[VOIPSEC] Confirmed cases of SPIT

Eric Chen eric.chen at lab.ntt.co.jp
Thu Mar 16 01:57:57 CST 2006


There has been a number of confirmed cases of SPIT in Japan, a country with 10 million VoIP subscribers (excluding Skype).  According to an article published by the Nikkei Communications magazine on 2005/06/01, a major VoIP provider called SoftbankBB (4.6M users) found three incidents of SPIT within its network in 2004.  It's quite a headline in that issue.  Let me summarize the incidents. 

----------------
2004/2 Unsolicited commercial messages for an adult website

2004/8 "Number scanning" for active VoIP phone numbers (starts with the area code 050 for VoIP and the provider code) at the rate of 6000 calls/day (hangs up right after the first ring)

2004/11 Unsolicited automatic messages asking for personal information

The caller ID in each incident appears to be different, but Softbank later found out they all belong to the same company.  As a result, Softbank terminated the service contract with this company.  Recently, providers in Japan start to explicitly prohibit SPIT in their contract agreements.
-----------------

Despite the incidents, I wonder how effective SPIT is from a marketer's point of view.  In a spam email, the advertised website is only one click away, but with SPIT, spammers would have to be more creative using only voice messages.  Simply asking people to write down a URL and access later doesn't sound effective.  (Maybe effective for advertising pay-per-call numbers, if they are available on VoIP)

m2cw,

Eric

-----
Eric Y. Chen, Ph.D. <eric.chen at lab.ntt.co.jp>
NTT Information Sharing Platform Laboratories
PGP Key ID: 0xD2A58AE8
Fingerprint: DAB9 19A8 C634 6713 A7F4 F67A B173 1AC3 D2A5 8AE8
-----




More information about the Voipsec mailing list