[VOIPSEC] VoIP and Fraud

Geoffrey esoteric at 3times25.net
Fri Feb 18 06:23:21 CST 2005


Christopher A. Martin wrote:
> You could only easily capture usable data if the carrier is not implementing
> SIP Digest authentication which uses MD5 hash combined with a fresh random
> number provided during authentication (although not all methods are
> authenticated depending on the carrier).

So, how does one determine this?  That is, outside of taking the 
vendor's word for it.

-- 
Until later, Geoffrey




More information about the Voipsec mailing list