Panoramica e POC su come è possibile sfruttare la tecnica dello Spoofing del Caller ID per violare la privacy delle Voice Mail. Presentanto in occasione dell'Hackmeeting 2014 (Bologna)
The report regarding the cybercrime activities conducted by threat actors through the SandiFlux fastflux botnet in the middle of 2019! We have tracked different malware campaigns including (i) attacks conducted by the APT group known as TA505, which are spreding FlawedAmmyyRAT, AmadeyBot and a EmailStealer, (ii) ransomware campaigns such as GandCrab and Sodinokibi, (iii) the campaigns of malware known as Phorphiex Worm/Trik and Ursnif, and (iv) other kind of cybercrime activities such as the hosting of phishingcampaigns and cadingsites domains.
vSphere Inventory Browser for VMware ESX/vCenter 4.xSalvatore Saeli
Produzione di un'Inventory Browser per server di tipo VMware ESX/vCenter 4.x sfruttando strumenti e tecniche di ottimizzazione server-side e client-side.
##### Problematiche affrontate:
- Ottimizzazione del numero di oggetti da creare all’interno del server a ogni sessione
- Riduzione del traffico d’informazioni tra il client e il server per contenere l’uso della banda
- Gestione dei problemi di coerenza e sincronizzazione dei dati da mantenere sul client
### Server-side
- uso degli oggetti ViewManager e View per rendere performante l’uso del PropertyCollector
- meccanismo di notifica WaitForUpdate per un uso efficiente delle risorse di rete, rimane in standby in attesa di aggiornamenti
### Client-side
- albero n-ario implementato con tabelle hash,
mantiene l’intera struttura in memoria con accesso in tempo costante ai nodi ai vari livelli dell’albero
- tecniche di multi-threading (C#) per ottenere l'esecuzione in parallelo delle operazione eseguite in background e la sincronizzazione dei dati sugli oggetti del server
- tecnica di riflessione (C#), consente l'accesso alle proprietà degli oggetti di tipo ManagedEntity dall’Inventory UI Tree
2024 State of Marketing Report – by HubspotMarius Sescu
https://www.hubspot.com/state-of-marketing
· Scaling relationships and proving ROI
· Social media is the place for search, sales, and service
· Authentic influencer partnerships fuel brand growth
· The strongest connections happen via call, click, chat, and camera.
· Time saved with AI leads to more creative work
· Seeking: A single source of truth
· TLDR; Get on social, try AI, and align your systems.
· More human marketing, powered by robots
ChatGPT is a revolutionary addition to the world since its introduction in 2022. A big shift in the sector of information gathering and processing happened because of this chatbot. What is the story of ChatGPT? How is the bot responding to prompts and generating contents? Swipe through these slides prepared by Expeed Software, a web development company regarding the development and technical intricacies of ChatGPT!
Product Design Trends in 2024 | Teenage EngineeringsPixeldarts
The realm of product design is a constantly changing environment where technology and style intersect. Every year introduces fresh challenges and exciting trends that mold the future of this captivating art form. In this piece, we delve into the significant trends set to influence the look and functionality of product design in the year 2024.
The report regarding the cybercrime activities conducted by threat actors through the SandiFlux fastflux botnet in the middle of 2019! We have tracked different malware campaigns including (i) attacks conducted by the APT group known as TA505, which are spreding FlawedAmmyyRAT, AmadeyBot and a EmailStealer, (ii) ransomware campaigns such as GandCrab and Sodinokibi, (iii) the campaigns of malware known as Phorphiex Worm/Trik and Ursnif, and (iv) other kind of cybercrime activities such as the hosting of phishingcampaigns and cadingsites domains.
vSphere Inventory Browser for VMware ESX/vCenter 4.xSalvatore Saeli
Produzione di un'Inventory Browser per server di tipo VMware ESX/vCenter 4.x sfruttando strumenti e tecniche di ottimizzazione server-side e client-side.
##### Problematiche affrontate:
- Ottimizzazione del numero di oggetti da creare all’interno del server a ogni sessione
- Riduzione del traffico d’informazioni tra il client e il server per contenere l’uso della banda
- Gestione dei problemi di coerenza e sincronizzazione dei dati da mantenere sul client
### Server-side
- uso degli oggetti ViewManager e View per rendere performante l’uso del PropertyCollector
- meccanismo di notifica WaitForUpdate per un uso efficiente delle risorse di rete, rimane in standby in attesa di aggiornamenti
### Client-side
- albero n-ario implementato con tabelle hash,
mantiene l’intera struttura in memoria con accesso in tempo costante ai nodi ai vari livelli dell’albero
- tecniche di multi-threading (C#) per ottenere l'esecuzione in parallelo delle operazione eseguite in background e la sincronizzazione dei dati sugli oggetti del server
- tecnica di riflessione (C#), consente l'accesso alle proprietà degli oggetti di tipo ManagedEntity dall’Inventory UI Tree
2024 State of Marketing Report – by HubspotMarius Sescu
https://www.hubspot.com/state-of-marketing
· Scaling relationships and proving ROI
· Social media is the place for search, sales, and service
· Authentic influencer partnerships fuel brand growth
· The strongest connections happen via call, click, chat, and camera.
· Time saved with AI leads to more creative work
· Seeking: A single source of truth
· TLDR; Get on social, try AI, and align your systems.
· More human marketing, powered by robots
ChatGPT is a revolutionary addition to the world since its introduction in 2022. A big shift in the sector of information gathering and processing happened because of this chatbot. What is the story of ChatGPT? How is the bot responding to prompts and generating contents? Swipe through these slides prepared by Expeed Software, a web development company regarding the development and technical intricacies of ChatGPT!
Product Design Trends in 2024 | Teenage EngineeringsPixeldarts
The realm of product design is a constantly changing environment where technology and style intersect. Every year introduces fresh challenges and exciting trends that mold the future of this captivating art form. In this piece, we delve into the significant trends set to influence the look and functionality of product design in the year 2024.
How Race, Age and Gender Shape Attitudes Towards Mental HealthThinkNow
Mental health has been in the news quite a bit lately. Dozens of U.S. states are currently suing Meta for contributing to the youth mental health crisis by inserting addictive features into their products, while the U.S. Surgeon General is touring the nation to bring awareness to the growing epidemic of loneliness and isolation. The country has endured periods of low national morale, such as in the 1970s when high inflation and the energy crisis worsened public sentiment following the Vietnam War. The current mood, however, feels different. Gallup recently reported that national mental health is at an all-time low, with few bright spots to lift spirits.
To better understand how Americans are feeling and their attitudes towards mental health in general, ThinkNow conducted a nationally representative quantitative survey of 1,500 respondents and found some interesting differences among ethnic, age and gender groups.
Technology
For example, 52% agree that technology and social media have a negative impact on mental health, but when broken out by race, 61% of Whites felt technology had a negative effect, and only 48% of Hispanics thought it did.
While technology has helped us keep in touch with friends and family in faraway places, it appears to have degraded our ability to connect in person. Staying connected online is a double-edged sword since the same news feed that brings us pictures of the grandkids and fluffy kittens also feeds us news about the wars in Israel and Ukraine, the dysfunction in Washington, the latest mass shooting and the climate crisis.
Hispanics may have a built-in defense against the isolation technology breeds, owing to their large, multigenerational households, strong social support systems, and tendency to use social media to stay connected with relatives abroad.
Age and Gender
When asked how individuals rate their mental health, men rate it higher than women by 11 percentage points, and Baby Boomers rank it highest at 83%, saying it’s good or excellent vs. 57% of Gen Z saying the same.
Gen Z spends the most amount of time on social media, so the notion that social media negatively affects mental health appears to be correlated. Unfortunately, Gen Z is also the generation that’s least comfortable discussing mental health concerns with healthcare professionals. Only 40% of them state they’re comfortable discussing their issues with a professional compared to 60% of Millennials and 65% of Boomers.
Race Affects Attitudes
As seen in previous research conducted by ThinkNow, Asian Americans lag other groups when it comes to awareness of mental health issues. Twenty-four percent of Asian Americans believe that having a mental health issue is a sign of weakness compared to the 16% average for all groups. Asians are also considerably less likely to be aware of mental health services in their communities (42% vs. 55%) and most likely to seek out information on social media (51% vs. 35%).
AI Trends in Creative Operations 2024 by Artwork Flow.pdfmarketingartwork
This article is all about what AI trends will emerge in the field of creative operations in 2024. All the marketers and brand builders should be aware of these trends for their further use and save themselves some time!
A report by thenetworkone and Kurio.
The contributing experts and agencies are (in an alphabetical order): Sylwia Rytel, Social Media Supervisor, 180heartbeats + JUNG v MATT (PL), Sharlene Jenner, Vice President - Director of Engagement Strategy, Abelson Taylor (USA), Alex Casanovas, Digital Director, Atrevia (ES), Dora Beilin, Senior Social Strategist, Barrett Hoffher (USA), Min Seo, Campaign Director, Brand New Agency (KR), Deshé M. Gully, Associate Strategist, Day One Agency (USA), Francesca Trevisan, Strategist, Different (IT), Trevor Crossman, CX and Digital Transformation Director; Olivia Hussey, Strategic Planner; Simi Srinarula, Social Media Manager, The Hallway (AUS), James Hebbert, Managing Director, Hylink (CN / UK), Mundy Álvarez, Planning Director; Pedro Rojas, Social Media Manager; Pancho González, CCO, Inbrax (CH), Oana Oprea, Head of Digital Planning, Jam Session Agency (RO), Amy Bottrill, Social Account Director, Launch (UK), Gaby Arriaga, Founder, Leonardo1452 (MX), Shantesh S Row, Creative Director, Liwa (UAE), Rajesh Mehta, Chief Strategy Officer; Dhruv Gaur, Digital Planning Lead; Leonie Mergulhao, Account Supervisor - Social Media & PR, Medulla (IN), Aurelija Plioplytė, Head of Digital & Social, Not Perfect (LI), Daiana Khaidargaliyeva, Account Manager, Osaka Labs (UK / USA), Stefanie Söhnchen, Vice President Digital, PIABO Communications (DE), Elisabeth Winiartati, Managing Consultant, Head of Global Integrated Communications; Lydia Aprina, Account Manager, Integrated Marketing and Communications; Nita Prabowo, Account Manager, Integrated Marketing and Communications; Okhi, Web Developer, PNTR Group (ID), Kei Obusan, Insights Director; Daffi Ranandi, Insights Manager, Radarr (SG), Gautam Reghunath, Co-founder & CEO, Talented (IN), Donagh Humphreys, Head of Social and Digital Innovation, THINKHOUSE (IRE), Sarah Yim, Strategy Director, Zulu Alpha Kilo (CA).
Trends In Paid Search: Navigating The Digital Landscape In 2024Search Engine Journal
The search marketing landscape is evolving rapidly with new technologies, and professionals, like you, rely on innovative paid search strategies to meet changing demands.
It’s important that you’re ready to implement new strategies in 2024.
Check this out and learn the top trends in paid search advertising that are expected to gain traction, so you can drive higher ROI more efficiently in 2024.
You’ll learn:
- The latest trends in AI and automation, and what this means for an evolving paid search ecosystem.
- New developments in privacy and data regulation.
- Emerging ad formats that are expected to make an impact next year.
Watch Sreekant Lanka from iQuanti and Irina Klein from OneMain Financial as they dive into the future of paid search and explore the trends, strategies, and technologies that will shape the search marketing landscape.
If you’re looking to assess your paid search strategy and design an industry-aligned plan for 2024, then this webinar is for you.
5 Public speaking tips from TED - Visualized summarySpeakerHub
From their humble beginnings in 1984, TED has grown into the world’s most powerful amplifier for speakers and thought-leaders to share their ideas. They have over 2,400 filmed talks (not including the 30,000+ TEDx videos) freely available online, and have hosted over 17,500 events around the world.
With over one billion views in a year, it’s no wonder that so many speakers are looking to TED for ideas on how to share their message more effectively.
The article “5 Public-Speaking Tips TED Gives Its Speakers”, by Carmine Gallo for Forbes, gives speakers five practical ways to connect with their audience, and effectively share their ideas on stage.
Whether you are gearing up to get on a TED stage yourself, or just want to master the skills that so many of their speakers possess, these tips and quotes from Chris Anderson, the TED Talks Curator, will encourage you to make the most impactful impression on your audience.
See the full article and more summaries like this on SpeakerHub here: https://speakerhub.com/blog/5-presentation-tips-ted-gives-its-speakers
See the original article on Forbes here:
http://www.forbes.com/forbes/welcome/?toURL=http://www.forbes.com/sites/carminegallo/2016/05/06/5-public-speaking-tips-ted-gives-its-speakers/&refURL=&referrer=#5c07a8221d9b
ChatGPT and the Future of Work - Clark Boyd Clark Boyd
Everyone is in agreement that ChatGPT (and other generative AI tools) will shape the future of work. Yet there is little consensus on exactly how, when, and to what extent this technology will change our world.
Businesses that extract maximum value from ChatGPT will use it as a collaborative tool for everything from brainstorming to technical maintenance.
For individuals, now is the time to pinpoint the skills the future professional will need to thrive in the AI age.
Check out this presentation to understand what ChatGPT is, how it will shape the future of work, and how you can prepare to take advantage.
A brief introduction to DataScience with explaining of the concepts, algorithms, machine learning, supervised and unsupervised learning, clustering, statistics, data preprocessing, real-world applications etc.
It's part of a Data Science Corner Campaign where I will be discussing the fundamentals of DataScience, AIML, Statistics etc.
Time Management & Productivity - Best PracticesVit Horky
Here's my presentation on by proven best practices how to manage your work time effectively and how to improve your productivity. It includes practical tips and how to use tools such as Slack, Google Apps, Hubspot, Google Calendar, Gmail and others.
The six step guide to practical project managementMindGenius
The six step guide to practical project management
If you think managing projects is too difficult, think again.
We’ve stripped back project management processes to the
basics – to make it quicker and easier, without sacrificing
the vital ingredients for success.
“If you’re looking for some real-world guidance, then The Six Step Guide to Practical Project Management will help.”
Dr Andrew Makar, Tactical Project Management
Unlocking the Power of ChatGPT and AI in Testing - A Real-World Look, present...Applitools
During this webinar, Anand Bagmar demonstrates how AI tools such as ChatGPT can be applied to various stages of the software development life cycle (SDLC) using an eCommerce application case study. Find the on-demand recording and more info at https://applitools.info/b59
Key takeaways:
• Learn how to use ChatGPT to add AI power to your testing and test automation
• Understand the limitations of the technology and where human expertise is crucial
• Gain insight into different AI-based tools
• Adopt AI-based tools to stay relevant and optimize work for developers and testers
* ChatGPT and OpenAI belong to OpenAI, L.L.C.
How Race, Age and Gender Shape Attitudes Towards Mental HealthThinkNow
Mental health has been in the news quite a bit lately. Dozens of U.S. states are currently suing Meta for contributing to the youth mental health crisis by inserting addictive features into their products, while the U.S. Surgeon General is touring the nation to bring awareness to the growing epidemic of loneliness and isolation. The country has endured periods of low national morale, such as in the 1970s when high inflation and the energy crisis worsened public sentiment following the Vietnam War. The current mood, however, feels different. Gallup recently reported that national mental health is at an all-time low, with few bright spots to lift spirits.
To better understand how Americans are feeling and their attitudes towards mental health in general, ThinkNow conducted a nationally representative quantitative survey of 1,500 respondents and found some interesting differences among ethnic, age and gender groups.
Technology
For example, 52% agree that technology and social media have a negative impact on mental health, but when broken out by race, 61% of Whites felt technology had a negative effect, and only 48% of Hispanics thought it did.
While technology has helped us keep in touch with friends and family in faraway places, it appears to have degraded our ability to connect in person. Staying connected online is a double-edged sword since the same news feed that brings us pictures of the grandkids and fluffy kittens also feeds us news about the wars in Israel and Ukraine, the dysfunction in Washington, the latest mass shooting and the climate crisis.
Hispanics may have a built-in defense against the isolation technology breeds, owing to their large, multigenerational households, strong social support systems, and tendency to use social media to stay connected with relatives abroad.
Age and Gender
When asked how individuals rate their mental health, men rate it higher than women by 11 percentage points, and Baby Boomers rank it highest at 83%, saying it’s good or excellent vs. 57% of Gen Z saying the same.
Gen Z spends the most amount of time on social media, so the notion that social media negatively affects mental health appears to be correlated. Unfortunately, Gen Z is also the generation that’s least comfortable discussing mental health concerns with healthcare professionals. Only 40% of them state they’re comfortable discussing their issues with a professional compared to 60% of Millennials and 65% of Boomers.
Race Affects Attitudes
As seen in previous research conducted by ThinkNow, Asian Americans lag other groups when it comes to awareness of mental health issues. Twenty-four percent of Asian Americans believe that having a mental health issue is a sign of weakness compared to the 16% average for all groups. Asians are also considerably less likely to be aware of mental health services in their communities (42% vs. 55%) and most likely to seek out information on social media (51% vs. 35%).
AI Trends in Creative Operations 2024 by Artwork Flow.pdfmarketingartwork
This article is all about what AI trends will emerge in the field of creative operations in 2024. All the marketers and brand builders should be aware of these trends for their further use and save themselves some time!
A report by thenetworkone and Kurio.
The contributing experts and agencies are (in an alphabetical order): Sylwia Rytel, Social Media Supervisor, 180heartbeats + JUNG v MATT (PL), Sharlene Jenner, Vice President - Director of Engagement Strategy, Abelson Taylor (USA), Alex Casanovas, Digital Director, Atrevia (ES), Dora Beilin, Senior Social Strategist, Barrett Hoffher (USA), Min Seo, Campaign Director, Brand New Agency (KR), Deshé M. Gully, Associate Strategist, Day One Agency (USA), Francesca Trevisan, Strategist, Different (IT), Trevor Crossman, CX and Digital Transformation Director; Olivia Hussey, Strategic Planner; Simi Srinarula, Social Media Manager, The Hallway (AUS), James Hebbert, Managing Director, Hylink (CN / UK), Mundy Álvarez, Planning Director; Pedro Rojas, Social Media Manager; Pancho González, CCO, Inbrax (CH), Oana Oprea, Head of Digital Planning, Jam Session Agency (RO), Amy Bottrill, Social Account Director, Launch (UK), Gaby Arriaga, Founder, Leonardo1452 (MX), Shantesh S Row, Creative Director, Liwa (UAE), Rajesh Mehta, Chief Strategy Officer; Dhruv Gaur, Digital Planning Lead; Leonie Mergulhao, Account Supervisor - Social Media & PR, Medulla (IN), Aurelija Plioplytė, Head of Digital & Social, Not Perfect (LI), Daiana Khaidargaliyeva, Account Manager, Osaka Labs (UK / USA), Stefanie Söhnchen, Vice President Digital, PIABO Communications (DE), Elisabeth Winiartati, Managing Consultant, Head of Global Integrated Communications; Lydia Aprina, Account Manager, Integrated Marketing and Communications; Nita Prabowo, Account Manager, Integrated Marketing and Communications; Okhi, Web Developer, PNTR Group (ID), Kei Obusan, Insights Director; Daffi Ranandi, Insights Manager, Radarr (SG), Gautam Reghunath, Co-founder & CEO, Talented (IN), Donagh Humphreys, Head of Social and Digital Innovation, THINKHOUSE (IRE), Sarah Yim, Strategy Director, Zulu Alpha Kilo (CA).
Trends In Paid Search: Navigating The Digital Landscape In 2024Search Engine Journal
The search marketing landscape is evolving rapidly with new technologies, and professionals, like you, rely on innovative paid search strategies to meet changing demands.
It’s important that you’re ready to implement new strategies in 2024.
Check this out and learn the top trends in paid search advertising that are expected to gain traction, so you can drive higher ROI more efficiently in 2024.
You’ll learn:
- The latest trends in AI and automation, and what this means for an evolving paid search ecosystem.
- New developments in privacy and data regulation.
- Emerging ad formats that are expected to make an impact next year.
Watch Sreekant Lanka from iQuanti and Irina Klein from OneMain Financial as they dive into the future of paid search and explore the trends, strategies, and technologies that will shape the search marketing landscape.
If you’re looking to assess your paid search strategy and design an industry-aligned plan for 2024, then this webinar is for you.
5 Public speaking tips from TED - Visualized summarySpeakerHub
From their humble beginnings in 1984, TED has grown into the world’s most powerful amplifier for speakers and thought-leaders to share their ideas. They have over 2,400 filmed talks (not including the 30,000+ TEDx videos) freely available online, and have hosted over 17,500 events around the world.
With over one billion views in a year, it’s no wonder that so many speakers are looking to TED for ideas on how to share their message more effectively.
The article “5 Public-Speaking Tips TED Gives Its Speakers”, by Carmine Gallo for Forbes, gives speakers five practical ways to connect with their audience, and effectively share their ideas on stage.
Whether you are gearing up to get on a TED stage yourself, or just want to master the skills that so many of their speakers possess, these tips and quotes from Chris Anderson, the TED Talks Curator, will encourage you to make the most impactful impression on your audience.
See the full article and more summaries like this on SpeakerHub here: https://speakerhub.com/blog/5-presentation-tips-ted-gives-its-speakers
See the original article on Forbes here:
http://www.forbes.com/forbes/welcome/?toURL=http://www.forbes.com/sites/carminegallo/2016/05/06/5-public-speaking-tips-ted-gives-its-speakers/&refURL=&referrer=#5c07a8221d9b
ChatGPT and the Future of Work - Clark Boyd Clark Boyd
Everyone is in agreement that ChatGPT (and other generative AI tools) will shape the future of work. Yet there is little consensus on exactly how, when, and to what extent this technology will change our world.
Businesses that extract maximum value from ChatGPT will use it as a collaborative tool for everything from brainstorming to technical maintenance.
For individuals, now is the time to pinpoint the skills the future professional will need to thrive in the AI age.
Check out this presentation to understand what ChatGPT is, how it will shape the future of work, and how you can prepare to take advantage.
A brief introduction to DataScience with explaining of the concepts, algorithms, machine learning, supervised and unsupervised learning, clustering, statistics, data preprocessing, real-world applications etc.
It's part of a Data Science Corner Campaign where I will be discussing the fundamentals of DataScience, AIML, Statistics etc.
Time Management & Productivity - Best PracticesVit Horky
Here's my presentation on by proven best practices how to manage your work time effectively and how to improve your productivity. It includes practical tips and how to use tools such as Slack, Google Apps, Hubspot, Google Calendar, Gmail and others.
The six step guide to practical project managementMindGenius
The six step guide to practical project management
If you think managing projects is too difficult, think again.
We’ve stripped back project management processes to the
basics – to make it quicker and easier, without sacrificing
the vital ingredients for success.
“If you’re looking for some real-world guidance, then The Six Step Guide to Practical Project Management will help.”
Dr Andrew Makar, Tactical Project Management
Unlocking the Power of ChatGPT and AI in Testing - A Real-World Look, present...Applitools
During this webinar, Anand Bagmar demonstrates how AI tools such as ChatGPT can be applied to various stages of the software development life cycle (SDLC) using an eCommerce application case study. Find the on-demand recording and more info at https://applitools.info/b59
Key takeaways:
• Learn how to use ChatGPT to add AI power to your testing and test automation
• Understand the limitations of the technology and where human expertise is crucial
• Gain insight into different AI-based tools
• Adopt AI-based tools to stay relevant and optimize work for developers and testers
* ChatGPT and OpenAI belong to OpenAI, L.L.C.
2. Caller ID
Il termine Caller ID viene utilizzato in telefonia per
identificare il numero telefonico dell'utente chiamante
L'informazione contenuta nel Caller ID è soggetta a
spoofing!
lunedì 30 giugno 2014
3. Caller ID Spoofing: cenni storici
La nascita del Caller ID Spoofing è da fare coincidere con la
creazione del concetto di Caller ID number (fine ’80)
Per oltre un decennio, lo Spoofing del Caller ID infatti veniva
utilizzato dalle imprese quale strumento per poter fruire di linee
telefoniche aventi tutte il medesimo numero di telefono a fronte
però dell’accesso ad onerosi sistemi PRI (Primary Rate Interface)
Intorno alla fine degli anni ‘90, molte agenzie di investigazione
privata si garantivano l’esclusiva d’uso delle già citate linee PRI al
fine di rivenderle ad altri colleghi ed agenzie e ad un prezzo
nettamente superiore, dando vita così alle c.d. “linee cieche”
lunedì 30 giugno 2014
4. Caller ID Spoofing: cenni storici
Questo tipo di accordi nascevano dall’esigenza di rendere fruibili ai soggetti
interessati servizi di linea che garantissero l’anonimato, facendo sì che il
proprio ID chiamante reale non venisse mostrato al soggetto ricevente
Contestualmente al fenomeno delle “linee cieche” prese corpo l’attività dei
primi hackers telefonici mirata a dar vita ai primi tentativi di utilizzo di questo
strumento per scopi privati, illegali e fraudolenti, ma ancora di carattere
“artigianale” e molto spesso di scarsa efficacia
Partendo dai sopracitati primi tentativi si è innescata una repentina attività di
sperimentazione (prima) e lancio commerciale (poi), di siti web e applicazioni
dedicate che dal 2004 ad oggi hanno portato lo spoofing telefonico a
divenire un business fiorente, oltre che a divenire un argomento molto
dibattuto, in tema di privacy e difesa dell’identità personale
lunedì 30 giugno 2014
5. Caller ID Spoofing ai nostri giorni
Da qualche anno a questa parte, grazie anche alla
diffusione delle comunicazioni che fanno uso di servizi
interconnessi attraverso il VoIP, lo spoofing del caller ID è
diventato alla portata di tutti
1.Spoofing Provider (SpoofCard, Telespoof… )
2.Un server Asterisk + un provider Voip che fornisca una
certa libertà di configurazione e inviare chiamate con il
CallerID desiderato
lunedì 30 giugno 2014
6. Caller ID Spoofing e la voicemail
Il Caller ID è utilizzato in alcuni casi come identificativo
dell'utente chiamante per garantire l'accesso a sistemi
riservati
Un esempio significativo è quello delle voicemail che
permettono la telelettura dei messaggi
Caller ID Spoofing + Caller ID is automatically trusted
lunedì 30 giugno 2014
7. USA: il caso della voicemail di AT&T/
Cingular
Hacking The next Generation (O’REILLY 2009)
Nel luglio del 2007 il ricercatore di sicurezza informatica
Nitesh Dhanjani rese noto che i cellulari di AT&T/Cingular
erano suscettibili allo spoofing del caller ID
Inoltre Dhanjani realizzò che era possibile accedere con i
privilegi di amministratore alla voicemail di tutti gli utenti di
AT&T/Cingular sfruttando la pratica dello spoofing del caller
ID
lunedì 30 giugno 2014
8. Si basò sul fatto che accedendo alla voicemail dal proprio
cellulare non era richiesto il codice d’accesso:
il sistema di autenticazione della voicemail di AT&T/Cingular
si basava sul caller ID per fornire le informazioni su chi sta
accedendo al menu di amministrazione della voicemail
USA: il caso della voicemail di AT&T/
Cingular
lunedì 30 giugno 2014
9. Per testare la vulnerabilità Dhanjani creò un account su SpoofCard:
1.L’attaccante fa una chiamata dal proprio cellulare verso il numero
della vittima usando SpoofCard;
2.Al momento in cui SpoofCard richiede il numero da spoofare,
l’attaccante inserisce il numero della vittima
3.A questo punto la vittima riceve una chiamata dal proprio
numero di cellulare; se la vittima non risponde l’attaccante
ottiene l’accesso con i diritti di amministratore alla voicemail
(ascolto e cancellazione dei messaggi, modifica del codice
d’accesso ...)
USA: il caso della voicemail di AT&T/
Cingular
lunedì 30 giugno 2014
10. Contromisure
attivare dalle impostazioni personali della voicemail l’utilizzo del
codice d’accesso in modo tale che questo venga richiesto anche
accedendovi dal proprio cellulare
Tracciabilità
1. Il flusso di chiamate consente di risalire all’attaccante in caso in cui
si abbia evidenza che sia stato compiuto un illecito;
2. L’attaccante deve avere l’abilità di cogliere la vittima alla sprovvista
in modo tale che questa non risponda alla chiamata e quindi che
l’attacco vada a buon fine;
USA: il caso della voicemail di AT&T/
Cingular
lunedì 30 giugno 2014
11. From the company’s blog ( 5 Aug. 2011)
Today, customers have the option and are strongly encouraged to
password-protect access to their wireless voicemail. Beginning
August 5, voicemail accounts for new customers, those who
change phone numbers, upgrade to Visual Voice Mail, or create a
new voicemail box will default to a password required setting
to check voicemail from their wireless or any other device.
Although AT&T strongly recommends using a password, customers
want a choice. Customers may opt out of using a password, but
only after the initial password is established and they affirmatively
turn off the password feature from the main menu.
AT&T says it is changing its voicemail
password policy
lunedì 30 giugno 2014
12. Articoli web sulle voicemail degli operatori telefonici
statunintensi vulnerabili (T-Mobile, Sprint....)
Script per asterisk che permette, chiamando un numero
registrato sul pbx, di digitare il numero dal quale si vuole far
partire la telefonata, il numero da chiamare e poi far partire
la chiamata con il callerID 'spoofato'
Casi di gossip di intercettazione della voicemail (Paris
Hilton, giornalisti.. )
Stato dell’arte
lunedì 30 giugno 2014
13. Le domande cui si tenterà di rispondere sono le seguenti:
E’ possibile eseguire un attacco del genere in Italia?
Esiste un modo per rendere l’attacco non tracciabile e invisibile alla vittima?
Italia: nessuno ne parla!?
Il caso della voicemail di WIND
Il caso Digilab del 2007 (Sky Tg 24 e PuntoInformatico)
“Il sistema telefonico permette di falsificare il mittente di una chiamata”
..............
lunedì 30 giugno 2014
14. Codice d’accesso
il codice d’accesso è richiesto
solamente nel caso in cui si tenti
di ascoltare i messaggi da un
altro telefono o dall’estero
Modalità d’accesso
1. Da un cellulare Wind occorre
digitare il 4200
2. Da un altro telefono (escluso TIM)
occorre digitare il 323 2054200
Caratteristiche della voicemail di Wind
Da un cellulare Wind utilizzando la modalità 2 si ottiene il medesimo
effetto che si ha utilizzando la modalità 1
lunedì 30 giugno 2014
15. Deposito Diretto
Viene illustrato come lasciare un messaggio nella voicemail senza fare
squillare il telefono della persona interessata anteponendo il prefisso
32 al numero di cellulare.
Caratteristiche della voicemail di Wind
Da un cellulare Wind digitando il proprio numero di cellulare anteponendo il
prefisso 32 si ottiene il medesimo effetto che si ha utilizzando la modalità 1
lunedì 30 giugno 2014
16. Ripilogando....
Da un cellulare Wind è possibile accedere al menù di amministrazione della
voicemail nei seguenti modi:
1. digitando 4200
2. digitando 323 2054200
3. digitando 32 [proprio numero di cellulare]
Condizioni verificate
1. il codice d’accesso è richiesto solo per l’ascolto della voicemail da un altro
telefono
2. il sistema di autenticazione della voicemail per l’accesso al menù di
amministrazione si basa sul caller ID
Caratteristiche della voicemail di Wind
lunedì 30 giugno 2014
17. Creando un account su Skype è possibile acquistare del
credito per effettuare delle chiamate verso telefoni fissi e
cellulari
Di default, chiamando un telefono fisso o cellulare non
verrà visualizzato alcun numero sul telefono dell'altra
persona, a meno che non venga impostato l'ID
chiamante
Chiamare da Skype impostando l’ID
chiamante
lunedì 30 giugno 2014
19. Utilizzando gli elementi raccolti fino ad ora e impostando
l’ID chiamante di Skype con il proprio numero di cellulare
Wind è possibile configurare l’attacco proposto da
Dhanjani in due varianti
Variante 1: Attacco tracciabile
Variante 2: Attacco non tracciabile
Proof Of Concept
lunedì 30 giugno 2014
20. VARIANTE 1: attacco in 3 step
1. Effettuare una chiamata verso il proprio numero di
cellulare usando Skype;
2. Al momento in cui si riceve la chiamata sul cellulare
attendere che a rispondere sia la voicemail;
3.
Si ottiene l’accesso al menù di amministrazione della
propria voicemail da Skype!
Proof Of Concept
lunedì 30 giugno 2014
21. VARIANTE 1: attacco in 2 step
1. Effettuare una chiamata verso il 323 2054200 o verso il
32 [proprio numero di cellulare] usando Skype;
2.
Si ottiene l’accesso al menu di amministrazione della
propria voicemail da Skype!
Proof Of Concept
lunedì 30 giugno 2014
22. Wind non permette in alcun modo di attivare l’utilizzo del codice
d’accesso in modo tale che questo venga richiesto anche
accedendo dal proprio cellulare
Wind lascia alla totale discrezione dell’utente la modifica del codice
d’accesso e quindi la protezione della privacy della voicemail
“Il codice d'accesso garantisce la riservatezza dei tuoi messaggi e
li protegge da ascolti indesiderati, ti suggeriamo perciò di
modificarlo e memorizzarlo”
➡ la voicemail di Wind è accessibile da qualunque telefono digitando
il 323 2054200 nel caso in cui non si modifichi il codice d’accesso
standard!
Contromisure??
lunedì 30 giugno 2014
23. Nella pagina di Vodafone dedicata al servizio di segreteria
telefonica, nella sezione Domande Frequenti, viene
espressamente indicato che non è possibile accedere alla
propria voicemail da un altro telefono finché non viene
modificato il codice d’accesso iniziale.
L’esempio di Vodafone
lunedì 30 giugno 2014