
Hacking Exposed Unified Communications & VoIP Security Secrets & Solutions, Second Edition
Description
Alles über E-Books | Antworten auf Fragen rund um E-Books, Kopierschutz und Dateiformate finden Sie in unserem Info- & Hilfebereich.
More details
Other editions
Additional editions

Content
- Cover
- HACKING EXPOSEDT: Unified Communications & VoIP Security Secrets & Solutions, Second Edition
- Copyright Page
- Dedication
- About the Authors
- At a Glance
- Contents
- Acknowledgments
- Introduction
- Part I Casing the Establishment
- Case Study: Is There Really Any SIP in the Internet?
- Scanning the Entire Internet for SIP Servers
- Using the Shodan Search Engine to Locate Internet SIP Servers
- 1 VoIP Targets, Threats, and Components
- Campus/Internal UC
- Session Initiation Protocol and SIP Trunk Threats
- Increased Threats from the Public Voice Network
- Hosted UC
- Summary
- References
- 2 Footprinting a UC Network
- Why Footprint First?
- UC Footprinting Methodology
- Scoping the Effort
- Summary
- References
- 3 Scanning a UC Network
- Our VoIP Test Bed
- Network Host/Device Discovery
- ICMP Ping Sweeps
- Other ICMP Ping Sweeps
- Port Scanning and Service Discovery
- Host/Device Identification
- UC Phone Scanning and Discovery
- Summary
- References
- 4 Enumerating a UC Network
- SIP 101
- SIP URIs
- SIP Architecture Elements
- SIP Requests
- SIP Responses
- Typical Call Flow
- Further Reading
- RTP 101
- Banner Grabbing
- SIP User/Extension Enumeration
- Enumeration of Other UC Support Services
- UC Application-Level Enumeration
- Summary
- References
- Part II Application Attacks
- Case Study: A Real-world Telephony Denial of Service (TDoS) Attack
- The Payday Loan Scam
- 5 Toll Fraud and Service Abuse
- Internal Abuse of Unmonitored Phones
- Full-Scale Toll Fraud
- Summary
- References
- 6 Calling Number Spoofing
- Calling Number 101
- Spoofing/Masking the Calling Number with an IP PBX
- Anonymous Calling
- Network Services and Smartphone Apps
- Summary
- References
- 7 Harassing Calls and Telephony Denial of Service (TDoS)
- Harassing and Threatening Calls
- Social Networking TDoS
- Automated TDoS
- SIP Trunking
- Getting Target Numbers
- Audio Content
- Call Generation
- Attack Timing
- TDoS Attack Demonstration
- Using Virtual Queues
- Using Automated DoS to Cover Fraud
- Call Pumping
- DTMF DoS and Fuzzing
- Summary
- References
- 8 Voice SPAM
- Understanding Voice SPAM
- The FTC Robocall Challenge
- Other Types of UC SPAM
- Summary
- References
- 9 Voice Social Engineering and Voice Phishing
- Voice Social Engineering
- Voice Phishing
- Anatomy of a Traditional Email-based Phishing Attack
- Summary
- References
- Part III Exploiting the UC Network
- Case Study: The Angry Ex-Employee
- 10 UC Network Eavesdropping
- UC Privacy: What's at Risk
- TFTP Configuration File Sniffing
- Number Harvesting
- Call Pattern Tracking
- Conversation Eavesdropping and Analysis
- First, Gain Access to the UC Traffic
- Compromising a Network Node
- Now That We Have Access, Let's Sniff!
- Summary
- References
- 11 UC Interception and Modifi cation
- ARP Poisoning
- ARP Poisoning Attack Scenario
- Application-Level Interception Techniques
- How to Insert Rogue Applications
- SIP Rogue Application
- Summary
- References
- 12 UC Network Infrastructure Denial of Service (DoS)
- Call and Session Quality
- Measuring UC Call Quality
- Network Latency
- Jitter
- Packet Loss
- UC Call Quality Tools
- What Are DoS and DDoS Attacks?
- Flooding Attacks
- Network Availability Attacks
- Supporting Infrastructure Attacks
- Summary
- References
- 13 Cisco Unifi ed Communications Manager
- Introduction to the Basic Cisco UC Components
- IP PBX and Proxy
- Hard Phones
- Softphones
- Voicemail
- Switches and Routing
- Communication Between Cisco Phones and CUCM with SCCP
- Basic Deployment Scenarios
- Network Reconnaissance
- Sniffing
- Scanning and Enumeration
- Exploiting the Network
- Summary
- References
- Part IV UC Session and Application Hacking
- Case Study: An Attack Against Central SIP
- 14 Fuzzing, Flooding, and Disruption of Service
- Access to SIP and RTP
- What Is Fuzzing?
- Vulnerabilities 101
- Who's Fuzzing?
- Flooding
- Summary
- References
- 15 Signaling Manipulation
- Registration Manipulation
- Registration Removal
- Registration Addition
- Registration Hijacking
- Redirection Attacks
- Session Teardown
- SIP Phone Reboot
- Other Signaling Manipulation Tools
- Summary
- References
- 16 Audio and Video Manipulation
- Media Manipulation
- Audio Insertion and Mixing
- Video Dropping, Injection, and DoS with VideoJak and VideoSnarf
- Media "Steganophony"
- Summary
- References
- 17 Emerging Technologies
- Other Enterprise UC Systems
- Microsoft Lync
- Over-the-Top (OTT)/Internet Softphone Applications
- Skype
- Mobility and Smartphones
- Security
- Other Forms of Communications
- Video
- Text Messaging
- Messaging
- Enterprise Messaging
- Social Networking
- Bring Your Own Device (BYOD)
- Security
- The Cloud
- Hosted UC
- Security
- WebRTC
- Security
- Summary
- References
- Index
System requirements
File format: ePUB
Copy protection: Adobe-DRM (Digital Rights Management)
System requirements:
- Computer (Windows; MacOS X; Linux): Install the free reader Adobe Digital Editions prior to download (see eBook Help).
- Tablet/smartphone (Android; iOS): Install the free app Adobe Digital Editions or the app PocketBook before downloading (see eBook Help).
- E-reader: Bookeen, Kobo, Pocketbook, Sony, Tolino and many more (not Kindle).
The file format ePub works well for novels and non-fiction books – i.e., „flowing” text without complex layout. On an e-reader or smartphone, line and page breaks automatically adjust to fit the small displays.
This eBook uses Adobe-DRM, a „hard” copy protection. If the necessary requirements are not met, unfortunately you will not be able to open the eBook. You will therefore need to prepare your reading hardware before downloading.
Please note: We strongly recommend that you authorise using your personal Adobe ID after installation of any reading software.
For more information, see our ebook Help page.
File format: PDF
Copy-Protection: Adobe-DRM (Digital Rights Management)
System requirements:
- Computer (Windows; MacOS X; Linux): Install the free reader Adobe Digital Editions prior to download (see eBook Help).
- Tablet/smartphone (Android; iOS): Install the free app Adobe Digital Editions or the app PocketBook before downloading (see eBook Help).
- E-reader: Bookeen, Kobo, Pocketbook, Sony, Tolino and many more (only limited: Kindle).
The file format PDF always displays a book page identically on any hardware. This makes PDF suitable for complex layouts such as those used in textbooks and reference books (images, tables, columns, footnotes). Unfortunately, on the small screens of e-readers or smartphones, PDFs are rather annoying, requiring too much scrolling.
This eBook uses Adobe-DRM, a „hard” copy protection. If the necessary requirements are not met, unfortunately you will not be able to open the eBook. You will therefore need to prepare your reading hardware before downloading.
Please note: We strongly recommend that you authorise using your personal Adobe ID after installation of any reading software.
For more information, see our eBook Help page.