TechMonkey Posted January 9, 2012 Posted January 9, 2012 Seems to be PBX hacking is on the increase & has spiked over the last 3 - 6 months. 2 forms that are linked, either the PBX gets rooted to be a step in a chain and forwards calls to a local number, increasing your bill slightly but maybe not so much as you'd noticed, or you end up being the final step in the chain, a number is routed to some far flung corner of the globe and you get whacked with anything from £1000 upwards, with costs of £10k or £30k. Seems to be a lot of uncertainty on how it happens but has happened to non-IP connected devices so it is not just a computer network issue. We have been advised that basically PBX's can not be trusted to be secure so anything implemented on them (forwarding blocks, locks, passwords) can be bypassed & anything else is reactive so you still get the costs racked up. The only solution given to us is an external service (installed on our server) that monitors the PBX actions and follows rules on whether it allows it or not. Anti Virus for phone systems!! Be careful out there!
Domino Posted January 9, 2012 Posted January 9, 2012 er, is it just me, or does that sound like someone was trying to sell you something?
glennda Posted January 9, 2012 Posted January 9, 2012 More to the Point for my Hosted VOIP solution I'm putting together!
Aethon Posted January 10, 2012 Posted January 10, 2012 We had a similar thing hit us about 12 months ago. One thing to check is that all voice mailboxes have a password set on them, mailboxes are a common way in and this will help stop a lot of attempts. Some anti-phreaking software was purchased as well but this is a real pita and, when it's accessed, it breaks the phone system. (While I don't look after the phone system, I do have to look after the servers so about every month I end up spending a day on the phone trying to talk to the software devs and get their software to work properly - fun times.)
plexer Posted January 10, 2012 Posted January 10, 2012 Even non ip based pbx's normally have remote dial in capabilities for the engineers to be able to configure them remotely and was wide spread "years" ago Ben
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now