19.04.2013 Views

2KKUU7ita

2KKUU7ita

2KKUU7ita

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Figure 13-16:<br />

Using Cain<br />

& Abel to<br />

capture,<br />

record, and<br />

playback<br />

VoIP conversations.<br />

Chapter 13: Communication and Messaging Systems<br />

Here’s the interesting part — the conversations are saved in .wav audio<br />

file format, so you simply right-click the recorded conversation you want<br />

to test and choose Play, as shown in Figure 13-16. Note that conversations<br />

being recorded show Recording . . . in the Status column.<br />

The voice quality with Cain and other tools depends on the codec your VoIP<br />

devices use. With my equipment, I find the quality is marginal at best. That’s<br />

not really a big deal, though, because your goal is to prove there’s a vulnerability<br />

— not to listen in on other people’s conversations.<br />

There’s also a Linux-based tool called vomit (http://vomit.xtdnet.nl) —<br />

short for voice over misconfigured Internet telephones — that you can use<br />

to convert VoIP conversations into .wav files. You first need to capture the<br />

actual conversation by using tcpdump, but if Linux is your preference, this<br />

solution offers basically the same results as Cain, outlined in the preceding<br />

steps.<br />

If you’re going to work a lot with VoIP, I highly recommend you invest in a<br />

good VoIP network analyzer. Check out WildPackets’ OmniPeek — a great allin-one<br />

wired and wireless analyzer (www.wildpackets.com/products/<br />

omnipeek_network_analyzer/) — and TamoSoft’s CommView (www.<br />

tamos.com/products/commview/), which is a great low-priced alternative.<br />

These VoIP vulnerabilities are only the tip of the iceberg. New systems, software,<br />

and related protocols continue to emerge, so it pays to remain vigilant,<br />

helping to ensure your conversations are locked down from those with malicious<br />

intent.<br />

275

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!