Live data from Hacker News

Your PBX has been hacked

cringely.com

1–10 of 63 posts

Re: Your PBX has been hacked

#2
With a cluster of Asterisk boxes and the right tools, it is easy to originate millions of calls. I was talking to a person today who is to place ~60 million calls in 20 days, and you can do that with a couple of Wombats and a small cluster of AWS boxes - plus a few willing termination providers.

Re: Your PBX has been hacked

#3
I've been wondering increasingly often over the past few years why we tolerate a phone network that allows for caller ID spoofing. I don't see how a system analogous to BCP38 would have any significant downsides, and there's a huge demand for anything that stems the rising tide of fraudulent robocalls.

Re: Your PBX has been hacked

#4
Seems like you should be able to program the auto-attendant to only allow a certain number of transfers, or make it require some unusual transfer operation, like *8 [extension] # on Audix VMSes. A lot of Nortel ones even have the option to detect sequential dialing, and pretend anything the user dials isn't in service.

That being said though, if you have access to ISUP fields on an incoming trunk, you can check and see if the JIP parameter matches an office corresponding to one of the two ANI fields, and route it to an operator if it doesn't. There'll always be a way to set your number to whatever you want, but if your number shows you're calling from a Centurylink phone in Seattle while the JIP corresponds to some random CLEC's switch in California, something is definitely up.

Re: Your PBX has been hacked

#5
post #3

I've been wondering increasingly often over the past few years why we tolerate a phone network that allows for caller ID spoofing. I don't see how a system analogous to BCP38 would have any significant downsides, and there's a huge demand for anything that stems the rising tide of fraudulent robocalls.

Agreed.

And it isn't even just fraud. Charities and marketing companies also fake/alter the caller ID.

I will say that a lot of IPphone networks terminate on numbers which look like local residential numbers, so even if caller ID could not be faked, they would just not put a caller ID in at all and let it resolve to the local area code number.

Unfortunately there might be no "good" answer to fraud. Maybe some kind of reporting service?

Re: Your PBX has been hacked

#6
post #3

I've been wondering increasingly often over the past few years why we tolerate a phone network that allows for caller ID spoofing. I don't see how a system analogous to BCP38 would have any significant downsides, and there's a huge demand for anything that stems the rising tide of fraudulent robocalls.

It really isn't a big deal though, CID/ANI should never be trusted to identify the caller anyway.

Re: Your PBX has been hacked

#7
post #6
post #3

I've been wondering increasingly often over the past few years why we tolerate a phone network that allows for caller ID spoofing. I don't see how a system analogous to BCP38 would have any significant downsides, and there's a huge demand for anything that stems the rising tide of fraudulent robocalls.

It really isn't a big deal though, CID/ANI should never be trusted to identify the caller anyway.

Not being able to identify the caller means I can't report it to the FTC for spamming me with "you've been approved for a $250k business loan!" and "this is cardmembers services for both Visa and Mastercard" scams.

Re: Your PBX has been hacked

#8
post #7
post #6

Earlier quoted context omitted.

It really isn't a big deal though, CID/ANI should never be trusted to identify the caller anyway.

Not being able to identify the caller means I can't report it to the FTC for spamming me with "you've been approved for a $250k business loan!" and "this is cardmembers services for both Visa and Mastercard" scams.

Why should FTC be able to help you? Phones work internationally.

Re: Your PBX has been hacked

#9
post #6
post #3

I've been wondering increasingly often over the past few years why we tolerate a phone network that allows for caller ID spoofing. I don't see how a system analogous to BCP38 would have any significant downsides, and there's a huge demand for anything that stems the rising tide of fraudulent robocalls.

It really isn't a big deal though, CID/ANI should never be trusted to identify the caller anyway.

That's only because we let that system be gamed. It doesn't have to be that way. Telcos always know who they're billing for a call; they have the capability to make caller ID reliable.

Re: Your PBX has been hacked

#10
Phone numbers are going to (eventually) disappear. They are inefficient, hard to remember and not human-friendly (they are great for computer-based routing :P ).

Easier thing we can do, is to map them down like we do it with IPs and domain names, but as usual, this is far from being a practical solution.

Best think is to let conventional telephony die and VoIP take over its place.

Post reply on HN