Off-path VoIP Interception Attacks

AuthorDai, Tianxiang; Shulman, Haya; Waidner, Michael
TypeConference Paper
AbstractThe proliferation of Voice-over-IP (VoIP) technologies make them a lucrative target of attacks. While many attack vectors have been uncovered, one critical vector has not yet received attention: hijacking telephony via DNS cache poisoning. We demonstrate practical VoIP hijack attacks by manipulating DNS responses with a weak off-path attacker. We evaluate our attacks against popular telephony VoIP systems in the Internet and provide a live demo of the attack against Extensible Messaging and Presence Protocol at
ConferenceInternational Conference on Distributed Computing Systems (ICDCS) <41, 2021, Online>
PartInstitute of Electrical and Electronics Engineers -IEEE-: IEEE 41st International Conference on Distributed Computing Systems, ICDCS 2021: July 7 - July 10, 2021, Virtual. Piscataway, NJ: IEEE, 2021, pp. 1122-1123