Your Ad Here
首页 | 编程语言 | 网站建设 | 游戏天堂 | 冲浪宝典 | 网络安全 | 操作系统 | 软件时空 | 硬件指南 | 病毒相关 | IT 认证
软讯网络 > 网络安全 > 安全知识 > Asterisk: A VoIP Hacker's Best Friend?
【标  题】:Asterisk: A VoIP Hacker's Best Friend?
【关键字】:Asterisk,VoIP,Hacker,Best,Friend
【来  源】:http://www.cublog.cn/u/4631/showart.php?id=153223

Asterisk: A VoIP Hacker's Best Friend?

Your Ad Here
Possibly the most disturbing news out of the Black Hat security conference last week was how Asterisk, the open source PBX, is being increasingly used by hackers in a wide variety of hard-to-stop VoIP hacks. Everyone, from home users to corporate networks, could become a target.

 

Talks at the show explained just how easily an Asterisk-based PBX can be used to launch attacks, notably "vishing" attacks, in which hackers use VoIP calls instead of phony Web links to steal personal and financial information.

Asterisk has become the hacker's favored tool because it's free, easy to use, and works with cheap, off-the-shelf hardware. Install Asterisk on an inexpensive PC, do a little tweaking, and you've got a full-blown PBX, something that previously would have been extremely expensive and time-consuming to do.

A vishing attack is simple to launch using Asterisk. War-dial using an Asterisk-based PBX, and send a recorded message to thousands of people, telling them their credit card number has been stolen, and that they need to call a phone number to solve the problem.

The number, of course, is the Asterisk-based PBX set up by the hacker. An automated message tells them to enter their credit card number and other personal information, for verification purposes. The PBX records the number and information, and the hacker now has a credit card to use.

Other hacks can be launched from Asterisk as well. There's the "man-in-the-middle" attack, in which a PBX-initiated call lures someone into calling a bank, credit card company, or other financial institution. The PBX answers, and forwards the caller to the real customer service number --- and then listens in and records the entire call. Again, the hacker comes away with personal and financial information he can use.

The upshot? Just as you shouldn't trust any unsolicited email, you also shouldn't trust any unsolicited phone calls. Asterisk-based vishing and similar attacks make fraud too easy these days.

看来Asterisk已经开始受到关注了。挺有意思的!
Windows Media 9学习笔记(一)--术语了解:【上一篇】
完全狙击4899肉鸡 [转]:【下一篇】
【相关文章】
  • 基于企业VPN的VOIP应用组网图
  • BESTINFO 短信平台
  • VOIP技术培训(一).ppt
  • cisco voip configure(GK+GW)
  • 如何成为一位 hacker
  • G11N Developement (2) --- Linux Best Practice
  • Hacker文化
  • VOIP 网络电话的误解
  • Eric S. Raymond五部曲之3.How To Become A Hacker
  • “How To Become A Hacker”摘录
  • 【随机文章】
  • 网络文件系统(NFS)安全性
  • Hibernate核心接口简介【转】
  • 在Unix环境下安装ACE
  • 翻译的IPF HOWTO,翻译的不错,
  • Windows 2000系统服务管理
  • 可变参数的用法
  • 校园网守护神:锐捷RG-WALL1000防火墙
  • vi
  • liferay中的article、structure和template之间的关系
  • 电话上网两不误。高速数据传输
  • 【相关评论】
    没有相关评论
    【发表评论】
    姓名:
    邮件:
    随机码*
    评论*
          
    |  首 页  |  版权声明  |  联系我们   |  网站地图  |
    CopyRight © 2004-2007 bbb软讯网络 All Rigths Reserved.