Neopwn, the World's First Pentesting Mobile Phone
thefanboy writes "What do you get when you cross BackTrack Linux apps with a mobile phone? This is the first ever publicly available mobile phone running a full custom Linux network auditing distribution, and it runs it surprisingly well. One can literally go from phone to pwn in 2 seconds. Based off of the Openmoko Neo Freerunner, many steps have been taken to compensate for the lack of a QWERTY keyboard with automation scripts, dialogs, and a point-and-pwn menu. It runs applications such as Metasploit and the Aircrack suite quite well, especially given the fact that it supports a wide array of USB WLAN cards."
'pwn' drives me nuts. In my eyes the use of it seriously undermines any project and gives the impression that it is presided over by annoying 13 years olds which, in turn, pretty much makes me dismiss it.
But can it run -- oh wait. Nevermind. Well then, imagine a Beowulf cluster of these suckers!
with a protesting mobile phone?
What?
Now, you might disagree with me, but I think this officially means that the NSA and other government agencies (I'm looking at you Alaska) need to work extra hard to ensure their networks are locked down good.
Point and click becomes point and own? Maybe not that easy, but All your AP are belong to us is going to happen soon enough. One thing that Linux and F/OSS definitely does do; puts real software and OS in the hands of those that the NSA would rather not need to worry about.
I see a rather large police state like effort coming.
Support NYCountryLawyer RIAA vs People
anyone else find the summary poorly worded and confusing?
Has had any luck downloading any of the source for this? Not seeing any GPL software links on their site, might have to shoot them an e-mail...
Good god, I generally consider myself on top of technology but this summary seems to be written in another language, and not just 1337sp33k....
Will the reaction to such devices be to strengthen the security of our cellular networks, or to simply outlaw such devices?
Hmmmm, ponder, ponder, ponder.
My money is on the latter.
The anti-iPhone: the Linux telephone that operates entirely from the command line! The Ultimate One-Dimensional Desktop! What can't you do with a bash prompt?
(The v2 version will, of course, run Emacs and be programmed entirely in eLisp written on the fly.)
http://rocknerd.co.uk
Jamie Zawinski.
http://rocknerd.co.uk
"The server is temporarily unable to service your request due to maintenance downtime or capacity problems. Please try again later."
Evidently they can't save their own site from being pwned.
the source code..
Can't see a link for it. Unless they are waiting until they start shipping to put it up..
or maybe its for customers only.
Wow, not even a single post and already a 503...
apparently you haven't seen the recipe for "stink fish" yet. seriously. no joke. and yes, that's the real name (in english) of the dish.
bury a freshly caught fish in the ground for a few days. dig it up. eat it.
Just get an eeeeeepc or something similar - it's cheaper and you can do real 'pwning' with that (has keyboard and screensize > 1'' or so).
in between a ton of 503 http replies (slashdotting in progress) i have managed to browse all those pages (F5 FTW!) and i have NOT seen a link to download the software itself or even the source code and not even a promise of future availability.
Since the Linux kernel is licensed under the GPL and they seem to provide a binary-only kernel for their customers (no source code that i saw) it seems we have here yet another clear cut GPL violation case.
On their page at http://www.neopwn.com/software.php i know that the following have GPL licenses and they must also provide the source code for but they don't do it:
Debian OS (Lenny / ARMEL) - packages are GPL mostly
Custom Kernel - (Linux 2.6.24) - GPL definitely
Open Source Penetration Testing Application Ports - again, mostly GPL stuff
Also on their site at http://www.neopwn.com/store.php the cheapest option is $80... with a SD card and dvd thrown in but again no source code download available...
so, what gives? Do they charge for source code too ?
Admittedly, the site is still under construction and the suite has not yet been formally released, so they still have time to correct the issues.
~~~~
just my 2 cents
root@127.0.0.1
all that effort put into getting a story onto slashdot, and it doesnt even tell you what it actually does.
portfolio
OMG! This ain't no Poniez. Is the full-on Backtrack CD (just google backtrack for the link). Most users know it on either Live-CD or USB-stick boot-up form. I don't know of any manufacturers until now, that offer it pre-installed, tweaked, and (semi?) supported.
You think its news when Dell pre-loads Ubuntu on a laptop? In certain circles, this is *much* bigger news. It makes auditing one's own network a much more routine task, because this is a handy little wifi tool! Even *with* a live CD or USB stick, Good Luck acquiring or tweaking the wifi hardware to run the Backtrack distro well. This is a really compelling tool for people responsible for securing wifi networks. And its a PHONE too; that just happens to run Debian/Gnome. I want one BAD. All it needs is a bluetooth folding keyboard and its Golden; and I'm certain that's do-able. Oh, a thumb-scanner would be cool too. Schweeet!
lol.
My time is very valuable, but a large part of that is directly because of all the time I have invested in Linux.
Linux software development and administration is big business. Linux is not only free, it actually pays you!
Test all you want. No pen can penetrate my 3M pocket protector.
I'll try it out the next time I go "penetration testing" in "places where being promiscuous and undetected is essential."
It's OK for "Serious" people with the maturity to not abuse any holes they find. But putting a point-and-click level device in the hands of irresponsible people is in itself irresponsible.
Engineering is the art of compromise.
You forget, emacs once (jokingly) stood for "Eight Megs and Constantly Swapping." You know how much memory emacs uses today? Eight megs. Now find an app that does everything that emacs can in less than tens times that much memory.
Debian runs very well on my openmoko and its not that hard to use the commandline with rastermans keyboard. The screen has excellent resolution so reading the terminal works really well.
This device makes things dandy for people who want an easy way to test their network. Scriptkiddies will love them to but thats just fine. The script kids are the ones who forces better security trough. The alternative is to be hacked all day by corps and govts and never nowing about it.
HTTP/1.1 400
It would be funny...if it was 1991.
This will be the single biggest justification that Apple and other locked down mobile device vendors will use against projects like OpenMoko. I mean, do they really have to distribute metasploit with it?
I understand the thrill of walking around with conveniant access to script kiddie^W^Wpenetration testing tools wherever you go and are, really, I do. Business treats you bad? Take over^W^Wpwn their network. Girlfriend breaks up with you? Upload a picture of your penis as her background. Okay, so let me be honest, I never think like this. But that's all I can think of when I see these kinds of projects. The old geek fantasy of finally being able to get back at the jock (or whoever) because he has computer skills!
But, in the end, it's all fun and games until someone gets sued.
You sure do have a thing for pubescent kids.
or packet injection with the built-in wifi module:
"Note that the current firmware limitations of the internal wireless does not allow for monitor mode nor packet injection. An external USB WLAN is required for this type of operation."
I like how an external adapter can be an option, but as of now it's a requirement. This sort of ruins the image of this being "a powerful discreet network auditing tool for the penetration tester", atleast for me.
(They do mention that it's the current firmware limiting this, but there's nothing about if and when they'll "fix" this)
This looks like the quickest way to get open source phones banned off every network that you can imagine. So it looks like a big fat juicy own goal, to me.
I'm old enough to remember when discussions on Slashdot were well informed.
Neopwn ... Pentesting ... BackTrack ... pwn ... Openmoko Neo Freerunner ... Metasploit ... Aircrack
Can anyone point me in the direction of an article-to-English dictionary?
the article's title is so misleading. immunity's silica, although not cheap has been out for years. http://www.immunityinc.com/products-silica.shtml