VoIPshield Presents New VoIP Security VulnerabilityBest Security Tips offers daily news, information, advices and tips about spyware, adware, viruses, trojans, web vulnerabilities, hackers, other threats    | Register now | Login
   
TIPS NEWS TOOLS DOWNLOADS MALWARE FORUM BOOKS FREE MAGAZINES FREE WEBCASTS & VIDEOS
GFI LANguard - New Version 9 Out Now - Dld 30-day trial!   Get A Free iPod   Bookmark and Share 
Best Tips
Security Scanner
Security Categories
Advertise With Us!
Latest Viruses / Threats
2009/12/24 0:00:00
2009/11/7 19:22:16
2009/11/7 19:22:16
2009/11/7 19:22:16
2009/11/7 15:40:03
Our Partners
Downloads
Security Incidents : VoIPshield Presents New VoIP Security Vulnerability
Posted by Max on 2008/6/26 8:53:36 (1144 reads)
Security Incidents

VoIPshield Laboratories, the research division of VoIPshield Systems Inc., today made its second announcement of security vulnerabilities in Voice over IP systems marketed by Avaya, Cisco and Nortel. This brings the total number of vulnerability groups reported to VoIP vendors in 2008 to over fifty, representing over 175 unique vulnerabilities.

The vulnerability groups will be disclosed in limited detail on VoIPshield's website . Vulnerabilities are categorized into four exploit types based on their most likely malicious intent: remote code execution; unauthorized access; denial of service; and information harvesting.

Under its Responsible Disclosure Policy, VoIPshield works with the VoIP vendors to assist them in reproducing the vulnerabilities in their labs, thus facilitating the development of software patches for the affected products. Avaya, Cisco and Nortel are acknowledging these vulnerabilities today on their websites, and issuing their own security advisories.

"Most security breaches result from a combination of attack methods" said Rick Dalmazzi, president and CEO of VoIPshield. "There is a trend in recent years of hacker attacks moving 'up the stack' to the application layer. One recent study found that over twenty percent of breaches included exploiting a known vulnerability in the targeted application. What's important is that the good guys find these vulnerabilities and protect against them faster than the bad guys find them and exploit them."

The VoIP vulnerabilities discovered by VoIPshield Labs, if successfully exploited, could result in losses to the corporation in the form of mitigation expenses, brand reputation, internal productivity, competitive advantage and compliance penalties.

"Security vulnerabilities and threats continue to evolve," said Russell Smoak, Cisco director of security intelligence engineering. "Continued collaboration with the vulnerability research community is important to the overall security of the Internet ecosystem. We greatly appreciate the opportunity to work with researchers on security vulnerabilities and welcome the opportunity to review and assist in their product reports. We thank VoIPshield for collaboratively reporting these vulnerabilities to Cisco."

Effective immediately, customers of VoIPshield's VoIPaudit(TM) VoIP Vulnerability Assessment product can download the new vulnerabilities to update their systems, using the VoIPshield Update(TM) subscription service. Customers using the VoIPguard(TM) Intrusion Prevention System, currently in field trials, can download the corresponding new threat signatures.

In April, VoIPshield was named one of five "Cool Vendors in Infrastructure Protection for 2008" by Gartner. "As IP telephony continues to gain momentum, targeted attacks -- and possibly broad-based attacks -- will surface and gain greater visibility, highlighting vulnerabilities and the overall lack of focus on IP telephony security," said Lawrence Orans, Gartner analyst for VoIP Security. "The limited number of high-profile attacks against IP telephony has lulled most chief information security officers and voice/data managers into a false sense of security, with the result that most do not have adequate protection for their converged
networks."

About VoIPshield Systems

VoIPshield Systems Inc. was recently named one of five "Cool Vendors in Infrastructure Protection for 2008" by Gartner. VoIPshield develops products to secure voice communications on IP networks. Each security application uses VoIPshield's proprietary database of VoIP-specific vulnerabilities and corresponding threat signatures, developed by VoIPshield Laboratories. VoIPaudit(TM) is an award-winning VoIP Vulnerability Assessment product. VoIPguard(TM) is the industry's most comprehensive VoIP Intrusion Prevention System (VIPS) based on signature-based and behavior-based detection technology. More information is available at http://www.voipshield.com.




Other articles
2009/11/3 14:55:39 - BitDefender Top Ten Malware Threats for October 09
2009/11/3 14:29:38 - Nov. 09 Microsoft Security Intelligence Report
2009/10/7 15:19:17 - StopSign AntiVirus and Anti-Malware is Windows 7 Compatible
2009/10/7 15:11:26 - New Outlook Backup and Migration Software By Disk Doctors
2009/9/30 4:20:57 - Microsoft Security Essentials, FREE Security Tool Just Released
2009/9/28 14:31:52 - New Rogue Antispyware Cloaked To Infects Computers
2009/9/9 4:31:49 - Trend Micro Proves Leadership in URL Filtering and Web Security
2009/9/9 4:16:20 - New Free Tool to Clean Conficker Once and For All
2009/9/1 8:37:11 - Kaspersky Internet Security 2010 and Kaspersky Anti-Virus 2010 Out Now
2009/9/1 7:54:50 - NEW P2P Advertising Network Protects Users Against Lawsuits And Identity Theft

The comments are owned by the poster. We aren't responsible for their content.