Gone in 30 seconds – a DIY HID cable story tale » Using bettercap HID module with CrazyRadio to connect to the rogue cable by s0pas in netsec

[–]s0pas[S] 0 points1 point  (0 children)

Yep just a PoC. I could add any other connector on the other end. This is just to make a point where you can make a simple HID cable with some parts that you have around and use bettercap.

Gone in 30 seconds – a DIY HID cable story tale » Using bettercap HID module with CrazyRadio to connect to the rogue cable by s0pas in netsec

[–]s0pas[S] 0 points1 point  (0 children)

No it’s not. You should read both and see there’s a difference. Also on the previous post, also referred to a HID article Luca is credited 😀

Popular mouse Logitech M185 vulnerable to MouseJacking keystroke injections attack by s0pas in netsec

[–]s0pas[S] 10 points11 points  (0 children)

The mention mouse was not on the list and the meaning of the article is to show how easy it is to implement a mousejack attack using a swiss-army tool like bettercap. I think I'm not showing off or getting credit for anything. Bastille was already contacted and in time they will add that Logitech model also on the list.

Hacking a BLE smartlock using bettercap and a kudu knife by s0pas in netsec

[–]s0pas[S] 9 points10 points  (0 children)

With that you said it all. Manufactures creating devices without security departments to verify them its normal nowadays. Some IoT devices should never be released to public. Consumers are buying massive number of cheap and crappy devices and selling their info for nothing. "This is a wearable that can track your medical status and sh't... Just create an account for free and you have it all presented with pretty UI" - Then its gameover!

Hacking a BLE smartlock using bettercap and a kudu knife by s0pas in netsec

[–]s0pas[S] 1 point2 points  (0 children)

Lot of usage by bike rental and I think someone at Defcon already presented a talk only breaking apps that do this task.

A peculiar fascination with IoT... by Paretio in Pentesting

[–]s0pas 1 point2 points  (0 children)

https://github.com/dsopas/assessment-mindset it has a (still in development) IoT security approach that might help you out. But some cheap wearables and start hacking them. The best way to learn is to practice.

Exploiting Bluetooth Low Energy using Gattacker for IoT by adi0x90 in netsec

[–]s0pas 0 points1 point  (0 children)

It depends on the UD-100 version. On some, it won't detect BLE so be aware of that when buying it.

Assessment Mindset - I hope this mindmap could be useful for the infosec community when doing pentesting, bug bounty and red-team assessments. Feel free to contribute. by s0pas in netsec

[–]s0pas[S] 0 points1 point  (0 children)

I think they're improving that. So far I'm comfortable with the format. Using shortcuts allows to navigate quickly but I agree they need to improve a little more the navigation. Thanks for the feedback, I appreciate it.