The damage from a single weekend usually runs into thousands of euros. The difference is when you find out.
A hacked phone system is the most common way for a company to lose money on telephony out of the blue. The attacker finds an extension with a weak password or a poorly secured SIP account and starts calling premium-rate and satellite numbers through your PBX, taking a share of the revenue. It happens at night and over holidays, so that it goes unnoticed for as long as possible. Your carrier will bill those calls – they left your PBX.
The PBX does what it is for – it connects calls. If the attacker has valid credentials, from its point of view the call is legitimate. The basis of the defence is therefore in the PBX: strong passwords, international calling barred where nobody needs it, calls restricted outside working hours, prefixes blocked. That only makes attacks harder, though. The second layer is watching what actually leaves the PBX – and that is the job of a call accounting program, which sees every call and knows its price.
The e-mail arrives within minutes and contains the extension, the numbers dialled, the amount and a link straight to those calls. If nobody responds, the program reminds you after half an hour and then every two hours – not every minute, because alerts that pester get switched off. If the call is legitimate, you click „this is fine“ and Tarifon remembers the exception. The protection is part of the program at no extra charge and nothing has to be configured.
It does not interrupt a call in progress and is not a gateway between you and your carrier. On Yeastar P-Series and 3CX V20, however, it blocks the suspicious extension automatically right in the PBX – no further calls leave it until you unblock it. The difference between learning about the fraud in minutes and learning about it from the invoice is usually a four-figure sum.
The e-mail arrives within minutes of the call that triggered the rule and contains the extension, the numbers dialled, the amount and a link straight to those calls.
No. The six rules are on from the first start and the protection is part of the program at no extra charge; you can adjust the thresholds and the list of risky prefixes.
No. Tarifon does not interrupt calls and is not a gateway between you and your carrier – it watches what leaves the PBX and alerts you. On Yeastar P-Series and 3CX V20, however, it blocks the suspicious extension, so no further call leaves it.
You click „this is fine“ and Tarifon remembers the exception. While nobody responds, it reminds you after half an hour and then every two hours.
With all the ones Tarifon collects calls from – 3CX, FreePBX and Asterisk, Yeastar P-Series, Grandstream UCM and Avaya IP Office. The details are on the pages of the individual systems.
The full version, no card needed. When the trial ends the program keeps collecting calls – once you buy a licence, no history is lost.