- 5paisa
- AdSense
- Android
- Asphalt 8 : Airborne Mod Apk 4.9.1b Unlimited Money
- Battlegrounds Mobile India
- Blogger
- Blogging
- Bug Hunting
- cloud storage
- Cmd
- Damn vulnerable Web Application
- Demat Account
- Difference between
- dj alok
- dj alok in free firefree
- Doodle Army 2 : Mini Militia 5.2.0 Apk + Mod for android
- DVMA
- E-books
- earn Bitcoins
- Ethical hacking tutorials
- Express vpn
- EXPRESSVPN PRO APK 7.12.1
- EXPRESVPN CRACKED APK
- fire dj alok
- Freefire
- Gaming
- Google drive
- Google llc
- gplink
- Groww App
- Health
- helo
- helo mela
- helo app
- Helo app earn paytm
- Helo app full guide
- Helo app invite and earn
- Helo app redeem proof
- Helo app refer and earn
- Helo app unlimited trick
- Helo app withdraw proof
- Helo Mela Offer: Get Rs.2 Free Paytm Cash + Win Upto Rs.10000 Paytm Cash
- helo refer and earn
- How to
- How to combine two Wifi Connections to get a faster Internet
- how to get dj alok for free
- how to get free dj alok
- how to get free dj alok in free fire
- How to install DVWA on Kali Linux 2020.2
- How To Use Light Speed WebCache on Your website
- ICICI Direct
- IOS
- kali linux
- Live streaming
- makeup
- meesho
- Money Earning
- My poems
- Netflix
- Netflix mod
- Netflix premium
- News
- online courses
- Pentesting
- programming
- PUBG
- Puffin Browser Pro 8.3.0.41446 (Full) Apk + Mod for Android
- Puzzles
- Recharge offers
- Refer and Earn
- Reviews
- SEO
- shell Scripting
- Shortlink
- Spotify Music 8.5.57.1164 APK Mega Mod Cracked Latest Android
- stylish name
- Technology
- Tips&Tricks
- Township Mod Apk 7.5.0 Unlimited Money
- Udemy
- Udemy courses
- Udemy free
- Udemy premium
- VClip app download link
- VClip app full details
- VClip app invitation link
- VClip app referral code
- VClip app referral link
- VClip app review
- Web designing
- What is
- WINDOWS
- Wishes
- Wordpress
- World Cricket Championship 2 2.8.9 Apk + Mod (Coins/Unlocked)
- Youtube tricks
- zoom app
- zoom bombing
- zoom call
- Zoom safety tips
PoisonTap: This $5 Device Hacks A Locked Computer In Seconds
PoisonTap: This $5 Device Hacks A Locked Computer In Seconds
Short : What can you do with your $5 bill? You can get a trickster Raspberry Pi Zero which can fool a locked and password protected computer. It can hijack cookies, create backdoors, compromise the internal router, and above all, make the computer believe it’s connected to the internet.
I have known many sorts of USB devices capable of killing a computer, enhance the security of a machine, perform HIV tests with 95% accuracy, used as a password generator, and much more.
Pi boards are often a part of various DIY hacks. For instance, using it as a device for Wardriving around your city. We have seen many instances of people taking advantage of the USB to gain access to a device. A Raspberry Pi board can be a good companion while doing such activities.
Usually, these USB hacking activities take advantage of one or more vulnerabilities in the operating system. But, what about a $5 Raspberry Pi Zero that’s an imposter.
PoisonTap, a trickster Pi Zero board, has been created by Samy Karkar. When connected to an exposed USB or Thunderbolt port, the device says to a computer that it’s an ethernet (via USB) device, not a regular USB device, and it’s a door to the entire internet.
Your innocent machine quickly believes what is said by the PoisonTap, completely unknown of its real intentions. The worst part, PoisonTap can gain access to a machine even if it’s locked – and password protected – by taking advantage of the trust factor a computer has on the ethernet devices.
Upon detecting an ethernet interface, your data hungry machine will make a switch from the regular battery-consuming WiFi to the wired internet. PoisonTap is equipped with the capabilities to assign an IP address to the fooled computer as a normal DHCP server would do. It will also tell the machine that it contains the whole IPv4 address space which is literally the entire internet if the newer IPv6 addresses are not included.
An active web browser on your computer can make efforts to connect to the false internet – powered by PoisonTap’s web server based on Node.js – to receive new data for the advertisement, analytics, and services. The USB hacking device is an unknown network interface to the machine with low priority, yet, it can hijack all the internet traffic.
PoisonTap can tunnel and store the HTTP cookies and session data of the web browser. It can also create web-based backdoors for an uncountable number of domains. These backdoors are stored in the HTTP cache. The device does it by making the browser load lots of iframes containing HTML and Javascript.
PoisonTap takes about a minute to all this stuff after it is connected to a computer.
The attacker also has the privilege to exploit these backdoors remotely because they continue to exist even if the device is removed and the attacker walks away. He can also use DNS rebinding and an outbound WebSocket interface to access the internal router of the computer already exposed by the hacking device.
For servers, the protection is easy by enabling Secure flag for cookies and implementing HSTS policy.
The most useful solution suggested by Karkar is cementing the open USB and Thunderbolt ports. And he literally put a link to a cement product. Some less practical, but effective to an extent, options would be closing the web browser every time you abandon your computer. Disabling the ports would remove slightest chance of your machine being hoodwinked. An effective way is to use encrypted deep sleep mode which will disable the web browser to make any requests when PoisonTap is connected.
You can read more about PoisonTap here. The source code is available on GitHub.
If you have something to add, tell us in the comments below.
Also Read
KUMAR JEERU
. I am a Programmer and Pentester. I find and Fix loophole in websites and networks. Connect with me for queries , web developemnt , Scanning and Fixing website Security issues. My company gives special discount for independent entrepreneur , small and Medium size companies. Contact me directly on my face page
Post a Comment
Post a Comment