- Strom Carlson
:"This article is about Strom Carlson, a blogger and phone phreak. For the defunct American telephone equipment manufacturing company, see
Stromberg-Carlson ."Strom Carlson is thepseudonym of an Americanblogger andphone phreak who is the organizer of the Los AngelesDEF CON Groups chapter DC213 and former co-host ofBinary Revolution Radio .Biography
Strom has presented at the
hacker conference sDef Con and LayerOne. He also co-hostedBinary Revolution Radio with fellow phone phreak Black Ratchet, having taken over fromStankDawg when Stank took a sabbatical in July 2005.In February 2006, Strom found a vulnerability in the
Kinko's ExpressPay smart card system that makes it possible to change the serial number and the value stored on the card. An attacker could then make photocopies or rent computers completely anonymously or without paying anything at all. Furthermore, since remaining balance on the cards can be cashed out, it would be easy for an attacker to use the vulnerability as a quick source of cash. Kinko's has stated that abusing this vulnerability is "no different from stealing". [ [http://www.eweek.com/article2/0,1895,1934424,00.asp FedEx: ExpressPay Hack No Different Than Stealing ] ] [ [http://www.securityfocus.com/archive/1/426315 SecurityFocus ] ]Presentations
* DEFCON 14: "Hacking FedEx Kinko's: How Not To Implement Stored-Value Card Systems." [ [http://www.defcon.org/html/defcon-14/dc-14-speakers.html#Carlson DEFCON 14 Speakers ] ]
* DEFCON 13: "Be Your Own Telephone Company...With Asterisk." (with BlackRatchet) [ [http://www.defcon.org/html/defcon-13/dc13-speakers.html#strom DEF CON 13 Speakers Page ] ]
* DEFCON 12: "Phreaking in the Age of Voice Over IP." (with Lucky225) [ [http://www.defcon.org/html/defcon-12/dc-12-speakers.html#lucky Defcon 12 Speakers ] ]
* LayerOne 2006: "Hacking the SLE4442" [ [http://layerone.info/?page_id=10 LayerOne 2006 Presentations ] ]References
External links
* http://www.stromcarlson.com/ - Strom Carlson's website
* http://www.la2600.org/recaps.php - notes on Strom's presentation on Asterisk and VoIP, July 1, 2005
* [http://www.mal-aware.org/2006/02/28/fedex-kinkos-smart-cards-hacked/ Kinko's Hack] - Whitepaper on Strom's Kinko's Smart Card Hack
Wikimedia Foundation. 2010.