Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email firstname.lastname@example.org
Re: [Full-Disclosure] ASN.1 telephony critical infrastructure warning - VOIP
From: Florian Weimer (fwdeneb.enyo.de)
Date: Tue Feb 17 2004 - 15:32:10 CST
> ASN.1 is used by many services, but all use different underlying
> protocols. It's not likely NetMeeting or MS ISA server to be primary
> attack targets. Attack against MS IPSec implementation, Exchange,
> SMB/CIFS, RPC services, IIS and specially IE will no have impact to VoIP
> infrastructure (except connectivity degradation because of massive
I wish your assessment were true, but it's not. Cisco Call Manager is
based on Windows, and Cisco still has to certify the patches Microsoft
It's sad that Microsoft apparently hasn't used those six months to
properly coordinate the issue with OEM vendors.
Full-Disclosure - We believe in it.