Tuesday, 18 November 2014

Cheesebox Plans

Cheesebox Plans                         Courtesy of The Jolly Roger

     A Cheesebox (named for the type of box the first one was
found in) is a type of box which will, in effect, make your
telephone a Pay-Phone.....This is a simple,modernized, and easy
way of doing it....

      Inside Info:These were first used by bookies many years ago
as a way of making calls to people without being called by the
cops or having their numbers traced and/or tapped......

     How To Make A Modern Cheese Box

     Ingredients:
     ------------

     1 Call Forwarding service on the line

     1 Set of Red Box Tones

     The number to your prefix's Intercept operator (do some scanning
     for this one)

     How To:
     -------

       After you find the number to the intercept operator in
your prefix, use your call-forwarding and forward all calls to
her...this will make your phone stay off the hook(actually, now
it waits for a quarter to be dropped in)...you now have a cheese
box... In Order To Call Out On This Line:You must use your Red
Box tones and generate the quarter dropping in...then,you can
make phone calls to people...as far as I know, this is fairly
safe, and they do not check much...Although I am not sure, I
think you can even make credit-card calls from a cheesebox
phone and not get traced...

-- Exodus --


Cellular Phreaking

Cellular Phreaking                         courtesy of The  Jolly Roger

     The cellular/mobile phone system is one that is perfectly set up to be
exploited by phreaks with the proper knowledge and equipment.  Thanks to
deregulation, the regional BOC's (Bell Operating Companies) are scattered
and do not communicate much with each other.  Phreaks can take advantage of
this by pretending to be mobile phone customers whose "home base" is a city
served by a different BOC, known as a "roamer".  Since it is impractical
for each BOC to keep track of the customers of all the other BOC's, they
will usually allow the customer to make the calls he wishes, often with a
surcharge of some sort.

The bill is then forwarded to the roamer's home BOC for collection.
However, it is fairly simple (with the correct tools) to create a bogus ID
number for your mobile phone, and pretend to be a roamer from some other
city and state, that's "just visiting".  When your BOC tries to collect for
the calls from your alleged "home BOC", they will discover you are not a
real customer; but by then, you can create an entirely new electronic
identity, and use that instead.
    How does the cellular system know who is calling, and where they are?
When a mobile phone enters a cell's area of transmission, it transmits its
phone number and its 8 digit ID number to that cell, who will keep track of
it until it gets far enough away that the sound quality is sufficiently
diminished, and then the phone is "handed off" to the cell that the customer
has walked or driven into.  This process continues as long as the phone has
power and is turned on.  If the phone is turned off (or the car is), someone
attempting to call the mobile phone will receive a recording along the
lines of "The mobile phone customer you have dialed has left the vehicle
or driven out of the service area."   When a call is made to a mobile phone,
the switching equipment will check to see if the mobile phone being called is
"logged in", so to speak, or present in one of the cells.  If it is, the
call will then act (to the speaking parties) just like a normal call - the
caller may hear a busy tone, the phone may just ring, or the call may be
answered.
    How does the switching equipment know whether or not a particular
phone is authorized to use the network?  Many times, it doesn't.  When a
dealer installs a mobile phone, he gives the phone's ID number (an 8 digit
hexadecimal number) to the local BOC, as well as the phone number the BOC
assigned to the customer.  Thereafter, whenever a phone is present in one
of the cells, the two numbers are checked - they should be registered to
the same person.  If they don't match, the telco knows that an attempted
fraud is taking place (or at best, some transmission error) and will not
allow calls to be placed or received at that phone.  However, it is
impractical (especially given the present state of deregulation) for the
telco to have records of every cellular customer of every BOC.  Therefore,
if you're going to create a fake ID/phone number combination, it will need
to be "based" in an area that has a cellular system (obviously), has a
different BOC than your local area does, and has some sort of a "roamer"
agreement with your local BOC.

   How can one "phreak" a cellular phone?  There are three general areas
when phreaking cellular phones; using one you found in an unlocked car
(or an unattended walk-about model), modifying your own chip set to look
like a different phone, or recording the phone number/ID number combinations
sent by other local cellular phones, and using those as your own.  Most
cellular phones include a crude "password" system to keep unauthorized
users from using the phone - however, dealers often set the password
(usually a 3 to 5 digit code) to the last four digits of the customer's
mobile phone number.  If you can find that somewhere on the phone, you're
in luck.  If not, it shouldn't be TOO hard to hack, since most people
aren't smart enough to use something besides "1111", "1234", or whatever.
If you want to modify the chip set in a cellular phone you bought
(or stole), there are two chips (of course, this depends on the model and
manufacturer, yours may be different) that will need to be changed - one
installed at the manufacturer (often epoxied in) with the phone's ID
number, and one installed by the dealer with the phone number, and possible
the security code.  To do this, you'll obviously need an EPROM burner
as well as the same sort of chips used in the phone (or a friendly and
unscrupulous dealer!).  As to recording the numbers of other mobile phone
customers and using them; as far as I know, this is just theory... but it
seems quite possible, if you've got the equipment to record and decode it.
The cellular system would probably freak out if two phones (with valid
ID/phone number combinations) were both present in the network at once,
but it remains to be seen what will happen.

-----Compiled by: Exodus-------

The BLAST Box

The BLAST Box                                 Courtesy of the Jolly Roger

Ever want to really make yourself be heard? Ever talk to someone on the phone
who just doesn't shut up? Or just call the operator and pop her eardrum? Well,
up until recently it has been impossible for you to do these things. That is,
unless of course you've got a blast box. All a blast box is, is a really cheap
amplifier, (around 5 watts or so) connected in place of the microphone on your
telephone. It works best on model 500 AT&T Phones, and if constructed small
enough, can be placed inside the phone.

Construction:

Construction is not really important. Well it is, but since I'm letting you make
your own amp, I really don't have to include this.

Usage:

Once you've built your blast box, simply connect a microphone (or use the
microphone from the phone) to the input of the amplifier, and presto. There it
is. Now, believe it or not, this device actually works. (At least on crossbar.)
It seems that Illinois bell switching systems allow quite alot of current to
pass right through the switching office, and out to whoever you're calling. When
you talk in the phone, it comes out of the other phone (again it works best if
the phone that you're calling has the standard western electric earpiece)
incredibly loud. This device is especially good for PBS Subscription drives.
Have "Phun", and don't get caught!

---- Compiled by: Exodus------

The BLAST Box

The BLAST Box                                 Courtesy of the Jolly Roger

Ever want to really make yourself be heard? Ever talk to someone on the phone
who just doesn't shut up? Or just call the operator and pop her eardrum? Well,
up until recently it has been impossible for you to do these things. That is,
unless of course you've got a blast box. All a blast box is, is a really cheap
amplifier, (around 5 watts or so) connected in place of the microphone on your
telephone. It works best on model 500 AT&T Phones, and if constructed small
enough, can be placed inside the phone.

Construction:

Construction is not really important. Well it is, but since I'm letting you make
your own amp, I really don't have to include this.

Usage:

Once you've built your blast box, simply connect a microphone (or use the
microphone from the phone) to the input of the amplifier, and presto. There it
is. Now, believe it or not, this device actually works. (At least on crossbar.)
It seems that Illinois bell switching systems allow quite alot of current to
pass right through the switching office, and out to whoever you're calling. When
you talk in the phone, it comes out of the other phone (again it works best if
the phone that you're calling has the standard western electric earpiece)
incredibly loud. This device is especially good for PBS Subscription drives.
Have "Phun", and don't get caught!

---- Compiled by: Exodus------

White Box Plans

White Box Plans                                 by the Jolly Roger

Introduction:
------------
     The White Box is simply a portable Touch-Tone keypad. For more
information on Touch-Tone, see my Silver Box Plans.
Materials:
---------
  1 Touch-Tone Keypad
  1 Miniature 1000 to 8 Ohm Transformer
    (Radio Shack # 273-1380)
  1 Standard 8 Ohm Speaker
  2 9V Batteries
  2 9V Battery Clips

Procedure:
---------
(1) Connect the Red Wire from the Transformer to either terminal on the
Speaker.
(2) Connect the White Wire from the Transformer to the other terminal on
the Speaker.
(3) Connect the Red Wire from one Battery Clip to the Black Wire from the other
Battery Clip.
(4) Connect the Red Wire from the second Battery Clip to the Green Wire
from the Keypad.
(5) Connect the Blue Wire from the Keypad to the Orange/Black Wire from
the Keypad.
(6) Connect the Black Wire from the first Battery Clip to the two above
wires (Blue and Black/Orange).
(7) Connect the Black Wire from the Keypad to the Blue Wire from the
Transformer.
(8) Connect the Red/Green Wire from the Keypad to the Green Wire from the
Transformer.
(9) Make sure the Black Wire from the Transformer and the remaining wires
from the Keypad are free.
(10) Hook up the Batteries.

Optional:
--------
(1) Put it all in a case.
(2) Add a Silver Box to it.

Use:
---
Just use it like a normal keypad, except put the speaker next to the
receiver of the phone you're using.

                              ---------Exodus--------


Verification Circuits

Verification Circuits                  courtesy of the Jolly Roger
      (originally an Apple ][ file so forgive the upper case!)

1. ONE BUSY VERIFICATION CONFERENCE CIRCUIT IS ALWAYS PROVIDED.THE CIRCUIT IS A
THREE-WAY CONFERENCE BRIDGE THAT ENABLES AN OPERERATOR TO  VERIFY THE BUSY/IDLE
CONDITION OF A SUBSCRIBER LINE.UPON REQUEST OF A PARTY ATTEMPTING TO REACH A
SPECIFIED DIRECTORY NUMBER, THE OPERATOR DIALS THE CALLED LINE NUMBER TO
DETERMINE IF THE LINE IS IN USE,IF THE RECEIVER IS OFF THE HOOK,OR IF THE LINE
IS IN LOCKOUT DUE TO A FAULT CONDITKON.THE OPERATOR THEN RETURNS TO THE PARTY
TRYING TO REACH THE DIRE CTORY NUMBER AND STATES THE CONDITION OF THE
LINE.LINES WITH DATA SECURITY CAN NOT BE ACCESSED FOR BUSY VERIFICATION WHEN
THE LINE IS IN USE.(REFER ALSO TO DATA SECURITY)
2. THREE PORTS ARE ASSIGNED TO EACH BUSY VERIFICATION CONFERENCE CIRCUIT.ONE
PORT IS FOR OPERATOR ACCESS AND TWO PORTS ARE USED TO SPLIT AN EXISTING
CONNECTION.TO VERKFY THE BUSY/IDLE CONDITION OF A LINE,THE OPERATOR
ESTABLISHED A CONNECTION TO THE OPERATOR ACCESS PORT AND DIALS THE DIRECTORY
NUMBER OF THE LINE TO BE VERIFIED.IF THE LINE IS IN USE,THE EXISTING
CONNECTION IS BROKEN AND IMMEDIATLY RE-ESTABLISHED THROUGH THE
OTHER TWO PORTS OF THE BUSY VERIFICATION CIRCUIT WITHOUT INTERRUPTION.
BUSY VERIFICATION CIRCUIT IS CONTROLLED BY ACCESS CODE. A DEDICATED TRUNK CAN
BE USED BUT IS NOT NECESSARY.
3. THE BUSY VREIFICATION CIRCUIT ALSO CAN BE USED FOR TEST VERIFY FROM THE WIRE
CHIEFS TEST PANEL.
   B. ADDITIONAL BUSY VERIFICATION CONFERENCE CIRCUITS (002749)
O.K. THERE IT IS-RIGHT OUT OF AN ESS MANUAL WORD FOR WORD! (AND IM GETTING 25
LINEAR FEET OF ESS MANUALS!!! NOT COUNTING THE STACK RECEIVED SO FAR!

            Brought to you in the Cookbook IV by Exodus!!!!

Hacking Vax's & Unix

Hacking Vax's & Unix                             by the Jolly Roger

    Unix is a trademark of At&t (and you know what that means)

_______________________________________
In this article, we discuss the unix system that runs on
the various vax systems.  If you are on another unix-type system, some
commands may differ, but since it is licenced to bell, they can't make many
changes.
_______________________________________
Hacking onto a unix system is very difficult, and in this case, we advise
having an inside source, if possible. The reason it is difficult to hack a
vax is this:  Many vax, after you get a carrier from them, respond=>
Login:
They give you no chance to see what the login name format is.  Most commonly
used are single words, under 8 digits, usually the person's name.  There is
a way around this:  Most vax have an acct. called 'suggest' for people to
use to make a suggestion to the system root terminal.  This is usually watched
by the system operator, but at late he is probably at home sleeping or
screwing someone's brains out.  So we can write a program to send at the
vax this type of a message:
A screen freeze (Cntrl-s), screen clear (system dependant), about 255
garbage characters, and then a command to create a login acct., after which
you clear the screen again, then unfreeze the terminal.  What this does:
When the terminal is frozen, it keeps a buffer of what is sent.  well, the
buffer is about 127 characters long. so you overflow it with trash, and then
you send a command line to create an acct. (System dependant).  after this
you clear the buffer and screen again, then unfreeze the terminal.  This is
a bad way to do it, and it is much nicer if you just send a command to
the terminal to shut the system down, or whatever you are after...
There is always, *Always* an acct. called root, the most powerful acct.
to be on, since it has all of the system files on it.  If you hack your
way onto this one, then everything is easy from here on...
On the unix system, the abort key is the Cntrl-d key.  watch how many times
you hit this, since it is also a way to log off the system!
A little about unix architechture: The root directory, called root, is
where the system resides.  After this come a few 'sub' root directories,
usually to group things (stats here, priv stuff here, the user log here...).
Under this comes the superuser (the operator of the system), and then
finally the normal users.  In the unix 'Shell' everything is treated the same.
By this we mean:  You can access a program the same way you access a user
directory, and so on.  The way the unix system was written, everything,
users included, are just programs belonging to the root directory.  Those
of you who hacked onto the root, smile, since you can screw everything...
the main level (exec level) prompt on the unix system is the $, and if you
are on the root, you have a # (superuser prompt).
Ok, a few basics for the system... To see where you are, and what paths
are active in regards to your user account, then type
=> pwd
This shows your acct. seperated by a slash with another pathname (acct.),
possibly many times. To connect through to another path,
or many paths, you would type:
You=> path1/path2/path3
and then you are connected all the way from path1 to path3.  You can
run the programs on all the paths you are connected to.  If it does
not allow you to connect to a path, then you have insufficient privs, or
the path is closed and archived onto tape.  You can run programs this way
also:
you=> path1/path2/path3/program-name
Unix treats everything as a program, and thus there a few commands to
learn...
To see what you have access to in the end path, type=>
ls
for list.  this show the programs you can run.  You can connect to
the root directory and run it's programs with=>
/root
By the way, most unix systems have their log file on the root, so you
can set up a watch on the file, waiting for people to log in and snatch their
password as it passes thru the file. To connect to a directory, use the
command:
=> cd pathname  This allows you to do what you want
with that directory.  You may be asked for a password, but this is a good
ay of finding other user names to hack onto.
The wildcard character in unix, if you want to search down a path for
a game or such, is the *.
=> ls /*
Should show you what you can access. The file types are the same as they
are on a dec, so refer to that section when examining file.  To see what is
in a file, use the
=> pr
filename command, for print file.
We advise playing with pathnames to get the hang of the concept.  There
is on-line help available on most systems with a 'help' or a '?'.
We advise you look thru the help files and pay attention to anything
they give you on pathnames, or the commands for the system.
You can, as a user, create or destroy directories on the tree beneath you.
This means that root can kill everything but root, and you can kill any
that are below you.  These are the
=> mkdir pathname
=> rmdir pathname
commands.
Once again, you are not alone on the system... type=>
who
to see what other users are logged in to the system at the time.  If you
want to talk to them=>
write username
Will allow you to chat at the same time, without having to worry
about the parser.  To send mail to a user, say
=> mail
And enter the mail sub-system. To send a message to all the users
on the system, say
=> wall
Which stands for 'write all'. By the way, on a few systems,
all you have to do is hit the <return> key to end the message,
but on others you must hit the cntrl-d key.
To send a single message to a user, say
=> write username
this is very handy again!  If you send the sequence of characters discussed
at the very beginning of this article, you can have the super-user terminal do
tricks for you again.

Privs:
If you want superuser privs, you can either log in as root, or edit your
acct. so it can say
=> su
this now gives you the # prompt, and allows you to completely by-pass the
protection.  The wonderful security conscious developers at bell made it
very difficult to do much without privs, but once you have them, there
is absolutely nothing stopping you from doing anything you want to.
To bring down a unix system:
=> chdir /bin
=> rm *
this wipes out the pathname bin, where all the system maintenance files are.
Or try:
=> r -r
This recursively removes everything from the system except the remove
command itself.
Or try:
=> kill -1,1
=> sync
This wipes out the system devices from operation.
When you are finally sick and tired from hacking on the vax systems, just
hit your cntrl-d and repeat key, and you will eventually be logged out.
_______________________________________
The reason this file seems to be very sketchy is the fact that bell has 7
licenced versions of unix out in the public domain, and these commands are
those common to all of them.  I recommend you hack onto the root or
bin directory, since they have the highest levels of privs, and there
is really not much you can do (except develop software) without them.
_______________________________________


df