[VOIPSEC] Actual Attacks

Robert Moskowitz rgm at icsalabs.com
Mon Feb 28 15:30:35 CST 2005


At 08:18 PM 2/25/2005, Brian Rosen wrote:

>Now, I always assume it's possible when designing systems; assume that every
>switch is a bridge..., but the reality is that sniffing packets for VoIP is
>much harder than most people think it is.

There are many ways for a provider to build a MAN, many of them not safe 
and the customer never knows.  Many companies rely on these MAN services 
for their Intranet.

We cannot operate on the basis that packet collection can't be done.  It 
might not be possible to insert a MITM device in the MAN, but packet 
collection is all to real.


Robert Moskowitz
Senior Technical Director
ICSA Labs, a division of Cybertrust, Inc.
W:      248-968-9809
F:      248-968-2824
E:      rgm at icsalabs.com

There's no limit to what can be accomplished
if it doesn't matter who gets the credit






More information about the Voipsec mailing list