Stay in touch VUC Mailing List : VUC FaceBook Page : iTunes
24/7 Leave a message or send an SMS : (518) VUC-VOIP (882-8647) : IRC #vuc

Our CDN is better than Amazon : Check out Rackspace Cloud

VUC Info: Next session - Future Topics - HOW TO Connect

Posts Tagged security

Acme Packet On Session Border Controllers

Audio : Download file (TS-359928.mp3)

Friday June 18th we will be extending our recent trend in discussing matters of VoIP security.  This call will feature Ken Kuenzel from Acme Packet. Acme Packet are the leading provider of “Session Border Controllers,” aka SBCs.

What’s an SBC? What does it do?  So glad you asked…as that’s just what we aim to find out on Friday!  Acme has uploaded a slide presentation to follow while listening.

In the mean time, and for the very curious among you, Acme Packet has some great background on the topic amongst their online articles and presentations.

Yes, there’s homework!

Acme products: session border controllers (SBC), session-aware load balancers (SLB), multiservice security gateways (MSG) and session routing proxies (SRP)—operate Acme Packet Net-Net OS.

, , , , , , , , , ,

No Comments

SIP Hacks: who should filter what, where?

Audio : Download file (TS-359935.mp3)

Among others, Ward Mundy (Nerd Vittles, our guest next week) and many of the VUC regulars join in this violent argument civil discussion about who is responsible for filtering, where it should take place and the how and why of their ideas on the subject.

If you’re into SIP technology, you’ll want to hear this discussion about who should protect people from SIP “CallerID stuffing” among Ward Mundy, Fred Posner (VoIP Tech Chat), Tim Panton, Karl Fife, Leif Madsen and the rest of the great gang of VoIP regulars. This is why you need to join us LIVE every Friday!

Programmers differ enormously over who should filter incoming data and where. There is no right answer, although the main point is to protect your users against whatever possible attacks might come through your system or pbx.

, , , , , , , , , , , , , , , , , , , , ,

3 Comments

Dan York’s 7 Deadliest UC Attacks

Audio : Download file (TS-359281.mp3)

Dan York’s name is certainly familiar to you if you’re a fan of VoIP. He has made a video to explain why he wrote this book. Dan’s credentials are strong and he’s an active community member. You’ve seen him in airports between conferences, or even at one of those Voxeo events.

Dan’s blog (perhaps we should say one of his many blogs) is Disruptive Telephony. Dan can be found on Twitter as @DanYork and he’s on Linkedin, Facebook, etc. Finding those links is left as an exercise for the enthusiastic student. :)

While I’m not sure what his current role there is, Dan is a part of another effort you should know about, the VoIP Security Alliance aka VOIPSA where he writes on the VOIPSA blog.

, , , , , ,

1 Comment

Amazon Indifference to EC2 Attacks Continues

EC2 attacks continue with no help from them. Amazon continues its “head in the sand” approach to our community and this is unacceptable. Forgive the intrusion on this page, look below for the VUC sessions.

You can help push this to their attention:

Please make sure you keep this issue visible by voting it up on SlashDot. If you haven’t followed out discussions, see Fred’s story. Asterisk user mailing list has a lot of info on it as well. Post on Twitter, their robot stupidly repeats all comments that contain EC2 so don’t forget to use that mention in anything you post. Post on your blogs and any forums you can.

I expected better from Amazon and I’ll withdraw my significant business from them if they don’t rise up to the challenge.

, , , , ,

No Comments

Beginning OpenVPN 2.0.9

Audio : Download file (TS-320846.mp3)

Audio : Download file (TS-315633.mp3)

OpenVPN_2.0.9
The VPN topic will be of interest to all on the VUC so we’re inviting Markus Feilner, author of “Beginning OpenVPN 2.0.9“.

Two copies of this book to give away today

The following is from the preface of the book, co-authored by Norbert Graf:
OpenVPN is an outstanding piece of software that was invented by James Yonan in the year 2001 and has steadily been improved since then. No other VPN solution offers a comparable mixture of enterprise-level security, usability, and feature richness. We have been working with OpenVPN for many years now, and it has always proven to be the best solution. This book is intended to introduce OpenVPN software to network specialists and VPN newbies alike. OpenVPN works where most other solutions fail and exists on almost any platform. Thus, it is an ideal solution for problematic setups and an easy approach for the inexperienced.
On the other hand, the complexity of classic VPN solutions, especially IPsec, gives the impression that VPN technology in general is difficult and a topic only for very experienced (network and security) specialists. OpenVPN proves that this can be different, and this book aims to document that.
I want to provide both a concise description of OpenVPN’s features and an easy-to-understand introduction for the inexperienced. Though there may be many other possible ways to success in the scenarios described, the ones presented have been tested in many setups and have been selected for simplicity reasons.
LINKS
 Next scheduled session in your time zone
Freenode.net IRC web client, just add your pseudo and you're on #vuc
 VUC Google Group

  VUC linkedin group (business contacts)
Links mentioned in IRC Feb 5, 2010
[6:19pm] NerdUno: Here are some good OpenVPN tutorials: http://pbxinaflash.com/forum/showthread.php?t=4856
[6:21pm] steely_glint: ecrist - http://www.phonefromhere.com/vuc/
[6:31pm] ecrist: Why TCP Over TCP Is A Bad Idea:  http://sites.inka.de/~bigred/devel/tcp-tcp.html
[6:32pm] kfife:        http://www.packtpub.com/openvpn/book
[6:34pm] Zeeek:        http://www.linux4afrika.de/vision.html?L=0
[6:40pm] mfeilner:        http://www.linux-magazine.com/Issues/2009/99/SAFE-CALL
[6:41pm] mfeilner:        http://www.feilner-it.net
[6:42pm] mfeilner:        http://www.openvpn.eu
[6:43pm] mfeilner:        http://www.openvpn.eu/index.php?id=23&L=0

[7:39pm] Skibum: BTW more info on Bria 3 is available at: http://www.counterpath.com/bria.html
[8:00pm] mjgraves:        http://gigaset.com/chagall/provider/general/chagall223_02.bin
[8:21pm] JimCifarelli:        http://www.embeddedarm.com/about/resource.php?item=408

Part 2: Bria Tests and more

, , , , , , , , , , , , , ,

No Comments

Digium Security Webinar

, , ,

No Comments