DIY Plasma Gun


[Richard] took another shot at his battery powered tesla coils. He sent in his latest hand held plasma gun. He modified his battery powered tesla coil to work as a handheld. He added a large copper pad to the drill handle to couple the RF ground to the human torch holding it.. Sure, we’ve seen plenty of tesla lately, but who here wouldn’t want one? (Maybe the guy in the server room…)

All the parts needed are listed – just be sure you fully understand everything before you get into this one.

Back From Vegas Extra


I made it home after a long day of travel. Airport security let me through with my new home server – a 1U dual P3 800Mhz Compaq rackmount that I scored from the guys at UNIX surplus. Yes, it was my carry-on personal item.

Somehow I missed the MIDI tesla coil last month. Thanks to [skuhl] for sending it in. It’s a solid state coil that’s modulated to create one bad-ass midi box. The videos are worth checking out.

[martin] tells me that the Pentax k10d firmware has been hacked for polish menus. I’ll let you guys sort through it, I’m honestly too tired to deal with translating it right now.

[Alex] re-cased a macbook power supply to repair a slightly ripped out power cable. Those power supplies aren’t cheap, so it’s worth noting.

By the way, I’ve got one of the midnight research wicrawl CDs, so ask nice if you want me to put up a torrent.

Defcon 15: Wrap-up


Our friend [Alex] was a little late getting to our t-shirt free-for-all today, but I just found out why: He was writing a great wrap-up of the many Defcon talks he attended. It’s well worth your time and will give you an idea of the broad slice of info that’s covered at the convention. That picture is him repruhzenting for Hack-A-Day in Fast Company magazine.

Update: I’m finally getting caught up on my RSS feeds; check out Richard Bejtlich’s equally good summary of Black Hat: part 1 and part 2.

Shirts Are Gone, But We’ve Got Stickers


I’m pretty happy with our skybox event. [Eliot] and I’ve both got a good pile of stickers to give away, so ask us if you want ’em. It was great turn out for all the shirts we gave out. Thanks to [Eliot]s g-string water bottle, we raised $263 for the EFF. [Eliot]’s heading to CCC later, so hit him up for stickers while he’s across the pond.

Defcon 15: Exploiting Authentication Systems


[Zac Franken] gave a good talk on authentication systems. (Card readers, biometric systems, etc). After a good introduction to various access control systems, he demoed an excellent exploit tool. Rather than focus on the access mechanism, he exploited the lack of reader installation security. Most card readers are secured by a plastic cover and a pair of screws. Inside, the reader wires are vulnerable. [Zac] put together the equivalent of a keyboard sniffer for the reader wiring. With this little device in place, he was able to collect access codes and use them to exploit the reader authentication system.

The operation goes like this: Install the sniffer. Let it collect some codes. On return, [Zac] is able to use his own card to become a pseudo authenticated card owner, restrict and allow access to other cards. That’s it. No sneaking up behind people to read their cards, just a few minutes with a screwdriver.

He’s not releasing the design, simply because measures to prevent this type of intercept/control mechanism would be extremely costly.

Defcon 15: Hacking EVDO


[King Tuna]’s Hacking EVDO was a popular talk. Things are really just starting on this front. Now that some of the newer cards have unlocked firmware (probably thanks to the need for sofware update EVDO revisions), It’s now possible to edit the firmware. With the door open, people can start mucking around with ESN’s and we’ll probably see some ESN duplication exploits soon.