Modded Raspberry Pi Zero Can Hack a Locked PC in under a Minute




/ 7 years ago

Modded Raspberry Pi Zero Can Hack a Locked PC in under a Minute

An ethical hacker has built a device using a £4 single board computer that can hack a locked PC in less than sixty seconds. Samy Kamkar, a security researcher and whistleblower, used a Raspberry Pi Zero to build an Ethernet over USB device, dubbed PoisonTap, that can hijack internet traffic on the target computer even if the system has been locked.

According to Kamkar’s blog, the PoisonTap:

  • emulates an Ethernet device over USB (or Thunderbolt)
  • hijacks all Internet traffic from the machine (despite being a low priority/unknown network interface)
  • siphons and stores HTTP cookies and sessions from the web browser for the Alexa top 1,000,000 websites
  • exposes the internal router to the attacker, making it accessible remotely via outbound WebSocket and DNS rebinding (thanks Matt Austin for rebinding idea!)
  • installs a persistent web-based backdoor in HTTP cache for hundreds of thousands of domains and common Javascript CDN URLs, all with access to the user’s cookies via cache poisoning
  • allows attacker to remotely force the user to make HTTP requests and proxy back responses (GET & POSTs) with the user’s cookies on any backdoored domain
  • does not require the machine to be unlocked
  • backdoors and remote access persist even after device is removed and attacker sashays away

PoisonTap can bypass the following security:

Kamkar reveals that, short of severing USB connectivity from your computer, the best way to protect against the kind of attack that PoisonTap is capable of is to set your system to hibernate, rather than sleep. While PoisonTap is a white hat proof-of-concept, to show that it is possible, Kamkar has released the source code he used to achieve the feat. Start blocking your USB ports now.


Topics: , , ,

Support eTeknix.com

By supporting eTeknix, you help us grow and continue to bring you the latest newsreviews, and competitions. Follow us on FacebookTwitter and Instagram to keep up with the latest technology news, reviews and more. Share your favourite articles, chat with the team and more. Also check out eTeknix YouTube, where you'll find our latest video reviews, event coverage and features in 4K!

Looking for more exciting features on the latest technology? Check out our What We Know So Far section or our Fun Reads for some interesting original features.

eTeknix Facebook eTeknix Twitter eTeknix Instagram eTeknix Instagram
  • Be Social With eTeknix

    Facebook Twitter YouTube Instagram Reddit RSS Discord Patreon TikTok Twitch
  • Features


Send this to a friend
})