Softpedia
 

NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
TRENDING TODAY
Home > News > Security > Security Blog

October 1st, 2012, 15:15 GMT · By

BLOG

Brute Force Attack Can Break PINs of Cisco CallManager Accounts, Researcher Finds

SHARE:

Adjust text size:


Researcher finds way to brute force PINs of accounts registered with Cisco's CallManager Enlarge picture - Researcher finds way to brute force PINs of accounts registered with Cisco's CallManager
While performing a review of Cisco’s Unified Communications Manager (CallManager) – a software-based call-processing system –, security researcher Roberto Suggi Liverani has identified a simple way to break the PINs of registered accounts by performing a brute force attack.

“When looking at the phone handset configuration, some URLs are set to allow the handset to retrieve Personal Address Book details or access the Fast Dials. That caught my attention and I immediately pointed my web proxy to those URLs, forgetting about the handset interface,” the expert explained.

The researcher noticed that the handset itself is actually performing simple GET HTTP requests to the CallManager to initiate the login sequence.

The response contains a “sid” token which is needed to perform the brute force attack. Then, a web proxy, such as Burp, can aid in performing this brute force attack.

The technical details for the attack are available here.

TELL US WHAT YOU THINK:

1,796 hits · 1 comment · Link to this article · Print article · Send to friend · Subscribe to news

MUST-READ RELATED ARTICLES:


Cybercriminals Hijack 4.5 Million ADLS Modems in Brazil to Serve Malware

Expert Finds XSS Flaw on eBay After Bypassing “Filtering Mechanisms”

Google Fixes over 40 Security Holes in Chrome 22, Large Rewards Handed Out

Oracle Confirms Sandbox Bypass Vulnerability in Java SE 5, 6 and 7

Researcher Finds Open Redirect Vulnerability in Facebook [Video]

READER COMMENTS:


Comment #1 by: anonymous on 03 Oct 2012, 18:08 UTC reply to this comment

So he brute forced a call manager with no lockout policy? How is that note worthy? Just turn on lockout policy. That's why it's there. http://www.cisco.com/en/US/docs/voice_ip_comm/cucm/admin/7_0_1/ccmcfg/b08crpol.html#wp1038402

Copyright © 2001-2013 Softpedia. Contact/Tip us at

WindowsGamesDriversMacLinuxScriptsMobileHandheldNews

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   UPDATE YOUR SOFTWARE   |   ROMANIAN FORUM