Sunday, May 05 2024 | Updated at 04:51 AM EDT

Stay Connected With Us F T R

Nov 23, 2016 08:10 AM EST

A developer created a tool that costs only $5 that can hack into screen-locked computers as long as the web browser is left running.

Los Angeles-based computer engineer Samy Kamkar revealed his creation, which he called the Poison Tap that only costs $5. The USB device can bypass any password locked computer and opens the machine to remote access without the user knowing anything about it.

Kamkar made a YouTube video of him demonstrating Poison Tap on a Macintosh computer but hinted that it should also work on other platforms, according to BBC News. The device is plugged into the computer's USB port, once plugged, masks itself as the internet, and begins to hijack all traffic.

The Device

The Poison Tap is a minuscule Raspberry Pi Zero computer that makes the target laptop or PC think it is connecting to a network. Once all unencrypted traffic is hijacked, it injects HTML into the open web browser pretending to serve up the correct pages to the computer.

The computer is forced to take in JavaScript code and stores it in the web cache and at the same time grants remote access to the computer's browser. The Poison Tap can also acquire and collect the user's unencrypted login cookies.

The hacker can then proceed to use the stolen cookie data to access all websites the user visited using the user's own login details, MacRumors reported. All this happens in less than a minute and remains within the compromised machine even after Poison Tap has been unplugged, and without having to unlock the computer.

Security threat

What's mind boggling is that the Poison Tap bypasses standard security measures such as password protection, two-factor authentication, DNS pinning and more. The device dupes the operating system by identifying the device as a LAN that encompasses the entire internet.

Protection

For his part, Kamkar also stated in the YouTube video how to protect unattended machines for possible attacks from Poison Tap and similar devices like his. The most basic are taking your laptop with you, always close your browser windows, or enable FireVault2 if you use a Mac. Server admins, on the other hand, can enforce HTTPS at entry level.

For those who would responsible enough and would want to try Poison Tap out, you'll need the $5 Raspberry Pi Zero and Kamkar's software available at his site.

See Now: Covert Team Inside Newsweek Revealed as Key Players in False Human Trafficking Lawsuit

Follows Hacking Tool, Poison Tap, Developer Tool, Computer Hacking, Raspberry PiZero, Compromised Machines, Computer Hack Tool
© 2024 University Herald, All rights reserved. Do not reproduce without permission.

Must Read

Common Challenges for College Students: How to Overcome Them

Oct 17, 2022 PM EDTFor most people, college is a phenomenal experience. However, while higher education offers benefits, it can also come with a number of challenges to ...

Top 5 Best Resources for Math Students

Oct 17, 2022 AM EDTMath is a subject that needs to be tackled differently than any other class, so you'll need the right tools and resources to master it. So here are 5 ...

Why Taking a DNA Test is Vital Before Starting a Family

Oct 12, 2022 PM EDTIf you're considering starting a family, this is an exciting time! There are no doubt a million things running through your head right now, from ...

By Enabling The Use Of Second-Hand Technology, Alloallo Scutter It's Growth While Being Economically And Environmentally Friendly.

Oct 11, 2022 PM EDTBrands are being forced to prioritise customer lifetime value and foster brand loyalty as return on advertising investment plummets. Several brands, ...