This is what it looks like:
Module 1: Introduction to VoIP technology, security threats and solutions
- Introduce the protocols
- Mitigation technologies
- How confidentiality / integrity / availability applies to VoIP
- fraud
- spying on phone calls
- modification of phone data
- denial of service
- SIP
- introduction to the protocol
- scanning for SIP
- attacking SIP
- exercises include:
- sniffing SIP
- scanning SIP
- SIP extension enumeration and online password cracking
- Avoiding toll / fraudulent calls
- INVITE floods
- Fuzzing SIP
- Using John the ripper to crack SIP passwords
- IAX2
- introduction to the protocol
- scanning for IAX2
- attacks on IAX2
- exercises include:
- online and offline password cracking
- scanning IAX2
- SCCP
- introduction to the protocol
- scanning for Cisco PBX / SCCP
- Attacks on SCCP
- exercises include:
- MiTM attacks using SCCP proxy
- Capture FAC code
- Callmanager hijack
- MGCP
- introduction to the protocol
- scanning for MGCP
- attacks on MGCP
- exercises include:
- Call fraud
- DoS on MGCP
- RTP redirection
- H.323
- introduction to the protocol
- H.225
- H.245
- scanning for H323
- attacks on H323
- Frames Injection
- DoS on H323
- introduction to the protocol
- Wiretapping
- Understanding the basics, ARP poisoning and other MiTM attacks
- exercises include using various tools, including Wireshark, for tapping VoIP calls
- RTP stream modification
- how it works
- Convert channels
- how it works, concepts and reality
- Trixbox / Elastix vulnerabilities
- default passwords are common
- TFTP abuse
- Spying on phone calls using your phone
- Privilege escalation
- Exercises include:
- spying on phone calls
- abusing Trixbox features
- exploitation of weak permissions
- Asterisk
- Dialplan injection
- Setting up a backdoor
- Hardware information gathering
- physical bridging
- passive ethernet tap
- bypassing lock / restrictions on the phone
- exercises include:
- hardware for tapping
- hardware phone abuse
- Cisco Unified Communications vulnerabilities
- Extension mobility abuse
- Webdialer
- CCMuser SQL injection
- Billing system
- Jailbreaking CUCM
- Exercises include:
- Jailbreaking CUCM
- Webdialer abuse


0 comments:
Post a Comment