Your Phone Shouldn’t Be Listening to Your Calls

When people think about cyber security, they tend to think about firewalls, servers, cloud platforms, laptops, and perhaps the occasional suspicious email.

What they rarely think about is the office phone sitting on their desk. Which is exactly why attackers like them.

During a recent penetration test, we encountered something that perfectly demonstrates how often organisations overlook everyday devices.

At first glance, it looked like a fairly standard VoIP phone.

Nothing unusual.

Nothing alarming.

Just another device quietly doing its job. A few minutes later, we were capturing phone calls.

It Started with a Login Prompt

Like many business VoIP phones, the device exposed a web-based management interface. These interfaces are typically used for configuration, troubleshooting, firmware updates, and diagnostics. Accessing the login page was straightforward. Authenticating was even easier. The credentials were:

Username: user

Password: user

Yes, really.

Unfortunately, default credentials remain one of the most common security issues we encounter during infrastructure penetration tests. While organisations generally do a good job securing servers, firewalls, and cloud services, devices such as printers, phones, cameras, and other embedded systems are often forgotten after installation.

The result is that years later they are still using the credentials they shipped with from the factory.

“It’s Only a Phone”

One of the most dangerous assumptions in cyber security is:

“It’s only a phone.”

The reality is that modern VoIP handsets are small computers connected directly to your network. Many have administrative interfaces, debugging tools, firmware management functionality, network diagnostics, and extensive troubleshooting capabilities.

In this case, one of those features was packet capture. For anyone unfamiliar with the term, a packet capture (PCAP) is effectively a recording of network traffic. Network engineers and security professionals use packet captures every day for troubleshooting and analysis.

Attackers do too.

The Phone Was Recording Everything

Once authenticated, the device allowed packet captures to be generated directly from the administrative interface. Testing confirmed that the captures contained SIP and RTP traffic associated with voice communications.

In plain English:

The phone was capable of recording the information required to reconstruct telephone conversations. At this point, the finding stopped being about a default password. It became a confidentiality issue.

Depending on how the phone is used, captured calls could potentially contain:

  • Sensitive business discussions
  • Customer information
  • Commercially confidential information
  • Authentication details shared verbally
  • Financial information
  • Personal data

The impact suddenly becomes much more significant than simply accessing a configuration page.

Why Attackers Love Forgotten Devices

Attackers are not always looking for the most sophisticated route into an environment.

Often they are looking for the easiest.

A forgotten phone.

An old printer.

A network camera nobody has touched for five years.

These devices frequently receive less attention than traditional IT systems despite often having administrative interfaces, network access, and valuable information flowing through them. During penetration testing, we regularly find organisations with excellent security controls protecting their servers while a forgotten device quietly sits in the corner using default credentials. Security is often strongest where organisations focus their attention.

Attackers look everywhere else.

The Real Lesson Isn’t About Phones

While this example involved a VoIP handset, the lesson applies to almost every connected device within an organisation.

The issue was not really the phone. The issue was visibility.

Many organisations simply do not know:

  • What devices are connected to their network
  • Which devices still use default credentials
  • Whether management interfaces are exposed
  • What sensitive functionality those devices provide

If you do not know a device exists, you cannot secure it.

How to Protect Your Organisation

Fortunately, this type of issue is usually straightforward to address.

Organisations should ensure:

  • Default credentials are changed during deployment
  • Firmware is kept up to date
  • Administrative interfaces are restricted where possible
  • Unnecessary diagnostic functionality is disabled
  • Device inventories are maintained
  • Internal security assessments are performed regularly

Most importantly, remember that every device connected to your network should be treated as a potential attack surface.

Even the ones that seem harmless.

Especially the ones that seem harmless.

Final Thoughts

Cyber security findings do not always involve advanced exploitation techniques or sophisticated attacks.

Sometimes they involve logging into a phone using the password “user”.

The interesting part is rarely the vulnerability itself.

The interesting part is what that vulnerability allows an attacker to do next.

In this case, a default password exposed the ability to capture sensitive business communications directly from a device sitting on someone’s desk.

Not exactly what most people expect when they pick up the phone.

If you would like to understand what forgotten devices may be hiding within your environment, speak to the team at Securebytes. Internal penetration testing regularly uncovers risks that traditional vulnerability scans and compliance checks simply do not see.