Category Archives: Podcasts

Telecom Junkies podcast: Interview with a VoIP Hacker (Robert Moore of the Pena/Moore voip fraud case)

imageRemember the Pena/Moore voip fraud case back in June 2006? Would you like to know how the attacks were done?  And how you can protect your network?

First, for those who don’t recall, this was a case where Edwin Pena was alleged to have set himself up as a voice service provider and then, with the assistance of a developer named Robert Moore, routed his customer’s calls across the networks of other VoIP service providers.  Pena is alleged to have stolen at least 10 million minutes from other voice service providers and made in excess of $1 million dollars. Pena subsequently fled the country (and remains even today a fugitive).  We wrote about it here and also covered it in Blue Box podcasts #31 and #33 and I was a guest on a Telecom Junkies podcast back in July 2006 discussing the case.

In any event, one year later Robert Moore has been convicted for his part in the scheme and on July 24th was sentenced to a two-year term in prison, 3 years probation and a $150+K fine.  

Before he reports to prison in about 6 weeks, though, Moore got in contact with Jason Huffman from The Voice Report to ask if Jason was interested in an interview.  Given my prior involvement with the Telecom Junkies podcast, Jason contacted me to see if I would also be interested in coming onto the show.  Both he and I were concerned about interviewing someone recently convicted (i.e. not wanting to glorify the crime or criminal), but I shared Jason’s view that if we could obtain information about how the attacks were done we could potentially help people protect their systems against these type of attacks.  (Jonathan was also invited and provided great feedback but was unable to attend due to scheduling issues.)

The result is a new Telecom Junkies podcast: “Interview with a VoIP Hacker” which is available for download.

As we’d discussed in our previous coverage of the case, there were really two different types of systems that were attacked:

  1. Voice gateways of VoIP service providers
  2. Servers/routers of other businesses that were compromised to hide the source of traffic going to the voice gateways

In the interview, Robert Moore confirms that all the voice gateway attacks were H.323 (no SIP was involved) and they weren’t terribly sophisticated because the VoIP service providers didn’t have all that much security in place.

Moore also indicates that all the other boxes (#2) were compromised primarily by easy means such as weak and easily guessable passwords – or even worse, unchanged default passwords.  In some cases, there were boxes on the Internet with exposed SNMP ports that then let the attackers learn all about the box so that they could then research potential vulnerabilities.  This part really had nothing whatsoever to do with VoIP but instead with really just basic IT security practices which were (and undoubtedly still are) very obviously not being followed by many folks out there. 

In any event, the interview is now available for listening.  Meanwhile, Moore is soon heading off to prison and Pena is still somewhere out there…

P.S. If anyone listening can identify the name of the second switch vendor that Moore indicates he went after, neither Jason nor I could identify it despite my request for the name to be repeated.

UPDATE: Thank you to all who responded (including Robert’s sister here in the comments). The other switch was a Quintum Tenor – http://www.quintum.com/

Blue Box #63: Cisco and Asterisk VoIP vulnerabilities, the "Athens affair" (Greek wiretapping), iPhones and Duke, IETF and SPIT, SunRocket flares out, Skype phishing, VoIP security news and more…

Synopsis: Blue Box #63: Cisco and Asterisk VoIP vulnerabilities, the “Athens affair” (Greek wiretapping), iPhones and Duke, IETF and SPIT, SunRocket flares out, Skype phishing, VoIP security news and more…


Welcome to Blue Box: The VoIP Security Podcast #63, a 38-minute podcast  from Dan York and Jonathan Zar covering VoIP security news, comments and opinions.   

Download the show here (MP3, 18MB) or subscribe to the RSS feed to download the show automatically. 

You may also listen to this podcast right now:

Show Content:

Comments, suggestions and feedback are welcome either as replies to this post  or via e-mail to blueboxpodcast@gmail.com.  Audio comments sent as attached MP3 files are definitely welcome and will be played in future shows.  You may also call the listener comment line at either +1-206-350-2583 or via SIP to ‘bluebox@voipuser.org‘ to leave a comment there. 

Thank you for listening and please do let us know what you think of the show.

Blue Box #62: CAPTCHA for SPIT, covert channels, SIP Identity, is VoIP safe?, Fiji, Google, VoIP security news and more

Synopsis: Blue Box #62: CAPTCHA for SPIT, covert channels, SIP Identity, is VoIP safe?, Fiji, Google, VoIP security news and more


Welcome to Blue Box: The VoIP Security Podcast #62, a 41-minute podcast  from Dan York and Jonathan Zar covering VoIP security news, comments and opinions.   

Download the show here (MP3, 19MB) or subscribe to the RSS feed to download the show automatically. 

You may also listen to this podcast right now:


Note: Originally recorded back on July 6th.  There were some, well, "challenges" with the quality of the recording and so post-production took far longer than usual and you will still hear some audio artifacts every once in a while when Jonathan is speaking.


Show Content:

Comments, suggestions and feedback are welcome either as replies to this post  or via e-mail to blueboxpodcast@gmail.com.  Audio comments sent as attached MP3 files are definitely welcome and will be played in future shows.  You may also call the listener comment line at either +1-206-350-2583 or via SIP to ‘bluebox@voipuser.org‘ to leave a comment there. 

Thank you for listening and please do let us know what you think of the show.

Blue Box Special Edition #18: Session Border Controllers (SBCs) – Interviews with Covergence and Borderware about the SBC

Synopsis: Session Border Controller (SBC) Special – Martyn Davies interviews Rod Hodgman from Covergence and Jeff Carr from Borderware about their products and the role of the SBC.


Welcome to Blue Box: The VoIP Security Podcast Special Edition #18, a 33-minute podcast of interviews by Martyn Davies of Rod Hodgman from Covergence and Jeff Carr from Borderware about their products and the role of the SBC and the question "Do SBCs break the rules of SIP?"

Download the show here (MP3, 15MB) or subscribe to the RSS feed to download the show automatically.

You may also listen to this podcast right now:


Show Content:

This Session Border Controller (SBC) special
features two back-to-back interviews with Rod Hodgman from Covergence (www.covergence.com) and Jeff Carr from
Borderware (www.borderware.com).

In the first interview, Martyn Davies speaks
to Rod Hodgman, VP of Marketing at Covergence, about their SBC product
line, Eclipse.  Rod talks about SBCs that support peering and access edge
applications, and then focuses on access edge features such as NAT traversal and
DoS protection.  The discussion also covers software vs. appliance; OS
hardening, ATCA and media acceleration.  Rod answers the question "do SBCs
break the rules of SIP?", and tells us a user story.

In the second part, Martyn speaks to Jeff Carr, VP of the SIP Solutions Group at Borderware, about their software SBC, SIPAssure.  Jeff talks about the access edge, SPIT (Internet Telephony SPAM): content filtering and reputation management; firewall vs. SBC.  He also tackles the question "do SBCs break the rules of SIP?", and goes on to tell us a story about one of their OEM customers.

We thank Martyn for contributing these interviews.

Comments, suggestions and feedback are welcome either as replies to this post  or via e-mail to blueboxpodcast@gmail.com.  Audio comments sent as attached MP3 files are definitely welcome and will be played in future shows.  You may also call the listener comment line at either +1-206-350-2583 or via SIP to ‘bluebox@voipuser.org‘ to leave a comment there.

Thank you for listening and please do let us know what you think of the show.

(P.S. In the spirit of full disclosure, I’ll note that one of the customer stories turns out to be my employer, but I had no clue about that as this was entirely Martyn’s production.)

Blue Box #61: IETF framework to fight SPIT, VoIP security video, new tools, voip security news, listener comments and only a brief mention of the iPhone

Synopsis: Blue Box #61: IETF framework to fight SPIT, VoIP security video, new tools, voip security news, listener comments and only a brief mention of the iPhone


Welcome to Blue Box: The VoIP Security Podcast #61, a 29-minute podcast  from Dan York and Jonathan Zar covering VoIP security news, comments and opinions.   

Download the show here (MP3) or subscribe to the RSS feed to download the show automatically. 

You may also listen to this podcast right now:


Show Content:

Comments, suggestions and feedback are welcome either as replies to this post  or via e-mail to blueboxpodcast@gmail.com.  Audio comments sent as attached MP3 files are definitely welcome and will be played in future shows.  You may also call the listener comment line at either +1-206-350-2583 or via SIP to ‘bluebox@voipuser.org‘ to leave a comment there. 

Thank you for listening and please do let us know what you think of the show.

Blue Box #60: new VoIP security offerings from CheckPoint, VoIPShield, VoIP and business continuity, CALEA, new VoIP Security book, NAC mini-tutorial, more on botnets, listener comments and more

Synopsis: Blue Box #60: new VoIP security offerings from CheckPoint, VoIPShield, VoIP and business continuity, CALEA, new VoIP Security book, NAC mini-tutorial, more on botnets, listener comments and more


Welcome to Blue Box: The VoIP Security Podcast #60, a 28-minute podcast  from Dan York and Jonathan Zar covering VoIP security news, comments and opinions.   

Download the show here (MP3) or subscribe to the RSS feed to download the show automatically. 

You may also listen to this podcast right now:


Show Content:

Comments, suggestions and feedback are welcome either as replies to this post  or via e-mail to blueboxpodcast@gmail.com.  Audio comments sent as attached MP3 files are definitely welcome and will be played in future shows.  You may also call the listener comment line at either +1-206-350-2583 or via SIP to ‘bluebox@voipuser.org‘ to leave a comment there. 

Thank you for listening and please do let us know what you think of the show.

Blue Box #59: 802.1X mini-tutorial, new VoIP security vulnerabilities, new security tools, the biggest threat to VoIP? … botnets hitting Estonia… and chimichangas and sushi trains…

Synopsis: 802.1X mini-tutorial, new VoIP security vulnerabilities, new security tools, the biggest threat to VoIP? … botnets hitting Estonia…  and chimichangas and sushi trains…


Welcome to Blue Box: The VoIP Security Podcast #59, a 55-minute podcast  from Dan York and Jonathan Zar covering VoIP security news, comments and opinions.   

Download the show here (MP3, 24MB) or subscribe to the RSS feed to download the show automatically. 

You may also listen to this podcast right now:


Show Content:

Comments, suggestions and feedback are welcome either as replies to this post  or via e-mail to blueboxpodcast@gmail.com.  Audio comments sent as attached MP3 files are definitely welcome and will be played in future shows.  You may also call the listener comment line at either +1-206-350-2583 or via SIP to ‘bluebox@voipuser.org‘ to leave a comment there. 

Thank you for listening and please do let us know what you think of the show.

Blue Box #58: The SIP Botnet edition – VoIP bots are here, now what? Also rogue firmware mini-tutorial, other VoIP security news, listener comments, more…

Synopsis: The SIP Botnet edition – VoIP bots are here, now what?  Also rogue firmware mini-tutorial, other VoIP security news, listener comments, more…


Welcome to Blue Box: The VoIP Security Podcast #58, a 35-minute podcast  from Dan York and Jonathan Zar covering VoIP security news, comments and opinions.   

Download the show here (MP3, 14MB) or subscribe to the RSS feed to download the show automatically. 

You may also listen to this podcast right now:


Show Content:

Comments, suggestions and feedback are welcome either as replies to this post  or via e-mail to blueboxpodcast@gmail.com.  Audio comments sent as attached MP3 files are definitely welcome and will be played in future shows.  You may also call the listener comment line at either +1-206-350-2583 or via SIP to ‘bluebox@voipuser.org‘ to leave a comment there. 

Thank you for listening and please do let us know what you think of the show.

Blue Box #57: Call signaling encryption mini-tutorial, VoIP eavesdropping, VoIP security news, listener comments and men in white vans…

Synopsis: Call signaling encryption mini-tutorial, VoIP eavesdropping, VoIP security news, listener comments and men in white vans…


Welcome to Blue Box: The VoIP Security Podcast #57, a 35-minute podcast  from Dan York and Jonathan Zar covering VoIP security news, comments and opinions.   

Download the show here (MP3, 18MB) or subscribe to the RSS feed to download the show automatically. 

You may also listen to this podcast right now:


Show Content:

(Time codes were lost in a browser crash and will be added back in the future.)

     

Comments, suggestions and feedback are welcome either as replies to this post  or via e-mail to blueboxpodcast@gmail.com.  Audio comments sent as attached MP3 files are definitely welcome and will be played in future shows.  You may also call the listener comment line at either +1-206-350-2583 or via SIP to ‘bluebox@voipuser.org‘ to leave a comment there. 

Thank you for listening and please do let us know what you think of the show.

Blue Box #56 – Voice encryption tutorial, Skype worm, McAfee’s Sage Journal, Zfone, VoIP security news, listener comments and more…

Synopsis: Voice encryption tutorial, Skype worm, McAfee’s Sage Journal, Zfone, VoIP security news, listener comments and more… 


UPDATE – April 24: Unfortunately, due to an error in coding the appropriate enclosure (now fixed) many of you who subscribe via RSS will have downloaded a PDF file instead of the MP3 file. My apologies, and you’ll need to unfortunately download the file directly from the website at this point.


Welcome to Blue Box: The VoIP Security Podcast #56, a 38-minute podcast  from Dan York and Jonathan Zar covering VoIP security news, comments and opinions.   

Download the show here (MP3, 18MB) or subscribe to the RSS feed to download the show automatically. 

You may also listen to this podcast right now:


Show Content:

Comments, suggestions and feedback are welcome either as replies to this post  or via e-mail to blueboxpodcast@gmail.com.  Audio comments sent as attached MP3 files are definitely welcome and will be played in future shows.  You may also call the listener comment line at either +1-206-350-2583 or via SIP to ‘bluebox@voipuser.org‘ to leave a comment there. 

Thank you for listening and please do let us know what you think of the show.