Dec 9 2008 1:46PM GMT
Posted by: Tony Bradley
Phishing,
VoIP security,
vishing,
Asterisk,
FBI,
Digium
The FBI has issued a warning that a vulnerability in the open-source Asterisk platform, used by many as a free IP PBX, can lead to the system being exploited to initiate vishing calls. Vishing, a term concocted to mean a voice or VoIP based phishing attack, uses a voice system to contact potential victims and attempt to get them to share sensitive or confidential information which can be used to compromise their accounts. Generally, the purpose would be to gain access to financial information and be able to gain access to bank or investment accounts to steal money from the victims.
Feb 24 2008 2:08PM GMT
Posted by: Tony Bradley
VoIP,
Unified Communications,
Data breach,
vishing
My Yiddish is rusty (OK, it is virtually non-existent), but it sounds a little like my ex-wife’s grandfather inviting me on a fishing trip. But alas, it is even more insidious than that. You are most likely familiar with the concept of ‘phishing’ which involves using some type of bait (generally an email or web site designed to elicit a response) to lure an unsuspecting user into surrendering confidential personal information, such as bank or credit card account numbers, or user names and passwords to sensitive accounts, for the purpose of stealing their money or identity. Well, ‘vishing’ is very similar, but it relies on VoIP phone calls rather than unsolicited spam emails for bait. You can learn more by reading this glossary explanation of ‘vishing’ from WhatIs.com posted on the SearchUnifiedCommunications site.
Dec 28 2007 8:27PM GMT
Posted by: Tony Bradley
VoIP,
Unified Communications,
vishing,
toll fraud,
skype worm
I know I am a broken record, or kicking a dead horse, or some other analogy about stating the same obvious thing over and over, but as the world adopts VoIP for voice communications they need to be aware of the security risks and take the appropriate steps to protect their communications and their networks. Sipera Systems has published a list of the Top 5 VoIP Vulnerabilities. If you have implemented, or plan to implement a VoIP solution, be aware that eavesdropping, VoIP hopping, vishing, toll fraud, and the Skype worm are all issues you should be concerned with. Take a look at Sipera’s Top 5 VoIP Vulnerabilities in 2007 list for more details.