LAN cables can be sniffed to reveal network traffic with a $30 setup, says researcher
- Reference: 1634200209
- News link: https://www.theregister.co.uk/2021/10/14/lantenna_ethernet_cable_rf_emissions/
- Source link:
Mordechai Guri of Israel's Ben Gurion University of the Negev described the disarmingly simple technique to The Register , which consists of putting an ordinary radio antenna up to four metres from a category 6A Ethernet cable and using an off-the-shelf software defined radio (SDR) to listen around 250MHz.
"From an engineering perspective, these cables can be used as antennas and used for RF transmission to attack the air-gap," said Guri.
[1]
His experimental technique consisted of slowing UDP packet transmissions over the target cable to a very low speed and then transmitting single letters of the alphabet. The cable's radiations could then be picked up by the SDR (in Guri's case, both an R820T2-based tuner and a HackRF unit) and, via a simple algorithm, be turned back into human-readable characters.
[2]
[3]
Nicknamed LANtenna, Guri's technique is an academic proof of concept and not a fully fledged attack that could be deployed today. Nonetheless, the research shows that poorly shielded cables have the potential to leak information which sysadmins may have believed were secure or otherwise air-gapped from the outside world.
He added that his setup's $1 antenna was a big limiting factor and that specialised antennas could well reach "tens of metres" of range.
[4]
"We could transmit both text and binary, and also achieve faster bit-rates," acknowledged Guri when El Reg asked about the obvious limitations described in his paper
[5]PDF
. "However, due to environmental noises (e.g. from other cables) higher bit-rate are rather theoretical and not practical in all scenarios."One obvious further research technique would be to look at sniffing information over network cables at their full operational speeds, Guri having acknowledged that slowing live network traffic down to levels used in his experiment would be impractical. His full paper, however, noted: "Transmitting UDP packets doesn't require higher privileges or interfering with the OS routing table. In addition, it is possible to evade detection at the network level by sending the raw UDP traffic within other legitimate UDP traffic."
The academic's previous research included [6]a technique for turning DRAM into a form of wireless transmitter , as part of his work looking at ways of pwning air-gapped networks.
[7]How to leak data via Wi-Fi when there's no Wi-Fi chip: Boffin turns memory bus into covert data transmitter
[8]Spoof an Ethernet adapter on USB, and you can sniff credentials from locked laptops
[9]GCHQ and Cable and Wireless teamed as Masters of the Internetâ„¢
[10]NSA coughs up secret TEMPEST specs
Professor Alan Woodward of the University of Surrey observed: "What this shows is that even an unplugged Ethernet cable can radiate energy which is detectable."
He added: "The paper is a nice piece of work and reminds us that whilst you might think something is air-gapped, it might be chattering away over the airwaves. People used to laugh at the great clunky terminals used in secure environments but they arose for a reason: TEMPEST."
[11]
TEMPEST, as we [12]reported 20 years ago , was originally a US government scheme for reducing the amount of RF emissions generated by computer equipment. Today it's been adopted as a NATO standard, with the UK's National Cyber Security Centre having a [13]public webpage about it.
"Often," observed Woodward, "modern security systems look for data leaving the network to know that they have an intruder. But if it's leaving on some unmonitored channel (over the air) then it has a low probability of intercept by the security measures."
We look forward to the infosec industry's next exciting product launch: a full spectrum RF analysis suite plumbed into your SIEM for a low, low subscription rate. ®
Get our [14]Tech Resources
[1] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_onprem/networks&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YWf-7IvjiDIhydvhPyuWHgAAAJE&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_onprem/networks&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YWf-7IvjiDIhydvhPyuWHgAAAJE&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_onprem/networks&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YWf-7IvjiDIhydvhPyuWHgAAAJE&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_onprem/networks&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YWf-7IvjiDIhydvhPyuWHgAAAJE&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[5] https://arxiv.org/pdf/2110.00104.pdf
[6] https://www.theregister.com/2020/12/16/wifi_memory_hacking/
[7] https://www.theregister.com/2020/12/16/wifi_memory_hacking/
[8] https://www.theregister.com/2016/09/07/spoof_an_ethernet_adapter_on_usb_and_you_can_sniff_credentials_from_locked_laptops/
[9] https://www.theregister.com/2014/11/21/mastering_the_internet_snowden_disclosure/
[10] https://www.theregister.com/2001/01/10/nsa_coughs_up_secret_tempest/
[11] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_onprem/networks&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YWf-7IvjiDIhydvhPyuWHgAAAJE&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[12] https://www.theregister.com/2001/01/10/nsa_coughs_up_secret_tempest/
[13] https://www.ncsc.gov.uk/information/tempest-and-ems-policy
[14] https://whitepapers.theregister.com/
Re: I thought LAN cables were shielded
If the cable happens to be running through the middle of a completely shielded RF anechoic chamber that also happens to house your SDR (i.e. in RF terms you are in the middle of nowhere - just you and the ethernet cable) then this might be plausible. I bet the software on the SDR didn't cost $30 to develop and I bet it can't cope with more noise than a statically-charged mosquito.
Re: I thought LAN cables were shielded
I was also under the impression that shielding was grounded, in yhis case that would help to eliminate induced current in the shielding which I guess may be readable with the right gear.
I was also under the impression that an air gap was no connection to anything that could communicate with external comms, or is this exploit referring to lan on internal networks?
Re: I thought LAN cables were shielded
Your server room will have lots of cables, and lots of data traffic going over them. Trying to separate out an individual signal from all the electrical noise is going to be very difficult.
Re: I thought LAN cables were shielded
Yes, that would be STP (Shielded Twisted Pair) cabling. However, driven by cost, many installations use UTP (Unshielded Twisted Pair) cabling.
Most of STP is used in static installations and patches in "expensive" data centers. Proper use of STP is difficult because you must be sure that the shield is actually acting as a shield, not as a re-transmittor of the cable's internals. This is expensive.
Most cabling, especially home-installs and PC stuff are UTP. You know, like that exceptionally cheapo cable you got with that router. And then, most consumer grade installations have no grounding to connect the shield to. Home-installations are a light-fire of EMI from many gadgets and computers. Nobody cares about adding a bit of cable noise to the spectrum when they can save a few cents on each sale.
Re: I thought LAN cables were shielded
Speaking as a time-served electromagnetic compatibility (EMC) troubleshooter, shielded cables merely reduce the stray field, they do not eliminate them. Moreover, the whole system acts as an integrated antenna network; it obeys basic 19th century physics, not systems designer's diagrams. The signal will in practice be leaking out from half a dozen different places for different reasons.
Good luck trying to sort out a single coherent stream of data from the bundles of cables shown in the rack in the header photo. If they had to artificially slow down UDP packets and transmit a single letter at a time on a single cable, I think it's going to be a while before we need worry about this in the real world.
I think this is imagine used on an airgapped computer sitting somewhere by itself in an otherwise secure facility. And then it's a means for malware that's already on it to use the patch cable someone were considerate enough to leave hanging on it to transmit the stolen data.
Use fibre-optic. Problem solved? (Apart from RFI coming off the computers themselves of course).
The reports of users being able to detect the contents of a CRT with some accuracy at very long ranges are not exaggerated.
How did I know from the headline alone ...
... where this "researcher" was located?
New? Bwahaha!
Aww, c'm on, reality check here. This kind of leakage was common knowledge in the 1980s, during my EMC Test Engineer incarnation. I usually fiddled with a twist of wire from my toolbox until it picked up a good enough signal. GCHQ offered TEMPEST courses even back then, but it was all a bit secret and I was not cleared to go on one.
I can say that TEMPEST is more about the installation than the individual boxen; lining a whole room with turkey foil is not unknown. If you haven't TEMPESTED the whole thing properly, LAN cables included, then you don't have an air gap, you have a WiFi transmitter.
I should imagine the field has moved on, on both sides, over the last 30-40 years.
Re: New? Bwahaha!
Agreed. The line about "having the potential to leak information which sysadmins may have believed were secure" gave me a laugh. What (proper) sysadmins in charge of sensitive data don't know about this kind of RF leakage?
So this whole report is "if you have RF leakage then someone can pick it up". Yes, we know that.
Re: New? Bwahaha!
Yes but this one is from a "security theatre researcher" therefore it must be IMPORTANT.
I guess it depends on the application as well. Given the use of https/ssh to secure most links even internally a lot of radiated data might well be impractical to decode.
I'm a PM implementing applications in the public sector and the use of HTTPS as the default connection to apps is rapidly becoming ubiquitous and is mandatory for any apps handling personally sensitive data.
arxiv.org is currently offline (workaround)
The website with the paper is down, oh well waybackmachine to the rescue: https://web.archive.org/web/20211012151924/https://arxiv.org/pdf/2110.00104.pdf
Network problem
I am getting a "Secure Connection Failed" message when I try to open the URL to the paper.
Or is my browser just giving me a summary of the paper's findings?
I thought LAN cables were shielded
Okay, I agree that nothing is perfect, but it seems a bit of a stretch to say that you could detect LAN traffic from tens of meters away by "listening" to a shielded cable.
You might be able to do it from the other side of a wall, but if you want to target a specific cable, good luck.
I accept this could work if you can set it up in the server room, but then we're back to the Primary Rule : if you have access, security is gone.