Showing posts with label hacking. Show all posts
Showing posts with label hacking. Show all posts

BBC: Oyster card hack details revealed



Details of how to hack one of the world’s most popular smartcards have been published online. The research by Professor Bart Jacobs and colleagues at Radboud University in Holland reveals a weakness in the widely used Mifare Classic RFID chip. This is used in building entry systems and is embedded in the Oyster card used on London’s transport network. (via BBC NEWS | Programmes | Click | Oyster card hack details revealed)

Source: Jump Box 02

John Draper aka Captain Crunch

From Wikipedia:
John T. Draper (born 1944), also known as Captain Crunch, Crunch or Crunchman (after Cap'n Crunch, the mascot of a breakfast cereal), is a former phone phreak.

Draper was the son of a U.S. Air Force engineer; he described his father as distant in an interview published on the front page of the Jan 13-14, 2007, issue of The Wall Street Journal. Mr. Draper himself entered the Air Force in 1964, and while stationed in Alaska helped his fellow servicemen make free phone calls home by devising access to a local telephone switchboard. He was honorably discharged from the Air Force in 1968, and did military-related work for several employers in the San Francisco Bay Area. He adopted the counterculture of the times and operated a pirate radio station out of a Volkswagen van.

A blind friend of John Draper's named Joe Engressia (now known as Joybubbles) informed him that a toy whistle that was, at the time, packaged in boxes of Cap'n Crunch cereal could be easily modified to emit a tone at precisely 2600 hertz—the same frequency that was used by AT&T long lines to indicate that a trunk line was ready and available to route a new call.[1] This would effectively disconnect one end of the trunk, allowing the still connected side to enter an operator mode. Experimenting with this whistle inspired Draper to build blue boxes: electronic devices capable of reproducing other tones used by the phone company.

“I don't do that. I don't do that anymore at all. And if I do it, I do it for one reason and one reason only. I'm learning about a system. The phone company is a System. A computer is a System, do you understand? If I do what I do, it is only to explore a system. Computers, systems, that's my bag. The phone company is nothing but a computer.” — From Secrets of the Little Blue Box by Ron Rosenbaum, Esquire Magazine (October 1971)

The class of vulnerabilities Draper and others discovered was limited to call routing switches that employed in-band signaling, whereas newer equipment relies almost exclusively on out-of-band signaling, the use of separate circuits to transmit voice and signals. Though they could no longer serve practical use, the Cap'n Crunch whistles did become valued collector's items. Some hackers sometimes go by the handle “Captain Crunch” even today; as a result of this incident 2600 The Hacker Quarterly is named after this whistle frequency. The expense of sustaining the unbilled phone calls, the redesign of the line protocols and the accelerated equipment replacement due to the blue box is difficult to calculate, or even to separate from something as complex and dynamic as the telephone long-distance network, but it is generally acknowledged to be a huge sum.

The 1971 Esquire Magazine article which told the world about phone phreaking got Draper in hot water. Draper was arrested on toll fraud charges in 1972 and sentenced to five years' probation. The article also brought him to the attention of Steve Wozniak. In the mid 1970s he taught his phone phreaking skills to Steve Jobs and Steve Wozniak, who later founded Apple Computer.[1] He was briefly employed at Apple, and created a telephone interface board for the Apple II personal computer.[1] Wozniak has said that the reason that the board was never marketed was that he was the only one in the company who liked him[2] and partially due to Draper's arrest and conviction for wire fraud in 1977. Draper wrote EasyWriter, the first word processor for the Apple II, in 1979. According to the Wall Street Journal, he hand-wrote the code while serving nights in the Alameda County Jail, then entered the code later into a computer. However, another account had him writing the code as he served his four-month sentence at the Federal Correctional Institution, Lompoc, California.
(Wikipedia - John Draper)

The Max Headroom pirating incident

From Wikipedia:


Max Headroom Pirating Incident occurred on Sunday November 22, 1987 and is an example of broadcast signal intrusion.

WGN
The first occurrence of the signal hijack occurred during WGN-TV's 9:00 News. During Bears Highlights in the Sports report the signal was interrupted by a video of a person wearing a Max Headroom mask in front of a swaying sheet of corrugated metal. There was no audio. The hijack was stopped after only 20 seconds when WGN switched transmission from the Sears Tower to the John Hancock Center. The incident left sports reporter Dan Roan flustered, who stated "Well, if you're wondering what happened… so am I."

WTTW
Later that night around 11:15pm during a broadcast of the Doctor Who episode Horror of Fang Rock on WTTW, the signal was hijacked by the same person. It was the same video that was broadcast during the WGN hijack, but this time there was audio. The person in the Max Headroom mask interrupted the broadcast, saying "He's a frickin nerd" before laughing and stating "Yeah I think I'm better than Chuck Swirsky!". The person continued to utter strange phrases including a Coke advertising slogan (Max Headroom was a Coke spokesperson at the time), humming the theme song to Clutch Cargo (pausing midway to say "I stole CBS"), he also states that he has, "made a giant masterpiece for all the greatest world's newspaper nerds" (WGN is an acronym for 'World's Greatest Newspaper'); before finally undressing below the waist and was spanked by an unknown person with a flyswatter before the masked person cut off his transmission. It was over in about 90 seconds. The pirate was never caught. WTTW, which maintains its transmitter atop the Sears Tower, found that its engineers were unable to stop the hijacker because at the time there were no engineers on duty at the Sears Tower. Also, the station's master control center was unable to contact its transmitting equipment remotely to switch the STL (Studio To Transmitter Link), unlike their counterparts at WGN-TV, who were able to thwart the intruder by switching their John Hancock Center transmitter STL remotely within seconds.

WTTW and WGN join HBO as victims of broadcast signal intrusion. There has not been an incident in America of this kind since. In January 2007 a broadcast hijack took place in Australia. The Max Headroom incident was reported on CBS Evening News.
(Wikipedia http://en.wikipedia.org/wiki/Max_Headroom_Pirating_Incident)