Home | Register |    
 
Forums         |        Articles          |      Software          |      Portals          |      Resource          |      Wiki      |    White Papers         
 
Go Back   PBX Info :: Your Free PBX, PABX and Telephone Information Resource > PBX SYSTEMS > NORTEL > BCM and Norstar
   SEARCH  
     
User Name Password      
Save ?
BCM and Norstar ICS, CICS, MICS, BCM, BCM 50 BCM 200 and BCM 400, Startalk Voicemail call pilot 150

Tags: , , , , ,


Post New Thread  Reply
 
LinkBack Thread Tools Display Modes
Old 02-17-2006, 01:14 PM   #1 (permalink)
snickered
Junior Member

Activity Longevity
0/20 9/20
Today Posts
0/0 ssssssss1
Rep Power: 0snickered is on a distinguished road

Total Points:
Donate

CALL PILOT - CENTREX USERS

I have some toll fraud going on. I think the perpetrator is coming in and going to voice mail then somehow getting an outside line. My logs are similar in the offending cases. Here is what a couple look like.

-------- 02/15/06 17:03:04 LINE = 0131 STN = 268
CALLING NUMBER 7185305773
NAME WIRELESS CALLER
UNKNOWN
BC = SPEECH
00:00:00 INCOMING CALL RINGING 0:08
00:00:31 HOLD
00:00:41 TRANSFERRED

-------- 02/15/06 17:03:45 LINE = 0131 STN = 267
00:00:00 FROM TRANSFER
00:00:00 UNHOLD
00:00:41 CALL RELEASED

-------- 02/15/06 17:03:06 LINE = 0075 STN = 375
BC = SPEECH
00:00:00 OUTGOING CALL
DIGITS DIALED 0116324304539
00:02:17 CALL RELEASED
++++++++++++++++++++++++++++++++++++
*021506 183600 0121 270 PRIVATE PRIVATE U A

-------- 02/15/06 18:39:21 LINE = 0123 STN = 269
BC = SPEECH
00:00:00 INCOMING CALL RINGING 0:05
00:00:07 CALL RELEASED

-------- 02/15/06 18:39:45 LINE = 0130 STN = 269
BC = SPEECH
00:00:00 INCOMING CALL RINGING 0:05
00:00:05 CALL RELEASED

-------- 02/15/06 18:36:33 LINE = 0124 STN = 269
BC = SPEECH
00:00:00 INCOMING CALL RINGING 0:04
00:00:08 HOLD
00:00:09 UNHOLD
00:02:48 HOLD
00:02:58 UNHOLD
00:03:12 HOLD
00:03:19 UNHOLD
00:03:19 HOLD
00:03:22 UNHOLD
00:03:23 CALL RELEASED

-------- 02/15/06 18:39:05 LINE = 0075 STN = 375
BC = SPEECH
00:00:00 OUTGOING CALL
DIGITS DIALED 0116324304539
00:00:51 CALL RELEASED
++++++++++++++++++++++++++++++++++++
There is a patter with the LINE and STN. That particular STN is my voice mail used by my remote users. And that line is an outbound trunk.

I have read around in the documentation of my switch (BCM 2.5/CallPilot 1.0) and they make mention of people being able to access outside lines (in my case LINE 0075). It particularly says "remote users can choose a line." How do they switch the line they are using manually? I figure if I can disable this functionality it would be a good step.

I am very new to this phone business so please go easy on me. I am sorry if I butchered your terminology in any way.
snickered is offline   sendpm.gif Reply With Quote
Old 02-17-2006, 02:52 PM   #2 (permalink)
gogoGophers
Junior Member
 
gogoGophers's Avatar

Activity Longevity
1/20 16/20
Today Posts
0/0 ssssss650
Location: Meechigan
Rep Power: 5gogoGophers is on a distinguished road

Total Points:
Donate
Gender:
Country:
Detroit Tigers Detroit Pistons Detroit Lions

Toll Fraud is a large, complicated subject. I have been working on N* and BCM's for quite a while and I don't even understand all the ways an auto-attendant/voicemail system can be hacked. I have been involved in a few toll fraud cases over the years, and even then, Nortel support just gives you ways to combat it, they don't explain exactly how they think someone hacked your system. They don't want people to know all the ways to hack thier stuff. Also, if I was an expert in toll fraud, it would be unwise to post methodologies of phreaking on this site.
All that being said, I have some comments. Specifically, there are ways of allow remote users access to thier voicemail boxes that do not involve the use of a dedicated, unattended extension. Look under remote access in the Call Pilot docs. You need to practice good password policy for AA programming and individual mailboxs. If you have any remote programming access (dial up or network) disable/disconnect these at least for the near term. Go through your mailbox list and delete all unused mailboxes. Go through all the individual mailboxes and deny outbound transfer and remote message notification. If someone ABSOLUTELY needs these features, you may want to deny them for the near term until the hackers move on to greener pastures. If the hacking continues, you may have to use business hours based or full time restriction service. This is set up under Telephony Services/Scheduled Services/Restriction Services. See the docs. Essentially, a user will have to input a 6 digit class of service code to make an outgoing phone call. Offsite users cannot , to my knowledge, bypass programmed line/set restrictions. If you have management/users barking about this, consider the following:
A year or so ago, we had a customer, BCM, sattelite office of less than 10 people, get hacked to the tune of 50K. No foolin'. Sprint was thier LD carrier and thier policy , even though it was painfully obvious which calls were phreakers, was - these are your lines, the calls were made on your lines, we don't administer your phone system, pay now. Last I heard they offered to settle for a measly 25 grand. We tried all manner of the usual procedures and the hacking did not stop until we implemented 24 hour line/set restrictions that meant a 6 digit COS password for every single outgoing call.
I'm sure others have stories, good luck.
gogoGophers is offline   sendpm.gif Reply With Quote
Old 02-17-2006, 03:17 PM   #3 (permalink)
gogoGophers
Junior Member
 
gogoGophers's Avatar

Activity Longevity
1/20 16/20
Today Posts
0/0 ssssss650
Location: Meechigan
Rep Power: 5gogoGophers is on a distinguished road

Total Points:
Donate
Gender:
Country:
Detroit Tigers Detroit Pistons Detroit Lions

This is good also ;

http://pbxinfo.com/index.php?name=PN...4be90c7036dc48
gogoGophers is offline   sendpm.gif Reply With Quote
Post New Thread  Reply



Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On

Similar Threads
Thread Thread Starter Forum Replies Last Post
Toll Fraud Help TelecomDude Definity Support 14 11-06-2003 09:55 AM

Tags   |   Advertise    |    Media Partners   |    Admin   |   About us   |   Contact Us   |   RSS   


Powered by vBulletin® Version 3.6.4
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Search Engine Friendly URLs by vBSEO 3.0.0
Copyright PBXINFO LLC 2006