Two Wheeled Wi-Fi Sniffing Robot
paulnuyu writes "ZDNet/MSN has an article about a robot that detects Wi-Fi vulnerabilities and intrusions. The two wheeled robot made by the Shmoo Group cruised around the DefCon convention in Vegas last Sunday, picking up telnet and POP passwords. Though still a prototype, the shipping version is projected to have autonomous steering capabilities."
There's this one guy in Akron who's building a robot. He has GPS on it. All it does is roll around, it's not exactly that great of a robot.
The thing is, I ask him all the time, "What does your robot do jalics?"
jalics: Right now the first thing it will just be a rover.
jalics: It'll have a webcam, gps, wifi.
jalics: So I can control it remotely.
jalics: To get accurate feedback on wheel position will be harder, but thats what I'm aiming for.
Could someone explain just why this is useful? Sounds like a terrible waste of robotics to me.
Hmm: "script bots?" It really doesn't have the same ring though. When I hear 'script kiddie,' my blood pressure starts going up, but 'script bot...' Nah...
Not to mention the fact that you can reach 1e6 times more random systems from location X on AOL than what you from a corporate wifi network.
If anyone is still using plaintext to send passwords over their lan they are insane.
Well, a lot of people don't have any choice. Our cable ISP here, for example, provided the usual email accounts, and for a lot of customers, that is their only email. If you use it, you have no choice other than POP, and I haven't seen anything in several mailers that talks about encrypting the passwords. Our ISP doesn't actually block port 25, so you could run your own mailer. This isn't feasible for most customers, though, for several reasons. One is the dynamic IP addresses and insane hostnames. I've fixed that by using one of the many independent registration services, but to most customers, that would be utterly baffling and unusable. Another problem is that running your own email server is in fact in violation of the TOS in the ISP's contract, and they can legally block your port(s) or kick you off entirely at any time, without warning or recourse.
So for most non-geek customers, unencrypted POP passwords are the only option. There's probably no way they could even learn from the ISP that there's a problem; they certainly wouldn't get (or understand) any advice on how to fix it.
(Myself, I use an account at a school. It has been stable and usable for over 15 years now, unlike commercial email accounts that force you to change your address every 6 months whenever there's a merger, buyout, or corporate renaming. And I can use a plain-text mail reader, eliminating all problems with virii, worms and the like. But I'm not sure I'd recommend this to the typical non-geek.)
Those who do study history are doomed to stand helplessly by while everyone else repeats it.
I know Verisign and others offer services like this often at a high rate but perhaps the initiative can be funded by governments participating in some W3 standard to secure transactions.
MoFscker
What about a robot that can sniff out RFID tags?
Oh, actually I think that was discussed already...
I saw this robot in action Tuesday evening at the opening of the Dorkbot show at COCA here in Seattle. Only it wasn't running around looking for open access points, it was out in front of the DJ stage *dancing*. Someone had brought their daughter, who looked to be about four, and for a few minutes the kid and the wheely-bot were dancing. Quite a scene, though I didn't have my camera handy.
-Mars