Direction territoriale Sud Ouest
Silent Wire Hacking
Hack In Paris 2018
Hack In Paris - 2018
erwan.broquaire@cerema.fr pierre-yves.tanniou@cerema.fr
Silent Wire Hacking Hack In Paris 2018 erwan.broquaire@cerema.fr - - PowerPoint PPT Presentation
Silent Wire Hacking Hack In Paris 2018 erwan.broquaire@cerema.fr pierre-yves.tanniou@cerema.fr Hack In Paris - 2018 Direction territoriale Sud Ouest Silent wire hacking ? You know about TCP hijacking, 802.1x bypass techniques
Direction territoriale Sud Ouest
Hack In Paris 2018
Hack In Paris - 2018
erwan.broquaire@cerema.fr pierre-yves.tanniou@cerema.fr
Hack In Paris - June 28th 2018 2
– TCP hijacking, – 802.1x bypass techniques (Valérian Legrand, HIP 2017), ways to exploit a MITM position with Fenrir
– …
– to connect to an ethernet 100Mb cable, – in order to take the man in the middle position – without any warning in supervision :
A silent wire hacking
Hack In Paris - June 28th 2018 3
Hack In Paris - June 28th 2018 4
From the ground… ...to the ceiling
Hack In Paris - June 28th 2018 5
Hack In Paris - June 28th 2018 6
Hack In Paris - June 28th 2018 7
Hack In Paris - June 28th 2018 8
Hack In Paris - June 28th 2018 9
network
Hack In Paris - June 28th 2018 10
network
Hack In Paris - June 28th 2018 11
network
back to standards and datasheets
Hack In Paris - June 28th 2018 12
Ethernet 100Mb/s link
– No link_down link_up – No snmp trap – No RSTP topology change – No LLDP detection
Hack In Paris - June 28th 2018 13
Hack In Paris - June 28th 2018 14
Signal conditioning with operational amplifiers? Classic OA (lm341, lf355): gain.band<10MHz DIY → no surface mounted components Signal manipulation activated by relays, Data manipulation with Raspberry
Hack In Paris - June 28th 2018 15
Hack In Paris - June 28th 2018 16
– Mac @ – IP @ – speed – existing protocols: RSTP, LLDP, SNMP, ETC.
Hack In Paris - June 28th 2018 17
Hack In Paris - June 28th 2018 18
Hack In Paris - June 28th 2018 19
the connection would require a crossover and automatically chooses the MDI or MDI-X configuration to properly match the other end of the link
→ To witch side affect collected data? Witch ip@ and mac@ belongs to witch device?
Hack In Paris - June 28th 2018 20
Tx+ Rx+ Rx+ Rx- Rx- Rx- Rx- Tx- Rx+ Tx- Tx- Tx- Tx+ Tx+ Tx+ Rx+
Hack In Paris - June 28th 2018 21
Hack In Paris - June 28th 2018 22
Hack In Paris - June 28th 2018 23
Hack In Paris - 28 june 2018 24
Hack In Paris - 28 june 2018 25
Hack In Paris - June 28th 2018 26
traffic
Hack In Paris - June 28th 2018 27
Hack In Paris - June 28th 2018 28
Hack In Paris - June 28th 2018 29
Hack In Paris - June 28th 2018 30
Hack In Paris - June 28th 2018 31
Hack In Paris - June 28th 2018 32
communication to devices with:
– Same speed – Quiet (no-RSTP, no-LLDP, etc.)
*5ms (relay switching time; Mosfet would be much quicker)
Hack In Paris - June 28th 2018 33
...how to ?
Hack In Paris - June 28th 2018 34
transition:
– High enough to keep the link up – Low enough to be considered as noise / signal
Hack In Paris - June 28th 2018 35
Hack In Paris - June 28th 2018 36
strips, checking...
to fix it :(
Hack In Paris - June 28th 2018 37
(we will just have to do some steps manually)
Hack In Paris - June 28th 2018 38
– Insertion of the electronics – Identification of Rx and Tx wires – Switching to well-configured devices – Diming legitimate signal during switching
Hack In Paris - June 28th 2018 39
– 2 Raspberry Pi: 120€ – electronics: 80€ – (managable switches: 250€) – candy: 5€
…Hacking : priceless
Hack In Paris - June 28th 2018 40
ethernet configuration
Hack In Paris - June 28th 2018 41
– difficult to implement in real world: Many existing EM perturbations (events on high power lines, lightning, lorries with electromagnetic retarders...) → Not suitable for plants, infrastructure operators...
Hack In Paris - June 28th 2018 42
erwan.broquaire@cerema.fr pierre-yves.tanniou@cerema.fr