<?xml version="1.0"?>
<rss version="2.0" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:media="http://search.yahoo.com/mrss/" xmlns:yt="http://gdata.youtube.com/schemas/2007">
   <channel>
      <title>VOIP Security Alliance (VOIPSA)-All Feeds</title>
      <description>Pipes Output</description>
      <link>http://pipes.yahoo.com/pipes/pipe.info?_id=3mmCjDy82xGmCvJXIBeTaQ</link>
      <pubDate>Sun, 29 Nov 2009 16:49:22 -0800</pubDate>
      <generator>http://pipes.yahoo.com/pipes/</generator>
      <item>
         <title>Blue Box Podcast #86 out, with an update on the show</title>
         <link>http://feedproxy.google.com/~r/VoiceOfVoipsa/~3/pYPUwnn3OHI/</link>
         <description>After literally a year of being away from the microphone, Jonathan and I posted Blue Box Podcast Episode #86 yesterday. The show is really just an update on what we&amp;#8217;ve been doing over the past year, why there haven&amp;#8217;t been new shows, what we are thinking about for the future, etc. We had [...]</description>
         <guid isPermaLink="false">http://voipsa.org/blog/?p=816</guid>
         <pubDate>Fri, 23 Oct 2009 06:32:22 -0700</pubDate>
         <content:encoded><![CDATA[<p><a rel="nofollow" target="_blank" href="http://www.blueboxpodcast.com/2009/10/blue-box-86-an-update-on-blue-box-one-year-later.html"><img src="http://voipsa.org/blog/wp-content/uploads/2007/12/imagesmd-bluebox157-2.jpg" alt="MD_bluebox157-2.jpg" border="0" width="157" height="157" align="right"/></a>After literally a year of being away from the microphone, Jonathan and I <a rel="nofollow" target="_blank" href="http://www.blueboxpodcast.com/2009/10/blue-box-86-an-update-on-blue-box-one-year-later.html">posted Blue Box Podcast Episode #86 yesterday</a>. The show is really just an update on what we&#8217;ve been doing over the past year, why there haven&#8217;t been new shows, what we are thinking about for the future, etc. We had <a rel="nofollow" target="_blank" href="http://voipsa.org/blog/2009/10/23/fugitive-voip-fraudster-edwin-pena-extradited-to-be-arraigned-today-in-nj-court/">a brief update on the Edwin Pena case</a> and talked about the fact that sadly the VoIP security issues out there really haven&#8217;t changed much in the past year.</p>
<p>Jonathan and I <em>have</em> decided that we won&#8217;t be returning Blue Box to its original <em>weekly</em> schedule. We&#8217;re not sure, honestly, how often we&#8217;ll put out new episodes&#8230; we will see how schedules and such align. In the meantime, BBP 86 is up there for those who would like an update.<br />
<p>Thanks to all of you who have continued to listen and who also sent notes to us while we were offline wondering how things were going. Thanks.</p>
<hr />
<p><em>If you found this post interesting or helpful, please consider either <a rel="nofollow" target="_blank" href="http://feeds2.feedburner.com/VoiceOfVoipsa">subscribing via RSS</a> or <a rel="nofollow" target="_blank" href="http://twitter.com/voipsa">following VOIPSA on Twitter</a>.</em></p>
<hr />
<div class="feedflare">
<a rel="nofollow" target="_blank" href="http://feeds.feedburner.com/~ff/VoiceOfVoipsa?a=pYPUwnn3OHI:FsxviQPUVUQ:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/VoiceOfVoipsa?d=yIl2AUoC8zA" border="0"></a> <a rel="nofollow" target="_blank" href="http://feeds.feedburner.com/~ff/VoiceOfVoipsa?a=pYPUwnn3OHI:FsxviQPUVUQ:7Q72WNTAKBA"><img src="http://feeds.feedburner.com/~ff/VoiceOfVoipsa?d=7Q72WNTAKBA" border="0"></a> <a rel="nofollow" target="_blank" href="http://feeds.feedburner.com/~ff/VoiceOfVoipsa?a=pYPUwnn3OHI:FsxviQPUVUQ:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/VoiceOfVoipsa?i=pYPUwnn3OHI:FsxviQPUVUQ:V_sGLiPBpWU" border="0"></a> <a rel="nofollow" target="_blank" href="http://feeds.feedburner.com/~ff/VoiceOfVoipsa?a=pYPUwnn3OHI:FsxviQPUVUQ:dnMXMwOfBR0"><img src="http://feeds.feedburner.com/~ff/VoiceOfVoipsa?d=dnMXMwOfBR0" border="0"></a> <a rel="nofollow" target="_blank" href="http://feeds.feedburner.com/~ff/VoiceOfVoipsa?a=pYPUwnn3OHI:FsxviQPUVUQ:qj6IDK7rITs"><img src="http://feeds.feedburner.com/~ff/VoiceOfVoipsa?d=qj6IDK7rITs" border="0"></a> <a rel="nofollow" target="_blank" href="http://feeds.feedburner.com/~ff/VoiceOfVoipsa?a=pYPUwnn3OHI:FsxviQPUVUQ:gIN9vFwOqvQ"><img src="http://feeds.feedburner.com/~ff/VoiceOfVoipsa?i=pYPUwnn3OHI:FsxviQPUVUQ:gIN9vFwOqvQ" border="0"></a>
</div><img src="http://feeds.feedburner.com/~r/VoiceOfVoipsa/~4/pYPUwnn3OHI" height="1" width="1"/>]]></content:encoded>
      </item>
      <item>
         <title>Fugitive VoIP fraudster Edwin Pena extradited, to be arraigned today in NJ court</title>
         <link>http://feedproxy.google.com/~r/VoiceOfVoipsa/~3/8H-Z3kFBMuQ/</link>
         <description>Following up on a story we&amp;#8217;ve literally been covering for years, SC Magazine reported last week that VoIP fraudster Edwin Pena was to be arrive back in the USA last Friday, October 16. The FBI news release indicates that Pena is to be arraigned today, October 23rd, in New Jersey.
For those not familiar, the story [...]</description>
         <guid isPermaLink="false">http://voipsa.org/blog/?p=814</guid>
         <pubDate>Fri, 23 Oct 2009 06:16:04 -0700</pubDate>
         <content:encoded><![CDATA[<p>Following up on a story we&#8217;ve literally been covering for years, <a rel="nofollow" target="_blank" href="http://www.scmagazineus.com/Venezuelan-VoIP-hacker-caught-back-in-court-Friday/article/155458/">SC Magazine reported last week</a> that VoIP fraudster Edwin Pena was to be arrive back in the USA last Friday, October 16. The <a rel="nofollow" target="_blank" href="http://newark.fbi.gov/dojpressrel/2009/nk101509.htm">FBI news release indicates</a> that Pena is to be arraigned <em>today</em>, October 23rd, in New Jersey.</p>
<p>For those not familiar, the story <a rel="nofollow" target="_blank" href="http://voipsa.org/blog/2006/06/07/hacker-cracks-net-phone-providers-for-gain/">began back in June 2006</a> with the initial reports that Pena masterminded a scheme to sell phone service and then running that service over other providers networks. We covered this at some length back in <a rel="nofollow" target="_blank" href="http://www.blueboxpodcast.com/2006/06/blue_box_31_voi.html">Blue Box Podcast #31</a>. Then, in September 2006, <a rel="nofollow" target="_blank" href="http://voipsa.org/blog/2006/09/16/fraudster-goes-to-ground/">Pena fled the country</a> and was a fugitive abroad until <a rel="nofollow" target="_blank" href="http://voipsa.org/blog/2009/02/17/voip-fraudster-penas-fugitive-run-comes-to-an-end/">he was nabbed in Mexico in February 2009</a>.</p>
<p>Meanwhile, his co-conspirator Robert Moore was convicted and sent to jail. I had a chance to <a rel="nofollow" target="_blank" href="http://voipsa.org/blog/2007/08/03/telecom-junkies-podcast-interview-with-a-voip-hacker-robert-moore-of-the-penamoore-voip-fraud-case/">interview Robert in conjunction with the Voice Report folks as part of their Telecom Junkies podcast</a> (also <a rel="nofollow" target="_blank" href="http://www.blueboxpodcast.com/2007/08/telecom-junkies.html">linked here</a>) which provided some insight into how the attack took place.</p>
<p>The good news now is that Pena is back in the US, in jail, and to be arraigned sometime today. Good to see this work by the FBI and other agencies.</p>
<hr />
<p><em>If you found this post interesting or helpful, please consider either <a rel="nofollow" target="_blank" href="http://feeds2.feedburner.com/VoiceOfVoipsa">subscribing via RSS</a> or <a rel="nofollow" target="_blank" href="http://twitter.com/voipsa">following VOIPSA on Twitter</a>.</em></p>
<hr />
<div class="feedflare">
<a rel="nofollow" target="_blank" href="http://feeds.feedburner.com/~ff/VoiceOfVoipsa?a=8H-Z3kFBMuQ:EhDhB_tYfsQ:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/VoiceOfVoipsa?d=yIl2AUoC8zA" border="0"></a> <a rel="nofollow" target="_blank" href="http://feeds.feedburner.com/~ff/VoiceOfVoipsa?a=8H-Z3kFBMuQ:EhDhB_tYfsQ:7Q72WNTAKBA"><img src="http://feeds.feedburner.com/~ff/VoiceOfVoipsa?d=7Q72WNTAKBA" border="0"></a> <a rel="nofollow" target="_blank" href="http://feeds.feedburner.com/~ff/VoiceOfVoipsa?a=8H-Z3kFBMuQ:EhDhB_tYfsQ:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/VoiceOfVoipsa?i=8H-Z3kFBMuQ:EhDhB_tYfsQ:V_sGLiPBpWU" border="0"></a> <a rel="nofollow" target="_blank" href="http://feeds.feedburner.com/~ff/VoiceOfVoipsa?a=8H-Z3kFBMuQ:EhDhB_tYfsQ:dnMXMwOfBR0"><img src="http://feeds.feedburner.com/~ff/VoiceOfVoipsa?d=dnMXMwOfBR0" border="0"></a> <a rel="nofollow" target="_blank" href="http://feeds.feedburner.com/~ff/VoiceOfVoipsa?a=8H-Z3kFBMuQ:EhDhB_tYfsQ:qj6IDK7rITs"><img src="http://feeds.feedburner.com/~ff/VoiceOfVoipsa?d=qj6IDK7rITs" border="0"></a> <a rel="nofollow" target="_blank" href="http://feeds.feedburner.com/~ff/VoiceOfVoipsa?a=8H-Z3kFBMuQ:EhDhB_tYfsQ:gIN9vFwOqvQ"><img src="http://feeds.feedburner.com/~ff/VoiceOfVoipsa?i=8H-Z3kFBMuQ:EhDhB_tYfsQ:gIN9vFwOqvQ" border="0"></a>
</div><img src="http://feeds.feedburner.com/~r/VoiceOfVoipsa/~4/8H-Z3kFBMuQ" height="1" width="1"/>]]></content:encoded>
      </item>
      <item>
         <title>Blue Box #86: An Update on Blue Box, One Year Later</title>
         <link>http://www.blueboxpodcast.com/2009/10/blue-box-86-an-update-on-blue-box-one-year-later.html</link>
         <description>&lt;div&gt;&lt;p&gt;&lt;strong&gt;Synopsis:&lt;/strong&gt; Blue Box #86: Dan and Jonathan provide an update on what's happened in the year since Blue Box #85 and talk a bit about what's next &lt;/p&gt;&lt;hr /&gt;&lt;p&gt;Welcome to &lt;strong&gt;Blue Box: The VoIP Security Podcast&lt;/strong&gt; #86, a 19-minute podcast from Dan York and Jonathan Zar covering VoIP security news, comments and opinions.&lt;/p&gt; &lt;p&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://media.libsyn.com/media/lodestar/BBP-086-2009-10-22.mp3&quot;&gt;Download the show here&lt;/a&gt; (MP3, 9 MB) or &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://feeds.feedburner.com/BlueBox&quot;&gt;subscribe to the RSS feed&lt;/a&gt; to download the show automatically.&lt;/p&gt; &lt;p&gt;You may also listen to this podcast right now:&lt;/p&gt; &lt;p&gt; &lt;/p&gt; &lt;p&gt;&lt;strong&gt;Show Content:&lt;/strong&gt;&lt;/p&gt; &lt;ul&gt; &lt;li&gt;00:20 - Intro to the show, contact information and how to provide comments.&amp;#0160; Welcome to all the new listeners - and to all those listeners who have been here for so long!&lt;/li&gt;
&lt;li&gt;Dan and Jonathan discuss what has happened in the past year and why there have not been new shows.
&lt;li&gt;Discussion of what some of the main issues in VoIP security have been over the past year.
&lt;li&gt;Mention that &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.scmagazineus.com/Venezuelan-VoIP-hacker-caught-back-in-court-Friday/article/155458/&quot;&gt;fugitive Edwin Pena was extradited back to the US and arraigned in New Jersey court last Friday&lt;/a&gt;
&lt;li&gt;Mention of the recent traffic on the &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.voipsa.org/VOIPSEC/&quot;&gt;VOIPSEC &lt;/a&gt;public mailing list&lt;br /&gt;
&lt;/li&gt;
&lt;li&gt;Wrap-up of the show&lt;br /&gt;
&lt;/li&gt;
&lt;li&gt;19:38 - End of show&amp;#0160; &lt;/li&gt;
&lt;/ul&gt; &lt;p&gt;Comments, suggestions and feedback are welcome either as replies to this post or via e-mail to &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;mailto:blueboxpodcast@gmail.com&quot;&gt;blueboxpodcast@gmail.com&lt;/a&gt;. Audio comments sent as attached MP3 files are definitely welcome and will be played in future shows. You may also call the listener comment line at either +1-415-830-5439 or via SIP to '&lt;a rel=&quot;nofollow&quot;&gt;bluebox@voipuser.org&lt;/a&gt;' to leave a comment there.&amp;#0160; &lt;/p&gt; &lt;p&gt;Thank you for listening and please do let us know what you think of the show. &lt;/p&gt;
&lt;hr/&gt;
&lt;p&gt;&lt;em&gt;If you found this post interesting or useful, please consider either &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://http://feedproxy.google.com/BlueBox&quot;&gt;subscribing to the RSS feed&lt;/a&gt; or &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://twitter.com/blueboxpodcast&quot;&gt;following BlueBox on Twitter&lt;/a&gt;.&lt;/em&gt;
&lt;hr&gt;&lt;/div&gt;</description>
         <author>Dan York</author>
         <guid isPermaLink="false">tag:typepad.com,2003:post-6a00d8341bfc6e53ef0120a66a2f02970c</guid>
         <pubDate>Thu, 22 Oct 2009 05:47:39 -0700</pubDate>
      </item>
      <item>
         <title>VoIP on the iPhone and iPod Touch – a security warning</title>
         <link>http://feedproxy.google.com/~r/VoiceOfVoipsa/~3/llDubgcv5F0/</link>
         <description>At first sight, using any VoIP client on the iPhone or the iPod Touch (a.k.a. iDevices) may seem like a uninteresting thing. The reason for this is that Apple does not allow 3rd party applications to run in the background. So when a user close down his iVoIP Client he will not be able to [...]</description>
         <guid isPermaLink="false">http://voipsa.org/blog/?p=807</guid>
         <pubDate>Mon, 28 Sep 2009 09:40:11 -0700</pubDate>
         <content:encoded><![CDATA[<p><img src="http://www.open-voip.com/blogs/media/blogs/vip/iVoIPclients.jpg" alt="iVoIP clients" width="217" height="259" align="left"/>At first sight, using any VoIP client on the iPhone or the iPod Touch (a.k.a. iDevices) may seem like a uninteresting thing. The reason for this is that Apple does not allow 3rd party applications to run in the background. So when a user close down his iVoIP Client he will not be able to receive any calls at all, thus defeating the reason for using VoIP on these devices in the first place.</p>
<p>However, if we take <a rel="nofollow" target="_blank" href="http://www.open-voip.com/blogs/blog1/2009/09/27/voip-on-the-iphone-and-ipod-touch-a-comp">a look at some of the VoIP clients offerings available</a> we notice that a few of these clients have the ability to receive incoming calls, even when the software it self is not running.</p>
<p>At first sight this seems to be a Good Thing &#8211; however, there are severe security implications by doing this. Users will in fact willingly, put them self under a man-in-the-middle attack.</p>
<p><span id="more-807"></span></p>
<h3>3rd party proxies</h3>
<p>Before continuing, let me use two pretty well known mobile applications as an example: Fring and Nimbuzz. Both applications support a whole slew of different means of communication &#8211; but if we take a closer look at the physical size of these program it become quite apparent that these applications does not have all the code for all the various services they let the user access.</p>
<p>The general rule is that these client providers will act as a proxy between the users client and the users service provider. Basically, when setting up your Nimbuzz client for SIP usage &#8211; it is not the client that will connect to your SIP server, but a server in the Nimbuzz network.</p>
<p>So in effect, Nimbuzz and Fring does keep a copy of your SIP credentials. It is unclear if they store the credential when the users client is not online.</p>
<h3>SIP and the Apple Push Notification Service (APNS)</h3>
<p>This is the new kid on the block. For quite some time now, the iDevices have had the ability to receive <em>Push Notifications</em>. This is something that could be of great use, and Apple has on numerous occasions stated how this technology can be used.</p>
<p>In practice a service provider can use the APNS to send out notifications to a specific iDevice. As far as I know, Apple has put no restriction on the content of such notifications.</p>
<p>What is happening behind the scene, is that SIP credentials stored in the iVoIP Client are transferred over to the client providers infrastructure (CPI). A server in the CPI will then re-register itself as a SIP client to your SIP server, with your SIP credentials.</p>
<p>When an incoming calls are present, the SIP signaling will be sent to the server in the CPI &#8211; and this server will then send out a <em>Push Notification</em> over the APNS netowrk, ending up in your iDevice. When the device receive the notification, it will display some information to the user. If the user confirm the notification &#8211; the VoIP Client is started, registering to your SIP server and will then accept the call.</p>
<p>In my opinion, giving away your SIP credentials to a 3rd party you have no control of, seems like a very bad idea. I also suspect that most service providers Acceptable End User Policy prohibit a user to give away his SIP credentials.</p>
<p>None of the companies providing 3rd party proxy solutions as their core business have, as far as I have found, publicly shown any documentation from a 3rd party stating that they do have a well funded security policy that is being upheld.</p>
<p>I do suspect that these companies are prime target for Black Hat telecom hackers. Just getting access to thousands of thousands SIP accounts which can be resold <strong>IS</strong> a tempting target.</p>
<h3>Possible solutions</h3>
<p>The easiest way out of this mess if of course not to enable the client to use the APNS network. However, this defeat using a iVoIP Client efficiently.</p>
<p>A much better solution would be for the CPI to offer a WebService solution.</p>
<p>When a call comes into the switch/PBX, the switch could then do a WebService call to the CPI, and the CPI would then issue the Push Notification message over the APNS.</p>
<p>This is a clean and efficient solution that will have the same result for the end user, without compromising security: A Push Notification message of a incoming call &#8211; enabling the iDevice to start up the iVoIP Client and let the client handle the call.</p>
<p>Another solution could be to let companies with their own APNS agreement, send out their own Push Notifications. I have not spent too much time with the rules that Apple have for the APNS, so I can not say if this is in fact possible.</p>
<div class="feedflare">
<a rel="nofollow" target="_blank" href="http://feeds.feedburner.com/~ff/VoiceOfVoipsa?a=llDubgcv5F0:I1mV9WUcSZ0:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/VoiceOfVoipsa?d=yIl2AUoC8zA" border="0"></a> <a rel="nofollow" target="_blank" href="http://feeds.feedburner.com/~ff/VoiceOfVoipsa?a=llDubgcv5F0:I1mV9WUcSZ0:7Q72WNTAKBA"><img src="http://feeds.feedburner.com/~ff/VoiceOfVoipsa?d=7Q72WNTAKBA" border="0"></a> <a rel="nofollow" target="_blank" href="http://feeds.feedburner.com/~ff/VoiceOfVoipsa?a=llDubgcv5F0:I1mV9WUcSZ0:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/VoiceOfVoipsa?i=llDubgcv5F0:I1mV9WUcSZ0:V_sGLiPBpWU" border="0"></a> <a rel="nofollow" target="_blank" href="http://feeds.feedburner.com/~ff/VoiceOfVoipsa?a=llDubgcv5F0:I1mV9WUcSZ0:dnMXMwOfBR0"><img src="http://feeds.feedburner.com/~ff/VoiceOfVoipsa?d=dnMXMwOfBR0" border="0"></a> <a rel="nofollow" target="_blank" href="http://feeds.feedburner.com/~ff/VoiceOfVoipsa?a=llDubgcv5F0:I1mV9WUcSZ0:qj6IDK7rITs"><img src="http://feeds.feedburner.com/~ff/VoiceOfVoipsa?d=qj6IDK7rITs" border="0"></a> <a rel="nofollow" target="_blank" href="http://feeds.feedburner.com/~ff/VoiceOfVoipsa?a=llDubgcv5F0:I1mV9WUcSZ0:gIN9vFwOqvQ"><img src="http://feeds.feedburner.com/~ff/VoiceOfVoipsa?i=llDubgcv5F0:I1mV9WUcSZ0:gIN9vFwOqvQ" border="0"></a>
</div><img src="http://feeds.feedburner.com/~r/VoiceOfVoipsa/~4/llDubgcv5F0" height="1" width="1"/>]]></content:encoded>
      </item>
      <item>
         <title>Added RSS Cloud plugin to this site (and what that means)</title>
         <link>http://feedproxy.google.com/~r/VoiceOfVoipsa/~3/Hs2ATUSbff4/</link>
         <description>For those interested in the underlying plumbing of this site, today I added the RSS Cloud plugin for WordPress to this site that is described in more detail in this post: &amp;#8220;RSSCloud for WordPress&amp;#8221;
What does this mean for you as readers?
In the short term, not much. The only RSS Cloud-enabled reader right now is Dave [...]</description>
         <guid isPermaLink="false">http://voipsa.org/blog/?p=804</guid>
         <pubDate>Fri, 11 Sep 2009 12:38:45 -0700</pubDate>
         <content:encoded><![CDATA[<p>For those interested in the underlying plumbing of this site, today I added the <a rel="nofollow" target="_blank" href="http://wordpress.org/extend/plugins/rsscloud/">RSS Cloud plugin</a> for WordPress to this site that is described in more detail in this post: &#8220;<a rel="nofollow" target="_blank" href="http://josephscott.org/archives/2009/09/rsscloud-for-wordpress/"><em>RSSCloud for WordPress</em></a>&#8221;</p>
<p>What does this mean for you as readers?</p>
<p>In the short term, not much. The only RSS Cloud-enabled reader right now is Dave Winer&#8217;s <a rel="nofollow" target="_blank" href="http://newsriver.org/river2">River2</a>.</p>
<p>However, both <a rel="nofollow" target="_blank" href="http://www.rsscloud.org/">RSS Cloud</a> and <a rel="nofollow" target="_blank" href="http://code.google.com/p/pubsubhubbub/">PubSubHubbub</a> are moving us closer to a &#8220;realtime&#8221; web where you as a reader can &#8220;subscribe&#8221; to feeds and receive updates as soon as those feeds are updated. Currently, when you &#8220;subscribe&#8221; to our RSS feed, you only see updates when your news reader <em>polls</em> the feeds to which you are subscribed. Given that a good number of feeds may <em>not</em> have changed since the last polling interval this process is also quite a waste of packets.</p>
<p>So the idea is to move from a &#8220;polling&#8221; paradigm to one of &#8220;subscribe/notify&#8221;. Much more will be happening in this space in the time ahead. In the meantime, if you do use River2 or any of the other readers that may support the RSSCloud tag, you&#8217;ll be able to interact with the Voice of VoIPSA blog in that model.</p>
<p><em>P.S. Yes, I&#8217;m also working to add the PubSubHubbub plugin for WordPress to this blog, but I&#8217;ve run into a technical issue I&#8217;m trying to debug.</em></p>
<div class="feedflare">
<a rel="nofollow" target="_blank" href="http://feeds.feedburner.com/~ff/VoiceOfVoipsa?a=Hs2ATUSbff4:Fz-c1e6nHXA:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/VoiceOfVoipsa?d=yIl2AUoC8zA" border="0"></a> <a rel="nofollow" target="_blank" href="http://feeds.feedburner.com/~ff/VoiceOfVoipsa?a=Hs2ATUSbff4:Fz-c1e6nHXA:7Q72WNTAKBA"><img src="http://feeds.feedburner.com/~ff/VoiceOfVoipsa?d=7Q72WNTAKBA" border="0"></a> <a rel="nofollow" target="_blank" href="http://feeds.feedburner.com/~ff/VoiceOfVoipsa?a=Hs2ATUSbff4:Fz-c1e6nHXA:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/VoiceOfVoipsa?i=Hs2ATUSbff4:Fz-c1e6nHXA:V_sGLiPBpWU" border="0"></a> <a rel="nofollow" target="_blank" href="http://feeds.feedburner.com/~ff/VoiceOfVoipsa?a=Hs2ATUSbff4:Fz-c1e6nHXA:dnMXMwOfBR0"><img src="http://feeds.feedburner.com/~ff/VoiceOfVoipsa?d=dnMXMwOfBR0" border="0"></a> <a rel="nofollow" target="_blank" href="http://feeds.feedburner.com/~ff/VoiceOfVoipsa?a=Hs2ATUSbff4:Fz-c1e6nHXA:qj6IDK7rITs"><img src="http://feeds.feedburner.com/~ff/VoiceOfVoipsa?d=qj6IDK7rITs" border="0"></a> <a rel="nofollow" target="_blank" href="http://feeds.feedburner.com/~ff/VoiceOfVoipsa?a=Hs2ATUSbff4:Fz-c1e6nHXA:gIN9vFwOqvQ"><img src="http://feeds.feedburner.com/~ff/VoiceOfVoipsa?i=Hs2ATUSbff4:Fz-c1e6nHXA:gIN9vFwOqvQ" border="0"></a>
</div><img src="http://feeds.feedburner.com/~r/VoiceOfVoipsa/~4/Hs2ATUSbff4" height="1" width="1"/>]]></content:encoded>
         <category>Voice of VOIPSA Info</category>
      </item>
      <item>
         <title>Stoned Bootkit</title>
         <link>http://feedproxy.google.com/~r/VoiceOfVoipsa/~3/3a9gSXyQYoA/</link>
         <description>Typically I don&amp;#8217;t follow the deluge of Windows rootkits available because the sheer number and variety make diligently understanding all of them more than fairly daunting. After all, given limited resources, one must choose their battles and specialties in the security field.
That said, occasionally a Windows rootkit surfaces that is so mean, nasty and [...]</description>
         <guid isPermaLink="false">http://voipsa.org/blog/?p=794</guid>
         <pubDate>Wed, 09 Sep 2009 07:22:04 -0700</pubDate>
         <content:encoded><![CDATA[<p><img src="http://web17.webbpro.de/uploads/images/Stoned%20Bootkit.png" alt="stoned bootkit"/>Typically I don&#8217;t follow the deluge of Windows rootkits available because the sheer number and variety make diligently understanding all of them more than fairly daunting. After all, given limited resources, one must choose their battles and specialties in the security field.</p>
<p>That said, occasionally a Windows rootkit surfaces that is so mean, nasty and downright cool, that it becomes a must-know. Such is the case with the newest release of <a rel="nofollow" target="_blank" href="http://www.stoned-vienna.com/">Stoned Bootkit</a>. Be sure to go to their site and check it out, along with the <a rel="nofollow" target="_blank" href="http://www.stoned-vienna.com/downloads/Paper.pdf">paper</a>, but here are a few highlights:</p>
 Attacks Windows XP, Sever 2003, Windows Vista, Windows 7 with one single master boot record 
 Attacks TrueCrypt full volume encryption 
 Has integrated FAT and NTFS drivers 
 Has an integrated structure for plugins and boot applications (for future development 
<p>Understanding the threats that Windows rootkits like this pose to VoIP security, especially on end users, is key.</p>
<div class="feedflare">
<a rel="nofollow" target="_blank" href="http://feeds.feedburner.com/~ff/VoiceOfVoipsa?a=3a9gSXyQYoA:76oHfI-0YfQ:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/VoiceOfVoipsa?d=yIl2AUoC8zA" border="0"></a> <a rel="nofollow" target="_blank" href="http://feeds.feedburner.com/~ff/VoiceOfVoipsa?a=3a9gSXyQYoA:76oHfI-0YfQ:7Q72WNTAKBA"><img src="http://feeds.feedburner.com/~ff/VoiceOfVoipsa?d=7Q72WNTAKBA" border="0"></a> <a rel="nofollow" target="_blank" href="http://feeds.feedburner.com/~ff/VoiceOfVoipsa?a=3a9gSXyQYoA:76oHfI-0YfQ:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/VoiceOfVoipsa?i=3a9gSXyQYoA:76oHfI-0YfQ:V_sGLiPBpWU" border="0"></a> <a rel="nofollow" target="_blank" href="http://feeds.feedburner.com/~ff/VoiceOfVoipsa?a=3a9gSXyQYoA:76oHfI-0YfQ:dnMXMwOfBR0"><img src="http://feeds.feedburner.com/~ff/VoiceOfVoipsa?d=dnMXMwOfBR0" border="0"></a> <a rel="nofollow" target="_blank" href="http://feeds.feedburner.com/~ff/VoiceOfVoipsa?a=3a9gSXyQYoA:76oHfI-0YfQ:qj6IDK7rITs"><img src="http://feeds.feedburner.com/~ff/VoiceOfVoipsa?d=qj6IDK7rITs" border="0"></a> <a rel="nofollow" target="_blank" href="http://feeds.feedburner.com/~ff/VoiceOfVoipsa?a=3a9gSXyQYoA:76oHfI-0YfQ:gIN9vFwOqvQ"><img src="http://feeds.feedburner.com/~ff/VoiceOfVoipsa?i=3a9gSXyQYoA:76oHfI-0YfQ:gIN9vFwOqvQ" border="0"></a>
</div><img src="http://feeds.feedburner.com/~r/VoiceOfVoipsa/~4/3a9gSXyQYoA" height="1" width="1"/>]]></content:encoded>
         <category>VoIP Security</category>
      </item>
      <item>
         <title>Home Medical Devices and VoIP Security</title>
         <link>http://feedproxy.google.com/~r/VoiceOfVoipsa/~3/npwFGZrnZyA/</link>
         <description>With all the hubbub surrounding medical insurance reform, town hall meetings, and other distractions events it&amp;#8217;s worthwhile looking at some of the technical medical devices coming into the marketplace to be placed in patients&amp;#8217; homes, connected to their broadband internet connection. Of several products in the patient home monitoring space, the Intel Health Guide PHS 6000 [...]</description>
         <guid isPermaLink="false">http://voipsa.org/blog/?p=788</guid>
         <pubDate>Wed, 02 Sep 2009 10:10:57 -0700</pubDate>
         <content:encoded><![CDATA[<p>With all the hubbub surrounding medical insurance reform, town hall meetings, and other <del datetime="2009-09-02T16:42:07+00:00">distractions</del> events it&#8217;s worthwhile looking at some of the technical medical devices coming into the marketplace to be placed in patients&#8217; homes, connected to their broadband internet connection.<br />
<img src="http://voipsa.org/blog/wp-content/uploads/phs6000_deathpanel.PNG" alt="death panels!"/><br />
Of several products in the patient home monitoring space, the <a rel="nofollow" target="_blank" href="http://download.intel.com/healthcare/pdf/Health_Guide_Brief.pdf">Intel Health Guide PHS 6000</a> is perhaps one of the better positioned to garner marketshare because of several factors: including the size of Intel, on-going placement of the PHS 6000 in settings, and FDA approval in July, 2008.</p>
<p>Of the many PHS 6000 features, the device also supports two-way video conferencing between patient and caregiver. As this communication takes place over the broadband connection, it&#8217;s reasonable to assume that some sort of VoIP software is in place. Of course, details at this point are thin, and it&#8217;s even hard to get a real handle on what the PHS 6000 operating system really is, with some reports indicating Microsoft Windows XP, and others indicating a embedded Linux derivative. Still, it looks like there is a VoIP stack, and it&#8217;s likely SIP-based.</p>
<p>Clearly, the importance of the security of devices like the Intel PHS 6000 is apparent. And with the growing interest and funding towards cost-reduction and tele-health, we can expect to see these types of devices deployed widely. But what of the security posture? Sure, there&#8217;s boasting of encryption for the connection, but <strong>features</strong> like SSL mean little in the face of real attacks and vulnerabilities &#8212; think SSL encryption downgrade attacks, spoofing and man-in-the-middle vectors to start.</p>
<p>To get the word out, I&#8217;ve started a <a rel="nofollow" target="_blank" href="http://www.linkedin.com/groups?gid=2206357">LinkedIn group called MedSec</a> to get together like-minded, talented security people with an interest in medical device security. I&#8217;ve been chumming the waters with this approach in the hopes that the right people with the right connections conduct proper security evaluations of this PHS 6000 device, and it&#8217;s back-end management system as well. Of course, if approached, I&#8217;m interested in some hand&#8217;s on time too <img src='http://voipsa.org/blog/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley'/> </p>
<div class="feedflare">
<a rel="nofollow" target="_blank" href="http://feeds.feedburner.com/~ff/VoiceOfVoipsa?a=npwFGZrnZyA:zyx8v9qWK_A:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/VoiceOfVoipsa?d=yIl2AUoC8zA" border="0"></a> <a rel="nofollow" target="_blank" href="http://feeds.feedburner.com/~ff/VoiceOfVoipsa?a=npwFGZrnZyA:zyx8v9qWK_A:7Q72WNTAKBA"><img src="http://feeds.feedburner.com/~ff/VoiceOfVoipsa?d=7Q72WNTAKBA" border="0"></a> <a rel="nofollow" target="_blank" href="http://feeds.feedburner.com/~ff/VoiceOfVoipsa?a=npwFGZrnZyA:zyx8v9qWK_A:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/VoiceOfVoipsa?i=npwFGZrnZyA:zyx8v9qWK_A:V_sGLiPBpWU" border="0"></a> <a rel="nofollow" target="_blank" href="http://feeds.feedburner.com/~ff/VoiceOfVoipsa?a=npwFGZrnZyA:zyx8v9qWK_A:dnMXMwOfBR0"><img src="http://feeds.feedburner.com/~ff/VoiceOfVoipsa?d=dnMXMwOfBR0" border="0"></a> <a rel="nofollow" target="_blank" href="http://feeds.feedburner.com/~ff/VoiceOfVoipsa?a=npwFGZrnZyA:zyx8v9qWK_A:qj6IDK7rITs"><img src="http://feeds.feedburner.com/~ff/VoiceOfVoipsa?d=qj6IDK7rITs" border="0"></a> <a rel="nofollow" target="_blank" href="http://feeds.feedburner.com/~ff/VoiceOfVoipsa?a=npwFGZrnZyA:zyx8v9qWK_A:gIN9vFwOqvQ"><img src="http://feeds.feedburner.com/~ff/VoiceOfVoipsa?i=npwFGZrnZyA:zyx8v9qWK_A:gIN9vFwOqvQ" border="0"></a>
</div><img src="http://feeds.feedburner.com/~r/VoiceOfVoipsa/~4/npwFGZrnZyA" height="1" width="1"/>]]></content:encoded>
         <category>VoIP Security</category>
      </item>
      <item>
         <title>Skype Trojan Records Your Calls</title>
         <link>http://feedproxy.google.com/~r/VoiceOfVoipsa/~3/0Y2Ey3zFtA4/</link>
         <description>Apparently there&amp;#8217;s a new piece of malware floating around that targets audio processors like Skype:
The Trojan has the ability to record audio from the computer &amp;#8212; including any Skype calls in progress &amp;#8212; and store the files locally in an encrypted MP3 file, where they can later be transmitted to the attacker. The Trojan, which [...]</description>
         <guid isPermaLink="false">http://voipsa.org/blog/?p=784</guid>
         <pubDate>Mon, 31 Aug 2009 13:34:36 -0700</pubDate>
         <content:encoded><![CDATA[<p>Apparently there&#8217;s a <a rel="nofollow" title="DarkReading" target="_blank" href="http://www.darkreading.com/securityservices/security/privacy/showArticle.jhtml;jsessionid=ES0ABVKYFXWFNQE1GHRSKHWATMY32JVN?articleID=219500491">new piece of malware</a> floating around that targets audio processors like Skype:</p>
<blockquote><p><span>The Trojan has the ability to record audio from the computer &#8212; including any Skype calls in progress &#8212; and store the files locally in an encrypted MP3 file, where they can later be transmitted to the attacker. </span></p>
<p><span>The Trojan, which Symantec calls Trojan.Peskyspy, can be downloaded to a computer by tricking the user with an email scam or other social engineering tactic, Symantec says. Once a machine has been compromised, the threat can exploit an application that handles audio processing within a computer and save the call data as an MP3 file. </span></p></blockquote>
<div class="feedflare">
<a rel="nofollow" target="_blank" href="http://feeds.feedburner.com/~ff/VoiceOfVoipsa?a=0Y2Ey3zFtA4:6dXfEj4fQvw:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/VoiceOfVoipsa?d=yIl2AUoC8zA" border="0"></a> <a rel="nofollow" target="_blank" href="http://feeds.feedburner.com/~ff/VoiceOfVoipsa?a=0Y2Ey3zFtA4:6dXfEj4fQvw:7Q72WNTAKBA"><img src="http://feeds.feedburner.com/~ff/VoiceOfVoipsa?d=7Q72WNTAKBA" border="0"></a> <a rel="nofollow" target="_blank" href="http://feeds.feedburner.com/~ff/VoiceOfVoipsa?a=0Y2Ey3zFtA4:6dXfEj4fQvw:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/VoiceOfVoipsa?i=0Y2Ey3zFtA4:6dXfEj4fQvw:V_sGLiPBpWU" border="0"></a> <a rel="nofollow" target="_blank" href="http://feeds.feedburner.com/~ff/VoiceOfVoipsa?a=0Y2Ey3zFtA4:6dXfEj4fQvw:dnMXMwOfBR0"><img src="http://feeds.feedburner.com/~ff/VoiceOfVoipsa?d=dnMXMwOfBR0" border="0"></a> <a rel="nofollow" target="_blank" href="http://feeds.feedburner.com/~ff/VoiceOfVoipsa?a=0Y2Ey3zFtA4:6dXfEj4fQvw:qj6IDK7rITs"><img src="http://feeds.feedburner.com/~ff/VoiceOfVoipsa?d=qj6IDK7rITs" border="0"></a> <a rel="nofollow" target="_blank" href="http://feeds.feedburner.com/~ff/VoiceOfVoipsa?a=0Y2Ey3zFtA4:6dXfEj4fQvw:gIN9vFwOqvQ"><img src="http://feeds.feedburner.com/~ff/VoiceOfVoipsa?i=0Y2Ey3zFtA4:6dXfEj4fQvw:gIN9vFwOqvQ" border="0"></a>
</div><img src="http://feeds.feedburner.com/~r/VoiceOfVoipsa/~4/0Y2Ey3zFtA4" height="1" width="1"/>]]></content:encoded>
      </item>
      <item>
         <title>Something Old, Something New: Nmap’s VoIP Fingerprinting</title>
         <link>http://feedproxy.google.com/~r/VoiceOfVoipsa/~3/m1WEHkoYsko/</link>
         <description>Over time, it&amp;#8217;s easy to become a bit out of touch with security tools. With new tools arriving on the scene daily, and updates to established tools occurring frequently, the deluge of information can be overwhelming; not to mention all of the other security fodder we process.
That said, I find it encouraging to revisit [...]</description>
         <guid isPermaLink="false">http://voipsa.org/blog/?p=767</guid>
         <pubDate>Wed, 12 Aug 2009 14:53:51 -0700</pubDate>
         <content:encoded><![CDATA[<p>Over time, it&#8217;s easy to become a bit out of touch with security tools. With new tools arriving on the scene daily, and updates to established tools occurring frequently, the deluge of information can be overwhelming; not to mention all of the other security fodder we process.</p>
<p>That said, I find it encouraging to revisit some of the really established tools to see what changes and improvements are in place. Nmap is without a doubt <strong>the classic security tool </strong> in every aspect, from quality, to longevity, to street credibility. Even Hollywood has clue when it comes to Nmap, as evidenced in <a rel="nofollow" target="_blank" href="http://nmap.org/images/">Matrix, Bourne, and Die Hard films with Nmap showing up on someone&#8217;s computer screen!</a></p>
<p>One of my favorite Nmap features is the OS Identification and Application Fingerprinting capabilities. In part, this type of identification relies on the Nmap community scanning known devices and submitting signatures to be added to the Nmap databases (<a rel="nofollow" target="_blank" href="http://nmap.org/svn/nmap-service-probes">service probes</a>, <a rel="nofollow" target="_blank" href="http://nmap.org/svn/nmap-os-db">OS</a>, etc.).</p>
<p>As of 21 July, 2009, the <a rel="nofollow" target="_blank" href="http://nmap.org/svn/nmap-os-db">Nmap OS database</a> has the following VoIP device Fingerprints:</p>
<ul>Fingerprint Alcatel 4035 VoIP phone<br />
Fingerprint Sirio by Alice VoIP phone<br />
Fingerprint AudioCodes Mediant 1000 VoIP gateway<br />
Fingerprint Audiocodes MP-114 or MP-118 VoIP gateway<br />
Fingerprint Avaya G350 Media Gateway (VoIP gateway)<br />
Fingerprint Avaya Office IP403 VoIP gateway<br />
Fingerprint Avaya Office IP500 VoIP gateway<br />
Fingerprint Aastra 480i GT or 9133i IP phone<br />
Fingerprint Inter-tel 8662 VoIP phone<br />
Fingerprint Comtrend CT-800 VoIP gateway<br />
Fingerprint D-Link DVG-4022S VoIP gateway<br />
Fingerprint Grandstream HandyTone HT-488 analog VoIP adapter<br />
Fingerprint Grandstream BudgeTone 100 VoIP phone<br />
Fingerprint Grandstream BudgeTone 100 VoIP phone<br />
Fingerprint Grandstream GXP2000 VoIP phone<br />
Fingerprint Grandstream GXP2020 VoIP phone<br />
Fingerprint Thomson ST 2020 or 2030 VoIP phone<br />
Fingerprint Interbell IB-305 VoIP phone<br />
Fingerprint Linksys PAP2T VoIP router<br />
Fingerprint Linksys SPA901 or SPA921 SIP VoIP phone<br />
Fingerprint Linksys SPA942, SPA962, or SPA9000 VoIP phone; SPA3102 VoIP gateway; or Sipura SPA-2100 or SPA-2101 VoIP adapter<br />
Fingerprint Mitel 3300 CXi VoIP PBX<br />
Fingerprint Netcomm V300 VoIP gateway<br />
Fingerprint Neuf Box Trio3D DSL modem/router/VoIP/TV<br />
Fingerprint Nortel CS1000M VoIP PBX or Xerox Phaser 8560DT printer<br />
Fingerprint Patton SmartNode 4960 VoIP gateway (SmartWare 4.2)<br />
Fingerprint Perfectone IP-301 VoIP phone<br />
Fingerprint Planet VIP-154T VoIP phone (MicroC/OS-II)<br />
Fingerprint Polycom SoundPoint IP 301 VoIP phone<br />
Fingerprint Polycom SoundPoint IP 301 VoIP phone<br />
Fingerprint Polycom SoundPoint IP 430 VoIP phone<br />
Fingerprint PORTech GSM VoIP gateway<br />
Fingerprint PORTech MV-374 GSM-SIP VoIP gateway<br />
Fingerprint Samsung OfficeServ 7200 VoIP gateway<br />
Fingerprint ShoreTel ShoreGear-T1 VoIP switch<br />
Fingerprint Siemens HiPath optiPoint 400 VoIP phone<br />
Fingerprint Sipura SPA-1001 or SPA-3000 VoIP adapter<br />
Fingerprint Sipura SPA-3000 VoIP adapter<br />
Fingerprint Thomson Symbio VoIP phone<br />
Fingerprint Vegastream Vega 400 VoIP Gateway
</ul>
<p>Also, it&#8217;s well worth taking a look at the VoIP devices identified in the <a rel="nofollow" target="_blank" href="http://nmap.org/svn/nmap-service-probes">Nmap Service Probes database</a> as services that identify a VoIP device do not necessarily mean that the VoIP device has a fingerprint. In other words, there are VoIP devices in the Service Probes database that are not in the OS Fingerprint database, so look carefully!</p>
<p>For even more coolness, be sure to check out the <a rel="nofollow" target="_blank" href="http://nmap.org/book/nse.html">NSE</a>.</p>
<p>Wrapping-up, I&#8217;ve nothing less than <a rel="nofollow" target="_blank" href="http://www.urbandictionary.com/define.php?term=mad+props">mad props</a> for <a rel="nofollow" target="_blank" href="http://insecure.org/fyodor/">Fyodor </a> and all of the other folks who&#8217;ve contributed to this fantastic tool. Nmap was one of the first tools I used 10 years ago when first cutting my teeth in security, and remarkably, is a tool that I continue to use almost daily.</p>
<div class="feedflare">
<a rel="nofollow" target="_blank" href="http://feeds.feedburner.com/~ff/VoiceOfVoipsa?a=m1WEHkoYsko:EHwMaihR6oc:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/VoiceOfVoipsa?d=yIl2AUoC8zA" border="0"></a> <a rel="nofollow" target="_blank" href="http://feeds.feedburner.com/~ff/VoiceOfVoipsa?a=m1WEHkoYsko:EHwMaihR6oc:7Q72WNTAKBA"><img src="http://feeds.feedburner.com/~ff/VoiceOfVoipsa?d=7Q72WNTAKBA" border="0"></a> <a rel="nofollow" target="_blank" href="http://feeds.feedburner.com/~ff/VoiceOfVoipsa?a=m1WEHkoYsko:EHwMaihR6oc:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/VoiceOfVoipsa?i=m1WEHkoYsko:EHwMaihR6oc:V_sGLiPBpWU" border="0"></a> <a rel="nofollow" target="_blank" href="http://feeds.feedburner.com/~ff/VoiceOfVoipsa?a=m1WEHkoYsko:EHwMaihR6oc:dnMXMwOfBR0"><img src="http://feeds.feedburner.com/~ff/VoiceOfVoipsa?d=dnMXMwOfBR0" border="0"></a> <a rel="nofollow" target="_blank" href="http://feeds.feedburner.com/~ff/VoiceOfVoipsa?a=m1WEHkoYsko:EHwMaihR6oc:qj6IDK7rITs"><img src="http://feeds.feedburner.com/~ff/VoiceOfVoipsa?d=qj6IDK7rITs" border="0"></a> <a rel="nofollow" target="_blank" href="http://feeds.feedburner.com/~ff/VoiceOfVoipsa?a=m1WEHkoYsko:EHwMaihR6oc:gIN9vFwOqvQ"><img src="http://feeds.feedburner.com/~ff/VoiceOfVoipsa?i=m1WEHkoYsko:EHwMaihR6oc:gIN9vFwOqvQ" border="0"></a>
</div><img src="http://feeds.feedburner.com/~r/VoiceOfVoipsa/~4/m1WEHkoYsko" height="1" width="1"/>]]></content:encoded>
         <category>VoIP Security</category>
      </item>
      <item>
         <title>First 911 Center to support SMS</title>
         <link>http://feedproxy.google.com/~r/VoiceOfVoipsa/~3/GgXs7IwE2Pk/</link>
         <description>Recently multiple news outlets reported on Waterloo, Iowa&amp;#8217;s Black Hawk County 911 center&amp;#8217;s new SMS capability.
While this subject is not specifically VoIP security, considering the blending of communications methods and the importance of 911 call centers I figure that SMS in this context is fair game for a VOIPSA Blog post. Several security implications [...]</description>
         <guid isPermaLink="false">http://voipsa.org/blog/?p=759</guid>
         <pubDate>Fri, 07 Aug 2009 13:32:01 -0700</pubDate>
         <content:encoded><![CDATA[<p>Recently multiple news outlets <a rel="nofollow" target="_blank" href="http://news.google.com/news/more?um=1&amp;ned=us&amp;cf=all&amp;ncl=d5RNOUOZK57OqOM6cDsKo0wjG0ENM">reported</a> on Waterloo, Iowa&#8217;s Black Hawk County 911 center&#8217;s new <a rel="nofollow" target="_blank" href="http://en.wikipedia.org/wiki/Short_message_service">SMS</a> capability.</p>
<p>While this subject is not specifically VoIP security, considering the blending of communications methods and the importance of 911 call centers I figure that SMS in this context is fair game for a VOIPSA Blog post. </p>
<p>Several security implications surrounding this new 911 SMS capability come to mind:</p>
<p><strong>Time Delays in SMS transmissions</strong> &#8211; we&#8217;ve all experienced some delay, from marginal to extended, when it comes to sending and receiving SMS messages. What remains unclear from reports is if the carriers supporting 911 SMS in Black Hawk County give SMS to 911 communication priority network access, either initially and/or throughout the entire SMS dialog.</p>
<p><strong>Lingo</strong> &#8211; SMS messages are limited to 160 characters. As a result, acronyms and texting lingo are pervasive. Reports say the 911 operators are brushing up on their texting lingo in preparation. I sure do hope they are using decent resources, such as <a rel="nofollow" target="_blank" href="http://www.netlingo.com/acronyms.php">TLLTMSIFW</a>, so when <a rel="nofollow" target="_blank" href="http://www.netlingo.com/word/hiooc.php">HIOOC</a> comes in <a rel="nofollow" target="_blank" href="http://www.netlingo.com/word/idgara.php">IDGARA</a> is the right response.</p>
<p><strong>Flooding </strong> &#8211; sending mass amounts of SMS messages could adversely affect the call center&#8217;s operations. Using pre-paid phones, bluetooth dongles and simple software, an attacker with marginal resources could initiate this kind of attack with ease. How will 911 call centers handling SMS handle floods of SMS messages? The nuisance facter here should not be underestimated; here&#8217;s some <a rel="nofollow" target="_blank" href="http://www.geekzone.co.nz/forums.asp?ForumId=22&amp;TopicId=12209">good anecdotal experience</a><code></code></p>
<p><strong><a rel="nofollow" target="_blank" href="http://en.wikipedia.org/wiki/SMS_spoofing">SMS Spoofing</a></strong> &#8211; with the advent of various spoofing services, we&#8217;ve seen the types of attacks that can leverage spoofing. <a rel="nofollow">SpoofCard</a> time and again has unauthorized access to voicemail, and still an issue with some carrier&#8217;s default user settings. We can expect to see the same issues with SMS spoofing.</p>
<p><strong>SMS <a rel="nofollow" target="_blank" href="http://en.wikipedia.org/wiki/Swatting">Swatting</a></strong> &#8211; will likely be a byproduct of spoofing SMS messages to 911 call centers. However, the use of SMS brings a new twist to Swatting, since the spoofed SMS message will be tied to a cellular phone, rather than a fixed landline number, perhaps leading to mobile Swatting as law enforcement will need to track the mobile phone (GPS, triangulation) to gain physical proximity the the SMS origin.</p>
<p><a rel="nofollow" target="_blank" href="http://en.wikipedia.org/wiki/Multimedia_Messaging_Service"><strong>MMS</strong></a> &#8211; while no mention is made in the news reports about MMS support at 911 call centers, I think it&#8217;s reasonable to assume that ability to handle multimedia messages is in the works. The implications of moving from 160 characters of text to multimedia messaging with attached video/photos are dramatic. Further, this opens new attack vectors in terms of how these multimedia files are processed and accessed (think trojan Flash, PNG, etc.).</p>
<p>I&#8217;ve only scratched the surface here of course, but hopefully this provides some food for thought &#8212; as always, comments welcome <img src='http://voipsa.org/blog/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley'/> </p>
<div class="feedflare">
<a rel="nofollow" target="_blank" href="http://feeds.feedburner.com/~ff/VoiceOfVoipsa?a=GgXs7IwE2Pk:ZktZil8_IOA:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/VoiceOfVoipsa?d=yIl2AUoC8zA" border="0"></a> <a rel="nofollow" target="_blank" href="http://feeds.feedburner.com/~ff/VoiceOfVoipsa?a=GgXs7IwE2Pk:ZktZil8_IOA:7Q72WNTAKBA"><img src="http://feeds.feedburner.com/~ff/VoiceOfVoipsa?d=7Q72WNTAKBA" border="0"></a> <a rel="nofollow" target="_blank" href="http://feeds.feedburner.com/~ff/VoiceOfVoipsa?a=GgXs7IwE2Pk:ZktZil8_IOA:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/VoiceOfVoipsa?i=GgXs7IwE2Pk:ZktZil8_IOA:V_sGLiPBpWU" border="0"></a> <a rel="nofollow" target="_blank" href="http://feeds.feedburner.com/~ff/VoiceOfVoipsa?a=GgXs7IwE2Pk:ZktZil8_IOA:dnMXMwOfBR0"><img src="http://feeds.feedburner.com/~ff/VoiceOfVoipsa?d=dnMXMwOfBR0" border="0"></a> <a rel="nofollow" target="_blank" href="http://feeds.feedburner.com/~ff/VoiceOfVoipsa?a=GgXs7IwE2Pk:ZktZil8_IOA:qj6IDK7rITs"><img src="http://feeds.feedburner.com/~ff/VoiceOfVoipsa?d=qj6IDK7rITs" border="0"></a> <a rel="nofollow" target="_blank" href="http://feeds.feedburner.com/~ff/VoiceOfVoipsa?a=GgXs7IwE2Pk:ZktZil8_IOA:gIN9vFwOqvQ"><img src="http://feeds.feedburner.com/~ff/VoiceOfVoipsa?i=GgXs7IwE2Pk:ZktZil8_IOA:gIN9vFwOqvQ" border="0"></a>
</div><img src="http://feeds.feedburner.com/~r/VoiceOfVoipsa/~4/GgXs7IwE2Pk" height="1" width="1"/>]]></content:encoded>
         <category>VoIP Security</category>
      </item>
      <item>
         <title>Google Trends on VoIP Security</title>
         <link>http://feedproxy.google.com/~r/VoiceOfVoipsa/~3/Tjuhc89M5_Y/</link>
         <description>I&amp;#8217;ve recently been using Google Trends for some research, and find it an interesting tool for, well, trending. Doing a Google Trends profile of VoIP Security shows an interesting tailing-off. So what&amp;#8217;s the story? Is this just another case of &amp;#8220;it&amp;#8217;s all the same, nobody cares&amp;#8221; in action?</description>
         <guid isPermaLink="false">http://voipsa.org/blog/?p=750</guid>
         <pubDate>Tue, 28 Jul 2009 14:22:40 -0700</pubDate>
         <content:encoded><![CDATA[<p>I&#8217;ve recently been using Google Trends for some research, and find it an interesting tool for, well, trending. Doing a Google Trends profile of <a rel="nofollow" target="_blank" href="http://www.google.com/trends?q=voip+security">VoIP Security</a> shows an interesting tailing-off. So what&#8217;s the story? Is this just another case of &#8220;it&#8217;s all the same, nobody cares&#8221; in action?</p>
<p><a rel="nofollow" target="_blank" href="http://voipsa.org/blog/wp-content/uploads/google_trends.PNG"><img src="http://voipsa.org/blog/wp-content/uploads/google_trends-300x152.PNG" alt="google_trends" width="400" height="200" class="aligncenter size-medium wp-image-751"/></a></p>
<div class="feedflare">
<a rel="nofollow" target="_blank" href="http://feeds.feedburner.com/~ff/VoiceOfVoipsa?a=Tjuhc89M5_Y:mq_b8clafj8:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/VoiceOfVoipsa?d=yIl2AUoC8zA" border="0"></a> <a rel="nofollow" target="_blank" href="http://feeds.feedburner.com/~ff/VoiceOfVoipsa?a=Tjuhc89M5_Y:mq_b8clafj8:7Q72WNTAKBA"><img src="http://feeds.feedburner.com/~ff/VoiceOfVoipsa?d=7Q72WNTAKBA" border="0"></a> <a rel="nofollow" target="_blank" href="http://feeds.feedburner.com/~ff/VoiceOfVoipsa?a=Tjuhc89M5_Y:mq_b8clafj8:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/VoiceOfVoipsa?i=Tjuhc89M5_Y:mq_b8clafj8:V_sGLiPBpWU" border="0"></a> <a rel="nofollow" target="_blank" href="http://feeds.feedburner.com/~ff/VoiceOfVoipsa?a=Tjuhc89M5_Y:mq_b8clafj8:dnMXMwOfBR0"><img src="http://feeds.feedburner.com/~ff/VoiceOfVoipsa?d=dnMXMwOfBR0" border="0"></a> <a rel="nofollow" target="_blank" href="http://feeds.feedburner.com/~ff/VoiceOfVoipsa?a=Tjuhc89M5_Y:mq_b8clafj8:qj6IDK7rITs"><img src="http://feeds.feedburner.com/~ff/VoiceOfVoipsa?d=qj6IDK7rITs" border="0"></a> <a rel="nofollow" target="_blank" href="http://feeds.feedburner.com/~ff/VoiceOfVoipsa?a=Tjuhc89M5_Y:mq_b8clafj8:gIN9vFwOqvQ"><img src="http://feeds.feedburner.com/~ff/VoiceOfVoipsa?i=Tjuhc89M5_Y:mq_b8clafj8:gIN9vFwOqvQ" border="0"></a>
</div><img src="http://feeds.feedburner.com/~r/VoiceOfVoipsa/~4/Tjuhc89M5_Y" height="1" width="1"/>]]></content:encoded>
         <category>VoIP Security</category>
      </item>
      <item>
         <title>Testing twitter integration with TypePad</title>
         <link>http://www.blueboxpodcast.com/2009/04/testing-twitter-integration-with-typepad.html</link>
         <description>&lt;div&gt;&lt;p&gt;Just testing Twitter integration... I have a growing suspicion that TypePad &lt;em&gt;only&lt;/em&gt; notifies Twitter if you &lt;em&gt;write your post online&lt;/em&gt; using TypePad's interface.&amp;#0160; But of course, I &lt;em&gt;don't&lt;/em&gt;.&amp;#0160; I write almost all my posts offline using the MarsEdit editor.&amp;#0160; Let's see if this shows up in &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://twitter.com/blueboxpodcast&quot;&gt;http://twitter.com/blueboxpodcast&lt;/a&gt;&lt;/p&gt;&lt;/div&gt;</description>
         <author>Dan York</author>
         <guid isPermaLink="false">tag:typepad.com,2003:post-65174719</guid>
         <pubDate>Tue, 07 Apr 2009 02:21:14 -0700</pubDate>
      </item>
      <item>
         <title>Blue Box is now on Twitter... and new shows *are* coming...</title>
         <link>http://www.blueboxpodcast.com/2009/04/blue-box-is-now-on-twitter-and-new-shows-are-coming.html</link>
         <description>&lt;div&gt;&lt;p&gt;FYI, if you use Twitter, you can now find out when new shows are out and/or interact with Jonathan and I by following us at:&lt;blockquote&gt;&lt;em&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://twitter.com/blueboxpodcast&quot;&gt;http://twitter.com/blueboxpodcast&lt;/a&gt;&lt;/em&gt;&lt;/blockquote&gt;
&lt;p&gt;And yes, new shows &lt;em&gt;are&lt;/em&gt; on the way. I've been a wee bit busy with &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.disruptivetelephony.com/2009/03/my-new-role-at-voxeo-director-of-conversations.html&quot;&gt;a recent job role change&lt;/a&gt; and Jonathan's had some crazy times on his end as well... but soon... real soon...&lt;/div&gt;</description>
         <author>Dan York</author>
         <guid isPermaLink="false">tag:typepad.com,2003:post-65173897</guid>
         <pubDate>Tue, 07 Apr 2009 01:54:08 -0700</pubDate>
      </item>
      <item>
         <title>eComm 2009: Dan, Jonathan and Martyn together for the first time</title>
         <link>http://www.blueboxpodcast.com/2009/03/ecomm-2009-dan-jonathan-and-martyn-together-for-the-first-time.html</link>
         <description>&lt;div&gt;&lt;p&gt;Last week at the &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://ecommconf.com/&quot;&gt;Emerging Communications Conference (eComm) 2009&lt;/a&gt; in San Francisco, a remarkable event happened: Jonathan Zar, Martyn Davies, and I (Dan York) all wound up at the same place at the same time. Over the 3.5 years since we started Blue Box back in October 2005, Jonathan and I have met at events, Martyn and I have met and Jonathan and Martyn have met. But the three of us had never been together at the same place.
&lt;p&gt;Now the particular place we met was a &quot;Dev Dinner&quot; hosted by (my employer) &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://blogs.voxeo.com/&quot;&gt;Voxeo&lt;/a&gt; after the end of eComm - and we had some great conversations along with the food. Martyn produced his camera and we did record the actual event:
&lt;div style=&quot;text-align:center;&quot;&gt;&lt;img src=&quot;http://lodestar.typepad.com/.a/6a00d8341bfc6e53ef011168cdc2d2970c-pi&quot; alt=&quot;bluebox-at-ecomm2009.jpg&quot; border=&quot;0&quot; width=&quot;400&quot; height=&quot;279&quot;/&gt;&lt;/div&gt;
&lt;p&gt;Alas, it was too noisy there for us to do any actual recording, but it was great to have all three of us there. For those who may not recall the history, Martyn was one of our earliest listeners and is the person who provided &lt;em&gt;both&lt;/em&gt; the image that we use for Blue Box (in iTunes, in the MP3 file, etc.) and also the music that we use for the intro and outro. He's also guest-hosted several times and contributed a couple of interviews over the years.
&lt;p&gt;P.S. And yes, Jonathan and I &lt;em&gt;will&lt;/em&gt; be getting some more shows out... 
&lt;p&gt;Technorati Tags:
&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://technorati.com/tag/bluebox&quot;&gt;bluebox&lt;/a&gt;, &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://technorati.com/tag/blue%20box&quot;&gt;blue box&lt;/a&gt;, &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://technorati.com/tag/danyork&quot;&gt;danyork&lt;/a&gt;, &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://technorati.com/tag/dan%20york&quot;&gt;dan york&lt;/a&gt;, &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://technorati.com/tag/jonathan%20zar&quot;&gt;jonathan zar&lt;/a&gt;, &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://technorati.com/tag/martyn%20davies&quot;&gt;martyn davies&lt;/a&gt;, &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://technorati.com/tag/ecomm&quot;&gt;ecomm&lt;/a&gt;, &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://technorati.com/tag/ecomm09&quot;&gt;ecomm09&lt;/a&gt;
&lt;/p&gt;
&lt;/div&gt;</description>
         <author>Dan York</author>
         <guid isPermaLink="false">tag:typepad.com,2003:post-63830453</guid>
         <pubDate>Mon, 09 Mar 2009 01:45:04 -0700</pubDate>
      </item>
      <item>
         <title>Speaking on &quot;SIP Trunking and Security&quot; at ITEXPO in Miami Feb 3rd</title>
         <link>http://www.blueboxpodcast.com/2009/01/speaking-on-sip-trunking-and-security-at-itexpo-in-miami-feb-3rd.html</link>
         <description>&lt;div&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.tmcnet.com/voip/conference/&quot;&gt;&lt;img src=&quot;http://voipsa.org/blog/wp-content/uploads/itexpo-east-logo-2.jpg&quot; alt=&quot;ITEXPO-East-logo-2.jpg&quot; border=&quot;0&quot; width=&quot;265&quot; height=&quot;94&quot; align=&quot;right&quot;/&gt;&lt;/a&gt;If you will be in Miami &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.tmcnet.com/voip/conference/&quot;&gt;at ITEXPO February 2-4&lt;/a&gt; you are welcome to attend a free &quot;&lt;em&gt;SIP Trunking And Security&lt;/em&gt;&quot; session I (Dan York) will be doing as part of Ingate Systems' &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.tmcnet.com/voip/conference/east-09/ingate-sip-trunking-workshop.htm&quot;&gt;SIP Trunking Workshops&lt;/a&gt;. The SIP trunking workshops are free to all attendees even if you only register for an exhibit pass. &lt;p&gt;My session will be 11:15-12:30 on Wednesday, February 3rd, and if you do attend please feel free to come up and introduce yourself (or &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;mailto:dyork@voxeo.com?subject=ITEXPO%20SIP%20Trunking%20workshop&quot;&gt;drop me a note&lt;/a&gt; in advance to let me know to look out for you). I'll be bringing my recording gear, too, and the talk will eventually go out in my &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.blueboxpodcast.com/&quot;&gt;Blue Box Podcast&lt;/a&gt; feed so you will be able to hear it later. &lt;p&gt;P.S. If you are attending ITEXPO and your company makes a product or provides a service related to VoIP security, please feel free to &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;mailto:dyork@voxeo.com?subject=ITEXPO%20SIP%20Trunking%20workshop&quot;&gt;let me know&lt;/a&gt; and perhaps we can schedule an interview to go out as a Blue Box Special Edition. 
&lt;p&gt;Technorati Tags:
&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://technorati.com/tag/danyork&quot;&gt;danyork&lt;/a&gt;, &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://technorati.com/tag/itexpo&quot;&gt;itexpo&lt;/a&gt;, &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://technorati.com/tag/miami&quot;&gt;miami&lt;/a&gt;, &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://technorati.com/tag/voipsa&quot;&gt;voipsa&lt;/a&gt;, &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://technorati.com/tag/voip%20security&quot;&gt;voip security&lt;/a&gt;, &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://technorati.com/tag/sip%20trunking&quot;&gt;sip trunking&lt;/a&gt;, &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://technorati.com/tag/sip&quot;&gt;sip&lt;/a&gt;, &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://technorati.com/tag/sip%20security&quot;&gt;sip security&lt;/a&gt;, &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://technorati.com/tag/security&quot;&gt;security&lt;/a&gt;
&lt;/p&gt;
&lt;/div&gt;</description>
         <author>Dan York</author>
         <guid isPermaLink="false">tag:typepad.com,2003:post-61809924</guid>
         <pubDate>Fri, 23 Jan 2009 00:51:13 -0800</pubDate>
      </item>
      <item>
         <title>FYI - &quot;Security Bloggers Network&quot; in transition... stay tuned...</title>
         <link>http://www.blueboxpodcast.com/2008/11/fyi---security-bloggers-network-in-transition-stay-tuned.html</link>
         <description>&lt;div&gt;For those of you who may be used to reading this blog through the &quot;Security Bloggers Network&quot; set up originally by Alan Shimel, you need to be aware that the &quot;SBN&quot; is going through a transition. &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.stillsecureafteralltheseyears.com/ashimmy/2008/11/what-happened-to-the-security-bloggers-network-feed-it-was-assimilated.html&quot;&gt;As Alan details on his blog&lt;/a&gt;, Google is in the process of shutting down the &quot;Network&quot; feature of Feedburner and as a result the page and feed for the SBN will be going away. &lt;p&gt;Alan is working on a new solution but in the meantime you may want to grab &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://networks.feedburner.com/Security-Bloggers-Network/opml&quot;&gt;the OPML file for the Security Bloggers Network&lt;/a&gt; (you should then be able to import this into most feed readers). There are a &lt;em&gt;lot&lt;/em&gt; of great security blogs out there. &lt;p&gt;Stay tuned for more information - once Alan has another solution in place I'll post an update.&lt;/div&gt;</description>
         <author>Dan York</author>
         <guid isPermaLink="false">tag:typepad.com,2003:post-58696978</guid>
         <pubDate>Tue, 18 Nov 2008 11:22:12 -0800</pubDate>
      </item>
      <item>
         <title>RSS feed back...</title>
         <link>http://www.blueboxpodcast.com/2008/10/rss-feed-back.html</link>
         <description>&lt;div&gt;&lt;p&gt;It looks like FeedBurner finally refreshed its DNS info and the RSS feed is back in action. My apologies for the interruption. Please do let me know if there is anything else strange going on with the website or feed. Thanks.&lt;/p&gt;&lt;/div&gt;</description>
         <author>Dan York</author>
         <guid isPermaLink="false">tag:typepad.com,2003:post-57596851</guid>
         <pubDate>Sun, 26 Oct 2008 20:24:16 -0700</pubDate>
      </item>
      <item>
         <title>Blue Box RSS feed dead - waiting for Feedburner to update its DNS</title>
         <link>http://www.blueboxpodcast.com/2008/10/blue-box-rss-feed-dead---waiting-for-feedburner-to-update-its-dns.html</link>
         <description>&lt;div&gt;Ah, the joys of switching domain name providers. I transferred blueboxpodcast.com from one registrar to another last week shortly before the domain name was set to expire. Unfortunately, I made one serious mistake - I didn't check the DNS nameservers for the domain at the new registrar (GoDaddy) to ensure they were pointing to the new nameservers. They weren't... they will still pointing to the old nameservers. As a result, when the domain name expired at the end of the day on Friday, the web site was no longer available and had the message that the domain name had expired.
&lt;p&gt;&lt;em&gt;MANY THANKS to the couple of you who contacted me on Saturday to let me know about this!&lt;/em&gt;
&lt;p&gt;So I fixed the web site yesterday morning so that &quot;www.blueboxpodcast.com&quot; pointed over to TypePad, where I host this site, and that all seems to be back in action. If you type in &quot;blueboxpodcast.com&quot; &lt;em&gt;without&lt;/em&gt; the &quot;www&quot;, it was going to a generic GoDaddy page but I've set up the forwarding now so that this &lt;em&gt;should&lt;/em&gt; now redirect you to www.blueboxpodcast.com once the DNS propagation occurs.
&lt;p&gt;&lt;img src=&quot;http://lodestar.typepad.com/.a/6a00d8341bfc6e53ef010535c00dd4970c-pi&quot; alt=&quot;feedburnerlogo.jpg&quot; border=&quot;0&quot; width=&quot;162&quot; height=&quot;44&quot; align=&quot;right&quot;/&gt;What is still dead, though, is the RSS feed... which is rather annoying since that is what podcast subscription tools like iTunes use! In working through the issues this morning, it appears to be the issue that &lt;blockquote&gt;&lt;em&gt;&lt;em&gt;Feedburner is not using the updated DNS information.&lt;/em&gt;&lt;/em&gt;&lt;/blockquote&gt; The Blue Box RSS feed, which is &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://feeds.feedburner.com/BlueBox&quot;&gt;http://feeds.feedburner.com/BlueBox&lt;/a&gt; is somehow pointing over to the old page. Yet the base feed for this site, &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.blueboxpodcast.com/atom.xml&quot;&gt;http://www.blueboxpodcast.com/atom.xml&lt;/a&gt; resolves perfectly fine and &lt;em&gt;does&lt;/em&gt; have the RSS information. (Please don't switch to subscribe to that one... I do like the stats I get through Feedburner.)
&lt;p&gt;So it appears that I'm waiting for FeedBurner to update its DNS. I've tried all sorts of options in the FeedBurner settings, including the &quot;Resync Feed&quot; but nothing works because it seems that it is unable to get to the new site (because of DNS).
&lt;p&gt;I've filed a help request in the FeedBurner Google Group (which appears to be the only way to get help). Hopefully FeedBurner will age out its DNS info &lt;em&gt;soon&lt;/em&gt; and the feed will be back in action.
&lt;p&gt;What I find strange, though, is that I'm 99% sure that all the DNS records had a TTL of 1 hour (and I'm 100% positive the new ones do). So my question to FeedBurner is - if that &lt;em&gt;is&lt;/em&gt; the case, why aren't they respected the TTL settings of the domains? &lt;p&gt;I'll update this post once I have more information. 
&lt;p&gt;Technorati Tags:
&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://technorati.com/tag/feeds&quot;&gt;feeds&lt;/a&gt;, &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://technorati.com/tag/rss&quot;&gt;rss&lt;/a&gt;, &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://technorati.com/tag/feedburner&quot;&gt;feedburner&lt;/a&gt;, &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://technorati.com/tag/google&quot;&gt;google&lt;/a&gt;, &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://technorati.com/tag/dns&quot;&gt;dns&lt;/a&gt;, &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://technorati.com/tag/bluebox&quot;&gt;bluebox&lt;/a&gt;
&lt;/p&gt;
&lt;/div&gt;</description>
         <author>Dan York</author>
         <guid isPermaLink="false">tag:typepad.com,2003:post-57562925</guid>
         <pubDate>Sun, 26 Oct 2008 01:24:43 -0700</pubDate>
      </item>
      <item>
         <title>Three years of Blue Box podcasts....</title>
         <link>http://www.blueboxpodcast.com/2008/10/three-years-of-blue-box-podcasts.html</link>
         <description>&lt;div&gt;Today is a special day for me. It was three years ago on October 24, 2005, that &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.blueboxpodcast.com/2005/10/blue_box_podcas.html&quot;&gt;Blue Box Podcast #1 was uploaded&lt;/a&gt;. It was an 11-minute episode where I talked about... Skype security, SIP security, IETF, VOIPSA and some other VoIP security news..... (Hmmm... sounds lot like our &lt;em&gt;recent&lt;/em&gt; shows, too, eh?) &lt;p&gt;Jonathan Zar joined me a week later on &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.blueboxpodcast.com/2005/11/blue_box_podcas.html&quot;&gt;Blue Box Podcast #2&lt;/a&gt; and we've been going ever since. We've now produced over 112 episodes, had close to 245,000 downloads of our various shows, met some amazing people, learned a lot along the way... and hopefully helped you all learn a lot out there as well. &lt;p&gt;Thank you to all of you who have joined with us on this journey... whether you've listened to our show from the very beginning (and we know of a couple of you who have) or have only recently joined in... &lt;em&gt;thank you&lt;/em&gt;! &lt;p&gt;And now... on to the next three years... :-) 
&lt;p&gt;Technorati Tags:
&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://technorati.com/tag/blue%20box&quot;&gt;blue box&lt;/a&gt;, &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://technorati.com/tag/bluebox&quot;&gt;bluebox&lt;/a&gt;, &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://technorati.com/tag/dan%20york&quot;&gt;dan york&lt;/a&gt;, &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://technorati.com/tag/danyork&quot;&gt;danyork&lt;/a&gt;, &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://technorati.com/tag/jonathan%20zar&quot;&gt;jonathan zar&lt;/a&gt;, &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://technorati.com/tag/security&quot;&gt;security&lt;/a&gt;, &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://technorati.com/tag/voip&quot;&gt;voip&lt;/a&gt;, &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://technorati.com/tag/voip%20security&quot;&gt;voip security&lt;/a&gt;, &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://technorati.com/tag/voipsa&quot;&gt;voipsa&lt;/a&gt;
&lt;/p&gt;
&lt;/div&gt;</description>
         <author>Dan York</author>
         <guid isPermaLink="false">tag:typepad.com,2003:post-57528131</guid>
         <pubDate>Fri, 24 Oct 2008 15:35:20 -0700</pubDate>
      </item>
      <item>
         <title>Blue Box #85: Internet phone calls and terrorism, Georgia Tech report on Emerging Cyber Security Threats, phone jamming, 802.1X-REV, 802.1AE, VoIP security news and more</title>
         <link>http://www.blueboxpodcast.com/2008/10/blue-box-85-internet-phone-calls-and-terrorism-georgia-tech-report-on-emerging-cyber-security-threats-phone-jamming-802.html</link>
         <description>&lt;div&gt;&lt;p&gt;&lt;strong&gt;Synopsis:&lt;/strong&gt; Blue Box #85: Internet phone calls and terrorism, Georgia Tech report on Emerging Cyber Security Threats, phone jamming, 802.1X-REV, 802.1AE, VoIP security news and more &lt;/p&gt;&lt;hr /&gt;&lt;p&gt;Welcome to &lt;strong&gt;Blue Box: The VoIP Security Podcast&lt;/strong&gt; #85, a 32-minute podcast&amp;#0160; from Dan York and Jonathan Zar covering VoIP security news, comments and opinions.&amp;#0160; &amp;#0160; &lt;/p&gt; &lt;p&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://media.libsyn.com/media/lodestar/BBP-085-2008-10-17.mp3&quot;&gt;Download the show here&lt;/a&gt; (MP3, 15 MB) or &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://feeds.feedburner.com/BlueBox&quot;&gt;subscribe to the RSS feed&lt;/a&gt; to download the show automatically.&amp;#0160; &lt;/p&gt; &lt;p&gt;You may also listen to this podcast right now:&lt;/p&gt; &lt;p&gt; &lt;/p&gt; &lt;p&gt;&lt;strong&gt;Show Content:&lt;/strong&gt;&lt;/p&gt; &lt;div&gt; &lt;div&gt; &lt;/div&gt;
&lt;/div&gt;&lt;ul&gt; &lt;li&gt;00:20 - Intro to the show, contact information and how to provide comments.&amp;#0160; Welcome to all the new listeners - and to all those listeners who have been here for so long!&lt;/li&gt;
&lt;li&gt;Programming notes: &lt;ul&gt; &lt;li&gt;Three-year anniversary of Blue Box coming up on October 24th - any thoughts you'd like to share with us? (Please send them to us by October 23rd.)&lt;/li&gt; &lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;The Times: &quot;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.timesonline.co.uk/tol/news/uk/crime/article4951864.ece&quot; id=&quot;wz0c&quot; title=&quot;Internet phone calls are crippling fight against terrorism&quot;&gt;Internet phone calls are crippling fight against terrorism&lt;/a&gt;&quot; - and &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://voipsa.org/blog/2008/10/16/internet-phone-calls-terrorism-and-finding-the-balance-for-law-enforcement/&quot; id=&quot;f.3z&quot; title=&quot;my response on the Voice of VOIPSA blog&quot;&gt;my response on the Voice of VOIPSA blog&lt;/a&gt; &lt;/li&gt;
&lt;li&gt;FierceVoIP: &quot;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.fiercetelecom.com/story/uk-crime-fighting-concern-over-voip-calls-social-networks/2008-10-16&quot; id=&quot;b1kd&quot; title=&quot;UK crimefighting concern over VoIP calls, social networks&quot;&gt;UK crimefighting concern over VoIP calls, social networks&lt;/a&gt;&quot;&amp;#0160; &lt;/li&gt;
&lt;li&gt;BBC:&amp;#0160;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://news.bbc.co.uk/2/hi/uk_news/7671759.stm&quot; id=&quot;ef5t&quot; title=&quot;Data powers behind the times&quot;&gt;Data powers behind the times&lt;/a&gt;&amp;#0160; &lt;br /&gt;
&lt;/li&gt;
&lt;li&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.gtiscsecuritysummit.com/pdf/CyberThreatsReport2009.pdf&quot; id=&quot;mo0b&quot; title=&quot;GA Tech Survey (PDF)&quot;&gt;GA Tech Survey (PDF)&amp;#0160;&lt;/a&gt;(link&amp;#0160;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.techlinks.net/blogs/events/archive/2008/09/25/gtisc-security-summit.aspx&quot; id=&quot;a5cx&quot; title=&quot;about the GA conference&quot;&gt;about the GA conference&lt;/a&gt; )&lt;/li&gt;
&lt;li&gt;Dark Reading:&amp;#0160;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.darkreading.com/document.asp?doc_id=166029&amp;amp;WT.svl=news2_1&quot; id=&quot;ipct&quot; title=&quot;Cellphone Botnets, Blackmailing VOIP &amp;amp; a Healthy Cybercrime Economy&quot;&gt;Cellphone Botnets, Blackmailing VOIP &amp;amp; a Healthy Cybercrime Economy&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;bMighty.com:&amp;#0160;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.bmighty.com/blog/main/archives/2008/10/georgia_techs_s.html&quot; id=&quot;dkj.&quot; title=&quot;Georgia Tech Security Report Scarier Than Its Football Team&quot;&gt;Georgia Tech Security Report Scarier Than Its Football Team&lt;/a&gt; &lt;/li&gt;
&lt;li&gt;cNet:&amp;#0160;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://news.cnet.com/8301-1009_3-10067994-83.html&quot; id=&quot;f-to&quot; title=&quot;Botnets on cell phones in 2009?&quot;&gt;Botnets on cell phones in 2009?&lt;/a&gt; &lt;/li&gt;
&lt;li&gt;telecoms.com: &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.telecoms.com/itmgcontent/tcoms/news/articles/20017581221.html&quot; id=&quot;r76:&quot; title=&quot;Smartphone is a hotbed of security issues&quot;&gt;Smartphone is a hotbed of security issues&lt;/a&gt; &lt;br /&gt;
&lt;/li&gt;
&lt;li&gt;VNUnet: &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.vnunet.com/vnunet/news/2228330/security-industry-falling&quot; id=&quot;znq2&quot; title=&quot;Security industry falling behind hackers&quot;&gt;Security industry falling behind hackers&lt;/a&gt; &lt;br /&gt;
&lt;/li&gt;
&lt;li&gt;AP: &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://hosted.ap.org/dynamic/stories/P/PHONE_JAMMING?SITE=WSAW&amp;amp;SECTION=HOME&amp;amp;TEMPLATE=DEFAULT&quot; id=&quot;pgn:&quot; title=&quot;Phone Jamming in NH&quot;&gt;Phone Jamming in NH&lt;/a&gt; &lt;br /&gt;
&lt;/li&gt;
&lt;li&gt;GigaOm:&amp;#0160;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://gigaom.com/2008/10/17/eef-challenges-telco-immunity-in-court/&quot; id=&quot;d_dk&quot; title=&quot;EEF Challenges Telco Immunity in Court&quot;&gt;EEF Challenges Telco Immunity in Court&lt;/a&gt;&amp;#0160; &lt;br /&gt;
&lt;/li&gt;
&lt;li&gt;Information Week: &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.informationweek.com/news/infrastructure/ethernet/showArticle.jhtml?articleID=210605169&amp;amp;cid=RSSfeed_IWK_All&quot; id=&quot;r.gq&quot; title=&quot;New Protocols Secure Layer 2&quot;&gt;New Protocols Secure Layer 2&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Voice of VOIPSA:&amp;#0160;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://voipsa.org/blog/2008/10/08/asking-the-cisco-systems-ipics-and-jps-raytheon-acu-2000-experts-questions-36-40/&quot; id=&quot;wpk1&quot; title=&quot;Asking The Cisco Systems IPICS and JPS Raytheon ACU-2000 Experts: Questions 36-40&quot;&gt;Asking The Cisco Systems IPICS and JPS Raytheon ACU-2000 Experts: Questions 36-40&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Other &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.voipsa.org/blog/&quot; id=&quot;ogdq&quot; title=&quot;Voice of VOIPSA&quot;&gt;Voice of VOIPSA&lt;/a&gt; articles&lt;/li&gt;
&lt;li&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.tmcnet.com/usubmit/-snom-technology-ag-snom-820-combines-mature-voip-/2008/10/15/3705379.htm&quot; id=&quot;kija&quot; style=&quot;color:#551a8b;&quot; title=&quot;news release&quot;&gt;snom technology AG: snom 820 combines mature VoIP technology with exclusive design&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.marketwatch.com/news/story/idc-finds-increasing-hype-around/story.aspx?guid=%7B095A1E35-5F22-42D7-A223-53A3E1300419%7D&amp;amp;dist=hppr&quot; id=&quot;gddr&quot; title=&quot;IDC Finds Increasing Hype Around Unified Communications Is Affecting How Customers Select Telephony Systems and Services&quot;&gt;IDC Finds Increasing Hype Around Unified Communications Is Affecting How Customers Select Telephony Systems and Services&amp;#0160;&lt;/a&gt;(interesting movement in the top vendors used &amp;#0160;- Nortel out and IBM in)&lt;/li&gt;
&lt;li&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.tmcnet.com/channels/voice-peering/articles/43001-peerless-voip-peering.htm&quot; id=&quot;m:8s&quot; title=&quot;Peerless VoIP Peering&quot;&gt;Peerless VoIP Peering&lt;/a&gt; &lt;/li&gt;
&lt;li&gt;Comment (IM) from Christian Wieser
&lt;/li&gt;
&lt;li&gt;Review of the last week's traffic on the &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.voipsa.org/VOIPSEC/&quot;&gt;VOIPSEC &lt;/a&gt;public mailing list&lt;br /&gt;
&lt;/li&gt;
&lt;li&gt;Wrap-up of the show&lt;br /&gt;
&lt;/li&gt;
&lt;li&gt;32:10 - End of show&amp;#0160; &lt;/li&gt;
&lt;/ul&gt; &lt;p&gt;Comments, suggestions and feedback are welcome either as replies to this post&amp;#0160; or via e-mail to &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;mailto:blueboxpodcast@gmail.com&quot;&gt;blueboxpodcast@gmail.com&lt;/a&gt;.&amp;#0160; Audio comments sent as attached MP3 files are definitely welcome and will be played in future shows.&amp;#0160; You may also call the listener comment line at either +1-415-830-5439 or via SIP to '&lt;a rel=&quot;nofollow&quot;&gt;bluebox@voipuser.org&lt;/a&gt;' to leave a comment there.&amp;#0160; &lt;/p&gt; &lt;p&gt;Thank you for listening and please do let us know what you think of the show. &lt;/p&gt;&lt;/div&gt;</description>
         <author>Dan York</author>
         <guid isPermaLink="false">tag:typepad.com,2003:post-57466277</guid>
         <pubDate>Thu, 23 Oct 2008 08:42:11 -0700</pubDate>
      </item>
      <item>
         <title>Blue Box's 3-year anniversary coming up on Friday...</title>
         <link>http://www.blueboxpodcast.com/2008/10/blue-boxs-3-yea.html</link>
         <description>&lt;div&gt;It was three years ago Friday, on October 24, 2005, that I uploaded &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.blueboxpodcast.com/2005/10/blue_box_podcas.html&quot;&gt;Blue Box Podcast #1&lt;/a&gt;, an 11-minute show where I introduced the show, talked about VoIP security news (To no surprise, I was talking about Skype security!), some projects of VOIPSA and some other podcasts people might find interesting. A week later, on Halloween 2005, Jonathan joined me in &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.blueboxpodcast.com/2005/11/blue_box_podcas.html&quot;&gt;Blue Box Podcast #2&lt;/a&gt; and we were off and running... &lt;p&gt;Three years later... 84 main Blue Box episodes (with one more recorded) .... 26 Special Editions (with about 10 in the queue)... almost &lt;em&gt;250,000&lt;/em&gt; downloads... we're still here and, with an admitted bit of a rough patch this summer, are still going along creating shows and enjoying what we do. &lt;p&gt;Jonathan and I are planning to record a 3-year show on this coming Friday, October 24th, and if you have any comments you would like us to include in that show, please do get them to us by the end of the day on Thursday, October 23rd. You can send them to us via:
&lt;ul&gt;
&lt;li&gt;Email to &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;mailto:blueboxpodcast@gmail.com&quot;&gt;blueboxpodcast@gmail.com&lt;/a&gt;
&lt;li&gt;Phone to +1-415-830-5439
&lt;li&gt;Phone via SIP to &lt;a rel=&quot;nofollow&quot;&gt;sip:bluebox@voipuser.org&lt;/a&gt;
&lt;/ul&gt;
&lt;p&gt;The show started out 3 years ago as really an experiment in seeing whether or not podcasting could be used to reach out to very specific audiences... and it's been both fun, amazing and interesting to see how well it's done.
&lt;p&gt;Thank you to all of you who have continued to listen and contribute over the years! 
&lt;p&gt;Technorati Tags:
&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://technorati.com/tag/blue%20box&quot;&gt;blue box&lt;/a&gt;, &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://technorati.com/tag/bluebox&quot;&gt;bluebox&lt;/a&gt;, &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://technorati.com/tag/voip&quot;&gt;voip&lt;/a&gt;, &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://technorati.com/tag/voip%20security&quot;&gt;voip security&lt;/a&gt;, &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://technorati.com/tag/security&quot;&gt;security&lt;/a&gt;, &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://technorati.com/tag/dan%20york&quot;&gt;dan york&lt;/a&gt;, &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://technorati.com/tag/jonathan%20zar&quot;&gt;jonathan zar&lt;/a&gt;, &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://technorati.com/tag/voipsa&quot;&gt;voipsa&lt;/a&gt;
&lt;/p&gt;
&lt;/div&gt;</description>
         <author>Dan York</author>
         <guid isPermaLink="false">tag:typepad.com,2003:post-57320011</guid>
         <pubDate>Mon, 20 Oct 2008 13:22:21 -0700</pubDate>
      </item>
      <item>
         <title>Blue Box #84: New Cisco, Avaya, Nortel VoIP security vulnerabilities from VoIPShield, Skype in China, UCSniff and other new tools, news and more</title>
         <link>http://www.blueboxpodcast.com/2008/10/blue-box-84-new.html</link>
         <description>&lt;div&gt;&lt;p&gt;&lt;strong&gt;Synopsis:&lt;/strong&gt;&amp;nbsp; Blue Box #84: New Cisco, Avaya, Nortel VoIP security vulnerabilities
from VoIPShield, Skype in China, UCSniff and other new tools, news and
more &lt;/p&gt;&lt;hr /&gt;&lt;p&gt;Welcome to &lt;strong&gt;Blue Box: The VoIP Security Podcast&lt;/strong&gt; #84, a 30-minute podcast&amp;nbsp; from Dan York and Jonathan Zar covering VoIP security news, comments and opinions.&amp;nbsp; &amp;nbsp; &lt;/p&gt; &lt;p&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://media.libsyn.com/media/lodestar/BBP-084-2008-10-10.mp3&quot;&gt;Download the show here&lt;/a&gt; (MP3, MB) or &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://feeds.feedburner.com/BlueBox&quot;&gt;subscribe to the RSS feed&lt;/a&gt; to download the show automatically.&amp;nbsp; &lt;/p&gt; &lt;p&gt;You may also listen to this podcast right now:&lt;/p&gt; &lt;p&gt; &lt;/p&gt; &lt;p&gt;&lt;strong&gt;Show Content:&lt;/strong&gt;&lt;/p&gt; &lt;ul&gt; &lt;li&gt;00:20 - Intro to the show, contact information and how to provide comments.&amp;nbsp; Welcome to all the new listeners - and to all those listeners who have been here for so long!&lt;/li&gt;
&lt;li&gt;Programming notes: &lt;ul&gt; &lt;li&gt;Three-year anniversary of Blue Box coming up on October 24th - any thoughts you'd like to share with us? (Please send them to us by October 23rd.)&lt;/li&gt; &lt;/ul&gt;
&lt;/li&gt; &lt;li&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.marketwatch.com/news/story/voipshield-uncovers-new-security-vulnerabilities/story.aspx?guid=%7B956C0D98-121F-4E95-BC14-3B5F448AF25A%7D&amp;amp;dist=hppr&quot;&gt;VoIPShield announces new vulnerabilities&lt;/a&gt; and &lt;a rel=&quot;nofollow&quot; id=&quot;r9se&quot; target=&quot;_blank&quot; href=&quot;http://www.voipshield.com/research.php&quot; title=&quot;http://www.voipshield.com/research.php&quot;&gt;http://www.voipshield.com/research.php&lt;/a&gt;&lt;/li&gt; &lt;li&gt;&lt;span style=&quot;font-family:Arial;&quot;&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.theregister.co.uk/2008/09/30/voip_eavesdropping_tool&quot;&gt;http://www.theregister.co.uk/2008/09/30/voip_eavesdropping_tool&lt;/a&gt;&lt;span style=&quot;font-size:0.8em;&quot;&gt;/&lt;/span&gt;&lt;/span&gt;&lt;/li&gt; &lt;li&gt;&lt;span style=&quot;font-family:Arial;&quot;&gt;&lt;span style=&quot;font-size:0.8em;&quot;&gt;&quot;Sipera Develops VoIP Spy Program - to Prove a Point&quot; - &lt;a rel=&quot;nofollow&quot; title=&quot;http://www.voipplanet.com/trends/article.php/3776136&quot; target=&quot;_blank&quot; href=&quot;http://www.voipplanet.com/trends/article.php/3776136&quot; id=&quot;gfhu&quot;&gt;http://www.voipplanet.com/trends/article.php/3776136&lt;/a&gt;&lt;/span&gt;&lt;/span&gt;&lt;/li&gt; &lt;li&gt;&lt;span style=&quot;font-family:Arial;&quot;&gt;&lt;span style=&quot;font-size:0.8em;&quot;&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.marketwatch.com/news/story/securelogix-announces-free-availability-voip/story.aspx?guid=%7BF1947C89-8177-4FA2-A40E-8D6E021BF558%7D&amp;amp;dist=hppr&quot;&gt;SecureLogix Announces Free Availability of VoIP Security Tools&lt;/a&gt;&lt;/span&gt;&lt;/span&gt;&lt;/li&gt; &lt;li&gt;NY Times: Surveillance of Skype Messages Found in China - &lt;a rel=&quot;nofollow&quot; title=&quot;http://www.nytimes.com/2008/10/02/technology/internet/02skype.html?_r=2&amp;amp;partner=rssnyt&amp;amp;pagewanted=print&quot; target=&quot;_blank&quot; href=&quot;http://www.nytimes.com/2008/10/02/technology/internet/02skype.html?_r=2&amp;amp;partner=rssnyt&amp;amp;pagewanted=print&quot; id=&quot;dnb2&quot;&gt;http://www.nytimes.com/2008/10/02/technology/internet/02skype.html?_r=2&amp;amp;partner=rssnyt&amp;amp;pagewanted=print&lt;/a&gt; &lt;/li&gt; &lt;li&gt;&lt;a rel=&quot;nofollow&quot; title=&quot;http://securitywatch.eweek.com/privacy/skypechina_breach_is_anyone_really_surprised.html&quot; target=&quot;_blank&quot; href=&quot;http://securitywatch.eweek.com/privacy/skypechina_breach_is_anyone_really_surprised.html&quot; id=&quot;i8rz&quot;&gt;http://securitywatch.eweek.com/privacy/skypechina_breach_is_anyone_really_surprised.html&lt;/a&gt; &lt;/li&gt; &lt;li&gt;&lt;a rel=&quot;nofollow&quot; title=&quot;http://www.informationweek.com/news/telecom/voip/showArticle.jhtml?articleID=210605439&quot; target=&quot;_blank&quot; href=&quot;http://www.informationweek.com/news/telecom/voip/showArticle.jhtml?articleID=210605439&quot; id=&quot;ugx5&quot;&gt;http://www.informationweek.com/news/telecom/voip/showArticle.jhtml?articleID=210605439&lt;/a&gt; &lt;/li&gt; &lt;li&gt;Skype CEO's blog post about the issue: &lt;a rel=&quot;nofollow&quot; title=&quot;http://share.skype.com/sites/en/2008/10/answers_to_some_commonly_asked.html&quot; target=&quot;_blank&quot; href=&quot;http://share.skype.com/sites/en/2008/10/answers_to_some_commonly_asked.html&quot; id=&quot;mucu&quot;&gt;http://share.skype.com/sites/en/2008/10/answers_to_some_commonly_asked.html&lt;/a&gt;&lt;/li&gt; &lt;li&gt;&lt;span style=&quot;font-family:Arial;&quot;&gt;&lt;a rel=&quot;nofollow&quot; title=&quot;http://www.itbusinessedge.com/blogs/top/?p=398&quot; target=&quot;_blank&quot; href=&quot;http://www.itbusinessedge.com/blogs/top/?p=398&quot;&gt;http://www.itbusinessedge.com/blogs/top/?p=398&lt;/a&gt;&lt;/span&gt;&lt;/li&gt; &lt;li&gt;&lt;span style=&quot;font-family:Arial;&quot;&gt;&lt;a rel=&quot;nofollow&quot; title=&quot;http://www.voip-news.com/feature/google-phone-europe-growth-092408/&quot; target=&quot;_blank&quot; href=&quot;http://www.voip-news.com/feature/google-phone-europe-growth-092408/&quot;&gt;http://www.voip-news.com/feature/google-phone-europe-growth-092408/&lt;/a&gt;&lt;/span&gt;&lt;/li&gt; &lt;li&gt;&lt;span style=&quot;font-family:Arial;&quot;&gt;&lt;a rel=&quot;nofollow&quot; title=&quot;http://www.itnewsafrica.com/?p=1269&quot; target=&quot;_blank&quot; href=&quot;http://www.itnewsafrica.com/?p=1269&quot;&gt;http://www.itnewsafrica.com/?p=1269&lt;/a&gt;&lt;/span&gt;&lt;/li&gt; &lt;li&gt;&lt;span style=&quot;font-family:Arial;&quot;&gt;&lt;a rel=&quot;nofollow&quot; title=&quot;http://news.cnet.com/8301-1009_3-10052393-83.html&quot; target=&quot;_blank&quot; href=&quot;http://news.cnet.com/8301-1009_3-10052393-83.html&quot;&gt;http://news.cnet.com/8301-1009_3-10052393-83.html&lt;/a&gt;&lt;/span&gt;&lt;/li&gt; &lt;li&gt;&lt;span style=&quot;font-family:Arial;&quot;&gt;&lt;a rel=&quot;nofollow&quot; title=&quot;http://www.broadbandreports.com/shownews/VoIP-Vulnerabilities-Being-Exposed-Today-98039&quot; target=&quot;_blank&quot; href=&quot;http://www.broadbandreports.com/shownews/VoIP-Vulnerabilities-Being-Exposed-Today-98039&quot;&gt;http://www.broadbandreports.com/shownews/VoIP-Vulnerabilities-Being-Exposed-Today-98039&lt;/a&gt;&lt;/span&gt;&lt;/li&gt; &lt;li&gt;&lt;span style=&quot;font-family:Arial;&quot;&gt;&lt;a rel=&quot;nofollow&quot; title=&quot;http://www.itbusinessedge.com/blogs/top/?p=402&quot; target=&quot;_blank&quot; href=&quot;http://www.itbusinessedge.com/blogs/top/?p=402&quot;&gt;http://www.itbusinessedge.com/blogs/top/?p=402&lt;/a&gt;&lt;/span&gt;&lt;/li&gt; &lt;li&gt;&lt;span style=&quot;font-family:Arial;&quot;&gt;&lt;a rel=&quot;nofollow&quot; id=&quot;tvjh&quot; target=&quot;_blank&quot; href=&quot;http://voipsa.org/blog/2008/10/07/5th-emergency-services-workshop-to-be-held-oct-21-23-in-vienna/&quot; title=&quot;http://voipsa.org/blog/2008/10/07/5th-emergency-services-workshop-to-be-held-oct-21-23-in-vienna/&quot;&gt;http://voipsa.org/blog/2008/10/07/5th-emergency-services-workshop-to-be-held-oct-21-23-in-vienna/&lt;/a&gt;&lt;/span&gt;&lt;/li&gt; &lt;li&gt;&lt;span style=&quot;font-family:Arial;&quot;&gt;&lt;a rel=&quot;nofollow&quot; title=&quot;http://eon.businesswire.com/news/eon/20080924005342/en&quot; target=&quot;_blank&quot; href=&quot;http://eon.businesswire.com/news/eon/20080924005342/en&quot;&gt;http://eon.businesswire.com/news/eon/20080924005342/en&lt;/a&gt;&lt;/span&gt;&lt;/li&gt; &lt;li&gt;&lt;span style=&quot;font-family:Arial;&quot;&gt;&lt;a rel=&quot;nofollow&quot; title=&quot;http://www.crn.com/security/210602442&quot; target=&quot;_blank&quot; href=&quot;http://www.crn.com/security/210602442&quot;&gt;http://www.crn.com/security/210602442&lt;/a&gt;&lt;/span&gt;&lt;/li&gt; &lt;li&gt;&lt;span style=&quot;font-family:Arial;&quot;&gt;&lt;a rel=&quot;nofollow&quot; title=&quot;http://it.tmcnet.com/topics/it/articles/41236-infoblox-unveils-dns-firewall-address-dns-vulnerability-concerns.htm&quot; target=&quot;_blank&quot; href=&quot;http://it.tmcnet.com/topics/it/articles/41236-infoblox-unveils-dns-firewall-address-dns-vulnerability-concerns.htm&quot;&gt;http://it.tmcnet.com/topics/it/articles/41236-infoblox-unveils-dns-firewall-address-dns-vulnerability-concerns.htm&lt;/a&gt;&lt;/span&gt;&lt;/li&gt; &lt;li&gt;&lt;span style=&quot;font-family:Arial;&quot;&gt;&lt;a rel=&quot;nofollow&quot; title=&quot;http://www.newswire.ca/en/releases/archive/September2008/29/c9005.html&quot; target=&quot;_blank&quot; href=&quot;http://www.newswire.ca/en/releases/archive/September2008/29/c9005.html&quot;&gt;http://www.newswire.ca/en/releases/archive/September2008/29/c9005.html&lt;/a&gt;&lt;/span&gt;&lt;/li&gt; &lt;li&gt;No comments this week.&lt;br /&gt;
&lt;/li&gt; &lt;li&gt;Review of the last week's traffic on the &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.voipsa.org/VOIPSEC/&quot;&gt;VOIPSEC &lt;/a&gt;public mailing list&lt;br /&gt;
&lt;/li&gt; &lt;li&gt;Wrap-up of the show&lt;br /&gt;
&lt;/li&gt; &lt;li&gt;30:26 - End of show&amp;nbsp; &lt;/li&gt;&lt;/ul&gt; &lt;p&gt;&lt;em&gt;NOTE: Long-time listeners will note that the show notes above are in a less descriptive form than usual. After almost three years of using one wiki for preparing for our shows, Jonathan and I switched to using a new system and are still working out some of the details that will speed the input into show notes. &lt;/em&gt;&lt;/p&gt; &lt;p&gt;Comments, suggestions and feedback are welcome either as replies to this post&amp;nbsp; or via e-mail to &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;mailto:blueboxpodcast@gmail.com&quot;&gt;blueboxpodcast@gmail.com&lt;/a&gt;.&amp;nbsp; Audio comments sent as attached MP3 files are definitely welcome and will be played in future shows.&amp;nbsp; You may also call the listener comment line at either +1-415-830-5439 or via SIP to '&lt;a rel=&quot;nofollow&quot;&gt;bluebox@voipuser.org&lt;/a&gt;' to leave a comment there.&amp;nbsp; &lt;/p&gt; &lt;p&gt;Thank you for listening and please do let us know what you think of the show. &lt;/p&gt;&lt;/div&gt;</description>
         <author>Dan York</author>
         <guid isPermaLink="false">tag:typepad.com,2003:post-57285477</guid>
         <pubDate>Mon, 20 Oct 2008 02:32:18 -0700</pubDate>
      </item>
      <item>
         <title>Blue Box #83: SIP and Asterisk vulnerabilities, voice biometrics, P2PSIP, Aircell blocking Skype, VoIP security news and more…</title>
         <link>http://www.blueboxpodcast.com/2008/10/blue-box-83-sip.html</link>
         <description>&lt;div&gt;&lt;p&gt;&lt;strong&gt;Synopsis:&lt;/strong&gt;&amp;nbsp; Blue Box #83: &lt;span class=&quot;caps&quot;&gt;SIP&lt;/span&gt; and Asterisk vulnerabilities, voice biometrics, &lt;span class=&quot;caps&quot;&gt;P2PSIP&lt;/span&gt;, Aircell blocking Skype, VoIP security news and more…&lt;/p&gt;&lt;hr /&gt;&lt;p&gt;Welcome to &lt;strong&gt;Blue Box: The VoIP Security Podcast&lt;/strong&gt; #83, a 39-minute podcast&amp;nbsp; from Dan York and Jonathan Zar covering VoIP security news, comments and opinions.&amp;nbsp; &amp;nbsp; &lt;/p&gt; &lt;p&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://media.libsyn.com/media/lodestar/BBP-083-2008-09-04.mp3&quot;&gt;Download the show here&lt;/a&gt; (MP3, 18MB) or &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://feeds.feedburner.com/BlueBox&quot;&gt;subscribe to the RSS feed&lt;/a&gt; to download the show automatically.&amp;nbsp; &lt;/p&gt; &lt;p&gt;&lt;strong&gt;NOTE: &lt;/strong&gt;&lt;em&gt;This show was recorded on September 4, 2008. &lt;/em&gt;&lt;/p&gt; &lt;p&gt;You may also listen to this podcast right now:&lt;/p&gt; &lt;p&gt; &lt;/p&gt; &lt;p&gt;&lt;strong&gt;Show Content:&lt;/strong&gt;&lt;/p&gt; &lt;ul&gt; &lt;li&gt;00:20 - Intro to the show, contact information and how to provide comments.&amp;nbsp; Welcome to all the new listeners - and to all those listeners who have been here for so long!&lt;/li&gt;
&lt;li&gt;Programming notes: &lt;ul&gt; &lt;li&gt;Three-year anniversary of Blue Box coming up on October 24th - any thoughts you'd like to share with us? (Please send them to us by October 23rd.)&lt;/li&gt; &lt;/ul&gt;
&lt;/li&gt; &lt;li&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://voipsa.org/pipermail/voipsec_voipsa.org/2008-July/002702.html&quot;&gt;Remote DoS in reSIProcate&lt;/a&gt;&lt;/li&gt; &lt;li&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://voipsa.org/pipermail/voipsec_voipsa.org/2008-July/002699.html&quot;&gt;Remote root shell in Trixbox&lt;/a&gt;&lt;/li&gt; &lt;li&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://voipsa.org/blog/2008/06/25/avaya-cisco-and-nortel-voip-security-vulnerabilities-to-be-announced-today/&quot;&gt;Second route of VoIPShield Cisco/Avaya/Nortel vulnerabilities&lt;/a&gt;&lt;/li&gt; &lt;li&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://voipsa.org/blog/2008/07/22/two-new-asterisk-security-advisories/&quot;&gt;AST-2008-010 – &lt;span class=&quot;caps&quot;&gt;IAX2 &lt;/span&gt;‘POKE’ Resource Exhaustion&lt;/a&gt;&lt;/li&gt; &lt;li&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://voipsa.org/blog/2008/07/22/two-new-asterisk-security-advisories/&quot;&gt;AST-2008-011 – &lt;span class=&quot;caps&quot;&gt;IAX2 &lt;/span&gt;Firmware Provisioning System&lt;/a&gt;&lt;/li&gt; &lt;li&gt;Saunderslog: &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://saunderslog.com/2008/07/14/squawkbox-july-10-2008-voice-biometrics-and-voiceverifiedcom/&quot;&gt;Squawk Box – July 10, 2008: Voice biometrics and VoiceVerified.com&lt;/a&gt;&lt;/li&gt; &lt;li&gt;Saunderslog: &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://saunderslog.com/2008/07/09/squawkbox-july-9-2008-p2psip-guest-david-bryan/&quot;&gt;Squawk Box – July 9, 2008: &lt;span class=&quot;caps&quot;&gt;P2PSIP&lt;/span&gt;&lt;/a&gt;&lt;/li&gt; &lt;li&gt;&lt;span class=&quot;caps&quot;&gt;IETF&lt;/span&gt;: &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.ietf.org/internet-drafts/draft-matuszewski-p2psip-security-requirements-03.txt&quot;&gt;P2PSIP Security Requirements&lt;/a&gt;&lt;/li&gt; &lt;li&gt;Voice of &lt;span class=&quot;caps&quot;&gt;VOIPSA&lt;/span&gt;: “Aircell blocking VoIP on a plane” – &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://voipsa.org/blog/2008/08/26/how-aircell-is-probably-blocking-voip-phone-calls-on-planes-hint-voip-whack-a-mole/&quot;&gt;part 1&lt;/a&gt; , &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://voipsa.org/blog/2008/08/26/the-reason-why-probably-you-can-use-phweet-on-a-plane-when-skype-is-blocked/&quot;&gt;part 2&lt;/a&gt; and an &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://voipsa.org/blog/2008/08/28/update-on-the-aircell-voip-on-a-plane-prohibition-and-an-aircell-response/&quot;&gt;update&lt;/a&gt;&lt;/li&gt; &lt;li&gt;Voice of &lt;span class=&quot;caps&quot;&gt;VOIPSA&lt;/span&gt;: Shawn Merdinger’s series on “Asking The Cisco &lt;span class=&quot;caps&quot;&gt;IPICS &lt;/span&gt;Expert” – Questions &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://voipsa.org/blog/2008/07/17/asking-the-cisco-systems-ipics-expert-questions-1-5/&quot;&gt;1-5&lt;/a&gt; – &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://voipsa.org/blog/2008/07/23/asking-the-cisco-systems-ipics-expert-questions-6-10/&quot;&gt;6-10&lt;/a&gt; – &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://voipsa.org/blog/2008/08/02/asking-the-cisco-systems-ipics-expert-questions-11-15/&quot;&gt;11-15&lt;/a&gt; – &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://voipsa.org/blog/2008/08/18/asking-the-cisco-systems-ipics-expert-questions-16-20/&quot;&gt;16-20&lt;/a&gt; – &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://voipsa.org/blog/2008/09/02/asking-the-cisco-systems-ipics-expert-questions-21-25/&quot;&gt;21-25&lt;/a&gt;&lt;/li&gt; &lt;li&gt;Voice of &lt;span class=&quot;caps&quot;&gt;VOIPSA&lt;/span&gt;: &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://voipsa.org/blog/2008/07/23/asterisk-hack-to-show-blocked-caller-id-points-to-larger-trust-issues-with-sip/&quot;&gt;Asterisk ‘hack’ to show blocked Caller-ID points to larger trust issues with &lt;span class=&quot;caps&quot;&gt;SIP&lt;/span&gt;&lt;/a&gt; (and SpeechTEK speech)&lt;/li&gt; &lt;li&gt;NetworkWorld: &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.networkworld.com/news/2008/072908-georgia-student-arrested-for-hacking.html&quot;&gt;Georgia student arrested for hacking grades, VoIP&lt;/a&gt;&lt;/li&gt; &lt;li&gt;&lt;span class=&quot;caps&quot;&gt;CRN&lt;/span&gt;: &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.crn.com/security/209900949&quot;&gt;Analysis: Hacking VoIP as easy as 1-2-3&lt;/a&gt;&lt;/li&gt; &lt;li&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://voipsa.org/blog/2008/07/16/ari-takanen-starts-blogging-at-itworld/&quot;&gt;Ari Takanen starts blogging at InfoWorld&lt;/a&gt;&lt;/li&gt; &lt;li&gt;InfoWorld: &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.itworld.com/security/54688/there-motivation-voip-fuzzing&quot; class=&quot;Is There&quot;&gt; Motivation for VoIP Fuzzing&lt;/a&gt;&lt;/li&gt; &lt;li&gt;TMCnet: How to keep your tech career afloat&lt;/li&gt; &lt;li&gt;New analyst report: &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.sunherald.com/prnewswire/story/687245.html&quot;&gt;Security Threats Loom Over Unified Communications&lt;/a&gt; pointing to &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.lightreading.com/entvoip/details.asp?sku_id=2230&amp;amp;skuitem_itemid=1113&amp;amp;promo_code=&amp;amp;aff_code=&amp;amp;next_url=%2Fentvoip%2Flist.asp%3Fpage_type%3Drecent_reports&quot;&gt;Light Reading report&lt;/a&gt; and &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.lightreading.com/entvoip/document.asp?doc_id=159146&quot;&gt;article&lt;/a&gt;&lt;/li&gt; &lt;li&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.callcentre.co.uk/c/portal/layout?p_l_id=259723&amp;amp;CMPI_SHARED_articleId=551057&amp;amp;CMPI_SHARED_CommentArticleId=551057&amp;amp;CMPI_SHARED_ImageArticleId=551057&amp;amp;CMPI_SHARED_ToolsArticleId=551057&amp;amp;CMPI_SHARED_articleIdRelated=551057&amp;amp;articleTitle=VoIP%20companies%20to%20fight%20for%20market%20share&quot;&gt;VoIP Companies to Fight For Market Share&lt;/a&gt;&lt;/li&gt; &lt;li&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.thetechherald.com/article.php/200836/1907/IEEE-approves-802-11r-roaming-Wi-Fi-standard&quot;&gt;IEEE approves 802.11r standard&lt;/a&gt;&lt;/li&gt; &lt;li&gt;Google Chrome – upgrading the web to be application-centric&lt;/li&gt; &lt;li&gt;Items on my &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.disruptivetelephony.com/&quot;&gt;DisruptiveTelephony&lt;/a&gt; blog… Skype 5th birthday, Asterisk future, Digium/Nortel&lt;/li&gt; &lt;li&gt;No comments this week.&lt;br /&gt;
&lt;/li&gt; &lt;li&gt;Review of the last week's traffic on the &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.voipsa.org/VOIPSEC/&quot;&gt;VOIPSEC &lt;/a&gt;public mailing list&lt;br /&gt;
&lt;/li&gt; &lt;li&gt;Wrap-up of the show&lt;br /&gt;
&lt;/li&gt; &lt;li&gt;39:08 - End of show&amp;nbsp; &lt;/li&gt;&lt;/ul&gt; &lt;p&gt;Comments, suggestions and feedback are welcome either as replies to this post&amp;nbsp; or via e-mail to &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;mailto:blueboxpodcast@gmail.com&quot;&gt;blueboxpodcast@gmail.com&lt;/a&gt;.&amp;nbsp; Audio comments sent as attached MP3 files are definitely welcome and will be played in future shows.&amp;nbsp; You may also call the listener comment line at either +1-415-830-5439 or via SIP to '&lt;a rel=&quot;nofollow&quot;&gt;bluebox@voipuser.org&lt;/a&gt;' to leave a comment there.&amp;nbsp; &lt;/p&gt; &lt;p&gt;Thank you for listening and please do let us know what you think of the show. &lt;/p&gt;&lt;/div&gt;</description>
         <author>Dan York</author>
         <guid isPermaLink="false">tag:typepad.com,2003:post-57081861</guid>
         <pubDate>Thu, 16 Oct 2008 04:10:43 -0700</pubDate>
      </item>
      <item>
         <title>Blue Box SE#026 - Astricon 2007 presentation on VoIP security and Asterisk</title>
         <link>http://www.blueboxpodcast.com/2008/09/blue-box-se026.html</link>
         <description>&lt;div&gt;&lt;p&gt;&lt;strong&gt;Synopsis:&lt;/strong&gt;&amp;nbsp; Blue Box Special Edition #26: Astricon 2007 presentation - &quot;Hacking and Attacking VoIP Systems: What you need to worry about&quot;&lt;/p&gt;&lt;hr /&gt;&lt;p&gt;Welcome to &lt;strong&gt;Blue Box: The VoIP Security Podcast&lt;/strong&gt; Special Edition #26, a 55-minute podcast&amp;nbsp; from Dan York and Jonathan Zar covering VoIP security news, comments and opinions.&amp;nbsp; &amp;nbsp; &lt;/p&gt; &lt;p&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://media.libsyn.com/media/lodestar/BBP-SE026-Astricon2007-VoIPSecurity.mp3&quot;&gt;Download the show here&lt;/a&gt; (MP3, 6MB) or &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://feeds.feedburner.com/BlueBox&quot;&gt;subscribe to the RSS feed&lt;/a&gt; to download the show automatically.&amp;nbsp; &lt;/p&gt; &lt;p&gt;You may also listen to this podcast right now:&lt;/p&gt; &lt;p&gt; &lt;/p&gt; &lt;p&gt;&lt;strong&gt;Show Content:&lt;/strong&gt;&lt;/p&gt; &lt;p&gt;A year ago in September 2007, I (Dan York) spoke at Astricon 2007 in Arizona, USA, about &quot;Hacking and Attacking VoIP Systems: What You Need To Worry About&quot; My presentation covered a lot of the typical VoIP security threats, tools and best practices but also expanded a bit into specific security issues with Asterisk.&amp;nbsp; Please do keep in mind that it has been a year since this presentation and so some of the issues I mention have been addressed. (&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.astricon.net/&quot;&gt;Astricon&lt;/a&gt;, for those who don't know, is an annual developer conference for those who work with the &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.asterisk.org/&quot;&gt;Asterisk open source telephony platform&lt;/a&gt;. Astricon 2008 is, in fact, coming up in about 3 weeks but I will not be attending this year.)
&lt;/p&gt; &lt;p&gt;The slides for this talk &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.slideshare.net/danyork/hacking-and-attacking-voip-systems-what-you-need-to-know/&quot;&gt;are available from Slideshare&lt;/a&gt;:
&lt;/p&gt; &lt;div id=&quot;__ss_178451&quot; style=&quot;width:425px;text-align:left;&quot;&gt;&lt;a rel=&quot;nofollow&quot; title=&quot;Hacking and Attacking VoIP Systems - What You Need To Know&quot; target=&quot;_blank&quot; href=&quot;http://www.slideshare.net/danyork/hacking-and-attacking-voip-systems-what-you-need-to-know?src=embed&quot; style=&quot;margin:12px 0pt 3px;font-family:Helvetica, Arial, Sans-serif;font-style:normal;font-variant:normal;font-weight:normal;font-size:14px;line-height:normal;font-size-adjust:none;font-stretch:normal;display:block;text-decoration:underline;&quot;&gt;Hacking and Attacking VoIP Systems - What You Need To Know&lt;/a&gt;&lt;iframe class=&quot;embeddedvideo&quot; width=&quot;425&quot; height=&quot;355&quot; type=&quot;application/x-shockwave-flash&quot; src=&quot;http://static.slideshare.net/swf/ssplayer2.swf?doc=hacking-and-attacking-voip-systems-what-you-need-to-know-119595215763603-5&amp;amp;stripped_title=hacking-and-attacking-voip-systems-what-you-need-to-know&quot;&gt;&lt;/iframe&gt;&lt;div style=&quot;font-size:11px;font-family:tahoma, arial;height:26px;padding-top:2px;&quot;&gt;View SlideShare &lt;a rel=&quot;nofollow&quot; title=&quot;View Hacking and Attacking VoIP Systems - What You Need To Know on SlideShare&quot; target=&quot;_blank&quot; href=&quot;http://www.slideshare.net/danyork/hacking-and-attacking-voip-systems-what-you-need-to-know?src=embed&quot; style=&quot;text-decoration:underline;&quot;&gt;presentation&lt;/a&gt; or &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.slideshare.net/upload?src=embed&quot; style=&quot;text-decoration:underline;&quot;&gt;Upload&lt;/a&gt; your own. (tags: &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://slideshare.net/tag/voip&quot; style=&quot;text-decoration:underline;&quot;&gt;voip&lt;/a&gt; &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://slideshare.net/tag/voipsecurity&quot; style=&quot;text-decoration:underline;&quot;&gt;voipsecurity&lt;/a&gt;)&lt;/div&gt;&lt;/div&gt;
&lt;p&gt;&lt;em&gt;(And yes, at some point I'll sync the audio with the slides.)&lt;/em&gt;
&lt;/p&gt; &lt;p&gt;Production assistance on this Special Edition was provided by Michael Graves who had a very tough task given the poor quality of the recording that I gave to him!&amp;nbsp; Kudos to Michael for getting it to sound as good as it does. &lt;/p&gt; &lt;p&gt;Comments, suggestions and feedback are welcome either as replies to this post&amp;nbsp; or via e-mail to &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;mailto:blueboxpodcast@gmail.com&quot;&gt;blueboxpodcast@gmail.com&lt;/a&gt;.&amp;nbsp; Audio comments sent as attached MP3 files are definitely welcome and will be played in future shows.&amp;nbsp; You may also call the listener comment line at either +1-415-830-5439 or via SIP to '&lt;a rel=&quot;nofollow&quot;&gt;bluebox@voipuser.org&lt;/a&gt;' to leave a comment there.&amp;nbsp; &lt;/p&gt; &lt;p&gt;Thank you for listening and please do let us know what you think of the show. &lt;/p&gt;&lt;/div&gt;</description>
         <author>Dan York</author>
         <guid isPermaLink="false">tag:typepad.com,2003:post-55099816</guid>
         <pubDate>Wed, 03 Sep 2008 12:54:03 -0700</pubDate>
      </item>
      <item>
         <title>Blue Box #82: Asterisk &amp; Skype security vulnerabilities, new VoIP security tools, VoIP steganography, VoIP security news and much, much more...</title>
         <link>http://www.blueboxpodcast.com/2008/08/blue-box-82-ast.html</link>
         <description>&lt;div&gt;&lt;p&gt;&lt;strong&gt;Synopsis:&lt;/strong&gt;&amp;nbsp; Blue Box #82: Asterisk &amp; Skype security vulnerabilities, new VoIP security tools, VoIP steganography, VoIP security news and much, much more...&lt;/p&gt;&lt;hr /&gt;&lt;p&gt;Welcome to &lt;strong&gt;Blue Box: The VoIP Security Podcast&lt;/strong&gt; #82, a 47-minute podcast&amp;nbsp; from Dan York and Jonathan Zar covering VoIP security news, comments and opinions.&amp;nbsp; &amp;nbsp; &lt;/p&gt; &lt;p&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://media.libsyn.com/media/lodestar/BBP-082-2008-06-21.mp3&quot;&gt;Download the show here&lt;/a&gt; (MP3, 21MB) or &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://feeds.feedburner.com/BlueBox&quot;&gt;subscribe to the RSS feed&lt;/a&gt; to download the show automatically.&amp;nbsp; &lt;/p&gt; &lt;p&gt;&lt;strong&gt;NOTE: &lt;/strong&gt;&lt;em&gt;This show was originally recorded on June 21, 2008. &lt;/em&gt;&lt;/p&gt; &lt;p&gt;You may also listen to this podcast right now:&lt;/p&gt; &lt;p&gt; &lt;/p&gt; &lt;p&gt;&lt;strong&gt;Show Content:&lt;/strong&gt;&lt;/p&gt; &lt;ul&gt; &lt;li&gt;00:20 - Intro to the show, contact information and how to provide comments.&amp;nbsp; Welcome to all the new listeners - and to all those listeners who have been here for so long!&lt;/li&gt;
&lt;li&gt;Programming notes: &lt;ul&gt; &lt;li&gt;Note about the production team &amp;#8211; new special editions coming soon.&lt;/li&gt; &lt;li&gt;Note about URLs for the media files&lt;/li&gt; &lt;/ul&gt;
&lt;li&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://downloads.digium.com/pub/security/AST-2008-008.html&quot;&gt;AST-2008-008 &amp;#8211; Remote Crash Vulnerability in &lt;span class=&quot;caps&quot;&gt;SIP&lt;/span&gt; channel driver when run in pedantic mode&lt;/a&gt;&lt;/li&gt; &lt;li&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://downloads.digium.com/pub/security/AST-2008-009.html&quot;&gt;AST-2008-009 &amp;#8211; Remote crash vulnerability in ooh323 channel driver&lt;/a&gt;&lt;/li&gt; &lt;li&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.skype.com/security/skype-sb-2008-003.html&quot;&gt;Skype-SB-2008-003 &amp;#8211; Skype File &lt;span class=&quot;caps&quot;&gt;URI &lt;/span&gt;Security Bypass Code Execution Vulnerability&lt;/a&gt;&lt;/li&gt; &lt;p&gt;&lt;li&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://voipsa.org/pipermail/voipsec_voipsa.org/2008-June/002677.html&quot;&gt;New version of SIPvicious&lt;/a&gt;&lt;/li&gt;&lt;br /&gt; &lt;li&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://code.google.com/p/sipflanker/&quot;&gt;Sipflanker &amp;#8211; tool to find &lt;span class=&quot;caps&quot;&gt;SIP&lt;/span&gt; devices with web GUIs&lt;/a&gt;&lt;/li&gt;&lt;br /&gt;
&lt;ul&gt;&lt;br /&gt; &lt;li&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://voipsa.org/pipermail/voipsec_voipsa.org/2008-June/002678.html&quot;&gt;Discussion about VoIP Steganography&lt;/a&gt; (pointed to by Craig Bowser)&lt;/li&gt;&lt;br /&gt; &lt;li&gt;Geeks Are Sexy: &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.geeksaresexy.net/2008/06/02/new-technology-hides-messages-in-internet-phone-calls/&quot;&gt;New Technology Hides Messages in Internet Phone Calls&lt;/a&gt; &amp;#8211; and Switched: &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.switched.com/2008/06/03/spies-to-use-skype-to-send-secret-messages/&quot;&gt;Spies to Use Skype to Send Secret Messages?&lt;/a&gt; &amp;#8211; and &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.theregister.co.uk/2008/06/03/voip_steganography/&quot;&gt;The Register&lt;/a&gt;&lt;/li&gt;&lt;br /&gt; &lt;li&gt;FierceVoIP: &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.fiercevoip.com/story/voip-security-and-circle-trust/2008-05-06&quot;&gt;VoIP Security and the Circle of Trust&lt;/a&gt; pointing to Government Computer News: &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.gcn.com/print/27_10/46209-1.html&quot;&gt;Careful with the call&lt;/a&gt;&lt;/li&gt;&lt;br /&gt; &lt;br /&gt; &lt;li&gt;The Register: &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.theregister.co.uk/2008/06/03/low_tech_phishing_scams/&quot;&gt;&amp;#8216;Untraceable&amp;#8217; phone fraudsters eye your credit card&lt;/a&gt;&lt;/li&gt;&lt;br /&gt; &lt;br /&gt; &lt;li&gt;SearchUnifiedCommunications: &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://searchunifiedcommunications.techtarget.com/news/article/0,289142,sid186_gci1315878,00.html&quot;&gt;Disaster and recovery in the VoIP/IPT &lt;span class=&quot;caps&quot;&gt;RFP&lt;/span&gt;&lt;/a&gt;&lt;/li&gt;&lt;br /&gt; &lt;br /&gt; &lt;li&gt;Secure Computing: &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.securecomputing.net.au/News/114221,voice-tools-under-enemy-fire.aspx&quot;&gt;Voice tools under enemy fire&lt;/a&gt;&lt;/li&gt;&lt;br /&gt; &lt;br /&gt; &lt;li&gt;VNUnet: &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.vnunet.com/computing/analysis/2217608/voip-application-worth-paying-4021945&quot;&gt;A good VoIP application is worth paying for&lt;/a&gt;&lt;/li&gt;&lt;br /&gt; &lt;br /&gt; &lt;li&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.ofcom.org.uk/media/news/2007/12/nr_22071205&quot;&gt;Ofcom confirms VoIP providers must provide access to 999 and 112&lt;/a&gt;&lt;/li&gt;&lt;br /&gt; &lt;br /&gt; &lt;li&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://blog.voipshield.com/&quot;&gt;Bogdan Materna&amp;#8217;s blog is live&lt;/a&gt;&lt;/li&gt;&lt;/p&gt; &lt;p&gt;&lt;li&gt;Realtime Community: &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.realtime-websecurity.com/ESMWSv3.asp&quot;&gt;The Essentials Series:&lt;br /&gt;Messaging and Web Security&lt;br /&gt;Volume &lt;span class=&quot;caps&quot;&gt;III&lt;/span&gt;&lt;/a&gt;&lt;/li&gt;&lt;br /&gt; &lt;li&gt;Global Knowledge: &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://images.globalknowledge.com/wwwimages/seminars/voipsec/player.html&quot;&gt;On-Demand Webinar on VoIP Security&lt;/a&gt; (hat tip to &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://tfl09.blogspot.com/2008/06/voip-security-web-seminar.html&quot;&gt;Thomas Lee&lt;/a&gt; )&lt;/li&gt;&lt;br /&gt; &lt;li&gt;SearchSecurity: &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://searchsecurity.techtarget.com.au/articles/24883-The-threats-to-telcos-and-how-they-can-repel-them&quot;&gt;The threats to telcos and how they can repel them&lt;/a&gt;&lt;/li&gt;&lt;br /&gt; &lt;li&gt;TMCnet: &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.tmcnet.com/news/2008/06/02/3476832.htm&quot;&gt;Balancing Issues in World of Telepresence&lt;/a&gt;&lt;/li&gt;&lt;br /&gt; &lt;li&gt;Network World: &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.networkworld.com/buyersguides/guide.php?cat=898361&quot;&gt;VoIP Security Buying Guide&lt;/a&gt;&lt;/li&gt;&lt;/p&gt; &lt;p&gt;&lt;li&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.fiercewireless.com/press-releases/nortel-and-securelogix-team-deliver-voice-security-and-management-solutions-worldwide&quot;&gt;Nortel and SecureLogix Team to Deliver Voice Security and Management Solutions to Worldwide Enterprise Market&lt;/a&gt; (see also &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.fiercevoip.com/story/nortel-adds-voip-security-thru-securelogix/2008-06-02?utm_medium=rss&amp;#38;utm_source=rss&amp;#38;cmp-id=OTC-RSS-FV0&quot;&gt;this analysis&lt;/a&gt; )&lt;/li&gt;&lt;br /&gt; &lt;li&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.earthtimes.org/articles/show/sipera-partner-network-arms-resellers-with-comprehensive-uc-and-voip-security,428703.shtml&quot;&gt;Sipera Partner Network Arms Resellers With Comprehensive UC and VoIP Security&lt;/a&gt;&lt;/li&gt;&lt;br /&gt; &lt;li&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.webitpr.com/release_detail.asp?ReleaseID=8791&quot;&gt;VIVOphone Deploys Paradial RealTunnel® to Solve &lt;span class=&quot;caps&quot;&gt;NAT &lt;/span&gt;Traversal Challenges for VoIP Services&lt;/a&gt;&lt;/li&gt;&lt;br /&gt; &lt;li&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.networkworld.com/newsletters/converg/2008/061608converge1.html&quot;&gt;Audiocodes joins the ranks of &lt;span class=&quot;caps&quot;&gt;SBC&lt;/span&gt; vendors&lt;/a&gt;&lt;/li&gt;&lt;br /&gt;
&lt;li&gt;SearchSecurity: &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://searchnetworking.techtarget.com.au/articles/24906-Securing-the-new-network&quot;&gt;Securing the new network&lt;/a&gt; (interesting because it shows the layers of a defense in depth)&lt;/li&gt;&lt;br /&gt;
&lt;li&gt;The Hindu Business News: &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.thehindubusinessline.com/ew/2008/06/16/stories/2008061650050201.htm&quot;&gt;Serious about Security&lt;/a&gt;&lt;/li&gt;&lt;br /&gt;
&lt;li&gt;Shows:&lt;br /&gt;
&lt;ul&gt;&lt;br /&gt; &lt;li&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.iptelephonyuniversity.com/home.html&quot;&gt;IP Telephony University&lt;/a&gt; &amp;#8211; June 23-24, Alexandria, VA&lt;/li&gt;&lt;br /&gt; &lt;li&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://voipsa.org/pipermail/voipsec_voipsa.org/2008-June/002675.html&quot;&gt;IPTComm 2008&lt;/a&gt; &amp;#8211; July 1-2, Heidelberg, Germany&lt;/li&gt;&lt;br /&gt; &lt;li&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.thelasthope.org/index.php&quot;&gt;The Last H.O.P.E.&lt;/a&gt; &amp;#8211; July 18-20, New York&lt;/li&gt;&lt;br /&gt; &lt;li&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.speechtek.com/&quot;&gt;SpeechTek&lt;/a&gt; &amp;#8211; August 18-20, New York&lt;/li&gt;&lt;br /&gt; &lt;/ul&gt;&lt;br /&gt;
&lt;li&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://article.gmane.org/gmane.comp.voip.security.voipsa/2562&quot;&gt;Call for papers for Hack-in-the-box Malaysia&lt;/a&gt; ends June 30th&lt;/li&gt;&lt;br /&gt; &lt;br /&gt; &lt;li&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.room362.com/archives/192-ShmooCon-2008-Videos-Hit-the-Shelves.html&quot;&gt;SchmooCon 2008 videos available &amp;#8211; several dealing with VoIP&lt;/a&gt;&lt;/li&gt;&lt;/p&gt; &lt;p&gt;&lt;li&gt;No comments this week.&lt;br /&gt;
&lt;li&gt;Review of the last week's traffic on the &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.voipsa.org/VOIPSEC/&quot;&gt;VOIPSEC &lt;/a&gt;public mailing list&amp;nbsp; &lt;/li&gt;&lt;br /&gt;
&lt;li&gt;Wrap-up of the show &lt;/li&gt;&lt;br /&gt;
&lt;li&gt;47:09 - End of show&amp;nbsp; &lt;/li&gt;&lt;/ul&gt; &lt;p&gt;Comments, suggestions and feedback are welcome either as replies to this post&amp;nbsp; or via e-mail to &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;mailto:blueboxpodcast@gmail.com&quot;&gt;blueboxpodcast@gmail.com&lt;/a&gt;.&amp;nbsp; Audio comments sent as attached MP3 files are definitely welcome and will be played in future shows.&amp;nbsp; You may also call the listener comment line at either +1-415-830-5439 or via SIP to '&lt;a rel=&quot;nofollow&quot;&gt;bluebox@voipuser.org&lt;/a&gt;' to leave a comment there.&amp;nbsp; &lt;/p&gt; &lt;p&gt;Thank you for listening and please do let us know what you think of the show. &lt;/p&gt;&lt;/div&gt;&lt;/ul&gt;</description>
         <author>Dan York</author>
         <guid isPermaLink="false">tag:typepad.com,2003:post-54784026</guid>
         <pubDate>Wed, 27 Aug 2008 13:53:17 -0700</pubDate>
      </item>
   </channel>
</rss>
<!-- fe2.pipes.sp1.yahoo.com uncompressed/chunked Sun Nov 29 16:49:22 PST 2009 -->
