Go Back   Velocity Reviews > Newsgroups > Computer Security
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply

Computer Security - Snooping through the power socket

 
Thread Tools Search this Thread
Old 07-13-2009, 08:01 PM   #1
Default Snooping through the power socket




Power sockets can be used to eavesdrop on what people type on a
computer.

Security researchers found that poor shielding on some keyboard cables
means useful data can be leaked about each character typed.

By analysing the information leaking onto power circuits, the
researchers could see what a target was typing.

The attack has been demonstrated to work at a distance of up to 15m, but
refinement may mean it could work over much longer distances.

Hotel attack

"Our goal is to show that information leaks in the most unexpected ways
and can be retrieved," wrote Andrea Barisani and Daniele Bianco, of
security firm Inverse Path, in a paper describing their work.

The research focused on the cables used to connect PS/2 keyboards to
desktop PCs.

Usefully, said the pair, the six wires inside a PS/2 cable are typically
"close to each other and poorly shielded". This means that information
travelling along the data wire, when a key is pressed, leaks onto the
earth (ground in the US) wire in the same cable.

The earth wire, via the PC's power unit, ultimately connects to the plug
in the power socket, and from there information leaks out onto the
circuit supplying electricity to a room.

Even better, said the researchers, data travels along PS/2 cables one
bit at a time and uses a clock speed far lower than any other PC
component. Both these qualities make it easy to pick out voltage changes
caused by key presses.

A digital oscilloscope was used to gather data about voltage changes on
a power line and filters were used to remove those caused by anything
other than the keyboard.

"The PS/2 signal square wave is preserved with good quality... and can
be decoded back to the original keystroke information," wrote the pair
in a paper describing their work.

They demonstrated it working over distances of 1, 5, 10 and 15m from a
target, far enough to suggest it could work in a hotel or office.

"The test performed in the laboratory represent a worst case scenario
for this type of measurement, which along with acceptable results
emphasizes the feasibility of the attack on normal conditions," they
added.

The pair said their research was "work in progress" and expect the
equipment to get more sensitive as it is refined.

The attack is due to be demonstrated at the Black Hat conference that
takes place in Las Vegas from 25-30 July.

Ref: http://news.bbc.co.uk/1/hi/technology/8147534.stm






~BD~
  Reply With Quote
Old 07-13-2009, 09:42 PM   #2
David H. Lipman
 
Posts: n/a
Default Re: Snooping through the power socket
From: "~BD~" <>



| Power sockets can be used to eavesdrop on what people type on a
| computer.

| Security researchers found that poor shielding on some keyboard cables
| means useful data can be leaked about each character typed.

| By analysing the information leaking onto power circuits, the
| researchers could see what a target was typing.

| The attack has been demonstrated to work at a distance of up to 15m, but
| refinement may mean it could work over much longer distances.

| Hotel attack

| "Our goal is to show that information leaks in the most unexpected ways
| and can be retrieved," wrote Andrea Barisani and Daniele Bianco, of
| security firm Inverse Path, in a paper describing their work.

| The research focused on the cables used to connect PS/2 keyboards to
| desktop PCs.

| Usefully, said the pair, the six wires inside a PS/2 cable are typically
| "close to each other and poorly shielded". This means that information
| travelling along the data wire, when a key is pressed, leaks onto the
| earth (ground in the US) wire in the same cable.

| The earth wire, via the PC's power unit, ultimately connects to the plug
| in the power socket, and from there information leaks out onto the
| circuit supplying electricity to a room.

| Even better, said the researchers, data travels along PS/2 cables one
| bit at a time and uses a clock speed far lower than any other PC
| component. Both these qualities make it easy to pick out voltage changes
| caused by key presses.

| A digital oscilloscope was used to gather data about voltage changes on
| a power line and filters were used to remove those caused by anything
| other than the keyboard.

| "The PS/2 signal square wave is preserved with good quality... and can
| be decoded back to the original keystroke information," wrote the pair
| in a paper describing their work.

| They demonstrated it working over distances of 1, 5, 10 and 15m from a
| target, far enough to suggest it could work in a hotel or office.

| "The test performed in the laboratory represent a worst case scenario
| for this type of measurement, which along with acceptable results
| emphasizes the feasibility of the attack on normal conditions," they
| added.

| The pair said their research was "work in progress" and expect the
| equipment to get more sensitive as it is refined.

| The attack is due to be demonstrated at the Black Hat conference that
| takes place in Las Vegas from 25-30 July.

Ref:: http://news.bbc.co.uk/1/hi/technology/8147534.stm


Tempest Monitoring.

--
Dave
http://www.claymania.com/removal-trojan-adware.html
Multi-AV - http://www.pctipp.ch/downloads/dl/35905.asp




David H. Lipman
  Reply With Quote
Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off

Similar Threads
Thread Thread Starter Forum Replies Last Post
reporting power with dc_shell perseo Hardware 0 10-11-2007 09:01 AM
Judge: File-swapping tools are legal Citizen Bob DVD Video 140 11-08-2006 06:42 PM
Diagnosing Power Supplies Dave Hardenbrook A+ Certification 2 04-18-2005 01:44 AM
Old PC Occasionally Won't Start, Doesn't Power Down all the time mr x A+ Certification 4 02-26-2004 04:50 AM
Power Supply Requirements Joe A+ Certification 1 12-20-2003 06:13 PM




SEO by vBSEO 3.3.2 ©2009, Crawlability, Inc.

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46