eWeek Security Watch
Advertisement
Advertisement
February 8, 2007 11:42 PM

Wireless Hacking Tool Makes Splash at RSA



Among the most intriguing technologies being shown off at this year's ongoing RSA Conference in San Francisco is a mobile penetration testing application made by Miami Beach, Fla.-based Immunity that allows people to scan networks for vulnerabilities on the go.

Dubbed Silica, the sleek handheld, based on a Nokia tablet device, claims the ability to test wireless network security using Wi-Fi technology—with other form factors and support for Bluetooth and wired Ethernet connectivity planned for delivery by Immunity soon.

The handheld is specifically being pitched by the 10-employee firm, founded in 2002, as a method for people to search for unprotected access points without drawing attention to their efforts. Users can casually stroll around any office building and simply scan the airwaves for network access "while behaving innocuously," said Justine Aitel, chief executive of Immunity.

The application is built around a Linux operating system and is based on the firm's more robust Canvas product line of penetration testing software. It features three simple functions—scan, stop and upgrade—making it the perfect choice for people seeking carefree mobile hacking capabilities, according to the vendor.

Aitel, a former chief security officer with business news outlet Bloomberg, said Immunity has received a fair number of orders for the devices over the last few days at RSA.

"We're always trying to reach different markets, and an increasingly sophisticated user base has been asking us for something like this that is simple to use and move around with," Aitel said. "It's also a way for us to reach out to slightly different groups of customers than in the past, and a different crowd than we typically cater to with Canvas."

The former CIO cooked up the idea for the mobile hacking device while at Bloomberg, where she was constantly worried about the use of rogue access points and unprotected wireless networking systems.

Whether being used to carry out man-in-the-middle attacks against unguarded wireless users or to seek out file shares sitting on people's desktops, the device is a convenient platform for proving the need for stronger access protection, according to the executive.

"People can ship this to their operations anywhere in the world to help test the vulnerability of their corporate networks," the CEO said. "We think there's a real market for this type of device."

TrackBack

TrackBack

http://securitywatch.eweek.com/cgi-bin/mte/mt-tb.cgi/10278

Comments (2)

OAF :

This is nothing new, Yellow Jacket has been around for years.

Paul-Andre Panon :

Your e-mail teaser for this story said
"Will criminal hackers use this for the wrong reasons?"

Criminals can already roll their own penetration testing tools similar to this. A criminal version might have been little more bulky perhaps, or a little more expensive. All Immunity have done is the systems integration work with expectation of economies of scale from mass marketing. It means administrators can test their networks the way criminals would without spending hundreds of man-hours rolling their own solution.

Yeah, you've now placed that hardware in the hands of the criminal equivalent of script kiddies. If your network was insecure before, this doesn't make it less secure; it just increases the pool of attackers. But if you use it to test your network properly, it might make it more secure. So, on the balance, this is a good thing.

Post a Comment

 
 


RSS Syndication
Advertisement
Advertisement
Security Watch     Contact Us | Advertise | Site Map
Ziff Davis Enterprise

Ziff Davis Enterprise Home | Contact Us | Advertise | Link to Us | Reprints | Magazine Subscriptions | Newsletters
RSS Feeds | White Papers | ROI Calculators | Tech Podcasts | Tech Video |

Baseline | Careers | Channel Insider | CIO Insight | DesktopLinux | DeviceForge | DevSource | eSeminars |
eWEEK | LinuxDevices | Linux Watch | Microsoft Watch | Mid-market | Networking | PDF Zone |
Publish | eWeek Security | Strategic Partner | Web Buyer's Guide | Windows for Devices

Developer Shed | Dev Shed | ASP Free | Dev Articles | Dev Hardware | SEO Chat | Tutorialized | Scripts |
Code Walkers | Web Hosters | Dev Mechanic | Dev Archives | IT Marketplace | igrep

Use of this site is governed by our Terms of Use and Privacy Policy

Copyright ©1996-2007 Ziff Davis Enterprise, Inc. All Rights Reserved. Security Watch is a trademark of Ziff Davis Enterprise, Inc. Reproduction in whole or in part in any form or medium without express written permission of Ziff Davis Enterprise Inc. is prohibited.

Ziff Davis Enterprise