[00:00.000 --> 00:00.300] Okay. [00:01.580 --> 00:03.040] Thank you, everybody, for coming out tonight. [00:08.400 --> 00:08.960] How's that? [00:10.440 --> 00:10.840] Okay. [00:11.400 --> 00:12.760] Thanks, everybody, for coming out tonight. [00:13.300 --> 00:19.500] Tonight we're going to talk about radio reconnaissance and penetration testing, or all your RFR belong to us. [00:20.320 --> 00:25.280] Throughout the talk, if anybody has any questions, raise your hand if I can see you. [00:26.540 --> 00:29.760] I'll call on you, repeat the question, and get it answered. [00:30.060 --> 00:33.560] If it starts to be too many questions, I might have them be held to the end, just to... [00:33.580 --> 00:34.580] keep it flowing along. [00:34.760 --> 00:38.160] But definitely, as it's going along, raise questions, want this to be good and interactive. [00:40.080 --> 00:43.300] So before we get started, just a brief synopsis about myself. [00:43.600 --> 00:47.040] Matt Neely, some of you might know me as Zamboni, as a handle. [00:47.340 --> 00:49.720] I'm the manager of the profiling team at SecureState. [00:49.840 --> 00:54.360] Basically means I run a group of ethical hackers that do a variety of penetration tests. [00:55.020 --> 01:07.980] My area of expertise, wireless penetration testing, physical security, security convergence, which is basically taking physical security devices, attaching them onto the network, with often hilarious consequences. [01:09.240 --> 01:11.240] And then also instant response. [01:11.620 --> 01:13.360] I've been doing security for about 10 years. [01:14.100 --> 01:21.140] Before getting into the consulting world, formed a TSCM team at a Fortune 200 company. [01:21.420 --> 01:29.480] And this is basically the group that went around, did bug sweeping, followed executives, make sure no one was bugging their activities, swept conference rooms, that type of thing. [01:29.700 --> 01:31.360] So again, very RF intensive. [01:32.540 --> 01:39.100] Outside of work, do a lot of security stuff, host of the security justice podcast, with a bunch of other guys. [01:39.340 --> 01:41.600] I have some stickers up here if anybody wants it. [01:41.760 --> 01:43.680] If you're looking for a new podcast, check it out. [01:43.920 --> 01:45.840] One note, it is filmed in a bar. [01:47.880 --> 01:51.720] So as the night goes on, the language becomes more and more bar appropriate. [01:52.000 --> 01:57.260] So probably not good to listen to when you have your kids in the car, but it's usually a fun time. [01:57.900 --> 02:00.760] I'm also one of the co-founders of the Cleveland Lockpick Group. [02:00.760 --> 02:02.780] Been involved in the Lockpick community for a while. [02:03.160 --> 02:06.100] Also been an amateur radio operator for about 20 years now. [02:06.620 --> 02:07.340] Technician grade. [02:07.980 --> 02:09.880] Highly recommended for anyone that wants to get into radio. [02:10.080 --> 02:11.900] Learned about radio theory, that type of stuff. [02:12.740 --> 02:16.400] And then finally, the radio up there is the first radio ever hacked. [02:16.560 --> 02:19.000] The Fisher-Price Skytalker walkie-talkie. [02:19.340 --> 02:23.560] When I was a kid, got tired of all those radios work on the same frequency. [02:23.860 --> 02:29.780] So if other kids in the neighborhood had the same radio, they could hear everything I was saying and they could, you know, interfere and stuff. [02:29.780 --> 02:31.700] So opened up the pair I had. [02:32.040 --> 02:33.960] Retuned them so they worked on a different frequency. [02:34.440 --> 02:36.920] Probably highly legal from the FCC point of view, but hey. [02:38.120 --> 02:42.120] And then basically retuned them so they could operate on their own frequency. [02:42.120 --> 02:45.700] So then me and my friends could have our own private little radio net going. [02:48.730 --> 02:50.550] So now onto the meat of the talk. [02:51.110 --> 02:55.030] This picture here is a visual representation of the radio spectrum. [02:55.030 --> 02:57.350] Don't really need to get the general gist of it. [02:57.890 --> 03:01.310] But it covers 3 kilohertz up to 300 gigahertz. [03:01.850 --> 03:07.770] Now the key here is, in most penetration tests, people are only looking at really two areas. [03:08.630 --> 03:12.630] The 2.4 gigahertz spectrum and the 5 gigahertz spectrum. [03:12.810 --> 03:14.770] So you're talking about basically Wi-Fi here. [03:16.770 --> 03:20.470] A, B, G, possibly N, depending on the testers. [03:20.470 --> 03:23.650] But a pretty narrow scope, maybe they'll include some Bluetooth. [03:23.990 --> 03:26.670] But for the most part, they're missing a huge spectrum. [03:28.250 --> 03:32.650] So what are some of the things that could be missing during a penetration test that just looks at these areas? [03:33.270 --> 03:40.930] You can have guards, guard radios, cordless phones, wireless headsets, security cameras. [03:41.450 --> 03:48.190] All sorts of other things can take place in this area that can be of interest to penetration testers, to people trying to gain access to corporations. [03:50.010 --> 03:54.410] The general summary of the talk is, if I have your frequencies, I will own you. [03:58.100 --> 04:00.320] Before we get started, just a couple of legal issues. [04:01.600 --> 04:03.560] First thing, I am not a lawyer. [04:04.520 --> 04:10.460] So, you know, anything I tell you here, be sure to run it by your legal counsel first to make sure you're not breaking the law. [04:12.800 --> 04:16.840] First big area, know the wiretap laws in your area and be sure not to violate them. [04:17.680 --> 04:18.300] You know, for example... [04:19.240 --> 04:20.100] Someone have a question? [04:20.540 --> 04:20.880] Nope, okay. [04:21.100 --> 04:25.540] For example, in some states, it requires two-party consent to record a phone call. [04:25.840 --> 04:30.940] So unless both parties give consent to have a phone call recorded, you could be violating the wiretap law in that state. [04:31.440 --> 04:36.700] So depending on what you're doing in terms of monitoring transmissions, you could be violating wiretap laws. [04:36.820 --> 04:39.140] So be sure to know those laws and obey them. [04:40.060 --> 04:43.080] Second, know the scanner laws for the state in which you operate in. [04:43.720 --> 04:48.660] Some states do not allow you to have scanners in your cars, in vehicles. [04:49.280 --> 04:53.280] You need to know that before you enter into that state, so you're not breaking the law when you get there. [04:54.480 --> 05:00.180] Second, make sure any activities that you are going to be performing or authorizing the rules of engagement you have set up with the client. [05:00.340 --> 05:08.100] If you're going to be monitoring things like wireless headsets, cameras, other things, make sure it's within the scope of the engagement, and you're legally allowed to be performing it. [05:08.900 --> 05:15.300] And finally, in most states, it is legal to monitor any radio transmission as long as it's not telephone or pager traffic. [05:15.560 --> 05:20.560] So from a legal point of view, there's a huge range out there as long as it's not, and again, telephone or pager traffic. [05:22.460 --> 05:25.380] A couple more illegal activities to avoid. [05:25.900 --> 05:27.620] First, I am still not a lawyer. [05:28.760 --> 05:31.480] Second, some activities that should be avoided. [05:31.780 --> 05:33.640] Jamming of any sort is illegal. [05:33.960 --> 05:46.120] Even if a client says you're able to jam transmissions on our property to test how resistant our network is to cell phone jammers, to this, to that, even if it's on their property, they don't actually own the spectrum. [05:46.120 --> 05:47.620] The spectrum is owned by the U.S. government. [05:49.040 --> 05:52.540] So unless the U.S. government is giving you permission to do it, you can't actually jam it inside the United States. [05:52.940 --> 05:56.920] So unless you're actually working for the government, you will not have permission to actually jam transmissions. [05:57.720 --> 06:00.960] Second, decoding pager traffic is also illegal. [06:02.460 --> 06:13.400] Sadly, this is an area that can't really be delved into too much, considering when you look at most companies, there's a lot of sensitive information that is transmitted through pagers that could be easily decoded with freely available software. [06:13.760 --> 06:17.580] But in terms of illegal activities, that's something that is not legally allowed. [06:18.320 --> 06:20.620] Secondly, be careful about actually transmitting. [06:21.460 --> 06:26.040] Unless you are licensed to transmit on a specific frequency, it, again, be illegal to transmit on that frequency. [06:26.280 --> 06:34.480] So if you're monitoring guard transmissions, want to throw them off by transmitting something back to them, pretend to be a guard, most likely that would be an illegal transmission, unless you're allowed to do it. [06:36.540 --> 06:47.120] So now that we're past all the legal warnings, get into kind of the steps I take when performing a physical pen-test or a logical pen-test to start pulling into radio traffic. [06:47.500 --> 06:50.220] First thing, like any penetration test, you want to profile the target. [06:51.520 --> 06:57.280] Profile the target to figure out information about it, start to gather up some facts that can help you in future attacks. [06:59.400 --> 07:10.260] Before I get on-site, I like to do some basic off-site profiling, basically to determine as much information as I can about the site and if radio traffic is in scope, about the radio systems that you use. [07:10.480 --> 07:15.800] A couple of examples of things you might want to be looking for, are they using an in-house or contract guard force? [07:16.560 --> 07:20.940] If they're using a contract guard force, you can then look up for that guard force or frequencies they use. [07:21.060 --> 07:25.260] If you use an in-house guard force, again, you can look up frequencies that are registered to that corporation. [07:26.080 --> 07:27.540] A nice bit of information to know. [07:27.660 --> 07:36.780] It could also change your plan of attack depending on if it's an in-house or outsourced guard force that could also adjust how you want to approach the organization during a physical penetration test. [07:37.660 --> 07:41.320] Next, you can look up what frequencies the corporation is licensed to use. [07:41.480 --> 07:43.120] Next page, we'll discuss how to find those. [07:43.360 --> 07:46.200] And then also see if you can find the make and model equipment they're using. [07:46.780 --> 07:49.600] Through news releases and stuff, you can sometimes find this information out. [07:51.100 --> 07:54.620] So, the easiest way to find this information out is ask the Oracle and go to Google. [07:55.260 --> 08:01.220] Some ideas of things you might want to Google, things like company name and then just scanner frequency, guard frequency, megahertz. [08:01.900 --> 08:14.500] There are tons of radio enthusiast websites out there which have already categorized large portions of the spectrum and have already set up, you know, here's for company A, here's our guards, here's the taxi service, here's this, here's that. [08:14.660 --> 08:19.000] So, lots of hobbyist websites out there that will already have a lot of information already figured out for you. [08:19.600 --> 08:21.100] Use Google to find that information. [08:21.980 --> 08:26.760] Next, look for things like press releases from radio manufacturers, resellers, other ones regarding the target. [08:28.160 --> 08:39.660] If a large manufacturer, you know, if Motorola sells a large radio system to company access to a well-known radio system, they could put out a press release saying, hey, we just sold this multimillion dollar radio system to this company that has all these features, [08:39.840 --> 08:41.060] does this, does that, does this. [08:41.400 --> 08:48.660] Great information when Pro found the target because you now know what features a radio system has, often what's been enabled, what the equipment can support, all sorts of good stuff. [08:49.660 --> 08:53.120] Additionally, look for similar press releases from guard outsourcing companies. [08:53.580 --> 08:59.180] If a guard company gets a contract with a large employer, they'll often, if they can, brag about it through press releases. [08:59.360 --> 09:03.340] So again, good way to figure out who's actually doing the guard services for the company. [09:03.720 --> 09:04.900] Again, additional information. [09:05.920 --> 09:10.300] Other good places to look online, one of my favorite sites is radioreference.com. [09:10.720 --> 09:17.180] They have a free section which has a huge database of frequencies out there basically populated by radio enthusiasts. [09:17.500 --> 09:25.560] So you can look up an area, pull up the frequencies you use for that area, dig through it, possibly you'll find your target in there with the frequencies listed. [09:27.000 --> 09:36.120] If you don't find the information there, if they're using FCC license frequencies, well, it should be licensed to the FCC, but sometimes they'll actually do it through a reseller. [09:36.240 --> 09:40.920] So the company name may not be listed and maybe the company that they bought the radios through or they're leasing them through. [09:42.060 --> 09:45.720] But if it is under the company name, you can search the FCC database directly. [09:46.520 --> 09:53.740] The FCC database itself can be downloaded online, searched through, but it's generally easier to just pay to use a third party service. [09:54.820 --> 09:57.700] National Radio Data is one of them, PerCom is another one. [09:57.840 --> 09:59.720] Two companies to check out for that service. [10:00.260 --> 10:00.320] Yeah? [10:00.400 --> 10:03.520] What's better about those than the FCC website? [10:03.920 --> 10:08.680] The FCC website, as I recall, you actually need to download the database directly. [10:08.700 --> 10:18.000] You can't actually search it through the FCC website, but you can download the database files and then you need to set up to parse through the database files. [10:18.140 --> 10:29.220] So depending on time activity and other things, and also the FCC database seems to fluctuate between being available for free online or being on some broken part of the FCC website, so you can actually download it. [10:30.700 --> 10:33.940] If you have the time, resources, download it, parse through it. [10:34.280 --> 10:36.740] If not, it could be easier just to pay to 30 bucks a year. [10:38.320 --> 10:46.120] The other interesting thing, if you do download the database directly, they do have latitude and longitude for the license location for the transmitters. [10:46.500 --> 10:48.240] So that can be very handy as well. [10:48.240 --> 10:51.240] And that's actually one service that PerCom offers. [10:51.440 --> 10:57.140] You can type into latitude and longitude, show all transmitters within 100 miles, 10 miles, whatnot. [10:57.900 --> 11:02.880] We'd use that service a lot when we were doing bug sweeping, because we need to know the legitimate frequencies in that area. [11:03.040 --> 11:14.620] So we would basically run a report from them saying, okay, they're staying at this hotel, show me all transmitters within X number of miles, so then we know, have a list of possible friendly frequencies in the area when we go into this, in to do our sweep. [11:15.100 --> 11:15.540] Yeah? [11:19.620 --> 11:20.320] I have one second, man. [11:20.600 --> 11:22.300] I'm about to combine yours with Martin Martin. [11:22.640 --> 11:36.100] And he had mentioned that on the facility they used something, or there was something that they were doing that prevented cell phones from single-prone person from leaving the grounds. [11:36.820 --> 11:40.000] But he was an engineer, so he really didn't know where he was talking about it. [11:40.000 --> 11:44.140] So that seems to apply to me, though, if it's not jammed. [11:45.520 --> 11:52.480] The question is, personally, if somebody works at a site that claims to block cell phone transmissions from leaving the site? [11:52.720 --> 11:54.960] I would think this is a DOD contractor. [11:55.640 --> 11:58.300] If you work at the other companies, would they be able to buy this? [12:00.460 --> 12:03.240] Possible that they would have the ability to jam transmissions. [12:03.400 --> 12:13.180] Most likely, what they're doing is most companies now will either shield hold buildings, so that basically you just have a Faraday cage so transmissions can't enter or exit. [12:13.820 --> 12:23.160] And also, if there's any sort of classified work that's being worked on, they'll usually be done inside a SCIF, which is basically a sealed vault where even if you took a transmitter inside of there, it couldn't transmit out. [12:23.760 --> 12:26.040] But a lot of those places, you also have to check your cell phone at the door. [12:26.160 --> 12:28.200] So they're usually kind of varying layers of defense. [12:28.420 --> 12:30.980] Most of the ones I've seen, though, aren't actually using jamming. [12:31.180 --> 12:32.620] They're just shielding the whole building. [12:32.620 --> 12:38.620] Because the other plus there is, if anyone brings in any sort of transmitter, a jammer is only going to work on a set range. [12:39.260 --> 12:45.540] Where if someone brings in any sort of transmitter, it's going to help deaden that signal and block it, so it could prevent other types of transmissions as well. [12:49.470 --> 12:50.670] Here's just a quick example. [12:51.470 --> 13:04.810] You know, literally a couple seconds on Google, did a search for, you know, double parentheses, or quote, Hotel Pennsylvania, end quote, frequency, and pulled up this hobbyist site that listed all these frequencies in New York City. [13:05.990 --> 13:15.510] Hotels are very popular, casinos are very popular, but even businesses in the area, if they have radios, you know, there are guys that this is, they spend all day listening to the radio, categorizing everything. [13:15.810 --> 13:17.110] Great resource to use. [13:20.360 --> 13:25.400] Next, when I arrive on site, there are a couple of steps I take to profile the target. [13:26.540 --> 13:28.740] First thing that I like to use is something called a frequency counter. [13:30.460 --> 13:32.220] This is an example of one up here. [13:32.620 --> 13:34.960] This is a great little device, pretty small. [13:35.380 --> 13:37.740] You can change on a couple of different antenna types. [13:37.900 --> 13:53.260] And what this does is basically finds near-field signals, so if it's a strong signal that's basically general rule of sight, if it's a mobile transmitter or a tower within sight, if it's a walk around like walkie-talkie, it's going to be 20 to 50 feet. [13:53.980 --> 13:57.440] Anything that transmits near this, it's going to record the frequency in this. [13:59.560 --> 14:02.120] And then you can use that to basically footprint the area. [14:02.520 --> 14:08.760] The one thing I like about the Scout, most frequency counters only can record one frequency at a time. [14:09.020 --> 14:15.260] The Scout can actually record, I believe it's 500 frequencies, and they can tell if each frequency has been hit up to 256 times. [14:15.560 --> 14:23.640] So it's very easy to run this through an area and basically take it back and see, okay, we have one frequency that was hit 100 times. [14:24.300 --> 14:26.180] Probably something of interest on that frequency. [14:27.580 --> 14:32.600] The analog Scout, which is the one you'd want for most use, I believe is $300 to $400. [14:33.700 --> 14:35.100] You can find them used. [14:35.280 --> 14:38.140] One tip if you find them used, I guarantee the battery pack will be dead. [14:38.360 --> 14:39.420] That's when most people sell them. [14:39.840 --> 14:42.160] Anyone that has any electronics experience can pop it open. [14:42.380 --> 14:49.000] Go down to RadioShack, your local battery store, get another, just four AAA batteries, pop it in, good as new. [14:50.180 --> 14:56.640] The other quick thing to note with these, if you do get them online, the front end amplifier is very sensitive and can often get blown out. [14:56.860 --> 14:59.740] So there's definitely a roulette game if you get it online. [14:59.860 --> 15:03.080] If that amplifier is blown out, the cost to fix it, you might as well buy a new radio. [15:04.720 --> 15:05.360] Question in back? [15:05.760 --> 15:06.880] What about trunking? [15:08.120 --> 15:10.100] Trunking, I'll be discussing that a little bit later. [15:11.080 --> 15:15.960] There is a digital version of the Scout, which can lock on to digital signals. [15:16.200 --> 15:18.760] So if it's something like APCO 25 or another digital format. [15:20.180 --> 15:29.220] Generally, though, that I found to be less useful because for the most part, if someone's using a digital radio system, unless you have a very high end gear, you're not going to be able to decode it. [15:29.460 --> 15:31.620] The question was, what about trunking systems? [15:32.840 --> 15:37.120] So for the most part, I just recommend going to the Analog Scout, but we'll talk about some of the trunking stuff later on. [15:37.680 --> 15:39.200] A couple of problems with this. [15:39.780 --> 15:42.400] It can be difficult to use in urban-rich area. [15:42.400 --> 15:55.140] For instance, inside New York City, this device would basically be worthless because it's going to lock on to the strongest signal and since there are so many TV transmitters in there and other things, basically the strongest signal is going to be the local TV station, [15:55.340 --> 15:56.540] not the guard radio. [15:58.020 --> 16:00.440] So just something to keep in mind, but a handy little tool. [16:02.900 --> 16:03.300] Yeah? [16:03.840 --> 16:04.240] If [16:07.580 --> 16:15.400] you do buy them off the eBay, they don't come with a power supply, be very careful about reversing the... [16:34.090 --> 16:40.330] Yeah, basically to repeat, the power supply in this, if you order it from eBay, may not come with a power supply. [16:40.490 --> 16:48.310] If you purchase one, make sure the polarity is correct because they don't even, you know, they didn't spend the two cents to put some diodes into this to protect you from connecting the wrong polarity. [16:48.310 --> 16:52.110] So if you connect the wrong polarity, you're going to blow the power supply and you need to get it repaired. [16:57.200 --> 17:00.060] Okay, on to some stuff to do for on-site recon. [17:01.480 --> 17:05.500] When you get there, try to visually identify a number of items. [17:06.040 --> 17:07.780] Look for the make and model of the radio. [17:08.420 --> 17:09.860] Note the length and type of antenna. [17:11.620 --> 17:20.600] If you have something that's a very short antenna versus a very long antenna, that's going to tell you something about the frequency range that's being used. [17:20.600 --> 17:24.280] Generally, the longer the antenna, the lower the frequency range. [17:24.860 --> 17:29.720] This is where getting into some of the ham radio stuff can be helpful to start to understand the physics involved. [17:31.020 --> 17:34.900] Also, be sure to note if they're using the same make and model of radio or if there's a mix. [17:36.520 --> 17:45.820] If there's a mix of radios, most likely they're not using any special features like trunking or encryption because generally those features do not work well across radio models. [17:45.980 --> 17:52.180] So if you're seeing a site where there are four different radio types, most likely they're not using anything super special because they need to get all these radios to work together. [17:52.920 --> 17:57.980] And generally, radios of different makes and models can sometimes not play well together on the same system. [17:59.680 --> 18:04.200] Using information gathered to determine things like frequency range and what features are used. [18:04.700 --> 18:11.580] Based off the make and model, you can then figure out if it support digital, trunking, encryption, those type of things. [18:12.220 --> 18:17.760] Something that would be very helpful here is to get a camera, take a picture, and then do some online searching for manufacturer. [18:18.560 --> 18:20.400] Radio geeks like myself, I've been doing this a while. [18:20.560 --> 18:26.780] I can look at a radio, know the make and model, tell you other sorts of things about it just because that's what I obsess about at home. [18:27.640 --> 18:30.420] For other folks, you know, get a picture, start looking online. [18:31.640 --> 18:35.600] Batlabs.com is a phenomenal site for anything related to Motorola radios. [18:37.900 --> 18:41.100] Next one is, again, on-site profiling. [18:41.240 --> 18:45.900] This is very resource intensive, but basically start searching common frequency ranges. [18:46.200 --> 18:55.660] You know, there's certain common frequency ranges people use, FRS, GMRS, dot frequencies, and then some ranges listed below that business and other things tend to fall into. [18:56.160 --> 18:57.880] Search these ranges looking for activity. [18:58.160 --> 19:02.380] Again, it's very resource intensive because you need to hear someone when they're transmitting. [19:02.840 --> 19:08.540] It can take a long time to find the frequency, but if it's the only option possible, as you're out, you can go. [19:09.140 --> 19:13.240] There are also set ranges for cordless phones, headsets, that type of thing. [19:13.400 --> 19:16.280] Again, just make sure it's in scope and you're legally monitoring it. [19:19.070 --> 19:21.270] So I'm going to breeze through some of the hardware recommendations. [19:21.750 --> 19:25.030] If anyone has questions about why I recommend these scanners, feel free to come up afterwards. [19:26.490 --> 19:39.830] Basically, just as a general recommendation of three levels of scanners to get, the top-end one, if you're not dealing with any trunk transmissions, which is generally for corporate profiling, I find it's not really... [19:39.830 --> 19:41.310] trunk systems generally are not used. [19:41.310 --> 19:44.590] If you're dealing with local municipalities or governments, trunk can come into play. [19:45.090 --> 19:55.710] If you're not interested in monitoring trunk radios, I recommend the Aero 8200, mainly because it has a wide frequency range, solid-made radio, and is very easy to control from a computer. [19:56.870 --> 20:08.750] We've written a number of programs to control 8200s to do fun things like drive around, map out frequencies with GPS, so basically you can kind of war dial around the area, figure out the frequency footprint. [20:09.090 --> 20:12.530] Very easy to do as someone who is not a programmer to interface with this thing. [20:14.090 --> 20:28.250] Next one down, if you're looking at trunk systems, the Uniden, Bearcat, BCD 396T, or the latest GRE radio in this range, it's comparable to our recommendation. [20:28.970 --> 20:29.910] Again, great radio. [20:30.450 --> 20:32.110] Haven't tried to computer control on it. [20:32.250 --> 20:33.250] Could be as easy to use. [20:33.630 --> 20:41.370] And then even a cheap radio, the Bearcat, their racing series, 180 bucks, can still receive a wide range of things. [20:41.470 --> 20:45.990] Not going to have some of the more advanced features, but can be great to get started. [20:46.310 --> 20:48.890] The other thing to look at is follow RadioShack. [20:48.990 --> 20:51.850] When they come out with a new radio, they greatly discount the old ones. [20:51.990 --> 20:53.270] Pawn shops are the great places. [20:54.030 --> 20:57.510] You don't need a super sophisticated radio to start listening to a lot of this stuff. [20:57.670 --> 21:01.350] So even a cheap one you can get off of eBay or other places can get the job done. [21:04.930 --> 21:08.870] If you haven't had unlimited budget, Icom makes some pretty amazing radios. [21:09.430 --> 21:19.430] The one listed here, wide frequency range, all sorts of bells and whistles, can decode video, has built-in data decoders, but, you know, costs 14 grand. [21:19.650 --> 21:23.210] And it's also like three or four are used, so it's a huge radio. [21:23.450 --> 21:26.350] But, you know, if you have the budget, might as well go all out. [21:27.770 --> 21:28.210] Sixties. [21:28.550 --> 21:28.990] Sixties? [21:30.130 --> 21:30.570] Sixties. [21:30.870 --> 21:31.310] Okay. [21:31.870 --> 21:32.230] Yeah. [21:33.070 --> 21:33.910] They're not small. [21:34.330 --> 21:35.390] It's far from portable. [21:35.650 --> 21:37.670] You're not going to be slapping it onto your belt to carry it around the site. [21:38.590 --> 21:39.650] There was a question in back. [21:40.150 --> 21:40.510] Yeah. [21:43.100 --> 21:46.080] Were those scanners or just radios? [21:47.140 --> 21:49.780] Or is there a difference in your lab work? [21:50.280 --> 21:51.700] I would say that they are... [21:51.700 --> 21:54.880] He's asking the radios in the last slide, are they scanners or are they radios? [21:54.980 --> 21:56.800] I would say that they are... [21:57.240 --> 22:03.200] Depending on your definition of radio versus scanner, I'd say all of them are scanners, because all of them have frequencies you can program in that will then scan... [22:03.200 --> 22:04.240] Or all of them are scanners. [22:04.880 --> 22:08.220] Because they all have channel banks you can program up to then scan through. [22:10.320 --> 22:19.120] The unit end ones are definitely more consumer grade hobbyist scanners, where AOR tends to make stuff that's more for the serious hobbyist or professional line. [22:19.500 --> 22:20.480] Tends to be the difference. [22:20.480 --> 22:21.820] Does that answer your question? [22:23.940 --> 22:25.980] Yeah, I guess they don't transmit. [22:26.040 --> 22:26.660] They don't transmit. [22:26.840 --> 22:27.160] Oh, yeah. [22:27.560 --> 22:29.820] Yeah, they do not transmit. [22:31.740 --> 22:37.160] For what I actually like to use is this little Yaesu, the VX6, I believe, VX5. [22:39.200 --> 22:42.740] And this is my ham radio as well, but can receive a wide range. [22:42.980 --> 22:48.880] If anyone is a ham radio operator, they probably already know more about radios to select a radio on their own, so I didn't really cover transmitting. [22:49.420 --> 22:50.720] And also, you get into legal issues. [22:51.020 --> 22:54.160] But when I do this, this is an radio I use just because it's what I have with me at most times. [22:54.820 --> 22:55.180] Yeah? [22:57.850 --> 23:00.730] Seeing all these issues, is it running any privacy issues? [23:01.710 --> 23:06.790] I'm not sure if you click on it, but since all of Google and Google and Google . [23:08.630 --> 23:10.970] Yeah, basically the question was, do you run any privacy issues? [23:11.050 --> 23:11.750] And you definitely can. [23:12.070 --> 23:18.490] And that's where, when looking at the rules of engagement, you definitely want to have your legal staff review them to make sure that you aren't breaking them. [23:18.490 --> 23:19.630] any privacy laws. [23:20.090 --> 23:28.250] Additionally, as we get into some of the case studies later on, we need to actually get involved to companies' legal staff to make sure they have proper language inside their employee handbook. [23:29.850 --> 23:30.390] Excuse me. [23:30.470 --> 23:32.110] To allow us to monitor these type of things. [23:32.350 --> 23:40.030] So you definitely can run into privacy problems, and very good to have legal staff involved to review it to make sure that you're remaining above board. [24:03.040 --> 24:03.420] Yes. [24:05.680 --> 24:06.400] Oh, yeah, yeah. [24:06.500 --> 24:08.960] The Icom would not be the best for that. [24:09.280 --> 24:11.020] It does have a spectrum scope function. [24:11.960 --> 24:16.260] You basically said it wouldn't be cheaper to get a spectrum analyzer off of eBay to use that. [24:16.800 --> 24:17.680] And that can be. [24:17.860 --> 24:22.300] When I was doing TSCM work, basically all that work was done with a spectrum analyzer. [24:22.520 --> 24:25.440] A lot of those that were up to like $50,000 spectrum analyzers. [24:26.700 --> 24:38.560] The biggest thing with spectrum analyzers is that they can be very expensive, they are heavy at times, and also they tend to have a shorter range than a dedicated receiver. [24:39.060 --> 24:41.720] Generally, we find a transmission with a spectrum analyzer we want to monitor. [24:41.960 --> 24:47.240] We would then flip over to a scanner radio of some sort to actually monitor that transmission. [24:47.820 --> 24:53.520] But it can be a great way to quickly see the spectrum, find peaks, zoom in on it. [24:53.520 --> 24:57.880] Generally, though, that would be outside the range of most normal penetration testers. [24:58.080 --> 25:02.340] I was talking about service monitors designed for analyzing cell phone sites. [25:02.740 --> 25:03.100] Oh. [25:03.760 --> 25:04.240] Okay. [25:04.400 --> 25:08.580] He was talking about service monitors for analyzing cell phone traffic. [25:08.820 --> 25:10.640] The biggest issue there is monitoring cell phone traffic. [25:10.820 --> 25:12.780] But they typically have a spectrum like... [25:12.780 --> 25:13.040] Okay. [25:13.900 --> 25:14.380] Yeah. [25:14.700 --> 25:17.680] And that would be one area to definitely look at. [25:18.080 --> 25:20.600] Some of the scanners have similar features. [25:20.800 --> 25:23.080] We will basically scan through and find active frequencies as well. [25:23.960 --> 25:27.100] There's a ton of radio stuff out there in terms of gear that you could pull in. [25:27.640 --> 25:28.220] Definitely true. [25:31.310 --> 25:34.370] I saw the question was, have I ever seen the poor man spectrum analyzer? [25:34.950 --> 25:35.750] I saw... [25:36.490 --> 25:43.570] I've seen various iterations where you can take like a oscilloscope, I believe it was one, to get the trace with some other things. [25:43.570 --> 25:45.170] It works on camera TV tuners. [25:45.430 --> 25:45.790] Okay. [25:45.910 --> 25:46.770] And you have to [25:50.280 --> 25:51.000] see it. [25:51.100 --> 25:51.740] Yeah, to see it. [25:51.960 --> 25:55.220] Just to see it. [25:55.820 --> 25:56.180] Okay. [25:56.400 --> 25:57.500] I'll definitely need to check that out. [25:57.580 --> 26:02.040] Because when I was doing the TSCM stuff, a lot of stuff had to be very sensitive. [26:02.440 --> 26:04.780] But for hobbyist stuff, free stuff like that is great. [26:06.500 --> 26:09.420] I'm going to keep moving on so we have time for the rest of it. [26:09.420 --> 26:13.000] Because I've got some case studies that tend to get a bit more interesting about how we've actually used this. [26:15.240 --> 26:16.040] Quick overview. [26:16.880 --> 26:18.060] I recommend other accessories. [26:18.380 --> 26:21.200] A good antenna basically makes a difference between hearing and missing a signal. [26:21.440 --> 26:25.580] If you had to look at investing in a good radio or a good antenna, invest in good antennas. [26:26.120 --> 26:27.560] That's really what's going to pull in the signal. [26:28.100 --> 26:30.040] You know, a couple of recommendations up there. [26:30.940 --> 26:33.240] You know, rubber ducky, flexible antennas can be great. [26:33.440 --> 26:34.660] They tend to have short range. [26:34.820 --> 26:37.420] But if you need to hide something on yourself, great way to hide it. [26:39.320 --> 26:42.960] Other things to recommend looking at frequency counter, which you already mentioned. [26:43.620 --> 26:44.940] Recording equipment can be helpful. [26:45.480 --> 26:47.800] Especially to record the transmissions that you're hearing. [26:48.220 --> 26:56.940] Because being able to play back audio, you know, for the head of security of their guards talking about something they shouldn't be, is often far more effective than trying to relay what they were saying. [26:57.560 --> 27:00.740] Again, make sure that's in the rules of engagement and be careful what you're recording. [27:01.680 --> 27:05.320] Cameras as well, as I mentioned, for visual profiling can be very helpful. [27:05.560 --> 27:08.300] Take a picture of the radio, then take it back and figure out what it is. [27:08.840 --> 27:11.080] So you're not trying to remember the details of it. [27:12.020 --> 27:14.660] DTMF decoders, also helpful, getting that into case studies. [27:15.660 --> 27:19.860] And finally, video converters, which can take signals from a radio and convert it into video. [27:20.260 --> 27:21.640] Discuss it again into case studies. [27:23.380 --> 27:28.300] So let's get into some real-world examples of where it used this technique and what it's gotten us. [27:29.960 --> 27:33.200] First scenario, a physical penetration test on a casino. [27:33.740 --> 27:39.660] During the off-site profiling of the site, discovered the frequency of the radio link between casino security and the state police. [27:39.880 --> 27:42.360] This was posted in a scanner enthusiast forum. [27:43.160 --> 27:44.360] This was very helpful. [27:45.560 --> 27:52.280] One, we wanted to be able to monitor that frequency because if casino security called the state police, we definitely want to know about it. [27:52.580 --> 27:57.260] Because casino security showing up and busting us, if we take out a card that says, yes, we're supposed to be here. [27:57.500 --> 27:59.440] They'll probably say, okay, that's fine. [27:59.760 --> 28:01.320] You know, end of test, get off site. [28:01.760 --> 28:07.960] If the police get involved, they may decide to say, well, yeah, but we now have 12 cop cars here. [28:07.960 --> 28:10.640] So we're going to take you down to have some more questions answered. [28:11.180 --> 28:14.920] So generally, you know, when the police start to get involved, good time to stop the test. [28:15.080 --> 28:20.320] So good thing to monitor just to see if the test goes outside of the casino itself. [28:21.040 --> 28:21.900] Got on site. [28:22.100 --> 28:26.100] When we arrived that night, started monitoring the link, found a couple of interesting things. [28:27.160 --> 28:36.600] The dispatchers were very chatty with the police, especially after hours when not much was going on in this small town and not much was going on in the casino. [28:37.600 --> 28:40.860] They spent a lot of time just talking back and forth, shooting the breeze. [28:41.880 --> 28:49.880] So through this, we learned a couple of interesting things, including the second and third shift dispatcher's name, which became very handy later on. [28:51.500 --> 28:56.680] Next, showed up on site the next day, did some visual identification, saw the radios they were carrying around. [28:57.020 --> 29:01.900] Looked like Motorola H2 Pro series, most likely to GP338. [29:03.620 --> 29:07.640] Went to bat labs, looked up that radio, found out the frequency ranges it operates in. [29:08.100 --> 29:16.060] Then looked at the antennas that were used on the radio, saw they were shorter antennas, tend to suggest they were used in just the two higher frequency ranges. [29:16.920 --> 29:21.880] Also notice that on the support site, these radios do not support encryption or trunking. [29:22.160 --> 29:25.580] So if we can find the frequencies, we can easily monitor it. [29:27.080 --> 29:32.440] Next, with it being a casino, where we can actually get access to the building, we did a walkthrough at the casino. [29:32.860 --> 29:37.300] Went in, had a little drink, moved around with a Scout. [29:38.400 --> 29:39.800] So basically this little guy. [29:40.440 --> 29:44.140] One note, anything related to a radio inside of a casino, make sure it's well hidden. [29:44.140 --> 29:56.140] If casino security guards see you carrying around a radio or anything that looks like a radio or anything that they don't understand that has blinky lights, you could find yourself slammed up against a wall and, you know, have all sorts of unhappy things happen to you. [29:56.980 --> 30:03.480] While not on engagements, I've gotten very odd questions and, you know, a little bit of manhandling from just having radios inside casinos. [30:03.960 --> 30:07.660] The guards there get very, very freaked out when they don't understand things. [30:07.660 --> 30:11.540] So just make sure if you are operating in that environment, keep it well hidden. [30:13.120 --> 30:27.860] So we did a little walk around, came out to the car, pulled the frequencies from the Scout, noted the ones in the range as the radio supported, found about a dozen frequencies, programmed those into the radio, and then into a scanner, started listening, and found the guards. [30:29.940 --> 30:31.400] I'm sure there's a question in back. [30:32.120 --> 30:39.080] Yeah, the scanner you have, other than visually kind of seeing it, can someone kind of detect that you have that to them? [30:41.700 --> 30:43.200] There... in essence, no. [30:43.460 --> 30:54.040] There are ways to detect receivers, but unless you're talking about some very high-end radio gear and stuff that's more academic than useful, not really, and definitely nothing that a casino would have. [30:54.960 --> 30:58.280] The question was, is there any way to detect that you have a scanner on you? [31:00.560 --> 31:02.680] You know, is there a way besides just seeing it? [31:03.040 --> 31:08.180] The other thing you can run into, depending on where you're at, you know, if you're a casino in downtown Detroit, you're going to have to go through mail detectors. [31:09.160 --> 31:12.380] You know, so taking all that stuff off your body and stuff is going to be visible. [31:12.540 --> 31:14.020] If you're in a casino, you can easily walk in. [31:14.460 --> 31:15.600] They're not really going to notice. [31:17.880 --> 31:20.140] So we started monitoring the guard frequencies. [31:20.640 --> 31:23.460] Heard again, general chatter, guards going on and off-duty. [31:23.460 --> 31:25.540] So we learned a couple of valuable things from this. [31:30.970 --> 31:34.310] First, we learned a lingo at the client site. [31:35.650 --> 31:39.270] And this is very handy for when we decided to go in as a physical pen-test. [31:39.470 --> 31:43.170] Once you get inside the building, if you can start using the lingo, they assume you need to be there. [31:43.490 --> 31:45.630] So one of the goals is getting into the data center. [31:45.770 --> 31:47.830] In this place, the data center was called the dungeon. [31:48.930 --> 31:51.810] So we got in and started asking people, hey, I'm looking for the dungeon. [31:52.070 --> 31:54.010] They just assume you know what you're talking about. [31:54.030 --> 31:55.750] And we'll say, oh, yeah, it's right through there. [31:56.370 --> 31:58.610] So again, getting into lingo can be very, very helpful. [31:59.050 --> 32:00.550] Next, start to learn guards' names. [32:01.770 --> 32:06.170] This was helpful because then when you run into people, you can say, oh, I ran into Sammy. [32:06.330 --> 32:07.730] Sammy said I should come over here. [32:07.810 --> 32:11.530] They instantly go, oh, I guess you're supposed to be here because someone I knew sent you over. [32:11.750 --> 32:16.410] So again, very helpful to build up trust and build up confidence that you should be allowed into the area. [32:16.970 --> 32:21.210] We also learned when shift changes occurred, which can often provide breaks in coverage. [32:21.770 --> 32:24.810] And finally, learned to schedule and rotation of guards when they're doing their rounds. [32:25.030 --> 32:28.990] So there's usually, you know, perimeter guards stationed around, then guards doing rounds. [32:29.290 --> 32:34.210] If you know the guard doing rounds is now on the other side of the building, that's very handy. [32:35.450 --> 32:37.250] In this case, we actually got a freebie. [32:38.130 --> 32:47.270] We were sitting there listening to the frequencies and in the back parking lot, Benson parking lot for the employees, there's a back gate where basically there's no guard access. [32:48.230 --> 32:50.070] There's just a guard saying that you have to flash a badge to. [32:51.050 --> 32:55.570] As we were listening to it, the guard basically really had to use the bathroom that day. [32:55.570 --> 32:58.490] So we kept on hearing, you know, rear guard check. [32:59.650 --> 33:00.830] I need to use the bathroom. [33:01.050 --> 33:02.030] We request to go on break. [33:02.770 --> 33:04.110] Okay, we'll get someone back there. [33:04.490 --> 33:06.630] You know, five minutes later, rear guard check. [33:06.770 --> 33:08.270] I really have to use the bathroom. [33:08.630 --> 33:10.230] Can you please get someone back here? [33:10.550 --> 33:16.490] Finally, after about a half an hour of this and they can't get anyone back there, finally the dispatcher goes, okay, I can get anyone back there. [33:16.610 --> 33:18.270] Just make it quick and get back to your post fast. [33:19.570 --> 33:23.710] So we then watch the guard leave, go inside and just pull right in and park. [33:23.710 --> 33:25.790] At that point, we're inside the employee lot. [33:25.970 --> 33:28.750] Already people start to trust us because, hey, we're in the employee lot. [33:29.370 --> 33:34.630] Get out of the car, walk in, go to the employee entrance, go up, drop the name of the dispatcher from last night. [33:35.530 --> 33:37.250] Hey, we were here last night working with Sally. [33:37.370 --> 33:38.370] We need to get some other parts. [33:38.590 --> 33:40.030] She just said to come back in and let you in. [33:40.090 --> 33:41.090] We need to finish this up in the dungeon. [33:41.270 --> 33:42.090] Oh, you're working with Sally? [33:42.230 --> 33:43.310] Oh, yeah, she's a great person. [33:43.770 --> 33:46.430] Get to throw in all these details that we learned from talking with the guards. [33:46.650 --> 33:48.770] You know, oh, yeah, she's talking about her kids, this and that. [33:49.350 --> 33:49.630] Great. [33:49.990 --> 33:51.250] Give us a visitor badge. [33:51.390 --> 33:52.230] She doesn't even check her IDs. [33:52.450 --> 33:53.110] Let us write in. [33:54.010 --> 33:54.650] Go inside. [33:54.850 --> 33:57.130] Then once we're inside, you can use other things, guard names, other things. [33:57.170 --> 34:02.810] Hey, we ran to Sam and he said that you could, you know, we were supposed to go down here to get to this thing, but I'm not sure where it is. [34:02.850 --> 34:03.830] Oh, let me take you to it. [34:04.150 --> 34:13.570] So all these little things you can then build up to then when you enter into the company, have them believe that you're supposed to be there, you know stuff, basically use some of that social engineering skills to gain people's trust. [34:15.230 --> 34:15.550] Yeah. [34:19.810 --> 34:21.210] Yeah. [34:21.230 --> 34:21.510] Yeah. [34:22.290 --> 34:23.690] Yeah. [34:25.530 --> 34:25.750] Mm-hmm. [34:26.270 --> 34:27.710] I'm not sure how sensitive they are. [34:28.290 --> 34:33.450] Is it possible to, we're just trying to conceal it, screw it up too badly? [34:33.610 --> 34:45.530] Like, I mean, like, I've seen people, like, you know, I don't know, take like a glass bottle or something and that's covered in labels and stick something, stick the transmitter in, you know, something that lets it still, it's only on this kind of toxin, [34:45.630 --> 34:48.130] so you still see that that conceals some hints. [34:48.990 --> 34:53.270] Generally, the way that we handle that, I mean, there, you can put inside stuff to hide it. [34:53.530 --> 35:00.450] The bigger thing is this antenna versus, you know, this antenna, this antenna is going to receive a lot more than a short one. [35:01.130 --> 35:16.790] Um, so the big thing is what we'll usually do is have a team outside that has radio gear, can have antennas on top of a car, on top of a van, uh, with much better antennas, get a better range listening to stuff, and then we'll relay that information to people inside, [35:16.990 --> 35:19.150] whether that be through earpieces or just cell phones. [35:19.790 --> 35:22.690] You know, today you can have someone walking around a building with a cell phone up to their ear. [35:23.270 --> 35:28.270] No one thinks anything of it, and in fact, if someone's carrying around a cell phone up to their ear, they're probably more likely to be left alone. [35:28.710 --> 35:31.690] You know, people even hold doors open for you if you look busy and you have a cell phone. [35:32.230 --> 35:37.830] Uh, so usually we have, you know, the stuff being intercepted right outside, then relayed into the team inside. [35:38.130 --> 35:47.970] That also just allows the team inside to focus on what they should be doing, opposed to needing to monitor all sorts of stuff and just, you know, limit the stuff they need to do so they can focus on their job. [35:52.170 --> 35:53.390] Case study number two. [35:53.650 --> 35:59.190] Uh, this was a internal penetration test at a, uh, against an insurance provider. [35:59.470 --> 36:03.770] Uh, this was more of a, uh, IT logical penetration test. [36:03.930 --> 36:08.570] Uh, while being escorted through the building, uh, we noticed a wide number of wireless headsets in use. [36:08.850 --> 36:19.710] Uh, so because of this, we requested to add this to the scope of the engagement and basically then, uh, worked with their lawyers, worked with our lawyers to come up with rules of engagement, determine the scope. [36:20.610 --> 36:34.350] In this case, we actually had to make sure that, um, various laws were complied with in terms of could we actually monitor these transmissions, looked at the, uh, employee handbook and found the employer did have the ability to monitor any, uh, phone calls that were taking place inside the facility. [36:34.610 --> 36:36.970] They could extend that right to us, blah, blah, blah, blah. [36:37.270 --> 36:46.070] Um, so we got that permission, uh, started scanning through headsets, found several dozen headsets in the 900 megahertz frequency range. [36:46.250 --> 36:53.450] Uh, the next thing was, uh, we needed to then use signal strength and their geographic information to figure out which headsets were inside the target building. [36:53.450 --> 36:58.330] Cause obviously we didn't want to start monitoring phone calls from someone outside the area. [36:58.910 --> 37:05.950] Uh, so did some triangulation, other tricks to figure out which ones were inside the building, came up with a list of targets, started monitoring them. [37:07.890 --> 37:14.310] What we heard, um, lots of phone calls, um, a lot of their help desk had the phone calls. [37:14.410 --> 37:20.250] In fact, the password reset section of the help desk was using these headsets, which was a nice little win. [37:20.790 --> 37:22.590] Uh, found employees checking their voicemail. [37:22.770 --> 37:29.670] And this is where, um, when they would type in their password, if you had a DTMF decoder, it could then decode those tones to tell you the numbers. [37:30.010 --> 37:33.770] Very helpful for them being able to, uh, check their voicemail for them. [37:34.930 --> 37:41.150] Um, the other neat thing is, uh, the radio that's up there and they're rebranded by a variety of different ones. [37:41.270 --> 37:47.910] But, uh, the older analog ones, even when they're, the phone is off the hook, if the headset is on, they're still transmitting. [37:48.370 --> 37:52.830] So they're basically a nice little room bug that is on as long as they're in the office. [37:52.830 --> 38:02.670] Uh, so that can be just really super helpful because also generally these headsets are given to, um, people that work at help desks, executives or executive assistants. [38:03.250 --> 38:07.130] So basically, you know, all the important people that we want to learn what they're talking about. [38:07.270 --> 38:10.030] So that's just a great way to, uh, learn information. [38:10.390 --> 38:15.570] I know, uh, when I was doing the corporate side for the TSCM, headsets were a huge concern with executives. [38:16.030 --> 38:20.070] Uh, cause you could learn a lot about, um, you know, a lot of the work I did there. [38:20.070 --> 38:26.990] I knew about things like mergers and acquisitions before most people did because you could hear the executives talking about on the phone and put two and two together. [38:27.630 --> 38:32.770] You know, clearly these things are, you know, areas you want to watch for sensitive conversations, especially if you have something that's transmitting all the time. [38:34.010 --> 38:34.970] So what do we learn? [38:35.130 --> 38:42.090] Uh, as I mentioned, uh, to use about a password reset section to help desk, uh, which was super helpful because we could then listen to them. [38:42.230 --> 38:42.890] Someone call up. [38:43.150 --> 38:44.010] Hey, this is Sally. [38:44.310 --> 38:45.010] I forgot my password. [38:45.150 --> 38:45.410] Okay. [38:45.470 --> 38:46.390] What's your social security number? [38:46.390 --> 38:46.690] Great. [38:48.130 --> 38:50.210] What's, you know, where do you work? [38:50.410 --> 38:52.510] You know, all sorts of information is very helpful about it. [38:52.610 --> 38:58.610] So one, we could reset their password at future day if we needed to, but also they would then say, okay, your new password is blah, blah, blah, blah. [38:58.790 --> 39:00.070] We need to change it once you log in. [39:00.410 --> 39:02.530] At that point, it basically becomes a basic race condition. [39:02.710 --> 39:10.870] If we can log in before she can, we then get a valid token, can use the system, you know, on windows, the token's usually good for like four to six hours. [39:11.730 --> 39:16.090] Log in, may not be a privileged account, but you still have access to domain, can start enumerating things. [39:16.290 --> 39:19.030] And if the password, you know, you need to change it, you just change it. [39:19.150 --> 39:20.990] Person on the phone goes, yeah, I tried that password. [39:21.090 --> 39:21.690] It doesn't work. [39:22.070 --> 39:23.150] Oh, let me change it again. [39:23.250 --> 39:26.830] They don't even think about it because, you know, stuff like that, you normally doesn't work with IT. [39:28.730 --> 39:38.430] Additionally, we found that these headsets, we actually did a little expansion on it and found that we could actually monitor these headsets for up to three blocks away using pretty simple equipment. [39:39.030 --> 39:45.230] So we then pulled this into the external penetration test where they were running Citrix and other stuff on the outside without two-factor authentication. [39:45.670 --> 39:47.270] So we could watch people call up. [39:47.370 --> 39:52.870] We could then log into the Citrix box, get access to the internal network and, you know, basically have it in into the company. [39:53.310 --> 39:59.350] Because of this, they started implementing two-factor authentication to actually be able to, you know, prevent against these types of attacks. [40:00.490 --> 40:03.530] Also then learned about voicemail passwords, other types of information. [40:03.530 --> 40:04.810] Again, very helpful stuff. [40:05.870 --> 40:08.310] You know, lots of sense of information. [40:10.710 --> 40:14.690] Second case study was a physical penetration test at a power plant. [40:15.130 --> 40:32.630] When we got on site, started profiling the site, we noticed along the back perimeter of the lot, it was basically the front was where the power plant was and there was a huge storage lot in back where they had probably acres of various equipment from poles to transformers, [40:32.690 --> 40:34.450] other things, back in the back lot. [40:34.830 --> 40:39.930] Along the back perimeter, we noticed that the cameras that were in place all had antennas on the same pole. [40:40.330 --> 40:42.710] So instantly, I was curious about this. [40:43.330 --> 40:47.130] Looked like the antennas were tuned about 900 megahertz by the size of them. [40:47.590 --> 40:51.010] So proceeded to then scan through common frequencies used by wireless cameras. [40:51.650 --> 40:54.610] If you do searches online, you'll find lists of these frequencies. [40:55.450 --> 41:03.510] Use the device listed here, which is an AOR device, which basically can plug into a high-end scanner that has what's called an IF output. [41:03.790 --> 41:04.710] It plugs into this device. [41:04.710 --> 41:09.390] It'll then convert that to a picture, which you can display on a TV. [41:10.050 --> 41:16.110] So then scan through, found a variety of video signals, and started looking at security camera feeds. [41:16.670 --> 41:20.650] One note, I found that the AOR device is one of the best ones in the area. [41:20.990 --> 41:23.990] The only problem is it only does NTSC. [41:24.110 --> 41:24.730] It doesn't do PAL. [41:25.190 --> 41:30.630] So if you're operating in Europe, where PAL is a video format, probably wouldn't be a good choice over there. [41:30.770 --> 41:31.890] But in the States, it works well. [41:33.250 --> 41:36.250] Icom makes a radio called the R3, which has a built-in little screen. [41:36.410 --> 41:37.210] It'll decode it for you. [41:37.670 --> 41:40.830] I've generally found that kind of be a piece of crap for this type of work. [41:40.930 --> 41:41.930] It has a very short range. [41:42.570 --> 41:44.850] So it's well worth to get a high-end radio. [41:45.290 --> 41:46.310] Plug in the external device. [41:46.450 --> 41:48.330] You get a larger setup, but it works very, very well. [41:49.730 --> 41:50.850] So plugged it in. [41:51.030 --> 41:52.210] Started watching the video feed. [41:52.790 --> 41:55.290] Learned another interesting things about the target. [41:55.850 --> 41:58.630] Could see things like, you know, where are there holes in the camera coverage? [41:58.750 --> 42:02.470] So it helped us plan, as we need to cross this large lot, what was the best way to plan it? [42:03.210 --> 42:07.670] We could see where the PTZ pan-tilt zoom cameras were looking. [42:08.010 --> 42:10.570] Again, to be able to figure out, were they just on a normal sweep? [42:10.710 --> 42:11.990] Were they actually being controlled by people? [42:12.210 --> 42:16.190] If they're being controlled by a person, so it's more erratic, there's probably someone looking at it. [42:16.190 --> 42:29.330] If it's just a normal sweep, most of the times, you know, if a guard's looking at a wall of video cameras, unless they have a smart video system in place that actually looks for anomalies, after five to ten minutes, even the best trained guard is just going to zone out. [42:29.750 --> 42:33.630] So if you just see it's just a general sweep going on, most likely no one's even watching it. [42:34.270 --> 42:36.050] So again, very easy to breach that. [42:36.710 --> 42:39.070] Could also see your personnel were moving inside the property. [42:39.070 --> 42:42.210] So again, you could avoid them as you're moving up to the building. [42:42.530 --> 42:44.610] So lots of valuable information could be learned. [42:45.010 --> 42:53.630] In this case, we actually found that the cameras were set up so that we actually decided to do the attempt penetration during the day. [42:53.870 --> 42:58.450] Because the way the cameras were set up, when the sun would rise, the cameras weren't set up correctly. [42:58.610 --> 43:00.510] It would actually wash out the video. [43:00.510 --> 43:07.170] So basically, they were blinded during the sun, when the sun was rising, lost all video coverage, could easily cut across. [43:07.650 --> 43:15.650] And again, once you get into those properties, you have a hard hat on, you have on the fireproof suits, all the other stuff that linemen have that you can purchase online. [43:16.210 --> 43:18.130] Most likely, people aren't going to really bother you. [43:18.670 --> 43:21.310] And if they do, you know, a lot of them are very helpful. [43:21.310 --> 43:22.770] If you're just like, man, I'm just a contractor. [43:22.930 --> 43:23.890] I sent out here to get this. [43:24.050 --> 43:25.890] And they're like, yeah, that's like inside the building. [43:26.050 --> 43:26.670] Oh, really? [43:26.770 --> 43:27.270] Can you show me? [43:28.250 --> 43:32.850] You know, so once you're on side there, you can gain some good trust if you have the right cover. [43:36.170 --> 43:38.290] So a couple of interesting things are coming on the horizon. [43:39.490 --> 43:41.730] One are VoIP-enabled radio dispatch systems. [43:44.370 --> 43:47.390] These have been really fun when I've been able to find them and play with them. [43:47.950 --> 43:52.250] Basically, a lot of VoIP radio systems that do dispatch are going over to VoIP. [43:53.210 --> 43:57.730] And the plus of this is you can then get some flexibility of where the dispatch center is located. [43:57.730 --> 44:01.690] An example of this, there's a university I was working with that was super excited. [44:01.830 --> 44:03.010] They installed this new radio system. [44:03.490 --> 44:08.850] And they're like, our dispatcher can take their laptop, plug in anywhere on the network, and start dispatching calls. [44:09.250 --> 44:09.930] It's great. [44:10.030 --> 44:14.270] If someone takes over our police station, there's a fire, there's whatever. [44:14.470 --> 44:20.510] They just need to grab their laptop in five minutes, find a network jack, go over to wireless, plug in, and start dispatching calls. [44:21.270 --> 44:22.590] Which to them is a great thing. [44:22.690 --> 44:24.310] To me, it's kind of scary and lots of fun. [44:25.170 --> 44:28.350] You know, so I started looking at that, found out, you know, they're not encrypting the VoIP. [44:28.550 --> 44:29.630] They're doing very poor authentication. [44:30.190 --> 44:32.990] You could also access the dispatch system from the student network. [44:33.310 --> 44:34.590] All sorts of other fun stuff. [44:36.050 --> 44:38.010] Similar with businesses, we're seeing this as well. [44:38.430 --> 44:40.810] A lot of large businesses are going over to VoIP systems. [44:40.970 --> 44:51.710] So if, you know, there's a port system we were doing work with where the main radio room, if that was taken over, they could take their laptops, plug in anywhere else in the building, start dispatching calls. [44:52.150 --> 44:56.470] Again, a really cool feature, but if it's not set up correctly, can cause a lot of problems. [44:58.130 --> 45:00.510] Other areas we're seeing, DECT interception. [45:02.270 --> 45:07.950] Two years ago, I believe, CCC, there was some research released on intercepting DECT communications. [45:08.610 --> 45:15.010] DECT is a digital format used by a lot of phones in Europe, cordless phones in Europe, and it's becoming more popular in the United States. [45:15.730 --> 45:22.230] So even what used to be considered secure transmissions, because they're digital encrypted, can now be intercepted with fairly cheap equipment. [45:22.930 --> 45:27.750] And the other interesting thing that's coming into this area is software-defined radios, such as the USRP. [45:28.310 --> 45:35.630] These are basically radios that instead need to rebuild the hardware to do some different monitoring, you can actually just do it all through code. [45:35.630 --> 45:39.730] So you're starting to see DECT interception can take place through USRP. [45:41.170 --> 45:52.930] Chris Padgett's been doing some really interesting stuff with intercepting GSM traffic, and it's really opening up a whole new array of area, where before you needed to get some very expensive radio gear, now just the USRP that's a grand. [45:53.210 --> 45:56.130] You can do a lot of really neat stuff if you have the programming ability. [45:59.050 --> 46:01.930] So with all this, what are some defenses that can be used? [46:02.350 --> 46:03.790] First of all, test your equipment. [46:04.410 --> 46:06.730] Make sure your headsets and cordless phones are secure. [46:08.330 --> 46:14.230] Make sure that, you know, they have adequate level of security for what your threat agent would be. [46:14.470 --> 46:17.970] You know, perform a risk assessment and understand who would be attacking your systems. [46:18.530 --> 46:26.230] You know, if you're a company that makes toilet paper for giraffes, you probably don't need to worry about someone spending millions of dollars to monitor your radio systems. [46:26.230 --> 46:27.650] There are probably easier ways to get in. [46:28.230 --> 46:33.690] If you are a government, do classified work, do other stuff like that, your threat agents are going to be very, very different. [46:33.890 --> 46:37.190] So you need to have an understanding of that so you make sure your equipment is secure to that standard. [46:38.250 --> 46:41.270] Next, check your facility for unencrypted radio traffic. [46:42.070 --> 46:43.850] Pretty interesting stuff that will come out. [46:44.930 --> 46:59.190] Another strange thing I occasionally find, there are occasional devices that are used by people that are hard of hearing, which will actually amplify audio, which can, again, transmit conversations. [46:59.190 --> 47:03.230] You know, those things will be in areas where you often pick up strange conversations there. [47:03.510 --> 47:09.070] A lot of presentations rooms, you know, where executives do their big executive presentations, use wireless microphones. [47:09.270 --> 47:13.810] So as they're having their super secret board meeting, they're basically transmitting out to the world for anyone to listen to. [47:14.530 --> 47:17.290] And depending on the city, news crews do know about that. [47:17.930 --> 47:29.010] I know some cases of news crews that would go around, would know about, hey, there's a merger coming up, a company XYZ, we're going to stick someone outside that and gain some information. [47:29.530 --> 47:43.110] You know, the place I worked at before was a fairly financially conservative bank, but they still decided to spend hundreds of thousands of dollars to have people follow around and sweep for transmitters, look for hidden things like that, bugs. [47:44.030 --> 47:49.030] You know, we tend to imply they saw some value in that because they were fairly averse to spending money on security. [47:50.410 --> 47:54.250] Next, look at switching from digital, switching to digital encrypted radios. [47:54.550 --> 47:57.490] For digital radios, most of the time that's going to stop the casual observer. [47:57.910 --> 48:01.530] If you have real concerns, go over to encryption, make sure it's real encryption. [48:02.170 --> 48:09.850] A lot of radio manufacturers will sell things that are encryption, but they're really just like voice inversion or very other simple techniques that can easily be unscrambled. [48:10.130 --> 48:17.690] So make sure it's using something like DES, AES, some algorithm they have published, not just something where the vendor goes, oh yeah, it's secure. [48:19.690 --> 48:22.090] We invented this algorithm, it has to be fine. [48:22.090 --> 48:27.610] I had one vendor where their defense to that, when they basically questioned it, they're like, well, the White House uses it, so it has to be secure. [48:27.990 --> 48:32.690] I'm like, okay, I still need to know more information about how you're actually encrypting it. [48:33.070 --> 48:35.230] So make sure it's actually legitimate encryption. [48:36.090 --> 48:41.430] Next, probably the cheapest and simplest thing to do is just train your guard force to be aware of what they say on the radios in public. [48:41.430 --> 48:45.410] It is astonishing to stuff I've heard guard forces say. [48:45.690 --> 48:48.050] Everything from just leaking information that's inappropriate. [48:48.790 --> 48:52.310] I had a case of a company that was doing some mergers and acquisitions. [48:53.030 --> 48:56.670] And, you know, there was a known list in the media of here are three companies looking at buying it. [48:56.890 --> 49:02.010] As soon as they're listening to it, the guards are like, the representatives from company XYZ are here to see the executives. [49:02.090 --> 49:03.070] I'm like, oh, there we go. [49:04.130 --> 49:06.370] You know, listen for stuff like that. [49:06.370 --> 49:15.390] Additionally, I have heard amazing things in terms of everything from cursing, lewd jokes, racial references, all sorts of stuff. [49:15.610 --> 49:20.150] Go over radios that, if got to the press, would be huge reputational risk to the company. [49:20.690 --> 49:24.590] So that's just another thing of, you know, again, news medias do listen to this. [49:24.930 --> 49:25.950] Hobbies do listen to it. [49:26.310 --> 49:32.270] Make sure that guards are aware of what they're saying, can be heard by anyone, just so that they think about what's being broadcast in public. [49:32.270 --> 49:39.280] Can I ask, PC keyboards and the potential to intercept that data? [49:39.900 --> 49:43.080] Question is wireless PC keyboards, potential intercept that data. [49:44.340 --> 49:46.540] A lot of those devices can be intercepted. [49:46.940 --> 49:54.880] The guys that do backtrack made the, like, the Kirkachoo, or I'm not sure quite how to pronounce it, but they made a board where you can actually build to receive that information. [49:55.940 --> 49:57.360] Again, depending on the device. [49:57.920 --> 49:59.040] Some use encryption. [49:59.340 --> 50:00.460] That's not really encryption. [50:00.900 --> 50:02.180] Some may actually use encryption. [50:03.540 --> 50:04.920] A lot of the benefits... [50:04.920 --> 50:07.220] Really, the best defense there is the line at a pretty short range. [50:08.020 --> 50:09.940] But there are definitely devices that can receive them. [50:10.320 --> 50:13.080] Even a Bluetooth, depending on how encryption is set up. [50:13.440 --> 50:18.420] Apple actually does a pretty good job with their encryption on the Bluetooth because the encryption key is fairly long. [50:18.840 --> 50:26.080] A lot of Bluetooth devices for encryption just use the key of either no key, 1, 1, 1, 0, 0, 0, or 1, 2, 3, 4. [50:26.320 --> 50:27.760] So it's a pretty small key space. [50:29.620 --> 50:32.240] You know, so it kind of depends on the technology there. [50:32.380 --> 50:36.100] Have you seen any real-world examples of that being exploited? [50:37.040 --> 50:40.800] I've seen demos at conferences and other events. [50:41.340 --> 50:41.860] I would... [50:42.500 --> 50:49.700] One of the things I actually want to get is some of that equipment, kind of on my hobbyist list of things to do to see how far away you could receive it. [50:50.180 --> 50:53.160] What I've generally seen in the past, unless you have... [50:53.160 --> 50:56.720] Generally, the range of those things is pretty poor, even if you have specialized equipment. [50:57.100 --> 50:58.620] But I would definitely like to try that in real-world. [50:58.860 --> 50:58.960] Yeah. [51:09.440 --> 51:10.080] Oh, nice. [51:17.790 --> 51:23.310] Yeah, someone mentioned USENIX paper that was up on basically intercepting these type of transmissions. [51:23.450 --> 51:34.370] And one of the more interesting things is keyboard transmissions of using the pipes inside the building is actually the antenna, which is a great idea, which I will now be trying to get into service rooms to play around with. [51:44.780 --> 51:45.580] Okay, there's... [51:45.580 --> 51:48.560] It looks like it's actually just the typing in the ground return, but... [51:48.560 --> 51:49.180] Which is... [51:57.140 --> 51:57.540] Yeah. [51:57.540 --> 51:57.620] Yeah. [51:57.720 --> 52:00.560] I'm just curious, since you were saying that... [52:00.560 --> 52:05.300] Today, since you were saying that unencrypted these things are going to travel three miles. [52:05.600 --> 52:06.740] I'm just curious... [52:06.740 --> 52:07.200] Oh, nothing miles. [52:07.300 --> 52:07.820] Three blocks. [52:08.080 --> 52:08.840] I'm just curious. [52:09.240 --> 52:17.140] What's the possibility of, we should say, holding that headset first, just sitting in, making the cell phone... [52:17.680 --> 52:20.580] I think it's talking to your headset, which we're talking... [52:21.380 --> 52:21.780] When... [52:21.780 --> 52:21.840] When... [52:21.840 --> 52:22.860] I think it's talking to your headset for... [52:23.760 --> 52:25.440] Make the person... [52:25.440 --> 52:26.120] Uh... [52:26.120 --> 52:27.320] Take a phone call... [52:27.320 --> 52:28.340] The person is... [52:28.340 --> 52:30.620] As there are companies that are using a headset... [52:30.620 --> 52:31.580] Think you were talking to yourself... [52:33.300 --> 52:36.940] Basically, talking about the potential for, kind of, man-to-middle attacks. [52:37.320 --> 52:39.900] Can you get a headset to pair to another device? [52:40.020 --> 52:40.800] Interject traffic? [52:41.600 --> 52:43.400] You know, trick them into thinking you're talking to somebody else? [52:44.720 --> 52:45.120] Um... [52:45.120 --> 52:46.580] Theoretically, that would definitely be possible. [52:46.840 --> 52:49.920] For Bluetooth, there are different tools out there to do that. [52:49.920 --> 52:55.920] Car Whisperer by the Trifinity Group is one who actually will pair up with cars, headsets, start injecting traffic. [52:56.520 --> 52:56.880] Uh... [52:56.880 --> 52:58.660] For the headsets, um... [52:58.660 --> 52:59.880] That would probably also be possible. [53:00.500 --> 53:02.900] Generally, that's an area I don't really do too much in, uh... [53:02.900 --> 53:03.760] Just because... [53:03.760 --> 53:08.120] That would require me to transmit, which the FCC looks down upon, especially as a ham radio operator. [53:08.260 --> 53:10.260] I don't really have the ability to say, I didn't know. [53:11.420 --> 53:11.780] Um... [53:11.780 --> 53:15.660] So generally, that's an area that I haven't really played around too much with, but theoretically, it would definitely be possible. [53:17.380 --> 53:17.740] Thanks. [53:17.740 --> 53:17.760] Thanks. [53:19.240 --> 53:23.760] So with that, finish up with all your RFR belong to us. [53:25.500 --> 53:26.900] And open up to questions. [53:28.000 --> 53:28.880] For, uh... [53:28.880 --> 53:31.460] More information, check out SecureState.com. [53:31.620 --> 53:32.500] I also have my blog. [53:32.780 --> 53:33.600] SecureState has a blog. [53:34.060 --> 53:39.400] Anything that's security-related that I do gets posted on SecureState's blog and my blog, and then just some other personal stuff on my blog. [53:39.880 --> 53:41.020] There's my email address. [53:41.600 --> 53:42.120] Also on Twitter. [53:42.820 --> 53:43.100] Uh... [53:43.100 --> 53:45.600] The one final thing I'll say, just as a kind of a plug for my company. [53:46.020 --> 53:48.440] If this is really cool stuff you want to do, uh... [53:48.440 --> 53:49.080] We are hiring. [53:49.340 --> 53:50.500] So definitely come up. [53:50.680 --> 53:50.840] Uh... [53:50.840 --> 53:54.720] We're looking for a couple of experienced folks that have, uh... [53:54.720 --> 53:57.420] Experienced in penetration testing, captured a flag, other things. [54:08.980 --> 54:09.380] Uh... [54:18.580 --> 54:19.140] Yes. [54:22.980 --> 54:23.540] Um... [54:23.540 --> 54:29.680] Part of that would be just knowing if it's outsourced to a security guard company, then you could look up, uh... [54:29.680 --> 54:32.840] You'd want to do searches for guard frequencies against that security guard company. [54:33.380 --> 54:33.940] Uh... [54:33.940 --> 54:42.080] Other thing could be, depending on the company involved in the area, I definitely know in the areas I work for, the, um... [54:42.080 --> 54:44.940] There are certain guard force companies that use far less training than others. [54:45.820 --> 54:46.280] Uh... [54:46.280 --> 54:48.840] So that would also tell me if they're using guard force X. [54:49.120 --> 54:55.940] Most likely their guards are, you know, college students, which are working there part-time, and have basically, um... [54:55.940 --> 54:57.880] Really have no training and don't care. [54:58.520 --> 55:07.680] Versus if it's a, you know, guard company that uses armed guards, very well-trained, other things, just knowing the local areas I work in that can be helpful. [55:08.940 --> 55:09.360] Um... [55:09.360 --> 55:11.580] It's more than just how you conduct the profile. [55:11.780 --> 55:13.060] Yeah, how you conduct the profile. [55:13.200 --> 55:15.680] And also, it can impact how you then approach the test. [55:15.680 --> 55:19.960] If I know, you know, company A is a very, um... [55:19.960 --> 55:26.540] You know, uses this outsourced guard company, and it's a good guard company in the area, I'll approach it differently than if I know they're going to be very poorly trained. [55:30.670 --> 55:31.090] Yes? [55:41.180 --> 55:41.560] Um... [55:41.560 --> 55:43.100] Did that back in a previous job. [55:43.520 --> 55:45.320] I will say, you... [55:45.320 --> 55:46.600] Stuff is found. [55:47.680 --> 55:48.060] Um... [55:48.060 --> 55:50.420] You know, they've asked me not to talk about what type of stuff was found. [55:50.700 --> 55:59.100] You know, I guess the general thing I would say is, you know, as a company that was very concerned about money that was being spent, you know, we probably had... [56:00.640 --> 56:06.260] Easily a couple hundred thousand dollars worth of gear, as well as four guys that would be devoted to doing this type of stuff. [56:08.080 --> 56:08.500] Um... [56:08.500 --> 56:12.000] That would travel around following executives, traveling outside the country with them. [56:12.280 --> 56:13.300] You know, so they... [56:13.300 --> 56:17.080] They saw some return on that investment, or else they probably wouldn't have kept on doing it. [56:18.480 --> 56:18.900] Um... [56:18.900 --> 56:19.800] The other thing... [56:19.800 --> 56:22.700] A lot of the stuff that we found was more stuff that... [56:23.560 --> 56:24.920] Kind of accidental stuff. [56:25.120 --> 56:28.760] You know, in terms of, like, the headsets that transmit all the time, other bizarre stuff like that. [56:29.580 --> 56:30.060] Um... [56:30.060 --> 56:31.960] The other thing is, uh... [56:31.960 --> 56:32.880] Hotels that... [56:32.880 --> 56:40.540] That frequently hold conferences are usually pre-wired for bugging, and people can just bribe the people there, so they don't need to actually get in. [56:41.060 --> 56:41.540] Um... [56:41.540 --> 56:43.020] So, high-end hotels that... [56:43.440 --> 56:44.760] That usually hold conferences. [56:45.460 --> 56:45.760] Um... [56:45.760 --> 56:55.700] Going into them can be challenging, because, in some cases, they're actually hardwired in, and, you know, have basically been very nice professional jobs installing microphones and stuff. [56:55.880 --> 56:56.620] So, there's... [56:56.620 --> 56:57.660] There's odd stuff out there. [56:58.960 --> 56:59.380] Uh... [56:59.380 --> 57:05.060] As an interesting thing to play with, if you go to a site, tscm.com, he has a list of the most common frequencies. [57:05.380 --> 57:08.720] If you have a scanner, just program that in, and start driving around major cities. [57:09.800 --> 57:10.240] And... [57:10.240 --> 57:12.040] You may hear some interesting stuff. [57:16.500 --> 57:16.940] Uh... [57:16.940 --> 57:18.140] Finding out what... [57:31.540 --> 57:33.100] Yeah, that's a great point. [57:33.200 --> 57:34.660] Basically, he's mentioning, uh... [57:34.660 --> 57:37.580] Certain Bearcat scanners have a feature called, uh... [57:37.580 --> 57:38.360] Frequency Stalker. [57:38.480 --> 57:41.240] Which basically will lock onto the strong frequencies in the area. [57:41.240 --> 57:42.520] So, similar... [57:43.660 --> 57:44.020] Uh... [57:44.020 --> 57:44.980] Functionality to this guy. [57:45.500 --> 57:45.620] Uh... [57:45.620 --> 57:48.380] Just find the strongest frequencies, and, uh... [57:48.820 --> 57:49.640] Save them into memory. [57:51.740 --> 57:55.260] A lot of the consumer ones, excuse me, also have, um... [57:55.260 --> 57:57.060] Features where you can set up to just scan a band. [57:57.320 --> 57:58.680] It'll save everything it finds. [57:58.960 --> 58:00.160] And how many times it was found. [58:00.280 --> 58:03.180] So, that can be helpful if you don't know where they are, but you know the frequency range. [58:03.280 --> 58:03.800] Set that up. [58:03.900 --> 58:04.840] Leave it go for half a day. [58:04.940 --> 58:05.380] Come back. [58:05.540 --> 58:07.040] So, you always hit the most start listening to them. [58:08.320 --> 58:09.420] Another thought, too. [58:09.920 --> 58:10.220] Uh... [58:10.220 --> 58:12.280] Going back to software-defined radios for a month. [58:12.720 --> 58:12.760] Yeah. [58:13.160 --> 58:13.280] Uh... [58:13.760 --> 58:17.800] WinRadio has been making software-defined radios for another few years out there. [58:18.100 --> 58:24.320] And old WinRadio 1000, which works on an ISA slot, can be had on eBay for about $50,000. [58:25.040 --> 58:28.040] Yeah, he's talking about, um... [58:31.760 --> 58:34.540] A good source for software-defined radios, a company called WinRadio. [58:34.680 --> 58:37.580] As you mentioned, that can be found on eBay, get the older ones used. [58:38.080 --> 58:38.500] Uh... [58:38.500 --> 58:40.200] Yeah, there are a lot of older versions of different... [58:40.220 --> 58:41.860] software-defined radios you can find out there. [58:42.140 --> 58:46.660] Really, when you start to get into it, just starting out, going to, um... [58:46.660 --> 58:56.900] One of my favorite things, if you find a city that recently upgraded their radio system to something that's, like, trunked or digital, go to the local pawn shop, so you can get some very nice radios for cheap, because people no longer have much of a use for them, [58:56.900 --> 58:57.580] and I sold them off. [58:59.080 --> 58:59.440] Yeah? [59:04.450 --> 59:04.810] Uh... [59:12.590 --> 59:14.250] Yeah, you mentioned just, uh... [59:14.250 --> 59:18.110] auction sites for universities, government auctions, all sorts of good stuff. [59:18.770 --> 59:19.130] Uh... [59:19.130 --> 59:22.230] We are up to midnight, or past midnight, one o'clock. [59:22.490 --> 59:22.750] Um... [59:22.750 --> 59:29.870] I have cards up here, if anybody wants to get in touch with me, feel free to grab a card, offices and bumper stickers, security justice, if you have any questions also, feel free to come up. [59:30.210 --> 59:31.570] Thank you very much for coming out. [59:31.750 --> 59:32.330] Hear me speak. [59:32.330 --> 59:37.510] I know that's, you know, midnight, there are parties, and sleep, and other stuff going on, so I appreciate everybody coming out. [59:37.730 --> 59:38.070] Thanks, guys. [59:47.320 --> 59:47.500] Yeah? [59:47.860 --> 59:50.220] Do you guys ever take off, or... [59:50.220 --> 59:53.500] you or anything, you know, take off interns, because I... [59:53.500 --> 59:53.940] Yes. [59:54.400 --> 59:54.460] Okay. [59:54.980 --> 59:55.160] Yes. [59:55.500 --> 59:58.340] Like, is this something that I'm interested in? [59:58.480 --> 59:58.580] Yep. [59:58.780 --> 01:00:01.160] And interested in, like, learning more about? [01:00:02.580 --> 01:00:02.980] Um... [01:00:02.980 --> 01:00:03.540] Yeah, we... [01:00:03.540 --> 01:00:04.780] So you guys do take off interns? [01:00:04.880 --> 01:00:05.400] Oh, yeah, we do. [01:00:05.680 --> 01:00:05.900] Okay. [01:00:06.000 --> 01:00:07.040] We definitely do. [01:00:08.060 --> 01:00:08.460] Um... [01:00:08.460 --> 01:00:09.740] So, yeah, drop us a line. [01:00:09.740 --> 01:00:09.960] Um... [01:00:09.960 --> 01:00:11.060] I think you're based in Cleveland. [01:00:11.300 --> 01:00:11.980] Yeah, where are you at? [01:00:12.240 --> 01:00:12.560] Um... [01:00:12.560 --> 01:00:13.020] I'm in Goldman. [01:00:13.300 --> 01:00:14.540] I'm in East Western. [01:00:14.860 --> 01:00:17.420] Drop me a line, because also I can get you involved with... [01:00:17.420 --> 01:00:19.280] There are all sorts of security groups in the area. [01:00:19.820 --> 01:00:21.340] We're in the lock picking group there. [01:00:22.020 --> 01:00:23.600] There are, like, 12 security groups. [01:00:24.080 --> 01:00:24.780] Drop me a line. [01:00:24.900 --> 01:00:25.920] We'll get you hooked up. [01:00:26.140 --> 01:00:26.920] And, um... [01:00:26.920 --> 01:00:28.900] Yeah, like I said, we're definitely looking for interns as well. [01:00:29.000 --> 01:00:31.360] I can definitely say that, especially with you being in Cleveland. [01:00:31.880 --> 01:00:32.040] Yeah. [01:00:32.240 --> 01:00:32.580] Let me know. [01:00:32.840 --> 01:00:32.940] Cool. [01:00:33.200 --> 01:00:33.340] Yep. [01:00:33.340 --> 01:00:39.660] Do you know of anybody who uses any kind of spread spectrum techniques for radios to enter a program? [01:00:41.640 --> 01:00:42.620] Can I see your comment? [01:00:42.820 --> 01:00:42.980] Yeah. [01:00:43.420 --> 01:00:43.620] Oh, yeah. [01:00:43.740 --> 01:00:44.100] Go for it. [01:00:44.220 --> 01:00:45.000] Battery is dead. [01:00:47.240 --> 01:00:47.640] Yeah. [01:00:47.900 --> 01:00:51.200] There are radio systems out there which will use spread spectrum. [01:00:53.320 --> 01:00:56.320] Tetra is one that uses some interesting frequency copy, mainly in Europe. [01:00:57.060 --> 01:01:04.260] But a lot of, like, the higher-end radios they start to see used by, like, Secret Service, other ones, will use spread spectrum. [01:01:04.500 --> 01:01:08.740] And, actually, a lot of federal agencies are getting away from individual handheld radios. [01:01:08.740 --> 01:01:12.660] And they actually use Nextel radios with custom vocoders. [01:01:13.440 --> 01:01:16.620] And that, again, uses some frequency copy and other technologies. [01:01:16.800 --> 01:01:18.080] So, that does come into play. [01:01:18.320 --> 01:01:21.180] Are you going to find that at a consumer site? [01:01:21.540 --> 01:01:22.300] Probably not. [01:01:23.540 --> 01:01:26.660] Because they're not going to want to pay for that type of functionality. [01:01:27.220 --> 01:01:28.160] But it is out there. [01:01:28.620 --> 01:01:30.240] Can you buy, like, a little short? [01:01:30.520 --> 01:01:33.980] Can you just send them a check, or do you have to be a government to get it? [01:01:35.460 --> 01:01:36.180] For, well... [01:01:38.400 --> 01:01:38.760] Depends. [01:01:40.180 --> 01:01:40.580] Yeah, you... [01:01:41.400 --> 01:01:43.340] Yeah, that's more what you get into. [01:01:43.520 --> 01:01:48.960] With getting, like, you can get on-block scanners in the United States for corporate use, if they're for testing. [01:01:49.340 --> 01:01:51.320] So, if you go through and fill out the paperwork, you can. [01:01:51.560 --> 01:01:53.460] But, usually, again, the budget stuff. [01:01:53.640 --> 01:01:58.340] I mean, that's where, you know, I had some amazing radio toys back when I did the TSCM work. [01:01:59.240 --> 01:02:08.420] Where right now, you know, the budget's less just because we don't need to spend, you know, tens of thousands of dollars on a frequency analyzer, as much as I would love to have one to play with. [01:02:09.680 --> 01:02:11.140] Yeah, eBay's a great place. [01:02:11.280 --> 01:02:12.080] University Labs. [01:02:15.940 --> 01:02:18.100] Yeah, you can get cheaper ones, definitely. [01:02:21.580 --> 01:02:22.920] Yeah, and those... [01:02:24.960 --> 01:02:25.320] Yeah. [01:02:25.780 --> 01:02:30.640] Yeah, and for the hobbyist-level stuff, and stuff that didn't work for this, yeah, you can get USB stuff. [01:02:30.640 --> 01:02:32.160] There are tons of options. [01:02:32.420 --> 01:02:35.640] I mean, that's one plus of a lot of the, you know, hobbyist movement. [01:02:36.060 --> 01:02:37.900] For cheap budget, you get some pretty cool stuff. [01:02:38.960 --> 01:02:42.720] At the radio, at least, is there a spectrum or is there a number of radars? [01:02:42.880 --> 01:02:43.760] And how is that in front of you? [01:02:44.260 --> 01:02:47.800] Yeah, um, Grover, uh, not, um...