Programmer Develops Phone Bot To Target Windows Support Scammers (onthewire.io)
Trailrunner7 quotes a report from On the Wire: The man who developed a bot that frustrates and annoys robocallers is planning to take on the infamous Windows support scam callers head-on. Roger Anderson last year debuted his Jolly Roger bot, a system that intercepts robocalls and puts the caller into a never-ending loop of pre-recorded phrases designed to waste their time. Anderson built the system as a way to protect his own landlines from annoying telemarketers and it worked so well that he later expanded it into a service for both consumers and businesses. Users can send telemarketing calls to the Jolly Roger bot and listen in while it chats inanely with the caller. Now, Anderson is targeting the huge business that is the Windows fake support scam. This one takes a variety of forms, often with a pre-recorded message informing the victim that technicians have detected that his computer has a virus and that he will be connected to a Windows support specialist to help fix it. The callers have no affiliation with Microsoft and no way of detecting any malware on a target's machine. It's just a scare tactic to intimidate victims into paying a fee to remove the nonexistent malware, and sometimes the scammers get victims to install other unwanted apps on their PCs, as well. Anderson plans to turn the tables on these scammers and unleash his bots on their call centers. "I'm getting ready for a major initiative to shut down Windows Support. It's like wack-a-mole, but I'm getting close to going nuclear on them. As fast as you can report fake 'you have a virus call this number now' messages to me, I will be able to hit them with thousands of calls from bots," Andrew said in a post Tuesday.
How is this even legal? It is a crime to waste the money of corporations. Maybe some of these tech support companies will put him in prison or send someone to physically harm him.
Some of the youtube calls are funny. I have salty sally on quick transfer. Its only six bucks a year.
Don't answer calls from unknown numbers. Problem solved.
Hi, this is Lenny!! Come again?
I've received calls from some of these scammers before. I've even tried to call them back to record them, but the caller ID records for the numbers they call from are most likely spoofed because without a single ring I either get disconnected or get the standard "doo doO dOO, we're sorry" message. Granted, they could have a system set up to block calls or play this message for calls from numbers on their lists, but it seems like you would need to wait for them to call you.
Go read how it works. You transfer crap calls to one of the robots and it talks to them for you. It now works with sip, so I added an extension on my pbx to transfer it to them. It emails you the recording but I also record it on my pbx.
Vigilante justice has never been funnier.
When your scam relies upon a script, it is easy to script a response that falls within the norms of what you're expecting out of your victims.
Queue the robot that checks the "I am not a robot" check box ... because it can.
Agent K: A *person* is smart. People are dumb, stupid, panicky animals, and you know it.
The summery says " 'you have a virus call this number now' messages" so it sounds like they are giving out a real number they expect the victims to call.
1984 was not supposed to be an instruction manual.
Most call center scammers are blissfully unaware they're commiting a scam. They really think they're trying to help people solve their computer "problems" by having them sign-up for support plans. They're just script monkies. Some of the reps may know that their "services" are bogus and commit the scam anyways as long as they get a paycheck, they don't care. The ones that really know what's going on are the C-level types within the call center company. Check out Lewis's Tech channel some time. Really funny and sad stuff there.
Atleast until the call centers turn all their extensions to 900 numbers
I was doing this 10 years ago with Asterisk phone server. get a phone call at the house, press *1 and it transfers them to telemarketer hell where it plays random human responses that are a lot better than his as I was looking for pauses in audio to respond, his is just random audio that is not responding to the audio coming in.
There was a asterisk guru that published all the goodies on how to do this over a decade ago and I used his code and modified it a bit. worked great and the longest I tired up a telemarketer was 2 hours.
about 4 years ago someone had a better one called "this is lenny" that emulated an old senile man and was recording the calls for everyones entertainment.
Do not look at laser with remaining good eye.
When this first started happening we waited for one and had a VM setup just waiting and wasted a couple of hours of ones time! Watch it here.....hilarious! https://www.youtube.com/watch?v=7T3e34DzGvo
But - now what do I do for entertainment?
It's wintery here.
General Relativity: Space-time tells matter where to go; Matter tells space-time what shape to be.
How could a hosts file possibly block phone calls?
This will discover if the telemarketers are really intelligent and self-aware.
See my subject: Says it all - but vs. advertisers & malwaremakers/botnet herders etc. it does wonders blocking 'em out!
APK
P.S.=> Anyhow, onwards & upwards... apk
... 1-800-whitehouse.
Thanks, Roger.
You're a peach.
It little behooves the best of us to comment on the rest of us.
Who cares if it's a 900 number? The scammer calls you, and that is all that is needed to utilize these response scripts.
This guy should be forced to wear a cape because he's a god damn hero.
Do those scammer make you download a "custom" teamviewer with virus or is it a genuine one ?
Could one develop a fake teamviewer "client" that will ultimately syskey the scammer pc ?
Maybe by pushing a command in the buffer and convincing the scammer to run it (with some social engineering) or by displaying a fake window
"
The teamviewer client didn't respond in time.
This is probably because of a too lengthy road.
We recommend you raise the maxhops [currently:100] for host [124.113.115.124].
The following command should fix this 'teamviewer.exe -clientreset -124.113.115.124 -maxhops:500'
This command has been pushed into the buffer of teamviewer server
It can be run in a cmd.exe
"
make sure it's a long text so that scammer will prefer to paste the command
but in the buffer you'd really push some nasty code after a donothing command
teamviewer.exe -clientreset -124.113.115.124 -maxhops:500............lot of space to hide this =>...............--comment:"teamviewer fix by"; __here_your_nasty_code__
So they won't stop peddling their crap because they won't get paid and, I suspect, it is now merely to grief slashdot for not letting him peddle his shit freely on here.
his hosts program is actually pretty good by xenotransplant
his hosts tool is actually useful for those cases in which one does indeed want to locally block stuff outright while consuming minimum system resources by alexgieg
I've never tried to belittle (APK's) work, I've flat out said it's good by BronsCon
take a look at the APK hosts file engine by SuperKendall
APK is kinda right. I've tried his hosts file generating software. It works by bmo
APK is totally right on this count. Adblock Plus on Firefox mobile is a dog on older, or lower end, phones. A hostfile based adblocker makes for a much better experience by chihowa
I like your host file system by Karmashock
I find your hosts file admirable by vel-ex-tech
* See subject: My code's liked & used + recommended & hosted by Malwarebytes' hpHosts!
(You WISH you could say the same but all you are is offtopic trolling unidentifiable scum... lol!)
APK
P.S.=> More coming... apk
I support APK's stand on the hosts file by Trax3001BBS
Your premise that hostfiles are a good way to deal with advertising and malvertising is quite valid by JazzLad
No complaints from me, I like APK... Reminds me to use a host file. Also, his stuff is free by aaaaaaargh!
APK's monolithic hosts file is looking pretty good by Culture20
APK... Awesome to see he's still spreading the good word by Molochi
ABP is insufficient as a solid hosts file does everything that APK reminds us about by fast turtle
APK isn't wrong by cfalcon
APK, I know people give you a lot of shit regarding hosts, but please don't ever stop by nasredin
You need APK's hosts file by Teun
APK solution STILL relevant by Thud457
you're right about hosts files by drinkypoo
APK
P.S.=> They're in addition to https://it.slashdot.org/comments.pl?sid=10221475&cid=53831617/ + 1,000's worldwide - there's no arguing w/ my success & YOUR failure... apk
See my subject (brand new 7 digit sockpuppet account troll) & proof vs. your libelous lies https://www.virustotal.com/en/file/e01211ca36aa02e923f20adee0a3c4f5d5187dc65bdf1c997b3da3c2b0745425/analysis/1433430542/ that prove my ware's safe/clean in addition to & the fact that the highly esteemed Malwarebytes' own employee verifed the code as safe too "I've seen the code & it's safe" http://forum.hosts-file.net/viewtopic.php?f=5&t=4290/ PLUS h t t p : / / f . v i r s c a n . o r g / A P K H o s t s F i l e E n g i n e I n s t a l l e r 3 2 _ 6 4 b i t . e x e . h t m l (take out spaces here)
* You WISH you could do the same vs. being an off-topic trolling sockpuppeteering "ne'er-do-well" that you clearly are!
APK
P.S.=> You're pitifully jealous others speak well of my work and they never will YOUR non-existent programs... apk
Yes, that's how it works. They get you to call them back, because it gives the victim more confidence. People have got the message that if random people call you claiming to be your bank, it's probably a scam, so you need to call them on their official number... And somehow telling people to call back with a number left in a voice mail fulfils this requirement.
It also means you have plenty of time to prepare a Windows 98 VM and set up a Skype account to call them with. Someone needs to make a VM with randomly generated user data and a virtual user who wastes the scammer's time, while auto-reporting their TeamViewer account for TOS violations etc.
const int one = 65536; (Silvermoon, Texture.cs)
SJW, n: "Someone I don't like, and by the way I'm a fuckwit" - AC
Who's have thought the 'lightness of touch' of your law makers and regulators would mean a whole industry would spring up!?
I'm not sure such a service exists in the UK because you know what - it's illegal for people to call you if you've made a preference for them to leave you alone. And believe it or not, call centres really do take it seriously. You do get the odd call from abroad, but even they're getting the squeeze put on them.
That said, it's great to see a 'solution' that uses SIP. Shame it still hangs up your landline for the duration :-(
Never heard of it before. Youtubed it. Absolutely hilarious!
I hadn't the slightest objection to his spending his time planning massacres for the bourgeoisie... (P.G. Wodehouse)
See my subject & proof Zontar makes sockpuppets to harass me & yes that he's mentally disturbed, literally https://ask.slashdot.org/comments.pl?sid=9954349&cid=53427117/ & Zontar's a KNOWN nutjob druggie admittedly in a few links there - so much so, the freak sent me a postcard threatening me, lol!
* Take your meds & GROW UP, loon!
APK
P.S.=> There's a reason you'll always be mentally damaged goods & trolling trash only online Zontar - you waste time & wasted your life (& mind, on drugs + being a pest freak)... apk
Are any of the popular tech support scam baiters on YouTube based out of Australia or New Zealand?
It also means you have plenty of time to prepare a Windows 98 VM and set up a Skype account to call them with.
The scammers have become wise to this. They refuse to deal with Windows 98 and Windows XP on grounds that Microsoft has announced their end of support.
Someone needs to make a VM with randomly generated user data and a virtual user who wastes the scammer's time
Someone needs to go on YouTube and watch Lewis's Tech, Thunder Tech, Each&Everything, etc. do exactly this.
You could waste their time, upload the waste of time to YouTube, and possibly even make a little money on ads. It works for the Scammer Sub Lounge partners.
Stopping advertisers/malwaremakers infecting/tracking/slowing us via NEW APK Hosts File Engine 9.0++ SR-7 32/64-bit https://www.google.com/search?hl=en&source=hp&biw=&bih=&q=%22APK+Hosts+File+Engine%22+and+%22start64%22&btnG=Google+Search&gbv=1/
Ads & malware rob speed/security/privacy
Hosts add speed (via hardcodes/adblocks), security (vs. bad sites/malware/poisoned dns), reliability (vs. dns down), & anonymity (vs. dns requestlogs/trackers).
Less power/cpu/ram + IO use vs. DNS/routers/addons/antivirus + less security bugs/complexity & faster vs. addons/routers/remote dns!
Avoids DNSChangers in routers/IP settings & dns redirects (99.999% of ISP DNS != patched vs. it) + lightens DNS load & resolves faster from local system RAM!
* Via what you NATIVELY have built into the TCP/IP stack in FASTER kernelmode!
APK
P.S. - Safe https://www.virustotal.com/en/file/e01211ca36aa02e923f20adee0a3c4f5d5187dc65bdf1c997b3da3c2b0745425/analysis/1433430542/
I think it's more to do with cost. Just like with real support, the more OS versions you target the more you have to spend on training. For the small number of W98 boxes still out there it's probably not worth developing a phone script and attack workflow.
> The scammers have become wise to this. They refuse to deal with Windows 98 and Windows XP on grounds that Microsoft has announced their end of support.
So much effort anyway....its easier to not setup a VM and...get this.... Lie to them.
Its fun. Treat it like a video game. Its role playing practice. Your just rolled a new character "stupid user". Just pretend to be the dumbest user you ever tried to help, and imagine what issues they might encounter. Feel free to be "too smart for your own good".
My favorite was when one guy asked me to open a link "in chrome", I agree. 3 mins later he is asking "whats going on now?" "oh I am installing chrome" "oh so you have a web....ok" He waited another 5 minutes before checking in again.
Hint: I wasn't installing chrome
"I opened my eyes, and everything went dark again"
its easier to not setup a VM
One of the first things a scammer does is get you to install a remote assistance application to give administrative access to Windows. No VM means the scammer can use syskey.exe to apply a boot password you don't know or otherwise completely wreck it.
My favorite was when one guy asked me to open a link "in chrome", I agree. 3 mins later he is asking "whats going on now?"
So your strategy appears to involve stalling the scammer to keep him from even getting to the LogMeIn or GoToMyPC or TeamViewer step. Are there videos of that strategy?
I also WIPED ARSTECHNICA OFF THE MAP in 2003-2006 @ Windows IT Pro easily - Jeremy Reimer got his website removed by Shaw of Canada his ISP & hosting provider + he was put on a tracking ticket by them for email harassment... his "henchman" Jay Little said "I am an EXPERT on Exchange" which much to his dismay worked against him @ "The Memory Optimization Hoax" where I proved to them AND Dr. Mark Russinovich (former "co-worker" of mine @ Sunbelt where we retailed our wares there & he bitched I outsold his work, awww) that that technology unhalted & sped up frozen Exchange Servers USING MICROSOFT'S OWN DOCUMENTATION TO DO IT (clearmem.exe is the same tech, but not GUI, & I designed the 1st program of that nature in GUI no less).
Jay Little then trolled & stalked me to other websites where I annihilated him on ramdrives as well - he was banned + had his website @ CrystalTech removed by that hosting provider for libeling me.
FOOLS... you're the same kind of scum, but you're just as easy to dispatch with truth & facts.
APK
P.S.=> Bad move bringing up the DOLTS of Arstechnica - all they can do is "gossip" like old biddies behind my back, BUT OUTSIDE THEIR "PRIVATE PLAYPEN"? The results are QUITE different, see above, lol... apk
See subject: It was just "too, Too, TOO EASY - just '2ez'" & I realized they're chumps. Your fake name 4 yer fake life doesn't appeal to me - I know you're mentally disturbed by your OWN admissions here, so that all said & aside? I don't waste time on LOONS like you, ok??
* Grow up, get a REAL life, instead of your 'phantasyland' FAKE NAME one online trolling/harassing/stalking others (as you do me nigh constantly, you sicko)... lol!
APK
P.S.=> There's NO question I took a former "co-worker" of mine down in Dr. Mark Russinovich - I used Microsoft's OWN documentation to do it (took Jay Little of arstechnica down too, the "exchange expert" by his own blowhard bs he couldn't backup when I proved mem defrags do the job - 1 problem w/ linked lists IS that (too many pointers ALL OVER MEMORY, causes 'thrash' 1st & then halting))... apk
Right, I don't actually DO any of the things I was claiming, I just lie to him. Its so much easier than actually going through with it. I put him on speakerphone and go about my business while I fuck with him.
No videos, but one dude totally caught on and started singing to me before he hung up.
"I opened my eyes, and everything went dark again"