<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
	<id>https://elvis.hcw.ac.at/wiki/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=FPaschinger</id>
	<title>Elvis Wiki - User contributions [en]</title>
	<link rel="self" type="application/atom+xml" href="https://elvis.hcw.ac.at/wiki/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=FPaschinger"/>
	<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php/Special:Contributions/FPaschinger"/>
	<updated>2026-09-10T19:41:36Z</updated>
	<subtitle>User contributions</subtitle>
	<generator>MediaWiki 1.41.5</generator>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=Saleae_Logic_Analyzer_Setup&amp;diff=11505</id>
		<title>Saleae Logic Analyzer Setup</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=Saleae_Logic_Analyzer_Setup&amp;diff=11505"/>
		<updated>2023-02-20T13:33:47Z</updated>

		<summary type="html">&lt;p&gt;FPaschinger: Created page with &amp;quot;== Summary ==   This article shows how the Saleae Logic Analyzer is set up.  == Requirements ==  * Operating system: Windows 10 * Software: Logic 2.4.4 (or newer versions)  == Description ==  === Step 1 ===  Download the software for analyzing the traffic captured on the digital circuit:  * Go to https://www.saleae.com/downloads/ * Click on &amp;quot;Download for Windows&amp;quot; * The download starts automatically * Follow the instructions of the installation wizard  === Step 2 ===  * C...&amp;quot;&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Summary == &lt;br /&gt;
&lt;br /&gt;
This article shows how the Saleae Logic Analyzer is set up.&lt;br /&gt;
&lt;br /&gt;
== Requirements ==&lt;br /&gt;
&lt;br /&gt;
* Operating system: Windows 10&lt;br /&gt;
* Software: Logic 2.4.4 (or newer versions)&lt;br /&gt;
&lt;br /&gt;
== Description ==&lt;br /&gt;
&lt;br /&gt;
=== Step 1 ===&lt;br /&gt;
&lt;br /&gt;
Download the software for analyzing the traffic captured on the digital circuit:&lt;br /&gt;
&lt;br /&gt;
* Go to https://www.saleae.com/downloads/&lt;br /&gt;
* Click on &amp;quot;Download for Windows&amp;quot;&lt;br /&gt;
* The download starts automatically&lt;br /&gt;
* Follow the instructions of the installation wizard&lt;br /&gt;
&lt;br /&gt;
=== Step 2 ===&lt;br /&gt;
&lt;br /&gt;
* Connect the wires with the logic analyzer  &lt;br /&gt;
** The black wires represent GND which are connected to the lower part of the channels&lt;br /&gt;
* Connect the Logic Analyzer via USB to the PC or Laptop&lt;br /&gt;
&lt;br /&gt;
=== Step 3 ===&lt;br /&gt;
&lt;br /&gt;
* Open the Logic 2.4.4 (or newer versions)&lt;br /&gt;
* The device should connect automatically&lt;br /&gt;
* [[File:Logic 2.4.4 Start.png]]&lt;br /&gt;
&lt;br /&gt;
On the right side the 8 channels are listed with colored backgorunds. In this case the Saleae Logic Analyzer 8 provides 8 channels of which each channel can be activated/deactivated individually by clicking the corresponding button. On the navigation bar of the software the category &amp;quot;Capture&amp;quot; is found. When clicking on it, the option &amp;quot;Start/Stop Capture&amp;quot; is shown. After clicking &amp;quot;Start/Stop Capture&amp;quot; the analyzer starts capturing.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[File:Logic 2.4.4 Capture.png]]&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
* https://www.saleae.com/downloads/&lt;br /&gt;
* https://support.saleae.com/getting-started/setup&lt;br /&gt;
&lt;br /&gt;
[[Category:Documentation]]&lt;/div&gt;</summary>
		<author><name>FPaschinger</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=File:Logic_2.4.4_Capture.png&amp;diff=11504</id>
		<title>File:Logic 2.4.4 Capture.png</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=File:Logic_2.4.4_Capture.png&amp;diff=11504"/>
		<updated>2023-02-20T13:27:34Z</updated>

		<summary type="html">&lt;p&gt;FPaschinger: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;/div&gt;</summary>
		<author><name>FPaschinger</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=File:Logic_2.4.4_Start.png&amp;diff=11503</id>
		<title>File:Logic 2.4.4 Start.png</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=File:Logic_2.4.4_Start.png&amp;diff=11503"/>
		<updated>2023-02-20T13:19:03Z</updated>

		<summary type="html">&lt;p&gt;FPaschinger: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;/div&gt;</summary>
		<author><name>FPaschinger</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=Endpoint_security_using_Cortex_XDR&amp;diff=11468</id>
		<title>Endpoint security using Cortex XDR</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=Endpoint_security_using_Cortex_XDR&amp;diff=11468"/>
		<updated>2023-02-03T16:50:23Z</updated>

		<summary type="html">&lt;p&gt;FPaschinger: /* Pentesting With Cortex XDR */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Summary == &lt;br /&gt;
&lt;br /&gt;
Endpoint security is a critical component of an organization&#039;s overall security strategy. It involves protecting devices such as laptops, smartphones, and servers from threats that can compromise the confidentiality, integrity, and availability of sensitive data. Cortex XDR is a next-generation endpoint security solution that provides advanced threat detection and response capabilities to help organizations protect their endpoints from a wide range of threats, including malware, ransomware, and advanced persistent threats (APTs).&lt;br /&gt;
&lt;br /&gt;
Cortex XDR uses a combination of artificial intelligence and machine learning algorithms to detect and respond to threats in real-time. It continuously monitors network traffic and endpoints for suspicious activity and immediately alerts security teams to potential threats. Additionally, Cortex XDR provides detailed forensic analysis and incident response capabilities, allowing organizations to quickly contain and remediate threats.&lt;br /&gt;
&lt;br /&gt;
With Cortex XDR, organizations can proactively protect their endpoints from known and unknown threats, and quickly respond to any incidents that do occur. This helps to minimize the risk of data breaches and ensure that sensitive information remains secure.&lt;br /&gt;
&lt;br /&gt;
Cortex XDR can be used in conjunction with other security solutions, such as firewalls, intrusion detection and prevention systems, and security information and event management (SIEM) platforms, to provide a comprehensive security posture for the organization. It also provides a simplified, centralized management console for security teams to easily manage and monitor their endpoint security posture.&lt;br /&gt;
&lt;br /&gt;
In summary, Cortex XDR is a powerful endpoint security solution that uses artificial intelligence and machine learning to detect and respond to threats in real-time, and provides incident response and forensic analysis capabilities to help organizations quickly contain and remediate threats, while providing a centralized, easy-to-use management console for security teams.&lt;br /&gt;
&lt;br /&gt;
== Description ==&lt;br /&gt;
&lt;br /&gt;
Endpoint security pentesting is a process of testing the security of endpoint devices, such as laptops, desktops, and servers, to identify vulnerabilities and assess the overall security of an organization&#039;s endpoint infrastructure.&lt;br /&gt;
&lt;br /&gt;
Endpoint security pentesting can include a variety of different techniques and tools, such as:&lt;br /&gt;
&lt;br /&gt;
* Vulnerability scanning: Identifying known vulnerabilities on endpoint devices&lt;br /&gt;
* Social engineering: Attempting to trick users into providing sensitive information or executing malicious code&lt;br /&gt;
* Application testing: Identifying vulnerabilities in software installed on endpoint devices&lt;br /&gt;
* Physical security testing: Attempting to gain unauthorized access to endpoint devices through physical means&lt;br /&gt;
* Network testing: Identifying vulnerabilities in the network infrastructure that could be used to compromise endpoint devices&lt;br /&gt;
&lt;br /&gt;
The goal of endpoint security pentesting is to identify and prioritize vulnerabilities, so that they can be remediated before they are exploited by attackers. This can include providing recommendations for mitigating vulnerabilities, as well as recommendations for improving overall security practices.&lt;br /&gt;
&lt;br /&gt;
It is important for organizations to regularly perform endpoint security pentesting to ensure that their endpoint infrastructure is secure. The results of the pentest can be used to improve the security posture of the organization and to prioritize security investments.&lt;br /&gt;
&lt;br /&gt;
It is important to note that using any tool or method that attempts to gain unauthorized access to systems is illegal in many countries and should only be used with explicit permission from the owner of the system.&lt;br /&gt;
&lt;br /&gt;
== Ransomware ==&lt;br /&gt;
&lt;br /&gt;
Ransomware is a type of malware that encrypts a victim&#039;s files and demands a ransom payment in exchange for the decryption key. The payment is typically demanded in the form of cryptocurrency, such as Bitcoin, and is often accompanied by a deadline for payment. Ransomware is typically spread through phishing emails or by exploiting vulnerabilities in software. It can cause significant financial and operational damage to individuals and organizations.&lt;br /&gt;
&lt;br /&gt;
Ransomware attacks can be particularly damaging to businesses, as they can disrupt operations and result in the loss of important data. In some cases, the ransom may be too high for the organization to afford, and they may be forced to pay it. In other cases, the organization may choose to not pay the ransom and instead restore their systems from backups or try to decrypt the files using other methods. Some Ransomware also have a double extortion mechanism, where they also steal data from the organization and threaten to release it publicly if the ransom is not paid. It is important for individuals and organizations to regularly backup their data and to keep their software and systems up to date to reduce the risk of falling victim to a ransomware attack.&lt;br /&gt;
&lt;br /&gt;
=== Cerber Ransomware ===&lt;br /&gt;
&lt;br /&gt;
Cerber is a type of ransomware that was first discovered in 2016. It is known for its use of advanced tactics to evade detection and to spread to other computers on a network. One of the tactics is the use of exploit kits to take advantage of vulnerabilities in software. It also uses a double extortion mechanism, where it steal data from the organization and threaten to release it publicly if the ransom is not paid.&lt;br /&gt;
Cerber is typically distributed through spam emails or via malicious websites that exploit vulnerabilities in web browsers and other software. Once a computer is infected, the malware encrypts files on the computer and on any connected network drives, making them inaccessible to the victim. A ransom note is then displayed, instructing the victim to pay a ransom in order to regain access to the encrypted files.&lt;br /&gt;
It is important to note that paying the ransom does not guarantee the recovery of the encrypted files and it is advisable to try to restore the data from backups or other means.&lt;br /&gt;
&lt;br /&gt;
=== WannaCry Ransomware ===&lt;br /&gt;
&lt;br /&gt;
WannaCry is a type of ransomware that was first discovered in May 2017. It quickly spread globally, causing widespread disruption to businesses, hospitals and other organizations. WannaCry was notable for its use of a specific exploit called EternalBlue, which was developed by the US National Security Agency (NSA) and leaked to the public by a hacking group called the Shadow Brokers. The exploit targeted a vulnerability in Microsoft Windows operating systems, allowing the ransomware to spread rapidly across networks.&lt;br /&gt;
Once a computer was infected, WannaCry encrypts files on the computer and on any connected network drives, making them inaccessible to the victim. A ransom note is then displayed, instructing the victim to pay a ransom in order to regain access to the encrypted files. The ransom payment was demanded in Bitcoin and the attackers threatened to double the ransom if it was not paid within three days.&lt;br /&gt;
WannaCry caused significant damage and disruption to organizations worldwide, and it was estimated that the total cost of the attack exceeded $4 billion. Microsoft had released a patch for the vulnerability before the outbreak, but many systems had not yet been updated, highlighting the importance of keeping software up to date.&lt;br /&gt;
&lt;br /&gt;
== Tools ==&lt;br /&gt;
&lt;br /&gt;
=== Cortex XDR ===&lt;br /&gt;
&lt;br /&gt;
Cortex XDR is a security solution developed by Palo Alto Networks that provides advanced threat detection and response capabilities. It combines multiple security technologies, including endpoint protection, network security, and cloud-based threat intelligence, to provide a comprehensive view of an organization&#039;s security posture.&lt;br /&gt;
&lt;br /&gt;
Cortex XDR uses machine learning and behavioral analytics to detect and respond to advanced threats, such as ransomware and APTs (Advanced Persistent Threats), in real-time. The platform also allows for automated incident response, which enables security teams to quickly contain and remediate threats.&lt;br /&gt;
&lt;br /&gt;
Cortex XDR also integrates with other security solutions, such as firewalls, to provide a unified view of security across an organization&#039;s entire infrastructure. This allows security teams to quickly identify and respond to threats, even if they are spread across multiple systems and networks.&lt;br /&gt;
&lt;br /&gt;
The Cortex XDR platform also includes a cloud-based management console, which enables security teams to monitor and manage security across multiple locations and devices. It allows security teams to identify, investigate and respond to security incidents across all users, devices, and networks with a single console.&lt;br /&gt;
&lt;br /&gt;
=== Mimikatz ===&lt;br /&gt;
&lt;br /&gt;
Mimikatz is a tool that is used to extract sensitive information, such as login credentials, from Windows systems. The tool is often used by attackers to gain access to systems and networks after they have successfully compromised a system. Mimikatz is able to extract information from the Windows operating system&#039;s memory, and it can be used to extract credentials from a wide range of applications, including web browsers, email clients, and other software.&lt;br /&gt;
&lt;br /&gt;
Mimikatz can extract a variety of information, including:&lt;br /&gt;
&lt;br /&gt;
* Passwords stored in memory&lt;br /&gt;
* Encryption keys&lt;br /&gt;
* Hashes of passwords&lt;br /&gt;
* Kerberos tickets&lt;br /&gt;
* Credentials for services and scheduled tasks&lt;br /&gt;
&lt;br /&gt;
Mimikatz can also be used to perform actions such as:&lt;br /&gt;
&lt;br /&gt;
* Changing a password for a user account&lt;br /&gt;
* Adding new user account&lt;br /&gt;
* Dumping the LSASS process memory.&lt;br /&gt;
&lt;br /&gt;
Mimikatz is considered a powerful and dangerous tool, and its use in an unauthorized manner is illegal in some countries. It is important for organizations to be aware of the presence of Mimikatz and other similar tools on their systems, and to take steps to protect against their use. This can include regularly monitoring systems for suspicious activity, implementing strong access controls, and regularly updating software to patch known vulnerabilities.&lt;br /&gt;
&lt;br /&gt;
=== BC-Security / Empire ===&lt;br /&gt;
&lt;br /&gt;
Empire is a post-exploitation framework, often used by penetration testers and red teamers to perform various tasks on a compromised system. Empire is based on the PowerShell scripting language and it is a popular tool among attackers because of its ability to execute arbitrary PowerShell commands and scripts, and its ability to perform various post-exploitation tasks such as privilege escalation, key logging, and network reconnaissance.&lt;br /&gt;
&lt;br /&gt;
Empire is a modular framework that allows users to easily create and execute custom modules, making it a powerful and flexible tool. Empire also has the ability to communicate with a command and control (C2) server, which can be used to remotely control a compromised system.&lt;br /&gt;
&lt;br /&gt;
Empire is often used in combination with other tools such as Metasploit, Mimikatz, and Cobalt Strike to perform advanced attacks.&lt;br /&gt;
&lt;br /&gt;
It is important for organizations to be aware of the presence of Empire and other similar tools on their systems, and to take steps to protect against their use. This can include regularly monitoring systems for suspicious activity, implementing strong access controls, and regularly updating software to patch known vulnerabilities.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Porchetta-Industries / CrackMapExec ===&lt;br /&gt;
&lt;br /&gt;
CrackMapExec (CME) is a tool that is used to perform network reconnaissance and attack execution. It is often used by penetration testers and red teamers to enumerate and attack Windows-based systems on a network. CME is based on the SMB (Server Message Block) protocol, which is used to provide shared access to files, printers, and other resources on a network.&lt;br /&gt;
&lt;br /&gt;
CME can perform various tasks, including:&lt;br /&gt;
&lt;br /&gt;
Enumerating users, groups, and computers on a network&lt;br /&gt;
Dumping password hashes for offline cracking&lt;br /&gt;
Executing arbitrary commands or scripts on remote systems&lt;br /&gt;
Attempting to authenticate to remote systems using a list of provided credentials&lt;br /&gt;
CME is a powerful and fast tool, which can be used to quickly gather information about systems on a network. It is important for organizations to be aware of the presence of CME and other similar tools on their systems, and to take steps to protect against their use. This can include regularly monitoring systems for suspicious activity, implementing strong access controls, and regularly updating software to patch known vulnerabilities.&lt;br /&gt;
&lt;br /&gt;
It is important to note that using CME or any other tool that attempts to gain unauthorized access to systems is illegal in many countries and should only be used with explicit permission from the owner of the system.&lt;br /&gt;
==Pentesting With Cortex XDR ==&lt;br /&gt;
&lt;br /&gt;
=== Installation ===&lt;br /&gt;
&lt;br /&gt;
# From Cortex XDR, select Endpoints → Agent Installations.&lt;br /&gt;
# Create a new installation package.&lt;br /&gt;
# Enter a unique Name and an optional Description to identify the installation package.&lt;br /&gt;
# Select the Package Type.&lt;br /&gt;
&lt;br /&gt;
###Standalone Installers—Use for fresh installations and to Upgrade Cortex XDR Agents on a registered endpoint that is connected to Cortex XDR.&lt;br /&gt;
&lt;br /&gt;
##Upgrade from ESM—Use this package to upgrade Traps agents which connect to the on-premises Traps Endpoint Security Manager to Cortex XDR. For more information, see Migrate from Traps Endpoint Security Manager.&lt;br /&gt;
&lt;br /&gt;
##(Linux only) Kubernetes Installer—Use for fresh installations and upgrades of Cortex XDR agents running on Kubernetes clusters.&lt;br /&gt;
&lt;br /&gt;
##Helm Installer—Use this package for fresh installations and upgrades of Cortex XDR agents running on Kubernetes clusters.&lt;br /&gt;
&lt;br /&gt;
# Specify the installation package settings.&lt;br /&gt;
# Create the installation package.&lt;br /&gt;
&lt;br /&gt;
Cortex XDR prepares your installation package and makes it available on the Agent Installations page.&lt;br /&gt;
# Download your installation package.&lt;br /&gt;
&lt;br /&gt;
When the status of the package shows Completed, right-click the agent version, and click Download.&lt;br /&gt;
#*For Windows endpoints, select between the architecture type. You can download the installer msi file only, or for Cortex XDR agents 7.4 and later, a distribution package that includes both the installer msi file and the latest content zip. The distribution package is recommended to reduce the network load and time typically required for the initial roll-out or major upgrades of the Cortex XDR agent. To understand the benefits, workflow, and requirements to support this type of deployment, refer to the Cortex XDR Agent Administrator Guide.&lt;br /&gt;
&lt;br /&gt;
#*For macOS endpoints, download the ZIP installation folder and upload it to the endpoint. To deploy the Cortex XDR agent using JAMF, upload the ZIP folder to JAMF. Alternatively, to install the agent manually on the endpoint, unzip the ZIP folder and double-click the pkg file.&lt;br /&gt;
&lt;br /&gt;
#*For Linux endpoints, you can download .rpm or .deb installers (according to the endpoint Linux distribution), and deploy the installers on the endpoints using the Linux package manager. Alternatively, you can download a Shell installer and deploy it manually on the endpoint.&lt;br /&gt;
&lt;br /&gt;
== Used Hardware ==&lt;br /&gt;
&lt;br /&gt;
HP Notebook&lt;br /&gt;
&lt;br /&gt;
== Used Software ==&lt;br /&gt;
&lt;br /&gt;
* Cortex XDR&lt;br /&gt;
* WannaCry Ransomware&lt;br /&gt;
* Cerber Ransomware&lt;br /&gt;
* Gentilkiwi / Mimikatz &lt;br /&gt;
* BC-Security / Empire &lt;br /&gt;
* Porchetta-Industries / CrackMapExec&lt;br /&gt;
&lt;br /&gt;
== Results ==&lt;br /&gt;
&lt;br /&gt;
Cortex XDR was able to prevent all attacks including the real ransomware execution mentioned in the &amp;quot;Ransomware&amp;quot; section. We got a precise analysis of processes which were considered abnormal or malicious. Cortex XDR recognizes behaviour related to known exploits which is then reported and blocked immediately.&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
*https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/7.9/Cortex-XDR-Agent-Administrator-Guide&lt;br /&gt;
*https://github.com/gentilkiwi/mimikatz&lt;br /&gt;
*https://github.com/Porchetta-Industries/CrackMapExec&lt;br /&gt;
*https://github.com/BC-SECURITY/Empire&lt;br /&gt;
*https://www.avast.com/de-de/c-cerber#:~:text=Link%20kopiert-,Was%20ist%20die%20Cerber%20Ransomware%3F,Sie%20wird%20eine%20L%C3%B6segeldzahlung%20verlangt.&lt;br /&gt;
*https://de.wikipedia.org/wiki/WannaCry&lt;br /&gt;
*&lt;br /&gt;
&lt;br /&gt;
[[Category:Documentation]]&lt;/div&gt;</summary>
		<author><name>FPaschinger</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=Endpoint_security_using_Cortex_XDR&amp;diff=11465</id>
		<title>Endpoint security using Cortex XDR</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=Endpoint_security_using_Cortex_XDR&amp;diff=11465"/>
		<updated>2023-02-03T16:47:37Z</updated>

		<summary type="html">&lt;p&gt;FPaschinger: /* Pentesting With Cortex XDR */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Summary == &lt;br /&gt;
&lt;br /&gt;
Endpoint security is a critical component of an organization&#039;s overall security strategy. It involves protecting devices such as laptops, smartphones, and servers from threats that can compromise the confidentiality, integrity, and availability of sensitive data. Cortex XDR is a next-generation endpoint security solution that provides advanced threat detection and response capabilities to help organizations protect their endpoints from a wide range of threats, including malware, ransomware, and advanced persistent threats (APTs).&lt;br /&gt;
&lt;br /&gt;
Cortex XDR uses a combination of artificial intelligence and machine learning algorithms to detect and respond to threats in real-time. It continuously monitors network traffic and endpoints for suspicious activity and immediately alerts security teams to potential threats. Additionally, Cortex XDR provides detailed forensic analysis and incident response capabilities, allowing organizations to quickly contain and remediate threats.&lt;br /&gt;
&lt;br /&gt;
With Cortex XDR, organizations can proactively protect their endpoints from known and unknown threats, and quickly respond to any incidents that do occur. This helps to minimize the risk of data breaches and ensure that sensitive information remains secure.&lt;br /&gt;
&lt;br /&gt;
Cortex XDR can be used in conjunction with other security solutions, such as firewalls, intrusion detection and prevention systems, and security information and event management (SIEM) platforms, to provide a comprehensive security posture for the organization. It also provides a simplified, centralized management console for security teams to easily manage and monitor their endpoint security posture.&lt;br /&gt;
&lt;br /&gt;
In summary, Cortex XDR is a powerful endpoint security solution that uses artificial intelligence and machine learning to detect and respond to threats in real-time, and provides incident response and forensic analysis capabilities to help organizations quickly contain and remediate threats, while providing a centralized, easy-to-use management console for security teams.&lt;br /&gt;
&lt;br /&gt;
== Description ==&lt;br /&gt;
&lt;br /&gt;
Endpoint security pentesting is a process of testing the security of endpoint devices, such as laptops, desktops, and servers, to identify vulnerabilities and assess the overall security of an organization&#039;s endpoint infrastructure.&lt;br /&gt;
&lt;br /&gt;
Endpoint security pentesting can include a variety of different techniques and tools, such as:&lt;br /&gt;
&lt;br /&gt;
* Vulnerability scanning: Identifying known vulnerabilities on endpoint devices&lt;br /&gt;
* Social engineering: Attempting to trick users into providing sensitive information or executing malicious code&lt;br /&gt;
* Application testing: Identifying vulnerabilities in software installed on endpoint devices&lt;br /&gt;
* Physical security testing: Attempting to gain unauthorized access to endpoint devices through physical means&lt;br /&gt;
* Network testing: Identifying vulnerabilities in the network infrastructure that could be used to compromise endpoint devices&lt;br /&gt;
&lt;br /&gt;
The goal of endpoint security pentesting is to identify and prioritize vulnerabilities, so that they can be remediated before they are exploited by attackers. This can include providing recommendations for mitigating vulnerabilities, as well as recommendations for improving overall security practices.&lt;br /&gt;
&lt;br /&gt;
It is important for organizations to regularly perform endpoint security pentesting to ensure that their endpoint infrastructure is secure. The results of the pentest can be used to improve the security posture of the organization and to prioritize security investments.&lt;br /&gt;
&lt;br /&gt;
It is important to note that using any tool or method that attempts to gain unauthorized access to systems is illegal in many countries and should only be used with explicit permission from the owner of the system.&lt;br /&gt;
&lt;br /&gt;
== Ransomware ==&lt;br /&gt;
&lt;br /&gt;
Ransomware is a type of malware that encrypts a victim&#039;s files and demands a ransom payment in exchange for the decryption key. The payment is typically demanded in the form of cryptocurrency, such as Bitcoin, and is often accompanied by a deadline for payment. Ransomware is typically spread through phishing emails or by exploiting vulnerabilities in software. It can cause significant financial and operational damage to individuals and organizations.&lt;br /&gt;
&lt;br /&gt;
Ransomware attacks can be particularly damaging to businesses, as they can disrupt operations and result in the loss of important data. In some cases, the ransom may be too high for the organization to afford, and they may be forced to pay it. In other cases, the organization may choose to not pay the ransom and instead restore their systems from backups or try to decrypt the files using other methods. Some Ransomware also have a double extortion mechanism, where they also steal data from the organization and threaten to release it publicly if the ransom is not paid. It is important for individuals and organizations to regularly backup their data and to keep their software and systems up to date to reduce the risk of falling victim to a ransomware attack.&lt;br /&gt;
&lt;br /&gt;
=== Cerber Ransomware ===&lt;br /&gt;
&lt;br /&gt;
Cerber is a type of ransomware that was first discovered in 2016. It is known for its use of advanced tactics to evade detection and to spread to other computers on a network. One of the tactics is the use of exploit kits to take advantage of vulnerabilities in software. It also uses a double extortion mechanism, where it steal data from the organization and threaten to release it publicly if the ransom is not paid.&lt;br /&gt;
Cerber is typically distributed through spam emails or via malicious websites that exploit vulnerabilities in web browsers and other software. Once a computer is infected, the malware encrypts files on the computer and on any connected network drives, making them inaccessible to the victim. A ransom note is then displayed, instructing the victim to pay a ransom in order to regain access to the encrypted files.&lt;br /&gt;
It is important to note that paying the ransom does not guarantee the recovery of the encrypted files and it is advisable to try to restore the data from backups or other means.&lt;br /&gt;
&lt;br /&gt;
=== WannaCry Ransomware ===&lt;br /&gt;
&lt;br /&gt;
WannaCry is a type of ransomware that was first discovered in May 2017. It quickly spread globally, causing widespread disruption to businesses, hospitals and other organizations. WannaCry was notable for its use of a specific exploit called EternalBlue, which was developed by the US National Security Agency (NSA) and leaked to the public by a hacking group called the Shadow Brokers. The exploit targeted a vulnerability in Microsoft Windows operating systems, allowing the ransomware to spread rapidly across networks.&lt;br /&gt;
Once a computer was infected, WannaCry encrypts files on the computer and on any connected network drives, making them inaccessible to the victim. A ransom note is then displayed, instructing the victim to pay a ransom in order to regain access to the encrypted files. The ransom payment was demanded in Bitcoin and the attackers threatened to double the ransom if it was not paid within three days.&lt;br /&gt;
WannaCry caused significant damage and disruption to organizations worldwide, and it was estimated that the total cost of the attack exceeded $4 billion. Microsoft had released a patch for the vulnerability before the outbreak, but many systems had not yet been updated, highlighting the importance of keeping software up to date.&lt;br /&gt;
&lt;br /&gt;
== Tools ==&lt;br /&gt;
&lt;br /&gt;
=== Cortex XDR ===&lt;br /&gt;
&lt;br /&gt;
Cortex XDR is a security solution developed by Palo Alto Networks that provides advanced threat detection and response capabilities. It combines multiple security technologies, including endpoint protection, network security, and cloud-based threat intelligence, to provide a comprehensive view of an organization&#039;s security posture.&lt;br /&gt;
&lt;br /&gt;
Cortex XDR uses machine learning and behavioral analytics to detect and respond to advanced threats, such as ransomware and APTs (Advanced Persistent Threats), in real-time. The platform also allows for automated incident response, which enables security teams to quickly contain and remediate threats.&lt;br /&gt;
&lt;br /&gt;
Cortex XDR also integrates with other security solutions, such as firewalls, to provide a unified view of security across an organization&#039;s entire infrastructure. This allows security teams to quickly identify and respond to threats, even if they are spread across multiple systems and networks.&lt;br /&gt;
&lt;br /&gt;
The Cortex XDR platform also includes a cloud-based management console, which enables security teams to monitor and manage security across multiple locations and devices. It allows security teams to identify, investigate and respond to security incidents across all users, devices, and networks with a single console.&lt;br /&gt;
&lt;br /&gt;
=== Mimikatz ===&lt;br /&gt;
&lt;br /&gt;
Mimikatz is a tool that is used to extract sensitive information, such as login credentials, from Windows systems. The tool is often used by attackers to gain access to systems and networks after they have successfully compromised a system. Mimikatz is able to extract information from the Windows operating system&#039;s memory, and it can be used to extract credentials from a wide range of applications, including web browsers, email clients, and other software.&lt;br /&gt;
&lt;br /&gt;
Mimikatz can extract a variety of information, including:&lt;br /&gt;
&lt;br /&gt;
* Passwords stored in memory&lt;br /&gt;
* Encryption keys&lt;br /&gt;
* Hashes of passwords&lt;br /&gt;
* Kerberos tickets&lt;br /&gt;
* Credentials for services and scheduled tasks&lt;br /&gt;
&lt;br /&gt;
Mimikatz can also be used to perform actions such as:&lt;br /&gt;
&lt;br /&gt;
* Changing a password for a user account&lt;br /&gt;
* Adding new user account&lt;br /&gt;
* Dumping the LSASS process memory.&lt;br /&gt;
&lt;br /&gt;
Mimikatz is considered a powerful and dangerous tool, and its use in an unauthorized manner is illegal in some countries. It is important for organizations to be aware of the presence of Mimikatz and other similar tools on their systems, and to take steps to protect against their use. This can include regularly monitoring systems for suspicious activity, implementing strong access controls, and regularly updating software to patch known vulnerabilities.&lt;br /&gt;
&lt;br /&gt;
=== BC-Security / Empire ===&lt;br /&gt;
&lt;br /&gt;
Empire is a post-exploitation framework, often used by penetration testers and red teamers to perform various tasks on a compromised system. Empire is based on the PowerShell scripting language and it is a popular tool among attackers because of its ability to execute arbitrary PowerShell commands and scripts, and its ability to perform various post-exploitation tasks such as privilege escalation, key logging, and network reconnaissance.&lt;br /&gt;
&lt;br /&gt;
Empire is a modular framework that allows users to easily create and execute custom modules, making it a powerful and flexible tool. Empire also has the ability to communicate with a command and control (C2) server, which can be used to remotely control a compromised system.&lt;br /&gt;
&lt;br /&gt;
Empire is often used in combination with other tools such as Metasploit, Mimikatz, and Cobalt Strike to perform advanced attacks.&lt;br /&gt;
&lt;br /&gt;
It is important for organizations to be aware of the presence of Empire and other similar tools on their systems, and to take steps to protect against their use. This can include regularly monitoring systems for suspicious activity, implementing strong access controls, and regularly updating software to patch known vulnerabilities.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Porchetta-Industries / CrackMapExec ===&lt;br /&gt;
&lt;br /&gt;
CrackMapExec (CME) is a tool that is used to perform network reconnaissance and attack execution. It is often used by penetration testers and red teamers to enumerate and attack Windows-based systems on a network. CME is based on the SMB (Server Message Block) protocol, which is used to provide shared access to files, printers, and other resources on a network.&lt;br /&gt;
&lt;br /&gt;
CME can perform various tasks, including:&lt;br /&gt;
&lt;br /&gt;
Enumerating users, groups, and computers on a network&lt;br /&gt;
Dumping password hashes for offline cracking&lt;br /&gt;
Executing arbitrary commands or scripts on remote systems&lt;br /&gt;
Attempting to authenticate to remote systems using a list of provided credentials&lt;br /&gt;
CME is a powerful and fast tool, which can be used to quickly gather information about systems on a network. It is important for organizations to be aware of the presence of CME and other similar tools on their systems, and to take steps to protect against their use. This can include regularly monitoring systems for suspicious activity, implementing strong access controls, and regularly updating software to patch known vulnerabilities.&lt;br /&gt;
&lt;br /&gt;
It is important to note that using CME or any other tool that attempts to gain unauthorized access to systems is illegal in many countries and should only be used with explicit permission from the owner of the system.&lt;br /&gt;
==Pentesting With Cortex XDR ==&lt;br /&gt;
&lt;br /&gt;
=== Installation ===&lt;br /&gt;
&lt;br /&gt;
# From Cortex XDR, select Endpoints → Agent Installations.&lt;br /&gt;
# Create a new installation package.&lt;br /&gt;
# Enter a unique Name and an optional Description to identify the installation package.&lt;br /&gt;
# Select the Package Type.&lt;br /&gt;
&lt;br /&gt;
*Standalone Installers—Use for fresh installations and to Upgrade Cortex XDR Agents on a registered endpoint that is connected to Cortex XDR.&lt;br /&gt;
&lt;br /&gt;
*Upgrade from ESM—Use this package to upgrade Traps agents which connect to the on-premises Traps Endpoint Security Manager to Cortex XDR. For more information, see Migrate from Traps Endpoint Security Manager.&lt;br /&gt;
&lt;br /&gt;
*(Linux only) Kubernetes Installer—Use for fresh installations and upgrades of Cortex XDR agents running on Kubernetes clusters.&lt;br /&gt;
&lt;br /&gt;
*Helm Installer—Use this package for fresh installations and upgrades of Cortex XDR agents running on Kubernetes clusters.&lt;br /&gt;
&lt;br /&gt;
# Specify the installation package settings.&lt;br /&gt;
# Create the installation package.&lt;br /&gt;
&lt;br /&gt;
Cortex XDR prepares your installation package and makes it available on the Agent Installations page.&lt;br /&gt;
# Download your installation package.&lt;br /&gt;
&lt;br /&gt;
When the status of the package shows Completed, right-click the agent version, and click Download.&lt;br /&gt;
*For Windows endpoints, select between the architecture type. You can download the installer msi file only, or for Cortex XDR agents 7.4 and later, a distribution package that includes both the installer msi file and the latest content zip. The distribution package is recommended to reduce the network load and time typically required for the initial roll-out or major upgrades of the Cortex XDR agent. To understand the benefits, workflow, and requirements to support this type of deployment, refer to the Cortex XDR Agent Administrator Guide.&lt;br /&gt;
&lt;br /&gt;
*For macOS endpoints, download the ZIP installation folder and upload it to the endpoint. To deploy the Cortex XDR agent using JAMF, upload the ZIP folder to JAMF. Alternatively, to install the agent manually on the endpoint, unzip the ZIP folder and double-click the pkg file.&lt;br /&gt;
&lt;br /&gt;
*For Linux endpoints, you can download .rpm or .deb installers (according to the endpoint Linux distribution), and deploy the installers on the endpoints using the Linux package manager. Alternatively, you can download a Shell installer and deploy it manually on the endpoint.&lt;br /&gt;
&lt;br /&gt;
== Used Hardware ==&lt;br /&gt;
&lt;br /&gt;
HP Notebook&lt;br /&gt;
&lt;br /&gt;
== Used Software ==&lt;br /&gt;
&lt;br /&gt;
* Cortex XDR&lt;br /&gt;
* WannaCry Ransomware&lt;br /&gt;
* Cerber Ransomware&lt;br /&gt;
* Gentilkiwi / Mimikatz &lt;br /&gt;
* BC-Security / Empire &lt;br /&gt;
* Porchetta-Industries / CrackMapExec&lt;br /&gt;
&lt;br /&gt;
== Results ==&lt;br /&gt;
&lt;br /&gt;
Cortex XDR was able to prevent all attacks including the real ransomware execution mentioned in the &amp;quot;Ransomware&amp;quot; section. We got a precise analysis of processes which were considered abnormal or malicious. Cortex XDR recognizes behaviour related to known exploits which is then reported and blocked immediately.&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
*https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/7.9/Cortex-XDR-Agent-Administrator-Guide&lt;br /&gt;
*https://github.com/gentilkiwi/mimikatz&lt;br /&gt;
*https://github.com/Porchetta-Industries/CrackMapExec&lt;br /&gt;
*https://github.com/BC-SECURITY/Empire&lt;br /&gt;
*https://www.avast.com/de-de/c-cerber#:~:text=Link%20kopiert-,Was%20ist%20die%20Cerber%20Ransomware%3F,Sie%20wird%20eine%20L%C3%B6segeldzahlung%20verlangt.&lt;br /&gt;
*https://de.wikipedia.org/wiki/WannaCry&lt;br /&gt;
*&lt;br /&gt;
&lt;br /&gt;
[[Category:Documentation]]&lt;/div&gt;</summary>
		<author><name>FPaschinger</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=Endpoint_security_using_Cortex_XDR&amp;diff=11463</id>
		<title>Endpoint security using Cortex XDR</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=Endpoint_security_using_Cortex_XDR&amp;diff=11463"/>
		<updated>2023-02-03T16:46:14Z</updated>

		<summary type="html">&lt;p&gt;FPaschinger: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Summary == &lt;br /&gt;
&lt;br /&gt;
Endpoint security is a critical component of an organization&#039;s overall security strategy. It involves protecting devices such as laptops, smartphones, and servers from threats that can compromise the confidentiality, integrity, and availability of sensitive data. Cortex XDR is a next-generation endpoint security solution that provides advanced threat detection and response capabilities to help organizations protect their endpoints from a wide range of threats, including malware, ransomware, and advanced persistent threats (APTs).&lt;br /&gt;
&lt;br /&gt;
Cortex XDR uses a combination of artificial intelligence and machine learning algorithms to detect and respond to threats in real-time. It continuously monitors network traffic and endpoints for suspicious activity and immediately alerts security teams to potential threats. Additionally, Cortex XDR provides detailed forensic analysis and incident response capabilities, allowing organizations to quickly contain and remediate threats.&lt;br /&gt;
&lt;br /&gt;
With Cortex XDR, organizations can proactively protect their endpoints from known and unknown threats, and quickly respond to any incidents that do occur. This helps to minimize the risk of data breaches and ensure that sensitive information remains secure.&lt;br /&gt;
&lt;br /&gt;
Cortex XDR can be used in conjunction with other security solutions, such as firewalls, intrusion detection and prevention systems, and security information and event management (SIEM) platforms, to provide a comprehensive security posture for the organization. It also provides a simplified, centralized management console for security teams to easily manage and monitor their endpoint security posture.&lt;br /&gt;
&lt;br /&gt;
In summary, Cortex XDR is a powerful endpoint security solution that uses artificial intelligence and machine learning to detect and respond to threats in real-time, and provides incident response and forensic analysis capabilities to help organizations quickly contain and remediate threats, while providing a centralized, easy-to-use management console for security teams.&lt;br /&gt;
&lt;br /&gt;
== Description ==&lt;br /&gt;
&lt;br /&gt;
Endpoint security pentesting is a process of testing the security of endpoint devices, such as laptops, desktops, and servers, to identify vulnerabilities and assess the overall security of an organization&#039;s endpoint infrastructure.&lt;br /&gt;
&lt;br /&gt;
Endpoint security pentesting can include a variety of different techniques and tools, such as:&lt;br /&gt;
&lt;br /&gt;
* Vulnerability scanning: Identifying known vulnerabilities on endpoint devices&lt;br /&gt;
* Social engineering: Attempting to trick users into providing sensitive information or executing malicious code&lt;br /&gt;
* Application testing: Identifying vulnerabilities in software installed on endpoint devices&lt;br /&gt;
* Physical security testing: Attempting to gain unauthorized access to endpoint devices through physical means&lt;br /&gt;
* Network testing: Identifying vulnerabilities in the network infrastructure that could be used to compromise endpoint devices&lt;br /&gt;
&lt;br /&gt;
The goal of endpoint security pentesting is to identify and prioritize vulnerabilities, so that they can be remediated before they are exploited by attackers. This can include providing recommendations for mitigating vulnerabilities, as well as recommendations for improving overall security practices.&lt;br /&gt;
&lt;br /&gt;
It is important for organizations to regularly perform endpoint security pentesting to ensure that their endpoint infrastructure is secure. The results of the pentest can be used to improve the security posture of the organization and to prioritize security investments.&lt;br /&gt;
&lt;br /&gt;
It is important to note that using any tool or method that attempts to gain unauthorized access to systems is illegal in many countries and should only be used with explicit permission from the owner of the system.&lt;br /&gt;
&lt;br /&gt;
== Ransomware ==&lt;br /&gt;
&lt;br /&gt;
Ransomware is a type of malware that encrypts a victim&#039;s files and demands a ransom payment in exchange for the decryption key. The payment is typically demanded in the form of cryptocurrency, such as Bitcoin, and is often accompanied by a deadline for payment. Ransomware is typically spread through phishing emails or by exploiting vulnerabilities in software. It can cause significant financial and operational damage to individuals and organizations.&lt;br /&gt;
&lt;br /&gt;
Ransomware attacks can be particularly damaging to businesses, as they can disrupt operations and result in the loss of important data. In some cases, the ransom may be too high for the organization to afford, and they may be forced to pay it. In other cases, the organization may choose to not pay the ransom and instead restore their systems from backups or try to decrypt the files using other methods. Some Ransomware also have a double extortion mechanism, where they also steal data from the organization and threaten to release it publicly if the ransom is not paid. It is important for individuals and organizations to regularly backup their data and to keep their software and systems up to date to reduce the risk of falling victim to a ransomware attack.&lt;br /&gt;
&lt;br /&gt;
=== Cerber Ransomware ===&lt;br /&gt;
&lt;br /&gt;
Cerber is a type of ransomware that was first discovered in 2016. It is known for its use of advanced tactics to evade detection and to spread to other computers on a network. One of the tactics is the use of exploit kits to take advantage of vulnerabilities in software. It also uses a double extortion mechanism, where it steal data from the organization and threaten to release it publicly if the ransom is not paid.&lt;br /&gt;
Cerber is typically distributed through spam emails or via malicious websites that exploit vulnerabilities in web browsers and other software. Once a computer is infected, the malware encrypts files on the computer and on any connected network drives, making them inaccessible to the victim. A ransom note is then displayed, instructing the victim to pay a ransom in order to regain access to the encrypted files.&lt;br /&gt;
It is important to note that paying the ransom does not guarantee the recovery of the encrypted files and it is advisable to try to restore the data from backups or other means.&lt;br /&gt;
&lt;br /&gt;
=== WannaCry Ransomware ===&lt;br /&gt;
&lt;br /&gt;
WannaCry is a type of ransomware that was first discovered in May 2017. It quickly spread globally, causing widespread disruption to businesses, hospitals and other organizations. WannaCry was notable for its use of a specific exploit called EternalBlue, which was developed by the US National Security Agency (NSA) and leaked to the public by a hacking group called the Shadow Brokers. The exploit targeted a vulnerability in Microsoft Windows operating systems, allowing the ransomware to spread rapidly across networks.&lt;br /&gt;
Once a computer was infected, WannaCry encrypts files on the computer and on any connected network drives, making them inaccessible to the victim. A ransom note is then displayed, instructing the victim to pay a ransom in order to regain access to the encrypted files. The ransom payment was demanded in Bitcoin and the attackers threatened to double the ransom if it was not paid within three days.&lt;br /&gt;
WannaCry caused significant damage and disruption to organizations worldwide, and it was estimated that the total cost of the attack exceeded $4 billion. Microsoft had released a patch for the vulnerability before the outbreak, but many systems had not yet been updated, highlighting the importance of keeping software up to date.&lt;br /&gt;
&lt;br /&gt;
== Tools ==&lt;br /&gt;
&lt;br /&gt;
=== Cortex XDR ===&lt;br /&gt;
&lt;br /&gt;
Cortex XDR is a security solution developed by Palo Alto Networks that provides advanced threat detection and response capabilities. It combines multiple security technologies, including endpoint protection, network security, and cloud-based threat intelligence, to provide a comprehensive view of an organization&#039;s security posture.&lt;br /&gt;
&lt;br /&gt;
Cortex XDR uses machine learning and behavioral analytics to detect and respond to advanced threats, such as ransomware and APTs (Advanced Persistent Threats), in real-time. The platform also allows for automated incident response, which enables security teams to quickly contain and remediate threats.&lt;br /&gt;
&lt;br /&gt;
Cortex XDR also integrates with other security solutions, such as firewalls, to provide a unified view of security across an organization&#039;s entire infrastructure. This allows security teams to quickly identify and respond to threats, even if they are spread across multiple systems and networks.&lt;br /&gt;
&lt;br /&gt;
The Cortex XDR platform also includes a cloud-based management console, which enables security teams to monitor and manage security across multiple locations and devices. It allows security teams to identify, investigate and respond to security incidents across all users, devices, and networks with a single console.&lt;br /&gt;
&lt;br /&gt;
=== Mimikatz ===&lt;br /&gt;
&lt;br /&gt;
Mimikatz is a tool that is used to extract sensitive information, such as login credentials, from Windows systems. The tool is often used by attackers to gain access to systems and networks after they have successfully compromised a system. Mimikatz is able to extract information from the Windows operating system&#039;s memory, and it can be used to extract credentials from a wide range of applications, including web browsers, email clients, and other software.&lt;br /&gt;
&lt;br /&gt;
Mimikatz can extract a variety of information, including:&lt;br /&gt;
&lt;br /&gt;
* Passwords stored in memory&lt;br /&gt;
* Encryption keys&lt;br /&gt;
* Hashes of passwords&lt;br /&gt;
* Kerberos tickets&lt;br /&gt;
* Credentials for services and scheduled tasks&lt;br /&gt;
&lt;br /&gt;
Mimikatz can also be used to perform actions such as:&lt;br /&gt;
&lt;br /&gt;
* Changing a password for a user account&lt;br /&gt;
* Adding new user account&lt;br /&gt;
* Dumping the LSASS process memory.&lt;br /&gt;
&lt;br /&gt;
Mimikatz is considered a powerful and dangerous tool, and its use in an unauthorized manner is illegal in some countries. It is important for organizations to be aware of the presence of Mimikatz and other similar tools on their systems, and to take steps to protect against their use. This can include regularly monitoring systems for suspicious activity, implementing strong access controls, and regularly updating software to patch known vulnerabilities.&lt;br /&gt;
&lt;br /&gt;
=== BC-Security / Empire ===&lt;br /&gt;
&lt;br /&gt;
Empire is a post-exploitation framework, often used by penetration testers and red teamers to perform various tasks on a compromised system. Empire is based on the PowerShell scripting language and it is a popular tool among attackers because of its ability to execute arbitrary PowerShell commands and scripts, and its ability to perform various post-exploitation tasks such as privilege escalation, key logging, and network reconnaissance.&lt;br /&gt;
&lt;br /&gt;
Empire is a modular framework that allows users to easily create and execute custom modules, making it a powerful and flexible tool. Empire also has the ability to communicate with a command and control (C2) server, which can be used to remotely control a compromised system.&lt;br /&gt;
&lt;br /&gt;
Empire is often used in combination with other tools such as Metasploit, Mimikatz, and Cobalt Strike to perform advanced attacks.&lt;br /&gt;
&lt;br /&gt;
It is important for organizations to be aware of the presence of Empire and other similar tools on their systems, and to take steps to protect against their use. This can include regularly monitoring systems for suspicious activity, implementing strong access controls, and regularly updating software to patch known vulnerabilities.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Porchetta-Industries / CrackMapExec ===&lt;br /&gt;
&lt;br /&gt;
CrackMapExec (CME) is a tool that is used to perform network reconnaissance and attack execution. It is often used by penetration testers and red teamers to enumerate and attack Windows-based systems on a network. CME is based on the SMB (Server Message Block) protocol, which is used to provide shared access to files, printers, and other resources on a network.&lt;br /&gt;
&lt;br /&gt;
CME can perform various tasks, including:&lt;br /&gt;
&lt;br /&gt;
Enumerating users, groups, and computers on a network&lt;br /&gt;
Dumping password hashes for offline cracking&lt;br /&gt;
Executing arbitrary commands or scripts on remote systems&lt;br /&gt;
Attempting to authenticate to remote systems using a list of provided credentials&lt;br /&gt;
CME is a powerful and fast tool, which can be used to quickly gather information about systems on a network. It is important for organizations to be aware of the presence of CME and other similar tools on their systems, and to take steps to protect against their use. This can include regularly monitoring systems for suspicious activity, implementing strong access controls, and regularly updating software to patch known vulnerabilities.&lt;br /&gt;
&lt;br /&gt;
It is important to note that using CME or any other tool that attempts to gain unauthorized access to systems is illegal in many countries and should only be used with explicit permission from the owner of the system.&lt;br /&gt;
==Pentesting With Cortex XDR ==&lt;br /&gt;
&lt;br /&gt;
1- From Cortex XDR, select Endpoints → Agent Installations.&lt;br /&gt;
2- Create a new installation package.&lt;br /&gt;
3- Enter a unique Name and an optional Description to identify the installation package.&lt;br /&gt;
4- Select the Package Type.&lt;br /&gt;
&lt;br /&gt;
*Standalone Installers—Use for fresh installations and to Upgrade Cortex XDR Agents on a registered endpoint that is connected to Cortex XDR.&lt;br /&gt;
&lt;br /&gt;
*Upgrade from ESM—Use this package to upgrade Traps agents which connect to the on-premises Traps Endpoint Security Manager to Cortex XDR. For more information, see Migrate from Traps Endpoint Security Manager.&lt;br /&gt;
&lt;br /&gt;
*(Linux only) Kubernetes Installer—Use for fresh installations and upgrades of Cortex XDR agents running on Kubernetes clusters.&lt;br /&gt;
&lt;br /&gt;
*Helm Installer—Use this package for fresh installations and upgrades of Cortex XDR agents running on Kubernetes clusters.&lt;br /&gt;
&lt;br /&gt;
5- Specify the installation package settings.&lt;br /&gt;
6- Create the installation package.&lt;br /&gt;
&lt;br /&gt;
Cortex XDR prepares your installation package and makes it available on the Agent Installations page.&lt;br /&gt;
7-Download your installation package.&lt;br /&gt;
&lt;br /&gt;
When the status of the package shows Completed, right-click the agent version, and click Download.&lt;br /&gt;
*For Windows endpoints, select between the architecture type. You can download the installer msi file only, or for Cortex XDR agents 7.4 and later, a distribution package that includes both the installer msi file and the latest content zip. The distribution package is recommended to reduce the network load and time typically required for the initial roll-out or major upgrades of the Cortex XDR agent. To understand the benefits, workflow, and requirements to support this type of deployment, refer to the Cortex XDR Agent Administrator Guide.&lt;br /&gt;
&lt;br /&gt;
*For macOS endpoints, download the ZIP installation folder and upload it to the endpoint. To deploy the Cortex XDR agent using JAMF, upload the ZIP folder to JAMF. Alternatively, to install the agent manually on the endpoint, unzip the ZIP folder and double-click the pkg file.&lt;br /&gt;
&lt;br /&gt;
*For Linux endpoints, you can download .rpm or .deb installers (according to the endpoint Linux distribution), and deploy the installers on the endpoints using the Linux package manager. Alternatively, you can download a Shell installer and deploy it manually on the endpoint.&lt;br /&gt;
&lt;br /&gt;
== Used Hardware ==&lt;br /&gt;
&lt;br /&gt;
HP Notebook&lt;br /&gt;
&lt;br /&gt;
== Used Software ==&lt;br /&gt;
&lt;br /&gt;
* Cortex XDR&lt;br /&gt;
* WannaCry Ransomware&lt;br /&gt;
* Cerber Ransomware&lt;br /&gt;
* Gentilkiwi / Mimikatz &lt;br /&gt;
* BC-Security / Empire &lt;br /&gt;
* Porchetta-Industries / CrackMapExec&lt;br /&gt;
&lt;br /&gt;
== Results ==&lt;br /&gt;
&lt;br /&gt;
Cortex XDR was able to prevent all attacks including the real ransomware execution mentioned in the &amp;quot;Ransomware&amp;quot; section. We got a precise analysis of processes which were considered abnormal or malicious. Cortex XDR recognizes behaviour related to known exploits which is then reported and blocked immediately.&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
*https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/7.9/Cortex-XDR-Agent-Administrator-Guide&lt;br /&gt;
*https://github.com/gentilkiwi/mimikatz&lt;br /&gt;
*https://github.com/Porchetta-Industries/CrackMapExec&lt;br /&gt;
*https://github.com/BC-SECURITY/Empire&lt;br /&gt;
*https://www.avast.com/de-de/c-cerber#:~:text=Link%20kopiert-,Was%20ist%20die%20Cerber%20Ransomware%3F,Sie%20wird%20eine%20L%C3%B6segeldzahlung%20verlangt.&lt;br /&gt;
*https://de.wikipedia.org/wiki/WannaCry&lt;br /&gt;
*&lt;br /&gt;
&lt;br /&gt;
[[Category:Documentation]]&lt;/div&gt;</summary>
		<author><name>FPaschinger</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=Endpoint_security_using_Cortex_XDR&amp;diff=11460</id>
		<title>Endpoint security using Cortex XDR</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=Endpoint_security_using_Cortex_XDR&amp;diff=11460"/>
		<updated>2023-02-03T16:40:29Z</updated>

		<summary type="html">&lt;p&gt;FPaschinger: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Summary == &lt;br /&gt;
&lt;br /&gt;
Endpoint security is a critical component of an organization&#039;s overall security strategy. It involves protecting devices such as laptops, smartphones, and servers from threats that can compromise the confidentiality, integrity, and availability of sensitive data. Cortex XDR is a next-generation endpoint security solution that provides advanced threat detection and response capabilities to help organizations protect their endpoints from a wide range of threats, including malware, ransomware, and advanced persistent threats (APTs).&lt;br /&gt;
&lt;br /&gt;
Cortex XDR uses a combination of artificial intelligence and machine learning algorithms to detect and respond to threats in real-time. It continuously monitors network traffic and endpoints for suspicious activity and immediately alerts security teams to potential threats. Additionally, Cortex XDR provides detailed forensic analysis and incident response capabilities, allowing organizations to quickly contain and remediate threats.&lt;br /&gt;
&lt;br /&gt;
With Cortex XDR, organizations can proactively protect their endpoints from known and unknown threats, and quickly respond to any incidents that do occur. This helps to minimize the risk of data breaches and ensure that sensitive information remains secure.&lt;br /&gt;
&lt;br /&gt;
Cortex XDR can be used in conjunction with other security solutions, such as firewalls, intrusion detection and prevention systems, and security information and event management (SIEM) platforms, to provide a comprehensive security posture for the organization. It also provides a simplified, centralized management console for security teams to easily manage and monitor their endpoint security posture.&lt;br /&gt;
&lt;br /&gt;
In summary, Cortex XDR is a powerful endpoint security solution that uses artificial intelligence and machine learning to detect and respond to threats in real-time, and provides incident response and forensic analysis capabilities to help organizations quickly contain and remediate threats, while providing a centralized, easy-to-use management console for security teams.&lt;br /&gt;
&lt;br /&gt;
== Description ==&lt;br /&gt;
&lt;br /&gt;
Endpoint security pentesting is a process of testing the security of endpoint devices, such as laptops, desktops, and servers, to identify vulnerabilities and assess the overall security of an organization&#039;s endpoint infrastructure.&lt;br /&gt;
&lt;br /&gt;
Endpoint security pentesting can include a variety of different techniques and tools, such as:&lt;br /&gt;
&lt;br /&gt;
* Vulnerability scanning: Identifying known vulnerabilities on endpoint devices&lt;br /&gt;
* Social engineering: Attempting to trick users into providing sensitive information or executing malicious code&lt;br /&gt;
* Application testing: Identifying vulnerabilities in software installed on endpoint devices&lt;br /&gt;
* Physical security testing: Attempting to gain unauthorized access to endpoint devices through physical means&lt;br /&gt;
* Network testing: Identifying vulnerabilities in the network infrastructure that could be used to compromise endpoint devices&lt;br /&gt;
&lt;br /&gt;
The goal of endpoint security pentesting is to identify and prioritize vulnerabilities, so that they can be remediated before they are exploited by attackers. This can include providing recommendations for mitigating vulnerabilities, as well as recommendations for improving overall security practices.&lt;br /&gt;
&lt;br /&gt;
It is important for organizations to regularly perform endpoint security pentesting to ensure that their endpoint infrastructure is secure. The results of the pentest can be used to improve the security posture of the organization and to prioritize security investments.&lt;br /&gt;
&lt;br /&gt;
It is important to note that using any tool or method that attempts to gain unauthorized access to systems is illegal in many countries and should only be used with explicit permission from the owner of the system.&lt;br /&gt;
&lt;br /&gt;
== Ransomware ==&lt;br /&gt;
&lt;br /&gt;
Ransomware is a type of malware that encrypts a victim&#039;s files and demands a ransom payment in exchange for the decryption key. The payment is typically demanded in the form of cryptocurrency, such as Bitcoin, and is often accompanied by a deadline for payment. Ransomware is typically spread through phishing emails or by exploiting vulnerabilities in software. It can cause significant financial and operational damage to individuals and organizations.&lt;br /&gt;
&lt;br /&gt;
Ransomware attacks can be particularly damaging to businesses, as they can disrupt operations and result in the loss of important data. In some cases, the ransom may be too high for the organization to afford, and they may be forced to pay it. In other cases, the organization may choose to not pay the ransom and instead restore their systems from backups or try to decrypt the files using other methods. Some Ransomware also have a double extortion mechanism, where they also steal data from the organization and threaten to release it publicly if the ransom is not paid. It is important for individuals and organizations to regularly backup their data and to keep their software and systems up to date to reduce the risk of falling victim to a ransomware attack.&lt;br /&gt;
&lt;br /&gt;
=== Cerber Ransomware ===&lt;br /&gt;
&lt;br /&gt;
Cerber is a type of ransomware that was first discovered in 2016. It is known for its use of advanced tactics to evade detection and to spread to other computers on a network. One of the tactics is the use of exploit kits to take advantage of vulnerabilities in software. It also uses a double extortion mechanism, where it steal data from the organization and threaten to release it publicly if the ransom is not paid.&lt;br /&gt;
Cerber is typically distributed through spam emails or via malicious websites that exploit vulnerabilities in web browsers and other software. Once a computer is infected, the malware encrypts files on the computer and on any connected network drives, making them inaccessible to the victim. A ransom note is then displayed, instructing the victim to pay a ransom in order to regain access to the encrypted files.&lt;br /&gt;
It is important to note that paying the ransom does not guarantee the recovery of the encrypted files and it is advisable to try to restore the data from backups or other means.&lt;br /&gt;
&lt;br /&gt;
=== WannaCry Ransomware ===&lt;br /&gt;
&lt;br /&gt;
WannaCry is a type of ransomware that was first discovered in May 2017. It quickly spread globally, causing widespread disruption to businesses, hospitals and other organizations. WannaCry was notable for its use of a specific exploit called EternalBlue, which was developed by the US National Security Agency (NSA) and leaked to the public by a hacking group called the Shadow Brokers. The exploit targeted a vulnerability in Microsoft Windows operating systems, allowing the ransomware to spread rapidly across networks.&lt;br /&gt;
Once a computer was infected, WannaCry encrypts files on the computer and on any connected network drives, making them inaccessible to the victim. A ransom note is then displayed, instructing the victim to pay a ransom in order to regain access to the encrypted files. The ransom payment was demanded in Bitcoin and the attackers threatened to double the ransom if it was not paid within three days.&lt;br /&gt;
WannaCry caused significant damage and disruption to organizations worldwide, and it was estimated that the total cost of the attack exceeded $4 billion. Microsoft had released a patch for the vulnerability before the outbreak, but many systems had not yet been updated, highlighting the importance of keeping software up to date.&lt;br /&gt;
&lt;br /&gt;
== Tools ==&lt;br /&gt;
&lt;br /&gt;
=== Cortex XDR ===&lt;br /&gt;
&lt;br /&gt;
Cortex XDR is a security solution developed by Palo Alto Networks that provides advanced threat detection and response capabilities. It combines multiple security technologies, including endpoint protection, network security, and cloud-based threat intelligence, to provide a comprehensive view of an organization&#039;s security posture.&lt;br /&gt;
&lt;br /&gt;
Cortex XDR uses machine learning and behavioral analytics to detect and respond to advanced threats, such as ransomware and APTs (Advanced Persistent Threats), in real-time. The platform also allows for automated incident response, which enables security teams to quickly contain and remediate threats.&lt;br /&gt;
&lt;br /&gt;
Cortex XDR also integrates with other security solutions, such as firewalls, to provide a unified view of security across an organization&#039;s entire infrastructure. This allows security teams to quickly identify and respond to threats, even if they are spread across multiple systems and networks.&lt;br /&gt;
&lt;br /&gt;
The Cortex XDR platform also includes a cloud-based management console, which enables security teams to monitor and manage security across multiple locations and devices. It allows security teams to identify, investigate and respond to security incidents across all users, devices, and networks with a single console.&lt;br /&gt;
&lt;br /&gt;
=== Mimikatz ===&lt;br /&gt;
&lt;br /&gt;
Mimikatz is a tool that is used to extract sensitive information, such as login credentials, from Windows systems. The tool is often used by attackers to gain access to systems and networks after they have successfully compromised a system. Mimikatz is able to extract information from the Windows operating system&#039;s memory, and it can be used to extract credentials from a wide range of applications, including web browsers, email clients, and other software.&lt;br /&gt;
&lt;br /&gt;
Mimikatz can extract a variety of information, including:&lt;br /&gt;
&lt;br /&gt;
* Passwords stored in memory&lt;br /&gt;
* Encryption keys&lt;br /&gt;
* Hashes of passwords&lt;br /&gt;
* Kerberos tickets&lt;br /&gt;
* Credentials for services and scheduled tasks&lt;br /&gt;
&lt;br /&gt;
Mimikatz can also be used to perform actions such as:&lt;br /&gt;
&lt;br /&gt;
* Changing a password for a user account&lt;br /&gt;
* Adding new user account&lt;br /&gt;
* Dumping the LSASS process memory.&lt;br /&gt;
&lt;br /&gt;
Mimikatz is considered a powerful and dangerous tool, and its use in an unauthorized manner is illegal in some countries. It is important for organizations to be aware of the presence of Mimikatz and other similar tools on their systems, and to take steps to protect against their use. This can include regularly monitoring systems for suspicious activity, implementing strong access controls, and regularly updating software to patch known vulnerabilities.&lt;br /&gt;
&lt;br /&gt;
=== BC-Security / Empire ===&lt;br /&gt;
&lt;br /&gt;
Empire is a post-exploitation framework, often used by penetration testers and red teamers to perform various tasks on a compromised system. Empire is based on the PowerShell scripting language and it is a popular tool among attackers because of its ability to execute arbitrary PowerShell commands and scripts, and its ability to perform various post-exploitation tasks such as privilege escalation, key logging, and network reconnaissance.&lt;br /&gt;
&lt;br /&gt;
Empire is a modular framework that allows users to easily create and execute custom modules, making it a powerful and flexible tool. Empire also has the ability to communicate with a command and control (C2) server, which can be used to remotely control a compromised system.&lt;br /&gt;
&lt;br /&gt;
Empire is often used in combination with other tools such as Metasploit, Mimikatz, and Cobalt Strike to perform advanced attacks.&lt;br /&gt;
&lt;br /&gt;
It is important for organizations to be aware of the presence of Empire and other similar tools on their systems, and to take steps to protect against their use. This can include regularly monitoring systems for suspicious activity, implementing strong access controls, and regularly updating software to patch known vulnerabilities.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Porchetta-Industries / CrackMapExec ===&lt;br /&gt;
&lt;br /&gt;
CrackMapExec (CME) is a tool that is used to perform network reconnaissance and attack execution. It is often used by penetration testers and red teamers to enumerate and attack Windows-based systems on a network. CME is based on the SMB (Server Message Block) protocol, which is used to provide shared access to files, printers, and other resources on a network.&lt;br /&gt;
&lt;br /&gt;
CME can perform various tasks, including:&lt;br /&gt;
&lt;br /&gt;
Enumerating users, groups, and computers on a network&lt;br /&gt;
Dumping password hashes for offline cracking&lt;br /&gt;
Executing arbitrary commands or scripts on remote systems&lt;br /&gt;
Attempting to authenticate to remote systems using a list of provided credentials&lt;br /&gt;
CME is a powerful and fast tool, which can be used to quickly gather information about systems on a network. It is important for organizations to be aware of the presence of CME and other similar tools on their systems, and to take steps to protect against their use. This can include regularly monitoring systems for suspicious activity, implementing strong access controls, and regularly updating software to patch known vulnerabilities.&lt;br /&gt;
&lt;br /&gt;
It is important to note that using CME or any other tool that attempts to gain unauthorized access to systems is illegal in many countries and should only be used with explicit permission from the owner of the system.&lt;br /&gt;
&lt;br /&gt;
== Used Hardware ==&lt;br /&gt;
&lt;br /&gt;
HP Notebook&lt;br /&gt;
&lt;br /&gt;
== Used Software ==&lt;br /&gt;
&lt;br /&gt;
* Cortex XDR&lt;br /&gt;
* WannaCry Ransomware&lt;br /&gt;
* Cerber Ransomware&lt;br /&gt;
* Gentilkiwi / Mimikatz &lt;br /&gt;
* BC-Security / Empire &lt;br /&gt;
* Porchetta-Industries / CrackMapExec&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
*https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/7.9/Cortex-XDR-Agent-Administrator-Guide&lt;br /&gt;
*https://github.com/gentilkiwi/mimikatz&lt;br /&gt;
*https://github.com/Porchetta-Industries/CrackMapExec&lt;br /&gt;
*https://github.com/BC-SECURITY/Empire&lt;br /&gt;
*https://www.avast.com/de-de/c-cerber#:~:text=Link%20kopiert-,Was%20ist%20die%20Cerber%20Ransomware%3F,Sie%20wird%20eine%20L%C3%B6segeldzahlung%20verlangt.&lt;br /&gt;
*https://de.wikipedia.org/wiki/WannaCry&lt;br /&gt;
*&lt;br /&gt;
&lt;br /&gt;
[[Category:Documentation]]&lt;/div&gt;</summary>
		<author><name>FPaschinger</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=Rowhammer/Throwhammer/Nethammer&amp;diff=10952</id>
		<title>Rowhammer/Throwhammer/Nethammer</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=Rowhammer/Throwhammer/Nethammer&amp;diff=10952"/>
		<updated>2023-01-08T17:28:02Z</updated>

		<summary type="html">&lt;p&gt;FPaschinger: Created page with &amp;quot;== Summary ==   Rowhammer is an attack which manipulates bits stored in the DRAM without accessing them. It is working and does damage directly on the hardware. Throwhammer and Nethammer are further implementations of Rowhammer the basic concept therefore is the same the execution however is different. How exactly they work will be discussed in detail in the corresponding subsections. For demonstrating, the software &amp;quot;Hammertime&amp;quot; from the Systems and Network Security Grou...&amp;quot;&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Summary == &lt;br /&gt;
&lt;br /&gt;
Rowhammer is an attack which manipulates bits stored in the DRAM without accessing them. It is working and does damage directly on the hardware. Throwhammer and Nethammer are further implementations of Rowhammer the basic concept therefore is the same the execution however is different. How exactly they work will be discussed in detail in the corresponding subsections. For demonstrating, the software &amp;quot;Hammertime&amp;quot; from the Systems and Network Security Group at Vrije Universiteit Amsterdam is shown.&lt;br /&gt;
&lt;br /&gt;
== Requirements ==&lt;br /&gt;
&lt;br /&gt;
* Operating system: Ubuntu 18.04 bionic amd64&lt;br /&gt;
* Packages: git emacs&lt;br /&gt;
&lt;br /&gt;
== Description ==&lt;br /&gt;
&lt;br /&gt;
=== DRAM ===&lt;br /&gt;
&lt;br /&gt;
Even though the name Rowhammer does not give an idea what is it in first place when looking deeper at what it is it makes absolutely sense. Firstly, let&#039;s look at the DRAM which is the main victim of this attack. The DRAM consists of several rows and columns like a Matrix for example. A collection of rows is called a &amp;quot;bank&amp;quot; with the characteristic of each row sharing the same row buffer. Furthermore a collection of banks is called a rank. The DRAM cells are made out of a transistor and capacitor. Depending on the charge of the capacitor the value of the cell is either a 1 or a 0. Since the RAM is volatile, the charge in the cells must be refreshed regularly, so it does not loose the original value. When a row is accessed the horizontal line of the DRAM Matrix of the specific row called the word-line is activated. With the vertical line called the bit-line connecting the different rows vertically with each other. When the wordline is now given a high voltage the values of the row is written into the row buffer, where the values can be modified or read. &lt;br /&gt;
&lt;br /&gt;
=== Rowhammer ===&lt;br /&gt;
&lt;br /&gt;
Due to the development and enhancement of the performance of DRAMs the cells got denser. A team of researchers found out that, when a row is accessed multiple times and in this case multiple times are at least 139 thousand times within the refresh cycle which is 64 milliseconds for a DDR3 DRAM, disturbance errors occurred. Disturbance errors is a phenomenon where the charge of adjacent cells is leaking to the high amount of accesses of another row. In other words, when row A is accessed 139 thousand times at a minimum row B and C, both are neighbour rows, experience loss of the charge of cells. If the charge however, is not refreshed timely, the cell cannot reproduce the original value. This is called a bit flip. A 1 is recognized as a zero and vice versa.&lt;br /&gt;
&lt;br /&gt;
As mentioned at the beginning of this section, the row must be activated 139 thousand times. Therefore two things must be taken into consideration:&lt;br /&gt;
&lt;br /&gt;
# Cache eviction&lt;br /&gt;
# Closing row after being activated&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
The cache eviction mechanism manages the flushing of the row buffer, so that the row needs to be written into the cache again. Secondly, the row must be closed which happens automatically when another row is activated, if not the row must be closed manually. Rowhammer must be executed locally on the target machine for example via a software downloaded on to the device. &lt;br /&gt;
&lt;br /&gt;
=== Throwhammer ===&lt;br /&gt;
&lt;br /&gt;
An advanced technique of Rowhammer is the bit flip induction over the network with network packets called Throwhammer. Throwhammer requires a Remote Direct Access Memory enabled network. This allows to bypass the CPU when exchanging network packets, which enhances the performance of the network. Bit flips can be achieved when sending 560.000 packets as a minimum over a internet connection of at least 10Gbps. &lt;br /&gt;
&lt;br /&gt;
=== Nethammer ===&lt;br /&gt;
&lt;br /&gt;
Another Rowhammer attack caused by network packets is called Nethammer. This does not need the Remote Direct Access Part. All it needs is a fast internet connection and handcrafted packets. If there is an application on the target machine using uncached memory, bit flips can be induced. However, there are many ways to bypass a cache or to implement cache eviction mechanism, like: &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* evicting and reloading the addresses&lt;br /&gt;
* using uncached memory which is used on all ARM-based machines for interacting with the hardware&lt;br /&gt;
* using non-temporal instructions performing their operations directly on the DRAM&lt;br /&gt;
* flushing and reloading the addresses for example&lt;br /&gt;
&lt;br /&gt;
== Hammertime ==&lt;br /&gt;
&lt;br /&gt;
Hammertime is a software which simulates, profiles and tests the DRAM for the vulnerability.&lt;br /&gt;
&lt;br /&gt;
=== Step 1 ===&lt;br /&gt;
* git clone https://github.com/vusec/hammertime.git&lt;br /&gt;
* cd hammertime&lt;br /&gt;
* rm -rf ramses &lt;br /&gt;
* git rm --cached ramses&lt;br /&gt;
* git submodule add https://github.com/vusec/ramses.git&lt;br /&gt;
&lt;br /&gt;
go to hammertime root directory and build it with &lt;br /&gt;
* make&lt;br /&gt;
&lt;br /&gt;
Search for the memory configuration with&lt;br /&gt;
&lt;br /&gt;
* sudo ramses/tools/msys_detect.py&lt;br /&gt;
&lt;br /&gt;
Executing the code for profiling the vulnerability&lt;br /&gt;
&lt;br /&gt;
* sudo profile/profile --s 256m mem.msys&lt;br /&gt;
&lt;br /&gt;
Execute the code for profiling the vulnerability and store it in file&lt;br /&gt;
&lt;br /&gt;
* sudo profile/profile --s 256m mem.msys &amp;gt;&amp;gt; example.res&lt;br /&gt;
&lt;br /&gt;
Prettify the file to get a readable output&lt;br /&gt;
&lt;br /&gt;
* py/prettyprofile.py example.res&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
* https://ieeexplore.ieee.org/document/6853210&lt;br /&gt;
* https://ieeexplore.ieee.org/stamp/stamp.jsp?tp=&amp;amp;arnumber=9229701&lt;br /&gt;
* https://www.usenix.org/system/files/conference/atc18/atc18-tatar.pdf&lt;br /&gt;
&lt;br /&gt;
[[Category:Documentation]]&lt;/div&gt;</summary>
		<author><name>FPaschinger</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=AirDrive_Forensic_Keylogger_Cable&amp;diff=10465</id>
		<title>AirDrive Forensic Keylogger Cable</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=AirDrive_Forensic_Keylogger_Cable&amp;diff=10465"/>
		<updated>2022-12-12T17:39:54Z</updated>

		<summary type="html">&lt;p&gt;FPaschinger: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;[[File:AirDrive Forensic Keylogger Cable.PNG|250px|thumb|right|AirDrive Forensic Keylogger Cable]]&lt;br /&gt;
&lt;br /&gt;
== Summary == &lt;br /&gt;
&lt;br /&gt;
This keylogger is one with WiFi access and a minimized risk of detection. The USB keylogger module is hidden in a USB extension cable. Externally, the USB cable does not differ from conventional cables.&lt;br /&gt;
&lt;br /&gt;
The AirDrive Forensic Keylogger Module which was built into the cable is an ultra-small USB keylogger module designed for installation in a USB keyboard.  The small size makes it easy to install in any USB keyboard. This is available as standard and pro version. &lt;br /&gt;
Exact information can be found [https://www.keelog.com/de/forensic-keylogger/ here]. A video with detailed installation instructions can be found [https://www.youtube.com/watch?v=7AUssrySD2I here].&lt;br /&gt;
&lt;br /&gt;
[[File:AirDrive Forensic Keylogger Module.PNG|250px|thumb|right|AirDrive Forensic Keylogger Module]]&lt;br /&gt;
&lt;br /&gt;
== Characteristics ==&lt;br /&gt;
&lt;br /&gt;
* Stores input from any USB keyboard&lt;br /&gt;
* 16MB internal flash memory&lt;br /&gt;
* Undetectable by security software&lt;br /&gt;
* Supports over 40 national keyboard layouts&lt;br /&gt;
* Compatible with barcode readers&lt;br /&gt;
* Works as a wireless Wi-Fi hotspot&lt;br /&gt;
* Connect from any computer, smartphone or tablet&lt;br /&gt;
* Data access via web browser&lt;br /&gt;
* Remote data retrieval without touching the device&lt;br /&gt;
* Supports WEP, WPA and WPA-2 network security&lt;br /&gt;
* Memory secured by hardware encryption&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Description ==&lt;br /&gt;
&lt;br /&gt;
The AirDrive cable acts as a Wi-Fi hotspot. This means that the cable can establish a Wi-Fi connection with any Wi-Fi device (smartphone, tablet or laptop). The selected Wi-Fi device can then connect to the interface with the data protocol. There, there is the possibility to set configurations, such as the WLAN settings of the WLAN access point and the options for logging the keyboard strokes. Over 40 national keyboard layouts, including the world&#039;s most popular languages and keyboard layouts, are supported. Installation requires no additional software or drivers.&lt;br /&gt;
&lt;br /&gt;
=== Hands-On ===&lt;br /&gt;
&lt;br /&gt;
1.	Connect the USB keylogger cable to the external keyboard and the target host. 2.&lt;br /&gt;
&lt;br /&gt;
2.	Connect your smartphone, tablet or computer to the Wi-Fi network &amp;quot;AIR_XXYYZZ&amp;quot;, where &amp;quot;XXYYZZ&amp;quot; is the device ID of the USB cable. 3.&lt;br /&gt;
&lt;br /&gt;
3.	You can then use any web browser to access the interface under the IP &amp;quot;192.168.4.1&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
[[File:Webinterface 1.PNG|800px|thumb|none|]]&lt;br /&gt;
&lt;br /&gt;
4.	Open the settings to configure the keylogger cable. Various configurations can be made there:&lt;br /&gt;
&lt;br /&gt;
[[File:Webinterface 2.PNG|800px|thumb|none|]]&lt;br /&gt;
&lt;br /&gt;
[[File:Webinterface 3.PNG|800px|thumb|none|]]&lt;br /&gt;
&lt;br /&gt;
[[File:Webinterface 4.PNG|800px|thumb|none|]]&lt;br /&gt;
&lt;br /&gt;
To apply the settings, click on &amp;quot;Save data logging settings&amp;quot; and/or on “Save Access Point settings”.&lt;br /&gt;
&lt;br /&gt;
5.	Since this is not a &amp;quot;Pro&amp;quot; device, there are no advanced settings available. Features like an internet connection via the access point, timestamps, reporting via email and data streaming can be set via this sub-menu.&lt;br /&gt;
&lt;br /&gt;
6.	However, we can download the &amp;quot;Data Log&amp;quot; under the &amp;quot;Download&amp;quot; button, which can be several pages long.&lt;br /&gt;
&lt;br /&gt;
7.	With a click on &amp;quot;Data Log&amp;quot; we can observe what is typed on the external keyboard.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Example of a Data Log&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
In the following you can see a screenshot of a typical user logon process on the portal of the FH Campus Wien.&lt;br /&gt;
&lt;br /&gt;
[[File:Webinterface 5.PNG|800px|thumb|none|]]&lt;br /&gt;
&lt;br /&gt;
=== Important Legal Notice [1] ===&lt;br /&gt;
&lt;br /&gt;
The usage of a keylogger is fully legal as long as a clear notice is displayed, informing the user of the monitored equipment about the presence of a keystroke logger. We encourage the use of this equipment only for the purpose of monitoring your own computer, especially for protecting children against online hazards. It is NOT LEGAL to use a keylogger for the purpose of intercepting third party data, especially passwords, banking data, confidential correspondence, etc. If in doubt, please seek legal advice before using a keystroke logger. A good starting point is the U.S. Department of Justice Letter on Keystroke Monitoring and Login Banners, according to which a clear notice should be displayed, warning that user keystrokes may be logged.&lt;br /&gt;
&lt;br /&gt;
[[File:This PC is monitored.PNG|300px|thumb|none|]]&lt;br /&gt;
&lt;br /&gt;
== Hardware Used ==&lt;br /&gt;
&lt;br /&gt;
[[Forensic USB keylogger cable]]&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
* https://www.keelog.com/de/forensic-keylogger/&lt;br /&gt;
* https://www.keelog.com/airdrive-keylogger-max-premium-usb-hardware-keylogger-with-wifi-and-flash-email-and-live-data-transfer/&lt;/div&gt;</summary>
		<author><name>FPaschinger</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=AirDrive_Keylogger_Max&amp;diff=10464</id>
		<title>AirDrive Keylogger Max</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=AirDrive_Keylogger_Max&amp;diff=10464"/>
		<updated>2022-12-12T17:37:21Z</updated>

		<summary type="html">&lt;p&gt;FPaschinger: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;[[File:AirDrive Keylogger Max.PNG|350px|thumb|right|AirDrive Keylogger Max]]&lt;br /&gt;
&lt;br /&gt;
== Summary == &lt;br /&gt;
&lt;br /&gt;
The &#039;&#039;&#039;AirDrive Keylogger Max&#039;&#039;&#039; is comparable to the &#039;&#039;&#039;AirDrive Forensic Keylogger Cable (Pro Version)&#039;&#039;&#039;. &lt;br /&gt;
It has additional connectivity and more download options. It works both as a Wi-Fi hotspot, and as a Wi-Fi device, enabling features such as Email reports and time stamping. 8GB of built-in memory was used.&lt;br /&gt;
&lt;br /&gt;
== Features==&lt;br /&gt;
&lt;br /&gt;
* Records keystrokes from any USB keyboard&lt;br /&gt;
* 8 gigabytes of built-in memory&lt;br /&gt;
* Memory accessible as a USB Hi-speed flash drive (480 Mbps)&lt;br /&gt;
* Undetectable for security software&lt;br /&gt;
* Supports over 40 national keyboard layouts&lt;br /&gt;
* Compatible with barcode readers&lt;br /&gt;
* Works as a Wi-Fi hotspot, or as a Wi-Fi device&lt;br /&gt;
* Sends Email reports with recorded keystroke data&lt;br /&gt;
* Supports time-stamping&lt;br /&gt;
* Supports live data streaming over network&lt;br /&gt;
* Connect from any computer, smartphone, or tablet&lt;br /&gt;
* Access keystroke data from web browser&lt;br /&gt;
* Supports WEP, WPA, and WPA-2 network security &lt;br /&gt;
&lt;br /&gt;
== Description ==&lt;br /&gt;
&lt;br /&gt;
You don’t need any physical access to access the logged data. It is available on its interface, which is accessible by connecting to it over Wi-Fi. Once you are connected, you can view the logged data in real-time or just download it. &lt;br /&gt;
To hide the keylogger, you can erase the log, disable further logging, or even hide the WLAN network.&lt;br /&gt;
It is simply installed by just connecting any types of USB keyboards or barcode reader. Just connect the keylogger in-line with the keyboard and all keystrokes will be recorded.&lt;br /&gt;
&lt;br /&gt;
There are a lot of configuring options, which will be shown in the practical part. &lt;br /&gt;
&lt;br /&gt;
=== Hands-On ===&lt;br /&gt;
&lt;br /&gt;
&amp;amp;emsp;1. Connect the USB keylogger in-line with the external keyboard and the target host. &lt;br /&gt;
&lt;br /&gt;
&amp;amp;emsp;2. Connect your smartphone, tablet or computer to the Wi-Fi network &amp;quot;AIR_XXYYZZ&amp;quot;, where &amp;quot;XXYYZZ&amp;quot; is the device ID of the USB cable. &lt;br /&gt;
&lt;br /&gt;
&amp;amp;emsp;3. You can then use any web browser to access the interface under the IP &amp;quot;192.168.4.1&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
[[File:Web Interface 1.PNG|600px|thumb|none|]]&lt;br /&gt;
&lt;br /&gt;
&amp;amp;emsp;4. Open the settings to configure the keylogger cable. Various configurations can be made there:&lt;br /&gt;
&lt;br /&gt;
[[File:Web Interface 2.PNG|600px|thumb|none|]]&lt;br /&gt;
&lt;br /&gt;
[[File:Web Interface 3.PNG|600px|thumb|none|]]&lt;br /&gt;
&lt;br /&gt;
We can click on “Toggle Keyboard” to make the keylogger act as a normal flash drive. &lt;br /&gt;
&lt;br /&gt;
&amp;amp;emsp;5. Since the Keylogger Max version has more features, we can take a look at the advanced settings: For every of the advanced settings, an internet connection will be needed. &lt;br /&gt;
&lt;br /&gt;
[[File:Web Interface 4.PNG|600px|thumb|none|]]&lt;br /&gt;
&lt;br /&gt;
After you entered the SSID and the password of your WLAN network, you have to press the save button and restart the device, to activate the configurations. &lt;br /&gt;
&lt;br /&gt;
[[File:Web Interface 5.PNG|600px|thumb|none|]]&lt;br /&gt;
&lt;br /&gt;
You can also use a specific NTP server from https://ntp.org&lt;br /&gt;
After configuration, keystrokes will be shown with timestamps in data log.&lt;br /&gt;
&lt;br /&gt;
[[File:Web Interface 6.PNG|600px|thumb|none|]]&lt;br /&gt;
&lt;br /&gt;
Find out your SMTP server addresses either by command line or by an online-tool like https://www.dnswatch.info.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Example (if you would use GMAIL):&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
* Gmail SMTP server address: smtp.gmail.com&lt;br /&gt;
* Gmail SMTP name: Your full name&lt;br /&gt;
* Gmail SMTP username: Your full Gmail address (e.g. you@gmail.com)&lt;br /&gt;
* Gmail SMTP password: The password that you use to log in to Gmail&lt;br /&gt;
* Gmail SMTP port (TLS): 587&lt;br /&gt;
* Gmail SMTP port (SSL): 465&lt;br /&gt;
&lt;br /&gt;
Don’t forget to press the “Save” button.&lt;br /&gt;
&lt;br /&gt;
[[File:Web Interface 7.PNG|600px|thumb|none|]]&lt;br /&gt;
&lt;br /&gt;
The IP of the target out by typing “ipconfig” in the terminal (Windows) and reading out the local IP address. Choose a free target port of your choice. &lt;br /&gt;
&lt;br /&gt;
You can download a UDP client or use instead the example client, which was already linked in the there.&lt;br /&gt;
&lt;br /&gt;
Don’t forget to press the “Save” button.&lt;br /&gt;
Don’t forget to apply settings with pressing for each section the “Save … “-button.&lt;br /&gt;
&lt;br /&gt;
&amp;amp;emsp;6. We can download the “Data log” under the “Download” button.&lt;br /&gt;
&lt;br /&gt;
[[File:Web Interface 8.PNG|600px|thumb|none|]]&lt;br /&gt;
&lt;br /&gt;
&amp;amp;emsp;7. With a click on &amp;quot;Data Log&amp;quot; we can observe what is typed on the external keyboard.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Example of a Data Log&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
In the following you can see a screenshot of a typical user logon process on the portal of the FH Campus Wien.&lt;br /&gt;
&lt;br /&gt;
[[File:Web Interface 9.PNG|600px|thumb|none|]]&lt;br /&gt;
&lt;br /&gt;
=== Important Legal Notice [1] ===&lt;br /&gt;
&lt;br /&gt;
The usage of a keylogger is fully legal as long as a clear notice is displayed, informing the user of the monitored equipment about the presence of a keystroke logger. We encourage the use of this equipment only for the purpose of monitoring your own computer, especially for protecting children against online hazards. It is NOT LEGAL to use a keylogger for the purpose of intercepting third party data, especially passwords, banking data, confidential correspondence, etc. If in doubt, please seek legal advice before using a keystroke logger. A good starting point is the U.S. Department of Justice Letter on Keystroke Monitoring and Login Banners, according to which a clear notice should be displayed, warning that user keystrokes may be logged.&lt;br /&gt;
&lt;br /&gt;
[[File:This PC is monitored.PNG|600px|thumb|none|]]&lt;br /&gt;
&lt;br /&gt;
=== Keyboard compability limitations [1] ===&lt;br /&gt;
&lt;br /&gt;
The device will work with almost all types of physical USB keyboards (it won&#039;t work with internal laptop keyboards). It works fine with wireless keyboards, with exception of Bluetooth keyboards. It won&#039;t work a few types of keyboards with built-in high-speed USB hubs (primarily Apple A1243 and Dell KB522), for which the Mac/MCP series should be used. Support for some gaming keyboards is not fully guaranteed, as they often use proprietary protocols.&lt;br /&gt;
&lt;br /&gt;
== Hardware Used ==&lt;br /&gt;
&lt;br /&gt;
[[USB Keylogger Max 8GB]]&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
* https://www.keelog.com/airdrive-keylogger-max-premium-usb-hardware-keylogger-with-wifi-and-flash-email-and-live-data-transfer/&lt;/div&gt;</summary>
		<author><name>FPaschinger</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=USB_Armory&amp;diff=10463</id>
		<title>USB Armory</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=USB_Armory&amp;diff=10463"/>
		<updated>2022-12-12T17:33:21Z</updated>

		<summary type="html">&lt;p&gt;FPaschinger: /* Boot Mechanisms */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Introduction ==&lt;br /&gt;
Launched in 2014, USB Armory is a small and portable USB-sized personal computer created by Andrea Barisani &amp;lt;ref&amp;gt;Andrea Barisani. Forging the USB armory, https://www.youtube.com/watch?v=bE5licRHMFs ,2014.&amp;lt;/ref&amp;gt;. Originally intended to be produced as a secure data store, USB Armory managed to become a versatile device with the development of its Hardware and Software. With its hardware sufficient as a computer, it can be configured on an installed Linux system that boots and thus powers up when plugged into any computer, for example, so that data not only ends up on an encrypted partition but is automatically re-encrypted when transferred &amp;lt;ref&amp;gt;NXP Community, Introducing USB armory, an Open Source Hardware Freescale i.MX53 Dongle&lt;br /&gt;
, https://community.nxp.com/t5/i-MX-Solutions-Knowledge-Base/Introducing-USB-armory-an-Open-Source-Hardware-Freescale-i-MX53/ta-p/1126823, 2014&amp;lt;/ref&amp;gt; .&lt;br /&gt;
[[File:Usbarmory coin.jpeg|Firmware|thumb|center|500px|link=https://inversepath.com/usbarmory_mark-one.html|OPEN SOURCE FLASH-DRIVE SIZED COMPUTER &amp;lt;ref&amp;gt;Inverse Path, OPEN SOURCE FLASH-DRIVE SIZED COMPUTER, https://inversepath.com/usbarmory_mark-one.html&amp;lt;/ref&amp;gt;  ]]&lt;br /&gt;
&lt;br /&gt;
=== Hardware ===&lt;br /&gt;
* NXP i.MX53 ARM® Cortex™-A8 800MHz, 512MB DDR3 RAM&lt;br /&gt;
* USB host powered (&amp;lt;500 mA) device with compact form factor (65 x 19 x 6 mm)&lt;br /&gt;
* ARM® TrustZone®, secure boot + storage + RAM&lt;br /&gt;
* microSD card slot&lt;br /&gt;
* 5-pin breakout header with GPIOs and UART&lt;br /&gt;
* customizable LED, including secure mode detection&lt;br /&gt;
* excellent native support (Android, Debian, Ubuntu, Arch Linux)&lt;br /&gt;
* USB device emulation (CDC Ethernet, mass storage, HID, etc.)&lt;br /&gt;
* Open Hardware &amp;amp; Software &amp;lt;ref&amp;gt;Inverse Path, Hardware, https://inversepath.com/usbarmory_mark-one.html &amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
===Software ===&lt;br /&gt;
&lt;br /&gt;
* Native Linux support – creating boot images is easy&lt;br /&gt;
* Precompiled images are available for Debian 9 (Stretch) and Arch Linux, with more on the way&lt;br /&gt;
* USB device emulation (CDC Ethernet, mass storage, HID, etc.) &amp;lt;ref&amp;gt;Andrea Barisani, MK II Introduction, https://github.com/f-secure-foundry/usbarmory/wiki/Mk-II-Introduction#software&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== How to connected ===&lt;br /&gt;
* HS USB 2.0 On-The-Go (OTG) with device emulation&lt;br /&gt;
* TCP/IP communication via CDC Ethernet emulation&lt;br /&gt;
* flash drive functionality via mass storage device emulation&lt;br /&gt;
* serial communication over USB or physical UART&lt;br /&gt;
* stand-alone mode with dedicated host adapter &amp;lt;ref&amp;gt; Inverse Path, How to Connect, https://inversepath.com/usbarmory_mark-one.html &amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Application examples ==&lt;br /&gt;
&lt;br /&gt;
* Hardware Security Module (HSM)&lt;br /&gt;
* file storage with advanced features such as automatic encryption, virus scanning, host authentication and data self-destruct&lt;br /&gt;
* OpenSSH client and agent for untrusted hosts (kiosk)&lt;br /&gt;
* router for end-to-end VPN tunnelling, Tor&lt;br /&gt;
* password manager with integrated web server&lt;br /&gt;
* electronic wallet (e.g. pocket Bitcoin wallet)&lt;br /&gt;
* authentication token&lt;br /&gt;
* portable penetration testing platform&lt;br /&gt;
* low level USB security testing &amp;lt;ref&amp;gt;Inverse Path, Applications, https://inversepath.com/usbarmory_mark-one.html&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Getting Started  ==&lt;br /&gt;
=== Boot Mechanisms ===&lt;br /&gt;
In order for USB Armory to work in a certain operating system, either the microSD card inserted. &amp;lt;ref&amp;gt;Getting started, https://github.com/f-secure-foundry/usbarmory/wiki/Starting#getting-started&amp;lt;/ref&amp;gt;:&lt;br /&gt;
&lt;br /&gt;
USB Armory has a valid Pre-Image file for each operating system on its own page. Optionally, booting can be done either manually or by downloading the appropriate file and flashing the microSD card (before it is inserted into the USB Armory) with balenaEtcher software.&lt;br /&gt;
&lt;br /&gt;
=== 1. Step ===&lt;br /&gt;
&lt;br /&gt;
You can find the following Pre-Image files at this link: https://github.com/f-secure-foundry/usbarmory/wiki/Available-images&lt;br /&gt;
&lt;br /&gt;
[[File:Preimages.jpeg|thumb|center|500px|link=https://github.com/f-secure-foundry/usbarmory/wiki/Available-images|Available images &amp;lt;ref&amp;gt;Andrea Barisani, Available images, https://github.com/f-secure-foundry/usbarmory/wiki/Available-images&amp;lt;/ref&amp;gt; ]]&lt;br /&gt;
&lt;br /&gt;
=== 2. Step ===&lt;br /&gt;
&lt;br /&gt;
You can download the following software here: https://www.balena.io/etcher/&lt;br /&gt;
&lt;br /&gt;
[[File:balenaET.jpeg||thumb|center|500px|link=https://www.balena.io/etcher/|Flash OS images to SD cards &amp;amp; USB drives, safely and easily &amp;lt;ref&amp;gt;balenaEtcher, https://www.balena.io/etcher/&amp;lt;/ref&amp;gt;]]&lt;br /&gt;
&lt;br /&gt;
=== Host communication ===&lt;br /&gt;
Since the booted microSD card is ready in the operating system, Host communication can be started &amp;lt;ref&amp;gt;Andrea Barisani, Setup &amp;amp; Connection Sharing: Linux , https://github.com/f-secure-foundry/usbarmory/wiki/Host-communication#setup--connection-sharing-linux&amp;lt;/ref&amp;gt;.&lt;br /&gt;
&lt;br /&gt;
 # look up the name of the USB virtual Ethernet interface which was created by the USB Armory&lt;br /&gt;
 ifconfig&lt;br /&gt;
&lt;br /&gt;
 # bring the USB virtual Ethernet interface up&lt;br /&gt;
 /sbin/ip link set usb0 up&lt;br /&gt;
&lt;br /&gt;
 # set the host IP address&lt;br /&gt;
 /sbin/ip addr add 10.0.0.2/24 dev usb0&lt;br /&gt;
&lt;br /&gt;
 # enable masquerading for outgoing connections towards wireless interface&lt;br /&gt;
 /sbin/iptables -t nat -A POSTROUTING -s 10.0.0.1/32 -o wlan0 -j MASQUERADE&lt;br /&gt;
&lt;br /&gt;
 # enable IP forwarding&lt;br /&gt;
 sudo sysctl -w net.ipv4.ip_forward=1&lt;br /&gt;
&lt;br /&gt;
 #connect to USB Armory via ssh - password: USB armory&lt;br /&gt;
 ssh usbarmory@10.0.0.1&lt;br /&gt;
&lt;br /&gt;
 #install Lynx Web browser on USB Armory&lt;br /&gt;
 sudo apt-get install Lynx&lt;br /&gt;
&lt;br /&gt;
 #launch Lynx Web browser on USB Armory&lt;br /&gt;
 lynx google.com&lt;br /&gt;
&lt;br /&gt;
== Hardware Used ==&lt;br /&gt;
&lt;br /&gt;
[[USB armory + Enclosure]]&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[Category:Documentation]]&lt;/div&gt;</summary>
		<author><name>FPaschinger</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=USB_Armory&amp;diff=10462</id>
		<title>USB Armory</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=USB_Armory&amp;diff=10462"/>
		<updated>2022-12-12T17:30:40Z</updated>

		<summary type="html">&lt;p&gt;FPaschinger: /* Design Goals */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Introduction ==&lt;br /&gt;
Launched in 2014, USB Armory is a small and portable USB-sized personal computer created by Andrea Barisani &amp;lt;ref&amp;gt;Andrea Barisani. Forging the USB armory, https://www.youtube.com/watch?v=bE5licRHMFs ,2014.&amp;lt;/ref&amp;gt;. Originally intended to be produced as a secure data store, USB Armory managed to become a versatile device with the development of its Hardware and Software. With its hardware sufficient as a computer, it can be configured on an installed Linux system that boots and thus powers up when plugged into any computer, for example, so that data not only ends up on an encrypted partition but is automatically re-encrypted when transferred &amp;lt;ref&amp;gt;NXP Community, Introducing USB armory, an Open Source Hardware Freescale i.MX53 Dongle&lt;br /&gt;
, https://community.nxp.com/t5/i-MX-Solutions-Knowledge-Base/Introducing-USB-armory-an-Open-Source-Hardware-Freescale-i-MX53/ta-p/1126823, 2014&amp;lt;/ref&amp;gt; .&lt;br /&gt;
[[File:Usbarmory coin.jpeg|Firmware|thumb|center|500px|link=https://inversepath.com/usbarmory_mark-one.html|OPEN SOURCE FLASH-DRIVE SIZED COMPUTER &amp;lt;ref&amp;gt;Inverse Path, OPEN SOURCE FLASH-DRIVE SIZED COMPUTER, https://inversepath.com/usbarmory_mark-one.html&amp;lt;/ref&amp;gt;  ]]&lt;br /&gt;
&lt;br /&gt;
=== Hardware ===&lt;br /&gt;
* NXP i.MX53 ARM® Cortex™-A8 800MHz, 512MB DDR3 RAM&lt;br /&gt;
* USB host powered (&amp;lt;500 mA) device with compact form factor (65 x 19 x 6 mm)&lt;br /&gt;
* ARM® TrustZone®, secure boot + storage + RAM&lt;br /&gt;
* microSD card slot&lt;br /&gt;
* 5-pin breakout header with GPIOs and UART&lt;br /&gt;
* customizable LED, including secure mode detection&lt;br /&gt;
* excellent native support (Android, Debian, Ubuntu, Arch Linux)&lt;br /&gt;
* USB device emulation (CDC Ethernet, mass storage, HID, etc.)&lt;br /&gt;
* Open Hardware &amp;amp; Software &amp;lt;ref&amp;gt;Inverse Path, Hardware, https://inversepath.com/usbarmory_mark-one.html &amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
===Software ===&lt;br /&gt;
&lt;br /&gt;
* Native Linux support – creating boot images is easy&lt;br /&gt;
* Precompiled images are available for Debian 9 (Stretch) and Arch Linux, with more on the way&lt;br /&gt;
* USB device emulation (CDC Ethernet, mass storage, HID, etc.) &amp;lt;ref&amp;gt;Andrea Barisani, MK II Introduction, https://github.com/f-secure-foundry/usbarmory/wiki/Mk-II-Introduction#software&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== How to connected ===&lt;br /&gt;
* HS USB 2.0 On-The-Go (OTG) with device emulation&lt;br /&gt;
* TCP/IP communication via CDC Ethernet emulation&lt;br /&gt;
* flash drive functionality via mass storage device emulation&lt;br /&gt;
* serial communication over USB or physical UART&lt;br /&gt;
* stand-alone mode with dedicated host adapter &amp;lt;ref&amp;gt; Inverse Path, How to Connect, https://inversepath.com/usbarmory_mark-one.html &amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Application examples ==&lt;br /&gt;
&lt;br /&gt;
* Hardware Security Module (HSM)&lt;br /&gt;
* file storage with advanced features such as automatic encryption, virus scanning, host authentication and data self-destruct&lt;br /&gt;
* OpenSSH client and agent for untrusted hosts (kiosk)&lt;br /&gt;
* router for end-to-end VPN tunnelling, Tor&lt;br /&gt;
* password manager with integrated web server&lt;br /&gt;
* electronic wallet (e.g. pocket Bitcoin wallet)&lt;br /&gt;
* authentication token&lt;br /&gt;
* portable penetration testing platform&lt;br /&gt;
* low level USB security testing &amp;lt;ref&amp;gt;Inverse Path, Applications, https://inversepath.com/usbarmory_mark-one.html&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Getting Started  ==&lt;br /&gt;
=== Boot Mechanisms ===&lt;br /&gt;
In order for USB Armory to work in a certain operating system, either the microSD card inserted. &amp;lt;ref&amp;gt;Getting started, https://github.com/f-secure-foundry/usbarmory/wiki/Starting#getting-started&amp;lt;/ref&amp;gt;:&lt;br /&gt;
&lt;br /&gt;
USB Armory has a valid Pre-Image file for each operating system on its own page. Optionally, booting can be done either manually or by downloading the appropriate file and flashing the microSD card (before it is inserted into the USB Armory) with balenaEtcher software &amp;lt;ref name=&amp;quot;And&amp;quot;/&amp;gt;.&lt;br /&gt;
&lt;br /&gt;
=== 1. Step ===&lt;br /&gt;
&lt;br /&gt;
You can find the following Pre-Image files at this link: https://github.com/f-secure-foundry/usbarmory/wiki/Available-images&lt;br /&gt;
&lt;br /&gt;
[[File:Preimages.jpeg|thumb|center|500px|link=https://github.com/f-secure-foundry/usbarmory/wiki/Available-images|Available images &amp;lt;ref&amp;gt;Andrea Barisani, Available images, https://github.com/f-secure-foundry/usbarmory/wiki/Available-images&amp;lt;/ref&amp;gt; ]]&lt;br /&gt;
&lt;br /&gt;
=== 2. Step ===&lt;br /&gt;
&lt;br /&gt;
You can download the following software here: https://www.balena.io/etcher/&lt;br /&gt;
&lt;br /&gt;
[[File:balenaET.jpeg||thumb|center|500px|link=https://www.balena.io/etcher/|Flash OS images to SD cards &amp;amp; USB drives, safely and easily &amp;lt;ref&amp;gt;balenaEtcher, https://www.balena.io/etcher/&amp;lt;/ref&amp;gt;]]&lt;br /&gt;
&lt;br /&gt;
=== Host communication ===&lt;br /&gt;
Since the booted microSD card is ready in the operating system, Host communication can be started &amp;lt;ref&amp;gt;Andrea Barisani, Setup &amp;amp; Connection Sharing: Linux , https://github.com/f-secure-foundry/usbarmory/wiki/Host-communication#setup--connection-sharing-linux&amp;lt;/ref&amp;gt;.&lt;br /&gt;
&lt;br /&gt;
 # look up the name of the USB virtual Ethernet interface which was created by the USB Armory&lt;br /&gt;
 ifconfig&lt;br /&gt;
&lt;br /&gt;
 # bring the USB virtual Ethernet interface up&lt;br /&gt;
 /sbin/ip link set usb0 up&lt;br /&gt;
&lt;br /&gt;
 # set the host IP address&lt;br /&gt;
 /sbin/ip addr add 10.0.0.2/24 dev usb0&lt;br /&gt;
&lt;br /&gt;
 # enable masquerading for outgoing connections towards wireless interface&lt;br /&gt;
 /sbin/iptables -t nat -A POSTROUTING -s 10.0.0.1/32 -o wlan0 -j MASQUERADE&lt;br /&gt;
&lt;br /&gt;
 # enable IP forwarding&lt;br /&gt;
 sudo sysctl -w net.ipv4.ip_forward=1&lt;br /&gt;
&lt;br /&gt;
 #connect to USB Armory via ssh - password: USB armory&lt;br /&gt;
 ssh usbarmory@10.0.0.1&lt;br /&gt;
&lt;br /&gt;
 #install Lynx Web browser on USB Armory&lt;br /&gt;
 sudo apt-get install Lynx&lt;br /&gt;
&lt;br /&gt;
 #launch Lynx Web browser on USB Armory&lt;br /&gt;
 lynx google.com&lt;br /&gt;
&lt;br /&gt;
== Hardware Used ==&lt;br /&gt;
&lt;br /&gt;
[[USB armory + Enclosure]]&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[Category:Documentation]]&lt;/div&gt;</summary>
		<author><name>FPaschinger</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=USB_Armory&amp;diff=10461</id>
		<title>USB Armory</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=USB_Armory&amp;diff=10461"/>
		<updated>2022-12-12T17:30:22Z</updated>

		<summary type="html">&lt;p&gt;FPaschinger: /* Hardware */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Introduction ==&lt;br /&gt;
Launched in 2014, USB Armory is a small and portable USB-sized personal computer created by Andrea Barisani &amp;lt;ref&amp;gt;Andrea Barisani. Forging the USB armory, https://www.youtube.com/watch?v=bE5licRHMFs ,2014.&amp;lt;/ref&amp;gt;. Originally intended to be produced as a secure data store, USB Armory managed to become a versatile device with the development of its Hardware and Software. With its hardware sufficient as a computer, it can be configured on an installed Linux system that boots and thus powers up when plugged into any computer, for example, so that data not only ends up on an encrypted partition but is automatically re-encrypted when transferred &amp;lt;ref&amp;gt;NXP Community, Introducing USB armory, an Open Source Hardware Freescale i.MX53 Dongle&lt;br /&gt;
, https://community.nxp.com/t5/i-MX-Solutions-Knowledge-Base/Introducing-USB-armory-an-Open-Source-Hardware-Freescale-i-MX53/ta-p/1126823, 2014&amp;lt;/ref&amp;gt; .&lt;br /&gt;
[[File:Usbarmory coin.jpeg|Firmware|thumb|center|500px|link=https://inversepath.com/usbarmory_mark-one.html|OPEN SOURCE FLASH-DRIVE SIZED COMPUTER &amp;lt;ref&amp;gt;Inverse Path, OPEN SOURCE FLASH-DRIVE SIZED COMPUTER, https://inversepath.com/usbarmory_mark-one.html&amp;lt;/ref&amp;gt;  ]]&lt;br /&gt;
&lt;br /&gt;
== Design Goals ==&lt;br /&gt;
* The microSD hinge replacement with a push/pull slot.&lt;br /&gt;
* Real USB plugs, plug + socket for integrated host adapter.&lt;br /&gt;
* Enclosure design right from the beginning.&lt;br /&gt;
* Full internal and third-party security audit for HABv4 and chain of trust.&lt;br /&gt;
* Addition of built-in eMMC storage and external crypto authenticator.&lt;br /&gt;
* Bluetooth communication &amp;lt;ref&amp;gt;Andrea Barisani, USB ARMORY RELOADED, https://www.nohat.it/2019/slides/nohat_barisani.pdf, 2019&amp;lt;/ref&amp;gt;.&lt;br /&gt;
&lt;br /&gt;
=== Hardware ===&lt;br /&gt;
* NXP i.MX53 ARM® Cortex™-A8 800MHz, 512MB DDR3 RAM&lt;br /&gt;
* USB host powered (&amp;lt;500 mA) device with compact form factor (65 x 19 x 6 mm)&lt;br /&gt;
* ARM® TrustZone®, secure boot + storage + RAM&lt;br /&gt;
* microSD card slot&lt;br /&gt;
* 5-pin breakout header with GPIOs and UART&lt;br /&gt;
* customizable LED, including secure mode detection&lt;br /&gt;
* excellent native support (Android, Debian, Ubuntu, Arch Linux)&lt;br /&gt;
* USB device emulation (CDC Ethernet, mass storage, HID, etc.)&lt;br /&gt;
* Open Hardware &amp;amp; Software &amp;lt;ref&amp;gt;Inverse Path, Hardware, https://inversepath.com/usbarmory_mark-one.html &amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
===Software ===&lt;br /&gt;
&lt;br /&gt;
* Native Linux support – creating boot images is easy&lt;br /&gt;
* Precompiled images are available for Debian 9 (Stretch) and Arch Linux, with more on the way&lt;br /&gt;
* USB device emulation (CDC Ethernet, mass storage, HID, etc.) &amp;lt;ref&amp;gt;Andrea Barisani, MK II Introduction, https://github.com/f-secure-foundry/usbarmory/wiki/Mk-II-Introduction#software&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== How to connected ===&lt;br /&gt;
* HS USB 2.0 On-The-Go (OTG) with device emulation&lt;br /&gt;
* TCP/IP communication via CDC Ethernet emulation&lt;br /&gt;
* flash drive functionality via mass storage device emulation&lt;br /&gt;
* serial communication over USB or physical UART&lt;br /&gt;
* stand-alone mode with dedicated host adapter &amp;lt;ref&amp;gt; Inverse Path, How to Connect, https://inversepath.com/usbarmory_mark-one.html &amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Application examples ==&lt;br /&gt;
&lt;br /&gt;
* Hardware Security Module (HSM)&lt;br /&gt;
* file storage with advanced features such as automatic encryption, virus scanning, host authentication and data self-destruct&lt;br /&gt;
* OpenSSH client and agent for untrusted hosts (kiosk)&lt;br /&gt;
* router for end-to-end VPN tunnelling, Tor&lt;br /&gt;
* password manager with integrated web server&lt;br /&gt;
* electronic wallet (e.g. pocket Bitcoin wallet)&lt;br /&gt;
* authentication token&lt;br /&gt;
* portable penetration testing platform&lt;br /&gt;
* low level USB security testing &amp;lt;ref&amp;gt;Inverse Path, Applications, https://inversepath.com/usbarmory_mark-one.html&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Getting Started  ==&lt;br /&gt;
=== Boot Mechanisms ===&lt;br /&gt;
In order for USB Armory to work in a certain operating system, either the microSD card inserted. &amp;lt;ref&amp;gt;Getting started, https://github.com/f-secure-foundry/usbarmory/wiki/Starting#getting-started&amp;lt;/ref&amp;gt;:&lt;br /&gt;
&lt;br /&gt;
USB Armory has a valid Pre-Image file for each operating system on its own page. Optionally, booting can be done either manually or by downloading the appropriate file and flashing the microSD card (before it is inserted into the USB Armory) with balenaEtcher software &amp;lt;ref name=&amp;quot;And&amp;quot;/&amp;gt;.&lt;br /&gt;
&lt;br /&gt;
=== 1. Step ===&lt;br /&gt;
&lt;br /&gt;
You can find the following Pre-Image files at this link: https://github.com/f-secure-foundry/usbarmory/wiki/Available-images&lt;br /&gt;
&lt;br /&gt;
[[File:Preimages.jpeg|thumb|center|500px|link=https://github.com/f-secure-foundry/usbarmory/wiki/Available-images|Available images &amp;lt;ref&amp;gt;Andrea Barisani, Available images, https://github.com/f-secure-foundry/usbarmory/wiki/Available-images&amp;lt;/ref&amp;gt; ]]&lt;br /&gt;
&lt;br /&gt;
=== 2. Step ===&lt;br /&gt;
&lt;br /&gt;
You can download the following software here: https://www.balena.io/etcher/&lt;br /&gt;
&lt;br /&gt;
[[File:balenaET.jpeg||thumb|center|500px|link=https://www.balena.io/etcher/|Flash OS images to SD cards &amp;amp; USB drives, safely and easily &amp;lt;ref&amp;gt;balenaEtcher, https://www.balena.io/etcher/&amp;lt;/ref&amp;gt;]]&lt;br /&gt;
&lt;br /&gt;
=== Host communication ===&lt;br /&gt;
Since the booted microSD card is ready in the operating system, Host communication can be started &amp;lt;ref&amp;gt;Andrea Barisani, Setup &amp;amp; Connection Sharing: Linux , https://github.com/f-secure-foundry/usbarmory/wiki/Host-communication#setup--connection-sharing-linux&amp;lt;/ref&amp;gt;.&lt;br /&gt;
&lt;br /&gt;
 # look up the name of the USB virtual Ethernet interface which was created by the USB Armory&lt;br /&gt;
 ifconfig&lt;br /&gt;
&lt;br /&gt;
 # bring the USB virtual Ethernet interface up&lt;br /&gt;
 /sbin/ip link set usb0 up&lt;br /&gt;
&lt;br /&gt;
 # set the host IP address&lt;br /&gt;
 /sbin/ip addr add 10.0.0.2/24 dev usb0&lt;br /&gt;
&lt;br /&gt;
 # enable masquerading for outgoing connections towards wireless interface&lt;br /&gt;
 /sbin/iptables -t nat -A POSTROUTING -s 10.0.0.1/32 -o wlan0 -j MASQUERADE&lt;br /&gt;
&lt;br /&gt;
 # enable IP forwarding&lt;br /&gt;
 sudo sysctl -w net.ipv4.ip_forward=1&lt;br /&gt;
&lt;br /&gt;
 #connect to USB Armory via ssh - password: USB armory&lt;br /&gt;
 ssh usbarmory@10.0.0.1&lt;br /&gt;
&lt;br /&gt;
 #install Lynx Web browser on USB Armory&lt;br /&gt;
 sudo apt-get install Lynx&lt;br /&gt;
&lt;br /&gt;
 #launch Lynx Web browser on USB Armory&lt;br /&gt;
 lynx google.com&lt;br /&gt;
&lt;br /&gt;
== Hardware Used ==&lt;br /&gt;
&lt;br /&gt;
[[USB armory + Enclosure]]&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[Category:Documentation]]&lt;/div&gt;</summary>
		<author><name>FPaschinger</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=USB_Armory&amp;diff=10460</id>
		<title>USB Armory</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=USB_Armory&amp;diff=10460"/>
		<updated>2022-12-12T17:28:25Z</updated>

		<summary type="html">&lt;p&gt;FPaschinger: /* Getting Started */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Introduction ==&lt;br /&gt;
Launched in 2014, USB Armory is a small and portable USB-sized personal computer created by Andrea Barisani &amp;lt;ref&amp;gt;Andrea Barisani. Forging the USB armory, https://www.youtube.com/watch?v=bE5licRHMFs ,2014.&amp;lt;/ref&amp;gt;. Originally intended to be produced as a secure data store, USB Armory managed to become a versatile device with the development of its Hardware and Software. With its hardware sufficient as a computer, it can be configured on an installed Linux system that boots and thus powers up when plugged into any computer, for example, so that data not only ends up on an encrypted partition but is automatically re-encrypted when transferred &amp;lt;ref&amp;gt;NXP Community, Introducing USB armory, an Open Source Hardware Freescale i.MX53 Dongle&lt;br /&gt;
, https://community.nxp.com/t5/i-MX-Solutions-Knowledge-Base/Introducing-USB-armory-an-Open-Source-Hardware-Freescale-i-MX53/ta-p/1126823, 2014&amp;lt;/ref&amp;gt; .&lt;br /&gt;
[[File:Usbarmory coin.jpeg|Firmware|thumb|center|500px|link=https://inversepath.com/usbarmory_mark-one.html|OPEN SOURCE FLASH-DRIVE SIZED COMPUTER &amp;lt;ref&amp;gt;Inverse Path, OPEN SOURCE FLASH-DRIVE SIZED COMPUTER, https://inversepath.com/usbarmory_mark-one.html&amp;lt;/ref&amp;gt;  ]]&lt;br /&gt;
&lt;br /&gt;
== Design Goals ==&lt;br /&gt;
* The microSD hinge replacement with a push/pull slot.&lt;br /&gt;
* Real USB plugs, plug + socket for integrated host adapter.&lt;br /&gt;
* Enclosure design right from the beginning.&lt;br /&gt;
* Full internal and third-party security audit for HABv4 and chain of trust.&lt;br /&gt;
* Addition of built-in eMMC storage and external crypto authenticator.&lt;br /&gt;
* Bluetooth communication &amp;lt;ref&amp;gt;Andrea Barisani, USB ARMORY RELOADED, https://www.nohat.it/2019/slides/nohat_barisani.pdf, 2019&amp;lt;/ref&amp;gt;.&lt;br /&gt;
&lt;br /&gt;
=== Hardware ===&lt;br /&gt;
* NXP i.MX53 ARM® Cortex™-A8 800MHz, 512MB DDR3 RAM&lt;br /&gt;
* USB host powered (&amp;lt;500 mA) device with compact form factor (65 x 19 x 6 mm)&lt;br /&gt;
* ARM® TrustZone®, secure boot + storage + RAM&lt;br /&gt;
* microSD card slot&lt;br /&gt;
* 5-pin breakout header with GPIOs and UART&lt;br /&gt;
* customizable LED, including secure mode detection&lt;br /&gt;
* excellent native support (Android, Debian, Ubuntu, Arch Linux)&lt;br /&gt;
* USB device emulation (CDC Ethernet, mass storage, HID, etc.)&lt;br /&gt;
* Open Hardware &amp;amp; Software&lt;br /&gt;
&lt;br /&gt;
===Software ===&lt;br /&gt;
&lt;br /&gt;
* Native Linux support – creating boot images is easy&lt;br /&gt;
* Precompiled images are available for Debian 9 (Stretch) and Arch Linux, with more on the way&lt;br /&gt;
* USB device emulation (CDC Ethernet, mass storage, HID, etc.) &amp;lt;ref&amp;gt;Andrea Barisani, MK II Introduction, https://github.com/f-secure-foundry/usbarmory/wiki/Mk-II-Introduction#software&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== How to connected ===&lt;br /&gt;
* HS USB 2.0 On-The-Go (OTG) with device emulation&lt;br /&gt;
* TCP/IP communication via CDC Ethernet emulation&lt;br /&gt;
* flash drive functionality via mass storage device emulation&lt;br /&gt;
* serial communication over USB or physical UART&lt;br /&gt;
* stand-alone mode with dedicated host adapter &amp;lt;ref&amp;gt; Inverse Path, How to Connect, https://inversepath.com/usbarmory_mark-one.html &amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Application examples ==&lt;br /&gt;
&lt;br /&gt;
* Hardware Security Module (HSM)&lt;br /&gt;
* file storage with advanced features such as automatic encryption, virus scanning, host authentication and data self-destruct&lt;br /&gt;
* OpenSSH client and agent for untrusted hosts (kiosk)&lt;br /&gt;
* router for end-to-end VPN tunnelling, Tor&lt;br /&gt;
* password manager with integrated web server&lt;br /&gt;
* electronic wallet (e.g. pocket Bitcoin wallet)&lt;br /&gt;
* authentication token&lt;br /&gt;
* portable penetration testing platform&lt;br /&gt;
* low level USB security testing &amp;lt;ref&amp;gt;Inverse Path, Applications, https://inversepath.com/usbarmory_mark-one.html&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Getting Started  ==&lt;br /&gt;
=== Boot Mechanisms ===&lt;br /&gt;
In order for USB Armory to work in a certain operating system, either the microSD card inserted. &amp;lt;ref&amp;gt;Getting started, https://github.com/f-secure-foundry/usbarmory/wiki/Starting#getting-started&amp;lt;/ref&amp;gt;:&lt;br /&gt;
&lt;br /&gt;
USB Armory has a valid Pre-Image file for each operating system on its own page. Optionally, booting can be done either manually or by downloading the appropriate file and flashing the microSD card (before it is inserted into the USB Armory) with balenaEtcher software &amp;lt;ref name=&amp;quot;And&amp;quot;/&amp;gt;.&lt;br /&gt;
&lt;br /&gt;
=== 1. Step ===&lt;br /&gt;
&lt;br /&gt;
You can find the following Pre-Image files at this link: https://github.com/f-secure-foundry/usbarmory/wiki/Available-images&lt;br /&gt;
&lt;br /&gt;
[[File:Preimages.jpeg|thumb|center|500px|link=https://github.com/f-secure-foundry/usbarmory/wiki/Available-images|Available images &amp;lt;ref&amp;gt;Andrea Barisani, Available images, https://github.com/f-secure-foundry/usbarmory/wiki/Available-images&amp;lt;/ref&amp;gt; ]]&lt;br /&gt;
&lt;br /&gt;
=== 2. Step ===&lt;br /&gt;
&lt;br /&gt;
You can download the following software here: https://www.balena.io/etcher/&lt;br /&gt;
&lt;br /&gt;
[[File:balenaET.jpeg||thumb|center|500px|link=https://www.balena.io/etcher/|Flash OS images to SD cards &amp;amp; USB drives, safely and easily &amp;lt;ref&amp;gt;balenaEtcher, https://www.balena.io/etcher/&amp;lt;/ref&amp;gt;]]&lt;br /&gt;
&lt;br /&gt;
=== Host communication ===&lt;br /&gt;
Since the booted microSD card is ready in the operating system, Host communication can be started &amp;lt;ref&amp;gt;Andrea Barisani, Setup &amp;amp; Connection Sharing: Linux , https://github.com/f-secure-foundry/usbarmory/wiki/Host-communication#setup--connection-sharing-linux&amp;lt;/ref&amp;gt;.&lt;br /&gt;
&lt;br /&gt;
 # look up the name of the USB virtual Ethernet interface which was created by the USB Armory&lt;br /&gt;
 ifconfig&lt;br /&gt;
&lt;br /&gt;
 # bring the USB virtual Ethernet interface up&lt;br /&gt;
 /sbin/ip link set usb0 up&lt;br /&gt;
&lt;br /&gt;
 # set the host IP address&lt;br /&gt;
 /sbin/ip addr add 10.0.0.2/24 dev usb0&lt;br /&gt;
&lt;br /&gt;
 # enable masquerading for outgoing connections towards wireless interface&lt;br /&gt;
 /sbin/iptables -t nat -A POSTROUTING -s 10.0.0.1/32 -o wlan0 -j MASQUERADE&lt;br /&gt;
&lt;br /&gt;
 # enable IP forwarding&lt;br /&gt;
 sudo sysctl -w net.ipv4.ip_forward=1&lt;br /&gt;
&lt;br /&gt;
 #connect to USB Armory via ssh - password: USB armory&lt;br /&gt;
 ssh usbarmory@10.0.0.1&lt;br /&gt;
&lt;br /&gt;
 #install Lynx Web browser on USB Armory&lt;br /&gt;
 sudo apt-get install Lynx&lt;br /&gt;
&lt;br /&gt;
 #launch Lynx Web browser on USB Armory&lt;br /&gt;
 lynx google.com&lt;br /&gt;
&lt;br /&gt;
== Hardware Used ==&lt;br /&gt;
&lt;br /&gt;
[[USB armory + Enclosure]]&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[Category:Documentation]]&lt;/div&gt;</summary>
		<author><name>FPaschinger</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=USB_Armory&amp;diff=10459</id>
		<title>USB Armory</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=USB_Armory&amp;diff=10459"/>
		<updated>2022-12-12T17:11:08Z</updated>

		<summary type="html">&lt;p&gt;FPaschinger: /* Software */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Introduction ==&lt;br /&gt;
Launched in 2014, USB Armory is a small and portable USB-sized personal computer created by Andrea Barisani &amp;lt;ref&amp;gt;Andrea Barisani. Forging the USB armory, https://www.youtube.com/watch?v=bE5licRHMFs ,2014.&amp;lt;/ref&amp;gt;. Originally intended to be produced as a secure data store, USB Armory managed to become a versatile device with the development of its Hardware and Software. With its hardware sufficient as a computer, it can be configured on an installed Linux system that boots and thus powers up when plugged into any computer, for example, so that data not only ends up on an encrypted partition but is automatically re-encrypted when transferred &amp;lt;ref&amp;gt;NXP Community, Introducing USB armory, an Open Source Hardware Freescale i.MX53 Dongle&lt;br /&gt;
, https://community.nxp.com/t5/i-MX-Solutions-Knowledge-Base/Introducing-USB-armory-an-Open-Source-Hardware-Freescale-i-MX53/ta-p/1126823, 2014&amp;lt;/ref&amp;gt; .&lt;br /&gt;
[[File:Usbarmory coin.jpeg|Firmware|thumb|center|500px|link=https://inversepath.com/usbarmory_mark-one.html|OPEN SOURCE FLASH-DRIVE SIZED COMPUTER &amp;lt;ref&amp;gt;Inverse Path, OPEN SOURCE FLASH-DRIVE SIZED COMPUTER, https://inversepath.com/usbarmory_mark-one.html&amp;lt;/ref&amp;gt;  ]]&lt;br /&gt;
&lt;br /&gt;
== Design Goals ==&lt;br /&gt;
* The microSD hinge replacement with a push/pull slot.&lt;br /&gt;
* Real USB plugs, plug + socket for integrated host adapter.&lt;br /&gt;
* Enclosure design right from the beginning.&lt;br /&gt;
* Full internal and third-party security audit for HABv4 and chain of trust.&lt;br /&gt;
* Addition of built-in eMMC storage and external crypto authenticator.&lt;br /&gt;
* Bluetooth communication &amp;lt;ref&amp;gt;Andrea Barisani, USB ARMORY RELOADED, https://www.nohat.it/2019/slides/nohat_barisani.pdf, 2019&amp;lt;/ref&amp;gt;.&lt;br /&gt;
&lt;br /&gt;
=== Hardware ===&lt;br /&gt;
* NXP i.MX53 ARM® Cortex™-A8 800MHz, 512MB DDR3 RAM&lt;br /&gt;
* USB host powered (&amp;lt;500 mA) device with compact form factor (65 x 19 x 6 mm)&lt;br /&gt;
* ARM® TrustZone®, secure boot + storage + RAM&lt;br /&gt;
* microSD card slot&lt;br /&gt;
* 5-pin breakout header with GPIOs and UART&lt;br /&gt;
* customizable LED, including secure mode detection&lt;br /&gt;
* excellent native support (Android, Debian, Ubuntu, Arch Linux)&lt;br /&gt;
* USB device emulation (CDC Ethernet, mass storage, HID, etc.)&lt;br /&gt;
* Open Hardware &amp;amp; Software&lt;br /&gt;
&lt;br /&gt;
===Software ===&lt;br /&gt;
&lt;br /&gt;
* Native Linux support – creating boot images is easy&lt;br /&gt;
* Precompiled images are available for Debian 9 (Stretch) and Arch Linux, with more on the way&lt;br /&gt;
* USB device emulation (CDC Ethernet, mass storage, HID, etc.) &amp;lt;ref&amp;gt;Andrea Barisani, MK II Introduction, https://github.com/f-secure-foundry/usbarmory/wiki/Mk-II-Introduction#software&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== How to connected ===&lt;br /&gt;
* HS USB 2.0 On-The-Go (OTG) with device emulation&lt;br /&gt;
* TCP/IP communication via CDC Ethernet emulation&lt;br /&gt;
* flash drive functionality via mass storage device emulation&lt;br /&gt;
* serial communication over USB or physical UART&lt;br /&gt;
* stand-alone mode with dedicated host adapter &amp;lt;ref&amp;gt; Inverse Path, How to Connect, https://inversepath.com/usbarmory_mark-one.html &amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Application examples ==&lt;br /&gt;
&lt;br /&gt;
* Hardware Security Module (HSM)&lt;br /&gt;
* file storage with advanced features such as automatic encryption, virus scanning, host authentication and data self-destruct&lt;br /&gt;
* OpenSSH client and agent for untrusted hosts (kiosk)&lt;br /&gt;
* router for end-to-end VPN tunnelling, Tor&lt;br /&gt;
* password manager with integrated web server&lt;br /&gt;
* electronic wallet (e.g. pocket Bitcoin wallet)&lt;br /&gt;
* authentication token&lt;br /&gt;
* portable penetration testing platform&lt;br /&gt;
* low level USB security testing &amp;lt;ref&amp;gt;Inverse Path, Applications, https://inversepath.com/usbarmory_mark-one.html&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Getting Started  ==&lt;br /&gt;
=== Boot Mechanisms ===&lt;br /&gt;
In order for USB Armory to work in a certain operating system, either the microSD card inserted in the device or the MMc (16 GB) in it must be booted. Mk II supports 3 boot mechanisms &amp;lt;ref&amp;gt;Getting started, https://github.com/f-secure-foundry/usbarmory/wiki/Starting#getting-started&amp;lt;/ref&amp;gt;:&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[File:Armory-mark-two-boot-switch.png||Firmware|thumb|center|500px|link=https://github.com/f-secure-foundry/usbarmory/wiki/Boot-Modes-(Mk-II)|USB armory Mk II boot modes &amp;lt;ref name=&amp;quot;And&amp;quot;/&amp;gt; ]]&lt;br /&gt;
&lt;br /&gt;
* internal 16GB eMMC&lt;br /&gt;
* external microSD&lt;br /&gt;
* USB Serial Download Protocol (SDP) &amp;lt;ref name=&amp;quot;And&amp;quot;&amp;gt;Andrea Barisani, USB armory Mk II boot modes, https://github.com/f-secure-foundry/usbarmory/wiki/Boot-Modes-(Mk-II)#usb-armory-mk-ii-boot-modes&amp;lt;/ref&amp;gt;&lt;br /&gt;
if we want to boot the MMC we have to drag the inverter to the left, and if we want to boot the SD micro card we have to drag the inverter to the right. If we want to put it in SDP mode we have to leave it in the middle.&lt;br /&gt;
How to boot a microSD card?&lt;br /&gt;
USB Armory has a valid Pre-Image file for each operating system on its own page. Optionally, booting can be done either manually or by downloading the appropriate file and flashing the microSD card (before it is inserted into the USB Armory) with balenaEtcher software &amp;lt;ref name=&amp;quot;And&amp;quot;/&amp;gt;.&lt;br /&gt;
&lt;br /&gt;
=== 1. Step ===&lt;br /&gt;
&lt;br /&gt;
You can find the following Pre-Image files at this link: https://github.com/f-secure-foundry/usbarmory/wiki/Available-images&lt;br /&gt;
&lt;br /&gt;
[[File:Preimages.jpeg|thumb|center|500px|link=https://github.com/f-secure-foundry/usbarmory/wiki/Available-images|Available images &amp;lt;ref&amp;gt;Andrea Barisani, Available images, https://github.com/f-secure-foundry/usbarmory/wiki/Available-images&amp;lt;/ref&amp;gt; ]]&lt;br /&gt;
&lt;br /&gt;
=== 2. Step ===&lt;br /&gt;
&lt;br /&gt;
You can download the following software here: https://www.balena.io/etcher/&lt;br /&gt;
&lt;br /&gt;
[[File:balenaET.jpeg||thumb|center|500px|link=https://www.balena.io/etcher/|Flash OS images to SD cards &amp;amp; USB drives, safely and easily &amp;lt;ref&amp;gt;balenaEtcher, https://www.balena.io/etcher/&amp;lt;/ref&amp;gt;]]&lt;br /&gt;
&lt;br /&gt;
=== Host communication ===&lt;br /&gt;
Since the booted microSD card is ready in the operating system, Host communication can be started &amp;lt;ref&amp;gt;Andrea Barisani, Setup &amp;amp; Connection Sharing: Linux , https://github.com/f-secure-foundry/usbarmory/wiki/Host-communication#setup--connection-sharing-linux&amp;lt;/ref&amp;gt;.&lt;br /&gt;
&lt;br /&gt;
 # look up the name of the USB virtual Ethernet interface which was created by the USB Armory&lt;br /&gt;
 ifconfig&lt;br /&gt;
&lt;br /&gt;
 # bring the USB virtual Ethernet interface up&lt;br /&gt;
 /sbin/ip link set usb0 up&lt;br /&gt;
&lt;br /&gt;
 # set the host IP address&lt;br /&gt;
 /sbin/ip addr add 10.0.0.2/24 dev usb0&lt;br /&gt;
&lt;br /&gt;
 # enable masquerading for outgoing connections towards wireless interface&lt;br /&gt;
 /sbin/iptables -t nat -A POSTROUTING -s 10.0.0.1/32 -o wlan0 -j MASQUERADE&lt;br /&gt;
&lt;br /&gt;
 # enable IP forwarding&lt;br /&gt;
 sudo sysctl -w net.ipv4.ip_forward=1&lt;br /&gt;
&lt;br /&gt;
 #connect to USB Armory via ssh - password: USB armory&lt;br /&gt;
 ssh usbarmory@10.0.0.1&lt;br /&gt;
&lt;br /&gt;
 #install Lynx Web browser on USB Armory&lt;br /&gt;
 sudo apt-get install Lynx&lt;br /&gt;
&lt;br /&gt;
 #launch Lynx Web browser on USB Armory&lt;br /&gt;
 lynx google.com&lt;br /&gt;
&lt;br /&gt;
== Hardware Used ==&lt;br /&gt;
&lt;br /&gt;
[[USB armory + Enclosure]]&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[Category:Documentation]]&lt;/div&gt;</summary>
		<author><name>FPaschinger</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=USB_Armory&amp;diff=10458</id>
		<title>USB Armory</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=USB_Armory&amp;diff=10458"/>
		<updated>2022-12-12T17:04:09Z</updated>

		<summary type="html">&lt;p&gt;FPaschinger: /* Application examples */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Introduction ==&lt;br /&gt;
Launched in 2014, USB Armory is a small and portable USB-sized personal computer created by Andrea Barisani &amp;lt;ref&amp;gt;Andrea Barisani. Forging the USB armory, https://www.youtube.com/watch?v=bE5licRHMFs ,2014.&amp;lt;/ref&amp;gt;. Originally intended to be produced as a secure data store, USB Armory managed to become a versatile device with the development of its Hardware and Software. With its hardware sufficient as a computer, it can be configured on an installed Linux system that boots and thus powers up when plugged into any computer, for example, so that data not only ends up on an encrypted partition but is automatically re-encrypted when transferred &amp;lt;ref&amp;gt;NXP Community, Introducing USB armory, an Open Source Hardware Freescale i.MX53 Dongle&lt;br /&gt;
, https://community.nxp.com/t5/i-MX-Solutions-Knowledge-Base/Introducing-USB-armory-an-Open-Source-Hardware-Freescale-i-MX53/ta-p/1126823, 2014&amp;lt;/ref&amp;gt; .&lt;br /&gt;
[[File:Usbarmory coin.jpeg|Firmware|thumb|center|500px|link=https://inversepath.com/usbarmory_mark-one.html|OPEN SOURCE FLASH-DRIVE SIZED COMPUTER &amp;lt;ref&amp;gt;Inverse Path, OPEN SOURCE FLASH-DRIVE SIZED COMPUTER, https://inversepath.com/usbarmory_mark-one.html&amp;lt;/ref&amp;gt;  ]]&lt;br /&gt;
&lt;br /&gt;
== Design Goals ==&lt;br /&gt;
* The microSD hinge replacement with a push/pull slot.&lt;br /&gt;
* Real USB plugs, plug + socket for integrated host adapter.&lt;br /&gt;
* Enclosure design right from the beginning.&lt;br /&gt;
* Full internal and third-party security audit for HABv4 and chain of trust.&lt;br /&gt;
* Addition of built-in eMMC storage and external crypto authenticator.&lt;br /&gt;
* Bluetooth communication &amp;lt;ref&amp;gt;Andrea Barisani, USB ARMORY RELOADED, https://www.nohat.it/2019/slides/nohat_barisani.pdf, 2019&amp;lt;/ref&amp;gt;.&lt;br /&gt;
&lt;br /&gt;
=== Hardware ===&lt;br /&gt;
* NXP i.MX53 ARM® Cortex™-A8 800MHz, 512MB DDR3 RAM&lt;br /&gt;
* USB host powered (&amp;lt;500 mA) device with compact form factor (65 x 19 x 6 mm)&lt;br /&gt;
* ARM® TrustZone®, secure boot + storage + RAM&lt;br /&gt;
* microSD card slot&lt;br /&gt;
* 5-pin breakout header with GPIOs and UART&lt;br /&gt;
* customizable LED, including secure mode detection&lt;br /&gt;
* excellent native support (Android, Debian, Ubuntu, Arch Linux)&lt;br /&gt;
* USB device emulation (CDC Ethernet, mass storage, HID, etc.)&lt;br /&gt;
* Open Hardware &amp;amp; Software&lt;br /&gt;
&lt;br /&gt;
===Software ===&lt;br /&gt;
* Boots from onboard eMMC or microSD (or via USB serial downloader)&lt;br /&gt;
* Native Linux support – creating boot images is easy&lt;br /&gt;
* Precompiled images are available for Debian 9 (Stretch) and Arch Linux, with more on the way&lt;br /&gt;
* USB device emulation (CDC Ethernet, mass storage, HID, etc.) &amp;lt;ref&amp;gt;Andrea Barisani, MK II Introduction, https://github.com/f-secure-foundry/usbarmory/wiki/Mk-II-Introduction#software&amp;lt;/ref&amp;gt;&lt;br /&gt;
=== How to connected ===&lt;br /&gt;
* HS USB 2.0 On-The-Go (OTG) with device emulation&lt;br /&gt;
* TCP/IP communication via CDC Ethernet emulation&lt;br /&gt;
* flash drive functionality via mass storage device emulation&lt;br /&gt;
* serial communication over USB or physical UART&lt;br /&gt;
* stand-alone mode with dedicated host adapter &amp;lt;ref&amp;gt; Inverse Path, How to Connect, https://inversepath.com/usbarmory_mark-one.html &amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Application examples ==&lt;br /&gt;
&lt;br /&gt;
* Hardware Security Module (HSM)&lt;br /&gt;
* file storage with advanced features such as automatic encryption, virus scanning, host authentication and data self-destruct&lt;br /&gt;
* OpenSSH client and agent for untrusted hosts (kiosk)&lt;br /&gt;
* router for end-to-end VPN tunnelling, Tor&lt;br /&gt;
* password manager with integrated web server&lt;br /&gt;
* electronic wallet (e.g. pocket Bitcoin wallet)&lt;br /&gt;
* authentication token&lt;br /&gt;
* portable penetration testing platform&lt;br /&gt;
* low level USB security testing &amp;lt;ref&amp;gt;Inverse Path, Applications, https://inversepath.com/usbarmory_mark-one.html&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Getting Started  ==&lt;br /&gt;
=== Boot Mechanisms ===&lt;br /&gt;
In order for USB Armory to work in a certain operating system, either the microSD card inserted in the device or the MMc (16 GB) in it must be booted. Mk II supports 3 boot mechanisms &amp;lt;ref&amp;gt;Getting started, https://github.com/f-secure-foundry/usbarmory/wiki/Starting#getting-started&amp;lt;/ref&amp;gt;:&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[File:Armory-mark-two-boot-switch.png||Firmware|thumb|center|500px|link=https://github.com/f-secure-foundry/usbarmory/wiki/Boot-Modes-(Mk-II)|USB armory Mk II boot modes &amp;lt;ref name=&amp;quot;And&amp;quot;/&amp;gt; ]]&lt;br /&gt;
&lt;br /&gt;
* internal 16GB eMMC&lt;br /&gt;
* external microSD&lt;br /&gt;
* USB Serial Download Protocol (SDP) &amp;lt;ref name=&amp;quot;And&amp;quot;&amp;gt;Andrea Barisani, USB armory Mk II boot modes, https://github.com/f-secure-foundry/usbarmory/wiki/Boot-Modes-(Mk-II)#usb-armory-mk-ii-boot-modes&amp;lt;/ref&amp;gt;&lt;br /&gt;
if we want to boot the MMC we have to drag the inverter to the left, and if we want to boot the SD micro card we have to drag the inverter to the right. If we want to put it in SDP mode we have to leave it in the middle.&lt;br /&gt;
How to boot a microSD card?&lt;br /&gt;
USB Armory has a valid Pre-Image file for each operating system on its own page. Optionally, booting can be done either manually or by downloading the appropriate file and flashing the microSD card (before it is inserted into the USB Armory) with balenaEtcher software &amp;lt;ref name=&amp;quot;And&amp;quot;/&amp;gt;.&lt;br /&gt;
&lt;br /&gt;
=== 1. Step ===&lt;br /&gt;
&lt;br /&gt;
You can find the following Pre-Image files at this link: https://github.com/f-secure-foundry/usbarmory/wiki/Available-images&lt;br /&gt;
&lt;br /&gt;
[[File:Preimages.jpeg|thumb|center|500px|link=https://github.com/f-secure-foundry/usbarmory/wiki/Available-images|Available images &amp;lt;ref&amp;gt;Andrea Barisani, Available images, https://github.com/f-secure-foundry/usbarmory/wiki/Available-images&amp;lt;/ref&amp;gt; ]]&lt;br /&gt;
&lt;br /&gt;
=== 2. Step ===&lt;br /&gt;
&lt;br /&gt;
You can download the following software here: https://www.balena.io/etcher/&lt;br /&gt;
&lt;br /&gt;
[[File:balenaET.jpeg||thumb|center|500px|link=https://www.balena.io/etcher/|Flash OS images to SD cards &amp;amp; USB drives, safely and easily &amp;lt;ref&amp;gt;balenaEtcher, https://www.balena.io/etcher/&amp;lt;/ref&amp;gt;]]&lt;br /&gt;
&lt;br /&gt;
=== Host communication ===&lt;br /&gt;
Since the booted microSD card is ready in the operating system, Host communication can be started &amp;lt;ref&amp;gt;Andrea Barisani, Setup &amp;amp; Connection Sharing: Linux , https://github.com/f-secure-foundry/usbarmory/wiki/Host-communication#setup--connection-sharing-linux&amp;lt;/ref&amp;gt;.&lt;br /&gt;
&lt;br /&gt;
 # look up the name of the USB virtual Ethernet interface which was created by the USB Armory&lt;br /&gt;
 ifconfig&lt;br /&gt;
&lt;br /&gt;
 # bring the USB virtual Ethernet interface up&lt;br /&gt;
 /sbin/ip link set usb0 up&lt;br /&gt;
&lt;br /&gt;
 # set the host IP address&lt;br /&gt;
 /sbin/ip addr add 10.0.0.2/24 dev usb0&lt;br /&gt;
&lt;br /&gt;
 # enable masquerading for outgoing connections towards wireless interface&lt;br /&gt;
 /sbin/iptables -t nat -A POSTROUTING -s 10.0.0.1/32 -o wlan0 -j MASQUERADE&lt;br /&gt;
&lt;br /&gt;
 # enable IP forwarding&lt;br /&gt;
 sudo sysctl -w net.ipv4.ip_forward=1&lt;br /&gt;
&lt;br /&gt;
 #connect to USB Armory via ssh - password: USB armory&lt;br /&gt;
 ssh usbarmory@10.0.0.1&lt;br /&gt;
&lt;br /&gt;
 #install Lynx Web browser on USB Armory&lt;br /&gt;
 sudo apt-get install Lynx&lt;br /&gt;
&lt;br /&gt;
 #launch Lynx Web browser on USB Armory&lt;br /&gt;
 lynx google.com&lt;br /&gt;
&lt;br /&gt;
== Hardware Used ==&lt;br /&gt;
&lt;br /&gt;
[[USB armory + Enclosure]]&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[Category:Documentation]]&lt;/div&gt;</summary>
		<author><name>FPaschinger</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=USB_Armory&amp;diff=10457</id>
		<title>USB Armory</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=USB_Armory&amp;diff=10457"/>
		<updated>2022-12-12T17:02:33Z</updated>

		<summary type="html">&lt;p&gt;FPaschinger: /* How to connected */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Introduction ==&lt;br /&gt;
Launched in 2014, USB Armory is a small and portable USB-sized personal computer created by Andrea Barisani &amp;lt;ref&amp;gt;Andrea Barisani. Forging the USB armory, https://www.youtube.com/watch?v=bE5licRHMFs ,2014.&amp;lt;/ref&amp;gt;. Originally intended to be produced as a secure data store, USB Armory managed to become a versatile device with the development of its Hardware and Software. With its hardware sufficient as a computer, it can be configured on an installed Linux system that boots and thus powers up when plugged into any computer, for example, so that data not only ends up on an encrypted partition but is automatically re-encrypted when transferred &amp;lt;ref&amp;gt;NXP Community, Introducing USB armory, an Open Source Hardware Freescale i.MX53 Dongle&lt;br /&gt;
, https://community.nxp.com/t5/i-MX-Solutions-Knowledge-Base/Introducing-USB-armory-an-Open-Source-Hardware-Freescale-i-MX53/ta-p/1126823, 2014&amp;lt;/ref&amp;gt; .&lt;br /&gt;
[[File:Usbarmory coin.jpeg|Firmware|thumb|center|500px|link=https://inversepath.com/usbarmory_mark-one.html|OPEN SOURCE FLASH-DRIVE SIZED COMPUTER &amp;lt;ref&amp;gt;Inverse Path, OPEN SOURCE FLASH-DRIVE SIZED COMPUTER, https://inversepath.com/usbarmory_mark-one.html&amp;lt;/ref&amp;gt;  ]]&lt;br /&gt;
&lt;br /&gt;
== Design Goals ==&lt;br /&gt;
* The microSD hinge replacement with a push/pull slot.&lt;br /&gt;
* Real USB plugs, plug + socket for integrated host adapter.&lt;br /&gt;
* Enclosure design right from the beginning.&lt;br /&gt;
* Full internal and third-party security audit for HABv4 and chain of trust.&lt;br /&gt;
* Addition of built-in eMMC storage and external crypto authenticator.&lt;br /&gt;
* Bluetooth communication &amp;lt;ref&amp;gt;Andrea Barisani, USB ARMORY RELOADED, https://www.nohat.it/2019/slides/nohat_barisani.pdf, 2019&amp;lt;/ref&amp;gt;.&lt;br /&gt;
&lt;br /&gt;
=== Hardware ===&lt;br /&gt;
* NXP i.MX53 ARM® Cortex™-A8 800MHz, 512MB DDR3 RAM&lt;br /&gt;
* USB host powered (&amp;lt;500 mA) device with compact form factor (65 x 19 x 6 mm)&lt;br /&gt;
* ARM® TrustZone®, secure boot + storage + RAM&lt;br /&gt;
* microSD card slot&lt;br /&gt;
* 5-pin breakout header with GPIOs and UART&lt;br /&gt;
* customizable LED, including secure mode detection&lt;br /&gt;
* excellent native support (Android, Debian, Ubuntu, Arch Linux)&lt;br /&gt;
* USB device emulation (CDC Ethernet, mass storage, HID, etc.)&lt;br /&gt;
* Open Hardware &amp;amp; Software&lt;br /&gt;
&lt;br /&gt;
===Software ===&lt;br /&gt;
* Boots from onboard eMMC or microSD (or via USB serial downloader)&lt;br /&gt;
* Native Linux support – creating boot images is easy&lt;br /&gt;
* Precompiled images are available for Debian 9 (Stretch) and Arch Linux, with more on the way&lt;br /&gt;
* USB device emulation (CDC Ethernet, mass storage, HID, etc.) &amp;lt;ref&amp;gt;Andrea Barisani, MK II Introduction, https://github.com/f-secure-foundry/usbarmory/wiki/Mk-II-Introduction#software&amp;lt;/ref&amp;gt;&lt;br /&gt;
=== How to connected ===&lt;br /&gt;
* HS USB 2.0 On-The-Go (OTG) with device emulation&lt;br /&gt;
* TCP/IP communication via CDC Ethernet emulation&lt;br /&gt;
* flash drive functionality via mass storage device emulation&lt;br /&gt;
* serial communication over USB or physical UART&lt;br /&gt;
* stand-alone mode with dedicated host adapter &amp;lt;ref&amp;gt; Inverse Path, How to Connect, https://inversepath.com/usbarmory_mark-one.html &amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Application examples ==&lt;br /&gt;
&lt;br /&gt;
* mass storage device with advanced features such as automatic&lt;br /&gt;
* encryption, virus scanning, host authentication, and data self-destruct&lt;br /&gt;
* OpenSSH client and agent for untrusted hosts (kiosk)&lt;br /&gt;
* router for end-to-end VPN tunneling, Tor&lt;br /&gt;
* password manager with integrated webserver&lt;br /&gt;
* electronic wallet (e.g. pocket Bitcoin wallet)&lt;br /&gt;
* authentication token&lt;br /&gt;
* portable penetration testing platform&lt;br /&gt;
* low-level USB security testing &amp;lt;ref&amp;gt;Andrea Barisani, Applications, https://github.com/f-secure-foundry/usbarmory/wiki/Applications&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Getting Started  ==&lt;br /&gt;
=== Boot Mechanisms ===&lt;br /&gt;
In order for USB Armory to work in a certain operating system, either the microSD card inserted in the device or the MMc (16 GB) in it must be booted. Mk II supports 3 boot mechanisms &amp;lt;ref&amp;gt;Getting started, https://github.com/f-secure-foundry/usbarmory/wiki/Starting#getting-started&amp;lt;/ref&amp;gt;:&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[File:Armory-mark-two-boot-switch.png||Firmware|thumb|center|500px|link=https://github.com/f-secure-foundry/usbarmory/wiki/Boot-Modes-(Mk-II)|USB armory Mk II boot modes &amp;lt;ref name=&amp;quot;And&amp;quot;/&amp;gt; ]]&lt;br /&gt;
&lt;br /&gt;
* internal 16GB eMMC&lt;br /&gt;
* external microSD&lt;br /&gt;
* USB Serial Download Protocol (SDP) &amp;lt;ref name=&amp;quot;And&amp;quot;&amp;gt;Andrea Barisani, USB armory Mk II boot modes, https://github.com/f-secure-foundry/usbarmory/wiki/Boot-Modes-(Mk-II)#usb-armory-mk-ii-boot-modes&amp;lt;/ref&amp;gt;&lt;br /&gt;
if we want to boot the MMC we have to drag the inverter to the left, and if we want to boot the SD micro card we have to drag the inverter to the right. If we want to put it in SDP mode we have to leave it in the middle.&lt;br /&gt;
How to boot a microSD card?&lt;br /&gt;
USB Armory has a valid Pre-Image file for each operating system on its own page. Optionally, booting can be done either manually or by downloading the appropriate file and flashing the microSD card (before it is inserted into the USB Armory) with balenaEtcher software &amp;lt;ref name=&amp;quot;And&amp;quot;/&amp;gt;.&lt;br /&gt;
&lt;br /&gt;
=== 1. Step ===&lt;br /&gt;
&lt;br /&gt;
You can find the following Pre-Image files at this link: https://github.com/f-secure-foundry/usbarmory/wiki/Available-images&lt;br /&gt;
&lt;br /&gt;
[[File:Preimages.jpeg|thumb|center|500px|link=https://github.com/f-secure-foundry/usbarmory/wiki/Available-images|Available images &amp;lt;ref&amp;gt;Andrea Barisani, Available images, https://github.com/f-secure-foundry/usbarmory/wiki/Available-images&amp;lt;/ref&amp;gt; ]]&lt;br /&gt;
&lt;br /&gt;
=== 2. Step ===&lt;br /&gt;
&lt;br /&gt;
You can download the following software here: https://www.balena.io/etcher/&lt;br /&gt;
&lt;br /&gt;
[[File:balenaET.jpeg||thumb|center|500px|link=https://www.balena.io/etcher/|Flash OS images to SD cards &amp;amp; USB drives, safely and easily &amp;lt;ref&amp;gt;balenaEtcher, https://www.balena.io/etcher/&amp;lt;/ref&amp;gt;]]&lt;br /&gt;
&lt;br /&gt;
=== Host communication ===&lt;br /&gt;
Since the booted microSD card is ready in the operating system, Host communication can be started &amp;lt;ref&amp;gt;Andrea Barisani, Setup &amp;amp; Connection Sharing: Linux , https://github.com/f-secure-foundry/usbarmory/wiki/Host-communication#setup--connection-sharing-linux&amp;lt;/ref&amp;gt;.&lt;br /&gt;
&lt;br /&gt;
 # look up the name of the USB virtual Ethernet interface which was created by the USB Armory&lt;br /&gt;
 ifconfig&lt;br /&gt;
&lt;br /&gt;
 # bring the USB virtual Ethernet interface up&lt;br /&gt;
 /sbin/ip link set usb0 up&lt;br /&gt;
&lt;br /&gt;
 # set the host IP address&lt;br /&gt;
 /sbin/ip addr add 10.0.0.2/24 dev usb0&lt;br /&gt;
&lt;br /&gt;
 # enable masquerading for outgoing connections towards wireless interface&lt;br /&gt;
 /sbin/iptables -t nat -A POSTROUTING -s 10.0.0.1/32 -o wlan0 -j MASQUERADE&lt;br /&gt;
&lt;br /&gt;
 # enable IP forwarding&lt;br /&gt;
 sudo sysctl -w net.ipv4.ip_forward=1&lt;br /&gt;
&lt;br /&gt;
 #connect to USB Armory via ssh - password: USB armory&lt;br /&gt;
 ssh usbarmory@10.0.0.1&lt;br /&gt;
&lt;br /&gt;
 #install Lynx Web browser on USB Armory&lt;br /&gt;
 sudo apt-get install Lynx&lt;br /&gt;
&lt;br /&gt;
 #launch Lynx Web browser on USB Armory&lt;br /&gt;
 lynx google.com&lt;br /&gt;
&lt;br /&gt;
== Hardware Used ==&lt;br /&gt;
&lt;br /&gt;
[[USB armory + Enclosure]]&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[Category:Documentation]]&lt;/div&gt;</summary>
		<author><name>FPaschinger</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=USB_Armory&amp;diff=10456</id>
		<title>USB Armory</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=USB_Armory&amp;diff=10456"/>
		<updated>2022-12-12T16:59:43Z</updated>

		<summary type="html">&lt;p&gt;FPaschinger: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Introduction ==&lt;br /&gt;
Launched in 2014, USB Armory is a small and portable USB-sized personal computer created by Andrea Barisani &amp;lt;ref&amp;gt;Andrea Barisani. Forging the USB armory, https://www.youtube.com/watch?v=bE5licRHMFs ,2014.&amp;lt;/ref&amp;gt;. Originally intended to be produced as a secure data store, USB Armory managed to become a versatile device with the development of its Hardware and Software. With its hardware sufficient as a computer, it can be configured on an installed Linux system that boots and thus powers up when plugged into any computer, for example, so that data not only ends up on an encrypted partition but is automatically re-encrypted when transferred &amp;lt;ref&amp;gt;NXP Community, Introducing USB armory, an Open Source Hardware Freescale i.MX53 Dongle&lt;br /&gt;
, https://community.nxp.com/t5/i-MX-Solutions-Knowledge-Base/Introducing-USB-armory-an-Open-Source-Hardware-Freescale-i-MX53/ta-p/1126823, 2014&amp;lt;/ref&amp;gt; .&lt;br /&gt;
[[File:Usbarmory coin.jpeg|Firmware|thumb|center|500px|link=https://inversepath.com/usbarmory_mark-one.html|OPEN SOURCE FLASH-DRIVE SIZED COMPUTER &amp;lt;ref&amp;gt;Inverse Path, OPEN SOURCE FLASH-DRIVE SIZED COMPUTER, https://inversepath.com/usbarmory_mark-one.html&amp;lt;/ref&amp;gt;  ]]&lt;br /&gt;
&lt;br /&gt;
== Design Goals ==&lt;br /&gt;
* The microSD hinge replacement with a push/pull slot.&lt;br /&gt;
* Real USB plugs, plug + socket for integrated host adapter.&lt;br /&gt;
* Enclosure design right from the beginning.&lt;br /&gt;
* Full internal and third-party security audit for HABv4 and chain of trust.&lt;br /&gt;
* Addition of built-in eMMC storage and external crypto authenticator.&lt;br /&gt;
* Bluetooth communication &amp;lt;ref&amp;gt;Andrea Barisani, USB ARMORY RELOADED, https://www.nohat.it/2019/slides/nohat_barisani.pdf, 2019&amp;lt;/ref&amp;gt;.&lt;br /&gt;
&lt;br /&gt;
=== Hardware ===&lt;br /&gt;
* NXP i.MX53 ARM® Cortex™-A8 800MHz, 512MB DDR3 RAM&lt;br /&gt;
* USB host powered (&amp;lt;500 mA) device with compact form factor (65 x 19 x 6 mm)&lt;br /&gt;
* ARM® TrustZone®, secure boot + storage + RAM&lt;br /&gt;
* microSD card slot&lt;br /&gt;
* 5-pin breakout header with GPIOs and UART&lt;br /&gt;
* customizable LED, including secure mode detection&lt;br /&gt;
* excellent native support (Android, Debian, Ubuntu, Arch Linux)&lt;br /&gt;
* USB device emulation (CDC Ethernet, mass storage, HID, etc.)&lt;br /&gt;
* Open Hardware &amp;amp; Software&lt;br /&gt;
&lt;br /&gt;
===Software ===&lt;br /&gt;
* Boots from onboard eMMC or microSD (or via USB serial downloader)&lt;br /&gt;
* Native Linux support – creating boot images is easy&lt;br /&gt;
* Precompiled images are available for Debian 9 (Stretch) and Arch Linux, with more on the way&lt;br /&gt;
* USB device emulation (CDC Ethernet, mass storage, HID, etc.) &amp;lt;ref&amp;gt;Andrea Barisani, MK II Introduction, https://github.com/f-secure-foundry/usbarmory/wiki/Mk-II-Introduction#software&amp;lt;/ref&amp;gt;&lt;br /&gt;
=== How to connected ===&lt;br /&gt;
* USB 2.0 over USB-C plug to host with full device emulation&lt;br /&gt;
* USB 2.0 over USB-C receptacle for the additional devices or as a connection to the host&lt;br /&gt;
* Full TCP/IP connection to/from USB armory via USB CDC Ethernet emulation&lt;br /&gt;
* Flash drive functionality via USB mass storage device emulation&lt;br /&gt;
* Serial communication over USB or physical UART using the Debug Board&lt;br /&gt;
* Wireless connectivity over BLE &amp;lt;ref&amp;gt;Mouser Electronic, F-Secure USB Armory Mk II, https://www.mouser.at/new/f-secure/crowd-supply-usb-armorymkii/&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Application examples ==&lt;br /&gt;
&lt;br /&gt;
* mass storage device with advanced features such as automatic&lt;br /&gt;
* encryption, virus scanning, host authentication, and data self-destruct&lt;br /&gt;
* OpenSSH client and agent for untrusted hosts (kiosk)&lt;br /&gt;
* router for end-to-end VPN tunneling, Tor&lt;br /&gt;
* password manager with integrated webserver&lt;br /&gt;
* electronic wallet (e.g. pocket Bitcoin wallet)&lt;br /&gt;
* authentication token&lt;br /&gt;
* portable penetration testing platform&lt;br /&gt;
* low-level USB security testing &amp;lt;ref&amp;gt;Andrea Barisani, Applications, https://github.com/f-secure-foundry/usbarmory/wiki/Applications&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Getting Started  ==&lt;br /&gt;
=== Boot Mechanisms ===&lt;br /&gt;
In order for USB Armory to work in a certain operating system, either the microSD card inserted in the device or the MMc (16 GB) in it must be booted. Mk II supports 3 boot mechanisms &amp;lt;ref&amp;gt;Getting started, https://github.com/f-secure-foundry/usbarmory/wiki/Starting#getting-started&amp;lt;/ref&amp;gt;:&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[File:Armory-mark-two-boot-switch.png||Firmware|thumb|center|500px|link=https://github.com/f-secure-foundry/usbarmory/wiki/Boot-Modes-(Mk-II)|USB armory Mk II boot modes &amp;lt;ref name=&amp;quot;And&amp;quot;/&amp;gt; ]]&lt;br /&gt;
&lt;br /&gt;
* internal 16GB eMMC&lt;br /&gt;
* external microSD&lt;br /&gt;
* USB Serial Download Protocol (SDP) &amp;lt;ref name=&amp;quot;And&amp;quot;&amp;gt;Andrea Barisani, USB armory Mk II boot modes, https://github.com/f-secure-foundry/usbarmory/wiki/Boot-Modes-(Mk-II)#usb-armory-mk-ii-boot-modes&amp;lt;/ref&amp;gt;&lt;br /&gt;
if we want to boot the MMC we have to drag the inverter to the left, and if we want to boot the SD micro card we have to drag the inverter to the right. If we want to put it in SDP mode we have to leave it in the middle.&lt;br /&gt;
How to boot a microSD card?&lt;br /&gt;
USB Armory has a valid Pre-Image file for each operating system on its own page. Optionally, booting can be done either manually or by downloading the appropriate file and flashing the microSD card (before it is inserted into the USB Armory) with balenaEtcher software &amp;lt;ref name=&amp;quot;And&amp;quot;/&amp;gt;.&lt;br /&gt;
&lt;br /&gt;
=== 1. Step ===&lt;br /&gt;
&lt;br /&gt;
You can find the following Pre-Image files at this link: https://github.com/f-secure-foundry/usbarmory/wiki/Available-images&lt;br /&gt;
&lt;br /&gt;
[[File:Preimages.jpeg|thumb|center|500px|link=https://github.com/f-secure-foundry/usbarmory/wiki/Available-images|Available images &amp;lt;ref&amp;gt;Andrea Barisani, Available images, https://github.com/f-secure-foundry/usbarmory/wiki/Available-images&amp;lt;/ref&amp;gt; ]]&lt;br /&gt;
&lt;br /&gt;
=== 2. Step ===&lt;br /&gt;
&lt;br /&gt;
You can download the following software here: https://www.balena.io/etcher/&lt;br /&gt;
&lt;br /&gt;
[[File:balenaET.jpeg||thumb|center|500px|link=https://www.balena.io/etcher/|Flash OS images to SD cards &amp;amp; USB drives, safely and easily &amp;lt;ref&amp;gt;balenaEtcher, https://www.balena.io/etcher/&amp;lt;/ref&amp;gt;]]&lt;br /&gt;
&lt;br /&gt;
=== Host communication ===&lt;br /&gt;
Since the booted microSD card is ready in the operating system, Host communication can be started &amp;lt;ref&amp;gt;Andrea Barisani, Setup &amp;amp; Connection Sharing: Linux , https://github.com/f-secure-foundry/usbarmory/wiki/Host-communication#setup--connection-sharing-linux&amp;lt;/ref&amp;gt;.&lt;br /&gt;
&lt;br /&gt;
 # look up the name of the USB virtual Ethernet interface which was created by the USB Armory&lt;br /&gt;
 ifconfig&lt;br /&gt;
&lt;br /&gt;
 # bring the USB virtual Ethernet interface up&lt;br /&gt;
 /sbin/ip link set usb0 up&lt;br /&gt;
&lt;br /&gt;
 # set the host IP address&lt;br /&gt;
 /sbin/ip addr add 10.0.0.2/24 dev usb0&lt;br /&gt;
&lt;br /&gt;
 # enable masquerading for outgoing connections towards wireless interface&lt;br /&gt;
 /sbin/iptables -t nat -A POSTROUTING -s 10.0.0.1/32 -o wlan0 -j MASQUERADE&lt;br /&gt;
&lt;br /&gt;
 # enable IP forwarding&lt;br /&gt;
 sudo sysctl -w net.ipv4.ip_forward=1&lt;br /&gt;
&lt;br /&gt;
 #connect to USB Armory via ssh - password: USB armory&lt;br /&gt;
 ssh usbarmory@10.0.0.1&lt;br /&gt;
&lt;br /&gt;
 #install Lynx Web browser on USB Armory&lt;br /&gt;
 sudo apt-get install Lynx&lt;br /&gt;
&lt;br /&gt;
 #launch Lynx Web browser on USB Armory&lt;br /&gt;
 lynx google.com&lt;br /&gt;
&lt;br /&gt;
== Hardware Used ==&lt;br /&gt;
&lt;br /&gt;
[[USB armory + Enclosure]]&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[Category:Documentation]]&lt;/div&gt;</summary>
		<author><name>FPaschinger</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=USB_Armory&amp;diff=10455</id>
		<title>USB Armory</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=USB_Armory&amp;diff=10455"/>
		<updated>2022-12-12T16:56:50Z</updated>

		<summary type="html">&lt;p&gt;FPaschinger: /* Hardware */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Introduction ==&lt;br /&gt;
Launched in 2014, USB Armory is a small and portable USB-sized personal computer created by Andrea Barisani &amp;lt;ref&amp;gt;Andrea Barisani. Forging the USB armory, https://www.youtube.com/watch?v=bE5licRHMFs ,2014.&amp;lt;/ref&amp;gt;. Originally intended to be produced as a secure data store, USB Armory managed to become a versatile device with the development of its Hardware and Software. With its hardware sufficient as a computer, it can be configured on an installed Linux system that boots and thus powers up when plugged into any computer, for example, so that data not only ends up on an encrypted partition but is automatically re-encrypted when transferred &amp;lt;ref&amp;gt;NXP Community, Introducing USB armory, an Open Source Hardware Freescale i.MX53 Dongle&lt;br /&gt;
, https://community.nxp.com/t5/i-MX-Solutions-Knowledge-Base/Introducing-USB-armory-an-Open-Source-Hardware-Freescale-i-MX53/ta-p/1126823, 2014&amp;lt;/ref&amp;gt; .&lt;br /&gt;
[[File:Usbarmory coin.jpeg|Firmware|thumb|center|500px|link=https://inversepath.com/usbarmory_mark-one.html|OPEN SOURCE FLASH-DRIVE SIZED COMPUTER &amp;lt;ref&amp;gt;Inverse Path, OPEN SOURCE FLASH-DRIVE SIZED COMPUTER, https://inversepath.com/usbarmory_mark-one.html&amp;lt;/ref&amp;gt;  ]]&lt;br /&gt;
&lt;br /&gt;
== Design Goals ==&lt;br /&gt;
* The microSD hinge replacement with a push/pull slot.&lt;br /&gt;
* Real USB plugs, plug + socket for integrated host adapter.&lt;br /&gt;
* Enclosure design right from the beginning.&lt;br /&gt;
* Full internal and third-party security audit for HABv4 and chain of trust.&lt;br /&gt;
* Addition of built-in eMMC storage and external crypto authenticator.&lt;br /&gt;
* Bluetooth communication &amp;lt;ref&amp;gt;Andrea Barisani, USB ARMORY RELOADED, https://www.nohat.it/2019/slides/nohat_barisani.pdf, 2019&amp;lt;/ref&amp;gt;.&lt;br /&gt;
=== Hardware ===&lt;br /&gt;
&lt;br /&gt;
* NXP i.MX53 ARM® Cortex™-A8 800MHz, 512MB DDR3 RAM&lt;br /&gt;
* USB host powered (&amp;lt;500 mA) device with compact form factor (65 x 19 x 6 mm)&lt;br /&gt;
* ARM® TrustZone®, secure boot + storage + RAM&lt;br /&gt;
* microSD card slot&lt;br /&gt;
* 5-pin breakout header with GPIOs and UART&lt;br /&gt;
* customizable LED, including secure mode detection&lt;br /&gt;
* excellent native support (Android, Debian, Ubuntu, Arch Linux)&lt;br /&gt;
* USB device emulation (CDC Ethernet, mass storage, HID, etc.)&lt;br /&gt;
* Open Hardware &amp;amp; Software&lt;br /&gt;
&lt;br /&gt;
===Software ===&lt;br /&gt;
* Boots from onboard eMMC or microSD (or via USB serial downloader)&lt;br /&gt;
* Native Linux support – creating boot images is easy&lt;br /&gt;
* Precompiled images are available for Debian 9 (Stretch) and Arch Linux, with more on the way&lt;br /&gt;
* USB device emulation (CDC Ethernet, mass storage, HID, etc.) &amp;lt;ref&amp;gt;Andrea Barisani, MK II Introduction, https://github.com/f-secure-foundry/usbarmory/wiki/Mk-II-Introduction#software&amp;lt;/ref&amp;gt;&lt;br /&gt;
=== How to connected ===&lt;br /&gt;
* USB 2.0 over USB-C plug to host with full device emulation&lt;br /&gt;
* USB 2.0 over USB-C receptacle for the additional devices or as a connection to the host&lt;br /&gt;
* Full TCP/IP connection to/from USB armory via USB CDC Ethernet emulation&lt;br /&gt;
* Flash drive functionality via USB mass storage device emulation&lt;br /&gt;
* Serial communication over USB or physical UART using the Debug Board&lt;br /&gt;
* Wireless connectivity over BLE &amp;lt;ref&amp;gt;Mouser Electronic, F-Secure USB Armory Mk II, https://www.mouser.at/new/f-secure/crowd-supply-usb-armorymkii/&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Application examples ==&lt;br /&gt;
&lt;br /&gt;
* mass storage device with advanced features such as automatic&lt;br /&gt;
* encryption, virus scanning, host authentication, and data self-destruct&lt;br /&gt;
* OpenSSH client and agent for untrusted hosts (kiosk)&lt;br /&gt;
* router for end-to-end VPN tunneling, Tor&lt;br /&gt;
* password manager with integrated webserver&lt;br /&gt;
* electronic wallet (e.g. pocket Bitcoin wallet)&lt;br /&gt;
* authentication token&lt;br /&gt;
* portable penetration testing platform&lt;br /&gt;
* low-level USB security testing &amp;lt;ref&amp;gt;Andrea Barisani, Applications, https://github.com/f-secure-foundry/usbarmory/wiki/Applications&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Getting Started  ==&lt;br /&gt;
=== Boot Mechanisms ===&lt;br /&gt;
In order for USB Armory to work in a certain operating system, either the microSD card inserted in the device or the MMc (16 GB) in it must be booted. Mk II supports 3 boot mechanisms &amp;lt;ref&amp;gt;Getting started, https://github.com/f-secure-foundry/usbarmory/wiki/Starting#getting-started&amp;lt;/ref&amp;gt;:&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[File:Armory-mark-two-boot-switch.png||Firmware|thumb|center|500px|link=https://github.com/f-secure-foundry/usbarmory/wiki/Boot-Modes-(Mk-II)|USB armory Mk II boot modes &amp;lt;ref name=&amp;quot;And&amp;quot;/&amp;gt; ]]&lt;br /&gt;
&lt;br /&gt;
* internal 16GB eMMC&lt;br /&gt;
* external microSD&lt;br /&gt;
* USB Serial Download Protocol (SDP) &amp;lt;ref name=&amp;quot;And&amp;quot;&amp;gt;Andrea Barisani, USB armory Mk II boot modes, https://github.com/f-secure-foundry/usbarmory/wiki/Boot-Modes-(Mk-II)#usb-armory-mk-ii-boot-modes&amp;lt;/ref&amp;gt;&lt;br /&gt;
if we want to boot the MMC we have to drag the inverter to the left, and if we want to boot the SD micro card we have to drag the inverter to the right. If we want to put it in SDP mode we have to leave it in the middle.&lt;br /&gt;
How to boot a microSD card?&lt;br /&gt;
USB Armory has a valid Pre-Image file for each operating system on its own page. Optionally, booting can be done either manually or by downloading the appropriate file and flashing the microSD card (before it is inserted into the USB Armory) with balenaEtcher software &amp;lt;ref name=&amp;quot;And&amp;quot;/&amp;gt;.&lt;br /&gt;
&lt;br /&gt;
=== 1. Step ===&lt;br /&gt;
&lt;br /&gt;
You can find the following Pre-Image files at this link: https://github.com/f-secure-foundry/usbarmory/wiki/Available-images&lt;br /&gt;
&lt;br /&gt;
[[File:Preimages.jpeg|thumb|center|500px|link=https://github.com/f-secure-foundry/usbarmory/wiki/Available-images|Available images &amp;lt;ref&amp;gt;Andrea Barisani, Available images, https://github.com/f-secure-foundry/usbarmory/wiki/Available-images&amp;lt;/ref&amp;gt; ]]&lt;br /&gt;
&lt;br /&gt;
=== 2. Step ===&lt;br /&gt;
&lt;br /&gt;
You can download the following software here: https://www.balena.io/etcher/&lt;br /&gt;
&lt;br /&gt;
[[File:balenaET.jpeg||thumb|center|500px|link=https://www.balena.io/etcher/|Flash OS images to SD cards &amp;amp; USB drives, safely and easily &amp;lt;ref&amp;gt;balenaEtcher, https://www.balena.io/etcher/&amp;lt;/ref&amp;gt;]]&lt;br /&gt;
&lt;br /&gt;
=== Host communication ===&lt;br /&gt;
Since the booted microSD card is ready in the operating system, Host communication can be started &amp;lt;ref&amp;gt;Andrea Barisani, Setup &amp;amp; Connection Sharing: Linux , https://github.com/f-secure-foundry/usbarmory/wiki/Host-communication#setup--connection-sharing-linux&amp;lt;/ref&amp;gt;.&lt;br /&gt;
&lt;br /&gt;
 # look up the name of the USB virtual Ethernet interface which was created by the USB Armory&lt;br /&gt;
 ifconfig&lt;br /&gt;
&lt;br /&gt;
 # bring the USB virtual Ethernet interface up&lt;br /&gt;
 /sbin/ip link set usb0 up&lt;br /&gt;
&lt;br /&gt;
 # set the host IP address&lt;br /&gt;
 /sbin/ip addr add 10.0.0.2/24 dev usb0&lt;br /&gt;
&lt;br /&gt;
 # enable masquerading for outgoing connections towards wireless interface&lt;br /&gt;
 /sbin/iptables -t nat -A POSTROUTING -s 10.0.0.1/32 -o wlan0 -j MASQUERADE&lt;br /&gt;
&lt;br /&gt;
 # enable IP forwarding&lt;br /&gt;
 sudo sysctl -w net.ipv4.ip_forward=1&lt;br /&gt;
&lt;br /&gt;
 #connect to USB Armory via ssh - password: USB armory&lt;br /&gt;
 ssh usbarmory@10.0.0.1&lt;br /&gt;
&lt;br /&gt;
 #install Lynx Web browser on USB Armory&lt;br /&gt;
 sudo apt-get install Lynx&lt;br /&gt;
&lt;br /&gt;
 #launch Lynx Web browser on USB Armory&lt;br /&gt;
 lynx google.com&lt;br /&gt;
&lt;br /&gt;
== Hardware Used ==&lt;br /&gt;
&lt;br /&gt;
[[USB armory + Enclosure]]&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[Category:Documentation]]&lt;/div&gt;</summary>
		<author><name>FPaschinger</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=USB_Armory&amp;diff=10454</id>
		<title>USB Armory</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=USB_Armory&amp;diff=10454"/>
		<updated>2022-12-12T16:55:58Z</updated>

		<summary type="html">&lt;p&gt;FPaschinger: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Introduction ==&lt;br /&gt;
Launched in 2014, USB Armory is a small and portable USB-sized personal computer created by Andrea Barisani &amp;lt;ref&amp;gt;Andrea Barisani. Forging the USB armory, https://www.youtube.com/watch?v=bE5licRHMFs ,2014.&amp;lt;/ref&amp;gt;. Originally intended to be produced as a secure data store, USB Armory managed to become a versatile device with the development of its Hardware and Software. With its hardware sufficient as a computer, it can be configured on an installed Linux system that boots and thus powers up when plugged into any computer, for example, so that data not only ends up on an encrypted partition but is automatically re-encrypted when transferred &amp;lt;ref&amp;gt;NXP Community, Introducing USB armory, an Open Source Hardware Freescale i.MX53 Dongle&lt;br /&gt;
, https://community.nxp.com/t5/i-MX-Solutions-Knowledge-Base/Introducing-USB-armory-an-Open-Source-Hardware-Freescale-i-MX53/ta-p/1126823, 2014&amp;lt;/ref&amp;gt; .&lt;br /&gt;
[[File:Usbarmory coin.jpeg|Firmware|thumb|center|500px|link=https://inversepath.com/usbarmory_mark-one.html|OPEN SOURCE FLASH-DRIVE SIZED COMPUTER &amp;lt;ref&amp;gt;Inverse Path, OPEN SOURCE FLASH-DRIVE SIZED COMPUTER, https://inversepath.com/usbarmory_mark-one.html&amp;lt;/ref&amp;gt;  ]]&lt;br /&gt;
&lt;br /&gt;
== Design Goals ==&lt;br /&gt;
* The microSD hinge replacement with a push/pull slot.&lt;br /&gt;
* Real USB plugs, plug + socket for integrated host adapter.&lt;br /&gt;
* Enclosure design right from the beginning.&lt;br /&gt;
* Full internal and third-party security audit for HABv4 and chain of trust.&lt;br /&gt;
* Addition of built-in eMMC storage and external crypto authenticator.&lt;br /&gt;
* Bluetooth communication &amp;lt;ref&amp;gt;Andrea Barisani, USB ARMORY RELOADED, https://www.nohat.it/2019/slides/nohat_barisani.pdf, 2019&amp;lt;/ref&amp;gt;.&lt;br /&gt;
=== Hardware ===&lt;br /&gt;
[[USB armory + Enclosure ]]&lt;br /&gt;
* SoC: NXP i.MX6ULZ ARM® Cortex™-A7 900 MHz&lt;br /&gt;
* RAM: 512 MB DDR3&lt;br /&gt;
* Storage: internal 16 GB eMMC + external microSD&lt;br /&gt;
* Bluetooth module: u-blox ANNA-B112 BLE&lt;br /&gt;
* USB-C ports: DRP (Dual Role Power) receptacle + UFP (Upstream Facing Port) plug, USB 2.0 only (no * video support)&lt;br /&gt;
* LEDs: two&lt;br /&gt;
* Slide switch: for boot mode selection between eMMC and microSD&lt;br /&gt;
* External security elements: Microchip ATECC608A + NXP A71CH&lt;br /&gt;
* Physical size: 66 mm x 19 mm x 8 mm (without enclosure, including USB-C connector)&lt;br /&gt;
* Enclosure: included with all units for device protection &amp;lt;ref&amp;gt;Hacker Warehouse, USB Armory MK II, https://hackerwarehouse.com/product/usb-armory-mkii/, 2019&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
===Software ===&lt;br /&gt;
* Boots from onboard eMMC or microSD (or via USB serial downloader)&lt;br /&gt;
* Native Linux support – creating boot images is easy&lt;br /&gt;
* Precompiled images are available for Debian 9 (Stretch) and Arch Linux, with more on the way&lt;br /&gt;
* USB device emulation (CDC Ethernet, mass storage, HID, etc.) &amp;lt;ref&amp;gt;Andrea Barisani, MK II Introduction, https://github.com/f-secure-foundry/usbarmory/wiki/Mk-II-Introduction#software&amp;lt;/ref&amp;gt;&lt;br /&gt;
=== How to connected ===&lt;br /&gt;
* USB 2.0 over USB-C plug to host with full device emulation&lt;br /&gt;
* USB 2.0 over USB-C receptacle for the additional devices or as a connection to the host&lt;br /&gt;
* Full TCP/IP connection to/from USB armory via USB CDC Ethernet emulation&lt;br /&gt;
* Flash drive functionality via USB mass storage device emulation&lt;br /&gt;
* Serial communication over USB or physical UART using the Debug Board&lt;br /&gt;
* Wireless connectivity over BLE &amp;lt;ref&amp;gt;Mouser Electronic, F-Secure USB Armory Mk II, https://www.mouser.at/new/f-secure/crowd-supply-usb-armorymkii/&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Application examples ==&lt;br /&gt;
&lt;br /&gt;
* mass storage device with advanced features such as automatic&lt;br /&gt;
* encryption, virus scanning, host authentication, and data self-destruct&lt;br /&gt;
* OpenSSH client and agent for untrusted hosts (kiosk)&lt;br /&gt;
* router for end-to-end VPN tunneling, Tor&lt;br /&gt;
* password manager with integrated webserver&lt;br /&gt;
* electronic wallet (e.g. pocket Bitcoin wallet)&lt;br /&gt;
* authentication token&lt;br /&gt;
* portable penetration testing platform&lt;br /&gt;
* low-level USB security testing &amp;lt;ref&amp;gt;Andrea Barisani, Applications, https://github.com/f-secure-foundry/usbarmory/wiki/Applications&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Getting Started  ==&lt;br /&gt;
=== Boot Mechanisms ===&lt;br /&gt;
In order for USB Armory to work in a certain operating system, either the microSD card inserted in the device or the MMc (16 GB) in it must be booted. Mk II supports 3 boot mechanisms &amp;lt;ref&amp;gt;Getting started, https://github.com/f-secure-foundry/usbarmory/wiki/Starting#getting-started&amp;lt;/ref&amp;gt;:&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[File:Armory-mark-two-boot-switch.png||Firmware|thumb|center|500px|link=https://github.com/f-secure-foundry/usbarmory/wiki/Boot-Modes-(Mk-II)|USB armory Mk II boot modes &amp;lt;ref name=&amp;quot;And&amp;quot;/&amp;gt; ]]&lt;br /&gt;
&lt;br /&gt;
* internal 16GB eMMC&lt;br /&gt;
* external microSD&lt;br /&gt;
* USB Serial Download Protocol (SDP) &amp;lt;ref name=&amp;quot;And&amp;quot;&amp;gt;Andrea Barisani, USB armory Mk II boot modes, https://github.com/f-secure-foundry/usbarmory/wiki/Boot-Modes-(Mk-II)#usb-armory-mk-ii-boot-modes&amp;lt;/ref&amp;gt;&lt;br /&gt;
if we want to boot the MMC we have to drag the inverter to the left, and if we want to boot the SD micro card we have to drag the inverter to the right. If we want to put it in SDP mode we have to leave it in the middle.&lt;br /&gt;
How to boot a microSD card?&lt;br /&gt;
USB Armory has a valid Pre-Image file for each operating system on its own page. Optionally, booting can be done either manually or by downloading the appropriate file and flashing the microSD card (before it is inserted into the USB Armory) with balenaEtcher software &amp;lt;ref name=&amp;quot;And&amp;quot;/&amp;gt;.&lt;br /&gt;
&lt;br /&gt;
=== 1. Step ===&lt;br /&gt;
&lt;br /&gt;
You can find the following Pre-Image files at this link: https://github.com/f-secure-foundry/usbarmory/wiki/Available-images&lt;br /&gt;
&lt;br /&gt;
[[File:Preimages.jpeg|thumb|center|500px|link=https://github.com/f-secure-foundry/usbarmory/wiki/Available-images|Available images &amp;lt;ref&amp;gt;Andrea Barisani, Available images, https://github.com/f-secure-foundry/usbarmory/wiki/Available-images&amp;lt;/ref&amp;gt; ]]&lt;br /&gt;
&lt;br /&gt;
=== 2. Step ===&lt;br /&gt;
&lt;br /&gt;
You can download the following software here: https://www.balena.io/etcher/&lt;br /&gt;
&lt;br /&gt;
[[File:balenaET.jpeg||thumb|center|500px|link=https://www.balena.io/etcher/|Flash OS images to SD cards &amp;amp; USB drives, safely and easily &amp;lt;ref&amp;gt;balenaEtcher, https://www.balena.io/etcher/&amp;lt;/ref&amp;gt;]]&lt;br /&gt;
&lt;br /&gt;
=== Host communication ===&lt;br /&gt;
Since the booted microSD card is ready in the operating system, Host communication can be started &amp;lt;ref&amp;gt;Andrea Barisani, Setup &amp;amp; Connection Sharing: Linux , https://github.com/f-secure-foundry/usbarmory/wiki/Host-communication#setup--connection-sharing-linux&amp;lt;/ref&amp;gt;.&lt;br /&gt;
&lt;br /&gt;
 # look up the name of the USB virtual Ethernet interface which was created by the USB Armory&lt;br /&gt;
 ifconfig&lt;br /&gt;
&lt;br /&gt;
 # bring the USB virtual Ethernet interface up&lt;br /&gt;
 /sbin/ip link set usb0 up&lt;br /&gt;
&lt;br /&gt;
 # set the host IP address&lt;br /&gt;
 /sbin/ip addr add 10.0.0.2/24 dev usb0&lt;br /&gt;
&lt;br /&gt;
 # enable masquerading for outgoing connections towards wireless interface&lt;br /&gt;
 /sbin/iptables -t nat -A POSTROUTING -s 10.0.0.1/32 -o wlan0 -j MASQUERADE&lt;br /&gt;
&lt;br /&gt;
 # enable IP forwarding&lt;br /&gt;
 sudo sysctl -w net.ipv4.ip_forward=1&lt;br /&gt;
&lt;br /&gt;
 #connect to USB Armory via ssh - password: USB armory&lt;br /&gt;
 ssh usbarmory@10.0.0.1&lt;br /&gt;
&lt;br /&gt;
 #install Lynx Web browser on USB Armory&lt;br /&gt;
 sudo apt-get install Lynx&lt;br /&gt;
&lt;br /&gt;
 #launch Lynx Web browser on USB Armory&lt;br /&gt;
 lynx google.com&lt;br /&gt;
&lt;br /&gt;
== Hardware Used ==&lt;br /&gt;
&lt;br /&gt;
[[USB armory + Enclosure]]&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[Category:Documentation]]&lt;/div&gt;</summary>
		<author><name>FPaschinger</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=Beagle_USB_12_Protocol_Analyzer:_Test&amp;diff=10453</id>
		<title>Beagle USB 12 Protocol Analyzer: Test</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=Beagle_USB_12_Protocol_Analyzer:_Test&amp;diff=10453"/>
		<updated>2022-12-12T16:34:14Z</updated>

		<summary type="html">&lt;p&gt;FPaschinger: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Summary == &lt;br /&gt;
&lt;br /&gt;
The Beagle USB 12 Protocol Analyzer is a nice tool to setup it quick and ease and allows engineers to debug problems quickly. You can capture, display and filter high-, full- and low-speed USB traffic in real time. &lt;br /&gt;
&lt;br /&gt;
[[File:Beagle_Analyzer_Front.jpg|400px|thumb|none|Beagle USB 12 Protocol Analyzer]]&lt;br /&gt;
&lt;br /&gt;
In the front of the analyzer there are the target host and target device ports. &lt;br /&gt;
They act as a passthrough to connect the target device to the host computer. &lt;br /&gt;
&lt;br /&gt;
[[File:Beagle Back.jpg|400px|thumb|none|Beagle USB 12 Protocol Analyzer]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Requirements ==&lt;br /&gt;
&lt;br /&gt;
To be able to monitor the USB traffic you will need a software that captures and displays USB, USB Type-C Power Delivery, I2C, SPI, eSPI and CAN bus data through the Beagle. To download it from the Totalphase website you will need to create an account. This does not come with any subscription or cost factor.&lt;br /&gt;
You can [https://www.totalphase.com/products/data-center/?___ Download] the Data Center Software for following architectures:&lt;br /&gt;
&lt;br /&gt;
* Windows&lt;br /&gt;
* Linux&lt;br /&gt;
* MacOS&lt;br /&gt;
&lt;br /&gt;
If you are using a Windows or a Linux host, it is also important to download the appropriate drivers since without them Windows will not recognize the analyzer:&lt;br /&gt;
&lt;br /&gt;
* Windows [https://www.totalphase.com/products/usb-drivers-windows/ (here)]&lt;br /&gt;
* Linux [https://www.totalphase.com/products/usb-drivers-linux/ (here)]&lt;br /&gt;
&lt;br /&gt;
MacOS do not require any driver.&lt;br /&gt;
For more details like, key features, technical specifications or software requirements follow this [https://www.totalphase.com/products/beagle-usb12/ link].&lt;br /&gt;
&lt;br /&gt;
== Description ==&lt;br /&gt;
&lt;br /&gt;
With the type B USB cable connect the target host port at the front of the analyzer with your PCs USB port type A. &lt;br /&gt;
The analyzis port at the backside of the analyzer is connected with another type B USB connector to your PCs USB port type A.&lt;br /&gt;
Lastly you can then plug in your target device into the USB port type A of the analyzer. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Hands-On ===&lt;br /&gt;
&lt;br /&gt;
To capture traffic, click in the top toolbar at “Analyzer” and then on “Connect to Analyzer”. Confirm that the correct device is selected and click “OK”. &lt;br /&gt;
&lt;br /&gt;
[[File:Connect to Analyzer.png|800px|thumb|none|]]&lt;br /&gt;
&lt;br /&gt;
You can then connect the USB target device (for example a mouse) to the analyzer. After clicking on the play-button, we should then see all the packet data in real-time.&lt;br /&gt;
&lt;br /&gt;
[[File:Data Center Capture 1.png|800px|thumb|none|]]&lt;br /&gt;
&lt;br /&gt;
We can see that some interesting parameters like speed, timestamp, endpoint address and the actual data were captured. The captured data has been decoded into human readable messages.&lt;br /&gt;
At the beginning we can see the handshake between the computer and the connected device. &lt;br /&gt;
We can double-click on any packet to see the low-level data and the corresponding details, which are shown in hexadecimal and ASCII. A mouse click is symbolized by a field named “Btns=[1]”.&lt;br /&gt;
&lt;br /&gt;
[[File:Data Center Capture 2.png|800px|thumb|none|]]&lt;br /&gt;
&lt;br /&gt;
It should be now possible to click on the bottom of the Navigator at “LiveFilter” to filter for those events. This should be possible by entering “btns=[1]” in the text field. Apply the filter and all “click”-mouse events are shown. This should be possible for every kind of patterns, endpoint addresses, and more. &lt;br /&gt;
&lt;br /&gt;
[[File:Data Center Capture 3.png|800px|thumb|none|]]&lt;br /&gt;
&lt;br /&gt;
By turning off scrolling and disabling the filter, we can see all the data that occurred before and after the events. &lt;br /&gt;
You can also connect a USB hub to the analyzer and plug in multiple USB devices. All devices with their assigned addresses will be shown under the navigator in the Data Center software.&lt;br /&gt;
&lt;br /&gt;
[[File:Data Center Capture 4.png|800px|thumb|none|]]&lt;br /&gt;
&lt;br /&gt;
You can also find a lot of already captured examples under “Help”, “Examples”:&lt;br /&gt;
&lt;br /&gt;
[[File:Data Center Example Captures.png|800px|thumb|none|]]&lt;br /&gt;
&lt;br /&gt;
The protocol analyzer can therefore be very helpful for debugging errors or for forensic analysis, for example.&lt;br /&gt;
&lt;br /&gt;
== Used Hardware ==&lt;br /&gt;
&lt;br /&gt;
[[Beagle USB 12 Protocol Analyzer]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
* https://www.totalphase.com&lt;/div&gt;</summary>
		<author><name>FPaschinger</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=Beagle_USB_12_Protocol_Analyzer:_Test&amp;diff=10452</id>
		<title>Beagle USB 12 Protocol Analyzer: Test</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=Beagle_USB_12_Protocol_Analyzer:_Test&amp;diff=10452"/>
		<updated>2022-12-12T16:31:33Z</updated>

		<summary type="html">&lt;p&gt;FPaschinger: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Summary == &lt;br /&gt;
&lt;br /&gt;
The Beagle USB 12 Protocol Analyzer is a nice tool to setup it quick and ease and allows engineers to debug problems quickly. You can capture, display and filter high-, full- and low-speed USB traffic in real time. &lt;br /&gt;
&lt;br /&gt;
[[File:Beagle_Analyzer_Front.jpg|400px|thumb|none|Beagle USB 12 Protocol Analyzer]]&lt;br /&gt;
&lt;br /&gt;
In the front of the analyzer there are the target host and target device ports. &lt;br /&gt;
They act as a passthrough to connect the target device to the host computer. &lt;br /&gt;
&lt;br /&gt;
[[File:Beagle Back.jpg|400px|thumb|none|Beagle USB 12 Protocol Analyzer]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Requirements ==&lt;br /&gt;
&lt;br /&gt;
To be able to monitor the USB traffic you will need a software that captures and displays USB, USB Type-C Power Delivery, I2C, SPI, eSPI and CAN bus data through the Beagle. To download it from the Totalphase website you will need to create an account. This does not come with any subscription or cost factor.&lt;br /&gt;
You can [https://www.totalphase.com/products/data-center/?___ Download] the Data Center Software for following architectures:&lt;br /&gt;
&lt;br /&gt;
* Windows&lt;br /&gt;
* Linux&lt;br /&gt;
* MacOS&lt;br /&gt;
&lt;br /&gt;
If you are using a Windows or a Linux host, it is also important to download the appropriate drivers since without them Windows will not recognize the analyzer:&lt;br /&gt;
&lt;br /&gt;
* Windows [https://www.totalphase.com/products/usb-drivers-windows/ (here)]&lt;br /&gt;
* Linux [https://www.totalphase.com/products/usb-drivers-linux/ (here)]&lt;br /&gt;
&lt;br /&gt;
MacOS do not require any driver.&lt;br /&gt;
For more details like, key features, technical specifications or software requirements follow this [https://www.totalphase.com/products/beagle-usb12/ link].&lt;br /&gt;
&lt;br /&gt;
== Description ==&lt;br /&gt;
&lt;br /&gt;
With the type B USB cable connect the target host port at the front of the analyzer with your PCs USB port type A. &lt;br /&gt;
The analyzis port at the backside of the analyzer is connected with another type B USB connector to your PCs USB port type A.&lt;br /&gt;
Lastly you can then plug in your target device into the USB port type A of the analyzer. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Hands-On ===&lt;br /&gt;
&lt;br /&gt;
To capture traffic, click in the top toolbar at “Analyzer” and then on “Connect to Analyzer”. Confirm that the correct device is selected and click “OK”. &lt;br /&gt;
&lt;br /&gt;
[[File:Connect to Analyzer.png|800px|thumb|none|]]&lt;br /&gt;
&lt;br /&gt;
You can then connect the USB target device (for example a mouse) to the analyzer. After clicking on the play-button, we should then see all the packet data in real-time.&lt;br /&gt;
&lt;br /&gt;
[[File:Data Center Capture 1.png|800px|thumb|none|]]&lt;br /&gt;
&lt;br /&gt;
We can see that some interesting parameters like speed, timestamp, endpoint address and the actual data were captured. The captured data has been decoded into human readable messages.&lt;br /&gt;
At the beginning we can see the handshake between the computer and the connected device. &lt;br /&gt;
We can double-click on any packet to see the low-level data and the corresponding details, which are shown in hexadecimal and ASCII. A mouse click is symbolized by a field named “Btns=[1]”.&lt;br /&gt;
&lt;br /&gt;
[[File:Data Center Capture 2.png|800px|thumb|none|]]&lt;br /&gt;
&lt;br /&gt;
It should be now possible to click on the bottom of the Navigator at “LiveFilter” to filter for those events. This should be possible by entering “btns=[1]” in the text field. Apply the filter and all “click”-mouse events are shown. This should be possible for every kind of patterns, endpoint addresses, and more. &lt;br /&gt;
&lt;br /&gt;
[[File:Data Center Capture 3.png|800px|thumb|none|]]&lt;br /&gt;
&lt;br /&gt;
By turning off scrolling and disabling the filter, we can see all the data that occurred before and after the events. &lt;br /&gt;
You can also connect a USB hub to the analyzer and plug in multiple USB devices. All devices with their assigned addresses will be shown under the navigator in the Data Center software.&lt;br /&gt;
&lt;br /&gt;
[[File:Data Center Capture 4.png|800px|thumb|none|]]&lt;br /&gt;
&lt;br /&gt;
You can also find a lot of already captured examples under “Help”, “Examples”:&lt;br /&gt;
&lt;br /&gt;
[[File:Data Center Example Captures.png|800px|thumb|none|]]&lt;br /&gt;
&lt;br /&gt;
The protocol analyzer can therefore be very helpful for debugging errors or for forensic analysis, for example.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
* https://www.totalphase.com&lt;/div&gt;</summary>
		<author><name>FPaschinger</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=Beagle_USB_12_Protocol_Analyzer:_Test&amp;diff=10451</id>
		<title>Beagle USB 12 Protocol Analyzer: Test</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=Beagle_USB_12_Protocol_Analyzer:_Test&amp;diff=10451"/>
		<updated>2022-12-12T16:30:40Z</updated>

		<summary type="html">&lt;p&gt;FPaschinger: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Summary == &lt;br /&gt;
&lt;br /&gt;
The Beagle USB 12 Protocol Analyzer is a nice tool to setup it quick and ease and allows engineers to debug problems quickly. You can capture, display and filter high-, full- and low-speed USB traffic in real time. &lt;br /&gt;
&lt;br /&gt;
[[File:Beagle_Analyzer_Front.jpg|400px|thumb|none|Beagle USB 12 Protocol Analyzer]]&lt;br /&gt;
&lt;br /&gt;
In the front of the analyzer there are the target host and target device ports. &lt;br /&gt;
They act as a passthrough to connect the target device to the host computer. &lt;br /&gt;
&lt;br /&gt;
[[File:Beagle Back.jpg|400px|thumb|none|Beagle USB 12 Protocol Analyzer]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Requirements ==&lt;br /&gt;
&lt;br /&gt;
To be able to monitor the USB traffic you will need a software that captures and displays USB, USB Type-C Power Delivery, I2C, SPI, eSPI and CAN bus data through the Beagle. To download it from the Totalphase website you will need to create an account. This does not come with any subscription or cost factor.&lt;br /&gt;
You can [https://www.totalphase.com/products/data-center/?___ Download] the Data Center Software for following architectures:&lt;br /&gt;
&lt;br /&gt;
* Windows&lt;br /&gt;
* Linux&lt;br /&gt;
* MacOS&lt;br /&gt;
&lt;br /&gt;
If you are using a Windows or a Linux host, it is also important to download the appropriate drivers since without them Windows will not recognize the analyzer:&lt;br /&gt;
&lt;br /&gt;
* Windows [https://www.totalphase.com/products/usb-drivers-windows/ (here)]&lt;br /&gt;
* Linux [https://www.totalphase.com/products/usb-drivers-linux/ (here)]&lt;br /&gt;
&lt;br /&gt;
MacOS do not require any driver.&lt;br /&gt;
For more details like, key features, technical specifications or software requirements follow this [https://www.totalphase.com/products/beagle-usb12/ link].&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Description ==&lt;br /&gt;
&lt;br /&gt;
With the type B USB cable connect the target host port at the front of the analyzer with your PCs USB port type A. &lt;br /&gt;
The analyzis port at the backside of the analyzer is connected with another type B USB connector to your PCs USB port type A.&lt;br /&gt;
Lastly you can then plug in your target device into the USB port type A of the analyzer. &lt;br /&gt;
&lt;br /&gt;
=== Hardware ===&lt;br /&gt;
&lt;br /&gt;
* Non-intrusively monitor I2C up to 4 MHz&lt;br /&gt;
* Non-intrusively monitor SPI up to 24 MHz†&lt;br /&gt;
* Non-intrusively monitor MDIO up to 2.5 MHz (Clause 22 and Clause 45)‡&lt;br /&gt;
* Real-Time Data Capture and Display - Watch I2C, and SPI packets as they occur on the bus.&lt;br /&gt;
* Bit-level timing down to 20 ns resolution.&lt;br /&gt;
* Fully Windows, Linux, and Mac OS X compatible&lt;br /&gt;
* Includes full function monitoring tools&lt;br /&gt;
* Low Cost&lt;br /&gt;
&lt;br /&gt;
=== Hands-On ===&lt;br /&gt;
&lt;br /&gt;
To capture traffic, click in the top toolbar at “Analyzer” and then on “Connect to Analyzer”. Confirm that the correct device is selected and click “OK”. &lt;br /&gt;
&lt;br /&gt;
[[File:Connect to Analyzer.png|800px|thumb|none|]]&lt;br /&gt;
&lt;br /&gt;
You can then connect the USB target device (for example a mouse) to the analyzer. After clicking on the play-button, we should then see all the packet data in real-time.&lt;br /&gt;
&lt;br /&gt;
[[File:Data Center Capture 1.png|800px|thumb|none|]]&lt;br /&gt;
&lt;br /&gt;
We can see that some interesting parameters like speed, timestamp, endpoint address and the actual data were captured. The captured data has been decoded into human readable messages.&lt;br /&gt;
At the beginning we can see the handshake between the computer and the connected device. &lt;br /&gt;
We can double-click on any packet to see the low-level data and the corresponding details, which are shown in hexadecimal and ASCII. A mouse click is symbolized by a field named “Btns=[1]”.&lt;br /&gt;
&lt;br /&gt;
[[File:Data Center Capture 2.png|800px|thumb|none|]]&lt;br /&gt;
&lt;br /&gt;
It should be now possible to click on the bottom of the Navigator at “LiveFilter” to filter for those events. This should be possible by entering “btns=[1]” in the text field. Apply the filter and all “click”-mouse events are shown. This should be possible for every kind of patterns, endpoint addresses, and more. &lt;br /&gt;
&lt;br /&gt;
[[File:Data Center Capture 3.png|800px|thumb|none|]]&lt;br /&gt;
&lt;br /&gt;
By turning off scrolling and disabling the filter, we can see all the data that occurred before and after the events. &lt;br /&gt;
You can also connect a USB hub to the analyzer and plug in multiple USB devices. All devices with their assigned addresses will be shown under the navigator in the Data Center software.&lt;br /&gt;
&lt;br /&gt;
[[File:Data Center Capture 4.png|800px|thumb|none|]]&lt;br /&gt;
&lt;br /&gt;
You can also find a lot of already captured examples under “Help”, “Examples”:&lt;br /&gt;
&lt;br /&gt;
[[File:Data Center Example Captures.png|800px|thumb|none|]]&lt;br /&gt;
&lt;br /&gt;
The protocol analyzer can therefore be very helpful for debugging errors or for forensic analysis, for example.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
* https://www.totalphase.com&lt;/div&gt;</summary>
		<author><name>FPaschinger</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=Evil_Portal_with_Wifi_Pineapple_Nano&amp;diff=10448</id>
		<title>Evil Portal with Wifi Pineapple Nano</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=Evil_Portal_with_Wifi_Pineapple_Nano&amp;diff=10448"/>
		<updated>2022-12-10T14:28:41Z</updated>

		<summary type="html">&lt;p&gt;FPaschinger: Created page with &amp;quot;== Summary ==   This documentation will show how easy it is to setup an evil portal, a fake website to receive credentials, with the Wifi Pineapple Nano. This is only for educational purposes and is illegal when used without permission.  == Requirements ==  * Wifi Pineapple Nano and included equipment * SD Card 8gb or above   The setup was tested on Kali Linux.  In order to complete these steps, you must have followed https://wiki.elvis.science/index.php?title=Pineappl...&amp;quot;&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Summary == &lt;br /&gt;
&lt;br /&gt;
This documentation will show how easy it is to setup an evil portal, a fake website to receive credentials, with the Wifi Pineapple Nano. This is only for educational purposes and is illegal when used without permission.&lt;br /&gt;
&lt;br /&gt;
== Requirements ==&lt;br /&gt;
&lt;br /&gt;
* Wifi Pineapple Nano and included equipment&lt;br /&gt;
* SD Card 8gb or above &lt;br /&gt;
&lt;br /&gt;
The setup was tested on Kali Linux.&lt;br /&gt;
&lt;br /&gt;
In order to complete these steps, you must have followed [[https://wiki.elvis.science/index.php?title=Pineapple_Setup]] for preparation.&lt;br /&gt;
&lt;br /&gt;
== Description ==&lt;br /&gt;
&lt;br /&gt;
=== Step 1 ===&lt;br /&gt;
&lt;br /&gt;
In order to use the SD Card the right way, it must formated previously. This is done on &amp;quot;Advanced&amp;quot; -&amp;gt; &amp;quot;USB &amp;amp; Storage&amp;quot; drop down arrow in the right corner -&amp;gt; &amp;quot;Format SD&amp;quot;&lt;br /&gt;
This will take couple of minutes. When it&#039;s done you can go to the next step.&lt;br /&gt;
&lt;br /&gt;
=== Step 2 ===&lt;br /&gt;
&lt;br /&gt;
Go the &amp;quot;Modules&amp;quot; section, click &amp;quot;Manage Modules&amp;quot;  then on &amp;quot;Get Modules from Hak5 Community Repositories&amp;quot; and look for the &amp;quot;Evil Portal&amp;quot; option. Click &amp;quot;Download&amp;quot; and enter the &amp;quot;Download to SD Card&amp;quot; option. &lt;br /&gt;
&lt;br /&gt;
Now there will be the &amp;quot;Evil Portal&amp;quot; option listed in the Modules section.&lt;br /&gt;
&lt;br /&gt;
To check if everthing works fine so far: &lt;br /&gt;
&lt;br /&gt;
* Enter a name for the test portal&lt;br /&gt;
* Click &amp;quot;Create New Portal&amp;quot;&lt;br /&gt;
* Activate new portal&lt;br /&gt;
* Captive Portal Start&lt;br /&gt;
* Start On Boot enable&lt;br /&gt;
* Reload the page to prevent errors&lt;br /&gt;
* Enter 172.16.42.1&lt;br /&gt;
&lt;br /&gt;
The result will look similar to this:&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[File:Pineapple Evil Portal Test Portal.png | 400px]]&lt;br /&gt;
&lt;br /&gt;
=== Step 3 ===&lt;br /&gt;
&lt;br /&gt;
Next, the pages with the realistic visuals must be downloaded. For this project the Evil Portals from https://github.com/kleo/evilportals.git are used.&lt;br /&gt;
In the shell use the command:&lt;br /&gt;
&lt;br /&gt;
*git clone https://github.com/kleo/evilportals.git&lt;br /&gt;
&lt;br /&gt;
Then transfer the portals either all of them or just specific ones to the Wifi Pineapple Nano.&lt;br /&gt;
&lt;br /&gt;
* Enter the folder where the portals are located&lt;br /&gt;
* scp -r &#039;&#039;choose-portal&#039;&#039; root@172.16.42.1:/root/portals &#039;&#039;&#039;OR WHEN AN ERROR OCCURS&#039;&#039;&#039; scp -r -O &#039;&#039;choose-portal&#039;&#039; root@172.16.42.1:/root/portals&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Now the preferred portal should be copied to the Nano.&lt;br /&gt;
&lt;br /&gt;
== Step 4 ==&lt;br /&gt;
&lt;br /&gt;
Enabling the new portals:&lt;br /&gt;
&lt;br /&gt;
* Go to the Modules section again&lt;br /&gt;
* The new Modules are listed in the work bench&lt;br /&gt;
* Deactivate or delete the test portal&lt;br /&gt;
* Activate the new portal&lt;br /&gt;
* Refresh the page&lt;br /&gt;
* Enter 172.16.42.1&lt;br /&gt;
* Enter the allowed client&#039;s MAC addresses in the white list&lt;br /&gt;
&lt;br /&gt;
The Evil Portal is now ready.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[File:Pineapple Evil Portal Google.png | 600px ]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
You can see on the picture that when entering the IP address you will be redirected to the fake Google page. On the Tab the name &amp;quot;Google&amp;quot; appears.&lt;br /&gt;
&lt;br /&gt;
== Result ==&lt;br /&gt;
&lt;br /&gt;
To see the entered credentials of the targets, click on &amp;quot;View&amp;quot; of the activated portal. There you will see a list of logs from the users.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[File:Pineapple Evil Portal Logs.png | 400 px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
* https://github.com/kleo/evilportals.git&lt;br /&gt;
&lt;br /&gt;
[[Category:Documentation]]&lt;/div&gt;</summary>
		<author><name>FPaschinger</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=File:Pineapple_Evil_Portal_Logs.png&amp;diff=10447</id>
		<title>File:Pineapple Evil Portal Logs.png</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=File:Pineapple_Evil_Portal_Logs.png&amp;diff=10447"/>
		<updated>2022-12-10T14:24:28Z</updated>

		<summary type="html">&lt;p&gt;FPaschinger: Logs of the entered credentials in the evil portal&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Summary ==&lt;br /&gt;
Logs of the entered credentials in the evil portal&lt;/div&gt;</summary>
		<author><name>FPaschinger</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=File:Pineapple_Evil_Portal_Google.png&amp;diff=10446</id>
		<title>File:Pineapple Evil Portal Google.png</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=File:Pineapple_Evil_Portal_Google.png&amp;diff=10446"/>
		<updated>2022-12-10T14:18:51Z</updated>

		<summary type="html">&lt;p&gt;FPaschinger: Wifi Pineapple Nano Evil Portal Google Example&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Summary ==&lt;br /&gt;
Wifi Pineapple Nano Evil Portal Google Example&lt;/div&gt;</summary>
		<author><name>FPaschinger</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=File:Pineapple_Evil_Portal_Test_Portal.png&amp;diff=10445</id>
		<title>File:Pineapple Evil Portal Test Portal.png</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=File:Pineapple_Evil_Portal_Test_Portal.png&amp;diff=10445"/>
		<updated>2022-12-10T13:55:05Z</updated>

		<summary type="html">&lt;p&gt;FPaschinger: Evil Portal Pineapple Nano Test Site&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Summary ==&lt;br /&gt;
Evil Portal Pineapple Nano Test Site&lt;/div&gt;</summary>
		<author><name>FPaschinger</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=Pineapple_Setup&amp;diff=10432</id>
		<title>Pineapple Setup</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=Pineapple_Setup&amp;diff=10432"/>
		<updated>2022-11-17T17:30:09Z</updated>

		<summary type="html">&lt;p&gt;FPaschinger: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Summary == &lt;br /&gt;
&lt;br /&gt;
Setup and Firmware upgrade [optional] of Wifi Pineapple Nano &lt;br /&gt;
&lt;br /&gt;
== Requirements ==&lt;br /&gt;
&lt;br /&gt;
* Operating system: Ubuntu 18.04 bionic amd64&lt;br /&gt;
* Operating system: Windows 10&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Description ==&lt;br /&gt;
&lt;br /&gt;
=== Basic setup ===&lt;br /&gt;
* Connect antennas and USB Y cable, WiFi Pineapple NANO needs a stable USB power supply capable of providing 9W for initial setup. Therefore plug both USB Ports of USB Y cable  into the Laptop. After that he blue led should have solid light.&lt;br /&gt;
&lt;br /&gt;
[[File:Pineapplenanothings.jpg|500px|WiFi Pineapple Nano]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Provision Linux ===&lt;br /&gt;
* Use lusb to verify that pineapple ASIX Electronics is recognized by your laptop&lt;br /&gt;
 &lt;br /&gt;
   lsusb&lt;br /&gt;
   ... &lt;br /&gt;
   Bus 001 Device 004: ID 0b95:772a ASIX Electronics Corp. AX88772A Fast Ethernet&lt;br /&gt;
   ...&lt;br /&gt;
&lt;br /&gt;
* Check networking interface and ip address&lt;br /&gt;
&lt;br /&gt;
   sudo ifconfig&lt;br /&gt;
   enx00c0ca91b581: flags=4163&amp;lt;UP,BROADCAST,RUNNING,MULTICAST&amp;gt;  mtu 1500&lt;br /&gt;
        inet 172.16.42.107  netmask 255.255.255.0  broadcast 172.16.42.255&lt;br /&gt;
        inet6 fe80::d2b0:568c:b39b:4c44  prefixlen 64  scopeid 0x20&amp;lt;link&amp;gt;&lt;br /&gt;
        ether 00:c0:ca:91:b5:81  txqueuelen 1000  (Ethernet)&lt;br /&gt;
        RX packets 15  bytes 1589 (1.5 KiB)&lt;br /&gt;
        RX errors 0  dropped 0  overruns 0  frame 0&lt;br /&gt;
        TX packets 40  bytes 5589 (5.4 KiB)&lt;br /&gt;
        TX errors 0  dropped 0 overruns 0  carrier 0  collisions 0&lt;br /&gt;
&lt;br /&gt;
=== Setup Windows/Linux ===&lt;br /&gt;
* Browse to the determined IP address  172.16.42.1:1471&lt;br /&gt;
&lt;br /&gt;
The Web interface should appear.&lt;br /&gt;
The interface then appearing is the main User Interface (UI) where the user is able to work with the WiFi Pineapple Nano. This UI is further described in: https://wiki.elvis.science/index.php?title=Wifi_Pineapple_Nano&lt;br /&gt;
&lt;br /&gt;
=== Internet connection Linux ===&lt;br /&gt;
* Download wp6 script&lt;br /&gt;
&lt;br /&gt;
   wget wifipinapple.com/wp6.sh&lt;br /&gt;
   ...&lt;br /&gt;
   2015-12-22 20:09:43 (4.69 MB/s) - &#039;wp6.sh&#039; saved [6112]&lt;br /&gt;
&lt;br /&gt;
* Make it executable &lt;br /&gt;
&lt;br /&gt;
   chmod +x wp6.sh&lt;br /&gt;
&lt;br /&gt;
* Execute it to set up connection. The predefined settings might work without alteration, if not, the settings are easily changed by answering some questions.  &lt;br /&gt;
&lt;br /&gt;
   sudo ./wp6.sh&lt;br /&gt;
&lt;br /&gt;
=== Internet connection Windows ===&lt;br /&gt;
* Got to network connections via the change adapter settings. A new ASIX USB Fast Ethernet adapter should have appeared here, which is the pineapple interface.&lt;br /&gt;
* In the settings of the interface that is responsible for the Internet connection, in the sharing tab, allow other users to connect through this computer&#039;s internet connection. Also use the drop down menu to select the interface of the Pineapple Nano and click OK.&lt;br /&gt;
* In the settings of the Pineapple Nano Interface, select the settings of the Internet Protocol Version 4. There you change the IP address to &#039;172.16.42.42&#039; and confirm with OK.&lt;br /&gt;
&lt;br /&gt;
=== User Interface ===&lt;br /&gt;
After connecting the Pineapple Nano to your device correctly as can be seen above, a User Interface (UI) opens under the IP address 172.16.42.1:1471&lt;br /&gt;
&lt;br /&gt;
The User Interface is the main working space for the penetration tester. The UI includes:&lt;br /&gt;
* Dashboard - shows the uptime of the device, the clients connected and the SSIDs in the pool&lt;br /&gt;
* Recon - scanning the Network&lt;br /&gt;
* Clients - List of Clients connected&lt;br /&gt;
* Tracking&lt;br /&gt;
* Modules - List of downloadable Modules&lt;br /&gt;
* Filters - Filtering Clients and connections&lt;br /&gt;
* PineAP - Main part of creating a new WiFi where youc an see the SSID pool, add and remove them and start it in order for the SSIDs to be public&lt;br /&gt;
* Logging&lt;br /&gt;
* Reporting&lt;br /&gt;
* Networking&lt;br /&gt;
* Configuration&lt;br /&gt;
* Advances&lt;br /&gt;
* Notes&lt;br /&gt;
* Help&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Upgrade to newest firmware version 2.7.0 [optional] ===&lt;br /&gt;
&lt;br /&gt;
* Download newest firmware from https://www.wifipineapple.com/downloads and verify shasum:&lt;br /&gt;
&lt;br /&gt;
   sha256sum upgrade-2.7.0.bin &lt;br /&gt;
   c69629ef90c715600e09f22ef12732c593f886db3b0ed145f549de551c48f79d upgrade-2.7.0.bin&lt;br /&gt;
&lt;br /&gt;
* Select file with newest firmware upgrade-2.7.0.bin  in the Web interface&lt;br /&gt;
** press reset button&lt;br /&gt;
** wait until firmware upgrade successfully verified appears&lt;br /&gt;
* After upgrade connect again to 172.16.42.107:1471 and get into Device Configuration&lt;br /&gt;
** Set root password for ssh and web interface access&lt;br /&gt;
** pwd: &amp;lt;ask for&amp;gt;&lt;br /&gt;
* Management AP Setup&lt;br /&gt;
** Management SSID:&lt;br /&gt;
** WPA2 pwd: &amp;lt;ask for&amp;gt;&lt;br /&gt;
** check Hide Management AP&lt;br /&gt;
* Open AP Setup&lt;br /&gt;
  is used for the target to connect to: f.e. **netlab** &lt;br /&gt;
&lt;br /&gt;
=== Troubleshooting ===&lt;br /&gt;
Error when trying to start module e.g. tcpdump:&lt;br /&gt;
&lt;br /&gt;
*Start a ssh connection to the Wifi Pineapple&lt;br /&gt;
*Enter the commands&lt;br /&gt;
**opkg update&lt;br /&gt;
**opkg install libpcap&lt;br /&gt;
&lt;br /&gt;
No internet connection from the PC when plugging in the WIFI Pineapple on Linux&lt;br /&gt;
*Ip route&lt;br /&gt;
*Ip route del default via 172.16.42.1&lt;br /&gt;
&lt;br /&gt;
=== Factory reset ===&lt;br /&gt;
&lt;br /&gt;
*Unplug the WiFi Pineapple completely from all power sources.&lt;br /&gt;
*Begin holding the RESET button on the device.&lt;br /&gt;
*With the RESET button held, power on the device.&lt;br /&gt;
*Continue holding the RESET button for 10 seconds, then release.&lt;br /&gt;
*NANO: The blue LED will remain solid&lt;br /&gt;
*Connect the host PC to the WiFi Pineapple via the USB Ethernet Port&lt;br /&gt;
*NANO: The male USB A plug&lt;br /&gt;
*From the host PC, configure a static IP address on the WiFi Pineapple facing Ethernet interface to 192.168.1.2 with netmask 255.255.255.0&lt;br /&gt;
*For example, in Linux run ifconfig eth1 192.168.1.2 netmask 255.255.255.0 up (where eth1 is the interface name of the WiFi Pineapple).&lt;br /&gt;
*From the host PC, browse to http://192.168.1.1&lt;br /&gt;
*Click Choose File and select the factory firmware image downloaded above.&lt;br /&gt;
*Click Update Firmware.&lt;br /&gt;
*This process will take several minutes. Do not interrupt the power supply while the firmware is updating. Once complete, the WiFi Pineapple will restart.&lt;br /&gt;
*Reset the WiFi Pineapple facing USB Ethernet interface back to DHCP or 172.16.42.42 with netmask 255.255.255.0 &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Used Hardware ==&lt;br /&gt;
&lt;br /&gt;
[[Wifi Pineapple Nano]]&lt;br /&gt;
&lt;br /&gt;
== Courses ==&lt;br /&gt;
&lt;br /&gt;
* [[Campus Cyber Security Team]] WiFi Hacking 21.06.2019&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
* https://docs.hak5.org/hc/en-us/articles/360010555313-Setup-Basics&lt;br /&gt;
* https://www.youtube.com/watch?v=CrHbEZd4t00&lt;br /&gt;
* https://0x00sec.org/t/solved-wifi-pineapple-nano-client-issues/4609&lt;br /&gt;
&lt;br /&gt;
[[Category:Documentation]]&lt;/div&gt;</summary>
		<author><name>FPaschinger</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=Pineapple_Setup&amp;diff=10431</id>
		<title>Pineapple Setup</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=Pineapple_Setup&amp;diff=10431"/>
		<updated>2022-11-17T17:26:39Z</updated>

		<summary type="html">&lt;p&gt;FPaschinger: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Summary == &lt;br /&gt;
&lt;br /&gt;
Setup and Firmware upgrade [optional] of Wifi Pineapple Nano &lt;br /&gt;
&lt;br /&gt;
== Requirements ==&lt;br /&gt;
&lt;br /&gt;
* Operating system: Ubuntu 18.04 bionic amd64&lt;br /&gt;
* Operating system: Windows 10&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Description ==&lt;br /&gt;
&lt;br /&gt;
=== Basic setup ===&lt;br /&gt;
* Connect antennas and USB Y cable, WiFi Pineapple NANO needs a stable USB power supply capable of providing 9W for initial setup. Therefore plug both USB Ports of USB Y cable  into the Laptop. After that he blue led should have solid light.&lt;br /&gt;
&lt;br /&gt;
[[File:Pineapplenanothings.jpg|500px|WiFi Pineapple Nano]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Provision Linux ===&lt;br /&gt;
* Use lusb to verify that pineapple ASIX Electronics is recognized by your laptop&lt;br /&gt;
 &lt;br /&gt;
   lsusb&lt;br /&gt;
   ... &lt;br /&gt;
   Bus 001 Device 004: ID 0b95:772a ASIX Electronics Corp. AX88772A Fast Ethernet&lt;br /&gt;
   ...&lt;br /&gt;
&lt;br /&gt;
* Check networking interface and ip address&lt;br /&gt;
&lt;br /&gt;
   sudo ifconfig&lt;br /&gt;
   enx00c0ca91b581: flags=4163&amp;lt;UP,BROADCAST,RUNNING,MULTICAST&amp;gt;  mtu 1500&lt;br /&gt;
        inet 172.16.42.107  netmask 255.255.255.0  broadcast 172.16.42.255&lt;br /&gt;
        inet6 fe80::d2b0:568c:b39b:4c44  prefixlen 64  scopeid 0x20&amp;lt;link&amp;gt;&lt;br /&gt;
        ether 00:c0:ca:91:b5:81  txqueuelen 1000  (Ethernet)&lt;br /&gt;
        RX packets 15  bytes 1589 (1.5 KiB)&lt;br /&gt;
        RX errors 0  dropped 0  overruns 0  frame 0&lt;br /&gt;
        TX packets 40  bytes 5589 (5.4 KiB)&lt;br /&gt;
        TX errors 0  dropped 0 overruns 0  carrier 0  collisions 0&lt;br /&gt;
&lt;br /&gt;
=== Setup Windows/Linux ===&lt;br /&gt;
* Browse to the determined IP address  172.16.42.1:1471&lt;br /&gt;
&lt;br /&gt;
The Web interface should appear.&lt;br /&gt;
The interface then appearing is the main User Interface (UI) where the user is able to work with the WiFi Pineapple Nano. This UI is further described in: https://wiki.elvis.science/index.php?title=Wifi_Pineapple_Nano&lt;br /&gt;
&lt;br /&gt;
=== Internet connection Linux ===&lt;br /&gt;
* Download wp6 script&lt;br /&gt;
&lt;br /&gt;
   wget wifipinapple.com/wp6.sh&lt;br /&gt;
   ...&lt;br /&gt;
   2015-12-22 20:09:43 (4.69 MB/s) - &#039;wp6.sh&#039; saved [6112]&lt;br /&gt;
&lt;br /&gt;
* Make it executable &lt;br /&gt;
&lt;br /&gt;
   chmod +x wp6.sh&lt;br /&gt;
&lt;br /&gt;
* Execute it to set up connection. The predefined settings might work without alteration, if not, the settings are easily changed by answering some questions.  &lt;br /&gt;
&lt;br /&gt;
   sudo ./wp6.sh&lt;br /&gt;
&lt;br /&gt;
=== Internet connection Windows ===&lt;br /&gt;
* Got to network connections via the change adapter settings. A new ASIX USB Fast Ethernet adapter should have appeared here, which is the pineapple interface.&lt;br /&gt;
* In the settings of the interface that is responsible for the Internet connection, in the sharing tab, allow other users to connect through this computer&#039;s internet connection. Also use the drop down menu to select the interface of the Pineapple Nano and click OK.&lt;br /&gt;
* In the settings of the Pineapple Nano Interface, select the settings of the Internet Protocol Version 4. There you change the IP address to &#039;172.16.42.42&#039; and confirm with OK.&lt;br /&gt;
&lt;br /&gt;
=== User Interface ===&lt;br /&gt;
After connecting the Pineapple Nano to your device correctly as can be seen above, a User Interface (UI) opens under the IP address 172.16.42.1:1471&lt;br /&gt;
&lt;br /&gt;
The User Interface is the main working space for the penetration tester. The UI includes:&lt;br /&gt;
* Dashboard - shows the uptime of the device, the clients connected and the SSIDs in the pool&lt;br /&gt;
* Recon - scanning the Network&lt;br /&gt;
* Clients - List of Clients connected&lt;br /&gt;
* Tracking&lt;br /&gt;
* Modules - List of downloadable Modules&lt;br /&gt;
* Filters - Filtering Clients and connections&lt;br /&gt;
* PineAP - Main part of creating a new WiFi where youc an see the SSID pool, add and remove them and start it in order for the SSIDs to be public&lt;br /&gt;
* Logging&lt;br /&gt;
* Reporting&lt;br /&gt;
* Networking&lt;br /&gt;
* Configuration&lt;br /&gt;
* Advances&lt;br /&gt;
* Notes&lt;br /&gt;
* Help&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Upgrade to newest firmware version 2.7.0 [optional] ===&lt;br /&gt;
&lt;br /&gt;
* Download newest firmware from https://www.wifipineapple.com/downloads and verify shasum:&lt;br /&gt;
&lt;br /&gt;
   sha256sum upgrade-2.7.0.bin &lt;br /&gt;
   c69629ef90c715600e09f22ef12732c593f886db3b0ed145f549de551c48f79d upgrade-2.7.0.bin&lt;br /&gt;
&lt;br /&gt;
* Select file with newest firmware upgrade-2.7.0.bin  in the Web interface&lt;br /&gt;
** press reset button&lt;br /&gt;
** wait until firmware upgrade successfully verified appears&lt;br /&gt;
* After upgrade connect again to 172.16.42.107:1471 and get into Device Configuration&lt;br /&gt;
** Set root password for ssh and web interface access&lt;br /&gt;
** pwd: &amp;lt;ask for&amp;gt;&lt;br /&gt;
* Management AP Setup&lt;br /&gt;
** Management SSID:&lt;br /&gt;
** WPA2 pwd: &amp;lt;ask for&amp;gt;&lt;br /&gt;
** check Hide Management AP&lt;br /&gt;
* Open AP Setup&lt;br /&gt;
  is used for the target to connect to: f.e. **netlab** &lt;br /&gt;
&lt;br /&gt;
=== Troubleshooting ===&lt;br /&gt;
Error when trying to start module e.g. tcpdump:&lt;br /&gt;
&lt;br /&gt;
*Start a ssh connection to the Wifi Pineapple&lt;br /&gt;
*Enter the commands&lt;br /&gt;
**opkg update&lt;br /&gt;
**opkg install libpcap&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Used Hardware ==&lt;br /&gt;
&lt;br /&gt;
[[Wifi Pineapple Nano]]&lt;br /&gt;
&lt;br /&gt;
== Courses ==&lt;br /&gt;
&lt;br /&gt;
* [[Campus Cyber Security Team]] WiFi Hacking 21.06.2019&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
* https://docs.hak5.org/hc/en-us/articles/360010555313-Setup-Basics&lt;br /&gt;
* https://www.youtube.com/watch?v=CrHbEZd4t00&lt;br /&gt;
&lt;br /&gt;
[[Category:Documentation]]&lt;/div&gt;</summary>
		<author><name>FPaschinger</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=Software-defined_radio_(SDR):_Relay_Attacks&amp;diff=10296</id>
		<title>Software-defined radio (SDR): Relay Attacks</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=Software-defined_radio_(SDR):_Relay_Attacks&amp;diff=10296"/>
		<updated>2022-07-12T19:03:12Z</updated>

		<summary type="html">&lt;p&gt;FPaschinger: /* Introduction */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Introduction ==&lt;br /&gt;
&lt;br /&gt;
We want to simulate a keyless car hacking situation. Therefore we want to interfere with a connection between a car and a car key during the opening process.&lt;br /&gt;
The key question is: How does a Passive Keyless Entry (PKE) system works? PKE communication is an electronic locking system which is mainly used for entering cars without needing any keys. The locking system uses passive components (keys) which will be activated by the car. The car constantly transmits its recognition signal, range is about 1.5-3 meters.&lt;br /&gt;
One of the most used systems is the so-called “keyless entry system”. Therefore, the car environment is surrounded by periodically low frequency signals about 130 kHz. If the right key is in this zone, the chip is reacting with those low frequencies and is creating an ID with ASK / FSK modulated signals.&lt;br /&gt;
Therefore, we got 2 possibilities:&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039; 1.     The car is sending a LF signal with some kind of “wake up signal”. &#039;&#039;&#039;&lt;br /&gt;
#  	The car is sending permanent wake up signals.&lt;br /&gt;
# 	If a “keyless entry key” is in the near of, an “Acknowledgement” is transmitted to the car.&lt;br /&gt;
#  	If the key and car fits together, an ID check is going to start.&lt;br /&gt;
# 	The car is sending an ID to the key – if it fits, the key is transmitting the right key code. If the key code fits to the one of the automotive, the car is opening.&lt;br /&gt;
&#039;&#039;&#039;2.     The car sends a LF signal with a car ID. &#039;&#039;&#039;&lt;br /&gt;
#  	Periodically a LF signal is transmitted by the car.&lt;br /&gt;
# 	If a “keyless entry key” is nearby and the ID fits to the one of the car’s, the key transmits the right “key code”. If the key code fits, the car is going to open.&lt;br /&gt;
&lt;br /&gt;
== Summary == &lt;br /&gt;
&lt;br /&gt;
This documentation is about SDR (Software defined radio) and relay attacks. This document will give you a better understanding of these definitions and how some devices in IOT can/could be attacked with SDR relay attacks. This documentations will also provides detailed information about devices we used, the setup of these devices and other requirements. &lt;br /&gt;
&lt;br /&gt;
== Requirements ==&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039; Software &#039;&#039;&#039;&lt;br /&gt;
*Computer with native Kali-Linux installed.&lt;br /&gt;
*License for PandwaRF.&lt;br /&gt;
*PandwaRF App for Android. (Must be a device with latest Android version installed)&lt;br /&gt;
&lt;br /&gt;
== Description ==&lt;br /&gt;
&lt;br /&gt;
=== Pentesting with PandwaRF ===&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039; Step 1 &#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
#Install the application on your Android Phone.&lt;br /&gt;
#Open the Device.&lt;br /&gt;
#Install the antennas. (Never use a SDR Device without antennas.)&lt;br /&gt;
#Connect the PandwaRF via USB-C to your phone.&lt;br /&gt;
#Open the application.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039; Step 2 &#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
#The device should have connected with your application. If not, do it manually in the search tab.&lt;br /&gt;
#After the device has connected, you can use the spectrum analyser to analyse the frequency which the device captures. If you want to get your desired signal, you need to choose your frequency. &lt;br /&gt;
#At the Rx/Tx tab you can scan you signal which you try to capture. It is even possible to auto detect a signal which is sent.The pandwaRF will give you the captured signal in hex or in Binary which you can afterwards analyze. &lt;br /&gt;
#In order to transmit a captured signal, you need to buy a &amp;quot;Kaiju License&amp;quot;. Kaiju is an online tool where you can analyze rolling code and generate those. Kaiju is mainly used to attack systems which use rolling code.&lt;br /&gt;
&lt;br /&gt;
=== Pentesting with HackRF one ===&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039; Step 1 &#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
#Set up a laptop with native kali linux &lt;br /&gt;
#If you want dual boot on your local machine use these instructions&lt;br /&gt;
&lt;br /&gt;
* Dualboot on windows machine &lt;br /&gt;
&lt;br /&gt;
#You need a USB stick with a minimum of 8gb storage&lt;br /&gt;
#Download Kali image from official website https://www.kali.org/docs/development/live-build-a-custom-kali-iso/&lt;br /&gt;
#Download e.g. Etcher to flash the image on the USB stick to make it bootable https://www.balena.io/etcher/&lt;br /&gt;
#On the computer enter BIOS and change the BIOS-Mode to Legacy instead of Secure Boot (if secure boot is enabled). Secure boot prevents booting from external device! Then change the BIOS-Priority to “USB” first.&lt;br /&gt;
#For further information follow the instructions on the official website https://www.kali.org/docs/usb/live-usb-install-with-linux/&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039; Step 2 &#039;&#039;&#039;&lt;br /&gt;
** Driver Installation on HackRF One&lt;br /&gt;
#Download Zadig https://zadig.akeo.ie/&lt;br /&gt;
#Only compatible with Windows &lt;br /&gt;
&lt;br /&gt;
* Set-up HackRF on Linux&lt;br /&gt;
#	Sudo apt-get update&lt;br /&gt;
#	Sudo apt-get -y install hackrf&lt;br /&gt;
&lt;br /&gt;
Download Universal Radio Hacker on Linux machine&lt;br /&gt;
* First method &lt;br /&gt;
#	Sudo python3 -m pip install –upgrade pip&lt;br /&gt;
#	Sudo python3 -m pip install urh&lt;br /&gt;
* Second method &lt;br /&gt;
#	Sudo apt -y install urh&lt;br /&gt;
* Third method&lt;br /&gt;
#	git clone https://github.com/jopohl/urh&lt;br /&gt;
#   cd urh&lt;br /&gt;
#   python setup.py install&lt;br /&gt;
* Start Universal Radio Hacker with the command “urh”&lt;br /&gt;
#	Choose HackRF&lt;br /&gt;
#	Enter the frequency&lt;br /&gt;
&lt;br /&gt;
=== Nesdr Smart – receive only ===&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039; Step 1 &#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
Install the driver with zadig (detailed information in the HackRF One section)&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039; Step 2 &#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
Enter the RTL-SDR the “Device” option of the device settings and the frequency and you are ready to receive signals!&lt;br /&gt;
&lt;br /&gt;
== Used Hardware ==&lt;br /&gt;
&lt;br /&gt;
* HackRF One&lt;br /&gt;
* PandwaRF&lt;br /&gt;
* Nooelec SDR&lt;br /&gt;
&lt;br /&gt;
== Conclusion ==&lt;br /&gt;
We were able to receive signals with all three Software defined radios. However, HackRF One was the only device which allowed us to transmit signals too. It should be possible to transmit signal with PandwaRF as well, but we struggled with the Kaiju license, which is necessary for the transmission process. Therefore, we were able to achieve our project goals with the HackRF One.&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
* https://www.youtube.com/watch?v=5CsD8I396wo&amp;amp;t=327s&lt;br /&gt;
* https://www.essentracomponents.com/en-gb/news/product-resources/explaining-remote-keyless-entry-in-cars&lt;br /&gt;
* https://en.wikipedia.org/wiki/Rolling_code#:~:text=A%20rolling%20code%20(or%20sometimes,and%20keyless%20car%20entry%20systems&lt;br /&gt;
* https://www.youtube.com/watch?v=XrRGDQ2IzDE&lt;br /&gt;
* https://en.wikipedia.org/wiki/Remote_keyless_system&lt;br /&gt;
* https://sectigo.com/resource-library/why-automotive-key-fob-encryption-hacks-are-making-headlines&lt;br /&gt;
* https://rolling.pandwarf.com/&lt;br /&gt;
* https://www.offensive-wireless.com/how-to-install-universal-radio-hacker/&lt;br /&gt;
* https://installati.one/ubuntu/20.04/hackrf/&lt;br /&gt;
* https://zadig.akeo.ie/&lt;br /&gt;
* https://www.kali.org/docs/usb/live-usb-install-with-linux/&lt;br /&gt;
* https://www.balena.io/etcher/&lt;br /&gt;
* https://www.kali.org/docs/introduction/download-official-kali-linux-images/&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[Category:Documentation]]&lt;/div&gt;</summary>
		<author><name>FPaschinger</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=Software-defined_radio_(SDR):_Relay_Attacks&amp;diff=10294</id>
		<title>Software-defined radio (SDR): Relay Attacks</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=Software-defined_radio_(SDR):_Relay_Attacks&amp;diff=10294"/>
		<updated>2022-07-12T19:00:09Z</updated>

		<summary type="html">&lt;p&gt;FPaschinger: /* Introduction */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Introduction ==&lt;br /&gt;
&lt;br /&gt;
We want to simulate a keyless car hacking situation. Therefore we want to interfere with a connection between a car and a car key during the opening process.&lt;br /&gt;
The key question is: How does a Passive Keyless Entry (PKE) system works? PKE communication is an electronic locking system which is mainly used for entering cars without needing any keys. The locking system uses passive components (keys) which will be activated by the car. The car constantly transmits its recognition signal, range is about 1.5-3 meters.&lt;br /&gt;
One of the most used systems is the so-called “keyless entry system”. Therefore, the car environment is surrounded by periodically low frequency signals about 130 kHz. If the right key is in this zone, the chip is reacting with those low frequencies and is creating an ID with ASK / FSK modulated signals.&lt;br /&gt;
Therefore, we got 2 possibilities:&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039; 1.     The car is sending a LF signal with some kind of “wake up signal”. &#039;&#039;&#039;&lt;br /&gt;
#a.  	The car is sending permanent wake up signals.&lt;br /&gt;
#b. 	If a “keyless entry key” is in the near of, an “Acknowledgement” is transmitted to the car.&lt;br /&gt;
#c.  	If the key and car fits together, an ID check is going to start.&lt;br /&gt;
#d. 	The car is sending an ID to the key – if it fits, the key is transmitting the right key code. If the key code fits to the one of the automotive, the car is opening.&lt;br /&gt;
&#039;&#039;&#039;2.     The car sends a LF signal with a car ID. &#039;&#039;&#039;&lt;br /&gt;
#a.  	Periodically a LF signal is transmitted by the car.&lt;br /&gt;
#b. 	If a “keyless entry key” is nearby and the ID fits to the one of the car’s, the key transmits the right “key code”. If the key code fits, the car is going to open.&lt;br /&gt;
&lt;br /&gt;
== Summary == &lt;br /&gt;
&lt;br /&gt;
This documentation is about SDR (Software defined radio) and relay attacks. This document will give you a better understanding of these definitions and how some devices in IOT can/could be attacked with SDR relay attacks. This documentations will also provides detailed information about devices we used, the setup of these devices and other requirements. &lt;br /&gt;
&lt;br /&gt;
== Requirements ==&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039; Software &#039;&#039;&#039;&lt;br /&gt;
*Computer with native Kali-Linux installed.&lt;br /&gt;
*License for PandwaRF.&lt;br /&gt;
*PandwaRF App for Android. (Must be a device with latest Android version installed)&lt;br /&gt;
&lt;br /&gt;
== Description ==&lt;br /&gt;
&lt;br /&gt;
=== Pentesting with PandwaRF ===&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039; Step 1 &#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
#Install the application on your Android Phone.&lt;br /&gt;
#Open the Device.&lt;br /&gt;
#Install the antennas. (Never use a SDR Device without antennas.)&lt;br /&gt;
#Connect the PandwaRF via USB-C to your phone.&lt;br /&gt;
#Open the application.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039; Step 2 &#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
#The device should have connected with your application. If not, do it manually in the search tab.&lt;br /&gt;
#After the device has connected, you can use the spectrum analyser to analyse the frequency which the device captures. If you want to get your desired signal, you need to choose your frequency. &lt;br /&gt;
#At the Rx/Tx tab you can scan you signal which you try to capture. It is even possible to auto detect a signal which is sent.The pandwaRF will give you the captured signal in hex or in Binary which you can afterwards analyze. &lt;br /&gt;
#In order to transmit a captured signal, you need to buy a &amp;quot;Kaiju License&amp;quot;. Kaiju is an online tool where you can analyze rolling code and generate those. Kaiju is mainly used to attack systems which use rolling code.&lt;br /&gt;
&lt;br /&gt;
=== Pentesting with HackRF one ===&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039; Step 1 &#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
#Set up a laptop with native kali linux &lt;br /&gt;
#If you want dual boot on your local machine use these instructions&lt;br /&gt;
&lt;br /&gt;
* Dualboot on windows machine &lt;br /&gt;
&lt;br /&gt;
#You need a USB stick with a minimum of 8gb storage&lt;br /&gt;
#Download Kali image from official website https://www.kali.org/docs/development/live-build-a-custom-kali-iso/&lt;br /&gt;
#Download e.g. Etcher to flash the image on the USB stick to make it bootable https://www.balena.io/etcher/&lt;br /&gt;
#On the computer enter BIOS and change the BIOS-Mode to Legacy instead of Secure Boot (if secure boot is enabled). Secure boot prevents booting from external device! Then change the BIOS-Priority to “USB” first.&lt;br /&gt;
#For further information follow the instructions on the official website https://www.kali.org/docs/usb/live-usb-install-with-linux/&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039; Step 2 &#039;&#039;&#039;&lt;br /&gt;
** Driver Installation on HackRF One&lt;br /&gt;
#Download Zadig https://zadig.akeo.ie/&lt;br /&gt;
#Only compatible with Windows &lt;br /&gt;
&lt;br /&gt;
* Set-up HackRF on Linux&lt;br /&gt;
#	Sudo apt-get update&lt;br /&gt;
#	Sudo apt-get -y install hackrf&lt;br /&gt;
&lt;br /&gt;
Download Universal Radio Hacker on Linux machine&lt;br /&gt;
* First method &lt;br /&gt;
#	Sudo python3 -m pip install –upgrade pip&lt;br /&gt;
#	Sudo python3 -m pip install urh&lt;br /&gt;
* Second method &lt;br /&gt;
#	Sudo apt -y install urh&lt;br /&gt;
* Third method&lt;br /&gt;
#	git clone https://github.com/jopohl/urh&lt;br /&gt;
#   cd urh&lt;br /&gt;
#   python setup.py install&lt;br /&gt;
* Start Universal Radio Hacker with the command “urh”&lt;br /&gt;
#	Choose HackRF&lt;br /&gt;
#	Enter the frequency&lt;br /&gt;
&lt;br /&gt;
=== Nesdr Smart – receive only ===&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039; Step 1 &#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
Install the driver with zadig (detailed information in the HackRF One section)&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039; Step 2 &#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
Enter the RTL-SDR the “Device” option of the device settings and the frequency and you are ready to receive signals!&lt;br /&gt;
&lt;br /&gt;
== Used Hardware ==&lt;br /&gt;
&lt;br /&gt;
* HackRF One&lt;br /&gt;
* PandwaRF&lt;br /&gt;
* Nooelec SDR&lt;br /&gt;
&lt;br /&gt;
== Conclusion ==&lt;br /&gt;
We were able to receive signals with all three Software defined radios. However, HackRF One was the only device which allowed us to transmit signals too. It should be possible to transmit signal with PandwaRF as well, but we struggled with the Kaiju license, which is necessary for the transmission process. Therefore, we were able to achieve our project goals with the HackRF One.&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
* https://www.youtube.com/watch?v=5CsD8I396wo&amp;amp;t=327s&lt;br /&gt;
* https://www.essentracomponents.com/en-gb/news/product-resources/explaining-remote-keyless-entry-in-cars&lt;br /&gt;
* https://en.wikipedia.org/wiki/Rolling_code#:~:text=A%20rolling%20code%20(or%20sometimes,and%20keyless%20car%20entry%20systems&lt;br /&gt;
* https://www.youtube.com/watch?v=XrRGDQ2IzDE&lt;br /&gt;
* https://en.wikipedia.org/wiki/Remote_keyless_system&lt;br /&gt;
* https://sectigo.com/resource-library/why-automotive-key-fob-encryption-hacks-are-making-headlines&lt;br /&gt;
* https://rolling.pandwarf.com/&lt;br /&gt;
* https://www.offensive-wireless.com/how-to-install-universal-radio-hacker/&lt;br /&gt;
* https://installati.one/ubuntu/20.04/hackrf/&lt;br /&gt;
* https://zadig.akeo.ie/&lt;br /&gt;
* https://www.kali.org/docs/usb/live-usb-install-with-linux/&lt;br /&gt;
* https://www.balena.io/etcher/&lt;br /&gt;
* https://www.kali.org/docs/introduction/download-official-kali-linux-images/&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[Category:Documentation]]&lt;/div&gt;</summary>
		<author><name>FPaschinger</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=Software-defined_radio_(SDR):_Relay_Attacks&amp;diff=10292</id>
		<title>Software-defined radio (SDR): Relay Attacks</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=Software-defined_radio_(SDR):_Relay_Attacks&amp;diff=10292"/>
		<updated>2022-07-12T18:59:28Z</updated>

		<summary type="html">&lt;p&gt;FPaschinger: /* Introduction */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Introduction ==&lt;br /&gt;
&lt;br /&gt;
We want to simulate a keyless car hacking situation. Therefore we want to interfere with a connection between a car and a car key during the opening process.&lt;br /&gt;
The key question is: How does a Passive Keyless Entry (PKE) system works? PKE communication is an electronic locking system which is mainly used for entering cars without needing any keys. The locking system uses passive components (keys) which will be activated by the car. The car constantly transmits its recognition signal, range is about 1.5-3 meters.&lt;br /&gt;
One of the most used systems is the so-called “keyless entry system”. Therefore, the car environment is surrounded by periodically low frequency signals about 130 kHz. If the right key is in this zone, the chip is reacting with those low frequencies and is creating an ID with ASK / FSK modulated signals.&lt;br /&gt;
 &lt;br /&gt;
#Therefore, we got 2 possibilities:&lt;br /&gt;
&#039;&#039;&#039; 1.     The car is sending a LF signal with some kind of “wake up signal”. &#039;&#039;&#039;&lt;br /&gt;
#a.  	The car is sending permanent wake up signals.&lt;br /&gt;
#b. 	If a “keyless entry key” is in the near of, an “Acknowledgement” is transmitted to the car.&lt;br /&gt;
#c.  	If the key and car fits together, an ID check is going to start.&lt;br /&gt;
#d. 	The car is sending an ID to the key – if it fits, the key is transmitting the right key code. If the key code fits to the one of the automotive, the car is opening.&lt;br /&gt;
&#039;&#039;&#039;2.     The car sends a LF signal with a car ID. &#039;&#039;&#039;&lt;br /&gt;
#a.  	Periodically a LF signal is transmitted by the car.&lt;br /&gt;
#b. 	If a “keyless entry key” is nearby and the ID fits to the one of the car’s, the key transmits the right “key code”. If the key code fits, the car is going to open.&lt;br /&gt;
&lt;br /&gt;
== Summary == &lt;br /&gt;
&lt;br /&gt;
This documentation is about SDR (Software defined radio) and relay attacks. This document will give you a better understanding of these definitions and how some devices in IOT can/could be attacked with SDR relay attacks. This documentations will also provides detailed information about devices we used, the setup of these devices and other requirements. &lt;br /&gt;
&lt;br /&gt;
== Requirements ==&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039; Software &#039;&#039;&#039;&lt;br /&gt;
*Computer with native Kali-Linux installed.&lt;br /&gt;
*License for PandwaRF.&lt;br /&gt;
*PandwaRF App for Android. (Must be a device with latest Android version installed)&lt;br /&gt;
&lt;br /&gt;
== Description ==&lt;br /&gt;
&lt;br /&gt;
=== Pentesting with PandwaRF ===&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039; Step 1 &#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
#Install the application on your Android Phone.&lt;br /&gt;
#Open the Device.&lt;br /&gt;
#Install the antennas. (Never use a SDR Device without antennas.)&lt;br /&gt;
#Connect the PandwaRF via USB-C to your phone.&lt;br /&gt;
#Open the application.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039; Step 2 &#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
#The device should have connected with your application. If not, do it manually in the search tab.&lt;br /&gt;
#After the device has connected, you can use the spectrum analyser to analyse the frequency which the device captures. If you want to get your desired signal, you need to choose your frequency. &lt;br /&gt;
#At the Rx/Tx tab you can scan you signal which you try to capture. It is even possible to auto detect a signal which is sent.The pandwaRF will give you the captured signal in hex or in Binary which you can afterwards analyze. &lt;br /&gt;
#In order to transmit a captured signal, you need to buy a &amp;quot;Kaiju License&amp;quot;. Kaiju is an online tool where you can analyze rolling code and generate those. Kaiju is mainly used to attack systems which use rolling code.&lt;br /&gt;
&lt;br /&gt;
=== Pentesting with HackRF one ===&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039; Step 1 &#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
#Set up a laptop with native kali linux &lt;br /&gt;
#If you want dual boot on your local machine use these instructions&lt;br /&gt;
&lt;br /&gt;
* Dualboot on windows machine &lt;br /&gt;
&lt;br /&gt;
#You need a USB stick with a minimum of 8gb storage&lt;br /&gt;
#Download Kali image from official website https://www.kali.org/docs/development/live-build-a-custom-kali-iso/&lt;br /&gt;
#Download e.g. Etcher to flash the image on the USB stick to make it bootable https://www.balena.io/etcher/&lt;br /&gt;
#On the computer enter BIOS and change the BIOS-Mode to Legacy instead of Secure Boot (if secure boot is enabled). Secure boot prevents booting from external device! Then change the BIOS-Priority to “USB” first.&lt;br /&gt;
#For further information follow the instructions on the official website https://www.kali.org/docs/usb/live-usb-install-with-linux/&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039; Step 2 &#039;&#039;&#039;&lt;br /&gt;
** Driver Installation on HackRF One&lt;br /&gt;
#Download Zadig https://zadig.akeo.ie/&lt;br /&gt;
#Only compatible with Windows &lt;br /&gt;
&lt;br /&gt;
* Set-up HackRF on Linux&lt;br /&gt;
#	Sudo apt-get update&lt;br /&gt;
#	Sudo apt-get -y install hackrf&lt;br /&gt;
&lt;br /&gt;
Download Universal Radio Hacker on Linux machine&lt;br /&gt;
* First method &lt;br /&gt;
#	Sudo python3 -m pip install –upgrade pip&lt;br /&gt;
#	Sudo python3 -m pip install urh&lt;br /&gt;
* Second method &lt;br /&gt;
#	Sudo apt -y install urh&lt;br /&gt;
* Third method&lt;br /&gt;
#	git clone https://github.com/jopohl/urh&lt;br /&gt;
#   cd urh&lt;br /&gt;
#   python setup.py install&lt;br /&gt;
* Start Universal Radio Hacker with the command “urh”&lt;br /&gt;
#	Choose HackRF&lt;br /&gt;
#	Enter the frequency&lt;br /&gt;
&lt;br /&gt;
=== Nesdr Smart – receive only ===&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039; Step 1 &#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
Install the driver with zadig (detailed information in the HackRF One section)&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039; Step 2 &#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
Enter the RTL-SDR the “Device” option of the device settings and the frequency and you are ready to receive signals!&lt;br /&gt;
&lt;br /&gt;
== Used Hardware ==&lt;br /&gt;
&lt;br /&gt;
* HackRF One&lt;br /&gt;
* PandwaRF&lt;br /&gt;
* Nooelec SDR&lt;br /&gt;
&lt;br /&gt;
== Conclusion ==&lt;br /&gt;
We were able to receive signals with all three Software defined radios. However, HackRF One was the only device which allowed us to transmit signals too. It should be possible to transmit signal with PandwaRF as well, but we struggled with the Kaiju license, which is necessary for the transmission process. Therefore, we were able to achieve our project goals with the HackRF One.&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
* https://www.youtube.com/watch?v=5CsD8I396wo&amp;amp;t=327s&lt;br /&gt;
* https://www.essentracomponents.com/en-gb/news/product-resources/explaining-remote-keyless-entry-in-cars&lt;br /&gt;
* https://en.wikipedia.org/wiki/Rolling_code#:~:text=A%20rolling%20code%20(or%20sometimes,and%20keyless%20car%20entry%20systems&lt;br /&gt;
* https://www.youtube.com/watch?v=XrRGDQ2IzDE&lt;br /&gt;
* https://en.wikipedia.org/wiki/Remote_keyless_system&lt;br /&gt;
* https://sectigo.com/resource-library/why-automotive-key-fob-encryption-hacks-are-making-headlines&lt;br /&gt;
* https://rolling.pandwarf.com/&lt;br /&gt;
* https://www.offensive-wireless.com/how-to-install-universal-radio-hacker/&lt;br /&gt;
* https://installati.one/ubuntu/20.04/hackrf/&lt;br /&gt;
* https://zadig.akeo.ie/&lt;br /&gt;
* https://www.kali.org/docs/usb/live-usb-install-with-linux/&lt;br /&gt;
* https://www.balena.io/etcher/&lt;br /&gt;
* https://www.kali.org/docs/introduction/download-official-kali-linux-images/&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[Category:Documentation]]&lt;/div&gt;</summary>
		<author><name>FPaschinger</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=Software-defined_radio_(SDR):_Relay_Attacks&amp;diff=10291</id>
		<title>Software-defined radio (SDR): Relay Attacks</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=Software-defined_radio_(SDR):_Relay_Attacks&amp;diff=10291"/>
		<updated>2022-07-12T18:59:13Z</updated>

		<summary type="html">&lt;p&gt;FPaschinger: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Introduction ==&lt;br /&gt;
&lt;br /&gt;
We want to simulate a keyless car hacking situation. Therefore we want to interfere with a connection between a car and a car key during the opening process.&lt;br /&gt;
The key question is: How does a Passive Keyless Entry (PKE) system works? PKE communication is an electronic locking system which is mainly used for entering cars without needing any keys. The locking system uses passive components (keys) which will be activated by the car. The car constantly transmits its recognition signal, range is about 1.5-3 meters.&lt;br /&gt;
One of the most used systems is the so-called “keyless entry system”. Therefore, the car environment is surrounded by periodically low frequency signals about 130 kHz. If the right key is in this zone, the chip is reacting with those low frequencies and is creating an ID with ASK / FSK modulated signals.&lt;br /&gt;
 &lt;br /&gt;
Therefore, we got 2 possibilities:&lt;br /&gt;
&#039;&#039;&#039; 1.     The car is sending a LF signal with some kind of “wake up signal”. &#039;&#039;&#039;&lt;br /&gt;
#a.  	The car is sending permanent wake up signals.&lt;br /&gt;
#b. 	If a “keyless entry key” is in the near of, an “Acknowledgement” is transmitted to the car.&lt;br /&gt;
#c.  	If the key and car fits together, an ID check is going to start.&lt;br /&gt;
#d. 	The car is sending an ID to the key – if it fits, the key is transmitting the right key code. If the key code fits to the one of the automotive, the car is opening.&lt;br /&gt;
&#039;&#039;&#039;2.     The car sends a LF signal with a car ID. &#039;&#039;&#039;&lt;br /&gt;
#a.  	Periodically a LF signal is transmitted by the car.&lt;br /&gt;
#b. 	If a “keyless entry key” is nearby and the ID fits to the one of the car’s, the key transmits the right “key code”. If the key code fits, the car is going to open. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Summary == &lt;br /&gt;
&lt;br /&gt;
This documentation is about SDR (Software defined radio) and relay attacks. This document will give you a better understanding of these definitions and how some devices in IOT can/could be attacked with SDR relay attacks. This documentations will also provides detailed information about devices we used, the setup of these devices and other requirements. &lt;br /&gt;
&lt;br /&gt;
== Requirements ==&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039; Software &#039;&#039;&#039;&lt;br /&gt;
*Computer with native Kali-Linux installed.&lt;br /&gt;
*License for PandwaRF.&lt;br /&gt;
*PandwaRF App for Android. (Must be a device with latest Android version installed)&lt;br /&gt;
&lt;br /&gt;
== Description ==&lt;br /&gt;
&lt;br /&gt;
=== Pentesting with PandwaRF ===&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039; Step 1 &#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
#Install the application on your Android Phone.&lt;br /&gt;
#Open the Device.&lt;br /&gt;
#Install the antennas. (Never use a SDR Device without antennas.)&lt;br /&gt;
#Connect the PandwaRF via USB-C to your phone.&lt;br /&gt;
#Open the application.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039; Step 2 &#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
#The device should have connected with your application. If not, do it manually in the search tab.&lt;br /&gt;
#After the device has connected, you can use the spectrum analyser to analyse the frequency which the device captures. If you want to get your desired signal, you need to choose your frequency. &lt;br /&gt;
#At the Rx/Tx tab you can scan you signal which you try to capture. It is even possible to auto detect a signal which is sent.The pandwaRF will give you the captured signal in hex or in Binary which you can afterwards analyze. &lt;br /&gt;
#In order to transmit a captured signal, you need to buy a &amp;quot;Kaiju License&amp;quot;. Kaiju is an online tool where you can analyze rolling code and generate those. Kaiju is mainly used to attack systems which use rolling code.&lt;br /&gt;
&lt;br /&gt;
=== Pentesting with HackRF one ===&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039; Step 1 &#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
#Set up a laptop with native kali linux &lt;br /&gt;
#If you want dual boot on your local machine use these instructions&lt;br /&gt;
&lt;br /&gt;
* Dualboot on windows machine &lt;br /&gt;
&lt;br /&gt;
#You need a USB stick with a minimum of 8gb storage&lt;br /&gt;
#Download Kali image from official website https://www.kali.org/docs/development/live-build-a-custom-kali-iso/&lt;br /&gt;
#Download e.g. Etcher to flash the image on the USB stick to make it bootable https://www.balena.io/etcher/&lt;br /&gt;
#On the computer enter BIOS and change the BIOS-Mode to Legacy instead of Secure Boot (if secure boot is enabled). Secure boot prevents booting from external device! Then change the BIOS-Priority to “USB” first.&lt;br /&gt;
#For further information follow the instructions on the official website https://www.kali.org/docs/usb/live-usb-install-with-linux/&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039; Step 2 &#039;&#039;&#039;&lt;br /&gt;
** Driver Installation on HackRF One&lt;br /&gt;
#Download Zadig https://zadig.akeo.ie/&lt;br /&gt;
#Only compatible with Windows &lt;br /&gt;
&lt;br /&gt;
* Set-up HackRF on Linux&lt;br /&gt;
#	Sudo apt-get update&lt;br /&gt;
#	Sudo apt-get -y install hackrf&lt;br /&gt;
&lt;br /&gt;
Download Universal Radio Hacker on Linux machine&lt;br /&gt;
* First method &lt;br /&gt;
#	Sudo python3 -m pip install –upgrade pip&lt;br /&gt;
#	Sudo python3 -m pip install urh&lt;br /&gt;
* Second method &lt;br /&gt;
#	Sudo apt -y install urh&lt;br /&gt;
* Third method&lt;br /&gt;
#	git clone https://github.com/jopohl/urh&lt;br /&gt;
#   cd urh&lt;br /&gt;
#   python setup.py install&lt;br /&gt;
* Start Universal Radio Hacker with the command “urh”&lt;br /&gt;
#	Choose HackRF&lt;br /&gt;
#	Enter the frequency&lt;br /&gt;
&lt;br /&gt;
=== Nesdr Smart – receive only ===&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039; Step 1 &#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
Install the driver with zadig (detailed information in the HackRF One section)&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039; Step 2 &#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
Enter the RTL-SDR the “Device” option of the device settings and the frequency and you are ready to receive signals!&lt;br /&gt;
&lt;br /&gt;
== Used Hardware ==&lt;br /&gt;
&lt;br /&gt;
* HackRF One&lt;br /&gt;
* PandwaRF&lt;br /&gt;
* Nooelec SDR&lt;br /&gt;
&lt;br /&gt;
== Conclusion ==&lt;br /&gt;
We were able to receive signals with all three Software defined radios. However, HackRF One was the only device which allowed us to transmit signals too. It should be possible to transmit signal with PandwaRF as well, but we struggled with the Kaiju license, which is necessary for the transmission process. Therefore, we were able to achieve our project goals with the HackRF One.&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
* https://www.youtube.com/watch?v=5CsD8I396wo&amp;amp;t=327s&lt;br /&gt;
* https://www.essentracomponents.com/en-gb/news/product-resources/explaining-remote-keyless-entry-in-cars&lt;br /&gt;
* https://en.wikipedia.org/wiki/Rolling_code#:~:text=A%20rolling%20code%20(or%20sometimes,and%20keyless%20car%20entry%20systems&lt;br /&gt;
* https://www.youtube.com/watch?v=XrRGDQ2IzDE&lt;br /&gt;
* https://en.wikipedia.org/wiki/Remote_keyless_system&lt;br /&gt;
* https://sectigo.com/resource-library/why-automotive-key-fob-encryption-hacks-are-making-headlines&lt;br /&gt;
* https://rolling.pandwarf.com/&lt;br /&gt;
* https://www.offensive-wireless.com/how-to-install-universal-radio-hacker/&lt;br /&gt;
* https://installati.one/ubuntu/20.04/hackrf/&lt;br /&gt;
* https://zadig.akeo.ie/&lt;br /&gt;
* https://www.kali.org/docs/usb/live-usb-install-with-linux/&lt;br /&gt;
* https://www.balena.io/etcher/&lt;br /&gt;
* https://www.kali.org/docs/introduction/download-official-kali-linux-images/&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[Category:Documentation]]&lt;/div&gt;</summary>
		<author><name>FPaschinger</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=Software-defined_radio_(SDR):_Relay_Attacks&amp;diff=10290</id>
		<title>Software-defined radio (SDR): Relay Attacks</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=Software-defined_radio_(SDR):_Relay_Attacks&amp;diff=10290"/>
		<updated>2022-07-12T18:45:44Z</updated>

		<summary type="html">&lt;p&gt;FPaschinger: /* Pentesting with HackRF one */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Summary == &lt;br /&gt;
&lt;br /&gt;
This documentation is about SDR (Software defined radio) and relay attacks. This document will give you a better understanding of these definitions and how some devices in IOT can/could be attacked with SDR relay attacks. This documentations will also provides detailed information about devices we used, the setup of these devices and other requirements. &lt;br /&gt;
&lt;br /&gt;
== Requirements ==&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039; Software &#039;&#039;&#039;&lt;br /&gt;
*Computer with native Kali-Linux installed.&lt;br /&gt;
*License for PandwaRF.&lt;br /&gt;
*PandwaRF App for Android. (Must be a device with latest Android version installed)&lt;br /&gt;
&lt;br /&gt;
== Description ==&lt;br /&gt;
&lt;br /&gt;
=== Pentesting with PandwaRF ===&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039; Step 1 &#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
#Install the application on your Android Phone.&lt;br /&gt;
#Open the Device.&lt;br /&gt;
#Install the antennas. (Never use a SDR Device without antennas.)&lt;br /&gt;
#Connect the PandwaRF via USB-C to your phone.&lt;br /&gt;
#Open the application.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039; Step 2 &#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
#The device should have connected with your application. If not, do it manually in the search tab.&lt;br /&gt;
#After the device has connected, you can use the spectrum analyser to analyse the frequency which the device captures. If you want to get your desired signal, you need to choose your frequency. &lt;br /&gt;
#At the Rx/Tx tab you can scan you signal which you try to capture. It is even possible to auto detect a signal which is sent.The pandwaRF will give you the captured signal in hex or in Binary which you can afterwards analyze. &lt;br /&gt;
#In order to transmit a captured signal, you need to buy a &amp;quot;Kaiju License&amp;quot;. Kaiju is an online tool where you can analyze rolling code and generate those. Kaiju is mainly used to attack systems which use rolling code.&lt;br /&gt;
&lt;br /&gt;
=== Pentesting with HackRF one ===&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039; Step 1 &#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
#Set up a laptop with native kali linux &lt;br /&gt;
#If you want dual boot on your local machine use these instructions&lt;br /&gt;
&lt;br /&gt;
* Dualboot on windows machine &lt;br /&gt;
&lt;br /&gt;
#You need a USB stick with a minimum of 8gb storage&lt;br /&gt;
#Download Kali image from official website https://www.kali.org/docs/development/live-build-a-custom-kali-iso/&lt;br /&gt;
#Download e.g. Etcher to flash the image on the USB stick to make it bootable https://www.balena.io/etcher/&lt;br /&gt;
#On the computer enter BIOS and change the BIOS-Mode to Legacy instead of Secure Boot (if secure boot is enabled). Secure boot prevents booting from external device! Then change the BIOS-Priority to “USB” first.&lt;br /&gt;
#For further information follow the instructions on the official website https://www.kali.org/docs/usb/live-usb-install-with-linux/&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039; Step 2 &#039;&#039;&#039;&lt;br /&gt;
** Driver Installation on HackRF One&lt;br /&gt;
#Download Zadig https://zadig.akeo.ie/&lt;br /&gt;
#Only compatible with Windows &lt;br /&gt;
&lt;br /&gt;
* Set-up HackRF on Linux&lt;br /&gt;
#	Sudo apt-get update&lt;br /&gt;
#	Sudo apt-get -y install hackrf&lt;br /&gt;
&lt;br /&gt;
Download Universal Radio Hacker on Linux machine&lt;br /&gt;
* First method &lt;br /&gt;
#	Sudo python3 -m pip install –upgrade pip&lt;br /&gt;
#	Sudo python3 -m pip install urh&lt;br /&gt;
* Second method &lt;br /&gt;
#	Sudo apt -y install urh&lt;br /&gt;
* Third method&lt;br /&gt;
#	git clone https://github.com/jopohl/urh&lt;br /&gt;
#   cd urh&lt;br /&gt;
#   python setup.py install&lt;br /&gt;
* Start Universal Radio Hacker with the command “urh”&lt;br /&gt;
#	Choose HackRF&lt;br /&gt;
#	Enter the frequency&lt;br /&gt;
&lt;br /&gt;
=== Nesdr Smart – receive only ===&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039; Step 1 &#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
Install the driver with zadig (detailed information in the HackRF One section)&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039; Step 2 &#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
Enter the RTL-SDR the “Device” option of the device settings and the frequency and you are ready to receive signals!&lt;br /&gt;
&lt;br /&gt;
== Used Hardware ==&lt;br /&gt;
&lt;br /&gt;
* HackRF One&lt;br /&gt;
* PandwaRF&lt;br /&gt;
* Nooelec SDR&lt;br /&gt;
&lt;br /&gt;
== Conclusion ==&lt;br /&gt;
We were able to receive signals with all three Software defined radios. However, HackRF One was the only device which allowed us to transmit signals too. It should be possible to transmit signal with PandwaRF as well, but we struggled with the Kaiju license, which is necessary for the transmission process. Therefore, we were able to achieve our project goals with the HackRF One.&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
* https://www.youtube.com/watch?v=5CsD8I396wo&amp;amp;t=327s&lt;br /&gt;
* https://www.essentracomponents.com/en-gb/news/product-resources/explaining-remote-keyless-entry-in-cars&lt;br /&gt;
* https://en.wikipedia.org/wiki/Rolling_code#:~:text=A%20rolling%20code%20(or%20sometimes,and%20keyless%20car%20entry%20systems&lt;br /&gt;
* https://www.youtube.com/watch?v=XrRGDQ2IzDE&lt;br /&gt;
* https://en.wikipedia.org/wiki/Remote_keyless_system&lt;br /&gt;
* https://sectigo.com/resource-library/why-automotive-key-fob-encryption-hacks-are-making-headlines&lt;br /&gt;
* https://rolling.pandwarf.com/&lt;br /&gt;
* https://www.offensive-wireless.com/how-to-install-universal-radio-hacker/&lt;br /&gt;
* https://installati.one/ubuntu/20.04/hackrf/&lt;br /&gt;
* https://zadig.akeo.ie/&lt;br /&gt;
* https://www.kali.org/docs/usb/live-usb-install-with-linux/&lt;br /&gt;
* https://www.balena.io/etcher/&lt;br /&gt;
* https://www.kali.org/docs/introduction/download-official-kali-linux-images/&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[Category:Documentation]]&lt;/div&gt;</summary>
		<author><name>FPaschinger</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=Software-defined_radio_(SDR):_Relay_Attacks&amp;diff=10289</id>
		<title>Software-defined radio (SDR): Relay Attacks</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=Software-defined_radio_(SDR):_Relay_Attacks&amp;diff=10289"/>
		<updated>2022-07-12T18:45:28Z</updated>

		<summary type="html">&lt;p&gt;FPaschinger: /* Pentesting with HackRF one */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Summary == &lt;br /&gt;
&lt;br /&gt;
This documentation is about SDR (Software defined radio) and relay attacks. This document will give you a better understanding of these definitions and how some devices in IOT can/could be attacked with SDR relay attacks. This documentations will also provides detailed information about devices we used, the setup of these devices and other requirements. &lt;br /&gt;
&lt;br /&gt;
== Requirements ==&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039; Software &#039;&#039;&#039;&lt;br /&gt;
*Computer with native Kali-Linux installed.&lt;br /&gt;
*License for PandwaRF.&lt;br /&gt;
*PandwaRF App for Android. (Must be a device with latest Android version installed)&lt;br /&gt;
&lt;br /&gt;
== Description ==&lt;br /&gt;
&lt;br /&gt;
=== Pentesting with PandwaRF ===&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039; Step 1 &#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
#Install the application on your Android Phone.&lt;br /&gt;
#Open the Device.&lt;br /&gt;
#Install the antennas. (Never use a SDR Device without antennas.)&lt;br /&gt;
#Connect the PandwaRF via USB-C to your phone.&lt;br /&gt;
#Open the application.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039; Step 2 &#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
#The device should have connected with your application. If not, do it manually in the search tab.&lt;br /&gt;
#After the device has connected, you can use the spectrum analyser to analyse the frequency which the device captures. If you want to get your desired signal, you need to choose your frequency. &lt;br /&gt;
#At the Rx/Tx tab you can scan you signal which you try to capture. It is even possible to auto detect a signal which is sent.The pandwaRF will give you the captured signal in hex or in Binary which you can afterwards analyze. &lt;br /&gt;
#In order to transmit a captured signal, you need to buy a &amp;quot;Kaiju License&amp;quot;. Kaiju is an online tool where you can analyze rolling code and generate those. Kaiju is mainly used to attack systems which use rolling code.&lt;br /&gt;
&lt;br /&gt;
=== Pentesting with HackRF one ===&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039; Step 1 &#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
#Set up a laptop with native kali linux &lt;br /&gt;
#If you want dual boot on your local machine use these instructions&lt;br /&gt;
&lt;br /&gt;
* Dualboot on windows machine &lt;br /&gt;
&lt;br /&gt;
#You need a USB stick with a minimum of 8gb storage&lt;br /&gt;
#Download Kali image from official website https://www.kali.org/docs/development/live-build-a-custom-kali-iso/&lt;br /&gt;
#Download e.g. Etcher to flash the image on the USB stick to make it bootable https://www.balena.io/etcher/&lt;br /&gt;
#On the computer enter BIOS and change the BIOS-Mode to Legacy instead of Secure Boot (if secure boot is enabled). Secure boot prevents booting from external device! Then change the BIOS-Priority to “USB” first.&lt;br /&gt;
#For further information follow the instructions on the official website https://www.kali.org/docs/usb/live-usb-install-with-linux/&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039; Step 2 &#039;&#039;&#039;&lt;br /&gt;
** Driver Installation on HackRF One&lt;br /&gt;
#Download Zadig &lt;br /&gt;
#Only compatible with Windows &lt;br /&gt;
&lt;br /&gt;
* Set-up HackRF on Linux&lt;br /&gt;
#	Sudo apt-get update&lt;br /&gt;
#	Sudo apt-get -y install hackrf&lt;br /&gt;
&lt;br /&gt;
Download Universal Radio Hacker on Linux machine&lt;br /&gt;
* First method &lt;br /&gt;
#	Sudo python3 -m pip install –upgrade pip&lt;br /&gt;
#	Sudo python3 -m pip install urh&lt;br /&gt;
* Second method &lt;br /&gt;
#	Sudo apt -y install urh&lt;br /&gt;
* Third method&lt;br /&gt;
#	git clone https://github.com/jopohl/urh&lt;br /&gt;
#   cd urh&lt;br /&gt;
#   python setup.py install&lt;br /&gt;
* Start Universal Radio Hacker with the command “urh”&lt;br /&gt;
#	Choose HackRF&lt;br /&gt;
#	Enter the frequency&lt;br /&gt;
&lt;br /&gt;
=== Nesdr Smart – receive only ===&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039; Step 1 &#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
Install the driver with zadig (detailed information in the HackRF One section)&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039; Step 2 &#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
Enter the RTL-SDR the “Device” option of the device settings and the frequency and you are ready to receive signals!&lt;br /&gt;
&lt;br /&gt;
== Used Hardware ==&lt;br /&gt;
&lt;br /&gt;
* HackRF One&lt;br /&gt;
* PandwaRF&lt;br /&gt;
* Nooelec SDR&lt;br /&gt;
&lt;br /&gt;
== Conclusion ==&lt;br /&gt;
We were able to receive signals with all three Software defined radios. However, HackRF One was the only device which allowed us to transmit signals too. It should be possible to transmit signal with PandwaRF as well, but we struggled with the Kaiju license, which is necessary for the transmission process. Therefore, we were able to achieve our project goals with the HackRF One.&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
* https://www.youtube.com/watch?v=5CsD8I396wo&amp;amp;t=327s&lt;br /&gt;
* https://www.essentracomponents.com/en-gb/news/product-resources/explaining-remote-keyless-entry-in-cars&lt;br /&gt;
* https://en.wikipedia.org/wiki/Rolling_code#:~:text=A%20rolling%20code%20(or%20sometimes,and%20keyless%20car%20entry%20systems&lt;br /&gt;
* https://www.youtube.com/watch?v=XrRGDQ2IzDE&lt;br /&gt;
* https://en.wikipedia.org/wiki/Remote_keyless_system&lt;br /&gt;
* https://sectigo.com/resource-library/why-automotive-key-fob-encryption-hacks-are-making-headlines&lt;br /&gt;
* https://rolling.pandwarf.com/&lt;br /&gt;
* https://www.offensive-wireless.com/how-to-install-universal-radio-hacker/&lt;br /&gt;
* https://installati.one/ubuntu/20.04/hackrf/&lt;br /&gt;
* https://zadig.akeo.ie/&lt;br /&gt;
* https://www.kali.org/docs/usb/live-usb-install-with-linux/&lt;br /&gt;
* https://www.balena.io/etcher/&lt;br /&gt;
* https://www.kali.org/docs/introduction/download-official-kali-linux-images/&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[Category:Documentation]]&lt;/div&gt;</summary>
		<author><name>FPaschinger</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=Software-defined_radio_(SDR):_Relay_Attacks&amp;diff=10288</id>
		<title>Software-defined radio (SDR): Relay Attacks</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=Software-defined_radio_(SDR):_Relay_Attacks&amp;diff=10288"/>
		<updated>2022-07-12T18:44:56Z</updated>

		<summary type="html">&lt;p&gt;FPaschinger: /* Pentesting with HackRF one */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Summary == &lt;br /&gt;
&lt;br /&gt;
This documentation is about SDR (Software defined radio) and relay attacks. This document will give you a better understanding of these definitions and how some devices in IOT can/could be attacked with SDR relay attacks. This documentations will also provides detailed information about devices we used, the setup of these devices and other requirements. &lt;br /&gt;
&lt;br /&gt;
== Requirements ==&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039; Software &#039;&#039;&#039;&lt;br /&gt;
*Computer with native Kali-Linux installed.&lt;br /&gt;
*License for PandwaRF.&lt;br /&gt;
*PandwaRF App for Android. (Must be a device with latest Android version installed)&lt;br /&gt;
&lt;br /&gt;
== Description ==&lt;br /&gt;
&lt;br /&gt;
=== Pentesting with PandwaRF ===&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039; Step 1 &#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
#Install the application on your Android Phone.&lt;br /&gt;
#Open the Device.&lt;br /&gt;
#Install the antennas. (Never use a SDR Device without antennas.)&lt;br /&gt;
#Connect the PandwaRF via USB-C to your phone.&lt;br /&gt;
#Open the application.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039; Step 2 &#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
#The device should have connected with your application. If not, do it manually in the search tab.&lt;br /&gt;
#After the device has connected, you can use the spectrum analyser to analyse the frequency which the device captures. If you want to get your desired signal, you need to choose your frequency. &lt;br /&gt;
#At the Rx/Tx tab you can scan you signal which you try to capture. It is even possible to auto detect a signal which is sent.The pandwaRF will give you the captured signal in hex or in Binary which you can afterwards analyze. &lt;br /&gt;
#In order to transmit a captured signal, you need to buy a &amp;quot;Kaiju License&amp;quot;. Kaiju is an online tool where you can analyze rolling code and generate those. Kaiju is mainly used to attack systems which use rolling code.&lt;br /&gt;
&lt;br /&gt;
=== Pentesting with HackRF one ===&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039; Step 1 &#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
#Set up a laptop with native kali linux &lt;br /&gt;
#If you want dual boot on your local machine use these instructions&lt;br /&gt;
&lt;br /&gt;
* Dualboot on windows machine &lt;br /&gt;
&lt;br /&gt;
#You need a USB stick with a minimum of 8gb storage&lt;br /&gt;
#Download Kali image from official website https://www.kali.org/docs/development/live-build-a-custom-kali-iso/&lt;br /&gt;
#Download e.g. Etcher to flash the image on the USB stick to make it bootable&lt;br /&gt;
#On the computer enter BIOS and change the BIOS-Mode to Legacy instead of Secure Boot (if secure boot is enabled). Secure boot prevents booting from external device! Then change the BIOS-Priority to “USB” first.&lt;br /&gt;
#For further information follow the instructions on the official website https://www.kali.org/docs/usb/live-usb-install-with-linux/&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039; Step 2 &#039;&#039;&#039;&lt;br /&gt;
** Driver Installation on HackRF One&lt;br /&gt;
#Download Zadig &lt;br /&gt;
#Only compatible with Windows &lt;br /&gt;
&lt;br /&gt;
* Set-up HackRF on Linux&lt;br /&gt;
#	Sudo apt-get update&lt;br /&gt;
#	Sudo apt-get -y install hackrf&lt;br /&gt;
&lt;br /&gt;
Download Universal Radio Hacker on Linux machine&lt;br /&gt;
* First method &lt;br /&gt;
#	Sudo python3 -m pip install –upgrade pip&lt;br /&gt;
#	Sudo python3 -m pip install urh&lt;br /&gt;
* Second method &lt;br /&gt;
#	Sudo apt -y install urh&lt;br /&gt;
* Third method&lt;br /&gt;
#	git clone https://github.com/jopohl/urh&lt;br /&gt;
#   cd urh&lt;br /&gt;
#   python setup.py install&lt;br /&gt;
* Start Universal Radio Hacker with the command “urh”&lt;br /&gt;
#	Choose HackRF&lt;br /&gt;
#	Enter the frequency&lt;br /&gt;
&lt;br /&gt;
=== Nesdr Smart – receive only ===&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039; Step 1 &#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
Install the driver with zadig (detailed information in the HackRF One section)&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039; Step 2 &#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
Enter the RTL-SDR the “Device” option of the device settings and the frequency and you are ready to receive signals!&lt;br /&gt;
&lt;br /&gt;
== Used Hardware ==&lt;br /&gt;
&lt;br /&gt;
* HackRF One&lt;br /&gt;
* PandwaRF&lt;br /&gt;
* Nooelec SDR&lt;br /&gt;
&lt;br /&gt;
== Conclusion ==&lt;br /&gt;
We were able to receive signals with all three Software defined radios. However, HackRF One was the only device which allowed us to transmit signals too. It should be possible to transmit signal with PandwaRF as well, but we struggled with the Kaiju license, which is necessary for the transmission process. Therefore, we were able to achieve our project goals with the HackRF One.&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
* https://www.youtube.com/watch?v=5CsD8I396wo&amp;amp;t=327s&lt;br /&gt;
* https://www.essentracomponents.com/en-gb/news/product-resources/explaining-remote-keyless-entry-in-cars&lt;br /&gt;
* https://en.wikipedia.org/wiki/Rolling_code#:~:text=A%20rolling%20code%20(or%20sometimes,and%20keyless%20car%20entry%20systems&lt;br /&gt;
* https://www.youtube.com/watch?v=XrRGDQ2IzDE&lt;br /&gt;
* https://en.wikipedia.org/wiki/Remote_keyless_system&lt;br /&gt;
* https://sectigo.com/resource-library/why-automotive-key-fob-encryption-hacks-are-making-headlines&lt;br /&gt;
* https://rolling.pandwarf.com/&lt;br /&gt;
* https://www.offensive-wireless.com/how-to-install-universal-radio-hacker/&lt;br /&gt;
* https://installati.one/ubuntu/20.04/hackrf/&lt;br /&gt;
* https://zadig.akeo.ie/&lt;br /&gt;
* https://www.kali.org/docs/usb/live-usb-install-with-linux/&lt;br /&gt;
* https://www.balena.io/etcher/&lt;br /&gt;
* https://www.kali.org/docs/introduction/download-official-kali-linux-images/&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[Category:Documentation]]&lt;/div&gt;</summary>
		<author><name>FPaschinger</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=Software-defined_radio_(SDR):_Relay_Attacks&amp;diff=10286</id>
		<title>Software-defined radio (SDR): Relay Attacks</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=Software-defined_radio_(SDR):_Relay_Attacks&amp;diff=10286"/>
		<updated>2022-07-12T18:43:04Z</updated>

		<summary type="html">&lt;p&gt;FPaschinger: /* Pentesting with HackRF one */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Summary == &lt;br /&gt;
&lt;br /&gt;
This documentation is about SDR (Software defined radio) and relay attacks. This document will give you a better understanding of these definitions and how some devices in IOT can/could be attacked with SDR relay attacks. This documentations will also provides detailed information about devices we used, the setup of these devices and other requirements. &lt;br /&gt;
&lt;br /&gt;
== Requirements ==&lt;br /&gt;
&lt;br /&gt;
We used 3 different devices for the penetration-testing of a car and a gate. &lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039; Hardware &#039;&#039;&#039;&lt;br /&gt;
*HackRF-One&lt;br /&gt;
*PandwaRF&lt;br /&gt;
*Nooelec SDR (No transmission possible)&lt;br /&gt;
*Car&lt;br /&gt;
*Garage gate&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039; Software &#039;&#039;&#039;&lt;br /&gt;
*Computer with native Kali-Linux installed.&lt;br /&gt;
*License for PandwaRF.&lt;br /&gt;
*Universal Radio Hacker.&lt;br /&gt;
*PandwaRF App for Android. (Must be a device with latest Android version installed)&lt;br /&gt;
&lt;br /&gt;
== Description ==&lt;br /&gt;
&lt;br /&gt;
=== Pentesting with PandwaRF ===&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039; Step 1 &#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
#Install the application on your Android Phone.&lt;br /&gt;
#Open the Device.&lt;br /&gt;
#Install the antennas. (Never use a SDR Device without antennas.)&lt;br /&gt;
#Connect the PandwaRF via USB-C to your phone.&lt;br /&gt;
#Open the application.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039; Step 2 &#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
#The device should have connected with your application. If not, do it manually in the search tab.&lt;br /&gt;
#After the device has connected, you can use the spectrum analyser to analyse the frequency which the device captures. If you want to get your desired signal, you need to choose your frequency. &lt;br /&gt;
#At the Rx/Tx tab you can scan you signal which you try to capture. It is even possible to auto detect a signal which is sent.The pandwaRF will give you the captured signal in hex or in Binary which you can afterwards analyze. &lt;br /&gt;
#In order to transmit a captured signal, you need to buy a &amp;quot;Kaiju License&amp;quot;. Kaiju is an online tool where you can analyze rolling code and generate those. Kaiju is mainly used to attack systems which use rolling code.&lt;br /&gt;
&lt;br /&gt;
=== Pentesting with HackRF one ===&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039; Step 1 &#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
#Set up a laptop with native kali linux &lt;br /&gt;
#If you want dual boot on your local machine use these instructions&lt;br /&gt;
&lt;br /&gt;
* Dualboot on windows machine &lt;br /&gt;
&lt;br /&gt;
#You need a USB stick with a minimum of 8gb storage&lt;br /&gt;
#Download Kali image from official website&lt;br /&gt;
#Download e.g. Etcher to flash the image on the USB stick to make it bootable&lt;br /&gt;
#On the computer enter BIOS and change the BIOS-Mode to Legacy instead of Secure Boot (if secure boot is enabled). Secure boot prevents booting from external device! Then change the BIOS-Priority to “USB” first.&lt;br /&gt;
#For further information follow the instructions on the official website &lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039; Step 2 &#039;&#039;&#039;&lt;br /&gt;
** Driver Installation on HackRF One&lt;br /&gt;
#Download Zadig &lt;br /&gt;
#Only compatible with Windows &lt;br /&gt;
&lt;br /&gt;
* Set-up HackRF on Linux&lt;br /&gt;
#	Sudo apt-get update&lt;br /&gt;
#	Sudo apt-get -y install hackrf&lt;br /&gt;
&lt;br /&gt;
Download Universal Radio Hacker on Linux machine&lt;br /&gt;
* First method &lt;br /&gt;
#	Sudo python3 -m pip install –upgrade pip&lt;br /&gt;
#	Sudo python3 -m pip install urh&lt;br /&gt;
* Second method &lt;br /&gt;
#	Sudo apt -y install urh&lt;br /&gt;
* Third method&lt;br /&gt;
#	git clone https://github.com/jopohl/urh&lt;br /&gt;
#   cd urh&lt;br /&gt;
#   python setup.py install&lt;br /&gt;
* Start Universal Radio Hacker with the command “urh”&lt;br /&gt;
#	Choose HackRF&lt;br /&gt;
#	Enter the frequency&lt;br /&gt;
&lt;br /&gt;
=== Nesdr Smart – receive only ===&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039; Step 1 &#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
Install the driver with zadig (detailed information in the HackRF One section)&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039; Step 2 &#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
Enter the RTL-SDR the “Device” option of the device settings and the frequency and you are ready to receive signals!&lt;br /&gt;
&lt;br /&gt;
== Used Hardware ==&lt;br /&gt;
&lt;br /&gt;
* HackRF One&lt;br /&gt;
* PandwaRF&lt;br /&gt;
* Nooelec SDR&lt;br /&gt;
&lt;br /&gt;
== Conclusion ==&lt;br /&gt;
We were able to receive signals with all three Software defined radios. However, HackRF One was the only device which allowed us to transmit signals too. It should be possible to transmit signal with PandwaRF as well, but we struggled with the Kaiju license, which is necessary for the transmission process. Therefore, we were able to achieve our project goals with the HackRF One.&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
* https://www.youtube.com/watch?v=5CsD8I396wo&amp;amp;t=327s&lt;br /&gt;
* https://www.essentracomponents.com/en-gb/news/product-resources/explaining-remote-keyless-entry-in-cars&lt;br /&gt;
* https://en.wikipedia.org/wiki/Rolling_code#:~:text=A%20rolling%20code%20(or%20sometimes,and%20keyless%20car%20entry%20systems&lt;br /&gt;
* https://www.youtube.com/watch?v=XrRGDQ2IzDE&lt;br /&gt;
* https://en.wikipedia.org/wiki/Remote_keyless_system&lt;br /&gt;
* https://sectigo.com/resource-library/why-automotive-key-fob-encryption-hacks-are-making-headlines&lt;br /&gt;
* https://rolling.pandwarf.com/&lt;br /&gt;
* https://www.offensive-wireless.com/how-to-install-universal-radio-hacker/&lt;br /&gt;
* https://installati.one/ubuntu/20.04/hackrf/&lt;br /&gt;
* https://zadig.akeo.ie/&lt;br /&gt;
* https://www.kali.org/docs/usb/live-usb-install-with-linux/&lt;br /&gt;
* https://www.balena.io/etcher/&lt;br /&gt;
* https://www.kali.org/docs/introduction/download-official-kali-linux-images/&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[Category:Documentation]]&lt;/div&gt;</summary>
		<author><name>FPaschinger</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=Software-defined_radio_(SDR):_Relay_Attacks&amp;diff=10285</id>
		<title>Software-defined radio (SDR): Relay Attacks</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=Software-defined_radio_(SDR):_Relay_Attacks&amp;diff=10285"/>
		<updated>2022-07-12T18:42:47Z</updated>

		<summary type="html">&lt;p&gt;FPaschinger: /* Pentesting with HackRF one */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Summary == &lt;br /&gt;
&lt;br /&gt;
This documentation is about SDR (Software defined radio) and relay attacks. This document will give you a better understanding of these definitions and how some devices in IOT can/could be attacked with SDR relay attacks. This documentations will also provides detailed information about devices we used, the setup of these devices and other requirements. &lt;br /&gt;
&lt;br /&gt;
== Requirements ==&lt;br /&gt;
&lt;br /&gt;
We used 3 different devices for the penetration-testing of a car and a gate. &lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039; Hardware &#039;&#039;&#039;&lt;br /&gt;
*HackRF-One&lt;br /&gt;
*PandwaRF&lt;br /&gt;
*Nooelec SDR (No transmission possible)&lt;br /&gt;
*Car&lt;br /&gt;
*Garage gate&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039; Software &#039;&#039;&#039;&lt;br /&gt;
*Computer with native Kali-Linux installed.&lt;br /&gt;
*License for PandwaRF.&lt;br /&gt;
*Universal Radio Hacker.&lt;br /&gt;
*PandwaRF App for Android. (Must be a device with latest Android version installed)&lt;br /&gt;
&lt;br /&gt;
== Description ==&lt;br /&gt;
&lt;br /&gt;
=== Pentesting with PandwaRF ===&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039; Step 1 &#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
#Install the application on your Android Phone.&lt;br /&gt;
#Open the Device.&lt;br /&gt;
#Install the antennas. (Never use a SDR Device without antennas.)&lt;br /&gt;
#Connect the PandwaRF via USB-C to your phone.&lt;br /&gt;
#Open the application.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039; Step 2 &#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
#The device should have connected with your application. If not, do it manually in the search tab.&lt;br /&gt;
#After the device has connected, you can use the spectrum analyser to analyse the frequency which the device captures. If you want to get your desired signal, you need to choose your frequency. &lt;br /&gt;
#At the Rx/Tx tab you can scan you signal which you try to capture. It is even possible to auto detect a signal which is sent.The pandwaRF will give you the captured signal in hex or in Binary which you can afterwards analyze. &lt;br /&gt;
#In order to transmit a captured signal, you need to buy a &amp;quot;Kaiju License&amp;quot;. Kaiju is an online tool where you can analyze rolling code and generate those. Kaiju is mainly used to attack systems which use rolling code.&lt;br /&gt;
&lt;br /&gt;
=== Pentesting with HackRF one ===&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039; Step 1 &#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
#Set up a laptop with native kali linux &lt;br /&gt;
#If you want dual boot on your local machine use these instructions&lt;br /&gt;
&lt;br /&gt;
* Dualboot on windows machine &lt;br /&gt;
&lt;br /&gt;
#You need a USB stick with a minimum of 8gb storage&lt;br /&gt;
#Download Kali image from official website&lt;br /&gt;
#Download e.g. Etcher to flash the image on the USB stick to make it bootable&lt;br /&gt;
#On the computer enter BIOS and change the BIOS-Mode to Legacy instead of Secure Boot (if secure boot is enabled). Secure boot prevents booting from external device! Then change the BIOS-Priority to “USB” first.&lt;br /&gt;
#For further information follow the instructions on the official website &lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039; Step 2 &#039;&#039;&#039;&lt;br /&gt;
** Driver Installation on HackRF One&lt;br /&gt;
#Download Zadig &lt;br /&gt;
#Only compatible with Windows &lt;br /&gt;
&lt;br /&gt;
* Set-up HackRF on Linux&lt;br /&gt;
#	Sudo apt-get update&lt;br /&gt;
#	Sudo apt-get -y install hackrf&lt;br /&gt;
&lt;br /&gt;
Download Universal Radio Hacker on Linux machine&lt;br /&gt;
* First method &lt;br /&gt;
#	Sudo python3 -m pip install –upgrade pip&lt;br /&gt;
#	Sudo python3 -m pip install urh&lt;br /&gt;
* Second method &lt;br /&gt;
#	Sudo apt -y install urh&lt;br /&gt;
 &lt;br /&gt;
* Third method&lt;br /&gt;
#	git clone https://github.com/jopohl/urh&lt;br /&gt;
#   cd urh&lt;br /&gt;
#   python setup.py install&lt;br /&gt;
* Start Universal Radio Hacker with the command “urh”&lt;br /&gt;
#	Choose HackRF&lt;br /&gt;
#	Enter the frequency&lt;br /&gt;
&lt;br /&gt;
=== Nesdr Smart – receive only ===&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039; Step 1 &#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
Install the driver with zadig (detailed information in the HackRF One section)&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039; Step 2 &#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
Enter the RTL-SDR the “Device” option of the device settings and the frequency and you are ready to receive signals!&lt;br /&gt;
&lt;br /&gt;
== Used Hardware ==&lt;br /&gt;
&lt;br /&gt;
* HackRF One&lt;br /&gt;
* PandwaRF&lt;br /&gt;
* Nooelec SDR&lt;br /&gt;
&lt;br /&gt;
== Conclusion ==&lt;br /&gt;
We were able to receive signals with all three Software defined radios. However, HackRF One was the only device which allowed us to transmit signals too. It should be possible to transmit signal with PandwaRF as well, but we struggled with the Kaiju license, which is necessary for the transmission process. Therefore, we were able to achieve our project goals with the HackRF One.&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
* https://www.youtube.com/watch?v=5CsD8I396wo&amp;amp;t=327s&lt;br /&gt;
* https://www.essentracomponents.com/en-gb/news/product-resources/explaining-remote-keyless-entry-in-cars&lt;br /&gt;
* https://en.wikipedia.org/wiki/Rolling_code#:~:text=A%20rolling%20code%20(or%20sometimes,and%20keyless%20car%20entry%20systems&lt;br /&gt;
* https://www.youtube.com/watch?v=XrRGDQ2IzDE&lt;br /&gt;
* https://en.wikipedia.org/wiki/Remote_keyless_system&lt;br /&gt;
* https://sectigo.com/resource-library/why-automotive-key-fob-encryption-hacks-are-making-headlines&lt;br /&gt;
* https://rolling.pandwarf.com/&lt;br /&gt;
* https://www.offensive-wireless.com/how-to-install-universal-radio-hacker/&lt;br /&gt;
* https://installati.one/ubuntu/20.04/hackrf/&lt;br /&gt;
* https://zadig.akeo.ie/&lt;br /&gt;
* https://www.kali.org/docs/usb/live-usb-install-with-linux/&lt;br /&gt;
* https://www.balena.io/etcher/&lt;br /&gt;
* https://www.kali.org/docs/introduction/download-official-kali-linux-images/&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[Category:Documentation]]&lt;/div&gt;</summary>
		<author><name>FPaschinger</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=Software-defined_radio_(SDR):_Relay_Attacks&amp;diff=10284</id>
		<title>Software-defined radio (SDR): Relay Attacks</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=Software-defined_radio_(SDR):_Relay_Attacks&amp;diff=10284"/>
		<updated>2022-07-12T18:42:16Z</updated>

		<summary type="html">&lt;p&gt;FPaschinger: /* Pentesting with HackRF one */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Summary == &lt;br /&gt;
&lt;br /&gt;
This documentation is about SDR (Software defined radio) and relay attacks. This document will give you a better understanding of these definitions and how some devices in IOT can/could be attacked with SDR relay attacks. This documentations will also provides detailed information about devices we used, the setup of these devices and other requirements. &lt;br /&gt;
&lt;br /&gt;
== Requirements ==&lt;br /&gt;
&lt;br /&gt;
We used 3 different devices for the penetration-testing of a car and a gate. &lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039; Hardware &#039;&#039;&#039;&lt;br /&gt;
*HackRF-One&lt;br /&gt;
*PandwaRF&lt;br /&gt;
*Nooelec SDR (No transmission possible)&lt;br /&gt;
*Car&lt;br /&gt;
*Garage gate&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039; Software &#039;&#039;&#039;&lt;br /&gt;
*Computer with native Kali-Linux installed.&lt;br /&gt;
*License for PandwaRF.&lt;br /&gt;
*Universal Radio Hacker.&lt;br /&gt;
*PandwaRF App for Android. (Must be a device with latest Android version installed)&lt;br /&gt;
&lt;br /&gt;
== Description ==&lt;br /&gt;
&lt;br /&gt;
=== Pentesting with PandwaRF ===&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039; Step 1 &#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
#Install the application on your Android Phone.&lt;br /&gt;
#Open the Device.&lt;br /&gt;
#Install the antennas. (Never use a SDR Device without antennas.)&lt;br /&gt;
#Connect the PandwaRF via USB-C to your phone.&lt;br /&gt;
#Open the application.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039; Step 2 &#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
#The device should have connected with your application. If not, do it manually in the search tab.&lt;br /&gt;
#After the device has connected, you can use the spectrum analyser to analyse the frequency which the device captures. If you want to get your desired signal, you need to choose your frequency. &lt;br /&gt;
#At the Rx/Tx tab you can scan you signal which you try to capture. It is even possible to auto detect a signal which is sent.The pandwaRF will give you the captured signal in hex or in Binary which you can afterwards analyze. &lt;br /&gt;
#In order to transmit a captured signal, you need to buy a &amp;quot;Kaiju License&amp;quot;. Kaiju is an online tool where you can analyze rolling code and generate those. Kaiju is mainly used to attack systems which use rolling code.&lt;br /&gt;
&lt;br /&gt;
=== Pentesting with HackRF one ===&lt;br /&gt;
&lt;br /&gt;
* Step 1&lt;br /&gt;
&lt;br /&gt;
#Set up a laptop with native kali linux &lt;br /&gt;
#If you want dual boot on your local machine use these instructions&lt;br /&gt;
&lt;br /&gt;
* Dualboot on windows machine &lt;br /&gt;
&lt;br /&gt;
#You need a USB stick with a minimum of 8gb storage&lt;br /&gt;
#Download Kali image from official website&lt;br /&gt;
#Download e.g. Etcher to flash the image on the USB stick to make it bootable&lt;br /&gt;
#On the computer enter BIOS and change the BIOS-Mode to Legacy instead of Secure Boot (if secure boot is enabled). Secure boot prevents booting from external device! Then change the BIOS-Priority to “USB” first.&lt;br /&gt;
#For further information follow the instructions on the official website &lt;br /&gt;
&lt;br /&gt;
* Step 2&lt;br /&gt;
** Driver Installation on HackRF One&lt;br /&gt;
#Download Zadig &lt;br /&gt;
#Only compatible with Windows &lt;br /&gt;
&lt;br /&gt;
* Set-up HackRF on Linux&lt;br /&gt;
#	Sudo apt-get update&lt;br /&gt;
#	Sudo apt-get -y install hackrf&lt;br /&gt;
&lt;br /&gt;
Download Universal Radio Hacker on Linux machine&lt;br /&gt;
* First method &lt;br /&gt;
#	Sudo python3 -m pip install –upgrade pip&lt;br /&gt;
#	Sudo python3 -m pip install urh&lt;br /&gt;
* Second method &lt;br /&gt;
#	Sudo apt -y install urh&lt;br /&gt;
 &lt;br /&gt;
* Third method&lt;br /&gt;
#	git clone https://github.com/jopohl/urh&lt;br /&gt;
#   cd urh&lt;br /&gt;
#   python setup.py install&lt;br /&gt;
* Start Universal Radio Hacker with the command “urh”&lt;br /&gt;
#	Choose HackRF&lt;br /&gt;
#	Enter the frequency&lt;br /&gt;
&lt;br /&gt;
=== Nesdr Smart – receive only ===&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039; Step 1 &#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
Install the driver with zadig (detailed information in the HackRF One section)&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039; Step 2 &#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
Enter the RTL-SDR the “Device” option of the device settings and the frequency and you are ready to receive signals!&lt;br /&gt;
&lt;br /&gt;
== Used Hardware ==&lt;br /&gt;
&lt;br /&gt;
* HackRF One&lt;br /&gt;
* PandwaRF&lt;br /&gt;
* Nooelec SDR&lt;br /&gt;
&lt;br /&gt;
== Conclusion ==&lt;br /&gt;
We were able to receive signals with all three Software defined radios. However, HackRF One was the only device which allowed us to transmit signals too. It should be possible to transmit signal with PandwaRF as well, but we struggled with the Kaiju license, which is necessary for the transmission process. Therefore, we were able to achieve our project goals with the HackRF One.&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
* https://www.youtube.com/watch?v=5CsD8I396wo&amp;amp;t=327s&lt;br /&gt;
* https://www.essentracomponents.com/en-gb/news/product-resources/explaining-remote-keyless-entry-in-cars&lt;br /&gt;
* https://en.wikipedia.org/wiki/Rolling_code#:~:text=A%20rolling%20code%20(or%20sometimes,and%20keyless%20car%20entry%20systems&lt;br /&gt;
* https://www.youtube.com/watch?v=XrRGDQ2IzDE&lt;br /&gt;
* https://en.wikipedia.org/wiki/Remote_keyless_system&lt;br /&gt;
* https://sectigo.com/resource-library/why-automotive-key-fob-encryption-hacks-are-making-headlines&lt;br /&gt;
* https://rolling.pandwarf.com/&lt;br /&gt;
* https://www.offensive-wireless.com/how-to-install-universal-radio-hacker/&lt;br /&gt;
* https://installati.one/ubuntu/20.04/hackrf/&lt;br /&gt;
* https://zadig.akeo.ie/&lt;br /&gt;
* https://www.kali.org/docs/usb/live-usb-install-with-linux/&lt;br /&gt;
* https://www.balena.io/etcher/&lt;br /&gt;
* https://www.kali.org/docs/introduction/download-official-kali-linux-images/&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[Category:Documentation]]&lt;/div&gt;</summary>
		<author><name>FPaschinger</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=Software-defined_radio_(SDR):_Relay_Attacks&amp;diff=10283</id>
		<title>Software-defined radio (SDR): Relay Attacks</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=Software-defined_radio_(SDR):_Relay_Attacks&amp;diff=10283"/>
		<updated>2022-07-12T18:42:06Z</updated>

		<summary type="html">&lt;p&gt;FPaschinger: /* Pentesting with PandwaRF */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Summary == &lt;br /&gt;
&lt;br /&gt;
This documentation is about SDR (Software defined radio) and relay attacks. This document will give you a better understanding of these definitions and how some devices in IOT can/could be attacked with SDR relay attacks. This documentations will also provides detailed information about devices we used, the setup of these devices and other requirements. &lt;br /&gt;
&lt;br /&gt;
== Requirements ==&lt;br /&gt;
&lt;br /&gt;
We used 3 different devices for the penetration-testing of a car and a gate. &lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039; Hardware &#039;&#039;&#039;&lt;br /&gt;
*HackRF-One&lt;br /&gt;
*PandwaRF&lt;br /&gt;
*Nooelec SDR (No transmission possible)&lt;br /&gt;
*Car&lt;br /&gt;
*Garage gate&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039; Software &#039;&#039;&#039;&lt;br /&gt;
*Computer with native Kali-Linux installed.&lt;br /&gt;
*License for PandwaRF.&lt;br /&gt;
*Universal Radio Hacker.&lt;br /&gt;
*PandwaRF App for Android. (Must be a device with latest Android version installed)&lt;br /&gt;
&lt;br /&gt;
== Description ==&lt;br /&gt;
&lt;br /&gt;
=== Pentesting with PandwaRF ===&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039; Step 1 &#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
#Install the application on your Android Phone.&lt;br /&gt;
#Open the Device.&lt;br /&gt;
#Install the antennas. (Never use a SDR Device without antennas.)&lt;br /&gt;
#Connect the PandwaRF via USB-C to your phone.&lt;br /&gt;
#Open the application.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039; Step 2 &#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
#The device should have connected with your application. If not, do it manually in the search tab.&lt;br /&gt;
#After the device has connected, you can use the spectrum analyser to analyse the frequency which the device captures. If you want to get your desired signal, you need to choose your frequency. &lt;br /&gt;
#At the Rx/Tx tab you can scan you signal which you try to capture. It is even possible to auto detect a signal which is sent.The pandwaRF will give you the captured signal in hex or in Binary which you can afterwards analyze. &lt;br /&gt;
#In order to transmit a captured signal, you need to buy a &amp;quot;Kaiju License&amp;quot;. Kaiju is an online tool where you can analyze rolling code and generate those. Kaiju is mainly used to attack systems which use rolling code.&lt;br /&gt;
&lt;br /&gt;
=== Pentesting with HackRF one ===&lt;br /&gt;
&lt;br /&gt;
* Step 1&lt;br /&gt;
&lt;br /&gt;
#Set up a laptop with native kali linux &lt;br /&gt;
#If you want dual boot on your local machine use these instructions&lt;br /&gt;
&lt;br /&gt;
** Dualboot on windows machine &lt;br /&gt;
&lt;br /&gt;
#You need a USB stick with a minimum of 8gb storage&lt;br /&gt;
#Download Kali image from official website&lt;br /&gt;
#Download e.g. Etcher to flash the image on the USB stick to make it bootable&lt;br /&gt;
#On the computer enter BIOS and change the BIOS-Mode to Legacy instead of Secure Boot (if secure boot is enabled). Secure boot prevents booting from external device! Then change the BIOS-Priority to “USB” first.&lt;br /&gt;
#For further information follow the instructions on the official website &lt;br /&gt;
&lt;br /&gt;
* Step 2&lt;br /&gt;
** Driver Installation on HackRF One&lt;br /&gt;
#Download Zadig &lt;br /&gt;
#Only compatible with Windows &lt;br /&gt;
&lt;br /&gt;
* Set-up HackRF on Linux&lt;br /&gt;
#	Sudo apt-get update&lt;br /&gt;
#	Sudo apt-get -y install hackrf&lt;br /&gt;
&lt;br /&gt;
Download Universal Radio Hacker on Linux machine&lt;br /&gt;
* First method &lt;br /&gt;
#	Sudo python3 -m pip install –upgrade pip&lt;br /&gt;
#	Sudo python3 -m pip install urh&lt;br /&gt;
* Second method &lt;br /&gt;
#	Sudo apt -y install urh&lt;br /&gt;
 &lt;br /&gt;
* Third method&lt;br /&gt;
#	git clone https://github.com/jopohl/urh&lt;br /&gt;
#   cd urh&lt;br /&gt;
#   python setup.py install&lt;br /&gt;
* Start Universal Radio Hacker with the command “urh”&lt;br /&gt;
#	Choose HackRF&lt;br /&gt;
#	Enter the frequency&lt;br /&gt;
&lt;br /&gt;
=== Nesdr Smart – receive only ===&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039; Step 1 &#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
Install the driver with zadig (detailed information in the HackRF One section)&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039; Step 2 &#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
Enter the RTL-SDR the “Device” option of the device settings and the frequency and you are ready to receive signals!&lt;br /&gt;
&lt;br /&gt;
== Used Hardware ==&lt;br /&gt;
&lt;br /&gt;
* HackRF One&lt;br /&gt;
* PandwaRF&lt;br /&gt;
* Nooelec SDR&lt;br /&gt;
&lt;br /&gt;
== Conclusion ==&lt;br /&gt;
We were able to receive signals with all three Software defined radios. However, HackRF One was the only device which allowed us to transmit signals too. It should be possible to transmit signal with PandwaRF as well, but we struggled with the Kaiju license, which is necessary for the transmission process. Therefore, we were able to achieve our project goals with the HackRF One.&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
* https://www.youtube.com/watch?v=5CsD8I396wo&amp;amp;t=327s&lt;br /&gt;
* https://www.essentracomponents.com/en-gb/news/product-resources/explaining-remote-keyless-entry-in-cars&lt;br /&gt;
* https://en.wikipedia.org/wiki/Rolling_code#:~:text=A%20rolling%20code%20(or%20sometimes,and%20keyless%20car%20entry%20systems&lt;br /&gt;
* https://www.youtube.com/watch?v=XrRGDQ2IzDE&lt;br /&gt;
* https://en.wikipedia.org/wiki/Remote_keyless_system&lt;br /&gt;
* https://sectigo.com/resource-library/why-automotive-key-fob-encryption-hacks-are-making-headlines&lt;br /&gt;
* https://rolling.pandwarf.com/&lt;br /&gt;
* https://www.offensive-wireless.com/how-to-install-universal-radio-hacker/&lt;br /&gt;
* https://installati.one/ubuntu/20.04/hackrf/&lt;br /&gt;
* https://zadig.akeo.ie/&lt;br /&gt;
* https://www.kali.org/docs/usb/live-usb-install-with-linux/&lt;br /&gt;
* https://www.balena.io/etcher/&lt;br /&gt;
* https://www.kali.org/docs/introduction/download-official-kali-linux-images/&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[Category:Documentation]]&lt;/div&gt;</summary>
		<author><name>FPaschinger</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=Software-defined_radio_(SDR):_Relay_Attacks&amp;diff=10268</id>
		<title>Software-defined radio (SDR): Relay Attacks</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=Software-defined_radio_(SDR):_Relay_Attacks&amp;diff=10268"/>
		<updated>2022-07-12T18:35:57Z</updated>

		<summary type="html">&lt;p&gt;FPaschinger: /* Pentesting with HackRF one */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Summary == &lt;br /&gt;
&lt;br /&gt;
This documentation is about SDR (Software defined radio) and relay attacks. This document will give you a better understanding of these definitions and how some devices in IOT can/could be attacked with SDR relay attacks. This documentations will also provides detailed information about devices we used, the setup of these devices and other requirements. &lt;br /&gt;
&lt;br /&gt;
== Requirements ==&lt;br /&gt;
&lt;br /&gt;
We used 3 different devices for the penetration-testing of a car and a gate. &lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039; Hardware &#039;&#039;&#039;&lt;br /&gt;
*HackRF-One&lt;br /&gt;
*PandwaRF&lt;br /&gt;
*Nooelec SDR (No transmission possible)&lt;br /&gt;
*Car&lt;br /&gt;
*Garage gate&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039; Software &#039;&#039;&#039;&lt;br /&gt;
*Computer with native Kali-Linux installed.&lt;br /&gt;
*License for PandwaRF.&lt;br /&gt;
*Universal Radio Hacker.&lt;br /&gt;
*PandwaRF App for Android. (Must be a device with latest Android version installed)&lt;br /&gt;
&lt;br /&gt;
In order to complete these steps, you must have followed [[Some Other Documentation]] before.&lt;br /&gt;
&lt;br /&gt;
== Description ==&lt;br /&gt;
&lt;br /&gt;
=== Pentesting with PandwaRF ===&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039; Step 1 &#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
1)Install the application on your Android Phone.&lt;br /&gt;
2)Open the Device.&lt;br /&gt;
3)Install the antennas. (Never use a SDR Device without antennas.)&lt;br /&gt;
4)Connect the PandwaRF via USB-C to your phone.&lt;br /&gt;
5)Open the application.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039; Step 2 &#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
1)The device should have connected with your application. If not, do it manually in the search tab.&lt;br /&gt;
2)After the device has connected, you can use the spectrum analyser to analyse the frequency which the device captures. If you want to get your desired signal, you need to choose your frequency. &lt;br /&gt;
3)At the Rx/Tx tab you can scan you signal which you try to capture. It is even possible to auto detect a signal which is sent.The pandwaRF will give you the captured signal in hex or in Binary which you can afterwards analyze. &lt;br /&gt;
4)In order to transmit a captured signal, you need to buy a &amp;quot;Kaiju License. Kaiju is an online tool where you can analyze rolling code and generate those. Kaiju is mainly used to attack systems which use rolling code.&lt;br /&gt;
&lt;br /&gt;
=== Pentesting with HackRF one ===&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039; Step 1 &#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
#    Set up a laptop with native kali linux &lt;br /&gt;
&lt;br /&gt;
#    If you want dual boot on your local machine use these instructions&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039; Dualboot on windows machine &#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
#	You need a USB stick with a minimum of 8gb storage&lt;br /&gt;
&lt;br /&gt;
#   Download Kali image from official website&lt;br /&gt;
&lt;br /&gt;
#   Download e.g. Etcher to flash the image on the USB stick to make it bootable&lt;br /&gt;
&lt;br /&gt;
#	On the computer enter BIOS and change the BIOS-Mode to Legacy instead of Secure Boot (if secure boot is enabled). Secure boot prevents booting from external device! Then change the BIOS-Priority to “USB” first.&lt;br /&gt;
&lt;br /&gt;
#	For further information follow the instructions on the official website &lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039; Step 2 &#039;&#039;&#039;&lt;br /&gt;
* Driver Installation on HackRF One&lt;br /&gt;
#	Download Zadig &lt;br /&gt;
#	Only compatible with Windows &lt;br /&gt;
&lt;br /&gt;
* Set-up HackRF on Linux&lt;br /&gt;
#	Sudo apt-get update&lt;br /&gt;
#	Sudo apt-get -y install hackrf&lt;br /&gt;
&lt;br /&gt;
Download Universal Radio Hacker on Linux machine&lt;br /&gt;
* First method &lt;br /&gt;
#	Sudo python3 -m pip install –upgrade pip&lt;br /&gt;
#	Sudo python3 -m pip install urh&lt;br /&gt;
* Second method &lt;br /&gt;
#	Sudo apt -y install urh&lt;br /&gt;
 &lt;br /&gt;
* Third method&lt;br /&gt;
#	git clone https://github.com/jopohl/urh&lt;br /&gt;
#   cd urh&lt;br /&gt;
#   python setup.py install&lt;br /&gt;
* Start Universal Radio Hacker with the command “urh”&lt;br /&gt;
** The device settings are listed below:&lt;br /&gt;
##	Choose HackRF&lt;br /&gt;
##	Enter the frequency&lt;br /&gt;
&lt;br /&gt;
=== Nesdr Smart – receive only ===&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039; Step 1 &#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
Install the driver with zadig (detailed information in the HackRF One section)&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039; Step 2 &#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
Enter the RTL-SDR the “Device” option of the device settings and the frequency and you are ready to receive signals!&lt;br /&gt;
&lt;br /&gt;
== Used Hardware ==&lt;br /&gt;
&lt;br /&gt;
* HackRF One&lt;br /&gt;
* PandwaRF&lt;br /&gt;
* Nooelec SDR&lt;br /&gt;
&lt;br /&gt;
== Conclusion ==&lt;br /&gt;
We were able to receive signals with all three Software defined radios. However, HackRF One was the only device which allowed us to transmit signals too. It should be possible to transmit signal with PandwaRF as well, but we struggled with the Kaiju license, which is necessary for the transmission process. Therefore, we were able to achieve our project goals with the HackRF One.&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
* https://www.youtube.com/watch?v=5CsD8I396wo&amp;amp;t=327s&lt;br /&gt;
* https://www.essentracomponents.com/en-gb/news/product-resources/explaining-remote-keyless-entry-in-cars&lt;br /&gt;
* https://en.wikipedia.org/wiki/Rolling_code#:~:text=A%20rolling%20code%20(or%20sometimes,and%20keyless%20car%20entry%20systems&lt;br /&gt;
* https://www.youtube.com/watch?v=XrRGDQ2IzDE&lt;br /&gt;
* https://en.wikipedia.org/wiki/Remote_keyless_system&lt;br /&gt;
* https://sectigo.com/resource-library/why-automotive-key-fob-encryption-hacks-are-making-headlines&lt;br /&gt;
* https://rolling.pandwarf.com/&lt;br /&gt;
* https://www.offensive-wireless.com/how-to-install-universal-radio-hacker/&lt;br /&gt;
* https://installati.one/ubuntu/20.04/hackrf/&lt;br /&gt;
* https://zadig.akeo.ie/&lt;br /&gt;
* https://www.kali.org/docs/usb/live-usb-install-with-linux/&lt;br /&gt;
* https://www.balena.io/etcher/&lt;br /&gt;
* https://www.kali.org/docs/introduction/download-official-kali-linux-images/&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[Category:Documentation]]&lt;/div&gt;</summary>
		<author><name>FPaschinger</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=Software-defined_radio_(SDR):_Relay_Attacks&amp;diff=10267</id>
		<title>Software-defined radio (SDR): Relay Attacks</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=Software-defined_radio_(SDR):_Relay_Attacks&amp;diff=10267"/>
		<updated>2022-07-12T18:35:10Z</updated>

		<summary type="html">&lt;p&gt;FPaschinger: /* Pentesting with HackRF one */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Summary == &lt;br /&gt;
&lt;br /&gt;
This documentation is about SDR (Software defined radio) and relay attacks. This document will give you a better understanding of these definitions and how some devices in IOT can/could be attacked with SDR relay attacks. This documentations will also provides detailed information about devices we used, the setup of these devices and other requirements. &lt;br /&gt;
&lt;br /&gt;
== Requirements ==&lt;br /&gt;
&lt;br /&gt;
We used 3 different devices for the penetration-testing of a car and a gate. &lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039; Hardware &#039;&#039;&#039;&lt;br /&gt;
*HackRF-One&lt;br /&gt;
*PandwaRF&lt;br /&gt;
*Nooelec SDR (No transmission possible)&lt;br /&gt;
*Car&lt;br /&gt;
*Garage gate&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039; Software &#039;&#039;&#039;&lt;br /&gt;
*Computer with native Kali-Linux installed.&lt;br /&gt;
*License for PandwaRF.&lt;br /&gt;
*Universal Radio Hacker.&lt;br /&gt;
*PandwaRF App for Android. (Must be a device with latest Android version installed)&lt;br /&gt;
&lt;br /&gt;
In order to complete these steps, you must have followed [[Some Other Documentation]] before.&lt;br /&gt;
&lt;br /&gt;
== Description ==&lt;br /&gt;
&lt;br /&gt;
=== Pentesting with PandwaRF ===&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039; Step 1 &#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
1)Install the application on your Android Phone.&lt;br /&gt;
2)Open the Device.&lt;br /&gt;
3)Install the antennas. (Never use a SDR Device without antennas.)&lt;br /&gt;
4)Connect the PandwaRF via USB-C to your phone.&lt;br /&gt;
5)Open the application.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039; Step 2 &#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
1)The device should have connected with your application. If not, do it manually in the search tab.&lt;br /&gt;
2)After the device has connected, you can use the spectrum analyser to analyse the frequency which the device captures. If you want to get your desired signal, you need to choose your frequency. &lt;br /&gt;
3)At the Rx/Tx tab you can scan you signal which you try to capture. It is even possible to auto detect a signal which is sent.The pandwaRF will give you the captured signal in hex or in Binary which you can afterwards analyze. &lt;br /&gt;
4)In order to transmit a captured signal, you need to buy a &amp;quot;Kaiju License. Kaiju is an online tool where you can analyze rolling code and generate those. Kaiju is mainly used to attack systems which use rolling code.&lt;br /&gt;
&lt;br /&gt;
=== Pentesting with HackRF one ===&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039; Step 1 &#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
#    Set up a laptop with native kali linux &lt;br /&gt;
&lt;br /&gt;
#    If you want dual boot on your local machine use these instructions&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039; Dualboot on windows machine &#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
#	You need a USB stick with a minimum of 8gb storage&lt;br /&gt;
&lt;br /&gt;
#   Download Kali image from official website&lt;br /&gt;
&lt;br /&gt;
#   Download e.g. Etcher to flash the image on the USB stick to make it bootable&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
#	On the computer enter BIOS and change the BIOS-Mode to Legacy instead of Secure Boot (if secure boot is enabled). Secure boot prevents booting from external device! Then change the BIOS-Priority to “USB” first.&lt;br /&gt;
&lt;br /&gt;
#	For further information follow the instructions on the official website &lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039; Step 2 &#039;&#039;&#039;&lt;br /&gt;
* Driver Installation on HackRF One&lt;br /&gt;
#	Download Zadig &lt;br /&gt;
#	Only compatible with Windows &lt;br /&gt;
&lt;br /&gt;
* Set-up HackRF on Linux&lt;br /&gt;
#	Sudo apt-get update&lt;br /&gt;
#	Sudo apt-get -y install hackrf&lt;br /&gt;
&lt;br /&gt;
Download Universal Radio Hacker on Linux machine&lt;br /&gt;
* First method &lt;br /&gt;
#	Sudo python3 -m pip install –upgrade pip&lt;br /&gt;
#	Sudo python3 -m pip install urh&lt;br /&gt;
* Second method &lt;br /&gt;
#	Sudo apt -y install urh&lt;br /&gt;
 &lt;br /&gt;
* Third method&lt;br /&gt;
#	git clone https://github.com/jopohl/urh&lt;br /&gt;
#   cd urh&lt;br /&gt;
#   python setup.py install&lt;br /&gt;
* Start Universal Radio Hacker with the command “urh”&lt;br /&gt;
** The device settings are listed below:&lt;br /&gt;
##	Choose HackRF&lt;br /&gt;
##	Enter the frequency&lt;br /&gt;
&lt;br /&gt;
=== Nesdr Smart – receive only ===&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039; Step 1 &#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
Install the driver with zadig (detailed information in the HackRF One section)&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039; Step 2 &#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
Enter the RTL-SDR the “Device” option of the device settings and the frequency and you are ready to receive signals!&lt;br /&gt;
&lt;br /&gt;
== Used Hardware ==&lt;br /&gt;
&lt;br /&gt;
* HackRF One&lt;br /&gt;
* PandwaRF&lt;br /&gt;
* Nooelec SDR&lt;br /&gt;
&lt;br /&gt;
== Conclusion ==&lt;br /&gt;
We were able to receive signals with all three Software defined radios. However, HackRF One was the only device which allowed us to transmit signals too. It should be possible to transmit signal with PandwaRF as well, but we struggled with the Kaiju license, which is necessary for the transmission process. Therefore, we were able to achieve our project goals with the HackRF One.&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
* https://www.youtube.com/watch?v=5CsD8I396wo&amp;amp;t=327s&lt;br /&gt;
* https://www.essentracomponents.com/en-gb/news/product-resources/explaining-remote-keyless-entry-in-cars&lt;br /&gt;
* https://en.wikipedia.org/wiki/Rolling_code#:~:text=A%20rolling%20code%20(or%20sometimes,and%20keyless%20car%20entry%20systems&lt;br /&gt;
* https://www.youtube.com/watch?v=XrRGDQ2IzDE&lt;br /&gt;
* https://en.wikipedia.org/wiki/Remote_keyless_system&lt;br /&gt;
* https://sectigo.com/resource-library/why-automotive-key-fob-encryption-hacks-are-making-headlines&lt;br /&gt;
* https://rolling.pandwarf.com/&lt;br /&gt;
* https://www.offensive-wireless.com/how-to-install-universal-radio-hacker/&lt;br /&gt;
* https://installati.one/ubuntu/20.04/hackrf/&lt;br /&gt;
* https://zadig.akeo.ie/&lt;br /&gt;
* https://www.kali.org/docs/usb/live-usb-install-with-linux/&lt;br /&gt;
* https://www.balena.io/etcher/&lt;br /&gt;
* https://www.kali.org/docs/introduction/download-official-kali-linux-images/&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[Category:Documentation]]&lt;/div&gt;</summary>
		<author><name>FPaschinger</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=Software-defined_radio_(SDR):_Relay_Attacks&amp;diff=10266</id>
		<title>Software-defined radio (SDR): Relay Attacks</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=Software-defined_radio_(SDR):_Relay_Attacks&amp;diff=10266"/>
		<updated>2022-07-12T18:34:48Z</updated>

		<summary type="html">&lt;p&gt;FPaschinger: /* Pentesting with HackRF one */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Summary == &lt;br /&gt;
&lt;br /&gt;
This documentation is about SDR (Software defined radio) and relay attacks. This document will give you a better understanding of these definitions and how some devices in IOT can/could be attacked with SDR relay attacks. This documentations will also provides detailed information about devices we used, the setup of these devices and other requirements. &lt;br /&gt;
&lt;br /&gt;
== Requirements ==&lt;br /&gt;
&lt;br /&gt;
We used 3 different devices for the penetration-testing of a car and a gate. &lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039; Hardware &#039;&#039;&#039;&lt;br /&gt;
*HackRF-One&lt;br /&gt;
*PandwaRF&lt;br /&gt;
*Nooelec SDR (No transmission possible)&lt;br /&gt;
*Car&lt;br /&gt;
*Garage gate&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039; Software &#039;&#039;&#039;&lt;br /&gt;
*Computer with native Kali-Linux installed.&lt;br /&gt;
*License for PandwaRF.&lt;br /&gt;
*Universal Radio Hacker.&lt;br /&gt;
*PandwaRF App for Android. (Must be a device with latest Android version installed)&lt;br /&gt;
&lt;br /&gt;
In order to complete these steps, you must have followed [[Some Other Documentation]] before.&lt;br /&gt;
&lt;br /&gt;
== Description ==&lt;br /&gt;
&lt;br /&gt;
=== Pentesting with PandwaRF ===&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039; Step 1 &#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
1)Install the application on your Android Phone.&lt;br /&gt;
2)Open the Device.&lt;br /&gt;
3)Install the antennas. (Never use a SDR Device without antennas.)&lt;br /&gt;
4)Connect the PandwaRF via USB-C to your phone.&lt;br /&gt;
5)Open the application.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039; Step 2 &#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
1)The device should have connected with your application. If not, do it manually in the search tab.&lt;br /&gt;
2)After the device has connected, you can use the spectrum analyser to analyse the frequency which the device captures. If you want to get your desired signal, you need to choose your frequency. &lt;br /&gt;
3)At the Rx/Tx tab you can scan you signal which you try to capture. It is even possible to auto detect a signal which is sent.The pandwaRF will give you the captured signal in hex or in Binary which you can afterwards analyze. &lt;br /&gt;
4)In order to transmit a captured signal, you need to buy a &amp;quot;Kaiju License. Kaiju is an online tool where you can analyze rolling code and generate those. Kaiju is mainly used to attack systems which use rolling code.&lt;br /&gt;
&lt;br /&gt;
=== Pentesting with HackRF one ===&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039; Step 1 &#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
#    Set up a laptop with native kali linux &lt;br /&gt;
&lt;br /&gt;
#    If you want dual boot on your local machine use these instructions&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039; Dualboot on windows maschine &#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
#	You need a USB stick with a minimum of 8gb storage&lt;br /&gt;
&lt;br /&gt;
#   Download Kali image from official website&lt;br /&gt;
&lt;br /&gt;
#   Download e.g. Etcher to flash the image on the USB stick to make it bootable&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
#	On the computer enter BIOS and change the BIOS-Mode to Legacy instead of Secure Boot (if secure boot is enabled). Secure boot prevents booting from external device! Then change the BIOS-Priority to “USB” first.&lt;br /&gt;
&lt;br /&gt;
#	For further information follow the instructions on the official website &lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039; Step 2 &#039;&#039;&#039;&lt;br /&gt;
* Driver Installation on HackRF One&lt;br /&gt;
#	Download Zadig &lt;br /&gt;
#	Only compatible with Windows &lt;br /&gt;
&lt;br /&gt;
* Set-up HackRF on Linux&lt;br /&gt;
#	Sudo apt-get update&lt;br /&gt;
#	Sudo apt-get -y install hackrf&lt;br /&gt;
&lt;br /&gt;
Download Universal Radio Hacker on Linux machine&lt;br /&gt;
* First method &lt;br /&gt;
#	Sudo python3 -m pip install –upgrade pip&lt;br /&gt;
#	Sudo python3 -m pip install urh&lt;br /&gt;
* Second method &lt;br /&gt;
#	Sudo apt -y install urh&lt;br /&gt;
 &lt;br /&gt;
* Third method&lt;br /&gt;
#	git clone https://github.com/jopohl/urh&lt;br /&gt;
#   cd urh&lt;br /&gt;
#   python setup.py install&lt;br /&gt;
* Start Universal Radio Hacker with the command “urh”&lt;br /&gt;
** The device settings are listed below:&lt;br /&gt;
##	Choose HackRF&lt;br /&gt;
##	Enter the frequency&lt;br /&gt;
&lt;br /&gt;
=== Nesdr Smart – receive only ===&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039; Step 1 &#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
Install the driver with zadig (detailed information in the HackRF One section)&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039; Step 2 &#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
Enter the RTL-SDR the “Device” option of the device settings and the frequency and you are ready to receive signals!&lt;br /&gt;
&lt;br /&gt;
== Used Hardware ==&lt;br /&gt;
&lt;br /&gt;
* HackRF One&lt;br /&gt;
* PandwaRF&lt;br /&gt;
* Nooelec SDR&lt;br /&gt;
&lt;br /&gt;
== Conclusion ==&lt;br /&gt;
We were able to receive signals with all three Software defined radios. However, HackRF One was the only device which allowed us to transmit signals too. It should be possible to transmit signal with PandwaRF as well, but we struggled with the Kaiju license, which is necessary for the transmission process. Therefore, we were able to achieve our project goals with the HackRF One.&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
* https://www.youtube.com/watch?v=5CsD8I396wo&amp;amp;t=327s&lt;br /&gt;
* https://www.essentracomponents.com/en-gb/news/product-resources/explaining-remote-keyless-entry-in-cars&lt;br /&gt;
* https://en.wikipedia.org/wiki/Rolling_code#:~:text=A%20rolling%20code%20(or%20sometimes,and%20keyless%20car%20entry%20systems&lt;br /&gt;
* https://www.youtube.com/watch?v=XrRGDQ2IzDE&lt;br /&gt;
* https://en.wikipedia.org/wiki/Remote_keyless_system&lt;br /&gt;
* https://sectigo.com/resource-library/why-automotive-key-fob-encryption-hacks-are-making-headlines&lt;br /&gt;
* https://rolling.pandwarf.com/&lt;br /&gt;
* https://www.offensive-wireless.com/how-to-install-universal-radio-hacker/&lt;br /&gt;
* https://installati.one/ubuntu/20.04/hackrf/&lt;br /&gt;
* https://zadig.akeo.ie/&lt;br /&gt;
* https://www.kali.org/docs/usb/live-usb-install-with-linux/&lt;br /&gt;
* https://www.balena.io/etcher/&lt;br /&gt;
* https://www.kali.org/docs/introduction/download-official-kali-linux-images/&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[Category:Documentation]]&lt;/div&gt;</summary>
		<author><name>FPaschinger</name></author>
	</entry>
</feed>