VoIP PBX Security Basics
What To Do if You Have Been Compromised
Unplug the PBX from the network connection.I strongly suggest having a trained IT professional deal with every aspect of the PBX. It may continue to be the connection the hackers use to make the fraudulent calls even after you think you may have secured it again. Change your SIP Trunk passwords or disable your SIP trunk at your provider to ensure the attacker cannot connect to your provider using your credentials. Just changing PBX passwords may or may not work depending on how the system was breached.
About Toll Fraud
Research suggests that toll fraud happens at twice the dollar amount of credit card fraud in the United States. In this scam fraudsters use your PBX to call overseas to call centers charging many dollars a minute. These call centers usually reside in countries that are outside of the reach of the court system making it near impossible to bring any action against the scammers.
Hackers can use your PBX to make fraudulent domestic calls as well. This usually consists of the attacker trying to get personal information from the called party for use in identity theft or calling random phone numbers to play recorded advertisements.
How Do I Protect My PBX ?
Ask yourself if you really even need a PBX. If you have a handful of extensions, a few forwards, and a menu then why pay big money to setup and constantly update a PBX? Contact a hosted PBX provider for a hosted PBX solution with security built right in and save yourself the hassle of paying for a PBX.
If you decide to keep the PBX there are some serious considerations that you need to take in order to ensure your PBX is secure. A list of those are as follows.
- Only run PBX software on a computer for your PBX and no other services
- Do not allow any PBX services or other any other services (SSH, VPC, ETC) to be accessed by the internet
- If you must run other services never run them on default ports
- Use strong random character passwords
- Always keep your PBX up to date with the latest software
- Disable all out dialing or thru-dialing functionality
- Block country codes and 900 numbers your company will never call
- Never use the same username and password on extensions. For example with the extension is 1101 the password for that extension should not be 1101
- Always place the PBX behind a firewall
- Block PING requests at the firewall to prevent discovery
- Limit registrations of extensions to the local subnet only
- Use access control lists where ever you can
- Security audit your system regularly
These are just a few ideas for keeping security in mind while using a PBX system.
