Hacker News new | ask | show | jobs
by dingaling 2712 days ago
> Also, using a nice "black box" that looked like a sort of electronic device

Disguised as one of those generic thermostat boxes on a wall it'd go unnoticed by 99.999% of people. Bonus points for a twiddly wheel.

4 comments

Or even better: find an old ethernet switch, gut it (but keep the connectors) and put Raspberry PI inside. You will need to solder 6 wires for ethernet and power, but the pins are fairly large so this should be easy.

Even if discovered, most people would not bother taking it apart --- they'll just assume it is broken and throw it away.

This is exactly what I was thinking. Even the network admin would probably be like, "well, I don't think so but I'd better not mess with it, just in case it's how the CEO is getting internet". Unless of course they engineered the network originally.
Or as a PoE injector. Even better is to make it piggyback on an actual PoE injector plugged into legitimate hardware.
I have a 4 outlet "surge protection" power board with a Pi Zero W, and USB power supply, and 4 240V mains relays and drivers all neatly tucked/hidden inside... I use it as Wi-Fi controllable power points, not for pen testing, but at this stage that's just a software update...
Or a power plug...

Article: https://www.hln.be/regio/antwerpen/rechter-straft-it-special...

Check out the image in the article. They attached keyloggers and sent the strokes to the box. Saving them and once in a week dump them over to a car in the parking lot.

The original article is great, but the guy was really not putting any effort into it.

Or a box with a high voltage warning sticker. Unlikely anyone will want to toy with it.
A high voltage warning sticker is likely to gather a lot of attention, especially inside a network closet.

There are many rules related to where high voltage stuff should be, how it should be installed and who can access it. And unless you do it by the rules (unlikely), it will get caught up during a safety inspection.

Okay what about one of those biohazard stickers then?
The goal is to avoid being noticed or drawing attention. Do you really think a biohazard sticker in a server closet wouldn't draw attention?
Probably just the "meh, another wannabe logo" type - abuse of nuclear/biohazard warning signs is becoming an issue.

https://99percentinvisible.org/article/biohazard-symbol-desi...