Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

So with this data diode I can install an application to use the PC speaker as an output device, and then record the sound for exfil? Nice.


exfil ideas are always interesting to think about! The PC speaker idea may work, assuming:

(1) protected computer has a built-in PC speaker (for example, the computer I am typing this message on does not)

(2) There is an insecure PC with sound card and a microphone (or at least headphones which can be used as microphone)

(3) Secure and insecure PCs are close to each other, as opposed to being in different rooms

(4) It's quiet enough, and no one will notice the sounds (because PC speakers are crappy and can't do infra/ultra sound)

Likelihood of this succeeding depends on a lot of factors, the biggest of them being "how good is the security team". Presumably if they are buying data diodes, they at least have some knowledge?

Other exfil ideas I've read were to emit sounds using HDD, emit sounds by changing fan speed, blink code messages on lights ("sleep mode" or caps/num lock), show special patterns on monitors to transmit RF, add hidden dots to printed pages, abuse wireless keyboard or mice.. There are many idea and most of them are pretty impractical outside of very limited circumstances.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: