ML
    • Recent
    • Categories
    • Tags
    • Popular
    • Users
    • Groups
    • Register
    • Login

    Business Stuck With Massive Bill After Phones Hacked

    News
    pbx phone system hacked security
    5
    15
    2.1k
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • scottalanmillerS
      scottalanmiller @AdamF
      last edited by

      @fuznutz04 said in Business Stuck With Massive Bill After Phones Hacked:

      1. Same question, but for web access.

      For us at @NTG this is really about the customer. Some want it from anywhere, some never use it. If they never use it, best to just turn it off completely.

      AdamFA 1 Reply Last reply Reply Quote 2
      • AdamFA
        AdamF @scottalanmiller
        last edited by

        @scottalanmiller Meaning that if SSH is turned off, you only access it from console?

        scottalanmillerS 1 Reply Last reply Reply Quote 0
        • scottalanmillerS
          scottalanmiller @AdamF
          last edited by

          @fuznutz04 said in Business Stuck With Massive Bill After Phones Hacked:

          @scottalanmiller Meaning that if SSH is turned off, you only access it from console?

          No, not only the console and we "never" use console access (admins don't get console access so that would be problematic, but we have some minor separation of duties there so effectively the console would only exist as an option in a break glass scenario where an admin like @Mike-Ralston escalated to either @art_of_shred or myself in order to get console access - I'm really the only crossover person) but we use Salt so there isn't need for login access at all (or we use Salt to turn it on at least.)

          AdamFA 1 Reply Last reply Reply Quote 0
          • Reid CooperR
            Reid Cooper
            last edited by

            Two hundred calls is not that many. 200x2 is 400 hours of calls, max. That's 24,000 minutes. First call rate that I found is $.89/min. So that could be around $22K. But only if their PBX allowed 200 simultaneous calls and all of them ran the full duration of the two hours.

            If this was loads of normal calls of a few minutes, how much was this bill really?

            coliverC 1 Reply Last reply Reply Quote 1
            • coliverC
              coliver @Reid Cooper
              last edited by

              @Reid-Cooper I'm wondering if they were calling a toll-line. That's the only thing that makes sense in this instance.

              Reid CooperR 1 Reply Last reply Reply Quote 0
              • Reid CooperR
                Reid Cooper @coliver
                last edited by

                @coliver said in Business Stuck With Massive Bill After Phones Hacked:

                @Reid-Cooper I'm wondering if they were calling a toll-line. That's the only thing that makes sense in this instance.

                Does Cuba have toll lines? They might not.

                1 Reply Last reply Reply Quote 0
                • AdamFA
                  AdamF @scottalanmiller
                  last edited by

                  @scottalanmiller said in Business Stuck With Massive Bill After Phones Hacked:

                  @fuznutz04 said in Business Stuck With Massive Bill After Phones Hacked:

                  1. Same question, but for web access.

                  For us at @NTG this is really about the customer. Some want it from anywhere, some never use it. If they never use it, best to just turn it off completely.

                  But again, in this scenario, if YOU would need it to make some changes, then you just turn it on via Salt, make changes, then turn if off?

                  1 Reply Last reply Reply Quote 0
                  • AdamFA
                    AdamF @scottalanmiller
                    last edited by

                    @scottalanmiller said in Business Stuck With Massive Bill After Phones Hacked:

                    @fuznutz04 said in Business Stuck With Massive Bill After Phones Hacked:

                    @scottalanmiller Meaning that if SSH is turned off, you only access it from console?

                    No, not only the console and we "never" use console access (admins don't get console access so that would be problematic, but we have some minor separation of duties there so effectively the console would only exist as an option in a break glass scenario where an admin like @Mike-Ralston escalated to either @art_of_shred or myself in order to get console access - I'm really the only crossover person) but we use Salt so there isn't need for login access at all (or we use Salt to turn it on at least.)

                    This is an interesting concept that I'd like to move to eventually. I need to get more up to speed with Salt however before moving to this route.

                    Idea for Mangocon 2017. Saltstack!

                    scottalanmillerS 1 Reply Last reply Reply Quote 2
                    • scottalanmillerS
                      scottalanmiller @AdamF
                      last edited by

                      @fuznutz04 said in Business Stuck With Massive Bill After Phones Hacked:

                      @scottalanmiller said in Business Stuck With Massive Bill After Phones Hacked:

                      @fuznutz04 said in Business Stuck With Massive Bill After Phones Hacked:

                      @scottalanmiller Meaning that if SSH is turned off, you only access it from console?

                      No, not only the console and we "never" use console access (admins don't get console access so that would be problematic, but we have some minor separation of duties there so effectively the console would only exist as an option in a break glass scenario where an admin like @Mike-Ralston escalated to either @art_of_shred or myself in order to get console access - I'm really the only crossover person) but we use Salt so there isn't need for login access at all (or we use Salt to turn it on at least.)

                      This is an interesting concept that I'd like to move to eventually. I need to get more up to speed with Salt however before moving to this route.

                      Idea for Mangocon 2017. Saltstack!

                      It's on the agenda. Not Salt specifically, but the concepts. It's the "State of the Art in System Administration" presentation that @art_of_shred and I are doing.

                      1 Reply Last reply Reply Quote 2
                      • scottalanmillerS
                        scottalanmiller
                        last edited by

                        I believe that @QuixoticJeremy is doing a talk about something kind of similar.

                        1 Reply Last reply Reply Quote 1
                        • 1 / 1
                        • First post
                          Last post