Rendered at 22:16:16 GMT+0000 (Coordinated Universal Time) with Cloudflare Workers.
toast0 2 days ago [-]
> It never really took off though, and even back in its early days it saw barely any use. Over the years it just deteriorated further, and today it's basically completely dead.
It's actually not completely dead... It's just (almost) completely non-public.
You can subscribe to services to get number porting information where the interface is basically e164.arpa/ENUM queries to a private nameserver over a VPN. I don't know the details, the cost was high enough that it didn't make sense for my employer to pursue it.
wolrah 2 days ago [-]
It's also not uncommon for telecom providers to use it for their own internal routing because enough telecom software did in fact develop support for it despite lack of public implementations.
As someone who's been in the VoIP industry for over 20 years it makes me sad to think of what could have been if both ENUM and IPv6 were more widely adopted. For many years you could reach me via email, SIP, or Jabber with the same identifier and if there were effective support for ENUM in the USA my work phone number would have been able to connect you to any of them, directly and with G.722 HD voice long before it eventually came to modern cellular networks.
tyromaniac 2 days ago [-]
There was a startup called WUPHF that used some telecom wizardry to multicast messages between providers given a single identifier, I'm not sure what happened to it...
Can confirm. Work for a major telco and we use ENUM internally.
trollbridge 2 days ago [-]
Yep. The traffic he got appears to be stuff that should have remained private that leaked to a public network; it's not the first time that's happened, particularly for U.S. military traffic which is accustomed to having its own publicly-routable /8's, as opposed to the rest of us who use non-routable 10, 192, etc. space.
lxgr 2 days ago [-]
My guess is that this is actually what happened here: Some carrier or VoIP software leaking its DNS queries to the public internet because the service is using is only set up to respond for e.g. NANP (+1) number ranges and the rest is falling through to the public (and largely unused) ENUM.
dmd 2 days ago [-]
I'm mostly amazed the author didn't land in jail, which is the normally the response to reporting this kind of thing to authorities.
contingencies 2 days ago [-]
Given the author appears to be a 19 year old German girl, UK bureaucrats proxying admin duties for offshore territories are unlikely to be motivated to start an international extradition for what amounts to a helpful tip.
Barbing 2 days ago [-]
When you see
“fun fact: this entire website is written without any javascript […]”
and “19 years old”,
you know there’s hope for our future.
selfmodruntime 2 days ago [-]
The entire blog at lina.sh gives me such a fuzzy feeling of the old web.
Barbing 2 days ago [-]
Didn’t click the links on bottom of homepage but betting many of those sites will give you that same feeling. Web rings! Just great.
nicbou 2 days ago [-]
This kind of internet is enjoying a small revival and I'm all for it.
neuroticnews25 1 days ago [-]
Lots of exogenous estrogen in that webring.
sph 1 days ago [-]
I remember the 2010s push to get women into tech, I guess it didn't work so they had to try another approach.
sandblast 1 days ago [-]
Which makes that hope for our future disappear.
BobbyTables2 2 days ago [-]
If the author was an 35 yr old Nigerian immigrant, would the response have been different?
NonHyloMorph 2 days ago [-]
Probably yes
fleroviumna 2 days ago [-]
[dead]
2 days ago [-]
2 days ago [-]
jakzurr 2 days ago [-]
Whew, absolutely!
I love the line near the end of the article: "So in the end, I was down 10€ in domain fees, there was sadly no bug bounty (I thankfully didn't get my door kicked in at least)."
Makes me cringe, imagining what that would be like.
Onavo 2 days ago [-]
[flagged]
eru 1 days ago [-]
I've had a look at the thread you linked, and I can't see how you get that impression from it.
The most I can see is you making a silly American-centric remark, and people gently correcting you that there are other places on earth.
chaz6 2 days ago [-]
It is a shame they did not actually set up a SIP server and see if any of those requests turned into actual call terminations.
There is another schema called TRIP [1] - telephony routing over ip that uses a number format "1234*1455" designed to be entered on a standard phone keypad. When I registered my ITAD (internet telephony administrative domain, the RHS of a TRIP number) I was lucky enough to get one that matches my local dialling code!
I enjoyed reading this much more than anything I read here recently. In particular I like how it absolutely shows that somethings just… fall through the cracks!
lxgr 1 days ago [-]
It's a shame that ENUM didn't really go anywhere, but I suppose ultimately many stakeholders consider the phone network being administratively separate from the Internet a feature, not a bug, even though it's now largely an overlay network on top of the Internet itself in its modern form (NGN).
As far as I remember, the Austrian telco regulator was particularly SIP-forward in the early 2000s, and there was a prefix dedicated exclusively to ENUM-based services back in the day.
Unlike its sibling VoIP prefix, which was terminated the "usual PSTN way" by operators that would then bridge to SIP or whatever internally, the idea of the "ENUM first" prefix was that you'd register a number with some registrar and then make it resolve to your SIP client (via a proxy/service provider or directly to any publicly reachable IP address). Reachability from the PSTN was provided via gateways that would translate from circuit switched voice to SIP/RTP, so effectively you could really be reachable for incoming calls independently of any telco.
Unfortunately, as far as I remember both the VoIP and the ENUM prefix ended up being prohibitively expensive to call from many plans (they were billed at higher rates than both landlines and cellphones from many carriers and not included in any flat rate plans).
Still, together with native SIP and Wi-Fi support in many early smartphones at the time, it felt like standards-based Internet telephony was just around the corner, which of course didn't quite play out, and we ended up with the fragmented OTT landscape of today instead that only uses phone numbers as user identifiers, with a per-service privately managed directory instead of a DNS-based one.
cryptolobster 2 days ago [-]
It's funny how such holes can remain for years, and no one notices until someone stumbles upon them. It's interesting that no serious organization wanted to address the issue until it was discovered that the military was involved.
It's a shame the author wasn't rewarded but at least the story can now be told over a beer.
bcx 2 days ago [-]
Their homepage, https://lina.sh/, reminds me of the early days of the internet. Are webrings back in fashion? Or is this just a group of old school folks keeping the nostalgia alive?
fc417fc802 2 days ago [-]
There are various subcultures outside the mainstream part of the internet that largely eschew modern web design. Not entirely dissimilar to HN itself.
jalict 1 days ago [-]
neocities exploded 2-3 years ago and #smallweb is super active
loads of webrings also started -- 90s internet is back, just look for it <3
jnmandal 1 days ago [-]
Its hip again on some parts of the fediverse.
j0ej0ej0e 2 days ago [-]
Just 19 too, what a talent!
MatthewWilkes 1 days ago [-]
The NCSC does give out challenge coins for particularly good reports. I feel like if you get one of those, that will be 10 euros well spent.
MotoriX 2 days ago [-]
Man, you really got lucky they didn’t throw you in jail. Anything related to national defense is pretty scary. Do you think you might get some kind of reward for exposing this vulnerability?
edelbitter 2 days ago [-]
You never know in Germany. Jail time might still be looming.. after some 3-5 years of delay because the telefax machine at the public prosecutors office is currently broken (and not even for DNS reasons!)
notpushkin 2 days ago [-]
> because the telefax machine [...] is currently broken (and not even for DNS reasons!)
Who knows! Maybe it’s working just fine, but the e164.arpa record is pointing to the public prosecutor’s teapot or something.
lukan 2 days ago [-]
Fortunately it was the national defense of a different country (UK and not germany) so that might have helped.
Barbing 2 days ago [-]
Don’t know how one could live with themself prosecuting security researchers. Think they’re saving face?
_bernd 1 days ago [-]
> security researchers
I don't want the miss the young girls skills but she is no security researcher but in the eyes for her target simple a hacker.
And I would say too that she got lucky. It would not be the first time that inexperienced young persona have to suffer the consequences even of their well intended actions.
shorsher 2 days ago [-]
The article mentions Ascension Island, a small island in the south atlantic. There's a really great spy novel that takes places there, Ascension by Oliver Harris.
dewey 2 days ago [-]
I just finished that recently, I think "A Shadow Intelligence" from the same author is even better so can recommend that too.
ivan888 1 days ago [-]
> when a carrier does an ENUM lookup for one of these numbers, they're essentially asking "where do I route this call?", and I could answer with whatever I wanted. I could point it at my own SIP server, accept the incoming call, and then place an outgoing call to the real destination with a spoofed number
How would the “outgoing call to the real destination” avoid this same lookup? Directives to route around the ENUM system?
trilogic 2 days ago [-]
R.I.P You remind me of Mitnick, this is incarnation cause you have the same style verbatim. Glad to know your breed is still active.
Insanity 2 days ago [-]
I know opinions about Mitnick are quite divided. But I enjoyed reading "Ghost in the Wires" (https://www.goodreads.com/book/show/10256723-ghost-in-the-wi...). It's giving this 90s-era hacker vibe that's kinda fun (even if the truth might be stretched a bit).
samteeeee 2 days ago [-]
Great story. Gives me nostalgia for the old days of the internet.
Elfener 2 days ago [-]
> skipping the expensive phone network and re-routing calls over the cheap internet instead.
I find this such a bad idea, if I want to use the cheap internet for a call I would use an internet based voice call system directly, rather than messing around with telephone numbers and I guess potentially accidentally doing an expensive phone call (same with RCS/SMS vs. just using an internet-based chat directly).
pseudohadamard 2 days ago [-]
People with POTS brains trying to make them do Internet things leads to a neverending stream of bad... no actually, terrible ideas. Look at H.323 for example, something that could only be created by someone who has no clue how the Internet (with firewalls, NAT, etc) works, and that's just the tip of the iceberg for the ITU-T standards stream.
Having said that, SIP is barely better.
adolph 2 days ago [-]
This is a great story. Almost wish the author had dug a little further in and discovered something like Clifford Stoll in The Cuckoo's Egg, but a nice writeup nontheless.
Makes me wonder how many partly implemented but ignored protocols like this exist.
seri4l 2 days ago [-]
So what software could be making these ENUM queries? Any theories?
bobmcnamara 2 days ago [-]
VoIP phones or telecom software
bdavbdav 2 days ago [-]
Amazed enum.org.uk hasn’t been scooped by a bot. 4 letters are £££.
barlow48 2 days ago [-]
Newbie question:A malicious actor could simply have MITM'ed the calls the blog states and obtaining the voice traffic. Is that possible because the author had the certificates( since holding the ownership of the domain)?
Nextgrid 2 days ago [-]
Although you can run SIP over TLS (for signalling) and use SRTP for media (key exchange done over the aforementioned signalling channel), in practice most SIP is over unencrypted UDP and media is unencrypted RTP.
If you control both endpoints and they support it you can configure them to use encryption, but even then implementation qualities vary widely (just because you enable SIP over TLS doesn’t mean they’ll actually verify the certificates for example - giving you at best opportunistic encryption), and I bet a lot of the implementations also have bugs/vulnerabilities.
If security is needed, it is often implemented by way of running the whole thing over private links (which can be secured with IPSec or any other VPN technology). In fact that’s presumably what’s happening, but misconfigured equipment making those ENUM lookups would allow the attacker to steer the traffic away from the secure link and towards an endpoint they control over the public internet.
zeristor 2 days ago [-]
I recall about 15 years ago Google had this project about one phone number for the person, things got all tidied away and could never find out much more about it.
I’d forgotten the keywords of power to find it again. I liked the idea.
No it predates that by a decade 2008 I seem to recall it being a thing.
I remember because it seemed quite a nice idea, almost obvious.
Drdiamond 1 days ago [-]
Really interesting and nice read. Wound see if something such also is there in my country
yellers 2 days ago [-]
!remind me 21-Apr-2027.....
I would not at all be surprised seeing that domain being abandoned again at a renewal in the near future.
joncrane 2 days ago [-]
Now THIS is what hacking is all about. Very cool.
brcmthrowaway 2 days ago [-]
Why is a phone call making a DNS query?
Is this related to Softphone / VOIP in any way?
somat 2 days ago [-]
The article covers it, but to reiterate. Yes, The idea is to have a mechanism to map phone numbers to hosts.
The normal path for voip phones given a phone number is to end up at a sip trunk provider go over the traditional phone network (which at this point probably routes over the internet anyway) hit another sip trunk and end up at the receiving sip phone.
This provides a method to bypass the traditional phone network and go directly over the internet. The sip phone looks up the host responsible for that phone number and directly connects. The sip providers would be responsible for maintaining this number to host mapping in dns.
When you think about it DNS is really just a big distributed phone book, a key value store to look up numbers based on names. The reverse records are a method to look up names based on numbers using that same distributed architecture.
There is also an interesting legacy architecture interaction here, traditional phones can only enter numbers. Cell phones could use dns names directly(but don't) or we could use ip addresses as a sort of modern phone number(but don't), The whole world was connected via phone numbers and that is now how we expect phones to operate.
would have been a lot cooler if you leaked the call logs to DDoSecrets instead so the public could see them
TheFerridge 2 days ago [-]
wow incredible story! Reminds me of phone phreaking stories from decades ago!
dkga 2 days ago [-]
Now a question daunted on me. Assuming away strategies like store-and-decrypt-later-in-a-quantum-future, could a MITM really eavesdrop, as in, aren’t such ARPA-routed phone calls encrypted?
thataccount 1 days ago [-]
IT career in general, nobody cares until suddenly everyone does.
hnicrcjk6o 2 days ago [-]
Neat
ChristmasTomer 2 days ago [-]
Honestly the military part isn't even the craziest thing here. It's the fact that this old, basically forgotten tech was still being used by real systems like nothing happened lol.
Makes you wonder how much ancient telecom stuff is still running somewhere just because nobody touched it in 15 years.
This doesn't even feel like a hack. More like someone opened an old door and realized nobody had checked if it was locked in forever.
tosti 2 days ago [-]
> The source IPs were mostly American.
> So I had accidentally logged hundreds of thousands of phone numbers and timestamps for calls going to military bases.
That's quite a jump to conclusion right there.
matteason 2 days ago [-]
Where else would they be calling on Diego Garcia apart from the military base?
bobmcnamara 2 days ago [-]
Are they still dumping Tamils there?
duskwuff 2 days ago [-]
You might be thinking of Nauru. Different island.
alasdair_ 2 days ago [-]
The poster knows the phone numbers that were called. It doesn’t seem difficult to check who owns the numbers.
dylan604 2 days ago [-]
Not really. It's a pretty logical assumption. It sounds as if you might not be familiar with Diego Garcia?
tosti 2 days ago [-]
Having looked into the matter, 4000 people live there. It's entirely possible there are subscribers outside the base, so numbers for that area aren't neccesarily terminated at the base. That said, it's likely. Military IT is rumoured to be outdated and awful.
RugnirViking 2 days ago [-]
no citizens are allowed on diego garcia and the native population was entirely kicked out. You need a very difficult to aquire permit directly from the millitary to land there.
I'm 99% sure anyone living there is millitary. There were some people fleeing from the sri lankan civil war that landed there and were stuck there for a bunch of years claiming asylum while the millitary tried to figure out what to do with them, but they were sent off the island a while back.
tosti 2 days ago [-]
Well, obviously everyone knows that!
herewulf 1 days ago [-]
Thanks to the Internet, yes, yes they do. Or rather they can in quite short order and then can thoughtfully join a discussion on the topic.
duskwuff 2 days ago [-]
> It's entirely possible there are subscribers outside the base
There are none. The native Chagossians were all expelled in the 1960s-70s.
herewulf 1 days ago [-]
"Native" is a stretch. It does not mean that they don't have a legitimate claim but the fact of the matter is that the islands were uninhabited prior to the Age of Sail.
It's actually not completely dead... It's just (almost) completely non-public.
You can subscribe to services to get number porting information where the interface is basically e164.arpa/ENUM queries to a private nameserver over a VPN. I don't know the details, the cost was high enough that it didn't make sense for my employer to pursue it.
As someone who's been in the VoIP industry for over 20 years it makes me sad to think of what could have been if both ENUM and IPv6 were more widely adopted. For many years you could reach me via email, SIP, or Jabber with the same identifier and if there were effective support for ENUM in the USA my work phone number would have been able to connect you to any of them, directly and with G.722 HD voice long before it eventually came to modern cellular networks.
https://www.youtube.com/watch?v=yL1z1ZHD0K4
you know there’s hope for our future.
I love the line near the end of the article: "So in the end, I was down 10€ in domain fees, there was sadly no bug bounty (I thankfully didn't get my door kicked in at least)."
Makes me cringe, imagining what that would be like.
The most I can see is you making a silly American-centric remark, and people gently correcting you that there are other places on earth.
There is another schema called TRIP [1] - telephony routing over ip that uses a number format "1234*1455" designed to be entered on a standard phone keypad. When I registered my ITAD (internet telephony administrative domain, the RHS of a TRIP number) I was lucky enough to get one that matches my local dialling code!
https://tripresurgence.org/trip/history/ [1]
As far as I remember, the Austrian telco regulator was particularly SIP-forward in the early 2000s, and there was a prefix dedicated exclusively to ENUM-based services back in the day.
Unlike its sibling VoIP prefix, which was terminated the "usual PSTN way" by operators that would then bridge to SIP or whatever internally, the idea of the "ENUM first" prefix was that you'd register a number with some registrar and then make it resolve to your SIP client (via a proxy/service provider or directly to any publicly reachable IP address). Reachability from the PSTN was provided via gateways that would translate from circuit switched voice to SIP/RTP, so effectively you could really be reachable for incoming calls independently of any telco.
Unfortunately, as far as I remember both the VoIP and the ENUM prefix ended up being prohibitively expensive to call from many plans (they were billed at higher rates than both landlines and cellphones from many carriers and not included in any flat rate plans).
Still, together with native SIP and Wi-Fi support in many early smartphones at the time, it felt like standards-based Internet telephony was just around the corner, which of course didn't quite play out, and we ended up with the fragmented OTT landscape of today instead that only uses phone numbers as user identifiers, with a per-service privately managed directory instead of a DNS-based one.
It's a shame the author wasn't rewarded but at least the story can now be told over a beer.
loads of webrings also started -- 90s internet is back, just look for it <3
Who knows! Maybe it’s working just fine, but the e164.arpa record is pointing to the public prosecutor’s teapot or something.
I don't want the miss the young girls skills but she is no security researcher but in the eyes for her target simple a hacker. And I would say too that she got lucky. It would not be the first time that inexperienced young persona have to suffer the consequences even of their well intended actions.
How would the “outgoing call to the real destination” avoid this same lookup? Directives to route around the ENUM system?
I find this such a bad idea, if I want to use the cheap internet for a call I would use an internet based voice call system directly, rather than messing around with telephone numbers and I guess potentially accidentally doing an expensive phone call (same with RCS/SMS vs. just using an internet-based chat directly).
Having said that, SIP is barely better.
Makes me wonder how many partly implemented but ignored protocols like this exist.
If you control both endpoints and they support it you can configure them to use encryption, but even then implementation qualities vary widely (just because you enable SIP over TLS doesn’t mean they’ll actually verify the certificates for example - giving you at best opportunistic encryption), and I bet a lot of the implementations also have bugs/vulnerabilities.
If security is needed, it is often implemented by way of running the whole thing over private links (which can be secured with IPSec or any other VPN technology). In fact that’s presumably what’s happening, but misconfigured equipment making those ENUM lookups would allow the attacker to steer the traffic away from the secure link and towards an endpoint they control over the public internet.
I’d forgotten the keywords of power to find it again. I liked the idea.
I’m assuming this is is it again.
[1] https://en.wikipedia.org/wiki/Google_Voice
I remember because it seemed quite a nice idea, almost obvious.
I would not at all be surprised seeing that domain being abandoned again at a renewal in the near future.
Is this related to Softphone / VOIP in any way?
The normal path for voip phones given a phone number is to end up at a sip trunk provider go over the traditional phone network (which at this point probably routes over the internet anyway) hit another sip trunk and end up at the receiving sip phone.
This provides a method to bypass the traditional phone network and go directly over the internet. The sip phone looks up the host responsible for that phone number and directly connects. The sip providers would be responsible for maintaining this number to host mapping in dns.
When you think about it DNS is really just a big distributed phone book, a key value store to look up numbers based on names. The reverse records are a method to look up names based on numbers using that same distributed architecture.
There is also an interesting legacy architecture interaction here, traditional phones can only enter numbers. Cell phones could use dns names directly(but don't) or we could use ip addresses as a sort of modern phone number(but don't), The whole world was connected via phone numbers and that is now how we expect phones to operate.
Makes you wonder how much ancient telecom stuff is still running somewhere just because nobody touched it in 15 years.
This doesn't even feel like a hack. More like someone opened an old door and realized nobody had checked if it was locked in forever.
> So I had accidentally logged hundreds of thousands of phone numbers and timestamps for calls going to military bases.
That's quite a jump to conclusion right there.
I'm 99% sure anyone living there is millitary. There were some people fleeing from the sri lankan civil war that landed there and were stuck there for a bunch of years claiming asylum while the millitary tried to figure out what to do with them, but they were sent off the island a while back.
There are none. The native Chagossians were all expelled in the 1960s-70s.