the ugly side of socmed marketing... companies, beware! http://j.mp/cIqelG http://koprol.com/s/3FyS
14 minutes ago by pepoluan on topsyZDNet is available in the following editions:
Penetration testers have demonstrated how to hack into numerous VoIP clients, but analysts say social-engineering attacks are a more pressing concern
Penetration testers have demonstrated a way of compromising computers by subverting VoIP software clients.
The testers, who are from VoIP security firm Sipera, claim that they have found similar vulnerabilities in several vendors' enterprise VoIP software clients. Sipera would not reveal the identity of the affected vendors, because they have not yet brought out patches.
The testers demonstrated a proof-of-concept exploit for one of the VoIP clients at the Black Hat security conference in Las Vegas on Wednesday. On a laptop running Windows XP SP2 with a Windows firewall, running McAfee antivirus, Sipera product manager Sachin Joglekar demonstrated a vulnerability that allows a hacker to cause a buffer-overflow condition.
This allows a small script to be inserted on the victim's laptop, which then enables the hacker to take control of the laptop and view directories, delete them, and steal files and data, Sipera claimed.
"Very specialized, small shell code, just bits and bytes, is inserted into a SIP message," Joglekar said. "As soon as the phone gets the malformed message, the shell code is executed on the laptop and opens a connection that allows an attacker to open a connection and steal files and data."
Joglekar claimed this was "very significant" because data could be smuggled "under the radar from the VoIP side", and that data security vendors were currently "not serious about VoIP".
"Previously there have been no threats to confidential data from softphones. Now there is a bridge built between the two islands," he said.
However, Jon Collins, service director with analyst firm Freeform Dynamics, said that, as few companies have yet rolled out VoIP, a more pressing security concern was "protecting employees from themselves" through education about social-engineering attacks, as working practices evolve.
"I'm not suggesting that finding VoIP or IM client holes isn't an issue, but there are 500 different ways of getting onto someone's laptop. Companies should be concentrating on protecting employees from themselves rather than worrying about external threats. Companies are trying to enable corporate employees to work from home. Corporate data is leaving the company--this is a major area of concern," said Collins.
Joglekar claimed that VoIP protocol subversion was an unrecognized problem in many vendor products. "We found vulnerabilities allowing shell-code execution in multiple vendor VoIP products and software," said Joglekar. "As different modes of communication like VoIP and IM are unified, privacy, security and compliance issues become (more significant)."
He said that most security products would be circumvented by VoIP client-exploit code, because finding anomalies required deep packet inspection and an understanding of VoIP user and client behaviour.
McAfee said that its antivirus software had not picked up the hack in the demonstration because the hack was proof-of-concept. "Both our consumer and enterprise generic products monitor the top 20 buffer-overflow methods," said McAfee analyst Greg Day. "If this is seen in the real world, we could create an antivirus signature, and would do that if it became common in the outside world."
Day said that behaviour-blocking in McAfee antivirus software would not stop this exploit because behaviour-blocking is "designed around a common threat rather than a proof-of-concept hacking technique". He added that McAfee had host and network intrusion-prevention products designed to stop this type of exploit.
Microsoft could offer no comment at the time of writing on how the researchers had managed to evade the Windows firewall.
the ugly side of socmed marketing... companies, beware! http://j.mp/cIqelG http://koprol.com/s/3FyS
14 minutes ago by pepoluan on topsyForeign LBS players need local tie-ups for commercial success in the region. http://tinyurl.com/yco936k
49 minutes ago by zdnetasia on twitterPersonal Finance Software - Productivity Software - Mac - Free ...: SEE Finance. Personal finance manager featurin... http://bit.ly/a38bXY
1 hour 38 minutes ago by alisha204 on topsyFor BitDefender antivirus users, check out what the company said regarding its bad security update: http://bit.ly/cYTGug
1 hour 54 minutes ago by zdnetasia on twitterAsia not ready for zero-client computing, says analyst. http://bit.ly/cALkZB
1 hour 54 minutes ago by zdnetasia on twitterFor BitDefender antivirus users, check out what the company said regarding its bad security update: http://bit.ly/cYTGug
2 hours 22 minutes ago by kevinzdnetasia on topsyAsia not ready for zero-client computing, says analyst. http://bit.ly/cALkZB
2 hours 33 minutes ago by vivianzdnetasia on topsyFour news blogs today, from Inside India, Msia Explorer, Mister Tech and Tech Legal. Do check them out. http://www.zdnetasia.com/blogs/
2 hours 41 minutes ago by zdnetasia on twitterRead my blog post on getting the most from your Nexus One: http://www.zdnetasia.com/blogs/m...
23 hours 39 minutes ago by mistertechblog on twitterRT @3wconsulting: Whitepaper from http://3W.com.au "Outsourcing Your IT Requirements to Philippines" now on @zdnetaustralia & @zdnetasia http://ow.ly/1oY9f
1 day 53 minutes ago by LeesaAT3W on twitterWhitepaper from http://3W.com.au "Outsourcing Your IT Requirements to Philippines" now on @zdnetaustralia & @zdnetasia http://ow.ly/1oYbA
1 day 54 minutes ago by itemployment on twitterWhitepaper from http://3W.com.au "Outsourcing Your IT Requirements to Philippines" now on @zdnetaustralia & @zdnetasia http://ow.ly/1oYbz
1 day 54 minutes ago by brucemills on twitterZdnetasia.com Estimated Worth $178,365 USD. Daily Ad Revenue:$244 USD, Daily Views:81,445 Pages... - http://www.haplog.com/www.zdneta...
1 day 37 minutes ago by Haplog on twitterThe receivers don't transmit back to the satellite. Unless there is a phone line attached to the receiver, they don't have any wa...
2 days 19 minutes ago by bessellbrowne on Apple to join the geolocation craze?whatever little understanding I have we 'll only progress toward end of the world if we use HPCs to lenthen life of human being. Huma...
2 days 26 minutes ago by abhi32002@gmail.com on High computing promises elixir of lifeThanks for the knowledgeable article on SDDs. Allas...when all this reasearch will happen in Indian Universities. Hope the new bill on Fo...
2 days 38 minutes ago by abhi32002@gmail.com on APAC HPC users eye solid-state drivesIt was a good article. This brings a good opportunity for Indian IT firms to come up with new solutions in this field. HPC can become a b...
2 days 57 minutes ago by abhi32002@gmail.com on High computing most-wanted job in AsiaCOL KR DHARMADHIKARY(RETD) its very late to reply the link, but if it is still alive and looking for opportunity, i would like to know th...
2 days 54 minutes ago by deb021280 on Education takes off in rural India, helped by PCsHigh performance computing (HPC) most-wanted job in Asia http://bit.ly/9vFC3i (via @zdnetasia) #singapore
3 days 11 minutes ago by mySingapore on twitterRT @zdnetasia: EMC COO, Pat Gelsinger, on bridging gaps in the organization and its cloud ambitions in Asia. (cont) http://tl.gd/i5jjd
3 days 266401 seconds ago by mistymaitimoe on twitterEMC COO, Pat Gelsinger, on bridging gaps in the organization and its cloud ambitions in Asia. http://bit.ly/9etOZW
3 days 4 minutes ago by zdnetasia on twitterAsian SMBs need to pay more attention to disaster recovery planning http://bit.ly/bDet08 via @zdnetasia
3 days 19 minutes ago by asiapacsolution on twitterAsian SMBs need to pay more attention to disaster recovery planning http://bit.ly/bDet08
3 days 34 minutes ago by zdnetasia on twitter"YOG should have social media rules, too - Internet - News" http://bit.ly/dn6vjD
3 days 42 minutes ago by socialsentiment on topsyall of sg's isps have been practising compulsory invisible proxy for all home subscribers at their backend since many years back alre...
4 days 38 minutes ago by melvinchia on Web filters mean bad news for businessit is not to good for china.
Proactol
Very good explanation of JMX
5 days 28 minutes ago by Babith B on Managing applications with JMXThe reaction to a report issued Tuesday by Flurry Analytics managed to completely overlook some interesting news--the Android-based Motorola Droid outsold the original iPhone over the same period of time following their respective launches--to focus instead on the sales numbers for the Nexus One.
5 days 32 minutes ago by lonemavericks on diggsAnother ZTE story....
5 days 34 minutes ago by Moderate Your Greed on Philippines opens bid for final 3G licenseWe at www.fifosys.com have also seen a growth in IT outsourcing and anticipate it as a growing field.
5 days 7 minutes ago by sarah Jane on Companies' outsourcing spend to increaseI agree with you. The iSiVaL is super portable and TVs can't expand their image size. I recorded a video that might bring some ideas to...
5 days 37 minutes ago by Jesse B Andersen on Buying a projector? Try an LED TV insteadhermm... he deserved it.. he shud not talk abt sensitive things like tat, well, he shud think twice before saying all those things, event...
5 days 15 minutes ago by ... on Facebook user charged in MalaysiaPassword manager tools are potential security threat. Criminals who hack into the computer can use the password manager to log onto any s...
6 days 15 minutes ago by ohanae on What defaults should random password generators use?I've found the cross platform utility unetbootin to be rather handy for this kind of thing as well.
6 days 50 minutes ago by Jim on Use Live USB Creator to install Fedora 12 from a USB stickThanks for the article. I think the debug command has an "\" after "C:" it should say w32tm /debug /enable /file:C:\l...
6 days 50 minutes ago by Roger Biefer on Manage time accuracy with W32TmThe Desktop Virtualization Revolution is here!
Find our more with Citrix Simplicity is Power
2010 IT Salary & Skills Report
Find out the salary range of IT professionals. Join activeTechPros for free access to the report.
The Internet Show 2010, 21-22 Apr 2010, Singapore
FREE admission for visitors who pre-register online. Register Today!