<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd"
xmlns:rawvoice="http://www.rawvoice.com/rawvoiceRssModule/"
>

<channel>
	<title>VoIP Users Conference &#187; attacks</title>
	<atom:link href="http://www.voipusersconference.org/tag/attacks/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.voipusersconference.org</link>
	<description> Live every Friday at 12 Noon Eastern time</description>
	<lastBuildDate>Fri, 03 Feb 2012 13:09:25 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
<!-- podcast_generator="Blubrry PowerPress/2.0.4" -->
	<itunes:new-feed-url>http://www.voipusersconference.org/feed/podcast/</itunes:new-feed-url>
	<itunes:summary>This is a weekly live meeting of people all over the world who are interested in sharing knowledge and experiences about telephony over the Internet. Guests include authors, innovators, programmers and Internet personalities.
The conference is reached by phoning in using SIP, Skype or a web page widget shown on the main web site http://vuc.me</itunes:summary>
	<itunes:author>@voipusers</itunes:author>
	<itunes:explicit>clean</itunes:explicit>
	<itunes:image href="http://www.voipusersconference.org/wp-content/uploads/powerpress/_vuc300.jpg" />
	<itunes:owner>
		<itunes:name>@voipusers</itunes:name>
		<itunes:email>itunes@voipusersconference.org</itunes:email>
	</itunes:owner>
	<managingEditor>itunes@voipusersconference.org (@voipusers)</managingEditor>
	<itunes:subtitle>VOIP allows you to do almost anything with incoming and outgoing telephone lines.</itunes:subtitle>
	<itunes:keywords>telephony,communications,international,asterisk,freeswitch,freepbx,skype</itunes:keywords>
	<image>
		<title>VoIP Users Conference &#187; attacks</title>
		<url>http://www.voipusersconference.org/wp-content/uploads/powerpress/_vuc144.jpg</url>
		<link>http://www.voipusersconference.org</link>
	</image>
	<itunes:category text="Technology">
		<itunes:category text="Software How-To" />
		<itunes:category text="Tech News" />
	</itunes:category>
		<item>
		<title>SIP Hacks: who should filter what, where?</title>
		<link>http://www.voipusersconference.org/2010/sip-hack-callerid-stuffing/</link>
		<comments>http://www.voipusersconference.org/2010/sip-hack-callerid-stuffing/#comments</comments>
		<pubDate>Mon, 24 May 2010 11:27:58 +0000</pubDate>
		<dc:creator>VUC</dc:creator>
				<category><![CDATA[VoIP]]></category>
		<category><![CDATA[attack]]></category>
		<category><![CDATA[attacks]]></category>
		<category><![CDATA[audio file]]></category>
		<category><![CDATA[broadband]]></category>
		<category><![CDATA[caller id]]></category>
		<category><![CDATA[callerid]]></category>
		<category><![CDATA[cleaning]]></category>
		<category><![CDATA[communication]]></category>
		<category><![CDATA[data]]></category>
		<category><![CDATA[difference]]></category>
		<category><![CDATA[electronic engineering]]></category>
		<category><![CDATA[electronics]]></category>
		<category><![CDATA[injection]]></category>
		<category><![CDATA[injections]]></category>
		<category><![CDATA[input data cleaning]]></category>
		<category><![CDATA[philosophical]]></category>
		<category><![CDATA[private branch exchange]]></category>
		<category><![CDATA[programmers]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[sip]]></category>
		<category><![CDATA[telephone exchanges]]></category>
		<category><![CDATA[voice over internet protocol]]></category>

		<guid isPermaLink="false">http://www.voipusersconference.org/?p=2139</guid>
		<description><![CDATA[Among others, Ward Mundy (Nerd Vittles, our guest next week) and many of the VUC regulars join in this violent argument civil discussion about who is responsible for filtering, where it should take place and the how and why of their ideas on the subject. If you&#8217;re into SIP technology, you&#8217;ll want to hear this [...]]]></description>
			<content:encoded><![CDATA[<p></p><p>Among others, Ward Mundy (<a title="Nerd Vittles" href="http://nerdvittles.com" target="_blank">Nerd Vittles</a>, our guest next week) and many of the VUC regulars join in this <span style="text-decoration: line-through;">violent argument</span> civil discussion about who is responsible for filtering, where it should take place and the how and why of their ideas on the subject.</p>
<p>If you&#8217;re into SIP technology, you&#8217;ll want to hear this discussion about who should protect people from SIP &#8220;CallerID stuffing&#8221; among Ward Mundy, Fred Posner (<a title="VoIP Tech Chat" href="http://www.voiptechchat.com/" target="_blank">VoIP Tech Chat</a>), Tim Panton, Karl Fife, Leif Madsen and the rest of the great gang of VoIP regulars. This is why you need to join us LIVE every Friday!</p>
<p>Programmers differ enormously over who should filter incoming data and where. There is no right answer, although the main point is to protect your users against whatever possible attacks might come through your system or pbx.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.voipusersconference.org/2010/sip-hack-callerid-stuffing/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
<enclosure url="http://media.blubrry.com/voipusers/recordings.talkshoe.com/TC-22622/TS-359935.mp3" length="35329854" type="audio/mpeg" />
			<itunes:keywords>attack,attacks,audio file,broadband,caller id,callerid,cleaning,communication,data,difference,electronic engineering,electronics</itunes:keywords>
		<itunes:subtitle>Among others, Ward Mundy (Nerd Vittles, our guest next week) and many of the VUC regulars join in this violent argument civil discussion about who is responsible for filtering, where it should take place and the how and why of their ideas on the subject.</itunes:subtitle>
		<itunes:summary>Among others, Ward Mundy (Nerd Vittles (http://nerdvittles.com), our guest next week) and many of the VUC regulars join in this violent argument civil discussion about who is responsible for filtering, where it should take place and the how and why of their ideas on the subject.

If you&#039;re into SIP technology, you&#039;ll want to hear this discussion about who should protect people from SIP &quot;CallerID stuffing&quot; among Ward Mundy, Fred Posner (VoIP Tech Chat (http://www.voiptechchat.com/)), Tim Panton, Karl Fife, Leif Madsen and the rest of the great gang of VoIP regulars. This is why you need to join us LIVE every Friday!

Programmers differ enormously over who should filter incoming data and where. There is no right answer, although the main point is to protect your users against whatever possible attacks might come through your system or pbx.</itunes:summary>
		<itunes:author>@voipusers</itunes:author>
		<itunes:explicit>clean</itunes:explicit>
		<itunes:duration>1:13:36</itunes:duration>
	</item>
		<item>
		<title>Dan York’s 7 Deadliest UC Attacks</title>
		<link>http://www.voipusersconference.org/2010/7-deadliest-uc-attacks/</link>
		<comments>http://www.voipusersconference.org/2010/7-deadliest-uc-attacks/#comments</comments>
		<pubDate>Fri, 21 May 2010 00:00:37 +0000</pubDate>
		<dc:creator>VUC</dc:creator>
				<category><![CDATA[Books]]></category>
		<category><![CDATA[VoIP]]></category>
		<category><![CDATA[attacks]]></category>
		<category><![CDATA[Dan York]]></category>
		<category><![CDATA[deadliest]]></category>
		<category><![CDATA[new books]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[uc]]></category>
		<category><![CDATA[voice over internet protocol]]></category>
		<category><![CDATA[Voxeo]]></category>

		<guid isPermaLink="false">http://www.voipusersconference.org/?p=2032</guid>
		<description><![CDATA[Dan York&#8217;s name is certainly familiar to you if you&#8217;re a fan of VoIP. He has made a video to explain why he wrote this book. Dan&#8217;s credentials are strong and he&#8217;s an active community member. You&#8217;ve seen him in airports between conferences, or even at one of those Voxeo events. Dan&#8217;s blog (perhaps we [...]]]></description>
			<content:encoded><![CDATA[<p></p><p><a href="http://www.7ducattacks.com/"><img class="alignright size-full wp-image-2033" title="7 Deadliest UC Attacks" src="http://www.voipusersconference.org/wp-content/uploads/2010/04/6a00d8341bfc6e53ef0120a8310200970b-800wi.png" alt="" width="172" height="211" /></a> Dan York&#8217;s name is certainly familiar to you if you&#8217;re a fan of VoIP. He has made a video to explain <a href="http://www.7ducattacks.com/2010/04/video-intro-to-seven-deadliest-unified-communications-attacks.html">why he wrote this book</a>. Dan&#8217;s credentials are strong and he&#8217;s an active community member. You&#8217;ve seen him in airports between conferences, or even at one of those<a href="http://www.voxeo.com/summits/customer"> Voxeo events</a>.</p>
<p>Dan&#8217;s blog (perhaps we should say one of his many blogs) is <a title="Disruptive Telephony" href="http://www.disruptivetelephony.com/" target="_blank">Disruptive Telephony</a>. Dan can be found on Twitter as <a title="Twitter" href="http://twitter.com/danyork" target="_blank">@DanYork</a> and he&#8217;s on Linkedin, Facebook, etc. Finding those links is left as an exercise for the enthusiastic student. <img src='http://www.voipusersconference.org/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<p>While I&#8217;m not sure what his current role there is, Dan is a part of another effort you should know about, the VoIP Security Alliance aka <a title="VOIPSA" href="http://www.voipsa.org/" target="_blank">VOIPSA</a> where he writes on <a href="http://www.voipsa.org/blog/">the VOIPSA blog</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.voipusersconference.org/2010/7-deadliest-uc-attacks/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
<enclosure url="http://media.blubrry.com/voipusers/recordings.talkshoe.com/TC-22622/TS-359281.mp3" length="24366055" type="audio/mpeg" />
			<itunes:keywords>attacks,Dan York,deadliest,new books,security,uc,voice over internet protocol,Voxeo</itunes:keywords>
		<itunes:subtitle>Dan York&#039;s name is certainly familiar to you if you&#039;re a fan of VoIP. He has made a video to explain why he wrote this book. Dan&#039;s credentials are strong and he&#039;s an active community member. You&#039;ve seen him in airports between conferences,</itunes:subtitle>
		<itunes:summary>(http://www.voipusersconference.org/wp-content/uploads/2010/04/6a00d8341bfc6e53ef0120a8310200970b-800wi.png) Dan York&#039;s name is certainly familiar to you if you&#039;re a fan of VoIP. He has made a video to explain why he wrote this book (http://www.7ducattacks.com/2010/04/video-intro-to-seven-deadliest-unified-communications-attacks.html). Dan&#039;s credentials are strong and he&#039;s an active community member. You&#039;ve seen him in airports between conferences, or even at one of those Voxeo events (http://www.voxeo.com/summits/customer).

Dan&#039;s blog (perhaps we should say one of his many blogs) is Disruptive Telephony (http://www.disruptivetelephony.com/). Dan can be found on Twitter as @DanYork (http://twitter.com/danyork) and he&#039;s on Linkedin, Facebook, etc. Finding those links is left as an exercise for the enthusiastic student. :)

While I&#039;m not sure what his current role there is, Dan is a part of another effort you should know about, the VoIP Security Alliance aka VOIPSA (http://www.voipsa.org/) where he writes on the VOIPSA blog (http://www.voipsa.org/blog/).</itunes:summary>
		<itunes:author>@voipusers</itunes:author>
		<itunes:explicit>clean</itunes:explicit>
		<itunes:duration>50:46</itunes:duration>
	</item>
		<item>
		<title>Amazon Indifference to EC2 Attacks Continues</title>
		<link>http://www.voipusersconference.org/2010/amazon-ec2-attacks-continue/</link>
		<comments>http://www.voipusersconference.org/2010/amazon-ec2-attacks-continue/#comments</comments>
		<pubDate>Sun, 18 Apr 2010 15:43:10 +0000</pubDate>
		<dc:creator>VUC</dc:creator>
				<category><![CDATA[The Rest]]></category>
		<category><![CDATA[VoIP]]></category>
		<category><![CDATA[Amazon]]></category>
		<category><![CDATA[attacks]]></category>
		<category><![CDATA[EC2]]></category>
		<category><![CDATA[Fraud]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[sip]]></category>

		<guid isPermaLink="false">http://www.voipusersconference.org/?p=1968</guid>
		<description><![CDATA[EC2 attacks continue with no help from them. Amazon continues its &#8220;head in the sand&#8221; approach to our community and this is unacceptable. Forgive the intrusion on this page, look below for the VUC sessions. You can help push this to their attention: Please make sure you keep this issue visible by voting it up [...]]]></description>
			<content:encoded><![CDATA[<p></p><p><a title="EC2 Attacks continue" href="http://www.voipusersconference.org/2010/amazon-ec2-flood-attacks/">EC2 attacks continue</a> with no help from them. Amazon continues its &#8220;head in the sand&#8221; approach to our community and this is unacceptable. Forgive the intrusion on this page, look below for the VUC sessions.</p>
<p><strong>You can help push this to their attention:</strong></p>
<p>Please make sure you keep this issue visible by voting it up on <a href="http://it.slashdot.org/story/10/04/17/2059256/SIP-Attacks-From-Amazon-EC2-Going-Unaddressed">SlashDot</a>. If you haven&#8217;t followed out discussions, see <a title="Amazon EC2 Attacks" href="http://www.voiptechchat.com/voip/457/amazon-ec2-sip-brute-force-attacks-on-rise/" target="_blank">Fred&#8217;s story</a>.<a title="Asterisk Amazon EC2 Attacks" href="http://lists.digium.com/pipermail/asterisk-users/2010-April/247094.html" target="_blank"> Asterisk user mailing list</a> has a lot of info on it as well. Post on Twitter, their robot stupidly repeats all comments that contain EC2 so don&#8217;t forget to use that mention in anything you post. Post on your blogs and any forums you can.</p>
<p>I expected better from Amazon and I&#8217;ll withdraw my significant business from them if they don&#8217;t rise up to the challenge.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.voipusersconference.org/2010/amazon-ec2-attacks-continue/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Amazon EC2 Flood Attacks from the Cloud</title>
		<link>http://www.voipusersconference.org/2010/amazon-ec2-flood-attacks/</link>
		<comments>http://www.voipusersconference.org/2010/amazon-ec2-flood-attacks/#comments</comments>
		<pubDate>Wed, 14 Apr 2010 23:00:57 +0000</pubDate>
		<dc:creator>VUC</dc:creator>
				<category><![CDATA[VoIP]]></category>
		<category><![CDATA[@voipusers]]></category>
		<category><![CDATA[abuse]]></category>
		<category><![CDATA[accountable]]></category>
		<category><![CDATA[Amazon]]></category>
		<category><![CDATA[amazon elastic compute cloud]]></category>
		<category><![CDATA[amazon.com]]></category>
		<category><![CDATA[attack]]></category>
		<category><![CDATA[attacks]]></category>
		<category><![CDATA[blockhosts]]></category>
		<category><![CDATA[brute force]]></category>
		<category><![CDATA[cloud]]></category>
		<category><![CDATA[cloud infrastructure]]></category>
		<category><![CDATA[clouds]]></category>
		<category><![CDATA[complaint]]></category>
		<category><![CDATA[computer network security]]></category>
		<category><![CDATA[computer security]]></category>
		<category><![CDATA[computing]]></category>
		<category><![CDATA[denial-of-service attack]]></category>
		<category><![CDATA[EC2]]></category>
		<category><![CDATA[fail2ban]]></category>
		<category><![CDATA[flood]]></category>
		<category><![CDATA[flood attacks]]></category>
		<category><![CDATA[ip address]]></category>
		<category><![CDATA[password]]></category>
		<category><![CDATA[swiftly]]></category>
		<category><![CDATA[system software]]></category>
		<category><![CDATA[Voip Tech Chat]]></category>
		<category><![CDATA[web services]]></category>

		<guid isPermaLink="false">http://www.voipusersconference.org/?p=1946</guid>
		<description><![CDATA[Part of this article is an edited summary of material from VoipTechChat.com Complaints of rampant SIP Brute Force Attacks coming from servers with Amazon EC2 IP Addresses cause many admins to simply drop all such traffic. Generally, SIP brute force attacks attempt to register various peer names to a system and/or attempt to guess passwords [...]]]></description>
			<content:encoded><![CDATA[<p></p><p><img class="aligncenter size-full wp-image-1952" title="cloud" src="http://www.voipusersconference.org/wp-content/uploads/2010/04/cloud.jpg" alt="" width="620" height="120" /><br />
Part of this article is an edited summary of material from <a href="http://www.voiptechchat.com/voip/457/amazon-ec2-sip-brute-force-attacks-on-rise/">VoipTechChat.com</a></p>
<p>Complaints of rampant SIP Brute Force Attacks coming from servers with Amazon EC2 IP Addresses cause many admins to simply drop all such traffic. Generally, SIP brute force attacks attempt to register various peer names to a system and/or attempt to guess passwords of known/guesses peers or endpoints. The object is theft of resources.</p>
<p>The complaints mentioned this weekend show an excessive amount of traffic; with some providers claiming 6GB of traffic dedicated to such attacks. Since we ourselves received an attack from an Amazon hosted server, we also reported and complained to the Amazon NOC/Abuse depts.</p>
<p>There are various techniques to assist with minimizing DDoS and Brute Force attacks, such as limiting access via the public internet, using strong passwords, not mapping extension name to peer/endpoint name, limiting simultaneous calls, and aggressively monitoring usage. Automatic blocking of abusive IP’s (fail2ban, blockhosts, etc.) can also assist with minimizing damage.</p>
<p>References: <a href="https://www.amazon.com/gp/html-forms-controller/AWSAbuse/">EC2 Abuse Report Form</a></p>
<p><a href="http://www.voipsa.org/">VOIPSA</a></p>
<p><strong>VUC official position</strong>: EC2 abuse costs victims time and money. Amazon is 100% accountable for what their customers do with their resources and must react swiftly to complaints.</p>
<p><strong>VUC 60 second rant</strong>: This week saw a new feature rolled out, the <strong>Voipusers One Minute Issue Talk</strong> (VOMIT) where all listeners are encouraged to phone in their VoIP-related rants. Call and leave yours at (<strong>518</strong>) <strong>VUC VOIP</strong> or (<strong>518</strong>) <strong>882-8647. </strong></p>
<p>Follow  <strong><a href="http://twitter.com/voipusers">@voipusers</a></strong> on Twitter.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.voipusersconference.org/2010/amazon-ec2-flood-attacks/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
<enclosure url="http://media.blubrry.com/voipusers/cloud.voipusersconference.org/EC2Attacks.mp3" length="52073269" type="audio/mpeg" />
			<itunes:keywords>@voipusers,abuse,accountable,Amazon,amazon elastic compute cloud,amazon.com,attack,attacks,blockhosts,brute force,cloud,cloud infrastructure</itunes:keywords>
		<itunes:subtitle>Part of this article is an edited summary of material from VoipTechChat.com - Complaints of rampant SIP Brute Force Attacks coming from servers with Amazon EC2 IP Addresses cause many admins to simply drop all such traffic. Generally,</itunes:subtitle>
		<itunes:summary>(http://www.voipusersconference.org/wp-content/uploads/2010/04/cloud.jpg)
Part of this article is an edited summary of material from VoipTechChat.com (http://www.voiptechchat.com/voip/457/amazon-ec2-sip-brute-force-attacks-on-rise/)

Complaints of rampant SIP Brute Force Attacks coming from servers with Amazon EC2 IP Addresses cause many admins to simply drop all such traffic. Generally, SIP brute force attacks attempt to register various peer names to a system and/or attempt to guess passwords of known/guesses peers or endpoints. The object is theft of resources.

The complaints mentioned this weekend show an excessive amount of traffic; with some providers claiming 6GB of traffic dedicated to such attacks. Since we ourselves received an attack from an Amazon hosted server, we also reported and complained to the Amazon NOC/Abuse depts.

There are various techniques to assist with minimizing DDoS and Brute Force attacks, such as limiting access via the public internet, using strong passwords, not mapping extension name to peer/endpoint name, limiting simultaneous calls, and aggressively monitoring usage. Automatic blocking of abusive IP’s (fail2ban, blockhosts, etc.) can also assist with minimizing damage.

References: EC2 Abuse Report Form (https://www.amazon.com/gp/html-forms-controller/AWSAbuse/)

VOIPSA (http://www.voipsa.org/)

VUC official position: EC2 abuse costs victims time and money. Amazon is 100% accountable for what their customers do with their resources and must react swiftly to complaints.

VUC 60 second rant: This week saw a new feature rolled out, the Voipusers One Minute Issue Talk (VOMIT) where all listeners are encouraged to phone in their VoIP-related rants. Call and leave yours at (518) VUC VOIP or (518) 882-8647. 

Follow  @voipusers (http://twitter.com/voipusers) on Twitter.</itunes:summary>
		<itunes:author>@voipusers</itunes:author>
		<itunes:explicit>clean</itunes:explicit>
		<itunes:duration>1:48:26</itunes:duration>
	</item>
		<item>
		<title>VoIP and SIP Security, Latest Attacks</title>
		<link>http://www.voipusersconference.org/2010/the-latest-in-voip-security-attacks/</link>
		<comments>http://www.voipusersconference.org/2010/the-latest-in-voip-security-attacks/#comments</comments>
		<pubDate>Fri, 12 Mar 2010 09:30:54 +0000</pubDate>
		<dc:creator>VUC</dc:creator>
				<category><![CDATA[VoIP]]></category>
		<category><![CDATA[attack]]></category>
		<category><![CDATA[attacks]]></category>
		<category><![CDATA[broadband]]></category>
		<category><![CDATA[communication]]></category>
		<category><![CDATA[electronics]]></category>
		<category><![CDATA[EnableSecurity.com]]></category>
		<category><![CDATA[fraudster]]></category>
		<category><![CDATA[gauci]]></category>
		<category><![CDATA[realistic]]></category>
		<category><![CDATA[sandro]]></category>
		<category><![CDATA[Sandro Gauci]]></category>
		<category><![CDATA[security conference]]></category>
		<category><![CDATA[Secutiry]]></category>
		<category><![CDATA[SIP scanning]]></category>
		<category><![CDATA[SIPVicious]]></category>
		<category><![CDATA[Sjur Usken]]></category>
		<category><![CDATA[voice over internet protocol]]></category>
		<category><![CDATA[voice over ip]]></category>
		<category><![CDATA[VoIP Security]]></category>
		<category><![CDATA[VOIPPACK]]></category>
		<category><![CDATA[VOIPSCANNER.com]]></category>

		<guid isPermaLink="false">http://www.voipusersconference.org/?p=1712</guid>
		<description><![CDATA[[audio:http://media.blubrry.com/winelover/recordings.talkshoe.com/TC-22622/TS-317306.mp3&#124;titles=VoIP Security] Sjur Usken and Sandro Gauci have been working together doing research on VoIP security attacks. They recently presented some of their work at Hackcon, a security conference in Norway. In this discussion they&#8217;ll be talking about a number of realistic VoIP attacks and what&#8217;s being exploited by fraudsters for profit. Sjur is a [...]]]></description>
			<content:encoded><![CDATA[<p></p><p>[audio:http://media.blubrry.com/winelover/recordings.talkshoe.com/TC-22622/TS-317306.mp3|titles=VoIP Security]</p>
<p><a title="Usken.no" href="http://www.usken.no/" target="_blank">Sjur Usken</a> and <a title="EnableSecurity" href="http://enablesecurity.com/" target="_blank">Sandro Gauci</a> have been working together doing research on VoIP security attacks. They recently presented some of their work at Hackcon, a security conference in Norway. In this discussion  they&#8217;ll be talking about a number of realistic VoIP attacks and what&#8217;s being exploited by fraudsters for profit.</p>
<p>Sjur  is a telecom consultant in Greenfield Consulting AS in Norway. He has been working with VoIP since 2002 and helping companies migrate to an all IP world.</p>
<p>Sandro  is a security researcher and consultant based in the small island of Malta. He is the author of VoIP security tools <a title="SIPvicious" href="http://code.google.com/p/sipvicious/" target="_blank">SIPVicious</a>, <a title="EnableSecurity" href="http://enablesecurity.com/" target="_blank">VOIPPACK</a> and <a href="http://voipscanner.com" target="_blank">VOIPSCANNER.com</a>. See <a title="EnableSecurity" href="http://enablesecurity.com/" target="_blank">http://enablesecurity.com/</a></p>
<p><a name="fb_share"></a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.voipusersconference.org/2010/the-latest-in-voip-security-attacks/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
<enclosure url="http://media.blubrry.com/voipusers/media.blubrry.com/winelover/recordings.talkshoe.com/TC-22622/TS-317306.mp3" length="30868836" type="audio/mpeg" />
			<itunes:keywords>SIP,Security,experts,voip,scanning,vulnerabilities,sipvicious</itunes:keywords>
		<itunes:subtitle>A review of recent attacks and tools to protect against vulnerability</itunes:subtitle>
		<itunes:summary>Two experts in SIP security research and attack prevention discuss how attacks are made and how to prevent them.</itunes:summary>
		<itunes:author>Randulo Zeeek</itunes:author>
		<itunes:explicit>clean</itunes:explicit>
		<itunes:duration>1:13:27</itunes:duration>
	</item>
	</channel>
</rss>

