• Home
  • Advertise
  • Contact Us
  • Free eBooks
  • Infographics
  • About Us


  • Technology
    • Programming
      • Java
      • PHP
      • HTML
      • CSS
      • Javascript
      • XML
      • AJAX
      • JQuery
      • Perl
      • IDE
    • CMS
      • Opencart
      • WordPress
      • Prestashop
      • Magento
    • Database
  • Security
    • Cyber Laws
    • Digital Signature
    • Passwords
    • Reverse Engineering
    • Steganography
    • Forensics
    • Networking
  • E-Commerce
  • Digital Media
    • SEO
    • Social Media
      • Facebook
  • Gadgets
    • Laptops
    • Tablets
    • Just CellPhones
    • Social CellPhones
  • OS
    • Linux
    • Mac
    • Windows
    • iOS
    • Android
  • Courses
    • Development in Android
  • General

Breaking

The supercomputer "Tianhe-2" Takes No. 1 Ranking on 41st TOP500 List

Export tweets in different formats

OWASP - Top 10 Vulnerabilities

New Windows-backdoor deletes MBR

The world's first CPU of 5GHz

Critical vulnerability in 60 + models of CCTV and IP-cameras

Hack a Samsung TV with SmartTV function

The man who "almost broke the Internet"

The search continues for the sixth member of LulzSec

Statistics on the botnet Carna


Hacking Cisco IP-phone

0 Comment
 01 Jan 2013   Posted by synt4x

1 Star2 Stars3 Stars4 Stars5 Stars
Loading ... Loading ...


flattr this!

Rating:

Two weeks ago a student of intrusion detection systems for Columbia Ang Kui (Ang Cui) published a report on exploiting vulnerabilities in the kernel CNU (Cisco Native Unix) in IP-phones of Cisco 7975G, 7971G-GE, 7970G, 7965G, 7962G, 7961G, 7961G-GE, 7945G, 7942G, 7941G, 7941G-GE, 7931G, 7911G, 7906, 7971G-GE, 7970G, 7961G, 7961G-GE, 7941G, 7941G-GE and 7906.

Because of the lack of security check, calls to syscall attacker could overwrite arbitrary kernel memory fragments and run any code execution. As promised, Ang Cui reported on the hacker conference 29C3 (29th Chaos Communication Congress), which was held from 27 to 30 December in Hamburg.

In his presentation, the author shows how to exploit the vulnerability in  Cisco IP-phone to becoming undetectable. Malicious code gains root access on the system, has access to a digital signal processor (DSP) interface and device control. The student has developed a patch that makes the necessary changes to the kernel and DSP, so the IP-phone unbeknownst to the owner includes a microphone and begins covert wiretapping and recording. November 2 was released firmware upgrades for some phone models, while for the older model, the new firmware to be released, because they are out of production.

“Just because you are paranoid doesn’t mean your phone isn’t listening to everything you say,” – the motto of Ang Cui his presentation started , which can be viewed on video.

Cisco IP Phones:

Cisco CP-7940G Unified IP Phone

Cisco SPA 504G 4-Line IP Phone

Incoming Search Terms :

  • Cicso 7941 hacks
  • sEARCH PHP Directory Interface for Cisco IP Phones
  • what is cisco cnu

Spread The Word:

  • Facebook
  • Twitter
  • Pinterest
  • StumbleUpon
  • Google +1
  • Digg
  • Reddit
  • Email
  • LinkedIn
  • Tumblr
    Share This


Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

You may use these HTML tags and attributes: <a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <strike> <strong>

  • Find Us On Facebook

  • Airtel Hello Tunes

  • Ads.

  • Ads.

  • Shrugs Online


  • More...

    • Advertise
    • Crawl Fashion | Fashion Directory
    • Information Technology Act 2000 Compliance [Sec 43A and Sec 72A]
    • Java Tutorial
    • Netbeans Tutorial
    • Photography Blogs
    • Street Shopping
    • Virus Protection And Internet Security
  • Recent Posts

    • OWASP - Top 10 Vulnerabilities
    • New Windows-backdoor deletes MBR
    • Critical vulnerability in 60 + models of CCTV and IP-cameras
    • Hack a Samsung TV with SmartTV function
    • The man who "almost broke the Internet"
    • The search continues for the sixth member of LulzSec
  • Enter your email address to subscribe to "Bytes" Mag & receive THE latest updates on Tech!


Copyright © LetsByteCode Inc.
DMCA.com
loading Cancel
Post was not sent - check your email addresses!
Email check failed, please try again
Sorry, your blog cannot share posts by email.