<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>usken.no - VoIP news! &#187; fraud</title>
	<atom:link href="http://www.usken.no/tag/fraud/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.usken.no</link>
	<description>VoIP news for VoIP people!</description>
	<lastBuildDate>Thu, 09 Sep 2010 14:13:23 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.1</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Cool way to make a video</title>
		<link>http://www.usken.no/2010/09/cool-way-to-make-a-video/</link>
		<comments>http://www.usken.no/2010/09/cool-way-to-make-a-video/#comments</comments>
		<pubDate>Thu, 09 Sep 2010 14:13:23 +0000</pubDate>
		<dc:creator>sjur</dc:creator>
				<category><![CDATA[VoIP]]></category>
		<category><![CDATA[fraud]]></category>
		<category><![CDATA[telecom]]></category>
		<category><![CDATA[video]]></category>

		<guid isPermaLink="false">http://www.usken.no/?p=375</guid>
		<description><![CDATA[Xtranormal.com is an easy way to make simpel videos. You can see mine about telecom fraud here (37 seconds).
Enjoy!
]]></description>
			<content:encoded><![CDATA[<p><a href="www.xtranormal.com" target="_blank">Xtranormal.com</a> is an easy way to make simpel videos. You can see mine about <a href="http://www.xtranormal.com/watch/7092769/" target="_blank">telecom fraud here</a> (37 seconds).</p>
<p>Enjoy!</p>
]]></content:encoded>
			<wfw:commentRss>http://www.usken.no/2010/09/cool-way-to-make-a-video/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Just 10 000 USD in hacking this time..</title>
		<link>http://www.usken.no/2010/08/just-10-000-usd-in-hacking-this-time/</link>
		<comments>http://www.usken.no/2010/08/just-10-000-usd-in-hacking-this-time/#comments</comments>
		<pubDate>Tue, 10 Aug 2010 07:59:21 +0000</pubDate>
		<dc:creator>sjur</dc:creator>
				<category><![CDATA[VoIP]]></category>
		<category><![CDATA[fraud]]></category>
		<category><![CDATA[hacking]]></category>

		<guid isPermaLink="false">http://www.usken.no/?p=362</guid>
		<description><![CDATA[A VoIP hacking that actually reached the public, was just 10 000,- USD being frauded for. I would say they were lucky. This is just top of the iceberg, I hear about so many more not being reported because the firm or institution does not want to &#8220;have beeing hacked&#8221;. The latest news about it [...]]]></description>
			<content:encoded><![CDATA[<p>A VoIP hacking that actually reached the public, was just 10 000,- USD being frauded for. I would say they were lucky. This is just top of the iceberg, I hear about so many more not being reported because the firm or institution does not want to &#8220;have beeing hacked&#8221;. The latest news about it in <a href="http://www.aftenposten.no/okonomi/article3762331.ece" target="_blank">Norwegian </a>or translated to <a href="http://translate.google.com/translate?js=y&amp;prev=_t&amp;hl=no&amp;ie=UTF-8&amp;layout=1&amp;eotf=1&amp;u=http%3A%2F%2Fwww.aftenposten.no%2Fokonomi%2Farticle3762331.ece&amp;sl=no&amp;tl=en" target="_blank">English</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.usken.no/2010/08/just-10-000-usd-in-hacking-this-time/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Number of VoIP scannings has exploded</title>
		<link>http://www.usken.no/2010/01/number-of-voip-scannings-has-exploded/</link>
		<comments>http://www.usken.no/2010/01/number-of-voip-scannings-has-exploded/#comments</comments>
		<pubDate>Mon, 11 Jan 2010 07:49:09 +0000</pubDate>
		<dc:creator>sjur</dc:creator>
				<category><![CDATA[VoIP]]></category>
		<category><![CDATA[fraud]]></category>
		<category><![CDATA[hack]]></category>
		<category><![CDATA[scanning]]></category>

		<guid isPermaLink="false">http://www.usken.no/?p=307</guid>
		<description><![CDATA[If you have an IP PBX on a public IP, and you are not quite sure if it is secure enough, you should get to it now!
Scannings on port 5060 has exploded the lastest days. Previously it was a couple hits in the week, now it&#8217;s up to a 100 a day. This means that [...]]]></description>
			<content:encoded><![CDATA[<p>If you have an IP PBX on a public IP, and you are not quite sure if it is secure enough, you should get to it now!</p>
<p>Scannings on port 5060 has exploded the lastest days. Previously it was a couple hits in the week, now it&#8217;s up to a 100 a day. This means that if your VoIP setup is not 100% secure, others will find it and abuse it!And you will get the telephony bill!</p>
<p>Get to it, secure your VoIP communication platform right now!</p>
<p>Check the following:</p>
<ul>
<li>All users has strong passwords</li>
<li>Access Lists are updated and preferably both ways (both incoming and outgoing traffic on the server)</li>
<li>No unused services are enabled</li>
<li>Latest patches are on the server OS</li>
<li>Latest patches are on the application</li>
<li>Latest SECURE firmware on the hardware endpoints (phones etc.)</li>
<li>Other services on the plattform like Web servers, TFTP, FTP, SSH are locked down or VERY strong passwords</li>
<li>Encrypt the traffic from the user and into the server (to make eavesdropping harder)</li>
<li>Make the PCs accessing your platform secure. Any keycatchers or sniffers installed here?</li>
<li>Forgotten someting? Please comment</li>
</ul>
<p><script type="text/javascript"><!--
google_ad_client = "pub-1177893919351833";
google_ad_slot = "0971638747";
google_ad_width = 468;
google_ad_height = 60;
//--></script>
<script type="text/javascript" src="http://pagead2.googlesyndication.com/pagead/show_ads.js"></script>
</p>
]]></content:encoded>
			<wfw:commentRss>http://www.usken.no/2010/01/number-of-voip-scannings-has-exploded/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>VoIP attacks are here again!</title>
		<link>http://www.usken.no/2009/01/voip-attacks-are-here-again/</link>
		<comments>http://www.usken.no/2009/01/voip-attacks-are-here-again/#comments</comments>
		<pubDate>Thu, 08 Jan 2009 17:00:24 +0000</pubDate>
		<dc:creator>sjur</dc:creator>
				<category><![CDATA[VoIP]]></category>
		<category><![CDATA[fraud]]></category>
		<category><![CDATA[h323]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[phone]]></category>
		<category><![CDATA[ringing]]></category>
		<category><![CDATA[scanning]]></category>
		<category><![CDATA[sip]]></category>

		<guid isPermaLink="false">http://www.usken.no/?p=137</guid>
		<description><![CDATA[Have you seen the movie &#8220;The Lawnmower Man&#8220;? When, in the end, all phones in the whole world is ringing? This was the scenario for several firms in Norway this week. The phones rang every 20 minutes!
Whose fault is it?
And the guilty one? Several are to blame.
First; the Piradius (again&#8230;) network doing SIP and H.323 [...]]]></description>
			<content:encoded><![CDATA[<p>Have you seen the movie &#8220;<a href="http://www.imdb.com/title/tt0104692/">The Lawnmower Man</a>&#8220;? When, in the end, all phones in the whole world is ringing? This was the scenario for several firms in Norway this week. The phones rang every 20 minutes!</p>
<p><strong>Whose fault is it?</strong></p>
<p>And the guilty one? Several are to blame.</p>
<p>First; the Piradius (again&#8230;) network doing SIP and H.323 scans on open phones and gateways.<br />
Second; the phone producer not making a secure enough phone.<br />
Third; the people putting such a solution onto the Internet with no security.</p>
<p><strong>What the attacker did</strong></p>
<p>The Piradius network was scanning the network sequential and sending H.323 Call Connect to each IP address. The phones were open to invites from any IP address. The phones then rang, and when answered by some people  there were nobody in the other end.</p>
<p><strong>Information about the packet</strong></p>
<p>In the h.323 packet the claim to use <a href="http://www.cisco.com" target="_blank">Cisco</a> equipment, but I&#8217;ve never heard about a <em>&#8220;balhophone&#8221;. </em>If you do know, please comment! The version does sound too suspicious (1.666666). I&#8217;m guessing on an <a href="http://www.asterisk.org">Asterisk&#8230;.</a></p>
<pre>vendor
           t35CountryCode: United States (181)
            t35Extension: 0
           manufacturerCode: 18
                             H.221 Manufacturer: Cisco (0xb5000012)
                            productId: balhophone
                            versionId: v 1.666666</pre>
<p>The contact information within the H.323 packet for audio so totally different from where the TCP traffic is originated from. It is an unallocated space.</p>
<pre>AS  | IP             | BGP Prefix   | CC | Registry | Allocated  | AS Name
NA | 36.27.177.136   | NA           |    |          |            | NA</pre>
<p>The attacker has just used this IP address as a /dev/null for the audio of those that actually answered the phone. This RTP traffic back from mass calling can be a DoS attack in itself. If every packet you send on 1500 bytes generates a continues stream of 0,1Mbit (G711), it could take down the attacker itself&#8230;.</p>
<p><strong>The called number</strong></p>
<p>Called party number: &#8216;40#5926693444&#8242;</p>
<p>I&#8217;ve seen that they do include the # in several attacks previously, but this is not used in any part of Scandinavia to make an outbound call. If you know why an attacker is using the #, please let me know.<br />
<script type="text/javascript"><!--
google_ad_client = "pub-1177893919351833";
google_ad_slot = "0971638747";
google_ad_width = 468;
google_ad_height = 60;
//--></script>
<script type="text/javascript" src="http://pagead2.googlesyndication.com/pagead/show_ads.js"></script>
</p>
]]></content:encoded>
			<wfw:commentRss>http://www.usken.no/2009/01/voip-attacks-are-here-again/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Asterisk vulnerabilites can be abused</title>
		<link>http://www.usken.no/2008/12/asterisk-vulnerabilites-can-be-abused/</link>
		<comments>http://www.usken.no/2008/12/asterisk-vulnerabilites-can-be-abused/#comments</comments>
		<pubDate>Sat, 06 Dec 2008 12:39:40 +0000</pubDate>
		<dc:creator>sjur</dc:creator>
				<category><![CDATA[VoIP]]></category>
		<category><![CDATA[asterisk]]></category>
		<category><![CDATA[fbi]]></category>
		<category><![CDATA[fraud]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://www.usken.no/?p=117</guid>
		<description><![CDATA[I remember in the old times when Cisco was running the Call Manager on a Windows 2000 system. The Call Manager servers were always six months behind with patches and updates, and had to be protected at all costs. Caution has to be taken as always when enabling new services, and especially when it can [...]]]></description>
			<content:encoded><![CDATA[<p>I remember in the old times when <a href="www.cisco.com">Cisco</a> was running the Call Manager on a Windows 2000 system. The Call Manager servers were always six months behind with patches and updates, and had to be protected at all costs. Caution has to be taken as always when enabling new services, and especially when it can hurt financially. PC World reports that &#8220;yes, you can abuse Asterisk with a bug for a time ago&#8221; in this <a href="http://www.pcworld.com/businesscenter/article/155074/fbi_criminals_autodialing_with_hacked_voip_systems.html">article. </a> They sited the <a href="http://www.ic3.gov">IC3s</a> <a href="http://www.ic3.gov/media/2008/081205-2.aspx">article</a> about VoIP fraud.</p>
<p>Do we need another firewall for all new services? There are several Media specialized firewalls, often called <a href="http://en.wikipedia.org/wiki/Session_border_controller">Session Border Controller</a> that does this, but is this the way to do it? Probably not. IMHO it is to have a good security audit and overview of your own infrastructure, take control! Don&#8217;t buy yourself out of the current biggest threats, there will be new! Take control with <a href="http://en.wikipedia.org/wiki/Intrusion_detection_system">IDS</a> and even <a href="http://en.wikipedia.org/wiki/Intrusion-prevention_system">IPS,</a> and have backup plans in case serious bugs and flaws makes your services vulnerable!</p>
<p>And good there is several other people talking about security, like <a href="http://voipsecurityblog.typepad.com/">Mark Collier</a> and the folks behind the <a href="http://www.blueboxpodcast.com/">bluebox security podcast!</a> Good job!</p>
<p><script type="text/javascript"><!--
google_ad_client = "pub-1177893919351833";
google_ad_slot = "0971638747";
google_ad_width = 468;
google_ad_height = 60;
//--></script>
<script type="text/javascript" src="http://pagead2.googlesyndication.com/pagead/show_ads.js"></script>
</p>
]]></content:encoded>
			<wfw:commentRss>http://www.usken.no/2008/12/asterisk-vulnerabilites-can-be-abused/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>VoIP system abused in an English bank service company&#8230;</title>
		<link>http://www.usken.no/2008/11/voip-system-abused-in-an-english-bank/</link>
		<comments>http://www.usken.no/2008/11/voip-system-abused-in-an-english-bank/#comments</comments>
		<pubDate>Thu, 20 Nov 2008 20:45:35 +0000</pubDate>
		<dc:creator>sjur</dc:creator>
				<category><![CDATA[VoIP]]></category>
		<category><![CDATA[bank]]></category>
		<category><![CDATA[banking]]></category>
		<category><![CDATA[fraud]]></category>
		<category><![CDATA[hack]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://www.usken.no/?p=98</guid>
		<description><![CDATA[I&#8217;ve had several responses to my previous article about VoIP attacks, and people are approaching the Honeynet organisation for help to figure out what they to do after being abused.  This is both good and bad. Good that they seek help, bad that they do not have a IT security plan.
IT hacking costs money, [...]]]></description>
			<content:encoded><![CDATA[<p>I&#8217;ve had several responses to my previous article about VoIP attacks, and people are approaching the <a href="http://www.honeynor.no">Honeynet </a>organisation for help to figure out what they to do after being abused.  This is both good and bad. Good that they seek help, bad that they do not have a IT security plan.</p>
<p>IT hacking costs money, and when implementing mis configured VoIP it shows up on the telephony bill as well. Previously it was costs that were not that obvious, down-time for the firm, stolen documents used against them in business competitions or just abuse of their Internet bandwidth to hurt others. How would the world been if all the security faults a firm had would show up on their monthly Internet bill? <em>&#8220;Your computers have been participating in a DDoS attacking costing a firm 5 million, this is your cost&#8221;</em></p>
<p>The companies need to take security more serious. It is a war going on on the Internet where the strongest one will survive. And the war has begun for a long time ago&#8230;<br />
<script type="text/javascript"><!--
google_ad_client = "pub-1177893919351833";
google_ad_slot = "0971638747";
google_ad_width = 468;
google_ad_height = 60;
//--></script>
<script type="text/javascript" src="http://pagead2.googlesyndication.com/pagead/show_ads.js"></script>
</p>
]]></content:encoded>
			<wfw:commentRss>http://www.usken.no/2008/11/voip-system-abused-in-an-english-bank/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
