- +
Strategies for Dealing With IT Complexity 24/12/2007 10:30:47
Every innovation, every business process improvement, comes with an IT complexity tax that must be paid by CIOs in time, money and sweat. Here are strategies to mitigate the increasing complexity of IT as it enables new business.Every innovation, every business process improvement, comes with an IT complexity tax that must be paid by CIOs in time, money and sweat. Here are strategies to mitigate the increasing complexity of IT as it enables new business.
Read up on the latest ideas and technologies from companies that sell hardware, software and services. Solve Exchange Mailbox Storage Issues Once and for All
Revolutionising Back-up and Recovery
Cutting printer costs
Email Archiving Implementation: Five Costly Mistakes to Avoid
Email Archiving Technical Overview
Taking On Demand CRM Integration to the Next Level
Best Practice in Building an Integrated Information Management Strategy
Strategies for Eliminating .PST Files
Zones provide focussed content from Computerworld and leading technology partners.Newsletter Subscription
A combination of simple dictionary and brute-force attacks in combination with Google hacking enabled a criminal pair to break into VOIP-provider networks and steal US$1 million worth of voice minutes, says one of the duo who has pleaded guilty to his crimes.
Had his victims observed security basics, most of the attacks would have been unsuccessful, says Robert Moore, the 23-year-old hacker from Spokane, Washington, who has been sentenced to two years in federal prison and fined US$150,000.
In the interest of corporate telecom executives that want to lock down their VOIP networks, Moore reveals his methods in a podcast interview with Telecom Junkies at thevoicereport.com.
Moore says he wrote generic software to run brute-force attacks against Cisco XM routers and Quintum Tenor voice gateways to gain access to them so he could route calls through them. These devices were located in business networks, and calls were routed through them to mask that they came from gear owned by the mastermind behind Moore's activity, Edwin Pena.
Pena was arrested last year along with Moore, but after posting bail fled the country and has not been caught.
Moore also conducted brute-force attacks against service provider networks in order to discover valid prefixes to let calls into their networks.
He designed software to generate 400 prefixes per second against the carrier gear, scanning all the combinations between 000 and 999 randomly to throw off intrusion-detection systems (IDS) that might pick up a sequential attack, Moore says. The attacks were made against VOIP gateways using the H.323 signaling protocol, but not those using SIP, he says.
The pair also scanned known corporate IP addresses for machines that might be vulnerable to their attacks, Moore says. Pena purchased a 2GB database of corporate IP addresses and their subnet ranges for US$800, he says.
"The way we got into them is that most of the telecom administrators were using the most basic password - Cisco, Cisco or admin, admin. They weren't hardening their boxes at all," Moore says.
Pena and Moore found many devices on the Internet with exposed SNMP ports that allowed probing for private information. "There were various object identifiers in the management database that would allow you to see critical information on a Cisco [router], like maybe [the] gateway where it's routing to so we would know where to choose our target," he says.
The object identifiers also helped them identify exactly what make and model machine they had found, and they used that information to research vulnerabilities those machines are known to have so they could exploit them, he says.
He also wrote search strings that he fed into Google seeking exposed Web interfaces on devices, and that proved fruitful as well. "It was really easy actually to launch these things from Google to find these peoples' switches," Moore says.
Dan York, a director of the VOIP Security Alliance who participated in the Moore interview, says standard best practices would thwart Moore's and Pena's tactics. "The attacks were relatively simple attacks that could have been prevented by IT Security 101," he says.
For instance, brute-force prefix searches could be headed off limiting numbers of logon attempts and timing out attempts after a set period. Closing up unused ports of Internet-exposed devices would reduce the chances of being probed, he says.
York also suggests businesses use attack tools published by VOIPSA to test individual VOIP networks for weaknesses.
Moore says Pena initially approached him to develop such tools allegedly to test his own network. Later, it became clear Pena was involved in illegal activity, but Moore continued to work for him because the money was good. He says he wanted to use the proceeds to pay medical bills for his parents who had cancer and lupus.
He says he was paid US$23,000.
Pena is charged with setting up a VOIP wholesaling business that routed calls from his customer's networks onto the networks of VOIP carriers that he and Moore had been able to compromise. Prosecutors said he took in more than $1 million from his customers.
Computerworld Member Login
Discover how SOA can create smarter outcomes for your business.
Attend and learn:
- How SOA is helping leading companies to become more agile
- Where you should be applying SOA processes in your company
- The top SOA implementation mistakes to avoid
Click here for more information.
- +
Computerworld Live Podcast #97: The Future of Enterprise Networking 25/07/2008 09:45:36
This week CW Live chats with Mark Thompson, global sales and marketing manager for HP ProCurve, on the future of the enterprise networking. Mark discusses the trends we can expect to see in the near future and how the right infrastructure can ensure your enterprise network is secure. - +
Computerworld Live Podcast #96: Security at the Edge 11/06/2008 09:22:22
CW Live speaks with Amol Mitra, HP ProCurve Director of Marketing for Asia Pacific and Japan. Today's topic: how enterprises are starting to shift away from simply controlling security via server logins, firewalls and moving to more adaptive security frameworks. - +
Data Management Edition #10: Multi-Petascale Systems 02/05/2008 09:12:33
This week we look at sustainability and the development of multicore technologies to build multi-petascale systems. - +
IT Security Edition #11: How to poison the Storm botnet 01/05/2008 08:51:55
This week CW Live presents a case study on how to poison the notorious Storm botnet . Plus we take a look at Cisco's plans for Ironport. - +
IT Security Edition #10: Cyber-battles fought and won 24/04/2008 11:09:47
Vendors bow to end user pressure to improve product security, and we take a look at the latest concepts shaping the cyber-battlefield of the future.
F-Secure achieves excellent results in Internet security suite comparison 2008-10-10 14:37:00+10
M2M Connectivity announces the new Sierra Wireless MC8792V embedded module for 900 MHz 3G/HSPA networks 2008-10-10 08:51:00+10
Pitney Bowes MapInfo Launches New Version of AnySite 2008-10-10 05:58:00+10
IOGEAR Gears Up in Australia 2008-10-09 20:18:00+10
Internet Service Providers offer new unlimited Online Backup from F-Secure 2008-10-09 19:42:00+10
Web Security SaaS: The Next Generation of Web Security
Discover the latest web security SaaS solutions. Learn how to increase overall security effectiveness and reduce the burden on your IT department. Uncover the security challenges facing SMB environments today and identify the critical elements that can provide you with lower-cost and easier-to-manage web security solutions.










