Tags SECURITY


Defend the BroadWorks XSP from Device Management Scanning Attacks

Cisco BroadWorks Device Management (DMS) servers are under continuous attack, as bad actors seek to access SIP Device configuration details. They use ths configurations to compromise the service, committing toll fraud, including traffic pumping costing millions of dollars per year. This article explains defensive approaches and gives a complete configuration to mitigate these attacks using a free, open source tool.


ECG: Engineering BroadWorks at US Department of Justice

MIAMI, FLORIDA - BroadSoft Connections 2018 - The US Department of Justice (DOJ) has now allowed ECG to publish information about the long-term relationship in which ECG, Inc. has been proudly supporting Federal law enforcement since 2007. This partnership is one of ECG's proudest contributions to reliable communications for critical, life-saving goals. The US DOJ approved release of the info...


Using SIP to Block Robocalling: On the Telephone, Nobody Knows You're a Robot

Robocalling, enabled by VoIP, causes real social harm Filtering based on Caller ID brings some temporary relief The telecom industry has real work ahead to protect Caller ID with STIR VoIP Drove down the cost of making phone calls. We love that about VoIP: free long distance! In the telecom industry now, the idea that calls within a country would cost a retail user more than local calls seems...


Cisco Crowdsources Critical Announcements: SSL Certificate Changes on SPA-500 phones

The Cisco Small Business SPA-500 series phones (such as the SPA-502G, SPA-508G) include a Cisco-signed SSL certificate. Until very recently, all of the Cisco SPA-500-series phones shipped were signed by a Sipura certificate. Sipura was the Korean company that was bought by Linksys before Linksys was bought by Cisco. Sometime after August 2013, Cisco Small Business started shipping phones sig...


"URL" Dialing: Calling arbitrary SIP places on the Internet

BroadWorks calls it "URL Dialing": calling from your hosted PBX VoIP phone or SIP Trunking device to a random SIP URI. Lately, Polycom has been handing out SIP URIs and inviting people to test out their video bridges. Let's say you want to call to sip:1234@opensips.org -- how should it work? Most VoIP services providers -- such as those built on BroadWorks and Metaswitch -- don't allow calls fr...


Interest High in VoIP Security at SIPNOC 2012

Large Financial Losses Dominate Concern June 2012, Hyatt Dulles, Sterling, Virginia, USA: Carrier VoIP Security was the first technical topic discussed at the SIPForum's SIPNOC 2012 conference. A standing-room-only crowd of engineers attended an informal Birds-of-Feather (BOF) session on the latest in VoIP Security Threats and Prevention techniques. Dollars Lost, Interest Gained Why th...