Explore the world of VoIP security in this 53-minute Black Hat conference talk by Fatih Ozavci. Delve into cutting-edge attacks, tools, and vulnerabilities in VoIP networks, focusing on cloud-based Unified Communications (UC) solutions. Learn about jailbreaking tenant environments, critical security flaws in major vendors' products, and exploiting VoIP protocol vulnerabilities. Discover techniques for testing IP Multimedia Subsystem (IMS) services and understand the custom toolset developed by the speaker. Gain insights into the business impact of these attacks on various implementations, including cloud UC services, commercial services, and corporate communications. Through live demonstrations, understand how to secure and test communication infrastructure and services. Get introduced to updated versions of Viproy and Viproxy tools used for attack demonstrations. Cover topics ranging from traditional phone systems to modern challenges in corporate and cloud communications, as well as federated systems and IMS. Examine attack surfaces, testing approaches, and specific techniques for targeting clients, call centers, and IMS. Conclude with strategies for securing unified communications and participate in a live workshop to reinforce the concepts presented.
Read more