|
There are more ways to access an organisation’s network than just hacking the Internet.
Today hackers are using war-dialing tactics – a technique to automatically scan a list of telephone numbers to search for computers - to locate vulnerable out-of-band entry points into the organisation such as modems and manipulate them to access corporate networks.
Despite the risks few organisations include war dialing as part of their regular external security audits. This opens them to potential network security breaches due to the lack of knowledge of rogue or poorly configured modems attached to their network infrastructure.
Many organisations may not even be aware of their existence as rogue modems may have been installed by disgruntled employees or an attacker who has breached the physical perimeter of the organisation.
By using war dialing techniques hackers can gain access to the protected network without having to compromise the corporate firewall that sits between public and private networks. Sometimes, these systems won’t even require valid authentication credentials (e.g. username and password) to be able to gain access to systems within the organisation’s network perimeter.
As with any vulnerability assessment, to receive the full benefits war dialing assessments should be performed on a continuous cycle. This will allow an organisation to perform trend analysis, which over time; can be used as a measure to answer the question, “Are we getting better?”
Benefits of War Dialing Assessment
- Locates insecure modems
- Locates insecure dial-in accounts
- Inventory and lock down devices accessible by PSTN
- Creates a base line for future war dialing assessments
- Tests and locates out–of-band devices
- Identifies holes and provides recommendations for repairing them
- Thwarts backdoor break-ins
- Enumerates current modem status
- Locates phone lines on your PBX that are not being used
- Locates rogue modems that may have been placed on your network for nefarious purposes
- Locates misconfigured remote access servers
- Locates inadequately secured remote access accounts
|