Sign up
 Vonage  

       
 
Vonage Forum Menu

Vonage Forums
Vonage VoIP Forum
tplink Posted:
Im trying to add
my HT802 vonage
adapter to my home
network. I
currently have
...

In The Forum:
Hard Wiring - Installation
Topic:
Vonage behind switch
On Dec 05, 2016 at 06:35:11

DWSupport Posted:
After recent
Vonage update that
took place on the
4th and 5th of
Nov. E-mails with
...

In The Forum:
Vonage
Topic:
Voicemail Not Forwarding to Outlook Accounts
On Nov 10, 2016 at 12:23:26

peterlee Posted:
Had a call from a
Hospital in Ajax,
Ontario to my home
in
Scarborough, Onta
rio
...

In The Forum:
Vonage Canada
Topic:
Hospital Incoming call unable to connect
On Nov 08, 2016 at 11:59:50

TELLDOUG Posted:
I am looking for a
product that will
make my phone ring
louder so I can
hear using
...

In The Forum:
Vonage
Topic:
Looking for a ringer ameliorate
On Oct 26, 2016 at 09:21:30

HildBeft Posted:
You can recollect
password by
connecting the
router to your pc
and open the
browser
...

In The Forum:
Hard Wiring - Installation
Topic:
How to arrive at wifi password?
On Oct 20, 2016 at 05:05:49

HildBeft Posted:
Great tips..
Thanks for sharing
...

In The Forum:
Hard Wiring - Installation
Topic:
How to have Vonage and another land line?
On Oct 20, 2016 at 04:55:03

massrman Posted:
The devices are
available at
different price
margins , please
share your
estimated
...

In The Forum:
Vonage
Topic:
IP PBX for small business
On Sep 30, 2016 at 00:48:03

massrman Posted:
Hi these are most
commonly used SIP
PBX interops and
their
configuration
guides,
...

In The Forum:
Vonage
Topic:
IP PBX for small business
On Sep 30, 2016 at 00:37:45

Sammy00 Posted:
Has anyone setup a
W52p phone for
vonage? I have
a W52p with two
wireless handsets,
...

In The Forum:
Hard Wiring - Installation
Topic:
W52p Setup
On Aug 30, 2016 at 10:38:01

James44 Posted:
Hi, I am
looking for a good
Sip Trunking
provider in
Canada. they
should offer
...

In The Forum:
Vonage
Topic:
A good sip trunking provider
On Jul 17, 2016 at 23:42:46


Vonage VoIP Forums

Vonage In The News
Vonage Holdings Corp. Reports Fourth Quarter and Full Year 2013 Results

Carolyn Katz Elected to Board of Directors of Vonage Holdings Corp.

Syndication

Vonage Customer Reviews
Vonage vs. Time Warner Cable SoCal
Vonage vs. Time Warner Cable SoCal



Vonage UK Review
Vonage UK Review



Vonage Pros and Cons for 2006
Vonage Pros and Cons for 2006



Vonage, a VT2142 and a RTP300, My Experiences - A Detailed Review
Vonage, a VT2142 and a RTP300, My Experiences - A Detailed Review



Salt Lake City: impressions after several months
Salt Lake City: impressions after several months




Vonage Reviews

Vonage What is a customer's risk? The highest risk comes to businesses who would





What is a customer's risk?

The highest risk comes to businesses who would be impacted by loss of incoming calls. An ordinary user on an unlimited plan may never notice that someone was placing outgoing calls unless they made international calls. Since calls to toll numbers (900, 976) aren't generally possible on Vonage systems the biggest threat is eliminated. 500 minute plan customers may be impacted if they and the hacker combined used more than 500 minutes.

So, in summation, the risk to the user is loss of incoming calls for the period the hacker's router is active, and the cost of toll calls (international calls) and the cost of calls above the 500 minute limit for limited plan users.

Phone impersonation

Another risk may come from someone who is attempting to impersonate you by using your phone. For example, if they stole a credit card from your mailbox but needed your phone to activate it, they could use this technique to place the call. This type of phone impersonation is more insidious than simple caller id spoofing because it would also provide the correct ANI information (used by toll free numbers to identify callers for example). However, the actual usefulness of this is limited. It is very simple to spoof calls to have your caller id through other mechanisms, so the need for this attack is extremely limited.

How could you be vulnerable?

A hacker could randomly attempt to spoof MAC addresses. It is likely that many of the Vonage addresses are in series so knowing a single MAC address would allow a hacker to simply add 1 to the number until he found an active line. Alternatively the hacker could go to the store and record numbers from packages and wait until the routers were activated. Finally, if the hacker knew your MAC address, which may be possible if he has access to your network, he could specifically target you.

Could this be fixed?

Linksys/Vonage could resolve this issue with a specific firmware upgrade. The could prevent the user from altering the MAC address sent by the router. A better solution would be to allow the user to specify a pass phrase (your Vonage account password perhaps) that was sent encrypted to the Vonage servers when your router attempted to download the configuration. This would prevent third parties without access to the pass phrase from cloning your device.

They could also allow you to lock your configuration file. Specifying that only updates could be received unless you permitted a one time download via the web site or a call to customer service. This would be required in the event of a factory reset for example.

What action can you take to protect yourself?

If you are a new user you could avoid this equipment. The news summary did not indicate the Motorola equipment was also vulnerable.

If you are an existing user with this equipment you could replace the equipment at your own cost. I seriously doubt either Vonage or Linksys would reimburse you. You could, I think, change the MAC address the device uses on your local network. I believe the Linksys devices allow you to spoof MAC addresses to fool cable modems. This spoofed MAC address is probably not used for your Vonage configuration. Therefore the MAC address visible on your LAN would be different than the one sent to Vonage. The one sent to Vonage could still be captured, but it would be harder. To make this effective you would want to use a real MAC address from a different Linksys router that was not on your network. This would still leave you open to a random attack, but less open to a targeted attack.

In my opinion this issue is not serious enough to warrant a consumer response in the majority of cases. It is a security flaw that Vonage should be concerned about. However, it is important to realize that credit card companies expect a certain level of identity theft, this is a detriment to credit card users who are affected by credit card theft. I would expect Vonage and Linksys to ignore this issue and simply expect a minimal level of fraud.



Read The Full Thread:

VoIP hijacking possibility


Partial excerpt from ABC news:
ahmagad... so Scary... wat can a custOmer do on their part? NADA? :( i
We've touched on the questionable choice Vonage/Linksys (actually Sipura/Motorola
Here is the abstract of Arias Hung's talk: http://www.defcon.org/html/defcon-14/dc-14-speakers.ht
Other than the fact that this was talked about at Defcon, this really isn't news.
Ethereal and Cain require you to have access to the target's network. Ethereal
I was hoping to discuss this matter without posting a virtual "how-to-guide"
Therefore, the basic questions remain. If I have one of these Linksys devices
No need to alter the MAC, far more useful (if not as immediate) to get the config

scerruti posted "What is a customer's risk? The highest risk comes to businesses who would" on 08/06/2006

Vonage Service Plans


Vonage VoIP Members
Members List Members
New Timbip
New Today 2
Yesterday 3
Total 99049

Who Is On Site
Visitors 121
Members 0
Total 121


Vonage VoIP Forum Members:
Login Here
Not a Member? You can Register Here
As a registered member you will have access to the VoIP Speed Test, Vonage Service Announcements and post comments in the
Vonage VoIP Forums

Vonage Stock Price
Value: 6.84
Change:   N/A
Up to 15 Minute Delay

Site Search
 






†AK and HI residents pay $29.95 shipping. ††Limited time offer. Valid for residents of the United States (&DC), 18 years or older, who open new accounts. Offer good while supplies last and only on new account activations. One kit per account/household. Offer cannot be combined with any other discounts, promotions or plans and is not applicable to past purchases. Good while supplies last. Allow up to 2 weeks for shipping. Other restrictions may apply.

1Unlimited calling and other services for all residential plans are based on normal residential, personal, non-commercial use. A combination of factors is used to determine abnormal use, including but not limited to: the number of unique numbers called, calls forwarded, minutes used and other factors. Subject to our Reasonable Use Policy and Terms of Service.

2Shipping and activation fees waived with 1-year agreement. An Early Termination Fee (with periodic pro-rated reductions) applies if service is terminated before the end of the first 12 months. Additional restrictions may apply. See Terms of Service for details.

HIGH SPEED INTERNET REQUIRED. †VALID FOR NEW LINES ONLY. RATES EXCLUDE INTERNET SERVICE, SURCHARGES, FEES AND TAXES. DEVICE MAY BE REFURBISHED. If you subscribe to plans with monthly minutes allotments, all call minutes placed from both from your home and registered ExtensionsTM phones will count toward your monthly minutes allotment. ExtensionsTM calls made from mobiles use airtime and may incur surcharges, depending on your mobile plan. Alarms, TTY and other systems may not be compatible. Vonage 911 service operates differently than traditional 911. See www.vonage.com/911 for details.

** Certain call types excluded.

www.vonage-forum.com is not an official Vonage support website & is independently operated.
All logos and trademarks are property of their respective owners. All comments are property of their posters.
All other www.vonage-forum.com content is © Copyright 2002 - 2013 by 4Sight Media LLC.

Thinking of signing up for Vonage but have questions?
Business and Residential customers can call Toll Free 24 hours a day at: 1-888-692-8074
No Vonage Promotion Code or Coupon Codes are required at www.vonage.com to receive any special,
best Vonage cheap deals, free sign up offers or discounts.

[ | | | | | ]

Vonage Forum Site Maps

Vonage | VoIP Forum | How VoIP Works | Wiring and Installation Page Two | International Rate Plans 2 | Internet Phone
Promotion | Vonage Review | VoIP | Broadband Phone | Free Month | Rebate | Vonnage | Vontage | VoIP | Phone Service
Phone | llamadas ilimitadas a Mexico | Latest News | VoIP Acronyms | Deal | Philippines Globe Phone | Site Maps

The Vonage Forum provides the Vonage sign up Best Offer Promotion Deal.
If you are considering signing up for Vonage and have found our Vonage News, Customer Reviews, Forums
& all other parts of this site useful, please use our Vonage Sign up page.


Vonage VoIP Phone Service is redefining communications by offering consumers
& small business VoIP Internet phones, an affordable alternative to traditional phone service.
The Vonage VoIP Forum Generated This Page In: 0.65 Seconds and 378 Pages In The Last 60 Seconds
The Vonage VoIP Forum