Technology Facilitates Caller ID Spoofing - PBX Info :: Your Free PBX, PABX and Telephone Information Resource
Home | Register |    
 
Forums         |        Articles          |        Blogs         |      Software          |      Portals          |      Resource          |      Wiki      |    White Papers         
 
Go Back   PBX Info :: Your Free PBX, PABX and Telephone Information Resource > GENERAL > Technology Chat
   SEARCH  
     
User Name Password      
Save ?
Technology Chat Computers, Websites, Telecom, Mobile Phones, VOIP, WIFI and more use this forum to talk tech.

Tags: , , ,


Reply
 
LinkBack Thread Tools Display Modes
Old 03-01-2006, 11:22 PM   #1 (permalink)
rixride
Admin
 
rixride's Avatar
rixride is replying to forum games...

Activity Longevity
5/20 20/20
Today Posts
0/0 sssss3127
Location: Dallas, Texas
Rep Power: 5rixride has much to be proud ofrixride has much to be proud ofrixride has much to be proud ofrixride has much to be proud ofrixride has much to be proud ofrixride has much to be proud ofrixride has much to be proud ofrixride has much to be proud of
Gender:
Country:
 
Technology Facilitates Caller ID Spoofing

NEW YORK - Last fall, U.S. Rep. Tim Murphy's office started getting phone calls from constituents who complained about receiving recorded phone messages that bad-mouthed Murphy.

The constituents were especially upset that the messages appeared to come from the congressman's own office. At least, that's what Caller ID said.
"People thought we were making the calls," Murphy said.
The calls, which the Pennsylvania Republican estimated in the thousands, were apparently placed with fake Caller ID. That has been possible for a long time, but it generally required special hardware and technical savvy.
In the last few years, Caller ID spoofing has become much easier. Millions of people have Internet telephone equipment that can be set to make any number appear on a Caller ID system. And several Web sites have sprung up to provide Caller ID spoofing services, eliminating the need for any special hardware.
For instance, Spoofcard.com sells a virtual "calling card" for $10 that provides 60 minutes of talk time. The user dials a toll-free number, then keys in the destination number and the Caller ID number to display. The service also provides optional voice scrambling, to make the caller sound like someone of the opposite sex.
Caller ID spoofing appears to be legal, though many of its uses are not. The Federal Communications Commission has never investigated the issue, spokeswoman Rosemary Kimball said.
Lance James, chief scientist at security company Secure Science Corp., said Caller ID spoofing Web sites are used by people who buy stolen credit card numbers. They will call a service such as Western Union, setting Caller ID to appear to originate from the card holder's home, and use the credit card number to order cash transfers that they then pick up.
Exposing a similar vulnerability, Caller ID is used by credit-card companies to authenticate newly issued cards. The recipients are generally asked to call from their home phones to activate their cards. Some card companies maintain, however, that they use additional means to confirm new cards. And caller ID spoofing may not work for calls to 1-800 numbers, where the hardware can identify calls using a separate technology.
Two spoofing services contacted by The Associated Press, Spoofcard.com and Telespoof.com, did not return messages seeking comment about their business. However, some of the five or so Web sites in the business don't appear to be completely unscrupulous: James said he had been hired by a few of them, which he would not name, to help stop the Western Union scam.
Also, both Spoofcard.com and SpoofTel.com say they will surrender call logs to authorities in response to subpoenas. Spoofcard.com's site says the service is "intended for entertainment purposes only."
Telephone companies can trace calls to their origin regardless of the Caller ID information they carry, but the process is laborious, especially since a call may be carried by several companies before reaching its destination. The fragmented nature of the telephone network also makes it technically difficult for the carriers to prevent spoofing.
At Verizon Communications Inc., security manager John Lewandowski said the company often gets complaints about fake Caller ID after a telemarketer has spoofed his number to cover his tracks.
In a typical case, someone will be jarred in the middle of the night by repeated telemarketing calls. He checks Caller ID, calls the number — which is false — and starts "cussing out" the person at the other end of the line, Lewandowski said.
"And that poor guy was asleep. It wasn't him at all," Lewandowski said. The company investigates and tracks down the callers, he added.
Apart from fraud and telemarketing, Caller ID spoofing can be used for pranks and spying.
In one case, SWAT teams surrounded a building in New Brunswick, N.J., last year after police received a call from a woman who said she was being held hostage in an apartment. Caller ID was spoofed to appear to come from the apartment.
It's also easy to break into a cell phone voice mailbox using spoofing, because many systems are set to automatically grant entry to calls from the owner of the account. Stopping that requires setting a PIN code or password for the mailbox.
In a slightly more complicated fashion, spoofing was part of the technique used by a hacker who broke into Paris Hilton's cell-phone voicemail in 2004, according to security consultant Kevin Mitnick, who said he was citing hacking sources. The hacker apparently called the celebrity socialite posing as a technical-support person from the carrier, and lured the password from her.
That is known as a "pretext" call — someone poses on the phone as a customer, employee or even a regulator to obtain personal information from companies and individuals. And indeed, while Spoofcard.com contends that its service is for "entertainment purposes," it also notes that "Private Investigators will find Caller ID spoofing valuable for pretext calls."
Robert Douglas, a privacy consultant in Colorado, testified before Congress last month that pretexters trade tips on finding the best spoofing services.
Pretexters generally claim their practices are legal, as long as they don't involve financial information. A bill introduced in the Senate would make it illegal to pose as someone else to obtain phone records, or to buy records from phone company insiders.
Douglas would like legislation against Caller ID spoofing as well, but there appears to be little interest in Washington.
"If I'm paying extra for Caller ID, which I do ... there should be some ability on my part to believe what I'm getting," Douglas said.
In Alaska, State Representative Bob Lynn has introduced a bill to make spoofing a misdemeanor. "False caller identification is more serious than pranks, or the annoyance of intrusive telemarketing," Lynn writes. "It facilitates fraud, and can be potentially deadly."
However, it is unclear what effect the bill would have. As Lynn notes, Caller ID is a federal issue
__________________
-=Welcome to PBXInfo=-
-Become a PBXInfo Supporter
-Get more PM Space, Profile Picture, a Signature
-Add yourself to Pbxinfo's Frappr
-Find Nortel Software

Last edited by rixride; 03-01-2006 at 11:27 PM.
rixride is offline   sendpm.gif Reply With Quote
Old 03-02-2006, 07:01 AM   #2 (permalink)
JulianW
Moderator
 
JulianW's Avatar
JulianW is drinking coffee.

Activity Longevity
10/20 11/20
Today Posts
0/0 sssss5517
Location: 254.45 miles from Tiverton, Devon (ENGLAND)
Rep Power: 9JulianW will become famous soon enough
Gender:
Country:
Someone needs to take control of this situation, Caller Id should be a service that we can all rely on to tell us where a call originates from, it annoys me enough when I get a number "withheld" that is likely to be from a marketing company but to be able to spoof your calling number, that's just not right.
JulianW is offline   sendpm.gif Reply With Quote
Old 03-03-2006, 10:53 AM   #3 (permalink)
slagburn
Senior Member
 
slagburn's Avatar
slagburn has no status.

Activity Longevity
3/20 19/20
Today Posts
0/0 ssss10376
Location: 3498.51 miles from Tiverton, Ontario (CANADA)
Rep Power: 16slagburn will become famous soon enough
Gender:
Country:
Happens all the time out here; people have even come to blows over it because they don't understand how the system works.

Our LEC engineers tell us that we can only send CLID that is within our DID range but I've proven time and time again that I can send any caller ID that I want on any trunk group and have it appear on the terminating phone.

I demonstrated this concept once in a lab by calling someones cell phone and sent their home phone number as the caller ID... they couldn't understand what was going on so they freaked out and drove home where they got security to escort them to thier condo... funny stuff.
slagburn is offline   sendpm.gif Reply With Quote
Old 03-03-2006, 11:17 AM   #4 (permalink)
papa-bear
Moderator
 
papa-bear's Avatar
papa-bear is suffering from a pad thai lunch

Activity Longevity
10/20 14/20
Today Posts
0/0 sssss3336
Location: @home
Rep Power: 8papa-bear will become famous soon enough
Gender:
Country:
Amazing the control we have over that information. One typo and you can make someones life miserable.
papa-bear is offline   sendpm.gif Reply With Quote
Old 03-03-2006, 12:21 PM   #5 (permalink)
slagburn
Senior Member
 
slagburn's Avatar
slagburn has no status.

Activity Longevity
3/20 19/20
Today Posts
0/0 ssss10376
Location: 3498.51 miles from Tiverton, Ontario (CANADA)
Rep Power: 16slagburn will become famous soon enough
Gender:
Country:
There is a hospital near that has numbers real close to our DID ranges... they are always fawking up their CLID tables and people start calling us.
slagburn is offline   sendpm.gif Reply With Quote
Old 03-03-2006, 04:29 PM   #6 (permalink)
bobmay
Moderator
 
bobmay's Avatar
bobmay has no status.

Activity Longevity
2/20 18/20
Today Posts
0/0 ssssss110
Location: Pittsfield, MA
Rep Power: 6bobmay is on a distinguished road
Had a woman at work who was nuts about Elvis. We setup an internal extension to show his name, and called her. For a brief moment she forgot Elvis was dead, and believed he was actually calling her! She was in heaven for a few seconds.
bobmay is offline   sendpm.gif Reply With Quote
Reply



Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


All times are GMT -5. The time now is 01:20 PM.

Tags   |   Advertise    |    Media Partners   |    Admin   |   About us   |   Contact Us   |   RSS   

Powered by vBulletin® Version 3.7.3
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Search Engine Friendly URLs by vBSEO 3.0.0
Copyright PBXINFO LLC 2006