Professional Documents
Culture Documents
E' rFRPRISFS. 11\('.. an eleemosynary organilatlon. Subscnptlon rates: $11}- I year. 55-- 6 months. 51 per back ISSue.
o\er.ca.. Stl 50 ! \ear Write tn _WKJ. 8m. 752. Middle Island. -";Y 11953-0752. M('I Mail: 26HUNDRED: -, I X; 6501994928.
VOLUME ONE, NUMBER NINE
HISTORY OFBRITISHPHREAKING
by Lex Luthor and The Lepon of Doom Recorder Conner'.<':>: '''~OH7., beeps every 15 seconds.
In Britain, phreaki!lg goes back to the early fifties, when the technique of ~Toll Multiparty Line Ring: Sdme frequency and modulation as ring, but I sec on, 2 sec
A drop hack"wasdiscovered. Toll A was an exchange near St. Pauls which routed off (twice as fast).
calls between London and the nearby non-London exchanges. The trick was to Titan the Scanner
dial an unallocated number, and then depress the receiver-rest for Y2 second. This In the early days of British phreaking, the Cambridge University Titan
flashing initiated the "clear forward" signal, leaving the caller with an open line computer was used to record and circulate numbers found by the exhaustive
into the Toll A exchange. He could then dial OIR, which forwarded him to the dialing of local networks. These numbers were used to create a chain of links from
trunk exchange-at that time, the first long distance exchange in Britain-and local exchange to local exchange across the country, bypassing the trunk circuits.
follow it with the code forthe distant exchange to which he would be connected at Because the internal routing codes in the U.K. network are not the same as those
no extra charge. dialed by the caller, the phreaks had to discover them by "probe and listen"
The signals needed to control the UK network were published in the Institution techniques, more commonly known in tile U.S. as scanning. What they did was put
()f Post Office Engineers Journal and reprinted in the Sunday Times 15 Oct. 1972. in likely signals and listen to find out if they succeeded, The results of scanning
(NOTE: The British Post Office is the U.K. equivalent of Ma Bell.) were circulated to other phreaks. Discovering each other took time at first, but
The system is called Signalling System No.3 and it uses pairs of frequencies eventually the phreaks became organized. The "TAP" of Britain was called
selected from 6 tones separated by 120Hz. With that info, the phreaks made "Undercurrents" which enable British phreaks to share the info on new numbers,
"Bleepers" or as they are called here in the U.S., blue boxes. The British, though, equipment, etc.
utilile different M F tones than the U.S., thus, your U.S. blue box that you To understand what the British phreaksdid, think of the phone network in three
smuggled into the U.K. will not work, unless you change the frequencies. (In the layers of lines: local, trunk, and international. In the U.K., Subscriber Trunk
early seventies, a simpler system based on different numbers of pulses with the Dialing (STD), is the mechanism which takes a call from the local lines and
same frequency (2280Hz) was used. For more info on that, try to get ahold of: (legitimately) elevates it toa trunk or international level. The U.K. phreaks figured
Atkinson's "Telephony and Systems Technology". that a call at trunk level can be routed through any number ofexchanges, provided
Boxing in Foreign Lands that the right routing codes were found and used correctly. They also had to
The following are timing and the frequencies for boxing in the U.K. and other discover how to get from local to trunk level either without being charged (which
foreign countries. Special thanks to Peter Mclvers for the following info: they did with a bleeper box) or without using (STD). Chaining has already been
British "bleeper" boxes have the very same layout as U.S. blue boxes. The mentioned b1lt it requires long strings of digits and speech gets more and more
frequencies are different, though. They use two sets of frequencies: forward and faint as the chain grows, just like it does when you stack trunks back and forth
backward. Forward signals are sent out by the bleeper box. The backward signals across the U.S. The way the security reps snagged the phreaks was to put a simple
may be ignored (it's sort of like using full duplex). The frequencies are as follows: "printermeter" or pen register, as we call it, on the suspect's line, which shows I'very
U.S. 700 900 1100 1300 1500 1700 Hz digit dialed from the subscriber's line.
Fwd 1380 1500 1620 1740 1860 1980 Hz The British prefer to get onto the trunks rather than chaining. One way was to
Bkwd ]]40 1020 900 780 660 540 Hz discover where local calls use the trunks between neighboring exchanges, start a
For exampie, change the 900Hz potentiometers in your box to 1500Hz. All call, and stay on the Hunk instead of returning to the local level on reaching the
numbers I'{) (10) are in the same order as in an American box. The ones after this distant switch. This again required exhaustive dialing and made more work for
are their codes for operator II, operator 12, spare 13, spare 14, and 15. One of Titan; it also revealed "fiddles", which were inserted by Post Office Engineers.
these is KP, one(prohably 15) is Star; it won't be too hard to figure out. The signals What fiddling means is that the engineers rewired the exchanges for their own
should carry -11.5dBm +!- IdB onto the line; the frequencies should be within benefit. The equipment is modified to give access to a trunk without being charged,
+ 4H7 (as is the British equipment). Also. the I YF system is still in operation in an operation which is pretty easy in Step by Step (SxS) electromechanical
parts of the U.K. This would encode all signals I to 16 as binary numbers; for exchanges. which were installed in Britain even in the 1970's.
instance, a five isOIOI. There are six intervals per digit, each 50ms long ora total of A famous British ~fiddler" revealed in the early 1970's worked by dialing 173.
300ms. First is a start pulse of 2280 for 50ms. Then, using the example of five The caller then added the trunk code of I and the subscriber's local number. At
(0101), there is a 50ms pause. a 50ms pulse of2280, a 50ms pause. and a 50ms pulse that time, most engineering test services began with 17X, so the engineers could
of 2280. Finally. there is a 50ms pause that signals the end of the digit. The hide their fiddles in the nest of service wires. When security reps started searching,
frequency tolerance on the 2280H7 is+/ -OJ~(: it is sent at ~ +! -ldBm. An idle line the fiddles were concealed by tones signalling: "number unobtainable" or
is signalled by the presence of a 3825Hz tone for more than 650ms. This must be "equipment engaged" which switched off after a delay. The necessary relays arc
within4H7. small and easily hidden.
France uses the same box codes 'is the U.S., with an additional 1900Hz There was another side to phreaking in the U.K, in the sixties. Before STD was
acknowledgement signal. at -8.7 + / - Idl:lm perfrequency. widespread, many "ordinary" people were driven to occasional phreaking from
Spain uses a 2 out of 5 mf code (same frequencies as U.S.), with a 1700Hz sheerfrustration at the inefficient operator controlled trunk system. This came toa
acknowledge signal. head during a strike about 1961 when operators could not be reached. Nothing
Other places using the IVF system are: complicated was needed. Many operators had been in the habit of repeating the
Australia: 2280H7 +' ~H7, 35ms/digit at ~dB. codes as they dialed the requested numbers so people soon learned the numbers
Germany, France: same as Australia; also, some 1YF systems in the UK. they called frequently. The only "trick" was to know which exchanges could be
Switzerland: ",me as Australia. only it uses 3000Hz, not 2280. dialed through to pa,ss on the trunk number. Callers also needed a pretty quiet
Sweden: same as above, but at 24OOH7. place to do it, since timing relative to clicks was important.
Spain: some parts use IYF with 2500H7. The most famous trial of British phreaks was called the Old Baily trial which
There is one other major system: the 2YF system. In this system, each digit is 35ms started on 3 Oct. 1973. What the phreaks did was dial a spare number at a local call
long. The number is encoded in binary as with the I YF system. Using the example rate but involving a trunk to another exchange. Then they sent a "clearforward"to
of five (0101). here's how the American 2VF system was sent: their local exchange, indicating to it that the call was finished-but the distant
2400 pulse, pause, 2040 pulse, pause, 2400 pulse, pause, 2040 pulse, pause. The exchange didn) realize this because the caller's phone was still off the hook. They
digits and pulses are all 35ms long for a total of 280ms per digit. now had an open line into thedistant trunk exchange and they sent a ~seize"signal
Other countries are still using a similar high! low pair with the same timings. Some (I) which put them on the outgoing lines. Since they figured out the codes, the
parts of Italy use the I YF system with 2040Hz; some use the 2YF system with 2040 world was open to them. All other exchanges trusted the local exchange to handle
and 24OOH, (same as original U.S.). The Netherlands uses a 2YFsystem with 2400 the billing - they just interpreted the tones they heard. Meanwhile, the local
and 2500H, pulses. With the 2VF system, all frequencies should be within 2Hz. exchange collected only for a local call. The inves,tigators discovered the phreaks
Also, here are some specs for American phone equipment: holding a conference somewhere in England surrounded by various phone
Dial Tone: 350+44OH7, -17.5 to -14.5 dBm/tone. equipment and bleeper boxes, also printouts Iisting"secret" Post Office codes. The
Off-Hook (ROH): 1400+2060+2450+26OO(!) onl off 5 times per second. judge said, "Some take to heroin, some take to telephones." For them phone
Busy: 480+620H7; slow busy: 0.5 + -0.05 sec = I period (about twice a second), at phreaking was not a crime but a hobby to be shared with phellow enthusiasts and
-28.5 to -22.5 dBm/ tone. discussed with the Post Office openly over dinner and by mail. Their approach and
Ring: 44O+480H7 at -23.5 to -20.5dBm/tone. A ring is modulated at 20+/ -3Hz, 2 attitude to the world's largest computer, the global telephone system, was that of
sec on, 4 sec off. scientists conducting experiments or programmers and engineers testing programs
Call Waiting: 44OH/. on I second. and systems. The judge appeared to agree, and even asked them for phreaking
codes to use from his local exchange!
1-49
MORE ON TRASHING
Once upon a time there was a most unusual phone phreak service or number<hanged recording. I'd say, "Hey Joanne, it's
and it was a phone phreak who didn't realize it. Her name was me, call me back!" And she would. And I'd talk to her all night
Joanne. She had a very remarkable position in that she was a long because I was a security guard at the time. We'd place long
telephone operator in an extremely small, rural, midwestern distance calls, conference calls like you wouldn't believe. One
community. A friend of mine, who was a radio D.J., got a job in day she said that the switchboard was going to get phased
this small town. One night he had a few drinks after he got off out-a new TSPS switchboard was being installed in the large
work. He called this operator up and started talking to her for a community and was going to seI:Ve all of the small communities
while. She didn't hang up. In fact, she was quite cordial. quite in a four or five state area.
nice, quite friendly. She said, "Would you like to call Dial-a But Joanne continued to be a phone phreak and to this day
Record (in Australia)? Or Dial-the-Time in London? Or any she's working as a secretary for a senator in Washington, DC.
other dial-it services? If there are any phone calls you'd like me She still does some pretty remarkable things, even though she's
to place for free, just let me know." not an operator.
So Joanne proceeded to place a lot of long distance calls for You might want to call up your local operator, provided you
the guy for free. He introduced me to her and said you can call live in a small town, and just say hi some~ime. I've done it on
Joanne for free by dialing a certain out-of-service number. occasion and operators are usually fairly friendly, but far from
She'd say, "What number did you dial, please?" And then she phone phreaks. You might want to try this with directory
would quickly forward it to the other intercept operator in the assistanc-e (they double as operators in smaller locales).
nearby large city where she would tell the operator what Who knows, you might find another Joanne someplace. One
number was dialed and then they'd put on the standard out-of never knows.
Dear 2600: up billing themselves for the call. Also, your phone number
Would you explain these terms to me? I don't know what need never be known by the person "meeting" you on the loop,
they are: since he's not ever dialing your number. Loops have two ends-
I) phone loop the silent end and the tone end. When a connection is
2) WATS extender. established, the tone stops and conversation can begin. Loops
Also, what became of TAP! are almost always found within the phone company test
Thanks. numbers (the 99XX suffix, in many cases). Loops are slowly but
AZ surely dying out, however.
Dear AZ: An extender is very similar to a Sprint or Mel dialup, except
Phone loops are basically test circuits that the phone that it's a number used exclusively by a particular business or
company uses for various purposes. They were never intended organization for their phone calls. A W ATS extender is one
for use by the public. The way it works is simple. One caller that is available on an 800 number. An employee calls up, hears
dials number A. Another caller dials number B. When both of the dial tone, enters a code, and dials away. There are many
these people call these numbers at the same time, they become extenders around and many different types. Watch for an
connected! Some loops make clicking or beeping sounds every article soon detailing these.
few seconds which makes talking on them rather hard. But As far as TAP, we sent a message to their MCI Mail account,
others are crystal clear connections. But while they may serve a and this is what their editor said:
purpose for the telco, what possible use could they be for "TAP is in hiatus. I was evicted from my apartment last
anyone else. Well, for one thing, in many cases there is no week, put everything I collid carry into storage, and left for
charge for calling a loop number since they fall within a series of California on vacation. When I get back to the East Coast, 111
test numbers the phone company uses. Loops are also a great be getting together issues 91 and 92. (While there is a possibility
way to have an anonymous conversation-it's an indirect of getting the issues out while I'm out here, I will not put TAP
connection to another person instead of a direct one, although out in California due to the restrictive state laws on proprietary
-it's far from impossible to be traced while using one. Finally, information.)
there's the old call<ollect trick where one person calls up one MCl Mail is a viable way of asking me questions that require
end of a loop that is within his local calling area. A friend from only short responses, but you should send me hard copy to
far away calls the other end of the loop collect. When the TAP's maildrop address (RM 603, 147 West 42nd St., New
connection is made between the two loops, the operator will York, NY 1(036) because I seldom check my MCI Mail
think that somebody answered the phone and will ask them if anywhere near a hard copy printer. MCI usually deletes my
they want to accept a collect call. The telephone company winds mail before I can call back in and pull it out on paper.
Hope this answers your question. Keep Smiling, Chesire."
1-52
IBM 'ADS DIRECTORY'
~
0\
<=
DIV ADS LOCATION
ADS
TIELINE
ADS
OUTSIDE DIV ADS LOCATION
ADS
TIELIKE
ADS
OUTSIDE
------------
<=
ArE CANADA 0 MILLS 8/942/5261 416/443/5261 NAD Rll ST LOUIS 8/775/9473 3111/5SII/91173
AfE CAIIAOA MARKHAM 8/241/2371 416/474/2371 /(AD R I 3 S FRAtICISCO 8/1173/4747 415/5115/47117
HE CAHADA MONTREAL SEE (1) 514/874/11270 tl AD RIll L AHGELES 8/285/4400 213/736/4400
HE CAIIAOA RTTI SEE (2) 416/360/2721 NAO 590 MADISON 8/2113/5600 212/407/5600
Aft: CAIIADA RTT2 SEE (2) 416/360/5123 !lAD 590 MADISON 8/2113/5125 212/407/5125
t.fE CAHAOA VAHCOUVR SEE (3) 604/665/8670 !lAD 590 MADISOt( 8/243/5186 212/407/5186
ArE TARRYTOWN II 8/48l/4333 914/997/4333 liMO ASC 5 DALLAS 8/668/6262 2111/888/6262
CHQ A P.MOIn: 8/251/5300 9,"/765/5300 HMO ASC 6 L ANGELES 8/285/61141 Z 13/7 ]6/6414 1
CHI? CCDI! HCP K/A YET NtlD NMDHQ ATLANTA 8/331/5155 40 lu2 38/5 ISS
CHI? HUTCH CORP PARK 8/566/3300 914/684/3300 NMO NtlSC ROCHESTER 8/456/7360 507/287/7360
CPO AUSTIN 8/678/8381 512/838/8381 NtlD R 1/2/3 I{'/ 8/325/2741 212/239/2741
CPO AUSTIN 8/678/5555 512/838/5555 HnD R-4,i'-S--·PH Hf&E-T-H 8/9113/6414 215/86'./6414
CPO KINGSTON 8/373/1000 914/385/1000 HMO R 5 BETHESDA 8/727/2522 301/987/2522
CPO P.ALEIGH 8/441/6801 919/543/6801 tHIO R 6 ATLAKTA 8/354/4970 404/393/6970
CSD fRANY.LIK LAKES 8/731/2200 201/848/2200 Htl0 R 6-8 SE'S 8/3511/4820 404/393/6820
CSD R 4 PHILADELPHA 8/9113/2757-215/8611/2757 till D R 8 C IIIC III1IA T I 8/635/7634 513/733/76311
OSO POUGHI~EEPSIE N/A YET liMO R 9 BLMfLD IIILL 8/]48/6564 313/5110/6564
DSO POUGHI:EEPSIE N/A 'tET Q IIt1D RIO RLG MEADOWS 8/788/6450 312/981/61150
~
EnE A IBM EHQ N/A YET tlND R 11 EDEN PRAIRI 8/653/2685 612/893/2685
EMEA IBM fR~"CE 331/296/1619 NMD R 1 Z OVEP.LAIID P.: 8/344/7387 913/661/7387
ErlEA IBM fUHCE SEE (4) Nfl0 RI3 DALLAS K/A YET
EtlE~ IBM GERMANY SEE (5) ~ liMO RI4 DEliVER 8/656/5315 303/773/5315
-
!!:
EM::A liltl ITALY
;:ll::A 1811 UI:
EMEA L.\ HULPE ED CTR N/A YET
39/275486550
441/408/0787
r::n r P AIII: LIH LAY.ES 8/731/4545 201/848/4545
rED GPEEIICASTLE 8/787/2020 317/658/2020
S'
~
~IM 0
1111 0
R15 HEWPORT BCH
R16 S fRANCISCO
RECD P.ECDIIQ TARRTWN
HCO TARRYTOWII I I
~ES ,/OPKTOWII
8/288/3233
8/473/4900
I(/A YET
N/A YET
8/862/ 370 I
7111/752/323]
.,'5/545/4900
914/9 115/fro,
.SO BETItESDA 8/765/1717 301/493/1717 sro BOCA RATOI( 8/443/0361 305/998/0361
f:::;O GllrIHERSBURG 8/372/6700 1')1/840/6700 SPO BOCA RATOH 8/1143/8500 ]05/998/8500
FSD HOI/STOH 8/671/7788 13/333/7788 SPD ROCHESTER 8/456/7400 507/287/7400
.50 NAliASSAS 8/725/5751 )3/367/5751 SPO SPOIIQ W PLI{S 8/236/1812 914/686/1812
.50 OWEGO 8/662/556t 607/751/5566 SSO DAYTON 8/529/4755 201/1Z9/117SS
.SO OWEGO 8/662/5777 607/751/5777 TCP PRINCETON 8/538/8845 609/7 311/88115
GPO SAil JOSE IU A YET WTC EMEA W PLUS 8/236/2626 914/686/2626
GPO SAil JOSE N/A YET
liro SAIITA TItERESA 8/543/3055 408/11&3/,3055
Ii?O TUCSON N/A YET
ISeG ISCGHQ 101 PLNS 8/524/4700 914/934/4700
ISG fRANI:LIK L,Y.ES 8/731/4040 201/8118/4040
ISG rSGHQ KIlIG ST 8/5211/11700 9111/9311/11700
IIAO ATL REGIOII 8/728/4230 202/833/11230
lit. 0 DULAS (GOSM) 8/668/1818 2111/7119/1818
II~D DEliVER 8/0 13' 8/656/5222 303/773/5222'
8/345/1077 713/9110/1077
~
~(A 0 HOUSTON
t(~D I~(fO IfTloIK TAMPA 8/1138/11300 813/872/4300
H.~ 0 IRVING 8/6111/5289 211l/556/5289
H.:IO LIIIE SW MY.TG WP 8/367/11655 914/899/4655 till
II !I 0 IIAOIIQ 101 PL!lS 8/2511/7100 914/696/7100
~
H ..\ 0 NFM BETHESDA 8/825/0311 301/493/0311
~
HAD R 9 CHICAGO 8/261/4444 312/245/441111
,
HOTES:
(I)
(2)
(3)
(4)
DIAL
DI.L
DIAL
DIAL
8/241/2111 ASK fOR OUTSIDE NUMBER
8/241/2111 ASK fOR 8/165/4270
8/241/!111 ASK rOR 8/187/8670
AP5 39-935-8400 [XT 4~70
~
E
"
~
~
(5) DIAL ADS 49-7031-6200 EXT eooo
til
@
We. ha.ve. made. .6 e.vVta.l un..6uc.c.e..6.6 6ui. aftempt.6 i:.o Jr.e.a.c.h you by te1.e.phone.
to fu c.~.6 rutimPOJr.ta.I1.t rra...tte..tr. c.onc.eJLn.iYLg YOM te1.e.phone. .6 e..tr.vic.e.
itt the New City a/tea..
GUll lte.c.OJt.d6 illdic.a..te. that you a.Jte. not ,~ub.6CJtibing to Touc.h Tone.
Se..tr.vic.e. but you Me. uoing a. p~h button phone.. It w..i.ll be nec.e..6.6a.Jty 60Jr.
you. .to C.Ol1.ta.c..t uo tlO la.:t.e.tr. .tha.n Jui.y 3.tr.d .60 .tha.:t we. TIny c.onve.tr..t YOM .6 e..tr.vic.e.
.to Tou.c.it Tone. a..t the a.ppM.tr.ia..te. c.ha..tr.ge..6. 16 you 6a,U. to do .60 you will.
not be. a. bte. to make outgoing ~ 6IWm YOM pu.6h bufton M~ a.6te.tr. Jui.y 8th
due i:.o OM new c.a.U pJr.oc.u6ing .6Y.6tem; which we.n.t into e.66e.c..t on June 9th •
.
The. new .6 Y.6tem .<A duigned i:.o hand1.e. moJr.e. c.a..t.e.l, a.nd pMC.U.6 .them
6a..~te..tr..
MAo; i.:t a.UOW.6 60Jr. .6oph-iAtic.a..te.d c.a1ling c.a.pa.bili;t.i.u c.aJ.1.e.d
Cu6tom Ca.ttbtg Se..tr.vic.e.6. The..6 e. .6 e.tr.vic.e..6 a.Jte. "Call. Wa.Lt.i.ng, Cill FoltWa.Jtding,
Spe.e.d Ca1.Ung, a.nd Th.tr.e.e. Wa.y Ca.tUng".
You ma.y wal1.t to .6ub.6CJtibe. i:.o .the..6e. .6e.tr.vic.e..6 whe.n YOM c.onve.tr..t .to Touc.h
Tone..
Ptea,.~ e. c.ol1.ta.c..t me. be.60Jr. July 3Jr.d, .60 .tha.:t 1 c.a.n ma.ke. .the. ne.c.Ul.>a.JtIj
a.JtJta.llgc.mCJU;6 to c.onnec..t you line. to Touc.h Tone. ana a.void a.ny itLte..tr.Jtuption
ilt YOM outgoing I.> e..tr.vic.e..
Sinc.e.tr.ei.y,
OH NO! THIS PERSON'S CENTRAL OFFICE HAS SWITCHED OVER TO ESS OR THE EQUIVALENT,
WHICH MEANS NO MORE FREE USE OF TOUCH TONES®. AND SOMEHOW (PROBABLY THROUGH
THE USE OF FCC REGISTRATION NUMBERS) THE PHONE COMPANY FOUND OUT THAT THIS
PERSON WAS USING A "PUSH-BUTTON". BY THE WAY, CHECK OUT THE MANY TYPOS IN THIS
LETTER. WE COUNTED FIVE MAJOR SCREWUPS, AND THERE ARE PROBABLY MORE,
1-54