[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: ***HUGE*** security hole??!! (Re: Lost root passwd)



In <[🔎] 19981011011501.A225@ruhr-uni-bochum.de>, on 10/11/98 
   at 01:15 AM, Marcus Brinkmann <Marcus.Brinkmann@ruhr-uni-bochum.de>
said:

[...]


>However, I said that the power chord should be removed. the reason is
>that I think you can get the monitor screen, user input etc from
>radiation led through the power chord. This may be hard but possible,
>someone else might know more.

No power cord is needed for this.  I can stand outside the building with
an antenna array and "tune in" to your screen.  The (S)VGA card is
basically a tv-transmitter with a non-standard signal.  Of course it isn't
really designed for transmission, but the card, cable and particularly the
monitor "leak" too much.  A big antenna and some sophisticated equipment
may be necessary, but it is possible. An antenna array can be used for
focusing on one particular monitor, so wa don't get confused by the 40
others in the building.

How to avoid this?  Shielded equipment, or simply a machine
without a video card.  Displaying only non-sensitive data
is safe too of course.

Helge Hafting
-- 
-----------------------------------------------------------
helge.hafting@daldata.no
-----------------------------------------------------------


Reply to: