cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
2552
Views
4
Helpful
3
Replies

CUCM toll fraud

Gezimvatovci
Level 1
Level 1

Hi,

Can also happen toll-fraud on CUCM as in CME ??

If yes, which is the best idea to protect from toll-fraud on CUM with E1-link ??
Any suggest? 

Thanks in Advance,

GV 

1 Accepted Solution

Accepted Solutions

The CME toll-fraud mechanism is built-in CUCM since beginning. CUCM will drop calls from unknown sources which aren't defined as trunks or gateways (this can be changed using service parameters).

From this aspect CUCM is protected. However, some of the attackers will use the response message from CUCM (Internal Server Error 500) for reconnaissance such as CUCM supported messages, CUCM version, CUCM IP etc. This will require looking at other stuff such as authentication and encryption messaging.

View solution in original post

3 Replies 3

The CME toll-fraud mechanism is built-in CUCM since beginning. CUCM will drop calls from unknown sources which aren't defined as trunks or gateways (this can be changed using service parameters).

From this aspect CUCM is protected. However, some of the attackers will use the response message from CUCM (Internal Server Error 500) for reconnaissance such as CUCM supported messages, CUCM version, CUCM IP etc. This will require looking at other stuff such as authentication and encryption messaging.

Alexey Minaev
Level 1
Level 1

Here is  an article about preventing toll fraud regarding CME

http://www.cisco.com/c/en/us/td/docs/voice_ip_comm/cucme/admin/configuration/manual/cmeadm/cmetoll.html

Ratheesh Kumar
VIP Alumni
VIP Alumni

Hi

This could help you out

http://www.shanekillen.com/2013/03/how-to-prevent-toll-fraud-on.html