Attacks/Breaches
9/29/2010
04:24 PM
Connect Directly
Google+
Twitter
RSS
E-Mail
50%
50%
Repost This

VoIP Abuse Project Blacklists Attackers

Fraudsters target, hack VoIP servers mainly as a vehicle for stealing financial data

A security expert at a managed services provider has kicked off a project to expose and blacklist the networks hosting VoIP attacks against his and other companies' VoIP PBX servers. The VoIP Abuse Project uses a honeypot to gather as much data as it can from incoming VoIP attacks, including the IP address and a recording of what the call was sending.

Some operators of the offending networks are unaware that their VoIP systems have been hacked and are being used to place fraudulent calls. The attacks range from brute-force hacking to acquire usernames and passwords of the VoIP systems to callers posing as a customer's bank in order to convince victims to hand over their bank account numbers.

J. Oquendo, the security engineer who built the so-called Arkeos VoIP honeypot that runs the VoIP Abuse Project, says he decided to launch the VoIP abuse project because he was tired of seeing brute-force attempts against VoIP PBXes and having to contact the organizations whose networks were being used in the attacks -- only to often be ignored. He also wanted to make other companies with VoIP PBX servers on the Internet aware of the threat and actual attacks out there so they could block them.

VoIP attacks have been on the upswing. Oquendo says that two- to three years ago, he would witness two or three attacks every other day. Now he sees three to four VoIP attacks per day. "I want other engineers and operators to be aware of this. There's a high cost for toll fraud because you have to mitigate it, and there's the potential for a denial-of-service (DoS) attack if the service is overwhelmed," he says. "There are lots of ways it can adversely affect you."

One of his company's clients that was compromised by VoIP attackers suffered $260,000 in losses. "They gave me a tally of the costs and the number was shocking," says Oquendo, who helped them pinpoint the offending equipment and to clean up the network while also keeping the client's service online.

The victim company's servers were being used to place thousands of expensive calls, to Romania and Sierra Leone, for instance, all the while saturating the network's bandwidth and affecting the company's legitimate VoIP customers. The company lost clients as a result of dropped calls and poor quality due to the VoIP attack, and Oquendo says it took him six weeks to clean up the network.

Attackers today are moving beyond scanning for open hosts and placing thousands of calls to more targeted attacks, many aimed at stealing credit card or other financial information. Oquendo says his PBX listens in as a user tries to register for VoIP, and then has the call ring through to his honeypot VoIP system, which mimics a phone. "I get to record the voicemail of what they are trying to send through," he says. "Mainly the recordings are, 'This is your bank and your account has been suspended. Enter your account number.'"

Most of the brute-force VoIP attacks originate out of China and Romania, he says. "And more of the calls go through Romania than anywhere else," he says.

The weakest link in VoIP servers is the same as email accounts: weak usernames and passwords. Oquendo says his blacklist is one way to expedite an investigation into a VoIP attack. Law enforcement efforts in these cases are time-consuming and difficult, especially when they cross jurisdictional boundaries, he says.

"The VoIP Abuse Project exposes the addresses of attackers attacking not only my servers, but some of my clients' servers and a few other servers who contribute data to us," Oquendo says. "What I try my best to do is figure out who owns the IP space, send them the abuse email, await a response, then post the attackers' information."

Have a comment on this story? Please click "Discuss" below. If you'd like to contact Dark Reading's editors directly, send us a message.

Kelly Jackson Higgins is Senior Editor at DarkReading.com. She is an award-winning veteran technology and business journalist with more than two decades of experience in reporting and editing for various publications, including Network Computing, Secure Enterprise Magazine, ... View Full Bio

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2012-3946
Published: 2014-04-24
Cisco IOS before 15.3(2)S allows remote attackers to bypass interface ACL restrictions in opportunistic circumstances by sending IPv6 packets in an unspecified scenario in which expected packet drops do not occur for "a small percentage" of the packets, aka Bug ID CSCty73682.

CVE-2012-5723
Published: 2014-04-24
Cisco ASR 1000 devices with software before 3.8S, when BDI routing is enabled, allow remote attackers to cause a denial of service (device reload) via crafted (1) broadcast or (2) multicast ICMP packets with fragmentation, aka Bug ID CSCub55948.

CVE-2013-6738
Published: 2014-04-24
Cross-site scripting (XSS) vulnerability in IBM SmartCloud Analytics Log Analysis 1.1 and 1.2 before 1.2.0.0-CSI-SCALA-IF0003 allows remote attackers to inject arbitrary web script or HTML via an invalid query parameter in a response from an OAuth authorization endpoint.

CVE-2014-0188
Published: 2014-04-24
The openshift-origin-broker in Red Hat OpenShift Enterprise 2.0.5, 1.2.7, and earlier does not properly handle authentication requests from the remote-user auth plugin, which allows remote attackers to bypass authentication and impersonate arbitrary users via the X-Remote-User header in a request to...

CVE-2014-2391
Published: 2014-04-24
The password recovery service in Open-Xchange AppSuite before 7.2.2-rev20, 7.4.1 before 7.4.1-rev11, and 7.4.2 before 7.4.2-rev13 makes an improper decision about the sensitivity of a string representing a previously used but currently invalid password, which allows remote attackers to obtain potent...

Best of the Web