Welcome to The Professional Security Testers Warehouse for the GPEN GSEC GCIH GREM CEH QISP Q/ISP OPST CPTS
Search
Nickname Password Security Code Security Code Type Security Code  
Penetration Testing the way it was meant to be
You are certified but are your qualified?  Become qualified today.

Video Library

Skimming for ID theft
5 / 2
Views: 179
Comments: 1
11-01-2008 00:18

Latest version of ATM skimmer hidden behind a speaker looking device
5 / 2
Views: 193
Comments: 0
11-01-2008 00:11

ATM Scam, do check your ATM machine before using it
5 / 1
Views: 180
Comments: 1
10-31-2008 23:59

Survey

Whic of the following certifications would you like to get?

GPEN
GCIH
CEH
QEH
GREM
GSEC
CISSP
Security+
Other (please leave a comment)



Results
Polls

Votes: 217
Comments: 0

Who's Online

There are currently, 101 guest(s) and 0 member(s) that are online.

You are Anonymous user. You can register for free by clicking here

UCSniff 3.0 Released
Posted on Wednesday, 11 November 2009 @ 17:22:45 EST
Contributed by cdupuis | Topic: VOIP

NOTE FROM CLEMENT:   Here is a posting from the Pen-Test mailing list on SecurityFocus.  Joshua Wright is commenting about the new UCSniff release.  Joshua is not easy to impress, he knows his stuff and his endorsement does speak for the quality and usability of this new version of UCSniff.  Here is the posting:

---------- Forwarded message ----------
From: Joshua Wright
Date: Tue, Nov 3, 2009 at 09:22
Subject: Re: UCSniff 3.0 Released
To: Arjun Sambamoorthy
Cc: pen-test@securityfocus.com

> Sipera VIPER Labs has released UCSniff 3.0:
> http://ucsniff.sourceforge.net.
>
> Here are some of the key features of the new version:
>
>  * Real time VoIP and Video monitoring. [ as presented at ToorCon 11, San Diego]
>  * New codec support, G729, G726, G723.
>  * GUI version of Windows and Linux. [ as presented at DefCon 17]
>  * TFTP MitM Modification of IP phone settings.
>  * New VideoSnarf tool - Converts offline RTP pcap file to media file.
>  * Windows VLAN implementation, for VLAN Hopping in Windows.

As a personal anecdote, I saw Arjun and Jason present the latest developments in UCSniff at ToorCon 11 and was awed at how smoothly the features worked, and the power of the video manipulation features.

Jason and Arjun's demo used a Cisco IPTV camera for video surveillance, watching a bottle of water.  First, they established MitM (I believe through ARP spoofing) and saved a segment of the existing video traffic.
 Then, they blocked the actual stream from the camera to the receiver and fed the receiver the old video footage instead, causing a momentary blip on the video monitoring side.  Then, they stole the bottle of
water, while the video monitoring system happily replayed the old footage.

It reminded me of the A-Team episode where Murdoch climbed into the ceiling and lifted a ceiling tile from above, then used a Polaroid camera to take an instant picture of the room from the perspective of a
ceiling-mounted camera.  Then, he taped the photo to the front of the camera so the security guards saw the same view while the rest of the team went through the room undetected.  Well, except that Arjun and
Jason's work was much cooler (and a lot less Polaroid-hurry-up-and-develop-waving-action).

Congrats to Jason and Arjun for their awesome work, this is a tool I'm looking forward to using in upcoming customer engagements.


- -Josh

Login

Nickname

Password

Security Code:
Security Code
Type Security Code

Don't have an account yet? You can create one. As a registered user you have some advantages like theme manager, comments configuration and post comments with your name.

Related Links

Article Rating

Average Score: 0
Votes: 0

Please take a second and vote for this article:

Excellent
Very Good
Good
Regular
Bad

Options

"UCSniff 3.0 Released" | Login/Create an Account | 0 comments
The comments are owned by the poster. We aren't responsible for their content.

No Comments Allowed for Anonymous, please register

You can syndicate our news using the file backend.php or ultramode.txt


All logos and trademarks in this site are property of their respective owner. The comments are property of their posters, all the rest © 2003-2008 by Clement Dupuis and Nathalie Lambert (Site Maintainers).

 


 

 


Page Generation: 0.17 Seconds