web statisticsweb stats

Business Phone Systems

Previous Thread
Next Thread
Print Thread
Rate Thread
Page 2 of 2 1 2
dans #547462 03/10/13 05:47 PM
Joined: Jul 2005
Posts: 1,336
Member
*****
Member
*****
Joined: Jul 2005
Posts: 1,336
Our carrier rang up this morning. Our office 8100 system was hacked at the weekend. Somehow they got in via one of our ADSL circuits and used a 3rd party SIP client to find a spare port with station number assigned and registered it and then used it to call out to South America. After the hack they dereistered all but one of the three ports they used and it was a dead give away as it came from 192.168.1.4 which is not in any of our address ranges and the SMRD show lots of calls over the weekend from these 3 stations... We have Intl Toll barred all ports except our desk sets in day mode and all ports in nite mode..
We have no form of remote access to our inhouse system and there were no MAC records in Webpro.
Here's hoping that our telco lets us off the call charges..:-)


Regards,

Paul W
Now back to a 0 day week. Love these 7 day weekends.
Atcom VoIP Phones
VoIP Demo

Best VoIP Phones Canada


Visit Atcom to get started with your new business VoIP phone system ASAP
Turn up is quick, painless, and can often be done same day.
Let us show you how to do VoIP right, resulting in crystal clear call quality and easy-to-use features that make everyone happy!
Proudly serving Canada from coast to coast.

dans #547463 03/10/13 06:13 PM
Joined: Jul 2005
Posts: 1,336
Member
*****
Member
*****
Joined: Jul 2005
Posts: 1,336
We now know how they got in. Last week we setup uMobility on one of our ADSL circuits with port 5070 pointing to our house systems. They must have done a random scan for an open port 5070 until they found one and the rest is history..


Regards,

Paul W
Now back to a 0 day week. Love these 7 day weekends.
dans #547571 03/12/13 03:26 PM
Joined: Aug 2005
Posts: 2,125
Member
Member
Offline
Joined: Aug 2005
Posts: 2,125
Just curious: did the int'l number start 9 011 632 xxxx xxxx ?

Used to be a lot of weak voicemails that got forwarded to Manila...

dans #547576 03/12/13 04:02 PM
Joined: Jul 2005
Posts: 1,336
Member
*****
Member
*****
Joined: Jul 2005
Posts: 1,336
No. Mostly to country code 232 = Sierra Leone and a couple to CC 972 = Israel and CC 562 Santiago (Metropolitan Region)

We could still see them yesterday trying to access the system,. One of guys is going to do some wireshark traces today and see if he can see where they are coming from though I suspect they will be using some relay system ..


Regards,

Paul W
Now back to a 0 day week. Love these 7 day weekends.
dans #547611 03/12/13 09:39 PM
Joined: Jul 2005
Posts: 1,336
Member
*****
Member
*****
Joined: Jul 2005
Posts: 1,336
The hackers are still at it. They seem to have a fixation with station numbers in the 2XX range. It is coming from IP address 37.8.45.72 ISP is Hadara located in Ramallah, Palestinian Territory. Time to send in a drone. Whether that is the origination location is anyones guess..


Regards,

Paul W
Now back to a 0 day week. Love these 7 day weekends.
dans #549613 04/10/13 10:53 AM
Joined: Apr 2007
Posts: 1,439
Member
****
Member
****
Joined: Apr 2007
Posts: 1,439
NEC's official response to the issue is pretty weak, but here it is none the less:

» Knowledgebase Hacking of the SV8100
ID# 10628 | Published 04/05/2013 08:36 AM | Updated 04/05/2013 09:17 AM

Products: SV8100 Categories: Documentation, Engineering, KB Article, Features, Business What can be done to protect the SV8100 from hacking?

Like other customer sensitive network equipment, the SV8100 should be placed behind a network firewall and all relative ports should be blocked from outside access. To ensure security, port XXX (HTTP) for the Web Pro port, port XXX for the PCPro port and port XXXX for the DIMM port should all be secured from outside Internet access.


Along with the above network firewall protection, all user names and passwords should be set to the maximum allowed entries in PRG 90-02.


User Names can be set for up to 10 upper case, lower case and special alphanumeric characters.


Passwords can be set for up to 8 digits using only digits 0-9, * and #. Note: Unlike the User Name, all special characters cannot be used in the password. Only * and # are allowed.


Avoid sequential numbers and mix in as many combinations of the allowed digits as possible. An example of usernames and passwords would be:


Username: TeSt96@K#*


Password: *538#*49


When changing the username and passwords, the changes should be documented and stored by the Associate. These changes should also be provided to the customer for safe storage.


If ports are going to be forwarded in the router for Remote Maintenance, then NEC recommends changing the default well known port numbers of Web Pro and PCPro in programs 90-54-01 and 90-54-02.


(I X'ed out the default port numbers so hackers don't know where to start.. Probably dosen't matter though ~TTECH)

Last edited by ttech; 04/10/13 05:24 PM.
Page 2 of 2 1 2

Moderated by  ttech 

Link Copied to Clipboard
Newest Topics
Answer ringing line without pressing a button
by Pinnacle Rich - 06/02/25 10:53 AM
IT Guy. Jersey City, NJ
by hitechcomm - 05/29/25 10:09 PM
Nortel Venture phone question
by empire - 05/26/25 04:27 PM
Vertical door phone
by newtecky - 05/23/25 07:15 PM
Forum Statistics
Forums84
Topics94,543
Posts640,074
Members49,857
Most Online5,661
May 23rd, 2018
Newest Members
telli, CCTechProf, Pinnacle Rich, chris c755555, empire
49,857 Registered Users
Top Posters(30 Days)
Toner 6
hbiss 2
Who's Online Now
1 members (justbill), 138 guests, and 35 robots.
Key: Admin, Global Mod, Mod
Contact Us | Sponsored by Atcom: One of the best VoIP Phone Canada Suppliers for your business telephone system!| Terms of Service

Sundance Communications is not affiliated with any of the above manufacturers. Sundance Phone System Forums - VOIP & Cloud Phone Help
©Copyright Sundance Communications 1998 - 2025
Powered by UBB.threads™ PHP Forum Software 8.0.0