VoIP vulnerabilities explained

VoIP vulnerabilities are weaknesses in the VoIP protocol or its implementations that expose users to privacy violations and other problems. VoIP is a group of technologies that enable voice calls online. VoIP contains similar vulnerabilities to those of other internet use.

Risks are not usually mentioned to potential customers.[1] VoIP provides no specific protections against fraud and illicit practices.

Vulnerabilities

Eavesdropping

Unencrypted connections are vulnerable to security breaches. Hackers/trackers can eavesdrop on conversations and extract valuable data.[2] [3]

Network attacks

Attacks on the user network or internet provider can disrupt or destroy the connection. Since VoIP requires an internet connection, direct attacks on the internet connection, or provider, can be effective. Such attacks target office telephony. Mobile applications that do not rely on an internet connection to make calls[4] are immune to such attacks.

Default security settings

VoIP phones are smart devices that need to be configured. In some cases, Chinese manufacturers are using default passwords that lead to vulnerabilities.[5]

VOIP over Wi-Fi

While VoIP is relatively secure, it still needs a source of internet, which is often a Wi-Fi network, making VoIP subject to Wi-Fi vulnerabilities[6]

Exploits

Spam

VoIP is subject to spam called SPIT (Spam over Internet Telephony). Using the extensions provided by VoIP PBX capabilities, the spammer can harass their target from different numbers. The process can be automated and can fill the target's voice mail with notifications. The spammer can make calls often enough to block the target from getting important calls.[7]

Phishing

VoIP users can change their Caller ID (a.k.a. Caller ID spoofing), allowing a caller to pose as a relative or colleague in order to extract information, money or benefits from the target.[8]

See also

Notes and References

  1. Securing VoIP Networks book by Peter Thermos, Ari Takanen,
  2. Web site: Unencrypted VoIP poses security threat. Stephen Pritchard. March 28, 2007. ITPro.
  3. Web site: Security Advisories ⋆ Asterisk. Asterisk.
  4. Web site: Mobile VOIP alternative for business international calls. www.pindo.me.
  5. Web site: Research: VoIP Phones Can Be Exploited If Not Set Up Properly.
  6. Web site: Top 9 VoIP Threats And Vulnerabilities. Andrew R.. Hickey. December 18, 2007. CRN.
  7. Web site: Top 14 VoIP vulnerabilities. Ellen. Messmer. October 1, 2007. Network World.
  8. Web site: The Vulnerabilities of VoIP.