VoIP Planet
www.voipplanet.com
VoIP Planet
The IT Manager's Guide to Voice over IP internet.com

VoIP Planet Newsletter


Search VoIP Planet

internet.commerce
Partners & Affiliates
Best Price
GPS
Promotional Golf
Online Shopping
Computer Hardware
Phone Cards
Promotional Products
Compare Prices
Disney World Tickets
Logo Design Custom
Server Racks
Televisions
Career Education
Send Text Messages

internet.com
IT
Developer
Internet News
Small Business
Personal Technology
International

Search internet.com
Advertise
Corporate Info
Newsletters
Tech Jobs
E-mail Offers

Download: “VoIP for Dummies” special edition booklet. Match your communications needs with your budget. No matter your business size, get the right fit with 3Com VoIP solutions.


  Generate Revenue Through IT Using Business Service Management
Sponsored by HP
Making sure that your business applications are available to their end users is an important part of running your business smoothly. Business operations have evolved to where IT must now broaden its focus to help the company attract, retain and grow customer relationships and increase customer satisfaction. Business service management (BSM) helps lay the foundation by managing services in dynamic support of business requirements. »
 
  Managing the Modern Network
Sponsored by HP
Networks are more than vehicles to transport e-mail and Web pages. In a global economy where information crosses the globe in an instant, and where Web-based applications power business, it's more important than ever to ensure your network is safe from threats and optimized to deliver the data your business needs. »
 
  Storage Networking 2, Configuration and Planning
Sponsored by HP
In Part 1, we discussed storage area networks (SANs) and fibre channel. In Part 2, delve into best practices and cover the general concepts you must know before configuring SAN-attached storage. The most critical, sometimes tedious, part of setting up a SAN is configuring each individual disk array. This guide examines configurations for SAN-attached servers and disk arrays, and also includes a look at the future of IP storage. »
 
  Is Your Disaster Recovery Plan Good Enough? Get Disaster Recovery Right
Sponsored by HP
Preparing for a disaster is more often than not part of the storage planning process, and without question it is one of the most difficult task, since it includes local hardware and software, networking equipment, and a test plan to ensure that you can recover from the disaster. Learn how to put your organization on the proper disaster recovery plan, now. »
 
Related Articles
VoIPowering Your Office: Being an Elite VoIP Consultant
VoIPowering Your Office: Debugging SIP Sessions Without Excessive Hair Loss
VoIPowering Your Office: Eavesdropping on VoIP Calls (Part 1)
July 30, 2007
By Carla Schroder

Just like with all TCP/IP traffic, it is easy for a snoopy person to sniff unencrypted VoIP packets and record your conversations. And don't think they won't. Remember the early days of cell phones, when people used ordinary police scanners to eavesdrop? Newt Gingrich, Nicole Kidman and Tom Cruise, Prince Charles, and hosts of other celebrities learned the hard way the value of using cell phones with strong encryption. It's not as easy to snoop wired IP traffic because you need physical access to the wires, but it's not that hard, either. Anyone on your network, anyone on other networks that you contact—and all points in between, including service providers—all have the opportunity to do an awful lot of juicy snooping. Throw in some poorly secured wireless access points, rogue wireless access points, or wireless VoIP endpoints, and you have a real security risk. While spying on other people's communications is mostly illegal, that's small comfort if it happens to you.

Eavesdropping on VoIP calls isn't as simple as sniffing ordinary TCP/IP traffic. For example, check out these snippets from running ngrep on an IRC session:

$ sudo ngrep -qpd eth0 host irc.server.org
interface: eth0 (192.168.1.0/255.255.255.0)
filter: (ip or ip6) and ( host irc.server.org )

T 192.168.1.10:35776 -> 140.22.33.44:6667 [AP]
PRIVMSG #spychannel :see how easy it is to spy on ordinary cleartext TCP/IP traffic.

T 192.168.1.10:35776 -> 140.22.33.44:6667 [AP]
PRIVMSG #spychannel :just fire up easily-available tools like ngrep or tcpdump.

You won't see this in a VoIP call, but rather a bunch of incomprehensible gump. But recording intercepted VoIP traffic is easy—just run any packet sniffer and store it in a file. Actually listening to the calls is a bit harder—you need a way to reconstruct the actual voice conversation out of mass chunks of binary data. But there are plenty of freely available software programs that do it all for you: capture, reconstruct, and play VoIP conversations. These are excellent tools with a legitimate purpose, which is debugging call-quality and VoIP service problems. But just like a hammer, they can also be used for ill.

RTP and SIP
Let's take a quick looks at RTP, the Real-time Transport Protocol. SIP (Session Initiation Protocol) is a signalling protocol. SIP handles the call control functions such as setting up the calls, tearing them down, and handling the call routing. SIP is a carrier for the Session Description Protocol (SDP) which defines the media content of a SIP session, such as what IP ports to use, and it negotiates which codecs to use. After all this housework is done, RTP carries the actual voice stream. So ace spies only need to capture RTP streams to get to the good stuff.

Vomiting VoIP
One favorite VoIP recording tool, favored possibly more for the name than for its abiltiies, is VOMIT (Voice Over Misconfigured Internet Telephones.). It only works on Cisco gear using the Cisco SCCP ("skinny") protocol, and it needs a separate tool to do the packet capture. So you might intercept a big chunk of the traffic you wish to spy on with tcpdump, then use VOMIT to convert it to a WAVE file which can be played on any computer.

Oreka is a more powerful VoIP capture tool, though its name is not quite so catchy. Oreka captures VoIP RTP sessions by passively listening to network packets, so you don't even know it's there. It has the ability to combine both sides of a conversation into a single audio file, and each call is captured into a separate audio file. It also captures the metadata from SIP and Cisco SCCP calls, which probably doesn't contain sensitive data, and can't be encrypted anyway or the SIP packets cannot be routed.

Oreka runs on both Linux and Windows, and it has a lot of nice features. You can filter on IP address or address ranges, it can monitor multiple network interfaces in parallel, and it has a nice Web control panel for retrieval and playback.

VoiPong is a powerful VoIP sniffer that runs on Solaris, Linux and FreeBSD. It supports SIP, H323, and Cisco's SCCP, and decodes all of the major codecs. VoiPong dumps calls into WAVE files for easy and fun playback. VoiPong even comes on a LiveCD now, so you can carry it with you and run it on any computer.

Is snooping really that easy?
Ha, you say, we only use VoIP internally and are on a nice stout switched network, so it would not be easy at all for our users to do VoIP snooping. I hope you're really not saying that, because VoIPowering Your Office: Debugging SIP Sessions Without Excessive Hair Loss showed how easy it is to capture remote network traffic without ever leaving your desk. Serious snoops know about arpspoof, which you can read all about in Switched Net? dsniff It. arpspoof is part of the dsniff suite of packet-sniffing tools that do everything from allow promiscuous network sniffing, to cracking passwords, to undetectably intercepting email messages, to spying on what Web pages other people are reading, and much more.

So the moral of this story is it's quite easy to spy on your VoIP traffic without you even knowing about it. What can you do about it? That's what we'll talk about in Part 2.

Tools:
Add voipplanet.com to your favorites
Add voipplanet.com to your browser search box
IE 7 | Firefox 2.0 | Firefox 1.5.x

Backgrounders Archives

Article: Manage Your Windows Infrastructure with Microsoft System Center
Five Trends for Application Development & Program Management. Download Complimentary Report Now.
Whitepaper: HP Integrated Citrix XenServer for HP ProLiant Servers. Sponsored by HP, Citrix, and Intel.
Best Practices: Make the Case for IT Investments. Complimentary Independent Report. Download Now!
Flash Demo: Learn how IBM Information Server Blade is easy to manage, highly scalable and efficient.





JupiterOnlineMedia

internet.comearthweb.comDevx.commediabistro.comGraphics.com

Search:

Jupitermedia Corporation has two divisions: Jupiterimages and JupiterOnlineMedia

Jupitermedia Corporate Info


Legal Notices, Licensing, Reprints, & Permissions, Privacy Policy.

Advertise | Newsletters | Tech Jobs | Shopping | E-mail Offers

Solutions
Whitepapers and eBooks
Microsoft Article: Will Hyper-V Make VMware This Decade's Netscape?
Microsoft Article: 7.0, Microsoft's Lucky Version?
Microsoft Article: Hyper-V--The Killer Feature in Windows Server 2008
Avaya Article: How to Feed Data into the Avaya Event Processor
Microsoft Article: Install What You Need with Windows Server 2008
HP eBook: Putting the Green into IT
Whitepaper: HP Integrated Citrix XenServer for HP ProLiant Servers
Intel Go Parallel Portal: Interview with C++ Guru Herb Sutter, Part 1
Intel Go Parallel Portal: Interview with C++ Guru Herb Sutter, Part 2--The Future of Concurrency
Avaya Article: Setting Up a SIP A/S Development Environment
IBM Article: How Cool Is Your Data Center?
Microsoft Article: Managing Virtual Machines with Microsoft System Center
HP eBook: Storage Networking , Part 1
Microsoft Article: Solving Data Center Complexity with Microsoft System Center Configuration Manager 2007
MORE WHITEPAPERS, EBOOKS, AND ARTICLES
Webcasts
Intel Video: Are Multi-core Processors Here to Stay?
On-Demand Webcast: Five Virtualization Trends to Watch
HP Video: Page Cost Calculator
Intel Video: APIs for Parallel Programming
HP Webcast: Storage Is Changing Fast - Be Ready or Be Left Behind
Microsoft Silverlight Video: Creating Fading Controls with Expression Design and Expression Blend 2
MORE WEBCASTS, PODCASTS, AND VIDEOS
Downloads and eKits
Sun Download: Solaris 8 Migration Assistant
Sybase Download: SQL Anywhere Developer Edition
Red Gate Download: SQL Backup Pro and free DBA Best Practices eBook
Red Gate Download: SQL Compare Pro 6
Iron Speed Designer Application Generator
MORE DOWNLOADS, EKITS, AND FREE TRIALS
Tutorials and Demos
How-to-Article: Preparing for Hyper-Threading Technology and Dual Core Technology
eTouch PDF: Conquering the Tyranny of E-Mail and Word Processors
IBM Article: Collaborating in the High-Performance Workplace
HP Demo: StorageWorks EVA4400
Intel Featured Algorhythm: Intel Threading Building Blocks--The Pipeline Class
Microsoft How-to Article: Get Going with Silverlight and Windows Live
MORE TUTORIALS, DEMOS AND STEP-BY-STEP GUIDES