POPULARITY
Jak wyglądają narzędzia używane podczas ataków na firmy? Co mogą robić? Ile kosztują? * WiFi Pineapple - jak atakuje się sieci WIFI * USB Rubber Ducky - dlaczego powinieneś się wylogować gdy odchodzisz od komputera * USB Killer - niszczenie portów USB * Proxmark - czy klonowanie kart dostępu jest możliwe * MouseJack - bezpieczeństwo bezprzewodowych prezenterów * USB Ninja - czy rozróżnisz prawdziwy kabel od złośliwego Grupa na Facebooku: https://www.facebook.com/groups/od0dopentestera/ Subskrybuj kanał: https://www.youtube.com/c/KacperSzurek?sub_confirmation=1 Spotify: https://open.spotify.com/show/4qGXKJyJicRJ0PfAX05V9O Google Podcast: https://www.google.com/podcasts?feed=aHR0cHM6Ly9hbmNob3IuZm0vcy81M2E4OTNjL3BvZGNhc3QvcnNz Apple Podcasts: https://itunes.apple.com/us/podcast/kacper-szurek/id1410369860?mt=2&uo=4 Anchor: https://anchor.fm/kacperszurek/ #od0dopentestera #pentest #hacking
This episode is brought to you by Netwrix Auditor, which empowers IT pros to detect, investigate and resolve critical issues before they stifle business activity, and proactively identify and mitigate misconfigurations in critical IT systems that could lead to downtime. In this episode, we talk about the Mousejacking attack, which allows someone with a crazy radio (or other similar device) to inject keystrokes into vulnerable keyboards and mice. Yikes! Not trying to be a doom and gloom guy here, but using this Mousejacking attack, pentesters/attackers could take over your entire Active Directory in just seconds - from the parking lot! I'll talk about how exactly that could be done - as well as ways to defend against mousejacking - in today's episode. If this episodes primes your appetite for more Mousejackin' fun, join me and my pals Paul and Dan for a deep-dive Mousejacking Webinar on Tuesday, April 2 at 12 p.m. CST! Some resources talked about in today's episode: Mousejack.com - great demo video of the attack Crazy Radio PA - one hardware option to perform mousejacking attacks Custom mousejacking firmware for Crazy Radio PA Jackit - tool for conducting mousejack attacks A cool Twitter thread on using mousejacking for pentests Vulnerable devices - nice repository of devices known to be susceptible to mousejacking attacks
This week Dave and Gunnar talk about: IoT hacks, cyborg insects, and Dave’s local crime report. “Let’s just put crime tape around it until we figure it out.” Fighting Unicorns win Excellence in Engineering Award at the Buckeye Regional Strong appearance at the Queen City Regional! The Ohio Pinball and Arcade Show Hilton Digital Key Police: Wanted Florida man bit fingerprints off to hide identity Summit prosecutor drops charge against former Stow BMV deputy registrar and now case dismissed Updategate: Microsoft splashes Tomb Raider ad over Windows 10 lock screens Google Hands Free Google Wants to Save News Sites From Cyberattacks—For Free Swarm of Tiny Pirate Transmitters Gets the Message out in Syria Speaking of swarms: Creepy experiment uses implanted electrodes to make beetles run faster Reddit’s warrant canary died? Hopelessly broken wireless burglar alarm lets intruders go undetected Garage door openers have had rolling codes since 1997 (which is slightly more secure) SimpliSafe uses 433 MHz and 315 MHz as noted by The Register with complementary video Remember Foscam from a previous episode? This is Why People Fear the ‘Internet of Things’ MouseJack: Injecting Keystrokes into Wireless Mice Amazon and Brita’s Wi-fi Water Pitcher Automatically Buys New Filters for You Amazon Now Offers More Than 100 Dash Buttons NSA boss reveals top 3 security nightmares that keep him awake at night Meanwhile at the Pentagon… DOD invites you (well, some of you) to “Hack the Pentagon” this month Michael Hayden interview on Off Message podcast New article by Lauren and NASA: Image processing at NASA with open source tools Dave interviewed by Federal News Radio: OMB’s 3rd policy memo in a week targets software purchasing RHEV 3.6 is out! Red Hat offers no-cost RHEL subscription to developers An Arduino-powered VR cycling experience for $40 Now There’s a Virtual Reality App To Help With Public Speaking Anxiety Why You Can’t Trust GPS in China Cutting Room Floor PHP Terminal GameBoy Emulator With Medieval Instruments, Band Performs Classic Songs by The Beatles, Red Hot Chili Peppers, Metallica & Deep Purple The SkyWall 100 bazooka captures drones with a giant net 4-Bot – A Raspberry Pi Connect 4 Robot! Apple Pi? Acrostic beat poem generator We Give Thanks The D&G Show Slack Clubhouse for the discussion topics!
Anonymous hits Belgium & Cincinnati. Twitter vs. jihad? MouseJack. Apple, FBI dispute updates.