254
3 Hardware Trojans in Electronic Devices
Chain letter
In the annual report for 2016, Dr. Web’s specialists mentioned a powerful infection
transmitted in a good old way—via messages. The most popular of such Trojans is
known as Mazar Bot. Here’s how it works: the user opens a link received from
a familiar person (!) and gets into a serious trouble. Such Trojans are created to
get root access; thus, Mazar Bot gains incredible power: it can control your SMS
messages, call the numbers from your list of contacts, change smartphone settings,
connect to the Internet, or simply delete your account and all the data in it.
Banker
Bankers are the most dangerous Trojans for users. These viruses do everything to
intercept the card details in order to empty your bank account. In 2016, Android-based
bankers mostly penetrated smartphones and tablets using the ad platform Google
AdSense.
In conclusion, we would like to note that the best protection from all Trojans,
spies, and other foul things is your head; you just need to be attentive. Also, warn
your dear ones not to open links received from unknown persons or download suspicious applications from markets. If possible, regularly check your smartphone for
vulnerabilities and remember that it is better to scan any downloaded APK with an
antivirus in advance. Observance of these simple rules will increase the level of your
protection from theft.
3.4 Electronic Devices for Wireless Data Interception
As a rule, as soon as people arrive at any venue, or, say, an airport, they immediately
start checking: is there a free Internet connection? At the same time, only few people
know that an open hotspot can actually be a router set in a specific manner that
intercepts all open traffic (this is not technically difficult, since everything passes
through it) and used various types of MITM attacks to intercept data transferred via
the seemingly secure connections.
For greater success, the intruder can use an impressive network name like Wi-Fi
Guest or disguise itself as a popular provider—in this case, there’ll be no shortage of
clients. A fake hotspot (Rogue AP) can be easily installed on any laptop. However, a
device thought out to the last detail, which implements an attack out of the box
in the literal sense, has long been known among hackers. This device is called
WiFi Pineapple; it was invented in 2008. Today, its fourth version is enjoying great
popularity [19].
Devices of the first generation were jokingly disguised as pineapples—this is
where the name comes from. In fact, the device is a regular wireless router (based
on Atheros AR9331 SoC wireless chip and 400 MHz processor), but with special
OpenWRT-based firmware, which includes utilities like Karma, DNS Spoof, SSL
Strip, URL Snarf, ngrep, and others. Therefore, it is only necessary to turn the device
3 Hardware Trojans in Electronic Devices
Chain letter
In the annual report for 2016, Dr. Web’s specialists mentioned a powerful infection
transmitted in a good old way—via messages. The most popular of such Trojans is
known as Mazar Bot. Here’s how it works: the user opens a link received from
a familiar person (!) and gets into a serious trouble. Such Trojans are created to
get root access; thus, Mazar Bot gains incredible power: it can control your SMS
messages, call the numbers from your list of contacts, change smartphone settings,
connect to the Internet, or simply delete your account and all the data in it.
Banker
Bankers are the most dangerous Trojans for users. These viruses do everything to
intercept the card details in order to empty your bank account. In 2016, Android-based
bankers mostly penetrated smartphones and tablets using the ad platform Google
AdSense.
In conclusion, we would like to note that the best protection from all Trojans,
spies, and other foul things is your head; you just need to be attentive. Also, warn
your dear ones not to open links received from unknown persons or download suspicious applications from markets. If possible, regularly check your smartphone for
vulnerabilities and remember that it is better to scan any downloaded APK with an
antivirus in advance. Observance of these simple rules will increase the level of your
protection from theft.
3.4 Electronic Devices for Wireless Data Interception
As a rule, as soon as people arrive at any venue, or, say, an airport, they immediately
start checking: is there a free Internet connection? At the same time, only few people
know that an open hotspot can actually be a router set in a specific manner that
intercepts all open traffic (this is not technically difficult, since everything passes
through it) and used various types of MITM attacks to intercept data transferred via
the seemingly secure connections.
For greater success, the intruder can use an impressive network name like Wi-Fi
Guest or disguise itself as a popular provider—in this case, there’ll be no shortage of
clients. A fake hotspot (Rogue AP) can be easily installed on any laptop. However, a
device thought out to the last detail, which implements an attack out of the box
in the literal sense, has long been known among hackers. This device is called
WiFi Pineapple; it was invented in 2008. Today, its fourth version is enjoying great
popularity [19].
Devices of the first generation were jokingly disguised as pineapples—this is
where the name comes from. In fact, the device is a regular wireless router (based
on Atheros AR9331 SoC wireless chip and 400 MHz processor), but with special
OpenWRT-based firmware, which includes utilities like Karma, DNS Spoof, SSL
Strip, URL Snarf, ngrep, and others. Therefore, it is only necessary to turn the device
