top
search
sender
user
myhome
Alliant is heating up 2010 – GET our Great Expertise and Personal Service in March -- Just e-mail ANY competitor quote to sales@goalliant.net and Alliant will BEAT it by 5% or more. Partner with Alliant NOW and in the New Year! We are here to be of service."We are manufacturer-neutral and application specific. Our experienced certified engineers deploy and support our “complete voice & data solutions” worldwide. Celebrating 14 years of excellence. JOIN one of our Zultys Webinars, see http://alliant.eventbrite.com/ for Details! >>>Your Innovation Partner for Converged IT Solutions.. GO ALLIANT!
Events

Dial Tone/Internet

A Single Point of Contact for All Your Telecom Needs

Today's telecom industry offers more choices than ever before: traditional and basic business line (POTS), switched long distance, dedicated long distance, DSL, integrated T1, PRI SIP, Trunking, Metro E, MPLS, and DS3...But as the list keeps growing, this multitude of options can start to seem like too much of a good thing.

click below for real time quotes

If you're not sure which services are the best fit for your budget and business requirements, Alliant DataTel can help.

Our certified staff of telecom consultants can do it all: analyze your needs, negotiate the best deal, manage the installation of your telecom services, and audit your billing.

Technical Support

We have Factory Certified Technicians who are trained in the installation of phone networks and business systems. We resell new and used business telephone systems from small to mid-size businesses. That includes the actual phone systems; TDM & IP-PBX, voicemail systems, additions such as message on hold, battery back-up, headsets, etc.

Prevent Your Business From Falling Victim To Dial Through Fraud

What steps would you take to protect your business from a burglar coming in after office hours and stealing £40,000? I suspect that you would make sure that all the doors have very good locks. You would install a burglar alarm and maybe even have CCTV surveillance. That should protect your business. Wrong! The burglar did not break into your office; they broke into your internal phone exchange (PBX). Unseen by human or electronic eyes, thousands of pounds are being spent on international telephone calls and your business will pay the bill.

How Does It Work? Dial through fraud is not a new problem, it just has limited publicity. It exploits a PBX feature that allows employees to ring in to the switchboard and by keying certain dialling codes, make national and international calls for which the company will pay the bill.

Many businesses will take an “It will never happen to me” approach to dial through fraud, even though most business PBXs are setup to be maintained remotely. This is to allow engineers from a maintenance company to make changes to the configuration without needing to make a site visit but it exposes the PBX. The administration port on the PBX will be connected to a modem that in turn is connected to an extension on the PBX.

Using trial and error, hackers will identify the number that this modem is on. The default passwords like “admin”, “0000″ or “1234″ will be tried first. Even if the password has been changed, there are plenty of free utilities on the Internet that will use brute force to try every number and letter combination until the right password is found. It has been known for 16 character passcodes to be cracked in this way.

Once the hacker has gained administrative access to your PBX, they will identify unused extension numbers and set them up to allow dial through using the company PSTN lines. For the cost of a local phone call, the hacker can be making calls to the Middle East, Far East, Africa, Australasia, etc. Some of these calls could be costing the business up to £3 a minute.

To compound the problem, the hacker will usually set up a disguised PBX that routes its calls through the company PBX. The hacker will then operate a “Call Sell”; selling international calls to customers at cheap rates. Alternatively they could make calls to their own premium rate revenue share services. It is possible that during the 15 hours when your office is closed, up to 10 simultaneous calls could be occurring. And that is just for one day! The problem is likely to go unnoticed and unresolved until the phone bill arrives at the end of the month.

It Will Never Happen To Me A recent report in the Guardian highlighted the plight of one UK Company that suffered from a fraud attack. The company had secured its PBX with a 16 character password but it was still compromised. The discovery of the fraud was by pure chance when the MD of the company came into the office early one day to find the lights on the telephone switchboard lit up like a Christmas tree, even though he was the only one in the office.

The report showed that recovering the losses was not easy. Although the company’s Telco admitted that the calls were fraudulent, it was not their responsibility to secure the customer’s equipment from attack. Therefore the customer was liable for any calls made through the PBX. It was also discovered that the company’s insurance policy had a standard clause exempting it from any “electronic losses”.

A Matter For The Police Surely if a fraud has been perpetrated, then the police should investigate the matter? This is true. The Regulation of Investigatory Powers Act 2000 (Ripa) gives police the power to request “intercept data” from the Telco that would identify the origin of the inbound calls into the PBX. Under the act, a Telco is allowed to charge up to £1,500 to cover their costs of retrieving the data asked for by the police. This means that in every case, the police must decide whether the financial losses involved in the fraud justifies the cost of the “intercept data”. For big losses, the answer is likely to be yes every time. However, in small cases involving just a few hundred or few thousand pounds, the answer may not be so clear cut.

How Can It Be Prevented The most obvious way is not to allow remote access to the administration facilities of the PBX. However this may not be practical and could lead to increased charges from the maintenance company. The second method is to use a very random password on the PBX, up to the maximum number of characters and to lock the modem so that it will only answer calls from a single phone number. This solution is very inflexible and after a while could be turned off if it becomes impractical.

Ideally, you would want a solution that could offer the following benefits:

  1. Use a modem that employs authenticated encryption to prevent hackers with standard modems from being able to connect.
  2. Some hardware to act as an intermediary between the connection and the PBX. The hardware could then determine through a username/password what level of access to give to the PBX.
  3. The hardware should proactively monitor the PBX looking for the first signs of fraudulent activity.

Secure Access Modems
Secure access modems tend to be hardware based. One modem is connected to the PBX, while one or more modems are deployed in the field. The modems use an encrypted secret key and a unique ID to provide a challenge/response to incoming calls. Consequently only a modem with a matching encrypted secret key, using an ID that is allowed by the PBX modem will be able to connect.

This provides a more flexible alternative to calling from a single phone number. The modem is self contained and does not require any special software. It is unlikely that a random hacker using a standard modem will be able to breach this initial barrier.

Hardware Acting As An Intermediary
If you use a hardware appliance, it can act as a gateway between the PBX and the user. It could log all login attempts. It could be configured to send out an alert (as an email for example) when it detects multiple login failures. This type of behaviour would occur if a hacker was using a brute force attack to try and discover the password.

Different combinations of usernames and passwords could be given different levels of access to the PBX. Users can therefore be restricted to performing only certain actions from a limited menu choice. This prevents the hacker from gaining full unrestricted access to all of the administration functionality.

Proactively Monitoring For Dial Through Fraud
A dial through fraud solution can proactively monitor the call output from the PBX. It can be set to look for suspicious call activity. In the case of the company featured in the Guardian article, this would use a “ruleset” to look for any call that occurred outside of office hours. When suspicious activity is detected, an alert would be sent out containing the details. This allows an appropriate response to be taken, reducing the potential losses caused by the fraud.

Dial through fraud can very quickly and silently cause thousands of pounds worth of losses to a business. The standard security precautions in place to prevent it are weak, especially compared to those used on IT networks. Trying to recover any loss is as difficult as detecting the fraud in the first instance. Data Track can offer a range of Tracker Solutions [http://www.datatrackplc.com/Tracker%20Platform/6] that will not only add extra security to your PBX but also provide a means of detecting losses before they progress too far.

Author: Dominic Martin
Article Source: EzineArticles.com
Provided by: Wordpress plugin expert

  • Share/Bookmark
Blog Traffic Exchange Related Posts
  • blog traffic exchangePBX Toll Fraud Protection - The "Extention 900" Scam Toll fraud is, or should be, a concern for any business with a telephone system. There are many scams that hackers may use to attempt to steal your business telephone system potentially costing your business thousands of dollars over a single weekend. The purpose of this article is to......
  • blog traffic exchangeVoip Providers Review--- Choose The Best One For Your Business Making phone calls applying a broadband Internet connection,known as VoIP (Voice over Internet Protocol), is becoming so popular with corporations of each size. The prospect of paying a flat fee for unlimited long-distance phone calls is attractive to each company that has struggled to balance the want to conduct......
  • blog traffic exchange9 Ways to Slash Phone Costs and Increase Productivity With Hosted VoIP 1. Switch to VoIP No matter what your industry, call costs for business VoIP service is significantly cheaper than call costs for analog phone service. Also, almost all Internet telephony providers promote a free 30 day money back guarantee and offer domestic long distance calls at no additional cost.......
  • blog traffic exchange4 Ways a Virtual PBX Can Aid a Small Business Information and communication are the lifelines of small to medium-sized businesses. Blockages in the flow of day-to-day communication can not only prove to be irksome and inefficient, but can result in costly collateral repercussions. Inefficient modes of communication cause confusion and result in lost calls and sales. However, communication......
  • blog traffic exchangeVoIP PBX Solutions For Businesses - What To Look For Business communications has always been a challenging arena for management....subject to cost, function, reliability, and other pressures and concerns. The emergence of VoIP technology....and specifically application to PBX systems via IP based protocols....has provided an enormous opportunity for companies to reap many benefits.Many companies today have multiple office locations around......
Blog Traffic Exchange Related Websites
  • hook-line-and-sinker-toastyken20 Ways to Avoid a Scam When a recession hits, everyone hurts... even the scam artists. Problem is, during times of economic distress (e.g. a recession or depression) the victim is hurting more than usual and any short term financial hit can put them into a cash flow crunch.  Money can become so tight that a scam victim might be forced......
  • The end of the office... and the future of work  (photo - istockphoto)The end of the office... and the future of work [/caption] By Drake Bennett By the end of the month, a company called txteagle will be the largest employer in Kenya. The firm, started in its original form in 2008 by a young computer engineer named Nathan Eagle and, as of this coming June, based in Boston, will have 10,000......
  • american express bankIrony: Credit Card Company Desperate For Credit American Express, often referred to as Amex, has decided it will become a commercial bank. Like Morgan Stanley and Goldman Sachs before it, Amex has determined it is better off under the more regulated role of a bank holding company. With it comes the good and the bad. The......
  • 12364944_14794d1055_mWhy Don't Companies Want My Business?? I am a business woman. I expanded my Dad's company to a whole different state. I am a saleswoman. And how did I do all this? By being humble and giving my customers great customer service. It's something we actually boast about. Most of my customers are my customers because they like......
  • money-tool.jpgThe Future of Personal Finance Tools Nearly two months ago, I mentioned that Expensr and NetworthIQ (now Money Strands) had invited some personal finance bloggers to talk about personal finance software. I learned quite a few things, but one thing stood out to me. When you have 20 people in a room, you are going......

Related posts:

  1. How To Prevent Toll Fraud
  2. PBX Toll Fraud Protection – The “Extention 900″ Scam
  3. Phone Fraud Still a Problem For US Businesses
  4. Toll Fraud Security and DISA
  5. Dial by Name Directory Vs Staff Extension Listing For Phone Systems

You must be logged in to post a comment.