Member You
#1 in Business Subscribe Email Print

You are here: Home > Business > Business > Prevent Your Business From Falling Victim To Dial Through Fraud

Tags

  • cuthow
  • proactively
  • modemssecure access
  • identify unused
  • gives police

  • Links

  • Trust in Government; We Wish it Were That Simple
  • The Reason Why
  • Are Omega 3 Fatty Acids Used For Joint Health And Are They Effective?
  • Member You - Prevent Your Business From Falling Victim To Dial Through Fraud

    How Can I Make Money With Surveys On The Web
    Do Online Surveys Really Pay?Anyone and everyone seem to be making a "paid surveys" website now-a-days. Not that it is difficult to make one, it is just a matter of some basic skills and a few hours of time, and they are raring to go. Most of these websites have single most intent – to make you pay to be a member, so that they would render you the service of pointing you to other URL's, where you can find and fill out surveys that pay. If you fall for them, you will find that they lead you to URL's of companies that have long ceased to exist or to websites that would ask you to pay again to join their websites.These websites charge anywhere between $30-$100 in fee for accessing their database or list of "highly paid" survey sources. But these websites offer you nothing else other than a waste of time and money ... As per the our research conducted in July 2006, which reviewed hundred's of work from home scams and paid survey websites, by interviewing their clients, workers and o
    dems
    Secure access modems tend to be hardware based. One modem is connected to the PBX, while one or more modems are deployed in the field. The modems use an encrypted secret key and a unique ID to provide a challenge/response to incoming calls. Consequently only a modem with a matching encrypted secret key, using an ID that is allowed by the PBX modem will be able to connect.

    This provides a more flexible alternative to calling from a single phone number. The modem is self contained and does not require any special software. It is unlikely that a random hacker using a standard modem will be able to breach this initial barrier.

    Hardware Acting As An Intermediary
    If you use a hardware appliance, it can act as a gateway between the PBX and the user. It could log all login attempts. It could be configured to send out an alert (as an email for example) when it detects multiple login failures. This type of behaviour would occur if a hacker was using a brute force attack to try and discover the password.

    Different combinations of usernames and passwords could be given different levels of access to the PBX. Users can therefore be restricted to performing only certain actions from a limited menu choice. This prevents the hacker from gaining full unrestricted access to all of the administration functionality.

    Proactiv

    T.G.I.M. - Thank God It's Monday
    Start strong on Monday if you want better sales results at the end of the week on Friday. Here are 11 practical sales tips:1. Set your alarm clock for 30 minutes earlier every Monday morning. It's a great way to start a week of selling.2. Back your car into your garage every Sunday night. You'll begin every Monday morning headed in the right direction.3. Begin the new week with a written priority to do list (Your six-pack). Focus on getting the most important things done first - like prospecting for new business.4. Set (in writing) defined objectives for every sales call - every sales call. Your customers can tell when your winging it.5. Attempt to obtain at least one customer commitment for every sales call. You're more likely to do this on Tuesday if you begin doing it on Monday.6. Make two proactive telephone sales calls to prospects. Make it a personal priority to prospect everyday starting Monday mornings.7. Send a handwritten or e-mai
    What steps would you take to protect your business from a burglar coming in after office hours and stealing ?40,000? I suspect that you would make sure that all the doors have very good locks. You would install a burglar alarm and maybe even have CCTV surveillance. That should protect your business. Wrong! The burglar did not break into your office; they broke into your internal phone exchange (PBX). Unseen by human or electronic eyes, thousands of pounds are being spent on international telephone calls and your business will pay the bill.

    How Does It Work?
    Dial through fraud is not a new problem, it just has limited publicity. It exploits a PBX feature that allows employees to ring in to the switchboard and by keying certain dialling codes, make national and international calls for which the company will pay the bill.

    Many businesses will take an "It will never happen to me" approach to dial through fraud, even though most business PBXs are setup to be maintained remotely. This is to allow engineers from a maintenance company to make changes to the configuration without needing to make a site visit but it exposes the PBX. The administration port on the PBX will be connected to a modem that in turn is connected to an extension on the PBX.

    Using trial and error, hackers will identify the number that this modem is on. The default passwords like "admin", "0000" or "1234" will be tried first. Even if the password has been changed, there are plenty of free utilities on the Internet that will use brute force to try every number and letter combination until the right password is found. It has been known for 16 character passcodes to be cracked in this way.

    Once the hacker has gained administrative access to your PBX, they will identify unused extension numbers and set them up to allow dial through using the company PSTN lines. For the cost of a local phone call, the hacker can be making calls to the Middle East, Far East, Africa, Australasia, etc. Some of these calls could be costing the business up to ?3 a minute.

    To compound the problem, the hacker will usually set up a disguised PBX that routes its calls through the company PBX. The hacker will then operate a "Call Sell"; selling international calls to customers at cheap rates. Alternatively they could make calls to their own premium rate revenue share services. It is possible that during the 15 hours when your office is closed, up to 10 simultaneous calls could be occurring. And that is just for one day! The problem is likely to go unnoticed and unresolved until the phone bill arrives at the end of the month.

    It Will Never Happen To Me
    A recent report in the Guardian highlighted the plight of one UK Company that suffered from a fraud attack. The company had secured its PBX with a 16 character password but it was still compromised. The discovery of the fraud was by pure chance when the MD of the company came into the office early one day to find the lights on the telephone switchboard lit up like a Christmas tree, even though he was the only one in the office.

    The report showed that recovering the losses was not easy. Although the company's Telco admitted that the calls were fraudulent, it was not their responsibility to secure the customer's equipment from attack. Therefore the customer was liable for any calls made through the PBX. It was also discovered that the company's insurance policy had a standard clause exempting it from any "electronic losses".

    A Matter For The Police
    Surely if a fraud has been perpetrated, then the police should investigate the matter? This is true. The Regulation of Investigatory Powers Act 2000 (Ripa) gives police the power to request "intercept data" from the Telco that would identify the origin of the inbound calls into the PBX. Under the act, a Telco is allowed to charge up to ?1,500 to cover their costs of retrieving the data asked for by the police. This means that in every case, the police must decide whether the financial losses involved in the fraud justifies the cost of the "intercept data". For big losses, the answer is likely to be yes every time. However, in small cases involving just a few hundred or few thousand pounds, the answer may not be so clear cut.

    How Can It Be Prevented
    The most obvious way is not to allow remote access to the administration facilities of the PBX. However this may not be practical and could lead to increased charges from the maintenance company. The second method is to use a very random password on the PBX, up to the maximum number of characters and to lock the modem so that it will only answer calls from a single phone number. This solution is very inflexible and after a while could be turned off if it becomes impractical.

    Ideally, you would want a solution that could offer the following benefits:

    1. Use a modem that employs authenticated encryption to prevent hackers with standard modems from being able to connect.
    2. Some hardware to act as an intermediary between the connection and the PBX. The hardware could then determine through a username/password what level of access to give to the PBX.
    3. The hardware should proactively monitor the PBX looking for the first signs of fraudulent activity.

    Secure Access Modems
    Secure access modems tend to be hardware based. One modem is connected to the PBX, while one or more modems are deployed in the field. The modems use an encrypted secret key and a unique ID to provide a challenge/response to incoming calls. Consequently only a modem with a matching encrypted secret key, using an ID that is allowed by the PBX modem will be able to connect.

    This provides a more flexible alternative to calling from a single phone number. The modem is self contained and does not require any special software. It is unlikely that a random hacker using a standard modem will be able to breach this initial barrier.

    Hardware Acting As An Intermediary
    If you use a hardware appliance, it can act as a gateway between the PBX and the user. It could log all login attempts. It could be configured to send out an alert (as an email for example) when it detects multiple login failures. This type of behaviour would occur if a hacker was using a brute force attack to try and discover the password.

    Different combinations of usernames and passwords could be given different levels of access to the PBX. Users can therefore be restricted to performing only certain actions from a limited menu choice. This prevents the hacker from gaining full unrestricted access to all of the administration functionality.

    Proactive

    Metal Detectors Ratings
    Metal detectors can be employed for a variety of applications in security, humanitarian, and industrial sectors. Metal detectors ratings are helpful for newcomers to choose metal detectors that are apt for them. Generally, metal detectors are rated by cost effectiveness, features, functions and usability.Different types of metal detectors are available. Typical metal detectors come with less features and buttons, but some are more complicated. If a customer wishes to choose metal detectors for extended use, it is better to select those with electronic features. The price of metal detectors may vary, based on features and functions. Aside from the normal rates of a detector, the customer must also spend on headphones, beach scoops, trowels, detector bag or coil cover. A good headphone extends the sound of the warning signal.The criteria to be considered for high ranking are usability and features. Prices are yet another consideration in metal detector ratings. Metal detectors are a
    sswords like "admin", "0000" or "1234" will be tried first. Even if the password has been changed, there are plenty of free utilities on the Internet that will use brute force to try every number and letter combination until the right password is found. It has been known for 16 character passcodes to be cracked in this way.

    Once the hacker has gained administrative access to your PBX, they will identify unused extension numbers and set them up to allow dial through using the company PSTN lines. For the cost of a local phone call, the hacker can be making calls to the Middle East, Far East, Africa, Australasia, etc. Some of these calls could be costing the business up to ?3 a minute.

    To compound the problem, the hacker will usually set up a disguised PBX that routes its calls through the company PBX. The hacker will then operate a "Call Sell"; selling international calls to customers at cheap rates. Alternatively they could make calls to their own premium rate revenue share services. It is possible that during the 15 hours when your office is closed, up to 10 simultaneous calls could be occurring. And that is just for one day! The problem is likely to go unnoticed and unresolved until the phone bill arrives at the end of the month.

    It Will Never Happen To Me
    A recent report in the Guardian highlighted the plight of one UK Company that suffered from a fraud attack. The company had secured its PBX with a 16 character password but it was still compromised. The discovery of the fraud was by pure chance when the MD of the company came into the office early one day to find the lights on the telephone switchboard lit up like a Christmas tree, even though he was the only one in the office.

    The report showed that recovering the losses was not easy. Although the company's Telco admitted that the calls were fraudulent, it was not their responsibility to secure the customer's equipment from attack. Therefore the customer was liable for any calls made through the PBX. It was also discovered that the company's insurance policy had a standard clause exempting it from any "electronic losses".

    A Matter For The Police
    Surely if a fraud has been perpetrated, then the police should investigate the matter? This is true. The Regulation of Investigatory Powers Act 2000 (Ripa) gives police the power to request "intercept data" from the Telco that would identify the origin of the inbound calls into the PBX. Under the act, a Telco is allowed to charge up to ?1,500 to cover their costs of retrieving the data asked for by the police. This means that in every case, the police must decide whether the financial losses involved in the fraud justifies the cost of the "intercept data". For big losses, the answer is likely to be yes every time. However, in small cases involving just a few hundred or few thousand pounds, the answer may not be so clear cut.

    How Can It Be Prevented
    The most obvious way is not to allow remote access to the administration facilities of the PBX. However this may not be practical and could lead to increased charges from the maintenance company. The second method is to use a very random password on the PBX, up to the maximum number of characters and to lock the modem so that it will only answer calls from a single phone number. This solution is very inflexible and after a while could be turned off if it becomes impractical.

    Ideally, you would want a solution that could offer the following benefits:

    1. Use a modem that employs authenticated encryption to prevent hackers with standard modems from being able to connect.
    2. Some hardware to act as an intermediary between the connection and the PBX. The hardware could then determine through a username/password what level of access to give to the PBX.
    3. The hardware should proactively monitor the PBX looking for the first signs of fraudulent activity.

    Secure Access Modems
    Secure access modems tend to be hardware based. One modem is connected to the PBX, while one or more modems are deployed in the field. The modems use an encrypted secret key and a unique ID to provide a challenge/response to incoming calls. Consequently only a modem with a matching encrypted secret key, using an ID that is allowed by the PBX modem will be able to connect.

    This provides a more flexible alternative to calling from a single phone number. The modem is self contained and does not require any special software. It is unlikely that a random hacker using a standard modem will be able to breach this initial barrier.

    Hardware Acting As An Intermediary
    If you use a hardware appliance, it can act as a gateway between the PBX and the user. It could log all login attempts. It could be configured to send out an alert (as an email for example) when it detects multiple login failures. This type of behaviour would occur if a hacker was using a brute force attack to try and discover the password.

    Different combinations of usernames and passwords could be given different levels of access to the PBX. Users can therefore be restricted to performing only certain actions from a limited menu choice. This prevents the hacker from gaining full unrestricted access to all of the administration functionality.

    Proactiv

    Professional Document Destruction Tips
    Document shredding is an essential measure to protecting your home or business's personal information. Learn the advantages of on site and off site professional document destruction.Identity theft is becoming more common. So are crimes like bank fraud and business spying. Believe it or not, dumpster divers are a real problem. Whether it be protecting yourself against someone opening a credit card under your name, or saving against an outsider learning your business secrets, document shredding has become a necessity in today's society.There are a few choices when it comes to shredding secure information. First is purchasing a small in-house shredder. This works for very minor tasks, such as shredding a couple bills or credit card applications received in the mail. This option is best for families who do not go through much paper. Businesses on the other hand would benefit from professional document shredding services.There are two main options when it comes to professional s
    ry/0,,1776705,00.html">report in the Guardian highlighted the plight of one UK Company that suffered from a fraud attack. The company had secured its PBX with a 16 character password but it was still compromised. The discovery of the fraud was by pure chance when the MD of the company came into the office early one day to find the lights on the telephone switchboard lit up like a Christmas tree, even though he was the only one in the office.

    The report showed that recovering the losses was not easy. Although the company's Telco admitted that the calls were fraudulent, it was not their responsibility to secure the customer's equipment from attack. Therefore the customer was liable for any calls made through the PBX. It was also discovered that the company's insurance policy had a standard clause exempting it from any "electronic losses".

    A Matter For The Police
    Surely if a fraud has been perpetrated, then the police should investigate the matter? This is true. The Regulation of Investigatory Powers Act 2000 (Ripa) gives police the power to request "intercept data" from the Telco that would identify the origin of the inbound calls into the PBX. Under the act, a Telco is allowed to charge up to ?1,500 to cover their costs of retrieving the data asked for by the police. This means that in every case, the police must decide whether the financial losses involved in the fraud justifies the cost of the "intercept data". For big losses, the answer is likely to be yes every time. However, in small cases involving just a few hundred or few thousand pounds, the answer may not be so clear cut.

    How Can It Be Prevented
    The most obvious way is not to allow remote access to the administration facilities of the PBX. However this may not be practical and could lead to increased charges from the maintenance company. The second method is to use a very random password on the PBX, up to the maximum number of characters and to lock the modem so that it will only answer calls from a single phone number. This solution is very inflexible and after a while could be turned off if it becomes impractical.

    Ideally, you would want a solution that could offer the following benefits:

    1. Use a modem that employs authenticated encryption to prevent hackers with standard modems from being able to connect.
    2. Some hardware to act as an intermediary between the connection and the PBX. The hardware could then determine through a username/password what level of access to give to the PBX.
    3. The hardware should proactively monitor the PBX looking for the first signs of fraudulent activity.

    Secure Access Modems
    Secure access modems tend to be hardware based. One modem is connected to the PBX, while one or more modems are deployed in the field. The modems use an encrypted secret key and a unique ID to provide a challenge/response to incoming calls. Consequently only a modem with a matching encrypted secret key, using an ID that is allowed by the PBX modem will be able to connect.

    This provides a more flexible alternative to calling from a single phone number. The modem is self contained and does not require any special software. It is unlikely that a random hacker using a standard modem will be able to breach this initial barrier.

    Hardware Acting As An Intermediary
    If you use a hardware appliance, it can act as a gateway between the PBX and the user. It could log all login attempts. It could be configured to send out an alert (as an email for example) when it detects multiple login failures. This type of behaviour would occur if a hacker was using a brute force attack to try and discover the password.

    Different combinations of usernames and passwords could be given different levels of access to the PBX. Users can therefore be restricted to performing only certain actions from a limited menu choice. This prevents the hacker from gaining full unrestricted access to all of the administration functionality.

    Proactiv

    Selling Equity In Your Business to Raise Funds
    Whether you are just starting a new business or need a cash infusion, the idea of selling an ownership interest will come to mind at some point. The question is whether this is a good idea or not.A business is in many ways the realization of a dream. Instead of working to put money in the pocket of someone else, you are doing it for yourself. Hopefully, you are also starting a business in a field that you find incredibly interesting. As the old saying goes, work in a field you love and you will not feel like you are working. If you can meet this goal, the money will follow sooner or later.As with many things, running a business comes with a unique set of issues that have to be addressed. Sooner or later, one of those problems will be your cash flow. You may be going through a rough patch and need funds to get you through a slow couple of months. On a more positive development, business may be great yet you still need more cash because you simply can’t keep up with the pace of manu
    nancial losses involved in the fraud justifies the cost of the "intercept data". For big losses, the answer is likely to be yes every time. However, in small cases involving just a few hundred or few thousand pounds, the answer may not be so clear cut.

    How Can It Be Prevented
    The most obvious way is not to allow remote access to the administration facilities of the PBX. However this may not be practical and could lead to increased charges from the maintenance company. The second method is to use a very random password on the PBX, up to the maximum number of characters and to lock the modem so that it will only answer calls from a single phone number. This solution is very inflexible and after a while could be turned off if it becomes impractical.

    Ideally, you would want a solution that could offer the following benefits:

    1. Use a modem that employs authenticated encryption to prevent hackers with standard modems from being able to connect.
    2. Some hardware to act as an intermediary between the connection and the PBX. The hardware could then determine through a username/password what level of access to give to the PBX.
    3. The hardware should proactively monitor the PBX looking for the first signs of fraudulent activity.

    Secure Access Modems
    Secure access modems tend to be hardware based. One modem is connected to the PBX, while one or more modems are deployed in the field. The modems use an encrypted secret key and a unique ID to provide a challenge/response to incoming calls. Consequently only a modem with a matching encrypted secret key, using an ID that is allowed by the PBX modem will be able to connect.

    This provides a more flexible alternative to calling from a single phone number. The modem is self contained and does not require any special software. It is unlikely that a random hacker using a standard modem will be able to breach this initial barrier.

    Hardware Acting As An Intermediary
    If you use a hardware appliance, it can act as a gateway between the PBX and the user. It could log all login attempts. It could be configured to send out an alert (as an email for example) when it detects multiple login failures. This type of behaviour would occur if a hacker was using a brute force attack to try and discover the password.

    Different combinations of usernames and passwords could be given different levels of access to the PBX. Users can therefore be restricted to performing only certain actions from a limited menu choice. This prevents the hacker from gaining full unrestricted access to all of the administration functionality.

    Proactiv

    Medical Billing - Insurance Carrier Perspective
    Everybody has their own point of view on every subject. In this world, our point of view, at least in our minds, is the right one. Well, that is no different in the world of medical billing. The patients think they should be paid for the claims, the medical billing companies want the patients to get paid for their claims so they can make their money and certainly the doctors want the patients to get paid for their claims or they'll go to another doctor. But what about the insurance carriers? It seems that they are the last people who want to pay claims. Well, this is for a very good reason. While everybody else is getting paid, the insurance carriers are paying out.Sure, these carriers also get a monthly premium from somewhere, whether it be from us poor workers if they are a government agency or from the patients themselves if they are a private insurance company. But the truth is, especially with government run agencies, the money coming in is far less than the money going out.
    dems
    Secure access modems tend to be hardware based. One modem is connected to the PBX, while one or more modems are deployed in the field. The modems use an encrypted secret key and a unique ID to provide a challenge/response to incoming calls. Consequently only a modem with a matching encrypted secret key, using an ID that is allowed by the PBX modem will be able to connect.

    This provides a more flexible alternative to calling from a single phone number. The modem is self contained and does not require any special software. It is unlikely that a random hacker using a standard modem will be able to breach this initial barrier.

    Hardware Acting As An Intermediary
    If you use a hardware appliance, it can act as a gateway between the PBX and the user. It could log all login attempts. It could be configured to send out an alert (as an email for example) when it detects multiple login failures. This type of behaviour would occur if a hacker was using a brute force attack to try and discover the password.

    Different combinations of usernames and passwords could be given different levels of access to the PBX. Users can therefore be restricted to performing only certain actions from a limited menu choice. This prevents the hacker from gaining full unrestricted access to all of the administration functionality.

    Proactively Monitoring For Dial Through Fraud
    A dial through fraud solution can proactively monitor the call output from the PBX. It can be set to look for suspicious call activity. In the case of the company featured in the Guardian article, this would use a "ruleset" to look for any call that occurred outside of office hours. When suspicious activity is detected, an alert would be sent out containing the details. This allows an appropriate response to be taken, reducing the potential losses caused by the fraud.

    Dial through fraud can very quickly and silently cause thousands of pounds worth of losses to a business. The standard security precautions in place to prevent it are weak, especially compared to those used on IT networks. Trying to recover any loss is as difficult as detecting the fraud in the first instance. Data Track can offer a range of Tracker Solutions that will not only add extra security to your PBX but also provide a means of detecting losses before they progress too far.

    HTTP = HTML link (for blogs, profiles,phorums):
    <a href="http://www.memberyou.net/article/2689/memberyou-Prevent-Your-Business-From-Falling-Victim-To-Dial-Through-Fraud.html">Prevent Your Business From Falling Victim To Dial Through Fraud</a>

    BB link (for phorums):
    [url=http://www.memberyou.net/article/2689/memberyou-Prevent-Your-Business-From-Falling-Victim-To-Dial-Through-Fraud.html]Prevent Your Business From Falling Victim To Dial Through Fraud[/url]

    Related Articles:

    Quickbooks Premier: A Notch Above the Rest

    Sun Zi Art Of War - Three Business Lessons From Deployment Of Troops In Marine Battles

    Move it or Lose it!

    Bookmark it: del.icio.us digg.com reddit.com netvouz.com google.com yahoo.com technorati.com furl.net bloglines.com socialdust.com ma.gnolia.com newsvine.com slashdot.org simpy.com shadows.com blinklist.com