[cisco-voip] E1 call Fraud + h.323 Gw

ccieid1ot ccieid1ot at gmail.com
Sat Jan 15 21:08:50 EST 2011


Change your call-forward pattern to local numbers only.

duy
ccie #27737 voice

tmobile g2
On Jan 15, 2011 12:29 PM, "Jawad A Hai" <ahjawad at hotmail.com> wrote:
> Hello Group,
>
> Recently I faced a problem with one of my client, who has got E1r2,
DID/DOD.
> He has Cisco CME and Cisco Voice Gateway.
> Suddenly all 30 ports got busy with international calls. All the calls are
being generated by ONE IP Phone which has got local extension 2000.
> This extension was translated to DID number, so that any call goes out via
this number takes the DID and any call comes on this DID will land on this
Phone.
> The CME was configured to access via outside with live IP. ie Live IP to
Local IP (NAT).
> Now the thing here is all the calls which were generated are international
calls, we rebooted the gw, we rebooted the CME it stayed same..once it
reboots all 30 ports got busy with international calls.
> calls going to african countries/russian countries( dial codes belongs to
these countries).
> When I changed the international dial peer on the CME they stopped.
> But catch here is they have received more than 100 k USD bill from TELCO.
DEAD DEAD Bang Bang.
> What are the chances of toll Fraud or any other way of hacking ?
> OR could it be TELCO side issue?
> Cuz I see mostly calls are being generated by single DID number ??
>
> Aali
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <https://puck.nether.net/pipermail/cisco-voip/attachments/20110115/421438a5/attachment.html>


More information about the cisco-voip mailing list