Disabling Weapons Abound
DISABLING WEAPONS - Threat to National Security?
by: Thomas V. Sobczak, Ph.D., PE
Since 1987, Sobczak has tried to explain to military and corporate security managers that
we are conducting intellectual exercises that affect people and things in ways never before
considered viable. Access points to affect people and electronics range from software-
based computer games (Hacking) to telephony (Phreaking) to industrial espionage (Spying)
to physical attack (Kill) mechanisms. Information available in the public domain can
damage the quality of life Americans take for granted. Disabling (Non-Lethal) weapon
research is an open book.
The political infighting between Military Services and Contractors or Laboratories causes
technology losses. Lawrence Livermore and Los Alamos have proponents of Dr. W (LLNL)
decrying the developments and ideas of Dr. A (LANL), and vice versa, in generally available
E-mail. Hackers from Vint Hill, Dahlgren, China Lake, San Antonio, Charleston, etc. freely
discuss their federally sponsored Disabling Weapon research. Compartmentization in
federal secret projects is both unique and divisive. Federal agencies do not share.
Hoarding forces those involved, who wish to be aware, to go underground to learn about
others doing similar research. Electronic transmissions are generally available. Intellectual
experimenters (hackers?) share knowledge and research interests. Experimenters enter
Bulletin Board Systems (BBS) at specific high privilege (access) levels and piece together
the projects' federal developers consider TOP SECRET. DOD has 30,234 penetrated host
computers. According to DISA they knew and reported only 302 penetrations.
Let me show some of the data base, collected from the public domain, about weapons to
interdict communications systems and networks. The sample provides an example of
information about civilian non-lethal (disabling) weapon monitoring and experiments. Right
now wire connected (telephone) system attack mechanisms are well documented on
Bulletin Board Systems and in Use Groups of the Internet. Newer technologies, such as
Fiber, Wireless, Satellite, Microwave, and RF projects, are in test or under definition by
various unsanctioned experimenters.
To assure the reasonableness of what he found, Sobczak has successfully reconstructed
experiments made public by unsanctioned weapon developers. If the weapon tested was
dangerous, we created, tested a neutralization mechanism and added to the ACC,
integrated software-based computer security system, V-PHAGE. After our research
concluded, we disassembled the device or deleted all executable software code strings that
someone could misuse.
Sobczak has been involved in research that produced VIRUS AS A WEAPON (VAAW) in
1987. The USAF ESD called VAAW a potential National Resource. As a part of the
research Sobczak analyzed ideas from several hundred Bulletin Board Systems in the
United States, Western Europe, the Pacific Rim, the Mid-East, South America, Eastern
Europe and, occasionally, the Soviet Union. What follows is a small (less than .01%)
picture of what a dedicated researcher might find publicly available to seekers of disabling
knowledge.
1. As early as the mid-1970s, Volkswagen developed a computer controlled fuel
injection valve control system. The car worked perfectly in Europe, but had unexplained
engine failures in the United States. The engine failure was intermittent and very short
lived. Anomalies appeared to occur randomly. Unsanctioned experimenters determined
the cause of failure to be Citizens Band radio frequency emission from mobile or base
stations that produced sufficient energy to distort. Knowledge sharing by experimenters
allowed testing to occur in Germany. Experimenters targeted the Volkswagen test track to
prove the accuracy of their research. Nationalism has no place in intellectual
experimentation. Hackers share that which governments hoard.
2. Some GM cars had similar problems with electronic control systems. Signal in the
two-meter range overcame the electronics. Other manufacturers' electronic controllers have
problems caused by cellular phone transmissions. In a democracy one can purchase an
equipment manual for the target automobile computer directly from GM and a used
computer from a salvage yard. Used auto computers are readily available from auto
salvage yards. Testing and fine tuning is a simple, invisible process.
3. Reports from England say chip upset problems occur in auto electronics in the area
around Coventry due to RF leaked from the transmitter used by Radio Four, a commercial
station transmitting on 1500 meters. The station antenna lobes are radiating unstable
energy. When cars pass close to the station, the transmitter will disrupt component chips
within the electronic ignition. Garage doors about Fort George Meade experienced similar
problems from signal emanating from transmitter side lobes. They documented this event
in the Baltimore Sun newspaper. The US Army denied it. Official denial by Federal
Agencies contributes to insecurity.
Experimenters are working to transmit signals at frequencies that override and/or control
the target computer. Imagine the effect of disabling devices under the control of criminals.
Signals could be used to stop law enforcement vehicles or disrupt communications.
Remember a Hacker, with impunity, continues to play with NYPD communications in
Manhattan. As you examine these occurrences, visualize the opportunity for urban
electronic warfare formulated by academic terrorists.
Use of directed radio energy to overlay software is a powerful disabling weapon against the
civilian population. Worse, terrorist factions seeking to disrupt a paramilitary operation,
such as drug smuggling interdiction, might reek havoc on unsuspecting civilians. Hackers
claim to disrupt Coast Guard patrol boat radar in New York and Florida on regular schedule.
Coast Guard personnel unaware of these experiments have reported electronic dead zones
in certain offshore areas along the south shore of Long Island.
Equipment designers have not given manipulating radio frequencies sufficient credence.
There is no way to stop directed RF / microwave energy radiating from hobbyist off-the-shelf
integrations, from becoming a new, invisible, tactic to cause major disruptions of computer
/communications systems. Sobczak research shows hobbyist experimentation is making
real the ability to effect high technology electronic systems.
SDI and the USAF Weapons Laboratory have "black" high powered "burn them up"
microwave beam and pulse weapons under development. Beam and pulse weapons are
very large requiring vast amounts of energy. However, a specifically derived low power
pulse can short out most commercial electrical, telecommunications, computer, and similar
devices that contain transistors or semiconductors. They have discussed and duplicated
accidents at Kirtland AFB in the high energy laser physics program at the Phillips
Laboratory. The thirty autos lost their onboard computers from being parked too near an
experimental laboratory years ago, created a subculture of "beam ray" experimenters.
Hobbyists target the "ARC" at Huntsville's Army Strategic Defense Command and free
speaking contractor personnel to learn how "Brilliant Pebbles" they might reduce technology
to small scale experiments. The USAF acceptance of the National Test Bed Facility at
Falcon Air Force Station, CO offers new access to hackers.
There are many ways to use technology to gather and alter electronic pulses. Best known
and easiest to duplicate, from available hobbyist equipment plans, is the interruption of
signals from a Home Box Office satellite and the insertion of a message that stated its
subscription rate was excessive. That incident instilled dread in communications industry
managers. It proved that anything in the transmitted signal universe is fair game. The
takeovers were for 22 and 90 seconds respectively, limited only by the hacker sponsor fear
of discovery. They have documented and upgraded the method in on-line Hobbyist
Magazines several times. Hobbyist's shareware software offers nontechnical means to
decrypt dozens of supposed secure software applications. Individuals claim to read Letters
of Credit downloaded from satellite to Merrill Lynch's Antenna Disk Farm in Richmond
County, NY (Staten Island). The captured code is decrypted using purloined software.
A group of researchers in Delaware/South Jersey study encryption technologies in use by
the pay TV companies. The members of this group have a good working knowledge of
military radar and communications systems and associated encryption technologies for data
transfer. Most are GS grade employees at a New Jersey area naval installation or are
involved with an Aegis prime contractor. This group claims capability to jam a satellite with
the few mobile systems it has constructed. Jamming systems are modeled upon military
technology. They built these using hobbyist equipments of the off-the-shelf class
mentioned earlier.
Some say those hacker weapons cannot succeed, yet if one looks in any number of
hobbyist on-line magazines for information on frequencies or locations, weapons are readily
available with step by step instructions about the interdiction process to affect currently
fielded military and civilian systems. They arrested individuals outside the fences of
McGuire AFB for copying signals. To date, no one has identified a similar activity outside
Andrews AFB near the AF-1 storage space.
Hackers claim the disruption of AT&T's ESS-7 switching system that malfunctioned in New
York City, Washington, Pittsburgh and Los Angeles are the results of their experiments
gone astray. Older readers will remember that the BELL TELEPHONE COSMOS operating
system managed earlier telephone switching. One needs only read "2600" or
"HACKTECH" magazines to learn that hackers know as much or more than COSMOS
systems operators. On-line hacker magazines give those capable an ability to create
weapons to "pay back" telephone companies for real or imagined slights. The supposed
security of fibre optic transmission does not exist.
HAM radio operators can contact both American and Soviet satellites. While generating
high powered signals in the mid range of 1-10 Ghz is expensive, signal generation does not
present a technical obstacle. Surplus military equipment is easy to obtain. All that we
need is a moderate size dish and power to generate microwave frequencies to produce an
effective jamming station. A derived signal may not be able to over ride true signals, but
jamming or saturating the true signal will affect operation, stability and potentially the orbit
of a satellite target. Knowledgeable attackers do not try to change orbit or location of a
satellite. They attempt to confuse the onboard programming to do this job for them.
A reader might reflect upon the New York Times stories of FAA programmatic errors that
turned on cockpit collision warning systems in the Long Island region in February and
March 1990. The transmitter was a jury rigged device set up in the parking lot of a Nassau
County NY waterfront park situated parallel to the JFK airport landing flight pattern. The
FAA fell victim to Radio Shack mentalities.
Hackers, who are DEC experts, use REXX and other shell mechanisms to manipulate
conventional computers. US Navy multiprocessor computer integrations, by firms such as
Harris, are only extensions of conventional computers. A "do loop" transmitted to a naval
vessel's six processor VAX computers hardened by Harris Corp. using FLEETSATCOM
works to stop the computer.
The possibility to intercept and harvest vast amounts of signal manipulation and weapon
creation knowledge is available to those who collect technology. The business of
distributing this knowledge in third world nations and to our enemies is yet to be explored
by American security agencies. It is happening. During Desert Shield/Storm individuals
from Australia and Kentucky sought to trade software for or purchase AWACS and JSTARS
frequencies. Individuals near a military facility in North Carolina freely discussed "drop
zones" with colleagues at Air Force Facilities at San Antonio and Travis AFB. Target
identification is a characteristic of free speech. When SAC was, General Searock could not
admit to this weakness. His targeting systems suffered. A USAF Colonel at the Pentagon
explained how to intrude of the mission planning computers at Offutt AFB via an overflow
office in down town Omaha.
ACC experiments find that the simplicity of homemade equipments detailed in BBS files
optimizes Military Standards. The electronics building blocks consist of comparators, signal
detectors, data separator gates, A to D - D to A converters, data amplifiers and signal
converters. A freely available device for signal modification may be a modified off-the-shelf
slow scan system with error correction and signal smoothing circuits sold via an electronics
magazine. The unit works on telephone lines and standard radio channels. Since
experimental units accept signals from multiple input sources, there is no problem adapting
the unit to accept a cleaned up signals from a modified digitizer circuit that emulates the
target.
Hackers have the capability to collect and/or modify RF and microwave signals if they have
an antenna on their roof attached to computing equipment. Most commercial off-the-shelf
radio communications units have attached signal amplification circuits to adjust for the ever
growing background noise generated by normal commercial stations and reception
characteristics. One can read specific signal information generated in any locality as easily
as tuning a commercial AM or FM radio station.
I have monitored a wide spectrum of personal computers emitted signals with a strong
signal between 9.0 and 9.250-mhz for the display of standard text scrolling. Better signal
display was found at the lower frequencies of 9 MHz. Monitor frequencies were found
around 11 through 19.5 - 20 MHz. Printer frequencies are between 140 and 200-mhz. We
detected disk operations in the ranges of 88 to 250-mhz. Overall frequency generation was
from 4 through 500-mhz. The modem was found between 28 and 300-mhz. Overall,
discovery of radiated or transmitted signals by means of common hobbyist radio enhances
weapons and hobbyist countermeasures. A narrow band antenna allows near precise target
selection.
Opportunity exists to use common ham transceivers for disabling operations. With simple,
easy concluded modifications, off-the-shelf devices can transmit frequencies from 1.6 to 30-
mhz. Hobbyist weapons offer the possibility to disrupt internal signals used to process
information. Causing other logic related electronic systems to act or not act is a logical
conclusion to this process.
Developing off-the-shelf disabling weapons produces problems in both military and
commercial electronic systems. Malicious intent can be associated with civilian targets
such as computer installations, bank and operations support structures (microwave
repeaters). In economic difficulties the "get even" idea causes negative realities. The
ability to override security and other equipment functions can be affected by manipulating
frequencies. We are at risk from a fringe element protected by our democracy
Capability to produce disabling weapons using off-the-shelf components is within reach of
any person with the intent to create mischief. The equipment identified in this discussion
is not sophisticated. Disabling weapons are no more then an integrations of simple block
circuits designed to produce a specified result. All described equipments, plans and
historical experiences, mentioned herein, are in the hands of free thinkers and aggressors
(even if they do not realize the capability they possess).
In conclusion consider most military and contractor technologists do not have knowledge
of the destructive systems that hackers and terrorists have designed to corrupt systems and
people. Disabling weapons beyond military research are a reality. How society deals with
their potential requires a rethinking of our national security policy.