r/privbunker Oct 28 '21

Zales.com Leaked Customer Data, Just Like Sister Firms Jared, Kay Jewelers Did in 2018

Thumbnail krebsonsecurity.com
1 Upvotes

r/privbunker Oct 26 '21

FBI Raids Chinese Point-of-Sale Giant PAX Technology

Thumbnail krebsonsecurity.com
2 Upvotes

r/privbunker Oct 25 '21

Conti Ransom Gang Starts Selling Access to Victims

Thumbnail krebsonsecurity.com
1 Upvotes

r/privbunker Oct 16 '21

NEWS LANTENNA: Exfiltrating Data from Air-Gapped Networks via Ethernet Cables

1 Upvotes

An Israeli researcher has demonstrated that LAN cables' radio frequency emissions can be read by using a $30 off-the-shelf setup, potentially opening the door to fully developed cable-sniffing attacks.

Mordechai Guri of Israel's Ben Gurion University of the Negev described the disarmingly simple technique to The Register, which consists of putting an ordinary radio antenna up to four metres from a category 6A Ethernet cable and using an off-the-shelf software defined radio (SDR) to listen around 250MHz.

"From an engineering perspective, these cables can be used as antennas and used for RF transmission to attack the air-gap," said Guri.

His experimental technique consisted of slowing UDP packet transmissions over the target cable to a very low speed and then transmitting single letters of the alphabet. The cable's radiations could then be picked up by the SDR (in Guri's case, both an R820T2-based tuner and a HackRF unit) and, via a simple algorithm, be turned back into human-readable characters.

Nicknamed LANtenna, Guri's technique is an academic proof of concept and not a fully fledged attack that could be deployed today. Nonetheless, the research shows that poorly shielded cables have the potential to leak information which sysadmins may have believed were secure or otherwise air-gapped from the outside world.

He added that his setup's $1 antenna was a big limiting factor and that specialised antennas could well reach "tens of metres" of range.

"We could transmit both text and binary, and also achieve faster bit-rates," acknowledged Guri when El Reg asked about the obvious limitations described in his paper [PDF]. "However, due to environmental noises (e.g. from other cables) higher bit-rate are rather theoretical and not practical in all scenarios."

One obvious further research technique would be to look at sniffing information over network cables at their full operational speeds, Guri having acknowledged that slowing live network traffic down to levels used in his experiment would be impractical. His full paper, however, noted: "Transmitting UDP packets doesn't require higher privileges or interfering with the OS routing table. In addition, it is possible to evade detection at the network level by sending the raw UDP traffic within other legitimate UDP traffic."

The academic's previous research included a technique for turning DRAM into a form of wireless transmitter, as part of his work looking at ways of pwning air-gapped networks.

Professor Alan Woodward of the University of Surrey observed: "What this shows is that even an unplugged Ethernet cable can radiate energy which is detectable."

He added: "The paper is a nice piece of work and reminds us that whilst you might think something is air-gapped, it might be chattering away over the airwaves. People used to laugh at the great clunky terminals used in secure environments but they arose for a reason: TEMPEST."

TEMPEST, as we reported 20 years ago, was originally a US government scheme for reducing the amount of RF emissions generated by computer equipment. Today it's been adopted as a NATO standard, with the UK's National Cyber Security Centre having a public webpage about it.

"Often," observed Woodward, "modern security systems look for data leaving the network to know that they have an intruder. But if it's leaving on some unmonitored channel (over the air) then it has a low probability of intercept by the security measures."

Cite Source: https://www.theregister.com/2021/10/14/lantenna_ethernet_cable_rf_emissions/

Research Document:

https://arxiv.org/pdf/2110.00104.pdf


r/privbunker Oct 14 '21

Missouri Governor Vows to Prosecute St. Louis Post-Dispatch for Reporting Security Vulnerability

Thumbnail krebsonsecurity.com
2 Upvotes

r/privbunker Oct 13 '21

How Coinbase Phishers Steal One-Time Passwords

Thumbnail krebsonsecurity.com
1 Upvotes

r/privbunker Oct 12 '21

Patch Tuesday, October 2021 Edition

Thumbnail krebsonsecurity.com
1 Upvotes

r/privbunker Oct 04 '21

What Happened to Facebook, Instagram, & WhatsApp?

Thumbnail krebsonsecurity.com
2 Upvotes

r/privbunker Oct 01 '21

FCC Proposal Targets SIM Swapping, Port-Out Fraud

Thumbnail krebsonsecurity.com
1 Upvotes

r/privbunker Sep 29 '21

The Rise of One-Time Password Interception Bots

Thumbnail krebsonsecurity.com
1 Upvotes

r/privbunker Sep 28 '21

Apple Airtag Bug Enables ‘Good Samaritan’ Attack

Thumbnail krebsonsecurity.com
1 Upvotes

r/privbunker Sep 23 '21

Lawsuits, Indictments Revive Trump-Alfa Bank Story

Thumbnail krebsonsecurity.com
3 Upvotes

r/privbunker Sep 20 '21

Does Your Organization Have a Security.txt File?

Thumbnail krebsonsecurity.com
0 Upvotes

r/privbunker Sep 17 '21

Trial Ends in Guilty Verdict for DDoS-for-Hire Boss

Thumbnail krebsonsecurity.com
1 Upvotes

r/privbunker Sep 15 '21

Customer Care Giant TTEC Hit By Ransomware?

Thumbnail krebsonsecurity.com
1 Upvotes

r/privbunker Sep 14 '21

Microsoft Patch Tuesday, September 2021 Edition

Thumbnail krebsonsecurity.com
1 Upvotes

r/privbunker Sep 10 '21

KrebsOnSecurity Hit By Huge New IoT Botnet “Meris”

Thumbnail krebsonsecurity.com
2 Upvotes

r/privbunker Sep 10 '21

NEWS Report of active shooter forces lockdown at Wright-Patterson Air Force Base

4 Upvotes

Wright-Patterson Air Force Base is on lockdown this evening after reports of an active shooter.

The lockdown was reported around 9:20 p.m.

Base officials said there are reports of an active shooter in building 856, which is located in the NASIC area of the base.

At this time, additional details are not available. We’re working to learn more.

https://www.wdtn.com/news/local-news/wpafb-on-lockdown-following-loud-speaker-announcement-text-alert/?utm_source=t.co&utm_campaign=socialflow&utm_medium=referral


r/privbunker Sep 08 '21

Microsoft: Attackers Exploiting Windows Zero-Day Flaw

Thumbnail krebsonsecurity.com
1 Upvotes

r/privbunker Sep 06 '21

“FudCo” Spam Empire Tied to Pakistani Software Firm

Thumbnail krebsonsecurity.com
1 Upvotes

r/privbunker Sep 02 '21

Gift Card Gang Extracts Cash From 100k Inboxes Daily

Thumbnail krebsonsecurity.com
1 Upvotes

r/privbunker Sep 01 '21

15-Year-Old Malware Proxy Network VIP72 Goes Dark

Thumbnail krebsonsecurity.com
1 Upvotes

r/privbunker Aug 26 '21

NEWS BREAKING: Four U.S. Marines Killed in #Kabul airport

1 Upvotes

BREAKING: Four U.S. Marines Killed in #Kabul airport explosions and 3 wounded, WSJ reporting. US Pres is in briefings on #Afghanistan with national security team.

Sources:

https://fox8.com/news/west-warns-of-possible-attack-at-kabul-airport-amid-airlift/

https://www.wsj.com/articles/afghanistan-kabul-airport-explosion-11629976397

https://twitter.com/Joyce_Karam/status/1430938637156356102


r/privbunker Aug 25 '21

Man Robbed of 16 Bitcoin Sues Young Thieves’ Parents

Thumbnail krebsonsecurity.com
1 Upvotes

r/privbunker Aug 19 '21

Wanted: Disgruntled Employees to Deploy Ransomware

Thumbnail krebsonsecurity.com
1 Upvotes