Voip Security Advisory
Properly securing a network and phone system is essential to prevent cybercriminals from gaining unauthorised access and using the system to make fraudulent calls, typically expensive international calls. The following guidance covers key steps to ensure you have a well protected system and are not a target for this kind of fraudulent activity
How to Secure Your VoIP System
- Place SIP devices such as phones or a PBX behind a firewall or NAT. Do not expose any ports to the public internet. Where SIP registration is used, port forwarding should not be required to achieve a working SIP service
- If IP peering or IP SIP trunking is in use and port forwarding is required, restrict this to the provider source IP ranges only. Do not forward all traffic on port 5060 or any other port to the PBX — only permit the source IP prefix for SIP and RTP ports from the provider. See here for 2talk ranges.
- Do not open any management ports to the internet. Remote management should be locked down to a trusted source such as a secure VPN, trusted jump host, remote access tool or ZTNA solution. Open management ports are one of the most common ways attackers gain access to networks. Any open ports on the public IP address can be checked by running a port scan or using a publicly accessible tool such as https://www.shodan.io/ and searching your networks public IP address to check for any open ports and known vulnerabilities.
- Ensure phones and the phone system do not allow direct internet calling — that is, calls that do not originate from the configured service provider or SIP proxy. Devices with this enabled can receive ghost calls from SIP scanners, which is a common method used by attackers to probe for vulnerabilities
- Use a unique strong password for each endpoint and phone number on the account. Passwords should be at least 8 characters using a mix of letters and numbers
- If a device provisioning server is in use, ensure it is properly secured. A compromised provisioning server can expose credentials across multiple devices
- When selling or discarding computer equipment or VoIP hardware, ensure all sensitive data has been erased including settings, usernames and passwords
- Enable a PIN code for international calling from within the 2talk Cloud PBX portal to prevent unauthorised international calls
- Set a limit on auto top-up amounts in the portal to reduce financial exposure in the event of a compromise
What Can Happen if Systems Are Not Secured
Failure to properly secure a network, phones or PBX can result in multiple security issues including toll fraud, scam calls, unauthorised access to phone settings and device credentials, and unauthorised access to call recordings, voicemail and your 2talk account.