This paper focuses on the security of videoconferencing endpoints made by Polycom Corporation. The paper begins by discussing the recent growth in videoconferencing and introducing the International Telecommunication Union (ITU) system of videoconferencing standards. Videoconferencing components are briefly reviewed, including H.323 Terminals, MCUs, and Gatekeepers. The paper then provides an overview of the videoconferencing endpoints offered by Polycom, and reviews some motivations for attacking videoconferencing endpoints. A number of vulnerabilities and related security measures are discussed, including: theft of endpoints, eavesdropping on videoconferencing calls, administrative security, ISDN and perimeter security, SNMP access threats, FTP access threats, and denial of service attacks. The paper describes how vulnerability scanners can misreport videoconferencing endpoints as Trojan horse programs and concludes with a checklist for Polycom endpoint security.
Read Entire Paper
E-Mail Link
Your IP address will be sent with this e-mail