Videos / Defcon / Moritz Abrell: Phreaking 2.0 — Abusing Microsoft Teams Direct Routing

Moritz Abrell: Phreaking 2.0 — Abusing Microsoft Teams Direct Routing

Duration: 20min 48sec Type: Presentation (lecture) Playlist: 114 of 146 in Defcon
A DEF CON 30 talk about vulnerabilities in Microsoft Teams’ Direct Routing feature, which allows organizations to integrate their own telephony infrastructure via SIP providers and certified Session Border Controllers.

During a security analysis of this integration, the researcher discovered several flaws that allow an external unauthenticated attacker to perform toll fraud — abusing the infrastructure to place paid calls. The talk breaks down the vulnerabilities, their practical exploitation, and how the vendor ultimately addressed the issue.