RE: VOIP: RTP vs SRTP

From: Robb Stacy (robb@stacy.org)
Date: Fri Mar 10 2006 - 15:39:21 EST


This is a subject you might try the VoIPSA group for. The whole focus there
is VoIP security. Some smart folks there.
-R

-----Original Message-----
From: Chris Serafin [mailto:chris@chrisserafin.com]
Sent: Friday, March 10, 2006 11:55 AM
To: defragz@hotmail.com; pen-test@securityfocus.com
Subject: RE: VOIP: RTP vs SRTP

I have been thinking of writing a paper about a VoIP security also. I my
experience [solely Cisco voip] there is absolutely no security in place for
any VoIP.

Chris Serafin
IT Security / VoIP Engineer
chris@chrisserafin.com

-----Original Message-----
From: defragz@hotmail.com [mailto:defragz@hotmail.com]
Sent: Friday, March 10, 2006 2:23 AM
To: pen-test@securityfocus.com
Subject: VOIP: RTP vs SRTP

Hello list,

Planning some internal presentations on VoIP, I was wondering if SRTP
(Secure Real Time Protocol) is now really in use, as a secure replacement of
RTP.

More generally, from your experience, and from what you have seen in "real
life", do you thing that VoIP security is getting better? Do people use
crypto to protect both data and signalling?
I will love to hear your feedbacks...
-Franck

----------------------------------------------------------------------------

--
This List Sponsored by: Cenzic
Concerned about Web Application Security? 
As attacks through web applications continue to rise, you need to
proactively 
protect your applications from hackers. Cenzic has the most comprehensive 
solutions to meet your application security penetration testing and 
vulnerability management needs. You have an option to go with a managed 
service (Cenzic ClickToSecure) or an enterprise software (Cenzic Hailstorm).
Download FREE whitepaper on how a managed service can help you: 
http://www.cenzic.com/news_events/wpappsec.php 
And, now for a limited time we can do a FREE audit for you to confirm your 
results from other product. Contact us at request@cenzic.com
----------------------------------------------------------------------------
--
----------------------------------------------------------------------------
--
This List Sponsored by: Cenzic
Concerned about Web Application Security? 
As attacks through web applications continue to rise, you need to
proactively 
protect your applications from hackers. Cenzic has the most comprehensive 
solutions to meet your application security penetration testing and 
vulnerability management needs. You have an option to go with a managed 
service (Cenzic ClickToSecure) or an enterprise software (Cenzic Hailstorm).
Download FREE whitepaper on how a managed service can help you: 
http://www.cenzic.com/news_events/wpappsec.php 
And, now for a limited time we can do a FREE audit for you to confirm your 
results from other product. Contact us at request@cenzic.com
----------------------------------------------------------------------------
--
------------------------------------------------------------------------------
This List Sponsored by: Cenzic
Concerned about Web Application Security? 
As attacks through web applications continue to rise, you need to proactively 
protect your applications from hackers. Cenzic has the most comprehensive 
solutions to meet your application security penetration testing and 
vulnerability management needs. You have an option to go with a managed 
service (Cenzic ClickToSecure) or an enterprise software (Cenzic Hailstorm). 
Download FREE whitepaper on how a managed service can help you: 
http://www.cenzic.com/news_events/wpappsec.php 
And, now for a limited time we can do a FREE audit for you to confirm your 
results from other product. Contact us at request@cenzic.com
------------------------------------------------------------------------------


This archive was generated by hypermail 2.1.7 : Sat Apr 12 2008 - 10:55:40 EDT