Phones eavesdropped via software bugs

19:57 • 15.02.16

A software bug can enable scammers to eavesdrop on phone conversations and make high-cost calls on other people's lines, BBC News reports, citing security experts.

The problem affects voice-over-internet-protocol (Voip) phones, commonly used by businesses.

Just by running a couple of lines of code on a website visited by the phone user, the researchers demonstrated how premium-rate calls could be made.

A security expert said such bugs could make "millions" for the perpetrators.

By exploiting the fact that Voip phones and desktop computers are connected to the same internet network at many organisations, attackers are often able to access the phones themselves and operate them without the owner becoming aware.

"It's incredibly easy to do," said security researcher Per Thorsheim, who was involved in the demonstration by fellow researcher Paul Moore.

Mr Thorsheim explained that the phone could be compromised if the user visited a web page containing a couple of lines of Javascript web code

This code was designed to launch the attack on a device made by phone hardware manufacturer Snom.

"It will charge you a pound a minute and I will listen to whatever is being said close to your phone - you will be paying me to be eavesdropped," he told the BBC.

Mr Thorsheim added that it was relatively easy to update the phone's security settings to prevent this.

However, he pointed out that most companies would probably not go to that trouble, as the phones operated perfectly well without making the security changes.

 

Phones eavesdropped via software bugs