Thursday, March 27, 2014

Remember the saying "Birdie told me" now, the birdie can steal your credentials.



This is a POC , the researchers were able to steal credentials from a Drone.


According to the article:- 

Snoopy, “a distributed tracking and profiling framework," was developed by SensePost Research Lab researchers Daniel Cuthbert and Glenn Wilkinson and was claiming victims by 2012. 

Snoopy was mounted on a quadcopter and flying over London spoofing Wi-Fi networks. The researchers were able to obtain “network names and GPS coordinates for about 150 mobile devices” in less than one hour. They also stole Amazon, PayPal and Yahoo credentials.

Snoopy, like the WiFi Pineapple, can spoof Wi-Fi networks and trick your device into connecting to it.

CNN Money added, “Devices two feet apart could both make connections with the quadcopter, each thinking it is a different, trusted Wi-Fi network. When the phones connect to the drone, Snoopy will intercept everything they send and receive,” including passwords, usernames, sites visited, credit card numbers entered, and location data. Snoopy also scoops up the MAC address, tying the traffic to a specific device. The researchers were even able to track a phone to the owner's home.


The links below has more information:-

No comments:

Post a Comment