ML
    • Recent
    • Categories
    • Tags
    • Popular
    • Users
    • Groups
    • Register
    • Login

    Business Stuck With Massive Bill After Phones Hacked

    News
    pbx phone system hacked security
    5
    15
    2.1k
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • gjacobseG
      gjacobse
      last edited by

      Business Stuck With Massive Bill After Phones Hacked

      CLARK COUNTY, KY (Lex 18) - A Winchester small business was stuck with a crippling phone bill after the company president said the phone system was hacked.

      On payroll day for New Moon Medical President Ben Worthington had to be very sure about each check he writes. Because of what happened one night a few weeks ago, he's pinching every penny.

      "We found out that somebody had hacked the phone system and used the system to dial international calls," Worthington explained.

      He said he learned the hackers made more than 200 calls in 2 hours, to be exact. Each call went to the same phone number in Buenavista, Cuba.

      1 Reply Last reply Reply Quote 3
      • scottalanmillerS
        scottalanmiller
        last edited by

        I wonder why they left calling to Cuba enabled with the carrier?

        gjacobseG 1 Reply Last reply Reply Quote 3
        • gjacobseG
          gjacobse @scottalanmiller
          last edited by

          @scottalanmiller said in Business Stuck With Massive Bill After Phones Hacked:

          I wonder why they left calling to Cuba enabled with the carrier?

          Difficult to say - Who manages their phone system (not NTG) - Are they experienced? and so many other questions...

          My first guess - Spectrum themselves are 'responsible' -

          1 Reply Last reply Reply Quote 0
          • AdamFA
            AdamF
            last edited by

            This would be a good time to discuss best practices for phone systems.

            For example:

            1. If you're PBX is cloud hosted, do you allow access to SSH access to it from anywhere, of do you only allow access from specific IPs?
            2. Same question, but for web access.
            3. What other methods are you taking to secure your PBX?
            scottalanmillerS 2 Replies Last reply Reply Quote 1
            • scottalanmillerS
              scottalanmiller @AdamF
              last edited by

              @fuznutz04 said in Business Stuck With Massive Bill After Phones Hacked:

              This would be a good time to discuss best practices for phone systems.

              For example:

              1. If you're PBX is cloud hosted, do you allow access to SSH access to it from anywhere, of do you only allow access from specific IPs?

              We are working on moving that to "no SSH at all", but it's currently more "SSH turned on when needed and turned off when done."

              AdamFA 1 Reply Last reply Reply Quote 1
              • scottalanmillerS
                scottalanmiller @AdamF
                last edited by

                @fuznutz04 said in Business Stuck With Massive Bill After Phones Hacked:

                1. Same question, but for web access.

                For us at @NTG this is really about the customer. Some want it from anywhere, some never use it. If they never use it, best to just turn it off completely.

                AdamFA 1 Reply Last reply Reply Quote 2
                • AdamFA
                  AdamF @scottalanmiller
                  last edited by

                  @scottalanmiller Meaning that if SSH is turned off, you only access it from console?

                  scottalanmillerS 1 Reply Last reply Reply Quote 0
                  • scottalanmillerS
                    scottalanmiller @AdamF
                    last edited by

                    @fuznutz04 said in Business Stuck With Massive Bill After Phones Hacked:

                    @scottalanmiller Meaning that if SSH is turned off, you only access it from console?

                    No, not only the console and we "never" use console access (admins don't get console access so that would be problematic, but we have some minor separation of duties there so effectively the console would only exist as an option in a break glass scenario where an admin like @Mike-Ralston escalated to either @art_of_shred or myself in order to get console access - I'm really the only crossover person) but we use Salt so there isn't need for login access at all (or we use Salt to turn it on at least.)

                    AdamFA 1 Reply Last reply Reply Quote 0
                    • Reid CooperR
                      Reid Cooper
                      last edited by

                      Two hundred calls is not that many. 200x2 is 400 hours of calls, max. That's 24,000 minutes. First call rate that I found is $.89/min. So that could be around $22K. But only if their PBX allowed 200 simultaneous calls and all of them ran the full duration of the two hours.

                      If this was loads of normal calls of a few minutes, how much was this bill really?

                      coliverC 1 Reply Last reply Reply Quote 1
                      • coliverC
                        coliver @Reid Cooper
                        last edited by

                        @Reid-Cooper I'm wondering if they were calling a toll-line. That's the only thing that makes sense in this instance.

                        Reid CooperR 1 Reply Last reply Reply Quote 0
                        • Reid CooperR
                          Reid Cooper @coliver
                          last edited by

                          @coliver said in Business Stuck With Massive Bill After Phones Hacked:

                          @Reid-Cooper I'm wondering if they were calling a toll-line. That's the only thing that makes sense in this instance.

                          Does Cuba have toll lines? They might not.

                          1 Reply Last reply Reply Quote 0
                          • AdamFA
                            AdamF @scottalanmiller
                            last edited by

                            @scottalanmiller said in Business Stuck With Massive Bill After Phones Hacked:

                            @fuznutz04 said in Business Stuck With Massive Bill After Phones Hacked:

                            1. Same question, but for web access.

                            For us at @NTG this is really about the customer. Some want it from anywhere, some never use it. If they never use it, best to just turn it off completely.

                            But again, in this scenario, if YOU would need it to make some changes, then you just turn it on via Salt, make changes, then turn if off?

                            1 Reply Last reply Reply Quote 0
                            • AdamFA
                              AdamF @scottalanmiller
                              last edited by

                              @scottalanmiller said in Business Stuck With Massive Bill After Phones Hacked:

                              @fuznutz04 said in Business Stuck With Massive Bill After Phones Hacked:

                              @scottalanmiller Meaning that if SSH is turned off, you only access it from console?

                              No, not only the console and we "never" use console access (admins don't get console access so that would be problematic, but we have some minor separation of duties there so effectively the console would only exist as an option in a break glass scenario where an admin like @Mike-Ralston escalated to either @art_of_shred or myself in order to get console access - I'm really the only crossover person) but we use Salt so there isn't need for login access at all (or we use Salt to turn it on at least.)

                              This is an interesting concept that I'd like to move to eventually. I need to get more up to speed with Salt however before moving to this route.

                              Idea for Mangocon 2017. Saltstack!

                              scottalanmillerS 1 Reply Last reply Reply Quote 2
                              • scottalanmillerS
                                scottalanmiller @AdamF
                                last edited by

                                @fuznutz04 said in Business Stuck With Massive Bill After Phones Hacked:

                                @scottalanmiller said in Business Stuck With Massive Bill After Phones Hacked:

                                @fuznutz04 said in Business Stuck With Massive Bill After Phones Hacked:

                                @scottalanmiller Meaning that if SSH is turned off, you only access it from console?

                                No, not only the console and we "never" use console access (admins don't get console access so that would be problematic, but we have some minor separation of duties there so effectively the console would only exist as an option in a break glass scenario where an admin like @Mike-Ralston escalated to either @art_of_shred or myself in order to get console access - I'm really the only crossover person) but we use Salt so there isn't need for login access at all (or we use Salt to turn it on at least.)

                                This is an interesting concept that I'd like to move to eventually. I need to get more up to speed with Salt however before moving to this route.

                                Idea for Mangocon 2017. Saltstack!

                                It's on the agenda. Not Salt specifically, but the concepts. It's the "State of the Art in System Administration" presentation that @art_of_shred and I are doing.

                                1 Reply Last reply Reply Quote 2
                                • scottalanmillerS
                                  scottalanmiller
                                  last edited by

                                  I believe that @QuixoticJeremy is doing a talk about something kind of similar.

                                  1 Reply Last reply Reply Quote 1
                                  • 1 / 1
                                  • First post
                                    Last post