Sign up
 Vonage  

       
 
Vonage Forum Menu

Vonage Forums
Vonage VoIP Forum
sssscary Posted:
Hi, I realize this
post is old, but I
was just trying to
find out how to
auto delete
...

In The Forum:
VoIP Feature Wish List
Topic:
Auto-Delete Voicemail When Forwarded to Email!!
On May 24, 2012 at 08:08:15

sandyj Posted:
The last few days
I've gotten a
couple of calls
from angry people
demanding that
...

In The Forum:
Vonage
Topic:
Someone is using my phone number? Hacked?
On May 18, 2012 at 20:07:46

vrtlassit7 Posted:
Can anyone help me
figure out a
solution to create
a virtual
attendant? I own
a small
...

In The Forum:
VoIP Feature Wish List
Topic:
Virtual Attendant
On May 18, 2012 at 07:53:07

rodisport Posted:
I have had this
problem for more
than 4 months now
when i call some
one it doesn't
...

In The Forum:
Vonage UK
Topic:
no ringing tone
On May 14, 2012 at 18:17:44

js123 Posted:
we already have
vonage device how
can i reactivate
the service and
what is the
procedure.
...

In The Forum:
Vonage
Topic:
how to reactivate the service
On May 12, 2012 at 14:57:39

dconnor Posted:
A photo would be
helpful.
...

In The Forum:
Hard Wiring - Installation
Topic:
Problem with home wireup
On May 08, 2012 at 10:47:17

rival Posted:
Thank you! This
was my exact
problem. Outgoing
calls would fail,
incoming calls
...

In The Forum:
Vonage
Topic:
Dial tone ok, incoming calls ok, no outgoing calls
On May 03, 2012 at 21:11:35

stevejone Posted:
This is really a
good topic.It
gives a quite
detailed
information about
the jammer
...

In The Forum:
Vonage UK
Topic:
Application of Cell Phone Jammer
On May 03, 2012 at 11:29:58

MiveAmige Posted:
The nature of a
cell phone jammer

By
mobile jammer
(jammer, cell ph
...

In The Forum:
Vonage UK
Topic:
Application of Cell Phone Jammer
On May 02, 2012 at 18:55:02

cotswold Posted:
I spoke to tech
support last night
and was promised a
call back in 10
minutes...the
...

In The Forum:
Vonage UK
Topic:
transfered calls to mobile come up as "unknown"
On May 02, 2012 at 03:35:55


Vonage VoIP Forums

Vonage In The News
Vonage Offers Free Calling to Latin American Destinations this Mother's Day Weekend

Vonage World® Now Includes Free Calling to Pakistan

Syndication

Vonage Customer Reviews
Appreciation
Appreciation



Vonage vs. Time Warner Cable SoCal
Vonage vs. Time Warner Cable SoCal



international connection
international connection



VDV21-VD adapter and Vonage service - a winner!
VDV21-VD adapter and Vonage service - a winner!



Should have signed up sooner!!!!
Should have signed up sooner!!!!




Vonage Reviews

Vonage Has anyone seen this? Can't find a response from Vonage. Should I be worried?



Has anyone seen this? Can't find a response from Vonage. Should I be worried?
8O
-
Original Advisory: Wednesday, August 13, 2003

Severity: Medium - High

Description: An attacker using the Voip (Voice Over IP) carrier Vonage,
has the ability to spoof the caller ID of a called party through the three-
way calling feature. This trick essentially acts similar to a POTS-based
diverter, as it allows the attacker to carry out illicit telephone
activities while hiding his or her phone number.

Version: This was tested using Cisco Systems' ATA 186 Voip hardware on the
Vonage carrier.

Author: Nathan Wosnack



Vonage Background:

"Using an existing high-speed Internet connection, Vonage technology
enables anyone to make and receive phone calls - worldwide - with a touch-
tone telephone. Offering quality phone service bundled with enhanced IP
communications services, our interactive communications portal is a
gateway to advanced features only available through digital telephone
service. Utilizing our global network and advanced routing technologies,
Vonage offers an innovative, feature-rich and cost effective alternative
to traditional telephony services."


Description of the problem:

By using SIP-enabled voice over IP (VOIP) hardware such as the Cisco ATA
186 Analog Telephone Adaptor, it's possible to spoof the caller
identification that shows up on a call. The attacker only needs to call up
a regular phone line (POTS - plain old telephone service), place the
caller on hold, flash over to a dial tone using the threeway call feature,
and then call a second party for this to work. The caller ID information
that tends to show up is the first called party's telephone number with
either their name listed or "unknown name" showing on a conventional
caller-id enabled telephone. The opportunity for abuse is high and could
allow the determined attacker to social engineer your telephone, cable, or
utility company into modifying your services. Since many companies only
require the person's name, address, and caller id for account
authentication, this vulnerability helps the attacker. The other
opportunities this vulnerability gives the attacker is the ability to
spoof anyone's caller id information for phone hacking (often
called "phreaking"); such as breaking into voice mail accounts and PBX
exploitation for the purpose of proprietary information gathering and
telephone fraud.


Solutions to the problem:

This issue is something that Vonage will need to investigate on their end.
The proper routing of caller id information after a third-party call is
initiated is the problem, and needs to be resolved by the Vonage IT staff
figuring out why their Voip switching equipment doesn't pass this data
properly. The Hypervivid Solutions staff has contacted Vonage directly
about this issue, so it can hopefully be resolved shortly.

For everyone else, your best defense is to be aware of who is calling you.
If you happen to receive a phone call from an unknown party who wants to
place you on hold, hang up immediately and then call them back.
If you hear a recording telling you the number is not in service, then
you've likely reached a Vonage gateway number, which mean you were likely
called by someone attempting to exploit this Vonage Voip vulnerability.


Conclusion:

In the past year, Voice over IP telephony has seen many security issues.
The Voip issues range from vendor implementations of the Session
Initiation Protocol (SIP), problems with remote-accessible code which can
be exploited to cause a denial of service, Voip phones that are weak in
ways that facilitate man-in-the-middle attacks directed at intercepting
telephone traffic, and most recently 3-way caller ID spoofing on Vonage.

When the information security community works closely with vendors and
carriers, these problems can be resolved quickly and efficiently enough to
limit or even eliminate any abuse by phone phreaks and criminals.


Related Links:


http://www.hypervivid.com/ - Information, Telecom and Wireless Security
Consulting Firm.


Vendor Contact:

http://www.cisco.com/ - Cisco Systems, Inc. Manufacturer.
http://www.vonage.com/ - American Voip telecom carrier.



Read The Full Thread:

Security Advisory


don't have the service but thought this was fixed in the next firmware upgrade
Go to www.covertcall.com/6133 this site offers caller id spoofing. check
The Caller Id spoofing was happening with Call Transfer (announcement). The
Yeah you can do this with camophone.com too. This is nothing new. Infact you can
I have personally used the service www.highvolumetraffic.com to spoof my caller

Robbo posted "Has anyone seen this? Can't find a response from Vonage. Should I be worried?" on 08/19/2003

Vonage Service Plans


Vonage VoIP Members
Members List Members
New JODI
New Today 3
Yesterday 5
Total 64287

Who Is On Site
Visitors 164
Members 0
Total 164


Vonage VoIP Forum Members:
Login Here
Not a Member? You can Register Here
As a registered member you will have access to the VoIP Speed Test, Vonage Service Announcements and post comments in the
Vonage VoIP Forums

Vonage Stock Price
Value: 1.70
Change:   -0.03
Up to 15 Minute Delay

Site Search
 




1Unlimited calling and other services for all residential plans are based on normal residential, personal, non-commercial use. A combination of factors is used to determine abnormal use, including but not limited to: the number of unique numbers called, calls forwarded, minutes used and other factors. Subject to our Reasonable Use Policy and Terms of Service.

2Shipping and activation fees waived with 1-year agreement. An Early Termination Fee (with periodic pro-rated reductions) applies if service is terminated before the end of the first 12 months. Additional restrictions may apply. See Terms of Service for details.

HIGH SPEED INTERNET REQUIRED. †VALID FOR NEW LINES ONLY. RATES EXCLUDE INTERNET SERVICE, SURCHARGES, FEES AND TAXES. DEVICE MAY BE REFURBISHED. If you subscribe to plans with monthly minutes allotments (for example, U.S. & Canada 300), all call minutes placed from both from your home and registered ExtensionsTM phones will count toward your monthly minutes allotment. ExtensionsTM calls made from mobiles use airtime and may incur surcharges, depending on your mobile plan. Alarms, TTY and other systems may not be compatible. Vonage 911 service operates differently than traditional 911. See www.vonage.com/911 for details.

** Certain call types excluded.

www.vonage-forum.com is not an official Vonage support website & is independently operated.
All logos and trademarks are property of their respective owners. All comments are property of their posters.
All other www.vonage-forum.com content is © Copyright 2002 - 2012 by 4Sight Media LLC.

Thinking of signing up for Vonage but have questions?
Business and Residential customers can call Toll Free 24 hours a day at: 1-888-692-8074
No Vonage Promotional Codes or Coupon Codes are required at www.vonage.com.

[ | | | | | ]

Vonage Forum Site Maps

Vonage | VoIP Forum | How VoIP Works | Wiring and Installation Page Two | International Rate Plans 2 | Internet Phone
Promotion | Vonage Review | VoIP | Broadband Phone | Free Month | VoIP | Phone Service | Rebate
Phone | Latest News | VoIP Acronyms | Vonnage | Vontage | Deal | Site Maps

The Vonage Forum provides the Vonage sign up Best Offer Promotion Deal as a means to offset our cost.
If you are considering signing up for Vonage and have found our Vonage News, Customer Reviews, Forums
& all other parts of this site useful, please use our Vonage FREE Month sign up offer Deal Coupon.


Vonage VoIP Phone Service is redefining communications by offering consumers
& small business VoIP Internet phones, an affordable alternative to traditional phone service.
The Vonage VoIP Forum Generated This Page In: 0.34 Seconds and 250 Pages In The Last 60 Seconds
The Vonage VoIP Forum