Put IT in High Gear – Engage!

Security Researchers Find Hole in VOIP software

February 24th, 2008 by engage

Cnet has an article this week pointing out a flaw in Cisco’s Discovery Protocol(CDP), a software protocol associated with a number of VOIP phones. Using a tool called VOIP Hopper, developed by Jason Ostrom at Vigilar, a IT security firm, its possible to use a public VOIP phone located in a lobby or a waiting area, to expose and gain access to a companies internal network. To protect against such an exploit the researchers recommend turning off CDP, disabling port 2 on public phones, and including public phones within firewall

No related posts.

blog comments powered by Disqus