All About PlugBot
PlugBot is a research project and I plan to release the code for free under GPL license. Please help me fund this project by donating via PayPal!
PlugBot is a hardware bot. It's a covert penetration testing device designed for use during physical penetration tests. PlugBot is a tiny computer that looks like a power adapter; this small size allows it to go physically undetected all the while powerful enough to scan, collect and deliver test results externally.
PlugBot Demo from RedTeam Security on Vimeo.
PlugBot Demo: Download & Install Exploit Scripts from RedTeam Security on Vimeo.
How do you use it?
Gain access to the target location (conference room?), plug the PlugBot in the nearest wall outlet and walk out. The PlugBot is configured to make an external connection (Wi-fi or Ethernet) to a specified IP address to receive instructions. Central Command allows the penetration tester to invoke scripts and applications. Output as a result of testing is encrypted and securely transmitted to the Drop Zone where data is imported into Central Command for analysis by the pen tester.
What's inside?
What makes this little guy run is a 1.2 GHz processor, 512 MB RAM and drawing just under 5 watts of power. Extra hard disk space can be added with an SD card. Here are some of the on board components: 802.11b, Gigabit Ethernet, Bluetooth, 1.2 GHz processor, 512MB RAM, USNAP I/O, MicroSD socket and more.
About the Inventor
PlugBot was brought to life by security researcher and penetration tester, Jeremiah Talamantes. Jeremiah (CISSP, CEH) has been in Information Security for over 13 years. He founded RedTeam Security, a Minneapolis based IT Security consulting company with a group of extremely talented close friends.
DISCLAIMER: The researcher, nor any other party involved, does not condone the use of this technology for malicious purposes, such as gaining unauthorized access.
Features
- Issue scan commands remotely
- Wireless 802.11b ready
- Gigabit Ethernet capable
- 1.2 Ghz processor
- Linux, Perl, PHP, MySQL on-board
- Covertly disguised as power adapter
- Capable of invoking most Linux-based scan apps & scripts
- Intelligent scan engine
- Very low wattage use
Requirements
- First, you need to get your hands on the PlugBot hardware.
- Then, configure the PlugBot's network settings
- Next, you need to install the Admin software on your website.
- Finally, you physically deploy the PlugBot inside the target location.
