meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Thursday, August 18th, 2022

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

News, Tech News

4.9754 Ratings

🗓️ 18 August 2022

⏱️ 6 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. Voip Experiment; Apple 0-Days; Chrome 0-Day; Insufficient Cisco Patch

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Thursday, August 18, 2020 edition of the Sandcent Storm Center's Stormcast.

0:07.9

My name is Johannes Ulrich, and I'm yet again recording from Jacksonville, Florida, which you may be able to tell by the thunderstorm and rain in the background.

0:17.9

These last couple of days, I spent some time looking at SIP traffic to play with

0:22.6

the Real Tech SDK vulnerability. And as part of this sort of overall experiments, I also set up a quick

0:30.4

asterisk server. What surprised me, and I guess should not have surprised me me was how much this increased the voice over

0:40.4

IP scanning traffic that was seen by this server. Now voice of IP or zip traffic is

0:48.0

quite commonly being used to scan random systems. It often makes one of the top 10 ports in our list. But as soon as I set up

0:59.3

this server, the number of hits per IP went up easily by a factor of 100. And this was a very

1:07.9

simple setup. The server didn't really allow any phone calls.

1:12.5

It just sort of was basically just accepting packets and returning permission denied.

1:18.9

There were sort of two kinds of attacks or scans that I noted.

1:24.0

One was where basically someone just tried to call a number via my server. The second one

1:30.1

was where they actually tried to register an extension with this voice or IP server, which then, of

1:35.9

course, would have allowed them to impersonate whatever company runs that particular server.

1:42.5

And the two most called numbers also sort of matched a common

1:46.8

exploit activity that's seen in exposed voice over IP servers. One number was in the Palestine

1:55.1

territories. Quite often in areas like this that are sort of not included in unlimited calling plans and such.

2:04.3

People still worry about the cost of calls.

2:08.3

And of course, that leads to them attempting to use unprotected voice of IP servers.

2:14.1

The second one was a number in Chicago.

2:17.4

This may have been attempt sort of to use it for scam calls.

2:21.3

Of course, using some badly configured voice over IP server makes it easier to hide the true

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.