Ads by TechWords

See your link here
Subscribe to our e-mail newsletters
For more info on a specific newsletter, click the title. Details will be displayed in a new window.
Mobile/Wireless Computing
Computerworld Daily News (First Look and Wrap-Up)
Computerworld Blogs Newsletter
The Weekly Top 10
More E-Mail Newsletters 
 

Hacker hits Telecom NZ's voice mail system

May 12, 2005 12:00 PM ET

Computerworld New Zealand - AUCKLAND, New Zealand -- Telecom New Zealand Ltd.'s 027 voice mail system is vulnerable to the same hack that led to the theft of Paris Hilton's mobile phone book -- and it has been actively exploited in New Zealand.
Users of Telecom's mobile phone network can protect themselves by disabling Optional PIN entry. Optional PIN entry is a feature that allows immediate access to voice mail when calling from the owner's phone, but leaves voice mail vulnerable to callers who can forge their caller ID.
An Auckland teenager showed Computerworld New Zealand how easy it is to access 027 voice mailboxes. A test with an 027 phone and a newly changed PIN confirmed that the service is vulnerable to spoofing. With Optional PIN enabled, the teenager, who cannot be named for legal reasons, was able to reveal the PIN for the mailbox as well as play back and record messages in it. With Optional PIN turned off, the mailbox could not be accessed.
The teenager claimed he had listened to messages in the mailboxes of Telecom spokesman John Goulter and Auckland Mayor Dick Hubbard. He also hinted that he had been listening in on messages in the voice mailboxes of senior police officers and had been able to glean details such as the names of officers involved in a local police pornography scandal.
The teenager said he had also targeted Labor MP John Tamihere, but had not been able to find his phone number.
Telecom was unaware of the vulnerability when contacted by Computerworld this week. An Internet search reveals the vulnerability is known about in some quarters and has also been exploited overseas, however.
The teenager told Computerworld the contents of a message left on the phone of Telecom's public affairs and industry relations manager, John Goulter. A surprised Goulter confirmed the content of the message to Computerworld yesterday.
Goulter said Telecom regards accessing its customers' voice mail as a serious breach of security and will alert the police over the matter.
The convoluted method the teenager used involves forging the caller ID and routing the call through an overseas VoIP provider. Computerworld will not reveal further details at this time.
Telephone networks depend on physical security with access to equipment being strictly controlled, as neither calls nor the controlling signals are encrypted. There is no authentication built into the telephony protocols either -- telcos operate a "web of trust" and apply policy filters to sanitize the information received, for example, by not accepting caller IDs originating from outside their


Reprinted with permission from

For more news from Computerworld New Zealand, visit its Web site.Story copyright 2006 Computerworld New Zealand. All rights reserved.

Additional Resources

Xerox
By using solid ink technology only from Xerox, you could save up to 65% by printing color for the cost of black and white. Enter for a chance to WIN a PhaserTM 8860 network color printer!
Microsoft
Save time and mitigate security risk. Deploy it now.
Sybase
In this white paper, IDC analyzes the role of next-generation mobile enterprise platforms as organizations seek a more strategic deployment of mobile solutions.

Learn the important issues you must consider before starting your next mobility initiative. Get your mobility white paper from IDC now, compliments of Sybase.

White Papers & Webcasts

IT Best Practices: To Support or Not Support Consumer Owned Smartphones
Companies have historically standardized on a single smartphone platform. Of late, IT is facing pressure to support the increasing influx of consumer owned...  

5 Best Practice Tips for Managing BlackBerry, iPhone, & Windows Mobile Devices
(Source: Zenprise) Mobile devices continue to proliferate across the enterprise, driven largely by the increase in worker productivity, efficiency, and flexibility they provide....

Success Story: Allina Hospitals & Clinics
(Source: Absolute Software) With an electronic health record system spanning 11 hospitals, Allina required a way to protect 2,700 laptops. Using Computrace, Allina...  

How Computrace Tracks and Secures Laptops
(Source: Absolute Software) View this flash demo to see Absolute in action. No matter where computers are connected, you can monitor installed software/hardware,...

Success Story: Grant Thornton LLP
(Source: Absolute Software) Grant Thornton needed to reduce computer loss rates and streamline IT asset management across 49 offices. The company used Computrace...  

Managing Laptops Outside the Office
(Source: Absolute Software) In this webinar, learn how you can reduce costs by tracking mobile computers no matter where they are located. Featuring...

Secure Mobility with Absolute Software
(Source: Absolute Software) Absolute Software allows you to centrally manage computers and mobile devices via any internet connection. In this product overview, learn...  

What Are 'Free' Remote Support Tools Really Costing You?
(Source: LogMeIn) In this webinar from LogMeIn, discover how "next generation" remote support tools are optimized to provide advanced capabilities like scripting, system...

Intelligent Client-Side Defense for Stolen Computers by Intel® and Absolute
(Source: Absolute Software) The combination of Absolute's SaaS-based computer tracking and Intel's hardware-based Anti-Theft technology gives you an unprecedented level of theft deterrence...  

Usability Is Everything
Learn what sets Workday's HR and Payroll solutions apart from the competition....