Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations strongm on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

BCM400 mailboxes are locking

Status
Not open for further replies.
Feb 14, 2002
137
US
Hi

I have a customer who has a BCM400 4.0.2.03 and they have been reporting that they have had many mailboxes in the office that have been locked the past few days.

I would suspect someone is attempting to hack their mailboxes but the only thing I'm not sure about is that the customer said that they had to reset the password a few times before they could log in with the default password for one of the mailboxes. Of course, it could be user error for this particular mailbox.

I wanted to ask to see if there have been any similar issues which have not been hacking.

I doubled checked the Class-of-Service and Notification and the off site transfer/forward are disabled.
Are there any other places I can lock down their system?

If I wanted to reboot just the voicemail would it be best to accomplish that with the services manager and then do a Stop and Start.
I see on the services that there are two services that are running for the Call Pilot: CallPilotProviderAgent and Voicemail.
Would I have to Stop and Start both or just the voicemail service.

Thanks,

Steve
 
I would go into the Call Pilot via the Browser and look at the mailbox activity reports for each of the affected mailbox's.

This will indicate if the mailbox is being hacked. It's best to tighten up security and remove any unused ones.

Firebird Scrambler
Nortel and Avaya Meridian 1 / Succession and BCM / Norstar Programmer

Very advance high level knowledge on the Linux BCM phone system.

Website
 
In my experience it has always been hackers attempting to gain access. Unless you have some sort of SMDR tracking it's impossible to tell for sure, and no, there is no way to prevent it. Disabling Off Premise Notification and Outbound Transfer in the COS will prevent anything bad from happening if the hackers do gain access to a mailbox.

We have also gone the extra step at some customers of putting overseas, third party LD access, and second dial tone restrictions on the trunks, then providing a F68 override code in the event the user needs to make an overseas call.

 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top