How to DDOS a federal wiretap
November 12, 2009 by Infowars Ireland
By Robert McMillan, IDG News Service
www.networkworld.com
Researchers say that wiretapping equipment standards aren’t up to the task
Researchers at the University of Pennsylvania say they’ve discovered a way to circumvent the networking technology used by law enforcement to tap phone lines in the U.S.
The flaws they’ve found “represent a serious threat to the accuracy and completeness of wiretap records used for both criminal investigation and as evidence in trial,” the researchers say in their paper, set to be presented Thursday at a computer security conference in Chicago.
Following up on earlier work on evading analog wiretap devices called loop extenders, the Penn researchers took a deep look at the newer technical standards used to enable wiretapping on telecommunication switches. They found that while these newer devices probably don’t suffer from many of the bugs they’d found in the loop extender world, they do introduce new flaws. In fact, wiretaps could probably be rendered useless if the connection between the switches and law enforcement are overwhelmed with useless data, something known as a denial of service (DOS) attack.
Four years ago, the University of Pennsylvania team made headlines after hacking an analog loop extender device they’d bought on eBay. This time, the team wanted to look at newer devices, but they couldn’t get a hold of a switch. So instead they took a close look at the telecommunication industry standard — ANSI Standard J-STD-025 — that defines how switches should transmit wiretapped information to authorities. This standard was developed in the 1990s to spell out how telecommunications companies could comply with the 1994 Communications Assistance for Law Enforcement Act (CALEA).
“We asked ourselves the question of whether this standard is sufficient to have reliable wiretapping,” said Micah Sherr, a post-doctoral researcher at the university and one of the paper’s co-authors. Eventually they were able to develop some proof-of-concept attacks that would disrupt devices. According to Sherr, the standard “really didn’t consider the case of a wiretap subject who is trying to thwart or confuse the wiretap itself.”
It turns out that the standard sets aside very little bandwidth — 64K bits per second — for keeping track of information about phone calls being made on the tapped line. When a wire tap is on, the switch is supposed to set up a 64Kbps Call Data Channel to send this information between the telco and the law enforcement agency doing the wiretap. Normally this channel has more than enough bandwidth for the whole system to work, but if someone tries to flood it with information by making dozens of SMS messages or VoIP (voice over Internet protocol) phone calls simultaneously, the channel could be overwhelmed and simply drop network traffic.
That means that law enforcement could lose records of who was called and when, and possibly miss entire call recordings as well, Sherr said.
Back in 2005, the FBI downplayed the Penn team’s loop extender research, saying that it applied to only about 10 percent of wire taps. The J- standard studied in this paper is much more widely used, however, Sherr said. An FBI representative did not return messages seeking comment for this story. Read more…
Related posts:
- Bush FBI sent 18 armored agents to search my house, wiretap whistleblower says John Byrne Raw Story Friday, June 5, 2009 The Bush...
- Ex-IBM Employee reveals TV Abandoned Analog Band to Make Room for RFID Chips According to a former 31-year IBM employee, the highly-publicized,...
- Intel: Chips in brains will control computers by 2020 www.computerworld.com Brain waves will replace keyboard and mouse, dial...
- Cell Phone Ultrasound Device Like Trek ‘Tricorder A small handheld ultrasound probe used in conjunction with a...
- Spanish PM under fire as wiretap scandal heats up www.expatica.com The Popular Party is accusing Prime Minister Zapatero...
- Breaking Web Browsers’ Trust Researchers reveal a flaw with the way most Web browsers...
- European Union to police drivers with black boxes www.timesonline.co.uk THE European Union is drawing up plans for...
- Nose scanning techniques could sniff out criminals By Doreen Walton Science reporter, BBC News 2 March...
- Traffic wardens get head cameras www.telegraph.co.uk Council traffic wardens are being fitted with head...
- Human fear-smelling device could help spot terrorists www.andhranews.net Scientists from City University London have developed what...
































































Comments
Feel free to leave a comment...
and oh, if you want a pic to show with your comment, go get a gravatar!