web statisticsweb stats Business Phone Systems Tech Talk Forum - VOIP & Cloud Phone Help

Business Phone Systems

Previous Thread
Next Thread
Print Thread
Rate Thread
#538241 10/24/12 10:56 AM
Joined: Oct 2012
Posts: 23
@work Offline OP
Member
OP Offline
Member
Joined: Oct 2012
Posts: 23
Hi folks
I'm new on the forum, some great topics that have help so I signed up.

I'm fairly new with SV8100 system and well I'm the phone guy at work.

just recently our provider explained we got hacked (most likely thought remote VM), because of this I've disabled access to remote VM in our dialing tables until I setup a pass for all VM's.

I just want to know if anyone can tell me if I should be looking at other things in our system to ensure hacker prevention to access our system to make ANY calls period.



Atcom VoIP Phones
VoIP Demo

Best VoIP Phones Canada


Visit Atcom to get started with your new business VoIP phone system ASAP
Turn up is quick, painless, and can often be done same day.
Let us show you how to do VoIP right, resulting in crystal clear call quality and easy-to-use features that make everyone happy!
Proudly serving Canada from coast to coast.

Joined: Jun 2004
Posts: 1,367
Member
*****
Offline
Member
*****
Joined: Jun 2004
Posts: 1,367
few things to consider.
How was your system hacked? is it web accessible from the outside world? Have you changed the password....to include the well known MF password?

Have you disabeled ALL unused mailboxes?
Do you have good passwords for all used mailboxes and stronger passwords for admin mailboxes?

Do you have Voicemail notification? If not, prevent trunk access; if so, make approriate Toll restrictions on the VM group.


You may also want to contact your vendor and ask why this happened. Se if they will get in and set this up for you. 1 hour remote (if you have all of the your ducks in a row) charge sure coudl be cheaper than getting hacked again.


[Linked Image from i26.servimg.com]
TouchPoint Networks.

Serving the Northwest Since 1991
NEC Shoretel Zultys T3 Tadiran
Joined: Jul 2005
Posts: 1,333
Member
*****
Offline
Member
*****
Joined: Jul 2005
Posts: 1,333
Also toll bar your voicemail ports for local service access only..


Regards,

Paul W
Now back to a 0 day week. Love these 7 day weekends.
Joined: Oct 2012
Posts: 23
@work Offline OP
Member
OP Offline
Member
Joined: Oct 2012
Posts: 23
thanks guys for the replies
This was hacked through VM that were not password is what was suspected. I don't know of any reporting with WebPro which I think you need added software that costs a gazillion dollars for reporting that could help identify this if I'm correct.
Accessible from the outside world = yes but not everyone knows this pass but I will change to make sure.
disabled on msgeboxes yesterday that I could find.

Vendor could only see outside the system and only knows our DID number so they can`t get into more details then that apparently.

I will look at toll restriction for VM`s and see about toll bar VM for service access only.

I`m told I can`t force a password with webpro for VM`s, I have to do this individually which sucks. I`m also told I can`t force users to change pass immediately on first log on like windows which I think sucks too. Let me know if any of you know where I can apply the change pass to VM after 30day rule would be in the system if that`s possible and save me time...

thanks again for the help!

Guy

Joined: Apr 2005
Posts: 2,498
Likes: 2
Member
*****
Offline
Member
*****
Joined: Apr 2005
Posts: 2,498
Likes: 2
If they have or you ever setup the UM8000 voice mail you automatically have default pass code which can be change by the installer before going online. Also when you setup the template for the mailboxes check first time enrollment, this will for the users to change their security code.

InMail does not have these options


We get old too soon, smart too late
Joined: Jun 2019
Posts: 9
Member
Offline
Member
Joined: Jun 2019
Posts: 9
Im curious @ Work. I have had this happen to me at 3 separate accounts of mine.After the hacking happened when you logged into the system was the modification history still there?
All three of my customers had the find me follow me turned on and the international telephone numbers were programmed as one of the entries. At one customer site I was able to find one entry the hackers missed deleting. Also every one of my customer hacks the modification history was gone, nothing was there. That means they hacked in thru the remote,I changed all the user names and passwords but its not going to do any good if they know the manufacturer UN and password.

Joined: Sep 2004
Posts: 4,194
Likes: 2
Member
*****
Offline
Member
*****
Joined: Sep 2004
Posts: 4,194
Likes: 2
This thread is from 2012.

Joined: Jun 2019
Posts: 9
Member
Offline
Member
Joined: Jun 2019
Posts: 9
Hey Coral Tech ,
Am I red in the face or what,? well as usual Im late to the game. My question still stands. : )

Joined: Sep 2004
Posts: 4,194
Likes: 2
Member
*****
Offline
Member
*****
Joined: Sep 2004
Posts: 4,194
Likes: 2
Apples and oranges. On an 8100 you have to set passwords on all mailboxes or they will find a mailbox to do this. Unless they have access through the network. There are MUCH batter ways to do this that a mailbox. Even so make sure it's not accessible thru teh network and change the MF password.


Last edited by Coral Tech; 06/17/19 07:07 PM.

Moderated by  ttech 

Link Copied to Clipboard
Forum Statistics
Forums84
Topics94,279
Posts638,738
Members49,763
Most Online5,661
May 23rd, 2018
Popular Topics(Views)
211,288 Shoretel
188,170 CTX100 install
187,019 1a2 system
Newest Members
gohunt, Darrick, telecopippo, highlysecptial, BPopilek
49,762 Registered Users
Top Posters(30 Days)
Toner 14
jc2it 4
dexman 4
teleco 4
Who's Online Now
0 members (), 98 guests, and 78 robots.
Key: Admin, Global Mod, Mod
Contact Us | Sponsored by Atcom: One of the best VoIP Phone Canada Suppliers for your business telephone system!| Terms of Service

Sundance Communications is not affiliated with any of the above manufacturers. Sundance Phone System Forums - VOIP & Cloud Phone Help
©Copyright Sundance Communications 1998-2024
Powered by UBB.threads™ PHP Forum Software 7.7.5