Multiple recipients of list <cypherpunks>: Some Happy Fool asked how we could defeat caller ID 'cause the *67 still sends along the calling number between switches (it just doesn't display it, but that is not the same as it not being available to the bad guys - *69 will still work, regardless). The discussion should probably be taken off the list, so please direct replies to me personally (or better: let us know of a more appropriate forum. I am disappointed in alt.hackers and 2600 really sucks, are there better places to go with this kind of stuff? Anybody?) To Happy Fool et al: I've got the specs for a program to use with your modem to generate what'll resemble a full CID. So with the computer set up to dial, even standard voice calls too and faxes, too, can be equipped with a fake field (or "header" if you will), displaying a homemade caller ID. Since it uses the exact same structure as the real caller ID, no telco along the entire system will ever doubt it. I can send the full specifications if you are seriously interested in doing the code in full or in part. Sorry, I can't implement it myself (lack of skills). If we get the thing running, it will dial any number and send the counterfeit header along with the call, making the telco switch believe it is dealing with a forwarded call. The beauty of it all is that this way, it will not insert its own header (it only does so when no previous CID header is detected). This is not just for use on the U-S Signaling System 7, because SS7 is now an international standard. Many countries are far more computerized than the U-S. In parts of Europe, some 95% of all areas now have digital switches. Caller ID is probably the most anticipated and feared part of these systems. This service, only available in digital areas, keeps track of the last 10 numbers that called and the time and date they did so. Example: Let's say you are in a digital area. You call a friend with a caller ID device (costing ~=$40). Between the first and second ring, they have your number. It's as easy as that. He doesn't even have to pick up the phone. Even busy calls or calls where no-one is home are registered! WARNING: When whole nations are digitalized, ANY system you call pegs you within 5 seconds of your call. What about diverters, call forwarders and stuff like that? They won't work. To cheat them, you need to produce fake headers. So if the software is not already written, let's write it. Volunteers? @@@@ This message has been brought to you by @ .. @ PETE "THE WIMP" WATKINS...BASICALLY SPINELESS(tm) | __ | \__/ <---Digitized representation of Pete Watkins My e-mail address is <mg5n+alias!wimp@andrew.cmu.edu>
[ I tried direct mail, but I haven't the energy to investigate why it didn't work. This is as relevant to the list as the drug war, at least :-) ] How exactly are you going to transmit the synthesized caller ID information from the subscriber equipment up the line to the local CO when that local CO has no expectation whatsoever of seeing the information in the first place? In other words, what existing signalling facility are you going to spoof? The caller ID information originates at the local CO, not at the subscriber drop. Between the time you complete dialing and the time at which a connection is established, the local CO is not listening to the subscriber line. Caller ID information is delivered from the remote CO to the called subscriber between the first and second ring pulses. How are you going to get your data there? Note that I could be wrong; if you know how or why my above assertions are wrong, I'd love to be corrected :-) | GOOD TIME FOR MOVIE - GOING ||| Mike McNally <m5@tivoli.com> | | TAKE TWA TO CAIRO. ||| Tivoli Systems, Austin, TX: | | (actual fortune cookie) ||| "Like A Little Bit of Semi-Heaven" |
participants (2)
-
anonymous-remailer@shell.portal.com -
m5@vail.tivoli.com