<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Hit News &#187; German security</title>
	<atom:link href="http://www.hitnews.net/tag/german-security/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.hitnews.net</link>
	<description>The Top News List and Links</description>
	<lastBuildDate>Tue, 29 Sep 2009 01:00:38 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0.4</generator>
		<item>
		<title>E-Passport Hacker Designs RFID Security Tool</title>
		<link>http://www.hitnews.net/e-passport-hacker-designs-rfid-security-tool/</link>
		<comments>http://www.hitnews.net/e-passport-hacker-designs-rfid-security-tool/#comments</comments>
		<pubDate>Wed, 21 Jan 2009 16:02:17 +0000</pubDate>
		<dc:creator>matt</dc:creator>
				<category><![CDATA[Technology]]></category>
		<category><![CDATA[rfid]]></category>
		<category><![CDATA[Boris Wolf]]></category>
		<category><![CDATA[German security]]></category>
		<category><![CDATA[hacker tool]]></category>
		<category><![CDATA[Lukas Grunwald]]></category>
		<category><![CDATA[Mifare Card]]></category>
		<category><![CDATA[Mifare Classic]]></category>
		<category><![CDATA[NeoCatena]]></category>
		<category><![CDATA[radio-frequency]]></category>
		<category><![CDATA[radio-frequency ID tags]]></category>
		<category><![CDATA[RFDump]]></category>
		<category><![CDATA[RFID cards]]></category>
		<category><![CDATA[RFID chip]]></category>
		<category><![CDATA[rfid cracked]]></category>
		<category><![CDATA[rfid hacker]]></category>
		<category><![CDATA[RFID hackers]]></category>
		<category><![CDATA[RFID Journal Live]]></category>
		<category><![CDATA[RFID reader]]></category>
		<category><![CDATA[RFID tags]]></category>
		<category><![CDATA[RFID technology]]></category>
		<category><![CDATA[SQL attacks]]></category>
		<category><![CDATA[SQL-injection]]></category>
		<category><![CDATA[SQL-injection attacks]]></category>

		<guid isPermaLink="false">http://www.hitnews.net/?p=76</guid>
		<description><![CDATA[The team that produced the RFDump research/hacker tool for cloning and altering data stored on radio-frequency ID tags has now come out with a product to thwart RFID hackers. German security researcher Lukas Grunwald, who made headlines two years ago for uncovering security vulnerabilities in new electronic passports being adopted by the U.S. and other [...]]]></description>
			<content:encoded><![CDATA[<p>The team that produced the RFDump research/hacker tool for cloning and altering data stored on radio-frequency ID tags has now come out with a product to thwart RFID hackers.</p>
<p>German security researcher Lukas Grunwald, who made headlines two years ago for uncovering security vulnerabilities in new electronic passports being adopted by the U.S. and other countries, created RFDump with colleague Boris Wolf in 2004.</p>
<p>Now the two have created <a title="RF-Wall" href="http://www.neo-catena.com/product.shtml">RF-Wall</a> (shown on the lower shelf in the picture at right) to help thwart RFID fraud and attacks against e-passports, electronic access cards and payment cards &#8212; such as the Mifare Classic card that is used in the London Underground and which security researchers recently cracked.</p>
<p>The device, which Grunwald and Wolf are producing for their new California-based company NeoCatena, is a hybrid firewall and intrusion-detection system that sits between an RFID reader and its back-end system. It&#8217;s designed to detect counterfeit and cloned RFID chips and prevent an attacker from injecting malware into a back-end system with a rogue RFID chip. They&#8217;ll be debuting the device this week at the RFID Journal Live conference in Las Vegas but gave me a demonstration of it this weekend.</p>
<div id="attachment_77" class="wp-caption alignleft" style="width: 360px"><a rel="attachment wp-att-77" href="http://www.hitnews.net/e-passport-hacker-designs-rfid-security-tool/rfid_tag_with_sql_injection/"><img class="size-full wp-image-77" title="rfid_tag_with_sql_injection" src="http://www.hitnews.net/wp-content/uploads/2009/01/rfid_tag_with_sql_injection.jpg" alt="Hacker Designs RFID Security Tool" width="350" height="297" /></a><p class="wp-caption-text">Hacker Designs RFID Security Tool</p></div>
<p>Rfwall_5 The box can be loaded with virus signatures to detect known types of attacks and uses heuristics to detect other malicious activity, such as generic SQL-injection attacks (such as the one that appears in the screenshot above right). The device can be restricted to read only RFID cards that have specific serial numbers and reject all others. It also can be used to digitally sign chips so that any chips that are altered after being issued are rejected by the RFID reader. The system uses the HMAC algorithm for the digital signature. Grunwald and Wolf hold a patent on the use of HMAC with RFID technology.</p>
<p>Last year Grunwald revealed that he&#8217;d been able to sabotage the e-passport readers of two unnamed manufacturers by embedding a buffer overrun exploit in the JPEG2000 file of a cloned passport chip. The JPEG file contains a digital photo of the passport holder.</p>
<p>Recently other researchers cracked the encryption used in Mifare Classic chips that are used in door access systems around the world as well as in the London Underground&#8217;s Oyster card.</p>
<p>It&#8217;s long been known that RFID readers and chips are insecure, but trying to fix systems that have already been widely deployed has its challenges, particularly since there are a number of different types of chips and readers on the market, which work at different frequencies.</p>
<p>&#8220;A lot of people are thinking about on-tag security &#8212; putting cryptography on the tag,&#8221; Wolf says. &#8220;But those tags are limited in their computational power or even if you can get that worked out the more encryption technology you have on the tag, the more expensive it is. We&#8217;re saying you don&#8217;t have to worry about what&#8217;s happening with your tag if you can verify whether there&#8217;s data integrity or not.&#8221;</p>
<p>Grunwald says they&#8217;ve shown the tool to a large pharmaceutical company based in Switzerland that is interested in using it to authenticate drugs and equipment &#8212; such as dialysis machines &#8212; from counterfeit products. He says an Asian country is also interested in using RF-Wall with its electronic passport system.</p>
<p>During a demonstration for me, Grunwald and Wolf used RFDump to alter the value on a digitally signed transportation card from $10 to $99. On a first pass without RF-Wall in place, the <a title="Meyer RFID | RFID Otopark, Araç Takip, Kamyon TIR hastane ve Otopark Takip Sistemleri" href="http://www.meyerrfid.com/">RFID</a> reader accepted the card. After they connected the device, however, the system rejected the tag. The system also rejected a tag that was embedded with SQL injection code.</p>
<p>The screenshot at right shows the backend of an <a title="RFID" href="http://www.meyer.com.tr/">RFID</a> inventory system after malware on a rogue chip has crashed it.</p>
<p><strong>Source and More :</strong> <a title="Blog wired" href="http://blog.wired.com/27bstroke6/2008/04/e-passport-hack.html">http://blog.wired.com</a></p>
<p><strong>Via  :</strong> computerworld.com <a href="http://www.computerworld.com/action/article.do?command=viewArticleBasic&amp;articleId=9069558">cracked the encryption used in Mifare Classic chips</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.hitnews.net/e-passport-hacker-designs-rfid-security-tool/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

