Attacks/Breaches
9/29/2010
04:24 PM
Connect Directly
Google+
Twitter
RSS
E-Mail
50%
50%

VoIP Abuse Project Blacklists Attackers

Fraudsters target, hack VoIP servers mainly as a vehicle for stealing financial data

A security expert at a managed services provider has kicked off a project to expose and blacklist the networks hosting VoIP attacks against his and other companies' VoIP PBX servers. The VoIP Abuse Project uses a honeypot to gather as much data as it can from incoming VoIP attacks, including the IP address and a recording of what the call was sending.

Some operators of the offending networks are unaware that their VoIP systems have been hacked and are being used to place fraudulent calls. The attacks range from brute-force hacking to acquire usernames and passwords of the VoIP systems to callers posing as a customer's bank in order to convince victims to hand over their bank account numbers.

J. Oquendo, the security engineer who built the so-called Arkeos VoIP honeypot that runs the VoIP Abuse Project, says he decided to launch the VoIP abuse project because he was tired of seeing brute-force attempts against VoIP PBXes and having to contact the organizations whose networks were being used in the attacks -- only to often be ignored. He also wanted to make other companies with VoIP PBX servers on the Internet aware of the threat and actual attacks out there so they could block them.

VoIP attacks have been on the upswing. Oquendo says that two- to three years ago, he would witness two or three attacks every other day. Now he sees three to four VoIP attacks per day. "I want other engineers and operators to be aware of this. There's a high cost for toll fraud because you have to mitigate it, and there's the potential for a denial-of-service (DoS) attack if the service is overwhelmed," he says. "There are lots of ways it can adversely affect you."

One of his company's clients that was compromised by VoIP attackers suffered $260,000 in losses. "They gave me a tally of the costs and the number was shocking," says Oquendo, who helped them pinpoint the offending equipment and to clean up the network while also keeping the client's service online.

The victim company's servers were being used to place thousands of expensive calls, to Romania and Sierra Leone, for instance, all the while saturating the network's bandwidth and affecting the company's legitimate VoIP customers. The company lost clients as a result of dropped calls and poor quality due to the VoIP attack, and Oquendo says it took him six weeks to clean up the network.

Attackers today are moving beyond scanning for open hosts and placing thousands of calls to more targeted attacks, many aimed at stealing credit card or other financial information. Oquendo says his PBX listens in as a user tries to register for VoIP, and then has the call ring through to his honeypot VoIP system, which mimics a phone. "I get to record the voicemail of what they are trying to send through," he says. "Mainly the recordings are, 'This is your bank and your account has been suspended. Enter your account number.'"

Most of the brute-force VoIP attacks originate out of China and Romania, he says. "And more of the calls go through Romania than anywhere else," he says.

The weakest link in VoIP servers is the same as email accounts: weak usernames and passwords. Oquendo says his blacklist is one way to expedite an investigation into a VoIP attack. Law enforcement efforts in these cases are time-consuming and difficult, especially when they cross jurisdictional boundaries, he says.

"The VoIP Abuse Project exposes the addresses of attackers attacking not only my servers, but some of my clients' servers and a few other servers who contribute data to us," Oquendo says. "What I try my best to do is figure out who owns the IP space, send them the abuse email, await a response, then post the attackers' information."

Have a comment on this story? Please click "Discuss" below. If you'd like to contact Dark Reading's editors directly, send us a message.

Kelly Jackson Higgins is Executive Editor at DarkReading.com. She is an award-winning veteran technology and business journalist with more than two decades of experience in reporting and editing for various publications, including Network Computing, Secure Enterprise ... View Full Bio

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Dark Reading December Tech Digest
Experts weigh in on the pros and cons of end-user security training.
Flash Poll
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2014-5314
Published: 2014-11-23
Buffer overflow in Cybozu Office 9 and 10 before 10.1.0, Mailwise 4 and 5 before 5.1.4, and Dezie 8 before 8.1.1 allows remote authenticated users to execute arbitrary code via e-mail messages.

CVE-2014-5325
Published: 2014-11-23
The (1) DOMConverter, (2) JDOMConverter, (3) DOM4JConverter, and (4) XOMConverter functions in Direct Web Remoting (DWR) through 2.0.10 and 3.x through 3.0.RC2 allow remote attackers to read arbitrary files via DOM data containing an XML external entity declaration in conjunction with an entity refe...

CVE-2014-5326
Published: 2014-11-23
Cross-site scripting (XSS) vulnerability in Direct Web Remoting (DWR) through 2.0.10 and 3.x through 3.0.RC2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVE-2014-6477
Published: 2014-11-23
Unspecified vulnerability in the JPublisher component in Oracle Database Server 11.1.0.7, 11.2.0.3, 11.2.0.4, 12.1.0.1, and 12.1.0.2 allows remote authenticated users to affect confidentiality via unknown vectors, a different vulnerability than CVE-2014-4290, CVE-2014-4291, CVE-2014-4292, CVE-2014-4...

CVE-2014-4807
Published: 2014-11-22
Sterling Order Management in IBM Sterling Selling and Fulfillment Suite 9.3.0 before FP8 allows remote authenticated users to cause a denial of service (CPU consumption) via a '\0' character.

Best of the Web
Dark Reading Radio
Archived Dark Reading Radio
Now that the holiday season is about to begin both online and in stores, will this be yet another season of nonstop gifting to cybercriminals?