Re: VoIP Security Alert: Hackers Now Working VOIP For Cash

Re: VoIP Security Alert: Hackers Now Working VOIP For Cash

NewsGroups | Search | Tools
 comp.dcom.telecom  Post an article  get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content  add this group's latest topics to your Google content  YahooMyWeb Yahoo!  Google Google  Windows Live Favorites Windows Live  del.icio.us del.icio.us  digg digg  Add to Netscape Netscape
Subject Author Date
Re: VoIP Security Alert: Hackers Now Working VOIP For Cash hancock4 06-12-2006
Posted by on June 12, 2006, 12:09 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
J. Nicholas Hoover wrote:

> IP phone crooks are learning how to rake in the dough. An owner of two
> small Miami voice-over-IP telephone companies was arrested last week
> and charged with making more than $1 million by breaking into
> third-party VoIP services and routing calls through their lines. That
> let him collect from customers without paying any fees to route calls.

Since VOIP is a relatively new feature, I would've thought the
providers had built in extensive security features to prevent hackers
and other sabotage attacks.

Another area of concern is intercepting calls, that is, developing
logs of who called whom and listening in to conversations.

I find it ironic that when the govt does this it's front page news and
raise the outrage of so many people. But when a criminal exploits
inherent and apparently obvious weaknesses in the Internet, it's a
yawner. Sorry, but I'm more worried about criminals listening in to my
phone calls than the govt.

> Prosecutors claim he paid $20,000 to Spokane,
> Wash., resident Robert Moore, to help send VoIP telecoms millions of
> test calls, guessing at proprietary prefixes encoded on packet
> headers. Eventually, the right one gave them access.

How (though what internet access points, computer resources, etc) did
the hackers generate "'millions' of test calls"? Presumably ISPs,
even those providing professional services, have limits on traffic
coming out of a short time. (Mine has very low limits to prevent
spammers).

Also, most computers shut off access after a few unsuccessful log on
attempts (like 3 [THREE]). After "millions" of hits, shouldn't the
computer have blocked access or raised a warning to a human operator?
This isn't only necessary for security, but also reliability--suppose a
failed computer someone else is in an "infinite loop" and sending out
calls repeatedly. Without protection (ie a "circurit breaker"), the
networks will get flooded.

Power systems have physical circuit breakers to isolate faults that
could damage equipment. These go off fairly often, but there is
redundant lines so troubles are rare. It seems the Internet should
have 'logical circuit breakers' to do the same thing for protection.

This is one of my concerns about the safety and security of the
Internet. If anyone can just get on and send out millions of
transactions unchecked by any protocol, the risk for disruption is
extremely great.


Similar ThreadsPosted
VoIP Security Alert: Hackers Now Working VOIP For Cash June 11, 2006, 8:00 pm
Hackers Working to Unlock iPhone July 3, 2007, 10:56 pm
Phishing by Phone -- VoIP Raises Security Concerns March 20, 2005, 11:40 pm
Hackers/Malware Writers Now Working as a Group July 17, 2006, 11:32 am
Book Review: Practical VoIP Security, Thomas Porter et al July 3, 2006, 1:41 pm
Voip Updated Basic, Translating, Voip News and Advanced April 12, 2006, 6:14 pm
Voip Updated Basic,Translating,Voip News and Advanced April 27, 2006, 8:42 pm
Symantec Security Alert January 26, 2007, 2:39 pm
Free VOIP Resources - Learn VOIP (H.323, SIP, MGCP, RTP) April 5, 2005, 10:05 am
ID Security Company Finds Snags in Fraud Alert System August 23, 2006, 7:01 pm

other useful resources:
The Federal Communications Commission (FCC)
Telecommunications Industry Association
Electronic and Software Security Products and Services
International Telecommunication Union

Custom CGI Perl and PHP programming by 1-Script.com

Contact Us | Privacy Policy
The site map in XML format XML site map