The Backtrack5 crew has just announced Release 3 of their well known penetration testing Linux distro. Backtrack5R3 not only includes bug-fixes, but the addition of over 60 new tools – several of which were released in BlackHat and Defcon 2012. A new “Physical Exploitation” tool category has been added including the Arduino IDE and libraries, […]
Category Archives: security
Notacon 9: Pwn the Drones
In this video from the recent Notacon 9 conference, EFF activists Trevor Timm and Parker Higgins present on the widespread and increasing use of drones by government. Aspects of recent drone hacks are highlighted, security flaws noted, as well as the growing popularity of DIY civilian drones. For more information on the use of drones […]
Black Hat hacker gains access to 4 million hotel rooms with Arduino microcontroller
This hack was demonstrated by Cody Brocious, a Mozilla software developer, at the Black Hat security conference in Las Vegas. At risk are four million hotel rooms secured by Onity programmable key card locks. According to Brocious, who should be scolded for not disclosing the hack to Onity before going public, there is no easy […]
Installing Metasploit on Raspberry Pi
We like Irongeek’s recipe for installing Metasploit on the Raspberry Pi. He presents a simple straightforward install method to install Metasploit on his board running the Debian “wheezy” public beta. For those looking for something more, you may want to consider PwnPi, which is a Linux-based penetration testing dropbox distribution for the Raspberry Pi.
Reverse engineering a home security system
Ken from OverEngineered writes us about his recent efforts in reverse engineering, I recently reverse-engineered the security system installed in my house and re-implemented the control board for it using a JeeNode (arduino-compatible with on-board RFM12 radio). Turn your whole house around with custom home renovation toronto. I created a post about the reverse-engineering here. […]
Warning: Ping-Pong balls are very flammable
In response to yesterdays post about the 8×16 LED matrix which used ping-pong balls as diffusers, Josh send this video and warns that the Ping-Pong balls are made of a very flammable material (nitro-cellulose). So If you are making a project using them as diffusers, keep in mind they catch fire very easily. I had […]
RTL-SDR and Backtrack5 R2
Inspired by the securestate article “All Your 900 MHz Are Belong to Us”, the hack4fun crew wondered about the potential for using the RTL-SDR dongle with Backtrack5 Linux distro. They were able to easily install the drivers and related software to use the RTL-SDR with GNU Radio and GNU Radio-companion and have written this article […]
O’Reilly webcast: Hacking and Securing iOS Applications
O’Reilly is presenting a free webcast by Jonathan Zdziarski on the topic of Hacking and Securing iOS Applications on May 3, 2012, at 1 PM PT. Jonathan is the author of the O’Reilly book by the same title. In this webcast, Jonathan will demonstrate a number of ways to manipulate the runtime of App Store […]
28C3: SCADA and PLC vulnerabilities in correctional facilities
In this full length presentation from the recent 28C3 conference in Berlin, Tiffany Rad, Teague Newman and John Strauchs describe the opportunities and challenges presented by SCADA systems used in prisons and jails. These systems are often used in conjunction with PLCs to open and close doors. Using original and publicly available exploits along with […]
Deconstructing a retail anti theft sensor device
In this short video, Jeri and company answer the age old question: what’s inside one of those anti-theft sensor alarm devices used by the big box stores? You could call this destructive reverse engineering, or literal brute forcing. It looks like the alarm is triggered by the cutting of the attached bands surrounding the package. […]
28c3: the FreedomBox
This lightning talk from the recent 28C3 conference in Berlin is a general introduction and status update on the development of the FreedomBox project. The FreedomBox is a personal server running a free software operating system and free applications, designed to preserve personal privacy by providing a secure platform upon which federated social networks can […]
Defcon 19: Vulnerabilities of Wireless Water Meter Networks
Security researcher John McNabb presented this talk at the Defcon 19 (2011) conference highlighting vulnerabilities of wireless water meter systems. John managed a small water system for 13 years and draws on his experiences in this presentation covering water security systems and more importantly the hardware, software, topology, and vulnerabilities of wireless water meter networks […]
How to build still another passive ethernet tap
firestorm_v1 from yourwarrantyisvoid has published this detailed tutorial on building and using a passive ethernet tap. His goal in this project is to facilitate network monitoring for intrusion detection purposes, and wanted hardware which will allow the monitoring for traffic without degrading performance.
Hacking home automation X10 devices over power lines
X10 home automation devices control household systems over AC power lines. In the past their online pop-up ads were pervasive and hard to avoid and these devices are fairly common today. Researchers Dave Kennedy, aka Rel1k, and Rob Simon, aka Kc57, revealed two X10 hacking devices at the recent Defcon 19 conference in Las Vegas. […]
OsmocomBB: open source GSM software
Osmocom stands for Open Source MObile COMmunications. The crew developing the OsmocomBB (baseband) software project presented the above talk at the DeepSec conference last November in Vienna, Austria. As they describe their efforts: OsmocomBB is an Free Software / Open Source GSM Baseband software implementation. It intends to completely replace the need for a proprietary […]
Square credit card reader hack: the sound of money
At the recent Black Hat security conference in Las Vegas, hacker Adam Laurie revealed a flaw in the Square credit card reader hardware/software that allows the injected emulation of credit card data to fraudulently obtain funds. This discovery highlights the importance of robust financial security. He inserted a different wire into the iPad’s headphone jack, […]
DIY aerial drone spoofs cell towers, hacks wifi + Bluetooth
You’ve probably seen aerial surveillance drones. You also probably know that GSM towers can be spoofed to fool unsuspecting users into connecting and having their phone security compromised. Well at this year’s Blackhat conference recently held in Las Vegas, security researchers Mike Tassey and Richard Perkins demoed their Wi-Fi Aerial Surveillance Platform (WASP) capable of […]
Gibson3d open source security software
Looking forward to the upcoming Defcon 19 conference, we note that Gibson open source software will be used there to monitor traffic. Dan Klinedinst, the project owner, writes: Some of you have seen the “Gibson” software, which models a network in 3D and shows security events on that network in real time. The code, as […]
FPGA bitstream security broken
Researchers in Germany have released two papers detailing how security of the bitstream on Xilinx FPGAs can be compromised. The first paper (11 pages) discusses power analysis attacks and extracting keys from Virtex-II devices. The second (3 pages) describes an analysis of the Virtex 4 and 5 bitstream encryption mechanism. Via Slashdot.
USRP 101: unlocking wireless PC locks (and freeing dolphins)
We’ve been interested in the Universal Software Radio Peripheral (USRP) SDR and the associated open source GNU Radio software for some time, but the $1500+ cost has kept the project on the back burner. Nevertheless, we always like a good story about RF hacking with the USRP. Corey and Max saw a wireless USB Proximity […]
