<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Chirashi Security &#187; Remote Listening</title>
	<atom:link href="http://chirashi.zenconsult.net/tag/remote-listening/feed/" rel="self" type="application/rss+xml" />
	<link>http://chirashi.zenconsult.net</link>
	<description>A blog with scattered thoughts on security</description>
	<lastBuildDate>Sun, 16 Oct 2011 17:26:37 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.2.1</generator>
		<item>
		<title>Remote Listening for the BlackBerry</title>
		<link>http://chirashi.zenconsult.net/2009/10/remote-listening-for-the-blackberry/</link>
		<comments>http://chirashi.zenconsult.net/2009/10/remote-listening-for-the-blackberry/#comments</comments>
		<pubDate>Thu, 22 Oct 2009 17:40:42 +0000</pubDate>
		<dc:creator></dc:creator>
				<category><![CDATA[BlackBerry]]></category>
		<category><![CDATA[Featured]]></category>
		<category><![CDATA[Bug]]></category>
		<category><![CDATA[Bugs and Kisses]]></category>
		<category><![CDATA[linkedin]]></category>
		<category><![CDATA[Listening Device]]></category>
		<category><![CDATA[Remote Listening]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[Spyware]]></category>

		<guid isPermaLink="false">http://chirashi.zensay.com/?p=260</guid>
		<description><![CDATA[I first blogged about PhoneSnoop, a component of Bugs, a few days ago.  PhoneSnoop demonstrates how a BlackBerry can be used to spy on its owner.  It cannot listen into phone conversations or conduct phone taps on BlackBerry handhelds at the moment.  It is, however, possible to add a feature that makes phone taps work.  [...]]]></description>
			<content:encoded><![CDATA[<p><img class="size-full wp-image-263 alignleft" title="bugs" src="http://chirashi.zenconsult.net/wp-content/uploads/2009/10/bugs.png" alt="bugs" width="80" height="80" /></p>
<p>I first blogged about <a href="http://chirashi.zensay.com/2009/10/phonesnoop-turn-a-blackberry-into-a-portable-bug/" target="_blank">PhoneSnoop</a>, a component of <a href="http://chirashi.zensay.com/resource">Bugs</a>, a few days ago.  PhoneSnoop demonstrates how a BlackBerry can be used to <a href="http://chirashi.zensay.com/2009/07/a-look-at-etisalats-blackberry-interceptor/">spy on its owner</a>.  It cannot listen into phone conversations or conduct phone taps on BlackBerry handhelds at the moment.  It is, however, possible to add a feature that makes phone taps work.  I have written <a href="http://chirashi.zensay.com/2009/10/the-theory-behind-blackberry-phone-taps/">more on how to tap phone calls here</a>.  FlexiSpy is offering this service in its new version.  Incidentally, <a href="http://chirashi.zensay.com/2009/10/the-anatomy-of-a-spyware-application-part-1/">I took apart FlexiSpy </a>and wrote a brief post on it.  While the BlackBerry remains one of the more secure devices out there, <a href="http://chirashi.zensay.com/2009/07/nevermind-the-software-get-educated/">user awareness and education</a> is paramount to remaining completely <a href="http://chirashi.zensay.com/2009/07/leaked-spyware-threat-to-security/">safe</a> from spyware.  I tweaked the application since my first post now allowing anyone to download, install and try it.  PhoneSnoop now has the ability for a user to customize the &#8216;trigger number&#8217;; rather than me having to give out customized versions.</p>
<p><strong><a href="http://www.zensay.com/PhoneSnoop.jad">Download PhoneSnoop</a> and take a look at the <a href="http://www.zenconsult.net/PhoneSnoop_Guide.pdf">User Guide</a></strong></p>
]]></content:encoded>
			<wfw:commentRss>http://chirashi.zenconsult.net/2009/10/remote-listening-for-the-blackberry/feed/</wfw:commentRss>
		<slash:comments>57</slash:comments>
		</item>
		<item>
		<title>PhoneSnoop &#8211; Turn a BlackBerry into a portable bug</title>
		<link>http://chirashi.zenconsult.net/2009/10/phonesnoop-turn-a-blackberry-into-a-portable-bug/</link>
		<comments>http://chirashi.zenconsult.net/2009/10/phonesnoop-turn-a-blackberry-into-a-portable-bug/#comments</comments>
		<pubDate>Mon, 19 Oct 2009 07:42:16 +0000</pubDate>
		<dc:creator></dc:creator>
				<category><![CDATA[BlackBerry]]></category>
		<category><![CDATA[Featured]]></category>
		<category><![CDATA[Bug]]></category>
		<category><![CDATA[Bugs and Kisses]]></category>
		<category><![CDATA[Hack In The Box]]></category>
		<category><![CDATA[linkedin]]></category>
		<category><![CDATA[Listening Device]]></category>
		<category><![CDATA[Remote Listening]]></category>
		<category><![CDATA[Spyware]]></category>
		<category><![CDATA[Surveillance]]></category>

		<guid isPermaLink="false">http://chirashi.zensay.com/?p=247</guid>
		<description><![CDATA[I’m back at work after attending Hack in the Box security conference.  It was an excellent conference and I managed to catch up with a few friends and industry professionals.  The Malaysian conference is still by far bigger than the one held in Dubai.  This year saw roughly 600 people.  I also heard that the [...]]]></description>
			<content:encoded><![CDATA[<p>I’m back at work after attending <a href="http://conference.hackinthebox.org/hitbsecconf2009kl/" target="_blank">Hack in the Box security conference</a>.  It was an excellent conference and I managed to catch up with a few friends and industry professionals.  The Malaysian conference is still by far bigger than the one held in Dubai.  This year saw roughly 600 people.  I also heard that the HITB crew is adding a new location to the list of venues &#8211; Amsterdam.  Now that will most likely be an awesome con.</p>
<p>I promised everyone at the conference that I’d have a working application that can spy on the audio of other users who own a BlackBerry.  I am ready to deliver on that promise today.  This post is a prelude to the release of the tool.  I’ve so far not packaged it with Bugs.  Its a separate program that I named <a href="http://chirashi.zensay.com/2009/10/remote-listening-for-the-blackberry/" target="_blank">PhoneSnoop</a>.  Please note that PhoneSnoop is not an application that does Phone Taps or give you the ability to listen into phone calls.  It can be done, however, and you can <a href="http://chirashi.zensay.com/2009/10/the-theory-behind-blackberry-phone-taps/">read more on that how to tap calls here</a>.  <span style="text-decoration: line-through;">I’d like to have some volunteer beta testers  to see how well the application works</span> You can now <a href="http://www.zensay.com/PhoneSnoop.jad">download PhoneSnoop directly from here</a> by using your BlackBerry (be sure to <a href="http://www.zenconsult.net/PhoneSnoop_Guide.pdf">read the guide</a> and also make sure to set your input language to English US for the app to work correctly).  You will be able to configure your own phone number.  <span style="text-decoration: line-through;">If you’re interested, please mail me on zen.chopstick@gmail.com</span> For the chickens out there, here’s a video of the app in action (I&#8217;ve not got audio on it, but it has closed captioning so make sure you turn it on).  I’m working on a video that shows the app on a real handheld with commentary, but for now, make do with this :p</p>
<p><object classid="clsid:d27cdb6e-ae6d-11cf-96b8-444553540000" width="640" height="385" codebase="http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab#version=6,0,40,0"><param name="allowFullScreen" value="true" /><param name="allowscriptaccess" value="always" /><param name="src" value="http://www.youtube.com/v/bpR_v62vQCA&amp;hl=en&amp;fs=1&amp;rel=0&amp;hd=1" /><param name="allowfullscreen" value="true" /><embed type="application/x-shockwave-flash" width="640" height="385" src="http://www.youtube.com/v/bpR_v62vQCA&amp;hl=en&amp;fs=1&amp;rel=0&amp;hd=1" allowscriptaccess="always" allowfullscreen="true"></embed></object></p>
<p><a href="http://www.youtube.com/watch?v=bpR_v62vQCA" target="_blank">PhoneSnoop &#8211; BlackBerry Bugging Application</a></p>
<p>Here’s how it works:</p>
<p>You install and run PhoneSnoop on a victims’ BlackBerry.  PhoneSnoop sets up a PhoneListener and waits for an incoming call from a specific number.  Once it detects a call from that specific number, it automatically answers the victims’ phone and puts the phone into SpeakerPhone mode.  This way, the attacker that called can now hear whats going on at the victims end.  Pretty simple right?  In the video above, I have setup PhoneSnoop to listen in for calls originating from +12120031337.  I first make a call from +12120031336 to show that there&#8217;s no effect.  Then, I show what happens when a call is made from the expected number.  The demo is on the BlackBerry simulator for now, but I&#8217;m working on bringing you a video that demonstrates the application on a real BlackBerry Bold.</p>
<p>Installation Instructions:</p>
<ol>
<li>Grab your friend’s BlackBerry</li>
<li>Download PhoneSnoop from the URL I mail you</li>
<li>Once installed, go to Options-&gt;Advanced Options-&gt;Applications-&gt;PhoneSnoop-&gt;Edit Permissions and change the “Input Simulation/Event Injection” to “Allow”</li>
<li>Run PhoneSnoop</li>
</ol>
<p>Checking the bugging capabilities:</p>
<ol>
<li>Call the victims phone number</li>
<li>Listen</li>
</ol>
<p><span style="text-decoration: line-through;">I will need to give you a customized version of PhoneSnoop hence there&#8217;s no download.  If you’re interested in trying it, mail me at zen.chopstick@gmail.com.  Include your phone number so that I can code it into the application.  I’m not doing a general release at the moment because of the implications of this tool.  I’m mainly looking for feedback so that I can refine the tool and write a paper on it.</span> The tool is now available for general release.  Anyone can download it.  <a href="http://chirashi.zensay.com/2009/10/remote-listening-for-the-blackberry/">Go here to read more.</a><span style="text-decoration: line-through;"><br />
</span></p>
]]></content:encoded>
			<wfw:commentRss>http://chirashi.zenconsult.net/2009/10/phonesnoop-turn-a-blackberry-into-a-portable-bug/feed/</wfw:commentRss>
		<slash:comments>36</slash:comments>
		</item>
	</channel>
</rss>

