Slashdot Mirror


3D Hacking Environment Links Kinect, Blender, and Metasploit

baxpace writes with a link describing a way to test your own security systems for vulnerabilities using Kinect-interpreted natural gestures in tandem with the Metasploit Framework and the Blender game engine, writing: "The idea is to hack into your own systems while in a 3D, first person shooter style environment that interfaces with the Kinect sensor. The game engine was built using Blender and looks to be one of the most pleasing ways of uncovering your own systems' architectural/networking vulnerabilities."

93 comments

  1. The Gibson by Anonymous Coward · · Score: 2, Funny

    We can finally hack it!

    1. Re:The Gibson by Anonymous Coward · · Score: 0

      Hack the planet! Hack the Planet!

    2. Re:The Gibson by Anonymous Coward · · Score: 0

      They're trashing our rights! Trashing them!

    3. Re:The Gibson by Anonymous Coward · · Score: 2, Funny

      This is UNIX! I know this!

    4. Re:The Gibson by squidflakes · · Score: 1

      Is that a twenty eight point eight kay bee pee ess modem?

    5. Re:The Gibson by Stupendoussteve · · Score: 1

      Except fsn was real file manager for IRIX. You can get fsv to recreate your own favorite Jurassic Park scene from the comfort and safety of your own home.

    6. Re:The Gibson by justforgetme · · Score: 1

      No, it's an active matrix LCD screen! A million psychedelic colours!

      --
      -- no sig today
  2. Swordfish by Ramin_HAL9001 · · Score: 4, Insightful

    I hate Hollywood style hacking with all that fancy 3D graphics that flash around on the computer screen while the "programmer" sits in front of it typing randomly on the keyboard saying, things like "512 bit encryption", "almost, almost", "come on!", "don't do this to me", "got it!".

    So now we have an actual hacking application with actual 3D graphics that actually mean something. Too bad it doesn't look as cool as in the movies.

    1. Re:Swordfish by Ramin_HAL9001 · · Score: 1

      Actually, now that I think about it, it looks more like Johny Quest.

    2. Re:Swordfish by pinkstuff · · Score: 2

      This is what me and my friends refer to as "HOS", Hollywood Operating System

    3. Re:Swordfish by Anonymous Coward · · Score: 0

      Anybody who knows something about a subject dislikes how it's generally depicted in films.

    4. Re:Swordfish by EdZ · · Score: 1

      As opposed to the other HOS , which results in rampaging construction machines due to malicious backdoor code.

    5. Re:Swordfish by Speare · · Score: 1

      How about Global Thermonuclear War? --David

      This is Unix! I know this! --Lex

      All I see now are... Blonde, Brunette, Redhead. --Cypher

      --
      [ .sig file not found ]
    6. Re:Swordfish by LordLimecat · · Score: 1

      This is Unix! I know this! --Lex

      If I remember correctly, it actually WAS Unix.

    7. Re:Swordfish by robthebloke · · Score: 1

      Hmmm..... Fancy 3D graphics? Unable to describe "programmers" without the use of quotes. Frequent uses of phrases such as "Come on!" "FFS" "Don't do this to me!!".

      You do realise you are describing Window Aero? :p

    8. Re:Swordfish by robthebloke · · Score: 1

      Irix running on an SGi machine (ILM would have had hundreds of the things lying around....)

    9. Re:Swordfish by Fatch+Racall · · Score: 2

      I distinctly remember seeing a c:\ prompt(DOS, usually), a Mac OS(trash can, quicktime, etc), Lex said it was Unix, and I remember them mentioning that they were 'supercomputers' which suggests CrayOS. In other words, the most retarded system ever created.

      --
      #include <disclaimer.h>
    10. Re:Swordfish by Opportunist · · Score: 1

      Userfriendly called it Movie-OS a decade ago.

      --
      We used to have a Bill of Rights. Now, with the rights gone, all we have left is the bill.
    11. Re:Swordfish by Opportunist · · Score: 1

      You just can't top this in terms of utter stupidity. Yes, it's German, but the idiocy should need no translation.

      But then, it's from an action show that seems to build its cars out of C4 explosives, so cut them some slack. :)

      --
      We used to have a Bill of Rights. Now, with the rights gone, all we have left is the bill.
    12. Re:Swordfish by DaVince21 · · Score: 1

      How about creating a GUI in Visual Basic to track down someone's IP address?

      --
      I am not devoid of humor.
  3. And you really need all this by aglider · · Score: 3, Insightful

    in order to audit your own systems?
    Cool, but rather complex for an audit!

    --
    Sent as ripples into the electromagnetic field. No single photon has been harmed in the process.
    1. Re:And you really need all this by DarkOx · · Score: 4, Funny

      Manager: What do you think you think you're doing you can't play video games at the office, at least not during business hours!

      Jr. Network Admin: Sir I am conducting a Pen test of against our dev environment.

      Manager: Yea I think my kid likes one too, its Japanese right?

      Network Admin: Sir I am its not a game.

      Manager: Look I know you guys take you aviators seriously, but try to do it on your own time ok.

      Jr Network Admin: Sir I think you mean avatar and like I said this is actually not a game its a front end for metasploit.

      Sr Network Admin: He cut the crap Jr that interface is not scriptable at all and how many times do I have to tell you if you think you're going to do it twice, script it once! It leaves more time for slashdot.

      Manager: What is slashdot?

      Sr Network Admin: Its a um.. hmm.. I guess you'd call it a computer based continuing education tool.

      Manager: Really, that sounds great, I want the whole department spending a couple hours a day on this slashdot.

      --
      Repeal the 17th Amendment TODAY! Also Please Read http://www.gnu.org/philosophy/right-to-read.html
    2. Re:And you really need all this by Anonymous Coward · · Score: 1

      Continuing education? I weep for the industry.

    3. Re:And you really need all this by Opportunist · · Score: 1

      I informed my manager that /. is a communication tool with various other experts in the business and that it is very beneficial to find all the security concerns quickly, so I have to spend a lot of time there.

      I think I mentioned before what's the key benefit of being in IT security is, didn't I? People know even less about ITSEC than about the rest of IT, so bullshitting them is even easier.

      --
      We used to have a Bill of Rights. Now, with the rights gone, all we have left is the bill.
    4. Re:And you really need all this by orgelspieler · · Score: 1

      I tell my boss it's where I find out about changes in patent law and important pending technology litigation.

  4. Command line for me by king_grumpy · · Score: 2

    Call me old school, but I'd prefer a command line. Can't see this taking off for security professionals.

    1. Re:Command line for me by Anonymous Coward · · Score: 0

      Call me old school, but I'd prefer a command line. Can't see this taking off for security professionals.

      That's it! I'm calling you old school, my liege.

    2. Re:Command line for me by Ramin_HAL9001 · · Score: 1

      I'm with you.
      With Compiz as your window manager, and an ordinary VT100 terminal emulator, or perhaps Emacs-GTK with a black background, you can make your computer look like a Hollywood movie hacker's computer, with it actually BEING a hacker's computer that can actually hack things. It's not the 3D that matters, it is how quick and efficient you are at searching through lots of code and modifying it. If the 3D isn't helping you be more efficient at that, get rid of it.

    3. Re:Command line for me by king_grumpy · · Score: 1

      Yeah doesn't Hugh Jackman have something like kinectasploit on a PDP-10 somewhere :)

    4. Re:Command line for me by Anonymous Coward · · Score: 0

      I'm with you.
      With Compiz as your window manage

      So no, you're not "with him".

    5. Re:Command line for me by Anonymous Coward · · Score: 0

      Old school? what happened did you loose your captain crunch whistle? get with the times before the times get you... Personally it might be enjoyable to see what the hip thrust movement does. :P

    6. Re:Command line for me by Anonymous Coward · · Score: 0

      Motherfucker, I got an Arduno and a BackTrack Live CD in a box of Cap'n Crunch. It's still as hackalicious as ever.

    7. Re:Command line for me by robthebloke · · Score: 1

      Call me old fashioned, but I'd prefer to see rows and rows and rows of blinky lights. No practical reason for this. I just like blinky lights.

    8. Re:Command line for me by Opportunist · · Score: 1

      Get offa my lawn, whippersnapper! Only a young'un could poop on that whistle, it saved me thousands of dollars worth of phone bills back in the ol' days!

      --
      We used to have a Bill of Rights. Now, with the rights gone, all we have left is the bill.
    9. Re:Command line for me by _0xd0ad · · Score: 1

      They're called blinkenlights.

    10. Re:Command line for me by eriqk · · Score: 1

      I'm with you. With Compiz as your window manager, and an ordinary VT100 terminal emulator, or perhaps Emacs-GTK with a black background, you can make your computer look like a Hollywood movie hacker's computer, with it actually BEING a hacker's computer that can actually hack things.

      Hollywood's way ahead of you.

    11. Re:Command line for me by DaVince21 · · Score: 1

      But now you can imitate even more Hollywood movies!

      --
      I am not devoid of humor.
  5. Waste of time? by Errol+backfiring · · Score: 1

    Gee, if you have so much time to waste, can you lend me some?

    --
    Nae king! Nae laird! Nae yurrupiean pressedent! We willna be fooled again!
  6. The hacking movies of the 90s were right! by rebelwarlock · · Score: 1

    Damn, now I have to buy roller skates and glow sticks. Penetration testing used to be so simple!

    1. Re:The hacking movies of the 90s were right! by SlashV · · Score: 1

      But hey, if you're lucky, you'll get to kiss Angelina! That should be worth your trouble.

    2. Re:The hacking movies of the 90s were right! by Anonymous Coward · · Score: 0

      Make sure you have a nice glass of wine as well while you're hacking away.

    3. Re:The hacking movies of the 90s were right! by Opportunist · · Score: 1

      Nah, that part of the movie is so unrealistic...

      --
      We used to have a Bill of Rights. Now, with the rights gone, all we have left is the bill.
  7. Typing speed is everything! by StoneyMahoney · · Score: 1

    Prior art: Wargames, hacker types on keyboard while saying what he's typing for the benefit of the audience who aren't looking at the screen.

    "What... {bashbashbashbashbashbashbashbashbash} ...is... {bashbashbashbashbashbashbashbashbashbashbashbash} ...the primary... {bashbashbashbashbashbashbashbashbashbashbashbashbashbashbashbashbashbash} ...goal?"

    Hollywood couldn't even do a chatbot session right back in the 80's!

  8. BFG by abelb · · Score: 0

    Merge it with the Doom source and play online with your friends and strangers!

    1. Re:BFG by olden · · Score: 2

      Yes! That's exactly what this reminds me of: psDooM ! http://psdoom.sourceforge.net/
      Why merely check for vulnerabilities when you can obliterate them, along with the rest of the system you're "auditing" :-)

    2. Re:BFG by Kompressor · · Score: 1

      Kill 'em all and let root sort 'em out!

      --
      kmem russian roulette: Aquillar> dd if=/dev/urandom of=/dev/kmem bs=1 count=1 seek=$RANDOM
  9. But can it hack... by Anonymous Coward · · Score: 0

    The Gibson?

  10. I hacked the Gibson! by Anonymous Coward · · Score: 0

    But the the Cisco fragged me! Aaaaaarrgh!

  11. I know what OS they are using at least by brunes69 · · Score: 1
  12. All these times... by BenevolentP · · Score: 2

    All these times you tried to explain people that what they see in the movies is bullshit when it comes to "hacking". And now, that SOME slowly get it - bam - they will inevitably see this and think that you have no idea what you're talking about when it comes to computers.

  13. Re:All these times... by Anonymous Coward · · Score: 0

    Lesson learned: quit trying to explain computer shit to lay people. They don't really want to know. And they will never really understand.

  14. Pleasing? WTF? by Qbertino · · Score: 1

    How on earth is this 'a pleasing way of uncovering system architecture'?
    3D visuals? OK, I get that. However, I'd leave out crappy wall textures and 3rd grade FPS props and stick to abstract platonic and geoedic shapes with distinct colors, connected with various forms of lines and indexed with a cool looking 3D-enviroment-friendly font. ... The pointy balls aside, I'd basically do pretty much everything exactly opposite of how they did the 3D. ... This guy has it pretty much nailed in terms of 3D enviroment UI and data ... since, like, 8 years ago or so.

    The actual work I'd have scripts do, while I go and flirt with the helpdesk cutie over a latte. ... As, errm, pretty much everybody does it today already, I might add.

    What system analyser in his right mind is going to wave his hands around and shake his hips to lauch scanners and change views?? My fingers can do that way faster. And much cheaper. ... And the technology is there allready.

    Bottom line: Nothing new. Not so spectacular realisation. Way better solutions out there allready. No cookie!

    My 2 cents.

    --
    We suffer more in our imagination than in reality. - Seneca
    1. Re:Pleasing? WTF? by Anonymous Coward · · Score: 0

      What system analyser in his right mind is going to wave his hands around and shake his hips to lauch scanners and change views??

      Mr The Plague already did this.

    2. Re:Pleasing? WTF? by Sinthet · · Score: 2

      I'm pretty sure this hack was done "just because" and "for fun" rather than a serious attempt at a front-end for metasploit.

    3. Re:Pleasing? WTF? by spaceman375 · · Score: 1

      While you visit a friend, give his kids a bootable USB stick and let THEM play the game. When they "win", show him what they just did.

      --
      On the one hand you take life too seriously, and on the other, you do not take playful existence seriously enough. Seth
  15. movie by goarilla · · Score: 1

    Reminds me a little bit of the movie nirvana, with christopher lambert of highlander fame.

  16. Works for me by Lieutenant_Dan · · Score: 1

    I found a trojan of some sorts in the NT kernel; someone left the message "Created by Warren Robinett". Weird, only happens when I hit this invisible spot with Metasploit in the Kinect/Blender interface. I wonder if he's still employed by Microsoft.

    --
    Wearing pants should always be optional.
  17. Zumba? by polle404 · · Score: 1

    "3D Hacking Environment Links Kinect, Blender, and Metasploit"....and Zumba!

    So now I can "hack" like a scriptkiddie, while playing 'Dance Dance Revolution'?
    come to think of it, my 7 Year old goddaughter would probably be a better "hacker" than me, if it comes to this.

    The positive sideeffect is that the scriptkiddies soon will have the physique to run from the cops/feds.
    "news at eleven: Hackers fitter than jocks!" (still can't catch a fuusball, though)

    --

    ~men are from earth. women are from earth. deal with it.~
  18. Re:All these times... by Anonymous Coward · · Score: 2, Insightful

    I smell bullshit. No real-life colleague could make the linguistic jump from taxonomic to taxonomy unaided.

  19. Scary! by Ian-K · · Score: 1

    Now that's scary.

    Hacking is going to be waaaaaay more fun with this thing... And lots of people are now going to have a go at it just for the fun of it.

    Hmmm

    --
    I'm no longer fed up with MS Windows: I go rid of them :)
  20. povray by flok · · Score: 1

    Slightly related: it would be nice if someone wrote a program that lets you create 3d models for e.g. blender or povray using a kinect. I wrote the beginning for that ( http://www.vanheusden.com/kinect2povray/ ) but don't have the time to extend it so that it combines multiple angles.

    --

    www.vanheusden.com - home of Multitail, HTTPing, CoffeeSaint, EntropyBroker, rsstail, bsod, listener, nagcon, nagi
    1. Re:povray by Khyber · · Score: 1

      How about creating a gesture-based 3d modeling program? Act like you're sculpting out stuff in a 3d space and instant model!

      --
      Still waiting on Serviscope_minor to wake up to fucking reality and realize that Jessica Price isn't going to fuck him.
    2. Re:povray by Anonymous Coward · · Score: 0

      How about creating a gesture-based 3d modeling program? Act like you're sculpting out stuff in a 3d space and instant model!

      The latest post addresses this - http://goo.gl/uzOmn

    3. Re:povray by Khyber · · Score: 1

      That's not even remotely close to what I'm talking about.

      I'm talking about starting with a blank space, you make a movement or gesture, a sphere appears. You start "grabbing" the sphere and start creating a model. There is nothing to interact with besides what you see on screen. You 'rotate' the sphere, it rotates on screen.

      --
      Still waiting on Serviscope_minor to wake up to fucking reality and realize that Jessica Price isn't going to fuck him.
  21. Doom by sgt+scrub · · Score: 1

    wasn't there a network management interface or something like that based on doom? supposedly you went around shooting stuff to make changes or something. i wish i could remember its name.

    --
    Having to work for a living is the root of all evil.
    1. Re:Doom by sgt+scrub · · Score: 1

      That's it! You shoot processes to kill them. Awesome.

      --
      Having to work for a living is the root of all evil.
  22. Eduard by haggus71 · · Score: 1

    Am I the only one picturing Ed on the Bebop making little fish to munch through someone's firewall?

    1. Re:Eduard by ginbot462 · · Score: 1

      You mean it's not Cowboy BeBop at his computer?

      --
      Atlas Shrugged : Thematic Story :: Battlefield Earth : Organized Religion
  23. Re:All these times... by Anonymous Coward · · Score: 1

    Perhaps the colleague was an English major?

  24. parallels in real life? by Thu+Anon+Coward · · Score: 1

    without reading any further, almost sounds like what they used in that movie 'Disclosure' with Michael Douglas; wearing the 3-D glasses and whatnot. or somewhat similar to 'Minority Report'

    --



    I'm good with numbers - .45, 7.62, 9.....
  25. What, no Johnny Mnemonic references yet? by JSC · · Score: 1

    Seriously? I mean, 3D VR hacking attempt, reaching out with VR Gloves to manipulate/hack interface, face palm into VR Gloves, etc.

    And no Pr0n jokes about 3D VR Penetration testing?

    Who are you and what have you done with my SlashDot?

    --
    Time's fun when you're having flies. - Kermit the Frog
    1. Re:What, no Johnny Mnemonic references yet? by WWWWolf · · Score: 1

      Seriously? I mean, 3D VR hacking attempt, reaching out with VR Gloves to manipulate/hack interface, face palm into VR Gloves, etc.

      "Sogo 7 Data Gloves, a GPL stealth module, one Burdine intelligent translator... Thompson iPhone."

      Well, folks didn't foresee the future in 1995. Blender is GPL, but Metasploit is BSD. And iPhones come from Apple. (And why Johnny Mnemonic would use iPhone to begin with? All that jailbreaking! Bleh.)

    2. Re:What, no Johnny Mnemonic references yet? by BetaDays · · Score: 1

      I'm with you and that there is no VR5 references yet with it's 10 levels of vr. http://en.wikipedia.org/wiki/VR.5

      --
      Paul: Father... father, the sleeper has awakened! - Dune
  26. LAWNMOWER MAN by Anonymous Coward · · Score: 0

    Let's not cross The Matrix with Sling Blade ever EVER again.

  27. Re:All these times... by T.E.D. · · Score: 1

    Good. That'll keep them from asking me to fix theirs.

  28. Garbage File by MoldySpore · · Score: 1

    Joey. I need you to drop your viruses, go after the worm. You're the closest. It's root slash period workspace slash period garbage period.

    --

    "I hope you know how very lucky you are to know me, because I am so incredibly incredible."

  29. Shatner Was Right by Anonymous Coward · · Score: 0

    Shatner predicted this next well have drugs on microchip, ah Tekwar

  30. Getting closer every day by squidflakes · · Score: 1

    Corporations having as much power as national governments, able to hire their own police forces.

    Implants that are making steps to improving biological abilities.

    3D visual hacking.

    Shadowrun seems closer and closer every day.

    1. Re:Getting closer every day by Opportunist · · Score: 1

      Come to think of it, the guy on the subway yesterday sure looked like a troll...

      --
      We used to have a Bill of Rights. Now, with the rights gone, all we have left is the bill.
  31. Uhhh, this was already invented in 1994... by bdabautcb · · Score: 0

    Jurassic Park, anyone? THE DOORLOCKS TESS!!!... I know this, its a Unix system!

    --
    Koalas. They're telepathic. Plus, they control the weather. -Margaret
    1. Re:Uhhh, this was already invented in 1994... by _0xd0ad · · Score: 1
  32. Add some EEG... by wjousts · · Score: 1

    ...and we'll finally have Neuromancer!

  33. Re:All these times... by tacokill · · Score: 1

    Good! Maybe they'll quit bugging me for help and asking stupid questions about "apps". For them to think I know nothing about computers is not the world's worst outcome....

  34. Re:I know what OS they are using at least by flimflammer · · Score: 1

    At least the software she was using was real.

  35. Sorry, I'll stick with CLI by Opportunist · · Score: 1

    In all seriousness, "3D input", i.e. flailing limbs and gyrating in front of your computer, is a cool toy, a nice pastime and maybe even some kind of workout for kids who wouldn't think about actually going outside and move a limb, but for hacking, they just fail. Why? Because we are still far from the ability to never misunderstand a gesture. Hell, we, as humans, trained and raised as creatures to understand each other, sometimes misjudge and misunderstand each other. The very last thing I need when dealing with a trigger-happy firewall is my hacking tool mistake a -T0 for a -T5 when assembling the options for nmap. In some cases you only have one attempt, and that should be a good one. The very last thing I need then is that my tool misunderstands me.

    It's also usually not faster than a CLI. Yes, most people probably gesture better and faster than they type. But, seriously, by the time you are good enough as a "hacker" to actually do something sensible with your skills, like conducting an audit, you CAN type faster than you can gesture. Your fingers are most likely the fastest part of your body (especially if they're the only thing that got any kind of workout for a few years ... *sigh*).

    The only real advantage body movement had over manual input is that you can use your reflexes to your advantage. But then, they have to be very precise, very well timed and you must not flinch at the wrong moments, something that's very hard to do with reflexes because, being reflexes, they are not exactly under your command.

    --
    We used to have a Bill of Rights. Now, with the rights gone, all we have left is the bill.
  36. Done with the Doom engine 12+ years ago by imgunby · · Score: 1

    I remember seeing this and thinking "YES!!!!!" http://www.cs.unm.edu/~dlchao/flake/doom/

  37. Speaking as a security consultant... by stixn · · Score: 1

    I'll use that lame 3D UI for pen testing right after they pry Backtrack 5 out of my cold, dead hands. Try and make sqlmap a better tool by giving it a flashy ui. Go ahead, make my day.

    But hey, the script kiddies will love it.

  38. Re:All these times... by Anonymous Coward · · Score: 0

    Once upon a time, there was a master of computers.
    And there was a herd of idiots.
    The idiots, despite knowing shit, judged the master.
    And the master, despite knowing they know shit, cared about their judgment.
    The moral of the story: Grow some balls and a spine, say NEIN, and you will be mighty fine! ^^

  39. So Hackers (the movie) wasn't far off after all by xyourfacekillerx · · Score: 1

    We all used to laugh about the ridiculous OS interface to the file system (flying through a 3D world of towers and things), the one they used to conduct their hacks.

    And now it looks like it was not far-fetched after all. Why is our future being so... regressive ... ?

  40. Re:All these times... by justforgetme · · Score: 1

    or a taxonomy major :-)

    --
    -- no sig today