I broke IKEA.

(or, well, one of their delivery services.) 🔊 Just a fair warning - there are some perhaps annoying glitch sounds in the attached recording. The volumes are normalized to limit loud spikes, as they were a lot worse in person. 😅 so, my phone service has a rather clever anti-spam tactic, which works like this: * I receive a phone call from an unknown number, and it goes through screening when I answer it. It rings until the fifth ring, the voicemail greeting plays out, then I've got 30 seconds to judge if it's a spam robocall or if it's genuine * If it's okay, I press 1, and it interrupts the ring/voicemail sequence and I answer the call like usual. * If it's spam, I press ### (the # key by itself normally opens my PBX menu, so it doesn't go through) and hang up immediately. Pressing ### and hanging up, will shove the call to voicemail, then launch a "DTMF bomb", which is a rapid sequence of over a hundred tones of DTMF keysmash, even including some of the "ABCD" keys. [https://en.wikipedia.org/wiki/Dual-tone_multi-frequency_signaling##,_*,_A,_B,_C,_and_D] This has blown up spammers' cheapass PBXes, especially ones with poor security and too much trust given to the DTMF decoder on the call server. So, when IKEA called from a random 1-877 number to confirm my furniture shipment worth $1200 (that's the equivalent of :sixty: blåhaj!), the only thing it said is "To continue in English, please press 1."... and I had no idea who it was, immediately thought it was spam, and did the ### gesture. Oops. What follows is a transcript of the call in the recording above. ---------------------------------------- > "To continue in English, please press 1️⃣." > [extremely rapid DTMF spam string] > "Your delivery is scheduled for Tuesday. Five. [A burst of digital static plays out here for about a quarter of a second.] $DeliveryDate between the hours of 2pm and 6pm. > > If an adult will not be available within the timeframe provided, or you have any other conflicts, please contact us at > 8 > 8 > 8 > 8 > 8 > 8 > 8 > 8 > 8 > 8 > 8 > 8 > 8 > 8 > 8 > 8 > 8 > 8 > 8 > 8 > Message repeat. ⚠️. Your delivery is scheduled for-" [total system breakdown occurs here... followed by dead line noise.] ............. [blerp] ............. [blerp] ............. [blerp] ............. [blerp] ... I should've just bought :sixty: blåhaj, instead. (Names, businesses, times, dates and phone numbers may be changed or redacted in order to protect the privacy of those involved.)

web.archive.org · sirocyl on cohost

0

If you have a fediverse account, you can quote this note from your own instance. Search https://infosec.exchange/users/da_667/statuses/115636729098236846 on your instance and quote it. (Note that quoting is not supported in Mastodon.)