"The word 'radical' derives from the Latin word for root. Therefore, if you want to get to the root of anything you must be radical. It is no accident that the word has now been totally demonized..." -- Gore Vidal
Ok... We all have heard of Vonage and the other VoIP providers that will give you unlimited phone services over your broadband connection using your regular old phone. But there are other services that are similar but have a few extra fun options. Let's take a look.
Let’s cover one of the services I have started playing with http://www.voipbuster.com/. Now for legitimate use it is a very good provider, and I have enjoyed calling friends all over the world. Now we move on to cover the dark side of online VoIP providers. One thing to think about is where the provider is located (what country). This is important because there are different laws for different countries, and, if you use the service to harass people (which is really lame), you could find yourself in real trouble. The kind of fun I am talking about is Spoofing Caller ID and also Call Bridging.
Direct or Call Bridging
This is the act of connecting two PSTN numbers from a 3rd party. Basically this function allows you to use software to call friends by having the VoIP service call your PSTN number 1st, and, after the call on your phone goes off hook, it will auto dial the remote end PSTN number. Since both land line phones where called, neither one of the landline phones will be billed for the call. The cool thing is that caller ID is sent in both directions from the numbers called, so your phone is ringing with your remote numbers caller ID. When you pick the line up the other end starts ringing, and they see your caller ID. So there is no trace of the 3rd party connection other than the 1st line getting an auto ringing when it goes off hook to the remote line.
This service used legitimately is very useful and cool. But if you decide to use this for fun, then you can force anyone to call anyone else, and they will have no idea what is happening. To the end caller it looks like they are getting called from the other line. This is fun to do when you are around to see the faces of the people you are forcing to call each other.
Now for the dark side. If you call someone’s cell phone, keep them online and call it again while spoofing the number to match their cell phone, it should force you into their voicemail. The trick here is that some cell providers do not set passwords to voicemail if it is called from it’s own number (even if you are prompted for a password a lot of systems have default passwords that never get changed). Other fun things to do with caller ID are spoofing your outbound ID to show something funny (like “BellSouth”). The idea here is that the sky is the limit since the PSTN is permanently hooked to the internet. I am sure we will see a lot of hacks coming to exploit the fact that the internet and phone infrastructure are now merging.
Yet another trick you can use to have fun is Phone Card Spoofing. Again there are legitimate reasons to have this kind of card. You perhaps need to call someone to give them an anonymous tip but wanted to make sure your call was not traced (the card provider could still release the call logs to law enforcement). One of the more popular spoofing card providers is http://www.spoofcard.com/. Now with the different spoofing card providers they offer different features such as:
* the ability to change what someone sees on their caller ID display when they receive a phone call
* make calls truly private
* ability to record calls
* web based control panels
* ability to change your voice on the call
Sniffing VoIP Calls
Now there are a few good reasons for sniffing VoIP calls like to troubleshoot VoIP routing issues or to record you own calls. Now there are also many bad things that can come out of sniffing VoIP like the fact that if you are on a open WiFi AP, others can be recording your calls and even rerouting them. There are many kinds of sniffers out on the internet for free, but the only one I trust and endorse would have to be Cain & Able from http://www.oxid.it/. With Cain & Able you can do a lot of different kinds of sniffing including the capturing of passwords, RPD sessions, SSH, Telnet and VoIP calls. Cain can do a lot more than just that, but I recommend going to their site to read more.
As everything moves to the internet there, will be many helpful advances in the way we live. But keep in mind that with every new convenience, there are risks associated with it. If you have any questions about VoIP or anything covered in this paper, feel free to Google your question first, and then join me in the forums here on www.ethicalhacker.net.
First picture of VoIP system courtesy of http://www.trust.com/products/info/voip/.