Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Attacks/Breaches

9/29/2010
04:24 PM
Connect Directly
Google+
Twitter
RSS
E-Mail
50%
50%

VoIP Abuse Project Blacklists Attackers

Fraudsters target, hack VoIP servers mainly as a vehicle for stealing financial data

A security expert at a managed services provider has kicked off a project to expose and blacklist the networks hosting VoIP attacks against his and other companies' VoIP PBX servers. The VoIP Abuse Project uses a honeypot to gather as much data as it can from incoming VoIP attacks, including the IP address and a recording of what the call was sending.

Some operators of the offending networks are unaware that their VoIP systems have been hacked and are being used to place fraudulent calls. The attacks range from brute-force hacking to acquire usernames and passwords of the VoIP systems to callers posing as a customer's bank in order to convince victims to hand over their bank account numbers.

J. Oquendo, the security engineer who built the so-called Arkeos VoIP honeypot that runs the VoIP Abuse Project, says he decided to launch the VoIP abuse project because he was tired of seeing brute-force attempts against VoIP PBXes and having to contact the organizations whose networks were being used in the attacks -- only to often be ignored. He also wanted to make other companies with VoIP PBX servers on the Internet aware of the threat and actual attacks out there so they could block them.

VoIP attacks have been on the upswing. Oquendo says that two- to three years ago, he would witness two or three attacks every other day. Now he sees three to four VoIP attacks per day. "I want other engineers and operators to be aware of this. There's a high cost for toll fraud because you have to mitigate it, and there's the potential for a denial-of-service (DoS) attack if the service is overwhelmed," he says. "There are lots of ways it can adversely affect you."

One of his company's clients that was compromised by VoIP attackers suffered $260,000 in losses. "They gave me a tally of the costs and the number was shocking," says Oquendo, who helped them pinpoint the offending equipment and to clean up the network while also keeping the client's service online.

The victim company's servers were being used to place thousands of expensive calls, to Romania and Sierra Leone, for instance, all the while saturating the network's bandwidth and affecting the company's legitimate VoIP customers. The company lost clients as a result of dropped calls and poor quality due to the VoIP attack, and Oquendo says it took him six weeks to clean up the network.

Attackers today are moving beyond scanning for open hosts and placing thousands of calls to more targeted attacks, many aimed at stealing credit card or other financial information. Oquendo says his PBX listens in as a user tries to register for VoIP, and then has the call ring through to his honeypot VoIP system, which mimics a phone. "I get to record the voicemail of what they are trying to send through," he says. "Mainly the recordings are, 'This is your bank and your account has been suspended. Enter your account number.'"

Most of the brute-force VoIP attacks originate out of China and Romania, he says. "And more of the calls go through Romania than anywhere else," he says.

The weakest link in VoIP servers is the same as email accounts: weak usernames and passwords. Oquendo says his blacklist is one way to expedite an investigation into a VoIP attack. Law enforcement efforts in these cases are time-consuming and difficult, especially when they cross jurisdictional boundaries, he says.

"The VoIP Abuse Project exposes the addresses of attackers attacking not only my servers, but some of my clients' servers and a few other servers who contribute data to us," Oquendo says. "What I try my best to do is figure out who owns the IP space, send them the abuse email, await a response, then post the attackers' information."

Have a comment on this story? Please click "Discuss" below. If you'd like to contact Dark Reading's editors directly, send us a message.

Kelly Jackson Higgins is the Executive Editor of Dark Reading. She is an award-winning veteran technology and business journalist with more than two decades of experience in reporting and editing for various publications, including Network Computing, Secure Enterprise ... View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Threaded  |  Newest First  |  Oldest First
DevSecOps: The Answer to the Cloud Security Skills Gap
Lamont Orange, Chief Information Security Officer at Netskope,  11/15/2019
Attackers' Costs Increasing as Businesses Focus on Security
Robert Lemos, Contributing Writer,  11/15/2019
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win a Starbucks Card! Click Here
Latest Comment: This comment is waiting for review by our moderators.
Current Issue
Navigating the Deluge of Security Data
In this Tech Digest, Dark Reading shares the experiences of some top security practitioners as they navigate volumes of security data. We examine some examples of how enterprises can cull this data to find the clues they need.
Flash Poll
Rethinking Enterprise Data Defense
Rethinking Enterprise Data Defense
Frustrated with recurring intrusions and breaches, cybersecurity professionals are questioning some of the industrys conventional wisdom. Heres a look at what theyre thinking about.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2011-4968
PUBLISHED: 2019-11-19
nginx http proxy module does not verify peer identity of https origin server which could facilitate man-in-the-middle attack (MITM)
CVE-2012-0824
PUBLISHED: 2019-11-19
gnusound 0.7.5 has format string issue
CVE-2012-0843
PUBLISHED: 2019-11-19
uzbl: Information disclosure via world-readable cookies storage file
CVE-2014-5439
PUBLISHED: 2019-11-19
sniffit 0.3.7 and prior: A configuration file can be leveraged to execute code as root
CVE-2011-4919
PUBLISHED: 2019-11-19
mpack 1.6 has information disclosure via eavesdropping on mails sent by other users