Cnet has an article this week pointing out a flaw in Cisco’s Discovery Protocol(CDP), a software protocol associated with a number of VOIP phones. Using a tool called VOIP Hopper, developed by Jason Ostrom at Vigilar, a IT security firm, its possible to use a public VOIP phone located in a lobby or a waiting area, to expose and gain access to a companies internal network. To protect against such an exploit the researchers recommend turning off CDP, disabling port 2 on public phones, and including public phones within firewall
No related posts.
