A researcher demonstrated how Cisco Voice-over-IP (VoIP) phones can be hijacked and turned into listening devices. Columbia University grad student Ang Cui demonstrated how networked printers can be abused by attackers. Cisco says that workarounds and a software patch are available to address the issue. The issue can be exploited remotely as well, explains Cui, where a likely method of exploiting the kernel is by using an arbitrary execution bug on the phone’s surface. Cui: “I’d like to see actual mechanical switches that control the various input/output devices on IP phones””]

