Grab our RSS Feed Follow us via Email Follow us on Twitter

Categories

Security Extra



PBX systems being hit by buffer overflows
 Posted by secExtra on March 21st, 2008

PbxYou may soon find your computerised telephone switchboard (PBX) hit by a new wave of security flaws. This comes following a report by Fortify Software.

The news follows on from reports from the MU Security Research Team about security flaws in the Asterix range of IP-PBX software applications, which a growing number of companies are using to computerise their switchboards and take advantage of low cost Internet telephony calls.

“Recent reports suggest that as many as 50 per cent of major companies are using Internet telephony services as a way of cutting their telecommunications costs, but our analysis is that they also need to review their IP telephony security arrangements as well,” said Rob Rachwald, Fortify’s director of product marketing.

“The buffer overload problem in the RTP payload handling code when dealing with a malformed INVITE or SIM packet with SDP, is, we predict, one of several buffer-based security problems you’re going to see with company IP telephony systems in the near future,” he said.

“Most companies have installed multi-layered security technology on their computer network, but IP telephony services almost always escape the scrutiny of the IT security systems in place to protect a company’s computers and network technology,” he added.

At the moment, says Rachwald, IP-PBX hackers are confining their activities to crashing systems or causing a denial of service attack for mischievous purposes.

“That situation will change, we predict, as hackers from the criminal side of things start to realise the revenue potential from hacking into company PBXs and then hack for monetary gain from that route,” he said.


This entry was posted on Friday, March 21st, 2008 at 5:45 am and is filed under IT security. You can follow any responses to this entry through the RSS 2.0 feed. You can leave a response, or trackback from your own site.

Leave a Reply


It Outsourcing
Sometimes you need help. Check out how to have your systems running perfectly with IT outsourcing.

Laptop Repairs UK
Do you want fast, reliable laptop repairs in the UK? Then this is good news! Click here for info.

Radiolink
For expertise and advice on Radiolink Alarms and more, go to SDFireAlarms.co.uk.

Web Design Lancaster
Great Web Design from Lancaster Based Oporation ICT

Marcus Evans Scams
Prevent fraud in the financial sector by knowing all about scams. Visit Marcus Evans for more.

Marcus Evans Scams
Protect your business by attending a Marcus Evans scams and fraud avoidance training course