Hack AT&T Voicemail With Android
An anonymous reader writes "It is shockingly easy to gain access to an AT&T customer's voicemail using caller ID spoofing techniques. What's worse is that AT&T knows about it. On your Android phone, download one of the two caller ID spoofing programs. Input the number of your target as the destination number and then enter the same number as the spoofed caller ID. Then connect your call. If the target has not added a voicemail password (the default is no password), you will be dropped into a random menu of their voicemail and eventually can drill up or down to get what you want. You can change greetings, erase messages, send voicemails out of the target account, and much more. How many politicians up in arms about Google Wi-Fi sniffing will want to know more about this?"
without a password voicemail should only accept connections from the owners phone.
Snowden and Manning are heroes.
If you don't have a password on your voicemail, you deserve to have it hacked into. Plain and simple.
"How many politicians up in arms about Google Wi-Fi sniffing will want to know more about this?"
Answer: none, since Microsoft isn't paying them to target AT&T.
Really? You think the caller ID spoofing is the problem here?
I am the one who posted this - it is my first Slashdot submission. Please don't flame too hard. I am posting anon because I am a convicted hacker on probation. I just wanted to add that we noticed a side effect of doing this: If the target is using an Iphone, their Visual Voicemail will prompt for a password the moment the attacker logs out of their voicemail box. The target must then reset their VM password.
It's the damn phone company. If it's a landline, you mean to tell me they can't see what circuit it's coming from all the way back to your house?
If it's a cell, likewise - there are cell specific identifiers. namely the SIM details...
For large sets, this will be our guide even unto death, for the LORD will work for each type of data it is applied to...
He's got a point. Why can't voice mail run over some data connection authenticated by the phone's unique ID or something similar? They certainly do billing that way. It is 2010, and voice mail still works by having the phone call out to a magic number- how antiquated!
Tsunami -- You can't bring a good wave down!
+1, this is NOT an included feature of Android. You have to download an application in order to accomplish this. And, if i'm not mistaken, blackberry and iphones both have access to such apps.
"How many politicians up in arms about Google Wi-Fi sniffing will want to know more about this?" - Seriously? what kind of statement is that? This has NOTHING to do with Google directly. As SilverHatHacker said, if you don't put a password on it, you're just as much to blame. Call spoofing has been around since before Android even existed. Some call spoof sites / applications prohibit you from entering the same number as both your number and the number you are calling (i'd assume to avoid their services being involved with things like this).
Bottom line, don't like it? Put a password on your voicemail. Upset that this is your option? Then complain to the developers / people behind services that allow call spoofing. Don't put the blame on an open source platform, let alone of one of many corporation behind that platform.
No it didn't. The fault here is entirely with AT&T, it is not because of missing passwords/pin numbers (which should not matter), nor is it a lack of regulation concerning caller ID.
So riddle me this, what would happen if i went to make a call from my cell phone to another number, but spoofed the caller ID, whose minutes am I then using? Who gets charged?
Doubt it would be the owner of the spoofed number paying. If it DOES work that way, it simply proves AT&T is incompetent. If it doesn't work that way, then their billing department isn't as dumb as their customer security department.
One is a revenue center, the other is a cost center. I think we can guess which one is further on the ball?
It's kind of sad how many situations this cut-and-paste troll is appropriate.
You know, there is a difference between trolling and pointing out the flaws in your reasoning. Just saying.
Yes, but if the story were to mention that, it wouldn't work as FUD.
You are welcome on my lawn.
So then, just require a password when calling from any phone besides the cellular phone to which the voice mail account is associated.
This is hardly an insurmountable technical issue. There's no reason you couldn't just have calls from the cell phone access the voice mail directly, but if you want to use a different phone to get you voice mail, you need to enter a 4 digit PIN or something (at least).
You can't get an email account without a password, so why should people expect voicemail to be any different, "for convenience"?
You are welcome on my lawn.
It is absolutely positively NOT how voicemail is supposed to work but Android isn't the blame.
AT&T knows very well that caller-id is worthless for authentication AND it has access to the much more authoritative ANI (which cannot be spoofed so easily).
I wouldn't blame the customers either. If you mistakenly believe that AT&T has a single grain of common sense, you might imagine they DO use ANI (I'll bet the manual reads "from your phone only" rather than "from any phone that sends your number in it's faked caller ID") even if you don't know what it's called. After all, they're the phone company, surely they know which phone you're calling from, they DO know who to bill the minutes to after all.
AT&T _still_ doesn't require a voicemail password? I thought pretty much every carrier did because of exactly this kind of trick. It surely didn't start with Android - I remember reading about it years ago, and it was old news even then.
But hell, anyone stupid enough to still use AT&T, when it seems that every week they're losing thousands of customer records, deserves anything that happens.
I dont see why Google should do anything about the applications. Nothing has violated Google's TOS here. They are violating AT&T's TOS so let AT&T be the bad guys and ban the violators from their networks.
Calling someone a "hater" only means you can not rationally rebut their argument.
How many politicians up in arms about Google Wi-Fi sniffing will want to know more about this?
Answer: none. Nobody knows Washington better than AT&T.
The higher the technology, the sharper that two-edged sword.