DEF CON 23 - Van Albert and Banks - Looping Surveillance Cameras through Live Editing

  Рет қаралды 167,800

DEFCONConference

DEFCONConference

Күн бұрын

Пікірлер: 113
@Dreadlockyx
@Dreadlockyx 9 жыл бұрын
"Zach is also a recent MIT graduate with over 0 years of security experience." laughed my ass off
@JonThomas92
@JonThomas92 7 жыл бұрын
"Everyone who cheered is a fed" that was the most I laughed at anyone's defcon intro ever.
@jodelboy
@jodelboy 9 жыл бұрын
This is now one of my top Defcon-talks. THANKS!
@MrKinir
@MrKinir 8 жыл бұрын
Yes it was amazing! Thanks guys!
@sirdouglashowel5thseat776
@sirdouglashowel5thseat776 8 жыл бұрын
very good talk!~
@jimothyus
@jimothyus 5 жыл бұрын
i love the description "Zach is also a recent MIT graduate with over 0 years of security experience" look at all that experience
@jenn5774
@jenn5774 6 жыл бұрын
these guys may not be the best speakers, and while high level this seems pretty self explanatory, these guys went all out and really committed to doing it properly, one of the best talks ive seen. Im happy they explained the lower levels without just showing how "cool" it is like some other talks do.
@lilliansmith6996
@lilliansmith6996 7 жыл бұрын
10:03 His statement about them being invisible to cable analyzers. It depends. The generic $100 ones you'll see many self-employed contractors use wouldn't see a difference. The test kits we lug around on a cart at work get fussy if we untwist the wires before terminating them. So it's likely they'd throw an error of some sort. But most cables are only certified and tested when they are installed, or if the devices they are connected to are having issues. So it's unlikely that a system like this would be discovered unless it caused a significant drop in performance.
@scotshabalam2432
@scotshabalam2432 6 жыл бұрын
That's what I was thinking with oscilloscopes. 50mhz might not spot it but a 1ghz would see the cable moving when they touched it. I agree with the conclusion unless it starts saying "you are being haxed lol, gg" with a cartoon dog dancing around the vault, which by the way I would love to see played out in a movie with a guard trying to figure out what's going on.
@spacepirateivynova
@spacepirateivynova 8 жыл бұрын
I don't think it was mentioned (Or I might have missed it during the talk), but the twisting itself is also extremely important, and untwisting them too much can cause degradation in the signal. You can tell a good network engineer and a wiremonkey using punchdown by how long the leads are before they twist up. It's a good idea to untwist as LITTLE as possible. Also, same thing with those who crimp their own cables, try to untwist as little as possible. It not only works better, it looks professional :)
@hyperhektor7733
@hyperhektor7733 6 жыл бұрын
i learned that up to 1,5cm ( 13/25 of an inch) is the max to go without problems
@arbyyyyh
@arbyyyyh 6 жыл бұрын
Yeah, they covered that in the talk.
@johnbrown1381
@johnbrown1381 2 жыл бұрын
Ahhh yes, thanks to common-mode rejection, any interference introduced on one single wire also gets introduced on the other wire in a twisted pair. Then the interference gets canceled out. This only works if they are twisted due to the fact that if the interference is allowed into only one single wire and not the other in the twisted pair, it gets accepted as a valid signal.
@ultraviper1884
@ultraviper1884 6 жыл бұрын
why does the con logo get more screen space than the actual presenters? wtf
@hyperhektor7733
@hyperhektor7733 6 жыл бұрын
its a scam
@tissuepaper9962
@tissuepaper9962 6 жыл бұрын
Because they can't really change the aspect ratio of the video, so, with the way they arranged the two streams, there is inevitably going to be a bunch of wasted screen real estate, which they decided to use for the logo.
@agumonkey
@agumonkey 8 жыл бұрын
Forget looping, time to play Mission Impossible level video games now
@over00lordunknown12
@over00lordunknown12 8 жыл бұрын
This was an amazing topic to cover, and I think that they covered it very well! However, I do not support bagging on Riley from National Treasure, that was what sparked my interest in technology as a kid.
@DrTune
@DrTune 8 жыл бұрын
Excellent work, I really like the Python stack for hacking the various protocol layers. Nice!
@gl_tonight
@gl_tonight 8 жыл бұрын
with access to two segments far enough apart im sure one could passively resolve individual bits streams from each end of a gigabit ethernet link with reasonable effectiveness
@ronanderson1023
@ronanderson1023 7 жыл бұрын
*Public Butt *Private Butt *Hybrid Butt *??? *Profit!
@mikemikson2565
@mikemikson2565 8 жыл бұрын
I never though it's possible to connect to Ethernet without disturbing connection :D
@DrTune
@DrTune 8 жыл бұрын
It isn't, not Gig-E anyway. You can (passively) tap 100mbit ethernet (see Great Scott's "Throwing Star Lan Tap") but the point of this is to modify the data not just sniff it). What their board is doing is the fancy equivalent of quickly unplugging the a network cable then reconnecting it to a dual-port NIC that is passing/modifying the packets. If you do it quickly it's pretty unlikely that anyone would notice. You're right to some degree - they point out in the Q+A that it's possible to optimize the renegotiation of the intercepting NICs so that there's no obvious up/down transition on the PHYs on network being patched;.
@davidthacher1397
@davidthacher1397 4 жыл бұрын
Wild card L2 forward ports or force VLAN ports on switch. Granted the switch has to support it but it would do this pretty easily. No POE outage, link log entries, or wire cuts. Isn't software just grand.
@JBFromOZ
@JBFromOZ 7 жыл бұрын
fantastic demo, love the giggling like a school girl!
@moth.monster
@moth.monster 6 жыл бұрын
What's next, they're gonna get Robert ')DROP TABLE Students;-- to present?
@Semperverus0
@Semperverus0 2 жыл бұрын
Little Bobby Tables we call him
@iDerekMC
@iDerekMC 6 жыл бұрын
the "cloud to butt" technique is awesome
@BierBart12
@BierBart12 2 жыл бұрын
The Advantages of Public Butt
@constantincolac1993
@constantincolac1993 6 жыл бұрын
Brilliant guys! Enjoyed the talk.
@NolePTR
@NolePTR 7 жыл бұрын
With MITM on HDMI you should be able to fake HDCP authentication, and forward decrypted steam elsewhere. Could just use multiple cables tho :/
@TekkGnostic
@TekkGnostic 8 жыл бұрын
Couldn't the signal be passively tapped (relative to the cable) with some opamps and a small battery? I'd think a simple voltage follower/unity-gain amp could feed off the lines and reproduce the signal with nearly zero current loss. (ed: nm I'm guessing that's what's being done with the usb supply.)
@ElectronicMarine
@ElectronicMarine 8 жыл бұрын
hmmm nice ideea, the only problem i could think is the capacitance of the lines... but they took it to the next level with the live editing of the live stream
@DrTune
@DrTune 8 жыл бұрын
A passive tap isn't very useful is it - the point is to intercept and modify the video, not just copy it.
@lmaoroflcopter
@lmaoroflcopter 7 жыл бұрын
Dr Tune I'd consider a passive tap useful. Being able to confirm viewing angles of camera feeds, occupation of rooms and movement of staff, etc.
@JoeArbiter
@JoeArbiter 7 жыл бұрын
Is there a device that can do this without splicing the wires even if the connection is broken for a few seconds? (ex taking the cat 5e and plugging it into the device while its connected into the system)
@stocktonjoans
@stocktonjoans 7 жыл бұрын
would be good to somehow connect 8, or at least 4 of the punch connector tools so you can make multiple conections at once
@nicholasosczypko2248
@nicholasosczypko2248 6 жыл бұрын
These guys are great...don't get me wrong....but, this reminds me of early Beavis and Butthead episodes. "Hey Beavis....yeah?... I totally changed their website to butt...huh..hee hee...ugh huh hee...TP my bunghole!"
@zwei-p1993
@zwei-p1993 3 жыл бұрын
best opening ever
@ZeroG84
@ZeroG84 7 жыл бұрын
hmm. Easy low level safety against this would be a clock on top of that safe that can't be manipulated and would be easy to detect if looped. Cool show still.
@SonOfNone
@SonOfNone 6 жыл бұрын
.... or just Gigabit infrastructure as he stated at the beginning... If you have a business which has a safe which is being monitored by camera on a 10[0]baseT network...
@ebouwman034
@ebouwman034 Жыл бұрын
They basically covered that with the timestamp thing. Just merge that part of the stream.
@wagyourtai1
@wagyourtai1 6 жыл бұрын
the vault looks like it's probably a ch751 anyway :P
@rkpetry
@rkpetry 7 жыл бұрын
[00:00] Introducer does a good 'Trump' imitation before that became popular... [07:39] couldn't you tap in two places and combine differentially for direction... [12:29] "without ever interrupting"-but it is interrupting impedance-matching... gradual-transition might be done with a ferrite clamp and 'smart' terminators...
@rkpetry
@rkpetry 7 жыл бұрын
[30:45] You could try Trojan-joke-ware to make it look like the camera fell off its mount and is dangling-about on its cable-distracting viewers a few seconds....
@iDerekMC
@iDerekMC 6 жыл бұрын
23:09 and what about RTMP :D
@OlafurArons
@OlafurArons 7 жыл бұрын
Amazing stuff.
@washboardman7435
@washboardman7435 7 жыл бұрын
But how do we know they didn't live edit the camera showing the video feed to look like they looped the feed, but didn't?
@jean-jacqueschirac8733
@jean-jacqueschirac8733 7 жыл бұрын
Anyone else think of payday ?
@netraft_4435
@netraft_4435 7 жыл бұрын
Jean-Jacques Chirac guys the thermal drill, go get it
@alanstone3125
@alanstone3125 8 жыл бұрын
almost like beavis and butthead but for entertainment sheer brilliance
@Bigonewsnetwork808
@Bigonewsnetwork808 7 жыл бұрын
You can run it on the new pi lol its 64 bits now .
@damianhardouin1137
@damianhardouin1137 7 жыл бұрын
throw in a gsm sim for a remote connection
@AgentOffice
@AgentOffice 7 жыл бұрын
incredible
@unixfreak
@unixfreak 7 жыл бұрын
Awesome
@amstorm8954
@amstorm8954 5 жыл бұрын
NSA like ''hold my beer''
@tokenlectronix5223
@tokenlectronix5223 4 жыл бұрын
HAK5 now has man in the middle for hdmi
@LemonChieff
@LemonChieff 6 жыл бұрын
this is epic
@Add12this
@Add12this 8 жыл бұрын
Guy asking question: "...ninth degree." ...you mean n'th degree?? lol.
@DerUnbekannte
@DerUnbekannte 6 жыл бұрын
a ninth degree of most things is also a lot
@famousamoso7
@famousamoso7 4 жыл бұрын
Freudian slip
@davemann6030
@davemann6030 7 жыл бұрын
Most security guards don't give a shit what happens you won't even need that. Most of the videos are very small and they don't even look at them it is just when something happens they have to spend a lot of time rerunning the video to see what happened by that time they bad guys are long gone.
@Crucizer
@Crucizer 5 жыл бұрын
Someone: What Do You Do? Me: I Do Shit.
@verymuchgoodgaming132
@verymuchgoodgaming132 9 жыл бұрын
cool shit ;)
@chickenlivers
@chickenlivers 9 жыл бұрын
The only other evidence is the punched/spliced wires :)
@eleftherios11
@eleftherios11 8 жыл бұрын
which won't have to be inspected if nothing breaks up
@SomeGuyFromCrowd
@SomeGuyFromCrowd 8 жыл бұрын
Solution: Lots of thermite
@lmaoroflcopter
@lmaoroflcopter 7 жыл бұрын
Steven Haussmann go the route of "badboys 2" and when you're out the building, blow up the tap device.
@redd_cat
@redd_cat 6 жыл бұрын
I think the wires are the least of a banks problem if this were to happen to them.
@hackbitchhackingbaarbi3426
@hackbitchhackingbaarbi3426 6 жыл бұрын
good
@jasonportnoy7866
@jasonportnoy7866 8 жыл бұрын
love this shit
@DoRC
@DoRC 7 жыл бұрын
Cool concept.... But man that delivery....
@timothyferrell245
@timothyferrell245 7 жыл бұрын
@22:00 I was laughing along.
@3rdgig
@3rdgig 4 жыл бұрын
10/10 good shit
@sadface
@sadface 7 жыл бұрын
cool shit
@paul123701
@paul123701 6 жыл бұрын
Guys has anyone seen bain, I have an idea to tell him
@mariarahelvarnhagen2729
@mariarahelvarnhagen2729 Жыл бұрын
Cool Down Down Date & Time For A Minute
@opiniondiscarded6650
@opiniondiscarded6650 5 жыл бұрын
I'd tap that
@DaltonR121
@DaltonR121 8 жыл бұрын
2 people got caught trying to rob a bank without this method.
@SouravBasuRoy
@SouravBasuRoy 4 ай бұрын
this dude talks exactly like Jesse Eisenberg did you notice?
@noobvisual1588
@noobvisual1588 4 жыл бұрын
Vigil players when they use erc-7
@izafas
@izafas 8 жыл бұрын
kid in black laughs like a dweeb
@over00lordunknown12
@over00lordunknown12 8 жыл бұрын
I haven't seen anyone use that insult in a long time... But it is true. x)
@PeterVanHertum
@PeterVanHertum 7 жыл бұрын
it's called a nerdgasm
@alexoja2918
@alexoja2918 6 жыл бұрын
Cute girl though
@XDRosenheim
@XDRosenheim 6 жыл бұрын
_inhales_ heee
@HylianOverlord
@HylianOverlord 6 жыл бұрын
'tism laughing.
@claudiahampton9946
@claudiahampton9946 8 жыл бұрын
If Anyone is looking to buy one of these tap boards "PCB Board Only" I've purchased 20 of them to get into programming. Just be aware that the project can get quite pricey. The Boards are cheap to produce, but some of the components to complete a working board can cost around 190 bucks all together. I'm selling the boards for 15 bucks each with shipping included. I bought them in bulk before I knew how much all the components to complete the board cost. If you'd like a picture of the boards I have just shoot me a message.
@claudiahampton9946
@claudiahampton9946 8 жыл бұрын
if you download REV 3 from their Github. From there you should see the DOM. That is a list of all the components. All you have to do is import the DOM into digikey. All the components cost around 212 USD.
@pierrekircher4383
@pierrekircher4383 8 жыл бұрын
github.com/ervanalb/lens/blob/master/hardware/release/bom.txt its all in there , the expensive part are the relays all other parts are cheap
@randall3981
@randall3981 8 жыл бұрын
Claudia Hampton do you have any additional boards available for purchase?
@Mastermodr94
@Mastermodr94 7 жыл бұрын
Do you have any pcbs? I would be willing to buy one or two off you and pay for shipping.
@GhostsPlace
@GhostsPlace 6 жыл бұрын
Can't you use cheaper relays?
@Cray2TheZ
@Cray2TheZ 7 жыл бұрын
A brilliant presentation despite the ANNOYING PERSON GIGGLING IN HIS MIC. Amazing work anyway !
@radekwysocki7875
@radekwysocki7875 7 жыл бұрын
BEEF!!
@jonascurry9996
@jonascurry9996 8 жыл бұрын
thats alot of shit lol haha
@ApexPredatorChrisHansen
@ApexPredatorChrisHansen 7 жыл бұрын
intro from king cringe
@AholicKnight
@AholicKnight 7 жыл бұрын
he said a lot of cool shit
@fredhauser7357
@fredhauser7357 7 жыл бұрын
anyone here that girly mouse laugh lol!!!
@Rising_Pho3nix_23
@Rising_Pho3nix_23 6 жыл бұрын
The easier solution is not to tap the ethernet traffic, but the video feed. Duplicate what goes into the glass lenses, and then feed that into the circuit directly. That's the same as the "low tech" that they said was "too easy"...Gotta love it when people pride themselves in making things harder and more risky than required.
@Mostlyharmless1985
@Mostlyharmless1985 6 жыл бұрын
brandon day the video feed IS the Ethernet traffic.
@over00lordunknown12
@over00lordunknown12 8 жыл бұрын
Am I the only one that gets annoyed by people with speech patterns like the guy in orange?
@maxmanwar
@maxmanwar 7 жыл бұрын
They've DEFINATELY never seen any decent cable diag machine. I've practiced with one this year in school and a tiny 1500€ monster knows every fucking twist in the cable in 30 km radius. They're monsters to detect any change in the cable. The Rtp&video part was boring af.
@yepee1
@yepee1 2 жыл бұрын
Incredible
СИНИЙ ИНЕЙ УЖЕ ВЫШЕЛ!❄️
01:01
DO$HIK
Рет қаралды 3,3 МЛН
Support each other🤝
00:31
ISSEI / いっせい
Рет қаралды 81 МЛН
I'll Let Myself In: Tactics of Physical Pen Testers
44:56
Wild West Hackin' Fest
Рет қаралды 2,9 МЛН
Defcon 21 - Stalking a City for Fun and Frivolity
45:20
HackersOnBoard
Рет қаралды 247 М.
DEF CON 26 - Si, Agent X - Wagging the Tail:Covert Passive Surveillance
47:14
DEFCON 17: That Awesome Time I Was Sued For Two Billion Dollars
31:28
Christiaan008
Рет қаралды 1,6 МЛН
Solving a REAL investigation using OSINT
19:03
Gary Ruddell
Рет қаралды 208 М.
DEFCON 16: Toying with Barcodes
44:26
Christiaan008
Рет қаралды 371 М.