Showing posts with label Tech. Show all posts
Showing posts with label Tech. Show all posts

How Attackers Can Use Radio Signals and Mobile Phones to Steal Protected Data

By Arsal Hussain   Posted at   2:54 AM   Technology No comments


Radio Signals Waves


Computers housing the world’s most sensitive data are usually “air-gapped” or isolated from the internet. They’re also not connected to other systems that are internet-connected, and their Bluetooth feature is disabled, too. Sometimes, workers are not even allowed to bring mobile phones within range of the computers. All of this is done to keep important data out of the hands of remote hackers.
But these security measures may be futile in the face of a new technique researchers in Israel have developed for stealthily extracting sensitive data from isolated machines—using radio frequency signals and a mobile phone.
The attack recalls a method the NSA has been secretly using for at least six years to siphon data in a similar manner. An NSA catalogue of spy tools leaked online last year describes systems that use radio frequency signals to remotely siphon data from air-gapped machines using transceivers—a combination receiver and transmitter—attached to or embedded in the computer instead of a mobile phone. The spy agency has reportedly used the method in China, Russia and even Iran. But the exact technique for doing this has never been revealed.
The researchers in Israel make no claims that theirs is the method used by the NSA, but Dudu Mimran, chief technology officer at the Israeli lab behind the research, acknowledges that if student researchers have discovered a method for using radio signals to extract data from hard-to-reach systems, professionals with more experience and resources likely have discovered it, too.
“We are doing research way behind people [like that],” he told WIRED. “The people who are doing that are getting a lot of money and are doing that [full time].”
Dubbed “AirHopper” by the researchers at Cyber Security Labs at Ben Gurion University, the proof-of-concept technique allows hackers and spies to surreptitiously siphon passwords and other data from an infected computer using radio signals generated and transmitted by the computer and received by a mobile phone. The research was conducted by Mordechai Guri, Gabi Kedma, Assaf Kachlon, and overseen by their advisor Yuval Elovici.
The attack borrows in part from previous research showing how radio signals(.pdf) can be generated by a computer’s video card (.pdf). The researchers in Israel have developed malware that exploits this vulnerability by generating radio signals that can transmit modulated data that is then received and decoded by the FM radio receiver built into mobile phones. FM receivers come installed in many mobile phones as an emergency backup, in part, for receiving radio transmissions when the internet and cell networks are down. Using this function, however, attackers can turn a ubiquitous and seemingly innocuous device into an ingenious spy tool. Though a company or agency may think it has protected its air-gapped network by detaching it from the outside world, the mobile phones on employee desktops and in their pockets still provide attackers with a vector to reach classified and other sensitive data.
The researchers tested two methods for transmitting digital data over audio signals but Audio Frequency-Shift Keying (A-FSK) turned out to be the most effective.
“[E]ach letter or character was keyed with different audio frequency,” they note ina paper released last week (.pdf) that describes their technique. “Using less than 40 distinct audio frequencies, we were able to encode simple textual data—both alphabetical and numerical. This method is very effective for transmitting short textual massages such as identifiers, key-stroking, keep-alive messages and notifications.”
The data can be picked up by a mobile phone up to 23 feet away and then transmitted over Wi-Fi or a cellular network to an attacker’s command-and-control server. The victim’s own mobile phone can be used to receive and transmit the stolen data, or an attacker lurking outside an office or lab can use his own phone to pick up the transmission.
“With appropriate software, compatible radio signals can be produced by a compromised computer, utilizing the electromagnetic radiation associated with the video display adapter,” the researchers write. “This combination, of a transmitter with a widely used mobile receiver, creates a potential covert channel that is not being monitored by ordinary security instrumentation.”
The researchers note that the chain of attack “is rather complicated,” but it’s not beyond the skills and abilities already seen in advanced attacks conducted by hackers in China and elsewhere. Or by the NSA.
Generally the most common method for infecting air-gapped machines is a USB flash drive or other removable media. Once one air-gapped machine is infected, the malware can spread to other machines on an air-gapped network. Data can be extracted the same way, though this is more of a challenge. The malware stores stolen data on the machine until a flash drive is inserted, at which point data is copied to the drive. When the flash drive is then inserted into another computer that’s connected to the internet, the data gets transmitted back to the attackers’ command-and-control center. This method takes time, however, since it requires the attacker to wait until someone inserts a flash drive into the air-gapped machine and carries it to an internet-connected machine.
AirHopper, however, doesn’t require repeated action like this once the malware is installed. An attacker only needs to get their malicious transmitter code onto the targeted machine and then either install the malicious receiver component on the victim’s mobile phone or use the attacker’s own mobile phone in the vicinity of the computer to receive the data and transmit it to the attacker’s command-and-control server. The malware can be programmed to store siphoned data on the infected machine for later transmission at specified hours or intervals. The researchers also devised methods for hiding the data transmission on the targeted machine to avoid detection, including transmitting data only when the monitor is turned off or in sleep mode and altering the FM receiver on the phone so that there is no audible tone when data is transmitted to it.
Although the distance for transmitting data from an infected computer to a mobile phone is limited—due to the limitations of the receiver in phones—attackers could use a stronger portable receiver, set up in a parking lot for example or installed on a drone flying overhead, to pick up data from greater distances.
There are other limitations, however. The proof-of-concept test allows for data to be transmitted at only 60 bytes a second—about a line of text per second—which limits the speed and volume at which attackers could siphon data. But Mimran notes that over time, a lot of sensitive data can still be extracted this way.
Table showing transmission time for various kinds of data. Courtesy of Cyber Security Labs.
Table showing transmission time for various kinds of data. Courtesy of Cyber Security Labs.
“We can take out whatever we want,” he told WIRED. “That only depends on the malicious software that resides on the computer. If it is a keylogger, then you can take out whatever the user types.”
A 100-byte password file takes 8-10 seconds to transmit using their method, and a day’s worth of keystrokes takes up to 14 minutes to transmit this way. But a document just .5 megabytes in size can take up to 15 hours to transmit.
Extracting documents “would be very slow and it will take a long time,” Mimran acknowledges, “but this [demonstration] is just a proof-of-concept. I guess the bad people can make it more sophisticated.”
Indeed, the NSA catalogue of surveillance tools leaked last year, known as the ANT catalogue, describes something called the Cottonmouth-I, a hardware implant that resembles an ordinary USB plug except it has a tiny transceiver, called the HowlerMonkey, embedded in it for extracting data via RF signals. According to theNew York Times, which published additional information about the Cottonmouth-I, the transceiver transmits the stolen data to a briefcase-sized NSA field station or relay station, called the Nightstand, which can be positioned up to eight miles away. Once the data is received by the relay station, it’s further transmitted to the NSA’s Remote Operations Center. Available since 2009, the Cottonmouth-1 is sold in packs of 50 for about $1 million.
This method of data extraction may have been used in Iran to siphon intelligence about the nuclear program there, the Times reports—perhaps in preparation for the Stuxnet attack, which sabotaged computers controlling centrifuges used to enrich uranium gas in Iran.
A USB plug, however, requires physical access to a targeted computer in the field or it requires the victim to unwittingly insert the USB plug into the computer before the transmission can occur. An alternative method to this, the leaked document notes, is embedding tiny circuit boards in the targeted computer to do the transmission. One way to compromise the machine would be to intercept new equipment enroute to a customer so that it arrives to the victim already equipped to transmit stolen data. According to the document published by the Times, the RF transceiver can also be used to implant malware on a targeted system, not just extract data from it.
Radio frequency hacks are difficult to mitigate, short of physically insulating computers and cables to prevent emissions from being picked up by receivers. This may be practical for military and other classified facilities to do, but not for commercial companies that are trying to protect sensitive data from such attacks. Prohibiting mobile phones from work areas will not help, since outside receivers can be used in place of mobile phones to extract data.
“We’re disclosing there is this danger,” Mimran says, “but the biggest problem that we are really working hard on is finding mitigation for that. From preliminary results, it’s not easy.”

Source: www.wired.com

5 Discoveries Made By the Large Hadron Collider (So Far)

By Unknown   Posted at   7:09 AM   Technology No comments
Sometimes the machine charged with facilitating head-spinning discoveries needs a little downtime. Here, a maintenance worker inspects the LHC tunnel on Nov. 19, 2013-Wired Hub
At times, it's the little things that drive you crazy. By the early 20th century, physicists seemed to have the universe pretty well sewn up, between Newtonian gravity and Maxwell's electromagnetic equations. There was just one nagging problem: how to explain radioactivity. Addressing it sparked a scientific revolution that revealed the amazing truth about little things: Sometimes they contain universes.
Particle physics and quantum mechanics, the sciences of the truly tiny, brought physics two more fundamental forces and a menagerie of strange elementary particles, but after the 1970s little remained but to test and refine the dominant theory, the standard model. Another 30 years' worth of subatomic specks churned out by accelerators and colliders filled key blanks, yet many questions remained: Why did some particles have mass while others didn't? Could we unify the four fundamental forces or make general relativity and quantum mechanics get along?
Would one of these dangling threads spark another revolution? Finding out would take a bigger, more powerful particle collider than ever before, a 16.8-mile (27-kilometer) ring of superconducting magnets colder than outer space, capable of slamming particles together at near light speed in an ultrahigh vacuum. On Sept. 10, 2008, this $10 billion Large Hadron Collider (LHC), the collaborative effort of hundreds of scientists and engineers globally, joined the European Organization for Nuclear Research (CERN) campus of accelerators and soon broke particle collision records.
Let's look back at what we've learned so far, starting with the most famous discovery of all.

Message Queue Telemetry Transport - Communication

By Unknown   Posted at   6:58 AM   Technology No comments
Have you heard about MQTT?
MQTT, which stands for Message Queue Telemetry Transport, is a publish or subscribe, lightweight messaging protocol designed for low-bandwidth communications with high latency. It is intended to be primarily used by machine to machine (M2M) or the Internet of Things (IoT) and telemetry data communications.
MQTT
The protocol was invented by Dr. Andy Stanford-Clark, an IBM Distinguished Engineer and Master Inventor, and Arlen Nipper of Arcom (now Eurotech) in 1999. You can see them talking about the protocol here.
Although the protocol is considered simple and lightweight, it can ensure reliability and some degree of assurance of delivery. You can find the MQ Telemetry Transport V3.1 Protocol Specification at the IBM developerWorks site.
For more information, there is an interesting IBM Redbooks publication Building Smarter Planet Solutions with MQTT and IBM WebSphere MQ Telemetry.
The MQTT FAQ is also a good resource for beginners.
Mobile applications and MQTT
With all these features, MQTT is becoming the de facto standard and the ideal protocol for all M2M and IoT applications, where we have many devices and sensors sending high volumes of messages continuously. However, MQTT is also being used by a growing number of mobile applications nowadays, mainly because MQTT seems to be a very smart choice for a protocol, as it demands fewer resources compared to many other protocols currently available for mobile application development.
One big example of a well-known application that uses MQTT is the Facebook Messenger client, and you can find out about its usage of the MQTT protocol here.
Also, there are many Android applications and Arduino applications starting to use MQTT as the main protocol.
MQTT and Eclipse tools
The website eclipse.org also supports MQTT, and it hosts and supports the Paho project.
The Eclipse Paho open source messaging project was proposed in late 2011 and is currently an incubator Eclipse project.
The initial contributions came from IBM as well as Eurotech in the form of Java and C clients. A Lua MQTT client was also contributed shortly after the project went live, and an MQTT JavaScript client is coming soon.
Other messaging protocols
While there are other messaging protocols, and while MQTT has been around for years now, it seems it is gaining traction as the de facto standard for M2M and IoT, as a recently created OASIS MQTT Technical Committee is now working on a common, standardized version of MQTT supported not only by IBM and Eurotech but also by Red Hat, Cisco and other companies.
So as it seems that MQTT is really becoming the definitive protocol for a Smarter Planet, would you use MQTT on your next mobile application? Do you see any advantages of using MQTT in more common mobile applications beyond M2M and IoT ones?
Let me know your opinion. Please provide feedback in the comments section or connect with me on Twitter.

Fingerprint scanner or passcode: Which is more secure for the enterprise

By Unknown   Posted at   6:50 AM   Technology No comments
When Apple launched the Touch ID fingerprint scanner on the new iPhone, the race was on to hack it. A crowd-funded website was set up, istouchidhacked.com, where people pledged money as incentive for the first person who could upload a video demonstrating the hack. It took only a few days for a hacking team called the Chaos Computer Club to do just that.
Fingerprint scanner or passcode
It took a much less sophisticated effort to learn that the passcode on my iPad had its own set of flaws. One evening I caught my four-year-old son picking up my iPad, no doubt in search of cartoons. To my astonishment he seamlessly entered my four-digit passcode and within seconds had the Netflix app streaming an episode of Curious George. I’d never told him my passcode; he’d simply watched me enter it time after time and had it memorized.
Trying to keep kids away from too many cartoons is one thing, but unauthorized access to a mobile device containing confidential enterprise data can be a whole lot more serious. So what’s the best way to protect your enterprise data?
Passcodes
Almost every smartphone can be secured with a four-digit passcode, which must be entered each time the phone is used or after a period of inactivity. Despite the almost universal availability of this feature, around 64 percent of mobile device users don’t use any form of screen lock. Of those that do use a passcode, about two-thirds use a four-digit pin, while the remainder use a longer pin, a password or an unlock pattern.
As my son demonstrated, a four-digit passcode can be relatively simple to break. A few glances at somebody unlocking their phone, and you’ll likely be able to deduce their passcode. A four-digit passcode is also susceptible to brute-force attacks (trying different combinations of passcodes until one works). It’s often not very difficult. According to a Time study, the most popular passcode is “1234,” followed by “0000.” Earlier versions of the iPhone and iPad could have their passcode cracked in under two minutes using malicious software.
Longer passcodes—actually passwords, as they consist of letters, numbers and other characters—make brute force attacks harder. But these suffer from the same deficiencies as passcodes (somebody can simply look over your shoulder to see what you entered), and often the user will write the password down so they will remember it, bringing more security concerns.
Fingerprint scanner
The Touch ID scanner on the iPhone 5s was one of the first fingerprint scanners to be added to a mobile device. It’s likely we’ll see this feature appearing on many more phones soon. Hacking Touch ID generated a lot of good headlines but did little to faze most security professionals.
Let me step you through the process. First, locate a pristine fingerprint that is authorized to unlock the phone (by itself not easy to find). Next, lift the print using a special type of glue and fingerprint powder to transfer the fingerprint to tape. Assuming you didn’t smudge the print you’re ready to start creating the fake fingerprint—with suitable experience it will take you a couple of hours and about $1,000 of equipment. Now give it a try, but you’d better cross your fingers as you only get five attempts before Touch ID will insist that you enter the passcode instead.
Clearly the everyday phone thief is not going to unlock your phone this way. Does that make fingerprint scanners safer than passcodes? Absolutely not—on the iPhone 5s you can at any point choose to unlock your phone with a passcode instead of the Touch ID sensor. So a fingerprint scanner is an alternative to passcodes but not a replacement.
Choosing the best option
Ultimately when it comes to security there is rarely a right answer. Nothing is completely secure. But some options are better than others. A four-digit passcode is better than no screen lock at all. A longer alphanumeric password or fingerprint scanner is better still.
The key is to ensure that whichever security policy you pick is enforced on all mobile devices where your enterprise data is stored. That’s where a mobile device management tool such as IBM Endpoint Manager for Mobile Devices can help. With this you can ensure the correct screen unlock policy is applied (and even if fingerprint scanners such as Touch ID are permitted). And should a mobile device get lost or stolen you can remotely wipe the device to protect your enterprise data.
And most important of all, beware of sharp-eyed children.

Charge Your Cell Phone By Your Clothing You Wear

By Arsal Hussain   Posted at   4:59 PM   Technology No comments
Clothing Can Charge Cell Phone
One of the future inventions that could greatly impact our lives are nanoribbons. Rubber films developed by engineers at Princeton University could power mobile devices and other electronic devices.
The silicone sheets are embedded with ceramic nanoribbons (piezoelectric ribbons) that generate electricity when flexed, converting mechanical energy to electrical energy.
Materials made of this material, such as shoes, would harvest electrical energy created from walking and power everything from an ipod to a pacemaker.
The nanoribbon strips are so narrow that 100 fit side-by-side in a space of a millimeter. The strips are then embedded into clear sheets of silicone rubber to create a chip.
These sheets could be woven into fabric and placed against any moving area on the body to create electricity.
For example, a vest made from this material could take advantage of breathing motions to generate energy.
Nanoribbons are highly efficient in converting about 80% of mechanical power into electricity.
Source: princeton.edu/main/news/research

Water Fueled Car – Green Enviroment

By Arsal Hussain   Posted at   4:54 PM   Technology No comments

When we look at alternative energy portfolio of most carmakers, it seems there is only one way to go – batteries. But Hyundai has chosen quite a different path with its Tucson Fuel Cell SUV. When it launches in the U.S., Tucson will be the first mass-produced water powered car.
Hyundai’s rollout will be quite limited, mainly due to almost non-existent hydrogen fuel infrastructure. The SUV will be available only in selected dealerships in Southern California, which are all close enough to Hyundai’s sources of hydrogen, including one waste water treatment plant. The owners of this Tucson will be able to fuel at these stations for free (there is only seven of them). It takes less than 10 minutes to fill-up a full tank of hydrogen that will last for about 300 miles.
Hyundai claims Tucson has longer range than most modern EV’s and is also more environmentally friendly. It definitely won’t be blamed for city smog – it emits only water vapour.

Hyundai Tucson Fuel Cell – Water Powered Car

Range: 300 miles
Top speed: 100 mph
Lease terms: $500/month; $3000 down

Night Vision Glasses Going To Obsolete! - New Technology

By Arsal Hussain   Posted at   4:50 PM   Technology No comments

Night vision contact lenses for future super-soldiers will replace current night vision glasses

Today, soldiers have to wear bulky night vision glasses to see in the dark. But those can be soon replaced by a much smaller solution, which utilizes contact lenses.
Using a material called graphene, Ted Norris and Zhaohui Zhong from the University of Michigan have developed a super-thin infrared light sensor that could be applied onto contact lenses or night vision glasses to improve their performance. Graphene is unique in its ability to absorb infrared rays and transform them into electrical signals, almost the same way that silicon chips in digital cameras absorb visible light.
To get a night-vision image, the trick was to insert an insulating layer between two graphene layers and then adding electric current. As infrared light reaches the lens, the electrical reaction is strengthened to the point where it can provides a visible image.
“If we integrate it with a contact lens or other wearable electronics, it expands your vision. It provides you another way of interacting with your environment” says Mr. Zhong.
The technology is still far from finished though and for today the only option to see in dark is by using night vision glasses. The scientists have years to go until they can attain enough light sensitivity and the ability to work in wide range of temperatures.
Besides initial support from National Science Foundation, the project needs governmental and commercial partners and supports to move forward. The teams say the lenses could have wide applications in areas like photography or even in car windshields.
Night Vision Glasses Will Be Soon Replaced
Night Vision Glasses Will Be Soon Replaced By  Night Vision Contacts


Seven Secret Weapons Never Completed - Pictures

By Arsal Hussain   Posted at   4:40 PM   Technology No comments
Mankind is in a never-ending arms race against himself, other nations, religions and whoever is deemed a threat to existence. This leads governments to spend enormous amounts of money on even the craziest of ides, often leading to ridiculous weapons that eventually disappoint or simply never get developed.

Lunar Nuclear Bomb

lunar nuclear bomb
Also known as Project 119-A, the plan was to Nuke the moon  to boost public morale in the United States after the Soviet Union took an early lead in the Space Race. This was never carried out, because they figures putting a man on the moon was better than trying to blow it up.

Iceberg Aircraft Carrier

Iceberg Aircraft Carrier
Also known as Project Habakkuk, the Brits developed a plan during World War II to construct an aircraft carrier out of pykrete (a mixture of wood pulp and ice). It took them some time, but developments in the war effort and realizing what a huge waste of resources it might be sunk the idea.

The Flying Dorito

Flying Dorito
The A-12 Avenger II was also known as the flying Dorito. It was to be an all-weather, carrier-based stealth bomber replacement for the Grumman A-6 Intruder in the United States Navy and Marine Corps; The development of the A-12 was troubled by cost overruns and several delays, eventually being cancelled in 1991 after wasting more than $5 billion on the project.

Soviet Doomsday Device

Doomsday Bomb
Some say it’s a myth, but in the early 1990s several former high-ranking members of the Soviet military and the Central Committee of the Communist Party in a series of interviews to the American defense contractor BDM admitted the existence of the Dead Hand, making somewhat contradictory statements concerning its deployment.
What is it? Possibly still fully operational, a nuclear-control system that can automatically trigger the launch of the Russian Intercontinental ballistic missiles (ICBMs) if a nuclear strike is detected by seismic, light, radioactivity and overpressure sensors, creating a fail-deadly deterrence.

The Un-landable Plane

XFV Salmon
Instead of having an aircraft take off only from carriers, the US government wanted fighters on all their ships. From that, the XFV Salmon was born, a plane with landing gear on its tail. After development and some thinking, the plan to have a fighter jet on every ship was scrapped, because pilots couldn’t land backwards. The jet was also much slower than other contemporary fighters and was too complicated to fly.

Intruder From the Future

Intruder From the Future
Imagine a bomber, designed to carry atomic bombs, that can fly at an altitude of 15 miles and three times the speed of sound. The B-70 Valkyrie was supposed to be the aviation dream from the future, but while it was developed, the improvements of high-altitude surface-to-air missiles, the change to low-level penetration bombing, the program’s high development costs, and the introduction of intercontinental ballistic missile (ICBMs) led to the cancellation of the B-70 program in 1961. Two prototypes were eventually used; one of them crashed following a midair collision in 1966.

The Thunderscreech


The XF-84H was an experimental turboprop aircraft, powered by a a turbine engine that was mated to a supersonic propeller. Too many aerodynamic decencies and the fact that it was the loudest aircraft ever made; the sound of its engine starting up could be heard 25 miles away, along with blowing out eardrums and causing severe nausea among the ground crews led to its cancellation.

11 Awesome War Spy Gadgets By KGB - Pictures

By Arsal Hussain   Posted at   4:36 PM   Technology No comments
These Gadget Are So Cool Not Meant To Be Ignored Check Them Out...

Poison Dart-Shooting Umbrella

Poison Dart Shooting Umbrella

Cyanide Gun

Cyanide Gun
A gun that fires a duel cyanide charge, killing almost instantly.

Decoder Lock Picks

Decoder Lock Picks

Coat Jacket Camera

Coat Jacket Camera

Shoe Tracker

Shoe Tracker
A transmitting device inside of a heel, used for tracking.

Wristwatch Camera

Wristwatch Camera

Authentic KGB Disappearing Ink Pen

KGB pen

Glove Pistol

Glove Pistol
Originally developed by the US Navy, this was later copied by the Soviets. In order to fire the pistol, the wearer pushed the plunger into his target’s body.

Hollow Coin to Conceal Microfilm

Hollow Coin

Lipstick Gun

Lipstick Gun

The Spy Bolt

Spy Bolt
That’s how real spies deliver messages or certain, tiny, valuables.

Back to top ↑
Connect with Us

    Powered by Blogger.

    Follow Me

    Translate

    Followers

    Popular Posts

    Video Of Day

What they says

A Quick Brown Fox Jumps A Very Lazy Dog
© 2013 Wired Hub . WP Mythemeshop Converted by Bloggertheme9
Blogger Website . Proudly Powered by Blogger .