Hackers Can Tap Into Vonage Lines, Says Security Firm

By Ed Oswald | Published October 25, 2007, 12:34 PM

A security firm disclosed Wednesday that a security hole in Vonage's VoIP system could allow an attacker to reroute and effectively hijack phone calls.

"This leaves the Vonage customer subject to spam, social engineering vulnerabilities, and scams," reads a security advisory issued yesterday by Sipera Systems, a relatively unknown VoIP security firm out of Richardson, Texas. The company said it had alerted Vonage to the problem over a month ago, however it never received a response.

While not necessarily a large security threat, the issue still shows that the beleaguered VoIP providers security measures may not be going far enough to ensure that calls made through the service are indeed making it to their intended recipient.

Sipera says it also found problems in services offered by Globe7 and Grandstream, although the Vonage issue affects the most people. Through that, the Vonage Phone Adapter VT 2142-VD is specifically said to have the issue.

Along with the VoIP hijacking issue, an attacker could also send multiple SIP INVITE messages, which would cause an internet version of "ringing the phone off the hook," Sipera said.

"These vulnerabilities create serious privacy and service availability issues for users," Sipera founder and CTO Krishna Kurapati said in a statement. ""Vonage, Globe7 and Grandstream customers can no longer assume that their VoIP providers are automatically securing their services."

With European VoIP provider Globe7, Sipera found holes in its online account access, and Grandstream's HandyTone-488 PSTN-to-VoIP adapter was found to be vulnerable to buffer overflows and fragmented packet attacks.

Comments

View comments by with a score of at least

this company has no luck

Score: 0

|

They have plenty it seems. Too bad it's all bad...

Score: 0

|

Guys, it may indeed seem that way, however, for folks who're old enough (such as me) to remember the early days of what's now known as the IT Industry, Vonage's troubles are just par for the course, don't despair, all will be fine. Good day.

Score: 0

|

yes indeed...it is a sad day for vonage..

Score: 0

|

Will Firefox beat IE9 to Direct2D rendering?

Just days after Microsoft executives gave conference attendees a peek at a new rendering technology, a Mozilla contributor revealed he's working on the same thing.

AOL's decision to rebrand as Aol. takes a bad brand and makes it worse

The idea behind the social Web is to crowd source before bringing out something new. But not at AOL, which new logo debuted with a cry of "fail!" across the blogosphere and Twittersphere today.

Microsoft's Bob Muglia and Ray Ozzie on Silverlight vs. standards

Bob Muglia: "We're trying to provide people with an environment that has capabilities that you just simply can't do today in the standards-based world."

Uh-oh, netbooks -- not Windows 7 -- will lift 2009 PC sales

Santa may bring a lump of coal to the Windows PC industry this holiday season. Netbook sales will sap PC margins, while weak Windows 7 PC sales could further drive down average selling prices.

A case study in improving software: What Office 2010 can learn from Notion 3

A music composition product gambles with a complete overhaul, in an effort to make headway against two well-known competitors in a tough market.

Kindle 2 update adds battery life, native PDF reader

Amazon has pushed out an update to the Kindle 2 e-reader that lengthens battery life and adds a native PDF viewer.

Safari on iPhone gets competition from a $1 browser app

Apple likes to say it gives iPhone users a full browsing experience, but a new competitor tries to incorporate more desktop browser features.

Action Replay maker sues Microsoft for Xbox 360 'predatory technological barriers'

Third-party video game accessory maker Datel has filed an antitrust lawsuit against Microsoft over the Xbox 360's recent Dashboard update.

Where there's smoke: Apple warranty stance raises troubling questions

Carmi Levy | Wide Angle Zoom: Smoking can be dangerous not only for your lungs, it appears, but for your Apple hardware warranty.

Microsoft's .NET Micro Framework is now free and open source

The latest version of Microsoft's .NET Micro framework is now in the hands of the FOSS community.

Google's value proposition for Chrome OS: Should we feel insulted?

For a search engine that has direct access to all the world's online history, it appears to have taught Google nothing about selling a machine.