Security researchers find vulnerability in Cisco VoIP phones

Dec 19, 2012 by Bob Yirka report
Computer scientists find vulnerabilities in Cisco VoIP phones
Columbia Engineering's computer science Ph.D. candidate Ang Cui designed this device to plug into a Cisco phone and download malware, showing the vulnerabilities of the phone. Credit: Columbia Engineering

(Phys.org)—Ang Cui a fifth year PhD student at Columbia University, has given a demonstration at this year's Amphion Forum in San Francisco, showing a security vulnerability he and colleagues have discovered in Cisco VoIP phones. The vulnerability, he said, allows an intruder to place an electronic device into an on-premise VoIP phone that can be controlled by a nearby smartphone – allowing the "Off Hook Switch" to be manipulated in such as way as to effectively turn the phone into a two-way walkie-talkie. He noted also that once a single phone had been breached all others on the same network could be breached as well though the single device.

Cui's demonstration was part of an overall theme – that embedded devices are vulnerable to attack by people bent on or who wish to cause harm. He noted that devices such as network printers are quite often installed without adequate protection, leaving them open to attack by those outside of the system who wish to get in. VoIP phones, he says, use roughly the same type of technology and thus are equally vulnerable.

VoIP phones are normal looking phones that make and receive telephone calls using the Internet instead of the traditional phone network. Many have installed them because of their increased utility. Governments use them as well, Cui demonstrated, by presenting pictures of them sitting in several different governmental offices, including that of the Director of the CIA. In his demonstration, he affixed a simple circuit board (he calls it the Thingp3wn3r) to a VoIP phone that he said could just as easily have been in someone's real office – in just minutes. Next, he demonstrated the effectiveness of the Thingp3wn3r by accessing it via a app. Words he spoke in the vicinity of the phone, despite the receiver being down – the traditional mode of putting a phone offline – were picked up by the circuit board and transmitted to the smarthone app and played for all to hear. The end result is an ability to place a bug in an office using a simple circuit board and available hardware.

Cui and his professor, Salvatore Stolfo notified Cisco of the vulnerability prior to the demonstration and Cisco has responded by creating a patch that prevents the vulnerability from occurring. Those who are concerned about the vulnerability of their own systems are urged to contact Cisco for support.

Explore further: DOCOMO and Huawei confirm LTE network over unlicensed spectrum

More information: ids.cs.columbia.edu/sites/defa… iles/paper-acsac.pdf

Press release

Related Stories

ZTE scrambles to get at root of phone flaw

May 18, 2012

(Phys.org) -- Rattling phone security news surfaced this week for those owning ZTE Score M phones after an anonymous post to Pastebin.com reported a backdoor hole where others can gain control over a user& ...

Recommended for you

Bringing emergency communications together

Aug 21, 2014

A new University of Adelaide research project aims to improve emergency operations through integrated communications systems for police and the emergency services.

For top broadband policy, look no further than Canada

Aug 20, 2014

You might have seen communications minister Malcolm Turnbull raising the issue about Australian press not discussing policy problems and solutions from overseas, in a speech delivered at the Lowy Institute Media Awards last week: ...

Cities, states face off on municipal broadband

Aug 19, 2014

Wilson, N.C., determined nearly a decade ago that high-speed Internet access would be essential to the community's social and economic health in the 21st century, just as electricity, water and sewers were in the previous ...

New loss mechanism for global 4G roaming

Aug 19, 2014

A loss mechanism that has not been an issue in previous mobile handset antennas will become important for global 4G roaming, according to results of experiments carried out in Aalborg, Denmark.

User comments : 0