Had a customer call this AM with Fraud- Mics 6.1 /analog lines/ cp150.
The fraud was caught within a day by Qwest, which was nice.
Anyways, I have locked down all the usual stuff, changed passwords, outdial, COS, etc.
In the cp logs there are some new entries starting yesterday that were never present before:
The change was Ctx Trans =89. Previously this was always 0. I am guessing this means the fraud went out over a centrex (flash) transfer.
The question- is this simply a hacker dialing in, guessing the password, and changing some settings? Or is there some hack/ backdoor I am not aware of? The calls were to 20 different countries.
I traced the log back to where it all started, but I am not familiar enough with them to know exactly what the guy did…anyone have experience with these logs…log is below.
If you know something about this, but don’t want to post for security reasons, please email me-
memtosh at yahoo.com
2005/02/08 15:24:11 FtLog buffer overrun attempted. See Module, Functi
et code below:
2005/02/08 15:24:11 Shell 1
2005/02/08 15:24:11 Warning: F986Start mbDisconnect() failed
2005/02/08 15:24:11 rc=39(0x27)
2005/02/08 15:24:11 Internal call from DN 348.
2005/02/08 15:24:11 Dump: Shell 1
2005/02/08 15:24:11 2005/02/08 15:15:57 AsResumePrompts 1st timeout
2005/02/08 15:24:12 2005/02/08 15:15:58 AsResumePrompts call disconnec
2005/02/08 15:24:12 2005/02/08 15:15:58 F981MainMenu call disconnec
2005/02/08 15:24:12 2005/02/08 15:15:58 F981Menu call disconnec
2005/02/08 15:24:12 2005/02/08 15:15:58 Idle State init event
2005/02/08 15:24:12 2005/02/08 15:24:10 Idle State call offered
2005/02/08 15:24:12 2005/02/08 15:24:10 WaitForAnswer init event
2005/02/08 15:24:12 2005/02/08 15:24:10 WaitForAnswer call answered
2005/02/08 15:24:12 2005/02/08 15:24:10 F986Start init event
2005/02/08 15:24:12 2005/02/08 15:24:10 AsInitAddrEntry init event
2005/02/08 15:24:12 2005/02/08 15:24:10 AsAddrEntry init event
2005/02/08 15:24:12 2005/02/08 15:24:10 AsAddrEntry data entry pro
2005/02/08 15:24:13 2005/02/08 15:24:10 AsPresentPrompt init event
2005/02/08 15:24:13 2005/02/08 15:24:10 AsResumePrompts init event
2005/02/08 15:24:13 2005/02/08 15:24:10 AsResumePrompts key three
2005/02/08 15:24:13 2005/02/08 15:24:10 AsAddrEntry key three
2005/02/08 15:24:13 2005/02/08 15:24:10 AsDataEntry key three
2005/02/08 15:24:13 2005/02/08 15:24:10 AsAddrEntry key three
2005/02/08 15:24:13 2005/02/08 15:24:10 AsDataEntry key three
2005/02/08 15:24:13 2005/02/08 15:24:10 AsAddrEntry key five
2005/02/08 15:24:13 2005/02/08 15:24:10 AsDataEntry key five
2005/02/08 15:24:13 2005/02/08 15:24:10 AsAddrEntry data entered
2005/02/08 15:24:13 2005/02/08 15:24:10 AsInitAddrEntry addr entered
2005/02/08 15:24:13 2005/02/08 15:24:10 F986Start addr entered