Hackers Can Tap Into Vonage Lines, Says Security Firm

By Ed Oswald | Published October 25, 2007, 12:34 PM

A security firm disclosed Wednesday that a security hole in Vonage's VoIP system could allow an attacker to reroute and effectively hijack phone calls.

"This leaves the Vonage customer subject to spam, social engineering vulnerabilities, and scams," reads a security advisory issued yesterday by Sipera Systems, a relatively unknown VoIP security firm out of Richardson, Texas. The company said it had alerted Vonage to the problem over a month ago, however it never received a response.

While not necessarily a large security threat, the issue still shows that the beleaguered VoIP providers security measures may not be going far enough to ensure that calls made through the service are indeed making it to their intended recipient.

Sipera says it also found problems in services offered by Globe7 and Grandstream, although the Vonage issue affects the most people. Through that, the Vonage Phone Adapter VT 2142-VD is specifically said to have the issue.

Along with the VoIP hijacking issue, an attacker could also send multiple SIP INVITE messages, which would cause an internet version of "ringing the phone off the hook," Sipera said.

"These vulnerabilities create serious privacy and service availability issues for users," Sipera founder and CTO Krishna Kurapati said in a statement. ""Vonage, Globe7 and Grandstream customers can no longer assume that their VoIP providers are automatically securing their services."

With European VoIP provider Globe7, Sipera found holes in its online account access, and Grandstream's HandyTone-488 PSTN-to-VoIP adapter was found to be vulnerable to buffer overflows and fragmented packet attacks.

Comments

View comments by with a score of at least

this company has no luck

Score: 0

|

They have plenty it seems. Too bad it's all bad...

Score: 0

|

Guys, it may indeed seem that way, however, for folks who're old enough (such as me) to remember the early days of what's now known as the IT Industry, Vonage's troubles are just par for the course, don't despair, all will be fine. Good day.

Score: 0

|

yes indeed...it is a sad day for vonage..

Score: 0

|

Breakthrough: AMD and Intel settle antitrust dispute, reach new cross-license agreement

UPDATED Only exclusionary business practices, not some rebates, may be covered by a new agreement on Intel's future business conduct.

Windows Marketplace for Mobile now available in browser, iTunes' App Store still not

You can now check out what Windows Marketplace for Mobile has to offer without a Windows Phone.

Microsoft damage control after marketer claims Win7 inspired by Mac

Have you ever said anything you wish you could take back? Ever? No? Not even once? Well then, you won't sympathize with a mid-level Microsoft manager today.

Facebook for iPhone developer goes from Apple supporter to 'I quit!' in 3 months

Fed up with Apple's App Store policies, the developer of Facebook for iPhone has bailed on the iPhone.

Google acquires Gizmo5, builds IP telephony portfolio

Google Voice today confirmed rumors that it would acquire IP telephony company Gizmo5

'A pivot from war to peace:' The AMD + Intel armistice, in their own words

An extraordinary day in technology history is recognized by two long-time rivals that mutually decided it's futile to fight anyplace else except the marketplace.

PS3, Xbox to soon get Twitter, Facebook integration

Both Microsoft's Xbox 360 and Sony's PlayStation 3 will integrate with Facebook in the near future.

The iTunes App Store at 100,000: Can we stop counting, already?

Carmi Levy | Wide Angle Zoom: Is a six-digit number truly reflective of a healthy applications ecosystem? Or is it another type of bloat?

Analysis: The end of business-by-litigation?

The AMD v. Intel case ended neither with a bang nor a whimper, but almost with a song. Is it catchy enough for the rest of the PC world to sing in perfect harmony?

The agreement: Intel and AMD 'wipe the slate clean'

As the Securities and Exchange Commission document shows, AMD did indeed make some compromises in favor of Intel, especially with regard to conduct.

EC still holds Intel accountable even after AMD settlement

Though the future of relations between AMD and Intel may be peaceful now, the EC believes Intel may still owe restitution for its past conduct.