Home > Services > Risk Management > War Dialing

RISK MANAGEMENT

War Dialing

Essentials

War dialing is an assessment where the SecureState team dials into an organization’s phone block attempting to identify numbers where a modem is present. When a modem is present, SecureState will attempt to circumvent security controls and access data. The goal of a war dialing assessment is to review the overall level of security and identify exposures associated with a company’s dial-in environment. This is accomplished by first, “War Dialing” selected telephone ranges from a remote telephone connection to identify modem connections to the internal network. Second, controlled penetration attacks are performed on the modem connections that are identified in order to gain access to the company’s internal network.

  • Assesses the overall level of security and identify exposures associated with a company’s dial-in environment Identifies modems currently present in your environment Performed controlled penetration attacks on discovered modems to identify insecure systems
  • Identifies modems currently present in your environment
  • Performed controlled penetration attacks on discovered modems to identify insecure systems

Benefits

Although most companies have made the switch to Internet based remote access solutions, analog (legacy) remote access solutions are still present. Often times, building management systems such as elevators, HVAC systems and lighting control systems have modems attached to allow vendors remote access to administer these systems. Similarly, Storage Area Networks (SANs), mainframes and PBX systems will often have modems attached allowing for remote support by the vendor. Frequently, these modems are insecurely setup when the equipment is installed and are quickly forgotten about. A War Dialing assessment will find these back doors into your network.

Expertise

SecureState provides the most comprehensive discovery and penetration tests of these devices with our War Dialing service. SecureState’s engineers are some of the top War Dialing professionals in the country, having been quoted by publications as well as a “white paper” published by SANS.

Did You Know?

  • Legacy devices allow an attacker an avenue to attack your systems and steal your data
  • SecureState’s engineers are some of the top War Dialing professionals in the country
  • War dialing should be performed quarterly to verify modems in the environment are securely configured; and to detect new modems added to the existing environment
  • Attackers still use war dialing today to compromise systems
  • Many building management systems such as elevators, HVAC and lighting systems have modems attached which are often poorly configured
  • Multi-Function Printers which contain fax modems can be misconfigured to allow attackers to access your internal network
  • SecureState has a 90% success rate of compromising one or more systems during the course of a war dialing engagement
  • Many Supervisory Control and Data Acquisition (SCADA), Programmable Logic Controllers (PLC) and Industrial Control Systems (ICS) have modems attached. These modems, if insecure, would allow an attacker to easily compromise critical infrastructure components.
  • Traditional phone lines are still used for SCADA and Industrial Control Systems.
  • Many organizations feel like they are secure because they have a solid external perimeter. The reality is the fact that unsecured modems can be used by attackers to bypass the external perimeter and place the attacker directly on the organization's internal network.

Our Approach and Methodology

SecureState closely follows a 6-step methodology process when performing a War Dialing assessment. This process has been refined over the years as SecureState has performed hundreds of War Dialing assessments. A summary of the methodology is provided below:

  • Obtain Exchanges
    • It is recommended to test all dial-in direct (DID) phone numbers owned by the organization
    • These numbers should be provided in a contiguous form
  • Configure and Run War Dialer
    • This phase involves dialing all of the phone numbers using specialized hardware and software
    • This software automates the dialing of all of the numbers using a large bank of modems
    • This allows parallel dialing efforts in order to complete this phase in a timely manner; SecureState’s war dialing lab can dial approximately 450 phone numbers per hour
    • This phase may be performed during and / or after hours depending on the needs of the organization
  • Analyze Carriers and Identify Systems
    • During this phase, the automated dialer software will categorize the phone devices found into categories including voice, busy, no answer, fax, and carrier systems
    • When a carrier system is found, the software will grab any system banners and attempt to identify the system
    • If a number dialed produces a busy or no answer result, additional attempts at connection will be made
  • Connect to Carriers Identified
    • Manually connect to each carrier system in chronological order to validate and make additional determinations of the carrier system
    • This includes trying different terminal emulation types, using different nudge strings, and additional identification of system banners
  • Brute Force if Prompted
    • Once SecureState has made a final carrier system determination, attempts are made to access the system
    • This process includes the use of default usernames and passwords as well as limited brute force attempts at common passwords
  • Access Granted
    • If system access is granted, SecureState will investigate that system to determine:
      • System information
      • Network information
      • Sensitive system data
      • Potential to penetrate the network

What Makes Us Different

  • SecureState’s consultants regularly perform War Dialing techniques, which gives them in-depth, firsthand knowledge of dial-in remote access systems
  • SecureState has been quoted by different publications as well as a “white paper” published by SANS
  • SecureState uses the best commercial and free war dialing tools when performing an assessment
  • SecureState has hands-on experience with War Dialing delicate production SCADA, PLC and ICS systems for electric, manufacturing and mining companies

Downloads

We Can Help You