Monday, November 9, 2015

Happy 101st Birthday to Hedy Lamar

The woman who proved that you can really have it all:


- Beauty (she was called the "most beautiful woman in Europe")
- Movie Career with a Star on the Hollywood walk of fame
- Developed an improved traffic stoplight
- Patents for spread spectrum and frequency hopping technology to thwart the Nazis that make our modern communications possible U.S. Patent 2,292,387 (but the US Navy did not use it until the patent had expired).
and she is today's Google Doodle

Sunday, February 22, 2015

Android malware can make calls even after switching your phone off

A recent warning has come out from AVG has come out that some 3rd party App stores have Apps which bring in a Android Trojan which pretends to shut off your phone when you press the power button.

 The Hacker News has a nice article about it Android Malware Can Spy On You Even When Your Mobile Is Off  or you can read the original AVG post Malware Is Still Spying On You Even When Your Mobile Is Off
As the AVG blog explains:
The malware affects versions of Android older than v.5 (Lollipop) and requires root permission to hijack the shut down process.
After pressing the power button, the phone displays an authentic shutdown animation, and the phone appears off. Although the screen is black, it is still on.
While the phone is in this state, the malware can make outgoing calls, take pictures and perform many other tasks without notifying you.
But beyond the obvious problems with a malware spying on you, recording you, and sending your data to Chinese servers, it can be making Premium Rate SMS or calls without your knowing it.

The Hacker news article points this out:
PowerOffHijack malware has ability to silently send lots of premium-rate text messages, make calls to expensive overseas numbers, take photos and perform many other tasks even if the phone is supposedly switched off.
The article also has good options for removing PowerOffHijack and preventing it from getting on your phone

Sunday, July 13, 2014

Preparing for Astricon 2014

I will be heading out to Vegas to talk security in October

I have been allocated the following date and time for my talk (but would advise that this may be subject to change):

Date: Thursday, October 23rd
Time: 10.00-10.35am
Track: Security
Title: Making your Asterisk system secure


Have you signed up Astricon yet? 

Wednesday, July 9, 2014

Celebrating 137 years of public telephone

Today is the birthday of good old Ma Bell:



The Bell Telephone Company, a common law joint stock company, was organized in Boston, Massachusetts on July 9, 1877, by Alexander Graham Bell's father-in-law Gardiner Greene Hubbard, who also helped organize a sister company — the New England Telephone and Telegraph Company. (Source Wikipedia)

It constantly amazes me that we have come so far from Bell's original design to HD voice, fiber to the home, the internet, mobile phones, smart phones, and VoIP.

In so little time we have gone well beyond anything that could be imagined by the science fiction authors, some of whom influenced the current tech trend.

To please take a min. to think of good ol'Ma Bell and all her children (legitimate or otherwise) that bring you this post today.

Monday, June 16, 2014

Is a Smart House a Smart choice?

Over the past several weeks there have been numerous announcements about smart houses and smart homes.

There was a nice summary about how The smart home is the next battleground: What to expect from the top 3 tech companies? In this article TechTimes explains how 
Google, Microsoft, and Apple getting involved in home automation, it is clear that this will be the next battleground, and at the moment no one truly has the upper hand.
But there are more players looking to get into this market.


There are even do it yourself (DIY) options with articles explaining It is cheap and easy to turn your home into a smart house.
 
As with any new connected technology there are reasons to be concerned. For example here is a slide show of 4 ‘smart home’ gadgets you don’t want hacked and there are 3 big risks with 'smart homes'.

But for me the biggest concern is stories like how Australian Apple devices hijacked and held for ransom. 

Now consider that someone could hack your home, change (or deactivate) your alarm, change the access code, play with your heat, etc. 

It reminds me of some of the tricks played by a computer in Robert Heinlein's The Moon is a Harsh Mistress:
Mike had thought up a dandy; his "illness" was wild oscillations in conditioning Warden's residence. He was running its heat up, then down, on an eleven-minute cycle, while oscillating its air pressure on a short cycle, ca. 2c/s, enough to make a man dreadfully nervy and perhaps cause earache.
Do you want someone to have that kind of control over your home? I don't.

Monday, May 19, 2014

As always, Scott Adams gets it right


And this is why we can not kill spam, phishing, and fraud
For every 99 people with a clue there is one that falls for it.

Tuesday, April 8, 2014

Move to end Bill Shock: Telecoms Slash Data Roaming

(Cross posted between my travel and telecom blogs)

Over the past 18 months or so the telecom industry has been slowly going through a subtle change that affects travelers.

Back in December 2012 Telecom [New Zealand] announced a breakthrough new approach to international data roaming that will slash costs for travellers when using their smartphones and other mobile devices overseas.
A feature is a flat daily rate for data roaming by postpaid customers across major travel markets. Australia roaming will start at a specially reduced rate of $6 a day (Telecom will review the rate in mid 2013). Customers will pay just $10 a day flat rate for data while travelling in the UK, USA, Canada, China, Hong Kong, Macau, Taiwan, and Saudi Arabia. Telecom’s fair use policy applies to these rates.

Telecom’s CEO, Simon Moutter, said the flat rate would make it much simpler for customers to understand data roaming costs and would give them the freedom to make use of their smartphones in the same way they would at home.

“We know data roaming charges have been a pain-point for customers – personally, it was a real bugbear of mine as a customer before I joined Telecom earlier this year. A flat fee provides certainty and puts an end to concerns about nasty bill shocks on your return home.

“It’s also much simpler to follow than any usage-based system – as most customers don’t really know how quickly their phone apps will chew through 1MB, 10MB or 100MB.”
               
Now other companies have started to follow suit:
On October 20, 2013 “T-Mobile changed the way you can use your smartphone in more than 100 foreign countries” with their T-Mobile's New Global Roaming. While T-Mobile’s Simple Choice plan allows certain customers to roam in about 116 countries as if they were at home.
In March 2014 T-Mobile added 7 countries to Simple Choice Global International roaming list so it is now 122 countries.

MTN cuts cost of roaming across own 'footprint' MTN has introduced its Roam like Home service that enables all its customers to keep in touch with family and friends at affordable rates while travelling in any of the 21 countries that it operates in.

Now the EU parliament votes to abolish roaming end to mobile roaming charges across the EU by 2016, if it is approved by all the member countries.

So, now with only a few SIM cards you can now have unlimited calling and flat rate data in 145 countries:

Country Telecom NZ SIM T-Mobile USA Simple Choice SIM Any MTN SIM Any EU Carrier
Afghanistan T-Mobile as Investcom
Aland Islands T-Mobile
Anguilla T-Mobile
Antigua and Barbuda T-Mobile
Argentina T-Mobile
Armenia T-Mobile
Aruba T-Mobile
Australia T-Mobile
Austria T-Mobile  in 2016
Bahrain T-Mobile
Barbados T-Mobile
Belgium T-Mobile  in 2016
Benin  as Investcom
Bermuda T-Mobile
Bolivia T-Mobile
Bonaire T-Mobile
Botswana  as Botswana Mascom
Brazil T-Mobile
British Virgin Islands T-Mobile
Bulgaria T-Mobile  in 2016
Cambodia T-Mobile
Cameroon  as MTN Cameroon
Canada Telecom NZ T-Mobile
Canary Islands T-Mobile
Cayman Islands T-Mobile
Chile T-Mobile
China Telecom NZ T-Mobile
Christmas Island T-Mobile
Colombia T-Mobile
Costa Rica T-Mobile
Cote d'Ivoire  as MTN Cote d'Ivoire
Croatia  in 2016
Curacao (Netherlands/Dutch Antilles) T-Mobile
Cyprus T-Mobile  as MTN Cyprus  in 2016
Czech Republic T-Mobile  in 2016
Denmark T-Mobile  in 2016
Dominica T-Mobile
Dominican Republic T-Mobile
Easter Island T-Mobile
Ecuador T-Mobile
Egypt T-Mobile
El Salvador T-Mobile
Estonia T-Mobile  in 2016
Faeroe Islands T-Mobile
Finland T-Mobile  in 2016
France T-Mobile  in 2016
French Guiana T-Mobile
Germany T-Mobile  in 2016
Ghana T-Mobile  as Investcom, MTN Ghana
Greece T-Mobile  in 2016
Grenada T-Mobile
Guadeloupe T-Mobile
Guam T-Mobile
Guatemala T-Mobile
Guinea Bissau  as Investcom
Guyana T-Mobile
Honduras T-Mobile
Hong Kong Telecom NZ T-Mobile
Hungary T-Mobile in 2016
Iceland T-Mobile
India T-Mobile
Indonesia T-Mobile
Iran  as MTN Irancell
Iraq T-Mobile
Ireland T-Mobile  in 2016
Israel T-Mobile
Italy T-Mobile  in 2016
Jamaica T-Mobile
Japan T-Mobile
Kenya T-Mobile
Kuwait T-Mobile
Latvia T-Mobile  in 2016
Liberia  as Lonestar Cell
Lithuania T-Mobile  in 2016
Luxembourg T-Mobile in 2016
Macau Telecom NZ T-Mobile
Malaysia T-Mobile
Malta T-Mobile  in 2016
Martinique T-Mobile
Mexico T-Mobile
Moldova T-Mobile
Montserrat T-Mobile
Netherlands T-Mobile  in 2016
Netherlands Antilles T-Mobile
New Zealand Telecom NZ T-Mobile
Nicaragua T-Mobile
Nigeria  as MTN Nigeria
North America & Caribbean T-Mobile
Northern Ireland T-Mobile
Norway T-Mobile
Pakistan T-Mobile
Panama T-Mobile
Peru T-Mobile
Philippines T-Mobile
Poland T-Mobile  in 2016
Portugal T-Mobile  in 2016
Qatar T-Mobile
Republic of Congo  as MTN Congo SA
Republic of Guinea  as Investcom
Romania T-Mobile  in 2016
Russia T-Mobile
Rwanda  as MTN Rwanda
San Marino T-Mobile
Saudi Arabia Telecom NZ T-Mobile
Scotland T-Mobile
Singapore T-Mobile
Sint Maarten T-Mobile
Slovakia T-Mobile  in 2016
Slovenia  in 2016
South Africa T-Mobile  as MTN South Africa
South Korea T-Mobile
South Sudan  as Investcom
Spain T-Mobile  in 2016
Sri Lanka T-Mobile
St. Barthelemy T-Mobile
St. Kitts and Nevis T-Mobile
St. Lucia T-Mobile
St. Martin T-Mobile
St. Vincent and the Grenadines T-Mobile
Sudan  as Investcom
Suriname T-Mobile
Svalbard T-Mobile
Swaziland  as MTN Swaziland
Sweden T-Mobile  in 2016
Switzerland T-Mobile
Syria  as Investcom
Taiwan Telecom NZ T-Mobile
Thailand T-Mobile
Trinidad and Tobago T-Mobile
Turkey T-Mobile
Turkmenistan (No Data network) T-Mobile
Turks and Caicos Islands T-Mobile
Uganda T-Mobile  as MTN Uganda
UK Telecom NZ T-Mobile  in 2016
Ukraine T-Mobile
United Arab Emirates T-Mobile
Uruguay T-Mobile
USA Telecom NZ T-Mobile
Vatican City T-Mobile
Venezuela T-Mobile
Vietnam T-Mobile
Wales T-Mobile
Yemen  as Investcom
Zambia T-Mobile  as MTN Zambia

Wednesday, February 12, 2014

Replacing Flappybird with Premium Number Fruad

Much to the dismay of millions of players, the creator of the Flappybird mobile game took it down from Google Play and Apple iTunes app stores.


Now there has been many speculations as to why someone would take down a game that was earning him $50,000 a day in advertising revenue. The various reasons have been stated as:


But regardless of what the real reason is people have come in to fill your Flappybird addiction with replacements or by selling phones with it installed on e-bay (which you can not do anymore).

But you should be wary of FlappyBird replacements -According to a report by Trend Microsystems
All of the fake versions we’ve seen so far are Premium Service Abusers — apps that send messages to premium numbers, thus causing unwanted charges to victims’ phone billing statements.


As the TrendMicro article advises:
We advise Android users (especially those who are keen to download the now “extinct” Flappy Bird app) to be careful when installing apps. Cybercriminals are constantly cashing in on popular games (like Candy Crush, Angry Birds Space, Temple Run 2; Bad Piggies) to unleash mobile threats. Our past entry, Checking the Legitimacy of Android Apps, enumerates some tips on how to do avoid suspicious or malicious apps. Users may also opt to install a security app (such as Trend Micro Mobile Security) to be able to check apps even before installation.         
Always remember in cases like this TANSTAAFL so be careful there are those who are out there to take advantage of you.

Thursday, November 21, 2013

Wednesday, September 11, 2013

Tuesday, April 9, 2013

What do the crooks get from PBX hacking?

I have been asked many times what the crooks get out of hacking or attacking a phone switch.

William Jackson offers a good explanation in this blog post

Phone DOS: What's in it for the crooks
http://gcn.com/blogs/cybereye/2013/04/phone-dos-whats-in-it-for-crooks.aspx
(Image from the blog).

Wednesday, March 27, 2013

Nice article on effects of Toll Fraud

Thanks to Mark Collier's VoIP Security Blog I point you to this article that  Toll fraud can put SMEs out of business in minutes.

Unfortunately the premise and conclusions are correct. If you think of the example from the 2011 Astricon where a company was hit for $400,000 in fraud over 2 days then it is easy to see how this kind of hit could cost a small business everything in almost no time.

Real time monitory and proper security checks are needed to help prevent this kind of fraud. I will keep posting details on how you can protect your company, or you can contact me directly for more information about real-time monitoring or VoIP Security Audits.

Monday, February 4, 2013

Pulp Phishing

Found a neat new web tool to create retro looking Pulp Fiction covers.

So here is one to remind everyone that telecom fraud is not just taking your money, but is being used to fund terror.



Past posts about Al Qaeda Phishing attacks
 
Pulp cover made with: http://thrilling-tales.webomator.com/derange-o-lab/pulp-o-mizer/pulp-o-mizer.html
 

Sunday, January 27, 2013

Al Qaeda-linked phone hackers are back

A little over a year ago I was explaining on the VoIP Users Conference weekly call about how Al Qaeda had been hacking AT&T customers for over US$2 million in the session titled  Shssshhhhhh!!!! Al-Qaeda Phreaking!  (a recording of the session is available at:  http://www.voipusersconference.org/?powerpress_embed=3669-podcast.

Now a year later New York Sen. Schumer: Al Qaeda-linked phone hackers costing NY small businesses says that another:
phone hacking ring with ties to Al Qaeda-related groups in the Philippines and Somalia have targeted small businesses in New York, stealing hundreds of thousands of dollars worth of overseas long distance calls.
It is not as large an amount  stolen as last time, but it is scary to think that in-spite of the assassination of their leader Al Qaeda is back to their old tricks of hiring people to hack to fund them.

As Sen. Schumer reports
26 businesses in New York's capital area, which includes Albany, have come forward to say they’ve been victims of a communications scheme. Schumer said hackers were manipulating businesses’ voicemail systems to make thousands of costly long-distance calls overseas, leaving New York businesses on the hook for the substantial bills.
 For example:
One dry cleaning company in the area, he said, was hit with a $150,000 phone bill for nearly 9,000 overseas calls. That business is currently in a legal battle with its telephone provider over the bill .

On his official site he has called on carriers to put in place limits.

A copy of Schumer’s letter to the telecom industry and the Federal Communications Commission appears below:

Dear US Telecom and NTCA,

I am writing today after learning of several instances of a voicemail scam praying on multiple New York small businesses. As I am sure you are aware, this fraud occurs when hackers discover a loophole in the voicemail system and use this to make long-distance calls that can cost thousands of dollars. As this scam can occur over a series of days or even weeks, many of these victims are left with a bill of hundreds of thousands of dollars. During these times, small businesses need all the available help in order for them to continue to prosper and grow.

Both your members and these small businesses have been victims of this crime. These hackers, as they mostly operate from overseas, can be very difficult for law enforcement to catch. Therefore, I am hopeful that we can work together on adequate steps to provide stringent fraud detection services for small business phone lines so that we can eliminate the charges for small businesses and for your members. I believe that the credit card industry could provide inspiration in this effort. They have established robust fraud prevention services to allow businesses and customers to learn almost immediately when a suspicious purchase is made. In addition, they can require authorization prior to a suspicious purchase.

We all have an interest in ending this fraud. Neither your members nor their customers wish to help connect potential criminals or terrorists with their allies overseas. I believe an industry-led effort to detect voicemail fraud and end these unauthorized charges would allow small businesses to continue to innovate without the fear of extremely high charges. I have copied the Federal Communications Commission to ask them to assist your members with their expertise in this matter.

I thank you for your attention to this important matter, and look forward to working with you to assist you in protecting American small businesses from unfair and deceptive practices.

Sincerely,
U.S. Senator Charles E. Schumer

CC: Federal Communications Commission
 Although Senetor Schumer is correct that this is a problem that the carriers need to address, that does not mean that businesses can not, or should not, be proactive with monitoring, blocking, and call restrictions on their phone switch.

As our security audits have shown many PBXs leave open holes that can be exploited.
  • Do all phones need long distance or international calling?
  • Have unused/unneeded voicemail boxes been left open?
  • Do you have time of day/day of week restrictions on your phones (why can calls be made at 2 am on a Saturday if you are only open Monday to Friday 9-5)?
  • Do you still have easy to use or default passwords on your voicemail, PBX, or phones?
 Have your phone staff or vendor check to make sure that these basic problems have been addressed or contact me and we can discuss a security audit.

Protect yourself because the phone companies will almost always expect you to pay at least part of the phone fraud done using your phone lines.

Wednesday, January 23, 2013

Interesting Article on the Challenges and Prevention in a VoIP Environment

 As I have been writing here, VoIP service has become more common and thus more of an attractive target for fraud attacks.

Jim Murphy, President of Phone Power has a nicely written article on TMCNet titled Toll Fraud Challenges and Prevention in a VoIP Environment

He discusses the fact that there are always new targets to attack and that many PBXs use default or easy to crack passwords (1234).

But to me the most worrying thing he mentions is how much this can cost a company:
The risks of toll fraud within a VoIP network are severe. Some hackers are able to hijack systems and push through charges that can total $2,000 an hour or more.
Now we have seen companies hit in a few days with $25,000 - $50,000 in fraud, or even 1 case for $400,000 over 2 days, so this number of $2,000 per hour sounds quite plausible to me.

This is why I moved to Greenfield Technologies and am specializing in doing Security Audits for Asterisk based VoIP PBXs.

After performing auditing on more than 35  PBXs

We have found that the most common Policy issues are:
—
Incomplete, non-existent, unenforced Password policies:

Many had identical default SIP passwords for all phones that were never changed
Many had identical default voice-mail passwords for all extensions that were never changed

Server / PBX Passwords

Multiple PBXs using the same password
Root access and web client interface using the same password (if any)

No update policy

Server OS
PBX software
Phone firmware

No mailbox polices

Who get voice-mail
When to close them
No policy to monitor phone usage / activity