Hi,
A BCM50 system that I look after was hacked overnight and a large bill racked up on international premium rate numbers before the provider was able to put a block in place.
After doing some research I believe the method used was to make an external call from within callpilot once the auto attendant had picked up the call.
I've since removed the ability to make external calls from all COS. I've also put mailbox restrictions in place on all mailboxes and had users change their PINs, as well as PINs for the System Manager and General Pickup mailboxes. I suspect that the System Manager or General Pickup mailbox PIN had been reset by the client and not set to something secure.
My questions are, is there anything else I should do to ensure this cannot be repeated and how is it possible to create an external call from within the voicemail system? Is it a case of dialing specific codes once the auto-attendant has picked up the call? I would like to attempt it myself to ensure all external calls are blocked.
Many thanks for any info.
Tubdub
A BCM50 system that I look after was hacked overnight and a large bill racked up on international premium rate numbers before the provider was able to put a block in place.
After doing some research I believe the method used was to make an external call from within callpilot once the auto attendant had picked up the call.
I've since removed the ability to make external calls from all COS. I've also put mailbox restrictions in place on all mailboxes and had users change their PINs, as well as PINs for the System Manager and General Pickup mailboxes. I suspect that the System Manager or General Pickup mailbox PIN had been reset by the client and not set to something secure.
My questions are, is there anything else I should do to ensure this cannot be repeated and how is it possible to create an external call from within the voicemail system? Is it a case of dialing specific codes once the auto-attendant has picked up the call? I would like to attempt it myself to ensure all external calls are blocked.
Many thanks for any info.
Tubdub