Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations bkrike on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

#90 Scam

Status
Not open for further replies.

Arugg

MIS
Sep 14, 2004
339
US
I have been asked to make sure our PBX is not vulnerable to the 90# scam. I have tested it and when we dial 90 we get a fast busy. How can I verify that the switch is set to avoid this scam?
 
haven't heard about the scam, but in load 90


REQ prt
CUST 0
FEAT net
TRAN ac1
TYPE spn

SPN 0

SPN 0
FLEN 0
INPL NO
RLI 21
SDRR NONE
ITEI NONE

then in load 86 using the rli from ld 90

REQ prt
CUST 0
FEAT rlb
RLI 21

RLI 21
ENTR 0
LTER NO
ROUT 157
TOD 0 ON 1 ON 2 ON 3 ON
4 ON 5 ON 6 ON 7 ON
VNS NO
CNV NO
EXP NO
FRL 1
DMI 0
FCI 0
FSNI 0
SBOC NRR
IDBB DBA
IOHQ NO
OHQ NO
CBQ NO

ISET 0
NALT 5
MFRL 1
OVLL 0

that shows me when you dial 9 (ac1) you are routed to route 157...that being a tie route to another switch, 0 from a station goes to an operator, 90 goes to another hospital operator in a sister site... if it would go to a carrier, you could get bitten


john poole
bellsouth business
columbia,sc
 
Ok. I did a PRT in LD 90. I showed nothing for SPN 0. The first one to show for us is 011. So I would assume that we are not vulnerable to this scam.
 
The primary use of this scam is in conjunction with attendant consoles. People will dial the main number to a company, get the attendant, tell her to dial 9-0 or 9 or 9-1 or in some cases just the phone number they want to call 91NPANXXXXXX. I'm not sure how the programming of the console would be changed to either allow or deny transfers to the external world, but I would start there. Also, check through your stations for phones with the ability to transfer a call externally. "Hi, I'm Mr. Joe Bob with Verizon, can you test your phone for me by hitting Transfer-9 and hang up? Thanks <snicker snicker>"

Arch
 
Also, if you have Meridian mail or Call Pilot, disable trhu-dial access trought mailbox or menu services. Example:
When you acces a mailbox, you can dial 09 plus number (091-area code-xxx-xxxx), if you don´t have restrictions, you can made a call.
 
allowing a trunk to trunk transfer will no doubt give you toll fraud.. the only way to stop this totally is to train the operators or deny trunk to trunk... most toll i have seen is thru the mail..our operators have to get outside lines to insure service to patients

john poole
bellsouth business
columbia,sc
 
I recently received an email from our school President (via his Admin) asking me if this was a hoax. He requested that I inform the entire University of this scam to prevent it from happening. Needless to say, I refused although tactfully...

Oy Vey
 
always a god idea to email 1000 students as to how they can get free ld...good move

john poole
bellsouth business
columbia,sc
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top