Hacker Newsnew | past | comments | ask | show | jobs | submitlogin
Identifying North American Phone Switches (omghax.ca)
96 points by doctorshady on June 28, 2016 | hide | past | favorite | 46 comments


I miss my phreaking days (the early to mid 90's). Me and a couple of buddies would drive out into the middle of nowhere late at night, find a convenience store with a COCOT, beige box off of it, and use my shitty 486 laptop to dial into the telephone switch for the local telco (which we found via trashing). We eventually worked out the password for an account that had the equivalent of "root" privileges and for a while basically owned the switch. The problem was, we didn't know how to do anything fun. We tried to do the thing we'd read about in that one Kevin Mitnick book, where you turn someone's home phone into a pay phone (that is, configure it so that when they pick up the phone and dial, they get the "please deposit $4.75 for the next 5 minutes" message) but never could get the exact right commands down. Well, so far as we know anyway. If it worked, we never heard about it. I won't say who the target was, to protect the guilty.

Those were the days... a 20+ foot phone cord stretched across a parking lot, and we'd sit there nervously looking for cars that might be cop cars, and try to figure out what we'd tell the cops if they stopped and asked what we were doing. But it was a rural area in the mid 90's, so we figured most of the cops were so technology illiterate that they would have no clue about hacking/phreaking or anything. At any rate, it (surprisingly, in hindsight) never came up.

There was a BBS we spent a lot of time on back then as well, from the 303 area code. I don't remember if the board was named Voyager, or if that was the nick of the guy who ran it. Anybody remember them/him?

Edit: Found it. The board was "Hacker's Haven" and the sysop was Voyager.


> * 5ESS line cards are pretty distinct sounding. They'll make weird noises whenever you go offhook, have a slightly higher noise floor then most line cards, and a very strange frequency response. This doesn't necessarily apply if you're using a line served out of a channel bank or something, but the line cards can give a very different experience on the phone network sometimes.

5E analog line cards are (as far as I know) are all concentrated at one level or another (think 4:1, 10:1, etc) - which means there is an analog cross point switch to tie your line up to a codec - when your line goes into permanent signal, you'll be linked up to what appears to be an analog announcement trunk, as to avoid tying up any of the TDM bandwidth on the switch.

Whereas DMS100's are codec per line, and are not concentrated in the same way. I think GTD-5's are also similar to the DMS and codec per line.

When you go off hook on a 5E you can her tick-ta-tick-tick-dialtone as it sets up the link thru the analog switching fabric - this seems to be universal to all 5E's - the 5E2000 sounds different, and I believe uses different ckt packs to do the switching, but fundamentally appears to work the same way (I've not had a chance to sit on a 5E2000 line to get permanent signal to confirm that).


Interesting! Sounds like you're pretty well versed in this sort of thing. The 5ESS analog line cards seem to roll off frequencies before 3100 hertz like on most switches (a fair bit too - like, maybe anything above 2950). Do you know if this is a byproduct of the analog switching stage? I always just assumed that was a bad design decision on someone's part.

As for the announcement trunks, I think the 13A/15A announcement machines, like the one on that 202-986 number, tend to break channels out into analog pairs. Sometimes you get crosstalk between the announcement pairs too - it's absolutely fantastic. For the longest time, I could've sworn the playback mechanism itself was analog between all the hiss, crosstalk, and analog source material you'd hear.

For the hell of it, here's some better examples of that system. That 202 number doesn't do it justice;

512-371-3337 (listen for the weird sweep crosstalk at the end)

425-433-0021


I know of no difference in the performance of the line card once the call is set up (as in I can't hear any), I do know what the subscriber hears from whatever announcement trunk generates permanent signal does sound fuzzy as hell (think ringing/wooshing S's).

If you wanna hear an interesting recording call 425-226-0000 - notice the lack of supe at the end of the call.


Haha, nice. They still haven't made the AIS report default to disconnection? When they first installed it five years ago or so, they never migrated the database over from the old unit, so pretty much everything said that. Makes me wonder how easy it'd be to get an operator asking for a number to key into that trunk.

As for the announcement trunk though, there are some 5Es equipped with other machines that sound pretty good;

503-632-1064 - ETC Digicept?

248-200-0015 - Lucent 17A (flash based replacement for the 16/-A. Lots of fun too. 0010 is the remote administration number)

By the way, someone mentioned a while ago that most of the relatively recent 5ESSes encapsulate everything over ATM. The few printouts I've seen from 5Es seem to show they're capable of speaking it, but haven't sent data over the interface. Do you know if there's any truth to that?


Yeah, it rings reorder, then busy, then after like full min after the recording is done it hangs up, it does hang up seem to hang up correctly when calling from inside that switch.

I don't think so on ATM - I have some documentation for it (training manual, system architecture processor, SM/CM), and ATM isn't mentioned anywhere in it, when you consider that the 5ESS architecture was designed in the 1978-1982 timeframe, ATM would make no sense at all, it'd be a backward forklift upgrade to retrofit it.

Do you have email or something, I'd love to converse further?


Sure! thoughtphreaker <at> shady <dot> tel


The details about being able to dial 0XX on some switches sounds scary. If I recall correctly, numbers starting with NPA-0XX and NPA-1XX were reserved for what essentially became network administrator functionality. These were ways to reach special telco operators, as well as testing equipment, either locally or across the long distance network.

Being able to reach this stuff is akin to bring able to talk to your ISP's internal IP network. Given the continued restriction of this special prefix (your telephone number still cannot start with a 0 or a 1 after the area code) and the persistence of legacy systems on the PSTN, I would not be surprised at all if these codes were still in use.


There's a lot of access tandem codes that use 0xx numbering. A lot of the really juicy stuff hides on toll networks though, and requires fairly specific trunks to reach them.

Overall though, I think most of the really sketchy stuff today hides in regular numbering ranges.

EDIT: I should qualify all that by saying nobody I know has actually gone through the trouble of rifling through all 10,000 (1,000? In some, the last digit seems to be ignored) numbers in an ATC before.

There's definitely stuff on there, but for whatever it's worth, Sprint's DMS-250 network will redirect the last four digits of an ATC destination to whatever number it thinks goes to the inward operator for that exchange. It's been like that for years, so maybe there's just nothing critical in there; else someone would've complained. Or on the other hand, maybe that's their way of locking it down.


Back in the day all the DATUs and SASS stuff were on regular exchanges, so I don't see why that would change. People like dec0der were indicted for rifling through all the carrier's "special" COs with wardialers to find them. And different providers would have different ranges for admin functions, maintenance, customer support, etc. It doesn't take long for a bored teenager with a modem to cycle through most of them (remember, only 540 COs per NPA, and while each CO had up to 10k subscribers, you could guess which ranges had something interesting on it)


Considering his text files, I'd think he went through the exchanges by hand. Typically faster and more accurate if you're just looking for test numbers.

http://oldskoolphreak.com/tfiles/phreak/ex_scan.txt http://oldskoolphreak.com/tfiles/phreak/espt2.txt


Oh sure, a lot was done by hand, but if you're looking at an exchange without knowing anything about the carrier and can't find whatever specific range they're using for op stuff, a wardialer looking for a 400hz tone will save you time sitting at a dialpad.

These files are from 5 years after I had started phreaking, which was 10-15 years after it had become popular. The only significant change I noticed was inbound dtmf tones being blocked, which really eliminated a lot of the fun you could have without finding your way into an admin line, an unsecured modem, or using social engineering.

Bellsouth-specific exchange scanning by hand: https://web.archive.org/web/20010311195935fw_/http://fl2600....

If you'd like to listen to what idiotic phreakers' podcasts from the early 2000s sounded like, here you go: http://audio.textfiles.com/shows/binrev/ http://audio.textfiles.com/shows/defaultradio/ (you'll notice default radio has fewer episodes, because decoder went to jail....)

There are some funny things though like Episode 84 of BinRev Radio, where Lucky225 finds out his voicemail number was found in Paris Hilton's phone's notes [after they were hacked], and social engineering their way through gated communities, which of course still works. Back when hacking was about fucking with systems, and not bug bounties and CTFs. (Get off my lawn!!!)


Although they're silly, I learnt a lot from things like BinRev growing up.

Lucky225 also owns the number of the former Mojave Phone Booth [0] which is now a party/conference line.

[0]: https://en.wikipedia.org/wiki/Mojave_phone_booth

[0.5]: http://99percentinvisible.org/episode/mojave-phone-booth/

[0.9]: +1 760-733-9969


This book is a great read and gives an amazing overview of the culture: https://smile.amazon.com/Exploding-Phone-Untold-Teenagers-Ou...

The group chats must of been so cool at that time.


It was fun. One of the interesting aspects of it (there were many) was the class of people who could share numbers via DTMF. They had build touch-tone decoders that could log the last 10-20 digits they heard. It separated the elite from the amateurs.


I think I hit the tail end of phreaking, most of the exposure I had was through text files downloaded from BBS/FTP sites that relayed the knowledge of building "boxes" with such colorful names as "blue", "brown", "rainbow", and "piss". The phreaking I knew moved from land lines (of which I only participated in 'beige-ing' from a neighbor's line, and I won a lineman's handset [thanks #303/cuervocon] ), to cell phone cloning, bridges, and the occasional digital switch. Less analog hardware, more software/digital systems. Nostalgic!


Having been born in the late 80s, this is before my time. But there seems to be a lot of fondness in hacker culture for phone phreaking. Frankly it seems almost out-sized: it even got a cameo in Pirates of Silicon Valley. So, why was this such a big deal? My perspective on it was just a way to get free calls from pay phones; is there more to it than that? How important/expensive were these phone calls that it became such a widely known technique? Is it just admiration for an early, and neat, hardware hack?


It's sort of hard to grasp how much more difficult long-distance communication was back then. Phone calls were relatively expensive and charged by the minute; you generally wouldn't call someone across the country without good reason or special occasion, and you'd feel real pressure to try to "keep it short".

Phone phreaking let you talk to whoever you wanted, as long as you wanted, as often as you wanted. This was a big deal in the days before instant messaging and was looked on almost as a type of magic.


The original MCI and Sprint started as long distance "disruptors" and I think it was the beginning of the end for phreaking. When you could suddenly call anywhere in the USA for $0.10/min (though that sounds expensive now) it was a game-changer.


I remember running a BBS and being surprised at the 20 or so users I had from Germany. When I caught one of them online I asked how they could afford the bill and was told he had hacked a PBX and was connected, somehow, through that. I hadn't heard of that trick back then (and don't know the specifics of it now).

Long Distance was a horrible thing. In 1997, I was working for a CLEC/long distance provider that existed as a result of the 1996 "deregulation[0]". Times were great for about two years.

The price for long distance was never perfect against cost, but when everything went flat rate/minute and that rate continued to drop (ultimately becoming flat rate, period), I remember sitting in an employee meeting hosted by the CEO of Frontier (pre-Global Crossing/Frontier and later Citizens/Frontier). He had a graph on the screen showing the cost of a minute of long distance and the price we could charge for it. The lines were converging and I asked the fateful question "what happens when they cross"? To which I received a political deflection[1]. The best part was all of the industry rags were, at the time, screaming that there will always be a long distance surcharge since there will always be call termination per-minute rates. I could see it was only a matter of time before those fellas were proven wrong. Younger folks, today, don't have any concept of domestic long-distance rates, but AFAIK (and I've been out of telecom for a little while now) call termination still has a per-minute cost.

[0] In quotes because it wasn't so much a deregulation as it was changed regulation. The goal was to get local carriers to start competing with one another and long distance carriers. I believe the local carrier had to have a CLEC in their service area in order to provide their own long distance service. The hope was more competition with similar kinds of services. The result was a bunch of CLECs that figured out the law opened up some interesting opportunities. I remember a friend of mine setting up an ISP for the cost of equipment. He'd received his local phone numbers from a CLEC that would hand out locals that would cover a huge geographical area at practically no cost. What I didn't understand, then, was because call termination is the "cost" incurred by the LEC, inbound calls were pure profit. ISP lines were all inbound so the CLEC made buckets of money in pennies/minute from Ameritech/AT&T for the hours that his customers spent online.

[1] The days after the 1996 telco bill were interesting. Competition opened up and a whole new set of operators started up doing things like offering lines to ISPs (most people were dial-up back then) practically for free since all of the calls would be inbound and result in a huge paycheck from Ameritech/AT&T or whomever was the major established local carrier.


Apologies - that second bullet point was supposed to be:

[1] The deflection was because his solution was to sell the company to Global Crossing -- at the time, a dot-com darling publicly traded on NASDAQ that lost heaping amounts of money. There really was no choice. Frontier was doomed because of the costs of its new SONET network and Global Crossing was offering way too much money so that passing up the deal would guarantee a shareholder lawsuit.


The public switched telephone network is a huge, complicated, and arcane network that spans the entire globe. Its language is incantations of tones and pulses responded to with more tones and clicks.

It feels magical! Someone who knows the right arcane magic words can end up on the other side of the planet. Meanwhile, your opponents are often seen as bumbling and unprepared. I can't think of any other system that so closely pairs intelligent exploration with the feelings of discovery.

...or, at least, that's my thought on the matter.


This is a bit how the Internet and the early web felt to me as a teenager in the mid 90s. When most people in my high school could barely turn a computer on, I felt like a wizard who knew about an entire secret world, and it was awesome.

I could dial into my local mom and pop ISP and be playing a MUD with people from three different continents at the same time. I think in those days I had more online friends from MUDs, IRCs and talkers than I did in "RL."

Or just surfing to random servers and seeing what was out there. In a time before Google indexed damn near everything, a lot of the Internet was just exploration and finding random, crazy or awesome things. One night I found a page from a professor at Purdue about lighting grills on fire with liquid oxygen.

Thankfully, my parents were good sports about all this and eventually got a second phone line installed. Probably because they got tired of me always tying up our main line with an Internet connection.


yes part of the magic was that there were so many different types of systems to get into. It was much, much more than just the 10 digit phone numbers. There was the parallel Blue Box system. There were mysterious things called "0488s," entry points to satellite systems, strange networks, loops, lots and lots of company voicemail systems, various ways to "extend" or evade traces, access points to service console to give yourself phone numbers, etc. In fact, almost all of the stuff, like conferences was in normal use by corporations during the day and crawled over by teenagers at night :) Even just payphones had numerous ways to be hacked.


Much like hackers, the definition of what a phone phreak is will change depending on who you ask. During the seventies, it centered around people who appreciated the network and loved to see it do unorthodox things - see some of the old Evan Doorbell recordings for good examples; http://www.evan-doorbell.com/production/ . Toll fraud was generally frowned upon by that sect of people.

By the eighties, the term more or less flipped and it became known mostly as just something people did to get free phone calls. This sorta continued on through the nineties.

The term is gradually flipping back again, thankfully. A phone phreak who just makes free calls is sort of an analog to a hacker that just compromises random Facebook accounts.


> see some of the old Evan Doorbell recordings for good examples; http://www.evan-doorbell.com/production/

I have no idea what I'm listening to but I'm strangely compelled. I'm going to chuck a few of these on my (uhh) phone to listen to later.


A good place to start is the "How Evan Became a Phone Phreak" recordings. Though it's about someone dealing with electromechanical switching equipment in the seventies, it's surprisingly parallel to how a lot of people get into phones today.

Dialing Those Mysterious "1xx" and "0xx" Codes is another good one, as is the 052 conference.


Thanks! I'll start there.


"The term is gradually flipping back again, thankfully."

I suppose that makes sense, as there is (largely) no such thing as non-free calls ...


>So, why was this such a big deal?

Well, it was our internet back then. Ignoring voice calls, its how we dialed BBS's. Back then unless the BBS was very nearby there was a per minute charge. So there was motivation to find ways around this for people who wanted to do things like chat, play games, use email, etc for non-trivial amount of time. Getting around long distance rates was quite the motivator. For reference, minimum wage in 1980's was $3.35. Dialing outside your local band could be as high as 5 to 10 cents a minute before you even hit long-distance rates. This stuff added up quick!

I was a kid back then but I had a computer with a modem and really got to know how phone billing worked after my parents got a couple high phone bills. There weren't many BBS's within band A for me, so it was pretty annoying I couldn't leave the modem on for a couple hours to download something (this was back then 1200 baud was common but still expensive - $350 [fixed for inflation]).

Also, there wasn't much else to hack that didn't belong to you. There was a 'hack it because its there' aspect here.


Where I lived, local calls were toll calls after a certain point. I recall downloading a game over an 18 hour period when my parents were away (Gunship 2000), and we got a bill for a significant amount of money... Probably more than the game in the store. ;)


My perspective on it was just a way to get free calls from pay phones; is there more to it than that?

This was before broadband, and access to external systems was done through a device that connected to...a phone. Your local calling area would be maybe a 30 mile radius or so (it varied a lot depending on local carrier). Wanna see what's on that mainframe at the university 100 miles away? Well, be quick because it's going to be pricey. Or...

How pricey? Someone else already looked it up, but I recall MCI advertising long distance calls for $0.10/minute. That's $6/hour. Minimum wage was something like $3/hour. So if you're a kid working at McDonald's, you needed to work two hours for every hour of access. Or...


Also time. I think cross country calls in the mid 80s were more like $0.50/min, and the first 1-3 minutes were billed at a higher rate.


Yup, that's why MCI was a big deal. I can't find a reference, but I recall long distance call rates varying by distance under the Bell System. MCI said "ten cents per minute no matter where you're calling to" (can't find a reference for that, either).

But I think the selling point for alternative LD carriers (MCI, Sprint, and the "10-10-..." numbers) was that you could set a timer and know at the end of the call how much it cost. Under AT&T? Get the calculator and paper out.


I worked for MCI in the '80s. People changed over for the savings - it was always cheaper than AT&T. In fact, a lot of AT&T's marketing played to the "loyalty" fear: if you leave us, you're suspect for being un-American. Not in so many words, of course, but that was the tuning fork it resonated with. (Worked great on older folks who lived through McCarthyism.)

Also, don't forget the difference between inter-LATA and intra-LATA calls. The latter was a call within your local provider's area, the former went to another. Sometimes the line between exchanges was literally across the road. Inter-LATA calls were generally more expensive than getting through on a long-distance trunk, so there was this ridiculous feature of phone bills in those days that calling grandma in the next town over was more expensive than calling your college girlfriend three states away.

I also used to work for a "connected car" manufacturer. The per-minute rates they get today for using the onboard phone are outrageous even by '80s standards. I won't mention the data rates they charge for using the "connected car." Let's just say it would be far cheaper to buy an iPhone and Verizon's 20GB plan if you're going to use it a lot.


Just for context, that's about $1.50/min in 2016 dollars


It had nothing to do with expensive phone calls. (Although it is true a lot of hacking has been done purely because someone didn't have the money for a given service)

Phreaking was (and is) just a way for an overly curious person to see what they can do with a big mysterious black box. Much like the first hackers trying to work around the first passwords on the first time-sharing computers, phreakers see what they can work around in the telephone network.

Bypassing voicemail PINs, changing Caller ID, hijacking PBXes, setting up conf lines for free, listening in on others' phone calls, obscuring your real phone number from the phone companies through op-diverting, spoofing IMEI, decrypting GSM to watch texts and calls in real time, free internet through holes in the paywall of data card providers...

And if you're a high school kid who needs to call his mom but the stupid COCOT at school won't let you dial local exchanges, you dial a 1-800 number, reset the trunk, and then dial any number you want. Never know when hacking will come in handy.


When I was in high school, the computer I got to play with was a CDC mainframe at Northwestern. It was housed in a purpose-built building on the university campus, and accessed through a teletype machine in my high school. Phone phreaking was at least as much fun as the hacking potential of the mainframe.

It served me well since my career in computing took me to some strange places like small digital PBXs that integrated interactive voice response with the switching function and hence call-state, and mobile data nodes that required knowledge of carrier charging and rating.

Until land lines die off and VoLTE is widely deployed, there will be circuit-switched calls that work very like they did in the 1970s.

Telephony is even relevant to the modern debate on surveillance. Pervasive surveillance dates back, at least, to the Daytona database and sucking in all available punched-card and mag-tape sources of call detail records. It was the first application of social network analytics on a big-data scale.


Long distance was pretty expensive. I don't remember specific rates from back then, though Metafilter has some specifics-- $0.434/min for daytime rates in 1980 (Source: http://ask.metafilter.com/211826/Long-Distance-Rates-For-the...). I do know that we basically couldn't call our cousins or grandparents a state away except on weekends, because we were assured by our parents that it would bankrupt the family to do otherwise.


As you imply, it wasn't just the cost themselves; the pricing plans were often quite complicated as well. Day or night rate? Weekend or weekday? Which network are you calling? Are they in your friends and family plan?

You never knew what your bill was going to be until it came in the mail each month. And as a kid, there was definite anxiety about how bad it would be and whether your parents would notice your calls...


Also the monthly fee, often from a separate carrier, just for being able to use long distance dialing. Back then you'd pay for local service, long distance service, long distance rates, and potentially ISP access; all this compounded by nebulous scale rates depending on when you used long distance.

It was also further complicated by the lack of local numbers for dial-in internet access, or local exchanges for BBS's. I remember having a schedule for when I could connect for cost efficacy. It's also one of the reasons I got into local war dialing. It wasn't only out of curiosity, but a potential way to gain access to a network for cheaper.

Imagine paying 40 cents per minute to dial-in to a location you could drive to in 20 minutes. God I'm old.


I was born in the late 70s, so I missed most of this. But I recall my extended family coming to my parents house to call cousins in Ireland at 10pm because my parents got an extra discount because they paid for touch tone dialing.


Telecom and mainframes were/are an insular world. But unlike mainframes, telecom reached into every home.

Also, it had global reach, operated on trust, and quite often security by obscurity was the only thing that stood between you and a free call to the pope.

Keep in mind that this all took place just as the first microcomputers that were practical to use (keyboard in, tv out, booting to cli from rom) became available.

All in all it was a age of innocence and exploration.


I knew people in college in the early '80s who ended up having to drop out of school because of long distance bills - usually conversations with a boyfriend or girlfriend they'd left behind.

My Dad is an old school phone guy ( member of the Telephone Pioneers of America ) and he still doesn't stay on a long distance call past a minute or two.


Lucky225 and Evan Doorbell (two contributors mentioned at the bottom) are pretty legendary phreaks. Probably they all are awesome people, I just know of those two. Evan Doorbell has an amazing collection of audio, if you're interested in this kind of thing.


Discussion is ongoing @ irc.2600.net #telephreak

Awesome write-up! thanks!!




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: