<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Redshift Networks Blog</title>
	<atom:link href="http://blog.redshiftnetworks.com/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.redshiftnetworks.com</link>
	<description></description>
	<lastBuildDate>Wed, 16 Nov 2011 12:03:50 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Recent Voicemail Hacking allegations at Murdoch News World exposes new Vulnerabilities in Communication Networks</title>
		<link>http://blog.redshiftnetworks.com/2011/07/08/voicemail-hacking-allegations-hits-rupert-murdoch%e2%80%99s-newspaper-real-hard/</link>
		<comments>http://blog.redshiftnetworks.com/2011/07/08/voicemail-hacking-allegations-hits-rupert-murdoch%e2%80%99s-newspaper-real-hard/#comments</comments>
		<pubDate>Fri, 08 Jul 2011 21:52:12 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[Redshift Networks]]></category>
		<category><![CDATA[UC security]]></category>

		<guid isPermaLink="false">http://blog.redshiftnetworks.com/2011/07/08/voicemail-hacking-allegations-hits-rupert-murdoch%e2%80%99s-newspaper-real-hard/</guid>
		<description><![CDATA[Recent coverage on voicemail hacking at “The News of the World” has exposed new set of vulnerabilities and threat vectors that can plague telephony networks. Allegations continue to multiply over its journalists hacking into voicemails of thousands of people from child murder victims, war victims, members of the royal family, parliament and other important dignitaries. [...]]]></description>
			<content:encoded><![CDATA[<p>Recent coverage on voicemail hacking at “The News of the World” has exposed new set of vulnerabilities and threat vectors that can plague telephony networks. Allegations continue to multiply over its journalists hacking into voicemails of thousands of people from child murder victims, war victims, members of the royal family, parliament and other important dignitaries. Sensitive conversations were either phone tapped or voice mails hacked into to gather dirt material that eventually made it into the tabloids.  According to latest coverage on the topic, the magnitude of the scandal has resulted in a decision to close the “The News of The world” paper.</p>
<p>In this global information age, the power of early access to information by perpetrators through malicious means often is a pre-cursor to more sophisticated illegitimate activities such as insider trading activities, leakage of sensitive information, stealing of company trade secrets, industry espionage or press tabloid materials as in the above case.</p>
<p>The growing prominence of IP- based communication networks and applications are empowering the user with ubiquitous instant-on connectivity, communications and collaboration with any person from any device, any location and at any time. This powerful user experience was never possible before and is now achievable through all pervasive and standard based IP networks. As a result, the conventional definition of perimeter security defense no longer exists. Any weakest link in the end-2-end communication leg can now effectively become the prima facie point for perpetrators to conduct malicious activities.</p>
<p>The stakeholders must understand that securing IP based communication networks and applications present unique security challenges that are vastly different and much stringent when compared to securing data applications – requiring near- zero false-positives and negatives, possessing deep understanding of call control (and services) stacks, device tracking, user/  application analytics, firewall capabilities possessing deep understanding of voice/video and UC protocols. The pervasiveness of IP-based communication networks makes it just much easier now to carry the hacking activities – wiretapping into conversations, brute force crawling and identifications of legal usernames/ extensions, illegitimate call pattern tracking, interception/rerouting of call traffic to hacker locations, presence tracking, stealing confidential voice messages from specific individuals (or extensions) are just few examples of security threats that can plague VOIP/UC networks if proper security measures are not enforced.</p>
<p>RedShift Networks honey pot research conducted over several months has indicated several threat vectors open in the wild today ranging from Voice/UC Denial-of-Service (VDOS/UC-DOS) attacks, SPAM over Internet Telephony (SPIT) attacks, Eavesdropping, Spoofing, Number Harvesting, Protocol Fuzzing, Toll Fraud, SQL Injections, Media tampering and a myriad of UC Infrastructure and Application layer threats. All these new threat vectors go completely undetected using existing protective solutions. Gartner in their recent study strongly recommend the use of SIP-aware Firewalls to protect your communication networks. For more information about RedShift Networks, products and services, please visit <a href="http://www.redshiftnetworks.com/">www.redshiftnetworks.com</a>.</p>
<p>Ref — <a title="blocked::http://news.yahoo.com/uk-soldiers-targeted-murdoch-phone-hacking-scandal-report-030337129.html" href="http://news.yahoo.com/uk-soldiers-targeted-murdoch-phone-hacking-scandal-report-030337129.html">http://news.yahoo.com/uk-soldiers-targeted-murdoch-phone-hacking-scandal-report-030337129.html</a></p>
]]></content:encoded>
			<wfw:commentRss>http://blog.redshiftnetworks.com/2011/07/08/voicemail-hacking-allegations-hits-rupert-murdoch%e2%80%99s-newspaper-real-hard/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Lead Story of the Month</title>
		<link>http://blog.redshiftnetworks.com/2011/05/25/lead-story-of-the-month%e2%80%a8%e2%80%a8/</link>
		<comments>http://blog.redshiftnetworks.com/2011/05/25/lead-story-of-the-month%e2%80%a8%e2%80%a8/#comments</comments>
		<pubDate>Wed, 25 May 2011 12:51:59 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Redshift Networks]]></category>

		<guid isPermaLink="false">http://blog.redshiftnetworks.com/?p=80</guid>
		<description><![CDATA[RedShift Networks, the leader in secure communications and collaboration solutions, announces the availability of RedShift UCTM E-SBC session border control appliance heavily tuned to serve the demanding security and interoperability requirements for enterprise VOIP/UC deployments. ??With the growing SIP Trunk deployments, RedShift UCTM E-SBC appliance provides unparalleled levels of security, control and visibility for today’s [...]]]></description>
			<content:encoded><![CDATA[<p>RedShift Networks, the leader in secure communications and collaboration solutions, announces the availability of RedShift UCTM E-SBC session border control appliance heavily tuned to serve the demanding security and interoperability requirements for enterprise VOIP/UC deployments. ??With the growing SIP Trunk deployments, RedShift UCTM E-SBC appliance provides unparalleled levels of security, control and visibility for today’s demanding Enterprise UC &amp; Collaboration networks – far exceeding security on any other E-SBC available in the planet today.</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.redshiftnetworks.com/2011/05/25/lead-story-of-the-month%e2%80%a8%e2%80%a8/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Redshift Networks is a Finalist for the 2011 Red Herring Top 100 North America Award</title>
		<link>http://blog.redshiftnetworks.com/2011/05/25/redshift-networks-is-a-finalist-for-the-2011-red-herring-top-100-north-america-award/</link>
		<comments>http://blog.redshiftnetworks.com/2011/05/25/redshift-networks-is-a-finalist-for-the-2011-red-herring-top-100-north-america-award/#comments</comments>
		<pubDate>Wed, 25 May 2011 12:27:47 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Redshift Networks]]></category>

		<guid isPermaLink="false">http://blog.redshiftnetworks.com/?p=76</guid>
		<description><![CDATA[Redshift Networks announced today it has been selected as a Finalist for Red Herring&#8217;s Top 100 North America award, a prestigious list honoring the year’s most promising private technology ventures from the North American business region.
The Red Herring editorial team selected the most innovative companies from a pool of hundreds from across North America. The [...]]]></description>
			<content:encoded><![CDATA[<p><strong><img class="alignright size-full wp-image-77" title="RHNA-Finalist-Logo-180" src="http://blog.redshiftnetworks.com/wp-content/uploads/2011/05/RHNA-Finalist-Logo-180.jpg" alt="" width="180" height="180" />Redshift Networks</strong> announced today it has been selected as a <a href="http://www.herring100.com/RHNA/2011/finalists.html">Finalist</a> for Red Herring&#8217;s Top 100 North America award, a prestigious list honoring the year’s most promising private technology ventures from the North American business region.</p>
<p>The Red Herring editorial team selected the most innovative companies from a pool of hundreds from across North America. The nominees are evaluated on both quantitative and qualitative criteria, such as financial performance, technology innovation, quality of management, execution of strategy, and integration into their respective industries.</p>
<p>This unique assessment of potential is complemented by a review of the actual track record and standing of a company, which allows Red Herring to see past the “buzz” and make the list an valuable instrument for discovering and advocating the greatest business opportunities in the industry.</p>
<p>&#8220;This year was very rewarding,&#8221; said Alex Vieux, publisher and CEO of Red Herring. &#8220;The global economic situation has abated and there are many great companies producing really innovative and amazing products. We had a very difficult time narrowing the pool and selecting the finalists. <strong>Redshift Networks</strong> shows great promise therefore deserves to be among the Finalists. Now we’re faced with the difficult task of selecting the Top 100 winners of Red Herring North America. We know that the 2011 crop will grow into some amazing companies that are sure to make an impact.&#8221;</p>
<p><a href="http://www.herring100.com/RHNA/2011/finalists.html">Finalists</a> for the 2011 edition of the Red Herring 100 North America award are selected based upon their technological innovation, management strength, market size, investor record, customer acquisition, and financial health. During the several months leading up to the announcement, hundreds of companies in the telecommunications, security, Web 2.0, software, hardware, biotech, mobile and other industries completed their submissions to qualify for the award.</p>
<p>The Finalists are invited to present their winning strategies at the Red Herring North America Forum in Hollywood, California, June 13-15, 2011. The Top 100 winners will be announced at a special awards ceremony the evening of June 15 at the event.</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.redshiftnetworks.com/2011/05/25/redshift-networks-is-a-finalist-for-the-2011-red-herring-top-100-north-america-award/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Use of Side channel attacks on High Frequency Trading networks to profit Millions of Dollars</title>
		<link>http://blog.redshiftnetworks.com/2011/01/11/use-of-side-channel-attacks-on-high-frequency-trading-networks-to-profit-millions-of-dollars/</link>
		<comments>http://blog.redshiftnetworks.com/2011/01/11/use-of-side-channel-attacks-on-high-frequency-trading-networks-to-profit-millions-of-dollars/#comments</comments>
		<pubDate>Tue, 11 Jan 2011 22:34:37 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://blog.redshiftnetworks.com/2011/01/11/use-of-side-channel-attacks-on-high-frequency-trading-networks-to-profit-millions-of-dollars/</guid>
		<description><![CDATA[High frequency trading networks which complete stock transactions in micro seconds can be vulnerable to manipulation by the hackers for unfair advantage. By inserting small amounts of nuisance packets and thereby latencies to the otherwise good traffic can subtly alter the course of the trading decisions resulting in pocketing millions of dollars in a matter [...]]]></description>
			<content:encoded><![CDATA[<p>High frequency trading networks which complete stock transactions in micro seconds can be vulnerable to manipulation by the hackers for unfair advantage. By inserting small amounts of nuisance packets and thereby latencies to the otherwise good traffic can subtly alter the course of the trading decisions resulting in pocketing millions of dollars in a matter of few seconds. A few extra milliseconds can enable trades to execute ahead of the competition, thereby increasing profits for the hackers.</p>
<p>With the growing adoption of VOIP technologies, ubiquitous connectivity, sophisticated online betting (and trading) algorithms, a sub micro second delay can result in enough perturbations to cause severe losses!!</p>
<p>The scary part is that there is no adequate security solution in the market today to adequately combat this threat. Traditional rate based controls that Session Border Controllers (SBC) provide are good in detecting DOS attacks when there is a sudden upsurge in malicious traffic coming from a specific IP source. However, a side-channel attack is infinitely more subtle, as it adds just enough nuisance packets to a legitimate data stream to slow the data just enough to give someone else a chance to move first in the market. And these attacks can be simultaneously triggered from multiple random source locations making the detection even much harder. </p>
<p>What is need is pretty much a self-guided learning and mitigation system that automatically figures out such nuisance traffic in real time; no matter where it comes from, what packet granularity it may arrive in or at what rate it comes in; thwart it, blacklist the offending source locations while allowing legitimate business traffic to operate uninterrupted at mission critical latencies. This will be the true utopia security solution required to protect such high frequency trading networks against these attacks.  </p>
<p>Ref &#8212; http://www.infoworld.com/d/the-industry-standard/hackers-find-new-way-cheat-wall-street-everyones-peril-699?source=IFWNLE_nlt_daily_2011-01-06</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.redshiftnetworks.com/2011/01/11/use-of-side-channel-attacks-on-high-frequency-trading-networks-to-profit-millions-of-dollars/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Phone hacking on United Kingdom Members of Parliaments and on Royals</title>
		<link>http://blog.redshiftnetworks.com/2010/10/04/phone-hacking-on-united-kingdom-members-of-parliaments-and-on-royals/</link>
		<comments>http://blog.redshiftnetworks.com/2010/10/04/phone-hacking-on-united-kingdom-members-of-parliaments-and-on-royals/#comments</comments>
		<pubDate>Mon, 04 Oct 2010 08:56:46 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Recent Attack]]></category>

		<guid isPermaLink="false">http://blog.redshiftnetworks.com/?p=72</guid>
		<description><![CDATA[This past month the United Kingdom is in the midst of a scandal involving the local newspapers and the Members of Parliament in the country. Apparently several overzealous journalists authorized the hacking of the phones and voicemails of Members of Parliaments and of several Royals to collect ‘dirt’ on them. This has caused quite a [...]]]></description>
			<content:encoded><![CDATA[<p>This past month the United Kingdom is in the midst of a scandal involving the local newspapers and the Members of Parliament in the country. Apparently several overzealous journalists authorized the hacking of the phones and voicemails of Members of Parliaments and of several Royals to collect ‘dirt’ on them. This has caused quite a stir which has been exasperated as the current ‘Media Director’ of the Prime Minister’s office supposedly authorized or knew about these hackings while he was working for these newspapers. Here is the link that talks about <a href="http://www.independent.co.uk/news/uk/home-news/coulson-listened-to-hacked-phone-messages-2096806.html" target="_blank">this scandal</a>.</p>
<p>This has tremendous security implications. Suppose that they were not listening or looking for ‘dirt’ but listening to sensitive information related to National Security for the United Kingdom and their allies. This was carried out by a bunch of journalists who are amateurs in this ‘hacking’ environment. Supposed this was carried out more sophisticated elements of any government or any industrial espionage ring or even criminal or terrorist elements. Imagine the implications of this. All of this occurred because the phone and voicemail <a href="http://www.editel.at/de/products-services/edi">edi</a> the Unified Communications and Collaborations were not secured properly.</p>
<p>That’s why it is so vital to comprehensively secure these Voice and Video environments – Unified Communications &amp; Collaborations application and networks MUST be secure!!</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.redshiftnetworks.com/2010/10/04/phone-hacking-on-united-kingdom-members-of-parliaments-and-on-royals/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>VOIP/UC Network Botnet Scanning and Discovery based Attacks on the Rise</title>
		<link>http://blog.redshiftnetworks.com/2010/07/28/voipuc-network-botnet-scanning-and-discovery-based-attacks-on-the-rise/</link>
		<comments>http://blog.redshiftnetworks.com/2010/07/28/voipuc-network-botnet-scanning-and-discovery-based-attacks-on-the-rise/#comments</comments>
		<pubDate>Wed, 28 Jul 2010 08:11:20 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Redshift Networks]]></category>
		<category><![CDATA[Security Threats]]></category>
		<category><![CDATA[UC&C]]></category>

		<guid isPermaLink="false">http://blog.redshiftnetworks.com/?p=56</guid>
		<description><![CDATA[Rich Unified Communications and Collaboration (UC&#38;C) services are now being delivered across any device, any place and at any time. With the rise of new powerful fixed and mobile endpoint technologies such as the IPAD, the Android or IPhone smart phone,  customers are now embracing UC/VOIP services at a potential never possible before.  As a result, [...]]]></description>
			<content:encoded><![CDATA[<p>Rich Unified Communications and Collaboration (UC&amp;C) services are now being delivered across any device, any place and at any time. With the rise of new powerful fixed and mobile endpoint technologies such as the IPAD, the Android or IPhone smart phone,  customers are now embracing UC/VOIP services at a potential never possible before.  As a result, VOIP/UC networks are also becoming more porous as the network perimeter once confined and secured inside the DMZ perimeter is now extended across multiple untrusted domains, geographies, users and endpoints.  The traditional definition of security perimeter is now broken.</p>
<p>In this posting, we talk about VOIP/UC network Botnet scanning and discovery based attacks being on the rise. The specific attacks happened in one of the major VOIP provider and this makes it very interesting. The SIP provides OPTIONS methods that allow a User Agent (UA) to query another UA or a proxy server as to its capabilities. This allows a client to discover information about the supported methods, content types, extensions, codecs, etc. without &#8220;ringing&#8221; the other party. All UAs MUST support the OPTIONS method.</p>
<p>Unfortunately, this also provides base for attackers to probe the network and find out more details on the internal VOIP/UC network topology, endpoints, server IPs, valid usernames or extensions etc. The attacker studies the responses from methods such as SIP OPTIONS, REGISTER or INVITE methods to make some pretty good guesses on valid extensions, usernames or server IPs etc. This often is a precursor to more sophisticated attacks such as Toll Fraud attacks, eavesdropping, message stealing, stealth DOS attacks on specific user extensions, War Dialing and SPAM attacks.</p>
<p>The scary part is that there are lot of publicly available tools that can quickly brute force and automate the generation of such requests and provide a list of valid usernames, extensions, user credentials, server names, IPs etc. Preventing such attacks without employing a sophisticated UC stateful and protection device is very difficult. It is very hard to shield UC/VOIP services that by their very nature need to be exposed to a certain extent.</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.redshiftnetworks.com/2010/07/28/voipuc-network-botnet-scanning-and-discovery-based-attacks-on-the-rise/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Attacks are happening on our customers networks</title>
		<link>http://blog.redshiftnetworks.com/2010/07/24/attacks-are-happening-on-our-customers-networks/</link>
		<comments>http://blog.redshiftnetworks.com/2010/07/24/attacks-are-happening-on-our-customers-networks/#comments</comments>
		<pubDate>Sat, 24 Jul 2010 10:34:45 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Redshift Networks]]></category>
		<category><![CDATA[UC&C]]></category>

		<guid isPermaLink="false">http://blog.redshiftnetworks.com/?p=53</guid>
		<description><![CDATA[We’ve been working very hard building our business with our products getting installed in different networks across the globe. We have started to see from our current deployments that attacks are happening in the Unified Communications and Collaboration realm. There is already a lot of news in the press and on the web about these [...]]]></description>
			<content:encoded><![CDATA[<p>We’ve been working very hard building our business with our products getting installed in different networks across the globe. We have started to see from our current deployments that attacks are happening in the Unified Communications and Collaboration realm. There is already a lot of news in the press and on the web about these attacks. We’re seeing our customers get attacked!!</p>
<p>Unfortunately enterprises and carriers that have Unified Communication &amp; Collaboration solutions and applications can’t detect these attacks; The current generation of security solutions are not adequate enough to provide protection or trace these new security threats. <span id="more-53"></span><br />
We saw a major VOIP provider get attacked from outside the US. This attack was an attempt to penetrate the core Unified Communication &amp; Collaboration Servers, which would allow them to get access to the VOIP provider customer internal network and topology. VOIP providers have both enterprise and residential customers <a href="http://www.editel.at/de/products-services/edi">edi</a>. The hackers were trying to get to their customers. The customers have rich information they can access and steal. The hackers are also using software that is readily available on the internet to generate these attacks which is even worse!!</p>
<p>What’s interesting here is that these kinds of attacks are happening all the time. If only people know that it’s actually happening it would be very helpful. Enterprises need to protect themselves and can’t be caught flat-footed. Don’t allow yourself to suffer the consequences of such attacks. There are several such security threats in the UC/VOIP realm that can shut down your business!! Pls. visit <a href="http://www.redshiftnetworks.com/" target="_blank">www.redshiftnetworks.com</a> to learn more about them.</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.redshiftnetworks.com/2010/07/24/attacks-are-happening-on-our-customers-networks/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Google your Unified Communications &amp; Collaborations (UC&amp;C) Infrastructure</title>
		<link>http://blog.redshiftnetworks.com/2010/05/27/google-your-unified-communications-collaborations-ucc-infrastructure/</link>
		<comments>http://blog.redshiftnetworks.com/2010/05/27/google-your-unified-communications-collaborations-ucc-infrastructure/#comments</comments>
		<pubDate>Thu, 27 May 2010 08:01:14 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Redshift Networks]]></category>
		<category><![CDATA[Security Threats]]></category>

		<guid isPermaLink="false">http://blog.redshiftnetworks.com/?p=11</guid>
		<description><![CDATA[It’s surprising and often easy to note how widespread and far reaching internet is today. Long time ago, Johnny Long documented on internet how one can use Google searches effectively to search for relevant and confidential information over the internet.
There’s a lot of information around the network around this topic; surprisingly one using very simple [...]]]></description>
			<content:encoded><![CDATA[<p>It’s surprising and often easy to note how widespread and far reaching internet is today. Long time ago, <a href="http://www.hackersforcharity.org/" target="_blank">Johnny Long</a> documented on internet how one can use Google searches effectively to search for relevant and confidential information over the internet.</p>
<p>There’s a lot of information around the network around this topic; surprisingly one using very simple scanning and discovery tools can find lot of information about companies that otherwise should never be disclosed. Most often, this is due to poor security controls being placed on information disclosure.</p>
<blockquote><p>Do you know what information is available on the internet about your UC&amp;C Infrastructure? Do you know if anybody can reconfigure your telephone from internet?</p></blockquote>
<p>So, I started googling the web in search for specific information about <a href="http://www.editel.at/de/products-services/edi">edi</a> UC&amp;C infrastructures using some standard keywords as listed below. The results are very alarming and show that several UC&amp;C internal networks and systems are publicly visible on the internet with very little security controls. Typical results ranged from absolutely no security enforcements being placed to limited security that uses default vendor published passwords that are easy for anyone to guess.<span id="more-11"></span></p>
<h4><strong>Here are few such examples:</strong></h4>
<p><strong>(I) Information Disclosure on a Cisco Unified Call Manager on a public IP.</strong></p>
<p><img class="aligncenter size-full wp-image-20" title="img-1" src="http://blog.redshiftnetworks.com/wp-content/uploads/2010/05/img-1.jpg" alt="img-1" width="620" height="519" /></p>
<p><strong>(II) Information Disclosure on Cisco UC&amp;C Devices available from VOIP Scanning</strong></p>
<p><img class="aligncenter size-full wp-image-21" title="img-2" src="http://blog.redshiftnetworks.com/wp-content/uploads/2010/05/img-2.jpg" alt="img-2" width="620" height="373" /></p>
<p><strong>(III) Information disclosure on Sipura SPA SIP Configuration</strong></p>
<p><img class="aligncenter size-full wp-image-22" title="img-3" src="http://blog.redshiftnetworks.com/wp-content/uploads/2010/05/img-3.jpg" alt="img-3" width="620" height="374" /></p>
<p><strong>(IV) Information Disclosure on Grandstream Device Configuration</strong></p>
<p><img class="aligncenter size-full wp-image-23" title="img-4" src="http://blog.redshiftnetworks.com/wp-content/uploads/2010/05/img-4.jpg" alt="img-4" width="620" height="371" /></p>
<p><strong>(V) Information Disclosure on Polycom Sound IP Configuration Utility</strong></p>
<p><img class="aligncenter size-full wp-image-24" title="img-5" src="http://blog.redshiftnetworks.com/wp-content/uploads/2010/05/img-5.jpg" alt="img-5" width="620" height="373" /></p>
<p>These are just few such examples of Information Disclosure on UC&amp;C networks and server configurations that can be available from the internet. Most often, Information disclosure and discovery based attacks the pre-cursors to more target and sophisticated attacks such as Toll Frauds, DOS, Service Abuse or stealing etc. The few examples in this document provide one of the several threat categories that can affect your UC&amp;C networks and systems — “Information Disclosure” category.</p>
<p>It is therefore important to establish a right security posture, methodologies and protection to your core UC&amp;C network, assets and systems.</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.redshiftnetworks.com/2010/05/27/google-your-unified-communications-collaborations-ucc-infrastructure/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>About this blog</title>
		<link>http://blog.redshiftnetworks.com/2010/05/26/about-this-blog/</link>
		<comments>http://blog.redshiftnetworks.com/2010/05/26/about-this-blog/#comments</comments>
		<pubDate>Wed, 26 May 2010 07:48:20 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Redshift Networks]]></category>

		<guid isPermaLink="false">http://blog.redshiftnetworks.com/?p=46</guid>
		<description><![CDATA[My name is Amitava  Mukherjee and I am the CEO of RedShift Networks. We are a company based  in Silicon Valley, California, with offices around the world.
This blog is meant to address the growing concern of security threats  and attacks around Unified Communications, Collaboration and  video/voice web-based applications.
Unified Communications &#38; Collaboration [...]]]></description>
			<content:encoded><![CDATA[<p><img class="alignright" title="amitava-mukherjee" src="http://blog.redshiftnetworks.com/wp-content/uploads/2010/03/amitava-mukherjee.jpg" alt="amitava-mukherjee" width="150" height="230" />My name is Amitava  Mukherjee and I am the CEO of RedShift Networks. We are a company based  in Silicon Valley, California, with offices around the world.</p>
<p>This blog is meant to address the growing concern of security threats  and attacks around Unified Communications, Collaboration and  video/voice web-based applications.<span id="more-46"></span></p>
<p>Unified Communications &amp; Collaboration applications are growing  at a feverish pace with global companies like Cisco, Microsoft, IBM,  Avaya, Polycom and many others, in the networking, application and  communications space targeting the market. Enterprises, large, medium  and small, are all embracing the power of this new interconnected world  where voice, data and video networks are merged, and the traditional  definition of enterprises and trusted silos are broken down daily.<br />
With the daily advent of new fixed and mobile endpoint technologies,  like the IPAD, the Android or IPhone smartphone, and cloud based  networks and systems, to interconnect enterprises with their customers,  with their partners and their own employees, the need to protect these  networks from the on slaughter of attacks, threats and vulnerabilities  is critical.</p>
<p>The Unified Communications &amp; Collaboration realm is defined  around real-time communications like: VOIP, Video Conferencing, Unified  Messaging, Contact Center/Call Center applications, IVR &amp; ACD  systems, Presence, Collaboration, and a myriad of other communication  applications. Some analysts have estimated that this market will grow to  become a $35B market by 2013. Others have estimated a faster growth  pace especially as global enterprises aggressively move towards reducing  costs structures using these technologies to innovate and become more  productive.</p>
<blockquote><p>The security market around this technology is estimated  to grow feverishly alongside the growth of UC &amp; Collaborations  market. RedShift estimates that this market will become a $1.7B by 2013.</p></blockquote>
<p>We shall also be addressing the concerns around Voice/Video web-based  applications.</p>
<p>As we all know security is not only about threats, attacks and  vulnerabilities. Security is about setting the right policies inside the  enterprise and giving the network managers enough information and  visibility so that he/she can make an educated decision on how best to  run the enterprise.<br />
We believe that the current security model is flawed and has tremendous  amount of holes. We can see this by the increase of attacks in the last  couple of years &#8211; attacks have increased 50% year to year.  “Best-of-breed’ solutions have given way to open source based solutions  which we believe perpetuate the problem.<br />
We, at RedShift Networks, have invited a set of luminaries from the  global Information technology market to write about this general topic.</p>
<p>The goal of the blog is both to educated and exchange ideas.<br />
I invite you to read this blog.</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.redshiftnetworks.com/2010/05/26/about-this-blog/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

