Author Topic: MiVoice Business call to high pay numbers  (Read 1003 times)

Offline nowickj

  • Jr. Member
  • **
  • Posts: 61
  • Country: pl
  • Karma: +1/-0
    • View Profile
MiVoice Business call to high pay numbers
« on: July 10, 2019, 02:39:06 AM »
Hello.

Is it possible to change Operator Extension field in Operator VM box using phone (I cannot see any changes in Audit Trial logs)? And how many times someone can type wrong PIN for VM box till box will be blocked. Additional question how someone can connect to the VM center from outside if VM HG is out of the DDI?
One of our customer had a some kind of hacker attack and system made a call to high pay number, and We have find that in Operator Extension field i VM box 0 was numer 00016042516000.


Offline PC77375

  • Full Member
  • ***
  • Posts: 191
  • Country: us
  • Karma: +6/-0
    • View Profile
Re: MiVoice Business call to high pay numbers
« Reply #1 on: July 15, 2019, 10:40:34 AM »
This can happen a number of ways- the most common is to access any VM user, then * or # until you get to the option to "login to your MB"- hackers will dial over and over until the figure out the correct pattern. Most of the time, it is pretty easy to do...admin mailboxes assigned as repetitive digits, with fairly easy passwords. This helps the installer to "remember" passwords to all of the hundreds of customers that they manage. I recommend that you CHANGE PASSWORDS for admin/manager mailboxes IMMEDIATELY! Also change the mailboxes to random digits. Also recommend you consider restricting VM from being able to access outgoing trunks. If the passcode length is 4, change it to 8. Make sure that mailbox lockout is enabled and set to max lockout duration as well. I used to have a great document on securing voicemail, I will share it if I can find it.

Offline ZuluAlpha

  • Global Moderator
  • Hero Member
  • *****
  • Posts: 692
  • Country: us
  • Karma: +17/-0
    • View Profile
Re: MiVoice Business call to high pay numbers
« Reply #2 on: July 15, 2019, 04:40:05 PM »

Offline PC77375

  • Full Member
  • ***
  • Posts: 191
  • Country: us
  • Karma: +6/-0
    • View Profile
Re: MiVoice Business call to high pay numbers
« Reply #3 on: July 16, 2019, 09:44:30 AM »
@ZuluAlpha - That looks to cover most of the basics! I had one for Nupoint as well.
I would probably add, "CHANGE ADMIN PASSCODES REGULARLY!"

Just as you have to change passwords on PC accounts, make it a habit to change VM admin passcodes as well- especially since you have been recently hacked and they may continue to try.

Offline nowickj

  • Jr. Member
  • **
  • Posts: 61
  • Country: pl
  • Karma: +1/-0
    • View Profile
Re: MiVoice Business call to high pay numbers
« Reply #4 on: July 17, 2019, 07:30:21 AM »
many THX for Your replay. Now problem is in Mitel, and We are trying to secure not only PBX but whole network.


 

Sitemap 1 2 3 4 5 6 7 8 9 10