21 ms·
The curious case of the Raspberry Pi in the network closet (2019)
- pantalaimon 5y agoThe nRF52832-MDK has neither WiFi nor RFID capabilities
- barbegal 5y agoThe chip has 13.56MHz RFID capabilities but obviously needs to be attached to an appropriate antenna which this dongle does not have.
- JoeAltmaier 5y agoSure it does! https://wiki.makerdiary.com/nrf52832-mdk/ https://wiki.makerdiary.com/nrf52832-mdk/
- BlueTemplar 5y agoBecause you can use the 2.4 Ghz chip antenna for anything you want to, including WiFi ?
- geek_at 5y agoAuthor of the article here. Since I first published this blog post I was getting messages from people asking how it ended. Sadly it's pretty anticlimactic as the owner of the place had a meeting with the guy who put the Pi there (without me as he didn't want the Pi-dropper to feel ambushed) and in the end decided not to escalate it to legal and just basically told him to pack his things and get out. So no legal after play and just a slap on the wrist
- helsinkiandrew 5y agoWould have been interesting to see what they were doing - nRF52832-MDK doesn't have wifi - perhaps the person was scanning/logging bluetooth devices.
- deleted 5y ago[deleted]
- qngcdvy 5y agoDid you ever find out what it did there exactly? Like, what it collected and what the "gifted person" wanted to do with that data? edit: Thanks for the write-up btw. Was a nice read, although a bit short (which is the story's fault I guess)
- deleted 5y ago[deleted]
- xattt 5y agoIs “gifted person” code for something? Are they from some sort of enrichment program?
- xwdv 5y ago“Gifted” individuals are selected at early ages to run through rigorous education programs that greatly push them ahead of their peers. It is a pipeline to create intellectual elites and captains of industry. Gifted kids are widely accepted as the most intelligent kids of a school and held up as the finest examples of the school’s educational abilities.
- bitexploder 5y agoDo kids in gifted programs go on to become intellectual elites and “captains of industry” at higher rates than their peers?
- didericis 5y agoGood question. The programs themselves are generally good, as far as I’ve experienced, but the culture around them is often quite toxic. Many kids are treated like race horses. I’m not sure how effective they are on net. Most highly successful people seem like autodidacts that end up finding the resources they need one way or another. Would guess the best way to create more of those people is just to keep a lot of doors open and hope someone like that walks through.
- gwd 5y ago> So no legal after play and just a slap on the wrist The problem with this is you have no idea what harm the guy actually may have caused; nor what other RPis he may have set up around the company or around town. Next time he may be more careful with his username, set up the disk to be encrypted w/ a network key, &c, making future exploits more difficult to track down.
- discardable_dan 5y agoThis, truly, is the thing to worry about: if it happened here, it likely happened at other companies. Turning a blind eye is a blank check to do it again.
- etothepii 5y agoThe issue here is that this isn't just "one bad apple" that if we can remove everything will be ok. Which is what motivates the idea that punishing this bad actor will make everything better. There is a systematic issue at the heart of the way we do network security. You can by a lighting / usb cable that can do all of these things and more for $120 if he'd used that he'd never have gotten caught. We treat network security like physical security at our peril.
- Ensorceled 5y ago> The issue here is that this isn't just "one bad apple" that if we can remove everything will be ok. Which is what motivates the idea that punishing this bad actor will make everything better. I think they are talking about this particular, singular, bad apple and the other companies that bad apple is also attacking right now and stopping that harm as opposed to "sending a message" to other bad apples.
- etothepii 5y agoThat feels like a choice for the victim. If after the business owner sat down with the perpetrator they decided it is just some script kiddie playing at being a spy then that's up to them. The wider issue remains that some script kiddie with $120 could have done this and got away with it for ever.
- makach 5y agoomg, that guy got of the hook easy. he should play the lottery considering how lucky this was.
- Chris2048 5y ago> told him to pack his things and get out I though the suspects were an ex-employee, and some guy that didn't work there (the part-owner), so was an actual current employee implicated in the end?
- pdpi 5y agoMy understanding is: ex-employee bought/acquired the device from the "gifted guy"/part-owner, and deployed it in the network cabinet by using the key he still had.
- smcl 5y agoAn ex-employee who still had a key to the office so they could move some stuff they had there. Presumably that courtesy was immediately terminated and the key was returned.
- Chris2048 5y agooooh, I didn't realise they still had the key at that point. OK, I wouldn't have even said that - I'd have asked for the key back and boxed the remaining stuff myself. TBH, I'm surprised to what extend the employee would of had a bunch of stuff there - did they have furniture there or something?!
- smcl 5y agoYeah it sounds like the person was on good terms with the company and was trusted enough, must have stung for whoever made the decision to trust the ex-employee to be sorta betrayed like that. The blog author is somewhere in the comments here, I don't know if they're willing to share much more info but let's see what they say.
- Chris2048 5y agoSo the article mentions: > It was registered (or first deployed or set up?) on May 13th 2018 and the post itself is dated 2019-01-16 Since it says: > he could still have a key for a few months I assumed that by then the employee had given back the key, but I guess I was making a few assumptions about when this happened, and when the device had been installed - they don't actually say what date the RADIUS logs revealed they had accessed the network.
- perfopt 5y agoAs I was reading this I was hoping for modern day Cuckoo's Egg. But it was not to be. Great write up. Thanks for sharing.
- danesparza 5y agoFor anybody wondering, the Cuckoo's Egg (written in 1989 by Cliff Stoll) is a wonderful read about tracking an early hacker. I highly recommend it.
- Joe_Boogz 5y agoThanks for the recommendation
- kumarvvr 5y agoSeem pertinent to atleast get an affidavit from the ex-employee detailing what he as done, agree to hold on to the hardware as evidence, put liability on the employee for any time-bombs that might have been stored, ask him explicitly to give in writing all the activities he performed, etc. Just to have a thread to pull on, in the future, when something might go wrong.
- geek_at 5y agoWe did get a hand written statement from him and the original evidence (hardware) is still untouched and locked away. In his statement he wrote that the pi logged to the SD card but there was no data on the SD card (well not on the data partition) and I'm pretty sure that was a lie and it just logged to Balena. But even though we could never decipher what the nodejs program actually did (because it was so heavily obfuscated) our internal working theory is that he was tracking the movement data of the boss to avoid him whenever possible.
- Abimelex 5y agohow hard can you obfuscate nodejs? I'm pretty sure if you drop the code in some infosec channels they will happily take the challenge and tell you what it does ;)
- TedDoesntTalk 5y agoAn easier solution might be to look at the packets the nodejs program is sending over the network (if you can configure a MITM)
- vorticalbox 5y agoIts package.json and / or node_modules might also give some clues
- ChuckNorris89 5y ago>he was tracking the movement data of the boss to avoid him whenever possible. Wow, imagine hating your boss so much you go to so much creative and illegal lengths (that can backfire against you) to track him, instead of using same skills legally to finding a better job. I just don't get, something doesn't feel right about this being the true reason. To me it looks more like he wanted a covert backdoor in the company network for IP-theft, black-mail or other such data exfiltration purposes. If only he knew that in a year he could avoid his boss all the time thanks to covid-WFH.
- causality0 5y agoShoot, with the info you got I'd have least called his parents and tattled on him. If you can't put him in jail at least embarrass the shit out of him.
- rheophile 5y agopost the nodejs in a git repo so we can see what he was doing.
- deleted 5y ago[deleted]
- cerved 5y ago> cat config.json | jq cries in UUoC
- JKCalhoun 5y agoSo, not just a Pi-Hole as I immediately first assumed.
- 2Gkashmiri 5y agonow i guess a smaller pi zero can do this with a much smaller footprint
- gambiting 5y agoPi Zero doesn't have an ethernet port, so you have the size of the pi+ethernet adapter then.
- JKCalhoun 5y agoTechnically, I believe Pi-Hole works over Wi-Fi as well: that is, you can have the Pi Zero running Pi-Hole connect to your router via Wi-Fi. Then all your devices connect to the Pi Zero for their internet access. I could be mistaken though; only over installed on a Pi 3.
- jq-r 5y agoYou're right. I have a Pi Zero W which runs Pi-Hole over wifi. My mobile devices use it as a DNS server.
- drewzero1 5y agoI've been playing around with orangepi zero for when I just need ethernet, wifi, and USB. It fits in an Altoids tin with room for some cable management.
- poopsmithe 5y agoAh damn, I didn't want the story to be over. That was a good read!
- phnofive 5y agooriginal discussion, 154 comments: https://news.ycombinator.com/item?id=18919129 https://news.ycombinator.com/item?id=18919129
- can16358p 5y agoThat one really felt like a written-version of a Mr. Robot episode. Lovely!
- ranma42 5y ago> they identified the dongle as a microprocessor, almost as powerful as the Rasberry Pi itself Well, its more like an order of magnitude slower than the Pi (and with a lot less RAM as well) > A very powerful wifi, bluetooth and RFID reader. It's 2.4GHz, but only BLE and custom protocols (2 Mbit max, GFSK modulation). The SoC can do RFID, but you have to connect a transmitter coil to use it, which doesn't seem to be the case from the photo. I'd guess this was just used as a remote control backup connection if LAN is not working?
- cf141q5325 5y agoMaybe a 6lowpan interface for maintenance. This way he could interact with it from inside the room without having to access the closet.
- HeyLaughingBoy 5y agoThat puzzled me too. I didn't remember the 52832 having WiFi, but I figured it was just faulty memory. I think the dongle might just be Nordic's cheap evaluation board.
- jokoon 5y agoI'm rather curious, why can't the RPi have soldered flash memory? How much would it cost to add 2, 4, or 8GB of flash memory on it? Because I would gladly pay for a Rpi with such memory if it added 10 dollars. I'm suspecting it would require for them to make a new SOC, breaking compability?
- gambiting 5y ago>>Because I would gladly pay for a Rpi with such memory if it added 10 dollars. That's the problem with the entire RPi ecosystem - there's a lot of things people want "even if it only adds another few dollars". Another ethernet, proper m.2 port, better audio, so-dimm slot etc etc etc.... The Rpi is meant to be cheap. Yes it means that it might not include the feature that you want. And no, "just making it a little bit more expensive" is not the solution here. It's already gotten way too expensive for what is was meant to be originally. And if you really want a Pi with built in flash, then the compute module has that: https://www.raspberrypi.com/products/compute-module-4/?variant=raspberry-pi-cm4001000 https://www.raspberrypi.com/products/compute-module-4/?varia...
- michaelt 5y agoUsing an SD card means you can reset the Pi to factory settings by swapping the card for another; and undo the reset by swapping the cards back. This is substantially simpler for beginners than using network boot, or messing around with a bootloader via serial console.
- Sebb767 5y agoAdditionally, as split root storage setup because the boot partition is small is a lot more complicated than simply buying a 64GB+ sd card and (usually) have no storage problems.
- goodpoint 5y agoHaving an 8GB eMMC does not preclude having an SD slot. Any beginner can plug in an auto-installer on the SD card and use the same SD for different devices. Simpler and cheaper. If that's not enough, the eMMC could even come preinstalled with an OS.
- mypastself 5y agoGripping! Would love to read more articles in this “genre”. I’m wondering if there was an easy way for the attacker to encrypt or obfuscate some of these configuration files, so that defenders can’t extract settings even when physically connected to the device.
- 8192kjshad09- 5y agoSome malware will store the executable and all configuration encrypted on the disk and will only decrypt in memory with a key downloaded from the internet. Ofcourse you can still defeat this if you dump the memory or reverse engineer the process to get the key yourself. Makes it a bit harder but still not impossible.
- suifbwish 5y agoUnless the disk has some way of checking the hash sum of its own file structure before execution, additional debug, logging scripts can be added which load at boot time and record the entire process. It’s a cat and mouse game.
- soldeace 5y agoThe investigative work in that piece reminds me of this old case: https://www.youtube.com/watch?v=OAI8S2houW4 https://www.youtube.com/watch?v=OAI8S2houW4
- fmajid 5y agoRead The Cuckoo's Egg by Cliff Stoll. An oldie but a goldie.
- mypastself 5y agoI’ve owned a copy for a while now. This might just be the push I needed to pick it up.
- BLKNSLVR 5y agoI read the whole book over a long weekend, I just couldn't put it down. Make sure you don't have any work deadlines in the few days after you start it.
- mschuster91 5y agoI do wonder when the first "smart SFP" with embedded wi-fi appears - an unlabeled RPi in a junction box raises alarms, but a SFP module that's just a bit longer than the rest? Many would rather assume on first glance that accounting bought some cheaper crap due to delivery chain issues. (For those OOTL, see https://blog.benjojo.co.uk/post/smart-sfp-linux-inside https://blog.benjojo.co.uk/post/smart-sfp-linux-inside - it made the rounds on Twitter and HN a couple days ago)
- bopbeepboop 5y ago
- BlueTemplar 5y agoOOTL ? This reminds me of a discussion I've seen... when the Pi first came out I think ? About how we could soon make whole electric kettles or even keyboards (and Pi recently did it !) with whole spying (on wireless) computers built into them, unbeknownst to people not aware of that "extra functionality". (IIRC with the context of potential Chinese spying ? The current reality is a bit more prosaic : USA can likely just use the backdoors (they likely have) in Intel CPUs (or Windows), and the Chinese - in Huawei's networking gear.)
- deleted 5y ago[deleted]
- magicalhippo 5y agoReminds me of this[1] good old quote from the IRC days <erno> hm. I've lost a machine.. literally _lost_. it responds to ping, it works completely, I just can't figure out where in my apartment it is. [1]: http://bash.org/?5273 http://bash.org/?5273
- wink 5y agoI've also had this problem once, on a university campus though. "net send <host> 'If you can read this, please call IT SUPPORT at ... and tell us'". It worked :)
- tinus_hn 5y agoThis should really only ever happen with wireless connections. You should always be able to tell what switchport a computer is connected to and work from there.
- mrspuratic 5y agoSwitch port? Jump back a few decades and try combined kilometers of shared coax runs that effectively become embedded into a building over years of redecoration...
- growt 5y agoAnd then? The cable disappears into a wall together with 100s of other cables (which most likely are not labeled or not correctly, otherwise you wouldn't have lost the machine in the first place)
- suifbwish 5y agoIt is completely irresponsible and without excuse for any main network operator/owner to not be completely aware of what each and every cable does which is connected to a switch/network router. If the owner refuses to determine this, they are responsible if there is a nefarious device on the network until they do. Wireless makes this much more complicated so any responsible admin will ensure the wireless network is completely isolated from the physical network and is privileged to only access the internet or separate devices.
- azalemeth 5y agoThat's a very obvious and very obviously bad way of planting a network exploit. Very rookie and rather sad. In entirely unrelated news, this guide details how to set up an encrypted boot process on a raspberry pi, with it waiting for you(r forked login agent) to ssh in and provide the LUKS password: https://github.com/ViRb3/pi-encrypted-boot-ssh https://github.com/ViRb3/pi-encrypted-boot-ssh
- suifbwish 5y agoWithout reverse ssh wouldn’t you need to be directly on the same network to do so?
- ertian 5y agoI was setting up an encrypted-root system with ssh access to pass the passphrase, and got reading. It looks like an initrd image can connect to a VPN or set up a Tor hidden service these days. I didn't try it, though.
- egypturnash 5y agoThe whole part with it being tracked back to a site for G/T kids makes it sound like this was a young person somewhere in the range between "script kiddie" and "beginner hacker", so "rookie" sounds about right. Bored teen or twentysomething with time to kill and an interest in computers.
- kingcharles 5y agoIt was the parent of the child who planted the bug.
- juanse 5y agoI would literally read one of these story every day before going to sleep. I will never have enough. Amazing read!
- inshadows 5y agoThis article was shared here before and since then I was failing to find it again. Thanks for reposting!
- eertami 5y ago>And what do we do, when we want to find out a location associated with a wifi name? We go to wigle.net, enter the SSID (=wifi name) and it tells us where on the world it is found. I've always enjoyed having unique/personal SSIDs, but had never seriously considered this consequence. I wonder what the worlds generic SSIDs are.
- jon-wood 5y agoIf you're ok with people's devices making attempts at connecting, eduroam, or some variant of Starbuck's Wifi might be good options. There'll be APs broadcasting those SSIDs all over the world.
- Hamuko 5y ago"Home" returns quite a lot of results in my area on Wigle.net despite the fact that English isn't an official language here. You can probably pick and choose any generic Wi-Fi router manufacturer name. "Linksys" paints the map pretty well.
- tgsovlerkhgsel 5y agoThere's a good chance he could have also recovered a MAC from logs etc. What's more important is that you don't set your SSID to hidden: Someone needs to broadcast the SSID for the connection to work, and if it isn't the AP, it will be your mobile device broadcasting it everywhere you go!
- fnord77 5y agohttps://wigle.net/stats#ssidstats https://wigle.net/stats#ssidstats
- CGamesPlay 5y agoConsequence of the generic SSID is that your device will try to connect to any instance of this SSID and re-prompt for a password when it fails to do so.
- egypturnash 5y agoA little browsing around wigle.net brings me to a page listing SSIDs and manufacturers: https://wigle.net/stats#ssidstats https://wigle.net/stats#ssidstats xfinitywifi is the top, with 2% of the routers seen having that name; it's followed by XFINITY (.73%), BTWiFi-with-FON (.38%), linksys (.37%), BTWifi-X (.35%), <no ssid> (.31%). The next one is AndroidAP at .28% and that feels like a good place to stop copying data, go look at the page if you wanna see more of the world's generic SSIDs. Basically "manufacturer name" and "internet provider name" dominate.
- BXWPU 5y agoReminds of this: https://www.youtube.com/watch?v=UeAKTjx_eKA https://www.youtube.com/watch?v=UeAKTjx_eKA
- boringg 5y agoThanks OP - great read. Seems like a very sloppy network logger - I mean there's a whole raspberry pi for physical evidence! True there are probably a lot of other network hardware so it could hide in plain sight. Either way fascinating that they thought they could get away with it.
- mrtesthah 5y agoYou have to wonder why they didn’t rather create a transparent bridge on the network whose traffic they were trying to log; such a device could’ve even been hidden along a network cable.
- mabbo 5y agoWhile the device itself is sloppy, for many organizations it's probably easier to install and less likely to be detected than a software-based attack. How frequently does IT run scans of what software is running on the server vs how often does IT physically inspect the server? Remember, one of those things means I have to get up out of this chair and the other does not.
- goodpoint 5y agoReminder (from a security guy): what the author did is risky. If you are really worried about a compromised server or a suspicious device call security consultant / forensic experts.
- aembleton 5y agoWhat are the potential risks around what he did?
- fatbird 5y agoMalware triggered by its absence? If the device disappears, it's likely because it was found and removed, so malware that starts erasing data or otherwise causing confusion or covering their tracks is a plausible next step (though not a good one in this case, given that the device itself led straight to the person who planted it).
- goodpoint 5y ago- Being suspected or charged of destruction of evidence. It happened. - Losing access to forensic data by not capturing the contents of the device RAM. Pretty common. - Becoming witness of a crime and getting personally targeted by some criminal organization in retaliation. This one should be obvious. - Wasting the opportunity to keep the device on to monitor the activity of the intruder
- neilv 5y agoI was a confused by a screenshot in the article, with the caption: > Not the actual site but a similar one Looks like the article, when speaking of tracing down a wrongdoing suspect, used a screenshot of a Web page of an uninvolved Web site. The screenshot included photos of actual people presumably uninvolved, and a name, phone number, and email address also presumably uninvolved. While I'd guess this probably reduces Internet vigilantism and accusations of libel (at least involving the actual suspect), I suspect that a journalism professor, editor, or lawyer would advise not to do it that way.
- deleted 5y ago[deleted]
- marcodiego 5y ago> [...] I got a message from my dad [...] I asked him to unplug it, [...] and to make an image from the SD card [...] What a technical dad you have!
- tlamponi 5y ago> What a technical dad you have! Working for over 35 years for IBM and inspiring BASIC/REXX to ones child may do the trick -> https://blog.haschek.at/about/ https://blog.haschek.at/about/
- tacticaldev 5y agoThis story sounds so familiar; did this get posted 3-4 years ago? Good story and good sleuthing tho.
- smm11 5y agoOnce found a Linksys Wifi router under a desk, the employee was using it to check their Hotmail. I was pretty impressed they knew to switch their network connection to wireless, but it WAS still on our network.
- soheil 5y agoI honestly think instead of the username if an email was found and published the author would be receiving so many offers for work from Silicon Valley companies. There aren't that many talented engineers even in SV who could pull something like this off. Sad to see amoral behavior from otherwise smart creative people who're stuck in shitty jobs with shittier bosses.
- HeyLaughingBoy 5y agoAre you serious? Monitor BLE traffic, filter it to a known device (his boss') and update an IoT server with that information when it changes? On an RPi, that's not even an afternoon of work. I mean, it's cool and I would definitely want to interview someone who did this, but it's hardly "hire this person now!!!" material.
- andygroundwater 5y agoWas working with a NOC technician who was responsible (along with some others) for a pretty large EMEA mobile network, with many millions of subscribers. There was an RFP to update their SMS/MMS system and a certain Israeli company came in to do a site survey, or installation or something in the network data center. Anyway the long and the short of it was one of their technicians was caught with the previous vendor's SMS-C prized open and some USB device insert into it. Similar response to this, a lot of hollering and hair pulling, but ultimately no contractual or legal implications. I guess it happens higher up the food chain too.
- WelcomeShorty 5y agoPR makes it possible. I have personally identified more than a handful of employees who'd use their work computers for... let's say "access to inappropriate content". All of them where invited by HR & legal and let go with a more then decent deal. Absolutely everything was done to prevent the company being associated with anything nasty.
- srram 5y agoReminds me of the time our head of networking came into the lab (early 2000's) asking about why our lab had '70% of the company's total outbound traffic'. Turns out that one of our sysadmins was running a porn server in the DMZ
- anonymousiam 5y agoSomething like this is less likely to be noticed: https://arstechnica.com/information-technology/2012/03/the-pwn-plug-is-a-little-white-box-that-can-hack-your-network/ https://arstechnica.com/information-technology/2012/03/the-p...
- amelius 5y agoSame category as those keylogger USB plugs.
- kekebo 5y agoAs for deobfuscating JS, I've often had good experiences using http://jsnice.org/ http://jsnice.org/ ("Statistical renaming, Type inference and Deobfuscation")
- teddyh 5y agoThis sounds like one of the classic stories by SecurityMonkey a.k.a. Chief: https://web.archive.org/web/20191006220253/https://it.toolbox.com/blogs/chiefmonkey/official-securitymonkey-case-file-index-022707 https://web.archive.org/web/20191006220253/https://it.toolbo... The individual stories seem to be still available on the non-archived web here: https://www.toolbox.com/user/about/ChiefMonkey/ https://www.toolbox.com/user/about/ChiefMonkey/ but not, from what I can find, the convenient story index, which I linked to above. He seems to have planned a rewrite of all the stories and put them on… Medium.com: https://medium.com/@chiefsecuritymonkey https://medium.com/@chiefsecuritymonkey However, the last update is from May, 2020.
- amelius 5y agoHeard a story about some ethernet device cemented into a wall, perhaps on HN. Good luck finding that ...
- Jolter 5y agoOnce upon a time when Zigbee was the latest hype, a friend worked on a project to cast cheap hygrometer sensors into concrete and have them report via a mesh network. Apparently sensors were predicted to be cheaper than to have an engineer walk the site taking readings to ensure it’s ok to start covering it up.
- jve 5y agoWhat a missed opportunity here. By publishing that obfuscated code, top notch specialists would have untangled it for you just for the sake of satisfying their curiosity. Speedrunning their way until it is crystal clear about what the device purpose was. And completely for free.