[00:56.440 --> 00:57.640] Hello, everyone. [00:58.280 --> 01:00.060] Second to last talk of the day. [01:00.340 --> 01:01.120] Super excited. [01:01.300 --> 01:03.420] Thank you all for being here without you. [01:04.100 --> 01:09.040] We're so excited to have you here as being live in this version of HOPE. [01:09.240 --> 01:11.110] So thank you again for being part of it. [01:11.900 --> 01:14.940] Quick note, the closing ceremonies today will be at 6 o'clock. [01:15.280 --> 01:25.340] The closing ceremonies will actually be in this room physically, but it will be simulcast into 206, which is downstairs on the second floor, in the back, not to Little Theater as is listed in the program. [01:25.340 --> 01:28.000] So don't wander down to Little Theater to see the simulcast. [01:28.280 --> 01:31.820] Head down to 206 to see the simulcast. [01:32.800 --> 01:35.880] Feedback is really appreciated from your experience here at the show. [01:36.260 --> 01:44.180] If you can, at some point, send criticism, comments, ideas, whatever, to feedback at hope.net. [01:44.420 --> 01:48.340] For those of you who are in the dorms, who are staying in the dorms, check out us at 8 p.m. [01:48.460 --> 01:48.660] tonight. [01:48.880 --> 01:51.760] If you're actually in the dorms until tomorrow, check out us at 2 p.m. [01:52.180 --> 01:53.560] And that's the last of the business. [01:53.560 --> 01:58.920] With that, we'll move on to our talk, $5 Cyber Weapons and How to Use Them, with Kody Kinzie [01:59.080 --> 01:59.320] Kody. [01:59.560 --> 02:00.350] Kody Kinzie. [02:00.440 --> 02:00.850] I apologize. [02:07.510 --> 02:08.290] Hello, everyone. [02:08.710 --> 02:09.470] Thank you for coming. [02:10.310 --> 02:18.330] So my talk is going to be an introduction on offensive hacking with microcontrollers and also some defensive and other interesting projects that they support. [02:18.530 --> 02:21.630] So if you're completely new to microcontrollers, hopefully this will be interesting to you. [02:21.710 --> 02:25.070] And if you are not new to microcontrollers, hopefully you will still learn something. [02:26.210 --> 02:26.910] All right. [02:27.050 --> 02:28.230] So my name is Kody Kinzie. [02:28.490 --> 02:30.710] I am a security researcher at Baronis. [02:30.890 --> 02:34.850] I teach a number of hacking channels on YouTube. [02:34.850 --> 02:38.410] So I currently produce content on the Hack5 channel. [02:38.710 --> 02:41.530] I also started the Nullbyte YouTube channel. [02:41.790 --> 02:44.650] And the name of that show was Cyber Weapons Lab. [02:44.850 --> 02:49.790] So this talk is kind of a callback to that if any of you happen to see that YouTube channel. [02:50.650 --> 02:53.710] So I live currently in the Treasure State, a.k.a. [02:53.870 --> 02:54.630] Big Sky Country. [02:55.710 --> 02:57.110] No one else here from that? [02:57.190 --> 02:57.710] Okay, great. [02:58.890 --> 03:05.130] And also, yeah, I live stream two times per week on the Hack5 and Security Forward channels. [03:05.770 --> 03:08.790] So if you want to see more stuff like this, make sure to check those out. [03:08.790 --> 03:10.110] You can ask me questions every week. [03:10.230 --> 03:11.530] We host a live Q&A. [03:11.690 --> 03:13.950] And it would be great to hear some feedback from some of you. [03:14.370 --> 03:17.630] So I specialize in Wi-Fi security, OSINT, and microcontrollers. [03:17.750 --> 03:20.350] And I've been interested in that for a very long time. [03:20.830 --> 03:23.230] If you take off the mask, you'll be less muffled. [03:23.710 --> 03:24.990] Oh, fair. [03:26.810 --> 03:27.410] How's that? [03:28.510 --> 03:29.070] All right. [03:30.450 --> 03:35.810] So outside of work, I really like urban exploration and particularly street art. [03:35.810 --> 03:40.310] So I have spent the last couple years mapping and documenting art in the L.A. [03:40.410 --> 03:44.830] Stormdrain system, which is something that I really enjoy. [03:45.990 --> 03:46.430] All right. [03:46.590 --> 03:49.590] So a lot of people have asked about how I got started with hacking. [03:50.210 --> 03:56.330] And I think it's interesting to tell stories of how people started in a completely unrelated career and then ended up here. [03:56.450 --> 04:02.430] So I started out wanting to be a photographer, moved to Los Angeles, became a bouncer at a venue called the Echoplex. [04:02.430 --> 04:06.610] And this is a real picture of me protecting Grumpy Cat from an unruly fan. [04:07.970 --> 04:14.930] I then went on to work at a Korean logistics tech startup that was trying to do Uber for trucking, learned a lot about wholesale, about logistics, and about technology. [04:15.390 --> 04:18.390] I moved on to starting to make tutorials around hacking. [04:18.930 --> 04:20.570] That's when I started Nullbyte. [04:20.690 --> 04:24.050] But it really frustrated me that I wasn't able to do programming. [04:24.090 --> 04:26.530] So I went back to Pasadena City College, a.k.a. [04:26.650 --> 04:28.650] the School of Wharf from Star Trek. [04:28.870 --> 04:29.650] Anybody else? [04:30.310 --> 04:30.710] Quopla. [04:30.910 --> 04:31.470] Yeah, great. [04:31.470 --> 04:35.970] And then studied their electrical engineering and programming. [04:36.810 --> 04:43.650] So around that time, I got picked up by Varonis to start making educational cybersecurity content and work as a security researcher. [04:43.910 --> 04:45.030] So that's how I got here. [04:45.450 --> 04:47.230] Kind of an unusual path. [04:48.910 --> 04:55.950] So my current project is a cat-shaped hacking tool with my friend Alex Lin sitting in the back back there. [04:56.850 --> 05:00.410] It uses some of the microcontrollers that we're going to be talking about today. [05:03.030 --> 05:05.630] So on the show, a lot of people are like, hey, do you have a Patreon? [05:05.970 --> 05:08.410] Like, do you have anything we can do to, like, support you if we like your content? [05:08.730 --> 05:10.450] And I'm always like, no, it feels a little weird to do that. [05:10.450 --> 05:15.230] So instead, we make this little cat-shaped microcontroller, and we make a lot of content around it. [05:15.230 --> 05:20.470] So beginners can get started with hacking, using microcontrollers, and if they're interested, they can support us as well. [05:20.670 --> 05:21.970] But this design is open source. [05:22.090 --> 05:28.450] So if you like it, you can go ahead and make it yourself if you have, like, a month and a bunch of brain cells that you want to kill. [05:31.010 --> 05:31.410] All right. [05:31.490 --> 05:35.590] So we're going to be covering a lot of different attacks today, and I have a lot of slides, so we're going to go through them kind of quickly. [05:35.650 --> 05:40.850] But I want to dive in enough on each one that you guys come away with an understanding of how these things work and what's possible. [05:40.850 --> 05:45.070] So we're going to talk about disconnecting Wi-Fi devices, deauthentication attacks. [05:45.310 --> 05:47.110] We're going to talk about Wi-Fi phishing attacks. [05:47.410 --> 05:54.050] We're going to talk about how we can use microcontrollers to identify the Wi-Fi networks that are stored inside people's phones. [05:54.290 --> 06:04.710] And we're also going to learn how we can use them to simulate a mouse or a keyboard in order to do keystroke injection, make mouse jigglers, and also extract Wi-Fi handshakes from people's devices. [06:05.590 --> 06:10.190] We're also going to talk about AGPS spoofing, so assisted GPS spoofing, Wi-Fi surveillance, [06:18.770 --> 06:23.290] So don't worry, we are going to cover lots of different ways you can use these microcontrollers. [06:23.430 --> 06:25.230] They are very, very cheap to do lots of bad stuff. [06:26.470 --> 06:30.590] So let's talk about the difference between a microcontroller and a computer. [06:30.850 --> 06:34.630] So a Raspberry Pi is a very well-known computer that is a single-board computer. [06:34.770 --> 06:36.150] It has everything you need to interact with it. [06:36.230 --> 06:37.850] It has ports for HDMI. [06:37.850 --> 06:42.110] It has a place for you to put a cable for a keyboard. [06:42.670 --> 06:47.430] It allows you to really work with it any other way you would expect to use a computer with an operating system and all that. [06:47.750 --> 06:51.250] Whereas a Raspberry Pi Pico is an example of a microcontroller. [06:51.610 --> 06:52.850] You need to program this. [06:53.030 --> 06:55.670] And it generally can be programmed with things with CircuitPython or Arduino. [06:56.350 --> 06:58.670] And the cost on this is really different. [06:58.810 --> 07:02.230] So right now, if you want to get a Raspberry Pi, it's probably going to be $200. [07:03.170 --> 07:04.290] That wasn't always the case. [07:04.390 --> 07:11.390] They were supposed to be $35, but because of the chip shortage and some other logistics issues, it's gotten to the point where they're very expensive to come by. [07:11.710 --> 07:14.530] Whereas a microcontroller are pretty consistently cheap. [07:14.650 --> 07:18.830] And you can find these for about $4 even when other things start to go higher and higher and higher. [07:18.950 --> 07:25.390] So if you're someone who's been priced out of the Raspberry Pi ecosystem recently, this might be a really interesting alternative for you. [07:27.690 --> 07:31.890] So what kind of skills do you need to do some of the things I'm going to be talking about today? [07:32.310 --> 07:41.010] Well, in order to try one of these projects that's already been created and is supported by these microcontrollers, you need to know how to flash some of these community projects via a web browser. [07:41.130 --> 07:43.310] So no command line stuff is really needed here. [07:43.790 --> 07:44.910] Installing Arduino IDE. [07:45.470 --> 07:48.670] Adding boards to Arduino IDE for the one that you want to work with. [07:49.070 --> 07:51.930] Compiling and flashing source code in Arduino, which is very simple. [07:52.470 --> 07:56.970] And then flashing CircuitPython via a web browser if you want to get started with interpreted languages. [07:57.490 --> 08:01.330] So that doesn't... that's not... no computer science degrees in this list, you know? [08:01.450 --> 08:04.870] Like you can get started with this as a total novice beginner just by following the instructions. [08:05.190 --> 08:07.050] And I think that's a really important takeaway here. [08:08.530 --> 08:10.050] So what if you want to go deeper? [08:10.190 --> 08:16.730] What if you don't want to just work with a community project that's already out there and you want to program your own hacking tool? [08:17.250 --> 08:20.530] Well, there's also not a CS degree necessary here. [08:20.650 --> 08:24.290] You just need to have some experience in C++, Arduino, or Python. [08:24.710 --> 08:27.270] Be willing to learn Python command line utilities. [08:27.530 --> 08:33.110] Maybe use something like Moo Editor or Arduino IDE and have a basic knowledge of how serial ports work. [08:33.210 --> 08:36.310] Because you're going to be communicating with serial ports a lot and that will be important. [08:36.570 --> 08:37.810] Also good research skills. [08:37.930 --> 08:42.090] If you can find Stack Overflow answers, then you'll probably be okay doing this. [08:43.650 --> 08:50.130] So there are three primary ways to program a microcontroller that I would like every beginner to walk away with. [08:50.250 --> 08:57.170] And this is the way that you can take a blank microcontroller and put a really interesting and cool project on it or program it with your own code. [08:57.410 --> 09:03.010] The first way is to flash an already compiled binary file via a web browser. [09:03.150 --> 09:11.350] And Chrome currently supports web serial, which makes it really, really easy to just plug this thing in, go to a website, flash a binary file, and boom, it works. [09:11.350 --> 09:12.430] It's not very hard. [09:13.270 --> 09:17.010] So the second way is you can flash over CircuitPython, which we'll get a little bit more into later. [09:17.450 --> 09:21.630] And that lets you use any Python skills you might have to start prototyping things with hardware. [09:22.310 --> 09:28.710] You just need to flash the CircuitPython binary the same way you do in a web browser, and then you can write CircuitPython code to the board. [09:30.010 --> 09:36.950] So probably the most discouraging for me, as someone who's bad at math and not good at C++, is programming in Arduino IDE. [09:37.610 --> 09:42.070] You will just need to flash over the compiled binary file once you finish writing your code. [09:42.370 --> 09:43.350] You'll need to install the board. [09:43.670 --> 09:47.430] But overall, this process, while more complicated than the other two, is really not that bad. [09:47.430 --> 09:51.630] So those are the three different ways that you can flash over code to a microcontroller. [09:51.830 --> 09:53.690] Pre-compiled code, flash over the browser. [09:54.270 --> 09:56.690] CircuitPython binary, so you can write your own CircuitPython. [09:57.090 --> 10:03.070] Or write compiled code, C++ or Arduino code, flash it over via Arduino IDE. [10:03.390 --> 10:07.330] So it's not very hard, and there are some really easy ways to get started doing this. [10:07.330 --> 10:14.930] So this is what it looks like to flash over a binary file via Google Chrome. [10:15.130 --> 10:19.430] So in the scope of this GIF, I am completely flashing a microcontroller with... [10:20.150 --> 10:22.070] I think in this case it is... [10:22.070 --> 10:22.790] Ah, yes. [10:22.910 --> 10:26.530] The firmware that runs on our rubber nugget or USB nugget device. [10:26.750 --> 10:33.470] And it's able to erase the microcontroller and flash it over completely in the browser without needing any sort of command line experience. [10:33.770 --> 10:36.850] I think that's really important because this didn't exist a couple years ago. [10:36.850 --> 10:42.670] And you needed to know the command line at least a little bit in order to flash over binary files like this. [10:42.830 --> 10:47.390] So this is a big step forward, I think, for beginners being able to work with these microcontrollers we're going to be covering today. [10:48.470 --> 10:49.950] And as you can see, we're pretty much done. [10:50.070 --> 10:57.030] As soon as this bar is loaded, we will have erased and written the firmware file to this microcontroller, and it will be ready to use. [10:57.170 --> 11:00.110] That's how easy it is for you to get started with one of these cheap microcontrollers. [11:00.230 --> 11:05.270] You can plug it in, and in the space that I've been talking, you would have already been done flashing this thing. [11:05.270 --> 11:06.490] So that's pretty cool. [11:08.250 --> 11:10.350] All right, so let's talk about CircuitPython. [11:10.550 --> 11:15.850] It's really cool because CircuitPython allows you, again, to use any Python skills you might have on a microcontroller environment. [11:16.090 --> 11:17.530] It shows up as a USB drive. [11:17.670 --> 11:19.190] You can basically drag and drop code. [11:19.350 --> 11:21.390] And the process for doing this is very similar. [11:21.670 --> 11:27.550] You would go to circuitpython.org, locate the board you want to work with, and flash over the CircuitPython binary. [11:27.550 --> 11:35.650] Once that's flashed over, you can access the USB drive that pops up, and literally just drag and drop or start typing your Python code. [11:36.010 --> 11:38.330] And this will allow you to start prototyping on a microcontroller. [11:38.590 --> 11:45.470] So if you're a Python person that's been holding off on using microcontrollers because you think you need to learn C++ or Arduino, that time has passed. [11:45.630 --> 11:47.790] You have no more excuses to try this sort of thing out. [11:48.650 --> 11:50.630] To not try to get this thing out. [11:51.590 --> 11:51.910] All right. [11:52.370 --> 11:59.790] So last up, we have, if you want to have a harder time, or if you are more experienced with C++ programming, you can flash over your code in Arduino IDE. [12:00.210 --> 12:03.170] So sometimes there's a piece of code that has a variable that needs to be changed. [12:03.370 --> 12:08.450] Let's say that it's something that connects to your WiFi network and then does something cool, like monitors it or something like that. [12:08.690 --> 12:14.230] Okay, well, you need to take that code and add your WiFi credentials, create the binary file, and flash it over. [12:14.330 --> 12:17.550] So that's one extra step, but Arduino IDE will generally do this for you. [12:17.550 --> 12:31.090] You'll need to add the device that you want to flash in the board manager URL, plug the device into... oh, install the board in the board manager, plug your device in and select the serial port, and then once you're done with your code, hit compile and send it over. [12:31.270 --> 12:35.610] So it's not that many steps, but again, this is only if you have a project that you need to modify something. [12:35.770 --> 12:40.690] You need to take the source code and maybe put in your WiFi credentials, put in a name you want to add to it, something like that. [12:42.590 --> 12:45.630] So there's a number of different programming languages you can use to interact with this. [12:45.750 --> 12:51.210] We're not going to talk too much about this, but I want you to take that away if you want to get started with this yourself, maybe make your own prototype. [12:51.690 --> 12:55.230] Virtually all the microcontrollers we're going to be talking about today can support Arduino IDE. [12:55.630 --> 12:58.090] Many of them can be programmed in MicroPython as well. [12:58.590 --> 13:07.170] And then only those that have USB support, AKA they can pop up as a USB drive to support easy drag-and-drop code, will support CircuitPython at the moment. [13:07.970 --> 13:13.270] I actually really like that because it simplifies this, and we'll go more into the difference between those two languages in just a sec. [13:14.550 --> 13:18.750] So CircuitPython is excellent because it's an interpreted language that's supported by Adafruit. [13:18.930 --> 13:21.910] Adafruit has wonderful documentation and great support. [13:22.350 --> 13:26.630] So in general, the experience is really excellent when working with these boards because they're targeted at beginners. [13:27.650 --> 13:30.330] Adding libraries is as easy as dragging and dropping it. [13:30.750 --> 13:35.170] And generally, I really, really like the experience that we have teaching this language to beginners. [13:36.410 --> 13:42.510] MicroPython is a community-supported project that has excellent documentation, all of it written like nine years ago. [13:42.710 --> 13:48.990] So I always get very nervous when I'm using it because I always find the right answers, but it's so old that sometimes I'm not sure if it's going to work or not. [13:49.130 --> 13:51.390] I get very nervous working with MicroPython. [13:51.530 --> 13:55.530] And it does work on a lot of boards that CircuitPython does not work on. [13:55.530 --> 14:02.170] So some of the really cool Wi-Fi-based microcontrollers we're going to talk about that don't support CircuitPython do support MicroPython. [14:02.310 --> 14:19.190] But the experience is, I would say, more difficult for beginners, requires command-line experience, and that's why typically between the two, I tend to go for CircuitPython over MicroPython when I'm teaching beginners how to use Python on a microcontroller because of the USB support, [14:19.470 --> 14:21.890] the support for web serial, so they can do it through a browser. [14:22.130 --> 14:24.070] They don't need any command-line experience. [14:24.070 --> 14:26.550] And Adafruit, again, has really excellent documentation. [14:28.790 --> 14:32.510] So last up, Arduino IDE is a compiled language based on C++. [14:32.850 --> 14:35.710] It allows you very, very low-level control. [14:35.890 --> 14:44.690] So Alex and I work as partners making prototypes where I will come up with a terrible thing you can do with a microcontroller and write it in CircuitPython in an absolute garbage-fire way. [14:44.850 --> 14:55.710] He will then look at that and then create a C++ version that has very fine-level control, lots of options, and is very polished and very nice, and release that as a binary file that anybody can just take and throw onto their boards. [14:56.150 --> 14:57.550] So that's kind of the difference between the two. [14:57.890 --> 15:00.030] C++ is more challenging to write and run. [15:00.610 --> 15:06.770] There's lots of different hardware libraries that are available for you to use, but some of these compile errors don't even make sense. [15:06.850 --> 15:08.790] Like, I got this huge red error as a beginner. [15:08.930 --> 15:09.870] I would think something was wrong. [15:10.150 --> 15:11.410] The board flashed perfectly fine. [15:11.470 --> 15:12.010] This is standard. [15:13.010 --> 15:22.690] As a beginner, I found Arduino to be a lot less fun to learn on, and it kind of killed my enthusiasm in some ways for making prototypes, but CircuitPython brought it back. [15:22.830 --> 15:28.530] So if you've been discouraged before trying to work with microcontrollers and you haven't tried CircuitPython, I really, really encourage you to try it out. [15:29.530 --> 15:31.050] So, all right, let's get to the microcontrollers. [15:33.510 --> 15:38.290] We're going to be talking about things that go all the way from $0.80 up to about $5.55. [15:38.610 --> 15:45.430] So I'm sorry to have baited you on that $0.55, but we'll try to keep it below $5 and stay honest for this presentation. [15:46.810 --> 15:48.830] We're going to start out with the ATtiny85. [15:49.190 --> 15:56.090] So this is a little low-power microcontroller in which the most useful form factor is the DigiSpark. [15:56.230 --> 16:01.610] Now, I have taught a lot of classes on making a bad USB device out of this little microcontroller. [16:01.990 --> 16:08.630] And the traces on it are not perfectly spaced to work with, for example, MacBook Pros or several other brands of computers. [16:08.770 --> 16:12.790] So I get lots of people who try to work with this microcontroller and they think it's broken. [16:12.990 --> 16:18.670] But then we try 10 of them that I know are good and they just don't work and we realize you need a USB adapter or some other nonsense for it. [16:18.810 --> 16:20.690] It's because they're so cheap. [16:20.810 --> 16:22.970] This is the cheapest one I'm going to cover in our presentation. [16:24.030 --> 16:32.390] And the fact that you can get one of these individual modules for as low as $0.80, this one is currently available for about $2.50 post-chip shortage. [16:32.830 --> 16:37.670] It's just a sign that, you know, for what you can do with these, the cost is extremely low. [16:38.230 --> 16:39.350] So projects this supports. [16:39.570 --> 16:40.710] Well, bad USB, obviously. [16:40.970 --> 16:43.590] You're able to make this look like a keyboard. [16:43.770 --> 16:46.230] So when it's plugged into a computer, it will execute a script. [16:46.410 --> 16:55.850] And you can also take existing DuckyScript, which is a Hack 5 scripting language to script out all these bad things you can do with a malicious keyboard, and transfer it over to this. [16:55.850 --> 16:56.750] So that's really cool. [16:56.870 --> 16:58.650] You can take existing payloads and move them over. [16:58.870 --> 17:00.430] They do need to be translated over. [17:01.270 --> 17:04.850] As I said, there's a high failure rate on this working in someone's USB port. [17:04.930 --> 17:10.850] So if you're trying to use this as a sneaky cyber weapon, and then they have an old MacBook Pro, it just won't work because the traces are the wrong size. [17:11.870 --> 17:20.090] It only takes one payload, and it is a bit of a burden to transfer some of these old DuckyScripts over and make them into actually something that works on this. [17:20.350 --> 17:30.690] So I would say, in summary, I hate these little shits because they have ruined many of my workshops, and overall, they are not powerful enough to do consistently interesting hacking things. [17:30.810 --> 17:36.830] Although intermittently, they're a great thing to work with if you want to teach a low-cost class and only want to spend, like, 80 cents per microcontroller. [17:38.150 --> 17:39.590] We can also make a mouse jiggler. [17:39.730 --> 17:46.970] So this is interesting because a lot of people are cheaters and like to cheat at video games, and auto-clickers are something that are very interesting to them. [17:47.050 --> 17:47.790] I would never do that. [17:48.650 --> 17:59.950] So this is something where, because you can also simulate a mouse, and you can click in specific coordinates, you could basically rig up buttons to this or whatever and make something that is an auto-clicker or, you know, controls both the keyboard and the mouse. [18:00.090 --> 18:03.430] Kind of interesting, but the way that you flash these is cursed. [18:04.070 --> 18:07.310] It is very, very annoying and not very reliable. [18:07.530 --> 18:09.170] So do I recommend these necessarily? [18:09.870 --> 18:11.390] Not... no, not necessarily. [18:11.650 --> 18:17.610] But if you want to buy a hundred of these and not care that, you know, a quarter of them don't work, then you can afford to with these. [18:17.730 --> 18:19.470] And they can still do some pretty interesting attacks. [18:19.670 --> 18:27.750] So on all of my slides, I have actually either covered this in a Nullbyte article, video, or a Hack 5 video. [18:27.950 --> 18:30.470] So if you want to see a 15-minute presentation on... [18:30.470 --> 18:33.770] basically a tutorial on exactly how to do every single one of these. [18:33.930 --> 18:34.810] You can take a picture of this. [18:34.970 --> 18:45.790] I will put this up on the Wiki later and you'll be able to go deep on any of these topics because I've literally tried out all of them and written guides on them, plus shot a 15-minute long video on how to do it so you can follow along yourself. [18:47.530 --> 18:47.870] All right. [18:48.010 --> 18:50.570] So next up is the ATmega32 4U. [18:50.810 --> 18:52.690] This is much faster than the ATtiny. [18:52.870 --> 18:53.910] It has similar capabilities. [18:54.070 --> 18:57.690] And if I was running a workshop, I would use one of these suckers because they work way better. [18:57.890 --> 19:01.110] They're way more reliable and they flash like a normal microcontroller. [19:01.250 --> 19:03.290] They don't have all the weirdness that the ATtiny's do. [19:03.810 --> 19:07.470] They don't have any wireless anything, which makes me substantially less interested in them. [19:07.770 --> 19:11.230] However, they are still a very smooth experience for USB attacks. [19:11.390 --> 19:12.650] And we'll get to that later. [19:12.930 --> 19:25.550] Because while these ones are not incredibly useful, much more useful than the previous category, they are substantially more stable and they can be combined with other cheap microcontrollers that do support Wi-Fi to do some truly interesting things. [19:26.690 --> 19:28.310] So next up, we have the Raspberry Pi Pico. [19:28.550 --> 19:34.010] This is based on the RP2040, a proprietary Raspberry Pi chip that they just came out with. [19:34.510 --> 19:35.510] Supports native USB. [19:35.810 --> 19:36.730] Very interesting to me. [19:36.850 --> 19:41.470] That means that it can support CircuitPython, which means it's open for anybody who has Python experience. [19:41.690 --> 19:43.950] And it also can do all sorts of bad USB stuff. [19:44.150 --> 19:46.270] You can make your auto-clicker cheaters. [19:46.430 --> 19:51.970] A lot of people are doing like art and music stuff with it too, making MIDI controllers and stuff with that, using the USB capabilities. [19:51.970 --> 19:54.590] But of course, I am interested in hacking stuff. [19:55.190 --> 19:59.890] So if we want to take a look at what we can do with it, we can look no further than the PicoDucky project. [20:00.190 --> 20:07.010] So this was created by Dave Bailey and basically allows you to run Ducky scripts as is on the Raspberry Pi Pico. [20:07.230 --> 20:12.430] Now the only problem with this is the Raspberry Pi Pico doesn't have any buttons, nor does it have a screen. [20:12.690 --> 20:19.610] So being able to flip it into programming versus attack mode requires you to jump to pins, which I don't particularly like. [20:20.030 --> 20:22.510] And you also don't really know what's going on because there's no output. [20:23.050 --> 20:30.190] So this does support, you know, a single payload or potentially like multiple payloads if you're able to trigger it with like shorting pins. [20:30.490 --> 20:34.330] But I don't like to short pins in the field because that's how you get magic smoke. [20:34.950 --> 20:40.430] So if you don't want to destroy this little thing, then you might want to rig a button or something like that. [20:41.110 --> 20:42.350] This is an open source project. [20:42.530 --> 20:43.710] It supports multiple keyboards. [20:44.130 --> 20:47.410] Dave has done a really good job of updating this and it is a circuit Python project. [20:47.570 --> 20:52.310] So if you're a Python person and you want to whip on some features to this, it's actually super easy to do that. [20:52.510 --> 20:53.750] That's why I love this project. [20:54.090 --> 20:58.330] And also, the Raspberry Pi Pico is coming out with the wireless version. [20:58.530 --> 21:06.630] So if you get it and you wanted to add Wi-Fi capability to it just as a Python person, you could totally do that in Python with very little microcontroller experience necessary, which is pretty cool. [21:07.910 --> 21:12.510] All right, now we're going to talk about the star of this presentation, the ESP8266. [21:13.050 --> 21:26.470] This is a $1.73 ESP8266 module like this can be stamped onto a lot of different larger modules that include USB support and other things that are very useful. [21:26.730 --> 21:29.570] They are capable of Wi-Fi packet injection. [21:29.830 --> 21:30.790] This is super cool. [21:30.890 --> 21:31.650] It means you can do deauthentication. [21:32.390 --> 21:33.190] You can spoof networks. [21:33.190 --> 21:38.550] You can do all sorts of spooky Wi-Fi things that most manufacturers will not allow you to do. [21:38.930 --> 21:40.810] Now, Espressif has actually locked this down. [21:41.230 --> 21:49.250] They got in kind of some trouble for allowing this to happen, but there's still an old software development kit out there that allows you to write arbitrary packets. [21:49.390 --> 21:54.970] And that's the key to this microcontroller's ability to easily send deauthentication packets or other sorts of bad packets. [21:55.210 --> 22:03.010] Most of the other microcontrollers we're talking about after this point are too new to allow that, because Espressif, the company behind it, has actually locked that feature down. [22:03.010 --> 22:08.430] And there's ways of getting around it, but it requires you to basically recompile the entire firmware, and it is not for beginners. [22:09.350 --> 22:09.550] All right. [22:09.730 --> 22:20.370] So this can also host web servers, which means this tiny little chip can support like a Wi-Fi interface that allows you to connect over your phone to this chip and have it run things. [22:20.770 --> 22:29.750] Now, unfortunately, it does not have native USB support, meaning it doesn't support CircuitPython and it doesn't pop up as a USB drive, which is really sad, because otherwise this thing is great, right? [22:29.750 --> 22:32.850] And it is a little bit low power, so there are some limitations there. [22:34.130 --> 22:41.170] So these always come in modules, and I have to buy lots and lots of these, so let me share my pain with you and maybe save you a little bit of your own. [22:42.090 --> 22:45.930] Version 3 of the NodeMCU is a big, chonky boy. [22:46.770 --> 22:47.570] You don't want it. [22:47.650 --> 22:49.510] It doesn't fit in a breadboard, and it is terrible. [22:49.850 --> 23:00.790] Pretty much everything else on the screen, aside from that, is fine if you want to start working with an ESP8266 that's in a module that includes USB serial support and has all the nice things you would want, including breakout pins. [23:00.990 --> 23:03.310] I personally love the D1 Mini. [23:03.510 --> 23:04.570] It's on the bottom of the screen. [23:04.570 --> 23:05.330] It is fantastic. [23:05.630 --> 23:07.750] You can see they're going for $1.73. [23:07.990 --> 23:09.010] They are wonderful. [23:09.270 --> 23:12.550] Some of them even allow you to add an external antenna. [23:12.730 --> 23:19.890] So if you wanted to make a directional antenna, make a fox-hunting device out of this, you'd have to flip a little tiny resistor to switch it over to the external antenna, but you can do it. [23:19.890 --> 23:21.610] And that is really, truly cool. [23:22.810 --> 23:25.310] And that is the pro version if you're interested in something like that. [23:25.670 --> 23:34.590] So again, these are the modules that we typically use when we're working with these because they include all the additional hardware we need to plug it into a computer via USB cable and get it to work. [23:34.770 --> 23:43.510] So this is what I recommend if you want to get started with it, particularly the D1 Mini is my all-time favorite microcontroller for Wi-Fi hacking things. [23:43.790 --> 23:46.930] So first up, we have the ESP8266 deauthor. [23:47.230 --> 23:48.950] A lot of you have probably heard of that. [23:48.950 --> 23:51.130] My friend Stefan Kremzer, a.k.a. [23:51.710 --> 23:53.470] Space Hoon, is the creator of this project. [23:53.710 --> 23:58.690] It runs on the ESP8266, and it offers both a web and a serial interface. [23:58.910 --> 24:05.710] And the web interface is over a Wi-Fi control network that it broadcasts and allows you to connect on your phone and do all sorts of interesting things. [24:05.890 --> 24:07.910] So it can scan for Wi-Fi access points. [24:07.910 --> 24:09.110] It can scan for clients. [24:09.310 --> 24:13.010] It can jam Wi-Fi clients via deauthentication attacks. [24:13.010 --> 24:16.210] So that's protocol-based jamming, not signal-based jamming, I should specify. [24:16.510 --> 24:23.210] And then it's able to create fake access points which trick any client that has joined an access point like that before into joining. [24:23.530 --> 24:24.470] Very fun and interesting. [24:24.610 --> 24:25.410] We'll do more with that later. [24:25.590 --> 24:35.270] And we can also create fake probe requests, a request for networks that would reveal something like a Hack5 Wi-Fi pineapple that's going to spin up a network in response to any of these probe requests we send out. [24:35.270 --> 24:43.070] So a lot of interesting things we can do by just kind of connecting over our phone to this microcontroller over a Wi-Fi network. [24:43.470 --> 24:45.790] So this is what the interface actually looks like. [24:45.890 --> 24:48.370] And I'm accessing it on computer, therefore it's wider. [24:48.510 --> 24:59.710] But it actually looks pretty good on mobile and allows you in the first part to run a scan, get a list of all the Wi-Fi devices that are near you with their relative signal strength displayed all nicely in color like this. [24:59.810 --> 25:05.210] It allows you to select different networks and either attack them, clone them, send requests to them. [25:05.570 --> 25:11.670] You can even, I believe, send fake networks only to a specific device. [25:11.810 --> 25:13.710] So all the other devices around it do not see it. [25:14.090 --> 25:19.990] It's a very, very interesting tool that allows you a lot of control over Wi-Fi in the 2.4 gigahertz spectrum. [25:21.050 --> 25:26.870] So there's also a serial-only version of this that I helped develop a couple of years ago called the V3. [25:27.130 --> 25:35.650] So the V3 of the Wi-Fi deauthor is the lesser-known version and it supports Wi-Fi phishing, which is a capability I pushed for demonstrating really hard. [25:36.090 --> 25:41.270] The creator, Stefan, didn't really want to do this originally, but I convinced him that it would be super cool to implement this on a microcontroller. [25:42.070 --> 25:47.050] It also supports rogue AP creation, but it doesn't allow you to send data. [25:47.190 --> 25:54.670] So devices can connect to the access point that it is creating, but they're not able to, like, you know, watch a YouTube video or something on it. [25:54.670 --> 26:00.530] And it also supports a beacon-swarming attack, which is some research that I did recently that I'm happy to share in a minute. [26:01.610 --> 26:03.150] So first off, Wi-Fi phishing. [26:03.390 --> 26:10.150] So the way that this works is instead of an interface, we're connecting over serial, so the Wi-Fi radio is completely free to do whatever we want. [26:10.410 --> 26:16.530] So in the first version of the Wi-Fi deauthor, we were making a friendly interface for the hacker to connect and, you know, do scans and stuff. [26:16.790 --> 26:26.030] In this version, we're first deauthenticating a victim from a Wi-Fi network, then we're popping up a fake Wi-Fi network with the exact same name but no security. [26:26.190 --> 26:30.930] So it's an open Wi-Fi network with the same name as the network our victim is being kicked off of. [26:31.250 --> 26:40.370] As soon as the victim connects, because, you know, they can no longer access their data, they're confused about what's going on, it pops up a fake router update page and says, Hi, I'm the router. [26:40.550 --> 26:41.890] I just received a security update. [26:42.050 --> 26:43.930] Please enter your password in order to proceed. [26:44.290 --> 26:51.550] As soon as the user types in a password, the microcontroller will attempt to join that network with the password that they provided. [26:51.790 --> 26:54.950] And if it was the right password, it stops the deauthentication attack. [26:55.170 --> 27:00.310] And if it worked correctly, the user thinks that they did a very good job updating the router today. [27:03.590 --> 27:16.610] So, I kind of saw how, by using the Wi-Fi interface, we were already creating the environment where it would be possible to do this sort of phishing attack on a microcontroller instead of needing to use, you know, a Linux computer with a wireless network adapter. [27:16.610 --> 27:19.390] So, this was really, really exciting to be able to do this. [27:19.490 --> 27:21.650] And if you want to check out the video, it's right here. [27:21.790 --> 27:25.490] And we go through the entire process of phishing and what it looks like and how to do it. [27:25.610 --> 27:26.650] So, really, really cool. [27:27.150 --> 27:29.450] So, the next piece of research I did was on beacon swarms. [27:29.650 --> 27:35.630] So, in the original version of the Wi-Fi deauthor, you were able to create, like, a hundred fake Wi-Fi networks. [27:35.630 --> 27:37.150] And it was all, like, rick-rolling stuff. [27:37.310 --> 27:58.130] But I was like, hey, what if instead you got a list of every open Wi-Fi network, every coffee shop, every, like, school that has open Wi-Fi, every, like, free trial, and also every, like, default router name, and made a huge list of this and broadcasted it and just waited and listened for which devices nearby responded because they had that network stored inside them. [27:58.130 --> 28:04.350] So, if you have joined an open network, for example, like a coffee shop, a hotel, maybe an airplane, that is stored in your phone. [28:04.450 --> 28:13.270] And what I can do is make a list of, like, one or two hundred of these very common open Wi-Fi network names and I can present it to your phone and see which ones you've joined in the past. [28:13.470 --> 28:19.710] And once I know a couple networks you've joined in the past, I can trick your phone into joining my network and start controlling your data connection. [28:19.830 --> 28:23.870] I don't know, creating a VPN and sending it to Japan and making all your websites load in Japanese. [28:24.010 --> 28:24.510] That one's fun. [28:27.070 --> 28:30.330] So, this is also a way that you can see where someone's been in the past. [28:30.430 --> 28:36.870] So, if you want to know where somebody works, you can create a list of all these different companies' office Wi-Fi network names. [28:37.070 --> 28:51.170] You can put it out there and, for example, if you're looking for, like, defense contractors or something sensitive, you can literally sense people who work at that company by their phone attempting to join that network as they walk by and their phones see a network that they recognize and go, [28:51.310 --> 28:52.810] oh, I recognize that and tried to join. [28:52.810 --> 28:56.950] They won't be able to successfully join because I don't know the password to their office network. [28:57.190 --> 29:02.710] But I do know that they have been there before because their phone recognizes that it automatically joins when it sees it. [29:02.850 --> 29:11.370] So, it's an interesting way that we can spot where people have been before by extracting information about networks stored in their phone by presenting them with networks with the exact same name. [29:11.510 --> 29:15.270] Because even though they have a different password, their phone doesn't know that until it attempts to connect. [29:15.270 --> 29:19.270] And by that point, it's already given up the fact that, hey, I have been to this place before. [29:19.410 --> 29:20.450] I've connected to this network before. [29:20.590 --> 29:25.030] So, if you've connected to the strip club network recently, you might want to delete that before you go home. [29:27.130 --> 29:29.670] So, another thing that's very interesting... I think I covered it. [29:29.730 --> 29:29.990] Oh, yes. [29:30.090 --> 29:31.190] Is the half handshake attack. [29:31.330 --> 29:32.830] So, let's take that a step further. [29:32.950 --> 29:34.050] We're using our microcontroller. [29:34.050 --> 29:39.890] I create a hundred Wi-Fi networks and one of them is, I don't know, my company, Varonis, our office. [29:41.010 --> 29:44.450] And I, as a hacker, want to be able to do something remote. [29:44.570 --> 29:49.930] So, I want to send like a package to the Varonis office and have it connect to the Wi-Fi and do all this bad stuff. [29:50.030 --> 29:51.690] But I need to know the Wi-Fi network first. [29:51.790 --> 30:06.190] So, if I knew a place that Varonis people hang out and I was able to use my microcontroller to create a network that looks like the office network, their devices would all attempt to join and send a hash of the password stored in their phones to this fake network that I'm creating. [30:06.370 --> 30:10.030] So, if I... and it is noted that you need a computer for this step. [30:10.370 --> 30:18.170] If I am running Wireshark on my computer and I'm listening for devices attempting to connect to this fake Varonis office network, I can get that hash and crack it. [30:18.270 --> 30:32.390] And if it's not very good, if I have an AWS instance with a huge GPU, then I can actually get the office network or your home network just by extracting it from your phone by presenting your phone with an identical looking network which has a totally different password. [30:32.830 --> 30:35.570] But again, your phone doesn't know that until it tries to connect to it. [30:35.730 --> 30:38.790] And by that point, it's too late and I can grab this hash. [30:39.230 --> 30:44.370] And now, it is noted that I can't verify it until I actually go there and try it and see whether or not it works. [30:44.390 --> 30:52.330] But I can extract information about devices you've connected to in the past and networks that you've connected to in the past I can extract a hash from. [30:52.470 --> 31:02.850] So, that's very interesting because again, if you have a weak home Wi-Fi password or if you have a weak office Wi-Fi password, if I create a version of that with a microcontroller that looks enticing to your phone, it will give up that information. [31:02.950 --> 31:09.670] And there's not really a lot you can do aside from disabling auto-connect to prevent that, which is very sneaky, if I don't say so myself. [31:11.030 --> 31:14.290] Alright, so next up, we can also mess with assisted GPS. [31:14.650 --> 31:15.150] Check the time. [31:15.330 --> 31:15.530] Cool. [31:15.970 --> 31:24.750] So, assisted GPS is the way that GPS solves the problem of bouncing GPS signals in a dense urban location like downtown Los Angeles or Manhattan or something like that. [31:24.750 --> 31:36.070] So, because the GPS signals bounce so much, your phone will actually do a scan of which Wi-Fi networks are around you and then approximate your location by submitting it to an API that knows where all of those Wi-Fi networks are. [31:36.230 --> 31:49.250] That's actually what those Google Street View cars were doing for a very long time, was geolocating all those Wi-Fi networks in order to create a Wi-Fi map of where every access point in America is so it can figure out where you are just based on Wi-Fi signals. [31:49.250 --> 31:50.910] So, we can totally f*ck with that. [31:52.550 --> 32:01.990] So, in areas that have poor GPS reception, we can present a series of Wi-Fi networks that look like the ones that are actually in a different location. [32:02.170 --> 32:04.030] Our favorite being Zuck's pool. [32:05.370 --> 32:20.490] So, somebody got a good scan, I guess at a party or something, of the Wi-Fi networks around Mark Zuckerberg's pool and made a kind of pre-packaged thing called Skylift that will allow you to put any networks you want to make it appear that somebody's phone is close to these networks that have a known location, [32:20.610 --> 32:21.610] a very well-known location. [32:21.830 --> 32:34.570] So, we were able to go into like a mall garage where there was poor GPS reception and start spoofing this and actually see our phones geolocate us, as you can see in the screenshot, in the Bay Area at Mark Zuckerberg's mansion. [32:34.850 --> 32:36.950] So, if you want to try this out, it does work. [32:36.950 --> 32:45.150] You do need, again, poor GPS reception in order to affect this because a good GPS signal will override a bunch of confusing Wi-Fi networks. [32:45.250 --> 32:54.430] But it's very funny to know how this convenience feature for making your GPS start up faster and work better in a city environment can totally be abused to spoof a location elsewhere. [32:54.690 --> 33:01.530] And of course, if somebody's being picked up somewhere or, you know, maybe they're in a building ordering an Uber, you could probably make that Uber go to France. [33:01.530 --> 33:07.290] You know, like if you were able to successfully spoof a location via just Wi-Fi positions. [33:07.770 --> 33:11.510] So, very, very interesting work and have tested this, can confirm it works. [33:13.070 --> 33:15.930] So, this is a creation by Alex Lin in the back. [33:16.150 --> 33:17.470] This is the ESP bug. [33:17.670 --> 33:26.570] So, this is an ESP8266 that hides inside of other electronics, connects to a Wi-Fi network, and then listens for the signal strength of nearby devices. [33:26.870 --> 33:38.710] So, once you start tagging them as, oh, this is my mom, this is my dad, you can pretty much find out when mom and dad are home from anywhere because it will push the signal strength for all of these known devices to a web server and let you look at it from anywhere. [33:39.130 --> 33:47.530] So, you could be, you know, on the bus or in the car or something and see exactly who's home by which Wi-Fi devices are close and which ones are moving, for example. [33:47.770 --> 34:05.350] So, this is a really interesting way of performing Wi-Fi surveillance on any 2.4 gigahertz Wi-Fi device that's in range because you can basically watch it move around a building as the signal strength gets higher and lower or leaves for a while and infer whether or not someone is home just by honing this in on cell phone or smartphone signals. [34:05.790 --> 34:22.530] So, because, you know, every smartphone is going to have Wi-Fi and not all smartphones randomize their Mac address all the time, especially when connecting consistently to the same network, it's possible to be able to tell when someone is home from anywhere by sneaking one of these tiny little devices into something like a USB charger or something like that. [34:22.590 --> 34:25.310] And you can see, I believe this one is supposed to be, yeah, like a USB hub or something. [34:25.310 --> 34:30.130] So, if this remains plugged in, it will persistently monitor who is in that area. [34:31.290 --> 34:35.990] And, yeah, it doesn't work as well against devices that are not associated with the same Wi-Fi network. [34:36.250 --> 34:40.670] So, they could be changing around their Mac address or doing some Mac address randomization to make it harder to track. [34:40.910 --> 34:48.170] But if it's people inside the home connecting to the Wi-Fi network, then it's very effective at tracking people who are in a building and telling when someone is there. [34:48.330 --> 34:53.270] Some hackerspaces use this to tell when, you know, the space is open and automatically, like, turn on the on button. [34:53.270 --> 34:58.490] Or you can use it, I mean, like, I can also see how it could be abused to track someone remotely. [34:58.750 --> 35:07.090] So, this is kind of a double-edged sword in proximity sensing and being able to tell whether or not somebody is inside a building or even inside a particular room. [35:08.890 --> 35:09.590] War driving. [35:09.830 --> 35:12.210] So, we decided to do some war flying, actually. [35:12.210 --> 35:13.970] And we post an experiment. [35:14.130 --> 35:23.650] Can we take a $2 GPS, a $1 SD card module, and a $1.80 ESP8266, connect them together, and fly them on a drone? [35:23.810 --> 35:35.350] So, we went to Missoula and decided to have our friend walk around with a smartphone that was projecting Wi-Fi signal that we kind of, like, created a filter for so we could look for it later on in the data. [35:35.350 --> 35:45.930] We flew a path around a park, and we were able later on, see if this plays, to very precisely identify exactly where they were and then verify it with the video footage from the drone. [35:46.410 --> 35:58.270] So, by looking for a specific known Wi-Fi device, I was able to use the range of the drone, which is over a mile, to run a search grid and be able to locate a single Wi-Fi device in a very large park. [35:58.270 --> 36:07.330] So, obviously, you can do war driving to locate, you know, where, you know, all the Wi-Fi networks around you are, save it to an SD card, and then be able to have a little map for yourself. [36:07.470 --> 36:13.590] But also, if you're tracking a device, being able to mount this on something highly mobile, like a drone, is really interesting. [36:13.870 --> 36:27.550] Of course, I had to take the SD card out and run this through a Python program to parse it and end up filtering for the device we're looking for, but it would be relatively easy to create a live running filter and detect when we get a hit on a device that we're looking for. [36:27.550 --> 36:40.290] So, what this means is if I'm looking for you, and I need to find you, and I know your phone's MAC address, I could potentially fly my drone around in a search grid and locate pretty precisely the area that you're in, which might be great for a search and rescue, [36:40.590 --> 36:42.150] but might be really bad for a hide-and-seek. [36:45.130 --> 36:49.430] So, the ESP8266 amazingly can also act as a NAT router. [36:49.610 --> 36:51.730] So, it basically acts as a network extender. [36:51.850 --> 36:54.170] The connection is crazy slow, but it does work. [36:54.250 --> 36:56.590] I was able to load a very low-resolution YouTube video. [36:57.290 --> 37:03.230] And I like to use this for practicing Wi-Fi hacking on something that behaves like a router, but doesn't cost as much as a router. [37:03.530 --> 37:06.050] So, you can connect multiple devices to this. [37:06.210 --> 37:06.950] It does routing. [37:07.070 --> 37:07.450] It does switching. [37:07.570 --> 37:10.070] You can attack it and it will behave like a regular router. [37:10.230 --> 37:15.850] So, if you're looking to get into Wi-Fi hacking and you want to create a little router to just attack, this thing is excellent for that. [37:15.990 --> 37:19.350] It's also great for isolating your IoT devices from your regular network. [37:19.350 --> 37:32.670] So, if you wanted to use it for that too, it makes kind of a good firewall thing where you can just deny it most of the access to your network and just assume that if something bad were going to happen to one of your IoT devices, it's limited to this little network that it creates. [37:32.830 --> 37:39.250] I'm actually pretty amazed that this little chip can both connect to a Wi-Fi network and then allow other devices to connect to it and share its Wi-Fi connection. [37:39.590 --> 37:41.250] That's incredible for $1.80. [37:41.410 --> 37:42.690] Like, I still can't get over that. [37:44.170 --> 37:45.490] Alright, so let's talk about limitations. [37:45.710 --> 37:47.790] Because obviously this thing is tiny and costs like next to nothing. [37:48.350 --> 37:51.110] It cannot see anything other than Wi-Fi packet headers. [37:51.430 --> 38:01.990] So, while it allows you to do sniffing and things like that, it is clipped off at a certain point and you cannot get any more information, which is unfortunate because that totally rules out Wi-Fi handshake capture. [38:02.270 --> 38:03.870] You cannot capture a handshake on this. [38:03.970 --> 38:09.150] It does not show enough information because it literally doesn't have enough space to store the whole packet or whatever. [38:09.370 --> 38:13.350] And there's some sort of limitation built in with the way that it gets a packet and reads it. [38:13.910 --> 38:15.190] It can't do five gigahertz Wi-Fi. [38:15.270 --> 38:16.450] People ask us this all the time. [38:16.550 --> 38:16.990] It just can't. [38:17.110 --> 38:17.890] You know, it's not built in. [38:18.250 --> 38:19.410] It sucks as a NAT router. [38:19.550 --> 38:20.450] It's not fun to work with. [38:20.650 --> 38:23.790] And no native USB support means that it's not easy for beginners to work with. [38:23.850 --> 38:30.950] You have to use command line stuff in order to work with this unless somebody like Spaceoon creates a web interface so that you can just flash it and then connect on your phone. [38:32.470 --> 38:37.030] So, alright, let's talk about the ESP8266 plus the ATmega32 for you. [38:37.190 --> 38:39.250] You can just lash these two things together. [38:39.250 --> 38:42.770] So, do you remember how I said the ESP8266 doesn't have native USB? [38:43.110 --> 38:47.650] Well, if you just connect it to a microcontroller that does, it kind of solves the problem, doesn't it? [38:48.250 --> 38:56.870] So, there is a project that I think is really interesting and worth mentioning that just sandwiches these two microcontrollers together rather than trying to find one that does both. [38:57.090 --> 38:59.830] And I think that that's actually pretty worth mentioning. [38:59.990 --> 39:04.190] So, we're going to talk about it even though it kind of comes very close to our budget and possibly goes over it a little bit. [39:05.390 --> 39:14.370] So, the Wi-Fi duck is a project that runs on the ESP8266 and the ATmega32 for you. [39:14.970 --> 39:29.130] The ATmega handles the USB functions and the ESP8266 creates a very attractive and very nice to work with Wi-Fi interface that lets you connect to this thing on your phone and run payloads on whatever computer that it's plugged into very easily. [39:29.310 --> 39:30.110] It lets you store them. [39:30.230 --> 39:30.990] It lets you edit them. [39:31.170 --> 39:33.210] And it's got lots of configurable features. [39:33.490 --> 39:37.590] You can set it up to run payloads as soon as it's plugged in as well, if that's what you want. [39:37.810 --> 39:40.730] And you can access the menu on any Wi-Fi device. [39:41.390 --> 39:43.990] So, you can see the little demo right here of what it looks like. [39:44.090 --> 39:46.050] That is actually it running on a mobile device. [39:46.170 --> 39:55.050] So, if you're trying to inject DuckyScript, this is a really cool open source project, which, while not particularly elegant, is still very, very capable. [39:55.350 --> 39:58.090] So, if we... I think I have... Yeah, this is what the web interface looks like. [39:58.230 --> 39:59.910] You're able to easily create scripts. [40:00.130 --> 40:01.990] The editor is super clean and intuitive. [40:02.250 --> 40:03.890] And again, it's an open source project, but look at it. [40:03.970 --> 40:04.790] I mean, it's just... No. [40:05.030 --> 40:08.090] It's just two microcontrollers just kind of sandwiched onto each other. [40:08.250 --> 40:11.930] So, didn't really solve the problem here of, like, not having good USB support. [40:12.030 --> 40:13.570] We just grabbed something else and stuck it on. [40:13.710 --> 40:15.850] That does work, but it's not my favorite solution. [40:16.030 --> 40:18.530] But it is definitely worth mentioning because this is an awesome project. [40:18.530 --> 40:20.270] And there's lots of good documentation for it. [40:20.810 --> 40:21.030] All right. [40:21.130 --> 40:22.490] So, let's move on to the ESP32. [40:22.930 --> 40:24.530] So, this is more powerful than the ESP8266. [40:25.530 --> 40:28.730] It supports Arduino, MicroPython, but it does not support native USB. [40:28.910 --> 40:30.470] So, we're not going to get CircuitPython on this. [40:31.070 --> 40:34.990] It's useful for basic applications like video routing, that sort of thing. [40:36.150 --> 40:37.430] It does do packet capture. [40:37.650 --> 40:41.110] So, unlike the ESP8266, it can see the entire packet. [40:41.310 --> 40:45.210] I have only tried about twice to try to get, like, a handshake, and I never succeeded. [40:45.430 --> 40:46.510] So, I don't know why that doesn't work. [40:46.510 --> 40:50.270] But in general, you're able to get much more information about packets. [40:50.830 --> 41:01.870] It can run either on an SD card or over serial to do packet capture, which is great because you can actually connect this to Wireshark and use this as a little wireless network adapter to do sniffing, which is really, really cool. [41:03.450 --> 41:09.090] So, it can also work as a NAT router, but it sucks way less than the ESP8266 because it's faster and better at everything. [41:09.090 --> 41:15.570] So, if you're looking to do any router attacking stuff, I would recommend an ESP32 over an ESP8266. [41:15.710 --> 41:17.330] This code is by the same person as well. [41:17.530 --> 41:20.790] They just made a scaled-up version that, in my opinion, works a lot better on the ESP32. [41:21.050 --> 41:25.590] Very useful for IoT devices or also, again, creating a hackable router for, like, five bucks. [41:26.730 --> 41:28.250] You can also make an offline chat. [41:28.410 --> 41:36.890] So, if you want to make a CTF, like, if you do, like, geocaching, or if you wanted to, in an area with no infrastructure, enable, like, a message board. [41:37.050 --> 41:43.430] This can run an offline message board for maybe clandestine communication or, you know, cyberpunk stuff. [41:43.450 --> 41:43.830] Who knows? [41:44.270 --> 41:50.450] And this can allow you to host a chat just on the microcontroller that runs through a web interface and allows anybody to connect and contribute. [41:50.750 --> 41:53.090] This is useful for a number of things, most of which I've mentioned. [41:54.210 --> 41:59.430] So, another two things stuck together is the ESP8266 plus the ESP32. [41:59.710 --> 42:05.150] Do you remember how I said that the ESP32 can do full packet capture and the ESP8266 can't? [42:05.330 --> 42:05.910] Well, guess what? [42:06.010 --> 42:08.730] If you stick them together, then you kind of solve the problem. [42:09.030 --> 42:13.130] So, again, this is kind of an inelegant solution in many ways, and it is outside of our budget. [42:13.230 --> 42:21.230] But I wanted to mention it because the ESP Marauder is something that links these two together, very similar to the Wi-Fi duck, and does a whole bunch of different Wi-Fi attacks. [42:21.230 --> 42:24.470] It's kind of a multi-tool, so I can't really tell you what it does super well. [42:24.870 --> 42:26.370] It does a lot of stuff kind of halfway well. [42:26.750 --> 42:30.610] But it is very interesting for the number of attacks that it supports and the way that they've solved this problem. [42:31.690 --> 42:33.510] So, next up we have the ESP32 cam. [42:33.650 --> 42:37.430] These things have an integrated camera, but no USB port. [42:37.590 --> 42:39.130] So, good luck as a beginner connecting to it. [42:39.190 --> 42:40.090] It's a little confusing. [42:40.350 --> 42:44.230] But this thing for 489 supports facial recognition. [42:44.530 --> 42:45.130] Like, are you kidding? [42:45.130 --> 42:48.810] So you can literally make code that executes when it recognizes someone's face. [42:50.030 --> 42:54.650] So, first off, it's easy to create a spy camera or something that is hidden with this little device. [42:54.870 --> 42:56.070] It connects over Wi-Fi. [42:56.210 --> 42:58.350] It allows an interface for you to change the different resolution. [42:58.910 --> 43:02.110] It's easy to also stream to something that records it. [43:02.210 --> 43:06.090] So, like, if you wanted to stream this thing to OBS and record it, then it's super easy to do that. [43:07.170 --> 43:11.450] Next interesting thing is that the facial recognition on it is not particularly great. [43:11.590 --> 43:12.650] But it does work. [43:12.850 --> 43:16.530] So you can get it to run when a specific person's face is presented. [43:16.990 --> 43:21.550] But the thing I found is if you have a picture of that person, it works equally as well as the real thing. [43:21.670 --> 43:25.110] So we're obviously kind of limited here on what we can do with accuracy. [43:25.370 --> 43:29.230] But we can make it trigger on either an unknown person or a known person. [43:29.410 --> 43:38.150] And that presents all sorts of interesting opportunities to maybe hide this thing in a room and have some crazy nonsense go off when it recognizes a particular person for a prank or something like that. [43:38.570 --> 43:40.190] If you're looking for a good idea. [43:40.810 --> 43:41.290] Not on me, though. [43:42.730 --> 43:43.330] So, yes. [43:43.430 --> 43:48.090] The ability to run a program when a face is detected for less than $5 is something truly incredible. [43:48.310 --> 43:49.830] And I want you to kind of let that sink in. [43:49.990 --> 43:56.650] Like, we're really at the point where, for $5, you can make a microcontroller that recognizes someone's face and then does something in response to it. [43:57.830 --> 44:00.550] So next up, let's talk about the ESP32-S2. [44:00.690 --> 44:02.750] This is a recent microcontroller and one of my favorites. [44:02.750 --> 44:05.690] We're kind of approaching the top tier of the ones we're going to be talking about today. [44:05.890 --> 44:06.970] This supports Wi-Fi. [44:07.090 --> 44:09.690] It has native USB, which means it supports CircuitPython. [44:09.850 --> 44:15.870] And it comes in a module that is PIN compatible with the D1 Mini, the one that I was talking about loving so much earlier. [44:16.110 --> 44:18.390] This is completely compatible PIN-wise with it. [44:18.450 --> 44:21.290] So you can slap this in on designs that supported the D1 Mini. [44:21.550 --> 44:23.310] And boom, you have all these new capabilities. [44:23.650 --> 44:27.970] Now, the problem here is it cannot do Wi-Fi attacks like the D1 Mini because it's too new. [44:27.970 --> 44:34.250] Express if the developer has locked down the SDK and doesn't allow for these old-school packet injection attacks anymore. [44:34.570 --> 44:44.790] So while we're taking a step back in terms of the Wi-Fi chaos we can cause, we're taking a step forward in terms of beginners being able to work with this super easily and spin up their own prototypes or flash over a community project. [44:45.110 --> 44:50.030] So this is the microcontroller we chose for me and Alex's personal project, the Wi-Fi Nugget. [44:50.030 --> 44:54.170] And the reason we chose it is because it's just so simple for beginners to work with. [44:54.410 --> 45:00.230] It works well as a human interface device as well, attack device as well, because it supports both native USB and Wi-Fi. [45:00.390 --> 45:02.730] So that's what the Wi-Fi duck needed. [45:02.770 --> 45:06.210] But that was two microcontrollers stuck together onto a third PCB. [45:06.450 --> 45:09.310] This is a single module that can do both things in one. [45:09.470 --> 45:15.610] So that means that as a human interface device, kind of attack tool, this thing is perfect for that sort of application. [45:15.910 --> 45:17.410] And of course, it can also control the mouse. [45:17.410 --> 45:22.130] So you can do your mouse jiggler stuff and all the other auto clicker stuff that you would do with the lower quality microcontroller. [45:22.310 --> 45:24.470] But this thing does it all, which is really awesome. [45:24.550 --> 45:25.610] Well, except for the Wi-Fi attacks. [45:26.470 --> 45:35.130] All right, so our project, well, my project first, was creating a CircuitPython prototype for the ESP32-S2 that I called the Rubber Nugget. [45:35.270 --> 45:36.950] And this is something that I wrote in CircuitPython. [45:37.070 --> 45:43.450] It's a little bit of a trash fire, but it is able to inject four different ducky script payloads with the touch of a button as soon as it's plugged in. [45:43.550 --> 45:46.310] And it offers a very basic little Wi-Fi interface as well. [45:46.310 --> 46:03.270] So next, Alex took this and turned it into the USB Nugget, which is an Arduino program that has a much better control, a very nice Wi-Fi interface, supports 36 payloads, and is able to do a lot of things that my Python trash fire was not able to do. [46:03.430 --> 46:16.470] So this is basically kind of like the Wi-Fi duck, but it allows you to do everything like button operated, which I really like because this is the first Hack5 tool that actually has a screen and will show you the payload as it's running. [46:16.650 --> 46:26.350] So if it stops working at a certain point on this little microcontroller, we have slapped on a screen and we're able to actually tell like what part of the payload is going awry and not working, which is a nice little improvement. [46:27.670 --> 46:30.390] So I also created what I call the Dam Vulnerable Nugget. [46:30.510 --> 46:36.190] So this currently runs on this microcontroller, but again, all these projects will work on any ESP32 S2 board. [46:36.190 --> 46:40.170] You might just not have a screen, which in my case I think is kind of the reward here. [46:40.550 --> 46:48.770] So the Dam Vulnerable Nugget is a deliberately vulnerable Python web application that teaches people how to use OWASP's app or Burp Suite by letting them use this thing as a punching bag. [46:48.870 --> 46:54.290] So it's a real login that looks like your most precious of all accounts, your cat fanciers association account. [46:54.590 --> 46:56.930] What if an attacker was to target this? [46:57.070 --> 47:08.890] So if you flash this program over to the microcontroller, it will connect to your Wi-Fi and you can just attack this vulnerable web application and learn about authentication vulnerabilities and learn how to use OWASP's app or Burp Suite. [47:09.270 --> 47:13.150] So something I wanted to point out is you can do CTFs on this sort of thing. [47:13.270 --> 47:22.990] And on my version, because I have a screen available, I make these wet anime eyes flash on the screen as soon as you beat the CTF and successfully like get around the authentication, log into the cat fancy account. [47:23.390 --> 47:28.350] So fun little CTF you can run if you don't want to rely on something like... [47:28.350 --> 47:34.150] I really love Portswigger for their online labs, but right when I was doing a Hack 5 video on this, it went down for three days. [47:34.330 --> 47:39.670] So I literally wrote this because sometimes the online resources might not be available or you might be in an area where they're not available. [47:39.930 --> 47:49.110] So I wanted to have a microcontroller version of that available for anybody that wants to learn, you know, web application pen-testing, but maybe doesn't want to rely on a cloud version of it. [47:50.430 --> 47:51.910] So let's compare these two modules. [47:52.970 --> 47:55.450] A lot of people say, hey, your product's kind of expensive. [47:55.610 --> 47:56.610] I'm just going to go and get my own. [47:56.690 --> 47:58.470] I'm like, okay, okay, but you're going to kill some brain cells. [47:58.570 --> 47:59.370] And here's an example of how. [47:59.370 --> 48:04.010] Just looking at this, can anybody tell me which one of these modules is defective? [48:05.450 --> 48:06.970] I hope not because I couldn't. [48:07.070 --> 48:09.110] And I would be embarrassed if somebody else could instantly. [48:09.450 --> 48:13.650] So we bought 500 of these and this is disconnected. [48:13.890 --> 48:15.990] This little via right here is not connected to ground. [48:16.150 --> 48:17.730] And that causes it to not work. [48:17.870 --> 48:26.110] So there's lots of quirks when it comes to buying microcontrollers either in large quantities or from new suppliers or new designs that are being copied by other people. [48:26.110 --> 48:31.330] Because depending on who you're buying them from and a couple other fine details, you can end up with something that doesn't work. [48:31.670 --> 48:40.690] So part of the experience of making a product and then passing on the value of that is making sure that everything works, testing it over and over, and making sure that people get a consistent experience. [48:40.970 --> 48:46.210] The downside of working with microcontrollers is little mistakes like this can really cost you if you don't catch them. [48:46.330 --> 48:52.670] And in this case, this was a product on AliExpress that was sold to us and was never tested until it got all the way to us. [48:52.790 --> 48:55.830] So you can really make some mistakes if you're buying these in large quantities. [48:55.930 --> 49:01.130] And that's something that I have learned working with a large volume of these ESP32 S2 boards. [49:02.930 --> 49:04.310] Alright, so let's talk about limitations. [49:04.490 --> 49:04.830] No Bluetooth. [49:05.170 --> 49:06.830] It also can't do the Wi-Fi attack. [49:06.970 --> 49:07.970] So the SDK is too new. [49:08.090 --> 49:10.150] And then it does not have 5 GHz Wi-Fi. [49:10.290 --> 49:11.910] But there's hope for that. [49:13.950 --> 49:22.790] So now we're going to get to the boards that are currently either not very well documented, were just announced, or you can only get in very limited quantities. [49:23.030 --> 49:35.510] So these are boards that we haven't really worked with yet because they're brand spanking new, they're super cool, and there's a limited rollout, or there's just no modules that have that board on them that are useful for me and Alex to experiment with at this time. [49:35.610 --> 49:40.770] But because I love these microcontrollers and I try to stay kind of at the forefront of what's going on with them, I want to stay current with them. [49:40.810 --> 49:46.490] And if you want to stay on top of some really interesting microcontrollers that are coming out, then pay attention to this part. [49:47.330 --> 49:50.010] So first up we have the ESP32C3. [49:50.290 --> 49:54.510] This supports 2.4 GHz Wi-Fi, native USB, but... [49:54.510 --> 49:54.870] Oh, sorry. [49:55.430 --> 49:59.870] Supports Bluetooth 5 LE, but no native USB. [50:00.150 --> 50:02.250] So that means that you have to connect to this over serial. [50:02.410 --> 50:05.330] It does require a little bit of command line experience. [50:05.510 --> 50:09.230] It doesn't support CircuitPython, at least the way that I'm used to dealing with it. [50:09.890 --> 50:12.510] So while this module exists, you can buy it. [50:12.570 --> 50:14.150] It's $4 and it supports Bluetooth. [50:14.150 --> 50:16.890] I honestly can't think of many interesting things to do with it. [50:17.010 --> 50:17.830] Perhaps one of you can. [50:18.810 --> 50:25.970] So lots of people who maybe will eventually get into the Bluetooth stack and might be able to make a Bluetooth hacking tool might be excited about this, but that's not really my area. [50:26.090 --> 50:26.870] I focus on Wi-Fi. [50:27.050 --> 50:30.910] So if you're a Bluetooth person, then, you know, maybe this one's for you. [50:32.490 --> 50:37.710] ESP32-S3, this is brand new, supports 2.4 GHz, native USB, the kitchen sink. [50:37.870 --> 50:38.870] And you can also buy these now. [50:39.070 --> 50:40.250] So you can experiment with these. [50:40.410 --> 50:41.810] They're very awesome, very cool. [50:42.110 --> 50:47.990] And in general, you can expect them to be able to do a lot more than most of the other microcontrollers we talked about today. [50:48.070 --> 50:49.070] These are the flagship ones. [50:49.190 --> 50:50.090] They're really, really nice. [50:50.210 --> 50:51.510] And I'm super excited about these. [50:51.510 --> 50:54.330] Next up, the ESP32-C5. [50:54.610 --> 51:05.870] It's the first 5 GHz microcontroller supported or offered by Espressif, meaning all the people that have been wanting to chase Wi-Fi devices off onto their 5 GHz partner network now can go get them. [51:06.270 --> 51:15.510] So this will allow you to potentially do all sorts of interesting 5 GHz stuff, but it's almost guaranteed that the arbitrary packet injection will be locked down because this thing is brand new. [51:15.650 --> 51:20.390] So don't expect to be able to do arbitrary packet injection like deauthentication or something right off the bat. [51:21.070 --> 51:22.770] No native USB either. [51:23.010 --> 51:24.370] So you're going to be connecting over serial. [51:24.630 --> 51:28.130] This chip is probably going to be a little bit more for advanced people, at least in the beginning. [51:28.570 --> 51:30.030] But it does support Bluetooth LE. [51:30.210 --> 51:33.970] So maybe somebody can make an app for it and make it a little bit easier to connect via that. [51:34.070 --> 51:38.230] And I think Adafruit and CircuitPython have been working on some things like that using Bluetooth. [51:38.690 --> 51:42.350] So the ESP32-C6, there's so many and they suck at naming them. [51:42.970 --> 51:48.130] So this is 2.4 GHz that supports Wi-Fi 6 with backwards compatibility, supports Bluetooth. [51:48.130 --> 51:52.130] It's a RISC5 32-bit microprocessor and supports USB serial. [51:53.150 --> 51:55.390] So not native USB, you'll still be connecting over serial. [51:55.550 --> 52:01.630] But it's still a really impressive microcontroller if you're interested in Wi-Fi 6 and also a Bluetooth interface. [52:02.690 --> 52:04.030] All right, so let's talk about some takeaways. [52:04.290 --> 52:06.510] So I learned all this in about three years. [52:07.450 --> 52:14.150] Microcontrollers are much more fun to use, abuse, and destroy than a Raspberry Pi that's going to cost you now $300 to get a new one. [52:15.110 --> 52:18.210] And you really do not need to be a computer scientist in order to get started with this stuff. [52:18.290 --> 52:24.130] I started without even knowing how to program and I had to go back to school because it was frustrating me and I wanted to write my own prototypes. [52:24.330 --> 52:28.730] But really, I was able to use a lot of these community projects with absolutely no experience doing this. [52:28.730 --> 52:35.490] So if you're intrigued by this, I really encourage you to go on Amazon, go on AliExpress, grab a microcontroller, and try this out for yourself. [52:36.230 --> 52:38.710] Meaningful attacks are absolutely within your reach for $5. [52:39.030 --> 52:45.490] And there is totally a place for every level of skill in hardware hacking when it comes to applying this stuff to security topics. [52:45.630 --> 52:50.030] So if you're interested in security and you're interested in microcontrollers, now is absolutely the time to start. [52:50.590 --> 52:52.190] And finally, thank you for coming. [52:52.410 --> 52:57.770] If you want to support our team, you can always pick up one of our products via USB Nugget on our website. [52:57.770 --> 53:08.490] And if you want to see more of my content, you can check out hack.gay, you can follow me on Twitter, and you can also check out the live stream on Hack5 every week where I do a live Q&A. [53:08.630 --> 53:09.510] Thank you very much for coming.