Affichage des articles dont le libellé est VoIP. Afficher tous les articles
Affichage des articles dont le libellé est VoIP. Afficher tous les articles

vendredi 25 juillet 2008

About phones

Hi all.

Using SJPhone, I have found a serious drawback. It is not capable of using my SIP freephonie.net account through a nat'ed router. Too bad.

Last week, my SIP hard phone failed to get a carrier. I used my soft phone to make calls. X-Lite works like a charm using my freebox in router mode. SJPhone not.

I am not sure it is only a SJPhone problem, because it works with voxalot, pulver.com. So ?

In fact, the only thing I am sure, it is that you always must test any VoIP equipment (phone, router, SBC, firewall, ...) deeply before adopting it.

The VoIP protocols are so complex that between two architecture, there is probably something that is not supported :-)

mercredi 25 juin 2008

VoIP is so exciting

Back to VoIP testing.

I (re)tested SJPhone 1.65 at home. It is a very good softphone.

But it has a annoying drawback: it can only register to one account at a time. I currently have freephonie.net, VoXaLot (eu), and FreeWorldDialup account. I only can register one !

So, I cannot use my enum number if I am always (almost always) registered through FWD. Too bad.

I tried gtalk, but it cannot send Video (works fine with audio, but my friends tell audio quality is worst than skype).

The solution is a Linux one (but I have not tested it yet): Ekiga. Multiple account registration, video, audio, SIP+H323 ! wonderful. But I do not use Linux at home (FreeBSD or Windows ...)

So, the ultimate solution is an Asterisk SOHO box dedicated to VoIP management.

I received an email (through sip-implementors ML) which announce pingtel opens a new SIP testing PBX gateway. Good thing. Not only for SIP implementors, but also for Security developer who needs to check that their control are not too rigorous. Good initiative.

mercredi 16 avril 2008

Stop global warming

I didn't know that link. One of my friend added it to its blog:
http://www.blueman.com/land/archive/earth/

Great !!


(while reading my mailbox, i read that: Quarterly VoIP vulnerability summary
You may discover that:
- old Cisco 7940/7960 phones still have security issues
- recent phones (snom ...) still have big security issues ..

I am afraid by the situation ;-)
)

lundi 14 avril 2008

Web Review : 14/04/2008

Almost one month from my last web review. I was very busy building my house :-)

So, what are the coolest project I have found:

- MathGL : something nice. It allows to generate nice graph, in 2D, 3D. The most interesting feature (well, not the most, but an interesting feature, sure) is the MGL scripting language, which allow a shell script to generate a JPG/EPS/SVG/PNG/anyOtherFormat graphic. [http://mathgl.sourceforge.net/index.html]

- GreenSQL : it may be very interesting for security. It is a MySQL application level gateway. It does for MySQL what a web filtering proxy do for HTTP. I took a look at the demo. If it work as presented, It is a very interesting project ! [http://www.greensql.net/]

- Because security is only a protection, you have to make backups. And if possible, automatic backup. This project seems to do the right job, local or network (through ssh).. zbackup-mysql [http://www.zmanda.com/backup-mysql.html]

- On a previous post, I talk about insecurity of VoIP clear voice stream. Give someone Dtmf2num, and dial your bank count access code with your prefered VoIP phone. You may be surprised ;-) dtmf2num

- Two of my friends will be very interested by the following: SMART [http://smart.conformix.com/]. This is a tool to manager security policy and its associated workflow. It looks cute ... (as long as security is cute ...)

- For those who are developing cross application (by cross, I mean Linux/Window*), check that: I'm a cross .... You should enjoy this one !

That's all folks !!

jeudi 28 février 2008

Web Review : 28/02/2008

For those who knows VOMIT (Voice Over Misconfigured Internet Telephones), take a read at RTP Break. I have not enough time to test it by myself, but if it does all that is written, It should be ... hum .. .quite interesting ! => http://xenion.antifork.org/rtpbreak/


But (for me) the most important new today is "FreeBSD 7.0 RELEASED" !! http://www.freebsd.org/releases/7.0R/announce.html

jeudi 21 février 2008

Web Review : 21/02/2008

I spent some time reading publikations located at http://www.snocer.org/. It is very interesting. It is about VoIP security.

mercredi 13 février 2008

Web Review : 13/02/2008

One of my friend sent me a good article on "Who Invented the Firewall ?"
For me, I consider that M.J. Ranum is the father of firewalling as we know it today.
I have worked for 7 years on *-gw proxies, then on *-pdk (for those who know). I rewrote smap/smapd, improved http-pdk and so on.
Until now, I am still working on a firewall software editor, and MJ Ranum concepts are still up to date. I do not say that other were not doing security, but who could say "packet filtering module is a firewall module" ?
Using authentication daemon of TIS you can add a usefull value to security: "who is doing what ?"
Today, firewalling, as I can see, is not as good as it could be.
The ultimate firewall solution should be a description not of host using ports, but users using services.
It is easier to tell: "allow Alice to contact Bob over XMPP" than "allow from 10.0.0.1 to bob.domain.tld port 5222 keep-state"
NuFW/EdenWall seems great for this. It is not a finished project yet, compared with some great closed products, but the right idea is here.

During my web review, I have seen the following announce: SignServer project 4.0 is released. http://www.signserver.org/. It looks very interesting. And it shows me that apache project as its own mail server ?! James ... googlize it !

(Last week was very rich !!)
This is a interesting post about FreeBSD 4->5->6->7 releases, and why some of Linux gurus are telling "FreeBSD sucks". Well, I do not want to say that "FreeBSD is better than Linux" or "Linux is a *BSD killer" (but it is not :-). Take a look at Truth on FreeBSD 5.x releases". I am very proud of FreeBSD developers, because I love FreeBSD, much more than the hundreds of Linux distros. And Explanations given here are the real world on project management. I encountered almost every day at my own job !


Some fun: http://icanhascheezburger.com/

VoIP security news:
Sipera 5 threats in 2008: VoIP Security Threat Predictions
Let's see....

samedi 26 janvier 2008

VoIP security

Lors de mes peregrinations, je suis tombé sur ce billet de blog:
http://pelloopback.blogspot.com/2007/11/trixbox-x-lite-et-un-peu-de-scurit.html
Bonne introduction aux problèmes VoIP. Je rappelle que le doc cité dans un billet précédent est plus interessant pour les concepts, mais ce billet est plus pragmatique, voire terre à terre. Bref, ca vaut le coup d'oeil.

samedi 12 janvier 2008

VoIP SANS doc

SANS published last week a "MUST READ" document about common VoIP
vulnerabilities.
As usual, I know 90% of what is written.
But, I didn't know how easy is to find information about VoIP system
installed in corporate networks.
Thank you google ! I really was impressed by "inurl:" power in requests !

SANS VoIP vulnerability on VOIPSA list:
http://voipsa.org/pipermail/voipsec_voipsa.org/2008-January/002554.html