<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title> &#187; Eavesdropping</title>
	<atom:link href="http://www.megapanzer.com/tag/eavesdropping/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.megapanzer.com</link>
	<description></description>
	<lastBuildDate>Fri, 23 Dec 2011 13:02:33 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3</generator>
		<item>
		<title>Eavesdropping on applications with MioStar 0.1</title>
		<link>http://www.megapanzer.com/2010/11/02/eavesdrop-on-applications-with-miostar/</link>
		<comments>http://www.megapanzer.com/2010/11/02/eavesdrop-on-applications-with-miostar/#comments</comments>
		<pubDate>Tue, 02 Nov 2010 14:07:20 +0000</pubDate>
		<dc:creator>carrumba</dc:creator>
				<category><![CDATA[Deutsch]]></category>
		<category><![CDATA[Info]]></category>
		<category><![CDATA[Tools & sources]]></category>
		<category><![CDATA[api]]></category>
		<category><![CDATA[apihooking]]></category>
		<category><![CDATA[DLL injection]]></category>
		<category><![CDATA[Eavesdropping]]></category>
		<category><![CDATA[Hooking]]></category>
		<category><![CDATA[miostar]]></category>
		<category><![CDATA[Passwords]]></category>

		<guid isPermaLink="false">http://www.megapanzer.com/?p=4329</guid>
		<description><![CDATA[http://let.de/index.php/eavesdropping-on-applications-with-miostar-0-1/]]></description>
			<content:encoded><![CDATA[<glossarycode><h3>Deutsch</h3>
<p>Während den letzten zwei Wochen habe ich an einem neuen Tool gearbeitet, welches auf den Methoden des SkypeTrojaners aufbaut. Es sollen Programme überwacht und aus ihnen sensitive Daten extrahiert werden. Dazu müssen zwischen der laufenden Anwendung und dem Betriebssystem Zwischenfunktionen eingefügt, ge-hookt, werden. Bis ich die richtigen Funktionen gefunden hatte, hat zwar ein wenig Zeit gebraucht aber das Resultat ist zufriedenstellend und ich denke, dass ich auf dem richtigen Weg bin. Momentan lassen sich Passwörter aus Google Chrome, Apple Safari, Windows Live (Instant Messenger + Mail), GoogleTalk, FireFirefox und Thunderbird extrahieren.  Zwar <a class="glossaryLink" href="http://www.megapanzer.com/" title="Glossary: SIN" target="_blank">sind</a> noch nicht alle Schwachpunkte optimal anfokusiert und der Datenabgriff könnte an treffsichereren stellen stattfinden, aber mit ein wenig mehr Zeit wird die Trefferquote, Zuverlässigkeit und der Umfang an abzuhörenden Programmen erweitert.</p>
<p><strong>Am 3. November um 13.00 (Schweizerzeit) wird der Quellcode für MioStar 0.1 veröffentlicht.</strong> Interessierte dürfen gerne den Code herunterladen, durchschauen und Kritik anbringen.<br />
In der selben Zeit habe ich den SkypeTrojaner für GoogleTalk umgeschrieben. Die Audiodaten werden mitgeschnitten, nach MP3 konvertiert und  gespeichert. Dieser Quellcode folgt nächste oder übernächste Woche. </p>
<h3>English</h3>
<p>Hello,</p>
<p>The last 2 weeks I have been working on a new tool, which is based on the methods of the Skype trojan. The objective is to surveil programs and extract sensible data from them. In order to do so you have to plant function hooks between the running program and the operating system. It took a while until i found the correct functions, but the result is satisfying and i think that I am on the right track. At the moment it is possible to extract passwords from Google Chrome, Apple Safari, Windows Live (Instant Messenger + Mail), GoogleTalk, FireFirefox and Thunderbird . For some programs there are better ways of attacking them, but with a little more time the procedures can be optimized.<br />
<strong>On the 3rd of November (1pm Swiss time) the MioStar source code will be relased.</strong> Those who are interested are welcome to download, explore, review and critizise it.<br />
Within the same time I have rewritten the SkypeTrojan code that way it can intercept GoogleTalk conversations. The audio data gets intercepted, converted to MP3 and saved. This source code will be released in the coming weeks. </p></glossarycode>]]></content:encoded>
			<wfw:commentRss>http://www.megapanzer.com/2010/11/02/eavesdrop-on-applications-with-miostar/feed/</wfw:commentRss>
		<slash:comments>16</slash:comments>
		</item>
		<item>
		<title>Report on SC Magazine about the Skype trojan (August 2009)</title>
		<link>http://www.megapanzer.com/2010/10/13/report-on-sc-magazine-about-the-skype-trojan-august-2009/</link>
		<comments>http://www.megapanzer.com/2010/10/13/report-on-sc-magazine-about-the-skype-trojan-august-2009/#comments</comments>
		<pubDate>Wed, 13 Oct 2010 15:04:42 +0000</pubDate>
		<dc:creator>carrumba</dc:creator>
				<category><![CDATA[Stuff]]></category>
		<category><![CDATA[Eavesdropping]]></category>
		<category><![CDATA[Skype]]></category>
		<category><![CDATA[skypetap]]></category>
		<category><![CDATA[trojan]]></category>

		<guid isPermaLink="false">http://www.megapanzer.com/?p=4287</guid>
		<description><![CDATA[Skype snooping trojan detected, August 31 2009 Source code for a new trojan has been released that has the ability to snoop on phone calls over the popular voice over IP (VoIP) program Skype. Ruben Unteregger, a Swiss software engineer formerly with the software development company ERA IT Solutions, released the source code for the [...]]]></description>
			<content:encoded><![CDATA[<glossarycode><glossarycode><glossarycode><glossarycode><glossarycode><p><img src="http://www.megapanzer.com/wp-content/uploads/newspaper-150x150.jpg" alt="" title="newspaper" width="75" height="75" class="alignright size-thumbnail wp-image-2595" /><strong>Skype snooping trojan detected,  August 31 2009 </strong></p>
<p>Source code for a new trojan has been released that has the ability to snoop on phone calls over the popular voice over IP (VoIP) program Skype. </p>
<p>Ruben Unteregger, a Swiss software engineer formerly with the software development company ERA IT Solutions, released the source code for the trojan Tuesday. Unteregger provided details about the trojan on his blog, Megapanzer, which he said can “&#8230;intercept all audio data coming and going to the Skype process.”</p>
<p>“What we&#8217;re looking at is something that could be considered the first ‘wiretap trojan,&#8217;” Karthik Selvaraj, an analyst at Symantec Security Response Team, wrote in a blog post Thursday. </p>
<p><span id="more-4287"></span><br />
The code, identified as Trojan.Peskyspy, has the ability to record audio from Skype calls, convert the audio to an MP3 file, encrypt it and send it back to the attacker, Symantec said. </p>
<p>“What this threat is doing is actually grabbing the sound coming from the audio devices plugged into the computer,” Selvaraj wrote. “It does this by hooking various Windows API calls that are used in audio input and output.”</p>
<p>The trojan sniffs inbound and outbound audio as it travels between the PC&#8217;s audio device and Skype, Selvaraj explained. Outbound audio coming from a user&#8217;s microphone is captured before it even reaches Skype, and inbound audio is captured after it leaves Skype, but before it reaches the PC&#8217;s speakers. </p>
<p>“It gathers the audio independently of any application-specific protocols or encryption applied by Skype when it passes voice data at the network level,” Selvaraj said. “Essentially, it sits below these security measures, recording the audio at the Windows level.”</p>
<p>The trojan does not rely on any issue in Skype itself and could potentially be crafted to <a class="glossaryLink" href="http://www.megapanzer.com/?page_id=2563" title="Glossary: Exploit" target="_blank">exploit</a> any VoIP program, Selvaraj said. </p>
<p>Though source code became publicly available Tuesday, Unteregger told German news outlet Gulli.com that the trojan actually had been in development <a class="glossaryLink" href="http://www.megapanzer.com/" title="Glossary: SIN" target="_blank">since</a> at least 2006. </p>
<p>As of now, the trojan has not been identified in the wild, Kevin Haley, director of Symantec Security Response, told SCmagazineUS.com on Friday. But now that source code has been released, there is a potential that attackers could add this trojan to their <a class="glossaryLink" href="http://www.megapanzer.com/?page_id=2563" title="Glossary: Exploit" target="_blank">exploits</a>.<br />
The source code does not have any means of propagating itself, so an attacker would have to use <a class="glossaryLink" href="http://www.megapanzer.com/?page_id=3299" title="Glossary: Social engineering" target="_blank">social engineering</a> to trick a user into installing it, or have physical access to the machine they wish to infect.</p>
<p>“For the most part, this is a tool that would be used in a targeted way at someone,” Haley said.</p>
<p>A Skype spokesperson told SCMagazineUS.com in an email statement Friday that Skype&#8217;s Information Security team is aware of Trojan.Peskyspy. </p>
<p>&#8220;Skype strongly recommends that users follow security best practices like maintaining an up-to-date anti-<a class="glossaryLink" href="http://www.megapanzer.com/?page_id=3302" title="Glossary: Virus" target="_blank">virus</a> program, using a personal <a class="glossaryLink" href="http://www.megapanzer.com/" title="Glossary: Firewall" target="_blank">firewall</a> and ensuring that their computer is current with patches to help defend against attacks such as this.&#8221;</p></glossarycode></glossarycode></glossarycode></glossarycode></glossarycode>]]></content:encoded>
			<wfw:commentRss>http://www.megapanzer.com/2010/10/13/report-on-sc-magazine-about-the-skype-trojan-august-2009/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Things to do for the next days &#8230;</title>
		<link>http://www.megapanzer.com/2010/10/01/things-to-do-for-the-next-days/</link>
		<comments>http://www.megapanzer.com/2010/10/01/things-to-do-for-the-next-days/#comments</comments>
		<pubDate>Fri, 01 Oct 2010 11:27:33 +0000</pubDate>
		<dc:creator>carrumba</dc:creator>
				<category><![CDATA[Info]]></category>
		<category><![CDATA[Stuff]]></category>
		<category><![CDATA[DLL]]></category>
		<category><![CDATA[DLL injection]]></category>
		<category><![CDATA[Eavesdropping]]></category>
		<category><![CDATA[Injection]]></category>
		<category><![CDATA[Skype]]></category>
		<category><![CDATA[skypetap]]></category>

		<guid isPermaLink="false">http://www.megapanzer.com/?p=4166</guid>
		<description><![CDATA[I&#8217;m still struggling to make SkypeTap (skype interception module) work on Win7. This week things just don&#8217;t go as smoothly as expected :/ As soon as I have a result (may it be positive or negative) I&#8217;ll let you know. If it works I think a further post would be appropriate that shows in detail [...]]]></description>
			<content:encoded><![CDATA[<p><img src="http://www.megapanzer.com/wp-content/uploads/trojan_horse.jpeg" alt="" title="trojanhorse" width="100" height="96" class="alignright size-full wp-image-2132" />I&#8217;m still struggling to make <strong>SkypeTap </strong>(skype interception module) work on Win7. This week things just don&#8217;t go as smoothly as expected :/ As soon as I have a result (may it be positive or negative) I&#8217;ll let you know.</p>
<p>If it works I think a further post would be appropriate that shows in detail how to inject <strong>*something*</strong> into a process and what different approches exist to do that.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.megapanzer.com/2010/10/01/things-to-do-for-the-next-days/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Hacker Spoofs Cell Phone Tower to Intercept Calls</title>
		<link>http://www.megapanzer.com/2010/08/02/hacker-spoofs-cell-phone-tower-to-intercept-calls/</link>
		<comments>http://www.megapanzer.com/2010/08/02/hacker-spoofs-cell-phone-tower-to-intercept-calls/#comments</comments>
		<pubDate>Mon, 02 Aug 2010 10:42:47 +0000</pubDate>
		<dc:creator>carrumba</dc:creator>
				<category><![CDATA[News & media]]></category>
		<category><![CDATA[Eavesdropping]]></category>
		<category><![CDATA[GSM]]></category>
		<category><![CDATA[IMSI catcher]]></category>

		<guid isPermaLink="false">http://www.megapanzer.com/?p=3636</guid>
		<description><![CDATA[A security researcher created a cell phone base station that tricks cell phones into routing their outbound calls through his device, allowing someone to intercept even encrypted calls in the clear. The device tricks the phones into disabling encryption and records call details and content before they’re routed on their proper way through voice-over-IP. The [...]]]></description>
			<content:encoded><![CDATA[<p><img src="http://www.megapanzer.com/wp-content/uploads/newspaper-150x150.jpg" alt="" title="newspaper" width="75" height="75" class="alignright size-thumbnail wp-image-2595" />A security researcher created a cell phone base station that tricks cell phones into routing their outbound calls through his device, allowing someone to intercept even encrypted calls in the clear.</p>
<p>The device tricks the phones into disabling encryption and records call details and content before they’re routed on their proper way through voice-over-IP.</p>
<p>The low-cost, home-brewed device, developed by researcher Chris Paget, mimics more expensive devices already used by intelligence and law enforcement agencies – called IMSI catchers – that can capture phone ID data and content. The devices essentially spoof a legitimate GSM tower and entice cell phones to send them data by emitting a signal that’s stronger than legitimate towers in the area.</p>
<p>“If you have the ability to deliver a reasonably strong signal, then those around are owned,” Paget said.</p>
<p>Paget’s system costs only about $1,500, as opposed to several hundreds of thousands for professional products. Most of the price is for the laptop he used to operate the system.</p>
<p>Doing this kind of interception “used to be a million dollars, now you can do it with a thousand times less cost,” Paget said during a press conference after his attack. “If it’s $1,500, it’s just beyond the range that people can start buying them for themselves and listening in on their neighbors.”</p>
<p>Paget’s device captures only 2G GSM calls, making AT&#038;T and T-Mobile calls, which use GSM, vulnerable to interception. Paget’s aim was to highlight vulnerabilities in the GSM standard that allows a rogue station to capture calls. GSM is a second-generation technology that is not as secure as 3G technology.</p>
<p>Read More : <a href="http://www.wired.com/threatlevel/2010/07/intercepting-cell-phone-calls" target="_blank">Wired Magazine</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.megapanzer.com/2010/08/02/hacker-spoofs-cell-phone-tower-to-intercept-calls/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Cell phone eavesdropping enters script-kiddie phase</title>
		<link>http://www.megapanzer.com/2010/07/29/cell-phone-eavesdropping-enters-script-kiddie-phase/</link>
		<comments>http://www.megapanzer.com/2010/07/29/cell-phone-eavesdropping-enters-script-kiddie-phase/#comments</comments>
		<pubDate>Thu, 29 Jul 2010 13:19:50 +0000</pubDate>
		<dc:creator>carrumba</dc:creator>
				<category><![CDATA[News & media]]></category>
		<category><![CDATA[Eavesdropping]]></category>
		<category><![CDATA[GSM]]></category>
		<category><![CDATA[Hacking]]></category>
		<category><![CDATA[Kraken]]></category>

		<guid isPermaLink="false">http://www.megapanzer.com/?p=3628</guid>
		<description><![CDATA[Black Hat Independent researchers have made good on a promise to release a comprehensive set of tools needed to eavesdrop on cell phone calls that use the world&#8217;s most widely deployed mobile technology. “The whole topic of GSM hacking now enters the script-kiddie stage, similar to Wi-Fi hacking a couple years ago, where people started [...]]]></description>
			<content:encoded><![CDATA[<glossarycode><glossarycode><p><img src="http://www.megapanzer.com/wp-content/uploads/newspaper-150x150.jpg" alt="" title="newspaper" width="75" height="75" class="alignright size-thumbnail wp-image-2595" /><strong><a class="glossaryLink" href="http://www.megapanzer.com/" title="Glossary: Black hat" target="_blank">Black Hat</a></strong> Independent researchers have made good on a promise to release a comprehensive set of tools needed to eavesdrop on cell phone calls that use the world&#8217;s most widely deployed mobile technology.</p>
<p>“The whole topic of GSM hacking now enters the script-kiddie stage, similar to Wi-Fi hacking a couple years ago, where people started cracking the neighbor&#8217;s Wi-Fi,” said Karsten Nohl, a cryptographer with the Security Research Labs in Berlin who helped spearhead the project. “Just as with Wi-Fi, where they changed the encryption to <a class="glossaryLink" href="http://www.megapanzer.com/?page_id=1322" title="Glossary: WPA" target="_blank">WPA</a>, hopefully that will happen with GSM, too.”<br />
The suite of applications now includes Kraken, software being released at the <a class="glossaryLink" href="http://www.megapanzer.com/" title="Glossary: Black hat" target="_blank">Black Hat</a> security conference on Thursday that can deduce the secret key encrypting SMS messages and voice conversations in as little as 30 seconds. It was developed by Frank A. Stevenson, the same Norwegian programmer who almost a decade ago developed software that cracked the CSS encryption scheme protecting DVDs.</p>
<p>
Find whole article here : <a href="http://www.theregister.co.uk/2010/07/29/cell_phone_snooping/" target="_blank">Cell phone eavesdropping enters script-kiddie phaset</a></p></glossarycode></glossarycode>]]></content:encoded>
			<wfw:commentRss>http://www.megapanzer.com/2010/07/29/cell-phone-eavesdropping-enters-script-kiddie-phase/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Czech experts uncover global virus network</title>
		<link>http://www.megapanzer.com/2010/02/18/czech-experts-uncover-global-virus-network/</link>
		<comments>http://www.megapanzer.com/2010/02/18/czech-experts-uncover-global-virus-network/#comments</comments>
		<pubDate>Thu, 18 Feb 2010 12:51:53 +0000</pubDate>
		<dc:creator>carrumba</dc:creator>
				<category><![CDATA[News & media]]></category>
		<category><![CDATA[botnet]]></category>
		<category><![CDATA[Eavesdropping]]></category>

		<guid isPermaLink="false">http://www.megapanzer.com/?p=3478</guid>
		<description><![CDATA[Czech security experts have uncovered a global network of devices attacked by computer viruses within which it was possible to wiretap and gain access to sensitive data, Jan Vykopal, head of the security project of Masaryk University, told CTK yesterday. Modems were among the attacked devices as they are only poorly protected. The viruses were [...]]]></description>
			<content:encoded><![CDATA[<glossarycode><p><img src="http://www.megapanzer.com/wp-content/uploads/newspaper-150x150.jpg" alt="" title="newspaper" width="75" height="75" class="alignright size-thumbnail wp-image-2595" /><strong>Czech security experts have uncovered a global network of devices attacked by <a class="glossaryLink" href="http://www.megapanzer.com/?page_id=3304" title="Glossary: Computer virus" target="_blank">computer viruses</a> within which it was possible to wiretap and gain access to sensitive data</strong>, Jan Vykopal, head of the security project of Masaryk University, told CTK yesterday.</p>
<p>Modems were among the attacked devices as they are only poorly protected. The viruses were able to deflect the communication of Internet users to servers where they could be wiretapped, Vykopal said.</p>
<p>Vykopal&#8217;s colleagues along with experts from the Brno Military Academy and the Defence Ministry have uncovered the dangerous network.</p>
<p>&#8220;The assailants have denoted the network of the subjugated installations as Chuck Norris,&#8221; Defence Ministry spokeswoman Lucie Kubovicova said.</p>
<p>Experts said the network&#8217;s main threats included the gaining of various sensitive data such as access details for bank accounts, e-mail boxes, passwords to various services, social networks and users&#8217; other personal data.</p>
<p>Besides, a number of computers and other installations connected through the Internet can be used for attacks on well secured servers as well, Vykopal said.</p>
<p>&#8220;We do not know whether the network we uncovered can also be used for this as we do not know the number of the devices that are included in it,&#8221; Vykopal said.</p>
<p>Read more here.</p></glossarycode>]]></content:encoded>
			<wfw:commentRss>http://www.megapanzer.com/2010/02/18/czech-experts-uncover-global-virus-network/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Secret code protecting cellphone calls set loose</title>
		<link>http://www.megapanzer.com/2009/12/29/secret-code-protecting-cellphone-calls-set-loose/</link>
		<comments>http://www.megapanzer.com/2009/12/29/secret-code-protecting-cellphone-calls-set-loose/#comments</comments>
		<pubDate>Tue, 29 Dec 2009 07:38:11 +0000</pubDate>
		<dc:creator>carrumba</dc:creator>
				<category><![CDATA[News & media]]></category>
		<category><![CDATA[Clellphone]]></category>
		<category><![CDATA[cryptography]]></category>
		<category><![CDATA[Eavesdropping]]></category>
		<category><![CDATA[GSM]]></category>
		<category><![CDATA[rainbow table]]></category>

		<guid isPermaLink="false">http://www.megapanzer.com/?p=3263</guid>
		<description><![CDATA[Cryptographers have moved closer to their goal of eavesdropping on cellphone conversations after cracking the secret code used to prevent the interception of radio signals as they travel between handsets and mobile operators&#8217; base stations. The code is designed to prevent the interception of phone calls by forcing mobile phones and base stations to rapidly [...]]]></description>
			<content:encoded><![CDATA[<glossarycode><glossarycode><p><a href="http://www.megapanzer.com/wp-content/uploads/newspaper.jpg"><img src="http://www.megapanzer.com/wp-content/uploads/newspaper-150x150.jpg" alt="" title="newspaper" width="75" height="75" class="alignright size-thumbnail wp-image-2595" /></a>Cryptographers have moved closer to their goal of eavesdropping on cellphone conversations after cracking the secret code used to prevent the interception of radio signals as they travel between handsets and mobile operators&#8217; base stations.</p>
<p>The code is designed to prevent the interception of phone calls by forcing mobile phones and base stations to rapidly change radio frequencies over a spectrum of 80 channels. Without knowing the precise sequence, would-be eavesdroppers can assemble only tiny fragments of a conversation.</p>
<p>At a <a class="glossaryLink" href="http://www.megapanzer.com/?page_id=1220" title="Glossary: Hacker" target="_blank">hacker</a> conference in Berlin that runs through Wednesday, the cryptographers said they&#8217;ve cracked the algorithm that determines the random channel hopping and have devised a practical means to capture entire calls using equipment that costs about $4,000. At the heart of the crack is open-source software for computer-controlled radios that makes the frequency changes at precisely the same time, and in the same order, that the cellphone and base station do.</p>
<p>&#8220;We now know this is possible,&#8221; said Karsten Nohl, a 28-year-old cryptographer and one of the members of an open-source project out to prove that GSM, the technical standard used by about 80 percent of the mobile market, can&#8217;t be counted on to keep calls private. The attack &#8220;is practical, and there are real vulnerabilities that people are <a class="glossaryLink" href="http://www.megapanzer.com/?page_id=2563" title="Glossary: Exploit" target="_blank">exploiting</a>.&#8221;</p>
<p>A spokeswoman for the GSM Association, which represents 800 operators in 219 countries, said officials hadn&#8217;t yet seen the research.</p>
<p>&#8220;GSM networks use encryption technology to make it difficult for criminals to intercept and eavesdrop on calls,&#8221; she wrote in an email. &#8220;Reports of an imminent GSM eavesdropping capability are common.&#8221;</p>
<p>The channel-hopping crack comes as the collective is completing the compilation of a rainbow table that allows them to decrypt calls as they happen. The table works because GSM encryption uses A5/1, a decades-old algorithm with known weaknesses. The table &#8211; a 2-terabyte list of known results that allows cryptographers to deduce the unique key that encrypts a given conversation &#8211; was developed by volunteers around the globe using giant clusters of computers and gaming consoles.</p>
<p>Read more <a href="http://www.theregister.co.uk/2009/12/28/gsm_eavesdropping_breakthrough/" target="_blank">here</a>.</p></glossarycode></glossarycode>]]></content:encoded>
			<wfw:commentRss>http://www.megapanzer.com/2009/12/29/secret-code-protecting-cellphone-calls-set-loose/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Watching encrypted Skype traffic with SkypeDLLInjector</title>
		<link>http://www.megapanzer.com/2009/08/04/watching-encrypted-skype-traffic-with-skypedllinjector/</link>
		<comments>http://www.megapanzer.com/2009/08/04/watching-encrypted-skype-traffic-with-skypedllinjector/#comments</comments>
		<pubDate>Tue, 04 Aug 2009 12:30:22 +0000</pubDate>
		<dc:creator>carrumba</dc:creator>
				<category><![CDATA[Tools & sources]]></category>
		<category><![CDATA[DLL]]></category>
		<category><![CDATA[Eavesdropping]]></category>
		<category><![CDATA[Injection]]></category>
		<category><![CDATA[Skype]]></category>

		<guid isPermaLink="false">http://www.megapanzer.com/?p=2471</guid>
		<description><![CDATA[Tool name : SkypeDLLInjector version 0.1 &#160; Description : SkypeDLLInjector is a tool to demonstrate how DLL injection works. In this proof of concept it is applied to the Skype application. It consists of a loader application which remains running in the background and a DLL which will be injected into every newly started program [...]]]></description>
			<content:encoded><![CDATA[<table border="0" width="100%">
<tbody>
<tr valign="top">
<td width="30%"></td>
<td width="70%"></td>
</tr>
<tr valign="top">
<td><strong>Tool name</strong> :</td>
<td>SkypeDLLInjector version 0.1</td>
</tr>
<tr>
<td colspan="2">&nbsp;</td>
</tr>
<tr valign="top">
<td><strong>Description</strong> :</td>
<td>SkypeDLLInjector is a tool to demonstrate how DLL injection works. In this proof of concept it is applied to the Skype application. It consists of a loader application which remains running in the background and a DLL which will be injected into every newly started program via a system wide Windows hook.<br />
All what this tool does is interception the function calls recv() and send() to inspect the network data skype is sending and receiving. Because Skype traffic is encrypted only a small portion of the traffic is readable. But it could inspire you to create your own tools which eavesdrop other calls to intercept sensitive data (as the username and password for example).
</td>
</tr>
<tr>
<td colspan="2">&nbsp;</td>
</tr>
<tr valign="top">
<td><strong>Tested on</strong> :</td>
<td>Windows XP</td>
</tr>
<tr>
<td colspan="2">&nbsp;</td>
</tr>
<tr>
<td><strong>Feedback</strong> :</td>
<td>In case you encounter any problems with the tool, you have suggestions to improve it, or you tested it with a Windows version i&#8217;ve not yet tested please drop me an <a href="http://www.megapanzer.com/contact/">email</a>.</td>
</tr>
<tr>
<td colspan="2">&nbsp;</td>
</tr>
<tr valign="top">
<td><strong>Downloads</strong> :</td>
<td><a href="http://www.megapanzer.com/wp-content/uploads/skypedllinjector_binary.zip">Binary</a> | <a href="http://www.megapanzer.com/wp-content/uploads/skypedllinjector_source.zip" target="_blank">Source</a></td>
</tr>
<tr>
<td colspan="2">&nbsp;</td>
</tr>
</tbody>
</table>
]]></content:encoded>
			<wfw:commentRss>http://www.megapanzer.com/2009/08/04/watching-encrypted-skype-traffic-with-skypedllinjector/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Tools for eavesdropping and video hijacking.</title>
		<link>http://www.megapanzer.com/2009/08/03/tools-for-eavesdropping-and-video-hijacking/</link>
		<comments>http://www.megapanzer.com/2009/08/03/tools-for-eavesdropping-and-video-hijacking/#comments</comments>
		<pubDate>Mon, 03 Aug 2009 20:20:53 +0000</pubDate>
		<dc:creator>carrumba</dc:creator>
				<category><![CDATA[News & media]]></category>
		<category><![CDATA[Eavesdropping]]></category>
		<category><![CDATA[hijacking]]></category>

		<guid isPermaLink="false">http://www.megapanzer.com/?p=2552</guid>
		<description><![CDATA[Just found this article on cnet about eavesdropping and video hijacking. Showing off technology that James Bond would love, two researchers at Defcon on Friday demonstrated tools that allow people to eavesdrop on video conference calls and intercept surveillance camera video. An attacker needs to be in the same building as the victims to carry [...]]]></description>
			<content:encoded><![CDATA[<p><img src="http://www.megapanzer.com/wp-content/uploads/newspaper-150x150.jpg" alt="newspaper" title="newspaper" width="75" height="75" class="alignright size-thumbnail wp-image-2595" />Just found this article on cnet about eavesdropping and video hijacking.</p>
<p>Showing off technology that James Bond would love, two researchers at Defcon on Friday demonstrated tools that allow people to eavesdrop on video conference calls and intercept surveillance camera video.</p>
<p>An attacker needs to be in the same building as the victims to carry out the man-in-the-middle attacks over the network.</p>
<p>The free UCSniff tool, available in Linux and Windows versions, offers a slick graphical user interface for sniffing video, said Jason Ostrom, director of the Viper Lab at Sipera Systems. The tool basically tricks the voice-over-IP network carrying the video into sending the data packets to the attacker&#8217;s computer, he said.<br />
<span id="more-2552"></span><br />
This could be used to spy on people. For instance, an attacker could listen in on and record confidential conversations between an executive who is on a video conference call with another remote executive, according to Ostrom. </p>
<p>Read the full article <a href="http://news.cnet.com/8301-27080_3-10301329-245.html" target="_blank">here</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.megapanzer.com/2009/08/03/tools-for-eavesdropping-and-video-hijacking/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

