Discussion
Loading...

Post

Log in
  • About
  • Code of conduct
  • Privacy
  • Users
  • Instances
  • About Bonfire
Cat 🐈🥗 (D.Burch) :blobcatrainbow:
Cat 🐈🥗 (D.Burch) :blobcatrainbow:
@catsalad@infosec.exchange  ·  activity timestamp 7 hours ago

This blog post by @sirocyl from when they broke IKEA has me fricking dying everytime I hear it!

The IKEA automated call service did NOT like the DTMF bomb sent their way 😹

🗃️ https://web.archive.org/web/20230919171037/https://cohost.org/sirocyl/post/2891449-i-broke-ikea

🔊 https://web.archive.org/web/20230919171037im_/https://staging.cohostcdn.org/attachment/3e10ef51-37d7-4f11-bf6a-7df5a637ee81/1_Voicemail_1877xxxxxxx_20210628.mp3

sirocyl on cohost

I broke IKEA.

(or, well, one of their delivery services.) 🔊 Just a fair warning - there are some perhaps annoying glitch sounds in the attached recording. The volumes are normalized to limit loud spikes, as they were a lot worse in person. 😅 so, my phone service has a rather clever anti-spam tactic, which works like this: * I receive a phone call from an unknown number, and it goes through screening when I answer it. It rings until the fifth ring, the voicemail greeting plays out, then I've got 30 seconds to judge if it's a spam robocall or if it's genuine * If it's okay, I press 1, and it interrupts the ring/voicemail sequence and I answer the call like usual. * If it's spam, I press ### (the # key by itself normally opens my PBX menu, so it doesn't go through) and hang up immediately. Pressing ### and hanging up, will shove the call to voicemail, then launch a "DTMF bomb", which is a rapid sequence of over a hundred tones of DTMF keysmash, even including some of the "ABCD" keys. [https://en.wikipedia.org/wiki/Dual-tone_multi-frequency_signaling##,_*,_A,_B,_C,_and_D] This has blown up spammers' cheapass PBXes, especially ones with poor security and too much trust given to the DTMF decoder on the call server. So, when IKEA called from a random 1-877 number to confirm my furniture shipment of :sixty: (sixty) blåhaj (about $1200) worth, the only thing it said is "To continue in English, please press 1."... and I had no idea who it was, immediately thought it was spam, and did the ### gesture. Oops. What follows is a transcript of the call in the recording above. ---------------------------------------- > "To continue in English, please press 1️⃣." > [extremely rapid DTMF spam string] > "Your delivery is scheduled for Tuesday. Five. [A burst of digital static plays out here for about a quarter of a second.] $DeliveryDate between the hours of 2pm and 6pm. > > If an adult will not be available within the timeframe provided, or you have any other conflicts, please contact us at > 8 > 8 > 8 > 8 > 8 > 8 > 8 > 8 > 8 > 8 > 8 > 8 > 8 > 8 > 8 > 8 > 8 > 8 > 8 > 8 > Message repeat. ⚠️. Your delivery is scheduled for-" [total system breakdown occurs here... followed by dead line noise.] ............. [blerp] ............. [blerp] ............. [blerp] ............. [blerp] (Names, businesses, times, dates and phone numbers may be changed or redacted in order to protect the privacy of those involved.)
View the link
  • Copy link
  • Flag this post
  • Block
Jonas
Jonas
@magnetic_tape@infosec.exchange replied  ·  activity timestamp 4 hours ago

@catsalad
I wonder if the dtmf bomb file is available somewhere to save me from writing a tool to write it
@sirocyl

  • Copy link
  • Flag this comment
  • Block
petterroea :verified: :archlinux: :nix:
petterroea :verified: :archlinux: :nix:
@petterroea@infosec.exchange replied  ·  activity timestamp 5 hours ago

@catsalad @sirocyl wait... are they using @internetarchive as a hosting provider?

  • Copy link
  • Flag this comment
  • Block
Cat 🐈🥗 (D.Burch) :blobcatrainbow:
Cat 🐈🥗 (D.Burch) :blobcatrainbow:
@catsalad@infosec.exchange replied  ·  activity timestamp 5 hours ago

@petterroea @sirocyl @internetarchive Cohost is only a ghost now, so yeah 😔

  • Copy link
  • Flag this comment
  • Block
petterroea :verified: :archlinux: :nix:
petterroea :verified: :archlinux: :nix:
@petterroea@infosec.exchange replied  ·  activity timestamp 5 hours ago

@catsalad ooooh, that explains. What a shame

  • Copy link
  • Flag this comment
  • Block
TiTiNoNero :__:
TiTiNoNero :__:
@77nn@goto.77nn.it replied  ·  activity timestamp 6 hours ago

@catsalad @sirocyl

That could make a really cool piece of music!

  • Copy link
  • Flag this comment
  • Block
Nazo
Nazo
@nazokiyoubinbou@urusai.social replied  ·  activity timestamp 7 hours ago

@catsalad @sirocyl And now I wish I had a phone service that could do this to spammers...

  • Copy link
  • Flag this comment
  • Block
Isocat
Isocat
@isocat@tiggi.es replied  ·  activity timestamp 7 hours ago

@catsalad @sirocyl Why'd they do this?

  • Copy link
  • Flag this comment
  • Block

bonfire.cafe

A space for Bonfire maintainers and contributors to communicate

bonfire.cafe: About · Code of conduct · Privacy · Users · Instances
Bonfire social · 1.0.1-alpha.41 no JS en
Automatic federation enabled
Log in
  • Explore
  • About
  • Members
  • Code of Conduct