<?xml version="1.0" encoding="UTF-8"?>
<feed xmlns="http://www.w3.org/2005/Atom" 
      xmlns:thr="http://purl.org/syndication/thread/1.0">
  <link rel="alternate" type="text/html" href="http://blog.tmcnet.com/blog/tom-keating/asterisk/astricon-voip-security---400000-fraud---yikes.asp" />
  <link rel="self" type="application/atom+xml" href="http://blog.tmcnet.com/blog/tom-keating/atom.xml" />
  <id>tag:blog.tmcnet.com,2013:/blog/tom-keating//4/tag:blog.tmcnet.com,2011:/blog/tom-keating//4.47781-</id>
  <updated></updated>
  <title>Comments for AstriCon VoIP Security - $400,000 toll fraud - YIKES!</title>
  <subtitle>VoIP &amp; Gadgets blog - Latest news in VoIP &amp; gadgets, wireless, mobile phones, reviews, &amp; opinions</subtitle>
  <generator uri="http://www.sixapart.com/movabletype/">Movable Type 4.38</generator>
  <entry>
    <id>tag:blog.tmcnet.com,2011:/blog/tom-keating//4.47781</id>
    <link rel="alternate" type="text/html" href="http://blog.tmcnet.com/blog/tom-keating/asterisk/astricon-voip-security---400000-fraud---yikes.asp" />
    <link rel="service.edit" type="application/atom+xml" href="http://blog.tmcnet.com/mt/mt-atom.cgi/weblog/blog_id=4/entry_id=47781" title="AstriCon VoIP Security - $400,000 toll fraud - YIKES!" />
    <published>2011-10-26T16:18:23Z</published>
    <updated>2011-10-26T16:18:41Z</updated>
    <title>AstriCon VoIP Security - $400,000 toll fraud - YIKES!</title>
    <summary>During an AstriCon session on VoIP security the speaker discussed how easy it was to hack voicemail PINs, but not to listen to your voice messages but to initiate &quot;call backs&quot; using spoofed CallerIDs. Essentially, this leverages the &quot;call back&quot;...</summary>
    <author>
      <name>Tom Keating</name>
      <uri>http://blog.tmcnet.com/blog/tom-keating/</uri>
    </author>
    
    <category term="Asterisk" />
    
    <category term="TMCnet" />
    
    <category term="VoIP" />
    
    <content type="html" xml:lang="en" xml:base="http://blog.tmcnet.com/blog/tom-keating/">
      <![CDATA[<img class="mt-image-none" src="http://blog.tmcnet.com/blog/tom-keating/images/astricon-2011-logo.jpg" alt="astricon-2011-logo.jpg" width="281" height="100" /><br />During an AstriCon session on VoIP security the speaker discussed how easy it was to hack voicemail PINs, but not to listen to your voice messages but to initiate "call backs" using spoofed CallerIDs. Essentially, this leverages the "call back" feature that many voicemail systems have to call back the person that left the message.<br /><br />He then asked the audience for any real world examples of how they were hacked. Several volunteered their stories. I captured one of them where their <a href="http://www.elastix.org">Elastix</a> server was hacked - due to their parent company locking them out of the server and not updating /patching the server. This resulted in the hackers racking up toll fraud (Korean calls) of $400,000! It's a fun watch. Enjoy! [HD available in full screen mode]<br /><iframe src="http://www.youtube.com/embed/ro8WMr04iBA" width="640" height="360" frameborder="0"></iframe>]]>
      
    </content>
  </entry>

</feed>
