Shmoocon 2006: VoIP WiFi Phone Security Analysis

shmoocon

Shawn Merdinger gave a presentation on his personal research project covering the security of VoIP WiFi phones. For his initial investigation he is employing a “level one” methodology. These would be attacks from a low to medium skilled hacker, a hacker’s “first look” at the device: looking for open ports, finding developer left-overs, and misusing features. One thing that was common across all phones is how easily they succumb to DOS attacks. He talked about the issues with several specific phones. Many left open port 17185, which is the VxWorks database debug port. The favorite was the Clipcomm CPW-100E which provides unauthenticated access to debugging accounts letting you read call logs and even place calls, turning it into a remote listening device. You can hear Shawn talk about his project on Blue Box Podcast #13. Blue Box also has a copy of Shawn’s detailed slides. Here’s a list of the new phone security threats released a Shmoocon.

Continue reading “Shmoocon 2006: VoIP WiFi Phone Security Analysis”

Shmoocon 2006: Anonym.OS: Security And Privacy, Everywhere You Go

shmoocon

kaos.theory’s Anonym.OS was probably the most widely covered project to come out of this year’s Shmoocon. This was spurred by Wired’s article which was picked up by Slashdot, Ars, and others. Anonym.OS is a live CD based on OpenBSD 3.8 that provides anonymous internet access and aims to be usable by anyone. On the network it appears as a Windows machine to hide among the majority of internet users. The CD does several things to protect the user, starting with secure operating system. The main component is Tor, which we’ve covered before, All traffic is sent through Tor and since the disk uses local DNS look-up you don’t have to worry about DNS requests leaking. I really like this project because kaos.theory has done all of the dirty work like setting up really strict packet filter rules and forcing everything through Tor. Of course, I would have liked it even if it was just an OpenBSD live CD that used Fluxbox. The only two apps it has now are Firefox and GAIM. They are taking suggestions for what to add in the future and will probably be adding cryptographic filesystem support so that users can save safely. If they added Gimp and a hard drive install script I would be using this at every con I attended.

Continue reading “Shmoocon 2006: Anonym.OS: Security And Privacy, Everywhere You Go”

RoboMaid Robot

robomaid

The RoboMaid (warning sound) really has nothing robotic about it. The website proclaims “smart sensor technology” and “programmable”. It’s actually just a Weasel Ball in a cage. Reader [Perry Cain] decided to keep the cage and add some real electronic brains if the form of a Prallax kit. The robot has 5 IR pairs: 2 in front, 2 on the side and one in the back. He says it works pretty well, but he hasn’t added detection to keep it from going down the basement steps yet.

Continue reading “RoboMaid Robot”

How-to: PSP 2.00-2.60 Homebrew With ELoader

eloader
Thanks go to sometimes hacker, C.K. Sample, III, author of PSP Hacks for contributing this how-to.

So you’ve heard about this homebrew thing that all the cool kids have been doing, but you have already upgraded to version 2.6 of the firmware so that you could play all the latest and greatest games on the PSP. Fortunately for you, some very diligent hackers have been working round the clock to discover ways to get around the limitations put in place by the latest firmware.

The solution isn’t in the form of a downgrader, but rather in the form of an eLoader (EBOOT loader) that lets you use Grand Theft Auto: Liberty City Stories to run homebrew on a PSP with version 2.0, 2.01, 2.5, and 2.6 of the firmware. Not all homebrew will run via this method, but there is a rather easy to read compatibility chart and I’m sure more things will begin working in future releases of the eLoader.

To help you along in your quest to homebrew, here’s a step by step (with pictures!) guide to using the eLoader:

Continue reading “How-to: PSP 2.00-2.60 Homebrew With ELoader”

Shmoocon 2006: A Young Gentleman’s Primer On The Reading And Emulation Of Magnetic Cards

shmoocon

If you payed attention to the comments on our story about a Magnetic stripe card emulator you would have seen Abend announce his Shmoocon talk. It was a pretty interesting talk about the basics of mag cards and some of the tricks employed by companies to obfuscate the data. To get the feel for the talk I suggest you listen to SploitCast #004 which features Abend as a guest. That combined with his slides and tools should give you a fine crash course in the technology. He also recommend’s Count Zero’s “A Day in the Life of a Flux Reversal“. Billy Hoffman, who did the Covert Crawler, has also worked with mag stripes and developed the program Stripe Snoop.

Continue reading “Shmoocon 2006: A Young Gentleman’s Primer On The Reading And Emulation Of Magnetic Cards”

RC Paintball Tank Built From Printer Parts

rc paintball tank

You could spend hours exploring the R/C Tank Combat website, so we will highlight one project to get you started. Steve Tyng built this awesome model based on the Russian T34-85 tank. The body is all wood an uses stainless steel axles salvaged from a printer. The original drive system used 24-volt DC motors from dot-matrix printers, but they’ve since been replaced. The most tedious part of this build appears to be the tracks which are made from a treadmill belt sandwiched between wooden blocks. The turret rotates and the barrel can elevate as well. The entire turret package can be easily removed. Inside is a cheap paintball gun that has been lightened and has a small RC servo bolted on to depress the trigger. Definitely have a look at the Maryland Attack Group’s other projects like their field artillery and armoured cars.

[thanks Jason]

Continue reading “RC Paintball Tank Built From Printer Parts”

Shmoocon 2006: Wi-Fi Trickery Or How To Secure, Break And Have Fun With Wi-Fi

shmoocon

Franck Veysset and Laurent Butti, both from France Telecom R&D, presented several proof-of-concept tools at Shmoocon that use 802.11 raw injection. The first is Raw Fake AP. The original Fake AP is a script that generates thousands of fake access points. It is easy to spot because of tell-tale signs like the BSSID showing the AP has only been up for a couple milliseconds. Raw Fake AP tries to generate legitimate access points by modifying BSSIDs and sending beacon frames at coherent time intervals.

Raw Glue AP is designed catch probe requests from clients scanning for a preferred ESSID. It then tries to generate the appropriate probe responses to keep the client occupied.

Raw Covert was the final tool. It creates a covert channel inside of valid ACK frames. ACK frames are usually considered harmless and ignored by wireless IDS. The tool is really basic right now, there is no encryption and it doesn’t handle dropped frames.

Continue reading “Shmoocon 2006: Wi-Fi Trickery Or How To Secure, Break And Have Fun With Wi-Fi”