[VOIPSEC] Cisco 7905 VoIP phone crashing from dsniff arpspoof?

Matthias Wenzel voipsec at mazzoo.de
Tue Sep 26 11:12:32 CDT 2006


sorry for responding so slow, I am on vacation.

Shawn Merdinger wrote:
> In the readme in the ohrwurm tarball from Matthius Wenzel's site:
> http://mazzoo.de/blog/2006/08/25#ohrwurm
>  - Cisco 7905 crashes with arpspoof alone :(

> No details as to 7905 firmware version, etc.  Can anyone confirm?


I blogged a few more details about the FW version under
http://mazzoo.de/blog/2006/08/05#ICMP3_cisco_insecurity

Sadly I don't own such a phone, so I cannot do anymore testing, but the
description is pretty obvious.

I had informed Cisco on 08/05/2006, their last words were "It may be
some time next week before you hear back from us once BlackHat/DEFCON is
over and we have more time to take a closer look at this issue." on the
same day.

Matthias




More information about the Voipsec mailing list