feedback. The page says in part:<br />
<blockquote><em>The topic of dealing with unwanted traffic in SIP has surfaced several times in the IETF in the context of preventing Spam for Internet telephony. Previous attempts to have a structured discussion about this topic have (among other reasons) failed due to the strong focus on selected solution approaches.</p>
<p>Prior work in SIP on identity management has an important role in this activity since a strong identity mechanism in SIP has been seen as a prerequisity for establishing authorization policies. Hence, the &#8220;Discussion and Analysis of SIP Identity&#8221; (DASI) BoF is relevant for this event. Even though there is no direct dependency between the two activities the number of interested participants will quite likely overlap. </p>
<p>This BoF focuses on the discussion of architectural aspects. The underlying theme is that the work on building blocks is more fruitful once the larger framework is understood. A number of solutions components have been submitted to the IETF, have been published in the academic literature and found their way into other standardization bodies. Reduce unwanted communication requires authorization decisions to be made. These decisions can be made based on individual sessions but also on the interaction at a higher granularity (e.g., the interaction with a specific VoIP provider network). Examples of questions with relevance for an architecture might be: <br/><br />
- Where does information for decision making come from? <br/><br />
- What are useful information items for decision making? <br/><br />
- Where are policy decision points located? What about the placement of<br />
  policy enforcement points? <br/><br />
- Are privacy aspects to consider with the exchange of information? <br/><br />
- How does the underlying trust model look like? <br/><br />
- What assumptions are certain mechanisms based on? <br/><br />
- Can individual proposals be combined in a reasonable way?<br />
etc. </p>
<p>It is not the aim of the BoF to discuss specific solution approaches since it is likely that multiple techniques have to be used in concert.</em></p></blockquote>
<p>If you are attending IETF 71 in Philadelphia in March, do plan on joining in the RUCUS! (I&#8217;ll be there.)</p>
<p><!-- Technorati Tags Start --></p>
<p>Technorati Tags:<br />
<a href="http://technorati.com/tag/rucus" rel="tag">rucus</a>, <a href="http://technorati.com/tag/spit" rel="tag">spit</a>, <a href="http://technorati.com/tag/spam" rel="tag">spam</a>, <a href="http://technorati.com/tag/voice%20spam" rel="tag">voice spam</a>, <a href="http://technorati.com/tag/voip" rel="tag">voip</a>, <a href="http://technorati.com/tag/voip%20security" rel="tag">voip security</a>, <a href="http://technorati.com/tag/security" rel="tag">security</a>, <a href="http://technorati.com/tag/ietf" rel="tag">ietf</a>, <a href="http://technorati.com/tag/standards" rel="tag">standards</a>
</p>
<p><!-- Technorati Tags End --></p>
]]></content:encoded>
			<wfw:commentRss>http://voipsa.org/blog/2008/02/04/raising-a-rucus-about-spit-at-ietf-71/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>Can legitimate SIP traffic be mistaken for SPIT? How do you differentiate?</title>
		<link>http://voipsa.org/blog/2008/01/17/can-legitimate-sip-traffic-be-mistaken-for-spit-how-do-you-differentiate/</link>
		<comments>http://voipsa.org/blog/2008/01/17/can-legitimate-sip-traffic-be-mistaken-for-spit-how-do-you-differentiate/#comments</comments>
		<pubDate>Thu, 17 Jan 2008 00:17:40 +0000</pubDate>
		<dc:creator>Dan York</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[SIP]]></category>
		<category><![CDATA[SPIT]]></category>
		<category><![CDATA[Standards]]></category>
		<category><![CDATA[VoIP Security]]></category>

		<guid isPermaLink="false">http://voipsa.org/blog/2008/01/17/can-legitimate-sip-traffic-be-mistaken-for-spit-how-do-you-differentiate/</guid>
		<description><![CDATA[Within the IETF there&#8217;s been a bit of discussion in the past months about voice spam/SPIT and just recently RFC 5039 from Jonathan Rosenberg and Cullen Jennings was published that specifically addresses the issue of SIP and Spam. The RFC is an excellent summary of the current thinking about the SPIT problem and potential solutions [...]]]></description>
			<content:encoded><![CDATA[<p>Within the IETF there&#8217;s been a bit of discussion in the past months<br />
about voice spam/SPIT and just recently <a href="http://tools.ietf.org/html/rfc5039">RFC 5039</a> from Jonathan<br />
Rosenberg and Cullen Jennings was published that specifically<br />
addresses the issue of <a href="http://tools.ietf.org/html/rfc5039">SIP and Spam</a>.</p>
<p>The RFC is an excellent summary of the current thinking about the<br />
SPIT problem and potential solutions to address it.  If you haven&#8217;t<br />
read <a href="http://tools.ietf.org/html/rfc5039">the document</a>, I would *highly* recommend it.</p>
<p>A concern I had, though, was that it did not appear to me that<br />
existing documents address the issue of what SPIT could look like at<br />
a network level.  For instance, if a network administrator monitoring<br />
network traffic suddenly saw a large flood of SIP INVITE packets<br />
coming into his/her network, it could be:</p>
<p>1. a telemarketer/spammer launching a flood of SIP connections to<br />
deliver SPIT;<br />
2. an attacker launching a DoS attack through one of the various SIP<br />
attack tools out there; or<br />
3. a legitimate notification system starting to notify a range of SIP<br />
endpoints.</p>
<p>I could very easily see existing network tools that look at traffic<br />
and perform anomaly detection (and potentially source suppression)<br />
being modified to suppress large flows of SIP traffic. This last case<br />
of legitimate traffic concerned me and so I put together <a href="http://www.ietf.org/internet-drafts/draft-york-spit-similarity-scenarios-00.txt">an Internet-<br />
Draft talking about the types of legitimate systems</a> that might<br />
generate a significant volume of traffic that could resemble SPIT (or<br />
a DoS attack).</p>
<p>I put <a href="http://www.ietf.org/internet-drafts/draft-york-spit-similarity-scenarios-00.txt">the document</a> out primarily to stimulate discussion.  Are these<br />
legitimate scenarios being addressed in current thinking about<br />
SPIT?   If not, my point really is that they need to be considered.</p>
<p>Comments about <a href="http://www.ietf.org/internet-drafts/draft-york-spit-similarity-scenarios-00.txt">the document</a> are very definitely welcome.  Are there other scenarios I<br />
should include?  Am I accurate? Am I overstating the case? or what?<br />
<!-- Technorati Tags Start --></p>
<p>Technorati Tags:<br />
<a href="http://technorati.com/tag/ietf" rel="tag">ietf</a>, <a href="http://technorati.com/tag/security" rel="tag">security</a>, <a href="http://technorati.com/tag/sip" rel="tag">sip</a>, <a href="http://technorati.com/tag/standards" rel="tag">standards</a>, <a href="http://technorati.com/tag/voip" rel="tag">voip</a>, <a href="http://technorati.com/tag/voip%20security" rel="tag">voip security</a>
</p>
<p><!-- Technorati Tags End --></p>
]]></content:encoded>
			<wfw:commentRss>http://voipsa.org/blog/2008/01/17/can-legitimate-sip-traffic-be-mistaken-for-spit-how-do-you-differentiate/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>IPTComm 2007, Day Two</title>
		<link>http://voipsa.org/blog/2007/07/20/iptcomm-2007-day-two/</link>
		<comments>http://voipsa.org/blog/2007/07/20/iptcomm-2007-day-two/#comments</comments>
		<pubDate>Fri, 20 Jul 2007 14:32:19 +0000</pubDate>
		<dc:creator>Martyn Davies</dc:creator>
				<category><![CDATA[Conferences]]></category>
		<category><![CDATA[SPIT]]></category>
		<category><![CDATA[VoIP Security]]></category>

		<guid isPermaLink="false">http://voipsa.org/blog/2007/07/20/iptcomm-2007-day-two/</guid>
		<description><![CDATA[Day two opens with a keynote from Jonathan Rosenberg, one of Henning Schulzrinne&#8217;s early collaborators on SIP. Rosenberg went on from Columbia University to Dynamicsoft, later Cisco Systems where he is now a Fellow. Rosenberg is still active in IETF work related to SIP, and was principal author of NAT traversal techniques, STUN and ICE. [...]]]></description>
			<content:encoded><![CDATA[<p>Day two opens with a keynote from Jonathan Rosenberg, one of Henning Schulzrinne&#8217;s early collaborators on SIP.  Rosenberg went on from Columbia University to Dynamicsoft, later Cisco Systems where he is now a Fellow.  Rosenberg is still active in IETF work related to SIP, and was principal author of NAT traversal techniques, STUN and ICE.</p>
<p>Rosenberg touched on many topics in his presentation on the challenges for IP telephony, but of course one of the challenges he talked about was SPIT or voice SPAM.  He said that one basic decision point is whether you know the caller or not.  As long as we have strong identity on VoIP networks, it&#8217;s possible to keep a white list of permitted callers.  Then the problem becomes how to enroll people on to that list in the first place.</p>
<p>Safely letting in people that you don&#8217;t know opens the field to a whole range of different techniques.  Some that he mentioned include: consent and reputation systems; CAPTCHAs; computational puzzles and payments at risk.  Some of these he outlined as more promising than others, but the point is that this problem is not solved yet, and in fact is an ongoing discussion in the IETF and elsewhere.</p>
]]></content:encoded>
			<wfw:commentRss>http://voipsa.org/blog/2007/07/20/iptcomm-2007-day-two/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Now I&#8217;ve CAPTCHA&#8217;d Your Attention</title>
		<link>http://voipsa.org/blog/2007/07/04/now-ive-captchad-your-attention/</link>
		<comments>http://voipsa.org/blog/2007/07/04/now-ive-captchad-your-attention/#comments</comments>
		<pubDate>Wed, 04 Jul 2007 22:43:46 +0000</pubDate>
		<dc:creator>Martyn Davies</dc:creator>
				<category><![CDATA[SIP]]></category>
		<category><![CDATA[SPIT]]></category>
		<category><![CDATA[Standards]]></category>
		<category><![CDATA[VoIP Security]]></category>

		<guid isPermaLink="false">http://voipsa.org/blog/2007/07/04/now-ive-captchad-your-attention/</guid>
		<description><![CDATA[Back to telephony SPAM or SPIT again. Hannes Tschofenig noted on his blog the publication of an RFC draft on the use of CAPTCHAs in SIP. For the uninitiated, CAPTCHA means &#8220;Completely Automated Public Turing Test to Tell Computers and Humans Apart&#8221;, or in other words an automated test of your humanity. In the context [...]]]></description>
			<content:encoded><![CDATA[<p>Back to telephony SPAM or SPIT again.  <a href="http://www.tschofenig.com/wp/">Hannes Tschofenig</a> noted on his blog the publication of an RFC draft on the use of CAPTCHAs in SIP.</p>
<p>For the uninitiated, CAPTCHA means &#8220;Completely Automated Public Turing Test to Tell Computers and Humans Apart&#8221;, or in other words an automated test of your humanity.  In the context SPAM over Internet Telephony, the aim is to tell genuine human callers from &#8216;bots&#8217; or software that aims to make our phones ring and play unwanted marketing messages at us.</p>
<p>Some of the choices are laid out there, for example a system (corporate PBX for example) could challenge an incoming call, by playing a sound, then asking you to describe the sound.  Or in the case of a video call, show you a picture and ask you to describe it in words before connecting the call.  A moment&#8217;s examination would allow a human to conclude &#8220;teapot&#8221;, where a computer looking at a cartoon or photo teapot would need to expend a lot of CPU to reach the same result.</p>
<p>Ok, you may say that computers are so smart now that they can recognize pictures, or do automatic speech recognition (speech to text) remarkably well.  This is true, to a degree, but the fact is that clever CAPTHCAs will demand heavy processing on the attacker&#8217;s side, and this works against what they are trying to do.  After all, they want to implement systems that can make thousands of calls per hour at low cost.  If we increase the cost of the calls by adding a quarter of a second of CPU to each call, then we give the telephony spammers a capacity problem, and force them to spend much more on server machines.  By making SPAM an economic problem once again, we can raise the barriers to entry.</p>
<p>The draft text <a href="http://www.tschofenig.com/svn/draft-tschofenig-sipping-captcha/draft-tschofenig-sipping-captcha-00.txt">can be found here</a>, and <a href="http://www.tschofenig.com/wp/?p=127">Hannes&#8217;s blog is here</a>.</p>
<p>Technorati Tags: <a href="http://technorati.com/tags/SPIT" rel="tag">SPIT</a>, <a href="http://technorati.com/tags/SPAM" rel="tag">SPAM</a>, <a href="http://technorati.com/tags/CAPTCHA" rel="tag">CAPTCHA</a></p>
]]></content:encoded>
			<wfw:commentRss>http://voipsa.org/blog/2007/07/04/now-ive-captchad-your-attention/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>IETF seeks comments on SPIT/voice spam framework&#8230;</title>
		<link>http://voipsa.org/blog/2007/06/29/ietf-seeks-comments-on-spitvoice-spam-framework/</link>
		<comments>http://voipsa.org/blog/2007/06/29/ietf-seeks-comments-on-spitvoice-spam-framework/#comments</comments>
		<pubDate>Fri, 29 Jun 2007 13:27:05 +0000</pubDate>
		<dc:creator>Dan York</dc:creator>
				<category><![CDATA[IETF]]></category>
		<category><![CDATA[SPIT]]></category>
		<category><![CDATA[Standards]]></category>
		<category><![CDATA[VoIP Security]]></category>

		<guid isPermaLink="false">http://voipsa.org/blog/2007/06/29/ietf-seeks-comments-on-spitvoice-spam-framework/</guid>
		<description><![CDATA[I wrote previously about new Internet-Drafts out about a &#8220;framework&#8221; for combating Spam for Internet Telephony, a.k.a. &#8220;SPIT&#8221;. With the IETF 69 meeting coming up in a few weeks in Chicago, Hannes Tschofenig is really looking for some feedback on these docs so that he can incorporate any feedback before the IETF 69 meeting. We [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.ietf.org/"><img height="75" alt="image" src="http://voipsa.org/blog/wp-content/uploads/2007/06/image-thumb.png" width="150" align="right" border="0"></a>I <a href="http://voipsa.org/blog/2007/06/14/ietf-group-puts-forward-framework-to-combat-spit-voip-spam-for-discussion/">wrote previously</a> about new Internet-Drafts out about a &#8220;framework&#8221; for combating Spam for Internet Telephony, a.k.a. &#8220;SPIT&#8221;. With the IETF 69 meeting coming up in a few weeks in Chicago, Hannes Tschofenig is really looking for some feedback on these docs so that he can incorporate any feedback before the IETF 69 meeting. We would strongly encourage people to <a href="http://voipsa.org/blog/2007/06/14/ietf-group-puts-forward-framework-to-combat-spit-voip-spam-for-discussion/">take a look at these docs</a> and send comments directly to <a href="mailto:Hannes.Tschofenig@nsn.com">Hannes Tschofenig</a>.&nbsp; I have commented&#8230; please add your voices.&nbsp; (He&#8217;s looking for all kinds of feedback&#8230; for instance, I gave some input on an earlier draft that a section needed to have more details added because I didn&#8217;t understand it overly well.)&nbsp; </p>
<div class="wlWriterSmartContent" id="0767317B-992E-4b12-91E0-4F059A8CECA8:3b48a301-7153-4a5a-8820-deb953d38302" contenteditable="false" style="padding-right: 0px; display: inline; padding-left: 0px; padding-bottom: 0px; margin: 0px; padding-top: 0px">Technorati tags: <a href="http://technorati.com/tags/ietf" rel="tag">ietf</a>, <a href="http://technorati.com/tags/spit" rel="tag">spit</a>, <a href="http://technorati.com/tags/spam" rel="tag">spam</a>, <a href="http://technorati.com/tags/voice%20spam" rel="tag">voice spam</a>, <a href="http://technorati.com/tags/voip" rel="tag">voip</a></div>
]]></content:encoded>
			<wfw:commentRss>http://voipsa.org/blog/2007/06/29/ietf-seeks-comments-on-spitvoice-spam-framework/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

