Earlier quoted context omitted.
Great plan, but we have to test it. Can you upload a sample dataset of you typing for 1 week so we can try this approach?
What's your address? I can send it on a usb key.
Hackers ship their exploits directly to their target’s mailroom
101–110 of 172 posts
Re: Hackers ship their exploits directly to their target’s mailroom
#102Earlier quoted context omitted.
If the password is a predictable, low-length alphanumeric password it’s not going to take long for something like a multi-GPU machine with some dictionaries to break it.
Maybe with a separate cellular antenna the device could capture all of the wifi data, communicate it to a server with more processing power and possibly break it there and communicate it back to the device.
> The device, which cost about $100 to build, was equipped with a 3G-enabled modem, allowing it to be remote-controlled so long as it had cell service.
> The warship listens for a handshake — the process of authorizing a user to log onto the Wi-Fi network — then sends that scrambled data over the cellular network back to the attacker’s servers, which has far more processing power to crack the hash into a readable Wi-Fi password.
It’s not uncommon for red teams to do something similar: pull a bunch of ciphertext and hashes from the target network, ship them off to their GPU farm at the office, wait for results.
Re: Hackers ship their exploits directly to their target’s mailroom
#103Earlier quoted context omitted.
Or just give them a giant wooden carving of the US presidential seal: https://en.wikipedia.org/wiki/The_Thing_(listening_device)
given the cheapness and compactness of modern electronics any furniture can carry a factory (or during shipping) installed chip these days, even without getting into smart/cloud connected office tables and chairs territory. One can hope at least NSA X-rays their furniture :)
I would assume it's becoming a a software war. You monitor all frequencies with SDR and try to shield as much as possible while on the offending side you try to push information on different frequencies and making it look a like like stuff that's already in the air.
Re: Hackers ship their exploits directly to their target’s mailroom
#104Earlier quoted context omitted.
Think about the distance factor. Sure, you could get good radio stuff set up so that you don't have to be in the parking lot to break in and can avoid appearing suspicious on any surveillance cameras, but you still have to be within a few kilometers at most. With warshipping you can be across the planet.
Having done a handful of red teams our last concern was security cameras since most times no one looks at security footage until they’re already compromised.
Re: Hackers ship their exploits directly to their target’s mailroom
#105Why an attacker should spend 100$ , sending hardware to the target that could be potentially tracked following the path between the resellers, could transport evidences like fingerprints or DNA, using a telephone connection that could also be tracked when the same thing could be done with a good radio equipment and more discretion ? Anyway, I am the kind of guy that inspects the ATM praying to find out a skimmer to d…
Re: Hackers ship their exploits directly to their target’s mailroom
#106Earlier quoted context omitted.
Think about the distance factor. Sure, you could get good radio stuff set up so that you don't have to be in the parking lot to break in and can avoid appearing suspicious on any surveillance cameras, but you still have to be within a few kilometers at most. With warshipping you can be across the planet.
Having done a handful of red teams our last concern was security cameras since most times no one looks at security footage until they’re already compromised.
Unless you're emulating nation state actors, your ideology of a 'red team' which focuses on physical access is a disservice to your client and your industry.
Re: Hackers ship their exploits directly to their target’s mailroom
#107Earlier quoted context omitted.
But what is more suspicious - a phone nobody ordered or (in the worst case of discovery) a stuffed animal nobody ordered with custom electronics in it?
Just disguise your electronics to look like a voice box. Heck, you could even make it functional; microphone, speaker, and a tiny bit of software would make a convincing toy.
Re: Hackers ship their exploits directly to their target’s mailroom
#108This makes me think of an even more straightforward attack. How hard would it be to actually just ship them computer hardware and hope it makes it into the system? I mean, if a package that looks like it came from NewEgg containing a router shows up, especially if it matches the type the company usually uses, which wouldn't be too hard to figure out, what are the chances it just gets tossed on a shelf to be used next…
https://arstechnica.com/tech-policy/2014/05/photos-of-an-nsa...
Re: Hackers ship their exploits directly to their target’s mailroom
#109Mailing a bunch of "free" and "promotional" USB drives, prepared with zero-day malware, would probably work too. Especially if it was official looking.
https://wikileaks.org/ciav7p1/cms/files/BypassAVDynamics.pdf
Re: Hackers ship their exploits directly to their target’s mailroom
#110Find someone who's out on leave for a while (just look for who's having a baby on IG) and ship the package to him/her! They won't discover it for weeks and you'll have plenty of time for your package to sit in the mailroom or on someone's desk. The danger is when the package is opened, the company may realize they've been hacked. Or have it there permanently: Ship an executive a fancy illuminated globe or desk clock…
One of the first pen testers I ever read pointed out that companies do (sometimes excessive) background checks on their staff all the time and then they outsource the cleaning crew. When I'm there during the day, there's only so much I could do without other people noticing. But here's a group with full access to an empty building full of your equipment for 10 hours a day. People are going to come at you from your bl…
Doing right by your workers would go a long way towards plugging this vulnerability.