The curious case of the Raspberry Pi in the network closet
blog.haschek.at
blog.haschek.at
If the author had setup an encrypted partition where all the "real stuff" was found, and the key for such partition was in-memory only, possibly going alone one of the small rpi UPS/batteries to prevent minor electrical hiccups to make the whole operation fail.... it would have been almost impossible to get back at the author.
Also, using a nice "black box" that looked like a sort of electronic device, instead of some randomly put together rpi+pieces, would have made the device mostly invisible.
So: an amateurish hacking job.
But even if you don't care, at least DON'T SIGN UP WITH YOUR REAL NAME to that service. What the freaking heck? I really hope they get what they deserve.
Disguised as one of those generic thermostat boxes on a wall it'd go unnoticed by 99.999% of people. Bonus points for a twiddly wheel.
Even if discovered, most people would not bother taking it apart --- they'll just assume it is broken and throw it away.
There are many rules related to where high voltage stuff should be, how it should be installed and who can access it. And unless you do it by the rules (unlikely), it will get caught up during a safety inspection.
https://99percentinvisible.org/article/biohazard-symbol-desi...
Article: https://www.hln.be/regio/antwerpen/rechter-straft-it-special...
Check out the image in the article. They attached keyloggers and sent the strokes to the box. Saving them and once in a week dump them over to a car in the parking lot.
The original article is great, but the guy was really not putting any effort into it.
Our home SSID isn't there, but a neighbour's network is visible on the street outside and is listed.
https://www.theguardian.com/technology/2010/may/15/google-ad...
There are no wifi hotspots around me so when I set up my old wifi (same ssid as before and same hardware (bssid)) and checked my phone on google maps it was saying that I still am at the old place because it had not GPS at the moment and then google maps checked the SSIDs around me and looked up where those are located
Was a very weird thing
I tried to check numbers on WiGLE but it's being painfully slow for me.
macchanger (I use a custom script that works better for me. Also does magic in places with limited interned, e.g. free 100MB limit)
I just realized people can track my relocation across cities and countries if they can see "Ah this SSID was there last month, and here this month!".
But it won't help much if there are any other wifi networks or devices around.
For enhanced sneakiness, deploy three or more Wi-Fi base stations at the same location with the radios tx power turned right down and directional antennas - and try to make the geometry lookalike it's just a lucky long range shot to a real public/free wifi behind the antennas...
Geocaching and trying to gather as much privacy sensitive information about the people around you are two different things. With geocaching there aren't any parties involved that are unaware of the activity who are still negatively impacted by it.
1) It allows building alternative location providers that make it possible to have an Android device that doesn't rely on Google maps.
2) Publicizing the existences of these databases might make the general public more conscious of privacy and data protection issues involved.
2) That is like saying you go around kicking people in the crotch to make them more conscious about the benefits of learning self-defence.
Update:
> Google and other entities already have that data.
How is this an argument FOR gathering sensitive information about the people around you? Should you also look to their trash and digitise any documents they throw away and make a website that allows you to search through these documents? You could argue that Google or some other entity already has that information anyway.
You could also argue that this would increase consciousness with regards to the privacy concerns of your trash.
Of course, the likely outcome is that only big multinational corporations with a legal team are allowed to kick you in the crotch.
It's pretty much like leaving the front door unlocked -- it would be unethical to use it to go inside and steal your stuff but we still need to lock the door if we want to reduce the chance of someone stealing your stuff.
Tips for avoiding this:
- Change SSID at least once per year.
- If your router support multiple SSID's, turn the current one off and use the next one in the settings instead -- it will usually result in the MAC address being changed as well.
- Do the above whenever you move the router from one location to another.
Installation
Download, install and activate the Xposed framework
Download, install and activate the XPrivacyLua module(I'm still using a perfectly workable phone that is forever stuck on Android 5)
SSID unique data is hashed into the password. If you use a very common name there will be a precomputed rainbow table that will make cracking much faster.
https://www.renderlab.net/projects/WPA-tables/
Ideally you would rotate your SSID regularly, but of couse that is a massive pain.
(Besides, it can be useful to treat your LAN as hostile, anyway, with rampant IOT and friends etc.)
It definitely seems like a good idea to put IOT things on a different subnet. I've not met a home router yet that allows me to put proper filters on devices. DD-WRT I guess. But there are so many patches which should be applied, I'm sceptical of old firmware for routers.
At the moment I have an embedded linux device with a wifi dongle and giant antennas. The modem box can probably still be hacked remotely (from the ISP), but at least I'm able to prevent any device on the network from talking to it and using some simple rebinding or XSS attack. (E.g.: https://www.gironsec.com/blog/2015/01/owning_modems_and_rout... http://www.routerpwn.com/ )
How quickly, really? I remember a while ago I had a discussion on here where someone told me a hash method was insecure, as you could crack it with a GPU. I downloaded hashcat, put in the hash of a 6 character string, and left it running overnight on a GTX1070 and it was still going.
A good GPU cracker rig will get 500k hashes/second per GPU. That is still very slow compared to the search space of a 12 character [a-z][A-Z][0-9][@#$_&-+*"':;!?~|{}%] password.
For a 6 character string, it still depends on what mask you are providing, or what the search space is, i.e are there requirements like one or more upper, 1 or more digits, or is it purely random from a RNG?
Still, if it isn't breaking it within a day I'd say you are in CPU mode, where a multicore box is still only 5k hashes/second.
So anyone in wireless range of you can 1) track you and recognize you again, and 2) possibly figure out where you work and live (although of course they may see your friends' wifi networks too and not be able to tell which is your network.)
I show this live when I do general security presentations. Live on stage with nothing more then a Raspi and a Wifi USB dongle.
It freaks people out to see there home, holiday, local bar, family in law and other historic SSIDs scroll by.
It's real limited in what it does, but it can turn wifi / bluetooth / other stuff on depending on time, location, the usual stuff.
I would love to have a real "Tasker" type app for iOS, but I doubt that will happen anytime soon.
https://robertheaton.com/2019/01/15/a-brief-history-of-wi-fi...
Looks like more recent phones are better about this, but there are still a lot of older phones out there! And there are still leakages that allow tracking.
Note that with "real computers", just keeping the software up to date is enough to get you the latest in MAC randomization and whatnot; with phones, you may or may not be able to upgrade your software. -.-
There are retail analytics startups who literally use this exact type of data to allow brick and mortar stores to gain insights into their passive customer behavior. Source: I used to work for one of them and designed and built a bunch of the hardware / software stack.
(only honored by google, other OSs need different approaches)
https://krebsonsecurity.com/2015/07/windows-10-shares-your-w...
1) What are DNS logs?
2) What are RADIUS logs?
Would someone be so good as to answer?
Thanks in advance for help you could provide.
Edit :- This got downvoted. Don’t know why should anyone asking an honest question be marked down. Am I not allowed to ask technical questions in comments section?
RADIUS is the authentication method for wifi. In larger offices you don't just share the same password for all users, but rather set up a RADIUS server that manages individual accounts. So every employee has their own username and password for wifi. Also called WPA2 Enterprise
> On-Topic: Anything that good hackers would find interesting.
Something which is common hacker's knowledge and easily googleable is probably boring.
won't someone please think of the lurkers
RADIUS logs -- RADIUS = AAA server (authorization, authentication, accounting). Basically, a server that answers the question "given these credentials, what resources can this user access?" All new connections to the network will show up in RADIUS logs. As a user, when you have your "own" wifi username and password (e.g. on an access point configured to use WPA Enterprise), usually what happens is the access point asks an external RADIUS server to authenticate the credentials, and then the DHCP server asks the RADIUS server to authorize the user for an IP address assignment.
It's amateur hour if you can just plug in any random rpi, it gets a DHCP lease, access to the company lan, and a route to the outside internet.
However I don't mind being able to get LAN internet at a hotel that wants me to pay $24 per day for wifi when they have VoiP phones that have internet access...
That gives me internet and streamability/casting to the tv :)
Every single hotel I’ve been to in the last year or so has pitiful bandwidth, which is completely saturated after dark once everyone fires up Netflix and lets it run all night long.
Getting a route to the outside internet is not such a big deal; access to internal data is.
By the way: it's "amateur hour" if, as you say, that happens for a switch in a public/semipublic area in an office structure. On the contrary, I've seen a lot of "all-enabled" switches if those were accessible just from INSIDE the datacenter, where few people had access. It's not a really reasonable scenario.
Great article though, very interesting read.
>Still no idea what it actually does except for the program being called "logger", the bluetooth dongle and it being only feet away from secretary / ceo office
[1] https://www.reddit.com/r/sysadmin/comments/9xveq5/rogue_rasp...
Either that person has phenomenally bad tradecraft, or they are actually innocent.
There are so many plausible ways in which the 'gifted person' is not in on the plot; for example, they may have sold the pi to the disgruntled employee before the employee was disgruntled or with no idea of the use that the disgruntled employee would put it too.
Have to kind of hope thats how it all ends up.
When I was young I often set up computers and stuff for others. These days I try and get slopy shoulders when people ask me for tech support, and if there were a young gifted wizkid nearby I'd be sending a lot of innocent business their way....
An investigation will have to see if the kid has anything to do with the attack at all.
Further legal investigation will no doubt follow. Maybe gifted kid is involved in something illegal, maybe not. Hopefully we'll hear more about this in the future.
Which is interesting, because I double-checked and the article is actually more circumspect: "The curious case of the Raspberry Pi in the network closet how we found, analyzed (with the help of Reddit) and in the end caught the culprit of a malicious device in our network"
They find the home address and name of the person who prepared the pi (although we don't know it was the person who installed the 'logger', whatever that is etc). And they have identified the disgruntled employee who seems to have installed it. Two separate things.
> This could be a wrong lead as usernames tend to be used by multiple people but let's just keep that name in mind.
Fixed number of people it could be ... and it turns out to be the ex employee ... who would have thought.
I'm pretty shocked at how obvious they left this. Surely they knew it would be found one day?
Always suspected that Agatha was a bit simplistic. Maybe the real bad guy always gets away!
[0] https://www.reddit.com/r/sysadmin/comments/9xveq5/rogue_rasp...
I love this article, and I wanna promote our works in this thread :)
We are build some little Nordic nRF52-based widgets for maker with a lot of documents, you can find more wiki at here[1][2]. And we are try to use MESH network technology to protect our IoT data, here is some tutorial for BLE MESH[3] and OpenThread MESH[4].
BTW, if you are intersted in FIDO U2F security key, please check here[5], an open source FIDO U2F implementation on nRF52 SoC.
[1]: https://wiki.makerdiary.com
[2]: https://blog.makerdiary.com
[3]: https://blog.makerdiary.com/getting-started-with-bluetooth-m...
[4]: https://blog.makerdiary.com/build-a-thread-network-with-nrf5...
If there is a criminal (or civil) case, there has been no chain of custody. If you find something like this, don't even touch it, get someone qualified.
Secondly, it seems highly likely the person who created the image is not the person who emplaced it. The use of a VPN is hardly an indicator of evil intent. At least the author did not put any names in their publication.
There was no conclusion drawn as to the involvement of the gifted kid other than the pi initially being set up by them.
Wow, I never wanted to work in a company where I had to say this. Really, if the pay grade decides which human you are, I better get no money but can do whatever I want, like go to that person, ring on its door and ask it about its plans.
This guy clearly was following that and did his due diligence of step 1 being, make a backup of the device. Then you have a record of everything as near time of discovery as possible, so if you're investigation hoses everything up, you can restore and start over.
The author is also correct in that once he's done his investigation, he passes it all on to the next level to do their job. So in his case, he's done. There is NOTHING else he should be doing. If he does it really could hose up any/all legal action.
Kinda like getting to court in a Sexual Assault case and finding on the arresting officer forgot to read the guy his Miranda Rights.... You can have 100% proof this is the guilty party, but he goes free because someone in the chain of custody hosed up their part.