The Little White Box That Can Hack Your Network
wired.com
wired.com
Extra work, but it is possible.
Perhaps there is no defense against this kind of attack.
The real solution here is proper network segregation and requiring encrypted traffic across the board, with sane key distribution schemes. But that's difficult and expensive.
Further yet, with "switch-port security" you can lock down mac addresses per port. With port security and proper device segregation if you spoofed a phones mac address and plugged in to that port the switch would still put you in to only the voice vlan not the data lan. It's not perfect but there are a lot of things you can do to secure a local LAN.
Unfortunately, most businesses must not even do the bare minimum if all they have to do is plug in a single PwnPlug without any attack vectors implemented like mac spoofing.
If your MAC appeared twice, you'd be locked out of the network and need to go and do some explaining (!). If your MAC moved around too much, ditto. If you had more than one ARP entry for your port, ditto.
Full authentication is only for College owned devices, not sure how they are managing that.
(Disclosure: I have no association with either Wired or Pwnie Express.)
And even with all of that, one day one of the computers gets a backdoor installed, and the attacker is able to copy everything off your network drive, because you didn't have any sort of IDS or firewall to prevent it.
Smarter people than you have thought about this. There's a reason the idea of an internal network exists at all; NAT certainly wasn't something people were considering right from the start.
That is very rude.
What's more is that it prevents learning. I was talking with friend of mine the other day about an idea to set up a sqlite database with a html/css/javascript front end in order to organize all the word documents and spreadsheets that currently are haphazardly tossed onto a shared drive at work.
He pointed out that that's basically a content management system, and I realized that up until that point I assumed I was the first person to ever think about this problem. Now I have a bunch of people's code to read and learn from.
Apparently in some sensitive facilities there are networks keyed off by MAC address, and then 802.1x key, so you need to have both the right MAC and the right key for that MAC to get an address and to send and receive packets. Connecting to the network switch with a 'non-authorized' MAC puts you on a different VPN than the if you connect with an authorized machine.
One of the attendees at the show told me they assumed that their network was 'unsafe' all the time and planned accordingly.
Now its probably naive to think we would go there in a year or two but it does seem to be a road we're being inexorably forced down.
If you run a large network, you'll have to deal with malware on users devices, and you'll have to deal with people gaining access to your network in other ways, such as this white box.
Having an "internal" network that isn't actually internal only gives you a false sense of security. Having access to an internal network should never give anyone higher access levels, but the whole idea of a "corporate intranet" pushes you in that direction.
- Assumption of breach
- Bring your own device
Assumption of breach is driven by the industry's over-emphasis on protection, versus detection and response. The harsh reality is an attacker will always be successful gaining access. The detection and response capabilities are historically anemic due to repeated under-investment. That's why you see so many intrusions reported and the attackers have been in place for months or years.One of the natural results of assuming breach is to shift focus from protecting _devices_ to protecting _data_. An attacker can always land on the secretary's machine, but you can put additional layers of protection around the organization's critical data.
Bring your own device (BYOD) is a natural extension of assuming breach and shifting focus from data to devices, and aligns nicely with the user desires to use their iPads and smartphones. The result in these environments is the IT shop becomes more ISP and less Dell technical support.
Many industries are adopting the assumption of breach and inevitability of compromise. RSA Exec Chairman at the RSA Conf a couple weeks ago: "We need to acknowledge once and for all that our networks will be penetrated." BYOD is harder - popular for universities and hospitals with significant user mobility, less so for governments and financials with higher protection thresholds and more static environments.
In another five years, these ideas will be common practice for many industries. If you HN'ers have some crafty plans in the enterprise space, take note.
We should disbanded corporate, local, state, federal and country law enforcement. there should be no countries, borders or walls anywhere and you should also leave your house/apartment/car door unlocked because we have all been hard ended by carrying loaded assult weapons and heavy armor 100% of the time, including your 5yo school kid.
oh.. will get karma from hell for this.
Even if the box has been "hardened"
They send them out in jiffy bags to the regional branches, manager plugs one in, they can stay at head office and check the (branch) network. Saves money, provides hard data.