<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/'><id>tag:blogger.com,1999:blog-6965515748199796807.post7731610981847695312..comments</id><updated>2012-02-01T17:37:07.224-08:00</updated><category term='twitter security'/><category term='invite scans'/><category term='storming sip security'/><category term='vulnerability'/><category term='blackhat'/><category term='sipvicious update'/><category term='replay'/><category term='voip ids'/><category term='voip phishing'/><category term='iax2autohack'/><category term='sips'/><category term='backtrack'/><category term='hids'/><category term='voip fraud'/><category term='flaw'/><category term='extension'/><category term='spam'/><category term='vast'/><category term='defcon 15'/><category term='xss'/><category term='site news'/><category term='ip phone hack'/><category term='voip scanning'/><category term='voip attack'/><category term='cisco tftp'/><category term='enablesecurity'/><category term='sec-t'/><category term='3cx'/><category term='sip flood'/><category term='shadow communication'/><category term='asterisk logs'/><category term='Catalin Slate'/><category term='re-invite'/><category term='root'/><category term='sniff voip'/><category term='wireless security'/><category term='asterisk'/><category term='mikey'/><category term='sip open relay'/><category term='gold-lock'/><category term='voip article'/><category term='ripe labs'/><category term='har'/><category term='rtp'/><category term='Microsoft Outlook'/><category term='buffer overflow'/><category term='toll fraud'/><category term='immunity'/><category term='trixbox tftp'/><category term='jailbreak'/><category term='pbx hacked'/><category term='svn'/><category term='securstar'/><category term='spit'/><category term='free phone calls'/><category term='podcast'/><category term='brussels security'/><category term='sjphone'/><category term='vishing'/><category term='pbx security'/><category term='svwar'/><category term='reverse engineering'/><category term='hacking'/><category term='phone phreak'/><category term='ip phone'/><category term='port 5060'/><category term='voip security course'/><category term='x-lite'/><category term='asterisk security'/><category term='madyes'/><category term='sip scan'/><category term='security tools'/><category term='canvas'/><category term='mosdef'/><category term='web application security'/><category term='grandstream'/><category term='update'/><category term='paper'/><category term='independent research'/><category term='ec2 flood'/><category term='voipscanner'/><category term='krakow'/><category term='voip snort'/><category term='cookies'/><category term='svcrash'/><category term='pbx'/><category term='e911'/><category term='24c3'/><category term='mediadefender'/><category term='goodies'/><category term='sdes'/><category term='voip lab'/><category term='Microsoft Office Communicator'/><category term='tftp brute force'/><category term='voip botnet'/><category term='sipvicious'/><category term='security consultancy X security vulnerability'/><category term='literature'/><category term='viper'/><category term='voip security paper analysis encryption zrtp mikey sdes sip'/><category term='homeland security'/><category term='zrtp'/><category term='tftp security'/><category term='DoS'/><category term='confidence 2009'/><category term='sip iax2'/><category term='sipvicious tools'/><category term='blue box'/><category term='tftp download'/><category term='zoiper abuse'/><category term='voip presentation'/><category term='har2009'/><category term='ekiga'/><category term='beer'/><category term='security paper'/><category term='siplib.py'/><category term='fingerprint'/><category term='penetration testing'/><category term='poland'/><category term='password policies'/><category term='voip report'/><category term='ccc'/><category term='open source'/><category term='phreak'/><category term='fake security'/><category term='voip penetration test'/><category term='softphone'/><category term='voip security report'/><category term='voip crime'/><category term='black hat'/><category term='white paper'/><category term='rsa europe 2008'/><category term='encryption'/><category term='cisco'/><category term='tls'/><category term='fake research'/><category term='astricon 2010'/><category term='netherlands hacking'/><category term='Unified Communications'/><category term='hardphone'/><category term='iax2lib.py'/><category term='cucm'/><category term='voipscanner.com'/><category term='digest leak'/><category term='microsoft voip'/><category term='iax2'/><category term='snort sip'/><category term='sip botnet'/><category term='voip spam'/><category term='caller id'/><category term='voip hacker'/><category term='brekeke'/><category term='voip ips'/><category term='voip flood'/><category term='h.323 voip interview robert moore'/><category term='hacker'/><category term='ghostcall'/><category term='voippack'/><category term='hacked'/><category term='invite flood'/><category term='short story'/><category term='ids'/><category term='svcrack'/><category term='sweden'/><category term='secure sip'/><category term='phone encryption'/><category term='security exploit'/><category term='voip tools'/><category term='exploit'/><category term='phonecrypt'/><category term='backtrack 3'/><category term='fingerprinting sip'/><category term='munich'/><category term='honeynet'/><category term='romania'/><category term='congress'/><category term='voip security'/><category term='sip penetration test'/><category term='voip open relay'/><category term='sip'/><category term='crack'/><category term='conference'/><category term='cellcrypt'/><category term='call forwarding'/><category term='infosec europe'/><category term='analysis'/><category term='python'/><category term='hakin9'/><category term='viper vast'/><category term='underground'/><category term='voip security training'/><category term='spoof call'/><category term='sip law'/><category term='ossec'/><category term='pbx phreak'/><category term='calea'/><category term='sip security'/><category term='callmanager'/><category term='brucon'/><category term='sniff phone calls'/><category term='blackhat europe'/><category term='voip phreak'/><category term='troopers09'/><category term='tutorial'/><category term='voip'/><category term='tftptheft'/><category term='blog'/><category term='spoof'/><category term='denial of service'/><category term='sip digest leak'/><category term='callid'/><category term='1/8 pollution'/><category term='scans'/><category term='voip honeypot'/><category term='digest authentication'/><category term='microsoft'/><category term='voip law'/><category term='svmap'/><category term='snort rules'/><category term='Cristian Ciuvat'/><category term='halloween scan'/><category term='viperlabs. sipvicious'/><category term='research and design'/><category term='sipautohack'/><title type='text'>Comments on SIPVicious: How to crash SIPVicious - introducing svcrash.py</title><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://blog.sipvicious.org/feeds/7731610981847695312/comments/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6965515748199796807/7731610981847695312/comments/default'/><link rel='alternate' type='text/html' href='http://blog.sipvicious.org/2010/06/how-to-crash-sipvicious-introducing.html'/><author><name>sandro</name><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>5</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>25</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-6965515748199796807.post-8189121956635486247</id><published>2010-11-29T12:05:48.412-08:00</published><updated>2010-11-29T12:05:48.412-08:00</updated><title type='text'>A big thanks for svcrash - worked a treat today af...</title><content type='html'>A big thanks for svcrash - worked a treat today after the useless cretins at softlayer have done nothing (three emails, a tweet, a phonecall and three days later).</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6965515748199796807/7731610981847695312/comments/default/8189121956635486247'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6965515748199796807/7731610981847695312/comments/default/8189121956635486247'/><link rel='alternate' type='text/html' href='http://blog.sipvicious.org/2010/06/how-to-crash-sipvicious-introducing.html?showComment=1291061148412#c8189121956635486247' title=''/><author><name>Adrian Bridgett</name><uri>http://smop.co.uk</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img1.blogblog.com/img/blank.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://blog.sipvicious.org/2010/06/how-to-crash-sipvicious-introducing.html' ref='tag:blogger.com,1999:blog-6965515748199796807.post-7731610981847695312' source='http://www.blogger.com/feeds/6965515748199796807/posts/default/7731610981847695312' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-879476768'/></entry><entry><id>tag:blogger.com,1999:blog-6965515748199796807.post-1107352596638930387</id><published>2010-06-24T06:11:43.143-07:00</published><updated>2010-06-24T06:11:43.143-07:00</updated><title type='text'>@Klaus: yes, and I answered that question here:
ht...</title><content type='html'>@Klaus: yes, and I answered that question here:&lt;br /&gt;http://code.google.com/p/sipvicious/wiki/SvcrashFrequentlyAskedQuestions#Won%27t_the_attackers_catch_up_and_fix_the_bug?&lt;br /&gt;&lt;br /&gt;From the faq:&lt;br /&gt;&amp;quot;&amp;quot;&amp;quot;&lt;br /&gt;The logic: flooding VoIP providers doesn&amp;#39;t do anyone good (granted that the attackers want free phone calls). Therefore the timeout added in SIPVicious version 0.2.5 is actually beneficial for both the victims and the attackers. &lt;br /&gt;&amp;quot;&amp;quot;&amp;quot;&lt;br /&gt;&lt;br /&gt;New version has the bug fixed.&lt;br /&gt;&lt;br /&gt;Oh, and as I explain the FAQ, I don&amp;#39;t expect this to be a solution. It helps mitigate but not solve the problem of bandwidth saturation.&lt;br /&gt;&lt;br /&gt;Contact me if you think the FAQ doesn&amp;#39;t cover all these issues ;-)</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6965515748199796807/7731610981847695312/comments/default/1107352596638930387'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6965515748199796807/7731610981847695312/comments/default/1107352596638930387'/><link rel='alternate' type='text/html' href='http://blog.sipvicious.org/2010/06/how-to-crash-sipvicious-introducing.html?showComment=1277385103143#c1107352596638930387' title=''/><author><name>sandro</name><uri>http://www.blogger.com/profile/10744753642125235069</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://blog.sipvicious.org/2010/06/how-to-crash-sipvicious-introducing.html' ref='tag:blogger.com,1999:blog-6965515748199796807.post-7731610981847695312' source='http://www.blogger.com/feeds/6965515748199796807/posts/default/7731610981847695312' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-1545614'/></entry><entry><id>tag:blogger.com,1999:blog-6965515748199796807.post-1229800687311253823</id><published>2010-06-24T05:53:40.090-07:00</published><updated>2010-06-24T05:53:40.090-07:00</updated><title type='text'>Don&amp;#39;t you think that attackers can edit python...</title><content type='html'>Don&amp;#39;t you think that attackers can edit python code to remove the timeout and handle the exception?</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6965515748199796807/7731610981847695312/comments/default/1229800687311253823'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6965515748199796807/7731610981847695312/comments/default/1229800687311253823'/><link rel='alternate' type='text/html' href='http://blog.sipvicious.org/2010/06/how-to-crash-sipvicious-introducing.html?showComment=1277384020090#c1229800687311253823' title=''/><author><name>Klaus</name><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img1.blogblog.com/img/blank.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://blog.sipvicious.org/2010/06/how-to-crash-sipvicious-introducing.html' ref='tag:blogger.com,1999:blog-6965515748199796807.post-7731610981847695312' source='http://www.blogger.com/feeds/6965515748199796807/posts/default/7731610981847695312' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-1302631342'/></entry><entry><id>tag:blogger.com,1999:blog-6965515748199796807.post-6014141755803642382</id><published>2010-06-22T23:17:40.627-07:00</published><updated>2010-06-22T23:17:40.627-07:00</updated><title type='text'>Freeswitch log - that would be great. Make sure th...</title><content type='html'>Freeswitch log - that would be great. Make sure that you get the source port and ideally, the user-agent or some other indication. Right now I think the best solution is the scapy / sniffing solution</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6965515748199796807/7731610981847695312/comments/default/6014141755803642382'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6965515748199796807/7731610981847695312/comments/default/6014141755803642382'/><link rel='alternate' type='text/html' href='http://blog.sipvicious.org/2010/06/how-to-crash-sipvicious-introducing.html?showComment=1277273860627#c6014141755803642382' title=''/><author><name>sandro</name><uri>http://www.blogger.com/profile/10744753642125235069</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://blog.sipvicious.org/2010/06/how-to-crash-sipvicious-introducing.html' ref='tag:blogger.com,1999:blog-6965515748199796807.post-7731610981847695312' source='http://www.blogger.com/feeds/6965515748199796807/posts/default/7731610981847695312' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-1545614'/></entry><entry><id>tag:blogger.com,1999:blog-6965515748199796807.post-6654184578534488117</id><published>2010-06-22T17:27:54.267-07:00</published><updated>2010-06-22T17:27:54.267-07:00</updated><title type='text'>Love the update, I&amp;#39;m going try and convince on...</title><content type='html'>Love the update, I&amp;#39;m going try and convince one of our programmers to add in Freeswitch log checking.&lt;br /&gt;&lt;br /&gt;Assuming it isn&amp;#39;t already in there.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6965515748199796807/7731610981847695312/comments/default/6654184578534488117'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6965515748199796807/7731610981847695312/comments/default/6654184578534488117'/><link rel='alternate' type='text/html' href='http://blog.sipvicious.org/2010/06/how-to-crash-sipvicious-introducing.html?showComment=1277252874267#c6654184578534488117' title=''/><author><name>Anonymous</name><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img1.blogblog.com/img/blank.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://blog.sipvicious.org/2010/06/how-to-crash-sipvicious-introducing.html' ref='tag:blogger.com,1999:blog-6965515748199796807.post-7731610981847695312' source='http://www.blogger.com/feeds/6965515748199796807/posts/default/7731610981847695312' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-1091201595'/></entry></feed>
