<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
	<id>https://elvis.hcw.ac.at/wiki/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=MMayer</id>
	<title>Elvis Wiki - User contributions [en]</title>
	<link rel="self" type="application/atom+xml" href="https://elvis.hcw.ac.at/wiki/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=MMayer"/>
	<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php/Special:Contributions/MMayer"/>
	<updated>2026-09-10T15:27:10Z</updated>
	<subtitle>User contributions</subtitle>
	<generator>MediaWiki 1.41.5</generator>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=Hak5_Signal_Owl&amp;diff=11022</id>
		<title>Hak5 Signal Owl</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=Hak5_Signal_Owl&amp;diff=11022"/>
		<updated>2023-01-08T22:08:58Z</updated>

		<summary type="html">&lt;p&gt;MMayer: /* WiFi Connect */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= Introduction =&lt;br /&gt;
&lt;br /&gt;
The [https://docs.hak5.org/signal-owl/ Signal Owl] is a hardware product developed by the company [https://shop.hak5.org/ Hak5].&lt;br /&gt;
It is a simple payload-based signals intelligence platform with a unique design for discreet planting or mobile operations on any engagement. The most popular application cases include classic network mapping and basic penetration tests for various wireless technologies.&lt;br /&gt;
&lt;br /&gt;
== Initial Setup ==&lt;br /&gt;
&lt;br /&gt;
When first unboxing the Signal Owl, the device runs a stager firmware that is designed to flash the latest firmware from a USB flash drive. In order to update the Signal Owl, the [https://downloads.hak5.org/owl latest firmware] has to be downloaded. Then, the downloaded file must be copied to the root of an EXT4 or FAT32 formatted USB flash drive. It is important not to modify this file. The next step is to plug the USB flash drive into the powered off Signal Owl. Afterwards, the device has to be powered on by a reliable USB source. The upgrade itself takes approximately five to ten minutes and is indicated by a solid red LED light. When finished, the device will reboot, enter Attack Mode and blink slowly, indicating an error running the payload because no payload has been found.&lt;br /&gt;
&lt;br /&gt;
= Hardware =&lt;br /&gt;
&lt;br /&gt;
[[File:SignalOwlDiagram.png|thumb|500px|frame|Components of the Signal Owl [Eigene Darstellung]]] &lt;br /&gt;
&lt;br /&gt;
The Signal Owl is designed to be rapidly deployed in all kinds of environments, allowing it to be an entry point for network analysis and basic wireless attacks in a variety of locations. With a power consumption of 100-200 mAh and the thermally optimized architecture, mobile operations as well as long term deployments, are enabled.&lt;br /&gt;
&lt;br /&gt;
== Components ==&lt;br /&gt;
&lt;br /&gt;
This device features several components of which some may not be visible to the human eye at first sight.&lt;br /&gt;
&lt;br /&gt;
=== USB Power / Passthrough Plug ===&lt;br /&gt;
&lt;br /&gt;
The USB power or passthrough plug is used to power the device. It can be powered from any reliable USB source.&lt;br /&gt;
&lt;br /&gt;
=== USB 2.0 Passthrough Port ===&lt;br /&gt;
&lt;br /&gt;
The USB 2.0 passthrough port is the port closest to the pigtail. Data and power pass through to that port, allowing for implant operations. If a device such as a keyboard is plugged in between this passthrough port and the power plug is connected to the target computer, the Signal Owl will remain undetected by the operating system. Only the keyboard will be visible on the target computer.&lt;br /&gt;
&lt;br /&gt;
=== USB 2.0 Host Port ===&lt;br /&gt;
&lt;br /&gt;
The USB 2.0 host port is the port farthest away from the pigtail. It is connected to the Linux socket of the Signal Owl and supports USB flash drives formatted with FAT32 and EXT4 file systems as well as many Wi-Fi, Bluetooth and other RF transceivers.&lt;br /&gt;
&lt;br /&gt;
=== Button ===&lt;br /&gt;
&lt;br /&gt;
The button on the bottom of the device is used to enter Arming Mode and to interact with payloads. It is not pressable without special tools like paperclips.&lt;br /&gt;
&lt;br /&gt;
=== Status LED ===&lt;br /&gt;
&lt;br /&gt;
The status LED indicates the current status of the Signal Owl. When it is turned off, it is not visible.&lt;br /&gt;
&lt;br /&gt;
The Signal Owl features a red LED with the following default status indications:&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
!|LED&lt;br /&gt;
!|Status&lt;br /&gt;
|-&lt;br /&gt;
|Blinking&lt;br /&gt;
|Booting&lt;br /&gt;
|-&lt;br /&gt;
|Solid&lt;br /&gt;
|Mounting external storage / Running upgrade&lt;br /&gt;
|-&lt;br /&gt;
|Single blinking&lt;br /&gt;
|Attack Mode&lt;br /&gt;
|-&lt;br /&gt;
|Double blinking&lt;br /&gt;
|Arming Mode&lt;br /&gt;
|-&lt;br /&gt;
|Slow blinking&lt;br /&gt;
|Error running payload&lt;br /&gt;
|-&lt;br /&gt;
|Fast blinking&lt;br /&gt;
|Select Mode (Deprecated from version 1.0.1 onward)&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= Software =&lt;br /&gt;
&lt;br /&gt;
== Modes of Operation ==&lt;br /&gt;
&lt;br /&gt;
The Signal Owl comes with two modes of operation, Attack Mode and Arming Mode. By default, the device will boot into Attack Mode. In order to access Arming Mode, the button on the bottom of the device has to be pressed while in Attack Mode. It is not recommended to press the button during the boot sequence, as this can possibly brick the device and render it useless. The arming mode is used for firmware updates and shell access, while the attack mode is used to load and execute the payload.&lt;br /&gt;
&lt;br /&gt;
=== Attack Mode ===&lt;br /&gt;
&lt;br /&gt;
Attack Mode is the default mode, the Signal Owl boots into. It provides two basic functions, being the payload loading function and the payload execution function. &lt;br /&gt;
&lt;br /&gt;
The payload loading function checks for any USB flash drives plugged into the host port of the device and copies payloads to &amp;lt;code&amp;gt;/root/payload&amp;lt;/code&amp;gt; and extensions to &amp;lt;code&amp;gt;/root/payload/extensions&amp;lt;/code&amp;gt; on the Signal Owl. &lt;br /&gt;
&lt;br /&gt;
The payload execution function is responsible for executing the payload that is currently stored on the root of the Signal Owl. In case no payload is found, the device will blink slowly, indicating the FAIL status.&lt;br /&gt;
&lt;br /&gt;
=== Arming Mode ===&lt;br /&gt;
&lt;br /&gt;
The Arming Mode provides two basic functions, being the firmware update function and the shell access function. The firmware update function checks for any USB flash drives plugged into the host port of the device and copies firmware upgrade files into the internal storage of the device and flashes it. The shell access function starts an open access point with the SSID Owl_xxxx in which xxxx indicates the last two octets of the device&#039;s MAC address. Additionally, a SSH server providing access to the shell of the Signal Owl is enabled.&lt;br /&gt;
&lt;br /&gt;
== Default Settings ==&lt;br /&gt;
&lt;br /&gt;
Default settings that are used in order to access the device via SSH are pictured in the table below.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
!colspan=&amp;quot;2&amp;quot;|Default Settings&lt;br /&gt;
|-&lt;br /&gt;
|Username&lt;br /&gt;
|root&lt;br /&gt;
|-&lt;br /&gt;
|Password&lt;br /&gt;
|hak5owl&lt;br /&gt;
|-&lt;br /&gt;
|SSID&lt;br /&gt;
|Owl_xxxx&lt;br /&gt;
|-&lt;br /&gt;
|IP Address&lt;br /&gt;
|172.16.56.1&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
SSH command: &amp;lt;code&amp;gt;ssh root@172.16.56.1&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The SSID during Arming Mode is Owl_xxxx in which xxxx indicates the last two octets of the devices MAC address.&lt;br /&gt;
&lt;br /&gt;
= Usage =&lt;br /&gt;
&lt;br /&gt;
== Arming Mode connection ==&lt;br /&gt;
&lt;br /&gt;
Step-by-step guide for accessing the arming mode&lt;br /&gt;
&lt;br /&gt;
#Click on the button located on the bottom of the Signal Owl while it is in attack mode. After pressing the button, the signal owl enters the arming mode and provides an open access point with the name Owl xxxx (where xxxx stands for the last two digits of the MAC address of the device).&lt;br /&gt;
#Connect to the access point.&amp;lt;br&amp;gt;[[File:Armingmode.png]][Eigene Darstellung]&lt;br /&gt;
#Now you can connect via ssh by using the [[#Default Settings|default settings]].&lt;br /&gt;
#After successful connection, you will end up in the root directory.&amp;lt;br&amp;gt;[[File:ArmingmodeSSH.png]][Eigene Darstellung]&lt;br /&gt;
#Now you can change the files and directories on the Signal Owl to view results, transfer payloads and extensions or to make further changes.&lt;br /&gt;
&lt;br /&gt;
== Directory Structure ==&lt;br /&gt;
&lt;br /&gt;
The following directory tree shows the directory structure of the Signal Owl.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
/&lt;br /&gt;
├── loot&lt;br /&gt;
└── payload/&lt;br /&gt;
    └── extensions&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
*Loot - Directory where the Signal Owl saves loot while executing payloads that produce loot.&lt;br /&gt;
*Payload - This directory holds the current payload. &lt;br /&gt;
*Extensions -  This directory holds all extensions.&lt;br /&gt;
&lt;br /&gt;
== Adding Payloads and Extensions ==&lt;br /&gt;
&lt;br /&gt;
Adding a payload can be done in two different ways. Either with a USB flash drive or via the Signal Owl access point to the internal storage of the device. &lt;br /&gt;
&lt;br /&gt;
When booting, payloads on USB flash drives are given priority and will override payloads stored on the Signal Owl. To successfully copy a payload to the Signal Owl, the payload must be named &amp;lt;code&amp;gt;payload.txt&amp;lt;/code&amp;gt; or &amp;lt;code&amp;gt;payload.sh&amp;lt;/code&amp;gt; and it has to be placed in the &amp;lt;code&amp;gt;root&amp;lt;/code&amp;gt; directory of the flash drive. Similarly, payload extensions should be stored in a &amp;lt;code&amp;gt;/extensions&amp;lt;/code&amp;gt; directory on the flash drive. &lt;br /&gt;
&lt;br /&gt;
In addition, it is possible to transfer payloads and payload extensions to the device via the Signal Owl access point in arming mode using SSH. There they are stored in the &amp;lt;code&amp;gt;/root/payload&amp;lt;/code&amp;gt; directory and Payload Extensions are stored in the &amp;lt;code&amp;gt;/root/payload/extensions&amp;lt;/code&amp;gt; directory.&lt;br /&gt;
&lt;br /&gt;
== Payload Development ==&lt;br /&gt;
&lt;br /&gt;
Payloads for the Signal Owl are written in bash with [https://github.com/hak5darren/USB-Rubber-Ducky/wiki/Duckyscript Ducky Script] and can be created with any standard text editor. All payloads should begin with an interpreter directive, like the shebang &amp;lt;code&amp;gt;#!/bin/bash&amp;lt;/code&amp;gt; for bash payloads and payloads must be named either &amp;lt;code&amp;gt;payload.txt&amp;lt;/code&amp;gt; or &amp;lt;code&amp;gt;payload.sh&amp;lt;/code&amp;gt;. In order to create effective payloads, the Signal Owl comes with several preinstalled penetration testing tools. These are as follows: [https://nmap.org/ Nmap], [https://www.aircrack-ng.org/ Aircrack-ng], [https://github.com/aircrack-ng/mdk4 MDK4] and [https://www.kismetwireless.net/ Kismet].&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Tools&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
• Kismet - detector for wireless networks and devices.&lt;br /&gt;
&lt;br /&gt;
• MDK4 - Wi-Fi testing tool.&lt;br /&gt;
&lt;br /&gt;
• Aircrack-ng Suite - a complete suite of tools for WiFi network security assessment.&lt;br /&gt;
&lt;br /&gt;
• Nmap - open source utility for network discovery and security auditing.&lt;br /&gt;
&lt;br /&gt;
Hak5 offers ready-to-use payloads and payload extensions on their [https://github.com/hak5/signalowl-payloads GitHub repository].&lt;br /&gt;
&lt;br /&gt;
== Implant / mobile operations ==&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Implant operations&lt;br /&gt;
&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
During long term wireless engagements, the Signal Owl may be planted inline between any typical 5V USB power source. This may be useful in situations where ports are occupied, or to deter the unit from being unplugged.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Mobile operations&lt;br /&gt;
&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
The Signal Owl features a low power consumption profile, with a typical power draw averaging 100-200 mAh. Additionally, it is thermally optimized for long term deployments in many indoor environments. One can expect a large 20,000 mAh USB battery bank to operate the unit for up to 4 days.&lt;br /&gt;
&lt;br /&gt;
= Use Cases =&lt;br /&gt;
&lt;br /&gt;
The Signal Owl has a variety of different use cases. Among the most popular ones are classical network mapping and wardriving as well as basic penetration tests for different wireless technologies.&lt;br /&gt;
&lt;br /&gt;
== Fake Beacon Flooding Attack ==&lt;br /&gt;
&lt;br /&gt;
The Fake Beacon Flooding Attack is one possible use case for the Signal Owl. With that attack, fake beacon frames are broadcasted to nearby devices. Beacon Frames include various parameters like the SSID, the type of encryption used and timestamps. This results in the creation of multiple fake Wi-Fi networks. Devices with Wi-Fi browsers are then flooded with these fake networks, causing potential network scanner and driver crashes. Furthermore, the attack may prevent legitimate users from finding their networks and lead to denial of service. The preinstalled tools Aircrack-ng and MDK4 were used to create this payload. After powering on the device, multiple fake networks with random SSIDs are generated and broadcasted to all nearby devices.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;bash&amp;quot;&amp;gt;&lt;br /&gt;
#!/bin/bash&lt;br /&gt;
&lt;br /&gt;
LED SETUP&lt;br /&gt;
sleep 10&lt;br /&gt;
airmon-ng check kill&lt;br /&gt;
sleep 10&lt;br /&gt;
#creates monitor mode interface on wirelss card of the Signal Owl&lt;br /&gt;
airmon-ng start wlan0&lt;br /&gt;
sleep 10&lt;br /&gt;
LED ATTACK&lt;br /&gt;
#floods nearby devices with random SSIDs&lt;br /&gt;
mdk4 wlan0mon b -a -m -s 500&lt;br /&gt;
&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The results as seen from a victim running a Windows 10 system are pictured in the figure below.&lt;br /&gt;
&lt;br /&gt;
[[File:FakeBeaconFloodingSignalOwl.png|Random SSIDs as seen from a victim Windows 10 client]][Eigene Darstellung]&lt;br /&gt;
&lt;br /&gt;
== Open AP Nmap Scanner ==&lt;br /&gt;
&lt;br /&gt;
With the Open AP Nmap Scanner payload, the Signal Owl scans for open access points. If the Signal Owl finds one or more open access points, it connects to them and uses Nmap to scan and analyze them. The results are then stored in the loot directory. For each discovered open access point, the Signal Owl generates a separate results file. This payload has some settings which can be seen in the following listing.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;bash&amp;quot;&amp;gt;&lt;br /&gt;
NMAP_OPTIONS=&amp;quot;-sP&amp;quot;&lt;br /&gt;
LOOT_DIR=/root/loot/open_ap_nmap_scan&lt;br /&gt;
MAX_CIDR=20&lt;br /&gt;
DEBUG=1&lt;br /&gt;
&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
*NMAP_OPTIONS - Is used to specify the type of Nmap scan.&lt;br /&gt;
*LOOT_DIR - Sets the destination folder for the scan results.&lt;br /&gt;
*MAX_CIDR - Sets the maximum Classless Inter-Domain Routing&lt;br /&gt;
*DEBUG - Specifies if debug information is saved to the payload.log file in the tmp folder.&lt;br /&gt;
** 1 - Debug information is saved.&lt;br /&gt;
** 0 - Debug information is not saved.&lt;br /&gt;
&lt;br /&gt;
The results of a scan with this payload can be seen in the figure below.&lt;br /&gt;
&lt;br /&gt;
[[File:OpenAPNmapScannerResult.png|750px]][Eigene Darstellung]&lt;br /&gt;
&lt;br /&gt;
== Basic Bluetooth Scanner ==&lt;br /&gt;
&lt;br /&gt;
This payload requires an external Bluetooth adapter, since the Signal Owl does not have Bluetooth built in. The Basic Bluetooth Scanner scans for devices that have Bluetooth enabled and optionally queries them using the hcitool and the info command. This payload does also have some settings, as shown in the listing below.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;bash&amp;quot;&amp;gt;&lt;br /&gt;
LOOT_DIR=/root/loot/bluetooth_scan&lt;br /&gt;
BT_OUTFILE=`date +%s`.bt.list&lt;br /&gt;
BT_INFOFILE=`date +%s`.bt.info   &lt;br /&gt;
BTDEV=hci0&lt;br /&gt;
DEBUG=0 &lt;br /&gt;
INTERROGATE=1 &lt;br /&gt;
&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
*LOOT_DIR - Sets the directory for the scan result.&lt;br /&gt;
*BT_OUTFILE - Sets a file name, in which all detected names and MAC addresses are saved.&lt;br /&gt;
*BT_INFOFILE - Sets a file name, in which the details of the discovered devices are saved if the INTERROGATE variable is set to 1. &lt;br /&gt;
*BTDEV - Specifies the bluetooth device used for scanning.&lt;br /&gt;
*DEBUG - Specifies if debug information is saved to the payload.log file in the tmp folder.&lt;br /&gt;
** 1 - Debug information is saved.&lt;br /&gt;
** 0 - Debug information is not saved.&lt;br /&gt;
*INTERROGATE - Specifies if the detected devices are interrogated.&lt;br /&gt;
** 1 - Detected devices are interrogated&lt;br /&gt;
** 0 - Detected devices are not interrogated&lt;br /&gt;
&lt;br /&gt;
After a successful scan, all detected devices are listed with their names and MAC addresses in the file specified by &amp;lt;code&amp;gt;BT_OUTFILE&amp;lt;/code&amp;gt;. If &amp;lt;code&amp;gt;INTERROGATE&amp;lt;/code&amp;gt; has been set to 1, a &amp;lt;code&amp;gt;.info&amp;lt;/code&amp;gt; file is generated that lists additional details about each scanned device.&lt;br /&gt;
&lt;br /&gt;
== WiFi Connect ==&lt;br /&gt;
&lt;br /&gt;
With the WiFi Connect payload, which can be seen in the following listing, and the wificonnect.sh Payload extension, the Signal Owl can be connected to a nearby network. The SSID and password of the network to which the Signal Owl should connect must be specified in the code. Optionally, the SSH server of the device can be started by removing the hash sign in the code before the corresponding command. &lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;bash&amp;quot;&amp;gt;&lt;br /&gt;
#!/bin/bash&lt;br /&gt;
&lt;br /&gt;
# WiFi Client Setup&lt;br /&gt;
WIFI_SSID=&amp;quot;network-name&amp;quot;&lt;br /&gt;
WIFI_PASS=&amp;quot;passphrase&amp;quot;&lt;br /&gt;
&lt;br /&gt;
LED SETUP&lt;br /&gt;
WIFI_CONNECT&lt;br /&gt;
# optionally start SSH server&lt;br /&gt;
# /etc/init.d/sshd start&lt;br /&gt;
LED ATTACK&lt;br /&gt;
&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The &amp;lt;code&amp;gt;WIFI_CONNECT&amp;lt;/code&amp;gt; command executes the wifi_connect.sh payload extension, which is shown in the following listing. &lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;bash&amp;quot;&amp;gt;&lt;br /&gt;
#!/bin/bash&lt;br /&gt;
&lt;br /&gt;
function WIFI_CONNECT() {&lt;br /&gt;
    [[ &amp;quot;x$WIFI_INT&amp;quot; == &amp;quot;x&amp;quot; ]] &amp;amp;&amp;amp; WIFI_INT=wlan0&lt;br /&gt;
    ifconfig $WIFI_INT up;sleep 10&lt;br /&gt;
    echo -e &amp;quot;network={\nssid=\&amp;quot;$WIFI_SSID\&amp;quot;\npsk=\&amp;quot;$WIFI_PASS\&amp;quot;\npriority=1\n}&amp;quot;&amp;gt;/tmp/wpa-$WIFI_INT.conf&lt;br /&gt;
    wpa_supplicant -B -Dnl80211 -i $WIFI_INT -c /tmp/wpa-$WIFI_INT.conf&lt;br /&gt;
    while(iwconfig $WIFI_INT | grep Not-Associated); do sleep 1; done&lt;br /&gt;
    udhcpc -i $WIFI_INT&lt;br /&gt;
}&lt;br /&gt;
export -f WIFI_CONNECT&lt;br /&gt;
&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The payload extension code uses the &amp;lt;code&amp;gt;WIFI_SSID&amp;lt;/code&amp;gt; and &amp;lt;code&amp;gt;WIFI_PASS&amp;lt;/code&amp;gt; variables of the payload to connect the Signal Owl to the network. With the command &amp;lt;code&amp;gt;export -f WIFI_CONNECT&amp;lt;/code&amp;gt; the function &amp;lt;code&amp;gt;WIFI_CONNECT&amp;lt;/code&amp;gt; is exported so that it can be called from the payload. &lt;br /&gt;
&lt;br /&gt;
If the SSH server is enabled, any SSH-enabled device can connect to the Signal Owl over the network, even though Attack Mode is enabled. The [[#Default Settings|default settings]] of the device can be used again for the connection, if they have not been changed yet. However, the IP address in this case is the IP address of the Signal Owl in this network.&lt;br /&gt;
&lt;br /&gt;
= Used Hardware =&lt;br /&gt;
&lt;br /&gt;
[[Signal Owl]]&lt;br /&gt;
&lt;br /&gt;
= References =&lt;br /&gt;
&lt;br /&gt;
*https://docs.hak5.org/signal-owl/&lt;br /&gt;
*https://github.com/hak5/signalowl-payloads&lt;br /&gt;
&lt;br /&gt;
[[Category:Pentesting]]&lt;/div&gt;</summary>
		<author><name>MMayer</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=Hak5_Signal_Owl&amp;diff=10932</id>
		<title>Hak5 Signal Owl</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=Hak5_Signal_Owl&amp;diff=10932"/>
		<updated>2023-01-08T15:32:18Z</updated>

		<summary type="html">&lt;p&gt;MMayer: /* Directory Structure */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= Introduction =&lt;br /&gt;
&lt;br /&gt;
The [https://docs.hak5.org/signal-owl/ Signal Owl] is a hardware product developed by the company [https://shop.hak5.org/ Hak5].&lt;br /&gt;
It is a simple payload-based signals intelligence platform with a unique design for discreet planting or mobile operations on any engagement. The most popular application cases include classic network mapping and basic penetration tests for various wireless technologies.&lt;br /&gt;
&lt;br /&gt;
== Initial Setup ==&lt;br /&gt;
&lt;br /&gt;
When first unboxing the Signal Owl, the device runs a stager firmware that is designed to flash the latest firmware from a USB flash drive. In order to update the Signal Owl, the [https://downloads.hak5.org/owl latest firmware] has to be downloaded. Then, the downloaded file must be copied to the root of an EXT4 or FAT32 formatted USB flash drive. It is important not to modify this file. The next step is to plug the USB flash drive into the powered off Signal Owl. Afterwards, the device has to be powered on by a reliable USB source. The upgrade itself takes approximately five to ten minutes and is indicated by a solid red LED light. When finished, the device will reboot, enter Attack Mode and blink slowly, indicating an error running the payload because no payload has been found.&lt;br /&gt;
&lt;br /&gt;
= Hardware =&lt;br /&gt;
&lt;br /&gt;
[[File:SignalOwlDiagram.png|thumb|500px|frame|Components of the Signal Owl [Eigene Darstellung]]] &lt;br /&gt;
&lt;br /&gt;
The Signal Owl is designed to be rapidly deployed in all kinds of environments, allowing it to be an entry point for network analysis and basic wireless attacks in a variety of locations. With a power consumption of 100-200 mAh and the thermally optimized architecture, mobile operations as well as long term deployments, are enabled.&lt;br /&gt;
&lt;br /&gt;
== Components ==&lt;br /&gt;
&lt;br /&gt;
This device features several components of which some may not be visible to the human eye at first sight.&lt;br /&gt;
&lt;br /&gt;
=== USB Power / Passthrough Plug ===&lt;br /&gt;
&lt;br /&gt;
The USB power or passthrough plug is used to power the device. It can be powered from any reliable USB source.&lt;br /&gt;
&lt;br /&gt;
=== USB 2.0 Passthrough Port ===&lt;br /&gt;
&lt;br /&gt;
The USB 2.0 passthrough port is the port closest to the pigtail. Data and power pass through to that port, allowing for implant operations. If a device such as a keyboard is plugged in between this passthrough port and the power plug is connected to the target computer, the Signal Owl will remain undetected by the operating system. Only the keyboard will be visible on the target computer.&lt;br /&gt;
&lt;br /&gt;
=== USB 2.0 Host Port ===&lt;br /&gt;
&lt;br /&gt;
The USB 2.0 host port is the port farthest away from the pigtail. It is connected to the Linux socket of the Signal Owl and supports USB flash drives formatted with FAT32 and EXT4 file systems as well as many Wi-Fi, Bluetooth and other RF transceivers.&lt;br /&gt;
&lt;br /&gt;
=== Button ===&lt;br /&gt;
&lt;br /&gt;
The button on the bottom of the device is used to enter Arming Mode and to interact with payloads. It is not pressable without special tools like paperclips.&lt;br /&gt;
&lt;br /&gt;
=== Status LED ===&lt;br /&gt;
&lt;br /&gt;
The status LED indicates the current status of the Signal Owl. When it is turned off, it is not visible.&lt;br /&gt;
&lt;br /&gt;
The Signal Owl features a red LED with the following default status indications:&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
!|LED&lt;br /&gt;
!|Status&lt;br /&gt;
|-&lt;br /&gt;
|Blinking&lt;br /&gt;
|Booting&lt;br /&gt;
|-&lt;br /&gt;
|Solid&lt;br /&gt;
|Mounting external storage / Running upgrade&lt;br /&gt;
|-&lt;br /&gt;
|Single blinking&lt;br /&gt;
|Attack Mode&lt;br /&gt;
|-&lt;br /&gt;
|Double blinking&lt;br /&gt;
|Arming Mode&lt;br /&gt;
|-&lt;br /&gt;
|Slow blinking&lt;br /&gt;
|Error running payload&lt;br /&gt;
|-&lt;br /&gt;
|Fast blinking&lt;br /&gt;
|Select Mode (Deprecated from version 1.0.1 onward)&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= Software =&lt;br /&gt;
&lt;br /&gt;
== Modes of Operation ==&lt;br /&gt;
&lt;br /&gt;
The Signal Owl comes with two modes of operation, Attack Mode and Arming Mode. By default, the device will boot into Attack Mode. In order to access Arming Mode, the button on the bottom of the device has to be pressed while in Attack Mode. It is not recommended to press the button during the boot sequence, as this can possibly brick the device and render it useless. The arming mode is used for firmware updates and shell access, while the attack mode is used to load and execute the payload.&lt;br /&gt;
&lt;br /&gt;
=== Attack Mode ===&lt;br /&gt;
&lt;br /&gt;
Attack Mode is the default mode, the Signal Owl boots into. It provides two basic functions, being the payload loading function and the payload execution function. &lt;br /&gt;
&lt;br /&gt;
The payload loading function checks for any USB flash drives plugged into the host port of the device and copies payloads to &amp;lt;code&amp;gt;/root/payload&amp;lt;/code&amp;gt; and extensions to &amp;lt;code&amp;gt;/root/payload/extensions&amp;lt;/code&amp;gt; on the Signal Owl. &lt;br /&gt;
&lt;br /&gt;
The payload execution function is responsible for executing the payload that is currently stored on the root of the Signal Owl. In case no payload is found, the device will blink slowly, indicating the FAIL status.&lt;br /&gt;
&lt;br /&gt;
=== Arming Mode ===&lt;br /&gt;
&lt;br /&gt;
The Arming Mode provides two basic functions, being the firmware update function and the shell access function. The firmware update function checks for any USB flash drives plugged into the host port of the device and copies firmware upgrade files into the internal storage of the device and flashes it. The shell access function starts an open access point with the SSID Owl_xxxx in which xxxx indicates the last two octets of the device&#039;s MAC address. Additionally, a SSH server providing access to the shell of the Signal Owl is enabled.&lt;br /&gt;
&lt;br /&gt;
== Default Settings ==&lt;br /&gt;
&lt;br /&gt;
Default settings that are used in order to access the device via SSH are pictured in the table below.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
!colspan=&amp;quot;2&amp;quot;|Default Settings&lt;br /&gt;
|-&lt;br /&gt;
|Username&lt;br /&gt;
|root&lt;br /&gt;
|-&lt;br /&gt;
|Password&lt;br /&gt;
|hak5owl&lt;br /&gt;
|-&lt;br /&gt;
|SSID&lt;br /&gt;
|Owl_xxxx&lt;br /&gt;
|-&lt;br /&gt;
|IP Address&lt;br /&gt;
|172.16.56.1&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
SSH command: &amp;lt;code&amp;gt;ssh root@172.16.56.1&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The SSID during Arming Mode is Owl_xxxx in which xxxx indicates the last two octets of the devices MAC address.&lt;br /&gt;
&lt;br /&gt;
= Usage =&lt;br /&gt;
&lt;br /&gt;
== Arming Mode connection ==&lt;br /&gt;
&lt;br /&gt;
Step-by-step guide for accessing the arming mode&lt;br /&gt;
&lt;br /&gt;
#Click on the button located on the bottom of the Signal Owl while it is in attack mode. After pressing the button, the signal owl enters the arming mode and provides an open access point with the name Owl xxxx (where xxxx stands for the last two digits of the MAC address of the device).&lt;br /&gt;
#Connect to the access point.&amp;lt;br&amp;gt;[[File:Armingmode.png]][Eigene Darstellung]&lt;br /&gt;
#Now you can connect via ssh by using the [[#Default Settings|default settings]].&lt;br /&gt;
#After successful connection, you will end up in the root directory.&amp;lt;br&amp;gt;[[File:ArmingmodeSSH.png]][Eigene Darstellung]&lt;br /&gt;
#Now you can change the files and directories on the Signal Owl to view results, transfer payloads and extensions or to make further changes.&lt;br /&gt;
&lt;br /&gt;
== Directory Structure ==&lt;br /&gt;
&lt;br /&gt;
The following directory tree shows the directory structure of the Signal Owl.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
/&lt;br /&gt;
├── loot&lt;br /&gt;
└── payload/&lt;br /&gt;
    └── extensions&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
*Loot - Directory where the Signal Owl saves loot while executing payloads that produce loot.&lt;br /&gt;
*Payload - This directory holds the current payload. &lt;br /&gt;
*Extensions -  This directory holds all extensions.&lt;br /&gt;
&lt;br /&gt;
== Adding Payloads and Extensions ==&lt;br /&gt;
&lt;br /&gt;
Adding a payload can be done in two different ways. Either with a USB flash drive or via the Signal Owl access point to the internal storage of the device. &lt;br /&gt;
&lt;br /&gt;
When booting, payloads on USB flash drives are given priority and will override payloads stored on the Signal Owl. To successfully copy a payload to the Signal Owl, the payload must be named &amp;lt;code&amp;gt;payload.txt&amp;lt;/code&amp;gt; or &amp;lt;code&amp;gt;payload.sh&amp;lt;/code&amp;gt; and it has to be placed in the &amp;lt;code&amp;gt;root&amp;lt;/code&amp;gt; directory of the flash drive. Similarly, payload extensions should be stored in a &amp;lt;code&amp;gt;/extensions&amp;lt;/code&amp;gt; directory on the flash drive. &lt;br /&gt;
&lt;br /&gt;
In addition, it is possible to transfer payloads and payload extensions to the device via the Signal Owl access point in arming mode using SSH. There they are stored in the &amp;lt;code&amp;gt;/root/payload&amp;lt;/code&amp;gt; directory and Payload Extensions are stored in the &amp;lt;code&amp;gt;/root/payload/extensions&amp;lt;/code&amp;gt; directory.&lt;br /&gt;
&lt;br /&gt;
== Payload Development ==&lt;br /&gt;
&lt;br /&gt;
Payloads for the Signal Owl are written in bash with [https://github.com/hak5darren/USB-Rubber-Ducky/wiki/Duckyscript Ducky Script] and can be created with any standard text editor. All payloads should begin with an interpreter directive, like the shebang &amp;lt;code&amp;gt;#!/bin/bash&amp;lt;/code&amp;gt; for bash payloads and payloads must be named either &amp;lt;code&amp;gt;payload.txt&amp;lt;/code&amp;gt; or &amp;lt;code&amp;gt;payload.sh&amp;lt;/code&amp;gt;. In order to create effective payloads, the Signal Owl comes with several preinstalled penetration testing tools. These are as follows: [https://nmap.org/ Nmap], [https://www.aircrack-ng.org/ Aircrack-ng], [https://github.com/aircrack-ng/mdk4 MDK4] and [https://www.kismetwireless.net/ Kismet].&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Tools&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
• Kismet - detector for wireless networks and devices.&lt;br /&gt;
&lt;br /&gt;
• MDK4 - Wi-Fi testing tool.&lt;br /&gt;
&lt;br /&gt;
• Aircrack-ng Suite - a complete suite of tools for WiFi network security assessment.&lt;br /&gt;
&lt;br /&gt;
• Nmap - open source utility for network discovery and security auditing.&lt;br /&gt;
&lt;br /&gt;
Hak5 offers ready-to-use payloads and payload extensions on their [https://github.com/hak5/signalowl-payloads GitHub repository].&lt;br /&gt;
&lt;br /&gt;
== Implant / mobile operations ==&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Implant operations&lt;br /&gt;
&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
During long term wireless engagements, the Signal Owl may be planted inline between any typical 5V USB power source. This may be useful in situations where ports are occupied, or to deter the unit from being unplugged.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Mobile operations&lt;br /&gt;
&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
The Signal Owl features a low power consumption profile, with a typical power draw averaging 100-200 mAh. Additionally, it is thermally optimized for long term deployments in many indoor environments. One can expect a large 20,000 mAh USB battery bank to operate the unit for up to 4 days.&lt;br /&gt;
&lt;br /&gt;
= Use Cases =&lt;br /&gt;
&lt;br /&gt;
The Signal Owl has a variety of different use cases. Among the most popular ones are classical network mapping and wardriving as well as basic penetration tests for different wireless technologies.&lt;br /&gt;
&lt;br /&gt;
== Fake Beacon Flooding Attack ==&lt;br /&gt;
&lt;br /&gt;
The Fake Beacon Flooding Attack is one possible use case for the Signal Owl. With that attack, fake beacon frames are broadcasted to nearby devices. Beacon Frames include various parameters like the SSID, the type of encryption used and timestamps. This results in the creation of multiple fake Wi-Fi networks. Devices with Wi-Fi browsers are then flooded with these fake networks, causing potential network scanner and driver crashes. Furthermore, the attack may prevent legitimate users from finding their networks and lead to denial of service. The preinstalled tools Aircrack-ng and MDK4 were used to create this payload. After powering on the device, multiple fake networks with random SSIDs are generated and broadcasted to all nearby devices.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;bash&amp;quot;&amp;gt;&lt;br /&gt;
#!/bin/bash&lt;br /&gt;
&lt;br /&gt;
LED SETUP&lt;br /&gt;
sleep 10&lt;br /&gt;
airmon-ng check kill&lt;br /&gt;
sleep 10&lt;br /&gt;
#creates monitor mode interface on wirelss card of the Signal Owl&lt;br /&gt;
airmon-ng start wlan0&lt;br /&gt;
sleep 10&lt;br /&gt;
LED ATTACK&lt;br /&gt;
#floods nearby devices with random SSIDs&lt;br /&gt;
mdk4 wlan0mon b -a -m -s 500&lt;br /&gt;
&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The results as seen from a victim running a Windows 10 system are pictured in the figure below.&lt;br /&gt;
&lt;br /&gt;
[[File:FakeBeaconFloodingSignalOwl.png|Random SSIDs as seen from a victim Windows 10 client]][Eigene Darstellung]&lt;br /&gt;
&lt;br /&gt;
== Open AP Nmap Scanner ==&lt;br /&gt;
&lt;br /&gt;
With the Open AP Nmap Scanner payload, the Signal Owl scans for open access points. If the Signal Owl finds one or more open access points, it connects to them and uses Nmap to scan and analyze them. The results are then stored in the loot directory. For each discovered open access point, the Signal Owl generates a separate results file. This payload has some settings which can be seen in the following listing.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;bash&amp;quot;&amp;gt;&lt;br /&gt;
NMAP_OPTIONS=&amp;quot;-sP&amp;quot;&lt;br /&gt;
LOOT_DIR=/root/loot/open_ap_nmap_scan&lt;br /&gt;
MAX_CIDR=20&lt;br /&gt;
DEBUG=1&lt;br /&gt;
&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
*NMAP_OPTIONS - Is used to specify the type of Nmap scan.&lt;br /&gt;
*LOOT_DIR - Sets the destination folder for the scan results.&lt;br /&gt;
*MAX_CIDR - Sets the maximum Classless Inter-Domain Routing&lt;br /&gt;
*DEBUG - Specifies if debug information is saved to the payload.log file in the tmp folder.&lt;br /&gt;
** 1 - Debug information is saved.&lt;br /&gt;
** 0 - Debug information is not saved.&lt;br /&gt;
&lt;br /&gt;
The results of a scan with this payload can be seen in the figure below.&lt;br /&gt;
&lt;br /&gt;
[[File:OpenAPNmapScannerResult.png|750px]][Eigene Darstellung]&lt;br /&gt;
&lt;br /&gt;
== Basic Bluetooth Scanner ==&lt;br /&gt;
&lt;br /&gt;
This payload requires an external Bluetooth adapter, since the Signal Owl does not have Bluetooth built in. The Basic Bluetooth Scanner scans for devices that have Bluetooth enabled and optionally queries them using the hcitool and the info command. This payload does also have some settings, as shown in the listing below.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;bash&amp;quot;&amp;gt;&lt;br /&gt;
LOOT_DIR=/root/loot/bluetooth_scan&lt;br /&gt;
BT_OUTFILE=`date +%s`.bt.list&lt;br /&gt;
BT_INFOFILE=`date +%s`.bt.info   &lt;br /&gt;
BTDEV=hci0&lt;br /&gt;
DEBUG=0 &lt;br /&gt;
INTERROGATE=1 &lt;br /&gt;
&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
*LOOT_DIR - Sets the directory for the scan result.&lt;br /&gt;
*BT_OUTFILE - Sets a file name, in which all detected names and MAC addresses are saved.&lt;br /&gt;
*BT_INFOFILE - Sets a file name, in which the details of the discovered devices are saved if the INTERROGATE variable is set to 1. &lt;br /&gt;
*BTDEV - Specifies the bluetooth device used for scanning.&lt;br /&gt;
*DEBUG - Specifies if debug information is saved to the payload.log file in the tmp folder.&lt;br /&gt;
** 1 - Debug information is saved.&lt;br /&gt;
** 0 - Debug information is not saved.&lt;br /&gt;
*INTERROGATE - Specifies if the detected devices are interrogated.&lt;br /&gt;
** 1 - Detected devices are interrogated&lt;br /&gt;
** 0 - Detected devices are not interrogated&lt;br /&gt;
&lt;br /&gt;
After a successful scan, all detected devices are listed with their names and MAC addresses in the file specified by &amp;lt;code&amp;gt;BT_OUTFILE&amp;lt;/code&amp;gt;. If &amp;lt;code&amp;gt;INTERROGATE&amp;lt;/code&amp;gt; has been set to 1, a &amp;lt;code&amp;gt;.info&amp;lt;/code&amp;gt; file is generated that lists additional details about each scanned device.&lt;br /&gt;
&lt;br /&gt;
== WiFi Connect ==&lt;br /&gt;
&lt;br /&gt;
With the WiFi Connect payload, which can be seen in the following Listing, and the wificonnect.sh Payload extension, the Signal Owl can be connected to a nearby network. The SSID and password of the network to which the Signal Owl should connect must be specified in the code. Optionally, the SSH server of the device can be started by removing the hash sign in the code before the corresponding command. &lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;bash&amp;quot;&amp;gt;&lt;br /&gt;
#!/bin/bash&lt;br /&gt;
&lt;br /&gt;
# WiFi Client Setup&lt;br /&gt;
WIFI_SSID=&amp;quot;network-name&amp;quot;&lt;br /&gt;
WIFI_PASS=&amp;quot;passphrase&amp;quot;&lt;br /&gt;
&lt;br /&gt;
LED SETUP&lt;br /&gt;
WIFI_CONNECT&lt;br /&gt;
# optionally start SSH server&lt;br /&gt;
# /etc/init.d/sshd start&lt;br /&gt;
LED ATTACK&lt;br /&gt;
&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The &amp;lt;code&amp;gt;WIFI_CONNECT&amp;lt;/code&amp;gt; command executes the wifi_connect.sh payload extension, which is shown in the following listing. &lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;bash&amp;quot;&amp;gt;&lt;br /&gt;
#!/bin/bash&lt;br /&gt;
&lt;br /&gt;
function WIFI_CONNECT() {&lt;br /&gt;
    [[ &amp;quot;x$WIFI_INT&amp;quot; == &amp;quot;x&amp;quot; ]] &amp;amp;&amp;amp; WIFI_INT=wlan0&lt;br /&gt;
    ifconfig $WIFI_INT up;sleep 10&lt;br /&gt;
    echo -e &amp;quot;network={\nssid=\&amp;quot;$WIFI_SSID\&amp;quot;\npsk=\&amp;quot;$WIFI_PASS\&amp;quot;\npriority=1\n}&amp;quot;&amp;gt;/tmp/wpa-$WIFI_INT.conf&lt;br /&gt;
    wpa_supplicant -B -Dnl80211 -i $WIFI_INT -c /tmp/wpa-$WIFI_INT.conf&lt;br /&gt;
    while(iwconfig $WIFI_INT | grep Not-Associated); do sleep 1; done&lt;br /&gt;
    udhcpc -i $WIFI_INT&lt;br /&gt;
}&lt;br /&gt;
export -f WIFI_CONNECT&lt;br /&gt;
&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The payload extension code uses the &amp;lt;code&amp;gt;WIFI_SSID&amp;lt;/code&amp;gt; and &amp;lt;code&amp;gt;WIFI_PASS&amp;lt;/code&amp;gt; variables of the payload to connect the Signal Owl to the network. With the command &amp;lt;code&amp;gt;export -f WIFI_CONNECT&amp;lt;/code&amp;gt; the function &amp;lt;code&amp;gt;WIFI_CONNECT&amp;lt;/code&amp;gt; is exported so that it can be called from the payload. &lt;br /&gt;
&lt;br /&gt;
If the SSH server is enabled, any SSH-enabled device can connect to the Signal Owl over the network, even though Attack Mode is enabled. The [[#Default Settings|default settings]] of the device can be used again for the connection, if they have not been changed yet. However, the IP address in this case is the IP address of the Signal Owl in this network.&lt;br /&gt;
&lt;br /&gt;
= Used Hardware =&lt;br /&gt;
&lt;br /&gt;
[[Signal Owl]]&lt;br /&gt;
&lt;br /&gt;
= References =&lt;br /&gt;
&lt;br /&gt;
*https://docs.hak5.org/signal-owl/&lt;br /&gt;
*https://github.com/hak5/signalowl-payloads&lt;br /&gt;
&lt;br /&gt;
[[Category:Pentesting]]&lt;/div&gt;</summary>
		<author><name>MMayer</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=Hak5_Signal_Owl&amp;diff=10921</id>
		<title>Hak5 Signal Owl</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=Hak5_Signal_Owl&amp;diff=10921"/>
		<updated>2023-01-08T15:08:32Z</updated>

		<summary type="html">&lt;p&gt;MMayer: /* Basic Bluetooth Scanner */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= Introduction =&lt;br /&gt;
&lt;br /&gt;
The [https://docs.hak5.org/signal-owl/ Signal Owl] is a hardware product developed by the company [https://shop.hak5.org/ Hak5].&lt;br /&gt;
It is a simple payload-based signals intelligence platform with a unique design for discreet planting or mobile operations on any engagement. The most popular application cases include classic network mapping and basic penetration tests for various wireless technologies.&lt;br /&gt;
&lt;br /&gt;
== Initial Setup ==&lt;br /&gt;
&lt;br /&gt;
When first unboxing the Signal Owl, the device runs a stager firmware that is designed to flash the latest firmware from a USB flash drive. In order to update the Signal Owl, the [https://downloads.hak5.org/owl latest firmware] has to be downloaded. Then, the downloaded file must be copied to the root of an EXT4 or FAT32 formatted USB flash drive. It is important not to modify this file. The next step is to plug the USB flash drive into the powered off Signal Owl. Afterwards, the device has to be powered on by a reliable USB source. The upgrade itself takes approximately five to ten minutes and is indicated by a solid red LED light. When finished, the device will reboot, enter Attack Mode and blink slowly, indicating an error running the payload because no payload has been found.&lt;br /&gt;
&lt;br /&gt;
= Hardware =&lt;br /&gt;
&lt;br /&gt;
[[File:SignalOwlDiagram.png|thumb|500px|frame|Components of the Signal Owl [Eigene Darstellung]]] &lt;br /&gt;
&lt;br /&gt;
The Signal Owl is designed to be rapidly deployed in all kinds of environments, allowing it to be an entry point for network analysis and basic wireless attacks in a variety of locations. With a power consumption of 100-200 mAh and the thermally optimized architecture, mobile operations as well as long term deployments, are enabled.&lt;br /&gt;
&lt;br /&gt;
== Components ==&lt;br /&gt;
&lt;br /&gt;
This device features several components of which some may not be visible to the human eye at first sight.&lt;br /&gt;
&lt;br /&gt;
=== USB Power / Passthrough Plug ===&lt;br /&gt;
&lt;br /&gt;
The USB power or passthrough plug is used to power the device. It can be powered from any reliable USB source.&lt;br /&gt;
&lt;br /&gt;
=== USB 2.0 Passthrough Port ===&lt;br /&gt;
&lt;br /&gt;
The USB 2.0 passthrough port is the port closest to the pigtail. Data and power pass through to that port, allowing for implant operations. If a device such as a keyboard is plugged in between this passthrough port and the power plug is connected to the target computer, the Signal Owl will remain undetected by the operating system. Only the keyboard will be visible on the target computer.&lt;br /&gt;
&lt;br /&gt;
=== USB 2.0 Host Port ===&lt;br /&gt;
&lt;br /&gt;
The USB 2.0 host port is the port farthest away from the pigtail. It is connected to the Linux socket of the Signal Owl and supports USB flash drives formatted with FAT32 and EXT4 file systems as well as many Wi-Fi, Bluetooth and other RF transceivers.&lt;br /&gt;
&lt;br /&gt;
=== Button ===&lt;br /&gt;
&lt;br /&gt;
The button on the bottom of the device is used to enter Arming Mode and to interact with payloads. It is not pressable without special tools like paperclips.&lt;br /&gt;
&lt;br /&gt;
=== Status LED ===&lt;br /&gt;
&lt;br /&gt;
The status LED indicates the current status of the Signal Owl. When it is turned off, it is not visible.&lt;br /&gt;
&lt;br /&gt;
The Signal Owl features a red LED with the following default status indications:&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
!|LED&lt;br /&gt;
!|Status&lt;br /&gt;
|-&lt;br /&gt;
|Blinking&lt;br /&gt;
|Booting&lt;br /&gt;
|-&lt;br /&gt;
|Solid&lt;br /&gt;
|Mounting external storage / Running upgrade&lt;br /&gt;
|-&lt;br /&gt;
|Single blinking&lt;br /&gt;
|Attack Mode&lt;br /&gt;
|-&lt;br /&gt;
|Double blinking&lt;br /&gt;
|Arming Mode&lt;br /&gt;
|-&lt;br /&gt;
|Slow blinking&lt;br /&gt;
|Error running payload&lt;br /&gt;
|-&lt;br /&gt;
|Fast blinking&lt;br /&gt;
|Select Mode (Deprecated from version 1.0.1 onward)&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= Software =&lt;br /&gt;
&lt;br /&gt;
== Modes of Operation ==&lt;br /&gt;
&lt;br /&gt;
The Signal Owl comes with two modes of operation, Attack Mode and Arming Mode. By default, the device will boot into Attack Mode. In order to access Arming Mode, the button on the bottom of the device has to be pressed while in Attack Mode. It is not recommended to press the button during the boot sequence, as this can possibly brick the device and render it useless. The arming mode is used for firmware updates and shell access, while the attack mode is used to load and execute the payload.&lt;br /&gt;
&lt;br /&gt;
=== Attack Mode ===&lt;br /&gt;
&lt;br /&gt;
Attack Mode is the default mode, the Signal Owl boots into. It provides two basic functions, being the payload loading function and the payload execution function. &lt;br /&gt;
&lt;br /&gt;
The payload loading function checks for any USB flash drives plugged into the host port of the device and copies payloads to &amp;lt;code&amp;gt;/root/payload&amp;lt;/code&amp;gt; and extensions to &amp;lt;code&amp;gt;/root/payload/extensions&amp;lt;/code&amp;gt; on the Signal Owl. &lt;br /&gt;
&lt;br /&gt;
The payload execution function is responsible for executing the payload that is currently stored on the root of the Signal Owl. In case no payload is found, the device will blink slowly, indicating the FAIL status.&lt;br /&gt;
&lt;br /&gt;
=== Arming Mode ===&lt;br /&gt;
&lt;br /&gt;
The Arming Mode provides two basic functions, being the firmware update function and the shell access function. The firmware update function checks for any USB flash drives plugged into the host port of the device and copies firmware upgrade files into the internal storage of the device and flashes it. The shell access function starts an open access point with the SSID Owl_xxxx in which xxxx indicates the last two octets of the device&#039;s MAC address. Additionally, a SSH server providing access to the shell of the Signal Owl is enabled.&lt;br /&gt;
&lt;br /&gt;
== Default Settings ==&lt;br /&gt;
&lt;br /&gt;
Default settings that are used in order to access the device via SSH are pictured in the table below.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
!colspan=&amp;quot;2&amp;quot;|Default Settings&lt;br /&gt;
|-&lt;br /&gt;
|Username&lt;br /&gt;
|root&lt;br /&gt;
|-&lt;br /&gt;
|Password&lt;br /&gt;
|hak5owl&lt;br /&gt;
|-&lt;br /&gt;
|SSID&lt;br /&gt;
|Owl_xxxx&lt;br /&gt;
|-&lt;br /&gt;
|IP Address&lt;br /&gt;
|172.16.56.1&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
SSH command: &amp;lt;code&amp;gt;ssh root@172.16.56.1&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The SSID during Arming Mode is Owl_xxxx in which xxxx indicates the last two octets of the devices MAC address.&lt;br /&gt;
&lt;br /&gt;
= Usage =&lt;br /&gt;
&lt;br /&gt;
== Arming Mode connection ==&lt;br /&gt;
&lt;br /&gt;
Step-by-step guide for accessing the arming mode&lt;br /&gt;
&lt;br /&gt;
#Click on the button located on the bottom of the Signal Owl while it is in attack mode. After pressing the button, the signal owl enters the arming mode and provides an open access point with the name Owl xxxx (where xxxx stands for the last two digits of the MAC address of the device).&lt;br /&gt;
#Connect to the access point.&amp;lt;br&amp;gt;[[File:Armingmode.png]][Eigene Darstellung]&lt;br /&gt;
#Now you can connect via ssh by using the [[#Default Settings|default settings]].&lt;br /&gt;
#After successful connection, you will end up in the root directory.&amp;lt;br&amp;gt;[[File:ArmingmodeSSH.png]][Eigene Darstellung]&lt;br /&gt;
#Now you can change the files and directories on the Signal Owl to view results, transfer payloads and extensions or to make further changes.&lt;br /&gt;
&lt;br /&gt;
== Directory structure ==&lt;br /&gt;
&lt;br /&gt;
The following directory tree shows the directory structure of the Signal Owl.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
/&lt;br /&gt;
├── loot&lt;br /&gt;
└── payload/&lt;br /&gt;
    └── extensions&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
*Loot - Directory where the Signal Owl saves loot while executing payloads that produce loot.&lt;br /&gt;
*Payload - This directory holds the current payload. &lt;br /&gt;
*Extensions -  This directory holds all extensions.&lt;br /&gt;
&lt;br /&gt;
== Adding Payloads and Extensions ==&lt;br /&gt;
&lt;br /&gt;
Adding a payload can be done in two different ways. Either with a USB flash drive or via the Signal Owl access point to the internal storage of the device. &lt;br /&gt;
&lt;br /&gt;
When booting, payloads on USB flash drives are given priority and will override payloads stored on the Signal Owl. To successfully copy a payload to the Signal Owl, the payload must be named &amp;lt;code&amp;gt;payload.txt&amp;lt;/code&amp;gt; or &amp;lt;code&amp;gt;payload.sh&amp;lt;/code&amp;gt; and it has to be placed in the &amp;lt;code&amp;gt;root&amp;lt;/code&amp;gt; directory of the flash drive. Similarly, payload extensions should be stored in a &amp;lt;code&amp;gt;/extensions&amp;lt;/code&amp;gt; directory on the flash drive. &lt;br /&gt;
&lt;br /&gt;
In addition, it is possible to transfer payloads and payload extensions to the device via the Signal Owl access point in arming mode using SSH. There they are stored in the &amp;lt;code&amp;gt;/root/payload&amp;lt;/code&amp;gt; directory and Payload Extensions are stored in the &amp;lt;code&amp;gt;/root/payload/extensions&amp;lt;/code&amp;gt; directory.&lt;br /&gt;
&lt;br /&gt;
== Payload Development ==&lt;br /&gt;
&lt;br /&gt;
Payloads for the Signal Owl are written in bash with [https://github.com/hak5darren/USB-Rubber-Ducky/wiki/Duckyscript Ducky Script] and can be created with any standard text editor. All payloads should begin with an interpreter directive, like the shebang &amp;lt;code&amp;gt;#!/bin/bash&amp;lt;/code&amp;gt; for bash payloads and payloads must be named either &amp;lt;code&amp;gt;payload.txt&amp;lt;/code&amp;gt; or &amp;lt;code&amp;gt;payload.sh&amp;lt;/code&amp;gt;. In order to create effective payloads, the Signal Owl comes with several preinstalled penetration testing tools. These are as follows: [https://nmap.org/ Nmap], [https://www.aircrack-ng.org/ Aircrack-ng], [https://github.com/aircrack-ng/mdk4 MDK4] and [https://www.kismetwireless.net/ Kismet].&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Tools&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
• Kismet - detector for wireless networks and devices.&lt;br /&gt;
&lt;br /&gt;
• MDK4 - Wi-Fi testing tool.&lt;br /&gt;
&lt;br /&gt;
• Aircrack-ng Suite - a complete suite of tools for WiFi network security assessment.&lt;br /&gt;
&lt;br /&gt;
• Nmap - open source utility for network discovery and security auditing.&lt;br /&gt;
&lt;br /&gt;
Hak5 offers ready-to-use payloads and payload extensions on their [https://github.com/hak5/signalowl-payloads GitHub repository].&lt;br /&gt;
&lt;br /&gt;
== Implant / mobile operations ==&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Implant operations&lt;br /&gt;
&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
During long term wireless engagements, the Signal Owl may be planted inline between any typical 5V USB power source. This may be useful in situations where ports are occupied, or to deter the unit from being unplugged.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Mobile operations&lt;br /&gt;
&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
The Signal Owl features a low power consumption profile, with a typical power draw averaging 100-200 mAh. Additionally, it is thermally optimized for long term deployments in many indoor environments. One can expect a large 20,000 mAh USB battery bank to operate the unit for up to 4 days.&lt;br /&gt;
&lt;br /&gt;
= Use Cases =&lt;br /&gt;
&lt;br /&gt;
The Signal Owl has a variety of different use cases. Among the most popular ones are classical network mapping and wardriving as well as basic penetration tests for different wireless technologies.&lt;br /&gt;
&lt;br /&gt;
== Fake Beacon Flooding Attack ==&lt;br /&gt;
&lt;br /&gt;
The Fake Beacon Flooding Attack is one possible use case for the Signal Owl. With that attack, fake beacon frames are broadcasted to nearby devices. Beacon Frames include various parameters like the SSID, the type of encryption used and timestamps. This results in the creation of multiple fake Wi-Fi networks. Devices with Wi-Fi browsers are then flooded with these fake networks, causing potential network scanner and driver crashes. Furthermore, the attack may prevent legitimate users from finding their networks and lead to denial of service. The preinstalled tools Aircrack-ng and MDK4 were used to create this payload. After powering on the device, multiple fake networks with random SSIDs are generated and broadcasted to all nearby devices.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;bash&amp;quot;&amp;gt;&lt;br /&gt;
#!/bin/bash&lt;br /&gt;
&lt;br /&gt;
LED SETUP&lt;br /&gt;
sleep 10&lt;br /&gt;
airmon-ng check kill&lt;br /&gt;
sleep 10&lt;br /&gt;
#creates monitor mode interface on wirelss card of the Signal Owl&lt;br /&gt;
airmon-ng start wlan0&lt;br /&gt;
sleep 10&lt;br /&gt;
LED ATTACK&lt;br /&gt;
#floods nearby devices with random SSIDs&lt;br /&gt;
mdk4 wlan0mon b -a -m -s 500&lt;br /&gt;
&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The results as seen from a victim running a Windows 10 system are pictured in the figure below.&lt;br /&gt;
&lt;br /&gt;
[[File:FakeBeaconFloodingSignalOwl.png|Random SSIDs as seen from a victim Windows 10 client]][Eigene Darstellung]&lt;br /&gt;
&lt;br /&gt;
== Open AP Nmap Scanner ==&lt;br /&gt;
&lt;br /&gt;
With the Open AP Nmap Scanner payload, the Signal Owl scans for open access points. If the Signal Owl finds one or more open access points, it connects to them and uses Nmap to scan and analyze them. The results are then stored in the loot directory. For each discovered open access point, the Signal Owl generates a separate results file. This payload has some settings which can be seen in the following listing.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;bash&amp;quot;&amp;gt;&lt;br /&gt;
NMAP_OPTIONS=&amp;quot;-sP&amp;quot;&lt;br /&gt;
LOOT_DIR=/root/loot/open_ap_nmap_scan&lt;br /&gt;
MAX_CIDR=20&lt;br /&gt;
DEBUG=1&lt;br /&gt;
&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
*NMAP_OPTIONS - Is used to specify the type of Nmap scan.&lt;br /&gt;
*LOOT_DIR - Sets the destination folder for the scan results.&lt;br /&gt;
*MAX_CIDR - Sets the maximum Classless Inter-Domain Routing&lt;br /&gt;
*DEBUG - Specifies if debug information is saved to the payload.log file in the tmp folder.&lt;br /&gt;
** 1 - Debug information is saved.&lt;br /&gt;
** 0 - Debug information is not saved.&lt;br /&gt;
&lt;br /&gt;
The results of a scan with this payload can be seen in the figure below.&lt;br /&gt;
&lt;br /&gt;
[[File:OpenAPNmapScannerResult.png|750px]][Eigene Darstellung]&lt;br /&gt;
&lt;br /&gt;
== Basic Bluetooth Scanner ==&lt;br /&gt;
&lt;br /&gt;
This payload requires an external Bluetooth adapter, since the Signal Owl does not have Bluetooth built in. The Basic Bluetooth Scanner scans for devices that have Bluetooth enabled and optionally queries them using the hcitool and the info command. This payload does also have some settings, as shown in the listing below.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;bash&amp;quot;&amp;gt;&lt;br /&gt;
LOOT_DIR=/root/loot/bluetooth_scan&lt;br /&gt;
BT_OUTFILE=`date +%s`.bt.list&lt;br /&gt;
BT_INFOFILE=`date +%s`.bt.info   &lt;br /&gt;
BTDEV=hci0&lt;br /&gt;
DEBUG=0 &lt;br /&gt;
INTERROGATE=1 &lt;br /&gt;
&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
*LOOT_DIR - Sets the directory for the scan result.&lt;br /&gt;
*BT_OUTFILE - Sets a file name, in which all detected names and MAC addresses are saved.&lt;br /&gt;
*BT_INFOFILE - Sets a file name, in which the details of the discovered devices are saved if the INTERROGATE variable is set to 1. &lt;br /&gt;
*BTDEV - Specifies the bluetooth device used for scanning.&lt;br /&gt;
*DEBUG - Specifies if debug information is saved to the payload.log file in the tmp folder.&lt;br /&gt;
** 1 - Debug information is saved.&lt;br /&gt;
** 0 - Debug information is not saved.&lt;br /&gt;
*INTERROGATE - Specifies if the detected devices are interrogated.&lt;br /&gt;
** 1 - Detected devices are interrogated&lt;br /&gt;
** 0 - Detected devices are not interrogated&lt;br /&gt;
&lt;br /&gt;
After a successful scan, all detected devices are listed with their names and MAC addresses in the file specified by &amp;lt;code&amp;gt;BT_OUTFILE&amp;lt;/code&amp;gt;. If &amp;lt;code&amp;gt;INTERROGATE&amp;lt;/code&amp;gt; has been set to 1, a &amp;lt;code&amp;gt;.info&amp;lt;/code&amp;gt; file is generated that lists additional details about each scanned device.&lt;br /&gt;
&lt;br /&gt;
== WiFi Connect ==&lt;br /&gt;
&lt;br /&gt;
With the WiFi Connect payload, which can be seen in the following Listing, and the wificonnect.sh Payload extension, the Signal Owl can be connected to a nearby network. The SSID and password of the network to which the Signal Owl should connect must be specified in the code. Optionally, the SSH server of the device can be started by removing the hash sign in the code before the corresponding command. &lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;bash&amp;quot;&amp;gt;&lt;br /&gt;
#!/bin/bash&lt;br /&gt;
&lt;br /&gt;
# WiFi Client Setup&lt;br /&gt;
WIFI_SSID=&amp;quot;network-name&amp;quot;&lt;br /&gt;
WIFI_PASS=&amp;quot;passphrase&amp;quot;&lt;br /&gt;
&lt;br /&gt;
LED SETUP&lt;br /&gt;
WIFI_CONNECT&lt;br /&gt;
# optionally start SSH server&lt;br /&gt;
# /etc/init.d/sshd start&lt;br /&gt;
LED ATTACK&lt;br /&gt;
&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The &amp;lt;code&amp;gt;WIFI_CONNECT&amp;lt;/code&amp;gt; command executes the wifi_connect.sh payload extension, which is shown in the following listing. &lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;bash&amp;quot;&amp;gt;&lt;br /&gt;
#!/bin/bash&lt;br /&gt;
&lt;br /&gt;
function WIFI_CONNECT() {&lt;br /&gt;
    [[ &amp;quot;x$WIFI_INT&amp;quot; == &amp;quot;x&amp;quot; ]] &amp;amp;&amp;amp; WIFI_INT=wlan0&lt;br /&gt;
    ifconfig $WIFI_INT up;sleep 10&lt;br /&gt;
    echo -e &amp;quot;network={\nssid=\&amp;quot;$WIFI_SSID\&amp;quot;\npsk=\&amp;quot;$WIFI_PASS\&amp;quot;\npriority=1\n}&amp;quot;&amp;gt;/tmp/wpa-$WIFI_INT.conf&lt;br /&gt;
    wpa_supplicant -B -Dnl80211 -i $WIFI_INT -c /tmp/wpa-$WIFI_INT.conf&lt;br /&gt;
    while(iwconfig $WIFI_INT | grep Not-Associated); do sleep 1; done&lt;br /&gt;
    udhcpc -i $WIFI_INT&lt;br /&gt;
}&lt;br /&gt;
export -f WIFI_CONNECT&lt;br /&gt;
&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The payload extension code uses the &amp;lt;code&amp;gt;WIFI_SSID&amp;lt;/code&amp;gt; and &amp;lt;code&amp;gt;WIFI_PASS&amp;lt;/code&amp;gt; variables of the payload to connect the Signal Owl to the network. With the command &amp;lt;code&amp;gt;export -f WIFI_CONNECT&amp;lt;/code&amp;gt; the function &amp;lt;code&amp;gt;WIFI_CONNECT&amp;lt;/code&amp;gt; is exported so that it can be called from the payload. &lt;br /&gt;
&lt;br /&gt;
If the SSH server is enabled, any SSH-enabled device can connect to the Signal Owl over the network, even though Attack Mode is enabled. The [[#Default Settings|default settings]] of the device can be used again for the connection, if they have not been changed yet. However, the IP address in this case is the IP address of the Signal Owl in this network.&lt;br /&gt;
&lt;br /&gt;
= Used Hardware =&lt;br /&gt;
&lt;br /&gt;
[[Signal Owl]]&lt;br /&gt;
&lt;br /&gt;
= References =&lt;br /&gt;
&lt;br /&gt;
*https://docs.hak5.org/signal-owl/&lt;br /&gt;
*https://github.com/hak5/signalowl-payloads&lt;br /&gt;
&lt;br /&gt;
[[Category:Pentesting]]&lt;/div&gt;</summary>
		<author><name>MMayer</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=File:FakeBeaconFloodingSignalOwl.png&amp;diff=10736</id>
		<title>File:FakeBeaconFloodingSignalOwl.png</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=File:FakeBeaconFloodingSignalOwl.png&amp;diff=10736"/>
		<updated>2023-01-07T02:35:57Z</updated>

		<summary type="html">&lt;p&gt;MMayer: MMayer uploaded a new version of File:FakeBeaconFloodingSignalOwl.png&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;/div&gt;</summary>
		<author><name>MMayer</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=Hak5_Signal_Owl&amp;diff=10735</id>
		<title>Hak5 Signal Owl</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=Hak5_Signal_Owl&amp;diff=10735"/>
		<updated>2023-01-07T02:33:34Z</updated>

		<summary type="html">&lt;p&gt;MMayer: /* Fake Beacon Flooding Attack */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= Introduction =&lt;br /&gt;
&lt;br /&gt;
The [https://docs.hak5.org/signal-owl/ Signal Owl] is a hardware product developed by the company [https://shop.hak5.org/ Hak5].&lt;br /&gt;
It is a simple payload-based signals intelligence platform with a unique design for discreet planting or mobile operations on any engagement. The most popular application cases include classic network mapping and basic penetration tests for various wireless technologies.&lt;br /&gt;
&lt;br /&gt;
== Initial Setup ==&lt;br /&gt;
&lt;br /&gt;
When first unboxing the Signal Owl, the device runs a stager firmware that is designed to flash the latest firmware from a USB flash drive. In order to update the Signal Owl, the [https://downloads.hak5.org/owl latest firmware] has to be downloaded. Then, the downloaded file must be copied to the root of an EXT4 or FAT32 formatted USB flash drive. It is important not to modify this file. The next step is to plug the USB flash drive into the powered off Signal Owl. Afterwards, the device has to be powered on by a reliable USB source. The upgrade itself takes approximately five to ten minutes and is indicated by a solid red LED light. When finished, the device will reboot, enter Attack Mode and blink slowly, indicating an error running the payload because no payload has been found.&lt;br /&gt;
&lt;br /&gt;
= Hardware =&lt;br /&gt;
&lt;br /&gt;
[[File:SignalOwlDiagram.png|thumb|500px|frame|Components of the Signal Owl [Eigene Darstellung]]] &lt;br /&gt;
&lt;br /&gt;
The Signal Owl is designed to be rapidly deployed in all kinds of environments, allowing it to be an entry point for network analysis and basic wireless attacks in a variety of locations. With a power consumption of 100-200 mAh and the thermally optimized architecture, mobile operations as well as long term deployments, are enabled.&lt;br /&gt;
&lt;br /&gt;
== Components ==&lt;br /&gt;
&lt;br /&gt;
This device features several components of which some may not be visible to the human eye at first sight.&lt;br /&gt;
&lt;br /&gt;
=== USB Power / Passthrough Plug ===&lt;br /&gt;
&lt;br /&gt;
The USB power or passthrough plug is used to power the device. It can be powered from any reliable USB source.&lt;br /&gt;
&lt;br /&gt;
=== USB 2.0 Passthrough Port ===&lt;br /&gt;
&lt;br /&gt;
The USB 2.0 passthrough port is the port closest to the pigtail. Data and power pass through to that port, allowing for implant operations. If a device such as a keyboard is plugged in between this passthrough port and the power plug is connected to the target computer, the Signal Owl will remain undetected by the operating system. Only the keyboard will be visible on the target computer.&lt;br /&gt;
&lt;br /&gt;
=== USB 2.0 Host Port ===&lt;br /&gt;
&lt;br /&gt;
The USB 2.0 host port is the port farthest away from the pigtail. It is connected to the Linux socket of the Signal Owl and supports USB flash drives formatted with FAT32 and EXT4 file systems as well as many Wi-Fi, Bluetooth and other RF transceivers.&lt;br /&gt;
&lt;br /&gt;
=== Button ===&lt;br /&gt;
&lt;br /&gt;
The button on the bottom of the device is used to enter Arming Mode and to interact with payloads. It is not pressable without special tools like paperclips.&lt;br /&gt;
&lt;br /&gt;
=== Status LED ===&lt;br /&gt;
&lt;br /&gt;
The status LED indicates the current status of the Signal Owl. When it is turned off, it is not visible.&lt;br /&gt;
&lt;br /&gt;
The Signal Owl features a red LED with the following default status indications:&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
!|LED&lt;br /&gt;
!|Status&lt;br /&gt;
|-&lt;br /&gt;
|Blinking&lt;br /&gt;
|Booting&lt;br /&gt;
|-&lt;br /&gt;
|Solid&lt;br /&gt;
|Mounting external storage / Running upgrade&lt;br /&gt;
|-&lt;br /&gt;
|Single blinking&lt;br /&gt;
|Attack Mode&lt;br /&gt;
|-&lt;br /&gt;
|Double blinking&lt;br /&gt;
|Arming Mode&lt;br /&gt;
|-&lt;br /&gt;
|Slow blinking&lt;br /&gt;
|Error running payload&lt;br /&gt;
|-&lt;br /&gt;
|Fast blinking&lt;br /&gt;
|Select Mode (Deprecated from version 1.0.1 onward)&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= Software =&lt;br /&gt;
&lt;br /&gt;
== Modes of Operation ==&lt;br /&gt;
&lt;br /&gt;
The Signal Owl comes with two modes of operation, Attack Mode and Arming Mode. By default, the device will boot into Attack Mode. In order to access Arming Mode, the button on the bottom of the device has to be pressed while in Attack Mode. It is not recommended to press the button during the boot sequence, as this can possibly brick the device and render it useless. The arming mode is used for firmware updates and shell access, while the attack mode is used to load and execute the payload.&lt;br /&gt;
&lt;br /&gt;
=== Attack Mode ===&lt;br /&gt;
&lt;br /&gt;
Attack Mode is the default mode, the Signal Owl boots into. It provides two basic functions, being the payload loading function and the payload execution function. &lt;br /&gt;
&lt;br /&gt;
The payload loading function checks for any USB flash drives plugged into the host port of the device and copies payloads to &amp;lt;code&amp;gt;/root/payload&amp;lt;/code&amp;gt; and extensions to &amp;lt;code&amp;gt;/root/payload/extensions&amp;lt;/code&amp;gt; on the Signal Owl. &lt;br /&gt;
&lt;br /&gt;
The payload execution function is responsible for executing the payload that is currently stored on the root of the Signal Owl. In case no payload is found, the device will blink slowly, indicating the FAIL status.&lt;br /&gt;
&lt;br /&gt;
=== Arming Mode ===&lt;br /&gt;
&lt;br /&gt;
The Arming Mode provides two basic functions, being the firmware update function and the shell access function. The firmware update function checks for any USB flash drives plugged into the host port of the device and copies firmware upgrade files into the internal storage of the device and flashes it. The shell access function starts an open access point with the SSID Owl_xxxx in which xxxx indicates the last two octets of the device&#039;s MAC address. Additionally, a SSH server providing access to the shell of the Signal Owl is enabled.&lt;br /&gt;
&lt;br /&gt;
== Default Settings ==&lt;br /&gt;
&lt;br /&gt;
Default settings that are used in order to access the device via SSH are pictured in the table below.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
!colspan=&amp;quot;2&amp;quot;|Default Settings&lt;br /&gt;
|-&lt;br /&gt;
|Username&lt;br /&gt;
|root&lt;br /&gt;
|-&lt;br /&gt;
|Password&lt;br /&gt;
|hak5owl&lt;br /&gt;
|-&lt;br /&gt;
|SSID&lt;br /&gt;
|Owl_xxxx&lt;br /&gt;
|-&lt;br /&gt;
|IP Address&lt;br /&gt;
|172.16.56.1&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
SSH command: &amp;lt;code&amp;gt;ssh root@172.16.56.1&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The SSID during Arming Mode is Owl_xxxx in which xxxx indicates the last two octets of the devices MAC address.&lt;br /&gt;
&lt;br /&gt;
= Usage =&lt;br /&gt;
&lt;br /&gt;
== Arming Mode connection ==&lt;br /&gt;
&lt;br /&gt;
Step-by-step guide for accessing the arming mode&lt;br /&gt;
&lt;br /&gt;
#Click on the button located on the bottom of the Signal Owl while it is in attack mode. After pressing the button, the signal owl enters the arming mode and provides an open access point with the name Owl xxxx (where xxxx stands for the last two digits of the MAC address of the device).&lt;br /&gt;
#Connect to the access point.&amp;lt;br&amp;gt;[[File:Armingmode.png]][Eigene Darstellung]&lt;br /&gt;
#Now you can connect via ssh by using the [[#Default Settings|default settings]].&lt;br /&gt;
#After successful connection, you will end up in the root directory.&amp;lt;br&amp;gt;[[File:ArmingmodeSSH.png]][Eigene Darstellung]&lt;br /&gt;
#Now you can change the files and directories on the Signal Owl to view results, transfer payloads and extensions or to make further changes.&lt;br /&gt;
&lt;br /&gt;
== Directory structure ==&lt;br /&gt;
&lt;br /&gt;
The following directory tree shows the directory structure of the Signal Owl.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
/&lt;br /&gt;
├── loot&lt;br /&gt;
└── payload/&lt;br /&gt;
    └── extensions&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
*Loot - Directory where the Signal Owl saves loot while executing payloads that produce loot.&lt;br /&gt;
*Payload - This directory holds the current payload. &lt;br /&gt;
*Extensions -  This directory holds all extensions.&lt;br /&gt;
&lt;br /&gt;
== Adding Payloads and Extensions ==&lt;br /&gt;
&lt;br /&gt;
Adding a payload can be done in two different ways. Either with a USB flash drive or via the Signal Owl access point to the internal storage of the device. &lt;br /&gt;
&lt;br /&gt;
When booting, payloads on USB flash drives are given priority and will override payloads stored on the Signal Owl. To successfully copy a payload to the Signal Owl, the payload must be named &amp;lt;code&amp;gt;payload.txt&amp;lt;/code&amp;gt; or &amp;lt;code&amp;gt;payload.sh&amp;lt;/code&amp;gt; and it has to be placed in the &amp;lt;code&amp;gt;root&amp;lt;/code&amp;gt; directory of the flash drive. Similarly, payload extensions should be stored in a &amp;lt;code&amp;gt;/extensions&amp;lt;/code&amp;gt; directory on the flash drive. &lt;br /&gt;
&lt;br /&gt;
In addition, it is possible to transfer payloads and payload extensions to the device via the Signal Owl access point in arming mode using SSH. There they are stored in the &amp;lt;code&amp;gt;/root/payload&amp;lt;/code&amp;gt; directory and Payload Extensions are stored in the &amp;lt;code&amp;gt;/root/payload/extensions&amp;lt;/code&amp;gt; directory.&lt;br /&gt;
&lt;br /&gt;
== Payload Development ==&lt;br /&gt;
&lt;br /&gt;
Payloads for the Signal Owl are written in bash with [https://github.com/hak5darren/USB-Rubber-Ducky/wiki/Duckyscript Ducky Script] and can be created with any standard text editor. All payloads should begin with an interpreter directive, like the shebang &amp;lt;code&amp;gt;#!/bin/bash&amp;lt;/code&amp;gt; for bash payloads and payloads must be named either &amp;lt;code&amp;gt;payload.txt&amp;lt;/code&amp;gt; or &amp;lt;code&amp;gt;payload.sh&amp;lt;/code&amp;gt;. In order to create effective payloads, the Signal Owl comes with several preinstalled penetration testing tools. These are as follows: [https://nmap.org/ Nmap], [https://www.aircrack-ng.org/ Aircrack-ng], [https://github.com/aircrack-ng/mdk4 MDK4] and [https://www.kismetwireless.net/ Kismet].&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Tools&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
• Kismet - detector for wireless networks and devices.&lt;br /&gt;
&lt;br /&gt;
• MDK4 - Wi-Fi testing tool.&lt;br /&gt;
&lt;br /&gt;
• Aircrack-ng Suite - a complete suite of tools for WiFi network security assessment.&lt;br /&gt;
&lt;br /&gt;
• Nmap - open source utility for network discovery and security auditing.&lt;br /&gt;
&lt;br /&gt;
Hak5 offers ready-to-use payloads and payload extensions on their [https://github.com/hak5/signalowl-payloads GitHub repository].&lt;br /&gt;
&lt;br /&gt;
== Implant / mobile operations ==&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Implant operations&lt;br /&gt;
&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
During long term wireless engagements, the Signal Owl may be planted inline between any typical 5V USB power source. This may be useful in situations where ports are occupied, or to deter the unit from being unplugged.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Mobile operations&lt;br /&gt;
&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
The Signal Owl features a low power consumption profile, with a typical power draw averaging 100-200 mAh. Additionally, it is thermally optimized for long term deployments in many indoor environments. One can expect a large 20,000 mAh USB battery bank to operate the unit for up to 4 days.&lt;br /&gt;
&lt;br /&gt;
= Use Cases =&lt;br /&gt;
&lt;br /&gt;
The Signal Owl has a variety of different use cases. Among the most popular ones are classical network mapping and wardriving as well as basic penetration tests for different wireless technologies.&lt;br /&gt;
&lt;br /&gt;
== Fake Beacon Flooding Attack ==&lt;br /&gt;
&lt;br /&gt;
The Fake Beacon Flooding Attack is one possible use case for the Signal Owl. With that attack, fake beacon frames are broadcasted to nearby devices. Beacon Frames include various parameters like the SSID, the type of encryption used and timestamps. This results in the creation of multiple fake Wi-Fi networks. Devices with Wi-Fi browsers are then flooded with these fake networks, causing potential network scanner and driver crashes. Furthermore, the attack may prevent legitimate users from finding their networks and lead to denial of service. The preinstalled tools Aircrack-ng and MDK4 were used to create this payload. After powering on the device, multiple fake networks with random SSIDs are generated and broadcasted to all nearby devices.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;bash&amp;quot;&amp;gt;&lt;br /&gt;
#!/bin/bash&lt;br /&gt;
&lt;br /&gt;
LED SETUP&lt;br /&gt;
sleep 10&lt;br /&gt;
airmon-ng check kill&lt;br /&gt;
sleep 10&lt;br /&gt;
#creates monitor mode interface on wirelss card of the Signal Owl&lt;br /&gt;
airmon-ng start wlan0&lt;br /&gt;
sleep 10&lt;br /&gt;
LED ATTACK&lt;br /&gt;
#floods nearby devices with random SSIDs&lt;br /&gt;
mdk4 wlan0mon b -a -m -s 500&lt;br /&gt;
&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The results as seen from a victim running a Windows 10 system are pictured in the figure below.&lt;br /&gt;
&lt;br /&gt;
[[File:FakeBeaconFloodingSignalOwl.png|Random SSIDs as seen from a victim Windows 10 client]][Eigene Darstellung]&lt;br /&gt;
&lt;br /&gt;
== Open AP Nmap Scanner ==&lt;br /&gt;
&lt;br /&gt;
With the Open AP Nmap Scanner payload, the Signal Owl scans for open access points. If the Signal Owl finds one or more open access points, it connects to them and uses Nmap to scan and analyze them. The results are then stored in the loot directory. For each discovered open access point, the Signal Owl generates a separate results file. This payload has some settings which can be seen in the following listing.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;bash&amp;quot;&amp;gt;&lt;br /&gt;
NMAP_OPTIONS=&amp;quot;-sP&amp;quot;&lt;br /&gt;
LOOT_DIR=/root/loot/open_ap_nmap_scan&lt;br /&gt;
MAX_CIDR=20&lt;br /&gt;
DEBUG=1&lt;br /&gt;
&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
*NMAP_OPTIONS - Is used to specify the type of Nmap scan.&lt;br /&gt;
*LOOT_DIR - Sets the destination folder for the scan results.&lt;br /&gt;
*MAX_CIDR - Sets the maximum Classless Inter-Domain Routing&lt;br /&gt;
*DEBUG - Specifies if debug information is saved to the payload.log file in the tmp folder.&lt;br /&gt;
** 1 - Debug information is saved.&lt;br /&gt;
** 0 - Debug information is not saved.&lt;br /&gt;
&lt;br /&gt;
The results of a scan with this payload can be seen in the figure below.&lt;br /&gt;
&lt;br /&gt;
[[File:OpenAPNmapScannerResult.png|750px]][Eigene Darstellung]&lt;br /&gt;
&lt;br /&gt;
== Basic Bluetooth Scanner ==&lt;br /&gt;
&lt;br /&gt;
This payload requires an external Bluetooth adapter, since the Signal Owl does not have Bluetooth built in. The Basic Bluetooth Scanner scans for devices that have Bluetooth enabled and optionally queries them using the hcitool and the info command. This payload does also have some settings, as shown in the listing below.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;bash&amp;quot;&amp;gt;&lt;br /&gt;
LOOT_DIR=/root/loot/bluetooth_scan&lt;br /&gt;
BT_OUTFILE=`date +%s`.bt.list&lt;br /&gt;
BT_INFOFILE=`date +%s`.bt.info   &lt;br /&gt;
BTDEV=hci0&lt;br /&gt;
DEBUG=0 &lt;br /&gt;
INTERROGATE=1 &lt;br /&gt;
&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
*LOOT_DIR - Sets the directory for the scan result.&lt;br /&gt;
*BT_OUTFILE - Sets a file name, in which all detected names and MAC addresses are saved.&lt;br /&gt;
*BT_INFOFILE - Sets a file name, in which the details of the discovered devices are saved if the INTERROGATE variable is set to 1. &lt;br /&gt;
*BTDEV - Specifies the bluetooth device used for scanning.&lt;br /&gt;
*DEBUG - Specifies if debug information is saved to the payload.log file in the tmp folder.&lt;br /&gt;
** 1 - Debug information is saved.&lt;br /&gt;
** 0 - Debug information is not saved.&lt;br /&gt;
*INTERROGATE - Specifies if the detected devices are interrogated.&lt;br /&gt;
** 1 - Detected devices are interrogated&lt;br /&gt;
** 0 - Detected devices are not interrogated&lt;br /&gt;
&lt;br /&gt;
== WiFi Connect ==&lt;br /&gt;
&lt;br /&gt;
With the WiFi Connect payload, which can be seen in the following Listing, and the wificonnect.sh Payload extension, the Signal Owl can be connected to a nearby network. The SSID and password of the network to which the Signal Owl should connect must be specified in the code. Optionally, the SSH server of the device can be started by removing the hash sign in the code before the corresponding command. &lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;bash&amp;quot;&amp;gt;&lt;br /&gt;
#!/bin/bash&lt;br /&gt;
&lt;br /&gt;
# WiFi Client Setup&lt;br /&gt;
WIFI_SSID=&amp;quot;network-name&amp;quot;&lt;br /&gt;
WIFI_PASS=&amp;quot;passphrase&amp;quot;&lt;br /&gt;
&lt;br /&gt;
LED SETUP&lt;br /&gt;
WIFI_CONNECT&lt;br /&gt;
# optionally start SSH server&lt;br /&gt;
# /etc/init.d/sshd start&lt;br /&gt;
LED ATTACK&lt;br /&gt;
&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The &amp;lt;code&amp;gt;WIFI_CONNECT&amp;lt;/code&amp;gt; command executes the wifi_connect.sh payload extension, which is shown in the following listing. &lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;bash&amp;quot;&amp;gt;&lt;br /&gt;
#!/bin/bash&lt;br /&gt;
&lt;br /&gt;
function WIFI_CONNECT() {&lt;br /&gt;
    [[ &amp;quot;x$WIFI_INT&amp;quot; == &amp;quot;x&amp;quot; ]] &amp;amp;&amp;amp; WIFI_INT=wlan0&lt;br /&gt;
    ifconfig $WIFI_INT up;sleep 10&lt;br /&gt;
    echo -e &amp;quot;network={\nssid=\&amp;quot;$WIFI_SSID\&amp;quot;\npsk=\&amp;quot;$WIFI_PASS\&amp;quot;\npriority=1\n}&amp;quot;&amp;gt;/tmp/wpa-$WIFI_INT.conf&lt;br /&gt;
    wpa_supplicant -B -Dnl80211 -i $WIFI_INT -c /tmp/wpa-$WIFI_INT.conf&lt;br /&gt;
    while(iwconfig $WIFI_INT | grep Not-Associated); do sleep 1; done&lt;br /&gt;
    udhcpc -i $WIFI_INT&lt;br /&gt;
}&lt;br /&gt;
export -f WIFI_CONNECT&lt;br /&gt;
&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The payload extension code uses the &amp;lt;code&amp;gt;WIFI_SSID&amp;lt;/code&amp;gt; and &amp;lt;code&amp;gt;WIFI_PASS&amp;lt;/code&amp;gt; variables of the payload to connect the Signal Owl to the network. With the command &amp;lt;code&amp;gt;export -f WIFI_CONNECT&amp;lt;/code&amp;gt; the function &amp;lt;code&amp;gt;WIFI_CONNECT&amp;lt;/code&amp;gt; is exported so that it can be called from the payload. &lt;br /&gt;
&lt;br /&gt;
If the SSH server is enabled, any SSH-enabled device can connect to the Signal Owl over the network, even though Attack Mode is enabled. The [[#Default Settings|default settings]] of the device can be used again for the connection, if they have not been changed yet. However, the IP address in this case is the IP address of the Signal Owl in this network.&lt;br /&gt;
&lt;br /&gt;
= Used Hardware =&lt;br /&gt;
&lt;br /&gt;
[[Signal Owl]]&lt;br /&gt;
&lt;br /&gt;
= References =&lt;br /&gt;
&lt;br /&gt;
*https://docs.hak5.org/signal-owl/&lt;br /&gt;
*https://github.com/hak5/signalowl-payloads&lt;br /&gt;
&lt;br /&gt;
[[Category:Pentesting]]&lt;/div&gt;</summary>
		<author><name>MMayer</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=Hak5_Signal_Owl&amp;diff=10734</id>
		<title>Hak5 Signal Owl</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=Hak5_Signal_Owl&amp;diff=10734"/>
		<updated>2023-01-07T02:32:53Z</updated>

		<summary type="html">&lt;p&gt;MMayer: /* Open AP Nmap Scanner */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= Introduction =&lt;br /&gt;
&lt;br /&gt;
The [https://docs.hak5.org/signal-owl/ Signal Owl] is a hardware product developed by the company [https://shop.hak5.org/ Hak5].&lt;br /&gt;
It is a simple payload-based signals intelligence platform with a unique design for discreet planting or mobile operations on any engagement. The most popular application cases include classic network mapping and basic penetration tests for various wireless technologies.&lt;br /&gt;
&lt;br /&gt;
== Initial Setup ==&lt;br /&gt;
&lt;br /&gt;
When first unboxing the Signal Owl, the device runs a stager firmware that is designed to flash the latest firmware from a USB flash drive. In order to update the Signal Owl, the [https://downloads.hak5.org/owl latest firmware] has to be downloaded. Then, the downloaded file must be copied to the root of an EXT4 or FAT32 formatted USB flash drive. It is important not to modify this file. The next step is to plug the USB flash drive into the powered off Signal Owl. Afterwards, the device has to be powered on by a reliable USB source. The upgrade itself takes approximately five to ten minutes and is indicated by a solid red LED light. When finished, the device will reboot, enter Attack Mode and blink slowly, indicating an error running the payload because no payload has been found.&lt;br /&gt;
&lt;br /&gt;
= Hardware =&lt;br /&gt;
&lt;br /&gt;
[[File:SignalOwlDiagram.png|thumb|500px|frame|Components of the Signal Owl [Eigene Darstellung]]] &lt;br /&gt;
&lt;br /&gt;
The Signal Owl is designed to be rapidly deployed in all kinds of environments, allowing it to be an entry point for network analysis and basic wireless attacks in a variety of locations. With a power consumption of 100-200 mAh and the thermally optimized architecture, mobile operations as well as long term deployments, are enabled.&lt;br /&gt;
&lt;br /&gt;
== Components ==&lt;br /&gt;
&lt;br /&gt;
This device features several components of which some may not be visible to the human eye at first sight.&lt;br /&gt;
&lt;br /&gt;
=== USB Power / Passthrough Plug ===&lt;br /&gt;
&lt;br /&gt;
The USB power or passthrough plug is used to power the device. It can be powered from any reliable USB source.&lt;br /&gt;
&lt;br /&gt;
=== USB 2.0 Passthrough Port ===&lt;br /&gt;
&lt;br /&gt;
The USB 2.0 passthrough port is the port closest to the pigtail. Data and power pass through to that port, allowing for implant operations. If a device such as a keyboard is plugged in between this passthrough port and the power plug is connected to the target computer, the Signal Owl will remain undetected by the operating system. Only the keyboard will be visible on the target computer.&lt;br /&gt;
&lt;br /&gt;
=== USB 2.0 Host Port ===&lt;br /&gt;
&lt;br /&gt;
The USB 2.0 host port is the port farthest away from the pigtail. It is connected to the Linux socket of the Signal Owl and supports USB flash drives formatted with FAT32 and EXT4 file systems as well as many Wi-Fi, Bluetooth and other RF transceivers.&lt;br /&gt;
&lt;br /&gt;
=== Button ===&lt;br /&gt;
&lt;br /&gt;
The button on the bottom of the device is used to enter Arming Mode and to interact with payloads. It is not pressable without special tools like paperclips.&lt;br /&gt;
&lt;br /&gt;
=== Status LED ===&lt;br /&gt;
&lt;br /&gt;
The status LED indicates the current status of the Signal Owl. When it is turned off, it is not visible.&lt;br /&gt;
&lt;br /&gt;
The Signal Owl features a red LED with the following default status indications:&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
!|LED&lt;br /&gt;
!|Status&lt;br /&gt;
|-&lt;br /&gt;
|Blinking&lt;br /&gt;
|Booting&lt;br /&gt;
|-&lt;br /&gt;
|Solid&lt;br /&gt;
|Mounting external storage / Running upgrade&lt;br /&gt;
|-&lt;br /&gt;
|Single blinking&lt;br /&gt;
|Attack Mode&lt;br /&gt;
|-&lt;br /&gt;
|Double blinking&lt;br /&gt;
|Arming Mode&lt;br /&gt;
|-&lt;br /&gt;
|Slow blinking&lt;br /&gt;
|Error running payload&lt;br /&gt;
|-&lt;br /&gt;
|Fast blinking&lt;br /&gt;
|Select Mode (Deprecated from version 1.0.1 onward)&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= Software =&lt;br /&gt;
&lt;br /&gt;
== Modes of Operation ==&lt;br /&gt;
&lt;br /&gt;
The Signal Owl comes with two modes of operation, Attack Mode and Arming Mode. By default, the device will boot into Attack Mode. In order to access Arming Mode, the button on the bottom of the device has to be pressed while in Attack Mode. It is not recommended to press the button during the boot sequence, as this can possibly brick the device and render it useless. The arming mode is used for firmware updates and shell access, while the attack mode is used to load and execute the payload.&lt;br /&gt;
&lt;br /&gt;
=== Attack Mode ===&lt;br /&gt;
&lt;br /&gt;
Attack Mode is the default mode, the Signal Owl boots into. It provides two basic functions, being the payload loading function and the payload execution function. &lt;br /&gt;
&lt;br /&gt;
The payload loading function checks for any USB flash drives plugged into the host port of the device and copies payloads to &amp;lt;code&amp;gt;/root/payload&amp;lt;/code&amp;gt; and extensions to &amp;lt;code&amp;gt;/root/payload/extensions&amp;lt;/code&amp;gt; on the Signal Owl. &lt;br /&gt;
&lt;br /&gt;
The payload execution function is responsible for executing the payload that is currently stored on the root of the Signal Owl. In case no payload is found, the device will blink slowly, indicating the FAIL status.&lt;br /&gt;
&lt;br /&gt;
=== Arming Mode ===&lt;br /&gt;
&lt;br /&gt;
The Arming Mode provides two basic functions, being the firmware update function and the shell access function. The firmware update function checks for any USB flash drives plugged into the host port of the device and copies firmware upgrade files into the internal storage of the device and flashes it. The shell access function starts an open access point with the SSID Owl_xxxx in which xxxx indicates the last two octets of the device&#039;s MAC address. Additionally, a SSH server providing access to the shell of the Signal Owl is enabled.&lt;br /&gt;
&lt;br /&gt;
== Default Settings ==&lt;br /&gt;
&lt;br /&gt;
Default settings that are used in order to access the device via SSH are pictured in the table below.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
!colspan=&amp;quot;2&amp;quot;|Default Settings&lt;br /&gt;
|-&lt;br /&gt;
|Username&lt;br /&gt;
|root&lt;br /&gt;
|-&lt;br /&gt;
|Password&lt;br /&gt;
|hak5owl&lt;br /&gt;
|-&lt;br /&gt;
|SSID&lt;br /&gt;
|Owl_xxxx&lt;br /&gt;
|-&lt;br /&gt;
|IP Address&lt;br /&gt;
|172.16.56.1&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
SSH command: &amp;lt;code&amp;gt;ssh root@172.16.56.1&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The SSID during Arming Mode is Owl_xxxx in which xxxx indicates the last two octets of the devices MAC address.&lt;br /&gt;
&lt;br /&gt;
= Usage =&lt;br /&gt;
&lt;br /&gt;
== Arming Mode connection ==&lt;br /&gt;
&lt;br /&gt;
Step-by-step guide for accessing the arming mode&lt;br /&gt;
&lt;br /&gt;
#Click on the button located on the bottom of the Signal Owl while it is in attack mode. After pressing the button, the signal owl enters the arming mode and provides an open access point with the name Owl xxxx (where xxxx stands for the last two digits of the MAC address of the device).&lt;br /&gt;
#Connect to the access point.&amp;lt;br&amp;gt;[[File:Armingmode.png]][Eigene Darstellung]&lt;br /&gt;
#Now you can connect via ssh by using the [[#Default Settings|default settings]].&lt;br /&gt;
#After successful connection, you will end up in the root directory.&amp;lt;br&amp;gt;[[File:ArmingmodeSSH.png]][Eigene Darstellung]&lt;br /&gt;
#Now you can change the files and directories on the Signal Owl to view results, transfer payloads and extensions or to make further changes.&lt;br /&gt;
&lt;br /&gt;
== Directory structure ==&lt;br /&gt;
&lt;br /&gt;
The following directory tree shows the directory structure of the Signal Owl.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
/&lt;br /&gt;
├── loot&lt;br /&gt;
└── payload/&lt;br /&gt;
    └── extensions&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
*Loot - Directory where the Signal Owl saves loot while executing payloads that produce loot.&lt;br /&gt;
*Payload - This directory holds the current payload. &lt;br /&gt;
*Extensions -  This directory holds all extensions.&lt;br /&gt;
&lt;br /&gt;
== Adding Payloads and Extensions ==&lt;br /&gt;
&lt;br /&gt;
Adding a payload can be done in two different ways. Either with a USB flash drive or via the Signal Owl access point to the internal storage of the device. &lt;br /&gt;
&lt;br /&gt;
When booting, payloads on USB flash drives are given priority and will override payloads stored on the Signal Owl. To successfully copy a payload to the Signal Owl, the payload must be named &amp;lt;code&amp;gt;payload.txt&amp;lt;/code&amp;gt; or &amp;lt;code&amp;gt;payload.sh&amp;lt;/code&amp;gt; and it has to be placed in the &amp;lt;code&amp;gt;root&amp;lt;/code&amp;gt; directory of the flash drive. Similarly, payload extensions should be stored in a &amp;lt;code&amp;gt;/extensions&amp;lt;/code&amp;gt; directory on the flash drive. &lt;br /&gt;
&lt;br /&gt;
In addition, it is possible to transfer payloads and payload extensions to the device via the Signal Owl access point in arming mode using SSH. There they are stored in the &amp;lt;code&amp;gt;/root/payload&amp;lt;/code&amp;gt; directory and Payload Extensions are stored in the &amp;lt;code&amp;gt;/root/payload/extensions&amp;lt;/code&amp;gt; directory.&lt;br /&gt;
&lt;br /&gt;
== Payload Development ==&lt;br /&gt;
&lt;br /&gt;
Payloads for the Signal Owl are written in bash with [https://github.com/hak5darren/USB-Rubber-Ducky/wiki/Duckyscript Ducky Script] and can be created with any standard text editor. All payloads should begin with an interpreter directive, like the shebang &amp;lt;code&amp;gt;#!/bin/bash&amp;lt;/code&amp;gt; for bash payloads and payloads must be named either &amp;lt;code&amp;gt;payload.txt&amp;lt;/code&amp;gt; or &amp;lt;code&amp;gt;payload.sh&amp;lt;/code&amp;gt;. In order to create effective payloads, the Signal Owl comes with several preinstalled penetration testing tools. These are as follows: [https://nmap.org/ Nmap], [https://www.aircrack-ng.org/ Aircrack-ng], [https://github.com/aircrack-ng/mdk4 MDK4] and [https://www.kismetwireless.net/ Kismet].&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Tools&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
• Kismet - detector for wireless networks and devices.&lt;br /&gt;
&lt;br /&gt;
• MDK4 - Wi-Fi testing tool.&lt;br /&gt;
&lt;br /&gt;
• Aircrack-ng Suite - a complete suite of tools for WiFi network security assessment.&lt;br /&gt;
&lt;br /&gt;
• Nmap - open source utility for network discovery and security auditing.&lt;br /&gt;
&lt;br /&gt;
Hak5 offers ready-to-use payloads and payload extensions on their [https://github.com/hak5/signalowl-payloads GitHub repository].&lt;br /&gt;
&lt;br /&gt;
== Implant / mobile operations ==&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Implant operations&lt;br /&gt;
&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
During long term wireless engagements, the Signal Owl may be planted inline between any typical 5V USB power source. This may be useful in situations where ports are occupied, or to deter the unit from being unplugged.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Mobile operations&lt;br /&gt;
&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
The Signal Owl features a low power consumption profile, with a typical power draw averaging 100-200 mAh. Additionally, it is thermally optimized for long term deployments in many indoor environments. One can expect a large 20,000 mAh USB battery bank to operate the unit for up to 4 days.&lt;br /&gt;
&lt;br /&gt;
= Use Cases =&lt;br /&gt;
&lt;br /&gt;
The Signal Owl has a variety of different use cases. Among the most popular ones are classical network mapping and wardriving as well as basic penetration tests for different wireless technologies.&lt;br /&gt;
&lt;br /&gt;
== Fake Beacon Flooding Attack ==&lt;br /&gt;
&lt;br /&gt;
The Fake Beacon Flooding Attack is one possible use case for the Signal Owl. With that attack, fake beacon frames are broadcasted to nearby devices. Beacon Frames include various parameters like the SSID, the type of encryption used and timestamps. This results in the creation of multiple fake Wi-Fi networks. Devices with Wi-Fi browsers are then flooded with these fake networks, causing potential network scanner and driver crashes. Furthermore, the attack may prevent legitimate users from finding their networks and lead to denial of service. The preinstalled tools Aircrack-ng and MDK4 were used to create this payload. After powering on the device, multiple fake networks with random SSIDs are generated and broadcasted to all nearby devices.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;bash&amp;quot;&amp;gt;&lt;br /&gt;
#!/bin/bash&lt;br /&gt;
&lt;br /&gt;
LED SETUP&lt;br /&gt;
sleep 10&lt;br /&gt;
airmon-ng check kill&lt;br /&gt;
sleep 10&lt;br /&gt;
#creates monitor mode interface on wirelss card of the Signal Owl&lt;br /&gt;
airmon-ng start wlan0&lt;br /&gt;
sleep 10&lt;br /&gt;
LED ATTACK&lt;br /&gt;
#floods nearby devices with random SSIDs&lt;br /&gt;
mdk4 wlan0mon b -a -m -s 500&lt;br /&gt;
&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The results as seen from a victim running a Windows 10 system are pictured in the figure below.&lt;br /&gt;
&lt;br /&gt;
[[File:FakeBeaconFloodingSignalOwl.png|none|Random SSIDs as seen from a victim Windows 10 client |]][Eigene Darstellung]&lt;br /&gt;
&lt;br /&gt;
== Open AP Nmap Scanner ==&lt;br /&gt;
&lt;br /&gt;
With the Open AP Nmap Scanner payload, the Signal Owl scans for open access points. If the Signal Owl finds one or more open access points, it connects to them and uses Nmap to scan and analyze them. The results are then stored in the loot directory. For each discovered open access point, the Signal Owl generates a separate results file. This payload has some settings which can be seen in the following listing.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;bash&amp;quot;&amp;gt;&lt;br /&gt;
NMAP_OPTIONS=&amp;quot;-sP&amp;quot;&lt;br /&gt;
LOOT_DIR=/root/loot/open_ap_nmap_scan&lt;br /&gt;
MAX_CIDR=20&lt;br /&gt;
DEBUG=1&lt;br /&gt;
&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
*NMAP_OPTIONS - Is used to specify the type of Nmap scan.&lt;br /&gt;
*LOOT_DIR - Sets the destination folder for the scan results.&lt;br /&gt;
*MAX_CIDR - Sets the maximum Classless Inter-Domain Routing&lt;br /&gt;
*DEBUG - Specifies if debug information is saved to the payload.log file in the tmp folder.&lt;br /&gt;
** 1 - Debug information is saved.&lt;br /&gt;
** 0 - Debug information is not saved.&lt;br /&gt;
&lt;br /&gt;
The results of a scan with this payload can be seen in the figure below.&lt;br /&gt;
&lt;br /&gt;
[[File:OpenAPNmapScannerResult.png|750px]][Eigene Darstellung]&lt;br /&gt;
&lt;br /&gt;
== Basic Bluetooth Scanner ==&lt;br /&gt;
&lt;br /&gt;
This payload requires an external Bluetooth adapter, since the Signal Owl does not have Bluetooth built in. The Basic Bluetooth Scanner scans for devices that have Bluetooth enabled and optionally queries them using the hcitool and the info command. This payload does also have some settings, as shown in the listing below.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;bash&amp;quot;&amp;gt;&lt;br /&gt;
LOOT_DIR=/root/loot/bluetooth_scan&lt;br /&gt;
BT_OUTFILE=`date +%s`.bt.list&lt;br /&gt;
BT_INFOFILE=`date +%s`.bt.info   &lt;br /&gt;
BTDEV=hci0&lt;br /&gt;
DEBUG=0 &lt;br /&gt;
INTERROGATE=1 &lt;br /&gt;
&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
*LOOT_DIR - Sets the directory for the scan result.&lt;br /&gt;
*BT_OUTFILE - Sets a file name, in which all detected names and MAC addresses are saved.&lt;br /&gt;
*BT_INFOFILE - Sets a file name, in which the details of the discovered devices are saved if the INTERROGATE variable is set to 1. &lt;br /&gt;
*BTDEV - Specifies the bluetooth device used for scanning.&lt;br /&gt;
*DEBUG - Specifies if debug information is saved to the payload.log file in the tmp folder.&lt;br /&gt;
** 1 - Debug information is saved.&lt;br /&gt;
** 0 - Debug information is not saved.&lt;br /&gt;
*INTERROGATE - Specifies if the detected devices are interrogated.&lt;br /&gt;
** 1 - Detected devices are interrogated&lt;br /&gt;
** 0 - Detected devices are not interrogated&lt;br /&gt;
&lt;br /&gt;
== WiFi Connect ==&lt;br /&gt;
&lt;br /&gt;
With the WiFi Connect payload, which can be seen in the following Listing, and the wificonnect.sh Payload extension, the Signal Owl can be connected to a nearby network. The SSID and password of the network to which the Signal Owl should connect must be specified in the code. Optionally, the SSH server of the device can be started by removing the hash sign in the code before the corresponding command. &lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;bash&amp;quot;&amp;gt;&lt;br /&gt;
#!/bin/bash&lt;br /&gt;
&lt;br /&gt;
# WiFi Client Setup&lt;br /&gt;
WIFI_SSID=&amp;quot;network-name&amp;quot;&lt;br /&gt;
WIFI_PASS=&amp;quot;passphrase&amp;quot;&lt;br /&gt;
&lt;br /&gt;
LED SETUP&lt;br /&gt;
WIFI_CONNECT&lt;br /&gt;
# optionally start SSH server&lt;br /&gt;
# /etc/init.d/sshd start&lt;br /&gt;
LED ATTACK&lt;br /&gt;
&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The &amp;lt;code&amp;gt;WIFI_CONNECT&amp;lt;/code&amp;gt; command executes the wifi_connect.sh payload extension, which is shown in the following listing. &lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;bash&amp;quot;&amp;gt;&lt;br /&gt;
#!/bin/bash&lt;br /&gt;
&lt;br /&gt;
function WIFI_CONNECT() {&lt;br /&gt;
    [[ &amp;quot;x$WIFI_INT&amp;quot; == &amp;quot;x&amp;quot; ]] &amp;amp;&amp;amp; WIFI_INT=wlan0&lt;br /&gt;
    ifconfig $WIFI_INT up;sleep 10&lt;br /&gt;
    echo -e &amp;quot;network={\nssid=\&amp;quot;$WIFI_SSID\&amp;quot;\npsk=\&amp;quot;$WIFI_PASS\&amp;quot;\npriority=1\n}&amp;quot;&amp;gt;/tmp/wpa-$WIFI_INT.conf&lt;br /&gt;
    wpa_supplicant -B -Dnl80211 -i $WIFI_INT -c /tmp/wpa-$WIFI_INT.conf&lt;br /&gt;
    while(iwconfig $WIFI_INT | grep Not-Associated); do sleep 1; done&lt;br /&gt;
    udhcpc -i $WIFI_INT&lt;br /&gt;
}&lt;br /&gt;
export -f WIFI_CONNECT&lt;br /&gt;
&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The payload extension code uses the &amp;lt;code&amp;gt;WIFI_SSID&amp;lt;/code&amp;gt; and &amp;lt;code&amp;gt;WIFI_PASS&amp;lt;/code&amp;gt; variables of the payload to connect the Signal Owl to the network. With the command &amp;lt;code&amp;gt;export -f WIFI_CONNECT&amp;lt;/code&amp;gt; the function &amp;lt;code&amp;gt;WIFI_CONNECT&amp;lt;/code&amp;gt; is exported so that it can be called from the payload. &lt;br /&gt;
&lt;br /&gt;
If the SSH server is enabled, any SSH-enabled device can connect to the Signal Owl over the network, even though Attack Mode is enabled. The [[#Default Settings|default settings]] of the device can be used again for the connection, if they have not been changed yet. However, the IP address in this case is the IP address of the Signal Owl in this network.&lt;br /&gt;
&lt;br /&gt;
= Used Hardware =&lt;br /&gt;
&lt;br /&gt;
[[Signal Owl]]&lt;br /&gt;
&lt;br /&gt;
= References =&lt;br /&gt;
&lt;br /&gt;
*https://docs.hak5.org/signal-owl/&lt;br /&gt;
*https://github.com/hak5/signalowl-payloads&lt;br /&gt;
&lt;br /&gt;
[[Category:Pentesting]]&lt;/div&gt;</summary>
		<author><name>MMayer</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=Hak5_Signal_Owl&amp;diff=10733</id>
		<title>Hak5 Signal Owl</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=Hak5_Signal_Owl&amp;diff=10733"/>
		<updated>2023-01-07T02:32:07Z</updated>

		<summary type="html">&lt;p&gt;MMayer: /* Open AP Nmap Scanner */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= Introduction =&lt;br /&gt;
&lt;br /&gt;
The [https://docs.hak5.org/signal-owl/ Signal Owl] is a hardware product developed by the company [https://shop.hak5.org/ Hak5].&lt;br /&gt;
It is a simple payload-based signals intelligence platform with a unique design for discreet planting or mobile operations on any engagement. The most popular application cases include classic network mapping and basic penetration tests for various wireless technologies.&lt;br /&gt;
&lt;br /&gt;
== Initial Setup ==&lt;br /&gt;
&lt;br /&gt;
When first unboxing the Signal Owl, the device runs a stager firmware that is designed to flash the latest firmware from a USB flash drive. In order to update the Signal Owl, the [https://downloads.hak5.org/owl latest firmware] has to be downloaded. Then, the downloaded file must be copied to the root of an EXT4 or FAT32 formatted USB flash drive. It is important not to modify this file. The next step is to plug the USB flash drive into the powered off Signal Owl. Afterwards, the device has to be powered on by a reliable USB source. The upgrade itself takes approximately five to ten minutes and is indicated by a solid red LED light. When finished, the device will reboot, enter Attack Mode and blink slowly, indicating an error running the payload because no payload has been found.&lt;br /&gt;
&lt;br /&gt;
= Hardware =&lt;br /&gt;
&lt;br /&gt;
[[File:SignalOwlDiagram.png|thumb|500px|frame|Components of the Signal Owl [Eigene Darstellung]]] &lt;br /&gt;
&lt;br /&gt;
The Signal Owl is designed to be rapidly deployed in all kinds of environments, allowing it to be an entry point for network analysis and basic wireless attacks in a variety of locations. With a power consumption of 100-200 mAh and the thermally optimized architecture, mobile operations as well as long term deployments, are enabled.&lt;br /&gt;
&lt;br /&gt;
== Components ==&lt;br /&gt;
&lt;br /&gt;
This device features several components of which some may not be visible to the human eye at first sight.&lt;br /&gt;
&lt;br /&gt;
=== USB Power / Passthrough Plug ===&lt;br /&gt;
&lt;br /&gt;
The USB power or passthrough plug is used to power the device. It can be powered from any reliable USB source.&lt;br /&gt;
&lt;br /&gt;
=== USB 2.0 Passthrough Port ===&lt;br /&gt;
&lt;br /&gt;
The USB 2.0 passthrough port is the port closest to the pigtail. Data and power pass through to that port, allowing for implant operations. If a device such as a keyboard is plugged in between this passthrough port and the power plug is connected to the target computer, the Signal Owl will remain undetected by the operating system. Only the keyboard will be visible on the target computer.&lt;br /&gt;
&lt;br /&gt;
=== USB 2.0 Host Port ===&lt;br /&gt;
&lt;br /&gt;
The USB 2.0 host port is the port farthest away from the pigtail. It is connected to the Linux socket of the Signal Owl and supports USB flash drives formatted with FAT32 and EXT4 file systems as well as many Wi-Fi, Bluetooth and other RF transceivers.&lt;br /&gt;
&lt;br /&gt;
=== Button ===&lt;br /&gt;
&lt;br /&gt;
The button on the bottom of the device is used to enter Arming Mode and to interact with payloads. It is not pressable without special tools like paperclips.&lt;br /&gt;
&lt;br /&gt;
=== Status LED ===&lt;br /&gt;
&lt;br /&gt;
The status LED indicates the current status of the Signal Owl. When it is turned off, it is not visible.&lt;br /&gt;
&lt;br /&gt;
The Signal Owl features a red LED with the following default status indications:&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
!|LED&lt;br /&gt;
!|Status&lt;br /&gt;
|-&lt;br /&gt;
|Blinking&lt;br /&gt;
|Booting&lt;br /&gt;
|-&lt;br /&gt;
|Solid&lt;br /&gt;
|Mounting external storage / Running upgrade&lt;br /&gt;
|-&lt;br /&gt;
|Single blinking&lt;br /&gt;
|Attack Mode&lt;br /&gt;
|-&lt;br /&gt;
|Double blinking&lt;br /&gt;
|Arming Mode&lt;br /&gt;
|-&lt;br /&gt;
|Slow blinking&lt;br /&gt;
|Error running payload&lt;br /&gt;
|-&lt;br /&gt;
|Fast blinking&lt;br /&gt;
|Select Mode (Deprecated from version 1.0.1 onward)&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= Software =&lt;br /&gt;
&lt;br /&gt;
== Modes of Operation ==&lt;br /&gt;
&lt;br /&gt;
The Signal Owl comes with two modes of operation, Attack Mode and Arming Mode. By default, the device will boot into Attack Mode. In order to access Arming Mode, the button on the bottom of the device has to be pressed while in Attack Mode. It is not recommended to press the button during the boot sequence, as this can possibly brick the device and render it useless. The arming mode is used for firmware updates and shell access, while the attack mode is used to load and execute the payload.&lt;br /&gt;
&lt;br /&gt;
=== Attack Mode ===&lt;br /&gt;
&lt;br /&gt;
Attack Mode is the default mode, the Signal Owl boots into. It provides two basic functions, being the payload loading function and the payload execution function. &lt;br /&gt;
&lt;br /&gt;
The payload loading function checks for any USB flash drives plugged into the host port of the device and copies payloads to &amp;lt;code&amp;gt;/root/payload&amp;lt;/code&amp;gt; and extensions to &amp;lt;code&amp;gt;/root/payload/extensions&amp;lt;/code&amp;gt; on the Signal Owl. &lt;br /&gt;
&lt;br /&gt;
The payload execution function is responsible for executing the payload that is currently stored on the root of the Signal Owl. In case no payload is found, the device will blink slowly, indicating the FAIL status.&lt;br /&gt;
&lt;br /&gt;
=== Arming Mode ===&lt;br /&gt;
&lt;br /&gt;
The Arming Mode provides two basic functions, being the firmware update function and the shell access function. The firmware update function checks for any USB flash drives plugged into the host port of the device and copies firmware upgrade files into the internal storage of the device and flashes it. The shell access function starts an open access point with the SSID Owl_xxxx in which xxxx indicates the last two octets of the device&#039;s MAC address. Additionally, a SSH server providing access to the shell of the Signal Owl is enabled.&lt;br /&gt;
&lt;br /&gt;
== Default Settings ==&lt;br /&gt;
&lt;br /&gt;
Default settings that are used in order to access the device via SSH are pictured in the table below.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
!colspan=&amp;quot;2&amp;quot;|Default Settings&lt;br /&gt;
|-&lt;br /&gt;
|Username&lt;br /&gt;
|root&lt;br /&gt;
|-&lt;br /&gt;
|Password&lt;br /&gt;
|hak5owl&lt;br /&gt;
|-&lt;br /&gt;
|SSID&lt;br /&gt;
|Owl_xxxx&lt;br /&gt;
|-&lt;br /&gt;
|IP Address&lt;br /&gt;
|172.16.56.1&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
SSH command: &amp;lt;code&amp;gt;ssh root@172.16.56.1&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The SSID during Arming Mode is Owl_xxxx in which xxxx indicates the last two octets of the devices MAC address.&lt;br /&gt;
&lt;br /&gt;
= Usage =&lt;br /&gt;
&lt;br /&gt;
== Arming Mode connection ==&lt;br /&gt;
&lt;br /&gt;
Step-by-step guide for accessing the arming mode&lt;br /&gt;
&lt;br /&gt;
#Click on the button located on the bottom of the Signal Owl while it is in attack mode. After pressing the button, the signal owl enters the arming mode and provides an open access point with the name Owl xxxx (where xxxx stands for the last two digits of the MAC address of the device).&lt;br /&gt;
#Connect to the access point.&amp;lt;br&amp;gt;[[File:Armingmode.png]][Eigene Darstellung]&lt;br /&gt;
#Now you can connect via ssh by using the [[#Default Settings|default settings]].&lt;br /&gt;
#After successful connection, you will end up in the root directory.&amp;lt;br&amp;gt;[[File:ArmingmodeSSH.png]][Eigene Darstellung]&lt;br /&gt;
#Now you can change the files and directories on the Signal Owl to view results, transfer payloads and extensions or to make further changes.&lt;br /&gt;
&lt;br /&gt;
== Directory structure ==&lt;br /&gt;
&lt;br /&gt;
The following directory tree shows the directory structure of the Signal Owl.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
/&lt;br /&gt;
├── loot&lt;br /&gt;
└── payload/&lt;br /&gt;
    └── extensions&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
*Loot - Directory where the Signal Owl saves loot while executing payloads that produce loot.&lt;br /&gt;
*Payload - This directory holds the current payload. &lt;br /&gt;
*Extensions -  This directory holds all extensions.&lt;br /&gt;
&lt;br /&gt;
== Adding Payloads and Extensions ==&lt;br /&gt;
&lt;br /&gt;
Adding a payload can be done in two different ways. Either with a USB flash drive or via the Signal Owl access point to the internal storage of the device. &lt;br /&gt;
&lt;br /&gt;
When booting, payloads on USB flash drives are given priority and will override payloads stored on the Signal Owl. To successfully copy a payload to the Signal Owl, the payload must be named &amp;lt;code&amp;gt;payload.txt&amp;lt;/code&amp;gt; or &amp;lt;code&amp;gt;payload.sh&amp;lt;/code&amp;gt; and it has to be placed in the &amp;lt;code&amp;gt;root&amp;lt;/code&amp;gt; directory of the flash drive. Similarly, payload extensions should be stored in a &amp;lt;code&amp;gt;/extensions&amp;lt;/code&amp;gt; directory on the flash drive. &lt;br /&gt;
&lt;br /&gt;
In addition, it is possible to transfer payloads and payload extensions to the device via the Signal Owl access point in arming mode using SSH. There they are stored in the &amp;lt;code&amp;gt;/root/payload&amp;lt;/code&amp;gt; directory and Payload Extensions are stored in the &amp;lt;code&amp;gt;/root/payload/extensions&amp;lt;/code&amp;gt; directory.&lt;br /&gt;
&lt;br /&gt;
== Payload Development ==&lt;br /&gt;
&lt;br /&gt;
Payloads for the Signal Owl are written in bash with [https://github.com/hak5darren/USB-Rubber-Ducky/wiki/Duckyscript Ducky Script] and can be created with any standard text editor. All payloads should begin with an interpreter directive, like the shebang &amp;lt;code&amp;gt;#!/bin/bash&amp;lt;/code&amp;gt; for bash payloads and payloads must be named either &amp;lt;code&amp;gt;payload.txt&amp;lt;/code&amp;gt; or &amp;lt;code&amp;gt;payload.sh&amp;lt;/code&amp;gt;. In order to create effective payloads, the Signal Owl comes with several preinstalled penetration testing tools. These are as follows: [https://nmap.org/ Nmap], [https://www.aircrack-ng.org/ Aircrack-ng], [https://github.com/aircrack-ng/mdk4 MDK4] and [https://www.kismetwireless.net/ Kismet].&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Tools&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
• Kismet - detector for wireless networks and devices.&lt;br /&gt;
&lt;br /&gt;
• MDK4 - Wi-Fi testing tool.&lt;br /&gt;
&lt;br /&gt;
• Aircrack-ng Suite - a complete suite of tools for WiFi network security assessment.&lt;br /&gt;
&lt;br /&gt;
• Nmap - open source utility for network discovery and security auditing.&lt;br /&gt;
&lt;br /&gt;
Hak5 offers ready-to-use payloads and payload extensions on their [https://github.com/hak5/signalowl-payloads GitHub repository].&lt;br /&gt;
&lt;br /&gt;
== Implant / mobile operations ==&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Implant operations&lt;br /&gt;
&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
During long term wireless engagements, the Signal Owl may be planted inline between any typical 5V USB power source. This may be useful in situations where ports are occupied, or to deter the unit from being unplugged.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Mobile operations&lt;br /&gt;
&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
The Signal Owl features a low power consumption profile, with a typical power draw averaging 100-200 mAh. Additionally, it is thermally optimized for long term deployments in many indoor environments. One can expect a large 20,000 mAh USB battery bank to operate the unit for up to 4 days.&lt;br /&gt;
&lt;br /&gt;
= Use Cases =&lt;br /&gt;
&lt;br /&gt;
The Signal Owl has a variety of different use cases. Among the most popular ones are classical network mapping and wardriving as well as basic penetration tests for different wireless technologies.&lt;br /&gt;
&lt;br /&gt;
== Fake Beacon Flooding Attack ==&lt;br /&gt;
&lt;br /&gt;
The Fake Beacon Flooding Attack is one possible use case for the Signal Owl. With that attack, fake beacon frames are broadcasted to nearby devices. Beacon Frames include various parameters like the SSID, the type of encryption used and timestamps. This results in the creation of multiple fake Wi-Fi networks. Devices with Wi-Fi browsers are then flooded with these fake networks, causing potential network scanner and driver crashes. Furthermore, the attack may prevent legitimate users from finding their networks and lead to denial of service. The preinstalled tools Aircrack-ng and MDK4 were used to create this payload. After powering on the device, multiple fake networks with random SSIDs are generated and broadcasted to all nearby devices.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;bash&amp;quot;&amp;gt;&lt;br /&gt;
#!/bin/bash&lt;br /&gt;
&lt;br /&gt;
LED SETUP&lt;br /&gt;
sleep 10&lt;br /&gt;
airmon-ng check kill&lt;br /&gt;
sleep 10&lt;br /&gt;
#creates monitor mode interface on wirelss card of the Signal Owl&lt;br /&gt;
airmon-ng start wlan0&lt;br /&gt;
sleep 10&lt;br /&gt;
LED ATTACK&lt;br /&gt;
#floods nearby devices with random SSIDs&lt;br /&gt;
mdk4 wlan0mon b -a -m -s 500&lt;br /&gt;
&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The results as seen from a victim running a Windows 10 system are pictured in the figure below.&lt;br /&gt;
&lt;br /&gt;
[[File:FakeBeaconFloodingSignalOwl.png|none|Random SSIDs as seen from a victim Windows 10 client |]][Eigene Darstellung]&lt;br /&gt;
&lt;br /&gt;
== Open AP Nmap Scanner ==&lt;br /&gt;
&lt;br /&gt;
With the Open AP Nmap Scanner payload, the Signal Owl scans for open access points. If the Signal Owl finds one or more open access points, it connects to them and uses Nmap to scan and analyze them. The results are then stored in the loot directory. For each discovered open access point, the Signal Owl generates a separate results file. This payload has some settings which can be seen in the following listing.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;bash&amp;quot;&amp;gt;&lt;br /&gt;
NMAP_OPTIONS=&amp;quot;-sP&amp;quot;&lt;br /&gt;
LOOT_DIR=/root/loot/open_ap_nmap_scan&lt;br /&gt;
MAX_CIDR=20&lt;br /&gt;
DEBUG=1&lt;br /&gt;
&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
*NMAP_OPTIONS - Is used to specify the type of Nmap scan.&lt;br /&gt;
*LOOT_DIR - Sets the destination folder for the scan results.&lt;br /&gt;
*MAX_CIDR - Sets the maximum Classless Inter-Domain Routing&lt;br /&gt;
*DEBUG - Specifies if debug information is saved to the payload.log file in the tmp folder.&lt;br /&gt;
** 1 - Debug information is saved.&lt;br /&gt;
** 0 - Debug information is not saved.&lt;br /&gt;
&lt;br /&gt;
The results of a scan with this payload can be seen in the figure below.&lt;br /&gt;
&lt;br /&gt;
[[File:OpenAPNmapScannerResult.png|750px]]&lt;br /&gt;
&lt;br /&gt;
== Basic Bluetooth Scanner ==&lt;br /&gt;
&lt;br /&gt;
This payload requires an external Bluetooth adapter, since the Signal Owl does not have Bluetooth built in. The Basic Bluetooth Scanner scans for devices that have Bluetooth enabled and optionally queries them using the hcitool and the info command. This payload does also have some settings, as shown in the listing below.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;bash&amp;quot;&amp;gt;&lt;br /&gt;
LOOT_DIR=/root/loot/bluetooth_scan&lt;br /&gt;
BT_OUTFILE=`date +%s`.bt.list&lt;br /&gt;
BT_INFOFILE=`date +%s`.bt.info   &lt;br /&gt;
BTDEV=hci0&lt;br /&gt;
DEBUG=0 &lt;br /&gt;
INTERROGATE=1 &lt;br /&gt;
&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
*LOOT_DIR - Sets the directory for the scan result.&lt;br /&gt;
*BT_OUTFILE - Sets a file name, in which all detected names and MAC addresses are saved.&lt;br /&gt;
*BT_INFOFILE - Sets a file name, in which the details of the discovered devices are saved if the INTERROGATE variable is set to 1. &lt;br /&gt;
*BTDEV - Specifies the bluetooth device used for scanning.&lt;br /&gt;
*DEBUG - Specifies if debug information is saved to the payload.log file in the tmp folder.&lt;br /&gt;
** 1 - Debug information is saved.&lt;br /&gt;
** 0 - Debug information is not saved.&lt;br /&gt;
*INTERROGATE - Specifies if the detected devices are interrogated.&lt;br /&gt;
** 1 - Detected devices are interrogated&lt;br /&gt;
** 0 - Detected devices are not interrogated&lt;br /&gt;
&lt;br /&gt;
== WiFi Connect ==&lt;br /&gt;
&lt;br /&gt;
With the WiFi Connect payload, which can be seen in the following Listing, and the wificonnect.sh Payload extension, the Signal Owl can be connected to a nearby network. The SSID and password of the network to which the Signal Owl should connect must be specified in the code. Optionally, the SSH server of the device can be started by removing the hash sign in the code before the corresponding command. &lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;bash&amp;quot;&amp;gt;&lt;br /&gt;
#!/bin/bash&lt;br /&gt;
&lt;br /&gt;
# WiFi Client Setup&lt;br /&gt;
WIFI_SSID=&amp;quot;network-name&amp;quot;&lt;br /&gt;
WIFI_PASS=&amp;quot;passphrase&amp;quot;&lt;br /&gt;
&lt;br /&gt;
LED SETUP&lt;br /&gt;
WIFI_CONNECT&lt;br /&gt;
# optionally start SSH server&lt;br /&gt;
# /etc/init.d/sshd start&lt;br /&gt;
LED ATTACK&lt;br /&gt;
&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The &amp;lt;code&amp;gt;WIFI_CONNECT&amp;lt;/code&amp;gt; command executes the wifi_connect.sh payload extension, which is shown in the following listing. &lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;bash&amp;quot;&amp;gt;&lt;br /&gt;
#!/bin/bash&lt;br /&gt;
&lt;br /&gt;
function WIFI_CONNECT() {&lt;br /&gt;
    [[ &amp;quot;x$WIFI_INT&amp;quot; == &amp;quot;x&amp;quot; ]] &amp;amp;&amp;amp; WIFI_INT=wlan0&lt;br /&gt;
    ifconfig $WIFI_INT up;sleep 10&lt;br /&gt;
    echo -e &amp;quot;network={\nssid=\&amp;quot;$WIFI_SSID\&amp;quot;\npsk=\&amp;quot;$WIFI_PASS\&amp;quot;\npriority=1\n}&amp;quot;&amp;gt;/tmp/wpa-$WIFI_INT.conf&lt;br /&gt;
    wpa_supplicant -B -Dnl80211 -i $WIFI_INT -c /tmp/wpa-$WIFI_INT.conf&lt;br /&gt;
    while(iwconfig $WIFI_INT | grep Not-Associated); do sleep 1; done&lt;br /&gt;
    udhcpc -i $WIFI_INT&lt;br /&gt;
}&lt;br /&gt;
export -f WIFI_CONNECT&lt;br /&gt;
&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The payload extension code uses the &amp;lt;code&amp;gt;WIFI_SSID&amp;lt;/code&amp;gt; and &amp;lt;code&amp;gt;WIFI_PASS&amp;lt;/code&amp;gt; variables of the payload to connect the Signal Owl to the network. With the command &amp;lt;code&amp;gt;export -f WIFI_CONNECT&amp;lt;/code&amp;gt; the function &amp;lt;code&amp;gt;WIFI_CONNECT&amp;lt;/code&amp;gt; is exported so that it can be called from the payload. &lt;br /&gt;
&lt;br /&gt;
If the SSH server is enabled, any SSH-enabled device can connect to the Signal Owl over the network, even though Attack Mode is enabled. The [[#Default Settings|default settings]] of the device can be used again for the connection, if they have not been changed yet. However, the IP address in this case is the IP address of the Signal Owl in this network.&lt;br /&gt;
&lt;br /&gt;
= Used Hardware =&lt;br /&gt;
&lt;br /&gt;
[[Signal Owl]]&lt;br /&gt;
&lt;br /&gt;
= References =&lt;br /&gt;
&lt;br /&gt;
*https://docs.hak5.org/signal-owl/&lt;br /&gt;
*https://github.com/hak5/signalowl-payloads&lt;br /&gt;
&lt;br /&gt;
[[Category:Pentesting]]&lt;/div&gt;</summary>
		<author><name>MMayer</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=Hak5_Signal_Owl&amp;diff=10732</id>
		<title>Hak5 Signal Owl</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=Hak5_Signal_Owl&amp;diff=10732"/>
		<updated>2023-01-07T02:31:47Z</updated>

		<summary type="html">&lt;p&gt;MMayer: /* Open AP Nmap Scanner */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= Introduction =&lt;br /&gt;
&lt;br /&gt;
The [https://docs.hak5.org/signal-owl/ Signal Owl] is a hardware product developed by the company [https://shop.hak5.org/ Hak5].&lt;br /&gt;
It is a simple payload-based signals intelligence platform with a unique design for discreet planting or mobile operations on any engagement. The most popular application cases include classic network mapping and basic penetration tests for various wireless technologies.&lt;br /&gt;
&lt;br /&gt;
== Initial Setup ==&lt;br /&gt;
&lt;br /&gt;
When first unboxing the Signal Owl, the device runs a stager firmware that is designed to flash the latest firmware from a USB flash drive. In order to update the Signal Owl, the [https://downloads.hak5.org/owl latest firmware] has to be downloaded. Then, the downloaded file must be copied to the root of an EXT4 or FAT32 formatted USB flash drive. It is important not to modify this file. The next step is to plug the USB flash drive into the powered off Signal Owl. Afterwards, the device has to be powered on by a reliable USB source. The upgrade itself takes approximately five to ten minutes and is indicated by a solid red LED light. When finished, the device will reboot, enter Attack Mode and blink slowly, indicating an error running the payload because no payload has been found.&lt;br /&gt;
&lt;br /&gt;
= Hardware =&lt;br /&gt;
&lt;br /&gt;
[[File:SignalOwlDiagram.png|thumb|500px|frame|Components of the Signal Owl [Eigene Darstellung]]] &lt;br /&gt;
&lt;br /&gt;
The Signal Owl is designed to be rapidly deployed in all kinds of environments, allowing it to be an entry point for network analysis and basic wireless attacks in a variety of locations. With a power consumption of 100-200 mAh and the thermally optimized architecture, mobile operations as well as long term deployments, are enabled.&lt;br /&gt;
&lt;br /&gt;
== Components ==&lt;br /&gt;
&lt;br /&gt;
This device features several components of which some may not be visible to the human eye at first sight.&lt;br /&gt;
&lt;br /&gt;
=== USB Power / Passthrough Plug ===&lt;br /&gt;
&lt;br /&gt;
The USB power or passthrough plug is used to power the device. It can be powered from any reliable USB source.&lt;br /&gt;
&lt;br /&gt;
=== USB 2.0 Passthrough Port ===&lt;br /&gt;
&lt;br /&gt;
The USB 2.0 passthrough port is the port closest to the pigtail. Data and power pass through to that port, allowing for implant operations. If a device such as a keyboard is plugged in between this passthrough port and the power plug is connected to the target computer, the Signal Owl will remain undetected by the operating system. Only the keyboard will be visible on the target computer.&lt;br /&gt;
&lt;br /&gt;
=== USB 2.0 Host Port ===&lt;br /&gt;
&lt;br /&gt;
The USB 2.0 host port is the port farthest away from the pigtail. It is connected to the Linux socket of the Signal Owl and supports USB flash drives formatted with FAT32 and EXT4 file systems as well as many Wi-Fi, Bluetooth and other RF transceivers.&lt;br /&gt;
&lt;br /&gt;
=== Button ===&lt;br /&gt;
&lt;br /&gt;
The button on the bottom of the device is used to enter Arming Mode and to interact with payloads. It is not pressable without special tools like paperclips.&lt;br /&gt;
&lt;br /&gt;
=== Status LED ===&lt;br /&gt;
&lt;br /&gt;
The status LED indicates the current status of the Signal Owl. When it is turned off, it is not visible.&lt;br /&gt;
&lt;br /&gt;
The Signal Owl features a red LED with the following default status indications:&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
!|LED&lt;br /&gt;
!|Status&lt;br /&gt;
|-&lt;br /&gt;
|Blinking&lt;br /&gt;
|Booting&lt;br /&gt;
|-&lt;br /&gt;
|Solid&lt;br /&gt;
|Mounting external storage / Running upgrade&lt;br /&gt;
|-&lt;br /&gt;
|Single blinking&lt;br /&gt;
|Attack Mode&lt;br /&gt;
|-&lt;br /&gt;
|Double blinking&lt;br /&gt;
|Arming Mode&lt;br /&gt;
|-&lt;br /&gt;
|Slow blinking&lt;br /&gt;
|Error running payload&lt;br /&gt;
|-&lt;br /&gt;
|Fast blinking&lt;br /&gt;
|Select Mode (Deprecated from version 1.0.1 onward)&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= Software =&lt;br /&gt;
&lt;br /&gt;
== Modes of Operation ==&lt;br /&gt;
&lt;br /&gt;
The Signal Owl comes with two modes of operation, Attack Mode and Arming Mode. By default, the device will boot into Attack Mode. In order to access Arming Mode, the button on the bottom of the device has to be pressed while in Attack Mode. It is not recommended to press the button during the boot sequence, as this can possibly brick the device and render it useless. The arming mode is used for firmware updates and shell access, while the attack mode is used to load and execute the payload.&lt;br /&gt;
&lt;br /&gt;
=== Attack Mode ===&lt;br /&gt;
&lt;br /&gt;
Attack Mode is the default mode, the Signal Owl boots into. It provides two basic functions, being the payload loading function and the payload execution function. &lt;br /&gt;
&lt;br /&gt;
The payload loading function checks for any USB flash drives plugged into the host port of the device and copies payloads to &amp;lt;code&amp;gt;/root/payload&amp;lt;/code&amp;gt; and extensions to &amp;lt;code&amp;gt;/root/payload/extensions&amp;lt;/code&amp;gt; on the Signal Owl. &lt;br /&gt;
&lt;br /&gt;
The payload execution function is responsible for executing the payload that is currently stored on the root of the Signal Owl. In case no payload is found, the device will blink slowly, indicating the FAIL status.&lt;br /&gt;
&lt;br /&gt;
=== Arming Mode ===&lt;br /&gt;
&lt;br /&gt;
The Arming Mode provides two basic functions, being the firmware update function and the shell access function. The firmware update function checks for any USB flash drives plugged into the host port of the device and copies firmware upgrade files into the internal storage of the device and flashes it. The shell access function starts an open access point with the SSID Owl_xxxx in which xxxx indicates the last two octets of the device&#039;s MAC address. Additionally, a SSH server providing access to the shell of the Signal Owl is enabled.&lt;br /&gt;
&lt;br /&gt;
== Default Settings ==&lt;br /&gt;
&lt;br /&gt;
Default settings that are used in order to access the device via SSH are pictured in the table below.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
!colspan=&amp;quot;2&amp;quot;|Default Settings&lt;br /&gt;
|-&lt;br /&gt;
|Username&lt;br /&gt;
|root&lt;br /&gt;
|-&lt;br /&gt;
|Password&lt;br /&gt;
|hak5owl&lt;br /&gt;
|-&lt;br /&gt;
|SSID&lt;br /&gt;
|Owl_xxxx&lt;br /&gt;
|-&lt;br /&gt;
|IP Address&lt;br /&gt;
|172.16.56.1&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
SSH command: &amp;lt;code&amp;gt;ssh root@172.16.56.1&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The SSID during Arming Mode is Owl_xxxx in which xxxx indicates the last two octets of the devices MAC address.&lt;br /&gt;
&lt;br /&gt;
= Usage =&lt;br /&gt;
&lt;br /&gt;
== Arming Mode connection ==&lt;br /&gt;
&lt;br /&gt;
Step-by-step guide for accessing the arming mode&lt;br /&gt;
&lt;br /&gt;
#Click on the button located on the bottom of the Signal Owl while it is in attack mode. After pressing the button, the signal owl enters the arming mode and provides an open access point with the name Owl xxxx (where xxxx stands for the last two digits of the MAC address of the device).&lt;br /&gt;
#Connect to the access point.&amp;lt;br&amp;gt;[[File:Armingmode.png]][Eigene Darstellung]&lt;br /&gt;
#Now you can connect via ssh by using the [[#Default Settings|default settings]].&lt;br /&gt;
#After successful connection, you will end up in the root directory.&amp;lt;br&amp;gt;[[File:ArmingmodeSSH.png]][Eigene Darstellung]&lt;br /&gt;
#Now you can change the files and directories on the Signal Owl to view results, transfer payloads and extensions or to make further changes.&lt;br /&gt;
&lt;br /&gt;
== Directory structure ==&lt;br /&gt;
&lt;br /&gt;
The following directory tree shows the directory structure of the Signal Owl.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
/&lt;br /&gt;
├── loot&lt;br /&gt;
└── payload/&lt;br /&gt;
    └── extensions&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
*Loot - Directory where the Signal Owl saves loot while executing payloads that produce loot.&lt;br /&gt;
*Payload - This directory holds the current payload. &lt;br /&gt;
*Extensions -  This directory holds all extensions.&lt;br /&gt;
&lt;br /&gt;
== Adding Payloads and Extensions ==&lt;br /&gt;
&lt;br /&gt;
Adding a payload can be done in two different ways. Either with a USB flash drive or via the Signal Owl access point to the internal storage of the device. &lt;br /&gt;
&lt;br /&gt;
When booting, payloads on USB flash drives are given priority and will override payloads stored on the Signal Owl. To successfully copy a payload to the Signal Owl, the payload must be named &amp;lt;code&amp;gt;payload.txt&amp;lt;/code&amp;gt; or &amp;lt;code&amp;gt;payload.sh&amp;lt;/code&amp;gt; and it has to be placed in the &amp;lt;code&amp;gt;root&amp;lt;/code&amp;gt; directory of the flash drive. Similarly, payload extensions should be stored in a &amp;lt;code&amp;gt;/extensions&amp;lt;/code&amp;gt; directory on the flash drive. &lt;br /&gt;
&lt;br /&gt;
In addition, it is possible to transfer payloads and payload extensions to the device via the Signal Owl access point in arming mode using SSH. There they are stored in the &amp;lt;code&amp;gt;/root/payload&amp;lt;/code&amp;gt; directory and Payload Extensions are stored in the &amp;lt;code&amp;gt;/root/payload/extensions&amp;lt;/code&amp;gt; directory.&lt;br /&gt;
&lt;br /&gt;
== Payload Development ==&lt;br /&gt;
&lt;br /&gt;
Payloads for the Signal Owl are written in bash with [https://github.com/hak5darren/USB-Rubber-Ducky/wiki/Duckyscript Ducky Script] and can be created with any standard text editor. All payloads should begin with an interpreter directive, like the shebang &amp;lt;code&amp;gt;#!/bin/bash&amp;lt;/code&amp;gt; for bash payloads and payloads must be named either &amp;lt;code&amp;gt;payload.txt&amp;lt;/code&amp;gt; or &amp;lt;code&amp;gt;payload.sh&amp;lt;/code&amp;gt;. In order to create effective payloads, the Signal Owl comes with several preinstalled penetration testing tools. These are as follows: [https://nmap.org/ Nmap], [https://www.aircrack-ng.org/ Aircrack-ng], [https://github.com/aircrack-ng/mdk4 MDK4] and [https://www.kismetwireless.net/ Kismet].&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Tools&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
• Kismet - detector for wireless networks and devices.&lt;br /&gt;
&lt;br /&gt;
• MDK4 - Wi-Fi testing tool.&lt;br /&gt;
&lt;br /&gt;
• Aircrack-ng Suite - a complete suite of tools for WiFi network security assessment.&lt;br /&gt;
&lt;br /&gt;
• Nmap - open source utility for network discovery and security auditing.&lt;br /&gt;
&lt;br /&gt;
Hak5 offers ready-to-use payloads and payload extensions on their [https://github.com/hak5/signalowl-payloads GitHub repository].&lt;br /&gt;
&lt;br /&gt;
== Implant / mobile operations ==&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Implant operations&lt;br /&gt;
&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
During long term wireless engagements, the Signal Owl may be planted inline between any typical 5V USB power source. This may be useful in situations where ports are occupied, or to deter the unit from being unplugged.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Mobile operations&lt;br /&gt;
&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
The Signal Owl features a low power consumption profile, with a typical power draw averaging 100-200 mAh. Additionally, it is thermally optimized for long term deployments in many indoor environments. One can expect a large 20,000 mAh USB battery bank to operate the unit for up to 4 days.&lt;br /&gt;
&lt;br /&gt;
= Use Cases =&lt;br /&gt;
&lt;br /&gt;
The Signal Owl has a variety of different use cases. Among the most popular ones are classical network mapping and wardriving as well as basic penetration tests for different wireless technologies.&lt;br /&gt;
&lt;br /&gt;
== Fake Beacon Flooding Attack ==&lt;br /&gt;
&lt;br /&gt;
The Fake Beacon Flooding Attack is one possible use case for the Signal Owl. With that attack, fake beacon frames are broadcasted to nearby devices. Beacon Frames include various parameters like the SSID, the type of encryption used and timestamps. This results in the creation of multiple fake Wi-Fi networks. Devices with Wi-Fi browsers are then flooded with these fake networks, causing potential network scanner and driver crashes. Furthermore, the attack may prevent legitimate users from finding their networks and lead to denial of service. The preinstalled tools Aircrack-ng and MDK4 were used to create this payload. After powering on the device, multiple fake networks with random SSIDs are generated and broadcasted to all nearby devices.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;bash&amp;quot;&amp;gt;&lt;br /&gt;
#!/bin/bash&lt;br /&gt;
&lt;br /&gt;
LED SETUP&lt;br /&gt;
sleep 10&lt;br /&gt;
airmon-ng check kill&lt;br /&gt;
sleep 10&lt;br /&gt;
#creates monitor mode interface on wirelss card of the Signal Owl&lt;br /&gt;
airmon-ng start wlan0&lt;br /&gt;
sleep 10&lt;br /&gt;
LED ATTACK&lt;br /&gt;
#floods nearby devices with random SSIDs&lt;br /&gt;
mdk4 wlan0mon b -a -m -s 500&lt;br /&gt;
&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The results as seen from a victim running a Windows 10 system are pictured in the figure below.&lt;br /&gt;
&lt;br /&gt;
[[File:FakeBeaconFloodingSignalOwl.png|none|Random SSIDs as seen from a victim Windows 10 client |]][Eigene Darstellung]&lt;br /&gt;
&lt;br /&gt;
== Open AP Nmap Scanner ==&lt;br /&gt;
&lt;br /&gt;
With the Open AP Nmap Scanner payload, the Signal Owl scans for open access points. If the Signal Owl finds one or more open access points, it connects to them and uses Nmap to scan and analyze them. The results are then stored in the loot directory. For each discovered open access point, the Signal Owl generates a separate results file. This payload has some settings which can be seen in the following listing.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;bash&amp;quot;&amp;gt;&lt;br /&gt;
NMAP_OPTIONS=&amp;quot;-sP&amp;quot;&lt;br /&gt;
LOOT_DIR=/root/loot/open_ap_nmap_scan&lt;br /&gt;
MAX_CIDR=20&lt;br /&gt;
DEBUG=1&lt;br /&gt;
&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
*NMAP_OPTIONS - Is used to specify the type of Nmap scan.&lt;br /&gt;
*LOOT_DIR - Sets the destination folder for the scan results.&lt;br /&gt;
*MAX_CIDR - Sets the maximum Classless Inter-Domain Routing&lt;br /&gt;
*DEBUG - Specifies if debug information is saved to the payload.log file in the tmp folder.&lt;br /&gt;
** 1 - Debug information is saved.&lt;br /&gt;
** 0 - Debug information is not saved.&lt;br /&gt;
&lt;br /&gt;
[[File:OpenAPNmapScannerResult.png|750px]]&lt;br /&gt;
&lt;br /&gt;
== Basic Bluetooth Scanner ==&lt;br /&gt;
&lt;br /&gt;
This payload requires an external Bluetooth adapter, since the Signal Owl does not have Bluetooth built in. The Basic Bluetooth Scanner scans for devices that have Bluetooth enabled and optionally queries them using the hcitool and the info command. This payload does also have some settings, as shown in the listing below.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;bash&amp;quot;&amp;gt;&lt;br /&gt;
LOOT_DIR=/root/loot/bluetooth_scan&lt;br /&gt;
BT_OUTFILE=`date +%s`.bt.list&lt;br /&gt;
BT_INFOFILE=`date +%s`.bt.info   &lt;br /&gt;
BTDEV=hci0&lt;br /&gt;
DEBUG=0 &lt;br /&gt;
INTERROGATE=1 &lt;br /&gt;
&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
*LOOT_DIR - Sets the directory for the scan result.&lt;br /&gt;
*BT_OUTFILE - Sets a file name, in which all detected names and MAC addresses are saved.&lt;br /&gt;
*BT_INFOFILE - Sets a file name, in which the details of the discovered devices are saved if the INTERROGATE variable is set to 1. &lt;br /&gt;
*BTDEV - Specifies the bluetooth device used for scanning.&lt;br /&gt;
*DEBUG - Specifies if debug information is saved to the payload.log file in the tmp folder.&lt;br /&gt;
** 1 - Debug information is saved.&lt;br /&gt;
** 0 - Debug information is not saved.&lt;br /&gt;
*INTERROGATE - Specifies if the detected devices are interrogated.&lt;br /&gt;
** 1 - Detected devices are interrogated&lt;br /&gt;
** 0 - Detected devices are not interrogated&lt;br /&gt;
&lt;br /&gt;
== WiFi Connect ==&lt;br /&gt;
&lt;br /&gt;
With the WiFi Connect payload, which can be seen in the following Listing, and the wificonnect.sh Payload extension, the Signal Owl can be connected to a nearby network. The SSID and password of the network to which the Signal Owl should connect must be specified in the code. Optionally, the SSH server of the device can be started by removing the hash sign in the code before the corresponding command. &lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;bash&amp;quot;&amp;gt;&lt;br /&gt;
#!/bin/bash&lt;br /&gt;
&lt;br /&gt;
# WiFi Client Setup&lt;br /&gt;
WIFI_SSID=&amp;quot;network-name&amp;quot;&lt;br /&gt;
WIFI_PASS=&amp;quot;passphrase&amp;quot;&lt;br /&gt;
&lt;br /&gt;
LED SETUP&lt;br /&gt;
WIFI_CONNECT&lt;br /&gt;
# optionally start SSH server&lt;br /&gt;
# /etc/init.d/sshd start&lt;br /&gt;
LED ATTACK&lt;br /&gt;
&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The &amp;lt;code&amp;gt;WIFI_CONNECT&amp;lt;/code&amp;gt; command executes the wifi_connect.sh payload extension, which is shown in the following listing. &lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;bash&amp;quot;&amp;gt;&lt;br /&gt;
#!/bin/bash&lt;br /&gt;
&lt;br /&gt;
function WIFI_CONNECT() {&lt;br /&gt;
    [[ &amp;quot;x$WIFI_INT&amp;quot; == &amp;quot;x&amp;quot; ]] &amp;amp;&amp;amp; WIFI_INT=wlan0&lt;br /&gt;
    ifconfig $WIFI_INT up;sleep 10&lt;br /&gt;
    echo -e &amp;quot;network={\nssid=\&amp;quot;$WIFI_SSID\&amp;quot;\npsk=\&amp;quot;$WIFI_PASS\&amp;quot;\npriority=1\n}&amp;quot;&amp;gt;/tmp/wpa-$WIFI_INT.conf&lt;br /&gt;
    wpa_supplicant -B -Dnl80211 -i $WIFI_INT -c /tmp/wpa-$WIFI_INT.conf&lt;br /&gt;
    while(iwconfig $WIFI_INT | grep Not-Associated); do sleep 1; done&lt;br /&gt;
    udhcpc -i $WIFI_INT&lt;br /&gt;
}&lt;br /&gt;
export -f WIFI_CONNECT&lt;br /&gt;
&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The payload extension code uses the &amp;lt;code&amp;gt;WIFI_SSID&amp;lt;/code&amp;gt; and &amp;lt;code&amp;gt;WIFI_PASS&amp;lt;/code&amp;gt; variables of the payload to connect the Signal Owl to the network. With the command &amp;lt;code&amp;gt;export -f WIFI_CONNECT&amp;lt;/code&amp;gt; the function &amp;lt;code&amp;gt;WIFI_CONNECT&amp;lt;/code&amp;gt; is exported so that it can be called from the payload. &lt;br /&gt;
&lt;br /&gt;
If the SSH server is enabled, any SSH-enabled device can connect to the Signal Owl over the network, even though Attack Mode is enabled. The [[#Default Settings|default settings]] of the device can be used again for the connection, if they have not been changed yet. However, the IP address in this case is the IP address of the Signal Owl in this network.&lt;br /&gt;
&lt;br /&gt;
= Used Hardware =&lt;br /&gt;
&lt;br /&gt;
[[Signal Owl]]&lt;br /&gt;
&lt;br /&gt;
= References =&lt;br /&gt;
&lt;br /&gt;
*https://docs.hak5.org/signal-owl/&lt;br /&gt;
*https://github.com/hak5/signalowl-payloads&lt;br /&gt;
&lt;br /&gt;
[[Category:Pentesting]]&lt;/div&gt;</summary>
		<author><name>MMayer</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=File:OpenAPNmapScannerResult.png&amp;diff=10731</id>
		<title>File:OpenAPNmapScannerResult.png</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=File:OpenAPNmapScannerResult.png&amp;diff=10731"/>
		<updated>2023-01-07T02:28:02Z</updated>

		<summary type="html">&lt;p&gt;MMayer: /* Summary */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Summary ==&lt;br /&gt;
The results of a scan with the Open AP Nmap Scanner payload.&lt;/div&gt;</summary>
		<author><name>MMayer</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=Hak5_Signal_Owl&amp;diff=10730</id>
		<title>Hak5 Signal Owl</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=Hak5_Signal_Owl&amp;diff=10730"/>
		<updated>2023-01-07T02:27:01Z</updated>

		<summary type="html">&lt;p&gt;MMayer: /* Open AP Nmap Scanner */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= Introduction =&lt;br /&gt;
&lt;br /&gt;
The [https://docs.hak5.org/signal-owl/ Signal Owl] is a hardware product developed by the company [https://shop.hak5.org/ Hak5].&lt;br /&gt;
It is a simple payload-based signals intelligence platform with a unique design for discreet planting or mobile operations on any engagement. The most popular application cases include classic network mapping and basic penetration tests for various wireless technologies.&lt;br /&gt;
&lt;br /&gt;
== Initial Setup ==&lt;br /&gt;
&lt;br /&gt;
When first unboxing the Signal Owl, the device runs a stager firmware that is designed to flash the latest firmware from a USB flash drive. In order to update the Signal Owl, the [https://downloads.hak5.org/owl latest firmware] has to be downloaded. Then, the downloaded file must be copied to the root of an EXT4 or FAT32 formatted USB flash drive. It is important not to modify this file. The next step is to plug the USB flash drive into the powered off Signal Owl. Afterwards, the device has to be powered on by a reliable USB source. The upgrade itself takes approximately five to ten minutes and is indicated by a solid red LED light. When finished, the device will reboot, enter Attack Mode and blink slowly, indicating an error running the payload because no payload has been found.&lt;br /&gt;
&lt;br /&gt;
= Hardware =&lt;br /&gt;
&lt;br /&gt;
[[File:SignalOwlDiagram.png|thumb|500px|frame|Components of the Signal Owl [Eigene Darstellung]]] &lt;br /&gt;
&lt;br /&gt;
The Signal Owl is designed to be rapidly deployed in all kinds of environments, allowing it to be an entry point for network analysis and basic wireless attacks in a variety of locations. With a power consumption of 100-200 mAh and the thermally optimized architecture, mobile operations as well as long term deployments, are enabled.&lt;br /&gt;
&lt;br /&gt;
== Components ==&lt;br /&gt;
&lt;br /&gt;
This device features several components of which some may not be visible to the human eye at first sight.&lt;br /&gt;
&lt;br /&gt;
=== USB Power / Passthrough Plug ===&lt;br /&gt;
&lt;br /&gt;
The USB power or passthrough plug is used to power the device. It can be powered from any reliable USB source.&lt;br /&gt;
&lt;br /&gt;
=== USB 2.0 Passthrough Port ===&lt;br /&gt;
&lt;br /&gt;
The USB 2.0 passthrough port is the port closest to the pigtail. Data and power pass through to that port, allowing for implant operations. If a device such as a keyboard is plugged in between this passthrough port and the power plug is connected to the target computer, the Signal Owl will remain undetected by the operating system. Only the keyboard will be visible on the target computer.&lt;br /&gt;
&lt;br /&gt;
=== USB 2.0 Host Port ===&lt;br /&gt;
&lt;br /&gt;
The USB 2.0 host port is the port farthest away from the pigtail. It is connected to the Linux socket of the Signal Owl and supports USB flash drives formatted with FAT32 and EXT4 file systems as well as many Wi-Fi, Bluetooth and other RF transceivers.&lt;br /&gt;
&lt;br /&gt;
=== Button ===&lt;br /&gt;
&lt;br /&gt;
The button on the bottom of the device is used to enter Arming Mode and to interact with payloads. It is not pressable without special tools like paperclips.&lt;br /&gt;
&lt;br /&gt;
=== Status LED ===&lt;br /&gt;
&lt;br /&gt;
The status LED indicates the current status of the Signal Owl. When it is turned off, it is not visible.&lt;br /&gt;
&lt;br /&gt;
The Signal Owl features a red LED with the following default status indications:&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
!|LED&lt;br /&gt;
!|Status&lt;br /&gt;
|-&lt;br /&gt;
|Blinking&lt;br /&gt;
|Booting&lt;br /&gt;
|-&lt;br /&gt;
|Solid&lt;br /&gt;
|Mounting external storage / Running upgrade&lt;br /&gt;
|-&lt;br /&gt;
|Single blinking&lt;br /&gt;
|Attack Mode&lt;br /&gt;
|-&lt;br /&gt;
|Double blinking&lt;br /&gt;
|Arming Mode&lt;br /&gt;
|-&lt;br /&gt;
|Slow blinking&lt;br /&gt;
|Error running payload&lt;br /&gt;
|-&lt;br /&gt;
|Fast blinking&lt;br /&gt;
|Select Mode (Deprecated from version 1.0.1 onward)&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= Software =&lt;br /&gt;
&lt;br /&gt;
== Modes of Operation ==&lt;br /&gt;
&lt;br /&gt;
The Signal Owl comes with two modes of operation, Attack Mode and Arming Mode. By default, the device will boot into Attack Mode. In order to access Arming Mode, the button on the bottom of the device has to be pressed while in Attack Mode. It is not recommended to press the button during the boot sequence, as this can possibly brick the device and render it useless. The arming mode is used for firmware updates and shell access, while the attack mode is used to load and execute the payload.&lt;br /&gt;
&lt;br /&gt;
=== Attack Mode ===&lt;br /&gt;
&lt;br /&gt;
Attack Mode is the default mode, the Signal Owl boots into. It provides two basic functions, being the payload loading function and the payload execution function. &lt;br /&gt;
&lt;br /&gt;
The payload loading function checks for any USB flash drives plugged into the host port of the device and copies payloads to &amp;lt;code&amp;gt;/root/payload&amp;lt;/code&amp;gt; and extensions to &amp;lt;code&amp;gt;/root/payload/extensions&amp;lt;/code&amp;gt; on the Signal Owl. &lt;br /&gt;
&lt;br /&gt;
The payload execution function is responsible for executing the payload that is currently stored on the root of the Signal Owl. In case no payload is found, the device will blink slowly, indicating the FAIL status.&lt;br /&gt;
&lt;br /&gt;
=== Arming Mode ===&lt;br /&gt;
&lt;br /&gt;
The Arming Mode provides two basic functions, being the firmware update function and the shell access function. The firmware update function checks for any USB flash drives plugged into the host port of the device and copies firmware upgrade files into the internal storage of the device and flashes it. The shell access function starts an open access point with the SSID Owl_xxxx in which xxxx indicates the last two octets of the device&#039;s MAC address. Additionally, a SSH server providing access to the shell of the Signal Owl is enabled.&lt;br /&gt;
&lt;br /&gt;
== Default Settings ==&lt;br /&gt;
&lt;br /&gt;
Default settings that are used in order to access the device via SSH are pictured in the table below.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
!colspan=&amp;quot;2&amp;quot;|Default Settings&lt;br /&gt;
|-&lt;br /&gt;
|Username&lt;br /&gt;
|root&lt;br /&gt;
|-&lt;br /&gt;
|Password&lt;br /&gt;
|hak5owl&lt;br /&gt;
|-&lt;br /&gt;
|SSID&lt;br /&gt;
|Owl_xxxx&lt;br /&gt;
|-&lt;br /&gt;
|IP Address&lt;br /&gt;
|172.16.56.1&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
SSH command: &amp;lt;code&amp;gt;ssh root@172.16.56.1&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The SSID during Arming Mode is Owl_xxxx in which xxxx indicates the last two octets of the devices MAC address.&lt;br /&gt;
&lt;br /&gt;
= Usage =&lt;br /&gt;
&lt;br /&gt;
== Arming Mode connection ==&lt;br /&gt;
&lt;br /&gt;
Step-by-step guide for accessing the arming mode&lt;br /&gt;
&lt;br /&gt;
#Click on the button located on the bottom of the Signal Owl while it is in attack mode. After pressing the button, the signal owl enters the arming mode and provides an open access point with the name Owl xxxx (where xxxx stands for the last two digits of the MAC address of the device).&lt;br /&gt;
#Connect to the access point.&amp;lt;br&amp;gt;[[File:Armingmode.png]][Eigene Darstellung]&lt;br /&gt;
#Now you can connect via ssh by using the [[#Default Settings|default settings]].&lt;br /&gt;
#After successful connection, you will end up in the root directory.&amp;lt;br&amp;gt;[[File:ArmingmodeSSH.png]][Eigene Darstellung]&lt;br /&gt;
#Now you can change the files and directories on the Signal Owl to view results, transfer payloads and extensions or to make further changes.&lt;br /&gt;
&lt;br /&gt;
== Directory structure ==&lt;br /&gt;
&lt;br /&gt;
The following directory tree shows the directory structure of the Signal Owl.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
/&lt;br /&gt;
├── loot&lt;br /&gt;
└── payload/&lt;br /&gt;
    └── extensions&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
*Loot - Directory where the Signal Owl saves loot while executing payloads that produce loot.&lt;br /&gt;
*Payload - This directory holds the current payload. &lt;br /&gt;
*Extensions -  This directory holds all extensions.&lt;br /&gt;
&lt;br /&gt;
== Adding Payloads and Extensions ==&lt;br /&gt;
&lt;br /&gt;
Adding a payload can be done in two different ways. Either with a USB flash drive or via the Signal Owl access point to the internal storage of the device. &lt;br /&gt;
&lt;br /&gt;
When booting, payloads on USB flash drives are given priority and will override payloads stored on the Signal Owl. To successfully copy a payload to the Signal Owl, the payload must be named &amp;lt;code&amp;gt;payload.txt&amp;lt;/code&amp;gt; or &amp;lt;code&amp;gt;payload.sh&amp;lt;/code&amp;gt; and it has to be placed in the &amp;lt;code&amp;gt;root&amp;lt;/code&amp;gt; directory of the flash drive. Similarly, payload extensions should be stored in a &amp;lt;code&amp;gt;/extensions&amp;lt;/code&amp;gt; directory on the flash drive. &lt;br /&gt;
&lt;br /&gt;
In addition, it is possible to transfer payloads and payload extensions to the device via the Signal Owl access point in arming mode using SSH. There they are stored in the &amp;lt;code&amp;gt;/root/payload&amp;lt;/code&amp;gt; directory and Payload Extensions are stored in the &amp;lt;code&amp;gt;/root/payload/extensions&amp;lt;/code&amp;gt; directory.&lt;br /&gt;
&lt;br /&gt;
== Payload Development ==&lt;br /&gt;
&lt;br /&gt;
Payloads for the Signal Owl are written in bash with [https://github.com/hak5darren/USB-Rubber-Ducky/wiki/Duckyscript Ducky Script] and can be created with any standard text editor. All payloads should begin with an interpreter directive, like the shebang &amp;lt;code&amp;gt;#!/bin/bash&amp;lt;/code&amp;gt; for bash payloads and payloads must be named either &amp;lt;code&amp;gt;payload.txt&amp;lt;/code&amp;gt; or &amp;lt;code&amp;gt;payload.sh&amp;lt;/code&amp;gt;. In order to create effective payloads, the Signal Owl comes with several preinstalled penetration testing tools. These are as follows: [https://nmap.org/ Nmap], [https://www.aircrack-ng.org/ Aircrack-ng], [https://github.com/aircrack-ng/mdk4 MDK4] and [https://www.kismetwireless.net/ Kismet].&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Tools&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
• Kismet - detector for wireless networks and devices.&lt;br /&gt;
&lt;br /&gt;
• MDK4 - Wi-Fi testing tool.&lt;br /&gt;
&lt;br /&gt;
• Aircrack-ng Suite - a complete suite of tools for WiFi network security assessment.&lt;br /&gt;
&lt;br /&gt;
• Nmap - open source utility for network discovery and security auditing.&lt;br /&gt;
&lt;br /&gt;
Hak5 offers ready-to-use payloads and payload extensions on their [https://github.com/hak5/signalowl-payloads GitHub repository].&lt;br /&gt;
&lt;br /&gt;
== Implant / mobile operations ==&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Implant operations&lt;br /&gt;
&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
During long term wireless engagements, the Signal Owl may be planted inline between any typical 5V USB power source. This may be useful in situations where ports are occupied, or to deter the unit from being unplugged.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Mobile operations&lt;br /&gt;
&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
The Signal Owl features a low power consumption profile, with a typical power draw averaging 100-200 mAh. Additionally, it is thermally optimized for long term deployments in many indoor environments. One can expect a large 20,000 mAh USB battery bank to operate the unit for up to 4 days.&lt;br /&gt;
&lt;br /&gt;
= Use Cases =&lt;br /&gt;
&lt;br /&gt;
The Signal Owl has a variety of different use cases. Among the most popular ones are classical network mapping and wardriving as well as basic penetration tests for different wireless technologies.&lt;br /&gt;
&lt;br /&gt;
== Fake Beacon Flooding Attack ==&lt;br /&gt;
&lt;br /&gt;
The Fake Beacon Flooding Attack is one possible use case for the Signal Owl. With that attack, fake beacon frames are broadcasted to nearby devices. Beacon Frames include various parameters like the SSID, the type of encryption used and timestamps. This results in the creation of multiple fake Wi-Fi networks. Devices with Wi-Fi browsers are then flooded with these fake networks, causing potential network scanner and driver crashes. Furthermore, the attack may prevent legitimate users from finding their networks and lead to denial of service. The preinstalled tools Aircrack-ng and MDK4 were used to create this payload. After powering on the device, multiple fake networks with random SSIDs are generated and broadcasted to all nearby devices.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;bash&amp;quot;&amp;gt;&lt;br /&gt;
#!/bin/bash&lt;br /&gt;
&lt;br /&gt;
LED SETUP&lt;br /&gt;
sleep 10&lt;br /&gt;
airmon-ng check kill&lt;br /&gt;
sleep 10&lt;br /&gt;
#creates monitor mode interface on wirelss card of the Signal Owl&lt;br /&gt;
airmon-ng start wlan0&lt;br /&gt;
sleep 10&lt;br /&gt;
LED ATTACK&lt;br /&gt;
#floods nearby devices with random SSIDs&lt;br /&gt;
mdk4 wlan0mon b -a -m -s 500&lt;br /&gt;
&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The results as seen from a victim running a Windows 10 system are pictured in the figure below.&lt;br /&gt;
&lt;br /&gt;
[[File:FakeBeaconFloodingSignalOwl.png|none|Random SSIDs as seen from a victim Windows 10 client |]][Eigene Darstellung]&lt;br /&gt;
&lt;br /&gt;
== Open AP Nmap Scanner ==&lt;br /&gt;
&lt;br /&gt;
With the Open AP Nmap Scanner payload, the Signal Owl scans for open access points. If the Signal Owl finds one or more open access points, it connects to them and uses Nmap to scan and analyze them. The results are then stored in the loot directory. For each discovered open access point, the Signal Owl generates a separate results file. This payload has some settings which can be seen in the following listing.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;bash&amp;quot;&amp;gt;&lt;br /&gt;
NMAP_OPTIONS=&amp;quot;-sP&amp;quot;&lt;br /&gt;
LOOT_DIR=/root/loot/open_ap_nmap_scan&lt;br /&gt;
MAX_CIDR=20&lt;br /&gt;
DEBUG=1&lt;br /&gt;
&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
*NMAP_OPTIONS - Is used to specify the type of Nmap scan.&lt;br /&gt;
*LOOT_DIR - Sets the destination folder for the scan results.&lt;br /&gt;
*MAX_CIDR - Sets the maximum Classless Inter-Domain Routing&lt;br /&gt;
*DEBUG - Specifies if debug information is saved to the payload.log file in the tmp folder.&lt;br /&gt;
** 1 - Debug information is saved.&lt;br /&gt;
** 0 - Debug information is not saved.&lt;br /&gt;
&lt;br /&gt;
[[File:OpenAPNmapScannerResult.png]]&lt;br /&gt;
&lt;br /&gt;
== Basic Bluetooth Scanner ==&lt;br /&gt;
&lt;br /&gt;
This payload requires an external Bluetooth adapter, since the Signal Owl does not have Bluetooth built in. The Basic Bluetooth Scanner scans for devices that have Bluetooth enabled and optionally queries them using the hcitool and the info command. This payload does also have some settings, as shown in the listing below.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;bash&amp;quot;&amp;gt;&lt;br /&gt;
LOOT_DIR=/root/loot/bluetooth_scan&lt;br /&gt;
BT_OUTFILE=`date +%s`.bt.list&lt;br /&gt;
BT_INFOFILE=`date +%s`.bt.info   &lt;br /&gt;
BTDEV=hci0&lt;br /&gt;
DEBUG=0 &lt;br /&gt;
INTERROGATE=1 &lt;br /&gt;
&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
*LOOT_DIR - Sets the directory for the scan result.&lt;br /&gt;
*BT_OUTFILE - Sets a file name, in which all detected names and MAC addresses are saved.&lt;br /&gt;
*BT_INFOFILE - Sets a file name, in which the details of the discovered devices are saved if the INTERROGATE variable is set to 1. &lt;br /&gt;
*BTDEV - Specifies the bluetooth device used for scanning.&lt;br /&gt;
*DEBUG - Specifies if debug information is saved to the payload.log file in the tmp folder.&lt;br /&gt;
** 1 - Debug information is saved.&lt;br /&gt;
** 0 - Debug information is not saved.&lt;br /&gt;
*INTERROGATE - Specifies if the detected devices are interrogated.&lt;br /&gt;
** 1 - Detected devices are interrogated&lt;br /&gt;
** 0 - Detected devices are not interrogated&lt;br /&gt;
&lt;br /&gt;
== WiFi Connect ==&lt;br /&gt;
&lt;br /&gt;
With the WiFi Connect payload, which can be seen in the following Listing, and the wificonnect.sh Payload extension, the Signal Owl can be connected to a nearby network. The SSID and password of the network to which the Signal Owl should connect must be specified in the code. Optionally, the SSH server of the device can be started by removing the hash sign in the code before the corresponding command. &lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;bash&amp;quot;&amp;gt;&lt;br /&gt;
#!/bin/bash&lt;br /&gt;
&lt;br /&gt;
# WiFi Client Setup&lt;br /&gt;
WIFI_SSID=&amp;quot;network-name&amp;quot;&lt;br /&gt;
WIFI_PASS=&amp;quot;passphrase&amp;quot;&lt;br /&gt;
&lt;br /&gt;
LED SETUP&lt;br /&gt;
WIFI_CONNECT&lt;br /&gt;
# optionally start SSH server&lt;br /&gt;
# /etc/init.d/sshd start&lt;br /&gt;
LED ATTACK&lt;br /&gt;
&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The &amp;lt;code&amp;gt;WIFI_CONNECT&amp;lt;/code&amp;gt; command executes the wifi_connect.sh payload extension, which is shown in the following listing. &lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;bash&amp;quot;&amp;gt;&lt;br /&gt;
#!/bin/bash&lt;br /&gt;
&lt;br /&gt;
function WIFI_CONNECT() {&lt;br /&gt;
    [[ &amp;quot;x$WIFI_INT&amp;quot; == &amp;quot;x&amp;quot; ]] &amp;amp;&amp;amp; WIFI_INT=wlan0&lt;br /&gt;
    ifconfig $WIFI_INT up;sleep 10&lt;br /&gt;
    echo -e &amp;quot;network={\nssid=\&amp;quot;$WIFI_SSID\&amp;quot;\npsk=\&amp;quot;$WIFI_PASS\&amp;quot;\npriority=1\n}&amp;quot;&amp;gt;/tmp/wpa-$WIFI_INT.conf&lt;br /&gt;
    wpa_supplicant -B -Dnl80211 -i $WIFI_INT -c /tmp/wpa-$WIFI_INT.conf&lt;br /&gt;
    while(iwconfig $WIFI_INT | grep Not-Associated); do sleep 1; done&lt;br /&gt;
    udhcpc -i $WIFI_INT&lt;br /&gt;
}&lt;br /&gt;
export -f WIFI_CONNECT&lt;br /&gt;
&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The payload extension code uses the &amp;lt;code&amp;gt;WIFI_SSID&amp;lt;/code&amp;gt; and &amp;lt;code&amp;gt;WIFI_PASS&amp;lt;/code&amp;gt; variables of the payload to connect the Signal Owl to the network. With the command &amp;lt;code&amp;gt;export -f WIFI_CONNECT&amp;lt;/code&amp;gt; the function &amp;lt;code&amp;gt;WIFI_CONNECT&amp;lt;/code&amp;gt; is exported so that it can be called from the payload. &lt;br /&gt;
&lt;br /&gt;
If the SSH server is enabled, any SSH-enabled device can connect to the Signal Owl over the network, even though Attack Mode is enabled. The [[#Default Settings|default settings]] of the device can be used again for the connection, if they have not been changed yet. However, the IP address in this case is the IP address of the Signal Owl in this network.&lt;br /&gt;
&lt;br /&gt;
= Used Hardware =&lt;br /&gt;
&lt;br /&gt;
[[Signal Owl]]&lt;br /&gt;
&lt;br /&gt;
= References =&lt;br /&gt;
&lt;br /&gt;
*https://docs.hak5.org/signal-owl/&lt;br /&gt;
*https://github.com/hak5/signalowl-payloads&lt;br /&gt;
&lt;br /&gt;
[[Category:Pentesting]]&lt;/div&gt;</summary>
		<author><name>MMayer</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=File:OpenAPNmapScannerResult.png&amp;diff=10729</id>
		<title>File:OpenAPNmapScannerResult.png</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=File:OpenAPNmapScannerResult.png&amp;diff=10729"/>
		<updated>2023-01-07T02:25:57Z</updated>

		<summary type="html">&lt;p&gt;MMayer: The results of a scan with this payload can be seen in the figure below.&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Summary ==&lt;br /&gt;
The results of a scan with this payload can be seen in the figure below.&lt;/div&gt;</summary>
		<author><name>MMayer</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=Hak5_Signal_Owl&amp;diff=10728</id>
		<title>Hak5 Signal Owl</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=Hak5_Signal_Owl&amp;diff=10728"/>
		<updated>2023-01-07T02:16:37Z</updated>

		<summary type="html">&lt;p&gt;MMayer: /* Basic Bluetooth Scanner */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= Introduction =&lt;br /&gt;
&lt;br /&gt;
The [https://docs.hak5.org/signal-owl/ Signal Owl] is a hardware product developed by the company [https://shop.hak5.org/ Hak5].&lt;br /&gt;
It is a simple payload-based signals intelligence platform with a unique design for discreet planting or mobile operations on any engagement. The most popular application cases include classic network mapping and basic penetration tests for various wireless technologies.&lt;br /&gt;
&lt;br /&gt;
== Initial Setup ==&lt;br /&gt;
&lt;br /&gt;
When first unboxing the Signal Owl, the device runs a stager firmware that is designed to flash the latest firmware from a USB flash drive. In order to update the Signal Owl, the [https://downloads.hak5.org/owl latest firmware] has to be downloaded. Then, the downloaded file must be copied to the root of an EXT4 or FAT32 formatted USB flash drive. It is important not to modify this file. The next step is to plug the USB flash drive into the powered off Signal Owl. Afterwards, the device has to be powered on by a reliable USB source. The upgrade itself takes approximately five to ten minutes and is indicated by a solid red LED light. When finished, the device will reboot, enter Attack Mode and blink slowly, indicating an error running the payload because no payload has been found.&lt;br /&gt;
&lt;br /&gt;
= Hardware =&lt;br /&gt;
&lt;br /&gt;
[[File:SignalOwlDiagram.png|thumb|500px|frame|Components of the Signal Owl [Eigene Darstellung]]] &lt;br /&gt;
&lt;br /&gt;
The Signal Owl is designed to be rapidly deployed in all kinds of environments, allowing it to be an entry point for network analysis and basic wireless attacks in a variety of locations. With a power consumption of 100-200 mAh and the thermally optimized architecture, mobile operations as well as long term deployments, are enabled.&lt;br /&gt;
&lt;br /&gt;
== Components ==&lt;br /&gt;
&lt;br /&gt;
This device features several components of which some may not be visible to the human eye at first sight.&lt;br /&gt;
&lt;br /&gt;
=== USB Power / Passthrough Plug ===&lt;br /&gt;
&lt;br /&gt;
The USB power or passthrough plug is used to power the device. It can be powered from any reliable USB source.&lt;br /&gt;
&lt;br /&gt;
=== USB 2.0 Passthrough Port ===&lt;br /&gt;
&lt;br /&gt;
The USB 2.0 passthrough port is the port closest to the pigtail. Data and power pass through to that port, allowing for implant operations. If a device such as a keyboard is plugged in between this passthrough port and the power plug is connected to the target computer, the Signal Owl will remain undetected by the operating system. Only the keyboard will be visible on the target computer.&lt;br /&gt;
&lt;br /&gt;
=== USB 2.0 Host Port ===&lt;br /&gt;
&lt;br /&gt;
The USB 2.0 host port is the port farthest away from the pigtail. It is connected to the Linux socket of the Signal Owl and supports USB flash drives formatted with FAT32 and EXT4 file systems as well as many Wi-Fi, Bluetooth and other RF transceivers.&lt;br /&gt;
&lt;br /&gt;
=== Button ===&lt;br /&gt;
&lt;br /&gt;
The button on the bottom of the device is used to enter Arming Mode and to interact with payloads. It is not pressable without special tools like paperclips.&lt;br /&gt;
&lt;br /&gt;
=== Status LED ===&lt;br /&gt;
&lt;br /&gt;
The status LED indicates the current status of the Signal Owl. When it is turned off, it is not visible.&lt;br /&gt;
&lt;br /&gt;
The Signal Owl features a red LED with the following default status indications:&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
!|LED&lt;br /&gt;
!|Status&lt;br /&gt;
|-&lt;br /&gt;
|Blinking&lt;br /&gt;
|Booting&lt;br /&gt;
|-&lt;br /&gt;
|Solid&lt;br /&gt;
|Mounting external storage / Running upgrade&lt;br /&gt;
|-&lt;br /&gt;
|Single blinking&lt;br /&gt;
|Attack Mode&lt;br /&gt;
|-&lt;br /&gt;
|Double blinking&lt;br /&gt;
|Arming Mode&lt;br /&gt;
|-&lt;br /&gt;
|Slow blinking&lt;br /&gt;
|Error running payload&lt;br /&gt;
|-&lt;br /&gt;
|Fast blinking&lt;br /&gt;
|Select Mode (Deprecated from version 1.0.1 onward)&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= Software =&lt;br /&gt;
&lt;br /&gt;
== Modes of Operation ==&lt;br /&gt;
&lt;br /&gt;
The Signal Owl comes with two modes of operation, Attack Mode and Arming Mode. By default, the device will boot into Attack Mode. In order to access Arming Mode, the button on the bottom of the device has to be pressed while in Attack Mode. It is not recommended to press the button during the boot sequence, as this can possibly brick the device and render it useless. The arming mode is used for firmware updates and shell access, while the attack mode is used to load and execute the payload.&lt;br /&gt;
&lt;br /&gt;
=== Attack Mode ===&lt;br /&gt;
&lt;br /&gt;
Attack Mode is the default mode, the Signal Owl boots into. It provides two basic functions, being the payload loading function and the payload execution function. &lt;br /&gt;
&lt;br /&gt;
The payload loading function checks for any USB flash drives plugged into the host port of the device and copies payloads to &amp;lt;code&amp;gt;/root/payload&amp;lt;/code&amp;gt; and extensions to &amp;lt;code&amp;gt;/root/payload/extensions&amp;lt;/code&amp;gt; on the Signal Owl. &lt;br /&gt;
&lt;br /&gt;
The payload execution function is responsible for executing the payload that is currently stored on the root of the Signal Owl. In case no payload is found, the device will blink slowly, indicating the FAIL status.&lt;br /&gt;
&lt;br /&gt;
=== Arming Mode ===&lt;br /&gt;
&lt;br /&gt;
The Arming Mode provides two basic functions, being the firmware update function and the shell access function. The firmware update function checks for any USB flash drives plugged into the host port of the device and copies firmware upgrade files into the internal storage of the device and flashes it. The shell access function starts an open access point with the SSID Owl_xxxx in which xxxx indicates the last two octets of the device&#039;s MAC address. Additionally, a SSH server providing access to the shell of the Signal Owl is enabled.&lt;br /&gt;
&lt;br /&gt;
== Default Settings ==&lt;br /&gt;
&lt;br /&gt;
Default settings that are used in order to access the device via SSH are pictured in the table below.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
!colspan=&amp;quot;2&amp;quot;|Default Settings&lt;br /&gt;
|-&lt;br /&gt;
|Username&lt;br /&gt;
|root&lt;br /&gt;
|-&lt;br /&gt;
|Password&lt;br /&gt;
|hak5owl&lt;br /&gt;
|-&lt;br /&gt;
|SSID&lt;br /&gt;
|Owl_xxxx&lt;br /&gt;
|-&lt;br /&gt;
|IP Address&lt;br /&gt;
|172.16.56.1&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
SSH command: &amp;lt;code&amp;gt;ssh root@172.16.56.1&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The SSID during Arming Mode is Owl_xxxx in which xxxx indicates the last two octets of the devices MAC address.&lt;br /&gt;
&lt;br /&gt;
= Usage =&lt;br /&gt;
&lt;br /&gt;
== Arming Mode connection ==&lt;br /&gt;
&lt;br /&gt;
Step-by-step guide for accessing the arming mode&lt;br /&gt;
&lt;br /&gt;
#Click on the button located on the bottom of the Signal Owl while it is in attack mode. After pressing the button, the signal owl enters the arming mode and provides an open access point with the name Owl xxxx (where xxxx stands for the last two digits of the MAC address of the device).&lt;br /&gt;
#Connect to the access point.&amp;lt;br&amp;gt;[[File:Armingmode.png]][Eigene Darstellung]&lt;br /&gt;
#Now you can connect via ssh by using the [[#Default Settings|default settings]].&lt;br /&gt;
#After successful connection, you will end up in the root directory.&amp;lt;br&amp;gt;[[File:ArmingmodeSSH.png]][Eigene Darstellung]&lt;br /&gt;
#Now you can change the files and directories on the Signal Owl to view results, transfer payloads and extensions or to make further changes.&lt;br /&gt;
&lt;br /&gt;
== Directory structure ==&lt;br /&gt;
&lt;br /&gt;
The following directory tree shows the directory structure of the Signal Owl.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
/&lt;br /&gt;
├── loot&lt;br /&gt;
└── payload/&lt;br /&gt;
    └── extensions&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
*Loot - Directory where the Signal Owl saves loot while executing payloads that produce loot.&lt;br /&gt;
*Payload - This directory holds the current payload. &lt;br /&gt;
*Extensions -  This directory holds all extensions.&lt;br /&gt;
&lt;br /&gt;
== Adding Payloads and Extensions ==&lt;br /&gt;
&lt;br /&gt;
Adding a payload can be done in two different ways. Either with a USB flash drive or via the Signal Owl access point to the internal storage of the device. &lt;br /&gt;
&lt;br /&gt;
When booting, payloads on USB flash drives are given priority and will override payloads stored on the Signal Owl. To successfully copy a payload to the Signal Owl, the payload must be named &amp;lt;code&amp;gt;payload.txt&amp;lt;/code&amp;gt; or &amp;lt;code&amp;gt;payload.sh&amp;lt;/code&amp;gt; and it has to be placed in the &amp;lt;code&amp;gt;root&amp;lt;/code&amp;gt; directory of the flash drive. Similarly, payload extensions should be stored in a &amp;lt;code&amp;gt;/extensions&amp;lt;/code&amp;gt; directory on the flash drive. &lt;br /&gt;
&lt;br /&gt;
In addition, it is possible to transfer payloads and payload extensions to the device via the Signal Owl access point in arming mode using SSH. There they are stored in the &amp;lt;code&amp;gt;/root/payload&amp;lt;/code&amp;gt; directory and Payload Extensions are stored in the &amp;lt;code&amp;gt;/root/payload/extensions&amp;lt;/code&amp;gt; directory.&lt;br /&gt;
&lt;br /&gt;
== Payload Development ==&lt;br /&gt;
&lt;br /&gt;
Payloads for the Signal Owl are written in bash with [https://github.com/hak5darren/USB-Rubber-Ducky/wiki/Duckyscript Ducky Script] and can be created with any standard text editor. All payloads should begin with an interpreter directive, like the shebang &amp;lt;code&amp;gt;#!/bin/bash&amp;lt;/code&amp;gt; for bash payloads and payloads must be named either &amp;lt;code&amp;gt;payload.txt&amp;lt;/code&amp;gt; or &amp;lt;code&amp;gt;payload.sh&amp;lt;/code&amp;gt;. In order to create effective payloads, the Signal Owl comes with several preinstalled penetration testing tools. These are as follows: [https://nmap.org/ Nmap], [https://www.aircrack-ng.org/ Aircrack-ng], [https://github.com/aircrack-ng/mdk4 MDK4] and [https://www.kismetwireless.net/ Kismet].&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Tools&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
• Kismet - detector for wireless networks and devices.&lt;br /&gt;
&lt;br /&gt;
• MDK4 - Wi-Fi testing tool.&lt;br /&gt;
&lt;br /&gt;
• Aircrack-ng Suite - a complete suite of tools for WiFi network security assessment.&lt;br /&gt;
&lt;br /&gt;
• Nmap - open source utility for network discovery and security auditing.&lt;br /&gt;
&lt;br /&gt;
Hak5 offers ready-to-use payloads and payload extensions on their [https://github.com/hak5/signalowl-payloads GitHub repository].&lt;br /&gt;
&lt;br /&gt;
== Implant / mobile operations ==&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Implant operations&lt;br /&gt;
&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
During long term wireless engagements, the Signal Owl may be planted inline between any typical 5V USB power source. This may be useful in situations where ports are occupied, or to deter the unit from being unplugged.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Mobile operations&lt;br /&gt;
&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
The Signal Owl features a low power consumption profile, with a typical power draw averaging 100-200 mAh. Additionally, it is thermally optimized for long term deployments in many indoor environments. One can expect a large 20,000 mAh USB battery bank to operate the unit for up to 4 days.&lt;br /&gt;
&lt;br /&gt;
= Use Cases =&lt;br /&gt;
&lt;br /&gt;
The Signal Owl has a variety of different use cases. Among the most popular ones are classical network mapping and wardriving as well as basic penetration tests for different wireless technologies.&lt;br /&gt;
&lt;br /&gt;
== Fake Beacon Flooding Attack ==&lt;br /&gt;
&lt;br /&gt;
The Fake Beacon Flooding Attack is one possible use case for the Signal Owl. With that attack, fake beacon frames are broadcasted to nearby devices. Beacon Frames include various parameters like the SSID, the type of encryption used and timestamps. This results in the creation of multiple fake Wi-Fi networks. Devices with Wi-Fi browsers are then flooded with these fake networks, causing potential network scanner and driver crashes. Furthermore, the attack may prevent legitimate users from finding their networks and lead to denial of service. The preinstalled tools Aircrack-ng and MDK4 were used to create this payload. After powering on the device, multiple fake networks with random SSIDs are generated and broadcasted to all nearby devices.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;bash&amp;quot;&amp;gt;&lt;br /&gt;
#!/bin/bash&lt;br /&gt;
&lt;br /&gt;
LED SETUP&lt;br /&gt;
sleep 10&lt;br /&gt;
airmon-ng check kill&lt;br /&gt;
sleep 10&lt;br /&gt;
#creates monitor mode interface on wirelss card of the Signal Owl&lt;br /&gt;
airmon-ng start wlan0&lt;br /&gt;
sleep 10&lt;br /&gt;
LED ATTACK&lt;br /&gt;
#floods nearby devices with random SSIDs&lt;br /&gt;
mdk4 wlan0mon b -a -m -s 500&lt;br /&gt;
&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The results as seen from a victim running a Windows 10 system are pictured in the figure below.&lt;br /&gt;
&lt;br /&gt;
[[File:FakeBeaconFloodingSignalOwl.png|none|Random SSIDs as seen from a victim Windows 10 client |]][Eigene Darstellung]&lt;br /&gt;
&lt;br /&gt;
== Open AP Nmap Scanner ==&lt;br /&gt;
&lt;br /&gt;
With the Open AP Nmap Scanner payload, the Signal Owl scans for open access points. If the Signal Owl finds one or more open access points, it connects to them and uses Nmap to scan and analyze them. The results are then stored in the loot directory. For each discovered open access point, the Signal Owl generates a separate results file. This payload has some settings which can be seen in the following listing.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;bash&amp;quot;&amp;gt;&lt;br /&gt;
NMAP_OPTIONS=&amp;quot;-sP&amp;quot;&lt;br /&gt;
LOOT_DIR=/root/loot/open_ap_nmap_scan&lt;br /&gt;
MAX_CIDR=20&lt;br /&gt;
DEBUG=1&lt;br /&gt;
&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
*NMAP_OPTIONS - Is used to specify the type of Nmap scan.&lt;br /&gt;
*LOOT_DIR - Sets the destination folder for the scan results.&lt;br /&gt;
*MAX_CIDR - Sets the maximum Classless Inter-Domain Routing&lt;br /&gt;
*DEBUG - Specifies if debug information is saved to the payload.log file in the tmp folder.&lt;br /&gt;
** 1 - Debug information is saved.&lt;br /&gt;
** 0 - Debug information is not saved.&lt;br /&gt;
&lt;br /&gt;
== Basic Bluetooth Scanner ==&lt;br /&gt;
&lt;br /&gt;
This payload requires an external Bluetooth adapter, since the Signal Owl does not have Bluetooth built in. The Basic Bluetooth Scanner scans for devices that have Bluetooth enabled and optionally queries them using the hcitool and the info command. This payload does also have some settings, as shown in the listing below.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;bash&amp;quot;&amp;gt;&lt;br /&gt;
LOOT_DIR=/root/loot/bluetooth_scan&lt;br /&gt;
BT_OUTFILE=`date +%s`.bt.list&lt;br /&gt;
BT_INFOFILE=`date +%s`.bt.info   &lt;br /&gt;
BTDEV=hci0&lt;br /&gt;
DEBUG=0 &lt;br /&gt;
INTERROGATE=1 &lt;br /&gt;
&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
*LOOT_DIR - Sets the directory for the scan result.&lt;br /&gt;
*BT_OUTFILE - Sets a file name, in which all detected names and MAC addresses are saved.&lt;br /&gt;
*BT_INFOFILE - Sets a file name, in which the details of the discovered devices are saved if the INTERROGATE variable is set to 1. &lt;br /&gt;
*BTDEV - Specifies the bluetooth device used for scanning.&lt;br /&gt;
*DEBUG - Specifies if debug information is saved to the payload.log file in the tmp folder.&lt;br /&gt;
** 1 - Debug information is saved.&lt;br /&gt;
** 0 - Debug information is not saved.&lt;br /&gt;
*INTERROGATE - Specifies if the detected devices are interrogated.&lt;br /&gt;
** 1 - Detected devices are interrogated&lt;br /&gt;
** 0 - Detected devices are not interrogated&lt;br /&gt;
&lt;br /&gt;
== WiFi Connect ==&lt;br /&gt;
&lt;br /&gt;
With the WiFi Connect payload, which can be seen in the following Listing, and the wificonnect.sh Payload extension, the Signal Owl can be connected to a nearby network. The SSID and password of the network to which the Signal Owl should connect must be specified in the code. Optionally, the SSH server of the device can be started by removing the hash sign in the code before the corresponding command. &lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;bash&amp;quot;&amp;gt;&lt;br /&gt;
#!/bin/bash&lt;br /&gt;
&lt;br /&gt;
# WiFi Client Setup&lt;br /&gt;
WIFI_SSID=&amp;quot;network-name&amp;quot;&lt;br /&gt;
WIFI_PASS=&amp;quot;passphrase&amp;quot;&lt;br /&gt;
&lt;br /&gt;
LED SETUP&lt;br /&gt;
WIFI_CONNECT&lt;br /&gt;
# optionally start SSH server&lt;br /&gt;
# /etc/init.d/sshd start&lt;br /&gt;
LED ATTACK&lt;br /&gt;
&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The &amp;lt;code&amp;gt;WIFI_CONNECT&amp;lt;/code&amp;gt; command executes the wifi_connect.sh payload extension, which is shown in the following listing. &lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;bash&amp;quot;&amp;gt;&lt;br /&gt;
#!/bin/bash&lt;br /&gt;
&lt;br /&gt;
function WIFI_CONNECT() {&lt;br /&gt;
    [[ &amp;quot;x$WIFI_INT&amp;quot; == &amp;quot;x&amp;quot; ]] &amp;amp;&amp;amp; WIFI_INT=wlan0&lt;br /&gt;
    ifconfig $WIFI_INT up;sleep 10&lt;br /&gt;
    echo -e &amp;quot;network={\nssid=\&amp;quot;$WIFI_SSID\&amp;quot;\npsk=\&amp;quot;$WIFI_PASS\&amp;quot;\npriority=1\n}&amp;quot;&amp;gt;/tmp/wpa-$WIFI_INT.conf&lt;br /&gt;
    wpa_supplicant -B -Dnl80211 -i $WIFI_INT -c /tmp/wpa-$WIFI_INT.conf&lt;br /&gt;
    while(iwconfig $WIFI_INT | grep Not-Associated); do sleep 1; done&lt;br /&gt;
    udhcpc -i $WIFI_INT&lt;br /&gt;
}&lt;br /&gt;
export -f WIFI_CONNECT&lt;br /&gt;
&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The payload extension code uses the &amp;lt;code&amp;gt;WIFI_SSID&amp;lt;/code&amp;gt; and &amp;lt;code&amp;gt;WIFI_PASS&amp;lt;/code&amp;gt; variables of the payload to connect the Signal Owl to the network. With the command &amp;lt;code&amp;gt;export -f WIFI_CONNECT&amp;lt;/code&amp;gt; the function &amp;lt;code&amp;gt;WIFI_CONNECT&amp;lt;/code&amp;gt; is exported so that it can be called from the payload. &lt;br /&gt;
&lt;br /&gt;
If the SSH server is enabled, any SSH-enabled device can connect to the Signal Owl over the network, even though Attack Mode is enabled. The [[#Default Settings|default settings]] of the device can be used again for the connection, if they have not been changed yet. However, the IP address in this case is the IP address of the Signal Owl in this network.&lt;br /&gt;
&lt;br /&gt;
= Used Hardware =&lt;br /&gt;
&lt;br /&gt;
[[Signal Owl]]&lt;br /&gt;
&lt;br /&gt;
= References =&lt;br /&gt;
&lt;br /&gt;
*https://docs.hak5.org/signal-owl/&lt;br /&gt;
*https://github.com/hak5/signalowl-payloads&lt;br /&gt;
&lt;br /&gt;
[[Category:Pentesting]]&lt;/div&gt;</summary>
		<author><name>MMayer</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=Hak5_Signal_Owl&amp;diff=10727</id>
		<title>Hak5 Signal Owl</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=Hak5_Signal_Owl&amp;diff=10727"/>
		<updated>2023-01-07T02:05:09Z</updated>

		<summary type="html">&lt;p&gt;MMayer: /* Open AP Nmap Scanner */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= Introduction =&lt;br /&gt;
&lt;br /&gt;
The [https://docs.hak5.org/signal-owl/ Signal Owl] is a hardware product developed by the company [https://shop.hak5.org/ Hak5].&lt;br /&gt;
It is a simple payload-based signals intelligence platform with a unique design for discreet planting or mobile operations on any engagement. The most popular application cases include classic network mapping and basic penetration tests for various wireless technologies.&lt;br /&gt;
&lt;br /&gt;
== Initial Setup ==&lt;br /&gt;
&lt;br /&gt;
When first unboxing the Signal Owl, the device runs a stager firmware that is designed to flash the latest firmware from a USB flash drive. In order to update the Signal Owl, the [https://downloads.hak5.org/owl latest firmware] has to be downloaded. Then, the downloaded file must be copied to the root of an EXT4 or FAT32 formatted USB flash drive. It is important not to modify this file. The next step is to plug the USB flash drive into the powered off Signal Owl. Afterwards, the device has to be powered on by a reliable USB source. The upgrade itself takes approximately five to ten minutes and is indicated by a solid red LED light. When finished, the device will reboot, enter Attack Mode and blink slowly, indicating an error running the payload because no payload has been found.&lt;br /&gt;
&lt;br /&gt;
= Hardware =&lt;br /&gt;
&lt;br /&gt;
[[File:SignalOwlDiagram.png|thumb|500px|frame|Components of the Signal Owl [Eigene Darstellung]]] &lt;br /&gt;
&lt;br /&gt;
The Signal Owl is designed to be rapidly deployed in all kinds of environments, allowing it to be an entry point for network analysis and basic wireless attacks in a variety of locations. With a power consumption of 100-200 mAh and the thermally optimized architecture, mobile operations as well as long term deployments, are enabled.&lt;br /&gt;
&lt;br /&gt;
== Components ==&lt;br /&gt;
&lt;br /&gt;
This device features several components of which some may not be visible to the human eye at first sight.&lt;br /&gt;
&lt;br /&gt;
=== USB Power / Passthrough Plug ===&lt;br /&gt;
&lt;br /&gt;
The USB power or passthrough plug is used to power the device. It can be powered from any reliable USB source.&lt;br /&gt;
&lt;br /&gt;
=== USB 2.0 Passthrough Port ===&lt;br /&gt;
&lt;br /&gt;
The USB 2.0 passthrough port is the port closest to the pigtail. Data and power pass through to that port, allowing for implant operations. If a device such as a keyboard is plugged in between this passthrough port and the power plug is connected to the target computer, the Signal Owl will remain undetected by the operating system. Only the keyboard will be visible on the target computer.&lt;br /&gt;
&lt;br /&gt;
=== USB 2.0 Host Port ===&lt;br /&gt;
&lt;br /&gt;
The USB 2.0 host port is the port farthest away from the pigtail. It is connected to the Linux socket of the Signal Owl and supports USB flash drives formatted with FAT32 and EXT4 file systems as well as many Wi-Fi, Bluetooth and other RF transceivers.&lt;br /&gt;
&lt;br /&gt;
=== Button ===&lt;br /&gt;
&lt;br /&gt;
The button on the bottom of the device is used to enter Arming Mode and to interact with payloads. It is not pressable without special tools like paperclips.&lt;br /&gt;
&lt;br /&gt;
=== Status LED ===&lt;br /&gt;
&lt;br /&gt;
The status LED indicates the current status of the Signal Owl. When it is turned off, it is not visible.&lt;br /&gt;
&lt;br /&gt;
The Signal Owl features a red LED with the following default status indications:&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
!|LED&lt;br /&gt;
!|Status&lt;br /&gt;
|-&lt;br /&gt;
|Blinking&lt;br /&gt;
|Booting&lt;br /&gt;
|-&lt;br /&gt;
|Solid&lt;br /&gt;
|Mounting external storage / Running upgrade&lt;br /&gt;
|-&lt;br /&gt;
|Single blinking&lt;br /&gt;
|Attack Mode&lt;br /&gt;
|-&lt;br /&gt;
|Double blinking&lt;br /&gt;
|Arming Mode&lt;br /&gt;
|-&lt;br /&gt;
|Slow blinking&lt;br /&gt;
|Error running payload&lt;br /&gt;
|-&lt;br /&gt;
|Fast blinking&lt;br /&gt;
|Select Mode (Deprecated from version 1.0.1 onward)&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= Software =&lt;br /&gt;
&lt;br /&gt;
== Modes of Operation ==&lt;br /&gt;
&lt;br /&gt;
The Signal Owl comes with two modes of operation, Attack Mode and Arming Mode. By default, the device will boot into Attack Mode. In order to access Arming Mode, the button on the bottom of the device has to be pressed while in Attack Mode. It is not recommended to press the button during the boot sequence, as this can possibly brick the device and render it useless. The arming mode is used for firmware updates and shell access, while the attack mode is used to load and execute the payload.&lt;br /&gt;
&lt;br /&gt;
=== Attack Mode ===&lt;br /&gt;
&lt;br /&gt;
Attack Mode is the default mode, the Signal Owl boots into. It provides two basic functions, being the payload loading function and the payload execution function. &lt;br /&gt;
&lt;br /&gt;
The payload loading function checks for any USB flash drives plugged into the host port of the device and copies payloads to &amp;lt;code&amp;gt;/root/payload&amp;lt;/code&amp;gt; and extensions to &amp;lt;code&amp;gt;/root/payload/extensions&amp;lt;/code&amp;gt; on the Signal Owl. &lt;br /&gt;
&lt;br /&gt;
The payload execution function is responsible for executing the payload that is currently stored on the root of the Signal Owl. In case no payload is found, the device will blink slowly, indicating the FAIL status.&lt;br /&gt;
&lt;br /&gt;
=== Arming Mode ===&lt;br /&gt;
&lt;br /&gt;
The Arming Mode provides two basic functions, being the firmware update function and the shell access function. The firmware update function checks for any USB flash drives plugged into the host port of the device and copies firmware upgrade files into the internal storage of the device and flashes it. The shell access function starts an open access point with the SSID Owl_xxxx in which xxxx indicates the last two octets of the device&#039;s MAC address. Additionally, a SSH server providing access to the shell of the Signal Owl is enabled.&lt;br /&gt;
&lt;br /&gt;
== Default Settings ==&lt;br /&gt;
&lt;br /&gt;
Default settings that are used in order to access the device via SSH are pictured in the table below.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
!colspan=&amp;quot;2&amp;quot;|Default Settings&lt;br /&gt;
|-&lt;br /&gt;
|Username&lt;br /&gt;
|root&lt;br /&gt;
|-&lt;br /&gt;
|Password&lt;br /&gt;
|hak5owl&lt;br /&gt;
|-&lt;br /&gt;
|SSID&lt;br /&gt;
|Owl_xxxx&lt;br /&gt;
|-&lt;br /&gt;
|IP Address&lt;br /&gt;
|172.16.56.1&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
SSH command: &amp;lt;code&amp;gt;ssh root@172.16.56.1&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The SSID during Arming Mode is Owl_xxxx in which xxxx indicates the last two octets of the devices MAC address.&lt;br /&gt;
&lt;br /&gt;
= Usage =&lt;br /&gt;
&lt;br /&gt;
== Arming Mode connection ==&lt;br /&gt;
&lt;br /&gt;
Step-by-step guide for accessing the arming mode&lt;br /&gt;
&lt;br /&gt;
#Click on the button located on the bottom of the Signal Owl while it is in attack mode. After pressing the button, the signal owl enters the arming mode and provides an open access point with the name Owl xxxx (where xxxx stands for the last two digits of the MAC address of the device).&lt;br /&gt;
#Connect to the access point.&amp;lt;br&amp;gt;[[File:Armingmode.png]][Eigene Darstellung]&lt;br /&gt;
#Now you can connect via ssh by using the [[#Default Settings|default settings]].&lt;br /&gt;
#After successful connection, you will end up in the root directory.&amp;lt;br&amp;gt;[[File:ArmingmodeSSH.png]][Eigene Darstellung]&lt;br /&gt;
#Now you can change the files and directories on the Signal Owl to view results, transfer payloads and extensions or to make further changes.&lt;br /&gt;
&lt;br /&gt;
== Directory structure ==&lt;br /&gt;
&lt;br /&gt;
The following directory tree shows the directory structure of the Signal Owl.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
/&lt;br /&gt;
├── loot&lt;br /&gt;
└── payload/&lt;br /&gt;
    └── extensions&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
*Loot - Directory where the Signal Owl saves loot while executing payloads that produce loot.&lt;br /&gt;
*Payload - This directory holds the current payload. &lt;br /&gt;
*Extensions -  This directory holds all extensions.&lt;br /&gt;
&lt;br /&gt;
== Adding Payloads and Extensions ==&lt;br /&gt;
&lt;br /&gt;
Adding a payload can be done in two different ways. Either with a USB flash drive or via the Signal Owl access point to the internal storage of the device. &lt;br /&gt;
&lt;br /&gt;
When booting, payloads on USB flash drives are given priority and will override payloads stored on the Signal Owl. To successfully copy a payload to the Signal Owl, the payload must be named &amp;lt;code&amp;gt;payload.txt&amp;lt;/code&amp;gt; or &amp;lt;code&amp;gt;payload.sh&amp;lt;/code&amp;gt; and it has to be placed in the &amp;lt;code&amp;gt;root&amp;lt;/code&amp;gt; directory of the flash drive. Similarly, payload extensions should be stored in a &amp;lt;code&amp;gt;/extensions&amp;lt;/code&amp;gt; directory on the flash drive. &lt;br /&gt;
&lt;br /&gt;
In addition, it is possible to transfer payloads and payload extensions to the device via the Signal Owl access point in arming mode using SSH. There they are stored in the &amp;lt;code&amp;gt;/root/payload&amp;lt;/code&amp;gt; directory and Payload Extensions are stored in the &amp;lt;code&amp;gt;/root/payload/extensions&amp;lt;/code&amp;gt; directory.&lt;br /&gt;
&lt;br /&gt;
== Payload Development ==&lt;br /&gt;
&lt;br /&gt;
Payloads for the Signal Owl are written in bash with [https://github.com/hak5darren/USB-Rubber-Ducky/wiki/Duckyscript Ducky Script] and can be created with any standard text editor. All payloads should begin with an interpreter directive, like the shebang &amp;lt;code&amp;gt;#!/bin/bash&amp;lt;/code&amp;gt; for bash payloads and payloads must be named either &amp;lt;code&amp;gt;payload.txt&amp;lt;/code&amp;gt; or &amp;lt;code&amp;gt;payload.sh&amp;lt;/code&amp;gt;. In order to create effective payloads, the Signal Owl comes with several preinstalled penetration testing tools. These are as follows: [https://nmap.org/ Nmap], [https://www.aircrack-ng.org/ Aircrack-ng], [https://github.com/aircrack-ng/mdk4 MDK4] and [https://www.kismetwireless.net/ Kismet].&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Tools&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
• Kismet - detector for wireless networks and devices.&lt;br /&gt;
&lt;br /&gt;
• MDK4 - Wi-Fi testing tool.&lt;br /&gt;
&lt;br /&gt;
• Aircrack-ng Suite - a complete suite of tools for WiFi network security assessment.&lt;br /&gt;
&lt;br /&gt;
• Nmap - open source utility for network discovery and security auditing.&lt;br /&gt;
&lt;br /&gt;
Hak5 offers ready-to-use payloads and payload extensions on their [https://github.com/hak5/signalowl-payloads GitHub repository].&lt;br /&gt;
&lt;br /&gt;
== Implant / mobile operations ==&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Implant operations&lt;br /&gt;
&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
During long term wireless engagements, the Signal Owl may be planted inline between any typical 5V USB power source. This may be useful in situations where ports are occupied, or to deter the unit from being unplugged.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Mobile operations&lt;br /&gt;
&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
The Signal Owl features a low power consumption profile, with a typical power draw averaging 100-200 mAh. Additionally, it is thermally optimized for long term deployments in many indoor environments. One can expect a large 20,000 mAh USB battery bank to operate the unit for up to 4 days.&lt;br /&gt;
&lt;br /&gt;
= Use Cases =&lt;br /&gt;
&lt;br /&gt;
The Signal Owl has a variety of different use cases. Among the most popular ones are classical network mapping and wardriving as well as basic penetration tests for different wireless technologies.&lt;br /&gt;
&lt;br /&gt;
== Fake Beacon Flooding Attack ==&lt;br /&gt;
&lt;br /&gt;
The Fake Beacon Flooding Attack is one possible use case for the Signal Owl. With that attack, fake beacon frames are broadcasted to nearby devices. Beacon Frames include various parameters like the SSID, the type of encryption used and timestamps. This results in the creation of multiple fake Wi-Fi networks. Devices with Wi-Fi browsers are then flooded with these fake networks, causing potential network scanner and driver crashes. Furthermore, the attack may prevent legitimate users from finding their networks and lead to denial of service. The preinstalled tools Aircrack-ng and MDK4 were used to create this payload. After powering on the device, multiple fake networks with random SSIDs are generated and broadcasted to all nearby devices.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;bash&amp;quot;&amp;gt;&lt;br /&gt;
#!/bin/bash&lt;br /&gt;
&lt;br /&gt;
LED SETUP&lt;br /&gt;
sleep 10&lt;br /&gt;
airmon-ng check kill&lt;br /&gt;
sleep 10&lt;br /&gt;
#creates monitor mode interface on wirelss card of the Signal Owl&lt;br /&gt;
airmon-ng start wlan0&lt;br /&gt;
sleep 10&lt;br /&gt;
LED ATTACK&lt;br /&gt;
#floods nearby devices with random SSIDs&lt;br /&gt;
mdk4 wlan0mon b -a -m -s 500&lt;br /&gt;
&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The results as seen from a victim running a Windows 10 system are pictured in the figure below.&lt;br /&gt;
&lt;br /&gt;
[[File:FakeBeaconFloodingSignalOwl.png|none|Random SSIDs as seen from a victim Windows 10 client |]][Eigene Darstellung]&lt;br /&gt;
&lt;br /&gt;
== Open AP Nmap Scanner ==&lt;br /&gt;
&lt;br /&gt;
With the Open AP Nmap Scanner payload, the Signal Owl scans for open access points. If the Signal Owl finds one or more open access points, it connects to them and uses Nmap to scan and analyze them. The results are then stored in the loot directory. For each discovered open access point, the Signal Owl generates a separate results file. This payload has some settings which can be seen in the following listing.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;bash&amp;quot;&amp;gt;&lt;br /&gt;
NMAP_OPTIONS=&amp;quot;-sP&amp;quot;&lt;br /&gt;
LOOT_DIR=/root/loot/open_ap_nmap_scan&lt;br /&gt;
MAX_CIDR=20&lt;br /&gt;
DEBUG=1&lt;br /&gt;
&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
*NMAP_OPTIONS - Is used to specify the type of Nmap scan.&lt;br /&gt;
*LOOT_DIR - Sets the destination folder for the scan results.&lt;br /&gt;
*MAX_CIDR - Sets the maximum Classless Inter-Domain Routing&lt;br /&gt;
*DEBUG - Specifies if debug information is saved to the payload.log file in the tmp folder.&lt;br /&gt;
** 1 - Debug information is saved.&lt;br /&gt;
** 0 - Debug information is not saved.&lt;br /&gt;
&lt;br /&gt;
== Basic Bluetooth Scanner ==&lt;br /&gt;
&lt;br /&gt;
This payload requires an external Bluetooth adapter, since the Signal Owl does not have Bluetooth built in. The Basic Bluetooth Scanner scans for devices that have Bluetooth enabled and optionally queries them using the hcitool and the info command. This payload does also have some settings, as shown in the listing below.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;bash&amp;quot;&amp;gt;&lt;br /&gt;
LOOT_DIR=/root/loot/bluetooth_scan&lt;br /&gt;
BT_OUTFILE=`date +%s`.bt.list&lt;br /&gt;
BT_INFOFILE=`date +%s`.bt.info   &lt;br /&gt;
BTDEV=hci0&lt;br /&gt;
DEBUG=0 &lt;br /&gt;
INTERROGATE=1 &lt;br /&gt;
&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== WiFi Connect ==&lt;br /&gt;
&lt;br /&gt;
With the WiFi Connect payload, which can be seen in the following Listing, and the wificonnect.sh Payload extension, the Signal Owl can be connected to a nearby network. The SSID and password of the network to which the Signal Owl should connect must be specified in the code. Optionally, the SSH server of the device can be started by removing the hash sign in the code before the corresponding command. &lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;bash&amp;quot;&amp;gt;&lt;br /&gt;
#!/bin/bash&lt;br /&gt;
&lt;br /&gt;
# WiFi Client Setup&lt;br /&gt;
WIFI_SSID=&amp;quot;network-name&amp;quot;&lt;br /&gt;
WIFI_PASS=&amp;quot;passphrase&amp;quot;&lt;br /&gt;
&lt;br /&gt;
LED SETUP&lt;br /&gt;
WIFI_CONNECT&lt;br /&gt;
# optionally start SSH server&lt;br /&gt;
# /etc/init.d/sshd start&lt;br /&gt;
LED ATTACK&lt;br /&gt;
&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The &amp;lt;code&amp;gt;WIFI_CONNECT&amp;lt;/code&amp;gt; command executes the wifi_connect.sh payload extension, which is shown in the following listing. &lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;bash&amp;quot;&amp;gt;&lt;br /&gt;
#!/bin/bash&lt;br /&gt;
&lt;br /&gt;
function WIFI_CONNECT() {&lt;br /&gt;
    [[ &amp;quot;x$WIFI_INT&amp;quot; == &amp;quot;x&amp;quot; ]] &amp;amp;&amp;amp; WIFI_INT=wlan0&lt;br /&gt;
    ifconfig $WIFI_INT up;sleep 10&lt;br /&gt;
    echo -e &amp;quot;network={\nssid=\&amp;quot;$WIFI_SSID\&amp;quot;\npsk=\&amp;quot;$WIFI_PASS\&amp;quot;\npriority=1\n}&amp;quot;&amp;gt;/tmp/wpa-$WIFI_INT.conf&lt;br /&gt;
    wpa_supplicant -B -Dnl80211 -i $WIFI_INT -c /tmp/wpa-$WIFI_INT.conf&lt;br /&gt;
    while(iwconfig $WIFI_INT | grep Not-Associated); do sleep 1; done&lt;br /&gt;
    udhcpc -i $WIFI_INT&lt;br /&gt;
}&lt;br /&gt;
export -f WIFI_CONNECT&lt;br /&gt;
&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The payload extension code uses the &amp;lt;code&amp;gt;WIFI_SSID&amp;lt;/code&amp;gt; and &amp;lt;code&amp;gt;WIFI_PASS&amp;lt;/code&amp;gt; variables of the payload to connect the Signal Owl to the network. With the command &amp;lt;code&amp;gt;export -f WIFI_CONNECT&amp;lt;/code&amp;gt; the function &amp;lt;code&amp;gt;WIFI_CONNECT&amp;lt;/code&amp;gt; is exported so that it can be called from the payload. &lt;br /&gt;
&lt;br /&gt;
If the SSH server is enabled, any SSH-enabled device can connect to the Signal Owl over the network, even though Attack Mode is enabled. The [[#Default Settings|default settings]] of the device can be used again for the connection, if they have not been changed yet. However, the IP address in this case is the IP address of the Signal Owl in this network.&lt;br /&gt;
&lt;br /&gt;
= Used Hardware =&lt;br /&gt;
&lt;br /&gt;
[[Signal Owl]]&lt;br /&gt;
&lt;br /&gt;
= References =&lt;br /&gt;
&lt;br /&gt;
*https://docs.hak5.org/signal-owl/&lt;br /&gt;
*https://github.com/hak5/signalowl-payloads&lt;br /&gt;
&lt;br /&gt;
[[Category:Pentesting]]&lt;/div&gt;</summary>
		<author><name>MMayer</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=Hak5_Signal_Owl&amp;diff=10726</id>
		<title>Hak5 Signal Owl</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=Hak5_Signal_Owl&amp;diff=10726"/>
		<updated>2023-01-07T01:58:06Z</updated>

		<summary type="html">&lt;p&gt;MMayer: /* WiFi Connect */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= Introduction =&lt;br /&gt;
&lt;br /&gt;
The [https://docs.hak5.org/signal-owl/ Signal Owl] is a hardware product developed by the company [https://shop.hak5.org/ Hak5].&lt;br /&gt;
It is a simple payload-based signals intelligence platform with a unique design for discreet planting or mobile operations on any engagement. The most popular application cases include classic network mapping and basic penetration tests for various wireless technologies.&lt;br /&gt;
&lt;br /&gt;
== Initial Setup ==&lt;br /&gt;
&lt;br /&gt;
When first unboxing the Signal Owl, the device runs a stager firmware that is designed to flash the latest firmware from a USB flash drive. In order to update the Signal Owl, the [https://downloads.hak5.org/owl latest firmware] has to be downloaded. Then, the downloaded file must be copied to the root of an EXT4 or FAT32 formatted USB flash drive. It is important not to modify this file. The next step is to plug the USB flash drive into the powered off Signal Owl. Afterwards, the device has to be powered on by a reliable USB source. The upgrade itself takes approximately five to ten minutes and is indicated by a solid red LED light. When finished, the device will reboot, enter Attack Mode and blink slowly, indicating an error running the payload because no payload has been found.&lt;br /&gt;
&lt;br /&gt;
= Hardware =&lt;br /&gt;
&lt;br /&gt;
[[File:SignalOwlDiagram.png|thumb|500px|frame|Components of the Signal Owl [Eigene Darstellung]]] &lt;br /&gt;
&lt;br /&gt;
The Signal Owl is designed to be rapidly deployed in all kinds of environments, allowing it to be an entry point for network analysis and basic wireless attacks in a variety of locations. With a power consumption of 100-200 mAh and the thermally optimized architecture, mobile operations as well as long term deployments, are enabled.&lt;br /&gt;
&lt;br /&gt;
== Components ==&lt;br /&gt;
&lt;br /&gt;
This device features several components of which some may not be visible to the human eye at first sight.&lt;br /&gt;
&lt;br /&gt;
=== USB Power / Passthrough Plug ===&lt;br /&gt;
&lt;br /&gt;
The USB power or passthrough plug is used to power the device. It can be powered from any reliable USB source.&lt;br /&gt;
&lt;br /&gt;
=== USB 2.0 Passthrough Port ===&lt;br /&gt;
&lt;br /&gt;
The USB 2.0 passthrough port is the port closest to the pigtail. Data and power pass through to that port, allowing for implant operations. If a device such as a keyboard is plugged in between this passthrough port and the power plug is connected to the target computer, the Signal Owl will remain undetected by the operating system. Only the keyboard will be visible on the target computer.&lt;br /&gt;
&lt;br /&gt;
=== USB 2.0 Host Port ===&lt;br /&gt;
&lt;br /&gt;
The USB 2.0 host port is the port farthest away from the pigtail. It is connected to the Linux socket of the Signal Owl and supports USB flash drives formatted with FAT32 and EXT4 file systems as well as many Wi-Fi, Bluetooth and other RF transceivers.&lt;br /&gt;
&lt;br /&gt;
=== Button ===&lt;br /&gt;
&lt;br /&gt;
The button on the bottom of the device is used to enter Arming Mode and to interact with payloads. It is not pressable without special tools like paperclips.&lt;br /&gt;
&lt;br /&gt;
=== Status LED ===&lt;br /&gt;
&lt;br /&gt;
The status LED indicates the current status of the Signal Owl. When it is turned off, it is not visible.&lt;br /&gt;
&lt;br /&gt;
The Signal Owl features a red LED with the following default status indications:&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
!|LED&lt;br /&gt;
!|Status&lt;br /&gt;
|-&lt;br /&gt;
|Blinking&lt;br /&gt;
|Booting&lt;br /&gt;
|-&lt;br /&gt;
|Solid&lt;br /&gt;
|Mounting external storage / Running upgrade&lt;br /&gt;
|-&lt;br /&gt;
|Single blinking&lt;br /&gt;
|Attack Mode&lt;br /&gt;
|-&lt;br /&gt;
|Double blinking&lt;br /&gt;
|Arming Mode&lt;br /&gt;
|-&lt;br /&gt;
|Slow blinking&lt;br /&gt;
|Error running payload&lt;br /&gt;
|-&lt;br /&gt;
|Fast blinking&lt;br /&gt;
|Select Mode (Deprecated from version 1.0.1 onward)&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= Software =&lt;br /&gt;
&lt;br /&gt;
== Modes of Operation ==&lt;br /&gt;
&lt;br /&gt;
The Signal Owl comes with two modes of operation, Attack Mode and Arming Mode. By default, the device will boot into Attack Mode. In order to access Arming Mode, the button on the bottom of the device has to be pressed while in Attack Mode. It is not recommended to press the button during the boot sequence, as this can possibly brick the device and render it useless. The arming mode is used for firmware updates and shell access, while the attack mode is used to load and execute the payload.&lt;br /&gt;
&lt;br /&gt;
=== Attack Mode ===&lt;br /&gt;
&lt;br /&gt;
Attack Mode is the default mode, the Signal Owl boots into. It provides two basic functions, being the payload loading function and the payload execution function. &lt;br /&gt;
&lt;br /&gt;
The payload loading function checks for any USB flash drives plugged into the host port of the device and copies payloads to &amp;lt;code&amp;gt;/root/payload&amp;lt;/code&amp;gt; and extensions to &amp;lt;code&amp;gt;/root/payload/extensions&amp;lt;/code&amp;gt; on the Signal Owl. &lt;br /&gt;
&lt;br /&gt;
The payload execution function is responsible for executing the payload that is currently stored on the root of the Signal Owl. In case no payload is found, the device will blink slowly, indicating the FAIL status.&lt;br /&gt;
&lt;br /&gt;
=== Arming Mode ===&lt;br /&gt;
&lt;br /&gt;
The Arming Mode provides two basic functions, being the firmware update function and the shell access function. The firmware update function checks for any USB flash drives plugged into the host port of the device and copies firmware upgrade files into the internal storage of the device and flashes it. The shell access function starts an open access point with the SSID Owl_xxxx in which xxxx indicates the last two octets of the device&#039;s MAC address. Additionally, a SSH server providing access to the shell of the Signal Owl is enabled.&lt;br /&gt;
&lt;br /&gt;
== Default Settings ==&lt;br /&gt;
&lt;br /&gt;
Default settings that are used in order to access the device via SSH are pictured in the table below.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
!colspan=&amp;quot;2&amp;quot;|Default Settings&lt;br /&gt;
|-&lt;br /&gt;
|Username&lt;br /&gt;
|root&lt;br /&gt;
|-&lt;br /&gt;
|Password&lt;br /&gt;
|hak5owl&lt;br /&gt;
|-&lt;br /&gt;
|SSID&lt;br /&gt;
|Owl_xxxx&lt;br /&gt;
|-&lt;br /&gt;
|IP Address&lt;br /&gt;
|172.16.56.1&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
SSH command: &amp;lt;code&amp;gt;ssh root@172.16.56.1&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The SSID during Arming Mode is Owl_xxxx in which xxxx indicates the last two octets of the devices MAC address.&lt;br /&gt;
&lt;br /&gt;
= Usage =&lt;br /&gt;
&lt;br /&gt;
== Arming Mode connection ==&lt;br /&gt;
&lt;br /&gt;
Step-by-step guide for accessing the arming mode&lt;br /&gt;
&lt;br /&gt;
#Click on the button located on the bottom of the Signal Owl while it is in attack mode. After pressing the button, the signal owl enters the arming mode and provides an open access point with the name Owl xxxx (where xxxx stands for the last two digits of the MAC address of the device).&lt;br /&gt;
#Connect to the access point.&amp;lt;br&amp;gt;[[File:Armingmode.png]][Eigene Darstellung]&lt;br /&gt;
#Now you can connect via ssh by using the [[#Default Settings|default settings]].&lt;br /&gt;
#After successful connection, you will end up in the root directory.&amp;lt;br&amp;gt;[[File:ArmingmodeSSH.png]][Eigene Darstellung]&lt;br /&gt;
#Now you can change the files and directories on the Signal Owl to view results, transfer payloads and extensions or to make further changes.&lt;br /&gt;
&lt;br /&gt;
== Directory structure ==&lt;br /&gt;
&lt;br /&gt;
The following directory tree shows the directory structure of the Signal Owl.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
/&lt;br /&gt;
├── loot&lt;br /&gt;
└── payload/&lt;br /&gt;
    └── extensions&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
*Loot - Directory where the Signal Owl saves loot while executing payloads that produce loot.&lt;br /&gt;
*Payload - This directory holds the current payload. &lt;br /&gt;
*Extensions -  This directory holds all extensions.&lt;br /&gt;
&lt;br /&gt;
== Adding Payloads and Extensions ==&lt;br /&gt;
&lt;br /&gt;
Adding a payload can be done in two different ways. Either with a USB flash drive or via the Signal Owl access point to the internal storage of the device. &lt;br /&gt;
&lt;br /&gt;
When booting, payloads on USB flash drives are given priority and will override payloads stored on the Signal Owl. To successfully copy a payload to the Signal Owl, the payload must be named &amp;lt;code&amp;gt;payload.txt&amp;lt;/code&amp;gt; or &amp;lt;code&amp;gt;payload.sh&amp;lt;/code&amp;gt; and it has to be placed in the &amp;lt;code&amp;gt;root&amp;lt;/code&amp;gt; directory of the flash drive. Similarly, payload extensions should be stored in a &amp;lt;code&amp;gt;/extensions&amp;lt;/code&amp;gt; directory on the flash drive. &lt;br /&gt;
&lt;br /&gt;
In addition, it is possible to transfer payloads and payload extensions to the device via the Signal Owl access point in arming mode using SSH. There they are stored in the &amp;lt;code&amp;gt;/root/payload&amp;lt;/code&amp;gt; directory and Payload Extensions are stored in the &amp;lt;code&amp;gt;/root/payload/extensions&amp;lt;/code&amp;gt; directory.&lt;br /&gt;
&lt;br /&gt;
== Payload Development ==&lt;br /&gt;
&lt;br /&gt;
Payloads for the Signal Owl are written in bash with [https://github.com/hak5darren/USB-Rubber-Ducky/wiki/Duckyscript Ducky Script] and can be created with any standard text editor. All payloads should begin with an interpreter directive, like the shebang &amp;lt;code&amp;gt;#!/bin/bash&amp;lt;/code&amp;gt; for bash payloads and payloads must be named either &amp;lt;code&amp;gt;payload.txt&amp;lt;/code&amp;gt; or &amp;lt;code&amp;gt;payload.sh&amp;lt;/code&amp;gt;. In order to create effective payloads, the Signal Owl comes with several preinstalled penetration testing tools. These are as follows: [https://nmap.org/ Nmap], [https://www.aircrack-ng.org/ Aircrack-ng], [https://github.com/aircrack-ng/mdk4 MDK4] and [https://www.kismetwireless.net/ Kismet].&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Tools&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
• Kismet - detector for wireless networks and devices.&lt;br /&gt;
&lt;br /&gt;
• MDK4 - Wi-Fi testing tool.&lt;br /&gt;
&lt;br /&gt;
• Aircrack-ng Suite - a complete suite of tools for WiFi network security assessment.&lt;br /&gt;
&lt;br /&gt;
• Nmap - open source utility for network discovery and security auditing.&lt;br /&gt;
&lt;br /&gt;
Hak5 offers ready-to-use payloads and payload extensions on their [https://github.com/hak5/signalowl-payloads GitHub repository].&lt;br /&gt;
&lt;br /&gt;
== Implant / mobile operations ==&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Implant operations&lt;br /&gt;
&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
During long term wireless engagements, the Signal Owl may be planted inline between any typical 5V USB power source. This may be useful in situations where ports are occupied, or to deter the unit from being unplugged.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Mobile operations&lt;br /&gt;
&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
The Signal Owl features a low power consumption profile, with a typical power draw averaging 100-200 mAh. Additionally, it is thermally optimized for long term deployments in many indoor environments. One can expect a large 20,000 mAh USB battery bank to operate the unit for up to 4 days.&lt;br /&gt;
&lt;br /&gt;
= Use Cases =&lt;br /&gt;
&lt;br /&gt;
The Signal Owl has a variety of different use cases. Among the most popular ones are classical network mapping and wardriving as well as basic penetration tests for different wireless technologies.&lt;br /&gt;
&lt;br /&gt;
== Fake Beacon Flooding Attack ==&lt;br /&gt;
&lt;br /&gt;
The Fake Beacon Flooding Attack is one possible use case for the Signal Owl. With that attack, fake beacon frames are broadcasted to nearby devices. Beacon Frames include various parameters like the SSID, the type of encryption used and timestamps. This results in the creation of multiple fake Wi-Fi networks. Devices with Wi-Fi browsers are then flooded with these fake networks, causing potential network scanner and driver crashes. Furthermore, the attack may prevent legitimate users from finding their networks and lead to denial of service. The preinstalled tools Aircrack-ng and MDK4 were used to create this payload. After powering on the device, multiple fake networks with random SSIDs are generated and broadcasted to all nearby devices.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;bash&amp;quot;&amp;gt;&lt;br /&gt;
#!/bin/bash&lt;br /&gt;
&lt;br /&gt;
LED SETUP&lt;br /&gt;
sleep 10&lt;br /&gt;
airmon-ng check kill&lt;br /&gt;
sleep 10&lt;br /&gt;
#creates monitor mode interface on wirelss card of the Signal Owl&lt;br /&gt;
airmon-ng start wlan0&lt;br /&gt;
sleep 10&lt;br /&gt;
LED ATTACK&lt;br /&gt;
#floods nearby devices with random SSIDs&lt;br /&gt;
mdk4 wlan0mon b -a -m -s 500&lt;br /&gt;
&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The results as seen from a victim running a Windows 10 system are pictured in the figure below.&lt;br /&gt;
&lt;br /&gt;
[[File:FakeBeaconFloodingSignalOwl.png|none|Random SSIDs as seen from a victim Windows 10 client |]][Eigene Darstellung]&lt;br /&gt;
&lt;br /&gt;
== Open AP Nmap Scanner ==&lt;br /&gt;
&lt;br /&gt;
With the Open AP Nmap Scanner payload, the Signal Owl scans for open access points. If the Signal Owl finds one or more open access points, it connects to them and uses Nmap to scan and analyze them. The results are then stored in the loot directory. For each discovered open access point, the Signal Owl generates a separate results file. This payload has some settings which can be seen in the following listing.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;bash&amp;quot;&amp;gt;&lt;br /&gt;
NMAP_OPTIONS=&amp;quot;-sP&amp;quot;&lt;br /&gt;
LOOT_DIR=/root/loot/open_ap_nmap_scan&lt;br /&gt;
MAX_CIDR=20&lt;br /&gt;
DEBUG=1&lt;br /&gt;
&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Basic Bluetooth Scanner ==&lt;br /&gt;
&lt;br /&gt;
This payload requires an external Bluetooth adapter, since the Signal Owl does not have Bluetooth built in. The Basic Bluetooth Scanner scans for devices that have Bluetooth enabled and optionally queries them using the hcitool and the info command. This payload does also have some settings, as shown in the listing below.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;bash&amp;quot;&amp;gt;&lt;br /&gt;
LOOT_DIR=/root/loot/bluetooth_scan&lt;br /&gt;
BT_OUTFILE=`date +%s`.bt.list&lt;br /&gt;
BT_INFOFILE=`date +%s`.bt.info   &lt;br /&gt;
BTDEV=hci0&lt;br /&gt;
DEBUG=0 &lt;br /&gt;
INTERROGATE=1 &lt;br /&gt;
&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== WiFi Connect ==&lt;br /&gt;
&lt;br /&gt;
With the WiFi Connect payload, which can be seen in the following Listing, and the wificonnect.sh Payload extension, the Signal Owl can be connected to a nearby network. The SSID and password of the network to which the Signal Owl should connect must be specified in the code. Optionally, the SSH server of the device can be started by removing the hash sign in the code before the corresponding command. &lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;bash&amp;quot;&amp;gt;&lt;br /&gt;
#!/bin/bash&lt;br /&gt;
&lt;br /&gt;
# WiFi Client Setup&lt;br /&gt;
WIFI_SSID=&amp;quot;network-name&amp;quot;&lt;br /&gt;
WIFI_PASS=&amp;quot;passphrase&amp;quot;&lt;br /&gt;
&lt;br /&gt;
LED SETUP&lt;br /&gt;
WIFI_CONNECT&lt;br /&gt;
# optionally start SSH server&lt;br /&gt;
# /etc/init.d/sshd start&lt;br /&gt;
LED ATTACK&lt;br /&gt;
&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The &amp;lt;code&amp;gt;WIFI_CONNECT&amp;lt;/code&amp;gt; command executes the wifi_connect.sh payload extension, which is shown in the following listing. &lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;bash&amp;quot;&amp;gt;&lt;br /&gt;
#!/bin/bash&lt;br /&gt;
&lt;br /&gt;
function WIFI_CONNECT() {&lt;br /&gt;
    [[ &amp;quot;x$WIFI_INT&amp;quot; == &amp;quot;x&amp;quot; ]] &amp;amp;&amp;amp; WIFI_INT=wlan0&lt;br /&gt;
    ifconfig $WIFI_INT up;sleep 10&lt;br /&gt;
    echo -e &amp;quot;network={\nssid=\&amp;quot;$WIFI_SSID\&amp;quot;\npsk=\&amp;quot;$WIFI_PASS\&amp;quot;\npriority=1\n}&amp;quot;&amp;gt;/tmp/wpa-$WIFI_INT.conf&lt;br /&gt;
    wpa_supplicant -B -Dnl80211 -i $WIFI_INT -c /tmp/wpa-$WIFI_INT.conf&lt;br /&gt;
    while(iwconfig $WIFI_INT | grep Not-Associated); do sleep 1; done&lt;br /&gt;
    udhcpc -i $WIFI_INT&lt;br /&gt;
}&lt;br /&gt;
export -f WIFI_CONNECT&lt;br /&gt;
&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The payload extension code uses the &amp;lt;code&amp;gt;WIFI_SSID&amp;lt;/code&amp;gt; and &amp;lt;code&amp;gt;WIFI_PASS&amp;lt;/code&amp;gt; variables of the payload to connect the Signal Owl to the network. With the command &amp;lt;code&amp;gt;export -f WIFI_CONNECT&amp;lt;/code&amp;gt; the function &amp;lt;code&amp;gt;WIFI_CONNECT&amp;lt;/code&amp;gt; is exported so that it can be called from the payload. &lt;br /&gt;
&lt;br /&gt;
If the SSH server is enabled, any SSH-enabled device can connect to the Signal Owl over the network, even though Attack Mode is enabled. The [[#Default Settings|default settings]] of the device can be used again for the connection, if they have not been changed yet. However, the IP address in this case is the IP address of the Signal Owl in this network.&lt;br /&gt;
&lt;br /&gt;
= Used Hardware =&lt;br /&gt;
&lt;br /&gt;
[[Signal Owl]]&lt;br /&gt;
&lt;br /&gt;
= References =&lt;br /&gt;
&lt;br /&gt;
*https://docs.hak5.org/signal-owl/&lt;br /&gt;
*https://github.com/hak5/signalowl-payloads&lt;br /&gt;
&lt;br /&gt;
[[Category:Pentesting]]&lt;/div&gt;</summary>
		<author><name>MMayer</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=Hak5_Signal_Owl&amp;diff=10725</id>
		<title>Hak5 Signal Owl</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=Hak5_Signal_Owl&amp;diff=10725"/>
		<updated>2023-01-07T01:57:20Z</updated>

		<summary type="html">&lt;p&gt;MMayer: /* WiFi Connect */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= Introduction =&lt;br /&gt;
&lt;br /&gt;
The [https://docs.hak5.org/signal-owl/ Signal Owl] is a hardware product developed by the company [https://shop.hak5.org/ Hak5].&lt;br /&gt;
It is a simple payload-based signals intelligence platform with a unique design for discreet planting or mobile operations on any engagement. The most popular application cases include classic network mapping and basic penetration tests for various wireless technologies.&lt;br /&gt;
&lt;br /&gt;
== Initial Setup ==&lt;br /&gt;
&lt;br /&gt;
When first unboxing the Signal Owl, the device runs a stager firmware that is designed to flash the latest firmware from a USB flash drive. In order to update the Signal Owl, the [https://downloads.hak5.org/owl latest firmware] has to be downloaded. Then, the downloaded file must be copied to the root of an EXT4 or FAT32 formatted USB flash drive. It is important not to modify this file. The next step is to plug the USB flash drive into the powered off Signal Owl. Afterwards, the device has to be powered on by a reliable USB source. The upgrade itself takes approximately five to ten minutes and is indicated by a solid red LED light. When finished, the device will reboot, enter Attack Mode and blink slowly, indicating an error running the payload because no payload has been found.&lt;br /&gt;
&lt;br /&gt;
= Hardware =&lt;br /&gt;
&lt;br /&gt;
[[File:SignalOwlDiagram.png|thumb|500px|frame|Components of the Signal Owl [Eigene Darstellung]]] &lt;br /&gt;
&lt;br /&gt;
The Signal Owl is designed to be rapidly deployed in all kinds of environments, allowing it to be an entry point for network analysis and basic wireless attacks in a variety of locations. With a power consumption of 100-200 mAh and the thermally optimized architecture, mobile operations as well as long term deployments, are enabled.&lt;br /&gt;
&lt;br /&gt;
== Components ==&lt;br /&gt;
&lt;br /&gt;
This device features several components of which some may not be visible to the human eye at first sight.&lt;br /&gt;
&lt;br /&gt;
=== USB Power / Passthrough Plug ===&lt;br /&gt;
&lt;br /&gt;
The USB power or passthrough plug is used to power the device. It can be powered from any reliable USB source.&lt;br /&gt;
&lt;br /&gt;
=== USB 2.0 Passthrough Port ===&lt;br /&gt;
&lt;br /&gt;
The USB 2.0 passthrough port is the port closest to the pigtail. Data and power pass through to that port, allowing for implant operations. If a device such as a keyboard is plugged in between this passthrough port and the power plug is connected to the target computer, the Signal Owl will remain undetected by the operating system. Only the keyboard will be visible on the target computer.&lt;br /&gt;
&lt;br /&gt;
=== USB 2.0 Host Port ===&lt;br /&gt;
&lt;br /&gt;
The USB 2.0 host port is the port farthest away from the pigtail. It is connected to the Linux socket of the Signal Owl and supports USB flash drives formatted with FAT32 and EXT4 file systems as well as many Wi-Fi, Bluetooth and other RF transceivers.&lt;br /&gt;
&lt;br /&gt;
=== Button ===&lt;br /&gt;
&lt;br /&gt;
The button on the bottom of the device is used to enter Arming Mode and to interact with payloads. It is not pressable without special tools like paperclips.&lt;br /&gt;
&lt;br /&gt;
=== Status LED ===&lt;br /&gt;
&lt;br /&gt;
The status LED indicates the current status of the Signal Owl. When it is turned off, it is not visible.&lt;br /&gt;
&lt;br /&gt;
The Signal Owl features a red LED with the following default status indications:&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
!|LED&lt;br /&gt;
!|Status&lt;br /&gt;
|-&lt;br /&gt;
|Blinking&lt;br /&gt;
|Booting&lt;br /&gt;
|-&lt;br /&gt;
|Solid&lt;br /&gt;
|Mounting external storage / Running upgrade&lt;br /&gt;
|-&lt;br /&gt;
|Single blinking&lt;br /&gt;
|Attack Mode&lt;br /&gt;
|-&lt;br /&gt;
|Double blinking&lt;br /&gt;
|Arming Mode&lt;br /&gt;
|-&lt;br /&gt;
|Slow blinking&lt;br /&gt;
|Error running payload&lt;br /&gt;
|-&lt;br /&gt;
|Fast blinking&lt;br /&gt;
|Select Mode (Deprecated from version 1.0.1 onward)&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= Software =&lt;br /&gt;
&lt;br /&gt;
== Modes of Operation ==&lt;br /&gt;
&lt;br /&gt;
The Signal Owl comes with two modes of operation, Attack Mode and Arming Mode. By default, the device will boot into Attack Mode. In order to access Arming Mode, the button on the bottom of the device has to be pressed while in Attack Mode. It is not recommended to press the button during the boot sequence, as this can possibly brick the device and render it useless. The arming mode is used for firmware updates and shell access, while the attack mode is used to load and execute the payload.&lt;br /&gt;
&lt;br /&gt;
=== Attack Mode ===&lt;br /&gt;
&lt;br /&gt;
Attack Mode is the default mode, the Signal Owl boots into. It provides two basic functions, being the payload loading function and the payload execution function. &lt;br /&gt;
&lt;br /&gt;
The payload loading function checks for any USB flash drives plugged into the host port of the device and copies payloads to &amp;lt;code&amp;gt;/root/payload&amp;lt;/code&amp;gt; and extensions to &amp;lt;code&amp;gt;/root/payload/extensions&amp;lt;/code&amp;gt; on the Signal Owl. &lt;br /&gt;
&lt;br /&gt;
The payload execution function is responsible for executing the payload that is currently stored on the root of the Signal Owl. In case no payload is found, the device will blink slowly, indicating the FAIL status.&lt;br /&gt;
&lt;br /&gt;
=== Arming Mode ===&lt;br /&gt;
&lt;br /&gt;
The Arming Mode provides two basic functions, being the firmware update function and the shell access function. The firmware update function checks for any USB flash drives plugged into the host port of the device and copies firmware upgrade files into the internal storage of the device and flashes it. The shell access function starts an open access point with the SSID Owl_xxxx in which xxxx indicates the last two octets of the device&#039;s MAC address. Additionally, a SSH server providing access to the shell of the Signal Owl is enabled.&lt;br /&gt;
&lt;br /&gt;
== Default Settings ==&lt;br /&gt;
&lt;br /&gt;
Default settings that are used in order to access the device via SSH are pictured in the table below.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
!colspan=&amp;quot;2&amp;quot;|Default Settings&lt;br /&gt;
|-&lt;br /&gt;
|Username&lt;br /&gt;
|root&lt;br /&gt;
|-&lt;br /&gt;
|Password&lt;br /&gt;
|hak5owl&lt;br /&gt;
|-&lt;br /&gt;
|SSID&lt;br /&gt;
|Owl_xxxx&lt;br /&gt;
|-&lt;br /&gt;
|IP Address&lt;br /&gt;
|172.16.56.1&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
SSH command: &amp;lt;code&amp;gt;ssh root@172.16.56.1&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The SSID during Arming Mode is Owl_xxxx in which xxxx indicates the last two octets of the devices MAC address.&lt;br /&gt;
&lt;br /&gt;
= Usage =&lt;br /&gt;
&lt;br /&gt;
== Arming Mode connection ==&lt;br /&gt;
&lt;br /&gt;
Step-by-step guide for accessing the arming mode&lt;br /&gt;
&lt;br /&gt;
#Click on the button located on the bottom of the Signal Owl while it is in attack mode. After pressing the button, the signal owl enters the arming mode and provides an open access point with the name Owl xxxx (where xxxx stands for the last two digits of the MAC address of the device).&lt;br /&gt;
#Connect to the access point.&amp;lt;br&amp;gt;[[File:Armingmode.png]][Eigene Darstellung]&lt;br /&gt;
#Now you can connect via ssh by using the [[#Default Settings|default settings]].&lt;br /&gt;
#After successful connection, you will end up in the root directory.&amp;lt;br&amp;gt;[[File:ArmingmodeSSH.png]][Eigene Darstellung]&lt;br /&gt;
#Now you can change the files and directories on the Signal Owl to view results, transfer payloads and extensions or to make further changes.&lt;br /&gt;
&lt;br /&gt;
== Directory structure ==&lt;br /&gt;
&lt;br /&gt;
The following directory tree shows the directory structure of the Signal Owl.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
/&lt;br /&gt;
├── loot&lt;br /&gt;
└── payload/&lt;br /&gt;
    └── extensions&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
*Loot - Directory where the Signal Owl saves loot while executing payloads that produce loot.&lt;br /&gt;
*Payload - This directory holds the current payload. &lt;br /&gt;
*Extensions -  This directory holds all extensions.&lt;br /&gt;
&lt;br /&gt;
== Adding Payloads and Extensions ==&lt;br /&gt;
&lt;br /&gt;
Adding a payload can be done in two different ways. Either with a USB flash drive or via the Signal Owl access point to the internal storage of the device. &lt;br /&gt;
&lt;br /&gt;
When booting, payloads on USB flash drives are given priority and will override payloads stored on the Signal Owl. To successfully copy a payload to the Signal Owl, the payload must be named &amp;lt;code&amp;gt;payload.txt&amp;lt;/code&amp;gt; or &amp;lt;code&amp;gt;payload.sh&amp;lt;/code&amp;gt; and it has to be placed in the &amp;lt;code&amp;gt;root&amp;lt;/code&amp;gt; directory of the flash drive. Similarly, payload extensions should be stored in a &amp;lt;code&amp;gt;/extensions&amp;lt;/code&amp;gt; directory on the flash drive. &lt;br /&gt;
&lt;br /&gt;
In addition, it is possible to transfer payloads and payload extensions to the device via the Signal Owl access point in arming mode using SSH. There they are stored in the &amp;lt;code&amp;gt;/root/payload&amp;lt;/code&amp;gt; directory and Payload Extensions are stored in the &amp;lt;code&amp;gt;/root/payload/extensions&amp;lt;/code&amp;gt; directory.&lt;br /&gt;
&lt;br /&gt;
== Payload Development ==&lt;br /&gt;
&lt;br /&gt;
Payloads for the Signal Owl are written in bash with [https://github.com/hak5darren/USB-Rubber-Ducky/wiki/Duckyscript Ducky Script] and can be created with any standard text editor. All payloads should begin with an interpreter directive, like the shebang &amp;lt;code&amp;gt;#!/bin/bash&amp;lt;/code&amp;gt; for bash payloads and payloads must be named either &amp;lt;code&amp;gt;payload.txt&amp;lt;/code&amp;gt; or &amp;lt;code&amp;gt;payload.sh&amp;lt;/code&amp;gt;. In order to create effective payloads, the Signal Owl comes with several preinstalled penetration testing tools. These are as follows: [https://nmap.org/ Nmap], [https://www.aircrack-ng.org/ Aircrack-ng], [https://github.com/aircrack-ng/mdk4 MDK4] and [https://www.kismetwireless.net/ Kismet].&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Tools&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
• Kismet - detector for wireless networks and devices.&lt;br /&gt;
&lt;br /&gt;
• MDK4 - Wi-Fi testing tool.&lt;br /&gt;
&lt;br /&gt;
• Aircrack-ng Suite - a complete suite of tools for WiFi network security assessment.&lt;br /&gt;
&lt;br /&gt;
• Nmap - open source utility for network discovery and security auditing.&lt;br /&gt;
&lt;br /&gt;
Hak5 offers ready-to-use payloads and payload extensions on their [https://github.com/hak5/signalowl-payloads GitHub repository].&lt;br /&gt;
&lt;br /&gt;
== Implant / mobile operations ==&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Implant operations&lt;br /&gt;
&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
During long term wireless engagements, the Signal Owl may be planted inline between any typical 5V USB power source. This may be useful in situations where ports are occupied, or to deter the unit from being unplugged.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Mobile operations&lt;br /&gt;
&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
The Signal Owl features a low power consumption profile, with a typical power draw averaging 100-200 mAh. Additionally, it is thermally optimized for long term deployments in many indoor environments. One can expect a large 20,000 mAh USB battery bank to operate the unit for up to 4 days.&lt;br /&gt;
&lt;br /&gt;
= Use Cases =&lt;br /&gt;
&lt;br /&gt;
The Signal Owl has a variety of different use cases. Among the most popular ones are classical network mapping and wardriving as well as basic penetration tests for different wireless technologies.&lt;br /&gt;
&lt;br /&gt;
== Fake Beacon Flooding Attack ==&lt;br /&gt;
&lt;br /&gt;
The Fake Beacon Flooding Attack is one possible use case for the Signal Owl. With that attack, fake beacon frames are broadcasted to nearby devices. Beacon Frames include various parameters like the SSID, the type of encryption used and timestamps. This results in the creation of multiple fake Wi-Fi networks. Devices with Wi-Fi browsers are then flooded with these fake networks, causing potential network scanner and driver crashes. Furthermore, the attack may prevent legitimate users from finding their networks and lead to denial of service. The preinstalled tools Aircrack-ng and MDK4 were used to create this payload. After powering on the device, multiple fake networks with random SSIDs are generated and broadcasted to all nearby devices.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;bash&amp;quot;&amp;gt;&lt;br /&gt;
#!/bin/bash&lt;br /&gt;
&lt;br /&gt;
LED SETUP&lt;br /&gt;
sleep 10&lt;br /&gt;
airmon-ng check kill&lt;br /&gt;
sleep 10&lt;br /&gt;
#creates monitor mode interface on wirelss card of the Signal Owl&lt;br /&gt;
airmon-ng start wlan0&lt;br /&gt;
sleep 10&lt;br /&gt;
LED ATTACK&lt;br /&gt;
#floods nearby devices with random SSIDs&lt;br /&gt;
mdk4 wlan0mon b -a -m -s 500&lt;br /&gt;
&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The results as seen from a victim running a Windows 10 system are pictured in the figure below.&lt;br /&gt;
&lt;br /&gt;
[[File:FakeBeaconFloodingSignalOwl.png|none|Random SSIDs as seen from a victim Windows 10 client |]][Eigene Darstellung]&lt;br /&gt;
&lt;br /&gt;
== Open AP Nmap Scanner ==&lt;br /&gt;
&lt;br /&gt;
With the Open AP Nmap Scanner payload, the Signal Owl scans for open access points. If the Signal Owl finds one or more open access points, it connects to them and uses Nmap to scan and analyze them. The results are then stored in the loot directory. For each discovered open access point, the Signal Owl generates a separate results file. This payload has some settings which can be seen in the following listing.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;bash&amp;quot;&amp;gt;&lt;br /&gt;
NMAP_OPTIONS=&amp;quot;-sP&amp;quot;&lt;br /&gt;
LOOT_DIR=/root/loot/open_ap_nmap_scan&lt;br /&gt;
MAX_CIDR=20&lt;br /&gt;
DEBUG=1&lt;br /&gt;
&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Basic Bluetooth Scanner ==&lt;br /&gt;
&lt;br /&gt;
This payload requires an external Bluetooth adapter, since the Signal Owl does not have Bluetooth built in. The Basic Bluetooth Scanner scans for devices that have Bluetooth enabled and optionally queries them using the hcitool and the info command. This payload does also have some settings, as shown in the listing below.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;bash&amp;quot;&amp;gt;&lt;br /&gt;
LOOT_DIR=/root/loot/bluetooth_scan&lt;br /&gt;
BT_OUTFILE=`date +%s`.bt.list&lt;br /&gt;
BT_INFOFILE=`date +%s`.bt.info   &lt;br /&gt;
BTDEV=hci0&lt;br /&gt;
DEBUG=0 &lt;br /&gt;
INTERROGATE=1 &lt;br /&gt;
&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== WiFi Connect ==&lt;br /&gt;
&lt;br /&gt;
With the WiFi Connect payload, which can be seen in the following Listing, and the wificonnect.sh Payload extension, the Signal Owl can be connected to a nearby network. The SSID and password of the network to which the Signal Owl should connect must be specified in the code. Optionally, the SSH server of the device can be started by removing the hash sign in the code before the corresponding command. &lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;bash&amp;quot;&amp;gt;&lt;br /&gt;
#!/bin/bash&lt;br /&gt;
&lt;br /&gt;
# WiFi Client Setup&lt;br /&gt;
WIFI_SSID=&amp;quot;network-name&amp;quot;&lt;br /&gt;
WIFI_PASS=&amp;quot;passphrase&amp;quot;&lt;br /&gt;
&lt;br /&gt;
LED SETUP&lt;br /&gt;
WIFI_CONNECT&lt;br /&gt;
# optionally start SSH server&lt;br /&gt;
# /etc/init.d/sshd start&lt;br /&gt;
LED ATTACK&lt;br /&gt;
&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The &amp;lt;code&amp;gt;WIFI_CONNECT&amp;lt;/code&amp;gt; command executes the wifi_connect.sh payload extension, which is shown in the following listing. &lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;bash&amp;quot;&amp;gt;&lt;br /&gt;
#!/bin/bash&lt;br /&gt;
&lt;br /&gt;
function WIFI_CONNECT() {&lt;br /&gt;
    [[ &amp;quot;x$WIFI_INT&amp;quot; == &amp;quot;x&amp;quot; ]] &amp;amp;&amp;amp; WIFI_INT=wlan0&lt;br /&gt;
    ifconfig $WIFI_INT up;sleep 10&lt;br /&gt;
    echo -e &amp;quot;network={\nssid=\&amp;quot;$WIFI_SSID\&amp;quot;\npsk=\&amp;quot;$WIFI_PASS\&amp;quot;\npriority=1\n}&amp;quot;&amp;gt;/tmp/wpa-$WIFI_INT.conf&lt;br /&gt;
    wpa_supplicant -B -Dnl80211 -i $WIFI_INT -c /tmp/wpa-$WIFI_INT.conf&lt;br /&gt;
    while(iwconfig $WIFI_INT | grep Not-Associated); do sleep 1; done&lt;br /&gt;
    udhcpc -i $WIFI_INT&lt;br /&gt;
}&lt;br /&gt;
export -f WIFI_CONNECT&lt;br /&gt;
&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The payload extension code uses the &amp;lt;code&amp;gt;WIFI_SSID&amp;lt;/code&amp;gt; and &amp;lt;code&amp;gt;WIFI_PASS&amp;lt;/code&amp;gt; variables of the payload to connect the Signal Owl to the network. With &amp;lt;code&amp;gt;export -f WIFI_CONNECT&amp;lt;/code&amp;gt; the function &amp;lt;code&amp;gt;WIFI_CONNECT&amp;lt;/code&amp;gt; is exported so that it can be called from the payload. &lt;br /&gt;
&lt;br /&gt;
If the SSH server is enabled, any SSH-enabled device can connect to the Signal Owl over the network, even though Attack Mode is enabled. The [[#Default Settings|default settings]] of the device can be used again for the connection, if they have not been changed yet. However, the IP address in this case is the IP address of the Signal Owl in this network.&lt;br /&gt;
&lt;br /&gt;
= Used Hardware =&lt;br /&gt;
&lt;br /&gt;
[[Signal Owl]]&lt;br /&gt;
&lt;br /&gt;
= References =&lt;br /&gt;
&lt;br /&gt;
*https://docs.hak5.org/signal-owl/&lt;br /&gt;
*https://github.com/hak5/signalowl-payloads&lt;br /&gt;
&lt;br /&gt;
[[Category:Pentesting]]&lt;/div&gt;</summary>
		<author><name>MMayer</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=Hak5_Signal_Owl&amp;diff=10724</id>
		<title>Hak5 Signal Owl</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=Hak5_Signal_Owl&amp;diff=10724"/>
		<updated>2023-01-07T01:53:51Z</updated>

		<summary type="html">&lt;p&gt;MMayer: /* WiFi Connect */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= Introduction =&lt;br /&gt;
&lt;br /&gt;
The [https://docs.hak5.org/signal-owl/ Signal Owl] is a hardware product developed by the company [https://shop.hak5.org/ Hak5].&lt;br /&gt;
It is a simple payload-based signals intelligence platform with a unique design for discreet planting or mobile operations on any engagement. The most popular application cases include classic network mapping and basic penetration tests for various wireless technologies.&lt;br /&gt;
&lt;br /&gt;
== Initial Setup ==&lt;br /&gt;
&lt;br /&gt;
When first unboxing the Signal Owl, the device runs a stager firmware that is designed to flash the latest firmware from a USB flash drive. In order to update the Signal Owl, the [https://downloads.hak5.org/owl latest firmware] has to be downloaded. Then, the downloaded file must be copied to the root of an EXT4 or FAT32 formatted USB flash drive. It is important not to modify this file. The next step is to plug the USB flash drive into the powered off Signal Owl. Afterwards, the device has to be powered on by a reliable USB source. The upgrade itself takes approximately five to ten minutes and is indicated by a solid red LED light. When finished, the device will reboot, enter Attack Mode and blink slowly, indicating an error running the payload because no payload has been found.&lt;br /&gt;
&lt;br /&gt;
= Hardware =&lt;br /&gt;
&lt;br /&gt;
[[File:SignalOwlDiagram.png|thumb|500px|frame|Components of the Signal Owl [Eigene Darstellung]]] &lt;br /&gt;
&lt;br /&gt;
The Signal Owl is designed to be rapidly deployed in all kinds of environments, allowing it to be an entry point for network analysis and basic wireless attacks in a variety of locations. With a power consumption of 100-200 mAh and the thermally optimized architecture, mobile operations as well as long term deployments, are enabled.&lt;br /&gt;
&lt;br /&gt;
== Components ==&lt;br /&gt;
&lt;br /&gt;
This device features several components of which some may not be visible to the human eye at first sight.&lt;br /&gt;
&lt;br /&gt;
=== USB Power / Passthrough Plug ===&lt;br /&gt;
&lt;br /&gt;
The USB power or passthrough plug is used to power the device. It can be powered from any reliable USB source.&lt;br /&gt;
&lt;br /&gt;
=== USB 2.0 Passthrough Port ===&lt;br /&gt;
&lt;br /&gt;
The USB 2.0 passthrough port is the port closest to the pigtail. Data and power pass through to that port, allowing for implant operations. If a device such as a keyboard is plugged in between this passthrough port and the power plug is connected to the target computer, the Signal Owl will remain undetected by the operating system. Only the keyboard will be visible on the target computer.&lt;br /&gt;
&lt;br /&gt;
=== USB 2.0 Host Port ===&lt;br /&gt;
&lt;br /&gt;
The USB 2.0 host port is the port farthest away from the pigtail. It is connected to the Linux socket of the Signal Owl and supports USB flash drives formatted with FAT32 and EXT4 file systems as well as many Wi-Fi, Bluetooth and other RF transceivers.&lt;br /&gt;
&lt;br /&gt;
=== Button ===&lt;br /&gt;
&lt;br /&gt;
The button on the bottom of the device is used to enter Arming Mode and to interact with payloads. It is not pressable without special tools like paperclips.&lt;br /&gt;
&lt;br /&gt;
=== Status LED ===&lt;br /&gt;
&lt;br /&gt;
The status LED indicates the current status of the Signal Owl. When it is turned off, it is not visible.&lt;br /&gt;
&lt;br /&gt;
The Signal Owl features a red LED with the following default status indications:&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
!|LED&lt;br /&gt;
!|Status&lt;br /&gt;
|-&lt;br /&gt;
|Blinking&lt;br /&gt;
|Booting&lt;br /&gt;
|-&lt;br /&gt;
|Solid&lt;br /&gt;
|Mounting external storage / Running upgrade&lt;br /&gt;
|-&lt;br /&gt;
|Single blinking&lt;br /&gt;
|Attack Mode&lt;br /&gt;
|-&lt;br /&gt;
|Double blinking&lt;br /&gt;
|Arming Mode&lt;br /&gt;
|-&lt;br /&gt;
|Slow blinking&lt;br /&gt;
|Error running payload&lt;br /&gt;
|-&lt;br /&gt;
|Fast blinking&lt;br /&gt;
|Select Mode (Deprecated from version 1.0.1 onward)&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= Software =&lt;br /&gt;
&lt;br /&gt;
== Modes of Operation ==&lt;br /&gt;
&lt;br /&gt;
The Signal Owl comes with two modes of operation, Attack Mode and Arming Mode. By default, the device will boot into Attack Mode. In order to access Arming Mode, the button on the bottom of the device has to be pressed while in Attack Mode. It is not recommended to press the button during the boot sequence, as this can possibly brick the device and render it useless. The arming mode is used for firmware updates and shell access, while the attack mode is used to load and execute the payload.&lt;br /&gt;
&lt;br /&gt;
=== Attack Mode ===&lt;br /&gt;
&lt;br /&gt;
Attack Mode is the default mode, the Signal Owl boots into. It provides two basic functions, being the payload loading function and the payload execution function. &lt;br /&gt;
&lt;br /&gt;
The payload loading function checks for any USB flash drives plugged into the host port of the device and copies payloads to &amp;lt;code&amp;gt;/root/payload&amp;lt;/code&amp;gt; and extensions to &amp;lt;code&amp;gt;/root/payload/extensions&amp;lt;/code&amp;gt; on the Signal Owl. &lt;br /&gt;
&lt;br /&gt;
The payload execution function is responsible for executing the payload that is currently stored on the root of the Signal Owl. In case no payload is found, the device will blink slowly, indicating the FAIL status.&lt;br /&gt;
&lt;br /&gt;
=== Arming Mode ===&lt;br /&gt;
&lt;br /&gt;
The Arming Mode provides two basic functions, being the firmware update function and the shell access function. The firmware update function checks for any USB flash drives plugged into the host port of the device and copies firmware upgrade files into the internal storage of the device and flashes it. The shell access function starts an open access point with the SSID Owl_xxxx in which xxxx indicates the last two octets of the device&#039;s MAC address. Additionally, a SSH server providing access to the shell of the Signal Owl is enabled.&lt;br /&gt;
&lt;br /&gt;
== Default Settings ==&lt;br /&gt;
&lt;br /&gt;
Default settings that are used in order to access the device via SSH are pictured in the table below.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
!colspan=&amp;quot;2&amp;quot;|Default Settings&lt;br /&gt;
|-&lt;br /&gt;
|Username&lt;br /&gt;
|root&lt;br /&gt;
|-&lt;br /&gt;
|Password&lt;br /&gt;
|hak5owl&lt;br /&gt;
|-&lt;br /&gt;
|SSID&lt;br /&gt;
|Owl_xxxx&lt;br /&gt;
|-&lt;br /&gt;
|IP Address&lt;br /&gt;
|172.16.56.1&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
SSH command: &amp;lt;code&amp;gt;ssh root@172.16.56.1&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The SSID during Arming Mode is Owl_xxxx in which xxxx indicates the last two octets of the devices MAC address.&lt;br /&gt;
&lt;br /&gt;
= Usage =&lt;br /&gt;
&lt;br /&gt;
== Arming Mode connection ==&lt;br /&gt;
&lt;br /&gt;
Step-by-step guide for accessing the arming mode&lt;br /&gt;
&lt;br /&gt;
#Click on the button located on the bottom of the Signal Owl while it is in attack mode. After pressing the button, the signal owl enters the arming mode and provides an open access point with the name Owl xxxx (where xxxx stands for the last two digits of the MAC address of the device).&lt;br /&gt;
#Connect to the access point.&amp;lt;br&amp;gt;[[File:Armingmode.png]][Eigene Darstellung]&lt;br /&gt;
#Now you can connect via ssh by using the [[#Default Settings|default settings]].&lt;br /&gt;
#After successful connection, you will end up in the root directory.&amp;lt;br&amp;gt;[[File:ArmingmodeSSH.png]][Eigene Darstellung]&lt;br /&gt;
#Now you can change the files and directories on the Signal Owl to view results, transfer payloads and extensions or to make further changes.&lt;br /&gt;
&lt;br /&gt;
== Directory structure ==&lt;br /&gt;
&lt;br /&gt;
The following directory tree shows the directory structure of the Signal Owl.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
/&lt;br /&gt;
├── loot&lt;br /&gt;
└── payload/&lt;br /&gt;
    └── extensions&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
*Loot - Directory where the Signal Owl saves loot while executing payloads that produce loot.&lt;br /&gt;
*Payload - This directory holds the current payload. &lt;br /&gt;
*Extensions -  This directory holds all extensions.&lt;br /&gt;
&lt;br /&gt;
== Adding Payloads and Extensions ==&lt;br /&gt;
&lt;br /&gt;
Adding a payload can be done in two different ways. Either with a USB flash drive or via the Signal Owl access point to the internal storage of the device. &lt;br /&gt;
&lt;br /&gt;
When booting, payloads on USB flash drives are given priority and will override payloads stored on the Signal Owl. To successfully copy a payload to the Signal Owl, the payload must be named &amp;lt;code&amp;gt;payload.txt&amp;lt;/code&amp;gt; or &amp;lt;code&amp;gt;payload.sh&amp;lt;/code&amp;gt; and it has to be placed in the &amp;lt;code&amp;gt;root&amp;lt;/code&amp;gt; directory of the flash drive. Similarly, payload extensions should be stored in a &amp;lt;code&amp;gt;/extensions&amp;lt;/code&amp;gt; directory on the flash drive. &lt;br /&gt;
&lt;br /&gt;
In addition, it is possible to transfer payloads and payload extensions to the device via the Signal Owl access point in arming mode using SSH. There they are stored in the &amp;lt;code&amp;gt;/root/payload&amp;lt;/code&amp;gt; directory and Payload Extensions are stored in the &amp;lt;code&amp;gt;/root/payload/extensions&amp;lt;/code&amp;gt; directory.&lt;br /&gt;
&lt;br /&gt;
== Payload Development ==&lt;br /&gt;
&lt;br /&gt;
Payloads for the Signal Owl are written in bash with [https://github.com/hak5darren/USB-Rubber-Ducky/wiki/Duckyscript Ducky Script] and can be created with any standard text editor. All payloads should begin with an interpreter directive, like the shebang &amp;lt;code&amp;gt;#!/bin/bash&amp;lt;/code&amp;gt; for bash payloads and payloads must be named either &amp;lt;code&amp;gt;payload.txt&amp;lt;/code&amp;gt; or &amp;lt;code&amp;gt;payload.sh&amp;lt;/code&amp;gt;. In order to create effective payloads, the Signal Owl comes with several preinstalled penetration testing tools. These are as follows: [https://nmap.org/ Nmap], [https://www.aircrack-ng.org/ Aircrack-ng], [https://github.com/aircrack-ng/mdk4 MDK4] and [https://www.kismetwireless.net/ Kismet].&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Tools&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
• Kismet - detector for wireless networks and devices.&lt;br /&gt;
&lt;br /&gt;
• MDK4 - Wi-Fi testing tool.&lt;br /&gt;
&lt;br /&gt;
• Aircrack-ng Suite - a complete suite of tools for WiFi network security assessment.&lt;br /&gt;
&lt;br /&gt;
• Nmap - open source utility for network discovery and security auditing.&lt;br /&gt;
&lt;br /&gt;
Hak5 offers ready-to-use payloads and payload extensions on their [https://github.com/hak5/signalowl-payloads GitHub repository].&lt;br /&gt;
&lt;br /&gt;
== Implant / mobile operations ==&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Implant operations&lt;br /&gt;
&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
During long term wireless engagements, the Signal Owl may be planted inline between any typical 5V USB power source. This may be useful in situations where ports are occupied, or to deter the unit from being unplugged.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Mobile operations&lt;br /&gt;
&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
The Signal Owl features a low power consumption profile, with a typical power draw averaging 100-200 mAh. Additionally, it is thermally optimized for long term deployments in many indoor environments. One can expect a large 20,000 mAh USB battery bank to operate the unit for up to 4 days.&lt;br /&gt;
&lt;br /&gt;
= Use Cases =&lt;br /&gt;
&lt;br /&gt;
The Signal Owl has a variety of different use cases. Among the most popular ones are classical network mapping and wardriving as well as basic penetration tests for different wireless technologies.&lt;br /&gt;
&lt;br /&gt;
== Fake Beacon Flooding Attack ==&lt;br /&gt;
&lt;br /&gt;
The Fake Beacon Flooding Attack is one possible use case for the Signal Owl. With that attack, fake beacon frames are broadcasted to nearby devices. Beacon Frames include various parameters like the SSID, the type of encryption used and timestamps. This results in the creation of multiple fake Wi-Fi networks. Devices with Wi-Fi browsers are then flooded with these fake networks, causing potential network scanner and driver crashes. Furthermore, the attack may prevent legitimate users from finding their networks and lead to denial of service. The preinstalled tools Aircrack-ng and MDK4 were used to create this payload. After powering on the device, multiple fake networks with random SSIDs are generated and broadcasted to all nearby devices.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;bash&amp;quot;&amp;gt;&lt;br /&gt;
#!/bin/bash&lt;br /&gt;
&lt;br /&gt;
LED SETUP&lt;br /&gt;
sleep 10&lt;br /&gt;
airmon-ng check kill&lt;br /&gt;
sleep 10&lt;br /&gt;
#creates monitor mode interface on wirelss card of the Signal Owl&lt;br /&gt;
airmon-ng start wlan0&lt;br /&gt;
sleep 10&lt;br /&gt;
LED ATTACK&lt;br /&gt;
#floods nearby devices with random SSIDs&lt;br /&gt;
mdk4 wlan0mon b -a -m -s 500&lt;br /&gt;
&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The results as seen from a victim running a Windows 10 system are pictured in the figure below.&lt;br /&gt;
&lt;br /&gt;
[[File:FakeBeaconFloodingSignalOwl.png|none|Random SSIDs as seen from a victim Windows 10 client |]][Eigene Darstellung]&lt;br /&gt;
&lt;br /&gt;
== Open AP Nmap Scanner ==&lt;br /&gt;
&lt;br /&gt;
With the Open AP Nmap Scanner payload, the Signal Owl scans for open access points. If the Signal Owl finds one or more open access points, it connects to them and uses Nmap to scan and analyze them. The results are then stored in the loot directory. For each discovered open access point, the Signal Owl generates a separate results file. This payload has some settings which can be seen in the following listing.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;bash&amp;quot;&amp;gt;&lt;br /&gt;
NMAP_OPTIONS=&amp;quot;-sP&amp;quot;&lt;br /&gt;
LOOT_DIR=/root/loot/open_ap_nmap_scan&lt;br /&gt;
MAX_CIDR=20&lt;br /&gt;
DEBUG=1&lt;br /&gt;
&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Basic Bluetooth Scanner ==&lt;br /&gt;
&lt;br /&gt;
This payload requires an external Bluetooth adapter, since the Signal Owl does not have Bluetooth built in. The Basic Bluetooth Scanner scans for devices that have Bluetooth enabled and optionally queries them using the hcitool and the info command. This payload does also have some settings, as shown in the listing below.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;bash&amp;quot;&amp;gt;&lt;br /&gt;
LOOT_DIR=/root/loot/bluetooth_scan&lt;br /&gt;
BT_OUTFILE=`date +%s`.bt.list&lt;br /&gt;
BT_INFOFILE=`date +%s`.bt.info   &lt;br /&gt;
BTDEV=hci0&lt;br /&gt;
DEBUG=0 &lt;br /&gt;
INTERROGATE=1 &lt;br /&gt;
&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== WiFi Connect ==&lt;br /&gt;
&lt;br /&gt;
With the WiFi Connect payload, which can be seen in the following Listing, and the wificonnect.sh Payload extension, the Signal Owl can be connected to a nearby network. The SSID and password of the network to which the Signal Owl should connect must be specified in the code. Optionally, the SSH server of the device can be started by removing the hash sign in the code before the corresponding command. &lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;bash&amp;quot;&amp;gt;&lt;br /&gt;
#!/bin/bash&lt;br /&gt;
&lt;br /&gt;
# WiFi Client Setup&lt;br /&gt;
WIFI_SSID=&amp;quot;network-name&amp;quot;&lt;br /&gt;
WIFI_PASS=&amp;quot;passphrase&amp;quot;&lt;br /&gt;
&lt;br /&gt;
LED SETUP&lt;br /&gt;
WIFI_CONNECT&lt;br /&gt;
# optionally start SSH server&lt;br /&gt;
# /etc/init.d/sshd start&lt;br /&gt;
LED ATTACK&lt;br /&gt;
&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The &amp;lt;code&amp;gt;WIFI_CONNECT&amp;lt;/code&amp;gt; command executes the wifi_connect.sh payload extension, which is shown in the following listing. &lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;bash&amp;quot;&amp;gt;&lt;br /&gt;
#!/bin/bash&lt;br /&gt;
&lt;br /&gt;
function WIFI_CONNECT() {&lt;br /&gt;
    [[ &amp;quot;x$WIFI_INT&amp;quot; == &amp;quot;x&amp;quot; ]] &amp;amp;&amp;amp; WIFI_INT=wlan0&lt;br /&gt;
    ifconfig $WIFI_INT up;sleep 10&lt;br /&gt;
    echo -e &amp;quot;network={\nssid=\&amp;quot;$WIFI_SSID\&amp;quot;\npsk=\&amp;quot;$WIFI_PASS\&amp;quot;\npriority=1\n}&amp;quot;&amp;gt;/tmp/wpa-$WIFI_INT.conf&lt;br /&gt;
    wpa_supplicant -B -Dnl80211 -i $WIFI_INT -c /tmp/wpa-$WIFI_INT.conf&lt;br /&gt;
    while(iwconfig $WIFI_INT | grep Not-Associated); do sleep 1; done&lt;br /&gt;
    udhcpc -i $WIFI_INT&lt;br /&gt;
}&lt;br /&gt;
export -f WIFI_CONNECT&lt;br /&gt;
&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
If the SSH server is enabled, any SSH-enabled device can connect to the Signal Owl over the network, even though Attack Mode is enabled. The [[#Default Settings|default settings]] of the device can be used again for the connection, if they have not been changed yet. However, the IP address in this case is the IP address of the Signal Owl in this network.&lt;br /&gt;
&lt;br /&gt;
= Used Hardware =&lt;br /&gt;
&lt;br /&gt;
[[Signal Owl]]&lt;br /&gt;
&lt;br /&gt;
= References =&lt;br /&gt;
&lt;br /&gt;
*https://docs.hak5.org/signal-owl/&lt;br /&gt;
*https://github.com/hak5/signalowl-payloads&lt;br /&gt;
&lt;br /&gt;
[[Category:Pentesting]]&lt;/div&gt;</summary>
		<author><name>MMayer</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=Hak5_Signal_Owl&amp;diff=10723</id>
		<title>Hak5 Signal Owl</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=Hak5_Signal_Owl&amp;diff=10723"/>
		<updated>2023-01-07T01:41:51Z</updated>

		<summary type="html">&lt;p&gt;MMayer: /* Use Cases */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= Introduction =&lt;br /&gt;
&lt;br /&gt;
The [https://docs.hak5.org/signal-owl/ Signal Owl] is a hardware product developed by the company [https://shop.hak5.org/ Hak5].&lt;br /&gt;
It is a simple payload-based signals intelligence platform with a unique design for discreet planting or mobile operations on any engagement. The most popular application cases include classic network mapping and basic penetration tests for various wireless technologies.&lt;br /&gt;
&lt;br /&gt;
== Initial Setup ==&lt;br /&gt;
&lt;br /&gt;
When first unboxing the Signal Owl, the device runs a stager firmware that is designed to flash the latest firmware from a USB flash drive. In order to update the Signal Owl, the [https://downloads.hak5.org/owl latest firmware] has to be downloaded. Then, the downloaded file must be copied to the root of an EXT4 or FAT32 formatted USB flash drive. It is important not to modify this file. The next step is to plug the USB flash drive into the powered off Signal Owl. Afterwards, the device has to be powered on by a reliable USB source. The upgrade itself takes approximately five to ten minutes and is indicated by a solid red LED light. When finished, the device will reboot, enter Attack Mode and blink slowly, indicating an error running the payload because no payload has been found.&lt;br /&gt;
&lt;br /&gt;
= Hardware =&lt;br /&gt;
&lt;br /&gt;
[[File:SignalOwlDiagram.png|thumb|500px|frame|Components of the Signal Owl [Eigene Darstellung]]] &lt;br /&gt;
&lt;br /&gt;
The Signal Owl is designed to be rapidly deployed in all kinds of environments, allowing it to be an entry point for network analysis and basic wireless attacks in a variety of locations. With a power consumption of 100-200 mAh and the thermally optimized architecture, mobile operations as well as long term deployments, are enabled.&lt;br /&gt;
&lt;br /&gt;
== Components ==&lt;br /&gt;
&lt;br /&gt;
This device features several components of which some may not be visible to the human eye at first sight.&lt;br /&gt;
&lt;br /&gt;
=== USB Power / Passthrough Plug ===&lt;br /&gt;
&lt;br /&gt;
The USB power or passthrough plug is used to power the device. It can be powered from any reliable USB source.&lt;br /&gt;
&lt;br /&gt;
=== USB 2.0 Passthrough Port ===&lt;br /&gt;
&lt;br /&gt;
The USB 2.0 passthrough port is the port closest to the pigtail. Data and power pass through to that port, allowing for implant operations. If a device such as a keyboard is plugged in between this passthrough port and the power plug is connected to the target computer, the Signal Owl will remain undetected by the operating system. Only the keyboard will be visible on the target computer.&lt;br /&gt;
&lt;br /&gt;
=== USB 2.0 Host Port ===&lt;br /&gt;
&lt;br /&gt;
The USB 2.0 host port is the port farthest away from the pigtail. It is connected to the Linux socket of the Signal Owl and supports USB flash drives formatted with FAT32 and EXT4 file systems as well as many Wi-Fi, Bluetooth and other RF transceivers.&lt;br /&gt;
&lt;br /&gt;
=== Button ===&lt;br /&gt;
&lt;br /&gt;
The button on the bottom of the device is used to enter Arming Mode and to interact with payloads. It is not pressable without special tools like paperclips.&lt;br /&gt;
&lt;br /&gt;
=== Status LED ===&lt;br /&gt;
&lt;br /&gt;
The status LED indicates the current status of the Signal Owl. When it is turned off, it is not visible.&lt;br /&gt;
&lt;br /&gt;
The Signal Owl features a red LED with the following default status indications:&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
!|LED&lt;br /&gt;
!|Status&lt;br /&gt;
|-&lt;br /&gt;
|Blinking&lt;br /&gt;
|Booting&lt;br /&gt;
|-&lt;br /&gt;
|Solid&lt;br /&gt;
|Mounting external storage / Running upgrade&lt;br /&gt;
|-&lt;br /&gt;
|Single blinking&lt;br /&gt;
|Attack Mode&lt;br /&gt;
|-&lt;br /&gt;
|Double blinking&lt;br /&gt;
|Arming Mode&lt;br /&gt;
|-&lt;br /&gt;
|Slow blinking&lt;br /&gt;
|Error running payload&lt;br /&gt;
|-&lt;br /&gt;
|Fast blinking&lt;br /&gt;
|Select Mode (Deprecated from version 1.0.1 onward)&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= Software =&lt;br /&gt;
&lt;br /&gt;
== Modes of Operation ==&lt;br /&gt;
&lt;br /&gt;
The Signal Owl comes with two modes of operation, Attack Mode and Arming Mode. By default, the device will boot into Attack Mode. In order to access Arming Mode, the button on the bottom of the device has to be pressed while in Attack Mode. It is not recommended to press the button during the boot sequence, as this can possibly brick the device and render it useless. The arming mode is used for firmware updates and shell access, while the attack mode is used to load and execute the payload.&lt;br /&gt;
&lt;br /&gt;
=== Attack Mode ===&lt;br /&gt;
&lt;br /&gt;
Attack Mode is the default mode, the Signal Owl boots into. It provides two basic functions, being the payload loading function and the payload execution function. &lt;br /&gt;
&lt;br /&gt;
The payload loading function checks for any USB flash drives plugged into the host port of the device and copies payloads to &amp;lt;code&amp;gt;/root/payload&amp;lt;/code&amp;gt; and extensions to &amp;lt;code&amp;gt;/root/payload/extensions&amp;lt;/code&amp;gt; on the Signal Owl. &lt;br /&gt;
&lt;br /&gt;
The payload execution function is responsible for executing the payload that is currently stored on the root of the Signal Owl. In case no payload is found, the device will blink slowly, indicating the FAIL status.&lt;br /&gt;
&lt;br /&gt;
=== Arming Mode ===&lt;br /&gt;
&lt;br /&gt;
The Arming Mode provides two basic functions, being the firmware update function and the shell access function. The firmware update function checks for any USB flash drives plugged into the host port of the device and copies firmware upgrade files into the internal storage of the device and flashes it. The shell access function starts an open access point with the SSID Owl_xxxx in which xxxx indicates the last two octets of the device&#039;s MAC address. Additionally, a SSH server providing access to the shell of the Signal Owl is enabled.&lt;br /&gt;
&lt;br /&gt;
== Default Settings ==&lt;br /&gt;
&lt;br /&gt;
Default settings that are used in order to access the device via SSH are pictured in the table below.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
!colspan=&amp;quot;2&amp;quot;|Default Settings&lt;br /&gt;
|-&lt;br /&gt;
|Username&lt;br /&gt;
|root&lt;br /&gt;
|-&lt;br /&gt;
|Password&lt;br /&gt;
|hak5owl&lt;br /&gt;
|-&lt;br /&gt;
|SSID&lt;br /&gt;
|Owl_xxxx&lt;br /&gt;
|-&lt;br /&gt;
|IP Address&lt;br /&gt;
|172.16.56.1&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
SSH command: &amp;lt;code&amp;gt;ssh root@172.16.56.1&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The SSID during Arming Mode is Owl_xxxx in which xxxx indicates the last two octets of the devices MAC address.&lt;br /&gt;
&lt;br /&gt;
= Usage =&lt;br /&gt;
&lt;br /&gt;
== Arming Mode connection ==&lt;br /&gt;
&lt;br /&gt;
Step-by-step guide for accessing the arming mode&lt;br /&gt;
&lt;br /&gt;
#Click on the button located on the bottom of the Signal Owl while it is in attack mode. After pressing the button, the signal owl enters the arming mode and provides an open access point with the name Owl xxxx (where xxxx stands for the last two digits of the MAC address of the device).&lt;br /&gt;
#Connect to the access point.&amp;lt;br&amp;gt;[[File:Armingmode.png]][Eigene Darstellung]&lt;br /&gt;
#Now you can connect via ssh by using the [[#Default Settings|default settings]].&lt;br /&gt;
#After successful connection, you will end up in the root directory.&amp;lt;br&amp;gt;[[File:ArmingmodeSSH.png]][Eigene Darstellung]&lt;br /&gt;
#Now you can change the files and directories on the Signal Owl to view results, transfer payloads and extensions or to make further changes.&lt;br /&gt;
&lt;br /&gt;
== Directory structure ==&lt;br /&gt;
&lt;br /&gt;
The following directory tree shows the directory structure of the Signal Owl.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
/&lt;br /&gt;
├── loot&lt;br /&gt;
└── payload/&lt;br /&gt;
    └── extensions&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
*Loot - Directory where the Signal Owl saves loot while executing payloads that produce loot.&lt;br /&gt;
*Payload - This directory holds the current payload. &lt;br /&gt;
*Extensions -  This directory holds all extensions.&lt;br /&gt;
&lt;br /&gt;
== Adding Payloads and Extensions ==&lt;br /&gt;
&lt;br /&gt;
Adding a payload can be done in two different ways. Either with a USB flash drive or via the Signal Owl access point to the internal storage of the device. &lt;br /&gt;
&lt;br /&gt;
When booting, payloads on USB flash drives are given priority and will override payloads stored on the Signal Owl. To successfully copy a payload to the Signal Owl, the payload must be named &amp;lt;code&amp;gt;payload.txt&amp;lt;/code&amp;gt; or &amp;lt;code&amp;gt;payload.sh&amp;lt;/code&amp;gt; and it has to be placed in the &amp;lt;code&amp;gt;root&amp;lt;/code&amp;gt; directory of the flash drive. Similarly, payload extensions should be stored in a &amp;lt;code&amp;gt;/extensions&amp;lt;/code&amp;gt; directory on the flash drive. &lt;br /&gt;
&lt;br /&gt;
In addition, it is possible to transfer payloads and payload extensions to the device via the Signal Owl access point in arming mode using SSH. There they are stored in the &amp;lt;code&amp;gt;/root/payload&amp;lt;/code&amp;gt; directory and Payload Extensions are stored in the &amp;lt;code&amp;gt;/root/payload/extensions&amp;lt;/code&amp;gt; directory.&lt;br /&gt;
&lt;br /&gt;
== Payload Development ==&lt;br /&gt;
&lt;br /&gt;
Payloads for the Signal Owl are written in bash with [https://github.com/hak5darren/USB-Rubber-Ducky/wiki/Duckyscript Ducky Script] and can be created with any standard text editor. All payloads should begin with an interpreter directive, like the shebang &amp;lt;code&amp;gt;#!/bin/bash&amp;lt;/code&amp;gt; for bash payloads and payloads must be named either &amp;lt;code&amp;gt;payload.txt&amp;lt;/code&amp;gt; or &amp;lt;code&amp;gt;payload.sh&amp;lt;/code&amp;gt;. In order to create effective payloads, the Signal Owl comes with several preinstalled penetration testing tools. These are as follows: [https://nmap.org/ Nmap], [https://www.aircrack-ng.org/ Aircrack-ng], [https://github.com/aircrack-ng/mdk4 MDK4] and [https://www.kismetwireless.net/ Kismet].&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Tools&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
• Kismet - detector for wireless networks and devices.&lt;br /&gt;
&lt;br /&gt;
• MDK4 - Wi-Fi testing tool.&lt;br /&gt;
&lt;br /&gt;
• Aircrack-ng Suite - a complete suite of tools for WiFi network security assessment.&lt;br /&gt;
&lt;br /&gt;
• Nmap - open source utility for network discovery and security auditing.&lt;br /&gt;
&lt;br /&gt;
Hak5 offers ready-to-use payloads and payload extensions on their [https://github.com/hak5/signalowl-payloads GitHub repository].&lt;br /&gt;
&lt;br /&gt;
== Implant / mobile operations ==&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Implant operations&lt;br /&gt;
&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
During long term wireless engagements, the Signal Owl may be planted inline between any typical 5V USB power source. This may be useful in situations where ports are occupied, or to deter the unit from being unplugged.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Mobile operations&lt;br /&gt;
&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
The Signal Owl features a low power consumption profile, with a typical power draw averaging 100-200 mAh. Additionally, it is thermally optimized for long term deployments in many indoor environments. One can expect a large 20,000 mAh USB battery bank to operate the unit for up to 4 days.&lt;br /&gt;
&lt;br /&gt;
= Use Cases =&lt;br /&gt;
&lt;br /&gt;
The Signal Owl has a variety of different use cases. Among the most popular ones are classical network mapping and wardriving as well as basic penetration tests for different wireless technologies.&lt;br /&gt;
&lt;br /&gt;
== Fake Beacon Flooding Attack ==&lt;br /&gt;
&lt;br /&gt;
The Fake Beacon Flooding Attack is one possible use case for the Signal Owl. With that attack, fake beacon frames are broadcasted to nearby devices. Beacon Frames include various parameters like the SSID, the type of encryption used and timestamps. This results in the creation of multiple fake Wi-Fi networks. Devices with Wi-Fi browsers are then flooded with these fake networks, causing potential network scanner and driver crashes. Furthermore, the attack may prevent legitimate users from finding their networks and lead to denial of service. The preinstalled tools Aircrack-ng and MDK4 were used to create this payload. After powering on the device, multiple fake networks with random SSIDs are generated and broadcasted to all nearby devices.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;bash&amp;quot;&amp;gt;&lt;br /&gt;
#!/bin/bash&lt;br /&gt;
&lt;br /&gt;
LED SETUP&lt;br /&gt;
sleep 10&lt;br /&gt;
airmon-ng check kill&lt;br /&gt;
sleep 10&lt;br /&gt;
#creates monitor mode interface on wirelss card of the Signal Owl&lt;br /&gt;
airmon-ng start wlan0&lt;br /&gt;
sleep 10&lt;br /&gt;
LED ATTACK&lt;br /&gt;
#floods nearby devices with random SSIDs&lt;br /&gt;
mdk4 wlan0mon b -a -m -s 500&lt;br /&gt;
&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The results as seen from a victim running a Windows 10 system are pictured in the figure below.&lt;br /&gt;
&lt;br /&gt;
[[File:FakeBeaconFloodingSignalOwl.png|none|Random SSIDs as seen from a victim Windows 10 client |]][Eigene Darstellung]&lt;br /&gt;
&lt;br /&gt;
== Open AP Nmap Scanner ==&lt;br /&gt;
&lt;br /&gt;
With the Open AP Nmap Scanner payload, the Signal Owl scans for open access points. If the Signal Owl finds one or more open access points, it connects to them and uses Nmap to scan and analyze them. The results are then stored in the loot directory. For each discovered open access point, the Signal Owl generates a separate results file. This payload has some settings which can be seen in the following listing.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;bash&amp;quot;&amp;gt;&lt;br /&gt;
NMAP_OPTIONS=&amp;quot;-sP&amp;quot;&lt;br /&gt;
LOOT_DIR=/root/loot/open_ap_nmap_scan&lt;br /&gt;
MAX_CIDR=20&lt;br /&gt;
DEBUG=1&lt;br /&gt;
&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Basic Bluetooth Scanner ==&lt;br /&gt;
&lt;br /&gt;
This payload requires an external Bluetooth adapter, since the Signal Owl does not have Bluetooth built in. The Basic Bluetooth Scanner scans for devices that have Bluetooth enabled and optionally queries them using the hcitool and the info command. This payload does also have some settings, as shown in the listing below.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;bash&amp;quot;&amp;gt;&lt;br /&gt;
LOOT_DIR=/root/loot/bluetooth_scan&lt;br /&gt;
BT_OUTFILE=`date +%s`.bt.list&lt;br /&gt;
BT_INFOFILE=`date +%s`.bt.info   &lt;br /&gt;
BTDEV=hci0&lt;br /&gt;
DEBUG=0 &lt;br /&gt;
INTERROGATE=1 &lt;br /&gt;
&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== WiFi Connect ==&lt;br /&gt;
&lt;br /&gt;
= Used Hardware =&lt;br /&gt;
&lt;br /&gt;
[[Signal Owl]]&lt;br /&gt;
&lt;br /&gt;
= References =&lt;br /&gt;
&lt;br /&gt;
*https://docs.hak5.org/signal-owl/&lt;br /&gt;
*https://github.com/hak5/signalowl-payloads&lt;br /&gt;
&lt;br /&gt;
[[Category:Pentesting]]&lt;/div&gt;</summary>
		<author><name>MMayer</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=Hak5_Signal_Owl&amp;diff=10722</id>
		<title>Hak5 Signal Owl</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=Hak5_Signal_Owl&amp;diff=10722"/>
		<updated>2023-01-07T01:32:12Z</updated>

		<summary type="html">&lt;p&gt;MMayer: /* Basic Bluetooth Scanner */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= Introduction =&lt;br /&gt;
&lt;br /&gt;
The [https://docs.hak5.org/signal-owl/ Signal Owl] is a hardware product developed by the company [https://shop.hak5.org/ Hak5].&lt;br /&gt;
It is a simple payload-based signals intelligence platform with a unique design for discreet planting or mobile operations on any engagement. The most popular application cases include classic network mapping and basic penetration tests for various wireless technologies.&lt;br /&gt;
&lt;br /&gt;
== Initial Setup ==&lt;br /&gt;
&lt;br /&gt;
When first unboxing the Signal Owl, the device runs a stager firmware that is designed to flash the latest firmware from a USB flash drive. In order to update the Signal Owl, the [https://downloads.hak5.org/owl latest firmware] has to be downloaded. Then, the downloaded file must be copied to the root of an EXT4 or FAT32 formatted USB flash drive. It is important not to modify this file. The next step is to plug the USB flash drive into the powered off Signal Owl. Afterwards, the device has to be powered on by a reliable USB source. The upgrade itself takes approximately five to ten minutes and is indicated by a solid red LED light. When finished, the device will reboot, enter Attack Mode and blink slowly, indicating an error running the payload because no payload has been found.&lt;br /&gt;
&lt;br /&gt;
= Hardware =&lt;br /&gt;
&lt;br /&gt;
[[File:SignalOwlDiagram.png|thumb|500px|frame|Components of the Signal Owl [Eigene Darstellung]]] &lt;br /&gt;
&lt;br /&gt;
The Signal Owl is designed to be rapidly deployed in all kinds of environments, allowing it to be an entry point for network analysis and basic wireless attacks in a variety of locations. With a power consumption of 100-200 mAh and the thermally optimized architecture, mobile operations as well as long term deployments, are enabled.&lt;br /&gt;
&lt;br /&gt;
== Components ==&lt;br /&gt;
&lt;br /&gt;
This device features several components of which some may not be visible to the human eye at first sight.&lt;br /&gt;
&lt;br /&gt;
=== USB Power / Passthrough Plug ===&lt;br /&gt;
&lt;br /&gt;
The USB power or passthrough plug is used to power the device. It can be powered from any reliable USB source.&lt;br /&gt;
&lt;br /&gt;
=== USB 2.0 Passthrough Port ===&lt;br /&gt;
&lt;br /&gt;
The USB 2.0 passthrough port is the port closest to the pigtail. Data and power pass through to that port, allowing for implant operations. If a device such as a keyboard is plugged in between this passthrough port and the power plug is connected to the target computer, the Signal Owl will remain undetected by the operating system. Only the keyboard will be visible on the target computer.&lt;br /&gt;
&lt;br /&gt;
=== USB 2.0 Host Port ===&lt;br /&gt;
&lt;br /&gt;
The USB 2.0 host port is the port farthest away from the pigtail. It is connected to the Linux socket of the Signal Owl and supports USB flash drives formatted with FAT32 and EXT4 file systems as well as many Wi-Fi, Bluetooth and other RF transceivers.&lt;br /&gt;
&lt;br /&gt;
=== Button ===&lt;br /&gt;
&lt;br /&gt;
The button on the bottom of the device is used to enter Arming Mode and to interact with payloads. It is not pressable without special tools like paperclips.&lt;br /&gt;
&lt;br /&gt;
=== Status LED ===&lt;br /&gt;
&lt;br /&gt;
The status LED indicates the current status of the Signal Owl. When it is turned off, it is not visible.&lt;br /&gt;
&lt;br /&gt;
The Signal Owl features a red LED with the following default status indications:&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
!|LED&lt;br /&gt;
!|Status&lt;br /&gt;
|-&lt;br /&gt;
|Blinking&lt;br /&gt;
|Booting&lt;br /&gt;
|-&lt;br /&gt;
|Solid&lt;br /&gt;
|Mounting external storage / Running upgrade&lt;br /&gt;
|-&lt;br /&gt;
|Single blinking&lt;br /&gt;
|Attack Mode&lt;br /&gt;
|-&lt;br /&gt;
|Double blinking&lt;br /&gt;
|Arming Mode&lt;br /&gt;
|-&lt;br /&gt;
|Slow blinking&lt;br /&gt;
|Error running payload&lt;br /&gt;
|-&lt;br /&gt;
|Fast blinking&lt;br /&gt;
|Select Mode (Deprecated from version 1.0.1 onward)&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= Software =&lt;br /&gt;
&lt;br /&gt;
== Modes of Operation ==&lt;br /&gt;
&lt;br /&gt;
The Signal Owl comes with two modes of operation, Attack Mode and Arming Mode. By default, the device will boot into Attack Mode. In order to access Arming Mode, the button on the bottom of the device has to be pressed while in Attack Mode. It is not recommended to press the button during the boot sequence, as this can possibly brick the device and render it useless. The arming mode is used for firmware updates and shell access, while the attack mode is used to load and execute the payload.&lt;br /&gt;
&lt;br /&gt;
=== Attack Mode ===&lt;br /&gt;
&lt;br /&gt;
Attack Mode is the default mode, the Signal Owl boots into. It provides two basic functions, being the payload loading function and the payload execution function. &lt;br /&gt;
&lt;br /&gt;
The payload loading function checks for any USB flash drives plugged into the host port of the device and copies payloads to &amp;lt;code&amp;gt;/root/payload&amp;lt;/code&amp;gt; and extensions to &amp;lt;code&amp;gt;/root/payload/extensions&amp;lt;/code&amp;gt; on the Signal Owl. &lt;br /&gt;
&lt;br /&gt;
The payload execution function is responsible for executing the payload that is currently stored on the root of the Signal Owl. In case no payload is found, the device will blink slowly, indicating the FAIL status.&lt;br /&gt;
&lt;br /&gt;
=== Arming Mode ===&lt;br /&gt;
&lt;br /&gt;
The Arming Mode provides two basic functions, being the firmware update function and the shell access function. The firmware update function checks for any USB flash drives plugged into the host port of the device and copies firmware upgrade files into the internal storage of the device and flashes it. The shell access function starts an open access point with the SSID Owl_xxxx in which xxxx indicates the last two octets of the device&#039;s MAC address. Additionally, a SSH server providing access to the shell of the Signal Owl is enabled.&lt;br /&gt;
&lt;br /&gt;
== Default Settings ==&lt;br /&gt;
&lt;br /&gt;
Default settings that are used in order to access the device via SSH are pictured in the table below.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
!colspan=&amp;quot;2&amp;quot;|Default Settings&lt;br /&gt;
|-&lt;br /&gt;
|Username&lt;br /&gt;
|root&lt;br /&gt;
|-&lt;br /&gt;
|Password&lt;br /&gt;
|hak5owl&lt;br /&gt;
|-&lt;br /&gt;
|SSID&lt;br /&gt;
|Owl_xxxx&lt;br /&gt;
|-&lt;br /&gt;
|IP Address&lt;br /&gt;
|172.16.56.1&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
SSH command: &amp;lt;code&amp;gt;ssh root@172.16.56.1&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The SSID during Arming Mode is Owl_xxxx in which xxxx indicates the last two octets of the devices MAC address.&lt;br /&gt;
&lt;br /&gt;
= Usage =&lt;br /&gt;
&lt;br /&gt;
== Arming Mode connection ==&lt;br /&gt;
&lt;br /&gt;
Step-by-step guide for accessing the arming mode&lt;br /&gt;
&lt;br /&gt;
#Click on the button located on the bottom of the Signal Owl while it is in attack mode. After pressing the button, the signal owl enters the arming mode and provides an open access point with the name Owl xxxx (where xxxx stands for the last two digits of the MAC address of the device).&lt;br /&gt;
#Connect to the access point.&amp;lt;br&amp;gt;[[File:Armingmode.png]][Eigene Darstellung]&lt;br /&gt;
#Now you can connect via ssh by using the [[#Default Settings|default settings]].&lt;br /&gt;
#After successful connection, you will end up in the root directory.&amp;lt;br&amp;gt;[[File:ArmingmodeSSH.png]][Eigene Darstellung]&lt;br /&gt;
#Now you can change the files and directories on the Signal Owl to view results, transfer payloads and extensions or to make further changes.&lt;br /&gt;
&lt;br /&gt;
== Directory structure ==&lt;br /&gt;
&lt;br /&gt;
The following directory tree shows the directory structure of the Signal Owl.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
/&lt;br /&gt;
├── loot&lt;br /&gt;
└── payload/&lt;br /&gt;
    └── extensions&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
*Loot - Directory where the Signal Owl saves loot while executing payloads that produce loot.&lt;br /&gt;
*Payload - This directory holds the current payload. &lt;br /&gt;
*Extensions -  This directory holds all extensions.&lt;br /&gt;
&lt;br /&gt;
== Adding Payloads and Extensions ==&lt;br /&gt;
&lt;br /&gt;
Adding a payload can be done in two different ways. Either with a USB flash drive or via the Signal Owl access point to the internal storage of the device. &lt;br /&gt;
&lt;br /&gt;
When booting, payloads on USB flash drives are given priority and will override payloads stored on the Signal Owl. To successfully copy a payload to the Signal Owl, the payload must be named &amp;lt;code&amp;gt;payload.txt&amp;lt;/code&amp;gt; or &amp;lt;code&amp;gt;payload.sh&amp;lt;/code&amp;gt; and it has to be placed in the &amp;lt;code&amp;gt;root&amp;lt;/code&amp;gt; directory of the flash drive. Similarly, payload extensions should be stored in a &amp;lt;code&amp;gt;/extensions&amp;lt;/code&amp;gt; directory on the flash drive. &lt;br /&gt;
&lt;br /&gt;
In addition, it is possible to transfer payloads and payload extensions to the device via the Signal Owl access point in arming mode using SSH. There they are stored in the &amp;lt;code&amp;gt;/root/payload&amp;lt;/code&amp;gt; directory and Payload Extensions are stored in the &amp;lt;code&amp;gt;/root/payload/extensions&amp;lt;/code&amp;gt; directory.&lt;br /&gt;
&lt;br /&gt;
== Payload Development ==&lt;br /&gt;
&lt;br /&gt;
Payloads for the Signal Owl are written in bash with [https://github.com/hak5darren/USB-Rubber-Ducky/wiki/Duckyscript Ducky Script] and can be created with any standard text editor. All payloads should begin with an interpreter directive, like the shebang &amp;lt;code&amp;gt;#!/bin/bash&amp;lt;/code&amp;gt; for bash payloads and payloads must be named either &amp;lt;code&amp;gt;payload.txt&amp;lt;/code&amp;gt; or &amp;lt;code&amp;gt;payload.sh&amp;lt;/code&amp;gt;. In order to create effective payloads, the Signal Owl comes with several preinstalled penetration testing tools. These are as follows: [https://nmap.org/ Nmap], [https://www.aircrack-ng.org/ Aircrack-ng], [https://github.com/aircrack-ng/mdk4 MDK4] and [https://www.kismetwireless.net/ Kismet].&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Tools&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
• Kismet - detector for wireless networks and devices.&lt;br /&gt;
&lt;br /&gt;
• MDK4 - Wi-Fi testing tool.&lt;br /&gt;
&lt;br /&gt;
• Aircrack-ng Suite - a complete suite of tools for WiFi network security assessment.&lt;br /&gt;
&lt;br /&gt;
• Nmap - open source utility for network discovery and security auditing.&lt;br /&gt;
&lt;br /&gt;
Hak5 offers ready-to-use payloads and payload extensions on their [https://github.com/hak5/signalowl-payloads GitHub repository].&lt;br /&gt;
&lt;br /&gt;
== Implant / mobile operations ==&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Implant operations&lt;br /&gt;
&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
During long term wireless engagements, the Signal Owl may be planted inline between any typical 5V USB power source. This may be useful in situations where ports are occupied, or to deter the unit from being unplugged.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Mobile operations&lt;br /&gt;
&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
The Signal Owl features a low power consumption profile, with a typical power draw averaging 100-200 mAh. Additionally, it is thermally optimized for long term deployments in many indoor environments. One can expect a large 20,000 mAh USB battery bank to operate the unit for up to 4 days.&lt;br /&gt;
&lt;br /&gt;
= Use Cases =&lt;br /&gt;
&lt;br /&gt;
The Signal Owl has a variety of different use cases. Among the most popular ones are classical network mapping and wardriving as well as basic penetration tests for different wireless technologies.&lt;br /&gt;
&lt;br /&gt;
== Fake Beacon Flooding Attack ==&lt;br /&gt;
&lt;br /&gt;
The Fake Beacon Flooding Attack is one possible use case for the Signal Owl. With that attack, fake beacon frames are broadcasted to nearby devices. Beacon Frames include various parameters like the SSID, the type of encryption used and timestamps. This results in the creation of multiple fake Wi-Fi networks. Devices with Wi-Fi browsers are then flooded with these fake networks, causing potential network scanner and driver crashes. Furthermore, the attack may prevent legitimate users from finding their networks and lead to denial of service. The preinstalled tools Aircrack-ng and MDK4 were used to create this payload. After powering on the device, multiple fake networks with random SSIDs are generated and broadcasted to all nearby devices.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;bash&amp;quot;&amp;gt;&lt;br /&gt;
#!/bin/bash&lt;br /&gt;
&lt;br /&gt;
LED SETUP&lt;br /&gt;
sleep 10&lt;br /&gt;
airmon-ng check kill&lt;br /&gt;
sleep 10&lt;br /&gt;
#creates monitor mode interface on wirelss card of the Signal Owl&lt;br /&gt;
airmon-ng start wlan0&lt;br /&gt;
sleep 10&lt;br /&gt;
LED ATTACK&lt;br /&gt;
#floods nearby devices with random SSIDs&lt;br /&gt;
mdk4 wlan0mon b -a -m -s 500&lt;br /&gt;
&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The results as seen from a victim running a Windows 10 system are pictured in the figure below.&lt;br /&gt;
&lt;br /&gt;
[[File:FakeBeaconFloodingSignalOwl.png|none|Random SSIDs as seen from a victim Windows 10 client |]][Eigene Darstellung]&lt;br /&gt;
&lt;br /&gt;
== Open AP Nmap Scanner ==&lt;br /&gt;
&lt;br /&gt;
With the Open AP Nmap Scanner payload, the Signal Owl scans for open access points. If the Signal Owl finds one or more open access points, it connects to them and uses Nmap to scan and analyze them. The results are then stored in the loot directory. For each discovered open access point, the Signal Owl generates a separate results file. This payload has some settings which can be seen in the following listing.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;bash&amp;quot;&amp;gt;&lt;br /&gt;
NMAP_OPTIONS=&amp;quot;-sP&amp;quot;&lt;br /&gt;
LOOT_DIR=/root/loot/open_ap_nmap_scan&lt;br /&gt;
MAX_CIDR=20&lt;br /&gt;
DEBUG=1&lt;br /&gt;
&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Basic Bluetooth Scanner ==&lt;br /&gt;
&lt;br /&gt;
This payload requires an external Bluetooth adapter, since the Signal Owl does not have Bluetooth built in. The Basic Bluetooth Scanner scans for devices that have Bluetooth enabled and optionally queries them using the hcitool and the info command. This payload does also have some settings, as shown in the listing below.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;bash&amp;quot;&amp;gt;&lt;br /&gt;
LOOT_DIR=/root/loot/bluetooth_scan&lt;br /&gt;
BT_OUTFILE=`date +%s`.bt.list&lt;br /&gt;
BT_INFOFILE=`date +%s`.bt.info   &lt;br /&gt;
BTDEV=hci0&lt;br /&gt;
DEBUG=0 &lt;br /&gt;
INTERROGATE=1 &lt;br /&gt;
&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
= Used Hardware =&lt;br /&gt;
&lt;br /&gt;
[[Signal Owl]]&lt;br /&gt;
&lt;br /&gt;
= References =&lt;br /&gt;
&lt;br /&gt;
*https://docs.hak5.org/signal-owl/&lt;br /&gt;
*https://github.com/hak5/signalowl-payloads&lt;br /&gt;
&lt;br /&gt;
[[Category:Pentesting]]&lt;/div&gt;</summary>
		<author><name>MMayer</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=Hak5_Signal_Owl&amp;diff=10721</id>
		<title>Hak5 Signal Owl</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=Hak5_Signal_Owl&amp;diff=10721"/>
		<updated>2023-01-07T01:26:48Z</updated>

		<summary type="html">&lt;p&gt;MMayer: /* Open AP Nmap Scanner */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= Introduction =&lt;br /&gt;
&lt;br /&gt;
The [https://docs.hak5.org/signal-owl/ Signal Owl] is a hardware product developed by the company [https://shop.hak5.org/ Hak5].&lt;br /&gt;
It is a simple payload-based signals intelligence platform with a unique design for discreet planting or mobile operations on any engagement. The most popular application cases include classic network mapping and basic penetration tests for various wireless technologies.&lt;br /&gt;
&lt;br /&gt;
== Initial Setup ==&lt;br /&gt;
&lt;br /&gt;
When first unboxing the Signal Owl, the device runs a stager firmware that is designed to flash the latest firmware from a USB flash drive. In order to update the Signal Owl, the [https://downloads.hak5.org/owl latest firmware] has to be downloaded. Then, the downloaded file must be copied to the root of an EXT4 or FAT32 formatted USB flash drive. It is important not to modify this file. The next step is to plug the USB flash drive into the powered off Signal Owl. Afterwards, the device has to be powered on by a reliable USB source. The upgrade itself takes approximately five to ten minutes and is indicated by a solid red LED light. When finished, the device will reboot, enter Attack Mode and blink slowly, indicating an error running the payload because no payload has been found.&lt;br /&gt;
&lt;br /&gt;
= Hardware =&lt;br /&gt;
&lt;br /&gt;
[[File:SignalOwlDiagram.png|thumb|500px|frame|Components of the Signal Owl [Eigene Darstellung]]] &lt;br /&gt;
&lt;br /&gt;
The Signal Owl is designed to be rapidly deployed in all kinds of environments, allowing it to be an entry point for network analysis and basic wireless attacks in a variety of locations. With a power consumption of 100-200 mAh and the thermally optimized architecture, mobile operations as well as long term deployments, are enabled.&lt;br /&gt;
&lt;br /&gt;
== Components ==&lt;br /&gt;
&lt;br /&gt;
This device features several components of which some may not be visible to the human eye at first sight.&lt;br /&gt;
&lt;br /&gt;
=== USB Power / Passthrough Plug ===&lt;br /&gt;
&lt;br /&gt;
The USB power or passthrough plug is used to power the device. It can be powered from any reliable USB source.&lt;br /&gt;
&lt;br /&gt;
=== USB 2.0 Passthrough Port ===&lt;br /&gt;
&lt;br /&gt;
The USB 2.0 passthrough port is the port closest to the pigtail. Data and power pass through to that port, allowing for implant operations. If a device such as a keyboard is plugged in between this passthrough port and the power plug is connected to the target computer, the Signal Owl will remain undetected by the operating system. Only the keyboard will be visible on the target computer.&lt;br /&gt;
&lt;br /&gt;
=== USB 2.0 Host Port ===&lt;br /&gt;
&lt;br /&gt;
The USB 2.0 host port is the port farthest away from the pigtail. It is connected to the Linux socket of the Signal Owl and supports USB flash drives formatted with FAT32 and EXT4 file systems as well as many Wi-Fi, Bluetooth and other RF transceivers.&lt;br /&gt;
&lt;br /&gt;
=== Button ===&lt;br /&gt;
&lt;br /&gt;
The button on the bottom of the device is used to enter Arming Mode and to interact with payloads. It is not pressable without special tools like paperclips.&lt;br /&gt;
&lt;br /&gt;
=== Status LED ===&lt;br /&gt;
&lt;br /&gt;
The status LED indicates the current status of the Signal Owl. When it is turned off, it is not visible.&lt;br /&gt;
&lt;br /&gt;
The Signal Owl features a red LED with the following default status indications:&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
!|LED&lt;br /&gt;
!|Status&lt;br /&gt;
|-&lt;br /&gt;
|Blinking&lt;br /&gt;
|Booting&lt;br /&gt;
|-&lt;br /&gt;
|Solid&lt;br /&gt;
|Mounting external storage / Running upgrade&lt;br /&gt;
|-&lt;br /&gt;
|Single blinking&lt;br /&gt;
|Attack Mode&lt;br /&gt;
|-&lt;br /&gt;
|Double blinking&lt;br /&gt;
|Arming Mode&lt;br /&gt;
|-&lt;br /&gt;
|Slow blinking&lt;br /&gt;
|Error running payload&lt;br /&gt;
|-&lt;br /&gt;
|Fast blinking&lt;br /&gt;
|Select Mode (Deprecated from version 1.0.1 onward)&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= Software =&lt;br /&gt;
&lt;br /&gt;
== Modes of Operation ==&lt;br /&gt;
&lt;br /&gt;
The Signal Owl comes with two modes of operation, Attack Mode and Arming Mode. By default, the device will boot into Attack Mode. In order to access Arming Mode, the button on the bottom of the device has to be pressed while in Attack Mode. It is not recommended to press the button during the boot sequence, as this can possibly brick the device and render it useless. The arming mode is used for firmware updates and shell access, while the attack mode is used to load and execute the payload.&lt;br /&gt;
&lt;br /&gt;
=== Attack Mode ===&lt;br /&gt;
&lt;br /&gt;
Attack Mode is the default mode, the Signal Owl boots into. It provides two basic functions, being the payload loading function and the payload execution function. &lt;br /&gt;
&lt;br /&gt;
The payload loading function checks for any USB flash drives plugged into the host port of the device and copies payloads to &amp;lt;code&amp;gt;/root/payload&amp;lt;/code&amp;gt; and extensions to &amp;lt;code&amp;gt;/root/payload/extensions&amp;lt;/code&amp;gt; on the Signal Owl. &lt;br /&gt;
&lt;br /&gt;
The payload execution function is responsible for executing the payload that is currently stored on the root of the Signal Owl. In case no payload is found, the device will blink slowly, indicating the FAIL status.&lt;br /&gt;
&lt;br /&gt;
=== Arming Mode ===&lt;br /&gt;
&lt;br /&gt;
The Arming Mode provides two basic functions, being the firmware update function and the shell access function. The firmware update function checks for any USB flash drives plugged into the host port of the device and copies firmware upgrade files into the internal storage of the device and flashes it. The shell access function starts an open access point with the SSID Owl_xxxx in which xxxx indicates the last two octets of the device&#039;s MAC address. Additionally, a SSH server providing access to the shell of the Signal Owl is enabled.&lt;br /&gt;
&lt;br /&gt;
== Default Settings ==&lt;br /&gt;
&lt;br /&gt;
Default settings that are used in order to access the device via SSH are pictured in the table below.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
!colspan=&amp;quot;2&amp;quot;|Default Settings&lt;br /&gt;
|-&lt;br /&gt;
|Username&lt;br /&gt;
|root&lt;br /&gt;
|-&lt;br /&gt;
|Password&lt;br /&gt;
|hak5owl&lt;br /&gt;
|-&lt;br /&gt;
|SSID&lt;br /&gt;
|Owl_xxxx&lt;br /&gt;
|-&lt;br /&gt;
|IP Address&lt;br /&gt;
|172.16.56.1&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
SSH command: &amp;lt;code&amp;gt;ssh root@172.16.56.1&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The SSID during Arming Mode is Owl_xxxx in which xxxx indicates the last two octets of the devices MAC address.&lt;br /&gt;
&lt;br /&gt;
= Usage =&lt;br /&gt;
&lt;br /&gt;
== Arming Mode connection ==&lt;br /&gt;
&lt;br /&gt;
Step-by-step guide for accessing the arming mode&lt;br /&gt;
&lt;br /&gt;
#Click on the button located on the bottom of the Signal Owl while it is in attack mode. After pressing the button, the signal owl enters the arming mode and provides an open access point with the name Owl xxxx (where xxxx stands for the last two digits of the MAC address of the device).&lt;br /&gt;
#Connect to the access point.&amp;lt;br&amp;gt;[[File:Armingmode.png]][Eigene Darstellung]&lt;br /&gt;
#Now you can connect via ssh by using the [[#Default Settings|default settings]].&lt;br /&gt;
#After successful connection, you will end up in the root directory.&amp;lt;br&amp;gt;[[File:ArmingmodeSSH.png]][Eigene Darstellung]&lt;br /&gt;
#Now you can change the files and directories on the Signal Owl to view results, transfer payloads and extensions or to make further changes.&lt;br /&gt;
&lt;br /&gt;
== Directory structure ==&lt;br /&gt;
&lt;br /&gt;
The following directory tree shows the directory structure of the Signal Owl.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
/&lt;br /&gt;
├── loot&lt;br /&gt;
└── payload/&lt;br /&gt;
    └── extensions&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
*Loot - Directory where the Signal Owl saves loot while executing payloads that produce loot.&lt;br /&gt;
*Payload - This directory holds the current payload. &lt;br /&gt;
*Extensions -  This directory holds all extensions.&lt;br /&gt;
&lt;br /&gt;
== Adding Payloads and Extensions ==&lt;br /&gt;
&lt;br /&gt;
Adding a payload can be done in two different ways. Either with a USB flash drive or via the Signal Owl access point to the internal storage of the device. &lt;br /&gt;
&lt;br /&gt;
When booting, payloads on USB flash drives are given priority and will override payloads stored on the Signal Owl. To successfully copy a payload to the Signal Owl, the payload must be named &amp;lt;code&amp;gt;payload.txt&amp;lt;/code&amp;gt; or &amp;lt;code&amp;gt;payload.sh&amp;lt;/code&amp;gt; and it has to be placed in the &amp;lt;code&amp;gt;root&amp;lt;/code&amp;gt; directory of the flash drive. Similarly, payload extensions should be stored in a &amp;lt;code&amp;gt;/extensions&amp;lt;/code&amp;gt; directory on the flash drive. &lt;br /&gt;
&lt;br /&gt;
In addition, it is possible to transfer payloads and payload extensions to the device via the Signal Owl access point in arming mode using SSH. There they are stored in the &amp;lt;code&amp;gt;/root/payload&amp;lt;/code&amp;gt; directory and Payload Extensions are stored in the &amp;lt;code&amp;gt;/root/payload/extensions&amp;lt;/code&amp;gt; directory.&lt;br /&gt;
&lt;br /&gt;
== Payload Development ==&lt;br /&gt;
&lt;br /&gt;
Payloads for the Signal Owl are written in bash with [https://github.com/hak5darren/USB-Rubber-Ducky/wiki/Duckyscript Ducky Script] and can be created with any standard text editor. All payloads should begin with an interpreter directive, like the shebang &amp;lt;code&amp;gt;#!/bin/bash&amp;lt;/code&amp;gt; for bash payloads and payloads must be named either &amp;lt;code&amp;gt;payload.txt&amp;lt;/code&amp;gt; or &amp;lt;code&amp;gt;payload.sh&amp;lt;/code&amp;gt;. In order to create effective payloads, the Signal Owl comes with several preinstalled penetration testing tools. These are as follows: [https://nmap.org/ Nmap], [https://www.aircrack-ng.org/ Aircrack-ng], [https://github.com/aircrack-ng/mdk4 MDK4] and [https://www.kismetwireless.net/ Kismet].&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Tools&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
• Kismet - detector for wireless networks and devices.&lt;br /&gt;
&lt;br /&gt;
• MDK4 - Wi-Fi testing tool.&lt;br /&gt;
&lt;br /&gt;
• Aircrack-ng Suite - a complete suite of tools for WiFi network security assessment.&lt;br /&gt;
&lt;br /&gt;
• Nmap - open source utility for network discovery and security auditing.&lt;br /&gt;
&lt;br /&gt;
Hak5 offers ready-to-use payloads and payload extensions on their [https://github.com/hak5/signalowl-payloads GitHub repository].&lt;br /&gt;
&lt;br /&gt;
== Implant / mobile operations ==&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Implant operations&lt;br /&gt;
&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
During long term wireless engagements, the Signal Owl may be planted inline between any typical 5V USB power source. This may be useful in situations where ports are occupied, or to deter the unit from being unplugged.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Mobile operations&lt;br /&gt;
&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
The Signal Owl features a low power consumption profile, with a typical power draw averaging 100-200 mAh. Additionally, it is thermally optimized for long term deployments in many indoor environments. One can expect a large 20,000 mAh USB battery bank to operate the unit for up to 4 days.&lt;br /&gt;
&lt;br /&gt;
= Use Cases =&lt;br /&gt;
&lt;br /&gt;
The Signal Owl has a variety of different use cases. Among the most popular ones are classical network mapping and wardriving as well as basic penetration tests for different wireless technologies.&lt;br /&gt;
&lt;br /&gt;
== Fake Beacon Flooding Attack ==&lt;br /&gt;
&lt;br /&gt;
The Fake Beacon Flooding Attack is one possible use case for the Signal Owl. With that attack, fake beacon frames are broadcasted to nearby devices. Beacon Frames include various parameters like the SSID, the type of encryption used and timestamps. This results in the creation of multiple fake Wi-Fi networks. Devices with Wi-Fi browsers are then flooded with these fake networks, causing potential network scanner and driver crashes. Furthermore, the attack may prevent legitimate users from finding their networks and lead to denial of service. The preinstalled tools Aircrack-ng and MDK4 were used to create this payload. After powering on the device, multiple fake networks with random SSIDs are generated and broadcasted to all nearby devices.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;bash&amp;quot;&amp;gt;&lt;br /&gt;
#!/bin/bash&lt;br /&gt;
&lt;br /&gt;
LED SETUP&lt;br /&gt;
sleep 10&lt;br /&gt;
airmon-ng check kill&lt;br /&gt;
sleep 10&lt;br /&gt;
#creates monitor mode interface on wirelss card of the Signal Owl&lt;br /&gt;
airmon-ng start wlan0&lt;br /&gt;
sleep 10&lt;br /&gt;
LED ATTACK&lt;br /&gt;
#floods nearby devices with random SSIDs&lt;br /&gt;
mdk4 wlan0mon b -a -m -s 500&lt;br /&gt;
&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The results as seen from a victim running a Windows 10 system are pictured in the figure below.&lt;br /&gt;
&lt;br /&gt;
[[File:FakeBeaconFloodingSignalOwl.png|none|Random SSIDs as seen from a victim Windows 10 client |]][Eigene Darstellung]&lt;br /&gt;
&lt;br /&gt;
== Open AP Nmap Scanner ==&lt;br /&gt;
&lt;br /&gt;
With the Open AP Nmap Scanner payload, the Signal Owl scans for open access points. If the Signal Owl finds one or more open access points, it connects to them and uses Nmap to scan and analyze them. The results are then stored in the loot directory. For each discovered open access point, the Signal Owl generates a separate results file. This payload has some settings which can be seen in the following listing.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;bash&amp;quot;&amp;gt;&lt;br /&gt;
NMAP_OPTIONS=&amp;quot;-sP&amp;quot;&lt;br /&gt;
LOOT_DIR=/root/loot/open_ap_nmap_scan&lt;br /&gt;
MAX_CIDR=20&lt;br /&gt;
DEBUG=1&lt;br /&gt;
&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Basic Bluetooth Scanner ==&lt;br /&gt;
&lt;br /&gt;
This payload requires an external Bluetooth adapter, since the Signal Owl does not have Bluetooth built in. The Basic Bluetooth Scanner scans for devices that have enabled Bluetooth and queries them, optionally using the hcitool and the command info. This payload does also have some settings, as shown in the listing below.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;bash&amp;quot;&amp;gt;&lt;br /&gt;
LOOT_DIR=/root/loot/bluetooth_scan&lt;br /&gt;
BT_OUTFILE=`date +%s`.bt.list&lt;br /&gt;
BT_INFOFILE=`date +%s`.bt.info   &lt;br /&gt;
BTDEV=hci0&lt;br /&gt;
DEBUG=0 &lt;br /&gt;
INTERROGATE=1 &lt;br /&gt;
&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
= Used Hardware =&lt;br /&gt;
&lt;br /&gt;
[[Signal Owl]]&lt;br /&gt;
&lt;br /&gt;
= References =&lt;br /&gt;
&lt;br /&gt;
*https://docs.hak5.org/signal-owl/&lt;br /&gt;
*https://github.com/hak5/signalowl-payloads&lt;br /&gt;
&lt;br /&gt;
[[Category:Pentesting]]&lt;/div&gt;</summary>
		<author><name>MMayer</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=Hak5_Signal_Owl&amp;diff=10720</id>
		<title>Hak5 Signal Owl</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=Hak5_Signal_Owl&amp;diff=10720"/>
		<updated>2023-01-07T01:25:09Z</updated>

		<summary type="html">&lt;p&gt;MMayer: /* Fake Beacon Flooding Attack */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= Introduction =&lt;br /&gt;
&lt;br /&gt;
The [https://docs.hak5.org/signal-owl/ Signal Owl] is a hardware product developed by the company [https://shop.hak5.org/ Hak5].&lt;br /&gt;
It is a simple payload-based signals intelligence platform with a unique design for discreet planting or mobile operations on any engagement. The most popular application cases include classic network mapping and basic penetration tests for various wireless technologies.&lt;br /&gt;
&lt;br /&gt;
== Initial Setup ==&lt;br /&gt;
&lt;br /&gt;
When first unboxing the Signal Owl, the device runs a stager firmware that is designed to flash the latest firmware from a USB flash drive. In order to update the Signal Owl, the [https://downloads.hak5.org/owl latest firmware] has to be downloaded. Then, the downloaded file must be copied to the root of an EXT4 or FAT32 formatted USB flash drive. It is important not to modify this file. The next step is to plug the USB flash drive into the powered off Signal Owl. Afterwards, the device has to be powered on by a reliable USB source. The upgrade itself takes approximately five to ten minutes and is indicated by a solid red LED light. When finished, the device will reboot, enter Attack Mode and blink slowly, indicating an error running the payload because no payload has been found.&lt;br /&gt;
&lt;br /&gt;
= Hardware =&lt;br /&gt;
&lt;br /&gt;
[[File:SignalOwlDiagram.png|thumb|500px|frame|Components of the Signal Owl [Eigene Darstellung]]] &lt;br /&gt;
&lt;br /&gt;
The Signal Owl is designed to be rapidly deployed in all kinds of environments, allowing it to be an entry point for network analysis and basic wireless attacks in a variety of locations. With a power consumption of 100-200 mAh and the thermally optimized architecture, mobile operations as well as long term deployments, are enabled.&lt;br /&gt;
&lt;br /&gt;
== Components ==&lt;br /&gt;
&lt;br /&gt;
This device features several components of which some may not be visible to the human eye at first sight.&lt;br /&gt;
&lt;br /&gt;
=== USB Power / Passthrough Plug ===&lt;br /&gt;
&lt;br /&gt;
The USB power or passthrough plug is used to power the device. It can be powered from any reliable USB source.&lt;br /&gt;
&lt;br /&gt;
=== USB 2.0 Passthrough Port ===&lt;br /&gt;
&lt;br /&gt;
The USB 2.0 passthrough port is the port closest to the pigtail. Data and power pass through to that port, allowing for implant operations. If a device such as a keyboard is plugged in between this passthrough port and the power plug is connected to the target computer, the Signal Owl will remain undetected by the operating system. Only the keyboard will be visible on the target computer.&lt;br /&gt;
&lt;br /&gt;
=== USB 2.0 Host Port ===&lt;br /&gt;
&lt;br /&gt;
The USB 2.0 host port is the port farthest away from the pigtail. It is connected to the Linux socket of the Signal Owl and supports USB flash drives formatted with FAT32 and EXT4 file systems as well as many Wi-Fi, Bluetooth and other RF transceivers.&lt;br /&gt;
&lt;br /&gt;
=== Button ===&lt;br /&gt;
&lt;br /&gt;
The button on the bottom of the device is used to enter Arming Mode and to interact with payloads. It is not pressable without special tools like paperclips.&lt;br /&gt;
&lt;br /&gt;
=== Status LED ===&lt;br /&gt;
&lt;br /&gt;
The status LED indicates the current status of the Signal Owl. When it is turned off, it is not visible.&lt;br /&gt;
&lt;br /&gt;
The Signal Owl features a red LED with the following default status indications:&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
!|LED&lt;br /&gt;
!|Status&lt;br /&gt;
|-&lt;br /&gt;
|Blinking&lt;br /&gt;
|Booting&lt;br /&gt;
|-&lt;br /&gt;
|Solid&lt;br /&gt;
|Mounting external storage / Running upgrade&lt;br /&gt;
|-&lt;br /&gt;
|Single blinking&lt;br /&gt;
|Attack Mode&lt;br /&gt;
|-&lt;br /&gt;
|Double blinking&lt;br /&gt;
|Arming Mode&lt;br /&gt;
|-&lt;br /&gt;
|Slow blinking&lt;br /&gt;
|Error running payload&lt;br /&gt;
|-&lt;br /&gt;
|Fast blinking&lt;br /&gt;
|Select Mode (Deprecated from version 1.0.1 onward)&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= Software =&lt;br /&gt;
&lt;br /&gt;
== Modes of Operation ==&lt;br /&gt;
&lt;br /&gt;
The Signal Owl comes with two modes of operation, Attack Mode and Arming Mode. By default, the device will boot into Attack Mode. In order to access Arming Mode, the button on the bottom of the device has to be pressed while in Attack Mode. It is not recommended to press the button during the boot sequence, as this can possibly brick the device and render it useless. The arming mode is used for firmware updates and shell access, while the attack mode is used to load and execute the payload.&lt;br /&gt;
&lt;br /&gt;
=== Attack Mode ===&lt;br /&gt;
&lt;br /&gt;
Attack Mode is the default mode, the Signal Owl boots into. It provides two basic functions, being the payload loading function and the payload execution function. &lt;br /&gt;
&lt;br /&gt;
The payload loading function checks for any USB flash drives plugged into the host port of the device and copies payloads to &amp;lt;code&amp;gt;/root/payload&amp;lt;/code&amp;gt; and extensions to &amp;lt;code&amp;gt;/root/payload/extensions&amp;lt;/code&amp;gt; on the Signal Owl. &lt;br /&gt;
&lt;br /&gt;
The payload execution function is responsible for executing the payload that is currently stored on the root of the Signal Owl. In case no payload is found, the device will blink slowly, indicating the FAIL status.&lt;br /&gt;
&lt;br /&gt;
=== Arming Mode ===&lt;br /&gt;
&lt;br /&gt;
The Arming Mode provides two basic functions, being the firmware update function and the shell access function. The firmware update function checks for any USB flash drives plugged into the host port of the device and copies firmware upgrade files into the internal storage of the device and flashes it. The shell access function starts an open access point with the SSID Owl_xxxx in which xxxx indicates the last two octets of the device&#039;s MAC address. Additionally, a SSH server providing access to the shell of the Signal Owl is enabled.&lt;br /&gt;
&lt;br /&gt;
== Default Settings ==&lt;br /&gt;
&lt;br /&gt;
Default settings that are used in order to access the device via SSH are pictured in the table below.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
!colspan=&amp;quot;2&amp;quot;|Default Settings&lt;br /&gt;
|-&lt;br /&gt;
|Username&lt;br /&gt;
|root&lt;br /&gt;
|-&lt;br /&gt;
|Password&lt;br /&gt;
|hak5owl&lt;br /&gt;
|-&lt;br /&gt;
|SSID&lt;br /&gt;
|Owl_xxxx&lt;br /&gt;
|-&lt;br /&gt;
|IP Address&lt;br /&gt;
|172.16.56.1&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
SSH command: &amp;lt;code&amp;gt;ssh root@172.16.56.1&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The SSID during Arming Mode is Owl_xxxx in which xxxx indicates the last two octets of the devices MAC address.&lt;br /&gt;
&lt;br /&gt;
= Usage =&lt;br /&gt;
&lt;br /&gt;
== Arming Mode connection ==&lt;br /&gt;
&lt;br /&gt;
Step-by-step guide for accessing the arming mode&lt;br /&gt;
&lt;br /&gt;
#Click on the button located on the bottom of the Signal Owl while it is in attack mode. After pressing the button, the signal owl enters the arming mode and provides an open access point with the name Owl xxxx (where xxxx stands for the last two digits of the MAC address of the device).&lt;br /&gt;
#Connect to the access point.&amp;lt;br&amp;gt;[[File:Armingmode.png]][Eigene Darstellung]&lt;br /&gt;
#Now you can connect via ssh by using the [[#Default Settings|default settings]].&lt;br /&gt;
#After successful connection, you will end up in the root directory.&amp;lt;br&amp;gt;[[File:ArmingmodeSSH.png]][Eigene Darstellung]&lt;br /&gt;
#Now you can change the files and directories on the Signal Owl to view results, transfer payloads and extensions or to make further changes.&lt;br /&gt;
&lt;br /&gt;
== Directory structure ==&lt;br /&gt;
&lt;br /&gt;
The following directory tree shows the directory structure of the Signal Owl.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
/&lt;br /&gt;
├── loot&lt;br /&gt;
└── payload/&lt;br /&gt;
    └── extensions&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
*Loot - Directory where the Signal Owl saves loot while executing payloads that produce loot.&lt;br /&gt;
*Payload - This directory holds the current payload. &lt;br /&gt;
*Extensions -  This directory holds all extensions.&lt;br /&gt;
&lt;br /&gt;
== Adding Payloads and Extensions ==&lt;br /&gt;
&lt;br /&gt;
Adding a payload can be done in two different ways. Either with a USB flash drive or via the Signal Owl access point to the internal storage of the device. &lt;br /&gt;
&lt;br /&gt;
When booting, payloads on USB flash drives are given priority and will override payloads stored on the Signal Owl. To successfully copy a payload to the Signal Owl, the payload must be named &amp;lt;code&amp;gt;payload.txt&amp;lt;/code&amp;gt; or &amp;lt;code&amp;gt;payload.sh&amp;lt;/code&amp;gt; and it has to be placed in the &amp;lt;code&amp;gt;root&amp;lt;/code&amp;gt; directory of the flash drive. Similarly, payload extensions should be stored in a &amp;lt;code&amp;gt;/extensions&amp;lt;/code&amp;gt; directory on the flash drive. &lt;br /&gt;
&lt;br /&gt;
In addition, it is possible to transfer payloads and payload extensions to the device via the Signal Owl access point in arming mode using SSH. There they are stored in the &amp;lt;code&amp;gt;/root/payload&amp;lt;/code&amp;gt; directory and Payload Extensions are stored in the &amp;lt;code&amp;gt;/root/payload/extensions&amp;lt;/code&amp;gt; directory.&lt;br /&gt;
&lt;br /&gt;
== Payload Development ==&lt;br /&gt;
&lt;br /&gt;
Payloads for the Signal Owl are written in bash with [https://github.com/hak5darren/USB-Rubber-Ducky/wiki/Duckyscript Ducky Script] and can be created with any standard text editor. All payloads should begin with an interpreter directive, like the shebang &amp;lt;code&amp;gt;#!/bin/bash&amp;lt;/code&amp;gt; for bash payloads and payloads must be named either &amp;lt;code&amp;gt;payload.txt&amp;lt;/code&amp;gt; or &amp;lt;code&amp;gt;payload.sh&amp;lt;/code&amp;gt;. In order to create effective payloads, the Signal Owl comes with several preinstalled penetration testing tools. These are as follows: [https://nmap.org/ Nmap], [https://www.aircrack-ng.org/ Aircrack-ng], [https://github.com/aircrack-ng/mdk4 MDK4] and [https://www.kismetwireless.net/ Kismet].&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Tools&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
• Kismet - detector for wireless networks and devices.&lt;br /&gt;
&lt;br /&gt;
• MDK4 - Wi-Fi testing tool.&lt;br /&gt;
&lt;br /&gt;
• Aircrack-ng Suite - a complete suite of tools for WiFi network security assessment.&lt;br /&gt;
&lt;br /&gt;
• Nmap - open source utility for network discovery and security auditing.&lt;br /&gt;
&lt;br /&gt;
Hak5 offers ready-to-use payloads and payload extensions on their [https://github.com/hak5/signalowl-payloads GitHub repository].&lt;br /&gt;
&lt;br /&gt;
== Implant / mobile operations ==&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Implant operations&lt;br /&gt;
&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
During long term wireless engagements, the Signal Owl may be planted inline between any typical 5V USB power source. This may be useful in situations where ports are occupied, or to deter the unit from being unplugged.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Mobile operations&lt;br /&gt;
&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
The Signal Owl features a low power consumption profile, with a typical power draw averaging 100-200 mAh. Additionally, it is thermally optimized for long term deployments in many indoor environments. One can expect a large 20,000 mAh USB battery bank to operate the unit for up to 4 days.&lt;br /&gt;
&lt;br /&gt;
= Use Cases =&lt;br /&gt;
&lt;br /&gt;
The Signal Owl has a variety of different use cases. Among the most popular ones are classical network mapping and wardriving as well as basic penetration tests for different wireless technologies.&lt;br /&gt;
&lt;br /&gt;
== Fake Beacon Flooding Attack ==&lt;br /&gt;
&lt;br /&gt;
The Fake Beacon Flooding Attack is one possible use case for the Signal Owl. With that attack, fake beacon frames are broadcasted to nearby devices. Beacon Frames include various parameters like the SSID, the type of encryption used and timestamps. This results in the creation of multiple fake Wi-Fi networks. Devices with Wi-Fi browsers are then flooded with these fake networks, causing potential network scanner and driver crashes. Furthermore, the attack may prevent legitimate users from finding their networks and lead to denial of service. The preinstalled tools Aircrack-ng and MDK4 were used to create this payload. After powering on the device, multiple fake networks with random SSIDs are generated and broadcasted to all nearby devices.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;bash&amp;quot;&amp;gt;&lt;br /&gt;
#!/bin/bash&lt;br /&gt;
&lt;br /&gt;
LED SETUP&lt;br /&gt;
sleep 10&lt;br /&gt;
airmon-ng check kill&lt;br /&gt;
sleep 10&lt;br /&gt;
#creates monitor mode interface on wirelss card of the Signal Owl&lt;br /&gt;
airmon-ng start wlan0&lt;br /&gt;
sleep 10&lt;br /&gt;
LED ATTACK&lt;br /&gt;
#floods nearby devices with random SSIDs&lt;br /&gt;
mdk4 wlan0mon b -a -m -s 500&lt;br /&gt;
&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The results as seen from a victim running a Windows 10 system are pictured in the figure below.&lt;br /&gt;
&lt;br /&gt;
[[File:FakeBeaconFloodingSignalOwl.png|none|Random SSIDs as seen from a victim Windows 10 client |]][Eigene Darstellung]&lt;br /&gt;
&lt;br /&gt;
== Open AP Nmap Scanner ==&lt;br /&gt;
&lt;br /&gt;
With the Open AP Nmap Scanner payload, the Signal Owl scans for open access points. If the Signal Owl finds one or more open access points, it connects to them and uses Nmap to scan and analyze them. The results are then stored in the loot directory. For each discovered open access point, the Signal Owl generates a separate results file. This payload has some settings which can be seen in the following listing.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;bash&amp;quot;&amp;gt;&lt;br /&gt;
NMAP_OPTIONS=&amp;quot;-sP&amp;quot;&lt;br /&gt;
LOOT_DIR=/root/loot/open_ap_nmap_scan&lt;br /&gt;
MAX_CIDR=20&lt;br /&gt;
DEBUG=1&lt;br /&gt;
&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Step-by-step guide&lt;br /&gt;
&lt;br /&gt;
    1) download the payload [https://github.com/hak5/signalowl-payloads/blob/master/payloads/library/wifi/Open-AP-Nmap-Scanner/payload.txt payload]&lt;br /&gt;
    2) store the payload in a usb stick and plug the stick into the signal owl&lt;br /&gt;
    3) after connecting the signal owl, the payload is loaded on the root folder and the scan starts. &lt;br /&gt;
    4) once successfully executed, you can start the signal owl in arming mode and see the results in the loot folder.&lt;br /&gt;
      example loot Directory&lt;br /&gt;
      [[File:ArmingmodeSSHloot.png]][Eigene Darstellung]&lt;br /&gt;
&lt;br /&gt;
== Basic Bluetooth Scanner ==&lt;br /&gt;
&lt;br /&gt;
This payload requires an external Bluetooth adapter, since the Signal Owl does not have Bluetooth built in. The Basic Bluetooth Scanner scans for devices that have enabled Bluetooth and queries them, optionally using the hcitool and the command info. This payload does also have some settings, as shown in the listing below.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;bash&amp;quot;&amp;gt;&lt;br /&gt;
LOOT_DIR=/root/loot/bluetooth_scan&lt;br /&gt;
BT_OUTFILE=`date +%s`.bt.list&lt;br /&gt;
BT_INFOFILE=`date +%s`.bt.info   &lt;br /&gt;
BTDEV=hci0&lt;br /&gt;
DEBUG=0 &lt;br /&gt;
INTERROGATE=1 &lt;br /&gt;
&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
= Used Hardware =&lt;br /&gt;
&lt;br /&gt;
[[Signal Owl]]&lt;br /&gt;
&lt;br /&gt;
= References =&lt;br /&gt;
&lt;br /&gt;
*https://docs.hak5.org/signal-owl/&lt;br /&gt;
*https://github.com/hak5/signalowl-payloads&lt;br /&gt;
&lt;br /&gt;
[[Category:Pentesting]]&lt;/div&gt;</summary>
		<author><name>MMayer</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=Hak5_Signal_Owl&amp;diff=10714</id>
		<title>Hak5 Signal Owl</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=Hak5_Signal_Owl&amp;diff=10714"/>
		<updated>2023-01-06T22:04:54Z</updated>

		<summary type="html">&lt;p&gt;MMayer: /* Arming Mode connection */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= Introduction =&lt;br /&gt;
&lt;br /&gt;
The [https://docs.hak5.org/signal-owl/ Signal Owl] is a hardware product developed by the company [https://shop.hak5.org/ Hak5].&lt;br /&gt;
It is a simple payload-based signals intelligence platform with a unique design for discreet planting or mobile operations on any engagement. The most popular application cases include classic network mapping and basic penetration tests for various wireless technologies.&lt;br /&gt;
&lt;br /&gt;
== Initial Setup ==&lt;br /&gt;
&lt;br /&gt;
When first unboxing the Signal Owl, the device runs a stager firmware that is designed to flash the latest firmware from a USB flash drive. In order to update the Signal Owl, the [https://downloads.hak5.org/owl latest firmware] has to be downloaded. Then, the downloaded file must be copied to the root of an EXT4 or FAT32 formatted USB flash drive. It is important not to modify this file. The next step is to plug the USB flash drive into the powered off Signal Owl. Afterwards, the device has to be powered on by a reliable USB source. The upgrade itself takes approximately five to ten minutes and is indicated by a solid red LED light. When finished, the device will reboot, enter Attack Mode and blink slowly, indicating an error running the payload because no payload has been found.&lt;br /&gt;
&lt;br /&gt;
= Hardware =&lt;br /&gt;
&lt;br /&gt;
[[File:SignalOwlDiagram.png|thumb|500px|frame|Components of the Signal Owl [Eigene Darstellung]]] &lt;br /&gt;
&lt;br /&gt;
The Signal Owl is designed to be rapidly deployed in all kinds of environments, allowing it to be an entry point for network analysis and basic wireless attacks in a variety of locations. With a power consumption of 100-200 mAh and the thermally optimized architecture, mobile operations as well as long term deployments, are enabled.&lt;br /&gt;
&lt;br /&gt;
== Components ==&lt;br /&gt;
&lt;br /&gt;
This device features several components of which some may not be visible to the human eye at first sight.&lt;br /&gt;
&lt;br /&gt;
=== USB Power / Passthrough Plug ===&lt;br /&gt;
&lt;br /&gt;
The USB power or passthrough plug is used to power the device. It can be powered from any reliable USB source.&lt;br /&gt;
&lt;br /&gt;
=== USB 2.0 Passthrough Port ===&lt;br /&gt;
&lt;br /&gt;
The USB 2.0 passthrough port is the port closest to the pigtail. Data and power pass through to that port, allowing for implant operations. If a device such as a keyboard is plugged in between this passthrough port and the power plug is connected to the target computer, the Signal Owl will remain undetected by the operating system. Only the keyboard will be visible on the target computer.&lt;br /&gt;
&lt;br /&gt;
=== USB 2.0 Host Port ===&lt;br /&gt;
&lt;br /&gt;
The USB 2.0 host port is the port farthest away from the pigtail. It is connected to the Linux socket of the Signal Owl and supports USB flash drives formatted with FAT32 and EXT4 file systems as well as many Wi-Fi, Bluetooth and other RF transceivers.&lt;br /&gt;
&lt;br /&gt;
=== Button ===&lt;br /&gt;
&lt;br /&gt;
The button on the bottom of the device is used to enter Arming Mode and to interact with payloads. It is not pressable without special tools like paperclips.&lt;br /&gt;
&lt;br /&gt;
=== Status LED ===&lt;br /&gt;
&lt;br /&gt;
The status LED indicates the current status of the Signal Owl. When it is turned off, it is not visible.&lt;br /&gt;
&lt;br /&gt;
The Signal Owl features a red LED with the following default status indications:&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
!|LED&lt;br /&gt;
!|Status&lt;br /&gt;
|-&lt;br /&gt;
|Blinking&lt;br /&gt;
|Booting&lt;br /&gt;
|-&lt;br /&gt;
|Solid&lt;br /&gt;
|Mounting external storage / Running upgrade&lt;br /&gt;
|-&lt;br /&gt;
|Single blinking&lt;br /&gt;
|Attack Mode&lt;br /&gt;
|-&lt;br /&gt;
|Double blinking&lt;br /&gt;
|Arming Mode&lt;br /&gt;
|-&lt;br /&gt;
|Slow blinking&lt;br /&gt;
|Error running payload&lt;br /&gt;
|-&lt;br /&gt;
|Fast blinking&lt;br /&gt;
|Select Mode (Deprecated from version 1.0.1 onward)&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= Software =&lt;br /&gt;
&lt;br /&gt;
== Modes of Operation ==&lt;br /&gt;
&lt;br /&gt;
The Signal Owl comes with two modes of operation, Attack Mode and Arming Mode. By default, the device will boot into Attack Mode. In order to access Arming Mode, the button on the bottom of the device has to be pressed while in Attack Mode. It is not recommended to press the button during the boot sequence, as this can possibly brick the device and render it useless. The arming mode is used for firmware updates and shell access, while the attack mode is used to load and execute the payload.&lt;br /&gt;
&lt;br /&gt;
=== Attack Mode ===&lt;br /&gt;
&lt;br /&gt;
Attack Mode is the default mode, the Signal Owl boots into. It provides two basic functions, being the payload loading function and the payload execution function. &lt;br /&gt;
&lt;br /&gt;
The payload loading function checks for any USB flash drives plugged into the host port of the device and copies payloads to &amp;lt;code&amp;gt;/root/payload&amp;lt;/code&amp;gt; and extensions to &amp;lt;code&amp;gt;/root/payload/extensions&amp;lt;/code&amp;gt; on the Signal Owl. &lt;br /&gt;
&lt;br /&gt;
The payload execution function is responsible for executing the payload that is currently stored on the root of the Signal Owl. In case no payload is found, the device will blink slowly, indicating the FAIL status.&lt;br /&gt;
&lt;br /&gt;
=== Arming Mode ===&lt;br /&gt;
&lt;br /&gt;
The Arming Mode provides two basic functions, being the firmware update function and the shell access function. The firmware update function checks for any USB flash drives plugged into the host port of the device and copies firmware upgrade files into the internal storage of the device and flashes it. The shell access function starts an open access point with the SSID Owl_xxxx in which xxxx indicates the last two octets of the device&#039;s MAC address. Additionally, a SSH server providing access to the shell of the Signal Owl is enabled.&lt;br /&gt;
&lt;br /&gt;
== Default Settings ==&lt;br /&gt;
&lt;br /&gt;
Default settings that are used in order to access the device via SSH are pictured in the table below.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
!colspan=&amp;quot;2&amp;quot;|Default Settings&lt;br /&gt;
|-&lt;br /&gt;
|Username&lt;br /&gt;
|root&lt;br /&gt;
|-&lt;br /&gt;
|Password&lt;br /&gt;
|hak5owl&lt;br /&gt;
|-&lt;br /&gt;
|SSID&lt;br /&gt;
|Owl_xxxx&lt;br /&gt;
|-&lt;br /&gt;
|IP Address&lt;br /&gt;
|172.16.56.1&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
SSH command: &amp;lt;code&amp;gt;ssh root@172.16.56.1&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The SSID during Arming Mode is Owl_xxxx in which xxxx indicates the last two octets of the devices MAC address.&lt;br /&gt;
&lt;br /&gt;
= Usage =&lt;br /&gt;
&lt;br /&gt;
== Arming Mode connection ==&lt;br /&gt;
&lt;br /&gt;
Step-by-step guide for accessing the arming mode&lt;br /&gt;
&lt;br /&gt;
#Click on the button located on the bottom of the Signal Owl while it is in attack mode. After pressing the button, the signal owl enters the arming mode and provides an open access point with the name Owl xxxx (where xxxx stands for the last two digits of the MAC address of the device).&lt;br /&gt;
#Connect to the access point.&amp;lt;br&amp;gt;[[File:Armingmode.png]][Eigene Darstellung]&lt;br /&gt;
#Now you can connect via ssh by using the [[#Default Settings|default settings]].&lt;br /&gt;
#After successful connection, you will end up in the root directory.&amp;lt;br&amp;gt;[[File:ArmingmodeSSH.png]][Eigene Darstellung]&lt;br /&gt;
#Now you can change the files and directories on the Signal Owl to view results, transfer payloads and extensions or to make further changes.&lt;br /&gt;
&lt;br /&gt;
== Directory structure ==&lt;br /&gt;
&lt;br /&gt;
The following directory tree shows the directory structure of the Signal Owl.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
/&lt;br /&gt;
├── loot&lt;br /&gt;
└── payload/&lt;br /&gt;
    └── extensions&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
*Loot - Directory where the Signal Owl saves loot while executing payloads that produce loot.&lt;br /&gt;
*Payload - This directory holds the current payload. &lt;br /&gt;
*Extensions -  This directory holds all extensions.&lt;br /&gt;
&lt;br /&gt;
== Adding Payloads and Extensions ==&lt;br /&gt;
&lt;br /&gt;
Adding a payload can be done in two different ways. Either with a USB flash drive or via the Signal Owl access point to the internal storage of the device. &lt;br /&gt;
&lt;br /&gt;
When booting, payloads on USB flash drives are given priority and will override payloads stored on the Signal Owl. To successfully copy a payload to the Signal Owl, the payload must be named &amp;lt;code&amp;gt;payload.txt&amp;lt;/code&amp;gt; or &amp;lt;code&amp;gt;payload.sh&amp;lt;/code&amp;gt; and it has to be placed in the &amp;lt;code&amp;gt;root&amp;lt;/code&amp;gt; directory of the flash drive. Similarly, payload extensions should be stored in a &amp;lt;code&amp;gt;/extensions&amp;lt;/code&amp;gt; directory on the flash drive. &lt;br /&gt;
&lt;br /&gt;
In addition, it is possible to transfer payloads and payload extensions to the device via the Signal Owl access point in arming mode using SSH. There they are stored in the &amp;lt;code&amp;gt;/root/payload&amp;lt;/code&amp;gt; directory and Payload Extensions are stored in the &amp;lt;code&amp;gt;/root/payload/extensions&amp;lt;/code&amp;gt; directory.&lt;br /&gt;
&lt;br /&gt;
== Payload Development ==&lt;br /&gt;
&lt;br /&gt;
Payloads for the Signal Owl are written in bash with [https://github.com/hak5darren/USB-Rubber-Ducky/wiki/Duckyscript Ducky Script] and can be created with any standard text editor. All payloads should begin with an interpreter directive, like the shebang &amp;lt;code&amp;gt;#!/bin/bash&amp;lt;/code&amp;gt; for bash payloads and payloads must be named either &amp;lt;code&amp;gt;payload.txt&amp;lt;/code&amp;gt; or &amp;lt;code&amp;gt;payload.sh&amp;lt;/code&amp;gt;. In order to create effective payloads, the Signal Owl comes with several preinstalled penetration testing tools. These are as follows: [https://nmap.org/ Nmap], [https://www.aircrack-ng.org/ Aircrack-ng], [https://github.com/aircrack-ng/mdk4 MDK4] and [https://www.kismetwireless.net/ Kismet].&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Tools&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
• Kismet - detector for wireless networks and devices.&lt;br /&gt;
&lt;br /&gt;
• MDK4 - Wi-Fi testing tool.&lt;br /&gt;
&lt;br /&gt;
• Aircrack-ng Suite - a complete suite of tools for WiFi network security assessment.&lt;br /&gt;
&lt;br /&gt;
• Nmap - open source utility for network discovery and security auditing.&lt;br /&gt;
&lt;br /&gt;
Hak5 offers ready-to-use payloads and payload extensions on their [https://github.com/hak5/signalowl-payloads GitHub repository].&lt;br /&gt;
&lt;br /&gt;
== Implant / mobile operations ==&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Implant operations&lt;br /&gt;
&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
During long term wireless engagements, the Signal Owl may be planted inline between any typical 5V USB power source. This may be useful in situations where ports are occupied, or to deter the unit from being unplugged.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Mobile operations&lt;br /&gt;
&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
The Signal Owl features a low power consumption profile, with a typical power draw averaging 100-200 mAh. Additionally, it is thermally optimized for long term deployments in many indoor environments. One can expect a large 20,000 mAh USB battery bank to operate the unit for up to 4 days.&lt;br /&gt;
&lt;br /&gt;
= Use Cases =&lt;br /&gt;
&lt;br /&gt;
The Signal Owl has a variety of different use cases. Among the most popular ones are classical network mapping and wardriving as well as basic penetration tests for different wireless technologies.&lt;br /&gt;
&lt;br /&gt;
== Fake Beacon Flooding Attack ==&lt;br /&gt;
&lt;br /&gt;
The fake beacon flooding attack is one possible use case for the Signal Owl. With that attack, fake beacon frames are broadcasted to nearby devices. Beacon Frames include various parameters like the SSID, the type of encryption used and timestamps. This results in the creation of multiple fake Wi-Fi networks. Devices with Wi-Fi browsers are then flooded with these fake networks, causing potential network scanner and driver crashes. Furthermore, the attack may prevent legitimate users from finding their networks and lead to denial of service. The preinstalled tools Aircrack-ng and MDK4 were used to create this payload. After powering on the device, multiple fake networks with random SSIDs are generated and broadcasted to all nearby devices.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;bash&amp;quot;&amp;gt;&lt;br /&gt;
#!/bin/bash&lt;br /&gt;
&lt;br /&gt;
LED SETUP&lt;br /&gt;
sleep 10&lt;br /&gt;
airmon-ng check kill&lt;br /&gt;
sleep 10&lt;br /&gt;
#creates monitor mode interface on wirelss card of the Signal Owl&lt;br /&gt;
airmon-ng start wlan0&lt;br /&gt;
sleep 10&lt;br /&gt;
LED ATTACK&lt;br /&gt;
#floods nearby devices with random SSIDs&lt;br /&gt;
mdk4 wlan0mon b -a -m -s 500&lt;br /&gt;
&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The results as seen from a victim running a Windows 10 system are pictured in the figure below.&lt;br /&gt;
&lt;br /&gt;
[[File:FakeBeaconFloodingSignalOwl.png|none|Random SSIDs as seen from a victim Windows 10 client |]][Eigene Darstellung]&lt;br /&gt;
&lt;br /&gt;
== Open AP Nmap Scanner ==&lt;br /&gt;
&lt;br /&gt;
With the Open AP Nmap Scanner payload, the Signal Owl scans for open access points. If the Signal Owl finds one or more open access points, it connects to them and uses Nmap to scan and analyze them. The results are then stored in the loot directory. For each discovered open access point, the Signal Owl generates a separate results file. This payload has some settings which can be seen in the following listing.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;bash&amp;quot;&amp;gt;&lt;br /&gt;
NMAP_OPTIONS=&amp;quot;-sP&amp;quot;&lt;br /&gt;
LOOT_DIR=/root/loot/open_ap_nmap_scan&lt;br /&gt;
MAX_CIDR=20&lt;br /&gt;
DEBUG=1&lt;br /&gt;
&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Step-by-step guide&lt;br /&gt;
&lt;br /&gt;
    1) download the payload [https://github.com/hak5/signalowl-payloads/blob/master/payloads/library/wifi/Open-AP-Nmap-Scanner/payload.txt payload]&lt;br /&gt;
    2) store the payload in a usb stick and plug the stick into the signal owl&lt;br /&gt;
    3) after connecting the signal owl, the payload is loaded on the root folder and the scan starts. &lt;br /&gt;
    4) once successfully executed, you can start the signal owl in arming mode and see the results in the loot folder.&lt;br /&gt;
      example loot Directory&lt;br /&gt;
      [[File:ArmingmodeSSHloot.png]][Eigene Darstellung]&lt;br /&gt;
&lt;br /&gt;
== Basic Bluetooth Scanner ==&lt;br /&gt;
&lt;br /&gt;
This payload requires an external Bluetooth adapter, since the Signal Owl does not have Bluetooth built in. The Basic Bluetooth Scanner scans for devices that have enabled Bluetooth and queries them, optionally using the hcitool and the command info. This payload does also have some settings, as shown in the listing below.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;bash&amp;quot;&amp;gt;&lt;br /&gt;
LOOT_DIR=/root/loot/bluetooth_scan&lt;br /&gt;
BT_OUTFILE=`date +%s`.bt.list&lt;br /&gt;
BT_INFOFILE=`date +%s`.bt.info   &lt;br /&gt;
BTDEV=hci0&lt;br /&gt;
DEBUG=0 &lt;br /&gt;
INTERROGATE=1 &lt;br /&gt;
&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
= Used Hardware =&lt;br /&gt;
&lt;br /&gt;
[[Signal Owl]]&lt;br /&gt;
&lt;br /&gt;
= References =&lt;br /&gt;
&lt;br /&gt;
*https://docs.hak5.org/signal-owl/&lt;br /&gt;
*https://github.com/hak5/signalowl-payloads&lt;br /&gt;
&lt;br /&gt;
[[Category:Pentesting]]&lt;/div&gt;</summary>
		<author><name>MMayer</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=Hak5_Signal_Owl&amp;diff=10713</id>
		<title>Hak5 Signal Owl</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=Hak5_Signal_Owl&amp;diff=10713"/>
		<updated>2023-01-06T22:00:30Z</updated>

		<summary type="html">&lt;p&gt;MMayer: /* Use Cases */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= Introduction =&lt;br /&gt;
&lt;br /&gt;
The [https://docs.hak5.org/signal-owl/ Signal Owl] is a hardware product developed by the company [https://shop.hak5.org/ Hak5].&lt;br /&gt;
It is a simple payload-based signals intelligence platform with a unique design for discreet planting or mobile operations on any engagement. The most popular application cases include classic network mapping and basic penetration tests for various wireless technologies.&lt;br /&gt;
&lt;br /&gt;
== Initial Setup ==&lt;br /&gt;
&lt;br /&gt;
When first unboxing the Signal Owl, the device runs a stager firmware that is designed to flash the latest firmware from a USB flash drive. In order to update the Signal Owl, the [https://downloads.hak5.org/owl latest firmware] has to be downloaded. Then, the downloaded file must be copied to the root of an EXT4 or FAT32 formatted USB flash drive. It is important not to modify this file. The next step is to plug the USB flash drive into the powered off Signal Owl. Afterwards, the device has to be powered on by a reliable USB source. The upgrade itself takes approximately five to ten minutes and is indicated by a solid red LED light. When finished, the device will reboot, enter Attack Mode and blink slowly, indicating an error running the payload because no payload has been found.&lt;br /&gt;
&lt;br /&gt;
= Hardware =&lt;br /&gt;
&lt;br /&gt;
[[File:SignalOwlDiagram.png|thumb|500px|frame|Components of the Signal Owl [Eigene Darstellung]]] &lt;br /&gt;
&lt;br /&gt;
The Signal Owl is designed to be rapidly deployed in all kinds of environments, allowing it to be an entry point for network analysis and basic wireless attacks in a variety of locations. With a power consumption of 100-200 mAh and the thermally optimized architecture, mobile operations as well as long term deployments, are enabled.&lt;br /&gt;
&lt;br /&gt;
== Components ==&lt;br /&gt;
&lt;br /&gt;
This device features several components of which some may not be visible to the human eye at first sight.&lt;br /&gt;
&lt;br /&gt;
=== USB Power / Passthrough Plug ===&lt;br /&gt;
&lt;br /&gt;
The USB power or passthrough plug is used to power the device. It can be powered from any reliable USB source.&lt;br /&gt;
&lt;br /&gt;
=== USB 2.0 Passthrough Port ===&lt;br /&gt;
&lt;br /&gt;
The USB 2.0 passthrough port is the port closest to the pigtail. Data and power pass through to that port, allowing for implant operations. If a device such as a keyboard is plugged in between this passthrough port and the power plug is connected to the target computer, the Signal Owl will remain undetected by the operating system. Only the keyboard will be visible on the target computer.&lt;br /&gt;
&lt;br /&gt;
=== USB 2.0 Host Port ===&lt;br /&gt;
&lt;br /&gt;
The USB 2.0 host port is the port farthest away from the pigtail. It is connected to the Linux socket of the Signal Owl and supports USB flash drives formatted with FAT32 and EXT4 file systems as well as many Wi-Fi, Bluetooth and other RF transceivers.&lt;br /&gt;
&lt;br /&gt;
=== Button ===&lt;br /&gt;
&lt;br /&gt;
The button on the bottom of the device is used to enter Arming Mode and to interact with payloads. It is not pressable without special tools like paperclips.&lt;br /&gt;
&lt;br /&gt;
=== Status LED ===&lt;br /&gt;
&lt;br /&gt;
The status LED indicates the current status of the Signal Owl. When it is turned off, it is not visible.&lt;br /&gt;
&lt;br /&gt;
The Signal Owl features a red LED with the following default status indications:&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
!|LED&lt;br /&gt;
!|Status&lt;br /&gt;
|-&lt;br /&gt;
|Blinking&lt;br /&gt;
|Booting&lt;br /&gt;
|-&lt;br /&gt;
|Solid&lt;br /&gt;
|Mounting external storage / Running upgrade&lt;br /&gt;
|-&lt;br /&gt;
|Single blinking&lt;br /&gt;
|Attack Mode&lt;br /&gt;
|-&lt;br /&gt;
|Double blinking&lt;br /&gt;
|Arming Mode&lt;br /&gt;
|-&lt;br /&gt;
|Slow blinking&lt;br /&gt;
|Error running payload&lt;br /&gt;
|-&lt;br /&gt;
|Fast blinking&lt;br /&gt;
|Select Mode (Deprecated from version 1.0.1 onward)&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= Software =&lt;br /&gt;
&lt;br /&gt;
== Modes of Operation ==&lt;br /&gt;
&lt;br /&gt;
The Signal Owl comes with two modes of operation, Attack Mode and Arming Mode. By default, the device will boot into Attack Mode. In order to access Arming Mode, the button on the bottom of the device has to be pressed while in Attack Mode. It is not recommended to press the button during the boot sequence, as this can possibly brick the device and render it useless. The arming mode is used for firmware updates and shell access, while the attack mode is used to load and execute the payload.&lt;br /&gt;
&lt;br /&gt;
=== Attack Mode ===&lt;br /&gt;
&lt;br /&gt;
Attack Mode is the default mode, the Signal Owl boots into. It provides two basic functions, being the payload loading function and the payload execution function. &lt;br /&gt;
&lt;br /&gt;
The payload loading function checks for any USB flash drives plugged into the host port of the device and copies payloads to &amp;lt;code&amp;gt;/root/payload&amp;lt;/code&amp;gt; and extensions to &amp;lt;code&amp;gt;/root/payload/extensions&amp;lt;/code&amp;gt; on the Signal Owl. &lt;br /&gt;
&lt;br /&gt;
The payload execution function is responsible for executing the payload that is currently stored on the root of the Signal Owl. In case no payload is found, the device will blink slowly, indicating the FAIL status.&lt;br /&gt;
&lt;br /&gt;
=== Arming Mode ===&lt;br /&gt;
&lt;br /&gt;
The Arming Mode provides two basic functions, being the firmware update function and the shell access function. The firmware update function checks for any USB flash drives plugged into the host port of the device and copies firmware upgrade files into the internal storage of the device and flashes it. The shell access function starts an open access point with the SSID Owl_xxxx in which xxxx indicates the last two octets of the device&#039;s MAC address. Additionally, a SSH server providing access to the shell of the Signal Owl is enabled.&lt;br /&gt;
&lt;br /&gt;
== Default Settings ==&lt;br /&gt;
&lt;br /&gt;
Default settings that are used in order to access the device via SSH are pictured in the table below.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
!colspan=&amp;quot;2&amp;quot;|Default Settings&lt;br /&gt;
|-&lt;br /&gt;
|Username&lt;br /&gt;
|root&lt;br /&gt;
|-&lt;br /&gt;
|Password&lt;br /&gt;
|hak5owl&lt;br /&gt;
|-&lt;br /&gt;
|SSID&lt;br /&gt;
|Owl_xxxx&lt;br /&gt;
|-&lt;br /&gt;
|IP Address&lt;br /&gt;
|172.16.56.1&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
SSH command: &amp;lt;code&amp;gt;ssh root@172.16.56.1&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The SSID during Arming Mode is Owl_xxxx in which xxxx indicates the last two octets of the devices MAC address.&lt;br /&gt;
&lt;br /&gt;
= Usage =&lt;br /&gt;
&lt;br /&gt;
== Arming Mode connection ==&lt;br /&gt;
&lt;br /&gt;
Step-by-step guide for accessing the arming mode&lt;br /&gt;
&lt;br /&gt;
#Click on the button located on the bottom of the Signal Owl while it is in attack mode. After pressing the button, the signal owl enters the arming mode and provides an open access point with the name Owl xxxx (where xxxx stands for the last two digits of the MAC address of the device).&lt;br /&gt;
#Connect to the access point.&amp;lt;br&amp;gt;[[File:Armingmode.png]][Eigene Darstellung]&lt;br /&gt;
#Now you can connect via ssh by using the [[#Default Settings|default settings]]&lt;br /&gt;
#After successful connection, you will end up in the root directory&amp;lt;br&amp;gt;[[File:ArmingmodeSSH.png]][Eigene Darstellung]&lt;br /&gt;
#Now you can change the files and directories on the Signal Owl to view results, transfer payloads and extensions or to make further changes&lt;br /&gt;
      &lt;br /&gt;
== Directory structure ==&lt;br /&gt;
&lt;br /&gt;
The following directory tree shows the directory structure of the Signal Owl.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
/&lt;br /&gt;
├── loot&lt;br /&gt;
└── payload/&lt;br /&gt;
    └── extensions&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
*Loot - Directory where the Signal Owl saves loot while executing payloads that produce loot.&lt;br /&gt;
*Payload - This directory holds the current payload. &lt;br /&gt;
*Extensions -  This directory holds all extensions.&lt;br /&gt;
&lt;br /&gt;
== Adding Payloads and Extensions ==&lt;br /&gt;
&lt;br /&gt;
Adding a payload can be done in two different ways. Either with a USB flash drive or via the Signal Owl access point to the internal storage of the device. &lt;br /&gt;
&lt;br /&gt;
When booting, payloads on USB flash drives are given priority and will override payloads stored on the Signal Owl. To successfully copy a payload to the Signal Owl, the payload must be named &amp;lt;code&amp;gt;payload.txt&amp;lt;/code&amp;gt; or &amp;lt;code&amp;gt;payload.sh&amp;lt;/code&amp;gt; and it has to be placed in the &amp;lt;code&amp;gt;root&amp;lt;/code&amp;gt; directory of the flash drive. Similarly, payload extensions should be stored in a &amp;lt;code&amp;gt;/extensions&amp;lt;/code&amp;gt; directory on the flash drive. &lt;br /&gt;
&lt;br /&gt;
In addition, it is possible to transfer payloads and payload extensions to the device via the Signal Owl access point in arming mode using SSH. There they are stored in the &amp;lt;code&amp;gt;/root/payload&amp;lt;/code&amp;gt; directory and Payload Extensions are stored in the &amp;lt;code&amp;gt;/root/payload/extensions&amp;lt;/code&amp;gt; directory.&lt;br /&gt;
&lt;br /&gt;
== Payload Development ==&lt;br /&gt;
&lt;br /&gt;
Payloads for the Signal Owl are written in bash with [https://github.com/hak5darren/USB-Rubber-Ducky/wiki/Duckyscript Ducky Script] and can be created with any standard text editor. All payloads should begin with an interpreter directive, like the shebang &amp;lt;code&amp;gt;#!/bin/bash&amp;lt;/code&amp;gt; for bash payloads and payloads must be named either &amp;lt;code&amp;gt;payload.txt&amp;lt;/code&amp;gt; or &amp;lt;code&amp;gt;payload.sh&amp;lt;/code&amp;gt;. In order to create effective payloads, the Signal Owl comes with several preinstalled penetration testing tools. These are as follows: [https://nmap.org/ Nmap], [https://www.aircrack-ng.org/ Aircrack-ng], [https://github.com/aircrack-ng/mdk4 MDK4] and [https://www.kismetwireless.net/ Kismet].&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Tools&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
• Kismet - detector for wireless networks and devices.&lt;br /&gt;
&lt;br /&gt;
• MDK4 - Wi-Fi testing tool.&lt;br /&gt;
&lt;br /&gt;
• Aircrack-ng Suite - a complete suite of tools for WiFi network security assessment.&lt;br /&gt;
&lt;br /&gt;
• Nmap - open source utility for network discovery and security auditing.&lt;br /&gt;
&lt;br /&gt;
Hak5 offers ready-to-use payloads and payload extensions on their [https://github.com/hak5/signalowl-payloads GitHub repository].&lt;br /&gt;
&lt;br /&gt;
== Implant / mobile operations ==&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Implant operations&lt;br /&gt;
&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
During long term wireless engagements, the Signal Owl may be planted inline between any typical 5V USB power source. This may be useful in situations where ports are occupied, or to deter the unit from being unplugged.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Mobile operations&lt;br /&gt;
&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
The Signal Owl features a low power consumption profile, with a typical power draw averaging 100-200 mAh. Additionally, it is thermally optimized for long term deployments in many indoor environments. One can expect a large 20,000 mAh USB battery bank to operate the unit for up to 4 days.&lt;br /&gt;
&lt;br /&gt;
= Use Cases =&lt;br /&gt;
&lt;br /&gt;
The Signal Owl has a variety of different use cases. Among the most popular ones are classical network mapping and wardriving as well as basic penetration tests for different wireless technologies.&lt;br /&gt;
&lt;br /&gt;
== Fake Beacon Flooding Attack ==&lt;br /&gt;
&lt;br /&gt;
The fake beacon flooding attack is one possible use case for the Signal Owl. With that attack, fake beacon frames are broadcasted to nearby devices. Beacon Frames include various parameters like the SSID, the type of encryption used and timestamps. This results in the creation of multiple fake Wi-Fi networks. Devices with Wi-Fi browsers are then flooded with these fake networks, causing potential network scanner and driver crashes. Furthermore, the attack may prevent legitimate users from finding their networks and lead to denial of service. The preinstalled tools Aircrack-ng and MDK4 were used to create this payload. After powering on the device, multiple fake networks with random SSIDs are generated and broadcasted to all nearby devices.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;bash&amp;quot;&amp;gt;&lt;br /&gt;
#!/bin/bash&lt;br /&gt;
&lt;br /&gt;
LED SETUP&lt;br /&gt;
sleep 10&lt;br /&gt;
airmon-ng check kill&lt;br /&gt;
sleep 10&lt;br /&gt;
#creates monitor mode interface on wirelss card of the Signal Owl&lt;br /&gt;
airmon-ng start wlan0&lt;br /&gt;
sleep 10&lt;br /&gt;
LED ATTACK&lt;br /&gt;
#floods nearby devices with random SSIDs&lt;br /&gt;
mdk4 wlan0mon b -a -m -s 500&lt;br /&gt;
&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The results as seen from a victim running a Windows 10 system are pictured in the figure below.&lt;br /&gt;
&lt;br /&gt;
[[File:FakeBeaconFloodingSignalOwl.png|none|Random SSIDs as seen from a victim Windows 10 client |]][Eigene Darstellung]&lt;br /&gt;
&lt;br /&gt;
== Open AP Nmap Scanner ==&lt;br /&gt;
&lt;br /&gt;
With the Open AP Nmap Scanner payload, the Signal Owl scans for open access points. If the Signal Owl finds one or more open access points, it connects to them and uses Nmap to scan and analyze them. The results are then stored in the loot directory. For each discovered open access point, the Signal Owl generates a separate results file. This payload has some settings which can be seen in the following listing.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;bash&amp;quot;&amp;gt;&lt;br /&gt;
NMAP_OPTIONS=&amp;quot;-sP&amp;quot;&lt;br /&gt;
LOOT_DIR=/root/loot/open_ap_nmap_scan&lt;br /&gt;
MAX_CIDR=20&lt;br /&gt;
DEBUG=1&lt;br /&gt;
&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Step-by-step guide&lt;br /&gt;
&lt;br /&gt;
    1) download the payload [https://github.com/hak5/signalowl-payloads/blob/master/payloads/library/wifi/Open-AP-Nmap-Scanner/payload.txt payload]&lt;br /&gt;
    2) store the payload in a usb stick and plug the stick into the signal owl&lt;br /&gt;
    3) after connecting the signal owl, the payload is loaded on the root folder and the scan starts. &lt;br /&gt;
    4) once successfully executed, you can start the signal owl in arming mode and see the results in the loot folder.&lt;br /&gt;
      example loot Directory&lt;br /&gt;
      [[File:ArmingmodeSSHloot.png]][Eigene Darstellung]&lt;br /&gt;
&lt;br /&gt;
== Basic Bluetooth Scanner ==&lt;br /&gt;
&lt;br /&gt;
This payload requires an external Bluetooth adapter, since the Signal Owl does not have Bluetooth built in. The Basic Bluetooth Scanner scans for devices that have enabled Bluetooth and queries them, optionally using the hcitool and the command info. This payload does also have some settings, as shown in the listing below.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;bash&amp;quot;&amp;gt;&lt;br /&gt;
LOOT_DIR=/root/loot/bluetooth_scan&lt;br /&gt;
BT_OUTFILE=`date +%s`.bt.list&lt;br /&gt;
BT_INFOFILE=`date +%s`.bt.info   &lt;br /&gt;
BTDEV=hci0&lt;br /&gt;
DEBUG=0 &lt;br /&gt;
INTERROGATE=1 &lt;br /&gt;
&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
= Used Hardware =&lt;br /&gt;
&lt;br /&gt;
[[Signal Owl]]&lt;br /&gt;
&lt;br /&gt;
= References =&lt;br /&gt;
&lt;br /&gt;
*https://docs.hak5.org/signal-owl/&lt;br /&gt;
*https://github.com/hak5/signalowl-payloads&lt;br /&gt;
&lt;br /&gt;
[[Category:Pentesting]]&lt;/div&gt;</summary>
		<author><name>MMayer</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=Hak5_Signal_Owl&amp;diff=10712</id>
		<title>Hak5 Signal Owl</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=Hak5_Signal_Owl&amp;diff=10712"/>
		<updated>2023-01-06T21:49:19Z</updated>

		<summary type="html">&lt;p&gt;MMayer: /* Open AP Nmap Scanner */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= Introduction =&lt;br /&gt;
&lt;br /&gt;
The [https://docs.hak5.org/signal-owl/ Signal Owl] is a hardware product developed by the company [https://shop.hak5.org/ Hak5].&lt;br /&gt;
It is a simple payload-based signals intelligence platform with a unique design for discreet planting or mobile operations on any engagement. The most popular application cases include classic network mapping and basic penetration tests for various wireless technologies.&lt;br /&gt;
&lt;br /&gt;
== Initial Setup ==&lt;br /&gt;
&lt;br /&gt;
When first unboxing the Signal Owl, the device runs a stager firmware that is designed to flash the latest firmware from a USB flash drive. In order to update the Signal Owl, the [https://downloads.hak5.org/owl latest firmware] has to be downloaded. Then, the downloaded file must be copied to the root of an EXT4 or FAT32 formatted USB flash drive. It is important not to modify this file. The next step is to plug the USB flash drive into the powered off Signal Owl. Afterwards, the device has to be powered on by a reliable USB source. The upgrade itself takes approximately five to ten minutes and is indicated by a solid red LED light. When finished, the device will reboot, enter Attack Mode and blink slowly, indicating an error running the payload because no payload has been found.&lt;br /&gt;
&lt;br /&gt;
= Hardware =&lt;br /&gt;
&lt;br /&gt;
[[File:SignalOwlDiagram.png|thumb|500px|frame|Components of the Signal Owl [Eigene Darstellung]]] &lt;br /&gt;
&lt;br /&gt;
The Signal Owl is designed to be rapidly deployed in all kinds of environments, allowing it to be an entry point for network analysis and basic wireless attacks in a variety of locations. With a power consumption of 100-200 mAh and the thermally optimized architecture, mobile operations as well as long term deployments, are enabled.&lt;br /&gt;
&lt;br /&gt;
== Components ==&lt;br /&gt;
&lt;br /&gt;
This device features several components of which some may not be visible to the human eye at first sight.&lt;br /&gt;
&lt;br /&gt;
=== USB Power / Passthrough Plug ===&lt;br /&gt;
&lt;br /&gt;
The USB power or passthrough plug is used to power the device. It can be powered from any reliable USB source.&lt;br /&gt;
&lt;br /&gt;
=== USB 2.0 Passthrough Port ===&lt;br /&gt;
&lt;br /&gt;
The USB 2.0 passthrough port is the port closest to the pigtail. Data and power pass through to that port, allowing for implant operations. If a device such as a keyboard is plugged in between this passthrough port and the power plug is connected to the target computer, the Signal Owl will remain undetected by the operating system. Only the keyboard will be visible on the target computer.&lt;br /&gt;
&lt;br /&gt;
=== USB 2.0 Host Port ===&lt;br /&gt;
&lt;br /&gt;
The USB 2.0 host port is the port farthest away from the pigtail. It is connected to the Linux socket of the Signal Owl and supports USB flash drives formatted with FAT32 and EXT4 file systems as well as many Wi-Fi, Bluetooth and other RF transceivers.&lt;br /&gt;
&lt;br /&gt;
=== Button ===&lt;br /&gt;
&lt;br /&gt;
The button on the bottom of the device is used to enter Arming Mode and to interact with payloads. It is not pressable without special tools like paperclips.&lt;br /&gt;
&lt;br /&gt;
=== Status LED ===&lt;br /&gt;
&lt;br /&gt;
The status LED indicates the current status of the Signal Owl. When it is turned off, it is not visible.&lt;br /&gt;
&lt;br /&gt;
The Signal Owl features a red LED with the following default status indications:&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
!|LED&lt;br /&gt;
!|Status&lt;br /&gt;
|-&lt;br /&gt;
|Blinking&lt;br /&gt;
|Booting&lt;br /&gt;
|-&lt;br /&gt;
|Solid&lt;br /&gt;
|Mounting external storage / Running upgrade&lt;br /&gt;
|-&lt;br /&gt;
|Single blinking&lt;br /&gt;
|Attack Mode&lt;br /&gt;
|-&lt;br /&gt;
|Double blinking&lt;br /&gt;
|Arming Mode&lt;br /&gt;
|-&lt;br /&gt;
|Slow blinking&lt;br /&gt;
|Error running payload&lt;br /&gt;
|-&lt;br /&gt;
|Fast blinking&lt;br /&gt;
|Select Mode (Deprecated from version 1.0.1 onward)&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= Software =&lt;br /&gt;
&lt;br /&gt;
== Modes of Operation ==&lt;br /&gt;
&lt;br /&gt;
The Signal Owl comes with two modes of operation, Attack Mode and Arming Mode. By default, the device will boot into Attack Mode. In order to access Arming Mode, the button on the bottom of the device has to be pressed while in Attack Mode. It is not recommended to press the button during the boot sequence, as this can possibly brick the device and render it useless. The arming mode is used for firmware updates and shell access, while the attack mode is used to load and execute the payload.&lt;br /&gt;
&lt;br /&gt;
=== Attack Mode ===&lt;br /&gt;
&lt;br /&gt;
Attack Mode is the default mode, the Signal Owl boots into. It provides two basic functions, being the payload loading function and the payload execution function. &lt;br /&gt;
&lt;br /&gt;
The payload loading function checks for any USB flash drives plugged into the host port of the device and copies payloads to &amp;lt;code&amp;gt;/root/payload&amp;lt;/code&amp;gt; and extensions to &amp;lt;code&amp;gt;/root/payload/extensions&amp;lt;/code&amp;gt; on the Signal Owl. &lt;br /&gt;
&lt;br /&gt;
The payload execution function is responsible for executing the payload that is currently stored on the root of the Signal Owl. In case no payload is found, the device will blink slowly, indicating the FAIL status.&lt;br /&gt;
&lt;br /&gt;
=== Arming Mode ===&lt;br /&gt;
&lt;br /&gt;
The Arming Mode provides two basic functions, being the firmware update function and the shell access function. The firmware update function checks for any USB flash drives plugged into the host port of the device and copies firmware upgrade files into the internal storage of the device and flashes it. The shell access function starts an open access point with the SSID Owl_xxxx in which xxxx indicates the last two octets of the device&#039;s MAC address. Additionally, a SSH server providing access to the shell of the Signal Owl is enabled.&lt;br /&gt;
&lt;br /&gt;
== Default Settings ==&lt;br /&gt;
&lt;br /&gt;
Default settings that are used in order to access the device via SSH are pictured in the table below.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
!colspan=&amp;quot;2&amp;quot;|Default Settings&lt;br /&gt;
|-&lt;br /&gt;
|Username&lt;br /&gt;
|root&lt;br /&gt;
|-&lt;br /&gt;
|Password&lt;br /&gt;
|hak5owl&lt;br /&gt;
|-&lt;br /&gt;
|SSID&lt;br /&gt;
|Owl_xxxx&lt;br /&gt;
|-&lt;br /&gt;
|IP Address&lt;br /&gt;
|172.16.56.1&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
SSH command: &amp;lt;code&amp;gt;ssh root@172.16.56.1&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The SSID during Arming Mode is Owl_xxxx in which xxxx indicates the last two octets of the devices MAC address.&lt;br /&gt;
&lt;br /&gt;
= Usage =&lt;br /&gt;
&lt;br /&gt;
== Arming Mode connection ==&lt;br /&gt;
&lt;br /&gt;
Step-by-step guide for accessing the arming mode&lt;br /&gt;
&lt;br /&gt;
#Click on the button located on the bottom of the Signal Owl while it is in attack mode. After pressing the button, the signal owl enters the arming mode and provides an open access point with the name Owl xxxx (where xxxx stands for the last two digits of the MAC address of the device).&lt;br /&gt;
#Connect to the access point.&amp;lt;br&amp;gt;[[File:Armingmode.png]][Eigene Darstellung]&lt;br /&gt;
#Now you can connect via ssh by using the [[#Default Settings|default settings]]&lt;br /&gt;
#After successful connection, you will end up in the root directory&amp;lt;br&amp;gt;[[File:ArmingmodeSSH.png]][Eigene Darstellung]&lt;br /&gt;
#Now you can change the files and directories on the Signal Owl to view results, transfer payloads and extensions or to make further changes&lt;br /&gt;
      &lt;br /&gt;
== Directory structure ==&lt;br /&gt;
&lt;br /&gt;
The following directory tree shows the directory structure of the Signal Owl.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
/&lt;br /&gt;
├── loot&lt;br /&gt;
└── payload/&lt;br /&gt;
    └── extensions&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
*Loot - Directory where the Signal Owl saves loot while executing payloads that produce loot.&lt;br /&gt;
*Payload - This directory holds the current payload. &lt;br /&gt;
*Extensions -  This directory holds all extensions.&lt;br /&gt;
&lt;br /&gt;
== Adding Payloads and Extensions ==&lt;br /&gt;
&lt;br /&gt;
Adding a payload can be done in two different ways. Either with a USB flash drive or via the Signal Owl access point to the internal storage of the device. &lt;br /&gt;
&lt;br /&gt;
When booting, payloads on USB flash drives are given priority and will override payloads stored on the Signal Owl. To successfully copy a payload to the Signal Owl, the payload must be named &amp;lt;code&amp;gt;payload.txt&amp;lt;/code&amp;gt; or &amp;lt;code&amp;gt;payload.sh&amp;lt;/code&amp;gt; and it has to be placed in the &amp;lt;code&amp;gt;root&amp;lt;/code&amp;gt; directory of the flash drive. Similarly, payload extensions should be stored in a &amp;lt;code&amp;gt;/extensions&amp;lt;/code&amp;gt; directory on the flash drive. &lt;br /&gt;
&lt;br /&gt;
In addition, it is possible to transfer payloads and payload extensions to the device via the Signal Owl access point in arming mode using SSH. There they are stored in the &amp;lt;code&amp;gt;/root/payload&amp;lt;/code&amp;gt; directory and Payload Extensions are stored in the &amp;lt;code&amp;gt;/root/payload/extensions&amp;lt;/code&amp;gt; directory.&lt;br /&gt;
&lt;br /&gt;
== Payload Development ==&lt;br /&gt;
&lt;br /&gt;
Payloads for the Signal Owl are written in bash with [https://github.com/hak5darren/USB-Rubber-Ducky/wiki/Duckyscript Ducky Script] and can be created with any standard text editor. All payloads should begin with an interpreter directive, like the shebang &amp;lt;code&amp;gt;#!/bin/bash&amp;lt;/code&amp;gt; for bash payloads and payloads must be named either &amp;lt;code&amp;gt;payload.txt&amp;lt;/code&amp;gt; or &amp;lt;code&amp;gt;payload.sh&amp;lt;/code&amp;gt;. In order to create effective payloads, the Signal Owl comes with several preinstalled penetration testing tools. These are as follows: [https://nmap.org/ Nmap], [https://www.aircrack-ng.org/ Aircrack-ng], [https://github.com/aircrack-ng/mdk4 MDK4] and [https://www.kismetwireless.net/ Kismet].&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Tools&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
• Kismet - detector for wireless networks and devices.&lt;br /&gt;
&lt;br /&gt;
• MDK4 - Wi-Fi testing tool.&lt;br /&gt;
&lt;br /&gt;
• Aircrack-ng Suite - a complete suite of tools for WiFi network security assessment.&lt;br /&gt;
&lt;br /&gt;
• Nmap - open source utility for network discovery and security auditing.&lt;br /&gt;
&lt;br /&gt;
Hak5 offers ready-to-use payloads and payload extensions on their [https://github.com/hak5/signalowl-payloads GitHub repository].&lt;br /&gt;
&lt;br /&gt;
== Implant / mobile operations ==&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Implant operations&lt;br /&gt;
&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
During long term wireless engagements, the Signal Owl may be planted inline between any typical 5V USB power source. This may be useful in situations where ports are occupied, or to deter the unit from being unplugged.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Mobile operations&lt;br /&gt;
&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
The Signal Owl features a low power consumption profile, with a typical power draw averaging 100-200 mAh. Additionally, it is thermally optimized for long term deployments in many indoor environments. One can expect a large 20,000 mAh USB battery bank to operate the unit for up to 4 days.&lt;br /&gt;
&lt;br /&gt;
= Use Cases =&lt;br /&gt;
&lt;br /&gt;
The Signal Owl has a variety of different use cases. Among the most popular ones are classical network mapping and wardriving as well as basic penetration tests for different wireless technologies.&lt;br /&gt;
&lt;br /&gt;
== Fake Beacon Flooding Attack ==&lt;br /&gt;
&lt;br /&gt;
The fake beacon flooding attack is one possible use case for the Signal Owl. With that attack, fake beacon frames are broadcasted to nearby devices. Beacon Frames include various parameters like the SSID, the type of encryption used and timestamps. This results in the creation of multiple fake Wi-Fi networks. Devices with Wi-Fi browsers are then flooded with these fake networks, causing potential network scanner and driver crashes. Furthermore, the attack may prevent legitimate users from finding their networks and lead to denial of service. The preinstalled tools Aircrack-ng and MDK4 were used to create this payload. After powering on the device, multiple fake networks with random SSIDs are generated and broadcasted to all nearby devices.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;bash&amp;quot;&amp;gt;&lt;br /&gt;
#!/bin/bash&lt;br /&gt;
&lt;br /&gt;
LED SETUP&lt;br /&gt;
sleep 10&lt;br /&gt;
airmon-ng check kill&lt;br /&gt;
sleep 10&lt;br /&gt;
#creates monitor mode interface on wirelss card of the Signal Owl&lt;br /&gt;
airmon-ng start wlan0&lt;br /&gt;
sleep 10&lt;br /&gt;
LED ATTACK&lt;br /&gt;
#floods nearby devices with random SSIDs&lt;br /&gt;
mdk4 wlan0mon b -a -m -s 500&lt;br /&gt;
&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The results as seen from a victim running a Windows 10 system are pictured in the figure below.&lt;br /&gt;
&lt;br /&gt;
[[File:FakeBeaconFloodingSignalOwl.png|none|Random SSIDs as seen from a victim Windows 10 client |]][Eigene Darstellung]&lt;br /&gt;
&lt;br /&gt;
== Open AP Nmap Scanner ==&lt;br /&gt;
&lt;br /&gt;
With the Open AP Nmap Scanner payload, the Signal Owl scans for open access points. If the Signal Owl finds one or more open access points, it connects to them and uses Nmap to scan and analyze them. The results are then stored in the loot directory. For each discovered open access point, the Signal Owl generates a separate results file. This payload has some settings which can be seen in the following listing.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;bash&amp;quot;&amp;gt;&lt;br /&gt;
NMAP_OPTIONS=&amp;quot;-sP&amp;quot;&lt;br /&gt;
LOOT_DIR=/root/loot/open_ap_nmap_scan&lt;br /&gt;
MAX_CIDR=20&lt;br /&gt;
DEBUG=1&lt;br /&gt;
&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Step-by-step guide&lt;br /&gt;
&lt;br /&gt;
    1) download the payload [https://github.com/hak5/signalowl-payloads/blob/master/payloads/library/wifi/Open-AP-Nmap-Scanner/payload.txt payload]&lt;br /&gt;
    2) store the payload in a usb stick and plug the stick into the signal owl&lt;br /&gt;
    3) after connecting the signal owl, the payload is loaded on the root folder and the scan starts. &lt;br /&gt;
    4) once successfully executed, you can start the signal owl in arming mode and see the results in the loot folder.&lt;br /&gt;
      example loot Directory&lt;br /&gt;
      [[File:ArmingmodeSSHloot.png]][Eigene Darstellung]&lt;br /&gt;
&lt;br /&gt;
= Used Hardware =&lt;br /&gt;
&lt;br /&gt;
[[Signal Owl]]&lt;br /&gt;
&lt;br /&gt;
= References =&lt;br /&gt;
&lt;br /&gt;
*https://docs.hak5.org/signal-owl/&lt;br /&gt;
*https://github.com/hak5/signalowl-payloads&lt;br /&gt;
&lt;br /&gt;
[[Category:Pentesting]]&lt;/div&gt;</summary>
		<author><name>MMayer</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=Hak5_Signal_Owl&amp;diff=10702</id>
		<title>Hak5 Signal Owl</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=Hak5_Signal_Owl&amp;diff=10702"/>
		<updated>2023-01-06T21:04:17Z</updated>

		<summary type="html">&lt;p&gt;MMayer: /* Fake Beacon Flooding Attack */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= Introduction =&lt;br /&gt;
&lt;br /&gt;
The [https://docs.hak5.org/signal-owl/ Signal Owl] is a hardware product developed by the company [https://shop.hak5.org/ Hak5].&lt;br /&gt;
It is a simple payload-based signals intelligence platform with a unique design for discreet planting or mobile operations on any engagement. The most popular application cases include classic network mapping and basic penetration tests for various wireless technologies.&lt;br /&gt;
&lt;br /&gt;
== Initial Setup ==&lt;br /&gt;
&lt;br /&gt;
When first unboxing the Signal Owl, the device runs a stager firmware that is designed to flash the latest firmware from a USB flash drive. In order to update the Signal Owl, the [https://downloads.hak5.org/owl latest firmware] has to be downloaded. Then, the downloaded file must be copied to the root of an EXT4 or FAT32 formatted USB flash drive. It is important not to modify this file. The next step is to plug the USB flash drive into the powered off Signal Owl. Afterwards, the device has to be powered on by a reliable USB source. The upgrade itself takes approximately five to ten minutes and is indicated by a solid red LED light. When finished, the device will reboot, enter Attack Mode and blink slowly, indicating an error running the payload because no payload has been found.&lt;br /&gt;
&lt;br /&gt;
= Hardware =&lt;br /&gt;
&lt;br /&gt;
[[File:SignalOwlDiagram.png|thumb|500px|frame|Components of the Signal Owl [Eigene Darstellung]]] &lt;br /&gt;
&lt;br /&gt;
The Signal Owl is designed to be rapidly deployed in all kinds of environments, allowing it to be an entry point for network analysis and basic wireless attacks in a variety of locations. With a power consumption of 100-200 mAh and the thermally optimized architecture, mobile operations as well as long term deployments, are enabled.&lt;br /&gt;
&lt;br /&gt;
== Components ==&lt;br /&gt;
&lt;br /&gt;
This device features several components of which some may not be visible to the human eye at first sight.&lt;br /&gt;
&lt;br /&gt;
=== USB Power / Passthrough Plug ===&lt;br /&gt;
&lt;br /&gt;
The USB power or passthrough plug is used to power the device. It can be powered from any reliable USB source.&lt;br /&gt;
&lt;br /&gt;
=== USB 2.0 Passthrough Port ===&lt;br /&gt;
&lt;br /&gt;
The USB 2.0 passthrough port is the port closest to the pigtail. Data and power pass through to that port, allowing for implant operations. If a device such as a keyboard is plugged in between this passthrough port and the power plug is connected to the target computer, the Signal Owl will remain undetected by the operating system. Only the keyboard will be visible on the target computer.&lt;br /&gt;
&lt;br /&gt;
=== USB 2.0 Host Port ===&lt;br /&gt;
&lt;br /&gt;
The USB 2.0 host port is the port farthest away from the pigtail. It is connected to the Linux socket of the Signal Owl and supports USB flash drives formatted with FAT32 and EXT4 file systems as well as many Wi-Fi, Bluetooth and other RF transceivers.&lt;br /&gt;
&lt;br /&gt;
=== Button ===&lt;br /&gt;
&lt;br /&gt;
The button on the bottom of the device is used to enter Arming Mode and to interact with payloads. It is not pressable without special tools like paperclips.&lt;br /&gt;
&lt;br /&gt;
=== Status LED ===&lt;br /&gt;
&lt;br /&gt;
The status LED indicates the current status of the Signal Owl. When it is turned off, it is not visible.&lt;br /&gt;
&lt;br /&gt;
The Signal Owl features a red LED with the following default status indications:&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
!|LED&lt;br /&gt;
!|Status&lt;br /&gt;
|-&lt;br /&gt;
|Blinking&lt;br /&gt;
|Booting&lt;br /&gt;
|-&lt;br /&gt;
|Solid&lt;br /&gt;
|Mounting external storage / Running upgrade&lt;br /&gt;
|-&lt;br /&gt;
|Single blinking&lt;br /&gt;
|Attack Mode&lt;br /&gt;
|-&lt;br /&gt;
|Double blinking&lt;br /&gt;
|Arming Mode&lt;br /&gt;
|-&lt;br /&gt;
|Slow blinking&lt;br /&gt;
|Error running payload&lt;br /&gt;
|-&lt;br /&gt;
|Fast blinking&lt;br /&gt;
|Select Mode (Deprecated from version 1.0.1 onward)&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= Software =&lt;br /&gt;
&lt;br /&gt;
== Modes of Operation ==&lt;br /&gt;
&lt;br /&gt;
The Signal Owl comes with two modes of operation, Attack Mode and Arming Mode. By default, the device will boot into Attack Mode. In order to access Arming Mode, the button on the bottom of the device has to be pressed while in Attack Mode. It is not recommended to press the button during the boot sequence, as this can possibly brick the device and render it useless. The arming mode is used for firmware updates and shell access, while the attack mode is used to load and execute the payload.&lt;br /&gt;
&lt;br /&gt;
=== Attack Mode ===&lt;br /&gt;
&lt;br /&gt;
Attack Mode is the default mode, the Signal Owl boots into. It provides two basic functions, being the payload loading function and the payload execution function. &lt;br /&gt;
&lt;br /&gt;
The payload loading function checks for any USB flash drives plugged into the host port of the device and copies payloads to &amp;lt;code&amp;gt;/root/payload&amp;lt;/code&amp;gt; and extensions to &amp;lt;code&amp;gt;/root/payload/extensions&amp;lt;/code&amp;gt; on the Signal Owl. &lt;br /&gt;
&lt;br /&gt;
The payload execution function is responsible for executing the payload that is currently stored on the root of the Signal Owl. In case no payload is found, the device will blink slowly, indicating the FAIL status.&lt;br /&gt;
&lt;br /&gt;
=== Arming Mode ===&lt;br /&gt;
&lt;br /&gt;
The Arming Mode provides two basic functions, being the firmware update function and the shell access function. The firmware update function checks for any USB flash drives plugged into the host port of the device and copies firmware upgrade files into the internal storage of the device and flashes it. The shell access function starts an open access point with the SSID Owl_xxxx in which xxxx indicates the last two octets of the device&#039;s MAC address. Additionally, a SSH server providing access to the shell of the Signal Owl is enabled.&lt;br /&gt;
&lt;br /&gt;
== Default Settings ==&lt;br /&gt;
&lt;br /&gt;
Default settings that are used in order to access the device via SSH are pictured in the table below.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
!colspan=&amp;quot;2&amp;quot;|Default Settings&lt;br /&gt;
|-&lt;br /&gt;
|Username&lt;br /&gt;
|root&lt;br /&gt;
|-&lt;br /&gt;
|Password&lt;br /&gt;
|hak5owl&lt;br /&gt;
|-&lt;br /&gt;
|SSID&lt;br /&gt;
|Owl_xxxx&lt;br /&gt;
|-&lt;br /&gt;
|IP Address&lt;br /&gt;
|172.16.56.1&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
SSH command: &amp;lt;code&amp;gt;ssh root@172.16.56.1&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The SSID during Arming Mode is Owl_xxxx in which xxxx indicates the last two octets of the devices MAC address.&lt;br /&gt;
&lt;br /&gt;
= Usage =&lt;br /&gt;
&lt;br /&gt;
== Arming Mode connection ==&lt;br /&gt;
&lt;br /&gt;
Step-by-step guide for accessing the arming mode&lt;br /&gt;
&lt;br /&gt;
#Click on the button located on the bottom of the Signal Owl while it is in attack mode. After pressing the button, the signal owl enters the arming mode and provides an open access point with the name Owl xxxx (where xxxx stands for the last two digits of the MAC address of the device).&lt;br /&gt;
#Connect to the access point.&amp;lt;br&amp;gt;[[File:Armingmode.png]][Eigene Darstellung]&lt;br /&gt;
#Now you can connect via ssh by using the [[#Default Settings|default settings]]&lt;br /&gt;
#After successful connection, you will end up in the root directory&amp;lt;br&amp;gt;[[File:ArmingmodeSSH.png]][Eigene Darstellung]&lt;br /&gt;
#Now you can change the files and directories on the Signal Owl to view results, transfer payloads and extensions or to make further changes&lt;br /&gt;
      &lt;br /&gt;
== Directory structure ==&lt;br /&gt;
&lt;br /&gt;
The following directory tree shows the directory structure of the Signal Owl.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
/&lt;br /&gt;
├── loot&lt;br /&gt;
└── payload/&lt;br /&gt;
    └── extensions&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
*Loot - Directory where the Signal Owl saves loot while executing payloads that produce loot.&lt;br /&gt;
*Payload - This directory holds the current payload. &lt;br /&gt;
*Extensions -  This directory holds all extensions.&lt;br /&gt;
&lt;br /&gt;
== Adding Payloads and Extensions ==&lt;br /&gt;
&lt;br /&gt;
Adding a payload can be done in two different ways. Either with a USB flash drive or via the Signal Owl access point to the internal storage of the device. &lt;br /&gt;
&lt;br /&gt;
When booting, payloads on USB flash drives are given priority and will override payloads stored on the Signal Owl. To successfully copy a payload to the Signal Owl, the payload must be named &amp;lt;code&amp;gt;payload.txt&amp;lt;/code&amp;gt; or &amp;lt;code&amp;gt;payload.sh&amp;lt;/code&amp;gt; and it has to be placed in the &amp;lt;code&amp;gt;root&amp;lt;/code&amp;gt; directory of the flash drive. Similarly, payload extensions should be stored in a &amp;lt;code&amp;gt;/extensions&amp;lt;/code&amp;gt; directory on the flash drive. &lt;br /&gt;
&lt;br /&gt;
In addition, it is possible to transfer payloads and payload extensions to the device via the Signal Owl access point in arming mode using SSH. There they are stored in the &amp;lt;code&amp;gt;/root/payload&amp;lt;/code&amp;gt; directory and Payload Extensions are stored in the &amp;lt;code&amp;gt;/root/payload/extensions&amp;lt;/code&amp;gt; directory.&lt;br /&gt;
&lt;br /&gt;
== Payload Development ==&lt;br /&gt;
&lt;br /&gt;
Payloads for the Signal Owl are written in bash with [https://github.com/hak5darren/USB-Rubber-Ducky/wiki/Duckyscript Ducky Script] and can be created with any standard text editor. All payloads should begin with an interpreter directive, like the shebang &amp;lt;code&amp;gt;#!/bin/bash&amp;lt;/code&amp;gt; for bash payloads and payloads must be named either &amp;lt;code&amp;gt;payload.txt&amp;lt;/code&amp;gt; or &amp;lt;code&amp;gt;payload.sh&amp;lt;/code&amp;gt;. In order to create effective payloads, the Signal Owl comes with several preinstalled penetration testing tools. These are as follows: [https://nmap.org/ Nmap], [https://www.aircrack-ng.org/ Aircrack-ng], [https://github.com/aircrack-ng/mdk4 MDK4] and [https://www.kismetwireless.net/ Kismet].&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Tools&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
• Kismet - detector for wireless networks and devices.&lt;br /&gt;
&lt;br /&gt;
• MDK4 - Wi-Fi testing tool.&lt;br /&gt;
&lt;br /&gt;
• Aircrack-ng Suite - a complete suite of tools for WiFi network security assessment.&lt;br /&gt;
&lt;br /&gt;
• Nmap - open source utility for network discovery and security auditing.&lt;br /&gt;
&lt;br /&gt;
Hak5 offers ready-to-use payloads and payload extensions on their [https://github.com/hak5/signalowl-payloads GitHub repository].&lt;br /&gt;
&lt;br /&gt;
== Implant / mobile operations ==&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Implant operations&lt;br /&gt;
&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
During long term wireless engagements, the Signal Owl may be planted inline between any typical 5V USB power source. This may be useful in situations where ports are occupied, or to deter the unit from being unplugged.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Mobile operations&lt;br /&gt;
&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
The Signal Owl features a low power consumption profile, with a typical power draw averaging 100-200 mAh. Additionally, it is thermally optimized for long term deployments in many indoor environments. One can expect a large 20,000 mAh USB battery bank to operate the unit for up to 4 days.&lt;br /&gt;
&lt;br /&gt;
= Use Cases =&lt;br /&gt;
&lt;br /&gt;
The Signal Owl has a variety of different use cases. Among the most popular ones are classical network mapping and wardriving as well as basic penetration tests for different wireless technologies.&lt;br /&gt;
&lt;br /&gt;
== Fake Beacon Flooding Attack ==&lt;br /&gt;
&lt;br /&gt;
The fake beacon flooding attack is one possible use case for the Signal Owl. With that attack, fake beacon frames are broadcasted to nearby devices. Beacon Frames include various parameters like the SSID, the type of encryption used and timestamps. This results in the creation of multiple fake Wi-Fi networks. Devices with Wi-Fi browsers are then flooded with these fake networks, causing potential network scanner and driver crashes. Furthermore, the attack may prevent legitimate users from finding their networks and lead to denial of service. The preinstalled tools Aircrack-ng and MDK4 were used to create this payload. After powering on the device, multiple fake networks with random SSIDs are generated and broadcasted to all nearby devices.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;bash&amp;quot;&amp;gt;&lt;br /&gt;
#!/bin/bash&lt;br /&gt;
&lt;br /&gt;
LED SETUP&lt;br /&gt;
sleep 10&lt;br /&gt;
airmon-ng check kill&lt;br /&gt;
sleep 10&lt;br /&gt;
#creates monitor mode interface on wirelss card of the Signal Owl&lt;br /&gt;
airmon-ng start wlan0&lt;br /&gt;
sleep 10&lt;br /&gt;
LED ATTACK&lt;br /&gt;
#floods nearby devices with random SSIDs&lt;br /&gt;
mdk4 wlan0mon b -a -m -s 500&lt;br /&gt;
&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The results as seen from a victim running a Windows 10 system are pictured in the figure below.&lt;br /&gt;
&lt;br /&gt;
[[File:FakeBeaconFloodingSignalOwl.png|none|Random SSIDs as seen from a victim Windows 10 client |]][Eigene Darstellung]&lt;br /&gt;
&lt;br /&gt;
== Open AP Nmap Scanner ==&lt;br /&gt;
&lt;br /&gt;
Description: First access points are scanned, then a connection is established to the open access points, after connecting, the nmap scan runs and analyses the AP, &lt;br /&gt;
the results are saved in the loot folder.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
Settings &lt;br /&gt;
&lt;br /&gt;
NMAP_OPTIONS=&amp;quot;-sP&amp;quot;&lt;br /&gt;
&lt;br /&gt;
LOOT_DIR=/root/loot/open_ap_nmap_scan&lt;br /&gt;
&lt;br /&gt;
MAX_CIDR=20&lt;br /&gt;
&lt;br /&gt;
DEBUG=1&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Step-by-step guide&lt;br /&gt;
&lt;br /&gt;
    1) download the payload [https://github.com/hak5/signalowl-payloads/blob/master/payloads/library/wifi/Open-AP-Nmap-Scanner/payload.txt payload]&lt;br /&gt;
    2) store the payload in a usb stick and plug the stick into the signal owl&lt;br /&gt;
    3) after connecting the signal owl, the payload is loaded on the root folder and the scan starts. &lt;br /&gt;
    4) once successfully executed, you can start the signal owl in arming mode and see the results in the loot folder.&lt;br /&gt;
      example loot Directory&lt;br /&gt;
      [[File:ArmingmodeSSHloot.png]][Eigene Darstellung]&lt;br /&gt;
&lt;br /&gt;
= Used Hardware =&lt;br /&gt;
&lt;br /&gt;
[[Signal Owl]]&lt;br /&gt;
&lt;br /&gt;
= References =&lt;br /&gt;
&lt;br /&gt;
*https://docs.hak5.org/signal-owl/&lt;br /&gt;
*https://github.com/hak5/signalowl-payloads&lt;br /&gt;
&lt;br /&gt;
[[Category:Pentesting]]&lt;/div&gt;</summary>
		<author><name>MMayer</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=Hak5_Signal_Owl&amp;diff=10690</id>
		<title>Hak5 Signal Owl</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=Hak5_Signal_Owl&amp;diff=10690"/>
		<updated>2023-01-06T20:17:22Z</updated>

		<summary type="html">&lt;p&gt;MMayer: /* Usage */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= Introduction =&lt;br /&gt;
&lt;br /&gt;
The [https://docs.hak5.org/signal-owl/ Signal Owl] is a hardware product developed by the company [https://shop.hak5.org/ Hak5].&lt;br /&gt;
It is a simple payload-based signals intelligence platform with a unique design for discreet planting or mobile operations on any engagement. The most popular application cases include classic network mapping and basic penetration tests for various wireless technologies.&lt;br /&gt;
&lt;br /&gt;
== Initial Setup ==&lt;br /&gt;
&lt;br /&gt;
When first unboxing the Signal Owl, the device runs a stager firmware that is designed to flash the latest firmware from a USB flash drive. In order to update the Signal Owl, the [https://downloads.hak5.org/owl latest firmware] has to be downloaded. Then, the downloaded file must be copied to the root of an EXT4 or FAT32 formatted USB flash drive. It is important not to modify this file. The next step is to plug the USB flash drive into the powered off Signal Owl. Afterwards, the device has to be powered on by a reliable USB source. The upgrade itself takes approximately five to ten minutes and is indicated by a solid red LED light. When finished, the device will reboot, enter Attack Mode and blink slowly, indicating an error running the payload because no payload has been found.&lt;br /&gt;
&lt;br /&gt;
= Hardware =&lt;br /&gt;
&lt;br /&gt;
[[File:SignalOwlDiagram.png|thumb|500px|frame|Components of the Signal Owl [Eigene Darstellung]]] &lt;br /&gt;
&lt;br /&gt;
The Signal Owl is designed to be rapidly deployed in all kinds of environments, allowing it to be an entry point for network analysis and basic wireless attacks in a variety of locations. With a power consumption of 100-200 mAh and the thermally optimized architecture, mobile operations as well as long term deployments, are enabled.&lt;br /&gt;
&lt;br /&gt;
== Components ==&lt;br /&gt;
&lt;br /&gt;
This device features several components of which some may not be visible to the human eye at first sight.&lt;br /&gt;
&lt;br /&gt;
=== USB Power / Passthrough Plug ===&lt;br /&gt;
&lt;br /&gt;
The USB power or passthrough plug is used to power the device. It can be powered from any reliable USB source.&lt;br /&gt;
&lt;br /&gt;
=== USB 2.0 Passthrough Port ===&lt;br /&gt;
&lt;br /&gt;
The USB 2.0 passthrough port is the port closest to the pigtail. Data and power pass through to that port, allowing for implant operations. If a device such as a keyboard is plugged in between this passthrough port and the power plug is connected to the target computer, the Signal Owl will remain undetected by the operating system. Only the keyboard will be visible on the target computer.&lt;br /&gt;
&lt;br /&gt;
=== USB 2.0 Host Port ===&lt;br /&gt;
&lt;br /&gt;
The USB 2.0 host port is the port farthest away from the pigtail. It is connected to the Linux socket of the Signal Owl and supports USB flash drives formatted with FAT32 and EXT4 file systems as well as many Wi-Fi, Bluetooth and other RF transceivers.&lt;br /&gt;
&lt;br /&gt;
=== Button ===&lt;br /&gt;
&lt;br /&gt;
The button on the bottom of the device is used to enter Arming Mode and to interact with payloads. It is not pressable without special tools like paperclips.&lt;br /&gt;
&lt;br /&gt;
=== Status LED ===&lt;br /&gt;
&lt;br /&gt;
The status LED indicates the current status of the Signal Owl. When it is turned off, it is not visible.&lt;br /&gt;
&lt;br /&gt;
The Signal Owl features a red LED with the following default status indications:&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
!|LED&lt;br /&gt;
!|Status&lt;br /&gt;
|-&lt;br /&gt;
|Blinking&lt;br /&gt;
|Booting&lt;br /&gt;
|-&lt;br /&gt;
|Solid&lt;br /&gt;
|Mounting external storage / Running upgrade&lt;br /&gt;
|-&lt;br /&gt;
|Single blinking&lt;br /&gt;
|Attack Mode&lt;br /&gt;
|-&lt;br /&gt;
|Double blinking&lt;br /&gt;
|Arming Mode&lt;br /&gt;
|-&lt;br /&gt;
|Slow blinking&lt;br /&gt;
|Error running payload&lt;br /&gt;
|-&lt;br /&gt;
|Fast blinking&lt;br /&gt;
|Select Mode (Deprecated from version 1.0.1 onward)&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= Software =&lt;br /&gt;
&lt;br /&gt;
== Modes of Operation ==&lt;br /&gt;
&lt;br /&gt;
The Signal Owl comes with two modes of operation, Attack Mode and Arming Mode. By default, the device will boot into Attack Mode. In order to access Arming Mode, the button on the bottom of the device has to be pressed while in Attack Mode. It is not recommended to press the button during the boot sequence, as this can possibly brick the device and render it useless. The arming mode is used for firmware updates and shell access, while the attack mode is used to load and execute the payload.&lt;br /&gt;
&lt;br /&gt;
=== Attack Mode ===&lt;br /&gt;
&lt;br /&gt;
Attack Mode is the default mode, the Signal Owl boots into. It provides two basic functions, being the payload loading function and the payload execution function. &lt;br /&gt;
&lt;br /&gt;
The payload loading function checks for any USB flash drives plugged into the host port of the device and copies payloads to &amp;lt;code&amp;gt;/root/payload&amp;lt;/code&amp;gt; and extensions to &amp;lt;code&amp;gt;/root/payload/extensions&amp;lt;/code&amp;gt; on the Signal Owl. &lt;br /&gt;
&lt;br /&gt;
The payload execution function is responsible for executing the payload that is currently stored on the root of the Signal Owl. In case no payload is found, the device will blink slowly, indicating the FAIL status.&lt;br /&gt;
&lt;br /&gt;
=== Arming Mode ===&lt;br /&gt;
&lt;br /&gt;
The Arming Mode provides two basic functions, being the firmware update function and the shell access function. The firmware update function checks for any USB flash drives plugged into the host port of the device and copies firmware upgrade files into the internal storage of the device and flashes it. The shell access function starts an open access point with the SSID Owl_xxxx in which xxxx indicates the last two octets of the device&#039;s MAC address. Additionally, a SSH server providing access to the shell of the Signal Owl is enabled.&lt;br /&gt;
&lt;br /&gt;
== Default Settings ==&lt;br /&gt;
&lt;br /&gt;
Default settings that are used in order to access the device via SSH are pictured in the table below.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
!colspan=&amp;quot;2&amp;quot;|Default Settings&lt;br /&gt;
|-&lt;br /&gt;
|Username&lt;br /&gt;
|root&lt;br /&gt;
|-&lt;br /&gt;
|Password&lt;br /&gt;
|hak5owl&lt;br /&gt;
|-&lt;br /&gt;
|SSID&lt;br /&gt;
|Owl_xxxx&lt;br /&gt;
|-&lt;br /&gt;
|IP Address&lt;br /&gt;
|172.16.56.1&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
SSH command: &amp;lt;code&amp;gt;ssh root@172.16.56.1&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The SSID during Arming Mode is Owl_xxxx in which xxxx indicates the last two octets of the devices MAC address.&lt;br /&gt;
&lt;br /&gt;
= Usage =&lt;br /&gt;
&lt;br /&gt;
== Arming Mode connection ==&lt;br /&gt;
&lt;br /&gt;
Step-by-step guide for accessing the arming mode&lt;br /&gt;
&lt;br /&gt;
#Click on the button located on the bottom of the Signal Owl while it is in attack mode. After pressing the button, the signal owl enters the arming mode and provides an open access point with the name Owl xxxx (where xxxx stands for the last two digits of the MAC address of the device).&lt;br /&gt;
#Connect to the access point.&amp;lt;br&amp;gt;[[File:Armingmode.png]][Eigene Darstellung]&lt;br /&gt;
#Now you can connect via ssh by using the [[#Default Settings|default settings]]&lt;br /&gt;
#After successful connection, you will end up in the root directory&amp;lt;br&amp;gt;[[File:ArmingmodeSSH.png]][Eigene Darstellung]&lt;br /&gt;
#Now you can change the files and directories on the Signal Owl to view results, transfer payloads and extensions or to make further changes&lt;br /&gt;
      &lt;br /&gt;
== Directory structure ==&lt;br /&gt;
&lt;br /&gt;
The following directory tree shows the directory structure of the Signal Owl.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
/&lt;br /&gt;
├── loot&lt;br /&gt;
└── payload/&lt;br /&gt;
    └── extensions&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
*Loot - Directory where the Signal Owl saves loot while executing payloads that produce loot.&lt;br /&gt;
*Payload - This directory holds the current payload. &lt;br /&gt;
*Extensions -  This directory holds all extensions.&lt;br /&gt;
&lt;br /&gt;
== Adding Payloads and Extensions ==&lt;br /&gt;
&lt;br /&gt;
Adding a payload can be done in two different ways. Either with a USB flash drive or via the Signal Owl access point to the internal storage of the device. &lt;br /&gt;
&lt;br /&gt;
When booting, payloads on USB flash drives are given priority and will override payloads stored on the Signal Owl. To successfully copy a payload to the Signal Owl, the payload must be named &amp;lt;code&amp;gt;payload.txt&amp;lt;/code&amp;gt; or &amp;lt;code&amp;gt;payload.sh&amp;lt;/code&amp;gt; and it has to be placed in the &amp;lt;code&amp;gt;root&amp;lt;/code&amp;gt; directory of the flash drive. Similarly, payload extensions should be stored in a &amp;lt;code&amp;gt;/extensions&amp;lt;/code&amp;gt; directory on the flash drive. &lt;br /&gt;
&lt;br /&gt;
In addition, it is possible to transfer payloads and payload extensions to the device via the Signal Owl access point in arming mode using SSH. There they are stored in the &amp;lt;code&amp;gt;/root/payload&amp;lt;/code&amp;gt; directory and Payload Extensions are stored in the &amp;lt;code&amp;gt;/root/payload/extensions&amp;lt;/code&amp;gt; directory.&lt;br /&gt;
&lt;br /&gt;
== Payload Development ==&lt;br /&gt;
&lt;br /&gt;
Payloads for the Signal Owl are written in bash with [https://github.com/hak5darren/USB-Rubber-Ducky/wiki/Duckyscript Ducky Script] and can be created with any standard text editor. All payloads should begin with an interpreter directive, like the shebang &amp;lt;code&amp;gt;#!/bin/bash&amp;lt;/code&amp;gt; for bash payloads and payloads must be named either &amp;lt;code&amp;gt;payload.txt&amp;lt;/code&amp;gt; or &amp;lt;code&amp;gt;payload.sh&amp;lt;/code&amp;gt;. In order to create effective payloads, the Signal Owl comes with several preinstalled penetration testing tools. These are as follows: [https://nmap.org/ Nmap], [https://www.aircrack-ng.org/ Aircrack-ng], [https://github.com/aircrack-ng/mdk4 MDK4] and [https://www.kismetwireless.net/ Kismet].&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Tools&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
• Kismet - detector for wireless networks and devices.&lt;br /&gt;
&lt;br /&gt;
• MDK4 - Wi-Fi testing tool.&lt;br /&gt;
&lt;br /&gt;
• Aircrack-ng Suite - a complete suite of tools for WiFi network security assessment.&lt;br /&gt;
&lt;br /&gt;
• Nmap - open source utility for network discovery and security auditing.&lt;br /&gt;
&lt;br /&gt;
Hak5 offers ready-to-use payloads and payload extensions on their [https://github.com/hak5/signalowl-payloads GitHub repository].&lt;br /&gt;
&lt;br /&gt;
== Implant / mobile operations ==&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Implant operations&lt;br /&gt;
&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
During long term wireless engagements, the Signal Owl may be planted inline between any typical 5V USB power source. This may be useful in situations where ports are occupied, or to deter the unit from being unplugged.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Mobile operations&lt;br /&gt;
&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
The Signal Owl features a low power consumption profile, with a typical power draw averaging 100-200 mAh. Additionally, it is thermally optimized for long term deployments in many indoor environments. One can expect a large 20,000 mAh USB battery bank to operate the unit for up to 4 days.&lt;br /&gt;
&lt;br /&gt;
= Use Cases =&lt;br /&gt;
&lt;br /&gt;
The Signal Owl has a variety of different use cases. Among the most popular ones are classical network mapping and wardriving as well as basic penetration tests for different wireless technologies.&lt;br /&gt;
&lt;br /&gt;
== Fake Beacon Flooding Attack ==&lt;br /&gt;
&lt;br /&gt;
The fake beacon flooding attack is one possible use case for the Signal Owl. With that attack, fake beacon frames are broadcasted to nearby devices. Beacon Frames include various parameters like the SSID, the type of encryption used and timestamps. This results in the creation of multiple fake Wi-Fi networks. Devices with Wi-Fi browsers are then flooded with these fake networks, causing potential network scanner and driver crashes. Furthermore, the attack may prevent legitimate users from finding their networks and lead to denial of service. &lt;br /&gt;
To execute the attack with the Signal Owl, the preinstalled tools Aircrack-ng and MDK4 are used. The following bash script is saved as payload.sh and placed on the root of an USB flash drive. Then the USB flash drive is plugged into the Signal Owl. After powering on the device, multiple fake networks with random SSIDs are generated and broadcasted to all nearby devices.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;bash&amp;quot;&amp;gt;&lt;br /&gt;
#!/bin/bash&lt;br /&gt;
&lt;br /&gt;
LED SETUP&lt;br /&gt;
#creates monitor mode interface on wirelss card of the Signal Owl&lt;br /&gt;
airmon-ng start wlan0&lt;br /&gt;
&lt;br /&gt;
LED ATTACK&lt;br /&gt;
#floods nearby devices with random SSIDs&lt;br /&gt;
mdk4 wlan0mon b -w a -m -s 1000&lt;br /&gt;
&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The results as seen from a victim running a Windows 10 system are pictured in the figure below.&lt;br /&gt;
&lt;br /&gt;
[[File:FakeBeaconFloodingSignalOwl.png|none|Random SSIDs as seen from a victim windows 10 client |]][Eigene Darstellung]&lt;br /&gt;
&lt;br /&gt;
== Open AP Nmap Scanner ==&lt;br /&gt;
&lt;br /&gt;
Description: First access points are scanned, then a connection is established to the open access points, after connecting, the nmap scan runs and analyses the AP, &lt;br /&gt;
the results are saved in the loot folder.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
Settings &lt;br /&gt;
&lt;br /&gt;
NMAP_OPTIONS=&amp;quot;-sP&amp;quot;&lt;br /&gt;
&lt;br /&gt;
LOOT_DIR=/root/loot/open_ap_nmap_scan&lt;br /&gt;
&lt;br /&gt;
MAX_CIDR=20&lt;br /&gt;
&lt;br /&gt;
DEBUG=1&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Step-by-step guide&lt;br /&gt;
&lt;br /&gt;
    1) download the payload [https://github.com/hak5/signalowl-payloads/blob/master/payloads/library/wifi/Open-AP-Nmap-Scanner/payload.txt payload]&lt;br /&gt;
    2) store the payload in a usb stick and plug the stick into the signal owl&lt;br /&gt;
    3) after connecting the signal owl, the payload is loaded on the root folder and the scan starts. &lt;br /&gt;
    4) once successfully executed, you can start the signal owl in arming mode and see the results in the loot folder.&lt;br /&gt;
      example loot Directory&lt;br /&gt;
      [[File:ArmingmodeSSHloot.png]][Eigene Darstellung]&lt;br /&gt;
&lt;br /&gt;
= Used Hardware =&lt;br /&gt;
&lt;br /&gt;
[[Signal Owl]]&lt;br /&gt;
&lt;br /&gt;
= References =&lt;br /&gt;
&lt;br /&gt;
*https://docs.hak5.org/signal-owl/&lt;br /&gt;
*https://github.com/hak5/signalowl-payloads&lt;br /&gt;
&lt;br /&gt;
[[Category:Pentesting]]&lt;/div&gt;</summary>
		<author><name>MMayer</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=Hak5_Signal_Owl&amp;diff=10687</id>
		<title>Hak5 Signal Owl</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=Hak5_Signal_Owl&amp;diff=10687"/>
		<updated>2023-01-06T20:01:49Z</updated>

		<summary type="html">&lt;p&gt;MMayer: /* Arming Mode connection */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= Introduction =&lt;br /&gt;
&lt;br /&gt;
The [https://docs.hak5.org/signal-owl/ Signal Owl] is a hardware product developed by the company [https://shop.hak5.org/ Hak5].&lt;br /&gt;
It is a simple payload-based signals intelligence platform with a unique design for discreet planting or mobile operations on any engagement. The most popular application cases include classic network mapping and basic penetration tests for various wireless technologies.&lt;br /&gt;
&lt;br /&gt;
== Initial Setup ==&lt;br /&gt;
&lt;br /&gt;
When first unboxing the Signal Owl, the device runs a stager firmware that is designed to flash the latest firmware from a USB flash drive. In order to update the Signal Owl, the [https://downloads.hak5.org/owl latest firmware] has to be downloaded. Then, the downloaded file must be copied to the root of an EXT4 or FAT32 formatted USB flash drive. It is important not to modify this file. The next step is to plug the USB flash drive into the powered off Signal Owl. Afterwards, the device has to be powered on by a reliable USB source. The upgrade itself takes approximately five to ten minutes and is indicated by a solid red LED light. When finished, the device will reboot, enter Attack Mode and blink slowly, indicating an error running the payload because no payload has been found.&lt;br /&gt;
&lt;br /&gt;
= Hardware =&lt;br /&gt;
&lt;br /&gt;
[[File:SignalOwlDiagram.png|thumb|500px|frame|Components of the Signal Owl [Eigene Darstellung]]] &lt;br /&gt;
&lt;br /&gt;
The Signal Owl is designed to be rapidly deployed in all kinds of environments, allowing it to be an entry point for network analysis and basic wireless attacks in a variety of locations. With a power consumption of 100-200 mAh and the thermally optimized architecture, mobile operations as well as long term deployments, are enabled.&lt;br /&gt;
&lt;br /&gt;
== Components ==&lt;br /&gt;
&lt;br /&gt;
This device features several components of which some may not be visible to the human eye at first sight.&lt;br /&gt;
&lt;br /&gt;
=== USB Power / Passthrough Plug ===&lt;br /&gt;
&lt;br /&gt;
The USB power or passthrough plug is used to power the device. It can be powered from any reliable USB source.&lt;br /&gt;
&lt;br /&gt;
=== USB 2.0 Passthrough Port ===&lt;br /&gt;
&lt;br /&gt;
The USB 2.0 passthrough port is the port closest to the pigtail. Data and power pass through to that port, allowing for implant operations. If a device such as a keyboard is plugged in between this passthrough port and the power plug is connected to the target computer, the Signal Owl will remain undetected by the operating system. Only the keyboard will be visible on the target computer.&lt;br /&gt;
&lt;br /&gt;
=== USB 2.0 Host Port ===&lt;br /&gt;
&lt;br /&gt;
The USB 2.0 host port is the port farthest away from the pigtail. It is connected to the Linux socket of the Signal Owl and supports USB flash drives formatted with FAT32 and EXT4 file systems as well as many Wi-Fi, Bluetooth and other RF transceivers.&lt;br /&gt;
&lt;br /&gt;
=== Button ===&lt;br /&gt;
&lt;br /&gt;
The button on the bottom of the device is used to enter Arming Mode and to interact with payloads. It is not pressable without special tools like paperclips.&lt;br /&gt;
&lt;br /&gt;
=== Status LED ===&lt;br /&gt;
&lt;br /&gt;
The status LED indicates the current status of the Signal Owl. When it is turned off, it is not visible.&lt;br /&gt;
&lt;br /&gt;
The Signal Owl features a red LED with the following default status indications:&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
!|LED&lt;br /&gt;
!|Status&lt;br /&gt;
|-&lt;br /&gt;
|Blinking&lt;br /&gt;
|Booting&lt;br /&gt;
|-&lt;br /&gt;
|Solid&lt;br /&gt;
|Mounting external storage / Running upgrade&lt;br /&gt;
|-&lt;br /&gt;
|Single blinking&lt;br /&gt;
|Attack Mode&lt;br /&gt;
|-&lt;br /&gt;
|Double blinking&lt;br /&gt;
|Arming Mode&lt;br /&gt;
|-&lt;br /&gt;
|Slow blinking&lt;br /&gt;
|Error running payload&lt;br /&gt;
|-&lt;br /&gt;
|Fast blinking&lt;br /&gt;
|Select Mode (Deprecated from version 1.0.1 onward)&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= Software =&lt;br /&gt;
&lt;br /&gt;
== Modes of Operation ==&lt;br /&gt;
&lt;br /&gt;
The Signal Owl comes with two modes of operation, Attack Mode and Arming Mode. By default, the device will boot into Attack Mode. In order to access Arming Mode, the button on the bottom of the device has to be pressed while in Attack Mode. It is not recommended to press the button during the boot sequence, as this can possibly brick the device and render it useless. The arming mode is used for firmware updates and shell access, while the attack mode is used to load and execute the payload.&lt;br /&gt;
&lt;br /&gt;
=== Attack Mode ===&lt;br /&gt;
&lt;br /&gt;
Attack Mode is the default mode, the Signal Owl boots into. It provides two basic functions, being the payload loading function and the payload execution function. &lt;br /&gt;
&lt;br /&gt;
The payload loading function checks for any USB flash drives plugged into the host port of the device and copies payloads to &amp;lt;code&amp;gt;/root/payload&amp;lt;/code&amp;gt; and extensions to &amp;lt;code&amp;gt;/root/payload/extensions&amp;lt;/code&amp;gt; on the Signal Owl. &lt;br /&gt;
&lt;br /&gt;
The payload execution function is responsible for executing the payload that is currently stored on the root of the Signal Owl. In case no payload is found, the device will blink slowly, indicating the FAIL status.&lt;br /&gt;
&lt;br /&gt;
=== Arming Mode ===&lt;br /&gt;
&lt;br /&gt;
The Arming Mode provides two basic functions, being the firmware update function and the shell access function. The firmware update function checks for any USB flash drives plugged into the host port of the device and copies firmware upgrade files into the internal storage of the device and flashes it. The shell access function starts an open access point with the SSID Owl_xxxx in which xxxx indicates the last two octets of the device&#039;s MAC address. Additionally, a SSH server providing access to the shell of the Signal Owl is enabled.&lt;br /&gt;
&lt;br /&gt;
== Default Settings ==&lt;br /&gt;
&lt;br /&gt;
Default settings that are used in order to access the device via SSH are pictured in the table below.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
!colspan=&amp;quot;2&amp;quot;|Default Settings&lt;br /&gt;
|-&lt;br /&gt;
|Username&lt;br /&gt;
|root&lt;br /&gt;
|-&lt;br /&gt;
|Password&lt;br /&gt;
|hak5owl&lt;br /&gt;
|-&lt;br /&gt;
|SSID&lt;br /&gt;
|Owl_xxxx&lt;br /&gt;
|-&lt;br /&gt;
|IP Address&lt;br /&gt;
|172.16.56.1&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
SSH command: &amp;lt;code&amp;gt;ssh root@172.16.56.1&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The SSID during Arming Mode is Owl_xxxx in which xxxx indicates the last two octets of the devices MAC address.&lt;br /&gt;
&lt;br /&gt;
= Usage =&lt;br /&gt;
&lt;br /&gt;
== Arming Mode connection ==&lt;br /&gt;
&lt;br /&gt;
Step-by-step guide for accessing the arming mode&lt;br /&gt;
&lt;br /&gt;
#Click on the button located on the bottom of the Signal Owl while it is in attack mode. After pressing the button, the signal owl enters the arming mode and provides an open access point with the name Owl xxxx (where xxxx stands for the last two digits of the MAC address of the device).&lt;br /&gt;
#Connect to the access point.&amp;lt;br&amp;gt;[[File:Armingmode.png]][Eigene Darstellung]&lt;br /&gt;
#Now you can connect via ssh by using the [[#Default Settings|default settings]]&lt;br /&gt;
#After successful connection, you will end up in the root directory&amp;lt;br&amp;gt;[[File:ArmingmodeSSH.png]][Eigene Darstellung]&lt;br /&gt;
#Now you can change the files and directories on the Signal Owl to view results, transfer payloads and extensions or to make further changes&lt;br /&gt;
      &lt;br /&gt;
example Directory structure&lt;br /&gt;
[[File:ArmingmodeSSHdirectories.png]][Eigene Darstellung]&lt;br /&gt;
&lt;br /&gt;
== Adding Payloads and Extensions ==&lt;br /&gt;
&lt;br /&gt;
Adding a payload can be done in two different ways. Either with a USB flash drive or via the Signal Owl access point to the internal storage of the device. &lt;br /&gt;
&lt;br /&gt;
When booting, payloads on USB flash drives are given priority and will override payloads stored on the Signal Owl. To successfully copy a payload to the Signal Owl, the payload must be named &amp;lt;code&amp;gt;payload.txt&amp;lt;/code&amp;gt; or &amp;lt;code&amp;gt;payload.sh&amp;lt;/code&amp;gt; and it has to be placed in the &amp;lt;code&amp;gt;root&amp;lt;/code&amp;gt; directory of the flash drive. Similarly, payload extensions should be stored in a &amp;lt;code&amp;gt;/extensions&amp;lt;/code&amp;gt; directory on the flash drive. &lt;br /&gt;
&lt;br /&gt;
In addition, it is possible to transfer payloads and payload extensions to the device via the Signal Owl access point in arming mode using SSH. There they are stored in the &amp;lt;code&amp;gt;/root/payload&amp;lt;/code&amp;gt; directory and Payload Extensions are stored in the &amp;lt;code&amp;gt;/root/payload/extensions&amp;lt;/code&amp;gt; directory.&lt;br /&gt;
&lt;br /&gt;
== Payload Development ==&lt;br /&gt;
&lt;br /&gt;
Payloads for the Signal Owl are written in bash with [https://github.com/hak5darren/USB-Rubber-Ducky/wiki/Duckyscript Ducky Script] and can be created with any standard text editor. All payloads should begin with an interpreter directive, like the shebang &amp;lt;code&amp;gt;#!/bin/bash&amp;lt;/code&amp;gt; for bash payloads and payloads must be named either &amp;lt;code&amp;gt;payload.txt&amp;lt;/code&amp;gt; or &amp;lt;code&amp;gt;payload.sh&amp;lt;/code&amp;gt;. In order to create effective payloads, the Signal Owl comes with several preinstalled penetration testing tools. These are as follows: [https://nmap.org/ Nmap], [https://www.aircrack-ng.org/ Aircrack-ng], [https://github.com/aircrack-ng/mdk4 MDK4] and [https://www.kismetwireless.net/ Kismet].&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Tools&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
• Kismet - detector for wireless networks and devices.&lt;br /&gt;
&lt;br /&gt;
• MDK4 - Wi-Fi testing tool.&lt;br /&gt;
&lt;br /&gt;
• Aircrack-ng Suite - a complete suite of tools for WiFi network security assessment.&lt;br /&gt;
&lt;br /&gt;
• Nmap - open source utility for network discovery and security auditing.&lt;br /&gt;
&lt;br /&gt;
Hak5 offers ready-to-use payloads and payload extensions on their [https://github.com/hak5/signalowl-payloads GitHub repository].&lt;br /&gt;
&lt;br /&gt;
== Implant / mobile operations ==&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Implant operations&lt;br /&gt;
&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
During long term wireless engagements, the Signal Owl may be planted inline between any typical 5V USB power source. This may be useful in situations where ports are occupied, or to deter the unit from being unplugged.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Mobile operations&lt;br /&gt;
&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
The Signal Owl features a low power consumption profile, with a typical power draw averaging 100-200 mAh. Additionally, it is thermally optimized for long term deployments in many indoor environments. One can expect a large 20,000 mAh USB battery bank to operate the unit for up to 4 days.&lt;br /&gt;
&lt;br /&gt;
= Use Cases =&lt;br /&gt;
&lt;br /&gt;
The Signal Owl has a variety of different use cases. Among the most popular ones are classical network mapping and wardriving as well as basic penetration tests for different wireless technologies.&lt;br /&gt;
&lt;br /&gt;
== Fake Beacon Flooding Attack ==&lt;br /&gt;
&lt;br /&gt;
The fake beacon flooding attack is one possible use case for the Signal Owl. With that attack, fake beacon frames are broadcasted to nearby devices. Beacon Frames include various parameters like the SSID, the type of encryption used and timestamps. This results in the creation of multiple fake Wi-Fi networks. Devices with Wi-Fi browsers are then flooded with these fake networks, causing potential network scanner and driver crashes. Furthermore, the attack may prevent legitimate users from finding their networks and lead to denial of service. &lt;br /&gt;
To execute the attack with the Signal Owl, the preinstalled tools Aircrack-ng and MDK4 are used. The following bash script is saved as payload.sh and placed on the root of an USB flash drive. Then the USB flash drive is plugged into the Signal Owl. After powering on the device, multiple fake networks with random SSIDs are generated and broadcasted to all nearby devices.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;bash&amp;quot;&amp;gt;&lt;br /&gt;
#!/bin/bash&lt;br /&gt;
&lt;br /&gt;
LED SETUP&lt;br /&gt;
#creates monitor mode interface on wirelss card of the Signal Owl&lt;br /&gt;
airmon-ng start wlan0&lt;br /&gt;
&lt;br /&gt;
LED ATTACK&lt;br /&gt;
#floods nearby devices with random SSIDs&lt;br /&gt;
mdk4 wlan0mon b -w a -m -s 1000&lt;br /&gt;
&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The results as seen from a victim running a Windows 10 system are pictured in the figure below.&lt;br /&gt;
&lt;br /&gt;
[[File:FakeBeaconFloodingSignalOwl.png|none|Random SSIDs as seen from a victim windows 10 client |]][Eigene Darstellung]&lt;br /&gt;
&lt;br /&gt;
== Open AP Nmap Scanner ==&lt;br /&gt;
&lt;br /&gt;
Description: First access points are scanned, then a connection is established to the open access points, after connecting, the nmap scan runs and analyses the AP, &lt;br /&gt;
the results are saved in the loot folder.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
Settings &lt;br /&gt;
&lt;br /&gt;
NMAP_OPTIONS=&amp;quot;-sP&amp;quot;&lt;br /&gt;
&lt;br /&gt;
LOOT_DIR=/root/loot/open_ap_nmap_scan&lt;br /&gt;
&lt;br /&gt;
MAX_CIDR=20&lt;br /&gt;
&lt;br /&gt;
DEBUG=1&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Step-by-step guide&lt;br /&gt;
&lt;br /&gt;
    1) download the payload [https://github.com/hak5/signalowl-payloads/blob/master/payloads/library/wifi/Open-AP-Nmap-Scanner/payload.txt payload]&lt;br /&gt;
    2) store the payload in a usb stick and plug the stick into the signal owl&lt;br /&gt;
    3) after connecting the signal owl, the payload is loaded on the root folder and the scan starts. &lt;br /&gt;
    4) once successfully executed, you can start the signal owl in arming mode and see the results in the loot folder.&lt;br /&gt;
      example loot Directory&lt;br /&gt;
      [[File:ArmingmodeSSHloot.png]][Eigene Darstellung]&lt;br /&gt;
&lt;br /&gt;
= Used Hardware =&lt;br /&gt;
&lt;br /&gt;
[[Signal Owl]]&lt;br /&gt;
&lt;br /&gt;
= References =&lt;br /&gt;
&lt;br /&gt;
*https://docs.hak5.org/signal-owl/&lt;br /&gt;
*https://github.com/hak5/signalowl-payloads&lt;br /&gt;
&lt;br /&gt;
[[Category:Pentesting]]&lt;/div&gt;</summary>
		<author><name>MMayer</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=Hak5_Signal_Owl&amp;diff=10647</id>
		<title>Hak5 Signal Owl</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=Hak5_Signal_Owl&amp;diff=10647"/>
		<updated>2023-01-06T14:52:36Z</updated>

		<summary type="html">&lt;p&gt;MMayer: /* Fake Beacon Flooding Attack */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= Introduction =&lt;br /&gt;
&lt;br /&gt;
The [https://docs.hak5.org/signal-owl/ Signal Owl] is a hardware product developed by the company [https://shop.hak5.org/ Hak5].&lt;br /&gt;
It is a simple payload-based signals intelligence platform with a unique design for discreet planting or mobile operations on any engagement. The most popular application cases include classic network mapping and basic penetration tests for various wireless technologies.&lt;br /&gt;
&lt;br /&gt;
== Initial Setup ==&lt;br /&gt;
&lt;br /&gt;
When first unboxing the Signal Owl, the device runs a stager firmware that is designed to flash the latest firmware from a USB flash drive. In order to update the Signal Owl, the [https://downloads.hak5.org/owl latest firmware] has to be downloaded. Then, the downloaded file must be copied to the root of an EXT4 or FAT32 formatted USB flash drive. It is important not to modify this file. The next step is to plug the USB flash drive into the powered off Signal Owl. Afterwards, the device has to be powered on by a reliable USB source. The upgrade itself takes approximately five to ten minutes and is indicated by a solid red LED light. When finished, the device will reboot, enter Attack Mode and blink slowly, indicating an error running the payload because no payload has been found.&lt;br /&gt;
&lt;br /&gt;
= Hardware =&lt;br /&gt;
&lt;br /&gt;
[[File:SignalOwlDiagram.png|thumb|500px|frame|Components of the Signal Owl [Eigene Darstellung]]] &lt;br /&gt;
&lt;br /&gt;
The Signal Owl is designed to be rapidly deployed in all kinds of environments, allowing it to be an entry point for network analysis and basic wireless attacks in a variety of locations. With a power consumption of 100-200 mAh and the thermally optimized architecture, mobile operations as well as long term deployments, are enabled.&lt;br /&gt;
&lt;br /&gt;
== Components ==&lt;br /&gt;
&lt;br /&gt;
This device features several components of which some may not be visible to the human eye at first sight.&lt;br /&gt;
&lt;br /&gt;
=== USB Power / Passthrough Plug ===&lt;br /&gt;
&lt;br /&gt;
The USB power or passthrough plug is used to power the device. It can be powered from any reliable USB source.&lt;br /&gt;
&lt;br /&gt;
=== USB 2.0 Passthrough Port ===&lt;br /&gt;
&lt;br /&gt;
The USB 2.0 passthrough port is the port closest to the pigtail. Data and power pass through to that port, allowing for implant operations. If a device such as a keyboard is plugged in between this passthrough port and the power plug is connected to the target computer, the Signal Owl will remain undetected by the operating system. Only the keyboard will be visible on the target computer.&lt;br /&gt;
&lt;br /&gt;
=== USB 2.0 Host Port ===&lt;br /&gt;
&lt;br /&gt;
The USB 2.0 host port is the port farthest away from the pigtail. It is connected to the Linux socket of the Signal Owl and supports USB flash drives formatted with FAT32 and EXT4 file systems as well as many Wi-Fi, Bluetooth and other RF transceivers.&lt;br /&gt;
&lt;br /&gt;
=== Button ===&lt;br /&gt;
&lt;br /&gt;
The button on the bottom of the device is used to enter Arming Mode and to interact with payloads. It is not pressable without special tools like paperclips.&lt;br /&gt;
&lt;br /&gt;
=== Status LED ===&lt;br /&gt;
&lt;br /&gt;
The status LED indicates the current status of the Signal Owl. When it is turned off, it is not visible.&lt;br /&gt;
&lt;br /&gt;
The Signal Owl features a red LED with the following default status indications:&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
!|LED&lt;br /&gt;
!|Status&lt;br /&gt;
|-&lt;br /&gt;
|Blinking&lt;br /&gt;
|Booting&lt;br /&gt;
|-&lt;br /&gt;
|Solid&lt;br /&gt;
|Mounting external storage / Running upgrade&lt;br /&gt;
|-&lt;br /&gt;
|Single blinking&lt;br /&gt;
|Attack Mode&lt;br /&gt;
|-&lt;br /&gt;
|Double blinking&lt;br /&gt;
|Arming Mode&lt;br /&gt;
|-&lt;br /&gt;
|Slow blinking&lt;br /&gt;
|Error running payload&lt;br /&gt;
|-&lt;br /&gt;
|Fast blinking&lt;br /&gt;
|Select Mode (Deprecated from version 1.0.1 onward)&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= Software =&lt;br /&gt;
&lt;br /&gt;
== Modes of Operation ==&lt;br /&gt;
&lt;br /&gt;
The Signal Owl comes with two modes of operation, Attack Mode and Arming Mode. By default, the device will boot into Attack Mode. In order to access Arming Mode, the button on the bottom of the device has to be pressed while in Attack Mode. It is not recommended to press the button during the boot sequence, as this can possibly brick the device and render it useless. The arming mode is used for firmware updates and shell access, while the attack mode is used to load and execute the payload.&lt;br /&gt;
&lt;br /&gt;
=== Attack Mode ===&lt;br /&gt;
&lt;br /&gt;
Attack Mode is the default mode, the Signal Owl boots into. It provides two basic functions, being the payload loading function and the payload execution function. &lt;br /&gt;
&lt;br /&gt;
The payload loading function checks for any USB flash drives plugged into the host port of the device and copies payloads to &amp;lt;code&amp;gt;/root/payload&amp;lt;/code&amp;gt; and extensions to &amp;lt;code&amp;gt;/root/payload/extensions&amp;lt;/code&amp;gt; on the Signal Owl. &lt;br /&gt;
&lt;br /&gt;
The payload execution function is responsible for executing the payload that is currently stored on the root of the Signal Owl. In case no payload is found, the device will blink slowly, indicating the FAIL status.&lt;br /&gt;
&lt;br /&gt;
=== Arming Mode ===&lt;br /&gt;
&lt;br /&gt;
The Arming Mode provides two basic functions, being the firmware update function and the shell access function. The firmware update function checks for any USB flash drives plugged into the host port of the device and copies firmware upgrade files into the internal storage of the device and flashes it. The shell access function starts an open access point with the SSID Owl_xxxx in which xxxx indicates the last two octets of the device&#039;s MAC address. Additionally, a SSH server providing access to the shell of the Signal Owl is enabled.&lt;br /&gt;
&lt;br /&gt;
== Default Settings ==&lt;br /&gt;
&lt;br /&gt;
Default settings that are used in order to access the device via SSH are pictured in the table below.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
!colspan=&amp;quot;2&amp;quot;|Default Settings&lt;br /&gt;
|-&lt;br /&gt;
|Username&lt;br /&gt;
|root&lt;br /&gt;
|-&lt;br /&gt;
|Password&lt;br /&gt;
|hak5owl&lt;br /&gt;
|-&lt;br /&gt;
|SSID&lt;br /&gt;
|Owl_xxxx&lt;br /&gt;
|-&lt;br /&gt;
|IP Address&lt;br /&gt;
|172.16.56.1&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
SSH command: &amp;lt;code&amp;gt;ssh root@172.16.56.1&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The SSID during Arming Mode is Owl_xxxx in which xxxx indicates the last two octets of the devices MAC address.&lt;br /&gt;
&lt;br /&gt;
= Usage =&lt;br /&gt;
&lt;br /&gt;
== Arming Mode connection ==&lt;br /&gt;
&lt;br /&gt;
Step-by-step guide for accessing the arming mode&lt;br /&gt;
&lt;br /&gt;
#Click on the button located on the bottom of the Signal Owl while it is in attack mode. After pressing the button, the signal owl enters the arming mode and provides an open access point with the name Owl xxxx (where xxxx stands for the last two digits of the MAC address of the device).&lt;br /&gt;
#Connect to the access point.&amp;lt;br&amp;gt;[[File:Armingmode.png]][Eigene Darstellung]&lt;br /&gt;
#Now you can connect via ssh by using the [[#Default Settings]]&lt;br /&gt;
#After successful connection, you will end up in the root directory&amp;lt;br&amp;gt;[[File:ArmingmodeSSH.png]][Eigene Darstellung]&lt;br /&gt;
#Now you can change the files and directories on the Signal Owl to view results, transfer payloads and extensions or to make further changes&lt;br /&gt;
      &lt;br /&gt;
example Directory structure&lt;br /&gt;
[[File:ArmingmodeSSHdirectories.png]][Eigene Darstellung]&lt;br /&gt;
&lt;br /&gt;
== Adding Payloads and Extensions ==&lt;br /&gt;
&lt;br /&gt;
Adding a payload can be done in two different ways. Either with a USB flash drive or via the Signal Owl access point to the internal storage of the device. &lt;br /&gt;
&lt;br /&gt;
When booting, payloads on USB flash drives are given priority and will override payloads stored on the Signal Owl. To successfully copy a payload to the Signal Owl, the payload must be named &amp;lt;code&amp;gt;payload.txt&amp;lt;/code&amp;gt; or &amp;lt;code&amp;gt;payload.sh&amp;lt;/code&amp;gt; and it has to be placed in the &amp;lt;code&amp;gt;root&amp;lt;/code&amp;gt; directory of the flash drive. Similarly, payload extensions should be stored in a &amp;lt;code&amp;gt;/extensions&amp;lt;/code&amp;gt; directory on the flash drive. &lt;br /&gt;
&lt;br /&gt;
In addition, it is possible to transfer payloads and payload extensions to the device via the Signal Owl access point in arming mode using SSH. There they are stored in the &amp;lt;code&amp;gt;/root/payload&amp;lt;/code&amp;gt; directory and Payload Extensions are stored in the &amp;lt;code&amp;gt;/root/payload/extensions&amp;lt;/code&amp;gt; directory.&lt;br /&gt;
&lt;br /&gt;
== Payload Development ==&lt;br /&gt;
&lt;br /&gt;
Payloads for the Signal Owl are written in bash with [https://github.com/hak5darren/USB-Rubber-Ducky/wiki/Duckyscript Ducky Script] and can be created with any standard text editor. All payloads should begin with an interpreter directive, like the shebang &amp;lt;code&amp;gt;#!/bin/bash&amp;lt;/code&amp;gt; for bash payloads and payloads must be named either &amp;lt;code&amp;gt;payload.txt&amp;lt;/code&amp;gt; or &amp;lt;code&amp;gt;payload.sh&amp;lt;/code&amp;gt;. In order to create effective payloads, the Signal Owl comes with several preinstalled penetration testing tools. These are as follows: [https://nmap.org/ Nmap], [https://www.aircrack-ng.org/ Aircrack-ng], [https://github.com/aircrack-ng/mdk4 MDK4] and [https://www.kismetwireless.net/ Kismet].&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Tools&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
• Kismet - detector for wireless networks and devices.&lt;br /&gt;
&lt;br /&gt;
• MDK4 - Wi-Fi testing tool.&lt;br /&gt;
&lt;br /&gt;
• Aircrack-ng Suite - a complete suite of tools for WiFi network security assessment.&lt;br /&gt;
&lt;br /&gt;
• Nmap - open source utility for network discovery and security auditing.&lt;br /&gt;
&lt;br /&gt;
Hak5 offers ready-to-use payloads and payload extensions on their [https://github.com/hak5/signalowl-payloads GitHub repository].&lt;br /&gt;
&lt;br /&gt;
== Implant / mobile operations ==&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Implant operations&lt;br /&gt;
&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
During long term wireless engagements, the Signal Owl may be planted inline between any typical 5V USB power source. This may be useful in situations where ports are occupied, or to deter the unit from being unplugged.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Mobile operations&lt;br /&gt;
&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
The Signal Owl features a low power consumption profile, with a typical power draw averaging 100-200 mAh. Additionally, it is thermally optimized for long term deployments in many indoor environments. One can expect a large 20,000 mAh USB battery bank to operate the unit for up to 4 days.&lt;br /&gt;
&lt;br /&gt;
= Use Cases =&lt;br /&gt;
&lt;br /&gt;
The Signal Owl has a variety of different use cases. Among the most popular ones are classical network mapping and wardriving as well as basic penetration tests for different wireless technologies.&lt;br /&gt;
&lt;br /&gt;
== Fake Beacon Flooding Attack ==&lt;br /&gt;
&lt;br /&gt;
The fake beacon flooding attack is one possible use case for the Signal Owl. With that attack, fake beacon frames are broadcasted to nearby devices. Beacon Frames include various parameters like the SSID, the type of encryption used and timestamps. This results in the creation of multiple fake Wi-Fi networks. Devices with Wi-Fi browsers are then flooded with these fake networks, causing potential network scanner and driver crashes. Furthermore, the attack may prevent legitimate users from finding their networks and lead to denial of service. &lt;br /&gt;
To execute the attack with the Signal Owl, the preinstalled tools Aircrack-ng and MDK4 are used. The following bash script is saved as payload.sh and placed on the root of an USB flash drive. Then the USB flash drive is plugged into the Signal Owl. After powering on the device, multiple fake networks with random SSIDs are generated and broadcasted to all nearby devices.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;bash&amp;quot;&amp;gt;&lt;br /&gt;
#!/bin/bash&lt;br /&gt;
&lt;br /&gt;
LED SETUP&lt;br /&gt;
#creates monitor mode interface on wirelss card of the Signal Owl&lt;br /&gt;
airmon-ng start wlan0&lt;br /&gt;
&lt;br /&gt;
LED ATTACK&lt;br /&gt;
#floods nearby devices with random SSIDs&lt;br /&gt;
mdk4 wlan0mon b -w a -m -s 1000&lt;br /&gt;
&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The results as seen from a victim running a Windows 10 system are pictured in the figure below.&lt;br /&gt;
&lt;br /&gt;
[[File:FakeBeaconFloodingSignalOwl.png|none|Random SSIDs as seen from a victim windows 10 client |]][Eigene Darstellung]&lt;br /&gt;
&lt;br /&gt;
== Open AP Nmap Scanner ==&lt;br /&gt;
&lt;br /&gt;
Description: First access points are scanned, then a connection is established to the open access points, after connecting, the nmap scan runs and analyses the AP, &lt;br /&gt;
the results are saved in the loot folder.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
Settings &lt;br /&gt;
&lt;br /&gt;
NMAP_OPTIONS=&amp;quot;-sP&amp;quot;&lt;br /&gt;
&lt;br /&gt;
LOOT_DIR=/root/loot/open_ap_nmap_scan&lt;br /&gt;
&lt;br /&gt;
MAX_CIDR=20&lt;br /&gt;
&lt;br /&gt;
DEBUG=1&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Step-by-step guide&lt;br /&gt;
&lt;br /&gt;
    1) download the payload [https://github.com/hak5/signalowl-payloads/blob/master/payloads/library/wifi/Open-AP-Nmap-Scanner/payload.txt payload]&lt;br /&gt;
    2) store the payload in a usb stick and plug the stick into the signal owl&lt;br /&gt;
    3) after connecting the signal owl, the payload is loaded on the root folder and the scan starts. &lt;br /&gt;
    4) once successfully executed, you can start the signal owl in arming mode and see the results in the loot folder.&lt;br /&gt;
      example loot Directory&lt;br /&gt;
      [[File:ArmingmodeSSHloot.png]][Eigene Darstellung]&lt;br /&gt;
&lt;br /&gt;
= Used Hardware =&lt;br /&gt;
&lt;br /&gt;
[[Signal Owl]]&lt;br /&gt;
&lt;br /&gt;
= References =&lt;br /&gt;
&lt;br /&gt;
*https://docs.hak5.org/signal-owl/&lt;br /&gt;
*https://github.com/hak5/signalowl-payloads&lt;br /&gt;
&lt;br /&gt;
[[Category:Pentesting]]&lt;/div&gt;</summary>
		<author><name>MMayer</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=Hak5_Signal_Owl&amp;diff=10646</id>
		<title>Hak5 Signal Owl</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=Hak5_Signal_Owl&amp;diff=10646"/>
		<updated>2023-01-06T14:45:13Z</updated>

		<summary type="html">&lt;p&gt;MMayer: /* Arming Mode connection */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= Introduction =&lt;br /&gt;
&lt;br /&gt;
The [https://docs.hak5.org/signal-owl/ Signal Owl] is a hardware product developed by the company [https://shop.hak5.org/ Hak5].&lt;br /&gt;
It is a simple payload-based signals intelligence platform with a unique design for discreet planting or mobile operations on any engagement. The most popular application cases include classic network mapping and basic penetration tests for various wireless technologies.&lt;br /&gt;
&lt;br /&gt;
== Initial Setup ==&lt;br /&gt;
&lt;br /&gt;
When first unboxing the Signal Owl, the device runs a stager firmware that is designed to flash the latest firmware from a USB flash drive. In order to update the Signal Owl, the [https://downloads.hak5.org/owl latest firmware] has to be downloaded. Then, the downloaded file must be copied to the root of an EXT4 or FAT32 formatted USB flash drive. It is important not to modify this file. The next step is to plug the USB flash drive into the powered off Signal Owl. Afterwards, the device has to be powered on by a reliable USB source. The upgrade itself takes approximately five to ten minutes and is indicated by a solid red LED light. When finished, the device will reboot, enter Attack Mode and blink slowly, indicating an error running the payload because no payload has been found.&lt;br /&gt;
&lt;br /&gt;
= Hardware =&lt;br /&gt;
&lt;br /&gt;
[[File:SignalOwlDiagram.png|thumb|500px|frame|Components of the Signal Owl [Eigene Darstellung]]] &lt;br /&gt;
&lt;br /&gt;
The Signal Owl is designed to be rapidly deployed in all kinds of environments, allowing it to be an entry point for network analysis and basic wireless attacks in a variety of locations. With a power consumption of 100-200 mAh and the thermally optimized architecture, mobile operations as well as long term deployments, are enabled.&lt;br /&gt;
&lt;br /&gt;
== Components ==&lt;br /&gt;
&lt;br /&gt;
This device features several components of which some may not be visible to the human eye at first sight.&lt;br /&gt;
&lt;br /&gt;
=== USB Power / Passthrough Plug ===&lt;br /&gt;
&lt;br /&gt;
The USB power or passthrough plug is used to power the device. It can be powered from any reliable USB source.&lt;br /&gt;
&lt;br /&gt;
=== USB 2.0 Passthrough Port ===&lt;br /&gt;
&lt;br /&gt;
The USB 2.0 passthrough port is the port closest to the pigtail. Data and power pass through to that port, allowing for implant operations. If a device such as a keyboard is plugged in between this passthrough port and the power plug is connected to the target computer, the Signal Owl will remain undetected by the operating system. Only the keyboard will be visible on the target computer.&lt;br /&gt;
&lt;br /&gt;
=== USB 2.0 Host Port ===&lt;br /&gt;
&lt;br /&gt;
The USB 2.0 host port is the port farthest away from the pigtail. It is connected to the Linux socket of the Signal Owl and supports USB flash drives formatted with FAT32 and EXT4 file systems as well as many Wi-Fi, Bluetooth and other RF transceivers.&lt;br /&gt;
&lt;br /&gt;
=== Button ===&lt;br /&gt;
&lt;br /&gt;
The button on the bottom of the device is used to enter Arming Mode and to interact with payloads. It is not pressable without special tools like paperclips.&lt;br /&gt;
&lt;br /&gt;
=== Status LED ===&lt;br /&gt;
&lt;br /&gt;
The status LED indicates the current status of the Signal Owl. When it is turned off, it is not visible.&lt;br /&gt;
&lt;br /&gt;
The Signal Owl features a red LED with the following default status indications:&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
!|LED&lt;br /&gt;
!|Status&lt;br /&gt;
|-&lt;br /&gt;
|Blinking&lt;br /&gt;
|Booting&lt;br /&gt;
|-&lt;br /&gt;
|Solid&lt;br /&gt;
|Mounting external storage / Running upgrade&lt;br /&gt;
|-&lt;br /&gt;
|Single blinking&lt;br /&gt;
|Attack Mode&lt;br /&gt;
|-&lt;br /&gt;
|Double blinking&lt;br /&gt;
|Arming Mode&lt;br /&gt;
|-&lt;br /&gt;
|Slow blinking&lt;br /&gt;
|Error running payload&lt;br /&gt;
|-&lt;br /&gt;
|Fast blinking&lt;br /&gt;
|Select Mode (Deprecated from version 1.0.1 onward)&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= Software =&lt;br /&gt;
&lt;br /&gt;
== Modes of Operation ==&lt;br /&gt;
&lt;br /&gt;
The Signal Owl comes with two modes of operation, Attack Mode and Arming Mode. By default, the device will boot into Attack Mode. In order to access Arming Mode, the button on the bottom of the device has to be pressed while in Attack Mode. It is not recommended to press the button during the boot sequence, as this can possibly brick the device and render it useless. The arming mode is used for firmware updates and shell access, while the attack mode is used to load and execute the payload.&lt;br /&gt;
&lt;br /&gt;
=== Attack Mode ===&lt;br /&gt;
&lt;br /&gt;
Attack Mode is the default mode, the Signal Owl boots into. It provides two basic functions, being the payload loading function and the payload execution function. &lt;br /&gt;
&lt;br /&gt;
The payload loading function checks for any USB flash drives plugged into the host port of the device and copies payloads to &amp;lt;code&amp;gt;/root/payload&amp;lt;/code&amp;gt; and extensions to &amp;lt;code&amp;gt;/root/payload/extensions&amp;lt;/code&amp;gt; on the Signal Owl. &lt;br /&gt;
&lt;br /&gt;
The payload execution function is responsible for executing the payload that is currently stored on the root of the Signal Owl. In case no payload is found, the device will blink slowly, indicating the FAIL status.&lt;br /&gt;
&lt;br /&gt;
=== Arming Mode ===&lt;br /&gt;
&lt;br /&gt;
The Arming Mode provides two basic functions, being the firmware update function and the shell access function. The firmware update function checks for any USB flash drives plugged into the host port of the device and copies firmware upgrade files into the internal storage of the device and flashes it. The shell access function starts an open access point with the SSID Owl_xxxx in which xxxx indicates the last two octets of the device&#039;s MAC address. Additionally, a SSH server providing access to the shell of the Signal Owl is enabled.&lt;br /&gt;
&lt;br /&gt;
== Default Settings ==&lt;br /&gt;
&lt;br /&gt;
Default settings that are used in order to access the device via SSH are pictured in the table below.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
!colspan=&amp;quot;2&amp;quot;|Default Settings&lt;br /&gt;
|-&lt;br /&gt;
|Username&lt;br /&gt;
|root&lt;br /&gt;
|-&lt;br /&gt;
|Password&lt;br /&gt;
|hak5owl&lt;br /&gt;
|-&lt;br /&gt;
|SSID&lt;br /&gt;
|Owl_xxxx&lt;br /&gt;
|-&lt;br /&gt;
|IP Address&lt;br /&gt;
|172.16.56.1&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
SSH command: &amp;lt;code&amp;gt;ssh root@172.16.56.1&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The SSID during Arming Mode is Owl_xxxx in which xxxx indicates the last two octets of the devices MAC address.&lt;br /&gt;
&lt;br /&gt;
= Usage =&lt;br /&gt;
&lt;br /&gt;
== Arming Mode connection ==&lt;br /&gt;
&lt;br /&gt;
Step-by-step guide for accessing the arming mode&lt;br /&gt;
&lt;br /&gt;
#Click on the button located on the bottom of the Signal Owl while it is in attack mode. After pressing the button, the signal owl enters the arming mode and provides an open access point with the name Owl xxxx (where xxxx stands for the last two digits of the MAC address of the device).&lt;br /&gt;
#Connect to the access point.&amp;lt;br&amp;gt;[[File:Armingmode.png]][Eigene Darstellung]&lt;br /&gt;
#Now you can connect via ssh by using the [[#Default Settings]]&lt;br /&gt;
#After successful connection, you will end up in the root directory&amp;lt;br&amp;gt;[[File:ArmingmodeSSH.png]][Eigene Darstellung]&lt;br /&gt;
#Now you can change the files and directories on the Signal Owl to view results, transfer payloads and extensions or to make further changes&lt;br /&gt;
      &lt;br /&gt;
example Directory structure&lt;br /&gt;
[[File:ArmingmodeSSHdirectories.png]][Eigene Darstellung]&lt;br /&gt;
&lt;br /&gt;
== Adding Payloads and Extensions ==&lt;br /&gt;
&lt;br /&gt;
Adding a payload can be done in two different ways. Either with a USB flash drive or via the Signal Owl access point to the internal storage of the device. &lt;br /&gt;
&lt;br /&gt;
When booting, payloads on USB flash drives are given priority and will override payloads stored on the Signal Owl. To successfully copy a payload to the Signal Owl, the payload must be named &amp;lt;code&amp;gt;payload.txt&amp;lt;/code&amp;gt; or &amp;lt;code&amp;gt;payload.sh&amp;lt;/code&amp;gt; and it has to be placed in the &amp;lt;code&amp;gt;root&amp;lt;/code&amp;gt; directory of the flash drive. Similarly, payload extensions should be stored in a &amp;lt;code&amp;gt;/extensions&amp;lt;/code&amp;gt; directory on the flash drive. &lt;br /&gt;
&lt;br /&gt;
In addition, it is possible to transfer payloads and payload extensions to the device via the Signal Owl access point in arming mode using SSH. There they are stored in the &amp;lt;code&amp;gt;/root/payload&amp;lt;/code&amp;gt; directory and Payload Extensions are stored in the &amp;lt;code&amp;gt;/root/payload/extensions&amp;lt;/code&amp;gt; directory.&lt;br /&gt;
&lt;br /&gt;
== Payload Development ==&lt;br /&gt;
&lt;br /&gt;
Payloads for the Signal Owl are written in bash with [https://github.com/hak5darren/USB-Rubber-Ducky/wiki/Duckyscript Ducky Script] and can be created with any standard text editor. All payloads should begin with an interpreter directive, like the shebang &amp;lt;code&amp;gt;#!/bin/bash&amp;lt;/code&amp;gt; for bash payloads and payloads must be named either &amp;lt;code&amp;gt;payload.txt&amp;lt;/code&amp;gt; or &amp;lt;code&amp;gt;payload.sh&amp;lt;/code&amp;gt;. In order to create effective payloads, the Signal Owl comes with several preinstalled penetration testing tools. These are as follows: [https://nmap.org/ Nmap], [https://www.aircrack-ng.org/ Aircrack-ng], [https://github.com/aircrack-ng/mdk4 MDK4] and [https://www.kismetwireless.net/ Kismet].&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Tools&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
• Kismet - detector for wireless networks and devices.&lt;br /&gt;
&lt;br /&gt;
• MDK4 - Wi-Fi testing tool.&lt;br /&gt;
&lt;br /&gt;
• Aircrack-ng Suite - a complete suite of tools for WiFi network security assessment.&lt;br /&gt;
&lt;br /&gt;
• Nmap - open source utility for network discovery and security auditing.&lt;br /&gt;
&lt;br /&gt;
Hak5 offers ready-to-use payloads and payload extensions on their [https://github.com/hak5/signalowl-payloads GitHub repository].&lt;br /&gt;
&lt;br /&gt;
== Implant / mobile operations ==&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Implant operations&lt;br /&gt;
&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
During long term wireless engagements, the Signal Owl may be planted inline between any typical 5V USB power source. This may be useful in situations where ports are occupied, or to deter the unit from being unplugged.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Mobile operations&lt;br /&gt;
&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
The Signal Owl features a low power consumption profile, with a typical power draw averaging 100-200 mAh. Additionally, it is thermally optimized for long term deployments in many indoor environments. One can expect a large 20,000 mAh USB battery bank to operate the unit for up to 4 days.&lt;br /&gt;
&lt;br /&gt;
= Use Cases =&lt;br /&gt;
&lt;br /&gt;
The Signal Owl has a variety of different use cases. Among the most popular ones are classical network mapping and wardriving as well as basic penetration tests for different wireless technologies.&lt;br /&gt;
&lt;br /&gt;
== Fake Beacon Flooding Attack ==&lt;br /&gt;
&lt;br /&gt;
The fake beacon flooding attack is one possible use case for the Signal Owl. With that attack, fake beacon frames are broadcasted to nearby devices. Beacon Frames include various parameters like the SSID, the type of encryption used and timestamps. This results in the creation of multiple fake Wi-Fi networks. Devices with Wi-Fi browsers are then flooded with these fake networks, causing potential network scanner and driver crashes. Furthermore, the attack may prevent legitimate users from finding their networks and lead to denial of service. &lt;br /&gt;
To execute the attack with the Signal Owl, the preinstalled tools Aircrack-ng and MDK4 are used. The following bash script is saved as payload.sh and placed on the root of an USB flash drive. Then the USB flash drive is plugged into the Signal Owl. After powering on the device, multiple fake networks with random SSIDs are generated and broadcasted to all nearby devices.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
#!/bin/bash&lt;br /&gt;
&lt;br /&gt;
LED SETUP&lt;br /&gt;
#creates monitor mode interface on wirelss card of the Signal Owl&lt;br /&gt;
airmon-ng start wlan0&lt;br /&gt;
&lt;br /&gt;
LED ATTACK&lt;br /&gt;
#floods nearby devices with random SSIDs&lt;br /&gt;
mdk4 wlan0mon b -w a -m -s 1000&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The results as seen from a victim running a Windows 10 system are pictured in the figure below.&lt;br /&gt;
&lt;br /&gt;
[[File:FakeBeaconFloodingSignalOwl.png|none|Random SSIDs as seen from a victim windows 10 client |]][Eigene Darstellung]&lt;br /&gt;
&lt;br /&gt;
== Open AP Nmap Scanner ==&lt;br /&gt;
&lt;br /&gt;
Description: First access points are scanned, then a connection is established to the open access points, after connecting, the nmap scan runs and analyses the AP, &lt;br /&gt;
the results are saved in the loot folder.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
Settings &lt;br /&gt;
&lt;br /&gt;
NMAP_OPTIONS=&amp;quot;-sP&amp;quot;&lt;br /&gt;
&lt;br /&gt;
LOOT_DIR=/root/loot/open_ap_nmap_scan&lt;br /&gt;
&lt;br /&gt;
MAX_CIDR=20&lt;br /&gt;
&lt;br /&gt;
DEBUG=1&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Step-by-step guide&lt;br /&gt;
&lt;br /&gt;
    1) download the payload [https://github.com/hak5/signalowl-payloads/blob/master/payloads/library/wifi/Open-AP-Nmap-Scanner/payload.txt payload]&lt;br /&gt;
    2) store the payload in a usb stick and plug the stick into the signal owl&lt;br /&gt;
    3) after connecting the signal owl, the payload is loaded on the root folder and the scan starts. &lt;br /&gt;
    4) once successfully executed, you can start the signal owl in arming mode and see the results in the loot folder.&lt;br /&gt;
      example loot Directory&lt;br /&gt;
      [[File:ArmingmodeSSHloot.png]][Eigene Darstellung]&lt;br /&gt;
&lt;br /&gt;
= Used Hardware =&lt;br /&gt;
&lt;br /&gt;
[[Signal Owl]]&lt;br /&gt;
&lt;br /&gt;
= References =&lt;br /&gt;
&lt;br /&gt;
*https://docs.hak5.org/signal-owl/&lt;br /&gt;
*https://github.com/hak5/signalowl-payloads&lt;br /&gt;
&lt;br /&gt;
[[Category:Pentesting]]&lt;/div&gt;</summary>
		<author><name>MMayer</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=Hak5_Signal_Owl&amp;diff=10645</id>
		<title>Hak5 Signal Owl</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=Hak5_Signal_Owl&amp;diff=10645"/>
		<updated>2023-01-06T14:28:19Z</updated>

		<summary type="html">&lt;p&gt;MMayer: /* Arming Mode connection */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= Introduction =&lt;br /&gt;
&lt;br /&gt;
The [https://docs.hak5.org/signal-owl/ Signal Owl] is a hardware product developed by the company [https://shop.hak5.org/ Hak5].&lt;br /&gt;
It is a simple payload-based signals intelligence platform with a unique design for discreet planting or mobile operations on any engagement. The most popular application cases include classic network mapping and basic penetration tests for various wireless technologies.&lt;br /&gt;
&lt;br /&gt;
== Initial Setup ==&lt;br /&gt;
&lt;br /&gt;
When first unboxing the Signal Owl, the device runs a stager firmware that is designed to flash the latest firmware from a USB flash drive. In order to update the Signal Owl, the [https://downloads.hak5.org/owl latest firmware] has to be downloaded. Then, the downloaded file must be copied to the root of an EXT4 or FAT32 formatted USB flash drive. It is important not to modify this file. The next step is to plug the USB flash drive into the powered off Signal Owl. Afterwards, the device has to be powered on by a reliable USB source. The upgrade itself takes approximately five to ten minutes and is indicated by a solid red LED light. When finished, the device will reboot, enter Attack Mode and blink slowly, indicating an error running the payload because no payload has been found.&lt;br /&gt;
&lt;br /&gt;
= Hardware =&lt;br /&gt;
&lt;br /&gt;
[[File:SignalOwlDiagram.png|thumb|500px|frame|Components of the Signal Owl [Eigene Darstellung]]] &lt;br /&gt;
&lt;br /&gt;
The Signal Owl is designed to be rapidly deployed in all kinds of environments, allowing it to be an entry point for network analysis and basic wireless attacks in a variety of locations. With a power consumption of 100-200 mAh and the thermally optimized architecture, mobile operations as well as long term deployments, are enabled.&lt;br /&gt;
&lt;br /&gt;
== Components ==&lt;br /&gt;
&lt;br /&gt;
This device features several components of which some may not be visible to the human eye at first sight.&lt;br /&gt;
&lt;br /&gt;
=== USB Power / Passthrough Plug ===&lt;br /&gt;
&lt;br /&gt;
The USB power or passthrough plug is used to power the device. It can be powered from any reliable USB source.&lt;br /&gt;
&lt;br /&gt;
=== USB 2.0 Passthrough Port ===&lt;br /&gt;
&lt;br /&gt;
The USB 2.0 passthrough port is the port closest to the pigtail. Data and power pass through to that port, allowing for implant operations. If a device such as a keyboard is plugged in between this passthrough port and the power plug is connected to the target computer, the Signal Owl will remain undetected by the operating system. Only the keyboard will be visible on the target computer.&lt;br /&gt;
&lt;br /&gt;
=== USB 2.0 Host Port ===&lt;br /&gt;
&lt;br /&gt;
The USB 2.0 host port is the port farthest away from the pigtail. It is connected to the Linux socket of the Signal Owl and supports USB flash drives formatted with FAT32 and EXT4 file systems as well as many Wi-Fi, Bluetooth and other RF transceivers.&lt;br /&gt;
&lt;br /&gt;
=== Button ===&lt;br /&gt;
&lt;br /&gt;
The button on the bottom of the device is used to enter Arming Mode and to interact with payloads. It is not pressable without special tools like paperclips.&lt;br /&gt;
&lt;br /&gt;
=== Status LED ===&lt;br /&gt;
&lt;br /&gt;
The status LED indicates the current status of the Signal Owl. When it is turned off, it is not visible.&lt;br /&gt;
&lt;br /&gt;
The Signal Owl features a red LED with the following default status indications:&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
!|LED&lt;br /&gt;
!|Status&lt;br /&gt;
|-&lt;br /&gt;
|Blinking&lt;br /&gt;
|Booting&lt;br /&gt;
|-&lt;br /&gt;
|Solid&lt;br /&gt;
|Mounting external storage / Running upgrade&lt;br /&gt;
|-&lt;br /&gt;
|Single blinking&lt;br /&gt;
|Attack Mode&lt;br /&gt;
|-&lt;br /&gt;
|Double blinking&lt;br /&gt;
|Arming Mode&lt;br /&gt;
|-&lt;br /&gt;
|Slow blinking&lt;br /&gt;
|Error running payload&lt;br /&gt;
|-&lt;br /&gt;
|Fast blinking&lt;br /&gt;
|Select Mode (Deprecated from version 1.0.1 onward)&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= Software =&lt;br /&gt;
&lt;br /&gt;
== Modes of Operation ==&lt;br /&gt;
&lt;br /&gt;
The Signal Owl comes with two modes of operation, Attack Mode and Arming Mode. By default, the device will boot into Attack Mode. In order to access Arming Mode, the button on the bottom of the device has to be pressed while in Attack Mode. It is not recommended to press the button during the boot sequence, as this can possibly brick the device and render it useless. The arming mode is used for firmware updates and shell access, while the attack mode is used to load and execute the payload.&lt;br /&gt;
&lt;br /&gt;
=== Attack Mode ===&lt;br /&gt;
&lt;br /&gt;
Attack Mode is the default mode, the Signal Owl boots into. It provides two basic functions, being the payload loading function and the payload execution function. &lt;br /&gt;
&lt;br /&gt;
The payload loading function checks for any USB flash drives plugged into the host port of the device and copies payloads to &amp;lt;code&amp;gt;/root/payload&amp;lt;/code&amp;gt; and extensions to &amp;lt;code&amp;gt;/root/payload/extensions&amp;lt;/code&amp;gt; on the Signal Owl. &lt;br /&gt;
&lt;br /&gt;
The payload execution function is responsible for executing the payload that is currently stored on the root of the Signal Owl. In case no payload is found, the device will blink slowly, indicating the FAIL status.&lt;br /&gt;
&lt;br /&gt;
=== Arming Mode ===&lt;br /&gt;
&lt;br /&gt;
The Arming Mode provides two basic functions, being the firmware update function and the shell access function. The firmware update function checks for any USB flash drives plugged into the host port of the device and copies firmware upgrade files into the internal storage of the device and flashes it. The shell access function starts an open access point with the SSID Owl_xxxx in which xxxx indicates the last two octets of the device&#039;s MAC address. Additionally, a SSH server providing access to the shell of the Signal Owl is enabled.&lt;br /&gt;
&lt;br /&gt;
== Default Settings ==&lt;br /&gt;
&lt;br /&gt;
Default settings that are used in order to access the device via SSH are pictured in the table below.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
!colspan=&amp;quot;2&amp;quot;|Default Settings&lt;br /&gt;
|-&lt;br /&gt;
|Username&lt;br /&gt;
|root&lt;br /&gt;
|-&lt;br /&gt;
|Password&lt;br /&gt;
|hak5owl&lt;br /&gt;
|-&lt;br /&gt;
|SSID&lt;br /&gt;
|Owl_xxxx&lt;br /&gt;
|-&lt;br /&gt;
|IP Address&lt;br /&gt;
|172.16.56.1&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
SSH command: &amp;lt;code&amp;gt;ssh root@172.16.56.1&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The SSID during Arming Mode is Owl_xxxx in which xxxx indicates the last two octets of the devices MAC address.&lt;br /&gt;
&lt;br /&gt;
= Usage =&lt;br /&gt;
&lt;br /&gt;
== Arming Mode connection ==&lt;br /&gt;
&lt;br /&gt;
Step-by-step guide for accessing the arming mode&lt;br /&gt;
&lt;br /&gt;
#Click on the button located on the bottom of the signal owl while it is in attack mode. After pressing the button, the signal owl enters the arming mode and provides an open access point with the name Owl xxxx (where xxxx stands for the last two digits of the MAC address of the device).&lt;br /&gt;
#Connect to the access point.&amp;lt;br&amp;gt;[[File:Armingmode.png]][Eigene Darstellung]&lt;br /&gt;
#Now you can connect via ssh by using the [[#Default Settings]]&lt;br /&gt;
#After a successful connection, you will end up in root directory&amp;lt;br&amp;gt;[[File:ArmingmodeSSH.png]][Eigene Darstellung]&lt;br /&gt;
#Now you can enter the directories loot and payload to either view the results or to make further settings&lt;br /&gt;
      &lt;br /&gt;
example Directory structure&lt;br /&gt;
[[File:ArmingmodeSSHdirectories.png]][Eigene Darstellung]&lt;br /&gt;
&lt;br /&gt;
== Adding Payloads and Extensions ==&lt;br /&gt;
&lt;br /&gt;
Adding a payload can be done in two different ways. Either with a USB flash drive or via the Signal Owl access point to the internal storage of the device. &lt;br /&gt;
&lt;br /&gt;
When booting, payloads on USB flash drives are given priority and will override payloads stored on the Signal Owl. To successfully copy a payload to the Signal Owl, the payload must be named &amp;lt;code&amp;gt;payload.txt&amp;lt;/code&amp;gt; or &amp;lt;code&amp;gt;payload.sh&amp;lt;/code&amp;gt; and it has to be placed in the &amp;lt;code&amp;gt;root&amp;lt;/code&amp;gt; directory of the flash drive. Similarly, payload extensions should be stored in a &amp;lt;code&amp;gt;/extensions&amp;lt;/code&amp;gt; directory on the flash drive. &lt;br /&gt;
&lt;br /&gt;
In addition, it is possible to transfer payloads and payload extensions to the device via the Signal Owl access point in arming mode using SSH. There they are stored in the &amp;lt;code&amp;gt;/root/payload&amp;lt;/code&amp;gt; directory and Payload Extensions are stored in the &amp;lt;code&amp;gt;/root/payload/extensions&amp;lt;/code&amp;gt; directory.&lt;br /&gt;
&lt;br /&gt;
== Payload Development ==&lt;br /&gt;
&lt;br /&gt;
Payloads for the Signal Owl are written in bash with [https://github.com/hak5darren/USB-Rubber-Ducky/wiki/Duckyscript Ducky Script] and can be created with any standard text editor. All payloads should begin with an interpreter directive, like the shebang &amp;lt;code&amp;gt;#!/bin/bash&amp;lt;/code&amp;gt; for bash payloads and payloads must be named either &amp;lt;code&amp;gt;payload.txt&amp;lt;/code&amp;gt; or &amp;lt;code&amp;gt;payload.sh&amp;lt;/code&amp;gt;. In order to create effective payloads, the Signal Owl comes with several preinstalled penetration testing tools. These are as follows: [https://nmap.org/ Nmap], [https://www.aircrack-ng.org/ Aircrack-ng], [https://github.com/aircrack-ng/mdk4 MDK4] and [https://www.kismetwireless.net/ Kismet].&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Tools&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
• Kismet - detector for wireless networks and devices.&lt;br /&gt;
&lt;br /&gt;
• MDK4 - Wi-Fi testing tool.&lt;br /&gt;
&lt;br /&gt;
• Aircrack-ng Suite - a complete suite of tools for WiFi network security assessment.&lt;br /&gt;
&lt;br /&gt;
• Nmap - open source utility for network discovery and security auditing.&lt;br /&gt;
&lt;br /&gt;
Hak5 offers ready-to-use payloads and payload extensions on their [https://github.com/hak5/signalowl-payloads GitHub repository].&lt;br /&gt;
&lt;br /&gt;
== Implant / mobile operations ==&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Implant operations&lt;br /&gt;
&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
During long term wireless engagements, the Signal Owl may be planted inline between any typical 5V USB power source. This may be useful in situations where ports are occupied, or to deter the unit from being unplugged.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Mobile operations&lt;br /&gt;
&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
The Signal Owl features a low power consumption profile, with a typical power draw averaging 100-200 mAh. Additionally, it is thermally optimized for long term deployments in many indoor environments. One can expect a large 20,000 mAh USB battery bank to operate the unit for up to 4 days.&lt;br /&gt;
&lt;br /&gt;
= Use Cases =&lt;br /&gt;
&lt;br /&gt;
The Signal Owl has a variety of different use cases. Among the most popular ones are classical network mapping and wardriving as well as basic penetration tests for different wireless technologies.&lt;br /&gt;
&lt;br /&gt;
== Fake Beacon Flooding Attack ==&lt;br /&gt;
&lt;br /&gt;
The fake beacon flooding attack is one possible use case for the Signal Owl. With that attack, fake beacon frames are broadcasted to nearby devices. Beacon Frames include various parameters like the SSID, the type of encryption used and timestamps. This results in the creation of multiple fake Wi-Fi networks. Devices with Wi-Fi browsers are then flooded with these fake networks, causing potential network scanner and driver crashes. Furthermore, the attack may prevent legitimate users from finding their networks and lead to denial of service. &lt;br /&gt;
To execute the attack with the Signal Owl, the preinstalled tools Aircrack-ng and MDK4 are used. The following bash script is saved as payload.sh and placed on the root of an USB flash drive. Then the USB flash drive is plugged into the Signal Owl. After powering on the device, multiple fake networks with random SSIDs are generated and broadcasted to all nearby devices.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
#!/bin/bash&lt;br /&gt;
&lt;br /&gt;
LED SETUP&lt;br /&gt;
#creates monitor mode interface on wirelss card of the Signal Owl&lt;br /&gt;
airmon-ng start wlan0&lt;br /&gt;
&lt;br /&gt;
LED ATTACK&lt;br /&gt;
#floods nearby devices with random SSIDs&lt;br /&gt;
mdk4 wlan0mon b -w a -m -s 1000&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The results as seen from a victim running a Windows 10 system are pictured in the figure below.&lt;br /&gt;
&lt;br /&gt;
[[File:FakeBeaconFloodingSignalOwl.png|none|Random SSIDs as seen from a victim windows 10 client |]][Eigene Darstellung]&lt;br /&gt;
&lt;br /&gt;
== Open AP Nmap Scanner ==&lt;br /&gt;
&lt;br /&gt;
Description: First access points are scanned, then a connection is established to the open access points, after connecting, the nmap scan runs and analyses the AP, &lt;br /&gt;
the results are saved in the loot folder.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
Settings &lt;br /&gt;
&lt;br /&gt;
NMAP_OPTIONS=&amp;quot;-sP&amp;quot;&lt;br /&gt;
&lt;br /&gt;
LOOT_DIR=/root/loot/open_ap_nmap_scan&lt;br /&gt;
&lt;br /&gt;
MAX_CIDR=20&lt;br /&gt;
&lt;br /&gt;
DEBUG=1&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Step-by-step guide&lt;br /&gt;
&lt;br /&gt;
    1) download the payload [https://github.com/hak5/signalowl-payloads/blob/master/payloads/library/wifi/Open-AP-Nmap-Scanner/payload.txt payload]&lt;br /&gt;
    2) store the payload in a usb stick and plug the stick into the signal owl&lt;br /&gt;
    3) after connecting the signal owl, the payload is loaded on the root folder and the scan starts. &lt;br /&gt;
    4) once successfully executed, you can start the signal owl in arming mode and see the results in the loot folder.&lt;br /&gt;
      example loot Directory&lt;br /&gt;
      [[File:ArmingmodeSSHloot.png]][Eigene Darstellung]&lt;br /&gt;
&lt;br /&gt;
= Used Hardware =&lt;br /&gt;
&lt;br /&gt;
[[Signal Owl]]&lt;br /&gt;
&lt;br /&gt;
= References =&lt;br /&gt;
&lt;br /&gt;
*https://docs.hak5.org/signal-owl/&lt;br /&gt;
*https://github.com/hak5/signalowl-payloads&lt;br /&gt;
&lt;br /&gt;
[[Category:Pentesting]]&lt;/div&gt;</summary>
		<author><name>MMayer</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=Hak5_Signal_Owl&amp;diff=10644</id>
		<title>Hak5 Signal Owl</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=Hak5_Signal_Owl&amp;diff=10644"/>
		<updated>2023-01-06T14:14:07Z</updated>

		<summary type="html">&lt;p&gt;MMayer: /* Arming Mode connection */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= Introduction =&lt;br /&gt;
&lt;br /&gt;
The [https://docs.hak5.org/signal-owl/ Signal Owl] is a hardware product developed by the company [https://shop.hak5.org/ Hak5].&lt;br /&gt;
It is a simple payload-based signals intelligence platform with a unique design for discreet planting or mobile operations on any engagement. The most popular application cases include classic network mapping and basic penetration tests for various wireless technologies.&lt;br /&gt;
&lt;br /&gt;
== Initial Setup ==&lt;br /&gt;
&lt;br /&gt;
When first unboxing the Signal Owl, the device runs a stager firmware that is designed to flash the latest firmware from a USB flash drive. In order to update the Signal Owl, the [https://downloads.hak5.org/owl latest firmware] has to be downloaded. Then, the downloaded file must be copied to the root of an EXT4 or FAT32 formatted USB flash drive. It is important not to modify this file. The next step is to plug the USB flash drive into the powered off Signal Owl. Afterwards, the device has to be powered on by a reliable USB source. The upgrade itself takes approximately five to ten minutes and is indicated by a solid red LED light. When finished, the device will reboot, enter Attack Mode and blink slowly, indicating an error running the payload because no payload has been found.&lt;br /&gt;
&lt;br /&gt;
= Hardware =&lt;br /&gt;
&lt;br /&gt;
[[File:SignalOwlDiagram.png|thumb|500px|frame|Components of the Signal Owl [Eigene Darstellung]]] &lt;br /&gt;
&lt;br /&gt;
The Signal Owl is designed to be rapidly deployed in all kinds of environments, allowing it to be an entry point for network analysis and basic wireless attacks in a variety of locations. With a power consumption of 100-200 mAh and the thermally optimized architecture, mobile operations as well as long term deployments, are enabled.&lt;br /&gt;
&lt;br /&gt;
== Components ==&lt;br /&gt;
&lt;br /&gt;
This device features several components of which some may not be visible to the human eye at first sight.&lt;br /&gt;
&lt;br /&gt;
=== USB Power / Passthrough Plug ===&lt;br /&gt;
&lt;br /&gt;
The USB power or passthrough plug is used to power the device. It can be powered from any reliable USB source.&lt;br /&gt;
&lt;br /&gt;
=== USB 2.0 Passthrough Port ===&lt;br /&gt;
&lt;br /&gt;
The USB 2.0 passthrough port is the port closest to the pigtail. Data and power pass through to that port, allowing for implant operations. If a device such as a keyboard is plugged in between this passthrough port and the power plug is connected to the target computer, the Signal Owl will remain undetected by the operating system. Only the keyboard will be visible on the target computer.&lt;br /&gt;
&lt;br /&gt;
=== USB 2.0 Host Port ===&lt;br /&gt;
&lt;br /&gt;
The USB 2.0 host port is the port farthest away from the pigtail. It is connected to the Linux socket of the Signal Owl and supports USB flash drives formatted with FAT32 and EXT4 file systems as well as many Wi-Fi, Bluetooth and other RF transceivers.&lt;br /&gt;
&lt;br /&gt;
=== Button ===&lt;br /&gt;
&lt;br /&gt;
The button on the bottom of the device is used to enter Arming Mode and to interact with payloads. It is not pressable without special tools like paperclips.&lt;br /&gt;
&lt;br /&gt;
=== Status LED ===&lt;br /&gt;
&lt;br /&gt;
The status LED indicates the current status of the Signal Owl. When it is turned off, it is not visible.&lt;br /&gt;
&lt;br /&gt;
The Signal Owl features a red LED with the following default status indications:&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
!|LED&lt;br /&gt;
!|Status&lt;br /&gt;
|-&lt;br /&gt;
|Blinking&lt;br /&gt;
|Booting&lt;br /&gt;
|-&lt;br /&gt;
|Solid&lt;br /&gt;
|Mounting external storage / Running upgrade&lt;br /&gt;
|-&lt;br /&gt;
|Single blinking&lt;br /&gt;
|Attack Mode&lt;br /&gt;
|-&lt;br /&gt;
|Double blinking&lt;br /&gt;
|Arming Mode&lt;br /&gt;
|-&lt;br /&gt;
|Slow blinking&lt;br /&gt;
|Error running payload&lt;br /&gt;
|-&lt;br /&gt;
|Fast blinking&lt;br /&gt;
|Select Mode (Deprecated from version 1.0.1 onward)&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= Software =&lt;br /&gt;
&lt;br /&gt;
== Modes of Operation ==&lt;br /&gt;
&lt;br /&gt;
The Signal Owl comes with two modes of operation, Attack Mode and Arming Mode. By default, the device will boot into Attack Mode. In order to access Arming Mode, the button on the bottom of the device has to be pressed while in Attack Mode. It is not recommended to press the button during the boot sequence, as this can possibly brick the device and render it useless. The arming mode is used for firmware updates and shell access, while the attack mode is used to load and execute the payload.&lt;br /&gt;
&lt;br /&gt;
=== Attack Mode ===&lt;br /&gt;
&lt;br /&gt;
Attack Mode is the default mode, the Signal Owl boots into. It provides two basic functions, being the payload loading function and the payload execution function. &lt;br /&gt;
&lt;br /&gt;
The payload loading function checks for any USB flash drives plugged into the host port of the device and copies payloads to &amp;lt;code&amp;gt;/root/payload&amp;lt;/code&amp;gt; and extensions to &amp;lt;code&amp;gt;/root/payload/extensions&amp;lt;/code&amp;gt; on the Signal Owl. &lt;br /&gt;
&lt;br /&gt;
The payload execution function is responsible for executing the payload that is currently stored on the root of the Signal Owl. In case no payload is found, the device will blink slowly, indicating the FAIL status.&lt;br /&gt;
&lt;br /&gt;
=== Arming Mode ===&lt;br /&gt;
&lt;br /&gt;
The Arming Mode provides two basic functions, being the firmware update function and the shell access function. The firmware update function checks for any USB flash drives plugged into the host port of the device and copies firmware upgrade files into the internal storage of the device and flashes it. The shell access function starts an open access point with the SSID Owl_xxxx in which xxxx indicates the last two octets of the device&#039;s MAC address. Additionally, a SSH server providing access to the shell of the Signal Owl is enabled.&lt;br /&gt;
&lt;br /&gt;
== Default Settings ==&lt;br /&gt;
&lt;br /&gt;
Default settings that are used in order to access the device via SSH are pictured in the table below.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
!colspan=&amp;quot;2&amp;quot;|Default Settings&lt;br /&gt;
|-&lt;br /&gt;
|Username&lt;br /&gt;
|root&lt;br /&gt;
|-&lt;br /&gt;
|Password&lt;br /&gt;
|hak5owl&lt;br /&gt;
|-&lt;br /&gt;
|SSID&lt;br /&gt;
|Owl_xxxx&lt;br /&gt;
|-&lt;br /&gt;
|IP Address&lt;br /&gt;
|172.16.56.1&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
SSH command: &amp;lt;code&amp;gt;ssh root@172.16.56.1&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The SSID during Arming Mode is Owl_xxxx in which xxxx indicates the last two octets of the devices MAC address.&lt;br /&gt;
&lt;br /&gt;
= Usage =&lt;br /&gt;
&lt;br /&gt;
== Arming Mode connection ==&lt;br /&gt;
&lt;br /&gt;
Step-by-step guide for accessing the arming mode&lt;br /&gt;
   1) Click on the button located on the bottom of the signal owl while it is in attack mode. After pressing the button, the signal owl enters the arming mode and provides an open access point with the name Owl xxxx (where xxxx stands for the last two digits of the MAC address of the device).&lt;br /&gt;
   2) Connect to the access point. &lt;br /&gt;
      [[File:Armingmode.png]][Eigene Darstellung]&lt;br /&gt;
   3) Now you can connect via ssh by using the username and password (default: Username: root, Password: hak5owl, IP Address: 172.16.56.1)&lt;br /&gt;
   4) After a successful connection, you will end up in root directory&lt;br /&gt;
      [[File:ArmingmodeSSH.png]][Eigene Darstellung]&lt;br /&gt;
   5) Now you can enter the directories loot and payload to either view the results or to make further settings&lt;br /&gt;
      &lt;br /&gt;
example Directory structure&lt;br /&gt;
[[File:ArmingmodeSSHdirectories.png]][Eigene Darstellung]&lt;br /&gt;
&lt;br /&gt;
== Adding Payloads and Extensions ==&lt;br /&gt;
&lt;br /&gt;
Adding a payload can be done in two different ways. Either with a USB flash drive or via the Signal Owl access point to the internal storage of the device. &lt;br /&gt;
&lt;br /&gt;
When booting, payloads on USB flash drives are given priority and will override payloads stored on the Signal Owl. To successfully copy a payload to the Signal Owl, the payload must be named &amp;lt;code&amp;gt;payload.txt&amp;lt;/code&amp;gt; or &amp;lt;code&amp;gt;payload.sh&amp;lt;/code&amp;gt; and it has to be placed in the &amp;lt;code&amp;gt;root&amp;lt;/code&amp;gt; directory of the flash drive. Similarly, payload extensions should be stored in a &amp;lt;code&amp;gt;/extensions&amp;lt;/code&amp;gt; directory on the flash drive. &lt;br /&gt;
&lt;br /&gt;
In addition, it is possible to transfer payloads and payload extensions to the device via the Signal Owl access point in arming mode using SSH. There they are stored in the &amp;lt;code&amp;gt;/root/payload&amp;lt;/code&amp;gt; directory and Payload Extensions are stored in the &amp;lt;code&amp;gt;/root/payload/extensions&amp;lt;/code&amp;gt; directory.&lt;br /&gt;
&lt;br /&gt;
== Payload Development ==&lt;br /&gt;
&lt;br /&gt;
Payloads for the Signal Owl are written in bash with [https://github.com/hak5darren/USB-Rubber-Ducky/wiki/Duckyscript Ducky Script] and can be created with any standard text editor. All payloads should begin with an interpreter directive, like the shebang &amp;lt;code&amp;gt;#!/bin/bash&amp;lt;/code&amp;gt; for bash payloads and payloads must be named either &amp;lt;code&amp;gt;payload.txt&amp;lt;/code&amp;gt; or &amp;lt;code&amp;gt;payload.sh&amp;lt;/code&amp;gt;. In order to create effective payloads, the Signal Owl comes with several preinstalled penetration testing tools. These are as follows: [https://nmap.org/ Nmap], [https://www.aircrack-ng.org/ Aircrack-ng], [https://github.com/aircrack-ng/mdk4 MDK4] and [https://www.kismetwireless.net/ Kismet].&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Tools&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
• Kismet - detector for wireless networks and devices.&lt;br /&gt;
&lt;br /&gt;
• MDK4 - Wi-Fi testing tool.&lt;br /&gt;
&lt;br /&gt;
• Aircrack-ng Suite - a complete suite of tools for WiFi network security assessment.&lt;br /&gt;
&lt;br /&gt;
• Nmap - open source utility for network discovery and security auditing.&lt;br /&gt;
&lt;br /&gt;
Hak5 offers ready-to-use payloads and payload extensions on their [https://github.com/hak5/signalowl-payloads GitHub repository].&lt;br /&gt;
&lt;br /&gt;
== Implant / mobile operations ==&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Implant operations&lt;br /&gt;
&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
During long term wireless engagements, the Signal Owl may be planted inline between any typical 5V USB power source. This may be useful in situations where ports are occupied, or to deter the unit from being unplugged.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Mobile operations&lt;br /&gt;
&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
The Signal Owl features a low power consumption profile, with a typical power draw averaging 100-200 mAh. Additionally, it is thermally optimized for long term deployments in many indoor environments. One can expect a large 20,000 mAh USB battery bank to operate the unit for up to 4 days.&lt;br /&gt;
&lt;br /&gt;
= Use Cases =&lt;br /&gt;
&lt;br /&gt;
The Signal Owl has a variety of different use cases. Among the most popular ones are classical network mapping and wardriving as well as basic penetration tests for different wireless technologies.&lt;br /&gt;
&lt;br /&gt;
== Fake Beacon Flooding Attack ==&lt;br /&gt;
&lt;br /&gt;
The fake beacon flooding attack is one possible use case for the Signal Owl. With that attack, fake beacon frames are broadcasted to nearby devices. Beacon Frames include various parameters like the SSID, the type of encryption used and timestamps. This results in the creation of multiple fake Wi-Fi networks. Devices with Wi-Fi browsers are then flooded with these fake networks, causing potential network scanner and driver crashes. Furthermore, the attack may prevent legitimate users from finding their networks and lead to denial of service. &lt;br /&gt;
To execute the attack with the Signal Owl, the preinstalled tools Aircrack-ng and MDK4 are used. The following bash script is saved as payload.sh and placed on the root of an USB flash drive. Then the USB flash drive is plugged into the Signal Owl. After powering on the device, multiple fake networks with random SSIDs are generated and broadcasted to all nearby devices.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
#!/bin/bash&lt;br /&gt;
&lt;br /&gt;
LED SETUP&lt;br /&gt;
#creates monitor mode interface on wirelss card of the Signal Owl&lt;br /&gt;
airmon-ng start wlan0&lt;br /&gt;
&lt;br /&gt;
LED ATTACK&lt;br /&gt;
#floods nearby devices with random SSIDs&lt;br /&gt;
mdk4 wlan0mon b -w a -m -s 1000&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The results as seen from a victim running a Windows 10 system are pictured in the figure below.&lt;br /&gt;
&lt;br /&gt;
[[File:FakeBeaconFloodingSignalOwl.png|none|Random SSIDs as seen from a victim windows 10 client |]][Eigene Darstellung]&lt;br /&gt;
&lt;br /&gt;
== Open AP Nmap Scanner ==&lt;br /&gt;
&lt;br /&gt;
Description: First access points are scanned, then a connection is established to the open access points, after connecting, the nmap scan runs and analyses the AP, &lt;br /&gt;
the results are saved in the loot folder.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
Settings &lt;br /&gt;
&lt;br /&gt;
NMAP_OPTIONS=&amp;quot;-sP&amp;quot;&lt;br /&gt;
&lt;br /&gt;
LOOT_DIR=/root/loot/open_ap_nmap_scan&lt;br /&gt;
&lt;br /&gt;
MAX_CIDR=20&lt;br /&gt;
&lt;br /&gt;
DEBUG=1&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Step-by-step guide&lt;br /&gt;
&lt;br /&gt;
    1) download the payload [https://github.com/hak5/signalowl-payloads/blob/master/payloads/library/wifi/Open-AP-Nmap-Scanner/payload.txt payload]&lt;br /&gt;
    2) store the payload in a usb stick and plug the stick into the signal owl&lt;br /&gt;
    3) after connecting the signal owl, the payload is loaded on the root folder and the scan starts. &lt;br /&gt;
    4) once successfully executed, you can start the signal owl in arming mode and see the results in the loot folder.&lt;br /&gt;
      example loot Directory&lt;br /&gt;
      [[File:ArmingmodeSSHloot.png]][Eigene Darstellung]&lt;br /&gt;
&lt;br /&gt;
= Used Hardware =&lt;br /&gt;
&lt;br /&gt;
[[Signal Owl]]&lt;br /&gt;
&lt;br /&gt;
= References =&lt;br /&gt;
&lt;br /&gt;
*https://docs.hak5.org/signal-owl/&lt;br /&gt;
*https://github.com/hak5/signalowl-payloads&lt;br /&gt;
&lt;br /&gt;
[[Category:Pentesting]]&lt;/div&gt;</summary>
		<author><name>MMayer</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=Hak5_Signal_Owl&amp;diff=10643</id>
		<title>Hak5 Signal Owl</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=Hak5_Signal_Owl&amp;diff=10643"/>
		<updated>2023-01-06T14:12:38Z</updated>

		<summary type="html">&lt;p&gt;MMayer: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= Introduction =&lt;br /&gt;
&lt;br /&gt;
The [https://docs.hak5.org/signal-owl/ Signal Owl] is a hardware product developed by the company [https://shop.hak5.org/ Hak5].&lt;br /&gt;
It is a simple payload-based signals intelligence platform with a unique design for discreet planting or mobile operations on any engagement. The most popular application cases include classic network mapping and basic penetration tests for various wireless technologies.&lt;br /&gt;
&lt;br /&gt;
== Initial Setup ==&lt;br /&gt;
&lt;br /&gt;
When first unboxing the Signal Owl, the device runs a stager firmware that is designed to flash the latest firmware from a USB flash drive. In order to update the Signal Owl, the [https://downloads.hak5.org/owl latest firmware] has to be downloaded. Then, the downloaded file must be copied to the root of an EXT4 or FAT32 formatted USB flash drive. It is important not to modify this file. The next step is to plug the USB flash drive into the powered off Signal Owl. Afterwards, the device has to be powered on by a reliable USB source. The upgrade itself takes approximately five to ten minutes and is indicated by a solid red LED light. When finished, the device will reboot, enter Attack Mode and blink slowly, indicating an error running the payload because no payload has been found.&lt;br /&gt;
&lt;br /&gt;
= Hardware =&lt;br /&gt;
&lt;br /&gt;
[[File:SignalOwlDiagram.png|thumb|500px|frame|Components of the Signal Owl [Eigene Darstellung]]] &lt;br /&gt;
&lt;br /&gt;
The Signal Owl is designed to be rapidly deployed in all kinds of environments, allowing it to be an entry point for network analysis and basic wireless attacks in a variety of locations. With a power consumption of 100-200 mAh and the thermally optimized architecture, mobile operations as well as long term deployments, are enabled.&lt;br /&gt;
&lt;br /&gt;
== Components ==&lt;br /&gt;
&lt;br /&gt;
This device features several components of which some may not be visible to the human eye at first sight.&lt;br /&gt;
&lt;br /&gt;
=== USB Power / Passthrough Plug ===&lt;br /&gt;
&lt;br /&gt;
The USB power or passthrough plug is used to power the device. It can be powered from any reliable USB source.&lt;br /&gt;
&lt;br /&gt;
=== USB 2.0 Passthrough Port ===&lt;br /&gt;
&lt;br /&gt;
The USB 2.0 passthrough port is the port closest to the pigtail. Data and power pass through to that port, allowing for implant operations. If a device such as a keyboard is plugged in between this passthrough port and the power plug is connected to the target computer, the Signal Owl will remain undetected by the operating system. Only the keyboard will be visible on the target computer.&lt;br /&gt;
&lt;br /&gt;
=== USB 2.0 Host Port ===&lt;br /&gt;
&lt;br /&gt;
The USB 2.0 host port is the port farthest away from the pigtail. It is connected to the Linux socket of the Signal Owl and supports USB flash drives formatted with FAT32 and EXT4 file systems as well as many Wi-Fi, Bluetooth and other RF transceivers.&lt;br /&gt;
&lt;br /&gt;
=== Button ===&lt;br /&gt;
&lt;br /&gt;
The button on the bottom of the device is used to enter Arming Mode and to interact with payloads. It is not pressable without special tools like paperclips.&lt;br /&gt;
&lt;br /&gt;
=== Status LED ===&lt;br /&gt;
&lt;br /&gt;
The status LED indicates the current status of the Signal Owl. When it is turned off, it is not visible.&lt;br /&gt;
&lt;br /&gt;
The Signal Owl features a red LED with the following default status indications:&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
!|LED&lt;br /&gt;
!|Status&lt;br /&gt;
|-&lt;br /&gt;
|Blinking&lt;br /&gt;
|Booting&lt;br /&gt;
|-&lt;br /&gt;
|Solid&lt;br /&gt;
|Mounting external storage / Running upgrade&lt;br /&gt;
|-&lt;br /&gt;
|Single blinking&lt;br /&gt;
|Attack Mode&lt;br /&gt;
|-&lt;br /&gt;
|Double blinking&lt;br /&gt;
|Arming Mode&lt;br /&gt;
|-&lt;br /&gt;
|Slow blinking&lt;br /&gt;
|Error running payload&lt;br /&gt;
|-&lt;br /&gt;
|Fast blinking&lt;br /&gt;
|Select Mode (Deprecated from version 1.0.1 onward)&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= Software =&lt;br /&gt;
&lt;br /&gt;
== Modes of Operation ==&lt;br /&gt;
&lt;br /&gt;
The Signal Owl comes with two modes of operation, Attack Mode and Arming Mode. By default, the device will boot into Attack Mode. In order to access Arming Mode, the button on the bottom of the device has to be pressed while in Attack Mode. It is not recommended to press the button during the boot sequence, as this can possibly brick the device and render it useless. The arming mode is used for firmware updates and shell access, while the attack mode is used to load and execute the payload.&lt;br /&gt;
&lt;br /&gt;
=== Attack Mode ===&lt;br /&gt;
&lt;br /&gt;
Attack Mode is the default mode, the Signal Owl boots into. It provides two basic functions, being the payload loading function and the payload execution function. &lt;br /&gt;
&lt;br /&gt;
The payload loading function checks for any USB flash drives plugged into the host port of the device and copies payloads to &amp;lt;code&amp;gt;/root/payload&amp;lt;/code&amp;gt; and extensions to &amp;lt;code&amp;gt;/root/payload/extensions&amp;lt;/code&amp;gt; on the Signal Owl. &lt;br /&gt;
&lt;br /&gt;
The payload execution function is responsible for executing the payload that is currently stored on the root of the Signal Owl. In case no payload is found, the device will blink slowly, indicating the FAIL status.&lt;br /&gt;
&lt;br /&gt;
=== Arming Mode ===&lt;br /&gt;
&lt;br /&gt;
The Arming Mode provides two basic functions, being the firmware update function and the shell access function. The firmware update function checks for any USB flash drives plugged into the host port of the device and copies firmware upgrade files into the internal storage of the device and flashes it. The shell access function starts an open access point with the SSID Owl_xxxx in which xxxx indicates the last two octets of the device&#039;s MAC address. Additionally, a SSH server providing access to the shell of the Signal Owl is enabled.&lt;br /&gt;
&lt;br /&gt;
== Default Settings ==&lt;br /&gt;
&lt;br /&gt;
Default settings that are used in order to access the device via SSH are pictured in the table below.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
!colspan=&amp;quot;2&amp;quot;|Default Settings&lt;br /&gt;
|-&lt;br /&gt;
|Username&lt;br /&gt;
|root&lt;br /&gt;
|-&lt;br /&gt;
|Password&lt;br /&gt;
|hak5owl&lt;br /&gt;
|-&lt;br /&gt;
|SSID&lt;br /&gt;
|Owl_xxxx&lt;br /&gt;
|-&lt;br /&gt;
|IP Address&lt;br /&gt;
|172.16.56.1&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
SSH command: &amp;lt;code&amp;gt;ssh root@172.16.56.1&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The SSID during Arming Mode is Owl_xxxx in which xxxx indicates the last two octets of the devices MAC address.&lt;br /&gt;
&lt;br /&gt;
= Usage =&lt;br /&gt;
&lt;br /&gt;
== Arming Mode connection ==&lt;br /&gt;
&lt;br /&gt;
Step-by-step guide for accessing the arming mode&lt;br /&gt;
   1) click on the button located on the bottom of the signal owl while it is in attack mode. After pressing the button, the signal owl enters the arming &lt;br /&gt;
      mode and provides an open access point with the name Owl xxxx (where xxxx stands for the last two digits of the MAC address of the device).&lt;br /&gt;
   2) Connect to the access point. &lt;br /&gt;
      [[File:Armingmode.png]][Eigene Darstellung]&lt;br /&gt;
   3) Now you can connect via ssh by using the username and password (default: Username: root, Password: hak5owl, IP Address: 172.16.56.1)&lt;br /&gt;
   4) after successful connection you will end up in root@Owl directory&lt;br /&gt;
      [[File:ArmingmodeSSH.png]][Eigene Darstellung]&lt;br /&gt;
   5) Now you can enter the directories loot and payload to either view the results or to make further settings&lt;br /&gt;
      &lt;br /&gt;
example Directory structure&lt;br /&gt;
[[File:ArmingmodeSSHdirectories.png]][Eigene Darstellung]&lt;br /&gt;
&lt;br /&gt;
== Adding Payloads and Extensions ==&lt;br /&gt;
&lt;br /&gt;
Adding a payload can be done in two different ways. Either with a USB flash drive or via the Signal Owl access point to the internal storage of the device. &lt;br /&gt;
&lt;br /&gt;
When booting, payloads on USB flash drives are given priority and will override payloads stored on the Signal Owl. To successfully copy a payload to the Signal Owl, the payload must be named &amp;lt;code&amp;gt;payload.txt&amp;lt;/code&amp;gt; or &amp;lt;code&amp;gt;payload.sh&amp;lt;/code&amp;gt; and it has to be placed in the &amp;lt;code&amp;gt;root&amp;lt;/code&amp;gt; directory of the flash drive. Similarly, payload extensions should be stored in a &amp;lt;code&amp;gt;/extensions&amp;lt;/code&amp;gt; directory on the flash drive. &lt;br /&gt;
&lt;br /&gt;
In addition, it is possible to transfer payloads and payload extensions to the device via the Signal Owl access point in arming mode using SSH. There they are stored in the &amp;lt;code&amp;gt;/root/payload&amp;lt;/code&amp;gt; directory and Payload Extensions are stored in the &amp;lt;code&amp;gt;/root/payload/extensions&amp;lt;/code&amp;gt; directory.&lt;br /&gt;
&lt;br /&gt;
== Payload Development ==&lt;br /&gt;
&lt;br /&gt;
Payloads for the Signal Owl are written in bash with [https://github.com/hak5darren/USB-Rubber-Ducky/wiki/Duckyscript Ducky Script] and can be created with any standard text editor. All payloads should begin with an interpreter directive, like the shebang &amp;lt;code&amp;gt;#!/bin/bash&amp;lt;/code&amp;gt; for bash payloads and payloads must be named either &amp;lt;code&amp;gt;payload.txt&amp;lt;/code&amp;gt; or &amp;lt;code&amp;gt;payload.sh&amp;lt;/code&amp;gt;. In order to create effective payloads, the Signal Owl comes with several preinstalled penetration testing tools. These are as follows: [https://nmap.org/ Nmap], [https://www.aircrack-ng.org/ Aircrack-ng], [https://github.com/aircrack-ng/mdk4 MDK4] and [https://www.kismetwireless.net/ Kismet].&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Tools&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
• Kismet - detector for wireless networks and devices.&lt;br /&gt;
&lt;br /&gt;
• MDK4 - Wi-Fi testing tool.&lt;br /&gt;
&lt;br /&gt;
• Aircrack-ng Suite - a complete suite of tools for WiFi network security assessment.&lt;br /&gt;
&lt;br /&gt;
• Nmap - open source utility for network discovery and security auditing.&lt;br /&gt;
&lt;br /&gt;
Hak5 offers ready-to-use payloads and payload extensions on their [https://github.com/hak5/signalowl-payloads GitHub repository].&lt;br /&gt;
&lt;br /&gt;
== Implant / mobile operations ==&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Implant operations&lt;br /&gt;
&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
During long term wireless engagements, the Signal Owl may be planted inline between any typical 5V USB power source. This may be useful in situations where ports are occupied, or to deter the unit from being unplugged.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Mobile operations&lt;br /&gt;
&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
The Signal Owl features a low power consumption profile, with a typical power draw averaging 100-200 mAh. Additionally, it is thermally optimized for long term deployments in many indoor environments. One can expect a large 20,000 mAh USB battery bank to operate the unit for up to 4 days.&lt;br /&gt;
&lt;br /&gt;
= Use Cases =&lt;br /&gt;
&lt;br /&gt;
The Signal Owl has a variety of different use cases. Among the most popular ones are classical network mapping and wardriving as well as basic penetration tests for different wireless technologies.&lt;br /&gt;
&lt;br /&gt;
== Fake Beacon Flooding Attack ==&lt;br /&gt;
&lt;br /&gt;
The fake beacon flooding attack is one possible use case for the Signal Owl. With that attack, fake beacon frames are broadcasted to nearby devices. Beacon Frames include various parameters like the SSID, the type of encryption used and timestamps. This results in the creation of multiple fake Wi-Fi networks. Devices with Wi-Fi browsers are then flooded with these fake networks, causing potential network scanner and driver crashes. Furthermore, the attack may prevent legitimate users from finding their networks and lead to denial of service. &lt;br /&gt;
To execute the attack with the Signal Owl, the preinstalled tools Aircrack-ng and MDK4 are used. The following bash script is saved as payload.sh and placed on the root of an USB flash drive. Then the USB flash drive is plugged into the Signal Owl. After powering on the device, multiple fake networks with random SSIDs are generated and broadcasted to all nearby devices.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
#!/bin/bash&lt;br /&gt;
&lt;br /&gt;
LED SETUP&lt;br /&gt;
#creates monitor mode interface on wirelss card of the Signal Owl&lt;br /&gt;
airmon-ng start wlan0&lt;br /&gt;
&lt;br /&gt;
LED ATTACK&lt;br /&gt;
#floods nearby devices with random SSIDs&lt;br /&gt;
mdk4 wlan0mon b -w a -m -s 1000&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The results as seen from a victim running a Windows 10 system are pictured in the figure below.&lt;br /&gt;
&lt;br /&gt;
[[File:FakeBeaconFloodingSignalOwl.png|none|Random SSIDs as seen from a victim windows 10 client |]][Eigene Darstellung]&lt;br /&gt;
&lt;br /&gt;
== Open AP Nmap Scanner ==&lt;br /&gt;
&lt;br /&gt;
Description: First access points are scanned, then a connection is established to the open access points, after connecting, the nmap scan runs and analyses the AP, &lt;br /&gt;
the results are saved in the loot folder.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
Settings &lt;br /&gt;
&lt;br /&gt;
NMAP_OPTIONS=&amp;quot;-sP&amp;quot;&lt;br /&gt;
&lt;br /&gt;
LOOT_DIR=/root/loot/open_ap_nmap_scan&lt;br /&gt;
&lt;br /&gt;
MAX_CIDR=20&lt;br /&gt;
&lt;br /&gt;
DEBUG=1&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Step-by-step guide&lt;br /&gt;
&lt;br /&gt;
    1) download the payload [https://github.com/hak5/signalowl-payloads/blob/master/payloads/library/wifi/Open-AP-Nmap-Scanner/payload.txt payload]&lt;br /&gt;
    2) store the payload in a usb stick and plug the stick into the signal owl&lt;br /&gt;
    3) after connecting the signal owl, the payload is loaded on the root folder and the scan starts. &lt;br /&gt;
    4) once successfully executed, you can start the signal owl in arming mode and see the results in the loot folder.&lt;br /&gt;
      example loot Directory&lt;br /&gt;
      [[File:ArmingmodeSSHloot.png]][Eigene Darstellung]&lt;br /&gt;
&lt;br /&gt;
= Used Hardware =&lt;br /&gt;
&lt;br /&gt;
[[Signal Owl]]&lt;br /&gt;
&lt;br /&gt;
= References =&lt;br /&gt;
&lt;br /&gt;
*https://docs.hak5.org/signal-owl/&lt;br /&gt;
*https://github.com/hak5/signalowl-payloads&lt;br /&gt;
&lt;br /&gt;
[[Category:Pentesting]]&lt;/div&gt;</summary>
		<author><name>MMayer</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=Hak5_Signal_Owl&amp;diff=10642</id>
		<title>Hak5 Signal Owl</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=Hak5_Signal_Owl&amp;diff=10642"/>
		<updated>2023-01-06T14:05:14Z</updated>

		<summary type="html">&lt;p&gt;MMayer: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= Introduction =&lt;br /&gt;
&lt;br /&gt;
The [https://docs.hak5.org/signal-owl/ Signal Owl] is a hardware product developed by the company [https://shop.hak5.org/ Hak5].&lt;br /&gt;
It is a simple payload-based signals intelligence platform with a unique design for discreet planting or mobile operations on any engagement. The most popular application cases include classic network mapping and basic penetration tests for various wireless technologies.&lt;br /&gt;
&lt;br /&gt;
== Initial Setup ==&lt;br /&gt;
&lt;br /&gt;
When first unboxing the Signal Owl, the device runs a stager firmware that is designed to flash the latest firmware from a USB flash drive. In order to update the Signal Owl, the [https://downloads.hak5.org/owl latest firmware] has to be downloaded. Then, the downloaded file must be copied to the root of an EXT4 or FAT32 formatted USB flash drive. It is important not to modify this file. The next step is to plug the USB flash drive into the powered off Signal Owl. Afterwards, the device has to be powered on by a reliable USB source. The upgrade itself takes approximately five to ten minutes and is indicated by a solid red LED light. When finished, the device will reboot, enter Attack Mode and blink slowly, indicating an error running the payload because no payload has been found.&lt;br /&gt;
&lt;br /&gt;
= Hardware =&lt;br /&gt;
&lt;br /&gt;
[[File:SignalOwlDiagram.png|thumb|500px|frame|Components of the Signal Owl [Eigene Darstellung]]] &lt;br /&gt;
&lt;br /&gt;
The Signal Owl is designed to be rapidly deployed in all kinds of environments, allowing it to be an entry point for network analysis and basic wireless attacks in a variety of locations. With a power consumption of 100-200 mAh and the thermally optimized architecture, mobile operations as well as long term deployments, are enabled.&lt;br /&gt;
&lt;br /&gt;
== Components ==&lt;br /&gt;
&lt;br /&gt;
This device features several components of which some may not be visible to the human eye at first sight.&lt;br /&gt;
&lt;br /&gt;
=== USB Power / Passthrough Plug ===&lt;br /&gt;
&lt;br /&gt;
The USB power or passthrough plug is used to power the device. It can be powered from any reliable USB source.&lt;br /&gt;
&lt;br /&gt;
=== USB 2.0 Passthrough Port ===&lt;br /&gt;
&lt;br /&gt;
The USB 2.0 passthrough port is the port closest to the pigtail. Data and power pass through to that port, allowing for implant operations. If a device such as a keyboard is plugged in between this passthrough port and the power plug is connected to the target computer, the Signal Owl will remain undetected by the operating system. Only the keyboard will be visible on the target computer.&lt;br /&gt;
&lt;br /&gt;
=== USB 2.0 Host Port ===&lt;br /&gt;
&lt;br /&gt;
The USB 2.0 host port is the port farthest away from the pigtail. It is connected to the Linux socket of the Signal Owl and supports USB flash drives formatted with FAT32 and EXT4 file systems as well as many Wi-Fi, Bluetooth and other RF transceivers.&lt;br /&gt;
&lt;br /&gt;
=== Button ===&lt;br /&gt;
&lt;br /&gt;
The button on the bottom of the device is used to enter Arming Mode and to interact with payloads. It is not pressable without special tools like paperclips.&lt;br /&gt;
&lt;br /&gt;
=== Status LED ===&lt;br /&gt;
&lt;br /&gt;
The status LED indicates the current status of the Signal Owl. When it is turned off, it is not visible.&lt;br /&gt;
&lt;br /&gt;
The Signal Owl features a red LED with the following default status indications:&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
!|LED&lt;br /&gt;
!|Status&lt;br /&gt;
|-&lt;br /&gt;
|Blinking&lt;br /&gt;
|Booting&lt;br /&gt;
|-&lt;br /&gt;
|Solid&lt;br /&gt;
|Mounting external storage / Running upgrade&lt;br /&gt;
|-&lt;br /&gt;
|Single blinking&lt;br /&gt;
|Attack Mode&lt;br /&gt;
|-&lt;br /&gt;
|Double blinking&lt;br /&gt;
|Arming Mode&lt;br /&gt;
|-&lt;br /&gt;
|Slow blinking&lt;br /&gt;
|Error running payload&lt;br /&gt;
|-&lt;br /&gt;
|Fast blinking&lt;br /&gt;
|Select Mode (Deprecated from version 1.0.1 onward)&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= Software =&lt;br /&gt;
&lt;br /&gt;
== Modes of Operation ==&lt;br /&gt;
&lt;br /&gt;
The Signal Owl comes with two modes of operation, Attack Mode and Arming Mode. By default, the device will boot into Attack Mode. In order to access Arming Mode, the button on the bottom of the device has to be pressed while in Attack Mode. It is not recommended to press the button during the boot sequence, as this can possibly brick the device and render it useless. The arming mode is used for firmware updates and shell access, while the attack mode is used to load and execute the payload.&lt;br /&gt;
&lt;br /&gt;
=== Attack Mode ===&lt;br /&gt;
&lt;br /&gt;
Attack Mode is the default mode, the Signal Owl boots into. It provides two basic functions, being the payload loading function and the payload execution function. &lt;br /&gt;
&lt;br /&gt;
The payload loading function checks for any USB flash drives plugged into the host port of the device and copies payloads to &amp;lt;code&amp;gt;/root/payload&amp;lt;/code&amp;gt; and extensions to &amp;lt;code&amp;gt;/root/payload/extensions&amp;lt;/code&amp;gt; on the Signal Owl. &lt;br /&gt;
&lt;br /&gt;
The payload execution function is responsible for executing the payload that is currently stored on the root of the Signal Owl. In case no payload is found, the device will blink slowly, indicating the FAIL status.&lt;br /&gt;
&lt;br /&gt;
=== Arming Mode ===&lt;br /&gt;
&lt;br /&gt;
The Arming Mode provides two basic functions, being the firmware update function and the shell access function. The firmware update function checks for any USB flash drives plugged into the host port of the device and copies firmware upgrade files into the internal storage of the device and flashes it. The shell access function starts an open access point with the SSID Owl_xxxx in which xxxx indicates the last two octets of the device&#039;s MAC address. Additionally, a SSH server providing access to the shell of the Signal Owl is enabled.&lt;br /&gt;
&lt;br /&gt;
= Usage =&lt;br /&gt;
&lt;br /&gt;
== Arming Mode connection ==&lt;br /&gt;
&lt;br /&gt;
Step-by-step guide for accessing the arming mode&lt;br /&gt;
   1) click on the button located on the bottom of the signal owl while it is in attack mode. After pressing the button, the signal owl enters the arming &lt;br /&gt;
      mode and provides an open access point with the name Owl xxxx (where xxxx stands for the last two digits of the MAC address of the device).&lt;br /&gt;
   2) Connect to the access point. &lt;br /&gt;
      [[File:Armingmode.png]][Eigene Darstellung]&lt;br /&gt;
   3) Now you can connect via ssh by using the username and password (default: Username: root, Password: hak5owl, IP Address: 172.16.56.1)&lt;br /&gt;
   4) after successful connection you will end up in root@Owl directory&lt;br /&gt;
      [[File:ArmingmodeSSH.png]][Eigene Darstellung]&lt;br /&gt;
   5) Now you can enter the directories loot and payload to either view the results or to make further settings&lt;br /&gt;
      &lt;br /&gt;
example Directory structure&lt;br /&gt;
[[File:ArmingmodeSSHdirectories.png]][Eigene Darstellung]&lt;br /&gt;
&lt;br /&gt;
== Adding Payloads and Extensions ==&lt;br /&gt;
&lt;br /&gt;
Adding a payload can be done in two different ways. Either with a USB flash drive or via the Signal Owl access point to the internal storage of the device. &lt;br /&gt;
&lt;br /&gt;
When booting, payloads on USB flash drives are given priority and will override payloads stored on the Signal Owl. To successfully copy a payload to the Signal Owl, the payload must be named &amp;lt;code&amp;gt;payload.txt&amp;lt;/code&amp;gt; or &amp;lt;code&amp;gt;payload.sh&amp;lt;/code&amp;gt; and it has to be placed in the &amp;lt;code&amp;gt;root&amp;lt;/code&amp;gt; directory of the flash drive. Similarly, payload extensions should be stored in a &amp;lt;code&amp;gt;/extensions&amp;lt;/code&amp;gt; directory on the flash drive. &lt;br /&gt;
&lt;br /&gt;
In addition, it is possible to transfer payloads and payload extensions to the device via the Signal Owl access point in arming mode using SSH. There they are stored in the &amp;lt;code&amp;gt;/root/payload&amp;lt;/code&amp;gt; directory and Payload Extensions are stored in the &amp;lt;code&amp;gt;/root/payload/extensions&amp;lt;/code&amp;gt; directory.&lt;br /&gt;
&lt;br /&gt;
== Payload Development ==&lt;br /&gt;
&lt;br /&gt;
Payloads for the Signal Owl are written in bash with [https://github.com/hak5darren/USB-Rubber-Ducky/wiki/Duckyscript Ducky Script] and can be created with any standard text editor. All payloads should begin with an interpreter directive, like the shebang &amp;lt;code&amp;gt;#!/bin/bash&amp;lt;/code&amp;gt; for bash payloads and payloads must be named either &amp;lt;code&amp;gt;payload.txt&amp;lt;/code&amp;gt; or &amp;lt;code&amp;gt;payload.sh&amp;lt;/code&amp;gt;. In order to create effective payloads, the Signal Owl comes with several preinstalled penetration testing tools. These are as follows: [https://nmap.org/ Nmap], [https://www.aircrack-ng.org/ Aircrack-ng], [https://github.com/aircrack-ng/mdk4 MDK4] and [https://www.kismetwireless.net/ Kismet].&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Tools&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
• Kismet - detector for wireless networks and devices.&lt;br /&gt;
&lt;br /&gt;
• MDK4 - Wi-Fi testing tool.&lt;br /&gt;
&lt;br /&gt;
• Aircrack-ng Suite - a complete suite of tools for WiFi network security assessment.&lt;br /&gt;
&lt;br /&gt;
• Nmap - open source utility for network discovery and security auditing.&lt;br /&gt;
&lt;br /&gt;
Hak5 offers ready-to-use payloads and payload extensions on their [https://github.com/hak5/signalowl-payloads GitHub repository].&lt;br /&gt;
&lt;br /&gt;
== Implant / mobile operations ==&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Implant operations&lt;br /&gt;
&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
During long term wireless engagements, the Signal Owl may be planted inline between any typical 5V USB power source. This may be useful in situations where ports are occupied, or to deter the unit from being unplugged.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Mobile operations&lt;br /&gt;
&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
The Signal Owl features a low power consumption profile, with a typical power draw averaging 100-200 mAh. Additionally, it is thermally optimized for long term deployments in many indoor environments. One can expect a large 20,000 mAh USB battery bank to operate the unit for up to 4 days.&lt;br /&gt;
&lt;br /&gt;
== Default Settings ==&lt;br /&gt;
&lt;br /&gt;
Default settings that are used in order to access the device via SSH are pictured in the table below.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
!colspan=&amp;quot;2&amp;quot;|Default Settings&lt;br /&gt;
|-&lt;br /&gt;
|Username&lt;br /&gt;
|root&lt;br /&gt;
|-&lt;br /&gt;
|Password&lt;br /&gt;
|hak5owl&lt;br /&gt;
|-&lt;br /&gt;
|SSID&lt;br /&gt;
|Owl_xxxx&lt;br /&gt;
|-&lt;br /&gt;
|IP Address&lt;br /&gt;
|172.16.56.1&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
SSH command: &amp;lt;code&amp;gt;ssh root@172.16.56.1&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The SSID during Arming Mode is Owl_xxxx in which xxxx indicates the last two octets of the devices MAC address.&lt;br /&gt;
&lt;br /&gt;
= Fake Beacon Flooding Attack =&lt;br /&gt;
&lt;br /&gt;
The fake beacon flooding attack is one possible use case for the Signal Owl. With that attack, fake beacon frames are broadcasted to nearby devices. Beacon Frames include various parameters like the SSID, the type of encryption used and timestamps. This results in the creation of multiple fake Wi-Fi networks. Devices with Wi-Fi browsers are then flooded with these fake networks, causing potential network scanner and driver crashes. Furthermore, the attack may prevent legitimate users from finding their networks and lead to denial of service. &lt;br /&gt;
To execute the attack with the Signal Owl, the preinstalled tools Aircrack-ng and MDK4 are used. The following bash script is saved as payload.sh and placed on the root of an USB flash drive. Then the USB flash drive is plugged into the Signal Owl. After powering on the device, multiple fake networks with random SSIDs are generated and broadcasted to all nearby devices.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
#!/bin/bash&lt;br /&gt;
&lt;br /&gt;
LED SETUP&lt;br /&gt;
#creates monitor mode interface on wirelss card of the Signal Owl&lt;br /&gt;
airmon-ng start wlan0&lt;br /&gt;
&lt;br /&gt;
LED ATTACK&lt;br /&gt;
#floods nearby devices with random SSIDs&lt;br /&gt;
mdk4 wlan0mon b -w a -m -s 1000&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The results as seen from a victim running a Windows 10 system are pictured in the figure below.&lt;br /&gt;
&lt;br /&gt;
[[File:FakeBeaconFloodingSignalOwl.png|none|Random SSIDs as seen from a victim windows 10 client |]][Eigene Darstellung]&lt;br /&gt;
&lt;br /&gt;
= Open AP Nmap Scanner =&lt;br /&gt;
&lt;br /&gt;
Description: First access points are scanned, then a connection is established to the open access points, after connecting, the nmap scan runs and analyses the AP, &lt;br /&gt;
the results are saved in the loot folder.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
Settings &lt;br /&gt;
&lt;br /&gt;
NMAP_OPTIONS=&amp;quot;-sP&amp;quot;&lt;br /&gt;
&lt;br /&gt;
LOOT_DIR=/root/loot/open_ap_nmap_scan&lt;br /&gt;
&lt;br /&gt;
MAX_CIDR=20&lt;br /&gt;
&lt;br /&gt;
DEBUG=1&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Step-by-step guide&lt;br /&gt;
&lt;br /&gt;
    1) download the payload [https://github.com/hak5/signalowl-payloads/blob/master/payloads/library/wifi/Open-AP-Nmap-Scanner/payload.txt payload]&lt;br /&gt;
    2) store the payload in a usb stick and plug the stick into the signal owl&lt;br /&gt;
    3) after connecting the signal owl, the payload is loaded on the root folder and the scan starts. &lt;br /&gt;
    4) once successfully executed, you can start the signal owl in arming mode and see the results in the loot folder.&lt;br /&gt;
      example loot Directory&lt;br /&gt;
      [[File:ArmingmodeSSHloot.png]][Eigene Darstellung]&lt;br /&gt;
&lt;br /&gt;
= Use Cases =&lt;br /&gt;
&lt;br /&gt;
The Signal Owl has a variety of different use cases. Among the most popular ones are classical network mapping and wardriving as well as basic penetration tests for different wireless technologies.&lt;br /&gt;
&lt;br /&gt;
= Used Hardware =&lt;br /&gt;
&lt;br /&gt;
[[Signal Owl]]&lt;br /&gt;
&lt;br /&gt;
= References =&lt;br /&gt;
&lt;br /&gt;
* https://docs.hak5.org/signal-owl/&lt;br /&gt;
*https://github.com/hak5/signalowl-payloads&lt;br /&gt;
&lt;br /&gt;
[[Category:Pentesting]]&lt;/div&gt;</summary>
		<author><name>MMayer</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=Hak5_Signal_Owl&amp;diff=10626</id>
		<title>Hak5 Signal Owl</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=Hak5_Signal_Owl&amp;diff=10626"/>
		<updated>2023-01-05T20:43:14Z</updated>

		<summary type="html">&lt;p&gt;MMayer: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= Introduction =&lt;br /&gt;
&lt;br /&gt;
The [https://docs.hak5.org/signal-owl/ Signal Owl] is a hardware product developed by the company [https://shop.hak5.org/ Hak5].&lt;br /&gt;
It is a simple payload-based signals intelligence platform with a unique design for discreet planting or mobile operations on any engagement. The most popular application cases include classic network mapping and basic penetration tests for various wireless technologies.&lt;br /&gt;
&lt;br /&gt;
== Initial Setup ==&lt;br /&gt;
&lt;br /&gt;
When first unboxing the Signal Owl, the device runs a stager firmware that is designed to flash the latest firmware from a USB flash drive. In order to update the Signal Owl, the [https://downloads.hak5.org/owl latest firmware] has to be downloaded. Then, the downloaded file must be copied to the root of an EXT4 or FAT32 formatted USB flash drive. It is important not to modify this file. The next step is to plug the USB flash drive into the powered off Signal Owl. Afterwards, the device has to be powered on by a reliable USB source. The upgrade itself takes approximately five to ten minutes and is indicated by a solid red LED light. When finished, the device will reboot, enter Attack Mode and blink slowly, indicating an error running the payload because no payload has been found.&lt;br /&gt;
&lt;br /&gt;
= Hardware =&lt;br /&gt;
&lt;br /&gt;
[[File:SignalOwlDiagram.png|thumb|500px|frame|Components of the Signal Owl [Eigene Darstellung]]] &lt;br /&gt;
&lt;br /&gt;
The Signal Owl is designed to be rapidly deployed in all kinds of environments, allowing it to be an entry point for network analysis and basic wireless attacks in a variety of locations. With a power consumption of 100-200 mAh and the thermally optimized architecture, mobile operations as well as long term deployments, are enabled.&lt;br /&gt;
&lt;br /&gt;
== Components ==&lt;br /&gt;
&lt;br /&gt;
This device features several components of which some may not be visible to the human eye at first sight.&lt;br /&gt;
&lt;br /&gt;
=== USB Power / Passthrough Plug ===&lt;br /&gt;
&lt;br /&gt;
The USB power or passthrough plug is used to power the device. It can be powered from any reliable USB source.&lt;br /&gt;
&lt;br /&gt;
=== USB 2.0 Passthrough Port ===&lt;br /&gt;
&lt;br /&gt;
The USB 2.0 passthrough port is the port closest to the pigtail. Data and power pass through to that port, allowing for implant operations. If a device such as a keyboard is plugged in between this passthrough port and the power plug is connected to the target computer, the Signal Owl will remain undetected by the operating system. Only the keyboard will be visible on the target computer.&lt;br /&gt;
&lt;br /&gt;
=== USB 2.0 Host Port ===&lt;br /&gt;
&lt;br /&gt;
The USB 2.0 host port is the port farthest away from the pigtail. It is connected to the Linux socket of the Signal Owl and supports USB flash drives formatted with FAT32 and EXT4 file systems as well as many Wi-Fi, Bluetooth and other RF transceivers.&lt;br /&gt;
&lt;br /&gt;
=== Button ===&lt;br /&gt;
&lt;br /&gt;
The button on the bottom of the device is used to enter Arming Mode and to interact with payloads. It is not pressable without special tools like paperclips.&lt;br /&gt;
&lt;br /&gt;
=== Status LED ===&lt;br /&gt;
&lt;br /&gt;
The status LED indicates the current status of the Signal Owl. When it is turned off, it is not visible.&lt;br /&gt;
&lt;br /&gt;
==== Status LED Indications ====&lt;br /&gt;
&lt;br /&gt;
The Signal Owl features a red LED with the following default status indications:&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
!|LED&lt;br /&gt;
!|Status&lt;br /&gt;
|-&lt;br /&gt;
|Blinking&lt;br /&gt;
|Booting&lt;br /&gt;
|-&lt;br /&gt;
|Solid&lt;br /&gt;
|Mounting external storage / Running upgrade&lt;br /&gt;
|-&lt;br /&gt;
|Single blinking&lt;br /&gt;
|Attack Mode&lt;br /&gt;
|-&lt;br /&gt;
|Double blinking&lt;br /&gt;
|Arming Mode&lt;br /&gt;
|-&lt;br /&gt;
|Slow blinking&lt;br /&gt;
|Error running payload&lt;br /&gt;
|-&lt;br /&gt;
|Fast blinking&lt;br /&gt;
|Select Mode (Deprecated from version 1.0.1 onward)&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Implant / mobile operations ==&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Implant operations&lt;br /&gt;
&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
During long term wireless engagements, the Signal Owl may be planted inline between any typical 5V USB power source. This may be useful in situations where ports are occupied, or to deter the unit from being unplugged.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Mobile operations&lt;br /&gt;
&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
The Signal Owl features a low power consumption profile, with a typical power draw averaging 100-200 mAh. Additionally, it is thermally optimized for long term deployments in many indoor environments. One can expect a large 20,000 mAh USB battery bank to operate the unit for up to 4 days.&lt;br /&gt;
&lt;br /&gt;
== Default Settings ==&lt;br /&gt;
&lt;br /&gt;
Default settings that are used in order to access the device via SSH are pictured in the table below.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
!colspan=&amp;quot;2&amp;quot;|Default Settings&lt;br /&gt;
|-&lt;br /&gt;
|Username&lt;br /&gt;
|root&lt;br /&gt;
|-&lt;br /&gt;
|Password&lt;br /&gt;
|hak5owl&lt;br /&gt;
|-&lt;br /&gt;
|SSID&lt;br /&gt;
|Owl_xxxx&lt;br /&gt;
|-&lt;br /&gt;
|IP Address&lt;br /&gt;
|172.16.56.1&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
SSH command: &amp;lt;code&amp;gt;ssh root@172.16.56.1&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The SSID during Arming Mode is Owl_xxxx in which xxxx indicates the last two octets of the devices MAC address.&lt;br /&gt;
&lt;br /&gt;
== Modes of Operation ==&lt;br /&gt;
&lt;br /&gt;
The Signal Owl comes with two modes of operation, Attack Mode and Arming Mode. By default, the device will boot into Attack Mode. In order to access Arming Mode, the button on the bottom of the device has to be pressed while in Attack Mode. It is not recommended to press the button during the boot sequence, as this can possibly brick the device and render it useless. The arming mode is used for firmware updates and shell access, while the attack mode is used to load and execute the payload.&lt;br /&gt;
&lt;br /&gt;
=== Attack Mode ===&lt;br /&gt;
&lt;br /&gt;
Attack Mode is the default mode, the Signal Owl boots into. It provides two basic functions, being the payload loading function and the payload execution function. The payload loading function checks for any USB flash drives plugged into the host port of the device and copies payloads and extensions to the root of the Signal Owl. The payload execution function is responsible for executing the payload that is currently stored on the root of the Signal Owl. In case no payload is found, the device will blink slowly, indicating the FAIL status.&lt;br /&gt;
&lt;br /&gt;
=== Arming Mode ===&lt;br /&gt;
&lt;br /&gt;
The Arming Mode provides two basic functions, being the firmware update function and the shell access function. The firmware update function checks for any USB flash drives plugged into the host port of the device and copies firmware upgrade files into the internal storage of the device and flashes it. The shell access function starts an open access point with the SSID Owl_xxxx in which xxxx indicates the last two octets of the device&#039;s MAC address. Additionally, a SSH server providing access to the shell of the Signal Owl is enabled.&lt;br /&gt;
&lt;br /&gt;
== Payload Development ==&lt;br /&gt;
&lt;br /&gt;
Payloads for the Signal Owl are written in bash with [https://github.com/hak5darren/USB-Rubber-Ducky/wiki/Duckyscript Ducky Script] and can be created with any standard text editor. All payloads should begin with an interpreter directive, like the shebang #!/bin/bash for bash payloads and payloads must be named either payload.txt or payload.sh. In order to create effective payloads, the Signal Owl comes with several preinstalled penetration testing tools. These are as follows: [https://nmap.org/ Nmap], [https://www.aircrack-ng.org/ Aircrack-ng], [https://github.com/aircrack-ng/mdk4 MDK4] and [https://www.kismetwireless.net/ Kismet].&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Tools&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
• Kismet - detector for wireless networks and devices.&lt;br /&gt;
&lt;br /&gt;
• MDK4 - Wi-Fi testing tool.&lt;br /&gt;
&lt;br /&gt;
• Aircrack-ng Suite - a complete suite of tools for WiFi network security assessment.&lt;br /&gt;
&lt;br /&gt;
• Nmap - open source utility for network discovery and security auditing.&lt;br /&gt;
&lt;br /&gt;
== Adding Payloads and Extensions ==&lt;br /&gt;
&lt;br /&gt;
Payloads can be stored on the internal storage of the Signal Owl as well as on a USB flash drive. When booting, payloads on USB flash drives are given priority and will override payloads stored on the Signal Owl. If no payload is found on the external storage and a payload is present on the internal storage, the internally stored payload will be executed. In case no payload is found on both internal and external storage, the Signal Owl will blink slowly. To successfully copy a payload to the Signal Owl and execute it, the payload must be named payload.txt or payload.sh and it has to be placed in the root directory of the flash drive. Similarly, payload extensions should be stored in a /extensions directory on the flash drive.&lt;br /&gt;
&lt;br /&gt;
After plugging the Signal Owl into a USB source, it will boot and then copy the payloads and payload extensions to the /root/payload and /root/payload/extensions directory respectively. Then, the device will enter Attack Mode and execute the payload.&lt;br /&gt;
&lt;br /&gt;
= Fake Beacon Flooding Attack =&lt;br /&gt;
&lt;br /&gt;
The fake beacon flooding attack is one possible use case for the Signal Owl. With that attack, fake beacon frames are broadcasted to nearby devices. Beacon Frames include various parameters like the SSID, the type of encryption used and timestamps. This results in the creation of multiple fake Wi-Fi networks. Devices with Wi-Fi browsers are then flooded with these fake networks, causing potential network scanner and driver crashes. Furthermore, the attack may prevent legitimate users from finding their networks and lead to denial of service. &lt;br /&gt;
To execute the attack with the Signal Owl, the preinstalled tools Aircrack-ng and MDK4 are used. The following bash script is saved as payload.sh and placed on the root of an USB flash drive. Then the USB flash drive is plugged into the Signal Owl. After powering on the device, multiple fake networks with random SSIDs are generated and broadcasted to all nearby devices.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
#!/bin/bash&lt;br /&gt;
&lt;br /&gt;
LED SETUP&lt;br /&gt;
#creates monitor mode interface on wirelss card of the Signal Owl&lt;br /&gt;
airmon-ng start wlan0&lt;br /&gt;
&lt;br /&gt;
LED ATTACK&lt;br /&gt;
#floods nearby devices with random SSIDs&lt;br /&gt;
mdk4 wlan0mon b -w a -m -s 1000&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The results as seen from a victim running a Windows 10 system are pictured in the figure below.&lt;br /&gt;
&lt;br /&gt;
[[File:FakeBeaconFloodingSignalOwl.png|none|Random SSIDs as seen from a victim windows 10 client |]][Eigene Darstellung]&lt;br /&gt;
&lt;br /&gt;
= Open AP Nmap Scanner =&lt;br /&gt;
&lt;br /&gt;
Description: First access points are scanned, then a connection is established to the open access points, after connecting, the nmap scan runs and analyses the AP, &lt;br /&gt;
the results are saved in the loot folder.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
Settings &lt;br /&gt;
&lt;br /&gt;
NMAP_OPTIONS=&amp;quot;-sP&amp;quot;&lt;br /&gt;
&lt;br /&gt;
LOOT_DIR=/root/loot/open_ap_nmap_scan&lt;br /&gt;
&lt;br /&gt;
MAX_CIDR=20&lt;br /&gt;
&lt;br /&gt;
DEBUG=1&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Step-by-step guide&lt;br /&gt;
&lt;br /&gt;
    1) download the payload [https://github.com/hak5/signalowl-payloads/blob/master/payloads/library/wifi/Open-AP-Nmap-Scanner/payload.txt payload]&lt;br /&gt;
    2) store the payload in a usb stick and plug the stick into the signal owl&lt;br /&gt;
    3) after connecting the signal owl, the payload is loaded on the root folder and the scan starts. &lt;br /&gt;
    4) once successfully executed, you can start the signal owl in arming mode and see the results in the loot folder.&lt;br /&gt;
      example loot Directory&lt;br /&gt;
      [[File:ArmingmodeSSHloot.png]][Eigene Darstellung]&lt;br /&gt;
&lt;br /&gt;
= Arming Mode connection =&lt;br /&gt;
&lt;br /&gt;
Step-by-step guide for accessing the arming mode&lt;br /&gt;
   1) click on the button located on the bottom of the signal owl while it is in attack mode. After pressing the button, the signal owl enters the arming &lt;br /&gt;
      mode and provides an open access point with the name Owl xxxx (where xxxx stands for the last two digits of the MAC address of the device).&lt;br /&gt;
   2) Connect to the access point. &lt;br /&gt;
      [[File:Armingmode.png]][Eigene Darstellung]&lt;br /&gt;
   3) Now you can connect via ssh by using the username and password (default: Username: root, Password: hak5owl, IP Address: 172.16.56.1)&lt;br /&gt;
   4) after successful connection you will end up in root@Owl directory&lt;br /&gt;
      [[File:ArmingmodeSSH.png]][Eigene Darstellung]&lt;br /&gt;
   5) Now you can enter the directories loot and payload to either view the results or to make further settings&lt;br /&gt;
      &lt;br /&gt;
&lt;br /&gt;
      example Directory structure&lt;br /&gt;
      [[File:ArmingmodeSSHdirectories.png]][Eigene Darstellung]&lt;br /&gt;
&lt;br /&gt;
= Use Cases =&lt;br /&gt;
&lt;br /&gt;
The Signal Owl has a variety of different use cases. Among the most popular ones are classical network mapping and wardriving as well as basic penetration tests for different wireless technologies.&lt;br /&gt;
&lt;br /&gt;
= Used Hardware =&lt;br /&gt;
&lt;br /&gt;
[[Signal Owl]]&lt;br /&gt;
&lt;br /&gt;
= References =&lt;br /&gt;
&lt;br /&gt;
* https://docs.hak5.org/signal-owl/&lt;br /&gt;
*https://github.com/hak5/signalowl-payloads&lt;br /&gt;
&lt;br /&gt;
[[Category:Pentesting]]&lt;/div&gt;</summary>
		<author><name>MMayer</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=Hak5_Signal_Owl&amp;diff=10625</id>
		<title>Hak5 Signal Owl</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=Hak5_Signal_Owl&amp;diff=10625"/>
		<updated>2023-01-05T17:19:27Z</updated>

		<summary type="html">&lt;p&gt;MMayer: /* Modes of Operation */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Summary ==&lt;br /&gt;
&lt;br /&gt;
The [https://docs.hak5.org/signal-owl/ Signal Owl] is a hardware product developed by the company Hak5.&lt;br /&gt;
It is a simple payload-based signals intelligence platform with a unique design for discreet planting or mobile operations on any engagement. The most popular application cases include classic network mapping and basic penetration tests for various wireless technologies.&lt;br /&gt;
&lt;br /&gt;
== Description ==&lt;br /&gt;
&lt;br /&gt;
[[File:SignalOwlDiagram.png|thumb|500px|frame|Components of the Signal Owl [Eigene Darstellung]]] &lt;br /&gt;
&lt;br /&gt;
The Signal Owl is designed to be rapidly deployed in all kinds of environments, allowing it to be an entry point for network analysis and basic wireless attacks in a variety of locations. With a power consumption of 100-200 mAh and the thermally optimized architecture, mobile operations as well as long term deployments, are enabled.&lt;br /&gt;
&lt;br /&gt;
=== Components ===&lt;br /&gt;
&lt;br /&gt;
This device features several components of which some may not be visible to the human eye at first sight.&lt;br /&gt;
&lt;br /&gt;
==== USB Power / Passthrough Plug ====&lt;br /&gt;
&lt;br /&gt;
The USB power or passthrough plug is used to power the device. It can be powered from any reliable USB source.&lt;br /&gt;
&lt;br /&gt;
==== USB 2.0 Passthrough Port ====&lt;br /&gt;
&lt;br /&gt;
The USB 2.0 passthrough port is the port closest to the pigtail. Data and power pass through to that port, allowing for implant operations. With devices like keyboards plugged plugged inline between this passthrough port and the power plug connected to the target computer, the Signal Owl will remain undetected from the operating system. Only the keyboard will be visible.&lt;br /&gt;
&lt;br /&gt;
==== USB 2.0 Host Port ====&lt;br /&gt;
&lt;br /&gt;
The USB 2.0 host port is the port farthest away from the pigtail. It is connected to the Linux socket of the Signal Owl and supports USB flash drives formatted with FAT32 and EXT4 file systems as well as many Wi-Fi, Bluetooth and other RF transceivers.&lt;br /&gt;
&lt;br /&gt;
==== Button ====&lt;br /&gt;
&lt;br /&gt;
The button on the bottom of the device is used to enter Arming Mode and to interact with payloads. It is not pressable without special tools like paperclips.&lt;br /&gt;
&lt;br /&gt;
==== Status LED ====&lt;br /&gt;
&lt;br /&gt;
The status LED indicates the current status of the Signal Owl. When turned off, it is not visible.&lt;br /&gt;
&lt;br /&gt;
=== Implant / mobile operations ===&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Implant operations&lt;br /&gt;
&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
During long term wireless engagements, the Signal Owl may be planted inline between any typical 5V USB power source. This may be useful in situations where ports are occupied, or to deter the unit from being unplugged.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Mobile operations&lt;br /&gt;
&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
The Signal Owl features a low power consumption profile, with a typical power draw averaging 100-200 mAh. Additionally, it is thermally optimized for long term deployments in many indoor environments. One can expect a large 20,000 mAh USB battery bank to operate the unit for up to 4 days.&lt;br /&gt;
&lt;br /&gt;
=== Default Settings ===&lt;br /&gt;
&lt;br /&gt;
Default settings that are used in order to access the device via SSH are pictured in the table below.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
!colspan=&amp;quot;2&amp;quot;|Default Settings&lt;br /&gt;
|-&lt;br /&gt;
|Username&lt;br /&gt;
|root&lt;br /&gt;
|-&lt;br /&gt;
|Password&lt;br /&gt;
|hak5owl&lt;br /&gt;
|-&lt;br /&gt;
|SSID&lt;br /&gt;
|Owl_xxxx&lt;br /&gt;
|-&lt;br /&gt;
|IP Address&lt;br /&gt;
|172.16.56.1&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
SSH command: &amp;lt;code&amp;gt;ssh root@172.16.56.1&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The SSID during Arming Mode is Owl_xxxx in which xxxx indicates the last two octets of the devices MAC address.&lt;br /&gt;
&lt;br /&gt;
=== LED Status Indications ===&lt;br /&gt;
&lt;br /&gt;
The Signal Owl features a red LED with the following default status indications:&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
!|LED&lt;br /&gt;
!|Status&lt;br /&gt;
|-&lt;br /&gt;
|Blinking&lt;br /&gt;
|Booting&lt;br /&gt;
|-&lt;br /&gt;
|Solid&lt;br /&gt;
|Mounting external storage / Running upgrade&lt;br /&gt;
|-&lt;br /&gt;
|Single blinking&lt;br /&gt;
|Attack Mode&lt;br /&gt;
|-&lt;br /&gt;
|Double blinking&lt;br /&gt;
|Arming Mode&lt;br /&gt;
|-&lt;br /&gt;
|Slow blinking&lt;br /&gt;
|Error running payload&lt;br /&gt;
|-&lt;br /&gt;
|Fast blinking&lt;br /&gt;
|Select Mode (Deprecated from version 1.0.1 onward)&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== Modes of Operation ===&lt;br /&gt;
&lt;br /&gt;
The Signal Owl comes with two modes of operation, Attack Mode and Arming Mode. By default, the device will boot into Attack Mode. In order to access Arming Mode, the button on the bottom of the device has to be pressed while in Attack Mode. It is not recommended to press the button during the boot sequence, as this can possibly brick the device and render it useless. The arming mode is used for firmware updates and shell access, while the attack mode is used to load and execute the payload.&lt;br /&gt;
&lt;br /&gt;
==== Attack Mode ====&lt;br /&gt;
&lt;br /&gt;
Attack Mode is the default mode, the Signal Owl boots into. It provides two basic functions, being the payload loading function and the payload execution function. The payload loading function checks for any USB flash drives plugged into the host port of the device and copies payloads and extensions to the root of the Signal Owl. The payload execution function is responsible for executing the payload that is currently stored on the root of the Signal Owl. In case no payload is found, the device will blink slowly, indicating the FAIL status.&lt;br /&gt;
&lt;br /&gt;
==== Arming Mode ====&lt;br /&gt;
&lt;br /&gt;
The Arming Mode provides two basic functions, being the firmware update function and the shell access function. The firmware update function checks for any USB flash drives plugged into the host port of the device and copies firmware upgrade files into the internal storage of the device and flashes it. The shell access function starts an open access point with the SSID Owl_xxxx in which xxxx indicates the last two octets of the device&#039;s MAC address. Additionally, a SSH server providing access to the shell of the Signal Owl is enabled.&lt;br /&gt;
&lt;br /&gt;
=== Initial Setup ===&lt;br /&gt;
&lt;br /&gt;
When first unboxing the Signal Owl, the device runs a stager firmware that is designed to flash the latest firmware from a USB flash drive. In order to update the Signal Owl, the [https://downloads.hak5.org/owl latest firmware] has to be downloaded. Then, the downloaded file must be copied to the root of an EXT4 or FAT32 formatted USB flash drive. It is important not to modify this file. The next step is to plug the USB flash drive into the powered off Signal Owl. Afterwards, the device has to be powered on by a reliable USB source. The upgrade itself takes approximately five to ten minutes and is indicated by a solid red LED light. When finished, the device will reboot, enter Attack Mode and blink slowly, indicating an error running the payload because no payload has been found.&lt;br /&gt;
&lt;br /&gt;
=== Payload Development ===&lt;br /&gt;
&lt;br /&gt;
Payloads for the Signal Owl are written in bash with [https://github.com/hak5darren/USB-Rubber-Ducky/wiki/Duckyscript Ducky Script] and can be created with any standard text editor. All payloads should begin with an interpreter directive, like the shebang #!/bin/bash for bash payloads and payloads must be named either payload.txt or payload.sh. In order to create effective payloads, the Signal Owl comes with several preinstalled penetration testing tools. These are as follows: [https://nmap.org/ Nmap], [https://www.aircrack-ng.org/ Aircrack-ng], [https://github.com/aircrack-ng/mdk4 MDK4] and [https://www.kismetwireless.net/ Kismet].&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Tools&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
• Kismet - detector for wireless networks and devices.&lt;br /&gt;
&lt;br /&gt;
• MDK4 - Wi-Fi testing tool.&lt;br /&gt;
&lt;br /&gt;
• Aircrack-ng Suite - a complete suite of tools for WiFi network security assessment.&lt;br /&gt;
&lt;br /&gt;
• Nmap - open source utility for network discovery and security auditing.&lt;br /&gt;
&lt;br /&gt;
=== Adding Payloads and Extensions ===&lt;br /&gt;
&lt;br /&gt;
Payloads can be stored on the internal storage of the Signal Owl as well as on a USB flash drive. When booting, payloads on USB flash drives are given priority and will override payloads stored on the Signal Owl. If no payload is found on the external storage and a payload is present on the internal storage, the internally stored payload will be executed. In case no payload is found on both internal and external storage, the Signal Owl will blink slowly. To successfully copy a payload to the Signal Owl and execute it, the payload must be named payload.txt or payload.sh and it has to be placed in the root directory of the flash drive. Similarly, payload extensions should be stored in a /extensions directory on the flash drive.&lt;br /&gt;
&lt;br /&gt;
After plugging the Signal Owl into a USB source, it will boot and then copy the payloads and payload extensions to the /root/payload and /root/payload/extensions directory respectively. Then, the device will enter Attack Mode and execute the payload.&lt;br /&gt;
&lt;br /&gt;
== Fake Beacon Flooding Attack ==&lt;br /&gt;
&lt;br /&gt;
The fake beacon flooding attack is one possible use case for the Signal Owl. With that attack, fake beacon frames are broadcasted to nearby devices. Beacon Frames include various parameters like the SSID, the type of encryption used and timestamps. This results in the creation of multiple fake Wi-Fi networks. Devices with Wi-Fi browsers are then flooded with these fake networks, causing potential network scanner and driver crashes. Furthermore, the attack may prevent legitimate users from finding their networks and lead to denial of service. &lt;br /&gt;
To execute the attack with the Signal Owl, the preinstalled tools Aircrack-ng and MDK4 are used. The following bash script is saved as payload.sh and placed on the root of an USB flash drive. Then the USB flash drive is plugged into the Signal Owl. After powering on the device, multiple fake networks with random SSIDs are generated and broadcasted to all nearby devices.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
#!/bin/bash&lt;br /&gt;
&lt;br /&gt;
LED SETUP&lt;br /&gt;
#creates monitor mode interface on wirelss card of the Signal Owl&lt;br /&gt;
airmon-ng start wlan0&lt;br /&gt;
&lt;br /&gt;
LED ATTACK&lt;br /&gt;
#floods nearby devices with random SSIDs&lt;br /&gt;
mdk4 wlan0mon b -w a -m -s 1000&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The results as seen from a victim running a Windows 10 system are pictured in the figure below.&lt;br /&gt;
&lt;br /&gt;
[[File:FakeBeaconFloodingSignalOwl.png|none|Random SSIDs as seen from a victim windows 10 client |]][Eigene Darstellung]&lt;br /&gt;
&lt;br /&gt;
== Open AP Nmap Scanner ==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Description: First access points are scanned, then a connection is established to the open access points, after connecting, the nmap scan runs and analyses the AP, &lt;br /&gt;
the results are saved in the loot folder.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
Settings &lt;br /&gt;
&lt;br /&gt;
NMAP_OPTIONS=&amp;quot;-sP&amp;quot;&lt;br /&gt;
&lt;br /&gt;
LOOT_DIR=/root/loot/open_ap_nmap_scan&lt;br /&gt;
&lt;br /&gt;
MAX_CIDR=20&lt;br /&gt;
&lt;br /&gt;
DEBUG=1&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Step-by-step guide&lt;br /&gt;
&lt;br /&gt;
    1) download the payload [https://github.com/hak5/signalowl-payloads/blob/master/payloads/library/wifi/Open-AP-Nmap-Scanner/payload.txt payload]&lt;br /&gt;
    2) store the payload in a usb stick and plug the stick into the signal owl&lt;br /&gt;
    3) after connecting the signal owl, the payload is loaded on the root folder and the scan starts. &lt;br /&gt;
    4) once successfully executed, you can start the signal owl in arming mode and see the results in the loot folder.&lt;br /&gt;
      example loot Directory&lt;br /&gt;
      [[File:ArmingmodeSSHloot.png]][Eigene Darstellung]&lt;br /&gt;
&lt;br /&gt;
== Arming Mode connection ==&lt;br /&gt;
&lt;br /&gt;
Step-by-step guide for accessing the arming mode&lt;br /&gt;
   1) click on the button located on the bottom of the signal owl while it is in attack mode. After pressing the button, the signal owl enters the arming &lt;br /&gt;
      mode and provides an open access point with the name Owl xxxx (where xxxx stands for the last two digits of the MAC address of the device).&lt;br /&gt;
   2) Connect to the access point. &lt;br /&gt;
      [[File:Armingmode.png]][Eigene Darstellung]&lt;br /&gt;
   3) Now you can connect via ssh by using the username and password (default: Username: root, Password: hak5owl, IP Address: 172.16.56.1)&lt;br /&gt;
   4) after successful connection you will end up in root@Owl directory&lt;br /&gt;
      [[File:ArmingmodeSSH.png]][Eigene Darstellung]&lt;br /&gt;
   5) Now you can enter the directories loot and payload to either view the results or to make further settings&lt;br /&gt;
      &lt;br /&gt;
&lt;br /&gt;
      example Directory structure&lt;br /&gt;
      [[File:ArmingmodeSSHdirectories.png]][Eigene Darstellung]&lt;br /&gt;
&lt;br /&gt;
== Use Cases ==&lt;br /&gt;
&lt;br /&gt;
The Signal Owl has a variety of different use cases. Among the most popular ones are classical network mapping and wardriving as well as basic penetration tests for different wireless technologies.&lt;br /&gt;
&lt;br /&gt;
== Used Hardware ==&lt;br /&gt;
&lt;br /&gt;
[[Signal Owl]]&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
* https://docs.hak5.org/signal-owl/&lt;br /&gt;
*https://github.com/hak5/signalowl-payloads&lt;br /&gt;
&lt;br /&gt;
[[Category:Pentesting]]&lt;/div&gt;</summary>
		<author><name>MMayer</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=Hak5_Signal_Owl&amp;diff=10624</id>
		<title>Hak5 Signal Owl</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=Hak5_Signal_Owl&amp;diff=10624"/>
		<updated>2023-01-05T17:18:51Z</updated>

		<summary type="html">&lt;p&gt;MMayer: /* Modes of Operation */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Summary ==&lt;br /&gt;
&lt;br /&gt;
The [https://docs.hak5.org/signal-owl/ Signal Owl] is a hardware product developed by the company Hak5.&lt;br /&gt;
It is a simple payload-based signals intelligence platform with a unique design for discreet planting or mobile operations on any engagement. The most popular application cases include classic network mapping and basic penetration tests for various wireless technologies.&lt;br /&gt;
&lt;br /&gt;
== Description ==&lt;br /&gt;
&lt;br /&gt;
[[File:SignalOwlDiagram.png|thumb|500px|frame|Components of the Signal Owl [Eigene Darstellung]]] &lt;br /&gt;
&lt;br /&gt;
The Signal Owl is designed to be rapidly deployed in all kinds of environments, allowing it to be an entry point for network analysis and basic wireless attacks in a variety of locations. With a power consumption of 100-200 mAh and the thermally optimized architecture, mobile operations as well as long term deployments, are enabled.&lt;br /&gt;
&lt;br /&gt;
=== Components ===&lt;br /&gt;
&lt;br /&gt;
This device features several components of which some may not be visible to the human eye at first sight.&lt;br /&gt;
&lt;br /&gt;
==== USB Power / Passthrough Plug ====&lt;br /&gt;
&lt;br /&gt;
The USB power or passthrough plug is used to power the device. It can be powered from any reliable USB source.&lt;br /&gt;
&lt;br /&gt;
==== USB 2.0 Passthrough Port ====&lt;br /&gt;
&lt;br /&gt;
The USB 2.0 passthrough port is the port closest to the pigtail. Data and power pass through to that port, allowing for implant operations. With devices like keyboards plugged plugged inline between this passthrough port and the power plug connected to the target computer, the Signal Owl will remain undetected from the operating system. Only the keyboard will be visible.&lt;br /&gt;
&lt;br /&gt;
==== USB 2.0 Host Port ====&lt;br /&gt;
&lt;br /&gt;
The USB 2.0 host port is the port farthest away from the pigtail. It is connected to the Linux socket of the Signal Owl and supports USB flash drives formatted with FAT32 and EXT4 file systems as well as many Wi-Fi, Bluetooth and other RF transceivers.&lt;br /&gt;
&lt;br /&gt;
==== Button ====&lt;br /&gt;
&lt;br /&gt;
The button on the bottom of the device is used to enter Arming Mode and to interact with payloads. It is not pressable without special tools like paperclips.&lt;br /&gt;
&lt;br /&gt;
==== Status LED ====&lt;br /&gt;
&lt;br /&gt;
The status LED indicates the current status of the Signal Owl. When turned off, it is not visible.&lt;br /&gt;
&lt;br /&gt;
=== Implant / mobile operations ===&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Implant operations&lt;br /&gt;
&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
During long term wireless engagements, the Signal Owl may be planted inline between any typical 5V USB power source. This may be useful in situations where ports are occupied, or to deter the unit from being unplugged.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Mobile operations&lt;br /&gt;
&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
The Signal Owl features a low power consumption profile, with a typical power draw averaging 100-200 mAh. Additionally, it is thermally optimized for long term deployments in many indoor environments. One can expect a large 20,000 mAh USB battery bank to operate the unit for up to 4 days.&lt;br /&gt;
&lt;br /&gt;
=== Default Settings ===&lt;br /&gt;
&lt;br /&gt;
Default settings that are used in order to access the device via SSH are pictured in the table below.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
!colspan=&amp;quot;2&amp;quot;|Default Settings&lt;br /&gt;
|-&lt;br /&gt;
|Username&lt;br /&gt;
|root&lt;br /&gt;
|-&lt;br /&gt;
|Password&lt;br /&gt;
|hak5owl&lt;br /&gt;
|-&lt;br /&gt;
|SSID&lt;br /&gt;
|Owl_xxxx&lt;br /&gt;
|-&lt;br /&gt;
|IP Address&lt;br /&gt;
|172.16.56.1&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
SSH command: &amp;lt;code&amp;gt;ssh root@172.16.56.1&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The SSID during Arming Mode is Owl_xxxx in which xxxx indicates the last two octets of the devices MAC address.&lt;br /&gt;
&lt;br /&gt;
=== LED Status Indications ===&lt;br /&gt;
&lt;br /&gt;
The Signal Owl features a red LED with the following default status indications:&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
!|LED&lt;br /&gt;
!|Status&lt;br /&gt;
|-&lt;br /&gt;
|Blinking&lt;br /&gt;
|Booting&lt;br /&gt;
|-&lt;br /&gt;
|Solid&lt;br /&gt;
|Mounting external storage / Running upgrade&lt;br /&gt;
|-&lt;br /&gt;
|Single blinking&lt;br /&gt;
|Attack Mode&lt;br /&gt;
|-&lt;br /&gt;
|Double blinking&lt;br /&gt;
|Arming Mode&lt;br /&gt;
|-&lt;br /&gt;
|Slow blinking&lt;br /&gt;
|Error running payload&lt;br /&gt;
|-&lt;br /&gt;
|Fast blinking&lt;br /&gt;
|Select Mode (Deprecated from version 1.0.1 onward)&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== Modes of Operation ===&lt;br /&gt;
&lt;br /&gt;
The Signal Owl comes with two modes of operation, Attack Mode and Arming Mode. By default, the device will boot into Attack Mode. In order to access Arming Mode, the button on the bottom of the device has to be pressed while in Attack Mode. It is not recommended to press the button during the boot sequence, as this can possibly brick the device and render it useless. The arming mode is used for firmware updates and shell access, while the attack mode is used to load and execute a payload and payload extensions.&lt;br /&gt;
&lt;br /&gt;
==== Attack Mode ====&lt;br /&gt;
&lt;br /&gt;
Attack Mode is the default mode, the Signal Owl boots into. It provides two basic functions, being the payload loading function and the payload execution function. The payload loading function checks for any USB flash drives plugged into the host port of the device and copies payloads and extensions to the root of the Signal Owl. The payload execution function is responsible for executing the payload that is currently stored on the root of the Signal Owl. In case no payload is found, the device will blink slowly, indicating the FAIL status.&lt;br /&gt;
&lt;br /&gt;
==== Arming Mode ====&lt;br /&gt;
&lt;br /&gt;
The Arming Mode provides two basic functions, being the firmware update function and the shell access function. The firmware update function checks for any USB flash drives plugged into the host port of the device and copies firmware upgrade files into the internal storage of the device and flashes it. The shell access function starts an open access point with the SSID Owl_xxxx in which xxxx indicates the last two octets of the device&#039;s MAC address. Additionally, a SSH server providing access to the shell of the Signal Owl is enabled.&lt;br /&gt;
&lt;br /&gt;
=== Initial Setup ===&lt;br /&gt;
&lt;br /&gt;
When first unboxing the Signal Owl, the device runs a stager firmware that is designed to flash the latest firmware from a USB flash drive. In order to update the Signal Owl, the [https://downloads.hak5.org/owl latest firmware] has to be downloaded. Then, the downloaded file must be copied to the root of an EXT4 or FAT32 formatted USB flash drive. It is important not to modify this file. The next step is to plug the USB flash drive into the powered off Signal Owl. Afterwards, the device has to be powered on by a reliable USB source. The upgrade itself takes approximately five to ten minutes and is indicated by a solid red LED light. When finished, the device will reboot, enter Attack Mode and blink slowly, indicating an error running the payload because no payload has been found.&lt;br /&gt;
&lt;br /&gt;
=== Payload Development ===&lt;br /&gt;
&lt;br /&gt;
Payloads for the Signal Owl are written in bash with [https://github.com/hak5darren/USB-Rubber-Ducky/wiki/Duckyscript Ducky Script] and can be created with any standard text editor. All payloads should begin with an interpreter directive, like the shebang #!/bin/bash for bash payloads and payloads must be named either payload.txt or payload.sh. In order to create effective payloads, the Signal Owl comes with several preinstalled penetration testing tools. These are as follows: [https://nmap.org/ Nmap], [https://www.aircrack-ng.org/ Aircrack-ng], [https://github.com/aircrack-ng/mdk4 MDK4] and [https://www.kismetwireless.net/ Kismet].&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Tools&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
• Kismet - detector for wireless networks and devices.&lt;br /&gt;
&lt;br /&gt;
• MDK4 - Wi-Fi testing tool.&lt;br /&gt;
&lt;br /&gt;
• Aircrack-ng Suite - a complete suite of tools for WiFi network security assessment.&lt;br /&gt;
&lt;br /&gt;
• Nmap - open source utility for network discovery and security auditing.&lt;br /&gt;
&lt;br /&gt;
=== Adding Payloads and Extensions ===&lt;br /&gt;
&lt;br /&gt;
Payloads can be stored on the internal storage of the Signal Owl as well as on a USB flash drive. When booting, payloads on USB flash drives are given priority and will override payloads stored on the Signal Owl. If no payload is found on the external storage and a payload is present on the internal storage, the internally stored payload will be executed. In case no payload is found on both internal and external storage, the Signal Owl will blink slowly. To successfully copy a payload to the Signal Owl and execute it, the payload must be named payload.txt or payload.sh and it has to be placed in the root directory of the flash drive. Similarly, payload extensions should be stored in a /extensions directory on the flash drive.&lt;br /&gt;
&lt;br /&gt;
After plugging the Signal Owl into a USB source, it will boot and then copy the payloads and payload extensions to the /root/payload and /root/payload/extensions directory respectively. Then, the device will enter Attack Mode and execute the payload.&lt;br /&gt;
&lt;br /&gt;
== Fake Beacon Flooding Attack ==&lt;br /&gt;
&lt;br /&gt;
The fake beacon flooding attack is one possible use case for the Signal Owl. With that attack, fake beacon frames are broadcasted to nearby devices. Beacon Frames include various parameters like the SSID, the type of encryption used and timestamps. This results in the creation of multiple fake Wi-Fi networks. Devices with Wi-Fi browsers are then flooded with these fake networks, causing potential network scanner and driver crashes. Furthermore, the attack may prevent legitimate users from finding their networks and lead to denial of service. &lt;br /&gt;
To execute the attack with the Signal Owl, the preinstalled tools Aircrack-ng and MDK4 are used. The following bash script is saved as payload.sh and placed on the root of an USB flash drive. Then the USB flash drive is plugged into the Signal Owl. After powering on the device, multiple fake networks with random SSIDs are generated and broadcasted to all nearby devices.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
#!/bin/bash&lt;br /&gt;
&lt;br /&gt;
LED SETUP&lt;br /&gt;
#creates monitor mode interface on wirelss card of the Signal Owl&lt;br /&gt;
airmon-ng start wlan0&lt;br /&gt;
&lt;br /&gt;
LED ATTACK&lt;br /&gt;
#floods nearby devices with random SSIDs&lt;br /&gt;
mdk4 wlan0mon b -w a -m -s 1000&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The results as seen from a victim running a Windows 10 system are pictured in the figure below.&lt;br /&gt;
&lt;br /&gt;
[[File:FakeBeaconFloodingSignalOwl.png|none|Random SSIDs as seen from a victim windows 10 client |]][Eigene Darstellung]&lt;br /&gt;
&lt;br /&gt;
== Open AP Nmap Scanner ==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Description: First access points are scanned, then a connection is established to the open access points, after connecting, the nmap scan runs and analyses the AP, &lt;br /&gt;
the results are saved in the loot folder.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
Settings &lt;br /&gt;
&lt;br /&gt;
NMAP_OPTIONS=&amp;quot;-sP&amp;quot;&lt;br /&gt;
&lt;br /&gt;
LOOT_DIR=/root/loot/open_ap_nmap_scan&lt;br /&gt;
&lt;br /&gt;
MAX_CIDR=20&lt;br /&gt;
&lt;br /&gt;
DEBUG=1&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Step-by-step guide&lt;br /&gt;
&lt;br /&gt;
    1) download the payload [https://github.com/hak5/signalowl-payloads/blob/master/payloads/library/wifi/Open-AP-Nmap-Scanner/payload.txt payload]&lt;br /&gt;
    2) store the payload in a usb stick and plug the stick into the signal owl&lt;br /&gt;
    3) after connecting the signal owl, the payload is loaded on the root folder and the scan starts. &lt;br /&gt;
    4) once successfully executed, you can start the signal owl in arming mode and see the results in the loot folder.&lt;br /&gt;
      example loot Directory&lt;br /&gt;
      [[File:ArmingmodeSSHloot.png]][Eigene Darstellung]&lt;br /&gt;
&lt;br /&gt;
== Arming Mode connection ==&lt;br /&gt;
&lt;br /&gt;
Step-by-step guide for accessing the arming mode&lt;br /&gt;
   1) click on the button located on the bottom of the signal owl while it is in attack mode. After pressing the button, the signal owl enters the arming &lt;br /&gt;
      mode and provides an open access point with the name Owl xxxx (where xxxx stands for the last two digits of the MAC address of the device).&lt;br /&gt;
   2) Connect to the access point. &lt;br /&gt;
      [[File:Armingmode.png]][Eigene Darstellung]&lt;br /&gt;
   3) Now you can connect via ssh by using the username and password (default: Username: root, Password: hak5owl, IP Address: 172.16.56.1)&lt;br /&gt;
   4) after successful connection you will end up in root@Owl directory&lt;br /&gt;
      [[File:ArmingmodeSSH.png]][Eigene Darstellung]&lt;br /&gt;
   5) Now you can enter the directories loot and payload to either view the results or to make further settings&lt;br /&gt;
      &lt;br /&gt;
&lt;br /&gt;
      example Directory structure&lt;br /&gt;
      [[File:ArmingmodeSSHdirectories.png]][Eigene Darstellung]&lt;br /&gt;
&lt;br /&gt;
== Use Cases ==&lt;br /&gt;
&lt;br /&gt;
The Signal Owl has a variety of different use cases. Among the most popular ones are classical network mapping and wardriving as well as basic penetration tests for different wireless technologies.&lt;br /&gt;
&lt;br /&gt;
== Used Hardware ==&lt;br /&gt;
&lt;br /&gt;
[[Signal Owl]]&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
* https://docs.hak5.org/signal-owl/&lt;br /&gt;
*https://github.com/hak5/signalowl-payloads&lt;br /&gt;
&lt;br /&gt;
[[Category:Pentesting]]&lt;/div&gt;</summary>
		<author><name>MMayer</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=Hak5_Signal_Owl&amp;diff=10623</id>
		<title>Hak5 Signal Owl</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=Hak5_Signal_Owl&amp;diff=10623"/>
		<updated>2023-01-05T17:07:55Z</updated>

		<summary type="html">&lt;p&gt;MMayer: /* Summary */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Summary ==&lt;br /&gt;
&lt;br /&gt;
The [https://docs.hak5.org/signal-owl/ Signal Owl] is a hardware product developed by the company Hak5.&lt;br /&gt;
It is a simple payload-based signals intelligence platform with a unique design for discreet planting or mobile operations on any engagement. The most popular application cases include classic network mapping and basic penetration tests for various wireless technologies.&lt;br /&gt;
&lt;br /&gt;
== Description ==&lt;br /&gt;
&lt;br /&gt;
[[File:SignalOwlDiagram.png|thumb|500px|frame|Components of the Signal Owl [Eigene Darstellung]]] &lt;br /&gt;
&lt;br /&gt;
The Signal Owl is designed to be rapidly deployed in all kinds of environments, allowing it to be an entry point for network analysis and basic wireless attacks in a variety of locations. With a power consumption of 100-200 mAh and the thermally optimized architecture, mobile operations as well as long term deployments, are enabled.&lt;br /&gt;
&lt;br /&gt;
=== Components ===&lt;br /&gt;
&lt;br /&gt;
This device features several components of which some may not be visible to the human eye at first sight.&lt;br /&gt;
&lt;br /&gt;
==== USB Power / Passthrough Plug ====&lt;br /&gt;
&lt;br /&gt;
The USB power or passthrough plug is used to power the device. It can be powered from any reliable USB source.&lt;br /&gt;
&lt;br /&gt;
==== USB 2.0 Passthrough Port ====&lt;br /&gt;
&lt;br /&gt;
The USB 2.0 passthrough port is the port closest to the pigtail. Data and power pass through to that port, allowing for implant operations. With devices like keyboards plugged plugged inline between this passthrough port and the power plug connected to the target computer, the Signal Owl will remain undetected from the operating system. Only the keyboard will be visible.&lt;br /&gt;
&lt;br /&gt;
==== USB 2.0 Host Port ====&lt;br /&gt;
&lt;br /&gt;
The USB 2.0 host port is the port farthest away from the pigtail. It is connected to the Linux socket of the Signal Owl and supports USB flash drives formatted with FAT32 and EXT4 file systems as well as many Wi-Fi, Bluetooth and other RF transceivers.&lt;br /&gt;
&lt;br /&gt;
==== Button ====&lt;br /&gt;
&lt;br /&gt;
The button on the bottom of the device is used to enter Arming Mode and to interact with payloads. It is not pressable without special tools like paperclips.&lt;br /&gt;
&lt;br /&gt;
==== Status LED ====&lt;br /&gt;
&lt;br /&gt;
The status LED indicates the current status of the Signal Owl. When turned off, it is not visible.&lt;br /&gt;
&lt;br /&gt;
=== Implant / mobile operations ===&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Implant operations&lt;br /&gt;
&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
During long term wireless engagements, the Signal Owl may be planted inline between any typical 5V USB power source. This may be useful in situations where ports are occupied, or to deter the unit from being unplugged.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Mobile operations&lt;br /&gt;
&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
The Signal Owl features a low power consumption profile, with a typical power draw averaging 100-200 mAh. Additionally, it is thermally optimized for long term deployments in many indoor environments. One can expect a large 20,000 mAh USB battery bank to operate the unit for up to 4 days.&lt;br /&gt;
&lt;br /&gt;
=== Default Settings ===&lt;br /&gt;
&lt;br /&gt;
Default settings that are used in order to access the device via SSH are pictured in the table below.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
!colspan=&amp;quot;2&amp;quot;|Default Settings&lt;br /&gt;
|-&lt;br /&gt;
|Username&lt;br /&gt;
|root&lt;br /&gt;
|-&lt;br /&gt;
|Password&lt;br /&gt;
|hak5owl&lt;br /&gt;
|-&lt;br /&gt;
|SSID&lt;br /&gt;
|Owl_xxxx&lt;br /&gt;
|-&lt;br /&gt;
|IP Address&lt;br /&gt;
|172.16.56.1&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
SSH command: &amp;lt;code&amp;gt;ssh root@172.16.56.1&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The SSID during Arming Mode is Owl_xxxx in which xxxx indicates the last two octets of the devices MAC address.&lt;br /&gt;
&lt;br /&gt;
=== LED Status Indications ===&lt;br /&gt;
&lt;br /&gt;
The Signal Owl features a red LED with the following default status indications:&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
!|LED&lt;br /&gt;
!|Status&lt;br /&gt;
|-&lt;br /&gt;
|Blinking&lt;br /&gt;
|Booting&lt;br /&gt;
|-&lt;br /&gt;
|Solid&lt;br /&gt;
|Mounting external storage / Running upgrade&lt;br /&gt;
|-&lt;br /&gt;
|Single blinking&lt;br /&gt;
|Attack Mode&lt;br /&gt;
|-&lt;br /&gt;
|Double blinking&lt;br /&gt;
|Arming Mode&lt;br /&gt;
|-&lt;br /&gt;
|Slow blinking&lt;br /&gt;
|Error running payload&lt;br /&gt;
|-&lt;br /&gt;
|Fast blinking&lt;br /&gt;
|Select Mode (Deprecated from version 1.0.1 onward)&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== Modes of Operation ===&lt;br /&gt;
&lt;br /&gt;
The Signal Owl comes with two modes of operation, Attack Mode and Arming Mode. By default, the device will boot into Attack Mode. In order to access Arming Mode, the button on the bottom of the device has to be pressed while in Attack Mode. It is not recommended to press the button during the boot sequence as this can possibly brick the device and render it useless. The arming mode is used for firmware updates and shell access, while the attack mode is used to load and execute the payload.&lt;br /&gt;
&lt;br /&gt;
==== Attack Mode ====&lt;br /&gt;
&lt;br /&gt;
Attack Mode is the default mode, the Signal Owl boots into. It provides two basic functions, being the payload loading function and the payload execution function. The payload loading function checks for any USB flash drives plugged into the host port of the device and copies payloads and extensions to the root of the Signal Owl. The payload execution function is responsible for executing the payload that is currently stored on the root of the Signal Owl. In case no payload is found, the device will blink slowly, indicating the FAIL status.&lt;br /&gt;
&lt;br /&gt;
==== Arming Mode ====&lt;br /&gt;
&lt;br /&gt;
The Arming Mode provides two basic functions, being the firmware update function and the shell access function. The firmware update function checks for any USB flash drives plugged into the host port of the device and copies firmware upgrade files into the internal storage of the device and flashes it. The shell access function starts an open access point with the SSID Owl_xxxx in which xxxx indicates the last two octets of the devices MAC address. Additionally, a SSH server providing access to the shell of the Signal Owl is enabled.&lt;br /&gt;
&lt;br /&gt;
=== Initial Setup ===&lt;br /&gt;
&lt;br /&gt;
When first unboxing the Signal Owl, the device runs a stager firmware that is designed to flash the latest firmware from a USB flash drive. In order to update the Signal Owl, the [https://downloads.hak5.org/owl latest firmware] has to be downloaded. Then, the downloaded file must be copied to the root of an EXT4 or FAT32 formatted USB flash drive. It is important not to modify this file. The next step is to plug the USB flash drive into the powered off Signal Owl. Afterwards, the device has to be powered on by a reliable USB source. The upgrade itself takes approximately five to ten minutes and is indicated by a solid red LED light. When finished, the device will reboot, enter Attack Mode and blink slowly, indicating an error running the payload because no payload has been found.&lt;br /&gt;
&lt;br /&gt;
=== Payload Development ===&lt;br /&gt;
&lt;br /&gt;
Payloads for the Signal Owl are written in bash with [https://github.com/hak5darren/USB-Rubber-Ducky/wiki/Duckyscript Ducky Script] and can be created with any standard text editor. All payloads should begin with an interpreter directive, like the shebang #!/bin/bash for bash payloads and payloads must be named either payload.txt or payload.sh. In order to create effective payloads, the Signal Owl comes with several preinstalled penetration testing tools. These are as follows: [https://nmap.org/ Nmap], [https://www.aircrack-ng.org/ Aircrack-ng], [https://github.com/aircrack-ng/mdk4 MDK4] and [https://www.kismetwireless.net/ Kismet].&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Tools&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
• Kismet - detector for wireless networks and devices.&lt;br /&gt;
&lt;br /&gt;
• MDK4 - Wi-Fi testing tool.&lt;br /&gt;
&lt;br /&gt;
• Aircrack-ng Suite - a complete suite of tools for WiFi network security assessment.&lt;br /&gt;
&lt;br /&gt;
• Nmap - open source utility for network discovery and security auditing.&lt;br /&gt;
&lt;br /&gt;
=== Adding Payloads and Extensions ===&lt;br /&gt;
&lt;br /&gt;
Payloads can be stored on the internal storage of the Signal Owl as well as on a USB flash drive. When booting, payloads on USB flash drives are given priority and will override payloads stored on the Signal Owl. If no payload is found on the external storage and a payload is present on the internal storage, the internally stored payload will be executed. In case no payload is found on both internal and external storage, the Signal Owl will blink slowly. To successfully copy a payload to the Signal Owl and execute it, the payload must be named payload.txt or payload.sh and it has to be placed in the root directory of the flash drive. Similarly, payload extensions should be stored in a /extensions directory on the flash drive.&lt;br /&gt;
&lt;br /&gt;
After plugging the Signal Owl into a USB source, it will boot and then copy the payloads and payload extensions to the /root/payload and /root/payload/extensions directory respectively. Then, the device will enter Attack Mode and execute the payload.&lt;br /&gt;
&lt;br /&gt;
== Fake Beacon Flooding Attack ==&lt;br /&gt;
&lt;br /&gt;
The fake beacon flooding attack is one possible use case for the Signal Owl. With that attack, fake beacon frames are broadcasted to nearby devices. Beacon Frames include various parameters like the SSID, the type of encryption used and timestamps. This results in the creation of multiple fake Wi-Fi networks. Devices with Wi-Fi browsers are then flooded with these fake networks, causing potential network scanner and driver crashes. Furthermore, the attack may prevent legitimate users from finding their networks and lead to denial of service. &lt;br /&gt;
To execute the attack with the Signal Owl, the preinstalled tools Aircrack-ng and MDK4 are used. The following bash script is saved as payload.sh and placed on the root of an USB flash drive. Then the USB flash drive is plugged into the Signal Owl. After powering on the device, multiple fake networks with random SSIDs are generated and broadcasted to all nearby devices.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
#!/bin/bash&lt;br /&gt;
&lt;br /&gt;
LED SETUP&lt;br /&gt;
#creates monitor mode interface on wirelss card of the Signal Owl&lt;br /&gt;
airmon-ng start wlan0&lt;br /&gt;
&lt;br /&gt;
LED ATTACK&lt;br /&gt;
#floods nearby devices with random SSIDs&lt;br /&gt;
mdk4 wlan0mon b -w a -m -s 1000&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The results as seen from a victim running a Windows 10 system are pictured in the figure below.&lt;br /&gt;
&lt;br /&gt;
[[File:FakeBeaconFloodingSignalOwl.png|none|Random SSIDs as seen from a victim windows 10 client |]][Eigene Darstellung]&lt;br /&gt;
&lt;br /&gt;
== Open AP Nmap Scanner ==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Description: First access points are scanned, then a connection is established to the open access points, after connecting, the nmap scan runs and analyses the AP, &lt;br /&gt;
the results are saved in the loot folder.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
Settings &lt;br /&gt;
&lt;br /&gt;
NMAP_OPTIONS=&amp;quot;-sP&amp;quot;&lt;br /&gt;
&lt;br /&gt;
LOOT_DIR=/root/loot/open_ap_nmap_scan&lt;br /&gt;
&lt;br /&gt;
MAX_CIDR=20&lt;br /&gt;
&lt;br /&gt;
DEBUG=1&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Step-by-step guide&lt;br /&gt;
&lt;br /&gt;
    1) download the payload [https://github.com/hak5/signalowl-payloads/blob/master/payloads/library/wifi/Open-AP-Nmap-Scanner/payload.txt payload]&lt;br /&gt;
    2) store the payload in a usb stick and plug the stick into the signal owl&lt;br /&gt;
    3) after connecting the signal owl, the payload is loaded on the root folder and the scan starts. &lt;br /&gt;
    4) once successfully executed, you can start the signal owl in arming mode and see the results in the loot folder.&lt;br /&gt;
      example loot Directory&lt;br /&gt;
      [[File:ArmingmodeSSHloot.png]][Eigene Darstellung]&lt;br /&gt;
&lt;br /&gt;
== Arming Mode connection ==&lt;br /&gt;
&lt;br /&gt;
Step-by-step guide for accessing the arming mode&lt;br /&gt;
   1) click on the button located on the bottom of the signal owl while it is in attack mode. After pressing the button, the signal owl enters the arming &lt;br /&gt;
      mode and provides an open access point with the name Owl xxxx (where xxxx stands for the last two digits of the MAC address of the device).&lt;br /&gt;
   2) Connect to the access point. &lt;br /&gt;
      [[File:Armingmode.png]][Eigene Darstellung]&lt;br /&gt;
   3) Now you can connect via ssh by using the username and password (default: Username: root, Password: hak5owl, IP Address: 172.16.56.1)&lt;br /&gt;
   4) after successful connection you will end up in root@Owl directory&lt;br /&gt;
      [[File:ArmingmodeSSH.png]][Eigene Darstellung]&lt;br /&gt;
   5) Now you can enter the directories loot and payload to either view the results or to make further settings&lt;br /&gt;
      &lt;br /&gt;
&lt;br /&gt;
      example Directory structure&lt;br /&gt;
      [[File:ArmingmodeSSHdirectories.png]][Eigene Darstellung]&lt;br /&gt;
&lt;br /&gt;
== Use Cases ==&lt;br /&gt;
&lt;br /&gt;
The Signal Owl has a variety of different use cases. Among the most popular ones are classical network mapping and wardriving as well as basic penetration tests for different wireless technologies.&lt;br /&gt;
&lt;br /&gt;
== Used Hardware ==&lt;br /&gt;
&lt;br /&gt;
[[Signal Owl]]&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
* https://docs.hak5.org/signal-owl/&lt;br /&gt;
*https://github.com/hak5/signalowl-payloads&lt;br /&gt;
&lt;br /&gt;
[[Category:Pentesting]]&lt;/div&gt;</summary>
		<author><name>MMayer</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=Hak5_Signal_Owl&amp;diff=10622</id>
		<title>Hak5 Signal Owl</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=Hak5_Signal_Owl&amp;diff=10622"/>
		<updated>2023-01-05T16:59:40Z</updated>

		<summary type="html">&lt;p&gt;MMayer: /* Default Settings */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Summary ==&lt;br /&gt;
&lt;br /&gt;
The [https://docs.hak5.org/hc/en-us/categories/360002117953-Signal-Owl Signal Owl] is a hardware product developed by the company Hak5.&lt;br /&gt;
It is a simple payload-based signals intelligence platform with a unique design for discreet planting or mobile operations on any engagement. The most popular application cases include classic network mapping and basic penetration tests for various wireless technologies.&lt;br /&gt;
&lt;br /&gt;
== Description ==&lt;br /&gt;
&lt;br /&gt;
[[File:SignalOwlDiagram.png|thumb|500px|frame|Components of the Signal Owl [Eigene Darstellung]]] &lt;br /&gt;
&lt;br /&gt;
The Signal Owl is designed to be rapidly deployed in all kinds of environments, allowing it to be an entry point for network analysis and basic wireless attacks in a variety of locations. With a power consumption of 100-200 mAh and the thermally optimized architecture, mobile operations as well as long term deployments, are enabled.&lt;br /&gt;
&lt;br /&gt;
=== Components ===&lt;br /&gt;
&lt;br /&gt;
This device features several components of which some may not be visible to the human eye at first sight.&lt;br /&gt;
&lt;br /&gt;
==== USB Power / Passthrough Plug ====&lt;br /&gt;
&lt;br /&gt;
The USB power or passthrough plug is used to power the device. It can be powered from any reliable USB source.&lt;br /&gt;
&lt;br /&gt;
==== USB 2.0 Passthrough Port ====&lt;br /&gt;
&lt;br /&gt;
The USB 2.0 passthrough port is the port closest to the pigtail. Data and power pass through to that port, allowing for implant operations. With devices like keyboards plugged plugged inline between this passthrough port and the power plug connected to the target computer, the Signal Owl will remain undetected from the operating system. Only the keyboard will be visible.&lt;br /&gt;
&lt;br /&gt;
==== USB 2.0 Host Port ====&lt;br /&gt;
&lt;br /&gt;
The USB 2.0 host port is the port farthest away from the pigtail. It is connected to the Linux socket of the Signal Owl and supports USB flash drives formatted with FAT32 and EXT4 file systems as well as many Wi-Fi, Bluetooth and other RF transceivers.&lt;br /&gt;
&lt;br /&gt;
==== Button ====&lt;br /&gt;
&lt;br /&gt;
The button on the bottom of the device is used to enter Arming Mode and to interact with payloads. It is not pressable without special tools like paperclips.&lt;br /&gt;
&lt;br /&gt;
==== Status LED ====&lt;br /&gt;
&lt;br /&gt;
The status LED indicates the current status of the Signal Owl. When turned off, it is not visible.&lt;br /&gt;
&lt;br /&gt;
=== Implant / mobile operations ===&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Implant operations&lt;br /&gt;
&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
During long term wireless engagements, the Signal Owl may be planted inline between any typical 5V USB power source. This may be useful in situations where ports are occupied, or to deter the unit from being unplugged.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Mobile operations&lt;br /&gt;
&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
The Signal Owl features a low power consumption profile, with a typical power draw averaging 100-200 mAh. Additionally, it is thermally optimized for long term deployments in many indoor environments. One can expect a large 20,000 mAh USB battery bank to operate the unit for up to 4 days.&lt;br /&gt;
&lt;br /&gt;
=== Default Settings ===&lt;br /&gt;
&lt;br /&gt;
Default settings that are used in order to access the device via SSH are pictured in the table below.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
!colspan=&amp;quot;2&amp;quot;|Default Settings&lt;br /&gt;
|-&lt;br /&gt;
|Username&lt;br /&gt;
|root&lt;br /&gt;
|-&lt;br /&gt;
|Password&lt;br /&gt;
|hak5owl&lt;br /&gt;
|-&lt;br /&gt;
|SSID&lt;br /&gt;
|Owl_xxxx&lt;br /&gt;
|-&lt;br /&gt;
|IP Address&lt;br /&gt;
|172.16.56.1&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
SSH command: &amp;lt;code&amp;gt;ssh root@172.16.56.1&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The SSID during Arming Mode is Owl_xxxx in which xxxx indicates the last two octets of the devices MAC address.&lt;br /&gt;
&lt;br /&gt;
=== LED Status Indications ===&lt;br /&gt;
&lt;br /&gt;
The Signal Owl features a red LED with the following default status indications:&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
!|LED&lt;br /&gt;
!|Status&lt;br /&gt;
|-&lt;br /&gt;
|Blinking&lt;br /&gt;
|Booting&lt;br /&gt;
|-&lt;br /&gt;
|Solid&lt;br /&gt;
|Mounting external storage / Running upgrade&lt;br /&gt;
|-&lt;br /&gt;
|Single blinking&lt;br /&gt;
|Attack Mode&lt;br /&gt;
|-&lt;br /&gt;
|Double blinking&lt;br /&gt;
|Arming Mode&lt;br /&gt;
|-&lt;br /&gt;
|Slow blinking&lt;br /&gt;
|Error running payload&lt;br /&gt;
|-&lt;br /&gt;
|Fast blinking&lt;br /&gt;
|Select Mode (Deprecated from version 1.0.1 onward)&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== Modes of Operation ===&lt;br /&gt;
&lt;br /&gt;
The Signal Owl comes with two modes of operation, Attack Mode and Arming Mode. By default, the device will boot into Attack Mode. In order to access Arming Mode, the button on the bottom of the device has to be pressed while in Attack Mode. It is not recommended to press the button during the boot sequence as this can possibly brick the device and render it useless. The arming mode is used for firmware updates and shell access, while the attack mode is used to load and execute the payload.&lt;br /&gt;
&lt;br /&gt;
==== Attack Mode ====&lt;br /&gt;
&lt;br /&gt;
Attack Mode is the default mode, the Signal Owl boots into. It provides two basic functions, being the payload loading function and the payload execution function. The payload loading function checks for any USB flash drives plugged into the host port of the device and copies payloads and extensions to the root of the Signal Owl. The payload execution function is responsible for executing the payload that is currently stored on the root of the Signal Owl. In case no payload is found, the device will blink slowly, indicating the FAIL status.&lt;br /&gt;
&lt;br /&gt;
==== Arming Mode ====&lt;br /&gt;
&lt;br /&gt;
The Arming Mode provides two basic functions, being the firmware update function and the shell access function. The firmware update function checks for any USB flash drives plugged into the host port of the device and copies firmware upgrade files into the internal storage of the device and flashes it. The shell access function starts an open access point with the SSID Owl_xxxx in which xxxx indicates the last two octets of the devices MAC address. Additionally, a SSH server providing access to the shell of the Signal Owl is enabled.&lt;br /&gt;
&lt;br /&gt;
=== Initial Setup ===&lt;br /&gt;
&lt;br /&gt;
When first unboxing the Signal Owl, the device runs a stager firmware that is designed to flash the latest firmware from a USB flash drive. In order to update the Signal Owl, the [https://downloads.hak5.org/owl latest firmware] has to be downloaded. Then, the downloaded file must be copied to the root of an EXT4 or FAT32 formatted USB flash drive. It is important not to modify this file. The next step is to plug the USB flash drive into the powered off Signal Owl. Afterwards, the device has to be powered on by a reliable USB source. The upgrade itself takes approximately five to ten minutes and is indicated by a solid red LED light. When finished, the device will reboot, enter Attack Mode and blink slowly, indicating an error running the payload because no payload has been found.&lt;br /&gt;
&lt;br /&gt;
=== Payload Development ===&lt;br /&gt;
&lt;br /&gt;
Payloads for the Signal Owl are written in bash with [https://github.com/hak5darren/USB-Rubber-Ducky/wiki/Duckyscript Ducky Script] and can be created with any standard text editor. All payloads should begin with an interpreter directive, like the shebang #!/bin/bash for bash payloads and payloads must be named either payload.txt or payload.sh. In order to create effective payloads, the Signal Owl comes with several preinstalled penetration testing tools. These are as follows: [https://nmap.org/ Nmap], [https://www.aircrack-ng.org/ Aircrack-ng], [https://github.com/aircrack-ng/mdk4 MDK4] and [https://www.kismetwireless.net/ Kismet].&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Tools&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
• Kismet - detector for wireless networks and devices.&lt;br /&gt;
&lt;br /&gt;
• MDK4 - Wi-Fi testing tool.&lt;br /&gt;
&lt;br /&gt;
• Aircrack-ng Suite - a complete suite of tools for WiFi network security assessment.&lt;br /&gt;
&lt;br /&gt;
• Nmap - open source utility for network discovery and security auditing.&lt;br /&gt;
&lt;br /&gt;
=== Adding Payloads and Extensions ===&lt;br /&gt;
&lt;br /&gt;
Payloads can be stored on the internal storage of the Signal Owl as well as on a USB flash drive. When booting, payloads on USB flash drives are given priority and will override payloads stored on the Signal Owl. If no payload is found on the external storage and a payload is present on the internal storage, the internally stored payload will be executed. In case no payload is found on both internal and external storage, the Signal Owl will blink slowly. To successfully copy a payload to the Signal Owl and execute it, the payload must be named payload.txt or payload.sh and it has to be placed in the root directory of the flash drive. Similarly, payload extensions should be stored in a /extensions directory on the flash drive.&lt;br /&gt;
&lt;br /&gt;
After plugging the Signal Owl into a USB source, it will boot and then copy the payloads and payload extensions to the /root/payload and /root/payload/extensions directory respectively. Then, the device will enter Attack Mode and execute the payload.&lt;br /&gt;
&lt;br /&gt;
== Fake Beacon Flooding Attack ==&lt;br /&gt;
&lt;br /&gt;
The fake beacon flooding attack is one possible use case for the Signal Owl. With that attack, fake beacon frames are broadcasted to nearby devices. Beacon Frames include various parameters like the SSID, the type of encryption used and timestamps. This results in the creation of multiple fake Wi-Fi networks. Devices with Wi-Fi browsers are then flooded with these fake networks, causing potential network scanner and driver crashes. Furthermore, the attack may prevent legitimate users from finding their networks and lead to denial of service. &lt;br /&gt;
To execute the attack with the Signal Owl, the preinstalled tools Aircrack-ng and MDK4 are used. The following bash script is saved as payload.sh and placed on the root of an USB flash drive. Then the USB flash drive is plugged into the Signal Owl. After powering on the device, multiple fake networks with random SSIDs are generated and broadcasted to all nearby devices.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
#!/bin/bash&lt;br /&gt;
&lt;br /&gt;
LED SETUP&lt;br /&gt;
#creates monitor mode interface on wirelss card of the Signal Owl&lt;br /&gt;
airmon-ng start wlan0&lt;br /&gt;
&lt;br /&gt;
LED ATTACK&lt;br /&gt;
#floods nearby devices with random SSIDs&lt;br /&gt;
mdk4 wlan0mon b -w a -m -s 1000&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The results as seen from a victim running a Windows 10 system are pictured in the figure below.&lt;br /&gt;
&lt;br /&gt;
[[File:FakeBeaconFloodingSignalOwl.png|none|Random SSIDs as seen from a victim windows 10 client |]][Eigene Darstellung]&lt;br /&gt;
&lt;br /&gt;
== Open AP Nmap Scanner ==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Description: First access points are scanned, then a connection is established to the open access points, after connecting, the nmap scan runs and analyses the AP, &lt;br /&gt;
the results are saved in the loot folder.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
Settings &lt;br /&gt;
&lt;br /&gt;
NMAP_OPTIONS=&amp;quot;-sP&amp;quot;&lt;br /&gt;
&lt;br /&gt;
LOOT_DIR=/root/loot/open_ap_nmap_scan&lt;br /&gt;
&lt;br /&gt;
MAX_CIDR=20&lt;br /&gt;
&lt;br /&gt;
DEBUG=1&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Step-by-step guide&lt;br /&gt;
&lt;br /&gt;
    1) download the payload [https://github.com/hak5/signalowl-payloads/blob/master/payloads/library/wifi/Open-AP-Nmap-Scanner/payload.txt payload]&lt;br /&gt;
    2) store the payload in a usb stick and plug the stick into the signal owl&lt;br /&gt;
    3) after connecting the signal owl, the payload is loaded on the root folder and the scan starts. &lt;br /&gt;
    4) once successfully executed, you can start the signal owl in arming mode and see the results in the loot folder.&lt;br /&gt;
      example loot Directory&lt;br /&gt;
      [[File:ArmingmodeSSHloot.png]][Eigene Darstellung]&lt;br /&gt;
&lt;br /&gt;
== Arming Mode connection ==&lt;br /&gt;
&lt;br /&gt;
Step-by-step guide for accessing the arming mode&lt;br /&gt;
   1) click on the button located on the bottom of the signal owl while it is in attack mode. After pressing the button, the signal owl enters the arming &lt;br /&gt;
      mode and provides an open access point with the name Owl xxxx (where xxxx stands for the last two digits of the MAC address of the device).&lt;br /&gt;
   2) Connect to the access point. &lt;br /&gt;
      [[File:Armingmode.png]][Eigene Darstellung]&lt;br /&gt;
   3) Now you can connect via ssh by using the username and password (default: Username: root, Password: hak5owl, IP Address: 172.16.56.1)&lt;br /&gt;
   4) after successful connection you will end up in root@Owl directory&lt;br /&gt;
      [[File:ArmingmodeSSH.png]][Eigene Darstellung]&lt;br /&gt;
   5) Now you can enter the directories loot and payload to either view the results or to make further settings&lt;br /&gt;
      &lt;br /&gt;
&lt;br /&gt;
      example Directory structure&lt;br /&gt;
      [[File:ArmingmodeSSHdirectories.png]][Eigene Darstellung]&lt;br /&gt;
&lt;br /&gt;
== Use Cases ==&lt;br /&gt;
&lt;br /&gt;
The Signal Owl has a variety of different use cases. Among the most popular ones are classical network mapping and wardriving as well as basic penetration tests for different wireless technologies.&lt;br /&gt;
&lt;br /&gt;
== Used Hardware ==&lt;br /&gt;
&lt;br /&gt;
[[Signal Owl]]&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
* https://docs.hak5.org/signal-owl/&lt;br /&gt;
*https://github.com/hak5/signalowl-payloads&lt;br /&gt;
&lt;br /&gt;
[[Category:Pentesting]]&lt;/div&gt;</summary>
		<author><name>MMayer</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=Hak5_Signal_Owl&amp;diff=10621</id>
		<title>Hak5 Signal Owl</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=Hak5_Signal_Owl&amp;diff=10621"/>
		<updated>2023-01-05T16:51:46Z</updated>

		<summary type="html">&lt;p&gt;MMayer: /* LED Status Indications */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Summary ==&lt;br /&gt;
&lt;br /&gt;
The [https://docs.hak5.org/hc/en-us/categories/360002117953-Signal-Owl Signal Owl] is a hardware product developed by the company Hak5.&lt;br /&gt;
It is a simple payload-based signals intelligence platform with a unique design for discreet planting or mobile operations on any engagement. The most popular application cases include classic network mapping and basic penetration tests for various wireless technologies.&lt;br /&gt;
&lt;br /&gt;
== Description ==&lt;br /&gt;
&lt;br /&gt;
[[File:SignalOwlDiagram.png|thumb|500px|frame|Components of the Signal Owl [Eigene Darstellung]]] &lt;br /&gt;
&lt;br /&gt;
The Signal Owl is designed to be rapidly deployed in all kinds of environments, allowing it to be an entry point for network analysis and basic wireless attacks in a variety of locations. With a power consumption of 100-200 mAh and the thermally optimized architecture, mobile operations as well as long term deployments, are enabled.&lt;br /&gt;
&lt;br /&gt;
=== Components ===&lt;br /&gt;
&lt;br /&gt;
This device features several components of which some may not be visible to the human eye at first sight.&lt;br /&gt;
&lt;br /&gt;
==== USB Power / Passthrough Plug ====&lt;br /&gt;
&lt;br /&gt;
The USB power or passthrough plug is used to power the device. It can be powered from any reliable USB source.&lt;br /&gt;
&lt;br /&gt;
==== USB 2.0 Passthrough Port ====&lt;br /&gt;
&lt;br /&gt;
The USB 2.0 passthrough port is the port closest to the pigtail. Data and power pass through to that port, allowing for implant operations. With devices like keyboards plugged plugged inline between this passthrough port and the power plug connected to the target computer, the Signal Owl will remain undetected from the operating system. Only the keyboard will be visible.&lt;br /&gt;
&lt;br /&gt;
==== USB 2.0 Host Port ====&lt;br /&gt;
&lt;br /&gt;
The USB 2.0 host port is the port farthest away from the pigtail. It is connected to the Linux socket of the Signal Owl and supports USB flash drives formatted with FAT32 and EXT4 file systems as well as many Wi-Fi, Bluetooth and other RF transceivers.&lt;br /&gt;
&lt;br /&gt;
==== Button ====&lt;br /&gt;
&lt;br /&gt;
The button on the bottom of the device is used to enter Arming Mode and to interact with payloads. It is not pressable without special tools like paperclips.&lt;br /&gt;
&lt;br /&gt;
==== Status LED ====&lt;br /&gt;
&lt;br /&gt;
The status LED indicates the current status of the Signal Owl. When turned off, it is not visible.&lt;br /&gt;
&lt;br /&gt;
=== Implant / mobile operations ===&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Implant operations&lt;br /&gt;
&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
During long term wireless engagements, the Signal Owl may be planted inline between any typical 5V USB power source. This may be useful in situations where ports are occupied, or to deter the unit from being unplugged.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Mobile operations&lt;br /&gt;
&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
The Signal Owl features a low power consumption profile, with a typical power draw averaging 100-200 mAh. Additionally, it is thermally optimized for long term deployments in many indoor environments. One can expect a large 20,000 mAh USB battery bank to operate the unit for up to 4 days.&lt;br /&gt;
&lt;br /&gt;
=== Default Settings ===&lt;br /&gt;
&lt;br /&gt;
Default settings that are used in order to access the device via SSH are pictured in the table below.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
!colspan=&amp;quot;2&amp;quot;|Default Settings&lt;br /&gt;
|-&lt;br /&gt;
|Username&lt;br /&gt;
|root&lt;br /&gt;
|-&lt;br /&gt;
|Password&lt;br /&gt;
|hak5owl&lt;br /&gt;
|-&lt;br /&gt;
|SSID&lt;br /&gt;
|Owl_xxxx&lt;br /&gt;
|-&lt;br /&gt;
|IP Address&lt;br /&gt;
|172.16.56.1&lt;br /&gt;
|-&lt;br /&gt;
|SSH command&lt;br /&gt;
|ssh root@172.16.56.1&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
The SSID during Arming Mode is Owl_xxxx in which xxxx indicates the last two octets of the devices MAC address.&lt;br /&gt;
&lt;br /&gt;
=== LED Status Indications ===&lt;br /&gt;
&lt;br /&gt;
The Signal Owl features a red LED with the following default status indications:&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
!|LED&lt;br /&gt;
!|Status&lt;br /&gt;
|-&lt;br /&gt;
|Blinking&lt;br /&gt;
|Booting&lt;br /&gt;
|-&lt;br /&gt;
|Solid&lt;br /&gt;
|Mounting external storage / Running upgrade&lt;br /&gt;
|-&lt;br /&gt;
|Single blinking&lt;br /&gt;
|Attack Mode&lt;br /&gt;
|-&lt;br /&gt;
|Double blinking&lt;br /&gt;
|Arming Mode&lt;br /&gt;
|-&lt;br /&gt;
|Slow blinking&lt;br /&gt;
|Error running payload&lt;br /&gt;
|-&lt;br /&gt;
|Fast blinking&lt;br /&gt;
|Select Mode (Deprecated from version 1.0.1 onward)&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== Modes of Operation ===&lt;br /&gt;
&lt;br /&gt;
The Signal Owl comes with two modes of operation, Attack Mode and Arming Mode. By default, the device will boot into Attack Mode. In order to access Arming Mode, the button on the bottom of the device has to be pressed while in Attack Mode. It is not recommended to press the button during the boot sequence as this can possibly brick the device and render it useless. The arming mode is used for firmware updates and shell access, while the attack mode is used to load and execute the payload.&lt;br /&gt;
&lt;br /&gt;
==== Attack Mode ====&lt;br /&gt;
&lt;br /&gt;
Attack Mode is the default mode, the Signal Owl boots into. It provides two basic functions, being the payload loading function and the payload execution function. The payload loading function checks for any USB flash drives plugged into the host port of the device and copies payloads and extensions to the root of the Signal Owl. The payload execution function is responsible for executing the payload that is currently stored on the root of the Signal Owl. In case no payload is found, the device will blink slowly, indicating the FAIL status.&lt;br /&gt;
&lt;br /&gt;
==== Arming Mode ====&lt;br /&gt;
&lt;br /&gt;
The Arming Mode provides two basic functions, being the firmware update function and the shell access function. The firmware update function checks for any USB flash drives plugged into the host port of the device and copies firmware upgrade files into the internal storage of the device and flashes it. The shell access function starts an open access point with the SSID Owl_xxxx in which xxxx indicates the last two octets of the devices MAC address. Additionally, a SSH server providing access to the shell of the Signal Owl is enabled.&lt;br /&gt;
&lt;br /&gt;
=== Initial Setup ===&lt;br /&gt;
&lt;br /&gt;
When first unboxing the Signal Owl, the device runs a stager firmware that is designed to flash the latest firmware from a USB flash drive. In order to update the Signal Owl, the [https://downloads.hak5.org/owl latest firmware] has to be downloaded. Then, the downloaded file must be copied to the root of an EXT4 or FAT32 formatted USB flash drive. It is important not to modify this file. The next step is to plug the USB flash drive into the powered off Signal Owl. Afterwards, the device has to be powered on by a reliable USB source. The upgrade itself takes approximately five to ten minutes and is indicated by a solid red LED light. When finished, the device will reboot, enter Attack Mode and blink slowly, indicating an error running the payload because no payload has been found.&lt;br /&gt;
&lt;br /&gt;
=== Payload Development ===&lt;br /&gt;
&lt;br /&gt;
Payloads for the Signal Owl are written in bash with [https://github.com/hak5darren/USB-Rubber-Ducky/wiki/Duckyscript Ducky Script] and can be created with any standard text editor. All payloads should begin with an interpreter directive, like the shebang #!/bin/bash for bash payloads and payloads must be named either payload.txt or payload.sh. In order to create effective payloads, the Signal Owl comes with several preinstalled penetration testing tools. These are as follows: [https://nmap.org/ Nmap], [https://www.aircrack-ng.org/ Aircrack-ng], [https://github.com/aircrack-ng/mdk4 MDK4] and [https://www.kismetwireless.net/ Kismet].&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Tools&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
• Kismet - detector for wireless networks and devices.&lt;br /&gt;
&lt;br /&gt;
• MDK4 - Wi-Fi testing tool.&lt;br /&gt;
&lt;br /&gt;
• Aircrack-ng Suite - a complete suite of tools for WiFi network security assessment.&lt;br /&gt;
&lt;br /&gt;
• Nmap - open source utility for network discovery and security auditing.&lt;br /&gt;
&lt;br /&gt;
=== Adding Payloads and Extensions ===&lt;br /&gt;
&lt;br /&gt;
Payloads can be stored on the internal storage of the Signal Owl as well as on a USB flash drive. When booting, payloads on USB flash drives are given priority and will override payloads stored on the Signal Owl. If no payload is found on the external storage and a payload is present on the internal storage, the internally stored payload will be executed. In case no payload is found on both internal and external storage, the Signal Owl will blink slowly. To successfully copy a payload to the Signal Owl and execute it, the payload must be named payload.txt or payload.sh and it has to be placed in the root directory of the flash drive. Similarly, payload extensions should be stored in a /extensions directory on the flash drive.&lt;br /&gt;
&lt;br /&gt;
After plugging the Signal Owl into a USB source, it will boot and then copy the payloads and payload extensions to the /root/payload and /root/payload/extensions directory respectively. Then, the device will enter Attack Mode and execute the payload.&lt;br /&gt;
&lt;br /&gt;
== Fake Beacon Flooding Attack ==&lt;br /&gt;
&lt;br /&gt;
The fake beacon flooding attack is one possible use case for the Signal Owl. With that attack, fake beacon frames are broadcasted to nearby devices. Beacon Frames include various parameters like the SSID, the type of encryption used and timestamps. This results in the creation of multiple fake Wi-Fi networks. Devices with Wi-Fi browsers are then flooded with these fake networks, causing potential network scanner and driver crashes. Furthermore, the attack may prevent legitimate users from finding their networks and lead to denial of service. &lt;br /&gt;
To execute the attack with the Signal Owl, the preinstalled tools Aircrack-ng and MDK4 are used. The following bash script is saved as payload.sh and placed on the root of an USB flash drive. Then the USB flash drive is plugged into the Signal Owl. After powering on the device, multiple fake networks with random SSIDs are generated and broadcasted to all nearby devices.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
#!/bin/bash&lt;br /&gt;
&lt;br /&gt;
LED SETUP&lt;br /&gt;
#creates monitor mode interface on wirelss card of the Signal Owl&lt;br /&gt;
airmon-ng start wlan0&lt;br /&gt;
&lt;br /&gt;
LED ATTACK&lt;br /&gt;
#floods nearby devices with random SSIDs&lt;br /&gt;
mdk4 wlan0mon b -w a -m -s 1000&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The results as seen from a victim running a Windows 10 system are pictured in the figure below.&lt;br /&gt;
&lt;br /&gt;
[[File:FakeBeaconFloodingSignalOwl.png|none|Random SSIDs as seen from a victim windows 10 client |]][Eigene Darstellung]&lt;br /&gt;
&lt;br /&gt;
== Open AP Nmap Scanner ==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Description: First access points are scanned, then a connection is established to the open access points, after connecting, the nmap scan runs and analyses the AP, &lt;br /&gt;
the results are saved in the loot folder.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
Settings &lt;br /&gt;
&lt;br /&gt;
NMAP_OPTIONS=&amp;quot;-sP&amp;quot;&lt;br /&gt;
&lt;br /&gt;
LOOT_DIR=/root/loot/open_ap_nmap_scan&lt;br /&gt;
&lt;br /&gt;
MAX_CIDR=20&lt;br /&gt;
&lt;br /&gt;
DEBUG=1&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Step-by-step guide&lt;br /&gt;
&lt;br /&gt;
    1) download the payload [https://github.com/hak5/signalowl-payloads/blob/master/payloads/library/wifi/Open-AP-Nmap-Scanner/payload.txt payload]&lt;br /&gt;
    2) store the payload in a usb stick and plug the stick into the signal owl&lt;br /&gt;
    3) after connecting the signal owl, the payload is loaded on the root folder and the scan starts. &lt;br /&gt;
    4) once successfully executed, you can start the signal owl in arming mode and see the results in the loot folder.&lt;br /&gt;
      example loot Directory&lt;br /&gt;
      [[File:ArmingmodeSSHloot.png]][Eigene Darstellung]&lt;br /&gt;
&lt;br /&gt;
== Arming Mode connection ==&lt;br /&gt;
&lt;br /&gt;
Step-by-step guide for accessing the arming mode&lt;br /&gt;
   1) click on the button located on the bottom of the signal owl while it is in attack mode. After pressing the button, the signal owl enters the arming &lt;br /&gt;
      mode and provides an open access point with the name Owl xxxx (where xxxx stands for the last two digits of the MAC address of the device).&lt;br /&gt;
   2) Connect to the access point. &lt;br /&gt;
      [[File:Armingmode.png]][Eigene Darstellung]&lt;br /&gt;
   3) Now you can connect via ssh by using the username and password (default: Username: root, Password: hak5owl, IP Address: 172.16.56.1)&lt;br /&gt;
   4) after successful connection you will end up in root@Owl directory&lt;br /&gt;
      [[File:ArmingmodeSSH.png]][Eigene Darstellung]&lt;br /&gt;
   5) Now you can enter the directories loot and payload to either view the results or to make further settings&lt;br /&gt;
      &lt;br /&gt;
&lt;br /&gt;
      example Directory structure&lt;br /&gt;
      [[File:ArmingmodeSSHdirectories.png]][Eigene Darstellung]&lt;br /&gt;
&lt;br /&gt;
== Use Cases ==&lt;br /&gt;
&lt;br /&gt;
The Signal Owl has a variety of different use cases. Among the most popular ones are classical network mapping and wardriving as well as basic penetration tests for different wireless technologies.&lt;br /&gt;
&lt;br /&gt;
== Used Hardware ==&lt;br /&gt;
&lt;br /&gt;
[[Signal Owl]]&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
* https://docs.hak5.org/signal-owl/&lt;br /&gt;
*https://github.com/hak5/signalowl-payloads&lt;br /&gt;
&lt;br /&gt;
[[Category:Pentesting]]&lt;/div&gt;</summary>
		<author><name>MMayer</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=Hak5_Signal_Owl&amp;diff=10620</id>
		<title>Hak5 Signal Owl</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=Hak5_Signal_Owl&amp;diff=10620"/>
		<updated>2023-01-05T16:39:55Z</updated>

		<summary type="html">&lt;p&gt;MMayer: /* Open AP Nmap Scanner */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Summary ==&lt;br /&gt;
&lt;br /&gt;
The [https://docs.hak5.org/hc/en-us/categories/360002117953-Signal-Owl Signal Owl] is a hardware product developed by the company Hak5.&lt;br /&gt;
It is a simple payload-based signals intelligence platform with a unique design for discreet planting or mobile operations on any engagement. The most popular application cases include classic network mapping and basic penetration tests for various wireless technologies.&lt;br /&gt;
&lt;br /&gt;
== Description ==&lt;br /&gt;
&lt;br /&gt;
[[File:SignalOwlDiagram.png|thumb|500px|frame|Components of the Signal Owl [Eigene Darstellung]]] &lt;br /&gt;
&lt;br /&gt;
The Signal Owl is designed to be rapidly deployed in all kinds of environments, allowing it to be an entry point for network analysis and basic wireless attacks in a variety of locations. With a power consumption of 100-200 mAh and the thermally optimized architecture, mobile operations as well as long term deployments, are enabled.&lt;br /&gt;
&lt;br /&gt;
=== Components ===&lt;br /&gt;
&lt;br /&gt;
This device features several components of which some may not be visible to the human eye at first sight.&lt;br /&gt;
&lt;br /&gt;
==== USB Power / Passthrough Plug ====&lt;br /&gt;
&lt;br /&gt;
The USB power or passthrough plug is used to power the device. It can be powered from any reliable USB source.&lt;br /&gt;
&lt;br /&gt;
==== USB 2.0 Passthrough Port ====&lt;br /&gt;
&lt;br /&gt;
The USB 2.0 passthrough port is the port closest to the pigtail. Data and power pass through to that port, allowing for implant operations. With devices like keyboards plugged plugged inline between this passthrough port and the power plug connected to the target computer, the Signal Owl will remain undetected from the operating system. Only the keyboard will be visible.&lt;br /&gt;
&lt;br /&gt;
==== USB 2.0 Host Port ====&lt;br /&gt;
&lt;br /&gt;
The USB 2.0 host port is the port farthest away from the pigtail. It is connected to the Linux socket of the Signal Owl and supports USB flash drives formatted with FAT32 and EXT4 file systems as well as many Wi-Fi, Bluetooth and other RF transceivers.&lt;br /&gt;
&lt;br /&gt;
==== Button ====&lt;br /&gt;
&lt;br /&gt;
The button on the bottom of the device is used to enter Arming Mode and to interact with payloads. It is not pressable without special tools like paperclips.&lt;br /&gt;
&lt;br /&gt;
==== Status LED ====&lt;br /&gt;
&lt;br /&gt;
The status LED indicates the current status of the Signal Owl. When turned off, it is not visible.&lt;br /&gt;
&lt;br /&gt;
=== Implant / mobile operations ===&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Implant operations&lt;br /&gt;
&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
During long term wireless engagements, the Signal Owl may be planted inline between any typical 5V USB power source. This may be useful in situations where ports are occupied, or to deter the unit from being unplugged.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Mobile operations&lt;br /&gt;
&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
The Signal Owl features a low power consumption profile, with a typical power draw averaging 100-200 mAh. Additionally, it is thermally optimized for long term deployments in many indoor environments. One can expect a large 20,000 mAh USB battery bank to operate the unit for up to 4 days.&lt;br /&gt;
&lt;br /&gt;
=== Default Settings ===&lt;br /&gt;
&lt;br /&gt;
Default settings that are used in order to access the device via SSH are pictured in the table below.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
!colspan=&amp;quot;2&amp;quot;|Default Settings&lt;br /&gt;
|-&lt;br /&gt;
|Username&lt;br /&gt;
|root&lt;br /&gt;
|-&lt;br /&gt;
|Password&lt;br /&gt;
|hak5owl&lt;br /&gt;
|-&lt;br /&gt;
|SSID&lt;br /&gt;
|Owl_xxxx&lt;br /&gt;
|-&lt;br /&gt;
|IP Address&lt;br /&gt;
|172.16.56.1&lt;br /&gt;
|-&lt;br /&gt;
|SSH command&lt;br /&gt;
|ssh root@172.16.56.1&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
The SSID during Arming Mode is Owl_xxxx in which xxxx indicates the last two octets of the devices MAC address.&lt;br /&gt;
&lt;br /&gt;
=== LED Status Indications ===&lt;br /&gt;
&lt;br /&gt;
The Signal Owl features a red LED with the following default status indications:&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
!|LED&lt;br /&gt;
!|Status&lt;br /&gt;
|-&lt;br /&gt;
|Blinking&lt;br /&gt;
|Booting&lt;br /&gt;
|-&lt;br /&gt;
|Solid&lt;br /&gt;
|Mounting external storage / Running upgrade&lt;br /&gt;
|-&lt;br /&gt;
|Single blinking&lt;br /&gt;
|Attack Mode&lt;br /&gt;
|-&lt;br /&gt;
|Double blinking&lt;br /&gt;
|Arming Mode&lt;br /&gt;
|-&lt;br /&gt;
|Slow blinking&lt;br /&gt;
|Error running payload&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== Modes of Operation ===&lt;br /&gt;
&lt;br /&gt;
The Signal Owl comes with two modes of operation, Attack Mode and Arming Mode. By default, the device will boot into Attack Mode. In order to access Arming Mode, the button on the bottom of the device has to be pressed while in Attack Mode. It is not recommended to press the button during the boot sequence as this can possibly brick the device and render it useless. The arming mode is used for firmware updates and shell access, while the attack mode is used to load and execute the payload.&lt;br /&gt;
&lt;br /&gt;
==== Attack Mode ====&lt;br /&gt;
&lt;br /&gt;
Attack Mode is the default mode, the Signal Owl boots into. It provides two basic functions, being the payload loading function and the payload execution function. The payload loading function checks for any USB flash drives plugged into the host port of the device and copies payloads and extensions to the root of the Signal Owl. The payload execution function is responsible for executing the payload that is currently stored on the root of the Signal Owl. In case no payload is found, the device will blink slowly, indicating the FAIL status.&lt;br /&gt;
&lt;br /&gt;
==== Arming Mode ====&lt;br /&gt;
&lt;br /&gt;
The Arming Mode provides two basic functions, being the firmware update function and the shell access function. The firmware update function checks for any USB flash drives plugged into the host port of the device and copies firmware upgrade files into the internal storage of the device and flashes it. The shell access function starts an open access point with the SSID Owl_xxxx in which xxxx indicates the last two octets of the devices MAC address. Additionally, a SSH server providing access to the shell of the Signal Owl is enabled.&lt;br /&gt;
&lt;br /&gt;
=== Initial Setup ===&lt;br /&gt;
&lt;br /&gt;
When first unboxing the Signal Owl, the device runs a stager firmware that is designed to flash the latest firmware from a USB flash drive. In order to update the Signal Owl, the [https://downloads.hak5.org/owl latest firmware] has to be downloaded. Then, the downloaded file must be copied to the root of an EXT4 or FAT32 formatted USB flash drive. It is important not to modify this file. The next step is to plug the USB flash drive into the powered off Signal Owl. Afterwards, the device has to be powered on by a reliable USB source. The upgrade itself takes approximately five to ten minutes and is indicated by a solid red LED light. When finished, the device will reboot, enter Attack Mode and blink slowly, indicating an error running the payload because no payload has been found.&lt;br /&gt;
&lt;br /&gt;
=== Payload Development ===&lt;br /&gt;
&lt;br /&gt;
Payloads for the Signal Owl are written in bash with [https://github.com/hak5darren/USB-Rubber-Ducky/wiki/Duckyscript Ducky Script] and can be created with any standard text editor. All payloads should begin with an interpreter directive, like the shebang #!/bin/bash for bash payloads and payloads must be named either payload.txt or payload.sh. In order to create effective payloads, the Signal Owl comes with several preinstalled penetration testing tools. These are as follows: [https://nmap.org/ Nmap], [https://www.aircrack-ng.org/ Aircrack-ng], [https://github.com/aircrack-ng/mdk4 MDK4] and [https://www.kismetwireless.net/ Kismet].&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Tools&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
• Kismet - detector for wireless networks and devices.&lt;br /&gt;
&lt;br /&gt;
• MDK4 - Wi-Fi testing tool.&lt;br /&gt;
&lt;br /&gt;
• Aircrack-ng Suite - a complete suite of tools for WiFi network security assessment.&lt;br /&gt;
&lt;br /&gt;
• Nmap - open source utility for network discovery and security auditing.&lt;br /&gt;
&lt;br /&gt;
=== Adding Payloads and Extensions ===&lt;br /&gt;
&lt;br /&gt;
Payloads can be stored on the internal storage of the Signal Owl as well as on a USB flash drive. When booting, payloads on USB flash drives are given priority and will override payloads stored on the Signal Owl. If no payload is found on the external storage and a payload is present on the internal storage, the internally stored payload will be executed. In case no payload is found on both internal and external storage, the Signal Owl will blink slowly. To successfully copy a payload to the Signal Owl and execute it, the payload must be named payload.txt or payload.sh and it has to be placed in the root directory of the flash drive. Similarly, payload extensions should be stored in a /extensions directory on the flash drive.&lt;br /&gt;
&lt;br /&gt;
After plugging the Signal Owl into a USB source, it will boot and then copy the payloads and payload extensions to the /root/payload and /root/payload/extensions directory respectively. Then, the device will enter Attack Mode and execute the payload.&lt;br /&gt;
&lt;br /&gt;
== Fake Beacon Flooding Attack ==&lt;br /&gt;
&lt;br /&gt;
The fake beacon flooding attack is one possible use case for the Signal Owl. With that attack, fake beacon frames are broadcasted to nearby devices. Beacon Frames include various parameters like the SSID, the type of encryption used and timestamps. This results in the creation of multiple fake Wi-Fi networks. Devices with Wi-Fi browsers are then flooded with these fake networks, causing potential network scanner and driver crashes. Furthermore, the attack may prevent legitimate users from finding their networks and lead to denial of service. &lt;br /&gt;
To execute the attack with the Signal Owl, the preinstalled tools Aircrack-ng and MDK4 are used. The following bash script is saved as payload.sh and placed on the root of an USB flash drive. Then the USB flash drive is plugged into the Signal Owl. After powering on the device, multiple fake networks with random SSIDs are generated and broadcasted to all nearby devices.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
#!/bin/bash&lt;br /&gt;
&lt;br /&gt;
LED SETUP&lt;br /&gt;
#creates monitor mode interface on wirelss card of the Signal Owl&lt;br /&gt;
airmon-ng start wlan0&lt;br /&gt;
&lt;br /&gt;
LED ATTACK&lt;br /&gt;
#floods nearby devices with random SSIDs&lt;br /&gt;
mdk4 wlan0mon b -w a -m -s 1000&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The results as seen from a victim running a Windows 10 system are pictured in the figure below.&lt;br /&gt;
&lt;br /&gt;
[[File:FakeBeaconFloodingSignalOwl.png|none|Random SSIDs as seen from a victim windows 10 client |]][Eigene Darstellung]&lt;br /&gt;
&lt;br /&gt;
== Open AP Nmap Scanner ==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Description: First access points are scanned, then a connection is established to the open access points, after connecting, the nmap scan runs and analyses the AP, &lt;br /&gt;
the results are saved in the loot folder.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
Settings &lt;br /&gt;
&lt;br /&gt;
NMAP_OPTIONS=&amp;quot;-sP&amp;quot;&lt;br /&gt;
&lt;br /&gt;
LOOT_DIR=/root/loot/open_ap_nmap_scan&lt;br /&gt;
&lt;br /&gt;
MAX_CIDR=20&lt;br /&gt;
&lt;br /&gt;
DEBUG=1&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Step-by-step guide&lt;br /&gt;
&lt;br /&gt;
    1) download the payload [https://github.com/hak5/signalowl-payloads/blob/master/payloads/library/wifi/Open-AP-Nmap-Scanner/payload.txt payload]&lt;br /&gt;
    2) store the payload in a usb stick and plug the stick into the signal owl&lt;br /&gt;
    3) after connecting the signal owl, the payload is loaded on the root folder and the scan starts. &lt;br /&gt;
    4) once successfully executed, you can start the signal owl in arming mode and see the results in the loot folder.&lt;br /&gt;
      example loot Directory&lt;br /&gt;
      [[File:ArmingmodeSSHloot.png]][Eigene Darstellung]&lt;br /&gt;
&lt;br /&gt;
== Arming Mode connection ==&lt;br /&gt;
&lt;br /&gt;
Step-by-step guide for accessing the arming mode&lt;br /&gt;
   1) click on the button located on the bottom of the signal owl while it is in attack mode. After pressing the button, the signal owl enters the arming &lt;br /&gt;
      mode and provides an open access point with the name Owl xxxx (where xxxx stands for the last two digits of the MAC address of the device).&lt;br /&gt;
   2) Connect to the access point. &lt;br /&gt;
      [[File:Armingmode.png]][Eigene Darstellung]&lt;br /&gt;
   3) Now you can connect via ssh by using the username and password (default: Username: root, Password: hak5owl, IP Address: 172.16.56.1)&lt;br /&gt;
   4) after successful connection you will end up in root@Owl directory&lt;br /&gt;
      [[File:ArmingmodeSSH.png]][Eigene Darstellung]&lt;br /&gt;
   5) Now you can enter the directories loot and payload to either view the results or to make further settings&lt;br /&gt;
      &lt;br /&gt;
&lt;br /&gt;
      example Directory structure&lt;br /&gt;
      [[File:ArmingmodeSSHdirectories.png]][Eigene Darstellung]&lt;br /&gt;
&lt;br /&gt;
== Use Cases ==&lt;br /&gt;
&lt;br /&gt;
The Signal Owl has a variety of different use cases. Among the most popular ones are classical network mapping and wardriving as well as basic penetration tests for different wireless technologies.&lt;br /&gt;
&lt;br /&gt;
== Used Hardware ==&lt;br /&gt;
&lt;br /&gt;
[[Signal Owl]]&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
* https://docs.hak5.org/signal-owl/&lt;br /&gt;
*https://github.com/hak5/signalowl-payloads&lt;br /&gt;
&lt;br /&gt;
[[Category:Pentesting]]&lt;/div&gt;</summary>
		<author><name>MMayer</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=Hak5_Signal_Owl&amp;diff=10619</id>
		<title>Hak5 Signal Owl</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=Hak5_Signal_Owl&amp;diff=10619"/>
		<updated>2023-01-05T16:39:47Z</updated>

		<summary type="html">&lt;p&gt;MMayer: /* Open AP Nmap Scanner */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Summary ==&lt;br /&gt;
&lt;br /&gt;
The [https://docs.hak5.org/hc/en-us/categories/360002117953-Signal-Owl Signal Owl] is a hardware product developed by the company Hak5.&lt;br /&gt;
It is a simple payload-based signals intelligence platform with a unique design for discreet planting or mobile operations on any engagement. The most popular application cases include classic network mapping and basic penetration tests for various wireless technologies.&lt;br /&gt;
&lt;br /&gt;
== Description ==&lt;br /&gt;
&lt;br /&gt;
[[File:SignalOwlDiagram.png|thumb|500px|frame|Components of the Signal Owl [Eigene Darstellung]]] &lt;br /&gt;
&lt;br /&gt;
The Signal Owl is designed to be rapidly deployed in all kinds of environments, allowing it to be an entry point for network analysis and basic wireless attacks in a variety of locations. With a power consumption of 100-200 mAh and the thermally optimized architecture, mobile operations as well as long term deployments, are enabled.&lt;br /&gt;
&lt;br /&gt;
=== Components ===&lt;br /&gt;
&lt;br /&gt;
This device features several components of which some may not be visible to the human eye at first sight.&lt;br /&gt;
&lt;br /&gt;
==== USB Power / Passthrough Plug ====&lt;br /&gt;
&lt;br /&gt;
The USB power or passthrough plug is used to power the device. It can be powered from any reliable USB source.&lt;br /&gt;
&lt;br /&gt;
==== USB 2.0 Passthrough Port ====&lt;br /&gt;
&lt;br /&gt;
The USB 2.0 passthrough port is the port closest to the pigtail. Data and power pass through to that port, allowing for implant operations. With devices like keyboards plugged plugged inline between this passthrough port and the power plug connected to the target computer, the Signal Owl will remain undetected from the operating system. Only the keyboard will be visible.&lt;br /&gt;
&lt;br /&gt;
==== USB 2.0 Host Port ====&lt;br /&gt;
&lt;br /&gt;
The USB 2.0 host port is the port farthest away from the pigtail. It is connected to the Linux socket of the Signal Owl and supports USB flash drives formatted with FAT32 and EXT4 file systems as well as many Wi-Fi, Bluetooth and other RF transceivers.&lt;br /&gt;
&lt;br /&gt;
==== Button ====&lt;br /&gt;
&lt;br /&gt;
The button on the bottom of the device is used to enter Arming Mode and to interact with payloads. It is not pressable without special tools like paperclips.&lt;br /&gt;
&lt;br /&gt;
==== Status LED ====&lt;br /&gt;
&lt;br /&gt;
The status LED indicates the current status of the Signal Owl. When turned off, it is not visible.&lt;br /&gt;
&lt;br /&gt;
=== Implant / mobile operations ===&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Implant operations&lt;br /&gt;
&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
During long term wireless engagements, the Signal Owl may be planted inline between any typical 5V USB power source. This may be useful in situations where ports are occupied, or to deter the unit from being unplugged.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Mobile operations&lt;br /&gt;
&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
The Signal Owl features a low power consumption profile, with a typical power draw averaging 100-200 mAh. Additionally, it is thermally optimized for long term deployments in many indoor environments. One can expect a large 20,000 mAh USB battery bank to operate the unit for up to 4 days.&lt;br /&gt;
&lt;br /&gt;
=== Default Settings ===&lt;br /&gt;
&lt;br /&gt;
Default settings that are used in order to access the device via SSH are pictured in the table below.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
!colspan=&amp;quot;2&amp;quot;|Default Settings&lt;br /&gt;
|-&lt;br /&gt;
|Username&lt;br /&gt;
|root&lt;br /&gt;
|-&lt;br /&gt;
|Password&lt;br /&gt;
|hak5owl&lt;br /&gt;
|-&lt;br /&gt;
|SSID&lt;br /&gt;
|Owl_xxxx&lt;br /&gt;
|-&lt;br /&gt;
|IP Address&lt;br /&gt;
|172.16.56.1&lt;br /&gt;
|-&lt;br /&gt;
|SSH command&lt;br /&gt;
|ssh root@172.16.56.1&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
The SSID during Arming Mode is Owl_xxxx in which xxxx indicates the last two octets of the devices MAC address.&lt;br /&gt;
&lt;br /&gt;
=== LED Status Indications ===&lt;br /&gt;
&lt;br /&gt;
The Signal Owl features a red LED with the following default status indications:&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
!|LED&lt;br /&gt;
!|Status&lt;br /&gt;
|-&lt;br /&gt;
|Blinking&lt;br /&gt;
|Booting&lt;br /&gt;
|-&lt;br /&gt;
|Solid&lt;br /&gt;
|Mounting external storage / Running upgrade&lt;br /&gt;
|-&lt;br /&gt;
|Single blinking&lt;br /&gt;
|Attack Mode&lt;br /&gt;
|-&lt;br /&gt;
|Double blinking&lt;br /&gt;
|Arming Mode&lt;br /&gt;
|-&lt;br /&gt;
|Slow blinking&lt;br /&gt;
|Error running payload&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== Modes of Operation ===&lt;br /&gt;
&lt;br /&gt;
The Signal Owl comes with two modes of operation, Attack Mode and Arming Mode. By default, the device will boot into Attack Mode. In order to access Arming Mode, the button on the bottom of the device has to be pressed while in Attack Mode. It is not recommended to press the button during the boot sequence as this can possibly brick the device and render it useless. The arming mode is used for firmware updates and shell access, while the attack mode is used to load and execute the payload.&lt;br /&gt;
&lt;br /&gt;
==== Attack Mode ====&lt;br /&gt;
&lt;br /&gt;
Attack Mode is the default mode, the Signal Owl boots into. It provides two basic functions, being the payload loading function and the payload execution function. The payload loading function checks for any USB flash drives plugged into the host port of the device and copies payloads and extensions to the root of the Signal Owl. The payload execution function is responsible for executing the payload that is currently stored on the root of the Signal Owl. In case no payload is found, the device will blink slowly, indicating the FAIL status.&lt;br /&gt;
&lt;br /&gt;
==== Arming Mode ====&lt;br /&gt;
&lt;br /&gt;
The Arming Mode provides two basic functions, being the firmware update function and the shell access function. The firmware update function checks for any USB flash drives plugged into the host port of the device and copies firmware upgrade files into the internal storage of the device and flashes it. The shell access function starts an open access point with the SSID Owl_xxxx in which xxxx indicates the last two octets of the devices MAC address. Additionally, a SSH server providing access to the shell of the Signal Owl is enabled.&lt;br /&gt;
&lt;br /&gt;
=== Initial Setup ===&lt;br /&gt;
&lt;br /&gt;
When first unboxing the Signal Owl, the device runs a stager firmware that is designed to flash the latest firmware from a USB flash drive. In order to update the Signal Owl, the [https://downloads.hak5.org/owl latest firmware] has to be downloaded. Then, the downloaded file must be copied to the root of an EXT4 or FAT32 formatted USB flash drive. It is important not to modify this file. The next step is to plug the USB flash drive into the powered off Signal Owl. Afterwards, the device has to be powered on by a reliable USB source. The upgrade itself takes approximately five to ten minutes and is indicated by a solid red LED light. When finished, the device will reboot, enter Attack Mode and blink slowly, indicating an error running the payload because no payload has been found.&lt;br /&gt;
&lt;br /&gt;
=== Payload Development ===&lt;br /&gt;
&lt;br /&gt;
Payloads for the Signal Owl are written in bash with [https://github.com/hak5darren/USB-Rubber-Ducky/wiki/Duckyscript Ducky Script] and can be created with any standard text editor. All payloads should begin with an interpreter directive, like the shebang #!/bin/bash for bash payloads and payloads must be named either payload.txt or payload.sh. In order to create effective payloads, the Signal Owl comes with several preinstalled penetration testing tools. These are as follows: [https://nmap.org/ Nmap], [https://www.aircrack-ng.org/ Aircrack-ng], [https://github.com/aircrack-ng/mdk4 MDK4] and [https://www.kismetwireless.net/ Kismet].&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Tools&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
• Kismet - detector for wireless networks and devices.&lt;br /&gt;
&lt;br /&gt;
• MDK4 - Wi-Fi testing tool.&lt;br /&gt;
&lt;br /&gt;
• Aircrack-ng Suite - a complete suite of tools for WiFi network security assessment.&lt;br /&gt;
&lt;br /&gt;
• Nmap - open source utility for network discovery and security auditing.&lt;br /&gt;
&lt;br /&gt;
=== Adding Payloads and Extensions ===&lt;br /&gt;
&lt;br /&gt;
Payloads can be stored on the internal storage of the Signal Owl as well as on a USB flash drive. When booting, payloads on USB flash drives are given priority and will override payloads stored on the Signal Owl. If no payload is found on the external storage and a payload is present on the internal storage, the internally stored payload will be executed. In case no payload is found on both internal and external storage, the Signal Owl will blink slowly. To successfully copy a payload to the Signal Owl and execute it, the payload must be named payload.txt or payload.sh and it has to be placed in the root directory of the flash drive. Similarly, payload extensions should be stored in a /extensions directory on the flash drive.&lt;br /&gt;
&lt;br /&gt;
After plugging the Signal Owl into a USB source, it will boot and then copy the payloads and payload extensions to the /root/payload and /root/payload/extensions directory respectively. Then, the device will enter Attack Mode and execute the payload.&lt;br /&gt;
&lt;br /&gt;
== Fake Beacon Flooding Attack ==&lt;br /&gt;
&lt;br /&gt;
The fake beacon flooding attack is one possible use case for the Signal Owl. With that attack, fake beacon frames are broadcasted to nearby devices. Beacon Frames include various parameters like the SSID, the type of encryption used and timestamps. This results in the creation of multiple fake Wi-Fi networks. Devices with Wi-Fi browsers are then flooded with these fake networks, causing potential network scanner and driver crashes. Furthermore, the attack may prevent legitimate users from finding their networks and lead to denial of service. &lt;br /&gt;
To execute the attack with the Signal Owl, the preinstalled tools Aircrack-ng and MDK4 are used. The following bash script is saved as payload.sh and placed on the root of an USB flash drive. Then the USB flash drive is plugged into the Signal Owl. After powering on the device, multiple fake networks with random SSIDs are generated and broadcasted to all nearby devices.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
#!/bin/bash&lt;br /&gt;
&lt;br /&gt;
LED SETUP&lt;br /&gt;
#creates monitor mode interface on wirelss card of the Signal Owl&lt;br /&gt;
airmon-ng start wlan0&lt;br /&gt;
&lt;br /&gt;
LED ATTACK&lt;br /&gt;
#floods nearby devices with random SSIDs&lt;br /&gt;
mdk4 wlan0mon b -w a -m -s 1000&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The results as seen from a victim running a Windows 10 system are pictured in the figure below.&lt;br /&gt;
&lt;br /&gt;
[[File:FakeBeaconFloodingSignalOwl.png|none|Random SSIDs as seen from a victim windows 10 client |]][Eigene Darstellung]&lt;br /&gt;
&lt;br /&gt;
== Open AP Nmap Scanner ==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Description: First access points are scanned, then a connection is established to the open access points, after connecting, the nmap scan runs and analyses the AP, &lt;br /&gt;
the results are saved in the loot folder.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
Settings &lt;br /&gt;
&lt;br /&gt;
NMAP_OPTIONS=&amp;quot;-sP&amp;quot;&lt;br /&gt;
&lt;br /&gt;
LOOT_DIR=/root/loot/open_ap_nmap_scan&lt;br /&gt;
&lt;br /&gt;
MAX_CIDR=20&lt;br /&gt;
&lt;br /&gt;
DEBUG=1&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Step-by-step guide&lt;br /&gt;
&lt;br /&gt;
    1) download the payload [https://github.com/hak5/signalowl-payloads/blob/master/payloads/library/wifi/Open-AP-Nmap-Scanner/payload.txt payload]&lt;br /&gt;
    2) store the payload in a usb stick and plug the stick into the signal owl&lt;br /&gt;
    3) after connecting the signal owl, the payload is loaded on the root folder and the scan starts. &lt;br /&gt;
    4) once successfully executed, you can start the signal owl in arming mode and see the results in the loot folder.&lt;br /&gt;
      example loot Directory&lt;br /&gt;
      [[File:ArmingmodeSSHloot.png]][Eigene Darstellung]&lt;br /&gt;
&lt;br /&gt;
== Arming Mode connection ==&lt;br /&gt;
&lt;br /&gt;
Step-by-step guide for accessing the arming mode&lt;br /&gt;
   1) click on the button located on the bottom of the signal owl while it is in attack mode. After pressing the button, the signal owl enters the arming &lt;br /&gt;
      mode and provides an open access point with the name Owl xxxx (where xxxx stands for the last two digits of the MAC address of the device).&lt;br /&gt;
   2) Connect to the access point. &lt;br /&gt;
      [[File:Armingmode.png]][Eigene Darstellung]&lt;br /&gt;
   3) Now you can connect via ssh by using the username and password (default: Username: root, Password: hak5owl, IP Address: 172.16.56.1)&lt;br /&gt;
   4) after successful connection you will end up in root@Owl directory&lt;br /&gt;
      [[File:ArmingmodeSSH.png]][Eigene Darstellung]&lt;br /&gt;
   5) Now you can enter the directories loot and payload to either view the results or to make further settings&lt;br /&gt;
      &lt;br /&gt;
&lt;br /&gt;
      example Directory structure&lt;br /&gt;
      [[File:ArmingmodeSSHdirectories.png]][Eigene Darstellung]&lt;br /&gt;
&lt;br /&gt;
== Use Cases ==&lt;br /&gt;
&lt;br /&gt;
The Signal Owl has a variety of different use cases. Among the most popular ones are classical network mapping and wardriving as well as basic penetration tests for different wireless technologies.&lt;br /&gt;
&lt;br /&gt;
== Used Hardware ==&lt;br /&gt;
&lt;br /&gt;
[[Signal Owl]]&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
* https://docs.hak5.org/signal-owl/&lt;br /&gt;
*https://github.com/hak5/signalowl-payloads&lt;br /&gt;
&lt;br /&gt;
[[Category:Pentesting]]&lt;/div&gt;</summary>
		<author><name>MMayer</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=Hak5_Signal_Owl&amp;diff=10618</id>
		<title>Hak5 Signal Owl</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=Hak5_Signal_Owl&amp;diff=10618"/>
		<updated>2023-01-05T16:39:36Z</updated>

		<summary type="html">&lt;p&gt;MMayer: /* Open AP Nmap Scanner */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Summary ==&lt;br /&gt;
&lt;br /&gt;
The [https://docs.hak5.org/hc/en-us/categories/360002117953-Signal-Owl Signal Owl] is a hardware product developed by the company Hak5.&lt;br /&gt;
It is a simple payload-based signals intelligence platform with a unique design for discreet planting or mobile operations on any engagement. The most popular application cases include classic network mapping and basic penetration tests for various wireless technologies.&lt;br /&gt;
&lt;br /&gt;
== Description ==&lt;br /&gt;
&lt;br /&gt;
[[File:SignalOwlDiagram.png|thumb|500px|frame|Components of the Signal Owl [Eigene Darstellung]]] &lt;br /&gt;
&lt;br /&gt;
The Signal Owl is designed to be rapidly deployed in all kinds of environments, allowing it to be an entry point for network analysis and basic wireless attacks in a variety of locations. With a power consumption of 100-200 mAh and the thermally optimized architecture, mobile operations as well as long term deployments, are enabled.&lt;br /&gt;
&lt;br /&gt;
=== Components ===&lt;br /&gt;
&lt;br /&gt;
This device features several components of which some may not be visible to the human eye at first sight.&lt;br /&gt;
&lt;br /&gt;
==== USB Power / Passthrough Plug ====&lt;br /&gt;
&lt;br /&gt;
The USB power or passthrough plug is used to power the device. It can be powered from any reliable USB source.&lt;br /&gt;
&lt;br /&gt;
==== USB 2.0 Passthrough Port ====&lt;br /&gt;
&lt;br /&gt;
The USB 2.0 passthrough port is the port closest to the pigtail. Data and power pass through to that port, allowing for implant operations. With devices like keyboards plugged plugged inline between this passthrough port and the power plug connected to the target computer, the Signal Owl will remain undetected from the operating system. Only the keyboard will be visible.&lt;br /&gt;
&lt;br /&gt;
==== USB 2.0 Host Port ====&lt;br /&gt;
&lt;br /&gt;
The USB 2.0 host port is the port farthest away from the pigtail. It is connected to the Linux socket of the Signal Owl and supports USB flash drives formatted with FAT32 and EXT4 file systems as well as many Wi-Fi, Bluetooth and other RF transceivers.&lt;br /&gt;
&lt;br /&gt;
==== Button ====&lt;br /&gt;
&lt;br /&gt;
The button on the bottom of the device is used to enter Arming Mode and to interact with payloads. It is not pressable without special tools like paperclips.&lt;br /&gt;
&lt;br /&gt;
==== Status LED ====&lt;br /&gt;
&lt;br /&gt;
The status LED indicates the current status of the Signal Owl. When turned off, it is not visible.&lt;br /&gt;
&lt;br /&gt;
=== Implant / mobile operations ===&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Implant operations&lt;br /&gt;
&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
During long term wireless engagements, the Signal Owl may be planted inline between any typical 5V USB power source. This may be useful in situations where ports are occupied, or to deter the unit from being unplugged.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Mobile operations&lt;br /&gt;
&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
The Signal Owl features a low power consumption profile, with a typical power draw averaging 100-200 mAh. Additionally, it is thermally optimized for long term deployments in many indoor environments. One can expect a large 20,000 mAh USB battery bank to operate the unit for up to 4 days.&lt;br /&gt;
&lt;br /&gt;
=== Default Settings ===&lt;br /&gt;
&lt;br /&gt;
Default settings that are used in order to access the device via SSH are pictured in the table below.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
!colspan=&amp;quot;2&amp;quot;|Default Settings&lt;br /&gt;
|-&lt;br /&gt;
|Username&lt;br /&gt;
|root&lt;br /&gt;
|-&lt;br /&gt;
|Password&lt;br /&gt;
|hak5owl&lt;br /&gt;
|-&lt;br /&gt;
|SSID&lt;br /&gt;
|Owl_xxxx&lt;br /&gt;
|-&lt;br /&gt;
|IP Address&lt;br /&gt;
|172.16.56.1&lt;br /&gt;
|-&lt;br /&gt;
|SSH command&lt;br /&gt;
|ssh root@172.16.56.1&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
The SSID during Arming Mode is Owl_xxxx in which xxxx indicates the last two octets of the devices MAC address.&lt;br /&gt;
&lt;br /&gt;
=== LED Status Indications ===&lt;br /&gt;
&lt;br /&gt;
The Signal Owl features a red LED with the following default status indications:&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
!|LED&lt;br /&gt;
!|Status&lt;br /&gt;
|-&lt;br /&gt;
|Blinking&lt;br /&gt;
|Booting&lt;br /&gt;
|-&lt;br /&gt;
|Solid&lt;br /&gt;
|Mounting external storage / Running upgrade&lt;br /&gt;
|-&lt;br /&gt;
|Single blinking&lt;br /&gt;
|Attack Mode&lt;br /&gt;
|-&lt;br /&gt;
|Double blinking&lt;br /&gt;
|Arming Mode&lt;br /&gt;
|-&lt;br /&gt;
|Slow blinking&lt;br /&gt;
|Error running payload&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== Modes of Operation ===&lt;br /&gt;
&lt;br /&gt;
The Signal Owl comes with two modes of operation, Attack Mode and Arming Mode. By default, the device will boot into Attack Mode. In order to access Arming Mode, the button on the bottom of the device has to be pressed while in Attack Mode. It is not recommended to press the button during the boot sequence as this can possibly brick the device and render it useless. The arming mode is used for firmware updates and shell access, while the attack mode is used to load and execute the payload.&lt;br /&gt;
&lt;br /&gt;
==== Attack Mode ====&lt;br /&gt;
&lt;br /&gt;
Attack Mode is the default mode, the Signal Owl boots into. It provides two basic functions, being the payload loading function and the payload execution function. The payload loading function checks for any USB flash drives plugged into the host port of the device and copies payloads and extensions to the root of the Signal Owl. The payload execution function is responsible for executing the payload that is currently stored on the root of the Signal Owl. In case no payload is found, the device will blink slowly, indicating the FAIL status.&lt;br /&gt;
&lt;br /&gt;
==== Arming Mode ====&lt;br /&gt;
&lt;br /&gt;
The Arming Mode provides two basic functions, being the firmware update function and the shell access function. The firmware update function checks for any USB flash drives plugged into the host port of the device and copies firmware upgrade files into the internal storage of the device and flashes it. The shell access function starts an open access point with the SSID Owl_xxxx in which xxxx indicates the last two octets of the devices MAC address. Additionally, a SSH server providing access to the shell of the Signal Owl is enabled.&lt;br /&gt;
&lt;br /&gt;
=== Initial Setup ===&lt;br /&gt;
&lt;br /&gt;
When first unboxing the Signal Owl, the device runs a stager firmware that is designed to flash the latest firmware from a USB flash drive. In order to update the Signal Owl, the [https://downloads.hak5.org/owl latest firmware] has to be downloaded. Then, the downloaded file must be copied to the root of an EXT4 or FAT32 formatted USB flash drive. It is important not to modify this file. The next step is to plug the USB flash drive into the powered off Signal Owl. Afterwards, the device has to be powered on by a reliable USB source. The upgrade itself takes approximately five to ten minutes and is indicated by a solid red LED light. When finished, the device will reboot, enter Attack Mode and blink slowly, indicating an error running the payload because no payload has been found.&lt;br /&gt;
&lt;br /&gt;
=== Payload Development ===&lt;br /&gt;
&lt;br /&gt;
Payloads for the Signal Owl are written in bash with [https://github.com/hak5darren/USB-Rubber-Ducky/wiki/Duckyscript Ducky Script] and can be created with any standard text editor. All payloads should begin with an interpreter directive, like the shebang #!/bin/bash for bash payloads and payloads must be named either payload.txt or payload.sh. In order to create effective payloads, the Signal Owl comes with several preinstalled penetration testing tools. These are as follows: [https://nmap.org/ Nmap], [https://www.aircrack-ng.org/ Aircrack-ng], [https://github.com/aircrack-ng/mdk4 MDK4] and [https://www.kismetwireless.net/ Kismet].&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Tools&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
• Kismet - detector for wireless networks and devices.&lt;br /&gt;
&lt;br /&gt;
• MDK4 - Wi-Fi testing tool.&lt;br /&gt;
&lt;br /&gt;
• Aircrack-ng Suite - a complete suite of tools for WiFi network security assessment.&lt;br /&gt;
&lt;br /&gt;
• Nmap - open source utility for network discovery and security auditing.&lt;br /&gt;
&lt;br /&gt;
=== Adding Payloads and Extensions ===&lt;br /&gt;
&lt;br /&gt;
Payloads can be stored on the internal storage of the Signal Owl as well as on a USB flash drive. When booting, payloads on USB flash drives are given priority and will override payloads stored on the Signal Owl. If no payload is found on the external storage and a payload is present on the internal storage, the internally stored payload will be executed. In case no payload is found on both internal and external storage, the Signal Owl will blink slowly. To successfully copy a payload to the Signal Owl and execute it, the payload must be named payload.txt or payload.sh and it has to be placed in the root directory of the flash drive. Similarly, payload extensions should be stored in a /extensions directory on the flash drive.&lt;br /&gt;
&lt;br /&gt;
After plugging the Signal Owl into a USB source, it will boot and then copy the payloads and payload extensions to the /root/payload and /root/payload/extensions directory respectively. Then, the device will enter Attack Mode and execute the payload.&lt;br /&gt;
&lt;br /&gt;
== Fake Beacon Flooding Attack ==&lt;br /&gt;
&lt;br /&gt;
The fake beacon flooding attack is one possible use case for the Signal Owl. With that attack, fake beacon frames are broadcasted to nearby devices. Beacon Frames include various parameters like the SSID, the type of encryption used and timestamps. This results in the creation of multiple fake Wi-Fi networks. Devices with Wi-Fi browsers are then flooded with these fake networks, causing potential network scanner and driver crashes. Furthermore, the attack may prevent legitimate users from finding their networks and lead to denial of service. &lt;br /&gt;
To execute the attack with the Signal Owl, the preinstalled tools Aircrack-ng and MDK4 are used. The following bash script is saved as payload.sh and placed on the root of an USB flash drive. Then the USB flash drive is plugged into the Signal Owl. After powering on the device, multiple fake networks with random SSIDs are generated and broadcasted to all nearby devices.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
#!/bin/bash&lt;br /&gt;
&lt;br /&gt;
LED SETUP&lt;br /&gt;
#creates monitor mode interface on wirelss card of the Signal Owl&lt;br /&gt;
airmon-ng start wlan0&lt;br /&gt;
&lt;br /&gt;
LED ATTACK&lt;br /&gt;
#floods nearby devices with random SSIDs&lt;br /&gt;
mdk4 wlan0mon b -w a -m -s 1000&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The results as seen from a victim running a Windows 10 system are pictured in the figure below.&lt;br /&gt;
&lt;br /&gt;
[[File:FakeBeaconFloodingSignalOwl.png|none|Random SSIDs as seen from a victim windows 10 client |]][Eigene Darstellung]&lt;br /&gt;
&lt;br /&gt;
== Open AP Nmap Scanner ==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Description: First access points are scanned, then a connection is established to the open access points, after connecting, the nmap scan runs and analyses the AP, &lt;br /&gt;
the results are saved in the loot folder.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
Settings &lt;br /&gt;
&lt;br /&gt;
NMAP_OPTIONS=&amp;quot;-sP&amp;quot;&lt;br /&gt;
&lt;br /&gt;
LOOT_DIR=/root/loot/open_ap_nmap_scan&lt;br /&gt;
&lt;br /&gt;
MAX_CIDR=20&lt;br /&gt;
&lt;br /&gt;
DEBUG=1&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Step-by-step guide&lt;br /&gt;
&lt;br /&gt;
    1) download the payload [https://github.com/hak5/signalowl-payloads/blob/master/payloads/library/wifi/Open-AP-Nmap-Scanner/payload.txt payload]&lt;br /&gt;
    2) store the payload in a usb stick and plug the stick into the signal owl&lt;br /&gt;
    3) after connecting the signal owl, the payload is loaded on the root folder and the scan starts. &lt;br /&gt;
    4) once successfully executed, you can start the signal owl in arming mode and see the results in the loot folder.&lt;br /&gt;
      example loot Directory&lt;br /&gt;
      [[File:ArmingmodeSSHloot.png]][Eigene Darstellung]&lt;br /&gt;
&lt;br /&gt;
== Arming Mode connection ==&lt;br /&gt;
&lt;br /&gt;
Step-by-step guide for accessing the arming mode&lt;br /&gt;
   1) click on the button located on the bottom of the signal owl while it is in attack mode. After pressing the button, the signal owl enters the arming &lt;br /&gt;
      mode and provides an open access point with the name Owl xxxx (where xxxx stands for the last two digits of the MAC address of the device).&lt;br /&gt;
   2) Connect to the access point. &lt;br /&gt;
      [[File:Armingmode.png]][Eigene Darstellung]&lt;br /&gt;
   3) Now you can connect via ssh by using the username and password (default: Username: root, Password: hak5owl, IP Address: 172.16.56.1)&lt;br /&gt;
   4) after successful connection you will end up in root@Owl directory&lt;br /&gt;
      [[File:ArmingmodeSSH.png]][Eigene Darstellung]&lt;br /&gt;
   5) Now you can enter the directories loot and payload to either view the results or to make further settings&lt;br /&gt;
      &lt;br /&gt;
&lt;br /&gt;
      example Directory structure&lt;br /&gt;
      [[File:ArmingmodeSSHdirectories.png]][Eigene Darstellung]&lt;br /&gt;
&lt;br /&gt;
== Use Cases ==&lt;br /&gt;
&lt;br /&gt;
The Signal Owl has a variety of different use cases. Among the most popular ones are classical network mapping and wardriving as well as basic penetration tests for different wireless technologies.&lt;br /&gt;
&lt;br /&gt;
== Used Hardware ==&lt;br /&gt;
&lt;br /&gt;
[[Signal Owl]]&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
* https://docs.hak5.org/signal-owl/&lt;br /&gt;
*https://github.com/hak5/signalowl-payloads&lt;br /&gt;
&lt;br /&gt;
[[Category:Pentesting]]&lt;/div&gt;</summary>
		<author><name>MMayer</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=Hak5_Signal_Owl&amp;diff=10617</id>
		<title>Hak5 Signal Owl</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=Hak5_Signal_Owl&amp;diff=10617"/>
		<updated>2023-01-05T16:36:22Z</updated>

		<summary type="html">&lt;p&gt;MMayer: /* Open AP Nmap Scanner */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Summary ==&lt;br /&gt;
&lt;br /&gt;
The [https://docs.hak5.org/hc/en-us/categories/360002117953-Signal-Owl Signal Owl] is a hardware product developed by the company Hak5.&lt;br /&gt;
It is a simple payload-based signals intelligence platform with a unique design for discreet planting or mobile operations on any engagement. The most popular application cases include classic network mapping and basic penetration tests for various wireless technologies.&lt;br /&gt;
&lt;br /&gt;
== Description ==&lt;br /&gt;
&lt;br /&gt;
[[File:SignalOwlDiagram.png|thumb|500px|frame|Components of the Signal Owl [Eigene Darstellung]]] &lt;br /&gt;
&lt;br /&gt;
The Signal Owl is designed to be rapidly deployed in all kinds of environments, allowing it to be an entry point for network analysis and basic wireless attacks in a variety of locations. With a power consumption of 100-200 mAh and the thermally optimized architecture, mobile operations as well as long term deployments, are enabled.&lt;br /&gt;
&lt;br /&gt;
=== Components ===&lt;br /&gt;
&lt;br /&gt;
This device features several components of which some may not be visible to the human eye at first sight.&lt;br /&gt;
&lt;br /&gt;
==== USB Power / Passthrough Plug ====&lt;br /&gt;
&lt;br /&gt;
The USB power or passthrough plug is used to power the device. It can be powered from any reliable USB source.&lt;br /&gt;
&lt;br /&gt;
==== USB 2.0 Passthrough Port ====&lt;br /&gt;
&lt;br /&gt;
The USB 2.0 passthrough port is the port closest to the pigtail. Data and power pass through to that port, allowing for implant operations. With devices like keyboards plugged plugged inline between this passthrough port and the power plug connected to the target computer, the Signal Owl will remain undetected from the operating system. Only the keyboard will be visible.&lt;br /&gt;
&lt;br /&gt;
==== USB 2.0 Host Port ====&lt;br /&gt;
&lt;br /&gt;
The USB 2.0 host port is the port farthest away from the pigtail. It is connected to the Linux socket of the Signal Owl and supports USB flash drives formatted with FAT32 and EXT4 file systems as well as many Wi-Fi, Bluetooth and other RF transceivers.&lt;br /&gt;
&lt;br /&gt;
==== Button ====&lt;br /&gt;
&lt;br /&gt;
The button on the bottom of the device is used to enter Arming Mode and to interact with payloads. It is not pressable without special tools like paperclips.&lt;br /&gt;
&lt;br /&gt;
==== Status LED ====&lt;br /&gt;
&lt;br /&gt;
The status LED indicates the current status of the Signal Owl. When turned off, it is not visible.&lt;br /&gt;
&lt;br /&gt;
=== Implant / mobile operations ===&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Implant operations&lt;br /&gt;
&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
During long term wireless engagements, the Signal Owl may be planted inline between any typical 5V USB power source. This may be useful in situations where ports are occupied, or to deter the unit from being unplugged.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Mobile operations&lt;br /&gt;
&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
The Signal Owl features a low power consumption profile, with a typical power draw averaging 100-200 mAh. Additionally, it is thermally optimized for long term deployments in many indoor environments. One can expect a large 20,000 mAh USB battery bank to operate the unit for up to 4 days.&lt;br /&gt;
&lt;br /&gt;
=== Default Settings ===&lt;br /&gt;
&lt;br /&gt;
Default settings that are used in order to access the device via SSH are pictured in the table below.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
!colspan=&amp;quot;2&amp;quot;|Default Settings&lt;br /&gt;
|-&lt;br /&gt;
|Username&lt;br /&gt;
|root&lt;br /&gt;
|-&lt;br /&gt;
|Password&lt;br /&gt;
|hak5owl&lt;br /&gt;
|-&lt;br /&gt;
|SSID&lt;br /&gt;
|Owl_xxxx&lt;br /&gt;
|-&lt;br /&gt;
|IP Address&lt;br /&gt;
|172.16.56.1&lt;br /&gt;
|-&lt;br /&gt;
|SSH command&lt;br /&gt;
|ssh root@172.16.56.1&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
The SSID during Arming Mode is Owl_xxxx in which xxxx indicates the last two octets of the devices MAC address.&lt;br /&gt;
&lt;br /&gt;
=== LED Status Indications ===&lt;br /&gt;
&lt;br /&gt;
The Signal Owl features a red LED with the following default status indications:&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
!|LED&lt;br /&gt;
!|Status&lt;br /&gt;
|-&lt;br /&gt;
|Blinking&lt;br /&gt;
|Booting&lt;br /&gt;
|-&lt;br /&gt;
|Solid&lt;br /&gt;
|Mounting external storage / Running upgrade&lt;br /&gt;
|-&lt;br /&gt;
|Single blinking&lt;br /&gt;
|Attack Mode&lt;br /&gt;
|-&lt;br /&gt;
|Double blinking&lt;br /&gt;
|Arming Mode&lt;br /&gt;
|-&lt;br /&gt;
|Slow blinking&lt;br /&gt;
|Error running payload&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== Modes of Operation ===&lt;br /&gt;
&lt;br /&gt;
The Signal Owl comes with two modes of operation, Attack Mode and Arming Mode. By default, the device will boot into Attack Mode. In order to access Arming Mode, the button on the bottom of the device has to be pressed while in Attack Mode. It is not recommended to press the button during the boot sequence as this can possibly brick the device and render it useless. The arming mode is used for firmware updates and shell access, while the attack mode is used to load and execute the payload.&lt;br /&gt;
&lt;br /&gt;
==== Attack Mode ====&lt;br /&gt;
&lt;br /&gt;
Attack Mode is the default mode, the Signal Owl boots into. It provides two basic functions, being the payload loading function and the payload execution function. The payload loading function checks for any USB flash drives plugged into the host port of the device and copies payloads and extensions to the root of the Signal Owl. The payload execution function is responsible for executing the payload that is currently stored on the root of the Signal Owl. In case no payload is found, the device will blink slowly, indicating the FAIL status.&lt;br /&gt;
&lt;br /&gt;
==== Arming Mode ====&lt;br /&gt;
&lt;br /&gt;
The Arming Mode provides two basic functions, being the firmware update function and the shell access function. The firmware update function checks for any USB flash drives plugged into the host port of the device and copies firmware upgrade files into the internal storage of the device and flashes it. The shell access function starts an open access point with the SSID Owl_xxxx in which xxxx indicates the last two octets of the devices MAC address. Additionally, a SSH server providing access to the shell of the Signal Owl is enabled.&lt;br /&gt;
&lt;br /&gt;
=== Initial Setup ===&lt;br /&gt;
&lt;br /&gt;
When first unboxing the Signal Owl, the device runs a stager firmware that is designed to flash the latest firmware from a USB flash drive. In order to update the Signal Owl, the [https://downloads.hak5.org/owl latest firmware] has to be downloaded. Then, the downloaded file must be copied to the root of an EXT4 or FAT32 formatted USB flash drive. It is important not to modify this file. The next step is to plug the USB flash drive into the powered off Signal Owl. Afterwards, the device has to be powered on by a reliable USB source. The upgrade itself takes approximately five to ten minutes and is indicated by a solid red LED light. When finished, the device will reboot, enter Attack Mode and blink slowly, indicating an error running the payload because no payload has been found.&lt;br /&gt;
&lt;br /&gt;
=== Payload Development ===&lt;br /&gt;
&lt;br /&gt;
Payloads for the Signal Owl are written in bash with [https://github.com/hak5darren/USB-Rubber-Ducky/wiki/Duckyscript Ducky Script] and can be created with any standard text editor. All payloads should begin with an interpreter directive, like the shebang #!/bin/bash for bash payloads and payloads must be named either payload.txt or payload.sh. In order to create effective payloads, the Signal Owl comes with several preinstalled penetration testing tools. These are as follows: [https://nmap.org/ Nmap], [https://www.aircrack-ng.org/ Aircrack-ng], [https://github.com/aircrack-ng/mdk4 MDK4] and [https://www.kismetwireless.net/ Kismet].&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Tools&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
• Kismet - detector for wireless networks and devices.&lt;br /&gt;
&lt;br /&gt;
• MDK4 - Wi-Fi testing tool.&lt;br /&gt;
&lt;br /&gt;
• Aircrack-ng Suite - a complete suite of tools for WiFi network security assessment.&lt;br /&gt;
&lt;br /&gt;
• Nmap - open source utility for network discovery and security auditing.&lt;br /&gt;
&lt;br /&gt;
=== Adding Payloads and Extensions ===&lt;br /&gt;
&lt;br /&gt;
Payloads can be stored on the internal storage of the Signal Owl as well as on a USB flash drive. When booting, payloads on USB flash drives are given priority and will override payloads stored on the Signal Owl. If no payload is found on the external storage and a payload is present on the internal storage, the internally stored payload will be executed. In case no payload is found on both internal and external storage, the Signal Owl will blink slowly. To successfully copy a payload to the Signal Owl and execute it, the payload must be named payload.txt or payload.sh and it has to be placed in the root directory of the flash drive. Similarly, payload extensions should be stored in a /extensions directory on the flash drive.&lt;br /&gt;
&lt;br /&gt;
After plugging the Signal Owl into a USB source, it will boot and then copy the payloads and payload extensions to the /root/payload and /root/payload/extensions directory respectively. Then, the device will enter Attack Mode and execute the payload.&lt;br /&gt;
&lt;br /&gt;
== Fake Beacon Flooding Attack ==&lt;br /&gt;
&lt;br /&gt;
The fake beacon flooding attack is one possible use case for the Signal Owl. With that attack, fake beacon frames are broadcasted to nearby devices. Beacon Frames include various parameters like the SSID, the type of encryption used and timestamps. This results in the creation of multiple fake Wi-Fi networks. Devices with Wi-Fi browsers are then flooded with these fake networks, causing potential network scanner and driver crashes. Furthermore, the attack may prevent legitimate users from finding their networks and lead to denial of service. &lt;br /&gt;
To execute the attack with the Signal Owl, the preinstalled tools Aircrack-ng and MDK4 are used. The following bash script is saved as payload.sh and placed on the root of an USB flash drive. Then the USB flash drive is plugged into the Signal Owl. After powering on the device, multiple fake networks with random SSIDs are generated and broadcasted to all nearby devices.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
#!/bin/bash&lt;br /&gt;
&lt;br /&gt;
LED SETUP&lt;br /&gt;
#creates monitor mode interface on wirelss card of the Signal Owl&lt;br /&gt;
airmon-ng start wlan0&lt;br /&gt;
&lt;br /&gt;
LED ATTACK&lt;br /&gt;
#floods nearby devices with random SSIDs&lt;br /&gt;
mdk4 wlan0mon b -w a -m -s 1000&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The results as seen from a victim running a Windows 10 system are pictured in the figure below.&lt;br /&gt;
&lt;br /&gt;
[[File:FakeBeaconFloodingSignalOwl.png|none|Random SSIDs as seen from a victim windows 10 client |]][Eigene Darstellung]&lt;br /&gt;
&lt;br /&gt;
== Open AP Nmap Scanner ==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Description: First access points are scanned, then a connection is established to the open access points, after connecting, the nmap scan runs and analyses the AP, &lt;br /&gt;
the results are saved in the loot folder.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Settings &lt;br /&gt;
&lt;br /&gt;
NMAP_OPTIONS=&amp;quot;-sP&amp;quot;&lt;br /&gt;
&lt;br /&gt;
LOOT_DIR=/root/loot/open_ap_nmap_scan&lt;br /&gt;
&lt;br /&gt;
MAX_CIDR=20&lt;br /&gt;
&lt;br /&gt;
DEBUG=1&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Step-by-step guide&lt;br /&gt;
&lt;br /&gt;
    1) download the payload [https://github.com/hak5/signalowl-payloads/blob/master/payloads/library/wifi/Open-AP-Nmap-Scanner/payload.txt payload]&lt;br /&gt;
    2) store the payload in a usb stick and plug the stick into the signal owl&lt;br /&gt;
    3) after connecting the signal owl, the payload is loaded on the root folder and the scan starts. &lt;br /&gt;
    4) once successfully executed, you can start the signal owl in arming mode and see the results in the loot folder.&lt;br /&gt;
      example loot Directory&lt;br /&gt;
      [[File:ArmingmodeSSHloot.png]][Eigene Darstellung]&lt;br /&gt;
&lt;br /&gt;
== Arming Mode connection ==&lt;br /&gt;
&lt;br /&gt;
Step-by-step guide for accessing the arming mode&lt;br /&gt;
   1) click on the button located on the bottom of the signal owl while it is in attack mode. After pressing the button, the signal owl enters the arming &lt;br /&gt;
      mode and provides an open access point with the name Owl xxxx (where xxxx stands for the last two digits of the MAC address of the device).&lt;br /&gt;
   2) Connect to the access point. &lt;br /&gt;
      [[File:Armingmode.png]][Eigene Darstellung]&lt;br /&gt;
   3) Now you can connect via ssh by using the username and password (default: Username: root, Password: hak5owl, IP Address: 172.16.56.1)&lt;br /&gt;
   4) after successful connection you will end up in root@Owl directory&lt;br /&gt;
      [[File:ArmingmodeSSH.png]][Eigene Darstellung]&lt;br /&gt;
   5) Now you can enter the directories loot and payload to either view the results or to make further settings&lt;br /&gt;
      &lt;br /&gt;
&lt;br /&gt;
      example Directory structure&lt;br /&gt;
      [[File:ArmingmodeSSHdirectories.png]][Eigene Darstellung]&lt;br /&gt;
&lt;br /&gt;
== Use Cases ==&lt;br /&gt;
&lt;br /&gt;
The Signal Owl has a variety of different use cases. Among the most popular ones are classical network mapping and wardriving as well as basic penetration tests for different wireless technologies.&lt;br /&gt;
&lt;br /&gt;
== Used Hardware ==&lt;br /&gt;
&lt;br /&gt;
[[Signal Owl]]&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
* https://docs.hak5.org/signal-owl/&lt;br /&gt;
*https://github.com/hak5/signalowl-payloads&lt;br /&gt;
&lt;br /&gt;
[[Category:Pentesting]]&lt;/div&gt;</summary>
		<author><name>MMayer</name></author>
	</entry>
</feed>