That seems like a lot of hassle and a pretty big federal crime for only being able to attack Wi-Fi networks. Why not just park your car outside and use a laptop?
Hackers ship their exploits directly to their target’s mailroom
91–100 of 172 posts
Re: Hackers ship their exploits directly to their target’s mailroom
#92Earlier quoted context omitted.
IDK. If they put it in a stuffed animal like the pic in the article, how many would rip it open to see what's inside?
But what is more suspicious - a phone nobody ordered or (in the worst case of discovery) a stuffed animal nobody ordered with custom electronics in it?
Re: Hackers ship their exploits directly to their target’s mailroom
#93Because I would think that's a very uncommon case, everywhere I've worked either didn't have WiFi or the WiFi was a completely external network.
Re: Hackers ship their exploits directly to their target’s mailroom
#94The WiFi network is an interesting attack vector, although I've seen lots of places that don't have wifi setup with direct internal network access, only for internet access. That could limit the effectiveness of the warship somewhat. When I started the article the first it came to me was that, once that package actually arrived at someone's desk, the main goal of the attackers would be to exploit Bluetooth attack vec…
But now I wonder how many other attacks can be launched from a sealed box in a mailroom. Van Eck phreaking will get you a decent image off an LCD monitor from 10+ meters away through multiple interior walls, and can survive significant channel noise. Other side-channel attacks can directly pick up keys during decryption, though the proofs are short-range and it's not clear whether increasing device size/power would boost that.
It'd be tricky and expensive to arrange, especially with the risk of ending up pointed in a boring direction. But it seems like an absolutely wild idea for remote access to the contents of even air-gapped monitors.
Re: Hackers ship their exploits directly to their target’s mailroom
#95Earlier quoted context omitted.
Why even bother with a novelty? Send some USBs or even drop a few outside the building. Curiosity is a massive vulnerability
I work close to IT (being software) for a company ~400 people. We were doing a security audit and this is one of the things they tested. USB's were loaded up with curious sounding files that when opened alerted our IT department. It was shocking how many people picked up and used these random USB's they found laying around.
You left out the good part, what sort of file names did you use?
Re: Hackers ship their exploits directly to their target’s mailroom
#96That seems like a lot of hassle and a pretty big federal crime for only being able to attack Wi-Fi networks. Why not just park your car outside and use a laptop?
How long can you sit outside a company running Kali Linux and a high gain antenna array before you attract attention? If you ship someone on the DevOps team a WiFi-connected plush toy that listens for webhooks from your CI/CD platform to make happy/sad noises when the build passes/fails -- AND THEY PLUG IT IN AND LEAVE IT ON -- then the ability to have passive access to the network for a long period of time will be l…
Re: Hackers ship their exploits directly to their target’s mailroom
#97I had an idea to do exactly this but I never did it
Careful. The Norwegian postal service almost ripped me a new one for having the gall to ship a microcontroller, a thermometer and a couple of accelerometers to myself; apparently, buried somewhere deep in some regulation is the fact that shipping live datalogging equipment is a big no-no. Their legal department assured me this was par for the course for UPI (International Postal Union) menber countries. Among the obs…
Re: Hackers ship their exploits directly to their target’s mailroom
#98Am I missing something or does this depend on the company having a WiFi network that's connected to the company's normal internal network and its only authentication is an somewhat insecure Wifi password? Because I would think that's a very uncommon case, everywhere I've worked either didn't have WiFi or the WiFi was a completely external network.
Re: Hackers ship their exploits directly to their target’s mailroom
#99Find someone who's out on leave for a while (just look for who's having a baby on IG) and ship the package to him/her! They won't discover it for weeks and you'll have plenty of time for your package to sit in the mailroom or on someone's desk. The danger is when the package is opened, the company may realize they've been hacked. Or have it there permanently: Ship an executive a fancy illuminated globe or desk clock…
People are going to come at you from your blindside, if they can find it. And if you consider a certain class of people invisible, then that's what a hacker wants to be.
Re: Hackers ship their exploits directly to their target’s mailroom
#100Earlier quoted context omitted.
Or just give them a giant wooden carving of the US presidential seal: https://en.wikipedia.org/wiki/The_Thing_(listening_device)
given the cheapness and compactness of modern electronics any furniture can carry a factory (or during shipping) installed chip these days, even without getting into smart/cloud connected office tables and chairs territory. One can hope at least NSA X-rays their furniture :)
Unrelated: WTF? I just had to do a reCAPTCHA on HN to log in!