Ethical Hacking

Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package.
Computer Forensics Training at InfoSec Institute

Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors.




Network Security FullDisclosure
[Top] [All Lists]

[Full-disclosure] Clever crooks can foil wiretaps, security flaw in tap

Subject: [Full-disclosure] Clever crooks can foil wiretaps, security flaw in tap technology
Date: Wed, 30 Nov 2005 10:48:02 -0800
heheheh

http://seattlepi.nwsource.com/national/250215_wiretap30.html

'The technology used for decades by law enforcement agents to wiretap
telephones has a security flaw that allows the person being wiretapped
to stop the recorder remotely, according to research by computer
security experts who studied the system. It is also possible to
falsify the numbers dialed, they said.

Someone who is being wiretapped can easily employ these "devastating
countermeasures" with off-the-shelf equipment, said the lead
researcher, Matt Blaze, an associate professor of computer and
information science at the University of Pennsylvania.

"This has implications not only for the accuracy of the intelligence
that can be obtained from these taps but also for the acceptability
and weight of legal evidence derived from it," Blaze and his
colleagues wrote in a paper that will be published today in Security &
Privacy, a journal of the Institute of Electrical and Electronics
Engineers.'

---

To defeat wiretapping systems, the target need only send the same
"idle signal" that the tapping equipment itself sends to the recorder
when the telephone is not in use. The target could continue to have a
conversation while sending the signal.

The tone, also known as a C-tone, sounds like a low buzzing and is
"slightly annoying," Blaze said, "but would not affect the voice
quality" of the call. "It turns the recorder right off," he said. (The
paper can be found at www.crypto.com/papers/wiretapping/.)

---

in band signalling++
_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/

<Prev in Thread] Current Thread [Next in Thread>