[Politech logo]

Politech is the oldest Internet resource devoted to politics and technology. Launched in 1994 by Declan McCullagh, the mailing list has chronicled the growing intersection of culture, technology, politics, and law. Since 2000, so has the Politech web site.

Activists reverse CyberPatrol 4, reveal zany secret "blacklist"



This work is brilliant. Kudos to Jansson and Skala.

Now, blocking software being overzealous and buggy is nothing new. This
article is four years old, and still timely:

http://www.eff.org/pub/Publications/Declan_McCullagh/cwd.keys.to.the.kingdom.0796.article

But it's somewhat surprising that CyberPatrol hasn't cleaned up its act
since being embarrassed so throughly back then.

-Declan


---------- Forwarded message ----------
Date: Sat, 11 Mar 2000 11:38:18 -0500
From: mskala@ansuz.sooke.bc.ca
Subject: Cyber Patrol 4 reversed

March 11, 2000 - ANNOUNCEMENT

Cyber Patrol(R) 4, a "censorware" product intended to prevent users from
accessing undesirable Internet content, has been reverse engineered by
youth rights activists Eddy L O Jansson and Matthew Skala.  A detailed
report of their findings, titled "The Breaking of Cyber Patrol(R) 4", with
commentary on the reverse engineering process and cryptographic attacks
against the product's authentication system, has been posted on the World
Wide Web at this address:

    http://hem.passagen.se/eddy1/reveng/cp4/cp4break.html

The abstract of the report:

    Several attacks are presented on the "sophisticated anti-hacker
    security" features of Cyber Patrol(R) 4, a "censorware" product intended
    to prevent users from accessing Internet content considered harmful.
    Motivations, tools, and methods are discussed for reverse engineering
    in general and reverse engineering of censorware in particular. The
    encryption of the configuration and data files is reversed, as are the
    password hash functions. File formats are documented, with commentary.
    Excerpts from the list of blocked sites are presented and commented
    upon. A package of source code and binaries implementing the attacks
    is included.

Eddy L O Jansson
srm_dfr@hotmail.com
http://hem.passagen.se/eddy1/index.html

Matthew Skala
mskala@ansuz.sooke.bc.ca
http://www.islandnet.com/~mskala/




--------------------------------------------------------------------------
POLITECH -- the moderated mailing list of politics and technology
To subscribe, visit http://www.politechbot.com/info/subscribe.html
This message is archived at http://www.politechbot.com/
--------------------------------------------------------------------------


Enter your email address to join Politech, Declan McCullagh's moderated technology and politics announcement list:

Return to politechbot.com