[VOIPSEC] Questions about recent Sipera reported RIM Blackberry (and other VoIP phone) vulnerabilities
Raul Siles
raul.siles at gmail.com
Fri Apr 6 03:38:34 CDT 2007
Further discussion about the VoIP Vulnerabilities and Exposures (VVE) will
follow on a separate thread created by Dan York in this mailing-list:
http://voipsa.org/pipermail/voipsec_voipsa.org/2007-April/002305.html.
Let's use this current thread to answer Shawn's original questions.
Thanks Shawn for your support of the VVE idea!
--
Raúl Siles
GSE
www.raulsiles.com
On 4/5/07, Vijay K. Gurbani <vkg at alcatel-lucent.com> wrote:
>
> Shawn Merdinger wrote:
> > I think the VoIP Vulnerabilities and Exposures (VVE) is a fine idea,
> > and with the right funding and organization could greatly benefit the
> > vendor, customer and research community in many, many ways.
> >
> > Considering that the academic year is almost over, and so many
> > students have an eye on security careers, perhaps some folks with
> > academic contacts could get the word out. Also, some vendors on this
> > list might consider contacting the VOIPSA leaders to show their
> > interest and support for this initiative.
>
> This is interesting, and timely. For a while now (time permitting),
> I have been compiling a list of VoIP vulnerabilities to collect
> a corpus that I can then analyze using the ITU-T X.805 security
> methodology. My aim has been to capture the data and mine
> it for vulnerabilities classified according to the dimensions
> in X.805. Hopefully, the data can pinpoint where security
> problems occur most and where we can focus our research on.
>
> The biggest open question has been of funding. If you have
> some leads to a funding source, I will be more than glad to
> pursue it.
>
> In the meantime, here is a paper that has been accepted for
> publication in this summer's Bell Labs Technical Journal
> on an early analysis of a couple of VoIP vulnerabilities.
> It gives you an idea of where I would like to go with this.
>
> Again, if you have a source of funding, I will be more than
> glad to pursue it.
>
> Regards,
>
> - vijay
> --
> Vijay K. Gurbani, Ph.D., Bell Laboratories, Alcatel-Lucent
> 2701 Lucent Lane, Rm. 9F-546, Lisle, Illinois 60532 (USA)
> Email: vkg@{alcatel-lucent.com,bell-labs.com,acm.org}
> WWW: http://www.alcatel-lucent.com/bell-labs
>
>
More information about the Voipsec
mailing list