Top
Best
New

Posted by gavide 3 hours ago

I accidentally logged phone calls to military bases(lina.sh)
146 points | 23 comments
toast0 1 hour ago|
> It never really took off though, and even back in its early days it saw barely any use. Over the years it just deteriorated further, and today it's basically completely dead.

It's actually not completely dead... It's just (almost) completely non-public.

You can subscribe to services to get number porting information where the interface is basically e164.arpa queries to a private nameserver over a VPN. I don't know the details, the cost was high enough that it didn't make sense for my employer to pursue it.

wolrah 1 hour ago|
It's also not uncommon for telecom providers to use it for their own internal routing because enough telecom software did in fact develop support for it despite lack of public implementations.

As someone who's been in the VoIP industry for over 20 years it makes me sad to think of what could have been if both ENUM and IPv6 were more widely adopted. For many years you could reach me via email, SIP, or Jabber with the same identifier and if there were effective support for ENUM in the USA my work phone number would have been able to connect you to any of them, directly and with G.722 HD voice long before it eventually came to modern cellular networks.

srejk 4 minutes ago|||
Can confirm. Work for a major telco and we use ENUM internally.
trollbridge 3 minutes ago||
Yep. The traffic he got appears to be stuff that should have remained private that leaked to a public network; it's not the first time that's happened, particularly for U.S. military traffic which is accustomed to having its own publicly-routable /8's, as opposed to the rest of us who use non-routable 10, 192, etc. space.
tyromaniac 33 minutes ago|||
There was a startup called WUPHF that used some telecom wizardry to multicast messages between providers given a single identifier, I'm not sure what happened to it...
dmd 47 minutes ago||
I'm mostly amazed the author didn't land in jail, which is the normally the response to reporting this kind of thing to authorities.
cryptolobster 35 minutes ago||
It's funny how such holes can remain for years, and no one notices until someone stumbles upon them. It's interesting that no serious organization wanted to address the issue until it was discovered that the military was involved.

It's a shame the author wasn't rewarded but at least the story can now be told over a beer.

MotoriX 15 minutes ago||
Man, you really got lucky they didn’t throw you in jail. Anything related to national defense is pretty scary. Do you think you might get some kind of reward for exposing this vulnerability?
brcmthrowaway 1 minute ago||
Why is a phone call making a DNS query?

Is this related to Softphone / VOIP in any way?

trilogic 52 minutes ago||
R.I.P You remind me of Mitnick, this is incarnation cause you have the same style verbatim. Glad to know your breed is still active.
Insanity 40 minutes ago|
I know opinions about Mitnick are quite divided. But I enjoyed reading "Ghost in the Wires" (https://www.goodreads.com/book/show/10256723-ghost-in-the-wi...). It's giving this 90s-era hacker vibe that's kinda fun (even if the truth might be stretched a bit).
shorsher 1 hour ago||
The article mentions Ascension Island, a small island in the south atlantic. There's a really great spy novel that takes places there, Ascension by Oliver Harris.
dewey 25 minutes ago|
I just finished that recently, I think "A Shadow Intelligence" from the same author is even better so can recommend that too.
joncrane 1 hour ago||
Now THIS is what hacking is all about. Very cool.
hnicrcjk6o 38 minutes ago||
Neat
adolph 1 hour ago|
This is a great story. Almost wish the author had dug a little further in and discovered something like Clifford Stoll in The Cuckoo's Egg, but a nice writeup nontheless.

Makes me wonder how many partly implemented but ignored protocols like this exist.