Payment cards. Library systems e-Passports. Smart cards. Standard range: ~3 -
10 cm. Lots of new Android phones have NFC. RFID Tag. Transceiver. Antenna.
Kiosks 101 What is an Internet Kiosk. Kiosk Software Security Model. Hacking Internet Kiosks Vulnerabilities in the Kiosk Security Model.
We'll need some of these items to add and remove components to the .... DigiKey. â Manufactures website. â Call the
visual) about the body's position and movement is contradictory to the movement
that is being sensed by your vestibular system, resulting in your body being ...
Aug 3, 2013 - Hacking Wireless Networks of the Future: Security in Cognitive Radio Networks. Hunter Scott / August 3 ...
Jun 18, 2011 ... My NFC/NDEF Security Tools (some new stuff). □. Nokia NFC phones. □.
Android/Google Nexus S (new stuff). □. Analysis of Field Test NFC ...
whoami. * Anthony Rose. * Ben Ramsey. Page 3. >>> Overview. 1. Goals. 2. What is Bluetooth Low Energy? 3. Why S
comms from device â FireEye and friends. ⢠But there's little defense specific to malicious devices, something the U
Live Free or RFID Hard. 03 Aug 2013 â DEF CON 21 (2013) .... to prevent drive-by card sniffing attacks. â¢. Physicall
Digital Signature. ⢠In 2008 IATA extended BCBP standard with support for digital signatures based on PKI. ⢠The fie
... possessed! ▫ DNS redirection allowed for malicious code insertion on
legitimate webpages. 2. 2009 DefCon 17 - Con Kung-Fu : Defending Yourself @
DefCon ...
Aug 21, 2009 - âMalicious activity from your accountâ ..... Free! â Capacity for DoS outweighs home user. â How
Types of Intelligence Gathering. ♢ Competitive Intelligence. ♢ Corporate
Espionage. ♢ Information Warfare. ♢ Personal Investigation. (*This talk is NOT
about ...
Access. Granted. ⢠Now we have access. ⢠FTP Script. Account. ⢠Ettercap. Now what? ... Login with a SPECIAL accou
Hands up if you run Android. Keep 'em ... topic or a cover. Th correspon. Agenda t beginning presentat. BORING KIT. The
Enhancements (SE) for Android. Pau Oliva Fora. DefConZl August 2013 ... the upcoming "Andllgmd, . 30 61' S. Android Hack
Aug 21, 2009 - your OS, you trust Amazon not to screw you ..... Free! â Capacity for DoS outweighs home user. â How
Get access to a new set of tools that automates all the attacks for you. How. Explore a âFunctionality. Issueâ disco
WEAKNESSES. Needs to be enhanced: Secure Boot + runtime integrity check. Page 16. WEAKNESSES. Multiple workarounds in co
Feb 6, 2006 ... PRIVATE INVESTIGATORS NOW! OR ... Michigan passed the “Professional
Investigator ..... You are correct, there is no official study guide.
memory will corrupt the DNS name. â« Registering those mangled domains. â« Rapture ... Google domain for serving stati
ââ¦the recovery and investigation of material found in digital devicesâ. ⢠Related tools ... (Saved form data). â
â¦manually starts his scan and waits⦠.... We decided to give something back because we use a lot of open source tool
EMV (Europay, Mastercard, and VISA) standard for communication between
chipped credit cards and POS terminals. Four “books” long. Based on ISO 14443
...
DEFCON 20
NFC Hacking: The Easy Way
Eddie Lee eddie{at}blackwinghq.com
About Me
! Security Researcher for Blackwing Intelligence (formerly Praetorian Global) ! We’re always looking for cool security projects ! Member of Digital Revelation ! 2-time CTF Champs – Defcon 9 & 10
! Not an NFC or RFID expert!
! Radio Frequency Identification - RFID
Introduction // RFID Primer
! Broad range of frequencies: low kHz to super high GHz
! Near Field Communication - NFC ! 13.56 MHz ! Payment cards ! Library systems ! e-Passports ! Smart cards ! Standard range: ~3 - 10 cm
! RFID Tag ! Transceiver ! Antenna ! Chip (processor) or memory
! RFID (tag) in credit cards
Introduction // RFID Primer
! ! ! !
Visa – PayWave MasterCard – PayPass American Express – ExpressPay Discover – Zip
! Proximity Coupling Devices (PCD) / Point of Sale (POS) terminal / Reader ! EMV (Europay, Mastercard, and VISA) standard for communication between chipped credit cards and POS terminals ! Four “books” long ! Based on ISO 14443 and ISO 7816 ! Communicate with Application Protocol Data Units (APDUs)
! Why create NFCProxy?
Introduction // Motivation
! I’m lazy ! Don’t like to read specs ! Didn’t want to learn protocol (from reading specs) ! Future releases should work with other standards (diff protocols) ! Make it easier to analyze protocols ! Make it easier for other people to get involved ! Contribute to reasons why this standard should be fixed
! Adam Laurie (Major Malfunction)
Previous work
! !
!
RFIDIOt http://rfidiot.org
Pablos Holman ! Skimming RFID credit cards with ebay reader ! http://www.youtube.com/watch?v=vmajlKJlT3U
! 3ric Johanson ! !
Pwnpass http://www.rfidunplugged.com/pwnpass/
! Kristen Paget ! Cloning RFID credit cards to mag strip ! http://www.shmoocon.org/2012/presentations/Paget_shmoocon2012-creditcards.pdf
OmniKey (~$50-90 ebay), ACG, etc. Proxmark ($230-$400)
! Mag stripe encoder ($200-$300)
! What is NFCProxy?
Tool Overview
! An open source Android app ! A tool that makes it easier to start messing with NFC/RFID ! Protocol analyzer
! Hardware required ! Two NFC capable Android phones for full feature set ! Nexus S (~$60 - $90 ebay) ! LG Optimus Elite (~$130 new. Contract free) ! No custom ROMs yet ! Galaxy Nexus, Galaxy S3, etc. (http://www.nfcworld.com/nfc-phones-list/)
! Software required ! One phone ! Android 2.3+ (Gingerbread) ! Tested 2.3.7 and ICS ! At least one phone needs: ! Cyanogen 9 nightly build from: Jan 20 - Feb 24 2012 ! Or Custom build of Cyanogen