4 ms·
Great write up. Does anybody have more information on the attack near the end "...defrauded by Lithuanian hacker gang which figured out how to use our applicat
by jonaldomo 10y ago
Great write up. Does anybody have more information on the attack near the end "...defrauded by Lithuanian hacker gang which figured out how to use our application to proxy a telephone call through Twilio’s phone number verification feature to a phone sex line in the Caribbean..."
- patio11 10y agoThis is fixed now, but for historical context: Twilio has a feature to allow you to make calls which appear to come from a non-Twilio phone number. To do this, you have to make an API request (see here: https://www.twilio.com/docs/api/rest/outgoing-caller-ids); https://www.twilio.com/docs/api/rest/outgoing-caller-ids); Twilio then responds to your application with a code that the user needs to enter, you tell that code to the user (via e.g. displaying it to their web browser), and Twilio calls the user to ask for the code. If they key in the correct code on their phone, their number is verified for your account, and you can now use it as the caller ID for future calls from your application. Because this causes an actual real-world phone call but doesn't look like a phone call to either Twilio or Appointment Reminder, it (at the time of the attack) bypassed some protections like, to name one example, AR's anti-abuse rate limiting logic. The bad guys "attempted to verify" the phone sex lines in the Caribbean, in much the same way as a legitimate AR customer would attempt to verify their office phone number so that appointment reminders would appear to originate from their office (and they'd get callbacks) as opposed to originating from our 1-800 number. Some of our customers are at larger institutions, which require you to put in an extension prior to reaching the customer. Think "hospitals." The bad guys put in an extension with over 100k digits to keep their phone calls from timing out. (Dial a 5, wait a second, dial a 5, wait a second...) The economic incentive here is "If someone calls a premium-rate number that you control, you get paid money." The economic damage is "If someone calls a premium-rate number, that someone pays to do so", so all the money the bad guys made came from either Twilio or I.