Showing posts with label The Hackers Black Book. Show all posts
Showing posts with label The Hackers Black Book. Show all posts

Saturday, June 2, 2007

CHAPTER 9 AND 10

CHAPTER 9

Radio Computer Data

Vast quantities of data traffic are transmitted daily over the

radio frequency spectrum; hacking is simply a matter of hooking up a

good quality radio receiver and a computer through a suitable

interface. On offer are news services from the world's great press

agencies, commercial and maritime messages, meteorological data, and

plenty of heavily-encrypted diplomatic and military traffic. A

variety of systems, protocols and transmission methods are in use and

the hacker jaded by land-line communication (and perhaps for the

moment put off by the cost of phone calls) will find plenty of fun on

the airwaves.

The techniques of radio hacking are similar to those necessary for

computer hacking. Data transmission over the airwaves uses either a

series of audio tones to indicate binary 0 and 1 which are modulated

on transmit and demodulated on receive or alternatively frequency

shift keying which involves the sending of one of two slightly

different radio frequency carriers, corresponding to binary 0 or

binary 1. The two methods of transmission sound identical on a

communications receiver (see below) and both are treated the same for

decoding purposes. The tones are different from those used on

land-lines--'space' is nearly always 1275 Hz and 'mark' can be one of

three tones: 1445 Hz (170 Hz shift--quite often used by amateurs and

with certain technical advantages); 1725 Hz (450 Hz shift--the one

most commonly used by commercial and news services) and 2125 Hz (850

Hz shift--also used commercially). The commonest protocol uses the

5-bit Baudot code rather than 7-bit or 8-bit ASCII. The asynchronous,

start/stop mode is the most common. Transmission speeds include: 45

baud (60 words/minute), 50 baud (66 words/minute), 75 baud (100

words/ minute). 50 baud is the most common. However, many

interesting variants can be heard--special versions of Baudot for

non- European languages, error correction protocols, and various

forms of facsimile.

The material of greatest interest is to be found in the high

frequency or 'short wave' part of the radio spectrum, which goes from

2 MHz, just above the top of the medium wave broadcast band, through

to 30 MHz, which is the far end of the 10-meter amateur band which

itself is just above the well-known Citizens' Band at 27 MHz.

** Page 99

The reason this section of the spectrum is so interesting is that,

unique among radio waves, it has the capacity for world-wide

propagation without the use of satellites, the radio signals being

bounced back, in varying degrees, by the ionosphere. This special

quality means that everyone wants to use HF (high frequency)

transmission--not only international broadcasters, the propaganda

efforts of which are the most familiar uses of HF. Data transmission

certainly occurs on all parts of the radio spectrum, from VLF (Very

Low Frequency, the portion below the Long Wave broadcast band which

is used for submarine communication), through the commercial and

military VHF and UHF bands, beyond SHF (Super High Frequency, just

above 1000 MHz) right to the microwave bands. But HF is the most

rewarding in terms of range of material available, content of

messages and effort required to access it.

Before going any further, hackers should be aware that in a number

of countries even receiving radio traffic for which you are not

licensed is an offence; in nearly all countries making use of

information so received is also an offence and, in the case of news

agency material, breach of copyright may also present a problem.

However, owning the equipment required is usually not illegal and,

since few countries require a special license to listen to amateur

radio traffic (as opposed to transmitting, where a license is needed)

and since amateurs transmit in a variety of data modes as well,

hackers can set about acquiring the necessary capability without

fear.

Equipment

The equipment required consists of a communications receiver, an

antenna, an interface unit/software and a computer.

Communications receiver - This is the name given to a good quality

high frequency receiver. Suitable models can be obtained,

second-hand, at around £100; new receivers cost upwards of £175.

There is no point is buying a radio simply designed to pick up

shortwave broadcasts which will lack the sensitivity, selectivity and

resolution necessary. A minimum specification would be:

Coverage 500 kHz--30 MHz

Resolution >100 Hz

** Page 100

Modes AM, Upper Side Band, Lower Side Band,

CW (Morse)

Tuning would be either by two knobs, one for MHz, one for kHz, or

by keypad. On more expensive models it is possible to vary the

bandwidth of the receiver so that it can be widened for musical

fidelity and narrowed when listening to bands with many signals close

to one another.

Broadcast stations transmit using AM (amplitude modulation), but

in the person-to-person contacts of the aeronautical, maritime and

amateur world, single-side-band-suppressed carrier techniques are

used--the receiver will feature a switch marked AM, USB, LSB, CW etc.

Side-band transmission uses less frequency space and so allows more

simultaneous conversations to take place, and is also more efficient

in its use of the power available at the transmitter. The chief

disadvantage is that equipment for receiving is more expensive and

must be more accurately tuned. Upper side band is used on the whole

for voice traffic, and lower side band for data traffic. (Radio

amateurs are an exception: they also use lower side-band for voice

transmissions below 10 MHz.) Suitable sources of supply for

communications receivers are amateur radio dealers, whose addresses

may be found in specialist magazines like Practical Wireless, Amateur

Radio, Ham Radio Today.

Antenna - Antennas are crucial to good shortwave reception--the sort

of short 'whip' aerial found on portable radios is quite insufficient

if you are to capture transmissions from across the globe. When using

a computer close to a radio you must also take considerable care to

ensure that interference from the CPU and monitor don't squash the

signal you are trying to receive. The sort of antenna I recommend is

the 'active dipole', which has the twin advantages of being small and

of requiring little operational attention. It consists of a couple of

1-meter lengths of wire tied parallel to the ground and meeting in a

small plastic box. This is mounted as high as possible, away from

interference, and is the 'active' part. From the plastic box descends

coaxial cable which is brought down to a small power supply next to

the receiver and from there the signal is fed into the receiver

itself. The plastic box contains special low-noise transistors.

It is possible to use simple lengths of wire, but these usually

operate well only on a limited range of frequencies, and you will

need to cover the entire HF spectrum. Active antennas can be obtained

by mail order from suppliers advertising in amateur radio

magazines--the Datong is highly recommended.

** Page 101

Interface The 'interface' is the equivalent of the modem in landline

communications; indeed, advertisements of newer products actually refer to

radio modems. Radio tele-type, or RTTY, as it is called, is traditionally

received on a modified teleprinter or telex machine; and the early interfaces

or terminal units (TUs) simply converted the received audio tones into 'mark'

and 'space' to act as the equivalent of the electrical line conditions of a

telex circuit. Since the arrival of the microcomputer, however, the design

has changed dramatically and the interface now has to perform the following

functions:

1 Detect the designated audio tones

2 Convert them into electrical logic states

3 Strip the start/stop bits, convert the Baudot code into ASCII

equivalents, reinsert start/stop bits

4 Deliver the new signal into an appropriate port on the computer.

(If RS232C is not available, then any other port, e.g. Game, that

is)

A large number of designs exist: some consist of hardware

interfaces plus a cassette, disc or ROM for the software; others

contain both the hardware for signal acquisition and firmware for its

decoding in one box.

Costs vary enormously and do not appear to be related to quality

of result. The kit-builder with a ZX81 can have a complete set-up for

under £40; semi-professional models, including keyboards and screen

can cost in excess of £1000.

The kit I use is based on the Apple II (because of that model's

great popularity in the USA, much hardware and software exists); the

interface talks into the game port and I have several items of

software to present Baudot, ASCII or Morse at will. There is even

some interesting software for the Apple which needs no extra

hardware--the audio from the receiver is fed direct into the cassette

port of the Apple, but this method is difficult to replicate on other

machines because of the Apple's unique method of reading data from

cassette.

** Page 102

Excellent inexpensive hard/firmware is available for many Tandy

computers, and also for the VlC20/Commodore 64. On the whole US

suppliers seem better than those in the UK or Japan-- products are

advertised in the US magazines QST and 73.

Setting Up Particular attention should be paid to linking all the

equipment together; there are special problems about using sensitive

radio receiving equipment in close proximity to computers and VDUs.

Computer logic blocks, power supplies and the synchronising pulses on

VDUs are all excellent sources of radio interference (rfi). RFI

appears not only as individual signals at specific points on the

radio dial, but also as a generalised hash which can blank out all

but the strongest signals.

Interference can escape from poorly packaged hardware, but also

from unshielded cables which act as aerials. The remedy is simple to

describe: encase and shield everything, connecting all shields to a

good earth, preferably one separate from the mains earth. In

practice, much attention must be paid to the detail of the

interconnections and the relative placing of items of equipment. In

particular, the radio's aerial should use coaxial feeder with a

properly earthed outer braid, so that the actual wires that pluck the

signals from the ether are well clear of computer-created rfi. It is

always a good idea to provide a communications receiver with a proper

earth, though it will work without one: if used with a computer, it

is essential.

Do not let these paragraphs put you off; with care excellent

results can be obtained. And bear in mind my own first experience:

ever eager to try out same new kit, I banged everything together with

great speed--ribbon cable, poor solder joints, an antenna taped

quickly to a window in a metal frame less than two meters from the

communications receiver--and all I could hear from 500 kHz to 30

MHz, wherever I tuned, was a great howl-whine of protest...

Where to listen

Scanning through the bands on a good communications receiver, you

realise just how crowded the radio spectrum is. The table in Appendix

VI gives you an outline of the sandwich-like fashion in which the

bands are organised.

The 'fixed' bands are the ones of interest; more particularly, the

following ones are where you could expect to locate news agency

transmissions (in kHz):

** Page 103

3155 -- 3400 14350 -- 14990

3500 -- 3900 15600 -- 16360

3950 -- 4063 17410 -- 17550

4438 -- 4650 18030 -- 18068

4750 -- 4995 18168 -- 18780

5005 -- 5480 18900 -- 19680

5730 -- 5950 19800 -- 19990

6765 -- 7000 20010 -- 21000

7300 -- 8195 21850 -- 21870

9040 -- 9500 22855 -- 23200

ggoo -- 9995 23350 -- 24890

10100 -- 11175 25010 -- 25070

11400 -- 11650 25210 -- 25550

12050 -- 12330 26175 -- 28000

13360 -- 13600 29700 -- 30005

13800 -- 14000

In addition, amateurs tend to congregate around certain spots on the

frequency map: 3590, 14090, 21090, 28090, and at VHF/UHF: 144.600,

145.300, MHz 432.600, 433.300.

Tuning In

Radio Teletype signals have a characteristic two-tone warble sound

which you will hear properly only if your receiver is operating in

SSB (single-side-band) mode. There are other digital tone-based

signals to be heard: FAX (facsimile), Helschcrieber (which uses a

technique similar to dot-matrix printers and is used for Chinese and

related pictogram-style alphabets), SSTV (slow scan television, which

can take up to 8 seconds to send a low-definition picture), and

others.

But with practice, the particular sound of RTTY can easily be

recognised. More experienced listeners can also identify shifts and

speeds by ear.

You should tune into the signal watching the indicators on your

terminal unit to see that the tones are being properly captured--

typically, this involves getting two LEDs to flicker simultaneously.

The software will now try to decode the signal, and it will be up

to you to set the speed and 'sense'. The first speed to try is 66/7

words per minute, which corresponds to 50 baud, as this is the most

common. On the amateur bands, the usual speed is 60 words per minute

(45 baud); thereafter, if the rate sounds unusually fast, you try 100

words per minute (approximately 75 baud).

** Page 104

By 'sense' or 'phase' is meant whether the higher tone corresponds

to logical 1 or logical 0. Services can use either format; indeed

the same transmission channel may use one 'sense' on one occasion and

the reverse 'sense' on another. Your software can usually cope with

this. If it can't, all is not lost: you retune your receiver to the

opposite, side-band and the phase will thereby be reversed. So, if

you are listening on the lower side-band (LSB), usually the

conventional way to receive, you simply switch over to USB (upper

side-band), retune the signal into the terminal unit, and the sense'

will have been reversed.

Many news agency stations try to keep their channels open even if

they have no news to put out: usually they do this by sending test

messages like: 'The quick brown fox....' or sequences like

'RYRYRYRYRYRY...' such signals are useful for testing purposes, if

a little dull to watch scrolling up the VDU screen.

You will discover many signals that you can't decode: the

commonest reason is that the transmissions do not use European

alphabets, and all the elements in the Baudot code have been

re-assigned--some versions of Baudot use not one shift, but two, to

give the required range of characters. Straightforward en- crypted

messages are usually recognisable as coming in groups of five

letters, but the encryption can also operate at the bit- as well as

at the character-level -- in that case, too, you will get

gobbleydegook.

A limited amount of ASCII code as opposed to Baudot is to be

found, but mostly on the amateur bands.

Finally, an error-correction protocol, called SITOR, is

increasingly to be found on the maritime bands, with AMTOR, an amateur

variant, in the amateur bands, SITOR has various modes of operation

but, in its fullest implementation, messages are sent in blocks which

must be formally acknowledged by the recipient before the next one is

despatched. The transmitter keeps trying until an acknowledgement is

received. You may even come across, on the amateur bands, packet

radio, which has some of the features of packet switching on digital

land lines. This is one of the latest enthusiasms in amateur radio

with at least two different protocols in relatively wide use.

Discussion of SITOR and packet radio is beyond the scope of this

book, but the reader is referred to BARTG (the British Amateur Radio

Teletype Group) and its magazine Datacom for further information. You

do not need to be a licensed radio amateur to join. The address is:

27 Cranmer Court, Richmond Road, Kingston KT2 SPY.

Operational problems of radio hacking are covered at the end of

Appendix I, the Baudot code is given Appendix IV and an outline

frequency plan is to be found in Appendix VI.

** Page 105

The material that follows represents some of the types of common

transmissions: news services, test slips (essentially devices for

keeping a radio channel open), and amateur. The corruption in places

is due either to poor radio propagation conditions or to the presence

of interfering signals.

REVUE DE LA PRESSE ITALIENNE DU VENDREDI 28 DECEMBRE 1984

LE PROCES AUX ASSASSINS DE L~ POIELUSZKO, LA VISITE DE

M. SPADOLINI A ISRAEL, LA SITUATION AU CAMBODGE ET LA GUER-

ILLA AU MOZAMBIQUE FONT LES TITES DES PAGES POLITIQUES

MOBILISATION TO WORK FOR THE ACCOUNT OF 1985

- AT THE ENVER HOXHA AUTOMOBILE AND

TRACTOR COMBINE IN TIRANA 2

TIRANA, JANUARY XATA/. - THE WORKING PEOPLE OF THE ENVER HOXH~/

AUTOMOBILE AND TRACTOR COMBINE BEGAN THEIR WORR WITH VIGOUR

AND MOBILISATION FOR THE ACCOUNT OF 1985. THE WORK IN THIS

IMPROVOWNT CENTER FOR MECHANICAL INDUSTRY WAS NOT INTERRUPTED

FOR ONE MOMENT AND THE WORKING PEOPLE 8~S ONE ANOTHER FOR

FRESHER GREATER VICTORIES UNDER THE LEADERSHIP OF THE PARTY

WITH ENVER HOXHA AT THE HEAD, DURING THE SHIFTS, NEAR

THE FURNANCES~ PRESSES ETC.. JUST LIKE SCORES OF WORKING COLLE-

CTIVES OF THE COUNTRY WHICH WERE NOT AT HOME DURING THE NEW

YEAR B

IN THE FRONTS OF WORK FOR THE BENEFITS OF THE SOCI-

ALIST CONSTRUCTION OF THE COUNTRY.

PUTTING INTO LIFE THE TEACHINGS OF THE PARTY AND THE INSTRU-

CTIONS OF COMRADE ENVER HOXHA, THE WORKING COLLECTIVE OF THIS

COMBINE SCORED FRESH SUCCESSES DURING 1984 TO REALIZE THE

INDICES OF THE STATE PLAN BY RASING THE ECEONOMIC EFFECTIVE-

NESS. THE WORKING PEOPLE SUCCESSFULLY REALIZED AND OVERFUL

FILLED THE OBJECTIVE OF THE REVOLUTIONARY DRIVE ON THE HIGHER

EFFECTIOVENESS OF PRODUCTION, UNDERTAKEN IN KLAIDQAULSK SO~

WITHIN 1984 THE PLANNED PRODUCTIVITY, ACCORDING TO THE INDEX

OF THE FIVE YEAR PLAN, WAS OVERFULFILLED BY 2 PER CENT.

MOREOVER, THE FIVE YEAR PLAN FOR THE GMWERING OF THE COST OF

PRODUCTION WAS RAISED 2 MONTHS AHEAD OF TIME, ONE FIVE YEAR

PLAN FOR THE PRODUCTION OF MACHINERIES LAND EQUIPMENT AND

THE PRODUCTION OF THE TRACTORS WAS OVER-

FULFILLED. THE NET INCOME OF THE FIVE YEAR PLAN WAS REALIZED

WITHIN 4 YEARS. ETCM

YRYRYRYRYRYRYRYRYRYRYRYRYRYRYRYRYRYRYRYRYRYRYRYRYRYRYRYRY

RYRYRYRYRYRYRYRYRYRYRYRYRYRYRYRYRYRYRYRYRYRYRYRYRYRYRYRYR

** Page 106

YRYRYRYRYRYRYRYRYRYRYRYRYRYRYRYRYRYRYRYRYRYRYRYRYRYRYRYRY

YRYRYRYRYRYRYRYRYRYRYRYRYRYRYRYRYRYRYRYRYRYRYRYRYRYRYRYRY

RYRYRYRYRYRYRYRYRYRYRYRYRYRYRYRYRYRYRYR~ u UL ~v_.~v

GJ4YAD GJ4YAD DE G4DF G4DF

SOME QRM BUT MOST OK. THE SHIFT IS NORMAL...SHIFT IS NORMAL.

FB ON YOUR RIG AND NICE TO MEET YOU IN RTTY. THE WEATHER HERE

TODAY IS FINE AND BEEN SUNNY BUT C9LD. I HAVE BEEN IN THIS MODE

BEFORE BUT NOT FOR A FEW YEARS HI HI.

GJ4YAD GJ4YAD DE G4DF G4DF

PSE KKK

G4ElE G4EJE DE G3IMS G3IMS

TNX FOR COMING BACk. RIG HERE IS ICOM 720A BUT I AM SENDING

AFSk; NOT FSk'. I USED TO HAVE A CREED BUT CHUCKED IT OUT IT WAS

TOO NOISY AND NOW HAVE VIC2D SYSTEM AND SOME US kIT MY SON

BROUGHT ME HE TRAVELS A LOT.

HAD LOTS OF TROUBLE WITH RFI AND HAVE NOT YET CURED IT. VERTY BAD

QRM AT MOMENT. CAN GET NOTHING ABOVE 1CI MEGS AND NOT MUCH EX-G ON

S(:). HI HI. SUNSPOT COUNT IS REALLY LOW.

G4EJE G4EJE DE G3IMS G3IMS

~I.Of;KKKk'KKKK

RYRYRYRYRYRYRYRYRYR

~K~fk'KKKKKKK

G3IMS G3IMS DE G4EJE G4EJE

FB OM. URM IS GETTING WORSE. I HAVE ALWAYS LIk.ED ICOM RIGS BUT

THEY ARE EXEPENSIVE. CAN YOU RUN FULL 1QCI PER CENT DUTY CYCLE ON

RTTY OR DO YOU HAVE TO RUN AROUND 50 PER CENT. I GET OVER-HEATING

ON THIS OLD YAESU lQl. WHAT SORT OF ANTENNA SYSTEM DO YOU USE.

HERE IS A TRAPPED VERTICAL WITH 8CI METERS TUNED TO RTTY SPOT AT

~;59(:1.

I STILL USE CREED 7 THOUGH AM GETTING FED UP WITH MECHANICAL

BREAK- W WN AND NOISE BUT I HAVE HEARD ABOUT RFI AND HOME

COMPUTER5. MY NEPHEW HAS A SPECTRUM, CAN YOU GET RTTY SOFTWARE

FOR THAT/.

G3IMs G3IMS DE G4EJE G4EJE

** Page 107

CHAPTER 10

Hacking: the Future

Security is now probably the biggest single growth area within the

mainstream computer business. At conference after conference,

consultants compete with each other to produce the most frightening

statistics.

The main concern, however, is not hacking but fraud. Donn Parker,

a frequent writer and speaker on computer crime based at the Stanford

Research Institute has put US computer fraud at $3000 million a year;

although reported crimes amount to only $100 million annually. In

June 1983 the Daily Telegraph claimed that British computer-related

frauds could be anything between £500 million and £2.5 billion a

year. Detective Inspector Ken McPherson, head of the computer crime

unit at the Metropolitan Police, was quoted in 1983 as saying that

within 15 years every fraud would involve a computer. The trouble is,

very few victims are prepared to acknowledge their losses. To date,

no British clearing bank has admitted to suffering from an

out-and-out computer fraud, other than the doctoring of credit and

plastic ID cards. Few consultants believe that they have been immune.

However, to put the various threats in perspective, here are two

recent US assessments. Robert P Campbell of Advanced Information

Management, formerly head of computer security in the US Army,

reckons that only one computer crime in 100 is detected; of those

detected, 15 per cent or fewer are reported to the authorities, and

that of those reported, one in 33 is successfully prosecuted--a

'clear-up' rate of one in 22,000.

And Robert Courtney, former security chief at IBM produced a list

of hazards to computers: 'The No 1 problem now and forever is errors

and omissions'. Then there is crime by insiders, particularly

non-technical people of three types: single women under 35; 'little

old ladies' over 50 who want to give the money to charity; and older

men who feel their careers have left them neglected. Next, natural

disasters. Sabotage by disgruntled employees. Water damage. As for

hackers and other outsiders who break in, he estimates it is less

than 3 per cent of the total.

** Page 108

Here in the UK, the National Computing Centre says that at least

90 per cent of computer crimes involve putting false information into

a computer, as opposed to sophisticated logic techniques; such crimes

are identical to conventional embezzlement: looking for weaknesses

in an accounting system and taking advantage. In such cases the

computer merely carries out the fraud with more thoroughness than a

human, and the print-out gives the accounts a spurious air of being

correct.

In the meantime, we are on the threshold of a new age of

opportunities for the hacker. The technology we can afford has

suddenly become much more interesting.

The most recent new free magazines to which I have acquired

subscriptions are for owners of the IBM PC, its variants and clones.

There are two UK monthlies for regular users, another for corporate

buyers and several US titles.

The IBM PC is only partly aimed at small business users as a

stand-alone machine to run accounting, word processing, spread- sheet

calculation and the usual business dross; increasingly the marketing

is pitching it as an executive work-station, so that the corporate

employee can carry out functions not only local to his own office,

but can access the corporate mainframe as well--for data, messaging

with colleagues, and for greater processing power.

In page after page, the articles debate the future of this

development--do employees want work-stations? Don't many bosses still

feel that anything to do with typing is best left to their secretary?

How does the executive workstation relate to the mainframe? Do you

allow the executive to merely collect data from it, or input as well?

If you permit the latter, what effect will this have on the integrity

of the mainframe's files? How do you control what is going on? What

is the future of the DP professional? Who is in charge?

And so the articles go on. Is IBM about to offer packages which

integrate mainframes and PCs in one enormous system, thus effectively

blocking out every other computer manufacturer and software publisher

in the world by sheer weight and presence?

I don't know the answers to these questions, but elsewhere in

these same magazines is evidence that the hardware products to

support the executive workstation revolution are there--or, even if

one has the usual cynicism about computer trade advertising ahead of

actual availability, about to be.

The products are high quality terminal emulators, not the sort of

thing hitherto achieved in software--variants on asynchronous

protocols with some fancy cursor addressing--but cards capable of

supporting a variety of key synchronous communications, like 327x

(bisynch and SDLC), and handling high-speed file transfers in CICs,

TSO, IMS and CMS.

** Page 109

These products feature special facilities, like windowing or

replicate aspects of mainframe operating systems like VM (Virtual

Machine), giving the user the experience of having several different

computers simultaneously at his command. Other cards can handle IBM's

smaller mini- mainframes, the Systems/34 and /38. Nor are other

mainframe manufacturers with odd-ball comms requirements ignored:

ICL, Honeywell and Burroughs are all catered for. There are even

several PC add-ons which give a machine direct X.25; it can sit on a

packet-switched network without the aid of a PAD.

Such products are expensive by personal micro standards, but it

means that, for the expenditure of around £8000, the hacker can call

up formidable power from his machine. The addition of special

environments on these new super micros which give the owner direct

experience of mainframe operating systems--and the manuals to go with

them--will greatly increase the population of knowledgeable computer

buffs. Add to this the fact that the corporate workstation market, if

it is at all succesful, must mean that many executives will want to

call their mainframe from home --and there will be many many more

computer ports on the PTSN or sitting on PSS.

There can be little doubt that the need for system security will

play an increasing role in the specification of new mainframe

installations. For some time, hardware and software engineers have

had available the technical devices necessary to make a computer

secure; the difficulty is to get regular users to implement the

appropriate methods--humans can only memorise a limited number of

passwords. I expect greater use will be made of threat monitoring

techniques: checking for sequences of unsuccessful attempts at

logging in, and monitoring the level of usage of customers for

extent, timing, and which terminals or ports they appear on.

The interesting thing as far as hackers are concerned is that it

is the difficulty of the exercise that motivates us, rather than the

prospect of instant wealth. It is also the flavour of naughty, but

not outright, illegality. I remember the Citizens Band radio boom of

a few years ago: it started quietly with just a handful of London

breakers who had imported US sets, really simply to talk to a few

friends. One day everyone woke up, switched on their rigs and

discovered overnight there was a whole new sub-culture out there,

breathing the ether. Every day there were more and more until no

spare channels could be found. Then some talented engineers found out

how to freak the rigs and add another 40 channels to the original 40.

And then another 40. Suddenly there were wholesalers and retailers

and fanzines, all selling and promoting products the using or

manufacturing of which was illegal under British law.

** Page 110

Finally, the government introduced a legalised CB, using different

standards from the imported US ones. Within six months the illegal

scene had greatly contracted, and no legal CB service of comparable

size ever took its place. Manufacturers and shop- keepers who had

expected to make a financial killing were left with warehouses full

of the stuff. Much of the attraction of AM CB was that it was

forbidden and unregulated. There is the desire to be an outlaw, but

clever and not too outrageous with it, in very many of us.

So I don't believe that hacking can be stopped by tougher

security, or by legislation, or even by the fear of punishment.

Don't get me wrong: I regard computers as vastly beneficial. But

they can threaten our traditional concepts of freedom, individuality

and human worth I like to believe hacking is a curious

re-assertion of some of those ideas.

The challenge of hacking is deeply ingrained in many computer

enthusiasts; where else can you find an activity the horizons of

which are constantly expanding, where new challenges and dangers can

be found every day, where you are not playing a visibly artificial

'game', where so much can be accessed with so little resource but a

small keyboard, a glowing VDU, an inquisitive and acquisitive brain,

and an impish mentality?

CHAPTER 8


Viewdata Systems

Viewdata, or videotex, has had a curious history. At one stage, in

the late 1970s, it was possible to believe that it was about to take

over the world, giving computer power to the masses via their

domestic tv sets. It was revolutionary in the time it was developed,

around 1975, in research laboratories owned by what was then called

the Post Office, but which is now British Telecom. It had a

colour-and-graphics display, a user-friendly means of talking to it

at a time when most computers needed precise grunts to make them

work, and the ordinary layperson could learn how to use it in five

minutes.

The viewdata revolution never happened, because Prestel, its most

public incarnation, was mismarketed by its owners, British Telecom,

and because, in its original version, it is simply too clumsy and

limited to handle more sophisticated applications. All information is

held on electronic file cards which can easily be either too big or

too small for a particular answer and the only way you can obtain the

desired information is by keying numbers, trundling down endless

indices. In the early days of Prestel, most of what you got was

indices, not substantive information. By the time that viewdata sets

were supposed to exist in their hundreds of thousands, home

computers, which had not been predicted at all when viewdata first

appeared, had already sold into the millionth British home.

Yet private viewdata, mini-computers configured to look like

Prestel and to use the same special terminals, has been a modest

success. At the time of writing there are between 120 and 150

significant installations. They have been set up partly to serve the

needs of individual companies, but also to help particular trades,

industries and professions. The falling cost of viewdata terminals

has made private systems attractive to the travel trade, to retail

stores, the motor trade, to some local authorities and to the

financial world.

** Page 86

The hacker, armed with a dumb viewdata set, or with a software

fix for his micro, can go ahead and explore these services. At the

beginning of this book, I said my first hack was of a viewdata

service. Viditel, the Dutch system. It is astonishing how many

British hackers have had a similar experience. Indeed, the habit of

viewdata hacking has spread throughout Europe also: the wonder- fully

named Chaos Computer Club of Hamburg had some well-publicised fun

with Bildschirmtext, the West German Prestel equivalent

colloquially-named Btx.

What they appear to have done was to acquire the password of the

Hamburger Sparkasse, the country's biggest savings bank group.

Whereas telebanking is a relatively modest part of Prestel --the

service is called Homelink--the West German banks have been a

powerful presence on Btx since its earliest days. In fact, another

Hamburg bank, the Verbraucher Bank, was responsible for the world's

first viewdata Gateway, for once in this technology, showing the

British the way. The 25-member Computer Chaos Club probably acquired

the password as a result of the carelessness of a bank employee.

Having done so, they set about accessing the bank's own, rather high

priced, pages, some of which cost almost DM10 (£2.70). In a

deliberate demonstration, the Club then set a computer to

systematically call the pages over and over again, achieving a

re-access rate of one page every 20 seconds. During a weekend in

mid-November 1984, they made more than 13,000 accesses and ran up a

notional bill of DM135,000 (£36,000). Information Providers, of

course, are not charged for looking at their own pages, so no bill

was payable and the real cost of the hack was embarrassment.

In hacking terms, the Hamburg hack was relatively trivial-- simple

password acquisition. Much more sophisticated hacks have been

perpertrated by British enthusiasts.

Viewdata hacking has three aspects: to break into systems and become

user, editor or system manager thereof; to discover hidden parts of

systems to which you have been legitimately admitted, and to uncover

new services.

Viewdata software structures

An understanding of how a viewdata database is set up is a great

aid in learning to discover what might be hidden away. Remember,

there are always two ways to each page--by following the internal

indexes, or by direct keying using *nnn#. In typical viewdata

software, each electronic file card or 'page' exists on an overall

tree-like structure:

** Page 87

Page

0

|

---------------------+----------------------- ...

1 2 3 4 5 6 7 8

|

------------+-------------------------------- ...

31 32 33 34 35 36 37 38

|

------------------------+-------------------- ...

351 352 353 354 355 356 357 358 3-digit

| node

-------------+------------------------------- ...

3531 3532 3533 3534 3535 3536 3537 3538

|

-------------------------------------------+-- ...

Top pages are called parents; lower pages filials. Thus page 3538

needs parent pages 353, 35, 3 and 0 to support it, i.e. these pages

must exist on the system. On Prestel, the parents owned by

Information Providers (the electronic publishers) are 3 digits long

(3-digit nodes). Single and double-digit pages (0 to 99) are owned by

the 'system manager' (and so are any pages beginning with the

sequences 100nn-199nn and any beginning with a 9nnn). When a page is

set up by an Information Provider (the process of going into 'edit'

mode varies from software package to package; on Prestel, you call up

page 910) two processes are necessary--the overt page (i.e. the

display the user sees) must be written using a screen editor. Then

the IP must select a series of options--e.g. whether the page is for

gathering a response from the user or is just to furnish information;

whether the page is to be open for viewing by all, by a Closed User

Group, or just by the IP (this facility is used while a large

database is being written and so that users don't access part of it

by mistake); the price (if any) the page will bear--and the 'routing

instructions'. When you look at a viewdata page and it says 'Key 8

for more information on ABC', it is the routing table that is

constructed during edit that tells the viewdata computer: 'If a user

on this page keys 8, take him through to the following next page'.

Thus, page 353880 may say 'More information on ABC....KEY 8'. The

information on ABC is actually held on page 3537891. The routing

table on page 353880 will say: 8=3537891. In this example, you will

see that 3537891 i9 not a true filial of 353880--this does not

matter; however, in order for 3537891 to exist on the system, its

parents must exist, i.e. there must be pages 353789, 35378, 3537

etc.

** Page 88

P R E S T E L

PRESTEL EDITING SYSTEM

Input Details -

Update option o

Pageno 4190100 Frame-Id a

User CUG User access y

Frame type i Frame price 2p

Choice type s

Choices

0- * 1- 4196121

2- 4196118 3- 4196120

4- 4196112 5- 4196119

6- 4196110 7- *

8- 4190101 9- 4199

Prestel Editing. This is the 'choices' page which se s up the frame

before the overt page - the one the user sees - is prepared.

These quirky features of viewdata software can help the hacker

search out hidden databases:

* Using a published directory, you can draw up a list of 'nodes' and

who occupies them. You can then list out apparently 'unoccupied'

nodes and see if they contain anything interesting. It was when a

hacker spotted that an 'obvious' Prestel node, 456, had been unused

for a while, that news first got out early in 1984 about the Prestel

Micro computing service, several weeks ahead of the official

announcement.

* If you look at the front page of a service, you can follow the

routings of the main index--are all the obvious immediate filials

used? If not, can you get at them by direct keying?

** Page 89

* Do any services start lower down a tree than you might expect

(i.e. more digits in a page number than you might have thought)? In

that case, try accessing the parents and see what happens.

* Remember that you can get a message 'no such page' for two

reasons: because the page really doesn't exist, or because the

Information Provider has put it on 'no user access'. In the latter

case, check to see whether this has been done consistently--look at

the immediate possible filials. To go back to when Prestel launched

its Prestel Microcom- puting service, using page 456 as a main node,

456 itself was closed off until the formal opening, but page 45600

was open.

Prestel Special Features

In general, this book has avoided giving specific hints about

individual services, but Prestel is so widely available in the UK and

so extensive in its coverage that a few generalised notes seem

worthwhile.

Not all Prestel's databases may be found via the main index or in

the printed directories; even some that are on open access are

unadvertised. Of particular interest over the last few years have

been nodes 640 (owned by the Research and Development team at

Martlesham), 651 (Scratchpad--used for ad hoc demonstration

databases), 601 (mostly mailbox facilities but also known to carry

experimental advanced features so that they can be tried out), and

650 (News for Information Providers--mostly but not exclusively in a

Closed User Group). Occasionally equipment manufacturers offer

experimental services as well: I have found high-res graphics and

even instruction codes for digitised full video lurking around.

In theory, what you find on one Prestel computer you will find on

all the others. In practice this has never been true, as it has

always been possible to edit individually on each computer, as well

as on the main updating machine which is supposed to broadcast to all

the others. The differences in what is held in each machine will

become greater over time.

Gateway is a means of linking non-viewdata external computers to

the Prestel system. It enables on-screen buying and booking, complete

with validation and confirmation. It even permits telebanking, Most

'live' forms of gateway are very secure, with several layers of

password and security. However, gateways require testing before they

can be offered to the public; in the past, hackers have been able to

secure free rides out of Prestel....

** Page 90

Careful second-guessing of the routings on the databases including

telesoftware(*) have given users free programs while the

telesoftware(*) was still being tested and before actual public

release.

Prestel, as far as the ordinary user is concerned, is a very

secure system--it uses 14-digit passwords and disconnects after three

unsuccessful tries. For most purposes, the only way of hacking into

Prestel is to acquire a legitimate user's password, perhaps because

they have copied it down and left it prominently displayed. Most

commercial viewdata sets allow the owner to store the first ten

digits in the set (some even permit the full 14), thus making the

casual hacker's task easier. However, Prestel was sensationally

hacked at the end of October 1984, the whole system Iying at the feet

of a team of four West London hackers for just long enough to

demonstrate the extent of their skill to the press. Their success was

the result of persistence and good luck on their side and poor

security and bad luck on the part of BT. As always happens with

hacking activities that do not end up in court, some of the details

are disputed; there are also grounds for believing that news of the

hack was deliberately held back until remedial action had taken

place, but this is the version I believe:

The public Prestel service consists of a network of computers,

mostly for access by ordinary users, but with two special-purpose

machines, Duke for IPs to update their information into and Pandora,

to handle Mailboxes (Prestel's variant on electronic mail). The

computers are linked by non-public packet-switched lines. Ordinary

Prestel users are registered (usually) onto two or three computers

local to them which they can access with the simple three-digit

telephone number 618 or 918. In most parts of the UK, these two

numbers will return a Prestel whistle. (BT Prestel have installed a

large number of local telephone nodes and

(*)Tefesoftware is a technique for making regular computer programs

available via viewdata the program lines are compressed according to

a simple set of rules and set up on a senes of viewdata frames. Each

frame contains a modest error-checking code. To receive a program,

the user's computer, under the control of a 'download' routine calls

the first program page down from the viewdata host, runs the error

check on it, and demands a re transmission if the check gives a

'false' If it gives a 'true', the user's machine unsqueezes the

programmes and dumps them into the Computers main memory or disc

store. It then requests the next viewdata page unfil the whole

program is collected. You then have a text file which must be

Converted into program instructions. Depending on what model of

micro you have, and which telesoftware package, you can either run

the program immediately or expect it. Personally I found the

telesoftware experience interesting the first time I tried it, and

quite useless in terms of speed, reliability and quality afterwards.

** Page 91

leased lines to transport users to their nearest machine at local

call rates, even though in some cases that machine may be 200 miles

away). Every Prestel machine also has several regular phone numbers

associated with it, for IPs and engineers. Most of these numbers

confer no extra privileges on callers: if you are registered to a

particular computer and get in via a 'back-door' phone number you

will pay Prestel and IPs exactly the same as if you had dialled 618

or 918. If you are not registered, you will be thrown off after three

tries.

In addition to the public Prestel computers there are a number of

other BT machines, not on the network, which look like Prestel and

indeed carry versions of the Prestel database. These machines, left

over from an earlier stage of Prestel's development, are now used for

testing and development of new Prestel features. The old Hogarth

computer, originally used for international access, is now called

'Gateway Test' and, as its name implies, is used by IPs to try out

the interconnections of their computers with those of Prestel prior

to public release. It is not clear how the hackers first became aware

of the existence of these 'extra' machines; one version is that it

was through the acquisition of a private phone book belonging to a BT

engineer. Another version suggests that they tried 'obvious' log-in

pass-numbers--2222222222 1234--on a public Prestel computer and found

themselves inside a BT internal Closed User Group which contained

lists of phone numbers for the develop computers. The existence of at

least two stories suggests that the hackers wished to protect their

actual sources. In fact, some of the phone numbers had, to my certain

knowledge, appeared previously on bulletin boards.

At this first stage, the hackers had no passwords; they could

simply call up the log-in page. Not being registered on that

computer, they were given the usual three tries before the line was

disconnected.

For a while, the existence of these log-in pages was a matter of

mild curiosity. Then, one day, in the last week of October, one of

the log-in pages looked different: it contained what appeared to be a

valid password, and one with system manager status, no less. A

satisfactory explanation for the appearance of this password

imprinted on a log-in page has not so far been forthcoming. Perhaps

it was carelessness on the part of a BT engineer who thought that, as

the phone number was unlisted, no unauthorised individual would ever

see it. The pass-number was tried and admission secured.

** Page 92

After a short period of exploration of the database, which

appeared to be a 'snapshot' of Prestel rather than a live version of

it--thus showing that particular computer was not receiving constant

updates from Duke--the hackers decided to explore the benefits of

System Manager status. Since they had between them some freelance

experience of editing on Prestel, they knew that all Prestel special

features pages are in the *9nn# range: 910 for editing; 920 to change

personal passwords; 930 for mailbox messages and so ...what would

pages 940, 950, 960 and so on do? It became obvious that these pages

would reveal details of users together with account numbers

(systelnos), passwords and personal passwords. There were facilities

to register and deregister users.

However, all this was taking place on a non-public computer. Would

the same passwords on a 'live' Prestel machine give the same

benefits? Amazingly enough, the passwords gave access to every

computer on the Prestel network. It was now time to examine the user

registration details of real users as opposed to the BT employees who

were on the development machine. The hackers were able to assume any

personality they wished and could thus enter any Closed User Group,

simply by picking the right name. Among the CUG services they swooped

into were high-priced ones providing investment advice for clients of

the stockbroker Hoare Govett and commentary on international currency

markets supplied by correspondents of the Financial Times. They were

also able to penetrate Homelink, the telebanking service run by the

Nottingham Building Society. They were not able to divert sums of

money, however, as Homelink uses a series of security checks which

are independent of the Prestel system.

Another benefit of being able to become whom they wished was the

ability to read Prestel Mailboxes, both messages in transit that had

not yet been picked up by the intended recipient and those that had

been stored on the system once they had been read. Among the

Mailboxes read was the one belonging to Prince Philip. Later, with a

newspaper reporter as witness, one hacker sent a Mailbox, allegedly

from Prince Philip to the Prestel System Manager:

I do so enjoy puzzles and games. Ta ta. Pip! Pip!

H R H Hacker

Newspaper reports also claimed that the hackers were able to gain

editing passwords belonging to IPs, enabling them to alter pages and

indeed the Daily Mail of November 2nd carried a photograph of a

Prestel page from the Financial Times International Financial Alert

saying:

** Page 93

FT NEWSFLASH!!! œ1 EQUALS $50

The FT maintained that, whatever might theoretically have been

possible, in fact they had no record of their pages actually being so

altered and hazarded the suggestion that the hacker, having broken

into their CUG and accessed the page, had 'fetched it back' onto his

own micro and then edited there, long enough for the Mail's

photographer to snap it for his paper, but without actually

retransmitting the false page back to Prestel. As with so many other

hacking incidents, the full truth will never be known because no one

involved has any interest in its being told.

However, it is beyond doubt that the incident was regarded with the

utmost seriousness by Prestel itself. They were convinced of the

extent of the breach when asked to view page 1, the main index page,

which bore the deliberate mis-spelling: Idnex. Such a change

theoretically could only have been made by a Prestel employee with

the highest internal security clearance. Within 30 minutes, the

system manager password had been changed on all computers, public and

research. All 50,000 Prestel users signing on immediately after

November 2nd were told to change their personal password without

delay on every computer to which they were registered. And every IP

received, by Special Delivery, a complete set of new user and editing

passwords.

Three weeks after the story broke, the Daily Mail thought it had

found yet another Prestel hack and ran the following page 1 headline:

'Royal codebuster spies in new raid on Prestel', a wondrous

collection of headline writer's buzzwords to capture the attention of

the sleepy reader. This time an Information Provider was claiming

that, even after new passwords had been distributed, further security

breaches had occurred and that there was a 'mole' within Prestel

itself. That evening, Independent Television News ran a feature much

enjoyed by cognoscenti: although the story was about the Prestel

service, half the film footage used to illustrate it was wrong: they

showed pictures of the Oracle (teletext) editing facility and of

some-one using a keypad that could only have belonged to a TOPIC set,

as used for the Stock Exchange's private service. Finally, the name

of the expert pulled in for interview was mis-spelled although he was

a well-known author of micro books. The following day, BBC-tv's

breakfast show ran an item on the impossibility of keeping Prestel

secure, also full of ludicrous inaccuracies.

** Page 94

It was the beginning of a period during which hackers and hacking

attracted considerable press interest. No news service operating in

the last two months of 1984 felt it was doing an effective job if it

couldn't feature its own Hacker's Confession, suitably filmed in deep

shadow. As happens now and again, press enthusiasm for a story ran

ahead of the ability to check for accuracy and a number of Hacks That

Never Were were reported and, in due course, solemnly commented on.

BT had taken much punishment for the real hack--as well as causing

deep depression among Prestel staff, the whole incident had occurred

at the very point when the corporation was being privatised and

shares being offered for sale to the public--and to suffer an

unwarranted accusation of further lapses in security was just more

than they could bear. It is unlikely that penetration of Prestel to

that extent will ever happen again, though where hacking is

concerned, nothing is impossible.

There is one, relatively uncommented-upon vulnerability in the

present Prestel set-up: the information on Prestel is most easily

altered via the bulk update protocols used by Information Providers,

where there is a remarkable lack of security. All the system

presently requires is a 4-character editing password and the IP's

systel number, which is usually the same as his mailbox number

(obtainable from the on-system mailbox directory on page *7#) which

in turn is very likely to be derived from a phone number.

Other viewdata services

Large numbers of other viewdata services exist: in addition to the

Stock Exchange's TOPIC and the other viewdata based services

mentioned in chapter 4, the travel trade has really clutched the

technology to its bosom: the typical High Street agent not only

accesses Prestel but several other services which give up-to-date

information on the take-up of holidays, announce price changes and

allow confirmed air-line and holiday bookings.

Several of the UK's biggest car manufacturers have a stock locator

system for their dealers: if you want a British Leyland model with a

specific range of accessories and in the colour combinations of your

choice, the chances are that your local dealer will not have it

stock. He can, however, use the stock locator to tell him with which

other dealer such a machine may be found.

Stock control and management information is used by retail chains

using, in the main, a package developed by a subsidiary of Debenhams.

Debenhams had been early enthusiasts of Prestel in the days when it

was still being pitched at a mass consumer audience--its service was

called Debtel which wags suggested was for people who owed money or,

alternatively, for upper-class young ladies.

** Page 95

Later it formed DISC to link together its retail outlets, and this

was hacked in 1983. The store denied that anything much had

happened, but the hacker appeared (in shadow) on a tv program

together with a quite convincing demonstration of his control over

the system.

Audience research data is despatched in viewdata mode to

advertising agencies and broadcasting stations by AGB market

research. There are even alternate viewdata networks rivalling that

owned by Prestel, the most important of which is, at the time of

writing, the one owned by Istel and headquartered at Redditch in the

Midlands. This network transports several different trade and

professional services as well as the internal data of British

Leyland, of whom Istel is a subsidiary.

A viewdata front-end processor is a minicomputer package which

sits between a conventionally-structured database and its ports which

look into the phone-lines. Its purpose is to allow users with

viewdata sets to search the main database without the need to

purchase an additional conventional dumb terminal. Some view- data

front-end processors (FEPs) expect the user to have a full alphabetic

keyboard, and merely transform the data into viewdata pages 40

characters by 24 lines in the usual colours. More sophisticated FEPs

go further and allow users with only numeric keypads to retrieve

information as well. By using FEPs a database publisher or system

provider can reach a larger population of users. FEPs have been known

to have a lower standard of security protection than the conventional

systems to which they were attached.

Viewdata standards

The UK viewdata standard--the particular graphics set and method

of transmitting frames -- is adopted in many other European countries

and in former UK imperial possessions. Numbers and passwords to

access these services occasionally appear on bulletin boards and the

systems are particularly interesting to enter while they are still on

trial. As a result of a quirk of Austrian law, anyone can

legitimately enter their service without a password; though one is

needed if you are to extract valuable information. However, important

variants to the UK standards exist: the French (inevitably) have a

system that is remarkably similar in outline but incompatible.

** Page 96

In North America, the emerging standard which was originally put

together by the Canadians for their Telidon service but which has

now, with modifications, been promoted by Ma Bell, has high

resolution graphics because, instead of building up images from block

graphics, it uses picture description techniques (eg draw line, draw

arc, fill-in etc) of the sort relatively familiar to most users of

modern home micros. Implementations of NALPS (as the US standard is

called) are available for the IBM PC.

The Finnish public service uses software which can handle nearly

all viewdata formats, including a near-photographic mode.

Software similar to that used in the Finnish public service can be

found on some private systems. Countries vary considerably in their

use of viewdata technology: the German and Dutch systems consist

almost entirely of gateways to third-party computers; the French

originally cost-justified their system by linking it to a massive

project to make all telephone directories open to electronic enquiry,

thus saving the cost of printed versions. French viewdata terminals

thus have full alpha-keyboards instead of the numbers-only versions

common in other countries. For the French, the telephone directory is

central and all other information peripheral. Teletel/Antiope, as the

service is called, suffered its first serious hack late in 1984 when

a journalist on the political/satirical weekly Le Canard Finchaine

claimed to have penetrated the Atomic Energy Commission's computer

files accessible via Teletel and uncovered details of laser projects,

nuclear tests in the South Pacific and an experimental nuclear

reactor.

Viewdata: the future

Viewdata grew up at a time when the idea of mass computer

ownership was a fantasy, when the idea that private individuals could

store and process data locally was considered far-fetched and when

there were fears that the general public would have difficulties in

tackling anything more complicated than a numbers- only key-pad.

These failures of prediction have lead to the limitations and

clumsiness of present-day viewdata. Nevertheless, the energy and

success of the hardware salesmen plus the reluctance of companies and

organisations to change their existing set-ups will ensure that for

some time to come, new private viewdata systems will continue to be

introduced...and be worth trying to break into.

There is one dirty trick that hackers have performed on private

viewdata systems. Entering them is often easy, because high-level

editing passwords are, as mentioned earlier, sometimes desperately

insecure (see chapter 6) and it is easy to acquire editing status.

** Page 97

Once you have discovered you are an editor, you can go to edit

mode and edit the first page on the system, page 0: you can usually

place your own message on it, of course; but you can also default all

the routes to page 90. Now *90# in most viewdata systems is the

log-out command, so the effect is that, as soon as someone logs in

successfully and tries to go beyond the first page, the system logs

them out....

However, this is no longer a new trick, and one which should be

used with caution: is the database used by an important organisation?

Are you going to tell the system manager what you have done and

urge more care in password selection in future?