[VOIPSEC] Voipsec Digest, Vol 61, Issue 4
Julian Frank
JulianF at hcl.in
Sat Jan 30 00:11:52 CST 2010
Unsubscribe me please!!
Warm Regards,
Julian Frank
Business Manager
-----Original Message-----
From: voipsec-bounces at voipsa.org [mailto:voipsec-bounces at voipsa.org] On Behalf Of voipsec-request at voipsa.org
Sent: Friday, 29 January, 2010 5:30 PM
To: voipsec at voipsa.org
Subject: Voipsec Digest, Vol 61, Issue 4
Send Voipsec mailing list submissions to
voipsec at voipsa.org
To subscribe or unsubscribe via the World Wide Web, visit
http://voipsa.org/mailman/listinfo/voipsec_voipsa.org
or, via email, send a message with subject or body 'help' to
voipsec-request at voipsa.org
You can reach the person managing the list at
voipsec-owner at voipsa.org
When replying, please edit your Subject line so it is more specific
than "Re: Contents of Voipsec digest..."
Today's Topics:
1. News: Leading voice encryption programs hacked in minutes
(Shawn Merdinger)
2. Re: News: Leading voice encryption programs hacked in minutes
(Richard L. Barnes)
----------------------------------------------------------------------
Message: 1
Date: Thu, 28 Jan 2010 14:13:39 -0500
From: Shawn Merdinger <shawnmer at gmail.com>
To: Voipsec <Voipsec at voipsa.org>
Subject: [VOIPSEC] News: Leading voice encryption programs hacked in
minutes
Message-ID:
<fb0927a81001281113r4365591ek5205d737903248f at mail.gmail.com>
Content-Type: text/plain; charset=windows-1252
http://news.techworld.com/security/3211263/leading-voice-encryption-programs-hacked-in-minutes/
Leading voice encryption programs hacked in minutes -- Most products
don't work, says researcher.
By John E. Dunn | Techworld | Published: 11:35 GMT, 27 January 10
Most voice encryption systems can be tapped in minutes by installing a
voice-recording Trojan on the target computer, a security researcher
has confirmed after testing a range of well-known products.
Although this type of attack has been known about for some time, the
scale of the issue uncovered by researcher ?Notrax' is still
surprising. In all, the unnamed engineer was able to intercept calls
made using twelve popular encryption programs and hardware systems
using an easily available $100 wiretapping utility called FlexiSPY.
This tapped the voice stream in real time before any encryption was
applied to the data.
The researcher then refined the principle of FlexiSPY into a
custom-written Trojan that could record both the microphone and
speaker and capture any conversation into a file for retrieval later
on. Crucially, both attacks were able to carry out their work
undetected by suppressing all rings, notifications and call logs.
Programs and hardware systems beaten included Zfone/ZRTP, Secure
Voice, Caspertech, and even the well-regarded GSM handset security
system from UK company Cellcrypt. Only three products resisted the
simple attack, an unnamed Rohde & Schwarz Bluetooth device, PhoneCrypt
from German company SecurStar, and a hardware product from SnapCell.
"It is easy to take the security at face value when the software told
me the call was secured. I decided to dig a little deeper. What I
discovered and what I was completely in shock about was I broke almost
all of them in less than 30 minutes," says the engineer in an ongoing
blog on the tests.
Using a Trojan to get around voice encryption software depends on
getting such a program on to a target PC or handset in advance of a
call, something that might or might not be difficult to achieve,
depending on the PC or device in question. But it is an attack method
that companies should know about given that it has been used against
the one program not tested by the researcher, Skype.
As long ago as 2006, the Swiss government was reported to be using
specially-written Trojans to record phone calls made by criminals
using Skype and other VoIP services. The author of this software,
Ruben Unteregger, later went public on his work, even going as far as
to publish the source code in an attempt to stop his software being
used for eavesdropping again.
"Like most security breaches, Notrax went for the weakest link; he did
not attempt to crack the encryption itself, but used simple
wiretapping techniques," says Wilfried Hafner, CEO at SecurStar, one
of the vendors that managed to resist the Trojan attack. PhoneCrypt
even threw up a skull and crossbones image when the Trojan tried to
access the program's memory-resident service, letting the user know
that the call was no longer secure.
Notrax has posted YouTube videos (scroll down) of how the hacks were
conducted on specific products. <http://infosecurityguard.com/>
------------------------------
Message: 2
Date: Thu, 28 Jan 2010 14:36:49 -0500
From: "Richard L. Barnes" <rbarnes at bbn.com>
To: Shawn Merdinger <shawnmer at gmail.com>
Cc: Voipsec <Voipsec at voipsa.org>
Subject: Re: [VOIPSEC] News: Leading voice encryption programs hacked
in minutes
Message-ID: <E011A33B-0899-4D59-8978-765B5F9B4488 at bbn.com>
Content-Type: text/plain; charset=WINDOWS-1252; format=flowed;
delsp=yes
In what way is it novel to capture audio before it gets encrypted (or
after it gets decrypted)? Am I missing something?
On Jan 28, 2010, at 2:13 PM, Shawn Merdinger wrote:
> http://news.techworld.com/security/3211263/leading-voice-encryption-programs-hacked-in-minutes/
>
> Leading voice encryption programs hacked in minutes -- Most products
> don't work, says researcher.
>
> By John E. Dunn | Techworld | Published: 11:35 GMT, 27 January 10
>
> Most voice encryption systems can be tapped in minutes by installing a
> voice-recording Trojan on the target computer, a security researcher
> has confirmed after testing a range of well-known products.
>
> Although this type of attack has been known about for some time, the
> scale of the issue uncovered by researcher ?Notrax' is still
> surprising. In all, the unnamed engineer was able to intercept calls
> made using twelve popular encryption programs and hardware systems
> using an easily available $100 wiretapping utility called FlexiSPY.
> This tapped the voice stream in real time before any encryption was
> applied to the data.
>
> The researcher then refined the principle of FlexiSPY into a
> custom-written Trojan that could record both the microphone and
> speaker and capture any conversation into a file for retrieval later
> on. Crucially, both attacks were able to carry out their work
> undetected by suppressing all rings, notifications and call logs.
>
> Programs and hardware systems beaten included Zfone/ZRTP, Secure
> Voice, Caspertech, and even the well-regarded GSM handset security
> system from UK company Cellcrypt. Only three products resisted the
> simple attack, an unnamed Rohde & Schwarz Bluetooth device, PhoneCrypt
> from German company SecurStar, and a hardware product from SnapCell.
>
> "It is easy to take the security at face value when the software told
> me the call was secured. I decided to dig a little deeper. What I
> discovered and what I was completely in shock about was I broke almost
> all of them in less than 30 minutes," says the engineer in an ongoing
> blog on the tests.
>
> Using a Trojan to get around voice encryption software depends on
> getting such a program on to a target PC or handset in advance of a
> call, something that might or might not be difficult to achieve,
> depending on the PC or device in question. But it is an attack method
> that companies should know about given that it has been used against
> the one program not tested by the researcher, Skype.
>
> As long ago as 2006, the Swiss government was reported to be using
> specially-written Trojans to record phone calls made by criminals
> using Skype and other VoIP services. The author of this software,
> Ruben Unteregger, later went public on his work, even going as far as
> to publish the source code in an attempt to stop his software being
> used for eavesdropping again.
>
> "Like most security breaches, Notrax went for the weakest link; he did
> not attempt to crack the encryption itself, but used simple
> wiretapping techniques," says Wilfried Hafner, CEO at SecurStar, one
> of the vendors that managed to resist the Trojan attack. PhoneCrypt
> even threw up a skull and crossbones image when the Trojan tried to
> access the program's memory-resident service, letting the user know
> that the call was no longer secure.
>
> Notrax has posted YouTube videos (scroll down) of how the hacks were
> conducted on specific products. <http://infosecurityguard.com/>
>
> _______________________________________________
> Voipsec mailing list
> Voipsec at voipsa.org
> http://voipsa.org/mailman/listinfo/voipsec_voipsa.org
------------------------------
_______________________________________________
Voipsec mailing list
Voipsec at voipsa.org
http://voipsa.org/mailman/listinfo/voipsec_voipsa.org
End of Voipsec Digest, Vol 61, Issue 4
**************************************
DISCLAIMER:
-----------------------------------------------------------------------------------------------------------------------
The contents of this e-mail and any attachment(s) are confidential and intended for the named recipient(s) only.
It shall not attach any liability on the originator or HCL or its affiliates. Any views or opinions presented in
this email are solely those of the author and may not necessarily reflect the opinions of HCL or its affiliates.
Any form of reproduction, dissemination, copying, disclosure, modification, distribution and / or publication of
this message without the prior written consent of the author of this e-mail is strictly prohibited. If you have
received this email in error please delete it and notify the sender immediately. Before opening any mail and
attachments please check them for viruses and defect.
-----------------------------------------------------------------------------------------------------------------------
More information about the Voipsec
mailing list