Welcome Guest. | Log In| Register | Membership Benefits
  • Email this page E-mail this page
  • |  Print Print this page
  • |   Bookmark and Share

Two Charged in VOIP Hacking Scandal

Authorities say two men ran a wholesale VOIP business using allegedly fake codes to load call traffic onto unsuspecting VOIP networks

Jun 08, 2006 | 05:00 AM

By Mark Sullivan
DarkReading

Federal authorities pressed charges Thursday against a second man who helped perpetrate a VOIP wholesale scheme that defrauded at least 15 VOIP service providers.

Robert Moore of Spokane, Wash., also known as the "Spokane Hacker," was served papers Thursday but had not yet been taken into custody, according U.S. Attorney's Office spokesman Michael Drewniak.

On Wednesday, the U.S. Attorney's Office in New Jersey had filed charges against Edwin Andres Pena, who they say set up the allegedly fraudulent wholesale business -- called Fortes Telecom Inc. -- in 2004. (See 'Free' Skype Could Be Costly.)

After charging his service provider customers cheap rates to route their calls, Pena's company secretly routed the calls over the IP networks of at least 15 VOIP providers, according to court documents.

This was done using a two-step process.

Step One. The men obscured the origin of the calls by sending them through an "intermediary." The feds believe Pena, with help from Moore, scanned the networks of companies all over the world looking for network ports to use for routing calls. The New Jersey U.S. Attorney's Office said it obtained records from AT&T Inc. (NYSE: T) showing that, between June and October of last year, Moore ran more than 6 million scans for those susceptible ports.

The two eventually decided on routing calls through a router owned by an unnamed New Jersey-based hedge fund company. (See Ingate Secures VOIP.)

Step Two. With a "blind" established, Pena then needed to gain admittance for his customers' calls to be routed onto the networks of other VOIP providers.

VOIP providers tag their own calls with a unique identifier or "prefix" so they can be admitted to the network. Pena allegedly bombarded the VOIP providers' networks with test calls -- each carrying a different prefix -- until he found one that was admitted to the network. He then tagged all his fraudelent calls with the winning prefix.

Having penetrated the networks of VOIP telephone service providers, Pena programmed the third party's computer networks to use the illegally obtained proprietary prefix to route calls of customers of his companies, federal authorities say.

The Pena case will certainly revive the issue of security among VOIP providers. Many in the VOIP community are all too aware of the security perils of running calls over the Internet. "This hacker's approach is certainly not a surprise to those in the Internet community who follow these types of issues," says Brian Lustig, spokesman for VOIP provider SunRocket Inc. . "It is just another variation of fraud that can be perpetrated."

So what does the VOIP community intend to do to protect itself from hacking? "The industry as a whole -- including Sun Rocket -- is already hard at work on standards and security measures that can prevent this type of activity," Lustig says.

Pena was taken into custody today and was scheduled to appear in court Thursday. Moore will appear in court soon, Drewniak said.

— Mark Sullivan, Reporter, Light Reading


Subscribe to RSS










Bugs
ENTERPRISE VULNERABILITIES
Vulnerability:suse linux
Published:2010-01-22
Severity:High
Description:SUSE Linux Enterprise 10 SP3 (SLE10-SP3) configures postfix to listen on all network interfaces, which might allow remote attackers to bypass intended access restrictions.
Vulnerability:ie
Published:2010-01-22
Severity:High
Description:The URL validation functionality in Microsoft Internet Explorer 7 and 8 does not properly process input parameters, which allows remote attackers to execute arbitrary local programs via a crafted URL, aka "URL Validation Vulnerability."
Vulnerability:bind
Published:2010-01-22
Severity:Medium
Description:ISC BIND 9.0.x through 9.3.x, 9.4 before 9.4.3-P5, 9.5 before 9.5.2-P2, 9.6 before 9.6.1-P3, and 9.7.0 beta does not properly validate DNSSEC (1) NSEC and (2) NSEC3 records, which allows remote attackers to add the Authenticated Data (AD) flag to a forged NXDOMAIN response for an existing domain.
Vulnerability:ie
Published:2010-01-22
Severity:High
Description:Microsoft Internet Explorer 6, 6 SP1, 7, and 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, leading to memory corruption, aka "Uninitialized Memory Corruption Vulnerability," a different vulnerability than CVE-2009-2530 and CVE-2009-2531.
Vulnerability:ie
Published:2010-01-22
Severity:High
Description:Microsoft Internet Explorer 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, leading to memory corruption, aka "Uninitialized Memory Corruption Vulnerability," a different vulnerability than CVE-2009-3671, CVE-2009-3674, and CVE-2010-0246.


Briefing Centers
POWERFUL INFORMATION
AT YOUR FINGERTIPS
(SPONSORED LINKS)