2 ms·
I used to work on a related problem (call traffic pumping) for a large VOIP provider, for domestic & international calls. It was a very interesting problem whic
by viknesh 3y ago
I used to work on a related problem (call traffic pumping) for a large VOIP provider, for domestic & international calls. It was a very interesting problem which has two distinct patterns of abuse.
First is just basic account takeover/hijacking, where a criminal will login to your account and receive a cut for calling expensive numbers (or in this case, sending SMS's to them). This is basically the web version of the pre-existing PBX hijacking issue.
The second, more interesting version, is people abusing free quotas to send calls (or SMS), such as in the verification case. This is novel (relative to the pre-web era) because historically it would have been hard to make free calls/texts.
- chx 3y agoAs an aside, PBX hijacking was how certain Fido BBS operators in the early 90s Hungary got their feed from abroad: a friendly installer left an extension in the PBX of the largest consumer bank which gave you a dial tone so very expensive calls abroad were billed to the bank. This went on for a few years.