[cisco-voip] Cisco phones vulnerable to hack / remote access?

Blake Pfankuch blake at pfankuch.me
Fri Jan 4 13:44:24 EST 2013


Uhhhhh....

[blake at shlt01-centos ~]# host psirt.cisco.com
psirt.cisco.com has address 172.18.104.137

I see a problem...

From: cisco-voip-bounces at puck.nether.net [mailto:cisco-voip-bounces at puck.nether.net] On Behalf Of Nick Matthews
Sent: Friday, January 04, 2013 8:48 AM
To: Ed Leatherman
Cc: Cisco VOIP
Subject: Re: [cisco-voip] Cisco phones vulnerable to hack / remote access?

This may help:
https://psirt.cisco.com/PSIRThot/7900KernelSysCall
Particularly that they need physical access or the user authentication details for this attack to happen.
-nick

On Fri, Jan 4, 2013 at 10:00 AM, Ed Leatherman <ealeatherman at gmail.com<mailto:ealeatherman at gmail.com>> wrote:
Hah i just had someone ask me about this same article this morning. There was a article on it in IEEE Spectrum also - neither article seemed to give enough info for customers to take specific action on.

On Fri, Jan 4, 2013 at 9:35 AM, Robert Kulagowski <rkulagow at gmail.com<mailto:rkulagow at gmail.com>> wrote:
Since no one who knows anything for real is probably going to say
anything for now, are there any mitigating factors that I can start
thinking about once management sees the following article?

http://redtape.nbcnews.com/_news/2013/01/04/16328998-popular-office-phones-vulnerable-to-eavesdropping-hack-researchers-say?lite
_______________________________________________
cisco-voip mailing list
cisco-voip at puck.nether.net<mailto:cisco-voip at puck.nether.net>
https://puck.nether.net/mailman/listinfo/cisco-voip



--
Ed Leatherman

_______________________________________________
cisco-voip mailing list
cisco-voip at puck.nether.net<mailto:cisco-voip at puck.nether.net>
https://puck.nether.net/mailman/listinfo/cisco-voip

-------------- next part --------------
An HTML attachment was scrubbed...
URL: <https://puck.nether.net/pipermail/cisco-voip/attachments/20130104/7499f32d/attachment.html>


More information about the cisco-voip mailing list