Questions tagged [voip]

VoIP is an acronym for "Voice over IP (or Internet Protocol)" which is a term that encapsulates the technologies that enable telephonic communication using the Internet as the carrier network rather than the traditional publicly switched telephone network.

65 questions
29
votes
8 answers

Do secure phone lines exist?

I could be out of context here about security, but , I would like to know if phone lines or phone calls over VOIP could be made secure . I know that Skype and other VOIP service providers have to give access to respective governments of countries…
Sairam
  • 693
  • 1
  • 9
  • 15
24
votes
1 answer

How can I spoof a phone call and make it appear to come from another phone?

I'm performing a penetration test against a company. Part of my social engineering procedure is to contact the IT department and try to convince them to that I'm an employee in the company and get them to reveal some sensitive information including…
Adi
  • 43,808
  • 16
  • 135
  • 167
23
votes
3 answers

Is Signal a secure and secret way to communicate via voice calls?

Signal (former RedPhone) provides end-to-end encryption for your calls, securing your conversations so that nobody can listen in. But really, how is the probability that a voice conversation is wiretapped still? And are the contact-details (like…
rubo77
  • 2,350
  • 10
  • 26
  • 48
15
votes
1 answer

Why is caller ID spoofing so simple, and catching offenders so hard?

There is plenty of software which allows a user to input a recipient's information, and a fake-originator's information, and the software will complete the caller ID spoof. I'm trying to understand why the telephony stack is so vulnerable to…
user3.1415927
  • 301
  • 1
  • 7
13
votes
1 answer

Connection to ports 2000 and 5060 successful despite filtering

I run my own (Ubuntu based) router and have iptables configured to drop all incoming packets by default. To my surprise, running an nmap scan (from the WAN side) shows two open ports related to VOIP: nmap -Pn -v --reason XXX.net Starting Nmap 7.60…
Christian David
  • 233
  • 1
  • 2
  • 5
12
votes
3 answers

Is secure Caller ID possible for SIP / VOIP?

Is there any way (standard, proposed or draft) that will allow for secure Caller ID over SIP / VOIP networks? I have constantly heard that Caller ID is insecure when used over these services. Can anyone explain why Caller ID is insecure when used…
makerofthings7
  • 50,090
  • 54
  • 250
  • 536
11
votes
2 answers

Is Mumble encryption end to end?

Is it possible for a Mumble server operator to monitor or record users' conversations? Or are Mumble conversations encrypted end-to-end?
user47127
  • 113
  • 1
  • 1
  • 4
11
votes
4 answers

How are "security levels" of identities in TeamSpeak 3 implemented?

TeamSpeak 3 VoIP communication system uses a concept of so called identities to identify the client to the server. These identities are basically public/private key pairs. In order to prevent people from just generating a new identity after being,…
Max Truxa
  • 213
  • 1
  • 2
  • 6
9
votes
3 answers

How do countries block encrypted protocols like Skype?

I can't make Skype calls outside of my country because they are blocked. As far as I understand, Skype uses strong encryption for the calls, thus, making Deep Packet Inspection unable to detect it. If it's not DPI, then what it can be? People I…
Mr.voip
  • 93
  • 1
  • 4
9
votes
2 answers

How do you Secure VOIP in a large organization

As part of a large organization looking to implement VoIP, to get on the bandwagon of savings and converged network focus, I'm being asked to look at the security concerns to develop a policy to help define a direction. Since I'm a geek first, and…
Ori
  • 2,757
  • 1
  • 15
  • 29
9
votes
1 answer

What are the vulnerabilities of VOIP-specific security protocols?

Existing relevant questions: How do you Secure VOIP in a large organization What are the main issues and best practice security controls when exposing SIP and H.323 to the Internet? Do secure phone lines exist? - especially advice by a certain…
Deer Hunter
  • 5,297
  • 5
  • 33
  • 50
9
votes
5 answers

Does chatting over Skype expose my IP address?

Is there a way to identify a person's IP address in Skype, when you're chatting with them? Does this depend on their Skype settings? And if you've recorded chat messages, can they lead to the actual person IP address, or their ISP's?
J.Olufsen
  • 231
  • 1
  • 4
  • 8
8
votes
1 answer

What are the main issues and best practice security controls when exposing SIP and H.323 to the Internet?

What are the main issues and recommended controls when exposing SIP and H.323 to the Internet (could be for voice, video, and instant messaging traffic or all three)? Specifically I'm looking for best practices in firewall/DMZ architecture, and any…
frankodwyer
  • 1,907
  • 12
  • 13
6
votes
1 answer

How to pentest DTLS-SRTP?

I'm currently working on a penetration test about DTLS-SRTP strengths and weaknesses. But I'm stuck on an eavesdropping test using Wireshark. Yes, it's protected by SRTP, but: What's DTLS actually doing/working on the media channel? What are…
alsterisk
  • 61
  • 1
6
votes
4 answers

Does a separate internet connection increase security for remote users?

Our network admin has requested that a single remote employee purchase a separate modem in their house for "work" traffic. I question if this is a legitimate security practice of any kind especially because other employees access company resources…
J K
  • 221
  • 1
  • 4
1
2 3 4 5