Security Risks Associated With Transferring Through Voice Messaging Systems - Lucent Technologies MERLIN LEGEND Release 7.0 System Planning Manual

Hide thumbs Also See for MERLIN LEGEND Release 7.0:
Table of Contents

Advertisement

MERLIN LEGEND Communications System Release 7.0
System Planning 555-670-112
A
Customer Support Information
Toll Fraud Prevention
Any time a call appears to be suspicious, call the Lucent Technologies BCS
Fraud Intervention Center at 1-800-628-2888 (fraud intervention for
System 25, PARTNER
Customers should also take advantage of Lucent Technologies monitoring
services and devices, such as the NetPROTECT
detection services, CAS with HackerTracker
Watchdog. Call 1-800-638-7233 to get more information on these Lucent
Technologies fraud detection services and products.
Security Risks Associated with Transferring
through Voice Messaging Systems
Toll fraud hackers try to dial into a voice mailbox and then execute a transfer by
dialing *T. The hacker then dials an access code (either 9 for Automatic Route
Selection or a pooled facility code), followed by the appropriate digit string to
either direct dial or access a network operator to complete the call.
NOTE:
In Release 3.1 and later systems, all extensions are initially, and by default,
restricted from dial access to pools. In order for an extension to use a pool
to access an outside line/trunk, this restriction must be removed.
Preventive Measures
Take the following preventive measures to limit the risk of unauthorized transfers
by hackers:
Outward restrict all MERLIN LEGEND Communications System voice mail
port extension numbers. This denies access to facilities (lines/trunks). In
Release 3.1 and later systems, voice mail ports are, by default, outward
restricted.
As an additional security step, network dialing for all extensions, including
voice mail port extensions, should be processed through ARS using dial
access code
!
®
and MERLIN Systems).
.
9
SECURITY ALERT:
The MERLIN LEGEND Communications System ships with ARS
activated with all extensions set to Facility Restriction Level 3,
allowing all international calling. To prevent toll fraud, ARS Facility
Restriction Levels (FRLs) should be established using:
FRL 0 for restriction to internal dialing only.
FRL 2 for restriction to local network calling only.
FRL 3 for restriction to domestic long-distance (excluding
area code 809 for the Dominican Republic as this is part of
the North American Numbering Plan, unless 809 is required).
FRL 4 for international calling.
family of fraud-
SM
®
, and CAT Terminal with
7
7
Issue 1
April 1999
A-12

Advertisement

Table of Contents
loading

Table of Contents