SlideShare ist ein Scribd-Unternehmen logo
1 von 248
Downloaden Sie, um offline zu lesen
The Security
   Saga of
SysAdmin Steve
    Dan York, CISSP
      ClueCon 2009
                      ClueCon 2009 – Dan York
Once upon a
  time...

          ClueCon 2009 – Dan York
big company


          ClueCon 2009 – Dan York
smaller company


            ClueCon 2009 – Dan York
SysAdmin Steve


           ClueCon 2009 – Dan York
promotion


            ClueCon 2009 – Dan York
IT


     ClueCon 2009 – Dan York
phones, too!


           ClueCon 2009 – Dan York
new VoIP system


            ClueCon 2009 – Dan York
net head


           ClueCon 2009 – Dan York
V


    ClueCon 2009 – Dan York
Voice


        ClueCon 2009 – Dan York
SIP


      ClueCon 2009 – Dan York
open standard


           ClueCon 2009 – Dan York
Security
  Isn’t
Possible
           ClueCon 2009 – Dan York
education


            ClueCon 2009 – Dan York
PSTN

                          SIP Service
                           Provider



               Internet



      IP-PBX



LAN




                                        ClueCon 2009 – Dan York
cheap


        ClueCon 2009 – Dan York
merged


         ClueCon 2009 – Dan York
quit


       ClueCon 2009 – Dan York
?


    ClueCon 2009 – Dan York
new IT staff


           ClueCon 2009 – Dan York
Juvenile Joe


           ClueCon 2009 – Dan York
BOFH


       ClueCon 2009 – Dan York
read e-mail


              ClueCon 2009 – Dan York
monitor


          ClueCon 2009 – Dan York
comment


          ClueCon 2009 – Dan York
playground


             ClueCon 2009 – Dan York
exploit chaos


            ClueCon 2009 – Dan York
fun


      ClueCon 2009 – Dan York
ultimate truism


             ClueCon 2009 – Dan York
voice = packets


             ClueCon 2009 – Dan York
packets = bits


            ClueCon 2009 – Dan York
bits can be
manipulated

          ClueCon 2009 – Dan York
“VoIP security
    tools”

            ClueCon 2009 – Dan York
tools, tools, tools


               ClueCon 2009 – Dan York
voipsa.org


             ClueCon 2009 – Dan York
hackingvoip.com


            ClueCon 2009 – Dan York
sectools.org


           ClueCon 2009 – Dan York
tools, tools, tools


               ClueCon 2009 – Dan York
good


       ClueCon 2009 – Dan York
evil


       ClueCon 2009 – Dan York
test/defend


              ClueCon 2009 – Dan York
attack


         ClueCon 2009 – Dan York
perspective


          ClueCon 2009 – Dan York
white hat


            ClueCon 2009 – Dan York
black hat


            ClueCon 2009 – Dan York
wireshark


            ClueCon 2009 – Dan York
ClueCon 2009 – Dan York
cain & abel


              ClueCon 2009 – Dan York
RTP


      ClueCon 2009 – Dan York
WAV


      ClueCon 2009 – Dan York
MP3s


       ClueCon 2009 – Dan York
iPod


       ClueCon 2009 – Dan York
2-hour commute


           ClueCon 2009 – Dan York
corporate
conversations

           ClueCon 2009 – Dan York
personal
  iPod

           ClueCon 2009 – Dan York
corporate
conversations

           ClueCon 2009 – Dan York
personal
  iPod

           ClueCon 2009 – Dan York
(scared yet?)


            ClueCon 2009 – Dan York
conversations


            ClueCon 2009 – Dan York
PIN


      ClueCon 2009 – Dan York
voicemail PINs


             ClueCon 2009 – Dan York
banking PINs


           ClueCon 2009 – Dan York
DTMF decoder


           ClueCon 2009 – Dan York
(fun stuff, eh?)


               ClueCon 2009 – Dan York
Teleworker Ted


            ClueCon 2009 – Dan York
envy


       ClueCon 2009 – Dan York
grudge


         ClueCon 2009 – Dan York
hang up Ted


          ClueCon 2009 – Dan York
cell phone


             ClueCon 2009 – Dan York
devious


          ClueCon 2009 – Dan York
mix in new
background

          ClueCon 2009 – Dan York
amusement park


           ClueCon 2009 – Dan York
screaming kids


            ClueCon 2009 – Dan York
dog


      ClueCon 2009 – Dan York
Ted’s dog


            ClueCon 2009 – Dan York
endless barking


            ClueCon 2009 – Dan York
no clue


          ClueCon 2009 – Dan York
Process Paul


           ClueCon 2009 – Dan York
new rules


            ClueCon 2009 – Dan York
worked late


              ClueCon 2009 – Dan York
wife


       ClueCon 2009 – Dan York
female


         ClueCon 2009 – Dan York
???


      ClueCon 2009 – Dan York
no clue


          ClueCon 2009 – Dan York
insecure firewall


              ClueCon 2009 – Dan York
family


         ClueCon 2009 – Dan York
SIP softphone


           ClueCon 2009 – Dan York
free long distance


              ClueCon 2009 – Dan York
(toll fraud)


               ClueCon 2009 – Dan York
Board
conf calls

             ClueCon 2009 – Dan York
revenues in the
     tank

             ClueCon 2009 – Dan York
only hope


            ClueCon 2009 – Dan York
acquisition


              ClueCon 2009 – Dan York
IT outsourced


           ClueCon 2009 – Dan York
job


      ClueCon 2009 – Dan York
(Uh-oh)


          ClueCon 2009 – Dan York
war


      ClueCon 2009 – Dan York
SIP trunk


            ClueCon 2009 – Dan York
unencrypted


          ClueCon 2009 – Dan York
sniff CID


            ClueCon 2009 – Dan York
lawyers


          ClueCon 2009 – Dan York
CFO


      ClueCon 2009 – Dan York
SIP Redirect


           ClueCon 2009 – Dan York
random extension


             ClueCon 2009 – Dan York
shipping


           ClueCon 2009 – Dan York
HR


     ClueCon 2009 – Dan York
labs


       ClueCon 2009 – Dan York
kitchen


          ClueCon 2009 – Dan York
?


    ClueCon 2009 – Dan York
acquire?


           ClueCon 2009 – Dan York
@#$@?%$!


           ClueCon 2009 – Dan York
SysAdmin Steve


           ClueCon 2009 – Dan York
fix it


         ClueCon 2009 – Dan York
DoS


      ClueCon 2009 – Dan York
BYE


      ClueCon 2009 – Dan York
hang up CEO


          ClueCon 2009 – Dan York
set reload


             ClueCon 2009 – Dan York
erase SIP
registration

           ClueCon 2009 – Dan York
no clue


          ClueCon 2009 – Dan York
packet flood


           ClueCon 2009 – Dan York
degrade


          ClueCon 2009 – Dan York
cell phones


              ClueCon 2009 – Dan York
acquire?


           ClueCon 2009 – Dan York
@#$@?%$!


           ClueCon 2009 – Dan York
SysAdmin Steve


           ClueCon 2009 – Dan York
fix it


         ClueCon 2009 – Dan York
3 strikes


            ClueCon 2009 – Dan York
investigation


            ClueCon 2009 – Dan York
truth


        ClueCon 2009 – Dan York
discovered


             ClueCon 2009 – Dan York
heart attack


           ClueCon 2009 – Dan York
corporate
conversations

           ClueCon 2009 – Dan York
SIP trunk


            ClueCon 2009 – Dan York
unencrypted


          ClueCon 2009 – Dan York
public Internet


             ClueCon 2009 – Dan York
clear


        ClueCon 2009 – Dan York
call records


           ClueCon 2009 – Dan York
public Internet


             ClueCon 2009 – Dan York
cleartext


            ClueCon 2009 – Dan York
(not good)


             ClueCon 2009 – Dan York
plan


       ClueCon 2009 – Dan York
Fire Joe!


            ClueCon 2009 – Dan York
defense in depth


             ClueCon 2009 – Dan York
layers


         ClueCon 2009 – Dan York
encryption


             ClueCon 2009 – Dan York
SRTP


       ClueCon 2009 – Dan York
TLS / DTLS


             ClueCon 2009 – Dan York
ZRTP


       ClueCon 2009 – Dan York
voice


        ClueCon 2009 – Dan York
call control


               ClueCon 2009 – Dan York
LAN


      ClueCon 2009 – Dan York
SIP trunk


            ClueCon 2009 – Dan York
clueless


           ClueCon 2009 – Dan York
new provider


           ClueCon 2009 – Dan York
call accounting


             ClueCon 2009 – Dan York
IP network


             ClueCon 2009 – Dan York
VLANs


        ClueCon 2009 – Dan York
IDS/IPS


          ClueCon 2009 – Dan York
monitoring


             ClueCon 2009 – Dan York
rate throttling


             ClueCon 2009 – Dan York
secure perimeter


             ClueCon 2009 – Dan York
firewall traversal


               ClueCon 2009 – Dan York
firmware


           ClueCon 2009 – Dan York
o/s patches


          ClueCon 2009 – Dan York
disable services


             ClueCon 2009 – Dan York
die,
  default
passwords,
die, die, die
            ClueCon 2009 – Dan York
layers


         ClueCon 2009 – Dan York
secure VoIP


          ClueCon 2009 – Dan York
caveat


         ClueCon 2009 – Dan York
internal


           ClueCon 2009 – Dan York
disgruntled


              ClueCon 2009 – Dan York
x%?


      ClueCon 2009 – Dan York
compromised
  servers

          ClueCon 2009 – Dan York
spyware


          ClueCon 2009 – Dan York
unsecured WiFi


            ClueCon 2009 – Dan York
(checked your
  parking lot
   lately?)
           ClueCon 2009 – Dan York
offline analysis


              ClueCon 2009 – Dan York
SIP trunk


            ClueCon 2009 – Dan York
$$$


      ClueCon 2009 – Dan York
security


           ClueCon 2009 – Dan York
Botnet Bob


             ClueCon 2009 – Dan York
zombies


          ClueCon 2009 – Dan York
fun


      ClueCon 2009 – Dan York
profit


         ClueCon 2009 – Dan York
Criminal Chris


            ClueCon 2009 – Dan York
espionage


            ClueCon 2009 – Dan York
identity theft


                 ClueCon 2009 – Dan York
human replay
   attack

           ClueCon 2009 – Dan York
Spammer Sue


          ClueCon 2009 – Dan York
SPIT


       ClueCon 2009 – Dan York
1,000s of calls


             ClueCon 2009 – Dan York
“significant
   event”

               ClueCon 2009 – Dan York
Congressman


          ClueCon 2009 – Dan York
mistress


           ClueCon 2009 – Dan York
public official


             ClueCon 2009 – Dan York
porn line


            ClueCon 2009 – Dan York
identity theft


             ClueCon 2009 – Dan York
13-yr-old


            ClueCon 2009 – Dan York
Wall St. Journal


             ClueCon 2009 – Dan York
“VOIP IS
INSECURE”

         ClueCon 2009 – Dan York
“(stupid) VOIP IS
   INSECURE”

              ClueCon 2009 – Dan York
“VOIP IS
INSECURE”

         ClueCon 2009 – Dan York
moral


        ClueCon 2009 – Dan York
VoIP *can* be
   secure

           ClueCon 2009 – Dan York
VoIP can be
MORE secure
 than PSTN
           ClueCon 2009 – Dan York
(red button,
  anyone?)

           ClueCon 2009 – Dan York
work


       ClueCon 2009 – Dan York
plan


       ClueCon 2009 – Dan York
questions


            ClueCon 2009 – Dan York
education


            ClueCon 2009 – Dan York
voipsa.org


             ClueCon 2009 – Dan York
VOIPSA Threat
  Taxonomy

           ClueCon 2009 – Dan York
VOIPSA
Best Practices

            ClueCon 2009 – Dan York
VOIPSEC
mailing list

               ClueCon 2009 – Dan York
blueboxpodcast.com


              ClueCon 2009 – Dan York
ClueCon 2009 – Dan York
(If you aren’t
reading them, be
     aware the
 attackers *are*)
              ClueCon 2009 – Dan York
defense in depth


             ClueCon 2009 – Dan York
layers and layers


              ClueCon 2009 – Dan York
voice


        ClueCon 2009 – Dan York
call control


               ClueCon 2009 – Dan York
SIP trunks


             ClueCon 2009 – Dan York
management
interfaces / APIs

              ClueCon 2009 – Dan York
PSTN
interfaces

             ClueCon 2009 – Dan York
PSTN


       ClueCon 2009 – Dan York
VoIP = IP + PSTN


             ClueCon 2009 – Dan York
it’s the network,
       stupid

              ClueCon 2009 – Dan York
cloud


        ClueCon 2009 – Dan York
IP network


             ClueCon 2009 – Dan York
voice = packets


             ClueCon 2009 – Dan York
packets = bits


            ClueCon 2009 – Dan York
bits can be
manipulated

          ClueCon 2009 – Dan York
VoIP *can* be
   secure

           ClueCon 2009 – Dan York
work


       ClueCon 2009 – Dan York
plan


       ClueCon 2009 – Dan York
SysAdmin Steve?


            ClueCon 2009 – Dan York
happily ever
   after?

           ClueCon 2009 – Dan York
acquisition?


           ClueCon 2009 – Dan York
job?


       ClueCon 2009 – Dan York
CIO?


       ClueCon 2009 – Dan York
another story


            ClueCon 2009 – Dan York
To be continued...


              ClueCon 2009 – Dan York
The End

(or is it the beginning?)

                            ClueCon 2009 – Dan York
Please practice
   safe VoIP!

             ClueCon 2009 – Dan York
Q&A
   www.voipsa.org
  www.voipsa.org/blog
www.blueboxpodcast.com
   blogs.voxeo.com

                         ClueCon 2009 – Dan York
Thank you

(Please practice safe VoIP!)

                               ClueCon 2009 – Dan York

Weitere ähnliche Inhalte

Andere mochten auch

Your Inner Sysadmin - Tutorial (SunshinePHP 2015)
Your Inner Sysadmin - Tutorial (SunshinePHP 2015)Your Inner Sysadmin - Tutorial (SunshinePHP 2015)
Your Inner Sysadmin - Tutorial (SunshinePHP 2015)Chris Tankersley
 
jQuery Plugins Intro
jQuery Plugins IntrojQuery Plugins Intro
jQuery Plugins IntroCasey West
 
Accessible dynamic forms
Accessible dynamic formsAccessible dynamic forms
Accessible dynamic formsDylan Barrell
 
OWASP App Sec US - 2010
OWASP App Sec US - 2010OWASP App Sec US - 2010
OWASP App Sec US - 2010Aditya K Sood
 
LAMP Management with Virtualmin
LAMP Management with VirtualminLAMP Management with Virtualmin
LAMP Management with VirtualminJoe Ferguson
 
Identifying Web Servers: A First-look Into the Future of Web Server Fingerpri...
Identifying Web Servers: A First-look Into the Future of Web Server Fingerpri...Identifying Web Servers: A First-look Into the Future of Web Server Fingerpri...
Identifying Web Servers: A First-look Into the Future of Web Server Fingerpri...Jeremiah Grossman
 
Php Security Workshop
Php Security WorkshopPhp Security Workshop
Php Security WorkshopAung Khant
 
UpsilonPiEpsilon-UniversityOfBridgeport-May1997
UpsilonPiEpsilon-UniversityOfBridgeport-May1997UpsilonPiEpsilon-UniversityOfBridgeport-May1997
UpsilonPiEpsilon-UniversityOfBridgeport-May1997Muthuselvam RS
 
Red Hat Training México /// Calendario de cursos 2016
Red Hat Training México /// Calendario de cursos 2016Red Hat Training México /// Calendario de cursos 2016
Red Hat Training México /// Calendario de cursos 2016Red Hat
 
SydPHP Security in PHP
SydPHP Security in PHPSydPHP Security in PHP
SydPHP Security in PHPAllan Shone
 
Safety LAMP: data security & agile languages
Safety LAMP: data security & agile languagesSafety LAMP: data security & agile languages
Safety LAMP: data security & agile languagesPostgreSQL Experts, Inc.
 
Web Technology – Web Server Setup : Chris Uriarte
Web Technology – Web Server Setup : Chris UriarteWeb Technology – Web Server Setup : Chris Uriarte
Web Technology – Web Server Setup : Chris Uriartewebhostingguy
 
Scalable Internet Servers and Load Balancing
Scalable Internet Servers and Load BalancingScalable Internet Servers and Load Balancing
Scalable Internet Servers and Load BalancingInformation Technology
 
jQuery Stack Overflow DevDays DC 2009
jQuery Stack Overflow DevDays DC 2009jQuery Stack Overflow DevDays DC 2009
jQuery Stack Overflow DevDays DC 2009Richard D. Worth
 
Memphis php 01 22-13 - laravel basics
Memphis php 01 22-13 - laravel basicsMemphis php 01 22-13 - laravel basics
Memphis php 01 22-13 - laravel basicsJoe Ferguson
 
Bring a Web Page Alive with jQuery
Bring a Web Page Alive with jQueryBring a Web Page Alive with jQuery
Bring a Web Page Alive with jQueryLearnNowOnline
 

Andere mochten auch (20)

Your Inner Sysadmin - Tutorial (SunshinePHP 2015)
Your Inner Sysadmin - Tutorial (SunshinePHP 2015)Your Inner Sysadmin - Tutorial (SunshinePHP 2015)
Your Inner Sysadmin - Tutorial (SunshinePHP 2015)
 
jQuery Plugins Intro
jQuery Plugins IntrojQuery Plugins Intro
jQuery Plugins Intro
 
Accessible dynamic forms
Accessible dynamic formsAccessible dynamic forms
Accessible dynamic forms
 
OWASP App Sec US - 2010
OWASP App Sec US - 2010OWASP App Sec US - 2010
OWASP App Sec US - 2010
 
LAMP Management with Virtualmin
LAMP Management with VirtualminLAMP Management with Virtualmin
LAMP Management with Virtualmin
 
RHCSA
RHCSARHCSA
RHCSA
 
Identifying Web Servers: A First-look Into the Future of Web Server Fingerpri...
Identifying Web Servers: A First-look Into the Future of Web Server Fingerpri...Identifying Web Servers: A First-look Into the Future of Web Server Fingerpri...
Identifying Web Servers: A First-look Into the Future of Web Server Fingerpri...
 
Php Security Workshop
Php Security WorkshopPhp Security Workshop
Php Security Workshop
 
UpsilonPiEpsilon-UniversityOfBridgeport-May1997
UpsilonPiEpsilon-UniversityOfBridgeport-May1997UpsilonPiEpsilon-UniversityOfBridgeport-May1997
UpsilonPiEpsilon-UniversityOfBridgeport-May1997
 
Red Hat Training México /// Calendario de cursos 2016
Red Hat Training México /// Calendario de cursos 2016Red Hat Training México /// Calendario de cursos 2016
Red Hat Training México /// Calendario de cursos 2016
 
SydPHP Security in PHP
SydPHP Security in PHPSydPHP Security in PHP
SydPHP Security in PHP
 
Safety LAMP: data security & agile languages
Safety LAMP: data security & agile languagesSafety LAMP: data security & agile languages
Safety LAMP: data security & agile languages
 
Web Technology – Web Server Setup : Chris Uriarte
Web Technology – Web Server Setup : Chris UriarteWeb Technology – Web Server Setup : Chris Uriarte
Web Technology – Web Server Setup : Chris Uriarte
 
Scalable Internet Servers and Load Balancing
Scalable Internet Servers and Load BalancingScalable Internet Servers and Load Balancing
Scalable Internet Servers and Load Balancing
 
jQuery Stack Overflow DevDays DC 2009
jQuery Stack Overflow DevDays DC 2009jQuery Stack Overflow DevDays DC 2009
jQuery Stack Overflow DevDays DC 2009
 
Apache Web Server Setup 2
Apache Web Server Setup 2Apache Web Server Setup 2
Apache Web Server Setup 2
 
PHP
PHPPHP
PHP
 
Memphis php 01 22-13 - laravel basics
Memphis php 01 22-13 - laravel basicsMemphis php 01 22-13 - laravel basics
Memphis php 01 22-13 - laravel basics
 
Bring a Web Page Alive with jQuery
Bring a Web Page Alive with jQueryBring a Web Page Alive with jQuery
Bring a Web Page Alive with jQuery
 
jQuery
jQueryjQuery
jQuery
 

Mehr von Dan York

Yes, IPv6 is Real! How To Make Your Apps Work (And Be As Fast As Possible)
Yes, IPv6 is Real! How To Make Your Apps Work (And Be As Fast As Possible) Yes, IPv6 is Real! How To Make Your Apps Work (And Be As Fast As Possible)
Yes, IPv6 is Real! How To Make Your Apps Work (And Be As Fast As Possible) Dan York
 
SIPNOC 2014 - Is It Time For TLS for SIP?
SIPNOC 2014 - Is It Time For TLS for SIP?SIPNOC 2014 - Is It Time For TLS for SIP?
SIPNOC 2014 - Is It Time For TLS for SIP?Dan York
 
A Choice Of Internet Futures: Will Nonprofits Be Stuck In The Slow Lane?
A Choice Of Internet Futures: Will Nonprofits Be Stuck In The Slow Lane?A Choice Of Internet Futures: Will Nonprofits Be Stuck In The Slow Lane?
A Choice Of Internet Futures: Will Nonprofits Be Stuck In The Slow Lane?Dan York
 
Open Source and The Global Disruption Of Telecom: What Choices Will We Make?
Open Source and The Global Disruption Of Telecom: What Choices Will We Make?Open Source and The Global Disruption Of Telecom: What Choices Will We Make?
Open Source and The Global Disruption Of Telecom: What Choices Will We Make?Dan York
 
DNS / DNSSEC / DANE / DPRIVE Results at IETF93 Hackathon
DNS / DNSSEC / DANE / DPRIVE Results at IETF93 HackathonDNS / DNSSEC / DANE / DPRIVE Results at IETF93 Hackathon
DNS / DNSSEC / DANE / DPRIVE Results at IETF93 HackathonDan York
 
Deploying New DNSSEC Algorithms (IEPG@IETF93 - July 2015)
Deploying New DNSSEC Algorithms (IEPG@IETF93 - July 2015)Deploying New DNSSEC Algorithms (IEPG@IETF93 - July 2015)
Deploying New DNSSEC Algorithms (IEPG@IETF93 - July 2015)Dan York
 
The State of VoIP Security, a.k.a. “Does Anyone Really Give A _____ About VoI...
The State of VoIP Security, a.k.a. “Does Anyone Really Give A _____ About VoI...The State of VoIP Security, a.k.a. “Does Anyone Really Give A _____ About VoI...
The State of VoIP Security, a.k.a. “Does Anyone Really Give A _____ About VoI...Dan York
 
How IPv6 Will Kill Telecom - And What We Need To Do About It
How IPv6 Will Kill Telecom - And What We Need To Do About ItHow IPv6 Will Kill Telecom - And What We Need To Do About It
How IPv6 Will Kill Telecom - And What We Need To Do About ItDan York
 
SIP, Unified Communications (UC) and Security
SIP, Unified Communications (UC) and SecuritySIP, Unified Communications (UC) and Security
SIP, Unified Communications (UC) and SecurityDan York
 
SIP Trunking & Security in an Enterprise Network
SIP Trunking & Security  in an Enterprise NetworkSIP Trunking & Security  in an Enterprise Network
SIP Trunking & Security in an Enterprise NetworkDan York
 
OSCON 2008: Mashing Up Voice and the Web Using Open Source and XML
OSCON 2008: Mashing Up Voice and the Web Using Open Source and XMLOSCON 2008: Mashing Up Voice and the Web Using Open Source and XML
OSCON 2008: Mashing Up Voice and the Web Using Open Source and XMLDan York
 
IP Telephony Security 101
IP Telephony Security 101IP Telephony Security 101
IP Telephony Security 101Dan York
 
Recording Remote Hosts/Interviews with VoIP/Skype
Recording Remote Hosts/Interviews with VoIP/SkypeRecording Remote Hosts/Interviews with VoIP/Skype
Recording Remote Hosts/Interviews with VoIP/SkypeDan York
 
Hacking and Attacking VoIP Systems - What You Need To Know
Hacking and Attacking VoIP Systems - What You Need To KnowHacking and Attacking VoIP Systems - What You Need To Know
Hacking and Attacking VoIP Systems - What You Need To KnowDan York
 
E Tel2007 Black Bag Session - VoIP Security Threats, Tools and Best Practices
E Tel2007 Black Bag Session - VoIP Security Threats, Tools and Best PracticesE Tel2007 Black Bag Session - VoIP Security Threats, Tools and Best Practices
E Tel2007 Black Bag Session - VoIP Security Threats, Tools and Best PracticesDan York
 
BLISS Problem Statement and Motivation
BLISS Problem Statement and MotivationBLISS Problem Statement and Motivation
BLISS Problem Statement and MotivationDan York
 
ETel2007: The Black Bag Security Review (VoIP Security)
ETel2007: The Black Bag Security Review (VoIP Security)ETel2007: The Black Bag Security Review (VoIP Security)
ETel2007: The Black Bag Security Review (VoIP Security)Dan York
 

Mehr von Dan York (17)

Yes, IPv6 is Real! How To Make Your Apps Work (And Be As Fast As Possible)
Yes, IPv6 is Real! How To Make Your Apps Work (And Be As Fast As Possible) Yes, IPv6 is Real! How To Make Your Apps Work (And Be As Fast As Possible)
Yes, IPv6 is Real! How To Make Your Apps Work (And Be As Fast As Possible)
 
SIPNOC 2014 - Is It Time For TLS for SIP?
SIPNOC 2014 - Is It Time For TLS for SIP?SIPNOC 2014 - Is It Time For TLS for SIP?
SIPNOC 2014 - Is It Time For TLS for SIP?
 
A Choice Of Internet Futures: Will Nonprofits Be Stuck In The Slow Lane?
A Choice Of Internet Futures: Will Nonprofits Be Stuck In The Slow Lane?A Choice Of Internet Futures: Will Nonprofits Be Stuck In The Slow Lane?
A Choice Of Internet Futures: Will Nonprofits Be Stuck In The Slow Lane?
 
Open Source and The Global Disruption Of Telecom: What Choices Will We Make?
Open Source and The Global Disruption Of Telecom: What Choices Will We Make?Open Source and The Global Disruption Of Telecom: What Choices Will We Make?
Open Source and The Global Disruption Of Telecom: What Choices Will We Make?
 
DNS / DNSSEC / DANE / DPRIVE Results at IETF93 Hackathon
DNS / DNSSEC / DANE / DPRIVE Results at IETF93 HackathonDNS / DNSSEC / DANE / DPRIVE Results at IETF93 Hackathon
DNS / DNSSEC / DANE / DPRIVE Results at IETF93 Hackathon
 
Deploying New DNSSEC Algorithms (IEPG@IETF93 - July 2015)
Deploying New DNSSEC Algorithms (IEPG@IETF93 - July 2015)Deploying New DNSSEC Algorithms (IEPG@IETF93 - July 2015)
Deploying New DNSSEC Algorithms (IEPG@IETF93 - July 2015)
 
The State of VoIP Security, a.k.a. “Does Anyone Really Give A _____ About VoI...
The State of VoIP Security, a.k.a. “Does Anyone Really Give A _____ About VoI...The State of VoIP Security, a.k.a. “Does Anyone Really Give A _____ About VoI...
The State of VoIP Security, a.k.a. “Does Anyone Really Give A _____ About VoI...
 
How IPv6 Will Kill Telecom - And What We Need To Do About It
How IPv6 Will Kill Telecom - And What We Need To Do About ItHow IPv6 Will Kill Telecom - And What We Need To Do About It
How IPv6 Will Kill Telecom - And What We Need To Do About It
 
SIP, Unified Communications (UC) and Security
SIP, Unified Communications (UC) and SecuritySIP, Unified Communications (UC) and Security
SIP, Unified Communications (UC) and Security
 
SIP Trunking & Security in an Enterprise Network
SIP Trunking & Security  in an Enterprise NetworkSIP Trunking & Security  in an Enterprise Network
SIP Trunking & Security in an Enterprise Network
 
OSCON 2008: Mashing Up Voice and the Web Using Open Source and XML
OSCON 2008: Mashing Up Voice and the Web Using Open Source and XMLOSCON 2008: Mashing Up Voice and the Web Using Open Source and XML
OSCON 2008: Mashing Up Voice and the Web Using Open Source and XML
 
IP Telephony Security 101
IP Telephony Security 101IP Telephony Security 101
IP Telephony Security 101
 
Recording Remote Hosts/Interviews with VoIP/Skype
Recording Remote Hosts/Interviews with VoIP/SkypeRecording Remote Hosts/Interviews with VoIP/Skype
Recording Remote Hosts/Interviews with VoIP/Skype
 
Hacking and Attacking VoIP Systems - What You Need To Know
Hacking and Attacking VoIP Systems - What You Need To KnowHacking and Attacking VoIP Systems - What You Need To Know
Hacking and Attacking VoIP Systems - What You Need To Know
 
E Tel2007 Black Bag Session - VoIP Security Threats, Tools and Best Practices
E Tel2007 Black Bag Session - VoIP Security Threats, Tools and Best PracticesE Tel2007 Black Bag Session - VoIP Security Threats, Tools and Best Practices
E Tel2007 Black Bag Session - VoIP Security Threats, Tools and Best Practices
 
BLISS Problem Statement and Motivation
BLISS Problem Statement and MotivationBLISS Problem Statement and Motivation
BLISS Problem Statement and Motivation
 
ETel2007: The Black Bag Security Review (VoIP Security)
ETel2007: The Black Bag Security Review (VoIP Security)ETel2007: The Black Bag Security Review (VoIP Security)
ETel2007: The Black Bag Security Review (VoIP Security)
 

Kürzlich hochgeladen

Digital Identity is Under Attack: FIDO Paris Seminar.pptx
Digital Identity is Under Attack: FIDO Paris Seminar.pptxDigital Identity is Under Attack: FIDO Paris Seminar.pptx
Digital Identity is Under Attack: FIDO Paris Seminar.pptxLoriGlavin3
 
Streamlining Python Development: A Guide to a Modern Project Setup
Streamlining Python Development: A Guide to a Modern Project SetupStreamlining Python Development: A Guide to a Modern Project Setup
Streamlining Python Development: A Guide to a Modern Project SetupFlorian Wilhelm
 
"ML in Production",Oleksandr Bagan
"ML in Production",Oleksandr Bagan"ML in Production",Oleksandr Bagan
"ML in Production",Oleksandr BaganFwdays
 
Generative AI for Technical Writer or Information Developers
Generative AI for Technical Writer or Information DevelopersGenerative AI for Technical Writer or Information Developers
Generative AI for Technical Writer or Information DevelopersRaghuram Pandurangan
 
How to write a Business Continuity Plan
How to write a Business Continuity PlanHow to write a Business Continuity Plan
How to write a Business Continuity PlanDatabarracks
 
Gen AI in Business - Global Trends Report 2024.pdf
Gen AI in Business - Global Trends Report 2024.pdfGen AI in Business - Global Trends Report 2024.pdf
Gen AI in Business - Global Trends Report 2024.pdfAddepto
 
WordPress Websites for Engineers: Elevate Your Brand
WordPress Websites for Engineers: Elevate Your BrandWordPress Websites for Engineers: Elevate Your Brand
WordPress Websites for Engineers: Elevate Your Brandgvaughan
 
Connect Wave/ connectwave Pitch Deck Presentation
Connect Wave/ connectwave Pitch Deck PresentationConnect Wave/ connectwave Pitch Deck Presentation
Connect Wave/ connectwave Pitch Deck PresentationSlibray Presentation
 
TrustArc Webinar - How to Build Consumer Trust Through Data Privacy
TrustArc Webinar - How to Build Consumer Trust Through Data PrivacyTrustArc Webinar - How to Build Consumer Trust Through Data Privacy
TrustArc Webinar - How to Build Consumer Trust Through Data PrivacyTrustArc
 
What is DBT - The Ultimate Data Build Tool.pdf
What is DBT - The Ultimate Data Build Tool.pdfWhat is DBT - The Ultimate Data Build Tool.pdf
What is DBT - The Ultimate Data Build Tool.pdfMounikaPolabathina
 
Unraveling Multimodality with Large Language Models.pdf
Unraveling Multimodality with Large Language Models.pdfUnraveling Multimodality with Large Language Models.pdf
Unraveling Multimodality with Large Language Models.pdfAlex Barbosa Coqueiro
 
Are Multi-Cloud and Serverless Good or Bad?
Are Multi-Cloud and Serverless Good or Bad?Are Multi-Cloud and Serverless Good or Bad?
Are Multi-Cloud and Serverless Good or Bad?Mattias Andersson
 
Transcript: New from BookNet Canada for 2024: Loan Stars - Tech Forum 2024
Transcript: New from BookNet Canada for 2024: Loan Stars - Tech Forum 2024Transcript: New from BookNet Canada for 2024: Loan Stars - Tech Forum 2024
Transcript: New from BookNet Canada for 2024: Loan Stars - Tech Forum 2024BookNet Canada
 
Nell’iperspazio con Rocket: il Framework Web di Rust!
Nell’iperspazio con Rocket: il Framework Web di Rust!Nell’iperspazio con Rocket: il Framework Web di Rust!
Nell’iperspazio con Rocket: il Framework Web di Rust!Commit University
 
The Ultimate Guide to Choosing WordPress Pros and Cons
The Ultimate Guide to Choosing WordPress Pros and ConsThe Ultimate Guide to Choosing WordPress Pros and Cons
The Ultimate Guide to Choosing WordPress Pros and ConsPixlogix Infotech
 
"Subclassing and Composition – A Pythonic Tour of Trade-Offs", Hynek Schlawack
"Subclassing and Composition – A Pythonic Tour of Trade-Offs", Hynek Schlawack"Subclassing and Composition – A Pythonic Tour of Trade-Offs", Hynek Schlawack
"Subclassing and Composition – A Pythonic Tour of Trade-Offs", Hynek SchlawackFwdays
 
Passkey Providers and Enabling Portability: FIDO Paris Seminar.pptx
Passkey Providers and Enabling Portability: FIDO Paris Seminar.pptxPasskey Providers and Enabling Portability: FIDO Paris Seminar.pptx
Passkey Providers and Enabling Portability: FIDO Paris Seminar.pptxLoriGlavin3
 
New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024BookNet Canada
 
A Deep Dive on Passkeys: FIDO Paris Seminar.pptx
A Deep Dive on Passkeys: FIDO Paris Seminar.pptxA Deep Dive on Passkeys: FIDO Paris Seminar.pptx
A Deep Dive on Passkeys: FIDO Paris Seminar.pptxLoriGlavin3
 
Transcript: New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
Transcript: New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024Transcript: New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
Transcript: New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024BookNet Canada
 

Kürzlich hochgeladen (20)

Digital Identity is Under Attack: FIDO Paris Seminar.pptx
Digital Identity is Under Attack: FIDO Paris Seminar.pptxDigital Identity is Under Attack: FIDO Paris Seminar.pptx
Digital Identity is Under Attack: FIDO Paris Seminar.pptx
 
Streamlining Python Development: A Guide to a Modern Project Setup
Streamlining Python Development: A Guide to a Modern Project SetupStreamlining Python Development: A Guide to a Modern Project Setup
Streamlining Python Development: A Guide to a Modern Project Setup
 
"ML in Production",Oleksandr Bagan
"ML in Production",Oleksandr Bagan"ML in Production",Oleksandr Bagan
"ML in Production",Oleksandr Bagan
 
Generative AI for Technical Writer or Information Developers
Generative AI for Technical Writer or Information DevelopersGenerative AI for Technical Writer or Information Developers
Generative AI for Technical Writer or Information Developers
 
How to write a Business Continuity Plan
How to write a Business Continuity PlanHow to write a Business Continuity Plan
How to write a Business Continuity Plan
 
Gen AI in Business - Global Trends Report 2024.pdf
Gen AI in Business - Global Trends Report 2024.pdfGen AI in Business - Global Trends Report 2024.pdf
Gen AI in Business - Global Trends Report 2024.pdf
 
WordPress Websites for Engineers: Elevate Your Brand
WordPress Websites for Engineers: Elevate Your BrandWordPress Websites for Engineers: Elevate Your Brand
WordPress Websites for Engineers: Elevate Your Brand
 
Connect Wave/ connectwave Pitch Deck Presentation
Connect Wave/ connectwave Pitch Deck PresentationConnect Wave/ connectwave Pitch Deck Presentation
Connect Wave/ connectwave Pitch Deck Presentation
 
TrustArc Webinar - How to Build Consumer Trust Through Data Privacy
TrustArc Webinar - How to Build Consumer Trust Through Data PrivacyTrustArc Webinar - How to Build Consumer Trust Through Data Privacy
TrustArc Webinar - How to Build Consumer Trust Through Data Privacy
 
What is DBT - The Ultimate Data Build Tool.pdf
What is DBT - The Ultimate Data Build Tool.pdfWhat is DBT - The Ultimate Data Build Tool.pdf
What is DBT - The Ultimate Data Build Tool.pdf
 
Unraveling Multimodality with Large Language Models.pdf
Unraveling Multimodality with Large Language Models.pdfUnraveling Multimodality with Large Language Models.pdf
Unraveling Multimodality with Large Language Models.pdf
 
Are Multi-Cloud and Serverless Good or Bad?
Are Multi-Cloud and Serverless Good or Bad?Are Multi-Cloud and Serverless Good or Bad?
Are Multi-Cloud and Serverless Good or Bad?
 
Transcript: New from BookNet Canada for 2024: Loan Stars - Tech Forum 2024
Transcript: New from BookNet Canada for 2024: Loan Stars - Tech Forum 2024Transcript: New from BookNet Canada for 2024: Loan Stars - Tech Forum 2024
Transcript: New from BookNet Canada for 2024: Loan Stars - Tech Forum 2024
 
Nell’iperspazio con Rocket: il Framework Web di Rust!
Nell’iperspazio con Rocket: il Framework Web di Rust!Nell’iperspazio con Rocket: il Framework Web di Rust!
Nell’iperspazio con Rocket: il Framework Web di Rust!
 
The Ultimate Guide to Choosing WordPress Pros and Cons
The Ultimate Guide to Choosing WordPress Pros and ConsThe Ultimate Guide to Choosing WordPress Pros and Cons
The Ultimate Guide to Choosing WordPress Pros and Cons
 
"Subclassing and Composition – A Pythonic Tour of Trade-Offs", Hynek Schlawack
"Subclassing and Composition – A Pythonic Tour of Trade-Offs", Hynek Schlawack"Subclassing and Composition – A Pythonic Tour of Trade-Offs", Hynek Schlawack
"Subclassing and Composition – A Pythonic Tour of Trade-Offs", Hynek Schlawack
 
Passkey Providers and Enabling Portability: FIDO Paris Seminar.pptx
Passkey Providers and Enabling Portability: FIDO Paris Seminar.pptxPasskey Providers and Enabling Portability: FIDO Paris Seminar.pptx
Passkey Providers and Enabling Portability: FIDO Paris Seminar.pptx
 
New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
 
A Deep Dive on Passkeys: FIDO Paris Seminar.pptx
A Deep Dive on Passkeys: FIDO Paris Seminar.pptxA Deep Dive on Passkeys: FIDO Paris Seminar.pptx
A Deep Dive on Passkeys: FIDO Paris Seminar.pptx
 
Transcript: New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
Transcript: New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024Transcript: New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
Transcript: New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
 

ClueCon2009: The Security Saga of SysAdmin Steve