Mr. Radar: Layer 1 Recon

Presented at ShmooCon 2023, Jan. 21, 2023, 10 a.m. (60 minutes).

When performing a cyber enabling, physical penetration test, open network ports spread throughout a target building can provide a great opportunity for exploitation. However, it’s not often apparent if those ports are connected to a network device on the other end. Determining if a port can be leveraged may take time you do not have. Also, the method of determination may set off port security on the network device.

Mr. Radar is a small, microcontroller driven circuit that determines at the physical layer whether or not a network port is attached to a twisted pair, ethernet based networking device. It can also determine other characteristics such as if the device is 10/100 Mbit/s based, whether a network device is PoE capable, and if the PoE provided is Mode A or Mode B in nature. All of this is determined without setting off port security.


Presenters:

  • Jason Baird
    Jason Baird (@SkinnyRaD) is the owner of Skinny R&D which specializes in technical training and consulting in technical surveillance countermeasures (TSCM) and red team spaces. He has twenty years of experience in the technical surveillance and counter-surveillance fields. His main research interests include blending surveillance technology with cyber exploitation hardware.

Similar Presentations: