27C3 - Version 1.6.3

27th Chaos Communication Congress
We come in peace

Wolfgang Beck
Tag Day 3 - 2010-12-29
Raum Saal 2
Beginn 14:30
Dauer 00:30
ID 4181
Veranstaltungstyp Vortrag
Track Hacking
Sprache der Veranstaltung englisch

SIP home gateways under fire

Source routing attacks applied to SIP

The SIP home gateway -- which combines a NAT router, a SIP proxy, and analogue phone adapters -- is the weakest link in a Voice over IP network. SIP's numerous source routing mechanisms share the well-known security weaknesses of IP source routing. The talk discusses possible exploits and countermeasures.

Telephony is steadily moving to Voice over IP, opening up a world of hacking opportunities. While many security issues have long been addressed in standardization, real-world VoIP suffers from incomplete and sometimes broken implementations. SIP home gateways -- which combine a NAT router, a SIP proxy, and a phone adapter are especially at risk.

The predominant VoIP protocol SIP (Session Initiation Protocol) has been designed as an -- almost -- stateless protocol. The network elements responsible for call routing only keep very little and short-lived state. This makes SIP highly scalable and substantially simplifies fail-over.

To achieve this, SIP uses source routing mechanisms extensively. Due to its security weaknesses, the network layer protocols have long abandoned the idea of source routing, despite its theoretical appeal. Some IP source routing attacks and countermeasures can be applied to SIP.

The talk will discuss

  • how to impersonate somebody else, with seemingly network-asserted identity
  • how to trick a home gateway into sending UDP packets to an arbitrary host and port in a victim's LAN.
  • how to make a victim's home gateway call an arbitrary number (with some effort)
  • how to get material for your off-line password guessing attack
  • what SIP providers do about those issues
  • how SIP passed the IETF's security reviews
  • how home gateway vendors should improve their products to avoid all this mess.
Archived page - Impressum/Datenschutz