EH-Net

Ethical Hacking Discussions and Related Certifications => Network Pen Testing => Topic started by: SephStorm on November 11, 2010, 07:02:04 AM



Title: WarDialing
Post by: SephStorm on November 11, 2010, 07:02:04 AM
I have seen this in computer security books for years as a pentesting skill. I figured, that with how long its been around, and well known eventually it would be useless and done away with, that doesnt seem to be the case, as it is still in books of today. So my question is, is war dialing still a useful and viable technique?


Title: Re: WarDialing
Post by: chrisj on November 11, 2010, 10:11:25 AM
Yes. You'd be surprised at how many systems are still connected to modems. Three that I know of.

1) Certain agencies in the government only all data to be passed to them by dial-up. The stance is, it's more secure than sending it over the internet.

2) System managers that have monitoring systems set up to send pages via dial up fail backs.

(https://encrypted.google.com/search?hl=en&q=sending+sms+over+dial+up)

3) systems that have to send faxes, may not be set up to ignore incoming phone calls.

*edit: Adding 1 more I know of.

4) Telco's providing turnkey solutions, maintaining the circuits and the routers, still use dial up for out of band access.

I've either seen or have been told about all 4 of those in the last two years.


Title: Re: WarDialing
Post by: ckirsch on November 11, 2010, 04:35:38 PM
Have you checked out WarVox yet?


Title: Re: WarDialing
Post by: SephStorm on November 11, 2010, 09:44:51 PM
Never heard of it.

*Thanks chris.