[VoiceOps] Just got hit with a new attack vector
Robert Dawson
RDawson at alliedtelecom.net
Sat Nov 17 23:23:19 EST 2012
User mailbox was compromised. The attacker called into the extension and left a voicemail while spoofing the number they wanted to call, then called back, logged into the mailbox, retrieved the message, and used the "Callback Caller" option from the playback menu to originate a call back to the spoofed number.
I disabled the option in the voice portal to mitigate further attacks. Figured it would be worth sharing.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <https://puck.nether.net/pipermail/voiceops/attachments/20121118/41a66dd3/attachment.html>
More information about the VoiceOps
mailing list