GSM exploit for unsolicited calls

This is a short presentation on a GSM exploit that can modify the standard options for the lock button on mobile devices. It allows users to selectively divert unsolicited calls to any number they enter. This exploit simply utilizes the device hardware buttons to modify the default setting.


Unsolicited callers GSM Exploit

Requirements: A GSM mobile phone, a volunteer from the audience or I can bring my own (My friendly goon buddies), a projector that I will connect my mobile device to via my own connection or airplay compatible, a mic and a stage. Mic for volunteer, myself and phone audio. Volunteer will be instructed to pretend to be a telemarketer selling extended vehicle warranties or have the volunteer attempt a social engineering call. Either way, it gets the audience attention. Worst case, the audience can call the number themselves to see what happens live. This presentation is interactive. The is not a call divert presentation, this is how to use the GSM exploit to selectively divert calls, this exploit allows the users to select which calls to divert. A user can answer the call, silence the call and divert to voicemail or divert unsolicited calls to any other number they select. No app to install, no service to subscribe to.

  1. Introduction:
    A. Who enjoys multiple unsolicited calls to your mobile device on a daily basis? You know, those automotive extended warranties and other spam calls? (May ask for a volunteer from the crowd or bring my own to complete the presentation.) Demonstration only requires audience to see me raise the mobile device and press the physical lock button on the device being held up.
    B. Hello, my name is Nacho and I stumbled onto this exploit years ago and it has helped me reduce 99% of my unsolicited calls to my mobile number. I would like to share this with you now so you can use it for your own needs.
  2. Some background:
    A. Several years back I was being bombarded by unsolicited calls and tried everything to get these to stop. I signed up for the do-not-call list, (Display the website of the do-not-call list) selectively blocked the numbers but nothing seemed to work. (Displaying a long list of blocked numbers on the screen) I was not going to pay or download any app that required access to my personal contacts either!
    B. Well, here is what I stumbled onto. Anyone know about the GSM codes? (Screenshot of the multiple GSM codes) I had used GSM codes in the past for hiding my number by using the “67” code before the actual number I would call. I used this so people would not record my number and add it to any future spam list.
    C. Users do certain things when we notice or identify a non-solicited call, we either select the “send to voicemail” option on the screen or press the physical lock button on the device, both Android and iOS devices have this feature. (Can demonstrate on the screen by having volunteer from audience dial my number). If they call back, you usually press the lock button twice to silence and force the call to voicemail.
    D. I was viewing a presentation very similar to this one about how some people will use the GSM codes to forward all their calls to a specific number using the “
    21[Destination number]#” GSM code and that one could dial “#21#” GSM code to determine if your device is forwarding all calls to another number. This is what got my curiosity, can a GSM code be used to divert unsolicited calls? Here is what I found.
  3. The findings:
    A. While reviewing the GSM codes I realized these codes can bypass any OS security options. The GSM network is how these devices connect and communicate. Android or iOS cannot restrict these GSM codes. The call options are on the Graphical User Interface of each OS for incoming calls, but by knowing the specific code you can force the device to comply.
    B. I decided to use the “If busy” GSM code, it’s basically a “Not Now!” option. Perfect for unsolicited calls! But how to use this? Well, if the phone is locked the device screen will display “tap to reply”, or “other” which displays Voicemail or Message on iOS. (A screenshot of what displays will be presented if needed) A similar option will display on an android device. It gives you the option to send to voicemail or respond with a message. That is how the OS displays the options.
    C. The other option is the physical buttons on the device, the lock button specifically. As mentioned before, it’s one press of the lock button to silence the call and eventually goes to voicemail after a predetermined number of rings or you can double press on the lock button to force it to voicemail. That double click is the equivalent to “I’m Busy!”. Typically, the default setting is that by double clicking the lock button the caller gets sent directly to voicemail not having to wait for all the rings. But what if you manually entered the GSM code for “if busy”?
  4. The unsolicited calls EXPLOIT!
    A. Next was determining the GSM code for “if busy” and a number to forward to. So, I now had to locate a number to forward all calls to. I had used a number in the past for registrations it was a local school district’s new IP phone system number. Basically, the area code, prefix followed by “0000”, it would respond with the traditional “This number has been disconnected and it no longer in use” recording when called. I then proceeded to enter the GSM code for “if busy”, by opening up my phone app and manually entering the GSM code “67[9564730000]#” then pressed the green dial option. Once entered the screen displayed the confirmation that the “if busy” is active to the specified number. It worked!!
    B. From then on, any suspected unsolicited call I received I would simply press the lock button twice and the call would divert to the disconnected number I had programmed. One problem, those unsolicited callers began spoofing my number believing it was a disconnected number so I began getting more calls from the people they would call.
  5. Solution:
    A. Seeing that this was an issue, I found a new number to call what would provide me a continuous amount of entertainment for all the unsolicited calls I received. During a recent cyber podcast, I learned about the Jolly Roger Telephone service “jollyrodgertelephone.com”! This service had Ai’s answering calls and dealing with the unsolicited callers and then emailed me the recorded calls! I received hundreds of recordings with telemarketers, sales agents, scammer and even other Ai’s having full conversations with the Jolly Rodger ai’s. The exploit worked great! I personally used that number, but you can use any other number you want, even the telemarketer’s own number so the telemarketer can be diverted to another telemarketer and so on.
  6. Conclusion:
    A. In short, this exploit can help you divert unsolicited calls to any number you choose. Calls from the in-laws, ex-girlfriends, salespeople and more. You decide who gets “diverted”. Simply by opening up the phone app on your mobile device, dialing the “If Busy” GSM code 67[destination number]# and dial. Then, by pressing the lock button of your GSM mobile phone twice, you can divert calls too with this exploit!
    B. Things to consider when using this exploit, if you are dialing out and if a call is coming in at the exact time, that call will be diverted because you are “Busy” calling out. If you select a fax line or a disconnected line as your “If Busy” number, the scammers may spoof your number now to call others. Live Voicemail options on the phone app used to have issues with this exploit on older versions of the iOS.
nachos

Over 30+ years in IT/Information Security working as a remote employee along the Texas/Mexico border.