Affichage des articles dont le libellé est security. Afficher tous les articles
Affichage des articles dont le libellé est security. Afficher tous les articles

vendredi 27 février 2009

Preshared key exchange

I have to exchange many sensible data with some partners. They are international phone companies.
But, no one knows about public/private key pairs, nor PGP/GPG.
All VPNs I set up are using PSK, no X.509 certificates.
Event gpg data are encrypted using symetric keys.
If someone knows why ?

mercredi 22 octobre 2008

mercredi 25 juin 2008

VoIP is so exciting

Back to VoIP testing.

I (re)tested SJPhone 1.65 at home. It is a very good softphone.

But it has a annoying drawback: it can only register to one account at a time. I currently have freephonie.net, VoXaLot (eu), and FreeWorldDialup account. I only can register one !

So, I cannot use my enum number if I am always (almost always) registered through FWD. Too bad.

I tried gtalk, but it cannot send Video (works fine with audio, but my friends tell audio quality is worst than skype).

The solution is a Linux one (but I have not tested it yet): Ekiga. Multiple account registration, video, audio, SIP+H323 ! wonderful. But I do not use Linux at home (FreeBSD or Windows ...)

So, the ultimate solution is an Asterisk SOHO box dedicated to VoIP management.

I received an email (through sip-implementors ML) which announce pingtel opens a new SIP testing PBX gateway. Good thing. Not only for SIP implementors, but also for Security developer who needs to check that their control are not too rigorous. Good initiative.

lundi 14 avril 2008

Web Review : 14/04/2008

Almost one month from my last web review. I was very busy building my house :-)

So, what are the coolest project I have found:

- MathGL : something nice. It allows to generate nice graph, in 2D, 3D. The most interesting feature (well, not the most, but an interesting feature, sure) is the MGL scripting language, which allow a shell script to generate a JPG/EPS/SVG/PNG/anyOtherFormat graphic. [http://mathgl.sourceforge.net/index.html]

- GreenSQL : it may be very interesting for security. It is a MySQL application level gateway. It does for MySQL what a web filtering proxy do for HTTP. I took a look at the demo. If it work as presented, It is a very interesting project ! [http://www.greensql.net/]

- Because security is only a protection, you have to make backups. And if possible, automatic backup. This project seems to do the right job, local or network (through ssh).. zbackup-mysql [http://www.zmanda.com/backup-mysql.html]

- On a previous post, I talk about insecurity of VoIP clear voice stream. Give someone Dtmf2num, and dial your bank count access code with your prefered VoIP phone. You may be surprised ;-) dtmf2num

- Two of my friends will be very interested by the following: SMART [http://smart.conformix.com/]. This is a tool to manager security policy and its associated workflow. It looks cute ... (as long as security is cute ...)

- For those who are developing cross application (by cross, I mean Linux/Window*), check that: I'm a cross .... You should enjoy this one !

That's all folks !!

jeudi 28 février 2008

Web Review : 28/02/2008

For those who knows VOMIT (Voice Over Misconfigured Internet Telephones), take a read at RTP Break. I have not enough time to test it by myself, but if it does all that is written, It should be ... hum .. .quite interesting ! => http://xenion.antifork.org/rtpbreak/


But (for me) the most important new today is "FreeBSD 7.0 RELEASED" !! http://www.freebsd.org/releases/7.0R/announce.html

jeudi 21 février 2008

Web Review : 21/02/2008

I spent some time reading publikations located at http://www.snocer.org/. It is very interesting. It is about VoIP security.

samedi 12 janvier 2008

VoIP SANS doc

SANS published last week a "MUST READ" document about common VoIP
vulnerabilities.
As usual, I know 90% of what is written.
But, I didn't know how easy is to find information about VoIP system
installed in corporate networks.
Thank you google ! I really was impressed by "inurl:" power in requests !

SANS VoIP vulnerability on VOIPSA list:
http://voipsa.org/pipermail/voipsec_voipsa.org/2008-January/002554.html