Insecure Meeting

While researching news on the Comoros, (the elections are almost here) I read an interesting site that describes Offshore Anjouan as an excellent tax haven for banks and casinos. The same site also advocates buying a second passport and nationality to escape taxes. Ugh.

Afan mentioned the Open H323 Project, which clearly aims to free the H.323 teleconferencing (VoIP) protocol stack and has some excellent backgrounder information on related standards. I also came across this handy PocketGuide to VoIP.

Working with NetMeeting, an H.323 application that runs over IP, I noticed TCP port 1720 is the trigger but it needs all incoming UDP ports 1024 to 65534. Obviously not a well thought out network application. In any case, here is an incomplete reference to ports for popular applications.

There are many serious and well documented security concerns for a NetMeeting call, although you can read Microsoft’s firewall configuration guide and judge for yourself…and I quote: “There are few available products that an organization can implement to securely transport inbound and outbound NetMeeting calls.”