10.09.2016 Views

Hacking_and_Penetration_Testing_with_Low_Power_Devices

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

190 CHAPTER 7 Building an army of devices<br />

The X2E-Z3C-W1-A provides two primary configuration <strong>and</strong> management interfaces.<br />

The gateway can be administered by connecting to a Web server on the device.<br />

The default administrative interface is iDigi Manager Pro. The iDigi Manager is a<br />

cloud-based service hosted by Digi. Services way beyond what you are likely to need<br />

for a penetration test are provided by iDigi. More details on this cloud service can be<br />

found at http://www.idigi.com.<br />

There are a number of ways the X2E-Z3C-W1-A can be programmed. The gateway<br />

supports programming <strong>with</strong> the Python language (version 2.7 as of this writing).<br />

Digi provides an integrated development environment (IDE) known as ESP that can<br />

be used to program the device. Not surprisingly, device programming is also available<br />

via the iDigi cloud service. Finally, because the device runs Linux, it may be<br />

programmed from a Linux shell.<br />

PENETRATION TESTING WITH MULTIPLE DRONES<br />

Now that we have a way of remotely controlling drones, we can ratchet up the attack<br />

<strong>and</strong> task multiple drones <strong>with</strong> different parts of the penetration test. Each device can<br />

be used as a wired drone, wireless drone, dropbox, or attack desktop. Phil’s Financial<br />

Enterprises is a bit too small to make the most out of a multidrone attack, so we will<br />

do a penetration test on a new organization.<br />

MEET PHIL’S FUN AND EDUTAINMENT<br />

Phil’s Fun <strong>and</strong> Edutainment Incorporated (PFE Inc.) is a software company that produces<br />

games <strong>and</strong> educational software. The founder of the company, Dr. Phil Starpol,<br />

has grown the company from a one-man organization into a company <strong>with</strong> over 200<br />

employees, the bulk of which are developers.<br />

Phil’s Fun <strong>and</strong> Edutainment primarily produces Linux applications <strong>and</strong> has<br />

recently started creating Android apps as well. Naturally, all of the developers are running<br />

Linux. There are a small number of Windows computers in the organization as<br />

well used by some (but not all) of the sales force <strong>and</strong> some administrative staff. Developers<br />

working on Android apps are issued an Android tablet. All company phones are<br />

Android phones as well. The company has a strict policy that forbids connecting anything<br />

other than a Linux or Android device to the company wireless network.<br />

The company’s office is located on the bottom two floors of an office park on<br />

Chastain Road in Kennesaw, Georgia. Kennesaw is a northern suburb of Atlanta.<br />

This location was chosen because it is close to Interstate 75 <strong>and</strong> a local airport, Cobb<br />

County McCollum Field. Dr. Starpol is an accomplished aviator who often travels<br />

<strong>with</strong> employees in the company aircraft to conferences. The proximity to the interstate<br />

allows clients <strong>and</strong> other visitors to fly in to Atlanta <strong>and</strong> also facilitates international<br />

travel for PFE employees. Additionally, most of the employees live in the area<br />

<strong>and</strong> appreciate the short commute.

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!