Could your phone system be a security risk waiting to happen? Jason Green, Marketing Manager, Snom, said 'yes,' when we sat down to discuss the security of IP phones. He continued, saying: "When a burglar wants to break into a house, they generally conduct their own risk assessment before doing so."
[caption id="attachment_24722" align="alignright" width="175"]
Jason Green[/caption]
These individuals ask vital questions like: Is there anyone at home? How difficult would it be to open locked doors or windows? Is there an alarm system? If the answer is yes, can it be disabled with ease? These are similar considerations that Green says hackers weigh when hacking a business phone. "The principles are alike, but the scale is different," he noted. According to Green, the global VoIP market could reach as much as $93.2 billion by the year 2024, making phone system hacking a lucrative enterprise for skilled cybercriminals, he continued:
"With the potential for intrusion growing each year, carriers, service providers, system integrators, IT administrators, users, and of course, hard/software vendors, as well as manufacturers, must focus on and improve network security"
Gaining access to a telephony system requires hackers to have the password of the device they want to break in to. Getting this password and compromising an IP-PBX system means that hackers have to identify an IP extension on the network and blast the device with various passwords with the hope that one will work. "Although this sounds like a long shot, many users do not change their passwords from the default setting," said Green. He said that the way things work today, cyber intruders can send thousands of passwords to an extension within a few minutes, increasing their chances of success.
"Often, it does not take long for the hackers to guess the right password and logon to an IP-PBX system," he maintains. Hackers can even identify vulnerabilities in a system so they can overwrite password requirements. There is also the concept of social engineering - this is when attackers use phishing methods like posing as IT administration so they can illicitly capture employee login credentials.




