This is voipsecurityblog's TypePad Profile.
Join TypePad and start following voipsecurityblog's activity
Join Now!
Already a member? Sign In
voipsecurityblog
I am a 50 year old, married, guy with four daughters, computer security professional.
Interests: my family, poker, exercise, hacking UC/VoIP
Recent Activity
Here is a video describing a Dial Through Fraud (DTF) attack. DTF is a form of toll fraud, there the attacker dials into a compromised PBX, gains dial tone, and then dials a new destination, usually an international number. They... Continue reading
Posted Apr 12, 2013 at Mark Collier's VoIP/UC Security Blog
Here is a brief white paper by SecureLogix on Telephony Denial of Servie (TDoS). Check it out. Download TDoS_paper_4-11-13 Continue reading
Posted Apr 11, 2013 at Mark Collier's VoIP/UC Security Blog
There have been a number of additional bulletins warning of Telephony Denial of Service (TDoS) attacks on 911 centers. Below is a summary of the bulletins I am aware of. If anyone knows of any others, please let me know... Continue reading
Posted Apr 4, 2013 at Mark Collier's VoIP/UC Security Blog
I am going to write a series of posts on Telephony Denial of Service (TDoS). I thought I would start with a brief description of how attackers actually generate automated TDoS attacks. I will follow up with other techniques, info... Continue reading
Posted Apr 4, 2013 at Mark Collier's VoIP/UC Security Blog
There has been a ton of press lately about Telephony Denial of Service (TDoS). There are real attacks occuring against 911 centers and financial contact centers. The targets are getting flooded with malicious calls that prevent legitmate users from accessing... Continue reading
Posted Apr 2, 2013 at Mark Collier's VoIP/UC Security Blog
I did a question and answer article for the folks at Connect Converge, on the topic of VoIP/UC security, check it out at: http://www.connect-converge.com/Spring_2013/#?page=34 Continue reading
Posted Mar 31, 2013 at Mark Collier's VoIP/UC Security Blog
Here is yet another article about toll fraud. This one makes a particularly scary point - that being that toll fraud can seriously affect, even put SME's out of business is a very short amount of time. Toll fraud can... Continue reading
Posted Mar 26, 2013 at Mark Collier's VoIP/UC Security Blog
Image
SecureLogix just released our 2013 Voice and Unified Communications State of Security Report. Rod Wallace and myself authored the report. The report covers the most significant voice and UC threats. the report describes the threats and why they have recently... Continue reading
Posted Mar 26, 2013 at Mark Collier's VoIP/UC Security Blog
The Comunications Fraud Control Association (CFCA) publised a link to a bulletin from the Department of Homeland Security (DHS) NCCIC. The bulletin describes threats and TDoS attacks against 911 emergency services. Apparently the attacker targets an administrative Public Safety Answering... Continue reading
Posted Mar 25, 2013 at Mark Collier's VoIP/UC Security Blog
Brian Krebs, a well know security expert, experienced a SWATing attack. For anyone not familiar with this term, the idea is simply that you call 911 and state that there is an emergency that requires a SWAT team to intervene.... Continue reading
Posted Mar 25, 2013 at Mark Collier's VoIP/UC Security Blog
There has been a lot of press about major companies twitter accounts being hacked and used to send out embarassing messages. If one is able to hack into any twitter account, such as a major brand, celebrity, politician, etc., especially... Continue reading
Posted Feb 28, 2013 at Mark Collier's VoIP/UC Security Blog
As I have reported, the FTC has a challenge and $50,000 award for whoever can come up with the best solution to the issue of robocalls. Here is a link to an article that gives a good summary of the... Continue reading
Posted Feb 21, 2013 at Mark Collier's VoIP/UC Security Blog
I will be speaking at the Enterprise Connect conference this year, March 18-21 on the topic of UC security. Our session is on Thursday at 10:00. If you are attending, please check it out: http://www.enterpriseconnect.com/orlando/conference/overview.php Continue reading
Posted Feb 21, 2013 at Mark Collier's VoIP/UC Security Blog
By now most everyone has seen all the press surrounding security issues with Cisco UC/VoIP phones. I need to post some links and comment on this issue. For now, Cisco has released a security advisory for the issue that you... Continue reading
Posted Jan 14, 2013 at Mark Collier's VoIP/UC Security Blog
Here is some information on a number of toll fraud attacks against small business in New York. There are indications that the attacks were perpetrated by Al Qaeda. New York Senator Charles Schumer held a press conference to highlight issues.... Continue reading
Posted Jan 10, 2013 at Mark Collier's VoIP/UC Security Blog
Here are a couple of links to the FBI IC3 page and an article in Newsweek about some recent forms of TDoS attacks. TDoS attacks are being used as cover and also for "coersion" - hammering a consumer or enterprise... Continue reading
Posted Jan 8, 2013 at Mark Collier's VoIP/UC Security Blog
Image
Here is a link to an article where Communicates Regulator warns businesses that phone hacking (toll fraud) will be increasing over the holidays. Makes sense - lots of business will shut down over the holidays, but the hackers won't. Businesses... Continue reading
Posted Dec 27, 2012 at Mark Collier's VoIP/UC Security Blog
Here is a link to a petition to the FCC, from a bit-time spammer, to request that service providers do not block political voice SPAM and texts. This is laughable. Enterprises, businesses, and consumers absolutely need the ability to block... Continue reading
Posted Dec 19, 2012 at Mark Collier's VoIP/UC Security Blog
Here is a link to an article covering a couple of vulnerabilities with Cisco VoIP phones. http://www.darkreading.com/threat-intelligence/167901121/security/attacks-breaches/240144378/security-researcher-compromises-cisco-voip-phones-with-vulnerability.html Continue reading
Posted Dec 19, 2012 at Mark Collier's VoIP/UC Security Blog
Here is a recent article on toll fraud on mobile devices. The article states that the most common type of mobile malware is toll fraud - this type of malware is the easiest way to make money: http://www.cnbc.com/id/100310988 Continue reading
Posted Dec 17, 2012 at Mark Collier's VoIP/UC Security Blog
Interesting article in Forbes about issues with eavesdropping on VoIP phones. Not new issues, but always interesting when a publication like Forbes picks this sort of issue up: http://www.forbes.com/sites/robertvamosi/2012/12/06/off-hook-voip-phone-security-vulnerability-affects-some-cisco-models/ Continue reading
Posted Dec 10, 2012 at Mark Collier's VoIP/UC Security Blog
Here is a link to a video from the recent Astricon on Telecom, voice, VoIP fraud: http://www.tmcnet.com/tmc/videos/default.aspx?vid=7499 Continue reading
Posted Dec 10, 2012 at Mark Collier's VoIP/UC Security Blog
Image
I posted an article a week ago covering the 8 most common UC security issues. http://voipsecurityblog.typepad.com/marks_voip_security_blog/2012/11/article-on-the-8-most-common-voipuc-security-issues.html After posting this, I thought it would be a good time to post MY OWN list of what see as the 8 most common... Continue reading
Posted Nov 26, 2012 at Mark Collier's VoIP/UC Security Blog
Here is a brief video showing how to exploit a UC phone to gather enough information, to allow different types of attacks on an IP PBX. http://www.youtube.com/watch?v=IPzSe36o7AI&feature=youtu.be Continue reading
Posted Nov 19, 2012 at Mark Collier's VoIP/UC Security Blog
Here is a link to a brief article on the top 8, most common VoIP/UC security issues. I do agree with some of this, although I would have included toll fraud and TDoS as issues: http://www.icciev.com/1/post/2012/11/8-most-common-voip-internet-security-threats.html Continue reading
Posted Nov 13, 2012 at Mark Collier's VoIP/UC Security Blog