That's a very obvious and very obviously bad way of planting a network exploit. Very rookie and rather sad. In entirely unrelated news, this guide details how to set up an encrypted boot process on a raspberry pi, with it waiting for you(r forked login agent) to ssh in and provide the LUKS password: https://github.com/ViRb3/pi-encrypted-boot-ssh
The curious case of the Raspberry Pi in the network closet (2019)
181–190 of 269 posts
Re: The curious case of the Raspberry Pi in the network closet (2019)
#182Earlier quoted context omitted.
We did get a hand written statement from him and the original evidence (hardware) is still untouched and locked away. In his statement he wrote that the pi logged to the SD card but there was no data on the SD card (well not on the data partition) and I'm pretty sure that was a lie and it just logged to Balena. But even though we could never decipher what the nodejs program actually did (because it was so heavily obf…
>he was tracking the movement data of the boss to avoid him whenever possible. Wow, imagine hating your boss so much you go to so much creative and illegal lengths (that can backfire against you) to track him, instead of using same skills legally to finding a better job. I just don't get, something doesn't feel right about this being the true reason. To me it looks more like he wanted a covert backdoor in the company…
https://www.tindie.com/products/dekuNukem/daytripper-hide-my...
Re: The curious case of the Raspberry Pi in the network closet (2019)
#183>And what do we do, when we want to find out a location associated with a wifi name? We go to wigle.net, enter the SSID (=wifi name) and it tells us where on the world it is found. I've always enjoyed having unique/personal SSIDs, but had never seriously considered this consequence. I wonder what the worlds generic SSIDs are.
xfinitywifi is the top, with 2% of the routers seen having that name; it's followed by XFINITY (.73%), BTWiFi-with-FON (.38%), linksys (.37%), BTWifi-X (.35%), (.31%). The next one is AndroidAP at .28% and that feels like a good place to stop copying data, go look at the page if you wanna see more of the world's generic SSIDs. Basically "manufacturer name" and "internet provider name" dominate.
Re: The curious case of the Raspberry Pi in the network closet (2019)
#184Reminds me of this[1] good old quote from the IRC days hm. I've lost a machine.. literally _lost_. it responds to ping, it works completely, I just can't figure out where in my apartment it is. [1]: http://bash.org/?5273
We now have a process that routinely scans our entire IP space for machines that somehow get lost from our inventory system.
Re: The curious case of the Raspberry Pi in the network closet (2019)
#185Earlier quoted context omitted.
There's a decent amount of infrastructure involved in getting 802.1x authentication up and running in an efficient manner. While it does provide very good security, it's not widely used because of that.
Any idea on a good, at-home or small network alternative?
Re: The curious case of the Raspberry Pi in the network closet (2019)
#186Earlier quoted context omitted.
Any idea on a good, at-home or small network alternative?
Having a list of allowed MAC addresses, enforced per-port by a managed switch (or at least by the DHCP server and router), is a first step, though naturally it's easy to spoof a MAC address.
Re: The curious case of the Raspberry Pi in the network closet (2019)
#187Earlier quoted context omitted.
> told him to pack his things and get out I though the suspects were an ex-employee, and some guy that didn't work there (the part-owner), so was an actual current employee implicated in the end?
An ex-employee who still had a key to the office so they could move some stuff they had there. Presumably that courtesy was immediately terminated and the key was returned.
I think he got off way to easy.
Re: The curious case of the Raspberry Pi in the network closet (2019)
#188Earlier quoted context omitted.
what if this guy is just a hell of an introvert who is more comfortable rigging something like this up than with interacting with this boss. If this kid was in his early 20s I'd probably slap his wrist and impress on him the dangers of screwing with the company network closet. If he is an adult he really ought to know better
just came here to say that while I understand the sentiment, people in their 20s can vote, and should be considered adults, not kids.
The day before your 18th birthday, you're a kid, the day after you're an adult. Makes perfect sense.
Clearly someone who looks at the world this way must be under 18.
Re: The curious case of the Raspberry Pi in the network closet (2019)
#189Turns out that one of our sysadmins was running a porn server in the DMZ
Re: The curious case of the Raspberry Pi in the network closet (2019)
#190Earlier quoted context omitted.
>he was tracking the movement data of the boss to avoid him whenever possible. Wow, imagine hating your boss so much you go to so much creative and illegal lengths (that can backfire against you) to track him, instead of using same skills legally to finding a better job. I just don't get, something doesn't feel right about this being the true reason. To me it looks more like he wanted a covert backdoor in the company…
> Wow, imagine hating your boss so much you go to so much creative and illegal lengths (that can backfire against you) to track him, instead of using same skills legally to finding a better job. I’ve mentored a lot of juniors. It’s not uncommon for young people, especially those with less developed social skills, to have an undeserved fear of their boss or anyone else with authority. It’s common with young people who…
Sure, but even as a junior employee, we're still talking about mature adults here, not kindergarten kiddies, who can vote, pay taxes and are held accountable for their actions in front of the law, so they should be aware that deliberately backdooring their employer so that they can surveillance their boss, not only most likely violates their employment contract they signed and can have serious legal backlash against then both from the company and from the person who's privacy they were trying to break.
>It’s common with young people who have debilitating anxiety and a tendency toward rumination.
Yeah, I get that, but how is this in excuse for hacking your employer/boss? Why not seek therapy from professionals for that and try to either quit toxic workplaces or report abusive bosses and find a workplace that accommodates your personality and emotional type, not try to hack and backdoor your employer's network to keep tabs on your boss.
There is no workplace in the world and no work colleagues that will tolerate you hacking their network and invading their privacy because you have anxiety and a tendency toward rumination.