Appendix A: Customer Support Information

Security Risks Associated with the Remote
Access Feature

Remote Access allows the MERLIN MAGIX Integrated System owner to access the system from a remote telephone and make an outgoing call or perform system administration using the network facilities (lines/trunks) connected to the MERLIN MAGIX Integrated System. Hackers, scanning the public switched network by randomly dialing numbers with war dialers (a device that randomly dials telephone numbers, including 800 numbers, until a modem or dial tone is obtained), can find this feature, which will return a dial tone to them. They can even employ war dialers to attempt to discover barrier codes.

Preventive Measures

Take the following preventive measures to limit the risk of unauthorized use of the MERLIN MAGIX Integrated System Remote Access feature:

Topics
  Support Telephone Number
  Federal Communications Commission (FCC) Electromagnetic Interference Information
  Canadian Department of Communications (DOC) Interference Information
  FCC Notification and Repair Information
  Installation and Operational Procedures
  DOC Notification and Repair Information
  Renseignements sur la Notification du Ministère des Communications du Canada et a Réparation
  Security of Your System: Preventing Toll Fraud
  Toll Fraud Prevention
 
  Physical Security, Social Engineering, and General Security Measures
Security Risks Associated with Transferring through Voice Messaging Systems
Security Risks Associated with the Automated Attendant Feature of Voice Messaging Systems
Security Risks Associated with the Remote Access Feature
  Other Security Hints
 
  Educating Users
Educating Operators
Detecting Toll Fraud
Establishing a Policy
Choosing Passwords
Physical Security
Limiting Outcalling
  Limited Warranty and Limitation of Liability
Remote Administration and Maintenance