22C3 Day 10 And 11 Round Up

bb
Now that the CCC is over, we finally dug ourselves out of a ginormous pile of cables (Kabelsalat ist gesund!) to bring you this round up post about the best stuff from the last two days of the con.

First up on day 10 was I See Airplanes!, Eric Blossom’s excellent speech on creating hardware for making homebrew radars and software using the GnuRadio project. He uses bistatic passive receivers in the 100 MHz range doing object detection using other peoples’ transmitters. The project has a lot yet to accomplish including the use of helical filters (if there are any antenna freaks reading this, contact Eric, he’s looking for a bit of help).

Next on the third day we attended Ilja van Sprundel‘s huge fuzzing  extravaganza. Fuzzers generate bad data that is designed to look like good data and will hopefully break something in an interesting way. Our fav part? When the list of irc clients broken by his ircfuzz tool was so long he had to use 10pt font to get it all on one slide (see slide 53)! His paper can be found here and the slides here.

We then wandered to Harald Welte‘s talk on hacking the Motorola EZX series phones (which we’ve reported on here before). In case you forgot, the EZX series has a linux kernel. Incidentally the phone runs lots of stuff it really doesn’t need (like glibc, 6 threads for just sound processes, and even inetd). He presented the project for the first time in an official context since we saw him at 0Sec in October. Apparently lots of kinks have been worked out and there’s an official code source tree here.

The clincher for day 11 was FX and FtR of Phenoelit‘s semi-controversial talk on Blackberry security (covering both handheld devices and server based RIM products). This talk was a bit of a wake up call for RIM and thus the slides are still not available online so keep a sharp eye out for the video when it’s released by the CCC.

Also available from the CCC are the full proceedings in a downloadable pdf (also available in paper format for you physical-space-doodle-in-the-margin freaks).

Continue reading “22C3 Day 10 And 11 Round Up”

RFID Based Spatial Address Book

rfid

The march of reader hacks continues and I couldn’t be happier. [Timo] has been experimenting with a prototype Nokia 3220 Near Field Communication phone. The phone features an RFID reader/writer (and an odd logo that seems to combine a Dreamcast with RSS). The phone’s Service Discovery application reads RFID tags that it encounters. The read data can trigger a variety of actions: dial a number, send a pre-defined SMS, or load a URL. Timo placed an array of RFID tags under the surface of his desk. He then recorded different actions to each tag and placed a corresponding Post-It note liable on the desk surface above each tag. So, by resting the phone on “call Jack” the phone would load the number. When he walks into the office he can set the phone down on “I’m in the office” and a text message will be sent. He’s got some interesting thoughts on this system. It made him very aware of where he had to set the phone when he didn’t want it to do anything. Timo also wonders how your acquaintances would feel if they found themselves ranked across your desktop.

Continue reading “RFID Based Spatial Address Book”

The Magic Phone: Take Two

hadmagicphone

We’ve posted Part Two of the Magic Phone How-To over at Engadget. In this Installment, we show you the process behind creating the custom circuit that will live inside the rotary phone. This circuit is as small as possible by making it two-sided and by using surface mount components. Part One of the How-To covered number pad matrix decoding on just about any phone or number pad.

Continue reading “The Magic Phone: Take Two”

High Altitude Linux Take 2

high altitude

[jcoxon] was inspired by the original Linux weather balloon project. His Pegasus 1 reached an altitude of 66,585ft and took over 600 pictures. The flight logging system is based on the Gumstix waysmall computer system. It captures data from the GPS receiver and controls two cameras. There are photos from both a downward facing camera and a side facing camera. Periodically the last three GPS entries are sent to Jame’s cellphone via SMS; this made recovering the payload a lot easier. There is already a second baloon planned.

Continue reading “High Altitude Linux Take 2”

Hacking The Motorola A780

A780

The Motorola A780 is a Linux based quad-band GSM phone. Kernel hacker Harald Welte has picked up one of these phones and started poking around in the system. The first thing of note is that the phone doesn’t use the typical lightweight tools found in most embedded systems. Instead of busybox or uClibc it uses their heavier counterparts. The phone also has a 2.4 kernel and switching to the 2.6 kernel is a long term goal. Harald has successfully built a compatible toolchain and has netfilter/iptables running on the A780. It should be possible to construct a firewall between the GPRS and the USB connection. Other hackers are working on adding the stock Linux bluetooth codebase; this may be one of the first phones supporting A2DP stereo headsets. The future looks bright for hackers with new exploitable features emerging everyday like JTAG pads for both processors and debugging callbacks built into the factory code. Harald Welte will be presenting these and future discoveries at the 22nd Chaos Communication Congress in December.

Continue reading “Hacking The Motorola A780”

HOW-TO: Make A Nokia Pop Port To Female Mini Jack With Volume Control

nokia popport
When Nokia announced their music player capable phones they neglected to mention the lack of support for external headphones. Since the release of the 6230 and its related family with mp3/aac playback support, many disgruntled users have made their own home-brew cables to plug in headphones. Today we will show one such mod for the Nokia HDS-3 cable. Our mod includes an analog volume dial integrated into the push to talk unit. The HDS-3 cable ships with the 6230 and other Nokia phones capable of stereo playback.

by Fabienne Serriere

Continue reading “HOW-TO: Make A Nokia Pop Port To Female Mini Jack With Volume Control”

Nextel Serial Charging For Always-on GPS

nextelnextelnextel

Tim uses his Nextel phone as a GPS receiver for his laptop. This drains the battery on the phone much quicker than usual. He decided to jump power into the system so the phone would actually charge when it is plugged in. The power is tapped from the 5 volts coming from the USB to RS-232 adapter. A full schematic and list of phones that this should work on are available at the site.

Continue reading “Nextel Serial Charging For Always-on GPS”