<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>P1 Security</title>
	<atom:link href="http://www.p1sec.com/corp/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.p1sec.com/corp</link>
	<description>Priority One Security</description>
	<lastBuildDate>Mon, 30 Aug 2010 10:05:24 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0.1</generator>
		<item>
		<title>New SS7 network mapping visualization technology for PTA</title>
		<link>http://www.p1sec.com/corp/2010/08/29/new-ss7-network-mapping-visualization-technology-for-pta/</link>
		<comments>http://www.p1sec.com/corp/2010/08/29/new-ss7-network-mapping-visualization-technology-for-pta/#comments</comments>
		<pubDate>Sun, 29 Aug 2010 20:40:57 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[News]]></category>
		<category><![CDATA[PTA]]></category>
		<category><![CDATA[Research]]></category>
		<category><![CDATA[Tools]]></category>

		<guid isPermaLink="false">http://www.p1sec.com/corp/?p=571</guid>
		<description><![CDATA[P1 Security Telecom Auditor (PTA) just got a new network mapping visualization technology. This enables better visualization of network topologies according to either the 3-8-3 address formatting or the 5-4-5 formatting. You get instant understanding of the network planning and topology, directly from the generated network maps during the audit. The main problem with SS7 [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.p1sec.com/corp/wp-content/uploads/2010/08/ss7map-default-network-5-4-5.png"><img class="alignright  size-medium wp-image-572" title="ss7map-default-network-5-4-5" src="http://www.p1sec.com/corp/wp-content/uploads/2010/08/ss7map-default-network-5-4-5-230x300.png" alt="" width="230" height="300" /></a>P1 Security Telecom Auditor (PTA) just got a new network mapping visualization technology. This enables better visualization of network topologies according to either the 3-8-3 address formatting or the 5-4-5 formatting. You get instant understanding of the network planning and topology, directly from the generated network maps during the audit.</p>
<p>The main problem with SS7 networks is that many different vendor provided the equipments, systems and network elements that constitute the network; many consultants deployed these with their own way of configuring systems and as a result, nobody has a clear view of the resulting SS7 network. PTA helps keeping a clear view on what is going on in the SS7 network.</p>
<p>This technology is available in PTA for all current users and for commercial licensing as OEM provider for software vendors. Contact us for more information.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.p1sec.com/corp/2010/08/29/new-ss7-network-mapping-visualization-technology-for-pta/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Announcement: P1 Telecom Security talk on SS7 at HES2010</title>
		<link>http://www.p1sec.com/corp/2010/03/29/announcement-telecom-security-talk-on-ss7-at-hes2010/</link>
		<comments>http://www.p1sec.com/corp/2010/03/29/announcement-telecom-security-talk-on-ss7-at-hes2010/#comments</comments>
		<pubDate>Mon, 29 Mar 2010 19:36:04 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Conferences]]></category>

		<guid isPermaLink="false">http://www.p1sec.com/corp/?p=556</guid>
		<description><![CDATA[Philippe Langlois will be talking at HES2010 about &#8220;Getting in the SS7 kingdom: hard technology and disturbingly easy hacks to get entry points in the walled garden&#8221; from 5pm to 6pm at MdO conference center in Paris. This talk will cover entry point discovery to real-world telecom signaling network and following exploitation using SS7 and [...]]]></description>
			<content:encoded><![CDATA[<p>Philippe Langlois will be talking at <a href="http://hackitoergosum.org/" target="_blank">HES2010</a> about &#8220;<a href="http://hackitoergosum.org/program/" target="_blank">Getting in the SS7 kingdom: hard technology and disturbingly easy hacks  to get entry points in the walled garden</a>&#8221; from 5pm to 6pm at MdO conference center in Paris. This talk will cover entry point discovery to real-world telecom signaling network and following exploitation using SS7 and SIGTRAN attacks to inject signaling into the Core Network of an operator. The talk will explain how critical and difficult it is to obtain a good perimeter monitoring on the SS7 and Signaling external side as well as on the internal signaling Core Network, be it Packet or Switched-oriented.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.p1sec.com/corp/2010/03/29/announcement-telecom-security-talk-on-ss7-at-hes2010/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Announcement: SOURCE Boston 2010 Conference, Boston, MA, USA</title>
		<link>http://www.p1sec.com/corp/2010/02/04/source-boston-2010-conference-boston-ma-usa-announcement/</link>
		<comments>http://www.p1sec.com/corp/2010/02/04/source-boston-2010-conference-boston-ma-usa-announcement/#comments</comments>
		<pubDate>Thu, 04 Feb 2010 14:06:38 +0000</pubDate>
		<dc:creator>pascaline</dc:creator>
				<category><![CDATA[Conferences]]></category>

		<guid isPermaLink="false">http://www.p1sec.com/corp/?p=523</guid>
		<description><![CDATA[Event: SOURCE Boston 2010 Location: Boston, MA, USA Date: April 21-23, 2010 read more &#124; agenda]]></description>
			<content:encoded><![CDATA[<p>Event: SOURCE Boston 2010<br />
Location: Boston, MA, USA<br />
Date: April 21-23, 2010</p>
<p><a target="_blank" href="http://www.sourceconference.com/index.php/boston2010/sb2010-schedule#Phil">read more</a> | <a target="_blank" href="http://www.sourceconference.com/index.php/en/boston2010/sb2010-schedule">agenda</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.p1sec.com/corp/2010/02/04/source-boston-2010-conference-boston-ma-usa-announcement/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>26C3 conference, Berlin: “Attacking the SS7 &amp; SIGTRAN applications”</title>
		<link>http://www.p1sec.com/corp/2009/12/09/ss7-security-speech-at-26c3-conference-berlin/</link>
		<comments>http://www.p1sec.com/corp/2009/12/09/ss7-security-speech-at-26c3-conference-berlin/#comments</comments>
		<pubDate>Wed, 09 Dec 2009 16:30:19 +0000</pubDate>
		<dc:creator>pascaline</dc:creator>
				<category><![CDATA[Conferences]]></category>

		<guid isPermaLink="false">http://www.p1sec.com/corp/?p=196</guid>
		<description><![CDATA[Event: 26C3 Location: Berlin Date: December 2009 On 28th of December 2009, Philippe Langlois delivered “SCCP hacking, attacking the SS7 &#38; SIGTRAN applications one step further and mapping the phone system” presentation for Chaos Communication Congress, in Berlin, Germany. This conference, 26C3 was one of the major conference about breakthrough in offensive and defensive computing. [...]]]></description>
			<content:encoded><![CDATA[<p>Event: 26C3<br />
Location: Berlin<br />
Date: December 2009</p>
<p>On 28th of December 2009, Philippe Langlois delivered “<strong>SCCP hacking, attacking the SS7 &amp; SIGTRAN applications one step further and mapping the phone system</strong>” presentation for  Chaos Communication Congress, in Berlin, Germany. This conference, 26C3 was one of the major conference about breakthrough in offensive and defensive computing.<br />
<object class="alignright" style="margin-top:25px;" width="400" height="300" data="http://media.ccc.de/js/flowplayer-3.1.3.swf" type="application/x-shockwave-flash"><param name="movie" value="http://media.ccc.de/js/flowplayer-3.1.3.swf" /><param name="allowfullscreen" value="true" /><param name="allowscriptaccess" value="always" /><param name="flashvars" value="config={'playlist':[{'url':'http://media.ccc.de/media/congress/2009/26c3-3555-en-sccp_hacking_attacking_the_ss7_amp_sigtran_applications_one_step_further_and_mapping_the_phone_system_preview.jpg'},{'autoPlay':false,'autoBuffering':false,'accelerated':true,'scaling':'fit','provider':'pseudo','url':'http://static.p1sec.com/medias/26c3-3555-en-sccp_hacking_attacking_the_ss7_amp_sigtran_applications_one_step_further_and_mapping_the_phone_system.mp4'}],'plugins':{'pseudo':{'url':'flowplayer.pseudostreaming-3.1.3.swf'},'controls':{'url':'flowplayer.controls-3.1.3.swf','bottom':0,'height':24,'zIndex':1,'timeFontColor':'#ffffff','progressColor':'0x619ab2','bufferColor':'0x17446e','backgroundColor':'transparent','autoHide':'always','mute':false}},'clip':{}}" /></object></p>
<p><strong><em>Back to the good old Blue Box?</em></strong></p>
<p><strong>SS7 is like TCP/IP in the 1990s. It used to be quite a secure network because nobody outside the organizations (here, the mobile operators and telecom companies) were connected to it. Now it&#8217;s getting interconnected to new actors which are not that trustworthy. Somehow, hackerdom made SS7 come into existence thanks to the massive use of Blue Boxes. Now, hackerdom is getting its toy back! SS7 is nowaday more and more accessible, and as such increasingly vulnerable. So we&#8217;re getting exposed to a totally new set of protocols, as secure as TCP/IP in the 1980s. This looks like the Blue Box is coming back to life, in a very different form.</strong></p>
<p>Attacking the SS7 network is fun, but there&#8217;s a world beyond pure SS7: the phone system applications themselves, and most notably what transforms phone numbers into telecom addresses (also known as Point Codes, DPCs and OPCs; Subsystem Numbers, SSNs and other various fun.), and that&#8217;s called Global Title Translation. Few people actually realize that the numbers they are punching on their phone are actually the same digits that are used for this critical translation function, and translate these into the mythical DPCs, SSNs and IMSIs. More and more data is now going through the phone network, creating more entry point for regular attacks to happen: injections, overflow, DoS by overloading capacities. And we have an ally: the mobile part is opening up, thanks to involuntary support from Motorola, Apple and Android. We&#8217;ll study all the entry points and the recent progresses in the Telecom security attacks.</p>
<div class="post" style="text-align: left; margin-top: 10px;margin-bottom:10px;"><img class="alignleft size-full wp-image-275" style="margin-right: 5px;" src="/corp/wp-content/uploads/2009/12/save-256x256-e1262614265835.png" alt="" width="15" height="15" /><a style="text-decoration: underline;" href="https://docs.google.com/a/p1sec.com/uc?export=download&#038;id=0BzUGOmQidvKyODQ2MTE5Y2QtOTFjYy00N2M4LTg1YjUtY2MzMTRjYjQzMzE5">download pdf</a></div>
<div class="post" style="text-align: left; margin-top: 10px;margin-bottom:10px;"><img class="alignleft size-full wp-image-275" style="margin-right: 5px;" src="/corp/wp-content/uploads/2009/12/save-256x256-e1262614265835.png" alt="" width="15" height="15" />download video: <a href="http://static.p1sec.com/medias/26c3-3555-en-sccp_hacking_attacking_the_ss7_amp_sigtran_applications_one_step_further_and_mapping_the_phone_system.mp4">mp4</a> &#8211; <a href="http://mirror.fem-net.de/CCC/26C3/mp4/26c3-3555-en-sccp_hacking_attacking_the_ss7_amp_sigtran_applications_one_step_further_and_mapping_the_phone_system.mp4.torrent">torrent</a> &#8211; <a href="http://mirror.informatik.uni-mannheim.de/pub/ccc/26C3-uc3-streamdump/wmv/day2/saal2/26C3-Day2-Room2-Slot23%3a00--ID3555-sccp_hacking-Main-2009-12-28T23%3a00%3a05%2b0100.wmv">wmv</a></div>
]]></content:encoded>
			<wfw:commentRss>http://www.p1sec.com/corp/2009/12/09/ss7-security-speech-at-26c3-conference-berlin/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
<enclosure url="http://static.p1sec.com/medias/26c3-3555-en-sccp_hacking_attacking_the_ss7_amp_sigtran_applications_one_step_further_and_mapping_the_phone_system.mp4" length="670895247" type="video/mp4" />
<enclosure url="http://ftp.ccc.de/congress/2009/mp4/26c3-3555-en-sccp_hacking_attacking_the_ss7_amp_sigtran_applications_one_step_further_and_mapping_the_phone_system.mp4" length="670893233" type="video/mp4" />
<enclosure url="http://mirror.informatik.uni-mannheim.de/pub/ccc/26C3-uc3-streamdump/wmv/day2/saal2/26C3-Day2-Room2-Slot23%3a00--ID3555-sccp_hacking-Main-2009-12-28T23%3a00%3a05%2b0100.wmv" length="484165339" type="video/x-ms-wmv" />
		</item>
		<item>
		<title>H2HC conference, Sao Paulo, Brazil: &#8220;Attacking SS7 applications&#8221;</title>
		<link>http://www.p1sec.com/corp/2009/12/08/h2hc-conference-sao-paulo-brazil-attacking-ss7-applications/</link>
		<comments>http://www.p1sec.com/corp/2009/12/08/h2hc-conference-sao-paulo-brazil-attacking-ss7-applications/#comments</comments>
		<pubDate>Tue, 08 Dec 2009 22:11:35 +0000</pubDate>
		<dc:creator>pascaline</dc:creator>
				<category><![CDATA[Conferences]]></category>

		<guid isPermaLink="false">http://www.p1sec.com/corp/?p=397</guid>
		<description><![CDATA[One step further toward the HLR: Attacking SS7 applications Event: H2HC Location: Sao Paulo, Brazil Date: December 2009 http://www.h2hc.org.br/en/ http://www.h2hc.com.br/palestrantes.php#Speaker18 download pdf Philippe Langlois also participated in &#8220;Hackers to CSO&#8221;, a meeting that brought together hackers, security professionals and CSO, IT decision makers, journalists in order to conduct an assessment of the maturity and current [...]]]></description>
			<content:encoded><![CDATA[<p><strong>One step further toward the HLR: Attacking SS7 applications</strong><br />
Event: H2HC<br />
Location: Sao Paulo, Brazil<br />
Date: December 2009</p>
<p><a target="_blank" href="http://www.h2hc.org.br/en/">http://www.h2hc.org.br/en/</a><br />
<a target="_blank" href="http://www.h2hc.com.br/palestrantes.php#Speaker18">http://www.h2hc.com.br/palestrantes.php#Speaker18</a></p>
<div class="post" style="text-align: left; margin-top: 10px;margin-bottom:10px;"><img class="alignleft size-full wp-image-275" style="margin-right: 5px;" src="http://www.p1sec.com/corp/wp-content/uploads/2009/12/save-256x256-e1262614265835.png" alt="" width="15" height="15" /><a style="text-decoration: underline;" href="https://docs.google.com/a/p1sec.com/uc?export=download&#038;id=0BzUGOmQidvKyOGVhZDE2MWQtYWQyMC00NDJmLWJlMGItNTY5NjIyNmVjZThm">download pdf</a></div>
<p>Philippe Langlois also participated in &#8220;Hackers to CSO&#8221;, a meeting that brought together hackers, security professionals and CSO, IT decision makers, journalists in order to conduct an assessment of the maturity and current stakes of security in the enterprise in South America and globally. </p>
<p>He also joined the CyberWar panel where he exposed the implication of &#8220;Cyber War&#8221; in Telecom security. What are the impact of one country, one mafia group, one nationalistic cracker group directing their effort against a Telecom infrastructure? How to defend against malicious SS7 maneuvers coming from a foreign country or foreign company? </p>
]]></content:encoded>
			<wfw:commentRss>http://www.p1sec.com/corp/2009/12/08/h2hc-conference-sao-paulo-brazil-attacking-ss7-applications/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Vital tool for SS7 security audit: ss7calc</title>
		<link>http://www.p1sec.com/corp/2009/11/20/ss7calc-opensource-tool-for-ss7-security-audit/</link>
		<comments>http://www.p1sec.com/corp/2009/11/20/ss7calc-opensource-tool-for-ss7-security-audit/#comments</comments>
		<pubDate>Sat, 21 Nov 2009 00:06:23 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Research]]></category>
		<category><![CDATA[Tools]]></category>
		<category><![CDATA[ss7]]></category>
		<category><![CDATA[telecom]]></category>

		<guid isPermaLink="false">http://www.p1sec.com/corp/?p=169</guid>
		<description><![CDATA[How many times did you use ipcalc in a pentest? Now you have the same thing for SS7 networking: ss7calc. Check our Tools page for our fresh project just released on Github. This utility was created due to the high number of SS7 point codes conversions we had to do during the last SS7 Core [...]]]></description>
			<content:encoded><![CDATA[<p>How many times did you use ipcalc in a pentest? Now you have the same thing for SS7 networking: <a href="/corp/research/tools/ss7calc/">ss7calc</a>. Check our <a href="/corp/research/tools/">Tools</a> page for our fresh project just released on Github.</p>
<p>This utility was created due to the high number of SS7 point codes conversions we had to do during the last SS7 Core Network audit. Online converters are nice but definitely lack scripting-friendliness. Now we share it with the community.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.p1sec.com/corp/2009/11/20/ss7calc-opensource-tool-for-ss7-security-audit/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Hack.lu conference, Luxembourg: &#8220;HostileWRT&#8221;</title>
		<link>http://www.p1sec.com/corp/2009/10/29/hack-lu-conference-luxembourg-hostilewrt/</link>
		<comments>http://www.p1sec.com/corp/2009/10/29/hack-lu-conference-luxembourg-hostilewrt/#comments</comments>
		<pubDate>Thu, 29 Oct 2009 22:16:18 +0000</pubDate>
		<dc:creator>pascaline</dc:creator>
				<category><![CDATA[Conferences]]></category>

		<guid isPermaLink="false">http://www.p1sec.com/corp/?p=401</guid>
		<description><![CDATA[HostileWRT: Fully-Automated Wireless Security Audit Platform on Embedded Hardware Philippe Langlois &#038; Eugene Parkinson Event: Hack.lu Location: Luxembourg Date: 2009-10-29 HostileWRT has beend presented during Hack.lu in Luxembourg. Eugene Parkinson and Philippe Langlois presented on Thursday 29.10.2009 their new development on their “Fully-Automated Wireless Security Audit Platform on Embedded Hardware” and released HostileWRT version 0.5.0 [...]]]></description>
			<content:encoded><![CDATA[<p><strong>HostileWRT: Fully-Automated Wireless Security Audit Platform on Embedded Hardware</strong><br />
Philippe Langlois &#038; Eugene Parkinson<br />
Event: Hack.lu<br />
Location: Luxembourg<br />
Date: 2009-10-29</p>
<p>HostileWRT has beend presented during Hack.lu in Luxembourg. Eugene Parkinson and Philippe Langlois presented on Thursday 29.10.2009 their new development on their “Fully-Automated Wireless Security Audit Platform on Embedded Hardware” and released HostileWRT version 0.5.0 during the conference.</p>
<p><a href="http://2009.hack.lu/index.php/List#HostileWRT:_Fully-Automated_Wireless_Security_Audit_Platform_on_Embedded_Hardware">hack.lu info page</a></p>
<p><a href="http://2009.hack.lu/index.php/Agenda">hack.lu agenda</a></p>
<div class="post" style="text-align: left; margin-top: 10px;margin-bottom:10px;"><img class="alignleft size-full wp-image-275" style="margin-right: 5px;" src="http://www.p1sec.com/corp/wp-content/uploads/2009/12/save-256x256-e1262614265835.png" alt="" width="15" height="15" /><a style="text-decoration: underline;" href="http://2009.hack.lu/archive/2009/tmplab-HostileWRT-5-hacklu.pdf">download pdf</a></div>
]]></content:encoded>
			<wfw:commentRss>http://www.p1sec.com/corp/2009/10/29/hack-lu-conference-luxembourg-hostilewrt/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Welcome to P1 Security</title>
		<link>http://www.p1sec.com/corp/2009/07/08/hello-world/</link>
		<comments>http://www.p1sec.com/corp/2009/07/08/hello-world/#comments</comments>
		<pubDate>Wed, 08 Jul 2009 16:05:50 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Home]]></category>

		<guid isPermaLink="false">http://www.p1sec.com/corp/?p=1</guid>
		<description><![CDATA[The security environment is changing. With top telecom infrastructure completely compromised, carrier company data exposed on public security mailing list, internal signaling core network backdoors and security officers laptop data leaks, we&#8217;re witnessing an environment more hostile by a degree of magnitude compared to ten years ago. This situation needs important proactive actions, pragmatic contingency [...]]]></description>
			<content:encoded><![CDATA[<p>The security environment is changing. With top telecom infrastructure completely compromised, carrier company data exposed on public security mailing list, internal signaling core network backdoors and security officers laptop data leaks, we&#8217;re witnessing an environment more hostile by a degree of magnitude compared to ten years ago. This situation needs important proactive actions, pragmatic contingency plans and an expanded reactive capacity.</p>
<p>P1 Security is dedicated to providing top <a href="/corp/products/">security products</a> and <a href="/corp/services/">services</a> in competitive and sensitive areas. Founded by experts in Security and Enterprise software and services, P1 Security places its value in maturity of security planning and implementation, while preserving the clients business.</p>
<p>P1 Security was founded by Philippe Langlois, founder of Qualys (world leader of vulnerability assessment service), INTRINsec (European consulting company, first to launch penetration testing in France and one of the earliest Payment Gateway security technology provider), Telecom Security Task Force (Research think tank and consulting network in Telecom sector), WaveSecurity (Wireless networks security technology manufacturer).</p>
<p>Please <a href="/corp/contact/">contact us</a> if you wish to enquire about our products and services.</p>
<p>P1 Security Team.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.p1sec.com/corp/2009/07/08/hello-world/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
