Menu DaniWeb
Log In Sign Up
  • Read
  • Contribute
  • Meet
  1. Home
  2. Hardware and Software Forum
  3. Networking Forum
  4. News Stories
  5. News Story

French reveal multiple vulnerabilities in popular PBX software

17 Years Ago happygeek 0 Tallied Votes 168 Views Share

FrSIRT, the French Security Incident Response Team, has reported that multiple vulnerabilities have been identified in various IP-PBX software applications that can be exploited by attackers to bypass security restrictions and cause denial of service attacks or otherwise compromise vulnerable systems. The software is used by an ever increasing number of companies in order to computerise their telephone switchboard systems and implement low cost Internet calls.

A number of issues have been highlighted by FrSIRT, including a buffer overflow error in the RTP payload handling code when processing a malformed INVITE or SIP packet with SDP. This could be exploited in order to execute arbitrary code. There is also a report of an error in the SIP channel driver itself when handling invalid "From" headers, which could be exploited to perform unauthenticated calls.

"Recent reports suggest that as many as 50 per cent of major companies are using Internet telephony services as a way of cutting their telecommunications costs, but our analysis is that they also need to review their IP telephony security arrangements as well" Rob Rachwald, Fortify Software's director of product marketing told us, adding "the buffer overload problem in the RTP payload handling code when dealing with a malformed INVITE or SIM packet with SDP, is, we predict, one of several buffer-based security problems you're going to see with company IP telephony systems in the near future. Most companies have installed multi-layered security technology on their computer network, but IP telephony services almost always escape the scrutiny of the IT security systems in place to protect a company's computers and network technology. That situation will change, we predict, as hackers from the criminal side of things start to realise the revenue potential from hacking into company PBXs and then hack for monetary gain from that route."

cybersecurity
About the Author
Member Avatar for happygeek
happygeek 2,411 Most Valuable Poster Team Colleague Featured Poster

A freelance technology journalist for 30 years, I have been a Contributing Editor at PC Pro (one of the best selling computer magazines in the UK) for most of them. As well as currently contributing to Forbes.com, The Times and Sunday Times via Raconteur…

Be the first to reply
Be a part of the DaniWeb community

We're a friendly, industry-focused community of developers, IT pros, digital marketers, and technology enthusiasts meeting, networking, learning, and sharing knowledge.

Sign Up — It's Free!
Related Topics
  • Member Avatar Cult of the Dead Cow releases Google hacking tool 1
  • Member Avatar Ten reasons why Harry Potter has not been hacked 3
  • Member Avatar HELP with Toshiba Laptop! 4
  • Member Avatar The strange case of the farting virus 0
  • Member Avatar What is a frame? 4
  • Member Avatar US Customs randomly confiscate laptops in global terror fight 11
  • Member Avatar Making dial up wireless 2
  • Member Avatar Internet cable cut conspiracy 0
  • Member Avatar Adding network switch to a router 4
  • Member Avatar Software identifies potential pedophiles online 6
  • Member Avatar connecting remote domain 4
  • Member Avatar Linux Kernel 2.6.x vulnerabilities 4
  • Member Avatar No wireless conection 1
  • Member Avatar Fewer flaws FUD wars as Microsoft paints misleading picture of Linux security 3
  • Member Avatar How to share Internet connection with Motorola Cable modem? 3
  • Member Avatar New security threats as DNS flaw is uncovered 0
  • Member Avatar Battley batters BBC as iPlayer gets hacked. Again 1
  • Member Avatar Gentoo Linux PHP Security Advisory 4
  • Member Avatar Warning! Linux Security. Are You at Risk? 3
  • Member Avatar Debian releases fix for Linux kernel 2.6.8 vulnerabilities 1
Not what you need?

Reach out to all the awesome people in our networking community by starting your own topic. We equally welcome both specific questions as well as open-ended discussions.

Start New Topic
Topics Feed
Reply to this Topic
Edit Preview

Share Post

Insert Code Block

  • Forums
  • Forum Index
  • Hardware/Software
    • Recommended Topics
  • Programming
    • Recommended Topics
  • Digital Media
    • Recommended Topics
  • Community Center
    • Recommended Topics
  • Latest Content
  • Newest Topics
  • Latest Topics
  • Latest Posts
  • Latest Comments
  • Top Tags
  • Topics Feed
  • Social
  • Top Members
  • Meet People
  • Community Functions
  • DaniWeb Premium
  • Newsletter Archive
  • Markdown Syntax
  • Community Rules
  • Developer APIs
  • Connect API
  • Forum API Docs
  • Tools
  • SEO Backlink Checker
  • Legal
  • Terms of Service
  • Privacy Policy
  • FAQ
  • About Us
  • Advertise
  • Contact Us
© 2025 DaniWeb® LLC