Featured Resources:

line

Newsletter

Email Address:


line

Ask the Expert

Have a question for our resident expert? Email your questions to Ken.

« Hendrik Scholz - More VoIP from Blackhat | Main | Skype Certifies McAfee - It's All About Spin »

Cisco at BlackHat - VoIP Zero Day Potential

This from Blackhat via SearchSecurity.com.

Note. Hendrik Scholz mentioned here stopped by and commented, mentioning his talk. I just managed to find a bit of time to catch up and add a lttle more information here

Possible Cisco zero-day exploit revealed at Black Hat
Update: LAS VEGAS -- Controversy looms for Cisco once again at Black Hat, as information revealed Wednesday could lead to another significant zero-day vulnerability and exploit.

Hendrik Scholz, lead VoIP developer and systems engineer with Freenet Cityline of Germany, saved the best for last during his Black Hat USA 2006 presentation Wednesday on SIP stack fingerprinting and attacks. His final slide appeared to featured limited details on an undisclosed flaw related to Session Initiation Protocol (SIP) in Cisco Systems Inc. PIX series of firewalls and security appliances.

According to Mike Caudill and Jeffrey Lanza, incident managers with Cisco's Product Security Incident Response Team (PSIRT), the networking giant is unsure whether the details describe a vulnerability or a misconfiguration.


Technorati Tags: , , , ,

Post a comment

(All comments are approved by site leader before appearing here. Thanks for commenting!)

line

Ken Camp's Bio:

Ken Camp has more than 25 years of experience in information technology. Ken spent 17 years with AT&T and Lucent Technologies successfully designing and implementing voice and data networks. He later worked in the security marketplace and played a key role in early IPSec VPN deployments. As an independent consultant, Ken's primary focal areas include network performance improvement, security practices and the design and deployment of integrated voice and data solutions. He may be contacted at: ken_camp@realtimepublishers.net

line

Blog Roll