Critical.
Authoritative.
Strategic.
Subscribe to CIO Magazine »

Hacker drone launches cyber attack

The Wireless Arial Surveillance Platform (WASP) can attack Wi-Fi, Bluetooth and GSM cell networks

US computer security specialists showed off a homemade drone aircraft capable of launching airborne cyber attacks, hijacking mobile phone calls, or even delivering a dirty bomb.

Rich Perkins and Mike Tassey built the bright yellow Wireless Arial Surveillance Platform in a garage from a used US Army target drone that they customised to find mobile phones and internet hotspots.

"It will fly a plotted course and return to base," Perkins said at a DefCon hackers gathering in Las Vegas.

"We loaded it up with the ability to attack Wi-Fi, Bluetooth, and GSM cellular networks."

WASP can grab packets of data being sent over the air on wireless networks, or use unsecured hot spots as gateways through which cyber attacks can be launched on computer systems.

The drone can grab GMS mobile phone identification numbers that can then be used to bill outgoing calls. It can also let hackers impersonate mobile phone towers and eavesdrop on people's calls.

Second-hand drones such as that used for WASP can be bought online for about $US150 ($A144).

The rest of the parts were purchased by mail-order for a total tab of $6200, not counting the tremendous number of hours spent working on the project started in 2009.

Perkins said the six-kilogram drone was built to put the computer security industry on notice that the components are available for such "do-it-yourself" creations, which could be used for good or evil.

WASP could find mobile phones in disaster areas, potentially leading rescuers to survivors. It could also fly over a disaster zone to act as a mobile phone tower enabling calls.

On the evil side, WASP could help slip into a company's computer networks through unsecured wireless networks set up in cafeterias or other spots for the convenience of customers and employees.

The modified drone could also identify key executives by their mobile telephones and then track their movements to look for data-stealing opportunities, such as working on a laptop connected wirelessly to the internet at a cafe.

"I can take the various pieces of your digital life - Bluetooth headset, cell phone, Wi-Fi - and find the least secure place you exist and attack you there," Perkins said of WASP.

Such a drone could also carry a small payload, opening up the potential for smugglers to use it or to serve as a targeted biological or nuclear weapon in a terror attack, its creators warned.

"I really fear a policy reaction that stifles research," Perkins said.

"Let's look at how to protect from the bad guys doing the same thing without telling us," he urged.

Perkins and Tassey displayed their creation to security industry professionals here for a major Black Hat conference this week before taking it to DefCon, the world's largest hacker gathering, that kicked off Friday.

Authorities wouldn't permit WASP to fly over populated areas such as Las Vegas, but video taken from the drone during a flight over a rural area in the US was posted online at rabbit-hole.org.

Join the CIO Australia group on LinkedIn. The group is open to CIOs, IT Directors, COOs, CTOs and senior IT managers.

More about: US Army

Comments

Post new comment

The content of this field is kept private and will not be shown publicly.
Users posting comments agree to the CIO comments policy.
Login or register to link comments to your user profile, or you may also post a comment without being logged in.
Related Coverage
Related Whitepapers
Latest Stories
Community Comments
Tags: bluetooth, cyber attacks, gsm, mobility, WASP, wi-fi, wireless, Wireless Arial Surveillance Platform, Wireless Arial Surveillance Platform (WASP)
Latest Blog Posts
Whitepapers
  • Customer Case Study: Yarra Valley Water Turns to Enterprise Software to Improve Information Flow
    “We don’t need to wait till month-end for management reports—they’re now available whenever we need them. We have much more efficient management, as everyone across the organization is looking at the same set of figures. Read on.
    Learn more »
  • Virtualise, Manage, Backup, Consolidate
    Datacenter sprawl is one of the larger challenges that datacenter managers are facing today. Over time, applications, servers, and storage can create many unique architectures across the IT infrastructure. This can introduce complexity, increase costs, and compromise business-critical application performance and availability. Read on.
    Learn more »
  • Top 10 Mistakes in Data Centre Operations: Operating Efficient and Effective Data Centers
    For years, the data centre industry has accepted that human operational error, not poor data centre design or engineering, is the number one cause of data centre downtime. Now is the time for companies to evaluate their data centre operations programs. They must be able to clearly articulate operational requirements and design an operations program based on the risk profile of the data centre. However, the road to creating an industry-best operations program will not be easy, especially for those companies whose core expertise is not in business critical facilities. Read on.
    Learn more »
All whitepapers
rhs_login_lockGet exclusive access to Invitation only events CIO, reports & analysis.
Recent comments