View Single Post
Old 02-22-2005, 04:53 AM   #29
Vin
Nameless Being
 
Paris Hilton and Vin Diesel’s Voicemail Hacked

As many of you know, yesterday Paris Hilton’s T-Mobile address book was stolen and posted online. But what you don’t know is, shortly thereafter a hacker gained access to both Paris’ and Vin’s private saved voicemail messages.

The hack is a simple one that I duplicated easily. If you have Sprint or T-Mobile and have auto voicemail login enabled, you are vulnerable to this type of attack. I have auto voicemail login enabled because I hate entering my voicemail PIN number each time I want to check my messages.

The voicemail authentication system is simple. It uses caller ID to validate the originating number – if the caller ID matches your cell phone number (ie. your cell phone calling in to check your voicemail messages), it will log you in automatically.

This system has worked great for the last few years. Well, that is until the advent of commercial caller ID spoofing systems such as CovertCall and Telespoof. For those not in-the-know, caller ID spoofing allows you to change your caller ID number to anything you like. To hack myself, I simply logged into CovertCall and placed a spoofed call to my cell phone. The spoofed call was to my cell phone, from my cell phone, forwarded to a pay phone. Sprint (my provider) thought I was calling from my cell, and automatically logged me in (even though I was performing this from a pay phone down the street).
  Reply With Quote