Thursday, July 14, 2011

(I)(W) Pwnie device can split your network in the palm of your hand

Just add a touch of Social Engineering and add this to any location, plug it into a wall jack near an ethernet jack, or use the WiFi version if you know or cracked the key. Install by a printer or under a desk would work best and you can start assessing and exploiting a network.

I can tell you from years of experience it would be trivial to get this device installed and talking out a corporate or government network.

This little PC in a brick the size of a power supply packs a punch of tools. The 'Standard' device comes with the following loaded:

:: Includes "Plug UI" for simple web-based setup
:: Tunnels through application-aware firewalls & IPS
:: Sends an SMS message when SSH tunnel is activated
:: Preloaded with Ubuntu, Metasploit, SET, Fasttrack, SSLstrip, nmap, dsniff, netcat, nikto, nbtscan, scapy, ettercap, JTR, medusa, & more!
:: Unpingable and no listening ports in stealth mode

For $320 USD it is cheap for the capability. They also make a Wireless version and 3G version as well and have accessories, which include stickers to make it look like an air freshened or printer power brick.

