IVR Security: Internal Network attacks via phone lines

By Rahul Sasi on 15 Feb 2012 @ Nullcon
πŸ“Ή Video πŸ”— Link
ivrs redteam
Focus Areas: Telecommunications Security , Penetration Testing

Abstract

The following research is on IVR (InteractiveVoice Response) systems which are currently used in Phone Banking, Call centers, Hospitals and corporate mainly for information retrieval and Remote Management via Telephone lines. The paper explains a serious of security issues concerning these systems (IVR) and exploitation techniques and ways of carrying out attacks on internal network via Telephone lines.A demonstration of few exploits on IVR systems and a real incident about a critical responsibly disclosed banking flow in its Phone Banking System would be done.