Image
 
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 39 guests and 1 member online
EH-Net Donations

Enter Amount:
$

Google Ads
EH-Net News Feeds
Latest Additions
Book Recommendations





 
Advertisement

You are here: Home arrow Forum arrow Columnsarrow Gatesarrow [Article]-TEMPEST, Conspiracy Theories and Tinfoil Dreams
Ethical Hacker Community Forums
December 02, 2008, 02:48:39 PM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: ChicagoCon 2-Day Ethical Hacking Conference with MS Blue Hats Oct 31 - Nov 1. Tickets Only $100! www.chicagocon.com/content/view/103/51/
 
   Home   Help Calendar Login Register  
Pages: [1]   Go Down
  Print  
Author Topic: [Article]-TEMPEST, Conspiracy Theories and Tinfoil Dreams  (Read 8669 times)
0 Members and 1 Guest are viewing this topic.
don
Editor-In-Chief
Administrator
Hero Member
*****
Offline Offline

Posts: 2380


Editor-In-Chief


View Profile WWW
« on: March 23, 2007, 04:35:34 AM »

If you're a CISSP or a conspiracy theorist, you've probably heard of TEMPEST at least from a theoretical standpoint. Once again, Chris dives into a topic with zeal and presents his research and references. Now you too can be educated in the some more of the details of Compromising Emanations (CE).

BTW - If you're at ShmooCon 2007 starting today, be sure to approach Chris very slowly with tin foil hat clearly visible.  Grin

Quote


Ok prepare to strap that tinfoil hat on two notches below excruciating, we’re going to talk about TEMPEST. What is TEMPEST?  It’s defined in NSTISSI-7000 as:

Electronic and electromechanical information-processing equipment can produce unintentional intelligence-bearing emanations, commonly known as TEMPEST. If intercepted and analyzed, these emanations may disclose information transmitted, received, handled, or otherwise processed by the equipment. (1)

and in NSTISSI 7003 (TEMPEST GLOSSARY) as:

“A short name referring to investigations and studies of compromising emanations. It is often used synonymously for the term "compromising emanations"; e.g., TEMPEST tests, TEMPEST inspections.” (2)

Compromising Emanations (CE) are defined as:

“Unintentional intelligence-bearing signals, which, if intercepted and analyzed, disclose the national security information transmitted, received, handled or otherwise processed by any information-processing equipment.” (3)

Clear as mud?  What this means is that your computer, your computer monitor, your CAT5 cable going into your router from your computer, your coax cable into your cable modem, and even your power cord going into the wall can carry electronic and electromechanical signals distances away from your computer and could possibly be intercepted either off the wires or through the air.  Ok, maybe one more notch on that hat.

Image at top of document with Rory Culkin, Mel Gibson and Abigail Breslin from the movie Signs (2002). © Touchstone Pictures. All rights reserved.

Permanent link:
[Article]-TEMPEST, Conspiracy Theories and Tinfoil Dreams

As always, leave comments or suggestions,
Don
« Last Edit: March 23, 2007, 04:41:10 AM by don » Logged

CISSP, MCSE, CEH, Security+ SME
jimbob
Sr. Member
****
Offline Offline

Posts: 316



View Profile WWW
« Reply #1 on: March 23, 2007, 07:03:00 AM »

Good stuff! Talk of TEMPEST has been around for years, but it's funny how something like this gets pushed to the back of your mind. There is certainly a lot more scope for monitoring CE now than there were a few years back when I last read about TEMPEST.

Jimbob
Logged
ChrisG
EH-Net Columnist
Hero Member
*****
Offline Offline

Posts: 1042


View Profile WWW
« Reply #2 on: March 23, 2007, 08:38:24 AM »

especially since "TEMPEST is dead" which is what i heard alot while researching this.

of course in this day and age its easier to physically steal the information or hack in than aim an antenna at a window.  but doesnt take away the cool factor of doing it though!
Logged

...tests i took go here...

http://carnal0wnage.blogspot.com/
Craig
EH-Net Columnist
Jr. Member
*****
Offline Offline

Posts: 62


View Profile WWW
« Reply #3 on: March 23, 2007, 08:55:55 AM »

Great article Chris! I did a little research into TEMPEST/Van Eck my self a while back...the Temptest for Elisa program is pretty cool, or at least I thought so.

Wondering if anyone here has played around with Eckbox? I wanted to try it, but found a lot of people who said it didn't work for them. Since I'm not very good with hardware, I didn't want to bother building an ADC for it if it wouldn't work anyway. Tongue

And while we're on the subject, let's not forget about Tinfoil Hat Linux! A cool name like that AND it fits on a floppy? You know it's gotta be good.
Logged

ChrisG
EH-Net Columnist
Hero Member
*****
Offline Offline

Posts: 1042


View Profile WWW
« Reply #4 on: March 23, 2007, 09:17:23 AM »

i think i am gonna try building that Eck Box when i get back from DC.  and mess around with TEMEPST for Eliza. i only have my mac with me and was having compile issues with the libSDL piece.  should compile fine on the linux box when i get back.  might be a good thing i didnt throw out that old school monitor in the garage yet :-)
« Last Edit: March 23, 2007, 09:19:13 AM by ChrisG » Logged

...tests i took go here...

http://carnal0wnage.blogspot.com/
Craig
EH-Net Columnist
Jr. Member
*****
Offline Offline

Posts: 62


View Profile WWW
« Reply #5 on: March 23, 2007, 09:48:47 AM »

I found that the Tempest for Eliza program worked best on my laptop screen...worked well on my desktop LCDs too.
Logged

ChrisG
EH-Net Columnist
Hero Member
*****
Offline Offline

Posts: 1042


View Profile WWW
« Reply #6 on: March 23, 2007, 10:09:02 AM »

cool, well i'll check it out and post up on how it goes.

Logged

...tests i took go here...

http://carnal0wnage.blogspot.com/
don
Editor-In-Chief
Administrator
Hero Member
*****
Offline Offline

Posts: 2380


Editor-In-Chief


View Profile WWW
« Reply #7 on: March 23, 2007, 12:22:12 PM »

Submitted to digg:

http://www.digg.com/security/TEMPEST_Conspiracy_Theories_and_Tinfoil_Dreams

Don
Logged

CISSP, MCSE, CEH, Security+ SME
slimjim100
EH-Net Columnist
Sr. Member
*****
Offline Offline

Posts: 365



View Profile WWW
« Reply #8 on: March 23, 2007, 08:16:46 PM »

beware of the "thought police" I have reinvested in my tin hat now!

Great article Chris!!!

Brian
Logged

CISSP, CCSE, CCNA, CCAI, Network+, Security+, JNCIA, & MCP
ChrisG
EH-Net Columnist
Hero Member
*****
Offline Offline

Posts: 1042


View Profile WWW
« Reply #9 on: March 26, 2007, 06:52:37 PM »

anybody bother to watch:

Dutch Voting Machine TEMPEST Video
http://www.youtube.com/watch?v=B05wPomCjEY

what did you think?
Logged

...tests i took go here...

http://carnal0wnage.blogspot.com/
Craig
EH-Net Columnist
Jr. Member
*****
Offline Offline

Posts: 62


View Profile WWW
« Reply #10 on: March 26, 2007, 09:21:57 PM »

I thought it was a good example that intelligent data can be gathered from electrical RF emissions. I've had an on-and-off interest in TEMPEST ever since I read Cryptonomicon, so real-life presentations are always interesting to me. Although, I have yet to see a video of someone doing real-time screen captures (if anyone knows of one post it up!).

Michal Zalewski's book Silence on the Wire touches briefly on TEMPEST and other ways of gathering information from unintentional emissions such as NIC activity lights. The whole subject is really interesting.
Logged

ChrisG
EH-Net Columnist
Hero Member
*****
Offline Offline

Posts: 1042


View Profile WWW
« Reply #11 on: March 26, 2007, 09:52:54 PM »

someone was able to reproduce data from nic lights, dont have the academic paper off hand but i know they did it.

there are some videos but they are hard to come by, i'll let you read between the lines on that one
Logged

...tests i took go here...

http://carnal0wnage.blogspot.com/
oleDB
Full Member
***
Offline Offline

Posts: 231



View Profile WWW
« Reply #12 on: May 15, 2007, 10:41:09 AM »

Even more fun with tempest
http://www.newscientist.com/article/dn2029-monitors-flicker-reveals-data-on-screen.html
Logged
Pages: [1]   Go Up
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.7 | SMF © 2006-2008, Simple Machines LLC
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.056 seconds with 24 queries.
 
Sponsors

cwnp_moto__120x90.gif

Polls
During the most recent election, I:
 
Support EH-Net


Support EH-Net by
Buying all of your
Amazon items using
the search bar above.

cbtnuggets_logo_125.jpg
Try CBT Nuggets Free!
Recent Forum Topics
Vote For EH-Net

progenic.com
Click here to Vote!

Sadikhov.com
Top IT Cert Sites

binarica.com
Binarica Logo

Add to Technorati Favorites
technorati fave

 
         
Advertisement

© 2008 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.