Velocity Reviews

Velocity Reviews (http://www.velocityreviews.com/forums/index.php)
-   VOIP (http://www.velocityreviews.com/forums/f35-voip.html)
-   -   Safe to put a Linksys 3000 in a DMZ (http://www.velocityreviews.com/forums/t235069-safe-to-put-a-linksys-3000-in-a-dmz.html)

Dave 04-18-2006 05:04 PM

Safe to put a Linksys 3000 in a DMZ
 
Just wondering is it safe to put a Linksys 3000 ATA on a router's DMZ, is it
likely to get hacked being 'wide open'

Dave.


Ivor Jones 04-19-2006 12:45 AM

Re: Safe to put a Linksys 3000 in a DMZ
 


"Dave" <me@me.com> wrote in message
news:44451c32$0$29192$8fcfb975@news.wanadoo.fr
> Just wondering is it safe to put a Linksys 3000 ATA on a
> router's DMZ, is it likely to get hacked being 'wide open'
>
> Dave.


What exactly would anyone be able to hack in an ATA..?

Ivor



William P.N. Smith 04-19-2006 01:52 AM

Re: Safe to put a Linksys 3000 in a DMZ
 
"Ivor Jones" <ivor@despammed.invalid> wrote:
>"Dave" <me@me.com> wrote in message
>> Just wondering is it safe to put a Linksys 3000 ATA on a
>> router's DMZ, is it likely to get hacked being 'wide open'


>What exactly would anyone be able to hack in an ATA..?


Well, you could attach to it and make outgoing phone calls on Dave's
dime...

Dave 04-19-2006 07:40 AM

Re: Safe to put a Linksys 3000 in a DMZ
 

"William P.N. Smith" <news2006b@compusmiths.com> wrote in message
news:3t5b4292h82qhsqn409rfi8mbdcj7crfn7@4ax.com...
> "Ivor Jones" <ivor@despammed.invalid> wrote:
> >"Dave" <me@me.com> wrote in message
> >> Just wondering is it safe to put a Linksys 3000 ATA on a
> >> router's DMZ, is it likely to get hacked being 'wide open'

>
> >What exactly would anyone be able to hack in an ATA..?

>
> Well, you could attach to it and make outgoing phone calls on Dave's
> dime...


EXACTLY what I was thinking someone hacking there way in and taking my
details and using my account .....
Not sure how vulnerable a ATA is, also maybe possible to hack back into the
network via the ATA....??

Dave..


Ivor Jones 04-19-2006 07:38 PM

Re: Safe to put a Linksys 3000 in a DMZ
 


"Dave" <me@me.com> wrote in message
news:4445e989$0$19704$8fcfb975@news.wanadoo.fr
> "William P.N. Smith" <news2006b@compusmiths.com> wrote in
> message news:3t5b4292h82qhsqn409rfi8mbdcj7crfn7@4ax.com...
> > "Ivor Jones" <ivor@despammed.invalid> wrote:
> > > "Dave" <me@me.com> wrote in message
> > > > Just wondering is it safe to put a Linksys 3000 ATA
> > > > on a router's DMZ, is it likely to get hacked being
> > > > 'wide open'

> >
> > > What exactly would anyone be able to hack in an ATA..?

> >
> > Well, you could attach to it and make outgoing phone
> > calls on Dave's dime...

>
> EXACTLY what I was thinking someone hacking there way in
> and taking my details and using my account .....
> Not sure how vulnerable a ATA is, also maybe possible to
> hack back into the network via the ATA....??


I can't see how.

Ivor



William P.N. Smith 04-19-2006 10:55 PM

Re: Safe to put a Linksys 3000 in a DMZ
 
"Ivor Jones" <ivor@despammed.invalid> wrote:
>> "William P.N. Smith" <news2006b@compusmiths.com> wrote in


>> > Well, you could attach to it and make outgoing phone
>> > calls on Dave's dime...


>I can't see how.


Well, it's got an FXO port, which Dave has attached to his incoming
POTS line. If I can get at it, I can make calls (including long
distance calls and $500/min 900 calls, which I've previously arranged
to get a cut of) on Dave's POTS line.

Ivor Jones 04-19-2006 11:22 PM

Re: Safe to put a Linksys 3000 in a DMZ
 


"William P.N. Smith" <news2006b@compusmiths.com> wrote in
message news:vqfd42htdfh22lqk27b8mvf62rgv46qqnk@4ax.com
> "Ivor Jones" <ivor@despammed.invalid> wrote:
> > > "William P.N. Smith" <news2006b@compusmiths.com>
> > > wrote in

>
> > > > Well, you could attach to it and make outgoing phone
> > > > calls on Dave's dime...

>
> > I can't see how.

>
> Well, it's got an FXO port, which Dave has attached to
> his incoming POTS line. If I can get at it, I can make
> calls (including long distance calls and $500/min 900
> calls, which I've previously arranged to get a cut of) on
> Dave's POTS line.


I can see what you're getting at, but I can't see how you would achieve
it. In almost 2 years of using VoIP on a day to day basis I have never
heard of an ATA being "hacked" in the manner you describe. An ATA isn't
the same thing as a PC. I am prepared to be proven wrong, but it's not
something I have ever heard of happening, or even discussed before now.


Ivor



B. Wright 04-21-2006 01:34 AM

Re: Safe to put a Linksys 3000 in a DMZ
 
Ivor Jones <ivor@despammed.invalid> wrote:


> "William P.N. Smith" <news2006b@compusmiths.com> wrote in
> message news:vqfd42htdfh22lqk27b8mvf62rgv46qqnk@4ax.com
> > "Ivor Jones" <ivor@despammed.invalid> wrote:
> > > > "William P.N. Smith" <news2006b@compusmiths.com>
> > > > wrote in

> >
> > > > > Well, you could attach to it and make outgoing phone
> > > > > calls on Dave's dime...

> >
> > > I can't see how.

> >
> > Well, it's got an FXO port, which Dave has attached to
> > his incoming POTS line. If I can get at it, I can make
> > calls (including long distance calls and $500/min 900
> > calls, which I've previously arranged to get a cut of) on
> > Dave's POTS line.


> I can see what you're getting at, but I can't see how you would achieve
> it. In almost 2 years of using VoIP on a day to day basis I have never
> heard of an ATA being "hacked" in the manner you describe. An ATA isn't
> the same thing as a PC. I am prepared to be proven wrong, but it's not
> something I have ever heard of happening, or even discussed before now.


Ivor, that's a dangerous assumption to be made really. You're
trusting that there's NO possible way that Sipura has a security hole.
Regardless of the fact that it doesn't run a traditional OS, it has an
embedded operating system of sorts and devices like this have security
flaws as well. Just because it hasn't happened yet doesn't mean it
won't happen, remember when (if you've used the internet long enough you
well) the internet was "safe" and no one got hacked, was this because
none of the systems had security problems? No, security was laughable,
it was just the fact that there were a lot less monkeys out there with a
desire to do such things. Once something becomes more interesting and
widespread (and VoIP has already become this) it is a huge target of
interest to be hacked. One very obvious problem with the Sipura is the
access to the web interface doesn't even support SSL! When it comes to
security it's better not to make assumptions and be overly paranoid than
to be overly sloppy and find out later you were wrong. I believe that,
even behind some type of security device, SIP devices are still going to
have exploits exposed.

Imagine you're on an extended trip, halfway around the world,
using your SPA-3000 for communication and it's hooked onto the local
phone line so you can make outgoing local calls as well. Now, you've
left it in the DMZ and it gets hacked. What are you going to do?
Call and cancel your phone line it's connected to in order to mitigate
the damages?


Ivor Jones 04-21-2006 12:13 PM

Re: Safe to put a Linksys 3000 in a DMZ
 


"B. Wright" <bmwright@xmission.com> wrote in message
news:e29crt$qm8$1@news.xmission.com

[snip]

> Imagine you're on an extended trip, halfway around the
> world,
> using your SPA-3000 for communication and it's hooked
> onto the local phone line so you can make outgoing local
> calls as well. Now, you've left it in the DMZ and it
> gets hacked. What are you going to do?
> Call and cancel your phone line it's connected to in
> order to mitigate the damages?


Ok, but let me hear of an actual *documented* case where it has happened
before I get paranoid.

Many systems, SIP included, by their very nature have to be seen by the
outside world in order to work. Even if they're not in the DMZ (they're
not here), are my ATA's going to be hacked..?

Ivor



Arun Khan 05-01-2006 04:09 AM

Re: Safe to put a Linksys 3000 in a DMZ
 
Dave wrote:

>
> "William P.N. Smith" <news2006b@compusmiths.com> wrote in message
>> Well, you could attach to it and make outgoing phone calls on Dave's
>> dime...

>
> EXACTLY what I was thinking someone hacking there way in and taking my
> details and using my account .....
> Not sure how vulnerable a ATA is, also maybe possible to hack back into
> the network via the ATA....??


What is the alternative if one wants to use the VoIP number for *inbound*
calls? Just like any other Internet node, you have to keep your ATA
firmware updated to the latest version.

It would be nice if the device manufacturers and service providers can
provide a "security announcement" list for such updates.

If you are going to use the device for outbound calls only then you can
place the ATA behind a firewall and it should work.

-- Arun Khan


All times are GMT. The time now is 01:38 PM.

Powered by vBulletin®. Copyright ©2000 - 2013, vBulletin Solutions, Inc.
SEO by vBSEO ©2010, Crawlability, Inc.


1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57