Tools of the NSA Playset Ruxcon 2014 Joe FitzPatrick Mike Ryan - - PowerPoint PPT Presentation

tools of the nsa playset
SMART_READER_LITE
LIVE PREVIEW

Tools of the NSA Playset Ruxcon 2014 Joe FitzPatrick Mike Ryan - - PowerPoint PPT Presentation

Tools of the NSA Playset Ruxcon 2014 Joe FitzPatrick Mike Ryan What is the NSA Playset? () nsaplayset.org 3D NSA Playset Price Sheet CONGAFLOCK - <$1 A Retroreflector, which is a passive device that reflects differently when a


slide-1
SLIDE 1

Ruxcon 2014 Joe FitzPatrick Mike Ryan

Tools of the NSA Playset

slide-2
SLIDE 2

What is the NSA Playset?

slide-3
SLIDE 3

()

slide-4
SLIDE 4

nsaplayset.org

3D

slide-5
SLIDE 5

NSA Playset Price Sheet

CONGAFLOCK - <$1

A ‘Retroreflector’, which is a passive device that reflects differently when a monitored wire changes ()

slide-6
SLIDE 6

()

slide-7
SLIDE 7

NSA Playset Price Sheet

TWILIGHTVEGETABLE - $50

Custom Boot environment for basic GSM monitoring

  • Sandisk 16G Extreme USB
  • NooElec RTL-SDL dongle + antenna

3D

slide-8
SLIDE 8

TWILIGHTVEGETABLE

3D

slide-9
SLIDE 9

NSA Playset Price Sheet

LEVITICUS - $50

OsmocomBB Phone for use with TWILIGHTVEGETABLE

  • Motorola C139 phone
  • Osmocom Cable

3D

slide-10
SLIDE 10

LEVITICUS

3D

slide-11
SLIDE 11

NSA Playset Price Sheet

DRIZZLECHAIR - $100

A5/1 Rainbow Tables + Kraken for use with TWILIGHTVEGETABLE

  • WD Elements 2TB USB 3.0 Hard Drive

3D

slide-12
SLIDE 12

DRIZZLECHAIR

3D

slide-13
SLIDE 13

NSA Playset Price Sheet

CHUCKWAGON - $25

I2C implant ()

slide-14
SLIDE 14

CHUCKWAGON

()

slide-15
SLIDE 15

Upcoming Toys in the NSA Playset

() ()

slide-16
SLIDE 16

NSA Playset Price Sheet

FLEABRAIN - $10

USB Cable implant that can store and transmit USB data 3D

slide-17
SLIDE 17

3D

slide-18
SLIDE 18

NSA Playset Price Sheet

DUCHESSRIDE - $45

USB Implant that allows for USB middling ()

slide-19
SLIDE 19

DUCHESSRIDE

()

slide-20
SLIDE 20

Our Favorite NSA Playset Toys:

()

slide-21
SLIDE 21

NSA Playset Price Sheet

TINYALAMO - $10

Bluetooth keystroke surveillance and injection ()

slide-22
SLIDE 22

TINYALAMO

+ PyBT

()

slide-23
SLIDE 23

()

slide-24
SLIDE 24

TINYALAMO Demo!

()

slide-25
SLIDE 25

NSA Playset Price Sheet

SLOTSCREAMER - $100

PCIe Attack Platform

  • USB3380-AB Evaluation Board with custom firmware

3D

slide-26
SLIDE 26

http://www.hwtools.net/PLX.html

SLOTSCREAMER Hardware

slide-27
SLIDE 27
slide-28
SLIDE 28

Diagram: PCIe 2.1 specification

slide-29
SLIDE 29

NSA Playset Price Sheet

HALIBUTDUGOUT - $300

PCIe Attack Platform

  • SLOTSCREAMER enclosed in a Thunderbolt Enclosure

3D

slide-30
SLIDE 30

HALIBUTDUGOUT

3D

slide-31
SLIDE 31

NSA Playset Price Sheet

GUPPYDUGOUT - $200

PCIe Attack Platform

  • Expresscard SLOTSCREAMER in a tiny thunderbolt

enclosure

3D

slide-32
SLIDE 32

GUPPYDUGOUT

3D

slide-33
SLIDE 33

SLOTSCREAMER Demo!

3D

slide-34
SLIDE 34

Building ALLOYVIPER

3D

slide-35
SLIDE 35

Building ALLOYVIPER

3D

slide-36
SLIDE 36

Building ALLOYVIPER

3D

slide-37
SLIDE 37

Building ALLOYVIPER

3D

slide-38
SLIDE 38

Building ALLOYVIPER

3D

slide-39
SLIDE 39

Building ALLOYVIPER

3D

slide-40
SLIDE 40

Building ALLOYVIPER

3D

slide-41
SLIDE 41

Building ALLOYVIPER

3D

slide-42
SLIDE 42

MITMing

3D

slide-43
SLIDE 43

NSA Playset Price Sheet

ALLOYVIPER - $50

PCIe Attack Platform

  • Decoy cable for use with HALIBUTDUGOUT

3D

slide-44
SLIDE 44

Who?

Security Researchers Hardware Hackers Hardware Developers Hobbyists Other Nerds, Geeks, and Dorks* An undercover agent or two* Tinfoil hat wearers*

*presumed 3(D)

slide-45
SLIDE 45

But Why?

Intelligence agencies are not magic

()

slide-46
SLIDE 46

But Why?

If the capability exists, designers need to know to protect against it

3D

slide-47
SLIDE 47

But Why?

‘Nation-state’ capabilities are out of scope. Cheap DIY hacker tools should not be.

()

slide-48
SLIDE 48

But Why?

If any 12-year old can do it, the design flaw will be fixed

3D

slide-49
SLIDE 49

Joe FitzPatrick @securelyfitz joefitz@securinghardware.com https://www.securinghardware.com

Questions?

Mike Ryan @mpeg4codec mikeryan@isecpartners.com https://lacklustre.net

3(D)