Internet Telephony Product of the Year

VIPER Lab Speaking at DefCon 17!

VIPER Lab will be speaking at the DefCon 17 security conference in Las Vegas on July 31st - August 1st.  The title of our talk is “Advancing Video Application Attacks with Video Interception, Recording, and Replay.”

In this talk, we’ll be exploring some tools and methods for next-generation attacks against video applications that run on top of IP networks.  This is getting interesting.  2009 was declared as the year of IP Video.  Many enterprises are rolling out video applications, but most of the time security is an afterthought with these rollouts.  We’re trying to create the education and awareness here of new video attack paths that can happen. 

With these new tools, VoIP owners and security professionals can test the security of their networks, in order to understand these risks, and make a decision as to whether it’s a risk they are willing to accept, or apply the requisite security controls.  Along the way in developing these new tools, we have found a couple of new video applications that are being used for businesses in real-world examples.  

For more details on our talk, see the DefCon abstract:

https://www.defcon.org/html/defcon-17/dc-17-speakers.html#Ostrom


In this talk, for the first time, we’ll be unveiling UCSniff IP Video eavesdropping to the world.  UCSniff is the first security tool that can test the security of an IP network for video eavesdropping and reconstruction of video media into an AVI file container, that can be stored and viewed by an attacker.  This version of UCSniff will be 3.0, a windows port of the code.  We are using the JUCE GUI Libraries to develop the UCSniff GUI.

We’ll also be unveiling VideoJak, an IP Video interception and replay DoS tool.  This tool will be revealed for the first time to the world with some new attacks against IP video surveillance and IP video phones.

VideoJak and UCSniff can now be followed on Twitter.  Check out the pages for both of them:

http://twitter.com/ucsniff

http://twitter.com/videojak

UC Security Defined
Sipera Systems, the leader in real-time Unified Communications (UC) security, is the choice of enterprises and service providers around the world to support their mission-critical UC deployments.
Sipera offers groundbreaking, production-proven solutions that secure voice, video, messaging, collaboration, and other real-time communications in converged IP networks, boosting compliance with information security requirements.
Backed by the industry-leading research of the VIPER lab, Sipera's solutions provide comprehensive threat protection, policy enforcement, access control, and encryption in a single flexible appliance.

© Copyright 2010 Sipera Systems, Inc. All rights reserved. Sipera, Sipera UC-Sec and related products, SLiC, Sipera LAVA and Sipera VIPER are trademarks of Sipera Systems, Inc.