Your PBX has been hacked
cringely.com
Your PBX has been hacked
1–10 of 63 posts
Re: Your PBX has been hacked
#2Re: Your PBX has been hacked
#3Re: Your PBX has been hacked
#4That being said though, if you have access to ISUP fields on an incoming trunk, you can check and see if the JIP parameter matches an office corresponding to one of the two ANI fields, and route it to an operator if it doesn't. There'll always be a way to set your number to whatever you want, but if your number shows you're calling from a Centurylink phone in Seattle while the JIP corresponds to some random CLEC's switch in California, something is definitely up.
Re: Your PBX has been hacked
#5I've been wondering increasingly often over the past few years why we tolerate a phone network that allows for caller ID spoofing. I don't see how a system analogous to BCP38 would have any significant downsides, and there's a huge demand for anything that stems the rising tide of fraudulent robocalls.
And it isn't even just fraud. Charities and marketing companies also fake/alter the caller ID.
I will say that a lot of IPphone networks terminate on numbers which look like local residential numbers, so even if caller ID could not be faked, they would just not put a caller ID in at all and let it resolve to the local area code number.
Unfortunately there might be no "good" answer to fraud. Maybe some kind of reporting service?
Re: Your PBX has been hacked
#6I've been wondering increasingly often over the past few years why we tolerate a phone network that allows for caller ID spoofing. I don't see how a system analogous to BCP38 would have any significant downsides, and there's a huge demand for anything that stems the rising tide of fraudulent robocalls.
Re: Your PBX has been hacked
#7I've been wondering increasingly often over the past few years why we tolerate a phone network that allows for caller ID spoofing. I don't see how a system analogous to BCP38 would have any significant downsides, and there's a huge demand for anything that stems the rising tide of fraudulent robocalls.
It really isn't a big deal though, CID/ANI should never be trusted to identify the caller anyway.
Re: Your PBX has been hacked
#8Earlier quoted context omitted.
It really isn't a big deal though, CID/ANI should never be trusted to identify the caller anyway.
Not being able to identify the caller means I can't report it to the FTC for spamming me with "you've been approved for a $250k business loan!" and "this is cardmembers services for both Visa and Mastercard" scams.
Re: Your PBX has been hacked
#9I've been wondering increasingly often over the past few years why we tolerate a phone network that allows for caller ID spoofing. I don't see how a system analogous to BCP38 would have any significant downsides, and there's a huge demand for anything that stems the rising tide of fraudulent robocalls.
It really isn't a big deal though, CID/ANI should never be trusted to identify the caller anyway.
Re: Your PBX has been hacked
#10Easier thing we can do, is to map them down like we do it with IPs and domain names, but as usual, this is far from being a practical solution.
Best think is to let conventional telephony die and VoIP take over its place.