Moritz Abrell: Phreaking 2.0 — Abusing Microsoft Teams Direct Routing
A DEF CON 30 talk about vulnerabilities in Microsoft Teams’ Direct Routing feature, which allows organizations to integrate their own telephony infrastructure via SIP providers and certified Session Border Controllers.
During a security analysis of this integration, the researcher discovered several flaws that allow an external unauthenticated attacker to perform toll fraud — abusing the infrastructure to place paid calls. The talk breaks down the vulnerabilities, their practical exploitation, and how the vendor ultimately addressed the issue.
During a security analysis of this integration, the researcher discovered several flaws that allow an external unauthenticated attacker to perform toll fraud — abusing the infrastructure to place paid calls. The talk breaks down the vulnerabilities, their practical exploitation, and how the vendor ultimately addressed the issue.