Author Archives: Dan York

Archive of VoIP User Conf interview about UC security now available

The archive of the audio interview I gave on May 21st to the VoIP Users Conference (VUC) is available at:

http://www.voipusersconference.org/2010/7-deadliest-uc-attacks/

You can either download the MP3 for later listening or play the show directly in the browser.

It was an enjoyable show that went for pretty much the entire hour.  We talked about the Seven Deadliest Unified Communications Attacks book, UC and VOIP security in general… and, well… a good number of other interesting side topics.  I think you'll find it an enjoyable listen.

Many thanks to Randy and the whole VUC gang for the chance to go on the show and talk about the book.

Live interview Friday, May 21, 1pm US EST on VoIP Users Conf about the book

vuc-7ducattacks.jpgThis Friday, May 21st, at 1pm US Eastern time, I’ll be live on the VoIP Users Conference call talking about the Seven Deadliest Unified Communications Attacks. We’ll be talking about the book, the attacks against UC systems and strategies to protect against those attacks. Based on past VUC calls, I’ll expect it to get highly interactive 🙂

The VUC is a long-running weekly conference call on Fridays typically at noon US Eastern time but with occasional sessions starting at 1pm as well. Randy Resnick is the host of a fun gathering of people interested in VoIP and IP communications. Many of the folks work with Asterisk and other open source tools and are generally trying to push the boundaries of what can be done with VoIP. I’ve been on a number of shows in the past as both a guest and a regular participant and enjoyed the conversations.

If you are able to participate live on Friday, you can join in the discussion and ask me questions during the session. You can call in on any of these numbers:

Regular phone: (567) 252-2286
sip:200901@login.zipdx.com
skype:vuc.me

The VUC uses a HD audio conferencing bridge from ZipDX so if you call in via Skype or SIP (with a wideband codec) you’ll be able to enjoy the call in high quality audio.

If you can’t attend the call live, the session will be recorded and available from the episode web page for later listening.

I look forward to talking to some of you there.

P.S. The VUC also uses IRC and will have a backchannel going on “#vuc” on freenode.irc.net (a web interface is available if you don’t have an IRC client handy).

Seven Deadliest UC Attacks book is “launched”… kinda, sorta…

calendar.jpgSilly me! I naively thought that maybe this time around the “launch” of the book could actually be nailed down to “a day“.

You see, back in the 1990’s and early 2000’s when I wrote my other four books, it was a different era. Amazon.com wasn’t quite the enormous industry player that it is today. You sent your text and edits into the publisher and then sometime a book showed up at your house… and sometime after that it appeared in local book stores. Sometime… whenever…

Fast forward 8 years and I thought it might be different now. I thought the launch date could be nailed down. I watched friends like Chris Brogan, Mitch Joel and Steve Garfield all focus on “launches” of their books on specific days… and figured it would be similar for mine.

Nope.

Now, granted, all of their books are targeted at the larger marketing/communications audience… and maybe they planned for a date after availability… and given everything else on my plate, I didn’t really spend that much time working on a launch plan. I just sort of thought it might work out easier.

The editors, publicity folks and others at Syngress were all great. They told me…

… the book should be available in their warehouses on April 28th and, yes indeed, you could order if directly from Syngress on that date… if you wanted to pay the $24.95 list price. But what I found in myself was this:

I wanted to know the date it was live on Amazon.com!

That, to me, seemed to be “the launch date”. And sadly… no one could tell me that. “It all depends upon when it gets to Amazon’s warehouses” … and … “it’s completely out of our control.”

Interesting.

When “the day” came, naturally I went to Amazon to see if it was available and met with:

7ducattacks-amazon1.jpg

Even though the site did say the 28th:

7ducattacks-amazon2-1.jpg

Checking back on Amazon on April 29th showed me that it was available, but with a 1-4 week availability! Which brought about amusing screens like this one (given that the date was April 29th):

amazon2day.jpg

And then today it is now showing as “Temporarily out of stock“:

7ducattacksoutofstock-1.jpg

Which I guess is a good thing in that initial demand must have been higher than their supply… maybe? (or is that the books didn’t actually get into the warehouse in the first place?)

So in any event… the book is kind of launched… you can’t really buy it from Amazon.com… you can buy it direct from Syngress if you want to spend $8 more… and in theory you should be able to get it in your local bookstore sometime soon…

All in all a bit of strange experience. But it’s out there… which is cool!


If you found this post interesting or useful, please consider either subscribing to the RSS feed, following me on Twitter or subscribing to my email newsletter.


Yea! Received my advance copies of Seven Deadliest Unified Communications Attacks

Only a few hours after writing my post today saying that I still didn’t have a copy of the book, a UPS truck pulled up outside my house and dropped off a box…

7ducattacks-dy-1.jpg

Having submitted the chapters back in November, December and early January … and then worked on proofs of the pages in February and early March… it’s great to finally hold the final version in my hands.

The book is now sort of available… Syngress is apparently selling the book from their site and they tell me the book should be available at Amazon any day now…

7 Deadliest UC Attacks spotted in the wild – at the InfoSec 10 conf in London

While I still don’t have a copy of the book yet, Jason Ostrom of Sipera System’s Viper Labs is over speaking at the InfoSecurity Europe 2010 conference in London and went by the Syngress booth where they have advance copies. The Syngress folks nicely sent along this pic via Twitter (click on the image to see the larger version):

7ducattacks-infosec10.jpg

I’m glad Jason got to see the book (he wrote a nice pre-review)… I’m hoping my copy shows up here soon!

P.S. If you have pictures like this of you with the book, it would be fun to have some on the Facebook page… please feel free to add them there.

Telecom Junkies: My first audio interview about 7 Deadliest UC Attacks book

telecomjunkies.jpgYesterday the folks over at The Voice Report posted a Telecom Junkies podcast where host Jessica Gdowski interviewed me about the book. As Jessica says in the intro, I'm a "veteran Junkie" in that I've participated in several previous podcasts including an interview with Robert Moore who was convicted of hacking into VoIP systems.

In this interview, Jessica started out asking me about why I wrote this book and how it is different from all the other books out there. We went from there into discussing the parts of the book, the areas I thought are of most concerns, solutions out there and much more. And at the end she had a little contest offering…

You can listen here.

It was fun to do and I thank Jessica for the opportunity to talk about the book. More interviews will be coming in the weeks ahead….

P.S. And if you are interested in interviewing me on your show or for your web site, please contact me.

Book Launch Date Confirmed -> April 28, 2010

So it turns out that the Amazon page for Seven Deadliest Unified Communications Attacks has the wrong info on it. I confirmed this morning with my editor at Syngress that the launch date is not April 15, as listed on Amazon, but instead April 28th.  So… a little bit longer to wait… 🙁

(Speaking of the wait, have you pre-ordered the book yet?  If you do, you'll get a copy as soon as they start shipping…)

7 Deadliest UC Attacks Chapter 3, “Eavesdropping and Modification”, now available as free PDF download

As part of the publicity in the run-up to the book's release in a few weeks, Syngress has made a PDF available for free download of Chapter 3, "Eavesdropping and Modification".  In the chapter, I talk about how you can use basic tools like Wireshark to eavesdrop on UC traffic and discuss some of the tools that can be found on the VOIPSA VoIP Security Tools list and how they can be used to both observe and modify traffic.  I also suggest strategies for how to secure your UC systems against these attacks.  The chapter is out there for free download… please feel free to share it… and I'd love to hear your feedback, either as comments here or over on the Facebook page for the book.  Thanks!