innovaphone fixed several vulnerabilities in two
VoIP products that we disclosed a while ago. The affected products are the
Linux Application Platform
and the
IPVA.
Unfortunately, the release notes are not public (yet?) and the vendor does not
include information about the vulnerabilities for the Linux Application
Platform. Therefore, we decided to publish some more technical details for the
issues.
Multiple Vulnerabilities in Linux Application Platform
The Linux Application Platform was affected by three vulnerabilities that could
be chained to get full root access to a target system. However, the initial
access vector is only exploitable by authenticated users. The vulnerabilities
have been identified on the Linux Application Platform V10 SR41. According to
the vendor they have been fixed in
V10 SR57.
We recently identified security issues in the UNIFY OpenScape Desk Phone CP600
HFA software. We disclosed the vulnerabilities to Unify, as a fix is now
provided we want to give a brief overview of the vulnerability affecting the web
interface.
We were able to identify the following vulnerabilities in the Web interface of
the telephone:
Command Injection in Picture Delete function of OpenScape Desk Phone Webportal
Unauthenticated Arbitrary File Access in the OpenScape Desk Phone Webportal
Memory Corruption in the OpenScape Desk Phone Webservice
Missing Hardening of the OpenScape Desk Phone Webservice Binary
Cross Site Request Forgery Missing in the OpenScape Desk Phone Webservice
T-mobile pioneered with the native seamless support for WiFi calling technology
embedded within the smartphones. This integrated WiFi calling feature is adopted
by most major providers as well as many smartphones today. T-mobile introduced
VoWiFi in Germany in May 2016. You can make voice calls that allows to switch
between LTE and WiFi networks seamlessly. This post is going to be about
security analysis of Voice over WiFi (VoWiFi), another name for WiFi calling,
from the user end. Before we get started, let me warn you in advance. If you are
not familiar with telecommunication network protocols, then you might get lost
in the heavy usage of acronyms and abbreviations. I am sorry about that. But
trust me, after a while, you get used to it 🙂 .
I am little bit late to the party, but I had the pleasure to present a talk
about VoIP based toll fraud incidents (more on this in a following blogpost, for
the moment my slides can be found
here) at the
annual t2 security conference in Helsinki. The conference took
place from 24th to 25th October in the Radisson Blu Royal hotel. I must say that
it was a blast. Tomi (the host) took really good care of all speakers, and I
really liked the spirit of the conference, very similar to
Troopers. It is not an commercial event, seats are
limited to 100 and it is all about delivering a
great set of talks to the audience and having a
good time during and after the conference. Sure the conference has some sponsors
and tickets are sold, but Tomi doesn’t do it to earn money. His only intention
is to cover the cost for setting up this great event.
The CTL is basically a binary TLV file with 1 byte type, followed by 2 bytes
length and finally the data. But as this is far to easy, some special fields
omit the length field and just place the data after the type (I guess those are
fields with a fixed length). Here is an example CTL file:
Some of you may have heard the topic before, as we have spoken about on this
years BlackHat Europe, TROOPERS12 and HES12,
so this is nothing completely new, but as we’re done with responsible disclosure
(finally (-; ) and all the stuff should be fixed, we’re going to publish the
code that brought us there. I will split the topic into two blog posts, this one
will wrap up the setup, used components and protocols, the next one [tbd. till
EOY, hopefully] will get into detail on the tools and techniques we used to
break the enterprise grade security.
2 AFFECTED PRODUCTS The following Products have been tested as vulnerable so far: Cisco Unified Meetingplace with the following modules: • MeetingPlace Agent 7.1.1.9 • MeetingPlace Audio Service 7.1.1.8 • MeetingPlace Gateway SIM 7.1.1.2 • MeetingPlace Replication Service 7.1.1.9 • MeetingPlace Master Service 7.1.1.8 • MeetingPlace Extension 7.1.1.8 • MeetingPlace Authentication Filter 7.1.1.8
3 DETAILS The following parameters are affected: http://$IP/mpweb/scripts/mpx.dll [POST Parameter wcRecurMtgID]
4 VULNERABILITY SCORING The severity rating based on CVSS Version 2: Base Vector: (AV:N / AC:L / Au:S / C:P / I:P / A:P) CVSS Version 2 Score: 6.5 Severity: Low
if you’re following this blog regularly or if you’ve ever attended an
ERNW-led workshop which included an
“architecture section” you will certainly remember the “Seven Sisters of
Infrastructure Security” stuff (used for example in
this post).
These are a number of (well, more precisely, it’s seven ;-)) fundamental
security principles which can be applied to any complex infrastructure, be that
a network, a building, an airport or the like.
As part of our upcoming
Black Hat
and
Troopers
talks we will apply those principles to some VoIP networks we (security-)
assessed and, given we won’t cover them in detail there, it might be helpful to
perform a quick refresher of them, together with an initial application to VoIP
deployments. Here we go; these are the “Seven Sisters of Infrastructure
Security”:
Hi everyone,
it’s me again with another story of a toll fraud incident at one of our
customers (not the same as
the last time
of course ;-)).
The story began basically like the last one: We received a call with an urgent
request to help investigating a toll fraud issue. Like the last time I visited
the site in order to get an idea on what was going on exactly. The customer has
a VoIP deployment consisting of the whole UC Suite Cisco offers: Call Manager,
Unity Connection for the voice mailboxes, Cisco based Voice-Gateways and of
course, IP phones.
One of our customers called us recently and asked for some support in
investigating a toll fraud issue they encountered in one of their sites. Their
telecommunications provider had contacted them informing them that they had
accumulated a bill of 30.000€ over the last ten days.
Without knowing anything more specific, I drove to the affected site to get the
whole picture.
They have a VoIP deployment based on Cisco Unified Communications Manager (CUCM,
aka Call Manager) as Call Agent. The CUCM is connected via a H.323 trunk to a
Cisco 2911 ISR G2 which is acting as a voice gateway. The ISR has a primary rate
ISDN (PRI) Interface which is connected to the PBX of the telco. Furthermore
they use a feature called Direct-inward Dial (DID) or Direct Dial-in (DDI) which
is offered by Telco’s to enable calling parties to dial directly to an extension
on a PBX or voice gateway.