Privacy Digest

News that can impact your privacy.
Login/Register
What is OpenID?
  • Log in using OpenID
  • Cancel OpenID login
  • Create new account
  • Request new password
Home Blogs MacRonin's blog
    • FAQ
    • Wishlists
    • Contact
    • Categories/RSS

Bookmark Us

Bookmark Privacy Digest 
Bookmark This Page 

Syndicate

Syndicate content
more

Advertisements

Tracking System
Tracking System
Private Detectives
Quality Security Services in California
Fleet Management
Hosting

Popular content

Last viewed:

  • Embattled Attorney General Resigns
  • Two Steps to Preventing False Arrests
  • Privacy issues allow blogger to contest
  • Analysis: Legality of Torrent Tracking Sites Unresolved Despite TorrentSpy Decision
  • Obama Puts FOIA Back On Track
  • Classic lobby pits broadcasters against satellite and cable giants
  • Advocacy Group Angry At Smithsonian's Fake Copyrights Claims Their Own Fake Copyright - UPDATED

tags in Topics

Activists Alert Anonymity Companies Congress Copyright Court (US) Databases Data Mining Editorial EFF Entertainment Exploits Fourth Amendment Government Hmmm ID Infrastructure Law Enforcement Laws Politics Privacy Remember Reports Rights Security Spin Zone Surveillance Telecommunications Tracking
more tags

View blog authority
Congressional Research
Broadcast Flag

FBI: Criminals Auto-dialing With Hacked VoIP Systems

Submitted by MacRonin on December 6, 2008 - 4:51pm
  • Alert
  • Companies
  • Exploits
  • FBI - Federal Bureau Of Investigation
  • Government
  • Hardware
  • Hmmm
  • Infrastructure
  • Open Source
  • Scams
  • Security
  • Software
  • Telecommunications

FBI: Criminals Auto-dialing With Hacked VoIP Systems: Via Business Center - PC World

Criminals are taking advantage of a bug in the Asterisk Internet telephony system that lets them pump out thousands of scam phone calls in an hour, the U.S. Federal Bureau of Investigation warned Friday.

The FBI didn't say which versions of Asterisk were vulnerable to the bug, but it advised users to upgrade to the latest version of the software. Asterisk is an open-source product that lets users turn a Linux computer into a VoIP (Voice over Internet Protocol) telephone exchange.

In so-called vishing attacks, scammers usually use a VoIP system to set up a phony call center and then use phishing e-mails to trick victims into calling the center. Once there, they are prompted to give private information. But in the scam described by the FBI, they apparently are taking over legitimate Asterisk systems in order to directly dial victims.

"Early versions of the Asterisk software are known to have a vulnerability," the FBI said in an advisory posted Friday to the Internet Crime Complaint Center. "The vulnerability can be exploited by cyber criminals to use the system as an auto dialer, generating thousands of vishing telephone calls to consumers within one hour."

The software, developed by Digium, has been available for nearly a decade, and a number of critical flaws have been found in the software. In March, researchers at Mu Security reported a bug that could allow an attacker to take control of an Asterisk system.

Digium wasn't certain what vulnerability the FBI was referencing in its advisory. However John Todd, the company's Asterisk open-source community director, believes that it was probably this March bug. That vulnerability "basically allowed you to take over the account of one individual," he said. "In the worst possible case, you could make thousands of calls in an hour."

However, the attack described by the FBI would be extremely hard to pull off, Todd said.

Most Asterisk systems are protected by firewalls or other security software and even if one could be accessed by a visher, administrators generally limit the number of calls any one account can make simultaneously, he explained. "Most of the time you would not be able to create thousands of calls in an hour."

The flaw affects older versions of Asterisk but not the most current version 1.6, he said.

Read Original Article (Via Business Center - PC World .)

Bookmark/Search this post with:
  • Twitter Twitter
  • Digg Digg
  • StumbleUpon StumbleUpon
  • Technorati Technorati
  • del.icio.us del.icio.us
  • Facebook Facebook
  • Furl Furl
  • LinkedIn LinkedIn
  • Yahoo Yahoo
  • MacRonin's blog
  • Add new comment

Recent blog posts

  • FBI Hoaxes Boost Online Fraud
  • NetFlix Cancels Recommendation Contest After Privacy Lawsuit
  • Advertising - Instant Ads Set the Pace on the Web
  • Best Practices for Government Datasets: Wrap-Up
  • TJX Hacking Conspirator Gets 4 Years
  • The Beginning of the End of Data Retention
  • Wanted: Trust Detector
  • Wikibooks Cryptography Textbook
  • Feds: TSA Worker Tried to Sabotage Terror Database
  • Hi-tech governments growing keener on snooping, says report
more

Performancing Metrics

Compilation © Copyright 1997-2010 Paul Hardwick, with Web Hosting provided by MacRonin.com.