[ News ] [ Issues ] [ Authors ] [ Comments ] [ Search ] [ Stats ] [ Contact ]


..[ Phrack Magazine ]..
.:: PHRACK ISSUES ::.

Issues: [ 1 ] [ 2 ] [ 3 ] [ 4 ] [ 5 ] [ 6 ] [ 7 ] [ 8 ] [ 9 ] [ 10 ] [ 11 ] [ 12 ] [ 13 ] [ 14 ] [ 15 ] [ 16 ] [ 17 ] [ 18 ] [ 19 ] [ 20 ] [ 21 ] [ 22 ] [ 23 ] [ 24 ] [ 25 ] [ 26 ] [ 27 ] [ 28 ] [ 29 ] [ 30 ] [ 31 ] [ 32 ] [ 33 ] [ 34 ] [ 35 ] [ 36 ] [ 37 ] [ 38 ] [ 39 ] [ 40 ] [ 41 ] [ 42 ] [ 43 ] [ 44 ] [ 45 ] [ 46 ] [ 47 ] [ 48 ] [ 49 ] [ 50 ] [ 51 ] [ 52 ] [ 53 ] [ 54 ] [ 55 ] [ 56 ] [ 57 ] [ 58 ] [ 59 ] [ 60 ] [ 61 ] [ 62 ] [ 63 ] [ 64 ] [ 65 ] [ 66 ]
Current issue : #64 | Release date : 27/05/2007 | Editor : The Circle of Lost Hackers
IntroductionThe Circle of Lost Hackers
Phrack Prophile of the new editorsThe Circle of Lost Hackers
Phrack World NewsThe Circle of Lost Hackers
A brief history of the Underground sceneDuvel
Hijacking RDS TMC traffic information signallcars & danbia
Attacking the Core: Kernel Exploitation Notestwiz & sgrakkyu
The revolution will be on YouTubegladio
Automated vulnerability auditing in machine codeTyler Durden
The use of set_head to defeat the wildernessg463
Cryptanalysis of DPA-128sysk
Mac OS X Wars - A XNU Hopenemo
Hacking deeper in the systemscythale
The art of exploitation: Autopsy of cvsxplAc1dB1tch3z
Know your enemy: Facing the copsLance
Remote blind TCP/IP spoofingklm
Hacking your brain: The projection of consciousnesskeptune
International scenesVarious
Title : The revolution will be on YouTube
Author : gladio
              _                                                _
            _/B\_                                            _/W\_
            (* *)             Phrack #64 file 7              (* *)
            | - |                                            | - |
            |   |     The Revolution will be on YouTube      |   |
            |   |                                            |   |
            |   |                 By Gladio                  |   |
            |   |                                            |   |
            |   |              Gladio@phrack.org             |   |
            (____________________________________________________)


Forget everything you know about revolutions. It's all wrong.

Fighting a conventional war in an industrialized nation is suicide. Even
if you could field a military force capable of defeating the government
forces, the wreckage wouldn't be worth having. Think about mortar shells
landing in chemical plants. Massive toxic waste spills. Poisonous clouds
drifting with the winds. Fighting a war in your own backyard is just
plain stupid. Notice how the super-powers fight each other with proxy
wars in other countries.

Sure it might be fun to form a militia and go play army with your friends
in Idaho. Got some full-auto assault rifles?  Maybe even mortars, heavy
machine guns and some anti-aircraft guns?

Think they can take out an AC-130 lobbing artillery shells from 12 miles
away? A flight of A-10s spitting depleted uranium shells the size of your
fist at a rate that makes the cannon sound like a redlined dirt bike? A
shooting war with a modern government is a shortcut to obliteration.

Most coups are accomplished (or thwarted) by skillful manipulation of
information. There have been a number of countries where tyrants (and
legitimate leaders) have been overthrown by very small groups using mass
communications effectively.

The typical method involves blocking all (or most) information sources
controlled by the government, and supplying an alternative that delivers
your message. Usually, you just announce the change in government, tell
everyone they are safe and impose a curfew for a short time to consolidate
your control. Announce that the country, the police and the military are
under your control, and keep repeating it. Saturate the airwaves with your
message, while preventing any contradictory messages from propagation.

Virtually all broadcast media use the telephone network to deliver content
from their studios to their transmitters.  Networks use satellites and
pstn to distribute content to local stations, which then use pstn to
deliver it to the transmitter site.

Hijacking these phone connections accomplishes both goals, of denying the
'official' media access, and putting your own message out.

In cases where you can't hijack the transmitters, dropping the pstn
will be effective. Police and military also use pstn to connect dispatch
centers with transmitter towers. Recently, many have installed wireless
(microwave) fallback systems.

Physically shutting down the pstn just prior to your broadcasts may be
very effective. This is most easily accomplished by physical damage to
the telco facilities, but there are also non-physical technical means to
do this on a broad scale.  Spelling them out here would only result in the
holes being closed, but if you have people with the skill set to do this,
it is preferable to physical means because you will have the advantage
of utilizing these communications resources as your plan progresses.


Leveraging the Internet

Most of the FUD produced about insurgence and the internet is focused on
"taking down" the internet. That's probably not the most effective use
of technical assets. An insurgency would benefit more from utilizing the
net. One use is mass communications. Get your message out to the masses
and recruit new members.

Another use is for communications within your group. This is where things
get sticky. Most governments have the ability to monitor and intercept
their citizen's internet traffic. The governments most deserving of
being overthrown are probably also the most effective at electronic
surveillance.

The gov will also infiltrate your group, so forums aren't going to
be the best means of communicating strategies and tactics. Forums can
be useful for broad discussions, such as mission statements, goals and
recruiting. Be wary of traffic analysis and sniffing. TOR can be useful,
particularly if your server is accessible only on TOR network.

Encryption is your best friend, but can also be your worst enemy. Keep
in mind that encryption only buys you time. A good, solid cipher will
not likely be read in real time by your opponent, but will eventually
be cracked. The important factor here is that it not be cracked until
it's too late to be useful.

A one time pad (OTP) is the best way to go. Generate random data and
write it to 2, and only 2, DVDs. Physically transport the DVDs to each
communications endpoint. Never let them out of your direct control. Do
not mail them. Do not send keys over ssh or ssl. Physically hand the DVD
to your counterpart on the other end. Never re-use a portion of the key.

Below is a good way to utilize your OTP:

Generate a good OTP (K), come up with a suspicious alternate message
(M), and knowing your secret text (P), you calculate (where "+" = mod
26 addition):

K' = M + K 
K'' = P + K 
C = K' + P

Lock up K'' in a safety deposit box, and hide k' in some other off
site, secure location. Keep C around with big "beware of Crypto systems"
signs. When the rubber hose is broken out, take at least 2 good lickings,
and then give up the key to the safety deposit box. They get K'',
and calculate

K'' + C = M

thus giving them the bogus message, and protecting your real text.


Operational Security

The classic "cellular" configuration is the most secure against
infiltration and compromise. A typical cell should have no more than 5-10
members. One leader, 2 members who each know how to contact one member
of an 'upstream' cell, and 2 members who each know how to contact one
member of a downstream cell. Nobody, including the leader, should know
how to contact more than one person outside of their own cell.

Never use your real name, and never use your organizational alias in
any other context.

Electronic communications between members should be kept to a
minimum. When it is necessary, it should only be conducted via the OTP
cipher. Preferably, these communications should consist of not much more
than arranging a physical meeting.  Meet at a pre-arranged place, and
then go to another, un-announced place where surveillance is difficult,
to discuss operational matters.

Do not carry a phone. Even a phone which is switched off can be
tracked, and most can be used to eavesdrop on discussions even when
powered down. Removing the battery is only marginally safer, because
tracking/listening gear can be built into the battery pack. If you find
yourself stuck with a phone during a meeting, remove the battery and
place both the phone and battery in a metal box and remove it from the
immediate area of conversation.

It never hurts to generate some bogus traffic. Gibberish, random data,
innocuous stories etc., all serve to generate noise in which to better
hide your real communications.

Steganography can be useful when combined with solid crypto. Encrypt and
stego small messages into something like a full length movie avi, and
distribute it to many people via a torrent. Only your intended recipient
will have the key to decrypt the stegged message. Be sure to stego some
purely random noise into other movies, and torrent them as well.

Hopefully you'll find this document useful as a starting point for
further discussion and refinement. It's not meant to be definitive, and
is surely not comprehensive. Feel free to copy, add, edit or change as
you see fit. Please do add more relative to your area(s) of expertise.
Comments :
« Back - 1 - Next »
TheNovaKing, on April 6th 2008 at 1:06 am :
One acronym, and only one acronym.


PGP.


'nuff said.
hu needs to be airported and all of best things is revolution as all is joghurt i think. do a headphone plug to your usb and need an rebootzzz. hitler was revolution by itself so wee don´t get enough too every one, i think. too much exploration and too much fuck is the wasted in it. i thought, and you thought, we thought..
nobodywithuid0, on January 25th 2008 at 3:42 pm :
The moon is a harsh mistress anyone?
Ahhh.....the talk of revolution. Unfortunately, revolution only removes the problem in the short term. Look at the U.S. We revolted against a monarch to get a monarchy which claims its a republic. Dictators will always take control eventually.
Some of this is very useful. For example, someone mentioned communism. Right now in Communist china, Falun Gong practitioners are doing all these things when they communicate, for fear of being spied on, kidnapped and tortured. Falun Gong is a spiritual discipline persecuted in China. This is a great primer. I don't understand how a phone can be used to spy though--can anyone explain this point?

There's also a post 1999 history of Falun Gong practitioners hijacking state tv broadcasts to put on documentaries exposing the brutal persecution of Falun Gong, and showing that it's practiced without persecution around the world etc.. I find many of the things in this article so relevant to this ongoing struggle.

A great and very useful article!
one time pads are inpractical. for each mensage you have to have 2 dvds. read this book about criptography and it's history, and you'l see why:

http://www.amazon.com/Codebreakers-Comprehensive-History-Communication-Internet/dp/0684831309
Hmm, recently, me and some friends were considering taking overthrowing the french goverment. This article provides some very useful info that we will be sure to utilize. Thanks for writing this!
whoops and there's another one trying to lift up his eyes in this sheer dead unfriendly earth. Revolution is good and should live as long as human senses live

Bravo dude!!!
Hello Comrades.

Ahhh, revolution, one of my favorite topics.
Revolutions are a fun thing to think about, but a bitch to go through with, kinda like Communism. ha.

The only "Good" Fighting Revolution was the American revolution. Mostly because the Technology used in the fighting wasn't devistating enough as, persay, a Nuclear or Biological Device being set off in the country of the invader, or invadee. The most damage caused my a bombard cannon back in the 1800's was maybe blowing the crap out of a hill that you weren't aiming at.

That was a justified revolution, unlike the example you give here.
I would much rather listen to a hacker that fights for human rights for the simple fact that we all deserve to live and breath for free. Instead of some bigot that preaches freedom while his/her own citizens are being arrested outside of a U.N. meeting on freedom of speech.
You can think of it as a heroic task.
May be you can keep records of your name on books
Do you need some attention? Does no one care about you?
As some one who caused interrupts to civilized world.
You will be happy for short time when everything goes on as you planed.
But why?

Governments impose regulations on purpose, but most of the time we don't agree to them. But do you like to live under hackers? Rules processed by them? Ultimately this government will become worse than one before.

I wouldn
Hex Machina, on August 21th 2007 at 6:10 am :
Maze, it's a fact the government spies on us.
We in Israel, for example, have all our ISPs installing military sniffers right there on their cables.
I know this not from speculation, but by speaking with a guy working for the Mossad, so...Yeah.
attention all you legions of tin-foil-hat-wearing government-conspiracy-theorist paranoids:

I have an island for sale, special deal just for you. No aliens-agents involved, we promise.
Hex Machina, on August 14th 2007 at 9:09 pm :
Sure, overthrowing civilization and all current laws sounds right, but think about it - Is it really worth it.
We all hate the system, that's also true, but without the system, we'd have nothing to hate.
Or we would hate something else, and something else, and something else, and so on.
I'm not saying we should quit the fight, but, like Userdan said, infinite loops are never a good thing.
just regarding the 'would not be worth having stuff'

surely the whole point of tjhis is to overturn all civilisation, property rights, government and any law except for survival of the fittest?

in this case, thats exactly what we want
Yes, well, but eventually, you would become the "government" which you overtook, and someone else will try and overtake you.
I think we all have enough programming experience to know that infinite loops are never good thing.
Vicis of Vereor, on June 30th 2007 at 3:36 am :
Interesting concept. I have thought about this much myself. I say let it begin. The real power would be tapping into the resources of Google, though. It would be quite interesting to the intelligence the CIA wields compared to the info Google has gather over its relatively few years. The coup could very well begin in Mountain View, California as apposed to Washington, D.C.
Nabukadnezar, on June 5th 2007 at 11:49 pm :
I got bored after the first few rows. The other articles of the e-zine are great though.
MudderFudder, on May 30th 2007 at 2:49 pm :
http://www.reuters.com/article/technologyNews/idUSN3040403520070530

Web site error rocks global oil markets

NEW YORK (Reuters) - World oil prices jumped briefly on Wednesday after a television station in Tulsa, Oklahoma -- the No. 62 U.S. media market -- posted an erroneous story about a refinery fire on its Web site.

At 10:14 EDT (1414 GMT), CBS affiliate KOTV reported that a lightning strike had caused a fire at an Oklahoma refinery -- sparking a flurry of excitement among energy traders and boosting U.S. crude prices 40 cents.

The refining company announced the story was "completely wrong" and the station withdrew the story.

"All it takes is a screw-up on a Web site to move the market. It just goes to show how tense this market is," said a Houston-based oil trader.

A string of refinery problems in the United States has propelled retail gasoline prices to record highs in recent weeks.
This wasn't that great.

Pretty much this sums up what you've said;

Coos manipulate mass media. You could manipulate mass media. Take your run of the mill paranoid security measures. Carry your one time pad'd doovdees around to wherever you go. Organize yourself like they did on every tv show ever.

Sorry man. Quite nice writing style though.
Add a new comment : (require validation)
Username : (required)
Email : (will not be published) (required)
Antispam : (required)
Text in English only : (required)
[ News ] [ Issues ] [ Authors ] [ Comments ] [ Search ] [ Stats ] [ Contact ]
© Copyleft 1985-2007, Phrack Magazine.