Our Videos

December 10, 08

NEWS / NEW TECHNIQUE UTILIZING PRIVATE BRANCH EXCHANGE (PBX SYSTEMS TO CONDUCT VISHING ATTACKS


The FBI has received information concerning a new technique used to conduct vishing (1) attacks. The recent attacks were conducted by hackers exploiting a security vulnerability in Asterisk software. Asterisk is free and widely used software developed to integrate PBX (2) systems with Voice over Internet Protocol (VoIP) digital Internet voice calling services; however, early versions of the Asterisk software are known to have a vulnerability. The vulnerability can be exploited by cyber criminals to use the system as an auto dialer, generating thousands of vishing telephone calls to consumers within one hour.

The vulnerability referred to in this alert is a known vulnerability. Digium, the original creator and primary developer of Asterisk, released a Security Advisory, AST-2008-003, in March of 2008, which contains the information necessary for users to configure a system, patch the software, or upgrade the software to protect against this vulnerability.

If a consumer falls victim to this exploit, their personally identifiable information (PII) will be compromised. To prevent further loss of consumers’ PII and to reduce the spread of this new technique, it is imperative that businesses using Asterisk upgrade their software to a version that has had the vulnerability fixed.

Further, consumers should not release personal information in response to unsolicited telephone calls. Providing your PII will compromise your identity!

If you have been a victim of Internet crime, please file a complaint at www.ic3.gov.

(1) Vishing utilizes caller ID spoofing via VoIP to contact potential victims in order to gain access to their PII by convincing the victim that the criminal is associated with a legitimate business with a need to know the victim’s PII.

(2) PBX Systems are used by companies to allow telephone calls between VoIP enterprise users on local lines while allowing all users to share a limited number of external lines
http://www.fbi.gov/cyberinvest/escams.htm

 




Testimonials

Brenna Erford

Thank you SO much for all your help, and your excellent communication throughout this whole proce...
Read More »
John Beacleay

Just wanted to say thanks again for all your help Anton. I mean it's really amazing to me that yo...
Read More »
Niranjan Sujay
I recently used LOGOS INTERNATIONAL for the translation of my bachelor’s certificate, and I couldn’t...
Read More »
Katia Nagata

As a foreigner, I needed a certified translation, so I called the DOE to give me a list of the ce...
Read More »




FAQ

Q. What is the restrictive theory of sovereign immunity?
Read More »
What kind of information does an organization need to provide to the CIS in order to obtain authorization to issue the certificates?
Read More »
I have been given duplicate copies of a document, each to be notarized as an original. What fees do I charge?

Read More »
My fiance (fiancee) has been denied a B1/B2 visitor visa to the U.S. before. Could that affect the decision on her K-1 visa application if I file a K-1 Fiance (e) visa petition for her now?
Read More »






News

August 21, 26
Indian woman accused of using fake death certificate to defraud mother-in-law
Read More »
August 13, 26
Man who killed family in Kansas had extensive criminal record – report
Read More »
August 10, 26
Nebraska woman arrested over power of attorney misuse to steal over $770,000
Read More »
August 4, 26
India considers stricter requirements for delayed birth and death certificates
Read More »