NODE 2ee96676C.I.D.
anonymous-remailer@shell.portal.comTue, 22 Nov 94 13:03:50 PST
Multiple recipients of list <cypherpunks>:
Some Happy Fool asked how we could defeat caller ID 'cause the *67
still sends along the calling number between switches (it just doesn't
display it, but that is not the same as it not being available to the
bad guys - *69 will still work, regardless).
The discussion should probably be taken off the list, so please direct
replies to me personally (or better: let us know of a more appropriate
forum. I am disappointed in alt.hackers and 2600 really sucks, are
there better places to go with this kind of stuff? Anybody?)
To Happy Fool et al:
I've got the specs for a program to use with your modem to generate
what'll resemble a full CID. So with the computer set up to dial, even
standard voice calls too and faxes, too, can be equipped with a fake
field (or "header" if you will), displaying a homemade caller ID.
Since it uses the exact same structure as the real caller ID, no telco
along the entire system will ever doubt it. I can send the full
specifications if you are seriously interested in doing the code in
full or in part. Sorry, I can't implement it myself (lack of skills).
If we get the thing running, it will dial any number and send the
counterfeit header along with the call, making the telco switch believe
it is dealing with a forwarded call.
The beauty of it all is that this way, it will not insert its own header
(it only does so when no previous CID header is detected).
This is not just for use on the U-S Signaling System 7, because SS7 is
now an international standard. Many countries are far more computerized
than the U-S. In parts of Europe, some 95% of all areas now have digital
switches.
Caller ID is probably the most anticipated and feared part of these
systems. This service, only available in digital areas, keeps track of
the last 10 numbers that called and the time and date they did so.
Example: Let's say you are in a digital area.
You call a friend with a caller ID device (costing ~=$40).
Between the first and second ring, they have your number.
It's as easy as that.
He doesn't even have to pick up the phone.
Even busy calls or calls where no-one is home are registered!
WARNING: When whole nations are digitalized, ANY system you call pegs you
within 5 seconds of your call.
What about diverters, call forwarders and stuff like that?
They won't work. To cheat them, you need to produce fake headers.
So if the software is not already written, let's write it. Volunteers?
@@@@ This message has been brought to you by
@ .. @ PETE "THE WIMP" WATKINS...BASICALLY SPINELESS(tm)
| __ |
\__/ <---Digitized representation of Pete Watkins
My e-mail address is <mg5n+alias!wimp@andrew.cmu.edu>
NODE 3e7f96a8C.I.D.
m5@vail.tivoli.com (Mike McNally)Tue, 22 Nov 94 15:22:08 PST
[ I tried direct mail, but I haven't the energy to investigate why it
didn't work. This is as relevant to the list as the drug war, at
least :-) ]
How exactly are you going to transmit the synthesized caller ID
information from the subscriber equipment up the line to the local CO
when that local CO has no expectation whatsoever of seeing the
information in the first place? In other words, what existing
signalling facility are you going to spoof?
The caller ID information originates at the local CO, not at the
subscriber drop. Between the time you complete dialing and the time
at which a connection is established, the local CO is not listening to
the subscriber line. Caller ID information is delivered from the
remote CO to the called subscriber between the first and second ring
pulses. How are you going to get your data there?
Note that I could be wrong; if you know how or why my above assertions
are wrong, I'd love to be corrected :-)
| GOOD TIME FOR MOVIE - GOING ||| Mike McNally <m5@tivoli.com> |
| TAKE TWA TO CAIRO. ||| Tivoli Systems, Austin, TX: |
| (actual fortune cookie) ||| "Like A Little Bit of Semi-Heaven" |