The PlugBot: A covert penetration testing device
theplugbot.com
theplugbot.com
http://en.wikipedia.org/wiki/SheevaPlug
This would be a fun project but it strikes me as a little lame that they want donations for what I imagine would be writing a few bash scripts.
For more elegance, use a guru plug with its dual gigE ports, turn it into a transparent bridge, and just put it inline with the ethernet cable of your target.
http://www.globalscaletechnologies.com/t-guruplugdetails.asp...
Once you realize you've got a fully capable linux server/router right there in the wall socket, all kinds of wild applications start springing to mind.
The fact that it is a SheevaPlug is probably the least remarkable thing about this project. What appears to be unique is that they're looking at this from a high level. They're asking the question: "What moving parts are required for a robust, remote-access penetration tool." The "Drop Zone" concept is probably the most intriguing.
Installing Linux plus a few security tools on a SheevaPlug is really simple. But that's not what this project appears to be. Have a look at the overview document:
http://theplugbot.com/assets/PlugBot_Overview.pdf
It's going to take more than writing a few bash scripts to have a robust framework for uploading results to a drop zone, and retrieving new command packages.
This reminds me a little bit of worms like Stuxnet, which reach out to outside sources for new information. They're more than a monitor. They're an agent.
You could do something similar already by leaving behind an iPhone (with custom software) plugged in somewhere in the office. It could probably be less conspicuous than this thing.
This device is a lot more dangerous, as it connects to an Ethernet port. Unsecured Ethernet ports are a lot easier to come by in most businesses. I've only ever worked with one company that secured their Ethernet network at such a low level (802.1X), and they were a very, very large multi-national corporation with a big manufacturing segment. They had to secure at the Ethernet layer as a matter of certification for the products they manufacture. Very few companies go through the trouble of implementing security at the Ethernet layer because of the expense and trouble involved.
Unfortunately, it didn't have the desired effect; and the network admin was pissed that he had to count all of the connection lights on the switches in the network closet once a week.
Rogue devices on your network are hard to detect and defeat.
Even rudimentary measures can help secure a network to some degree.
802.1X-2010 and MACsec would address this issue, but they require more expensive hardware and not yet widely supported.
http://www.globalscaletechnologies.com/t-guruplugdetails.asp...
then just install debian and compile whatever script^H^H^H^H^H^Hpenetration test tools you need.
http://theplugbot.com/assets/PlugBot_Overview.pdf
This involves a web server component with a reporting interface and some method of proxying "command packages" between the operator and the plug, which resides behind a firewall.