Showing posts with label computers. Show all posts
Showing posts with label computers. Show all posts
Friday, February 5, 2010
Tuesday, August 4, 2009
Be Aware! Voice and Data Can Be Spied on
Attackers seeking to do harm or mischief to your networks work with an ever expanding arsenal of tools that sometimes seem to be the stuff of spy fiction, but they are all too real.Here are 10 Spy style cloak-and-dagger ways, legal and illegal, to secretly tap into networks and computers to capture data and conversations.
1. Wireless keyboard eavesdropping: Remote-exploit.org has released an open source hardware design and accompanying software for a device that captures then decrypts signals from wireless keyboards. The device uses a wireless receiver that can be concealed in clothing or disguised as a common object that could be left on a desk near a PC to pick up signals.
Called Keykeriki, the technology targets 27MHz wireless keyboards to exploit insecurities that remote-expoit.org discovered earlier. The company plans to build and sell the hardware.
2. Wired keyboard eavesdropping: Electromagnetic pulses that keyboards make to signal what key is being hit travel through the grounding system of the keyboard and the computer itself as well as the ground for the electrical wiring in the building where the computer is plugged in.
Probes placed on the ground for the electric wiring can pick up these electromagnetic fluctuations, and they can be captured and translated into characters. The potential for this type of eavesdropping has been known for decades, and many experts believe spy agencies have refined techniques that make it practical. Andrea Barisani and Daniele Bianco, researchers for network security consultancy Inverse Path, are presenting their quick-and-dirty research on the topic at this year's Black Hat USA conference in the hopes of sparking more public research of these techniques.
3. Laptop eavesdropping via lasers: Bouncing lasers off laptops and capturing the vibrations made as keys are struck give attackers enough data to deduce what is being typed. Each key makes a unique set of vibrations different from any other. The space bar makes an even more unique set, Barisani and Bianco say.
Language analysis software can help determine which set of vibrations correspond to which key, and if the attacker knows the language being used, the message can be exposed, they say.
4. Commercial keyloggers: Early keyloggers were devices attached in-line with keyboards, but they advanced to software tools that grab keystrokes and store or send them to an attack server. Commercial versions have the software loaded on memory sticks that can dump the software on a computer and then be reinserted later to download the collected data.
5. Cell phones as remotely activated bugs: Software loaded onto certain models of cell phones can silence the ringers and cut off the light displays that would normally be triggered when calls are made to them. The caller can then listen in on conversations in the room where the phone is located.
According to press reports, the FBI received court permission to use this technique to spy on suspected Mafia members in New York.
6. Cell phone SIM card compromise: If attackers can get possession of a cell phone briefly, they can use commercially available software to download and read SIM cards and their store of phone numbers, call logs, SMS messages, photos and so on.
For instance PhoneFile Pro is software on a USB stick that claims to enable both the download and the display of the data.
7. Law enforcement wiretapping based on voice print: Phone company voice switches include software that can search all conversations going through it for voices that match sets of voiceprints. Whenever the switch makes a match, it can trigger a recording of the conversation and alert law enforcement officials, says James Atkinson, an expert in technical surveillance countermeasures.
The feature is designed to support communications assistance for law enforcement (CALEA) -- the law that requires phone companies to provide wiretapping access under court order to specific communications traffic.
8. Remote capture of computer data: Under a sketchy technique called Computer and Internet Protocol Address Verifier (CIPAV), the FBI has remotely tracked down data about individual computers.
Details of the technology have never been publicly revealed, but they were used to track down high-school students who sent e-mail bomb threats. CIPAV grabs IP and MAC addresses, running processes, visited Web sites, versions of operating systems, registered owner and logging of computers the target computers connect to. It is believed the software that does this is dropped in via exploiting instant messaging.
9. Cable TV as an exploitable network: Because most cable TV networks are essentially hubbed, any node can monitor any other node's traffic, says James Atkinson, an expert in technical surveillance countermeasures. By and large security is rudimentary and the encryption used could be hacked by someone with basic technical skills and readily available decryption tools, he says.
10. Cell phone monitoring: Commercially available software claims to capture cell phone conversations and texting. Attackers need to get physical access to the phone to upload the software that enables this.
There are several commercial brands on the market, but there are also online complaints that the software doesn't work as advertised or is more complicated to use than the vendors let on.
Conficker Worm - Still Ice Cold at DefCon Conference
All talk of the Conficker Worm was sanitised at the Black Hat conference to protect the current investigation.The criminal ring is very savvy and might have infiltrated the group hunting it down, one investigator says.
The international security team tracking down Conficker thought that the masterminds behind it would have been apprehended by now, according to one of the leaders of the effort to stamp out the resilient worm but that’s not the way it has worked out.
Investigators cautious
A meeting and presentation talk at Black Hat yesterday had to be scaled back because it contained information about Conficker that might tip the investigators’ hand and send the perpetrators further underground, says Mikko Hypponen, chief research officer at F-Secure and a member of the Conficker Working Group.
A Forensic Look
When Hypponen submitted the abstract for his Black Hat briefing more than six months ago, he thought he’d be presenting a forensic look at a dead worm and that the team who had written and managed it would be out of action. “I had hoped that by the end of July we would be in a totally different situation, the case would be closed and the group would be in jail,” Hypponen said in an interview after his talk.
Critical Information
His official line was that he was asked last week not to reveal critical information that might help prolong Conficker’s reign over millions of computers and inhibit the ongoing criminal investigation. “So I will end my presentation here,” Hypponen said at the conclusion of his Black Hat session. “Thank you very much. I will not be taking any questions.”
Holding Back
Hypponen said afterwards that he wasn’t forced to curtail his remarks (Black Hat has been the site of numerous speech-blockings and speech-blocking attempts, including that of a researcher Cisco sued because he was to reveal a flaw in the company's IOS code). Rather, Hypponen had already realised that it made sense to hold back some of what the working group has found out. “It’s better to keep them in the dark about what is known,” he says.
Agility and Precision
Given the agility and precision with which Conficker alters its tactics, Hypponen doesn’t rule out that the Conficker Working Group itself might have been infiltrated by Conficker operatives.
He wouldn’t say how close he thinks authorities are to bringing down the group, but did say there is an indication that it is based in the Ukraine. Some techniques used in Conficker match those used in an earlier worm, which might mean the same people were behind both.
Ukrainian Police
That earlier worm avoided propagating to machines in the Ukraine, which might mean that the group is based there and was trying to avoid committing a local crime to keep Ukrainian police off their backs, Hypponen says.
Technical Sophistication
During his talk Hypponen outlined some of Confickter’s technical sophistication. In one version change – the worm has gone through five major revisions – the worm adopted the MD-6 cryptographic hash algorithm. Investigators estimate that MD-6 was only a month or so old when it was incorporated in Conficker, making the worm one of the earliest implementations of MD-6, he says.
Buffer Overflow
The next major revision of Conficker patched an MD-6 buffer-overflow vulnerability that was publicly announced about six weeks earlier, which means the criminals keep themselves in the loop with the latest advances, he says. (The patch they used was identical to the one issued by MD-6 creators.)
Disables Infected Machines
The worm avoids sending itself to domains owned by members of the Conficker Working Group, and it disables infected machines so they can’t reach sites where they might seek help.
F-Secure Help Site
Hypponen’s company set up a help site with a different domain name from its regular business site that included the term F-secure, and the next version of Conficker blocked it. The company changed the term to Fsecure with no hyphen, and the next revision blocked that, too, he says.
The worm had been propagating to eight top level Internet domains and the working group mustered enough cooperation to shut it down in all those domains, Hypponen says. The next version propagated to 116 domains, he says.
Strategy Weak
“These guys are very good in cryptography and code development,” he says, but maybe not so good about strategy, given the attention they drew to themselves. “They didn’t know better than to infect 10 million computers in a couple of days.” The goal of any botnet ought to be to remain hidden, not draw attention to itself, he says.
“They might have experience in another crime business but hadn’t run a botnet before. If they were more experienced, they’d know better.”
The Malady Lingers on
It would make sense, Hypponen says, for the Conficker gang to abandon its current botnet and build a new one that doesn’t get too big too fast and doesn’t draw a team of experts to fight it. “Maybe they already have,” he says.
Subscribe to:
Posts (Atom)