[VOIPSEC] VOIP for free??

Robert Moskowitz rgm at icsalabs.com
Mon Apr 11 14:18:00 CDT 2005


At 10:59 AM 4/11/2005, Diana Cionoiu wrote:
>Hello Michael,
>
>I was refering on the fact that you have to be in the middle (as in man
>in the middle), which is far more complicated then you may think.

Wireless is the first place where this is not true.

Even a switched environment is open to localized attack.

Some of the new DNS poisioning attacks add to the mitm toolkit.

Don't be complacent.  Perhaps only .1% of the calls placed can be attacked 
this way.  That would still be a lot of them.

And other than wireless, most users would not understand the attack vectors 
and think they are ok.


Robert Moskowitz
Senior Technical Director
ICSA Labs, a division of Cybertrust, Inc.
W:      248-968-9809
F:      248-968-2824
E:      rgm at icsalabs.com

There's no limit to what can be accomplished
if it doesn't matter who gets the credit






More information about the Voipsec mailing list