21 comments

  • toast012 hours ago
    &gt; It never really took off though, and even back in its early days it saw barely any use. Over the years it just deteriorated further, and today it&#x27;s basically completely dead.<p>It&#x27;s actually not completely dead... It&#x27;s just (almost) completely non-public.<p>You can subscribe to services to get number porting information where the interface is basically e164.arpa&#x2F;ENUM queries to a private nameserver over a VPN. I don&#x27;t know the details, the cost was high enough that it didn&#x27;t make sense for my employer to pursue it.
    • wolrah12 hours ago
      It&#x27;s also not uncommon for telecom providers to use it for their own internal routing because enough telecom software did in fact develop support for it despite lack of public implementations.<p>As someone who&#x27;s been in the VoIP industry for over 20 years it makes me sad to think of what could have been if both ENUM and IPv6 were more widely adopted. For many years you could reach me via email, SIP, or Jabber with the same identifier and if there were effective support for ENUM in the USA my work phone number would have been able to connect you to any of them, directly and with G.722 HD voice long before it eventually came to modern cellular networks.
      • tyromaniac11 hours ago
        There was a startup called WUPHF that used some telecom wizardry to multicast messages between providers given a single identifier, I&#x27;m not sure what happened to it...
        • skinfaxi3 hours ago
          Is this a veiled reference to The Office?
        • pknopf9 hours ago
          I heard they had a buyer and sold early.
      • srejk11 hours ago
        Can confirm. Work for a major telco and we use ENUM internally.
        • trollbridge11 hours ago
          Yep. The traffic he got appears to be stuff that should have remained private that leaked to a public network; it&#x27;s not the first time that&#x27;s happened, particularly for U.S. military traffic which is accustomed to having its own publicly-routable &#x2F;8&#x27;s, as opposed to the rest of us who use non-routable 10, 192, etc. space.
  • dmd11 hours ago
    I&#x27;m mostly amazed the author didn&#x27;t land in jail, which is the normally the response to reporting this kind of thing to authorities.
    • jakzurr10 hours ago
      Whew, absolutely!<p>I love the line near the end of the article: &quot;So in the end, I was down 10€ in domain fees, there was sadly no bug bounty (I thankfully didn&#x27;t get my door kicked in at least).&quot;<p>Makes me cringe, imagining what that would be like.
    • contingencies9 hours ago
      Given the author appears to be a 19 year old German girl, UK bureaucrats proxying admin duties for offshore territories are unlikely to be motivated to start an international extradition for what amounts to a helpful tip.
      • Barbing8 hours ago
        When you see<p><pre><code> “fun fact: this entire website is written without any javascript […]” </code></pre> and “19 years old”,<p>you know there’s hope for our future.
        • selfmodruntime6 hours ago
          The entire blog at lina.sh gives me such a fuzzy feeling of the old web.
          • Barbing2 hours ago
            Didn’t click the links on bottom of homepage but betting many of those sites will give you that same feeling. Web rings! Just great.
      • BobbyTables23 hours ago
        If the author was an 35 yr old Nigerian immigrant, would the response have been different?
  • chaz611 hours ago
    It is a shame they did not actually set up a SIP server and see if any of those requests turned into actual call terminations.<p>There is another schema called TRIP [1] - telephony routing over ip that uses a number format &quot;1234*1455&quot; designed to be entered on a standard phone keypad. When I registered my ITAD (internet telephony administrative domain, the RHS of a TRIP number) I was lucky enough to get one that matches my local dialling code!<p><a href="https:&#x2F;&#x2F;tripresurgence.org&#x2F;trip&#x2F;history&#x2F;" rel="nofollow">https:&#x2F;&#x2F;tripresurgence.org&#x2F;trip&#x2F;history&#x2F;</a> [1]
  • dkga8 hours ago
    I enjoyed reading this much more than anything I read here recently. In particular I like how it absolutely shows that somethings just… fall through the cracks!
  • cryptolobster11 hours ago
    It&#x27;s funny how such holes can remain for years, and no one notices until someone stumbles upon them. It&#x27;s interesting that no serious organization wanted to address the issue until it was discovered that the military was involved.<p>It&#x27;s a shame the author wasn&#x27;t rewarded but at least the story can now be told over a beer.
  • MotoriX11 hours ago
    Man, you really got lucky they didn’t throw you in jail. Anything related to national defense is pretty scary. Do you think you might get some kind of reward for exposing this vulnerability?
    • edelbitter4 hours ago
      You never know in Germany. Jail time might still be looming.. after some 3-5 years of delay because the telefax machine at the public prosecutors office is currently broken (and not even for DNS reasons!)
    • lukan8 hours ago
      Fortunately it was the national defense of a different country (UK and not germany) so that might have helped.
      • Barbing8 hours ago
        Don’t know how one could live with themself prosecuting security researchers. Think they’re saving face?
  • edm0nd23 minutes ago
    would have been a lot cooler if you leaked the call logs to DDoSecrets instead so the public could see them
  • bcx7 hours ago
    Their homepage, <a href="https:&#x2F;&#x2F;lina.sh&#x2F;" rel="nofollow">https:&#x2F;&#x2F;lina.sh&#x2F;</a>, reminds me of the early days of the internet. Are webrings back in fashion? Or is this just a group of old school folks keeping the nostalgia alive?
    • fc417fc8023 hours ago
      There are various subcultures outside the mainstream part of the internet that largely eschew modern web design. Not entirely dissimilar to HN itself.
    • j0ej0ej0e5 hours ago
      Just 19 too, what a talent!
  • yellers1 hour ago
    !remind me 21-Apr-2027.....<p>I would not at all be surprised seeing that domain being abandoned again at a renewal in the near future.
  • trilogic11 hours ago
    R.I.P You remind me of Mitnick, this is incarnation cause you have the same style verbatim. Glad to know your breed is still active.
    • Insanity11 hours ago
      I know opinions about Mitnick are quite divided. But I enjoyed reading &quot;Ghost in the Wires&quot; (<a href="https:&#x2F;&#x2F;www.goodreads.com&#x2F;book&#x2F;show&#x2F;10256723-ghost-in-the-wires" rel="nofollow">https:&#x2F;&#x2F;www.goodreads.com&#x2F;book&#x2F;show&#x2F;10256723-ghost-in-the-wi...</a>). It&#x27;s giving this 90s-era hacker vibe that&#x27;s kinda fun (even if the truth might be stretched a bit).
  • shorsher12 hours ago
    The article mentions Ascension Island, a small island in the south atlantic. There&#x27;s a really great spy novel that takes places there, Ascension by Oliver Harris.
    • dewey11 hours ago
      I just finished that recently, I think &quot;A Shadow Intelligence&quot; from the same author is even better so can recommend that too.
  • samteeeee10 hours ago
    Great story. Gives me nostalgia for the old days of the internet.
  • bdavbdav6 hours ago
    Amazed enum.org.uk hasn’t been scooped by a bot. 4 letters are £££.
  • seri4l5 hours ago
    So what software could be making these ENUM queries? Any theories?
  • joncrane12 hours ago
    Now THIS is what hacking is all about. Very cool.
  • TheFerridge8 hours ago
    wow incredible story! Reminds me of phone phreaking stories from decades ago!
  • dkga5 hours ago
    Now a question daunted on me. Assuming away strategies like store-and-decrypt-later-in-a-quantum-future, could a MITM really eavesdrop, as in, aren’t such ARPA-routed phone calls encrypted?
  • brcmthrowaway11 hours ago
    Why is a phone call making a DNS query?<p>Is this related to Softphone &#x2F; VOIP in any way?
    • somat8 hours ago
      The article covers it, but to reiterate. Yes, The idea is to have a mechanism to map phone numbers to hosts.<p>The normal path for voip phones given a phone number is to end up at a sip trunk provider go over the traditional phone network (which at this point probably routes over the internet anyway) hit another sip trunk and end up at the receiving sip phone.<p>This provides a method to bypass the traditional phone network and go directly over the internet. The sip phone looks up the host responsible for that phone number and directly connects. The sip providers would be responsible for maintaining this number to host mapping in dns.<p>When you think about it DNS is really just a big distributed phone book, a key value store to look up numbers based on names. The reverse records are a method to look up names based on numbers using that same distributed architecture.<p>There is also an interesting legacy architecture interaction here, traditional phones can only enter numbers. Cell phones could use dns names directly(but don&#x27;t) or we could use ip addresses as a sort of modern phone number(but don&#x27;t), The whole world was connected via phone numbers and that is now how we expect phones to operate.
    • implements10 hours ago
      If the phone is behind a NAT firewall &#x2F; router it may need external help to receive calls: <a href="https:&#x2F;&#x2F;support.aa.net.uk&#x2F;VoIP_NAT" rel="nofollow">https:&#x2F;&#x2F;support.aa.net.uk&#x2F;VoIP_NAT</a>
      • fsfod9 hours ago
        aa.net.uk a couple of months did actually break calls with badly configured DNS entries.
        • implements9 hours ago
          Cheers! - hadn’t heard that. Here’s the report: <a href="https:&#x2F;&#x2F;aastatus.net&#x2F;42881" rel="nofollow">https:&#x2F;&#x2F;aastatus.net&#x2F;42881</a>
  • adolph12 hours ago
    This is a great story. Almost wish the author had dug a little further in and discovered something like Clifford Stoll in The Cuckoo&#x27;s Egg, but a nice writeup nontheless.<p>Makes me wonder how many partly implemented but ignored protocols like this exist.
  • hnicrcjk6o11 hours ago
    Neat
  • tosti12 hours ago
    &gt; The source IPs were mostly American.<p>&gt; So I had accidentally logged hundreds of thousands of phone numbers and timestamps for calls going to military bases.<p>That&#x27;s quite a jump to conclusion right there.
    • matteason11 hours ago
      Where else would they be calling on Diego Garcia apart from the military base?
      • bobmcnamara2 hours ago
        Are they still dumping Tamils there?
        • duskwuff1 hour ago
          You might be thinking of Nauru. Different island.
    • alasdair_12 hours ago
      The poster knows the phone numbers that were called. It doesn’t seem difficult to check who owns the numbers.
    • dylan60412 hours ago
      Not really. It&#x27;s a pretty logical assumption. It sounds as if you might not be familiar with Diego Garcia?
      • tosti11 hours ago
        Having looked into the matter, 4000 people live there. It&#x27;s entirely possible there are subscribers outside the base, so numbers for that area aren&#x27;t neccesarily terminated at the base. That said, it&#x27;s likely. Military IT is rumoured to be outdated and awful.
        • RugnirViking11 hours ago
          no citizens are allowed on diego garcia and the native population was entirely kicked out. You need a very difficult to aquire permit directly from the millitary to land there.<p>I&#x27;m 99% sure anyone living there is millitary. There were some people fleeing from the sri lankan civil war that landed there and were stuck there for a bunch of years claiming asylum while the millitary tried to figure out what to do with them, but they were sent off the island a while back.
        • duskwuff11 hours ago
          &gt; It&#x27;s entirely possible there are subscribers outside the base<p>There are none. The native Chagossians were all expelled in the 1960s-70s.
        • dylan60410 hours ago
          [flagged]