As already explained, eavesdropping is defined as the intercepting of conversations by unintended recipients. This is probably the simplest VoIP attack to carry out with numerous readily available software tools able to implement it effectively. Information on the used CoDec can be retrieved from the header of every RTP packet, inside the PT header field. An attacker with the ability to intercept unencrypted VoIP media traffic has, therefore, no problem in saving RTP streams for later analysis and decoding.

This passive attack impacts the confidentiality requirement of the CIA paradigm and can have important and unexpected consequences for an organization.

