<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>AVST Blog &#187; trunk to trunk</title>
	<atom:link href="http://www.avst.com/blog/tag/trunk-to-trunk/feed" rel="self" type="application/rss+xml" />
	<link>http://www.avst.com/blog</link>
	<description>Tune into the AVST blog where AVST thought leaders and industry experts discuss issues and offer opinions pertaining to the communications marketplace.</description>
	<lastBuildDate>Wed, 01 Feb 2012 16:22:01 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0.3</generator>
		<item>
		<title>Protecting Yourself Against Toll Fraud</title>
		<link>http://www.avst.com/blog/13/protect_yourself_against_toll_fraud</link>
		<comments>http://www.avst.com/blog/13/protect_yourself_against_toll_fraud#comments</comments>
		<pubDate>Thu, 02 Oct 2008 00:00:11 +0000</pubDate>
		<dc:creator>Matt Sawyer</dc:creator>
				<category><![CDATA[Voices]]></category>
		<category><![CDATA[CallXpress]]></category>
		<category><![CDATA[hackers]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[toll fraud]]></category>
		<category><![CDATA[trunk to trunk]]></category>

		<guid isPermaLink="false">http://www.avst.com/blog/?p=13</guid>
		<description><![CDATA[These days with unlimited long distance calling plans for $30/month or less, you don&#8217;t hear too much about toll fraud taking place any more. However, it still happens from time to time where the hacker places international calls which can still be quite costly. Below is some info on just some of the ways to [...]]]></description>
			<content:encoded><![CDATA[<p><img id="Toll_Fraud" height="105" alt="Toll Fraud" width="100" align="left" src="http://www.avst.com/blog/wp-content/uploads/2008/10/icon_digitalvoice.jpg" />These days with unlimited long distance calling plans for $30/month or less, you don&#8217;t hear too much about toll fraud taking place any more. However, it still happens from time to time where the hacker places international calls which can still be quite costly. Below is some info on just some of the ways to help protect yourself agains toll fraud. This is by no means intended to be a complete list, but to highlight some of the security related features in CallXpress that you can use to help protect yourself against toll fraud.</p>
<p>The first thing to remember about security is that it is only as strong as the weakest link in the chain. For example, calling random employees posing as someone in the company&rsquo;s Telecom/IT department and asking people for their security code is the oldest trick in the book and yet still very effective.</p>
<p>Some of the ways <a target="_blank" href="http://www.avst.com/products/callxpressMessaging/index.asp" name="CallXpress">CallXpress</a> helps to protect from toll fraud are:</p>
<ul>
<li>Security code expiration &#8211; Forces users to change their security code on a periodic basis</li>
<li>Security code history &#8211; Forces users to create a certain number of unique security codes before allowing them to repeat one</li>
<li>Advanced security policy &#8211; Forces users to create security codes that do NOT contain simple combinations of digits like 0000, 1234, 2468, etc. that are easy to guess</li>
<li>Login attempts &ndash; Restricts a user to just 2 attempts per call to enter their correct security code. After the 2nd attempt, the call is automatically disconnected.</li>
<li>Mailbox lockout &#8211; Locks the mailbox after so many login attempts such that an administrator has to unlock the mailbox before it can be used again</li>
<li>Dial plan &#8211; Restricts what numbers a user&#8217;s mailbox is allowed to call for things like callout services (aka through-calling), message notification, live reply, etc.</li>
<li>Trunk to Trunk reply &ndash; Allows/restricts live reply to external numbers</li>
</ul>
<p>In addition to configuring the CallXpress security features, it&rsquo;s also recommended that you program the PBX to restrict services on the CallXpress ports to only those being offered to your user population. For example, many PBXs can restrict trunk to trunk connections involving voicemail ports.</p>
<p>Lastly, there&rsquo;s not much protection against somebody giving a hacker their security code, so you should periodically remind users to never give their security code to anyone (including Telecom/IT staff) and that they should report any instance where someone asks for their password in person, over the phone, via email, etc.</p>
<p align="left"><a target="_blank" rel="nofollow" class="tt" href="http://twitter.com/home/?status=#AVST+Protecting+Yourself+Against+Toll+Fraud+http://www.avst.com/blog/?p=13" title="Post to Twitter"><img class="nothumb" src="http://www.avst.com/blog/wp-content/plugins/tweet-this/icons/tt-twitter-micro3.png" alt="Post to Twitter" /></a></p><fb:share-button href="http://www.avst.com/blog/13/protect_yourself_against_toll_fraud" type="button"></fb:share-button>]]></content:encoded>
			<wfw:commentRss>http://www.avst.com/blog/13/protect_yourself_against_toll_fraud/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

