Preventing Exploitation of Your �VoIP Network
Rohit Dhamankar, Manager of Digital Vaccine�David Endler, Director of Security Research
TippingPoint, a division of 3Com
Agenda
Agenda
Introduction - VoIP Security is Holistic
Introduction - VoIP Threat Scenarios
Introduction – VoIP Introduces New Risks
Introduction – Obligatory VoIP Adoption Slide
Agenda
Enterprise VoIP Building Blocks
Enterprise VoIP Building Blocks
Agenda
VoIP Attacks - VoIP Security is Holistic
VoIP Attacks - Slice of VoIP Security Threats
Network Security (IP, UDP , TCP, etc)
Physical Security
Policies and Procedures
OS Security
Supporting Service Security
(web server, database, DHCP)
VoIP Protocol and �Application Security
Weak Voicemail Passwords
Abuse of Long Distance Privileges
Total Call Server Compromise,
Reboot, Denial of Service
Syn Flood, ICMP unreachable, �trivial flooding attacks, DDoS, etc.
SQL Injection, �DHCP resource exhaustion
Buffer Overflows, Worms, Denial of
Service (Crash), Weak Configuration
Toll Fraud, SPIT, Phishing
Malformed Messages (fuzzing)�INVITE/BYECANCEL Floods
CALL Hijacking
Call Eavesdropping�Call Modificaiton
Agenda
Vulnerabilities in VoIP Components
SIP Proxy
RedHat Linux
H.323 Gatekeeper
IOS
Softswitch
CallManager
Windows 2000
IIS, MS-SQL,
Apache Tomcat
H.323
HTTP
Skinny
MGCP
Q.931/IP
SIP
RTP
RTCP
Media Server
MCS
Windows 2000
IIS
MS-SQL
Border Router
IOS
Internet
Vulnerabilities in VoIP Components
Vulnerabilities in VoIP Components - Examples
Vulnerabilities in VoIP Components
Agenda
Support Services and Infrastructure Dependencies
VoIP Support Services
VoIP Component Configuration Weaknesses
Protection Strategies
Agenda
Network Infrastructure Attacks
Network Infrastructure Attack Examples
Protection Strategies
Agenda
VoIP Protocol Implementation Attacks
VoIP Protocol Implementation Attacks
SIP / SDP Message Format
INVITE sip:6713@192.168.26.180:6060;user=phone SIP/2.0
Via: SIP/2.0/UDP 192.168.22.36:6060
From: UserAgent<sip:6710@192.168.22.36:6060;user=phone>
To: 6713<sip:6713@192.168.26.180:6060;user=phone>
Call-ID: 96561418925909@192.168.22.36
Cseq: 1 INVITE
Subject: VovidaINVITE
Contact: <sip:6710@192.168.22.36:6060;user=phone>
Content-Type: application/sdp
Content-Length: 168
v=0
o=- 238540244 238540244 IN IP4 192.168.22.36
s=VOVIDA Session
c=IN IP4 192.168.22.36
t=3174844751 0
m=audio 23456 RTP/AVP 0
a=rtpmap:0 PCMU/8000
a=ptime:20
SDP
Payload
Example Fuzzed Packet
INVITE sip:6713@192.168.26.180:6060;user=phone SIP/2.0
Via: aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa
aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa
aaaaaaaaaaaaa…
From: UserAgent<sip:6710@192.168.22.36:6060;user=phone>
To: 6713<sip:6713@192.168.26.180:6060;user=phone>
Call-ID: 96561418925909@192.168.22.36
Cseq: 1 INVITE
Subject: VovidaINVITE
Contact: <sip:6710@192.168.22.36:6060;user=phone>
Content-Type: application/sdp
Content-Length: 168
v=0
o=- 238540244 238540244 IN IP4 192.168.22.36
s=VOVIDA Session
c=IN IP4 192.168.22.36
t=3174844751 0
m=audio 23456 RTP/AVP 0
a=rtpmap:0 PCMU/8000
a=ptime:20
SDP
Payload
Summary of High-Value Target Protocols
Fuzzing VoIP protocol implementations is only at the tip of the iceberg:
Agenda
VoIP Applications Attacks
Normal Registration
Location Server
Registrar
2. “To contact sip:derek@tpti.com
Use sip:derek@11.5.6.7 for 60 minutes”
derek’s
Phone
1. REGISTER sip:derek@tpti.com
Contact <sip:derek@11.5.6.7>
Expires: 3600
3. 200 OK
Threat Scenario – Registration Hijacking
Location Server
Registrar
2. “To contact sip:derek@tpti.com
Use sip:derek@11.5.6.7 for 60 minutes”
derek’s
Phone
1. REGISTER sip:derek@tpti.com
Contact <sip:derek@11.5.6.7>
Expires: 3600
3. 200 OK
4. “To contact sip:derek@tpti.com
Use sip:mugatu@11.5.6.8 for 30 minutes”
3. REGISTER sip:derek@tpti.com
Contact < mugatu@11.5.6.8 >
Expires: 1800
Threat Scenario – BYE/CANCEL Denial of Service
7. 200 OK
6. INVITE derek@11.5.6.7
8. RTP Coversation
9. SIP BYE derek@11.5.6.7
7. SIP CANCEL derek@11.5.6.7
Authentication Protection Features
Autentication Protection Features Con’t
Threat Scenario – Killer SIP Messages
Proxy Server (redirect mode)
Location Server
Malformed SIP
Malformed SIP
Malformed SIP
Threat Scenario – RFC Conformance
INVITE sip:6713@192.168.26.180:6060;user=phone SIP/2.0
Via: aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa
aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa
aaaaaaaaaaaaa…
From: UserAgent<sip:6710@192.168.22.36:6060;user=phone>
To: 6713<sip:6713@192.168.26.180:6060;user=phone>
Call-ID: 96561418925909@192.168.22.36
Cseq: 1 INVITE
Subject: VovidaINVITE
Contact: <sip:6710@192.1%s%s%s68.22.36:6060;user=phone>
Content-Type: application/sdp
Content-Length: 168
v=0
o=- 238540244 238540244 IN IP4 192.168.22.36
s=VOVIDA Session
c=IN IP4 192.168.22.36
t=3174844751 0
m=audio 23456 RTP/AVP 0
a=rtpmap:0 PCMU/8000
a=ptime:20
Protection Strategy
Proxy Server (redirect mode)
Location Server
Malformed SIP
Malformed SIP
Malformed SIP
Threat Scenario – INVITE/REGISTER/etc Flood
1. INVITE derek@tpti
(spoofed source IP)
2. 302 Moved Temporarily� derek@11.5.6.7
Proxy Server (redirect mode)
Location Server
4: “Where is derek@tpti”
5: “Use derek@11.5.6.7”
Send 10000 INVITES/sec
Threat Scenario – Quality of Service Abuse
Protection Measures
Protection Measures
Other VoIP Application Attacks
Agenda
Industry Needs
Enter VOIPSA
VOIPSA
VOIPSA
VOIPSA – Participate!
www.voipsa.org
Agenda
Conclusion
Questions?
Thank you very much!
Questions?
rohitd@tippingpoint.com
dendler@tippingpoint.com