It's actually not completely dead... It's just (almost) completely non-public.
You can subscribe to services to get number porting information where the interface is basically e164.arpa/ENUM queries to a private nameserver over a VPN. I don't know the details, the cost was high enough that it didn't make sense for my employer to pursue it.
As someone who's been in the VoIP industry for over 20 years it makes me sad to think of what could have been if both ENUM and IPv6 were more widely adopted. For many years you could reach me via email, SIP, or Jabber with the same identifier and if there were effective support for ENUM in the USA my work phone number would have been able to connect you to any of them, directly and with G.722 HD voice long before it eventually came to modern cellular networks.
I love the line near the end of the article: "So in the end, I was down 10€ in domain fees, there was sadly no bug bounty (I thankfully didn't get my door kicked in at least)."
Makes me cringe, imagining what that would be like.
“fun fact: this entire website is written without any javascript […]”
and “19 years old”,you know there’s hope for our future.
There is another schema called TRIP [1] - telephony routing over ip that uses a number format "1234*1455" designed to be entered on a standard phone keypad. When I registered my ITAD (internet telephony administrative domain, the RHS of a TRIP number) I was lucky enough to get one that matches my local dialling code!
It's a shame the author wasn't rewarded but at least the story can now be told over a beer.
loads of webrings also started -- 90s internet is back, just look for it <3
Who knows! Maybe it’s working just fine, but the e164.arpa record is pointing to the public prosecutor’s teapot or something.
I don't want the miss the young girls skills but she is no security researcher but in the eyes for her target simple a hacker. And I would say too that she got lucky. It would not be the first time that inexperienced young persona have to suffer the consequences even of their well intended actions.
I find this such a bad idea, if I want to use the cheap internet for a call I would use an internet based voice call system directly, rather than messing around with telephone numbers and I guess potentially accidentally doing an expensive phone call (same with RCS/SMS vs. just using an internet-based chat directly).
Having said that, SIP is barely better.
I’d forgotten the keywords of power to find it again. I liked the idea.
I’m assuming this is is it again.
If you control both endpoints and they support it you can configure them to use encryption, but even then implementation qualities vary widely (just because you enable SIP over TLS doesn’t mean they’ll actually verify the certificates for example - giving you at best opportunistic encryption), and I bet a lot of the implementations also have bugs/vulnerabilities.
If security is needed, it is often implemented by way of running the whole thing over private links (which can be secured with IPSec or any other VPN technology). In fact that’s presumably what’s happening, but misconfigured equipment making those ENUM lookups would allow the attacker to steer the traffic away from the secure link and towards an endpoint they control over the public internet.
I would not at all be surprised seeing that domain being abandoned again at a renewal in the near future.
Makes me wonder how many partly implemented but ignored protocols like this exist.
Is this related to Softphone / VOIP in any way?
The normal path for voip phones given a phone number is to end up at a sip trunk provider go over the traditional phone network (which at this point probably routes over the internet anyway) hit another sip trunk and end up at the receiving sip phone.
This provides a method to bypass the traditional phone network and go directly over the internet. The sip phone looks up the host responsible for that phone number and directly connects. The sip providers would be responsible for maintaining this number to host mapping in dns.
When you think about it DNS is really just a big distributed phone book, a key value store to look up numbers based on names. The reverse records are a method to look up names based on numbers using that same distributed architecture.
There is also an interesting legacy architecture interaction here, traditional phones can only enter numbers. Cell phones could use dns names directly(but don't) or we could use ip addresses as a sort of modern phone number(but don't), The whole world was connected via phone numbers and that is now how we expect phones to operate.
Makes you wonder how much ancient telecom stuff is still running somewhere just because nobody touched it in 15 years.
This doesn't even feel like a hack. More like someone opened an old door and realized nobody had checked if it was locked in forever.
> So I had accidentally logged hundreds of thousands of phone numbers and timestamps for calls going to military bases.
That's quite a jump to conclusion right there.
I'm 99% sure anyone living there is millitary. There were some people fleeing from the sri lankan civil war that landed there and were stuck there for a bunch of years claiming asylum while the millitary tried to figure out what to do with them, but they were sent off the island a while back.
There are none. The native Chagossians were all expelled in the 1960s-70s.