Remote Laser Security Camera Defeat

[John] sent in this cell phone activated rifle scope laser security camera blinder. The phone plays a tone when it receives a SMS message. The sound activates an audio controlled relay. (Not elegant, but it works) which powers a laser that’s been mounted to a rifle scope. The scope is used to align the laser with the target lens – on activation it’s supposed to blind the camera. Looks like a fun hack, even if the uses are a bit nefarious. (He left out a little detail that’ll make or break the project to keep things on the level, but it’s not that hard to figure out.)

CCCamp 2007: GSM A5 Cracking

Steve Schear and David Hulton gave a presentation on A5 cracking. A5 is the encryption employed on GSM cellphone networks between the handset and the tower (nowhere else in the network). To sniff the GSM band, they use the GNU radio USRP. GNU radio is a software defined radio project, which given some effort you should be able to both receive and transmit in any RF band. You could use it to broadcast digital television, track radio tags, or even mess with garage door openers. For their initial investigation they used a Nokia 3310 in trace mode to dump the initial frames. Using a box with at least 27 FPGA’s they plan on constructing a 6+ terabyte rainbow table (it’ll take a couple months). Once complete, any GSM conversation can be cracked in less than 5 minutes using a single FPGA. The Hackers Choice has more info on the USRP based GSM analyzer and what they did to crack A5.