Hackers could use VoIP phones to eavesdrop on you

Weak default passwords leave handsets vulnerable to attack

Hackers could listen in on you via your VoIP phone, security researchers have warned.

By using a simple exploit taking advantage of weak default passwords, attackers can hack your VoIP phone to make and receive calls, transfer calls without your knowledge and even spy on your in-person conversations.

Security expert Paul Moore discovered the flaw after consulting on the installation of several VoIP phones.

During the process, he noticed installers and IT professionals neglecting to change the default passwords, saying that they would do "for now".

Advertisement - Article continues below

"Of course, as soon as the device burst into life, it's on to the next one," he said. "At which point, 'now' becomes a distant memory, along with any thoughts of hardening the device for use in a commercial setting."

One major problem Moore highlighted was a lack of device-level authentication.

He noted that the equipment was from well-known and trusted industry names such as Cisco, Snom and Ubiquiti UniFi, but said that although these brands are often assumed to be secure when placed behind a firewall, this is not necessarily the case.

With the help of fellow security professionals Per Thorsheim and Scott Helme, he demonstrated how easy VoIP phones are to hack.

Moore reset a Snom 320 VoIP phone to its factory default settings, and the only thing the attacker needed to do in order to gain complete control of the device was to visit a site infected with a malicious payload.

Once infected, the hacker has complete control over the phone, allowing them to block incoming calls, silently call premium-rate numbers, and secretly listen in on a user's conversations.

Moore has called for manufacturers to take better care in securing their products before sending them out into the wild.

"Vendors," he said, "if you must supply devices with 'default' credentials, disable all other functionality until a suitably-secure password is set to replace it".

He also urged IT staff to be aware of the dangers posed by any internet-connected appliance.

"If you install, use or just find yourself sat next to one of these devices," he advised, "just remember... it's basically a PC, with all the security vulnerabilities associated with them."

Advertisement - Article continues below

"Don't assume it's safe because it's running as the manufacturer intended; seek professional advice."

Featured Resources

The IT Pro guide to Windows 10 migration

Everything you need to know for a successful transition

Download now

Managing security risk and compliance in a challenging landscape

How key technology partners grow with your organisation

Download now

Software-defined storage for dummies

Control storage costs, eliminate storage bottlenecks and solve storage management challenges

Download now

6 best practices for escaping ransomware

A complete guide to tackling ransomware attacks

Download now



Google confirms Android cameras can be hijacked to spy on you

20 Nov 2019

Most Popular

Microsoft Windows

This exploit could give users free Windows 7 updates beyond 2020

9 Dec 2019
Business strategy

Ex-Apple CPU architect accuses the firm of invading privacy

10 Dec 2019

Patch issued for critical Windows bug

11 Dec 2019
Microsoft Azure

Microsoft, not Amazon, is going to win the cloud wars

30 Nov 2019