Penetration Testing mailing list archives

Re: [PEN-TEST] Penetration Testing and Van Eck Scanning


From: "Deus, Attonbitus" <Thor () HammerofGod Com>
Date: Wed, 8 Nov 2000 08:45:57 -0800

Though van Eck focused in on reassembling CRT raster emissions, it is
important to remember that other peripheral emissions are included in
TEMPEST scanning mechanisms such as isolating keyboard RF generation as well
as the CPU cycles itself.  I guess you would have to get hold of NACSIM
5100a to really see what the skinny on that is (if it really exists).  I
would assume that non-military personnel that are successfully gathering
information via these less common methods are not too eager to tell the rest
of us about it.
AD


----- Original Message -----
From: "Johann van Duyn" <johann.vanduyn () APPLETON COM>
To: <PEN-TEST () SECURITYFOCUS COM>
Sent: Wednesday, November 08, 2000 8:11 AM
Subject: Re: [PEN-TEST] Penetration Testing and Van Eck Scanning


PGP Security had a "Tempest" surveillance prevention option in its secure
viewer (used when viewing encrypted text files), which is basically a
low-contrast window in which your text is viewed. That would probably
obfuscate the text if viewed from a van... I suppose high-contrast text is
easier to pick up that way. Hmmm... I can just imagine telling our Board
of
Directors that they need to view all their documents in grey on grey...

-----Original Message-----
From: David Alexander [mailto:dalexander () TRISKELE CO UK]
Sent: 08 November 2000 17:59
To: PEN-TEST () SECURITYFOCUS COM
Subject: Re: [PEN-TEST] Penetration Testing and Van Eck Scanning


I have never done it, but I have seen the results, it shows legible text.
Ross Anderson at Cambridge University has produced a set of word
processing
software that can defeat V-E scanning using software only. What you see on
the screen is not what you see in the van - it's unintelligible. I don't
know how it works and I have no idea if anyone is picking up on it
commercially.
Regards
David Alexander
Project Manager & Information Security Consultant
Qualified BS7799 Lead Auditor
Triskele Ltd.
Office  01491 833280
Mobile 0780 308 3130


-----Original Message-----
<snippety-snip!>


***The Appleton Group Ltd***

This message, including any attachments, is intended only for the
individual
or institution to which it is addressed and may contain information that
is
privileged, confidential or prohibited from disclosure or unauthorized
use.
If the recipient of this transmission is not the intended recipient, you
are
hereby notified that any use, reproduction dissemination, copying,
disclosure, modification, distribution and/or publication of this email
message or any of its attachments other than by its intended recipient is
strictly prohibited by the sender. If you have received this message in
error, please notify The Appleton Group Ltd immediately at
postmaster () appleton com and destroy the message and all copies thereof in
your possession.

****************************


Current thread: