There have been many recent articles published and posts circulating regarding caller ID spoofing (IP spoofing, but with phone numbers). I have no problem with reporting recent incidents that have resulted from caller ID exploitation, but it’s important to understand that this is far from being a new security threat.
For those relatively new (this century) to network security and its nemesis field of “hacking”, please note that “Security Phreak” contains no misspellings. It contains a reference to the early days of hacking, a time when one could receive their intellectual endorphin fix by simply manipulating telephone communication systems with 2600 Hz tones. Using everything from “blue boxes” to toy whistles found in cereal boxes (props-Capt. K), this practice became known as “phone phreaking”. Therefore, being a former phreak (and current freak), I feel responsible to provide a little education on spoofing phone numbers through caller ID.
After some successful trials in the late 1980’s, caller ID was quickly embraced by the public as a new service and soon became an essential function… and then, necessity. Over the years, it has existed in slightly different forms, consisting mostly of variations in the underlying technology and the country of its use. This has led to a wonderful assortment of names and acronyms that are basically synonymous. Aside from caller ID, it has been referred to as: calling line identification, caller display, calling line identity, calling line identification presentation, calling number identification, and several other permutations. While immortalized as merely “caller ID”, the security practitioner will note that the number, from which the call was placed, does not necessarily identify the caller. This leaves us with “calling number ID” (CNID) as the preferred technical name. Services such as “enhanced caller ID” or “caller name presentation” provide the addition of a display name -meaningless in terms of security.
I would love nothing more than to impress you, and bore you, with my knowledge of POTS, PBX systems, ANI, Bell Core specs, FSK and T1 PRI trunks, but I’ve read that it is important to make your readers want to return to your blog. I will tell you that those terms that I pretend to know, constitute only a small fraction of the technologies used today. Riding on the back of telecommunications’ exponential sophistication, caller ID became equally complex. With rapid advancement and deployment, come exploits and vulnerabilities.
There are many different ways to spoof one’s caller ID. Computer, modems, wireless networking, cell phones, VoIP and open source PBX systems (Asterix) have provided spoofers an arsenal of weapons. Social engineering, FSK emulation, VoiceXML and just about anyone with access to a basic ISDN PRI circuit, have been able to change the appearance of their call origins. Although these techniques required some actual technical knowledge, so it was inevitable that simple applications and websites soon appeared online that catered to the “script kiddies” of telephony.
Let’s take a quick look at the online services that have provided caller ID spoofing services to the masses. In 2004, the Star38 service debuted, which quickly generated competition from sites like, Camophone, and CovertCall. However, as quickly as they came, they folded….and then more came, and they folded. Currently, a handful of sites exist in the form of Telespoof, Spoofem, PhoneGangster and SpoofCard -which even offers an OS X widget to its service.
Getting back to the point of this blog, these recent incidents involving a spoofed caller ID is not based on a new exploit. I’m continually fascinated by the effective malicious use of technology and the lack of appropriate action. Some of the recent incidents I refer to, are run-of-the-mill stalking and harassing cases. I am not belittling those incidents, but in the world of villainous computer hacking, things could have been a lot worse.
The news story that captured my attention and fueled this blog, was the one involving “swatting”. An individual had called the local authorities, claiming to have murdered someone and was threatening to do so again. However, this was not the case; he only wanted the police to act as though this were true. This person employed caller ID spoofing to send the authorities to an address based on the number of the incoming call. As a result, a SWAT team was deployed to the home of a quiet sleeping family, causing what was most likely a terrifying experience that they will be discussing in therapy for the next several years. The practice of doing this has just added to the “S” section of the urban dictionary -“swatting”. Great.
So we have this technology, and a means for exploitation….what’s a girl to do? (I’m not really a girl)
End user education, public education, education, education, education…
Just because it’s antiquated, don’t forget that a phone call is just another form of communication, like email (free debt consolidation! Viagra!), or postal mail (sweepstakes instant winner!), and should be treated with the same amount of healthy skepticism and paranoia as everything else today.
Unlike past perception, a phone number is not a form of identification or verification. This knowledge must be reflected in the actions taken as a result of a single call. You can call them back? You can arrange for a meet and greet? Employ voice recognition analysis? Tell them they’ve called at a bad time and ask them to call back later. Or like me, screen out all calls from unknown numbers and rarely answer the ones you do know.
My number is in the book; spoof me at your convenience.
Questions, comments, concerns? Spoof your IP and email me at greyhat@computer.org




