web statisticsweb stats

Business Phone Systems

Previous Thread
Next Thread
Print Thread
Rate Thread
Page 1 of 2 1 2
#547010 03/04/13 03:16 PM
Joined: Apr 2005
Posts: 2,526
Likes: 4
Member
*****
Member
*****
Offline
Joined: Apr 2005
Posts: 2,526
Likes: 4
We had our 1st SV8100 hacked, they got past the fire wall, used web pro to set call forward all calls to international numbers, I don't know what extension they used, they were smart enough to go back and undo the settings. The way I know they did it is the modification history, it shows the program number along with date and time, it does not and will not show what extension was used.

To all NEC techs change all passwords in web pro and make notes of what they are.

Dan S


We get old too soon, smart too late
Atcom VoIP Phones
VoIP Demo

Best VoIP Phones Canada


Visit Atcom to get started with your new business VoIP phone system ASAP
Turn up is quick, painless, and can often be done same day.
Let us show you how to do VoIP right, resulting in crystal clear call quality and easy-to-use features that make everyone happy!
Proudly serving Canada from coast to coast.

dans #547011 03/04/13 03:27 PM
Joined: Jul 2005
Posts: 1,336
Member
*****
Member
*****
Joined: Jul 2005
Posts: 1,336
If they hacked the VPN password assuming thats how they got in maybe an inside job??


Regards,

Paul W
Now back to a 0 day week. Love these 7 day weekends.
dans #547133 03/06/13 10:30 AM
Joined: Apr 2005
Posts: 2,526
Likes: 4
Member
*****
Member
*****
Offline
Joined: Apr 2005
Posts: 2,526
Likes: 4
Paul

No inside job.


We get old too soon, smart too late
dans #547178 03/06/13 04:00 PM
Joined: Jul 2005
Posts: 1,336
Member
*****
Member
*****
Joined: Jul 2005
Posts: 1,336
Dial up or via VPN??


Regards,

Paul W
Now back to a 0 day week. Love these 7 day weekends.
dans #547179 03/06/13 04:04 PM
Joined: Mar 2005
Posts: 38
Member
Member
Offline
Joined: Mar 2005
Posts: 38
If you look in modification history, what user name did they use? Was the password default for that login? What day of the week was it done. Just curious, we had 4 SV8100s that were on public IPs due to CCIS, hacked on the last few saturdays. We made a mistake of not changing USER1 password due to keeping it default for software like desktop and shared services. All 4 system had someone log in as user 1 and fwd an extension to an international number (3 systems were the same number).
We have sinced changed/ disabled USER1 and also changed 90-28 logins for all extensions.
So if port 80 is open, you should change all of those.



Last edited by PhoneGuy25; 03/06/13 04:04 PM.
dans #547181 03/06/13 04:32 PM
Joined: Apr 2005
Posts: 2,526
Likes: 4
Member
*****
Member
*****
Offline
Joined: Apr 2005
Posts: 2,526
Likes: 4
They came in through port 80 using tech as the user name, I have since changed all passwords, not only on this system but all the ones we service.


We get old too soon, smart too late
dans #547182 03/06/13 04:38 PM
Joined: Sep 2004
Posts: 4,220
Likes: 2
Member
*****
Member
*****
Offline
Joined: Sep 2004
Posts: 4,220
Likes: 2
First thing I do is change the passwords on the system.

dans #547267 03/07/13 04:24 PM
Joined: Jul 2005
Posts: 1,336
Member
*****
Member
*****
Joined: Jul 2005
Posts: 1,336
Originally Posted by dans
They came in through port 80 using tech as the user name, I have since changed all passwords, not only on this system but all the ones we service.

Via the Internet?? I don't know of any one here who will allow direct access via port 80 via the Internet. They insist on convoluted VPN access only or dialup (if you don't have SIP trunks)..


Regards,

Paul W
Now back to a 0 day week. Love these 7 day weekends.
dans #547330 03/08/13 09:59 AM
Joined: Apr 2005
Posts: 2,526
Likes: 4
Member
*****
Member
*****
Offline
Joined: Apr 2005
Posts: 2,526
Likes: 4
Our customers IT company was supposed to setup the customers router to only allow access to port 80 from my offices WAN IP address, they failed to put that security procedure in place.


We get old too soon, smart too late
dans #547331 03/08/13 10:11 AM
Joined: Oct 2004
Posts: 1,492
Member
*****
Member
*****
Joined: Oct 2004
Posts: 1,492
Changing port 80 is one of the first things I usually do. 1 reason being most of the time the customer is already using port 80. 2nd reason being a small SV8100 with like 3 phones was in service for 1 day and started to crash. it would come back up and then crash. With port 80 open it was getting flooded and would crash the system. I was on the road and had the customer reboot it and it would come up and then would go right back down. I had them unplug the patch cable to it thinking it was a bad port on the switch and it was fine. I called their IT guy and he checked and told me about the flood and ever since then I have changed it.

Page 1 of 2 1 2

Moderated by  ttech 

Link Copied to Clipboard
Newest Topics
SV8100 beeping
by Jackcmann - 04/10/25 05:29 AM
Samsung xchange server
by scanjet - 04/07/25 06:37 PM
NEC IP Phones
by juno - 04/04/25 09:05 AM
Forum Statistics
Forums84
Topics94,516
Posts639,970
Members49,848
Most Online5,661
May 23rd, 2018
Newest Members
Kevin usama, Pruitt roger, ActiveTelephones, yeloshak, ty3995
49,847 Registered Users
Top Posters(30 Days)
Toner 9
Taddeo 6
dexman 2
Who's Online Now
0 members (), 162 guests, and 41 robots.
Key: Admin, Global Mod, Mod
Contact Us | Sponsored by Atcom: One of the best VoIP Phone Canada Suppliers for your business telephone system!| Terms of Service

Sundance Communications is not affiliated with any of the above manufacturers. Sundance Phone System Forums - VOIP & Cloud Phone Help
©Copyright Sundance Communications 1998 - 2025
Powered by UBB.threads™ PHP Forum Software 8.0.0