All About Call Spoofing
Real call spoofing requires
serious infrastructure and
technical knowledge - not that
TextNow app bullshit or
Telegram ripper garbage that floods your DMs. Those dipshits selling "private number" services wouldnt know proper spoofing if it slapped them in their face.
View attachment 6349
This guide breaks down call spoofing from basic concepts to
advanced exploitation. No flashy promises, no magic apps - just the hard technical knowledge that lets you
bypass modern call detection systems.
Big Money Still Flows Through Voice
Phone systems still drive billions in sales across major retailers. Companies like
Victorias Secret,
Nordstrom and countless others actively push customers to order by phone. Why? Because old people are retarded when it comes to technology. As to why your granma needs Victoria Secret lingerie, thats a mystery for another day.
But even without direct phone carding, voice spoofing unlocks a trove of opportunities:
- Balance checking at scale
- Mass OTP interception
- Bank account takeover
- Order rerouting/address changes
- Refund fraud at scale
- Corporate account compromise
- Customer service social engineering
The financial sector especially runs on voice. Those phone reps get trained to "help customers" work around security measures, creating perfect social engineering opportunities. One clean spoofed call can accomplish more than days of failed web-based attempts.
The Technical Stack
View attachment 6350
Modern phone systems are a beautiful clusterfuck of old and new tech mashed together. Understanding this mess matters because most fraud prevention still relies on legacy systems that barely changed since the 90s.
Three levels of spoofing exist in this ecosystem:
- Basic ID Spoofing: What those garbage apps do. Just changes the displayed number without touching underlying call data. Fine for pranking your friends, useless for anything serious.
- Carrier-Level Spoofing: Routes calls through legitimate telcos, making them appear as normal PSTN traffic. Expensive as fuck but nearly impossible to detect. Required for serious bank operations.
- Full SIP Spoofing: The sweet spot for most carders. Controls the entire call chain and mimics legitimate traffic patterns. Needs proper infrastructure but can bypass most detection systems.
The Building Blocks
Three main types of phone systems matter for us:
PSTN (Public Switched Telephone Network)
The granddaddy of them all. This traditional phone network still connects landlines worldwide. Banks, credit card companies and big corporations use PSTN because its reliable as fuck. When you call
Chase or
Amex, youre probably hitting their PSTN lines.
For carders, PSTN matters because:
- Most financial institutions trust PSTN calls more than VoIP
- Caller ID spoofing detection barely exists
- Crystal clear audio quality (crucial for social engineering)
- Less recording/monitoring compared to VoIP
VoIP (Voice over IP)
Voice transmitted over internet protocol - basically turning voice into data packets. Think
Skype or your sketchy calling app. Most modern business phone systems use VoIP because its cheap and flexible.
VoIP advantages for fraud:
- Easy to mask origin location
- Dirt cheap international calls
- Simple operation scaling
- Multiple numbers on one system
- Advanced call routing options
SIP (Session Initiation Protocol)
The protocol that makes VoIP work. SIP handles all the setup, teardown and control of VoIP calls. Think of it like HTTP but for voice communication. Most importantly, SIP lets us build our own private phone infrastructure.
Why SIP rocks for carders:
- Complete control over caller ID presentation
- Route calls through multiple servers
- Mix with VPNs for extra anonymity
- Build private phone networks
- No central provider to snitch
Typical call flow looks like this:
View attachment 6351
Code:
Your Device -> SIP Server -> VoIP Provider -> PSTN Gateway -> Target Phone
Mα»i bΖ°α»c nhαΊ£y trong chuα»i nΓ y αΊ£nh hΖ°α»ng ΔαΊΏn cΓ‘ch hα» thα»ng tiαΊΏp nhαΊn xem cuα»c gα»i cα»§a bαΊ‘n. NgΓ’n hΓ ng khΓ΄ng chα» kiα»m tra sα» Δiα»n thoαΊ‘i - hα» phΓ’n tΓch toΓ n bα» chα»― kΓ½ cuα»c gα»i khi nΓ³ Δi qua cΖ‘ sα» hαΊ‘ tαΊ§ng nΓ y.
ΔΓ’y lΓ lΓ½ do tαΊ‘i sao viα»c chαΊ‘y thiαΊΏt lαΊp SIP cα»§a riΓͺng bαΊ‘n lαΊ‘i quan trα»ng. CΓ‘c dα»ch vα»₯ "sα» riΓͺng" ΔΓ³ cΓ³ thα» hoαΊ‘t Δα»ng cho cΓ‘c ΔΖ‘n ΔαΊ·t hΓ ng pizza nhΖ°ng bαΊ₯t kα»³ thα»© gΓ¬ liΓͺn quan ΔαΊΏn hα» thα»ng tΓ i chΓnh Δα»u cαΊ§n cΖ‘ sα» hαΊ‘ tαΊ§ng phΓΉ hợp.
Sα»± thαΊt vα» ID ngΖ°α»i gα»i
View attachment 6352
CΓ‘c ngΓ’n hΓ ng vΓ tα» chα»©c tΓ i chΓnh xΓ‘c thα»±c cΓ‘c cuα»c gα»i ΔαΊΏn thΓ΄ng qua nhiα»u lα»p kiα»m tra mΓ nhα»―ng kαΊ» giαΊ£ mαΊ‘o giΓ‘ rαΊ» khΓ΄ng thα» vượt qua. Khi mα»t cuα»c gα»i ΔαΊΏn hα» thα»ng cα»§a hα», hα» sαΊ½ kiα»m tra:
- Sα» ID ngΖ°α»i gα»i Δược trΓ¬nh bΓ y
- Cuα»c gα»i bαΊ―t nguα»n tα»« ΔΓ’u
- Nhα»―ng nhΓ cung cαΊ₯p nΓ o xα» lΓ½ viα»c Δα»nh tuyαΊΏn
- MαΊ«u tΓn hiα»u cuα»c gα»i vΓ siΓͺu dα»― liα»u
- MαΊ«u sα» dα»₯ng lα»ch sα»
ΔΓ’y lΓ lΓ½ do tαΊ‘i sao cΓ‘c cuα»c gα»i
TextNow cα»§a bαΊ‘n bα» chαΊ·n ngay lαΊp tα»©c. CΓ‘c sα» cΓ³ thα» trΓ΄ng hợp lα» nhΖ°ng chα»― kΓ½ bΓͺn dΖ°α»i lαΊ‘i cho thαΊ₯y ΔΓ’y lΓ gian lαΊn VoIP.
Vα»i SIP, bαΊ‘n kiα»m soΓ‘t toΓ n bα» chuα»i cuα»c gα»i. CΓ‘c cuα»c gα»i cα»§a bαΊ‘n cΓ³ thα» mΓ΄ phα»ng lΖ°u lượng PSTN hợp phΓ‘p Δi qua cΓ‘c nhΓ mαΊ‘ng ΔΓ‘ng tin cαΊy. BΓ quyαΊΏt nαΊ±m α» viα»c hiα»u cΓ‘ch cΓ‘c tα» chα»©c tΓ i chΓnh khΓ‘c nhau xΓ‘c thα»±c cΓ‘c sα» ΔαΊΏn.
Mα»t sα» ngΓ’n hΓ ng chα» kiα»m tra ID ngΖ°α»i gα»i cΖ‘ bαΊ£n. ΔΓ’y lΓ nhα»―ng mα»₯c tiΓͺu dα»
dΓ ng cα»§a bαΊ‘n - viα»c giαΊ£ mαΊ‘o sα» cΖ‘ bαΊ£n hoαΊ‘t Δα»ng tα»t. Nhα»―ng ngΓ’n hΓ ng khΓ‘c ΔΓ o sΓ’u hΖ‘n, xem xΓ©t Δα»nh tuyαΊΏn cuα»c gα»i vΓ chα»― kΓ½ cα»§a nhΓ mαΊ‘ng. Nhα»―ng Δiα»u nΓ y cαΊ§n cΖ‘ sα» hαΊ‘ tαΊ§ng SIP phΓΉ hợp Δα» cΓ³ vαΊ» hợp phΓ‘p.
CΓ‘c hα» thα»ng tinh vi nhαΊ₯t phΓ’n tΓch cΓ‘c mαΊ«u cuα»c gα»i theo thα»i gian. ChΓΊng theo dΓ΅i tαΊ§n suαΊ₯t cΓ‘c sα» ΔαΊΏn hα» thα»ng cα»§a chΓΊng, nhΓ mαΊ‘ng nΓ o Δα»nh tuyαΊΏn chΓΊng vΓ cΓ‘c mαΊ«u sα» dα»₯ng thΓ΄ng thΖ°α»ng.
XΓ’y dα»±ng thiαΊΏt lαΊp cα»§a riΓͺng bαΊ‘n
Sau ΔΓ’y lΓ hai phΖ°Ζ‘ng phΓ‘p thα»±c sα»± hiα»u quαΊ£ mΓ khΓ΄ng cαΊ§n phαΊ£i cΓ³ bαΊ±ng TiαΊΏn sΔ© vα» viα»
n thΓ΄ng:
PhΖ°Ζ‘ng phΓ‘p 1: ΔΖ°α»ng dΓ’y SIP cΓ³ thαΊ»
PhΖ°Ζ‘ng phΓ‘p dα»
nhαΊ₯t vαΊ«n mang lαΊ‘i kαΊΏt quαΊ£. ThαΊ»
Twilio ,
Telnyx hoαΊ·c
voip.ms. Nhα»―ng phΖ°Ζ‘ng phΓ‘p nΓ y hoαΊ‘t Δα»ng tα»t vα»i hαΊ§u hαΊΏt cΓ‘c trang web.
YΓͺu cαΊ§u:
- ThαΊ» sαΊ‘ch vα»i thiαΊΏt lαΊp chα»ng phΓ‘t hiα»n chαΊ―c chαΊ―n
- Email doanh nghiα»p (khΓ΄ng phαΊ£i email miα»
n phΓ)
- MicroSIP (softphone miα»
n phΓ)
- Proxy dΓ’n cΖ°
CΓ‘c bΖ°α»c thα»±c hiα»n:
View attachment 6353
- ΔΔng kΓ½ tΓ i khoαΊ£n Telnyx (hoαΊ·c cΓ‘c nhΓ cung cαΊ₯p SIP khΓ‘c):
- ΔΔng kΓ½ tΓ i khoαΊ£n vα»i Telnyx hoαΊ·c nhΓ cung cαΊ₯p SIP mΓ bαΊ‘n Ζ°a thΓch.
- Mua sα» DID:
- Mua sα» DID phΓΉ hợp vα»i khu vα»±c mα»₯c tiΓͺu cα»§a bαΊ‘n Δα» gα»i Δiα»n nα»i hαΊ‘t.
- LαΊ₯y thΓ΄ng tin xΓ‘c thα»±c tα»« BαΊ£ng Δiα»u khiα»n:
- ΔΔng nhαΊp vΓ o bαΊ£ng Δiα»u khiα»n Telnyx vΓ Δiα»u hΖ°α»ng ΔαΊΏn phαΊ§n nΖ‘i bαΊ‘n cΓ³ thα» tΓ¬m thαΊ₯y thΓ΄ng tin xΓ‘c thα»±c SIP (tΓͺn ngΖ°α»i dΓΉng, mαΊt khαΊ©u vΓ thΓ΄ng tin chi tiαΊΏt vα» mΓ‘y chα»§ SIP).
- Thay Δα»i ID ngΖ°α»i gα»i:
- Trong tΓ i khoαΊ£n Telnyx cα»§a bαΊ‘n, hΓ£y tΓ¬m tΓΉy chα»n Δα» thiαΊΏt lαΊp Ghi ΔΓ¨ ID ngΖ°α»i gα»i . TΓΉy chα»n nΓ y cho phΓ©p bαΊ‘n chα» Δα»nh ID ngΖ°α»i gα»i mΓ bαΊ‘n muα»n hiα»n thα» khi thα»±c hiα»n cuα»c gα»i Δi.
- CαΊ₯u hΓ¬nh MicroSIP:
- Mα» MicroSIP vΓ vΓ o TΓ i khoαΊ£n > ThΓͺm Δα» tαΊ‘o tΓ i khoαΊ£n SIP mα»i.
- NhαΊp cΓ‘c thΓ΄ng tin sau:
- TΓͺn miα»n:
(hoαΊ·c Δα»a chα» mΓ‘y chα»§ SIP do nhΓ cung cαΊ₯p cα»§a bαΊ‘n cung cαΊ₯p).
- TΓͺn ngΖ°α»i dΓΉng: TΓͺn ngΖ°α»i dΓΉng SIP cα»§a bαΊ‘n tα»« bαΊ£ng Δiα»u khiα»n Telnyx.
- MαΊt khαΊ©u: MαΊt khαΊ©u SIP cα»§a bαΊ‘n tα»« bαΊ£ng Δiα»u khiα»n Telnyx.
- VαΊn chuyα»n: Chα»n TCP .
- ΔαΊ·t Sα» Δα»a phΖ°Ζ‘ng lΓ m DID cα»§a bαΊ‘n: NhαΊp sα» DID ΔΓ£ mua vΓ o trΖ°α»ng thΓch hợp.
- LΖ°u cαΊ₯u hΓ¬nh:
- NhαΊ₯p vΓ o OK Δα» lΖ°u cΓ i ΔαΊ·t tΓ i khoαΊ£n trong MicroSIP.
- Kiα»m tra thiαΊΏt lαΊp:
- Thα»±c hiα»n cuα»c gα»i Δi bαΊ±ng MicroSIP Δα» ΔαΊ£m bαΊ£o ID ngΖ°α»i gα»i Δược hiα»n thα» nhΖ° ΔΓ£ chα» Δα»nh vΓ cuα»c gα»i Δược kαΊΏt nα»i thΓ nh cΓ΄ng.
PhΖ°Ζ‘ng phΓ‘p 2: Tα»± lΓ m FreePBX
Nhiα»u cΓ΄ng viα»c thiαΊΏt lαΊp hΖ‘n nhΖ°ng tα»t hΖ‘n cho gian lαΊn liΓͺn quan ΔαΊΏn ngΓ’n hΓ ng. KhΓ³ phΓ‘t hiα»n hΖ‘n vΓ¬ bαΊ‘n kiα»m soΓ‘t toΓ n bα» hα» thα»ng.
View attachment 6354
YΓͺu cαΊ§u:
- VPS cΓ³ thαΊ» ( OVH hoαΊ·c DigitalOcean hoαΊ‘t Δα»ng tα»t)
- ISO cα»§a FreePBX
- Sα» DID tα»« bαΊ₯t kα»³ nhΓ cung cαΊ₯p nΓ o (mα»t sα» nhΓ cung cαΊ₯p dα»
bα» giαΊ£ mαΊ‘o hΖ‘n, vΓ¬ vαΊy hΓ£y tα»± nghiΓͺn cα»©u)
- MicroSIP
- ThiαΊΏt lαΊp proxy giα»ng nhΖ° PhΖ°Ζ‘ng phΓ‘p 1
CΓ‘c bΖ°α»c thα»±c hiα»n:
- ThαΊ» VPS:
- Chα»n nhΓ cung cαΊ₯p VPS vΓ thiαΊΏt lαΊp mΓ‘y chα»§ cα»§a bαΊ‘n.
- TαΊ£i xuα»ng vΓ cΓ i ΔαΊ·t FreePBX:
- LΓ m theo hΖ°α»ng dαΊ«n cΓ i ΔαΊ·t FreePBX trΓͺn VPS cα»§a bαΊ‘n.
- CαΊ₯u hΓ¬nh cΖ‘ bαΊ£n trong BαΊ£ng quαΊ£n trα»:
- ThΓͺm tiα»n Γch mα» rα»ng:
- VΓ o Ứng dα»₯ng > Tiα»n Γch mα» rα»ng vΓ tαΊ‘o cΓ‘c tiα»n Γch mα» rα»ng cαΊ§n thiαΊΏt.
- ThiαΊΏt lαΊp tuyαΊΏn Δi:
- Δiα»u hΖ°α»ng ΔαΊΏn KαΊΏt nα»i > TuyαΊΏn Δi vΓ cαΊ₯u hΓ¬nh tuyαΊΏn Δi cα»§a bαΊ‘n.
- Trong cΓ i ΔαΊ·t tuyαΊΏn Δi, hΓ£y tΓ¬m TΓΉy chα»n CID Δα» ΔαΊ·t ID ngΖ°α»i gα»i mαΊ·c Δα»nh mΓ bαΊ‘n muα»n sα» dα»₯ng cho cΓ‘c cuα»c gα»i Δi.
- CαΊ₯u hΓ¬nh DID cα»§a bαΊ‘n:
- VΓ o KαΊΏt nα»i > TuyαΊΏn ΔαΊΏn vΓ thiαΊΏt lαΊp bαΊ₯t kα»³ sα» gα»i ΔαΊΏn trα»±c tiαΊΏp (DID) nΓ o bαΊ‘n cΓ³.
- ThiαΊΏt lαΊp giαΊ£ mαΊ‘o ID ngΖ°α»i gα»i:
- Trong Outbound Routes , hΓ£y chα» Δα»nh ID ngΖ°α»i gα»i mΓ bαΊ‘n muα»n sα» dα»₯ng trong trΖ°α»ng Caller ID (ΔαΊ£m bαΊ£o rαΊ±ng bαΊ‘n cΓ³ quyα»n sα» dα»₯ng sα» nΓ y).
- ΔαΊ£m bαΊ£o cΓ i ΔαΊ·t ΔΖ°α»ng truyα»n cα»§a bαΊ‘n cho phΓ©p thay Δα»i ID ngΖ°α»i gα»i.
- Trα» MicroSIP tα»i IP VPS cα»§a bαΊ‘n:
- TαΊ£i xuα»ng vΓ cΓ i ΔαΊ·t MicroSIP trΓͺn mΓ‘y cα»₯c bα» cα»§a bαΊ‘n.
- Mα» MicroSIP vΓ vΓ o TΓ i khoαΊ£n > ThΓͺm Δα» tαΊ‘o tΓ i khoαΊ£n SIP mα»i.
- NhαΊp thΓ΄ng tin sau:
- TΓͺn hiα»n thα»: TΓͺn cα»§a tΓ i khoαΊ£n.
- MΓ‘y chα»§ SIP: Δα»a chα» IP hoαΊ·c tΓͺn miα»n VPS cα»§a bαΊ‘n.
- TΓͺn ngΖ°α»i dΓΉng SIP: Sα» mΓ‘y nhΓ‘nh bαΊ‘n ΔΓ£ tαΊ‘o.
- MαΊt khαΊ©u SIP: MαΊt khαΊ©u Δược liΓͺn kαΊΏt vα»i phαΊ§n mα» rα»ng ΔΓ³.
- MΓ‘y chα»§ STUN (tΓΉy chα»n): Sα» dα»₯ng mΓ‘y chα»§ STUN nαΊΏu cαΊ§n cho NAT.
- LΖ°u cαΊ₯u hΓ¬nh trong MicroSIP:
- NhαΊ₯p vΓ o OK Δα» lΖ°u cΓ i ΔαΊ·t tΓ i khoαΊ£n.
- Kiα»m tra kαΊΏt nα»i:
- Thα»±c hiα»n cuα»c gα»i thα» Δα» ΔαΊ£m bαΊ£o rαΊ±ng ID ngΖ°α»i gα»i giαΊ£ mαΊ‘o Δược hiα»n thα» chΓnh xΓ‘c vΓ cuα»c gα»i Δược thα»±c hiα»n thΓ nh cΓ΄ng.
CαΊ£ hai phΖ°Ζ‘ng phΓ‘p Δα»u hiα»u quαΊ£ nhΖ°ng hΓ£y nhα» nhα»―ng quy tαΊ―c cα»t lΓ΅i sau:
* VΔn bαΊ£n αΊ©n: khΓ΄ng thα» trΓch dαΊ«n. *
Viα»c chαΊ‘y mΓ‘y chα»§ PBX cα»§a riΓͺng bαΊ‘n sαΊ½ mang lαΊ‘i cho bαΊ‘n sα»± nhαΊ₯t quΓ‘n hΖ‘n, vΓ¬ cΓ‘c nhΓ cung cαΊ₯p SIP nΓ y khΓ΄ng chαΊ―c chαΊ―n vΓ cΓ³ xu hΖ°α»ng vΓ΄ hiα»u hΓ³a cΓ‘c tΓ i khoαΊ£n mΓ hα» nghi ngα» cΓ³ hoαΊ‘t Δα»ng Δα»c hαΊ‘i theo thα»i gian. Tuy nhiΓͺn, nαΊΏu bαΊ‘n mα»i bαΊ―t ΔαΊ§u, hΓ£y sα» dα»₯ng PhΖ°Ζ‘ng phΓ‘p 1. NΓ³ ΔΖ‘n giαΊ£n hΖ‘n vΓ Δα»§ tα»t cho hαΊ§u hαΊΏt mα»i thα»©. Chα» bαΊn tΓ’m ΔαΊΏn FreePBX nαΊΏu bαΊ‘n Δang thα»±c hiα»n gian lαΊn ngΓ’n hΓ ng nghiΓͺm trα»ng hoαΊ·c cαΊ§n kiα»m soΓ‘t hoΓ n toΓ n cΖ‘ sα» hαΊ‘ tαΊ§ng cα»§a mΓ¬nh.
PhαΊ§n kαΊΏt luαΊn
Viα»c giαΊ£ mαΊ‘o cuα»c gα»i khΓ΄ng phαΊ£i lΓ trΓ² αΊ£o thuαΊt - ΔΓ³ lΓ mα»t kα»Ή nΔng kα»Ή thuαΊt ΔΓ²i hα»i kiαΊΏn thα»©c chuyΓͺn mΓ΄n vΓ cΖ‘ sα» hαΊ‘ tαΊ§ng nghiΓͺm tΓΊc. NαΊΏu bαΊ‘n vαΊ«n Δang nghΔ© ΔαΊΏn viα»c sα» dα»₯ng mα»t sα» α»©ng dα»₯ng nhαΊ£m nhΓ hoαΊ·c dα»ch vα»₯ Telegram, bαΊ‘n ΔΓ£ bα» lα»‘ hoΓ n toΓ n mα»₯c ΔΓch.
Hiα»u Δược cΓ΄ng nghα» lΓ rαΊ₯t quan trα»ng vΓ cΓ‘c thiαΊΏt lαΊp DIY giΓΊp bαΊ‘n kiα»m soΓ‘t vΓ nhαΊ₯t quΓ‘n hΖ‘n. HΖ°α»ng dαΊ«n nΓ y khΓ΄ng dΓ nh cho nhα»―ng ngΖ°α»i mα»i vΓ o nghα» hoαΊ·c nhα»―ng Δα»©a trαΊ» thΓch viαΊΏt kα»ch bαΊ£n. HΖ°α»ng dαΊ«n nΓ y dΓ nh cho nhα»―ng ngΖ°α»i sαΊ΅n sΓ ng lΓ m viα»c vΓ giα»i hΖ‘n trong viα»c gian lαΊn.
NαΊ―m vα»―ng nhα»―ng kα»Ή thuαΊt nΓ y, vΓ bαΊ‘n sαΊ½ mα» ra nhα»―ng cΓ‘nh cα»a mΓ hαΊ§u hαΊΏt "ngΖ°α»i ΔΓ‘nh bΓ i" chα» cΓ³ thα» mΖ‘ Ζ°α»c. Chα» cαΊ§n Δα»«ng khΓ³c lΓ³c khi bαΊ‘n lΓ m hα»ng vΓ bα» bαΊ―t. CΓ‘i nΓ y khΓ΄ng phαΊ£i lΓ trΓ² chΖ‘i. HΓ£y luΓ΄n cαΊ£nh giΓ‘c, thαΊn trα»ng vΓ luΓ΄n hα»c hα»i. Hα» thα»ng Δiα»n thoαΊ‘i Δang hα»n loαΊ‘n, vΓ ΔΓ³ lΓ lợi thαΊΏ cα»§a bαΊ‘n - nαΊΏu bαΊ‘n Δα»§ thΓ΄ng minh Δα» sα» dα»₯ng nΓ³. d0ctrine out.