Image
 
linkedin_logo.png rss_logo.jpg
twitter_logo.png youtube_logo.jpg
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 51 guests online
 
Advertisement

You are here: Home arrow Ethical Hacking Discussions and Related Certificationsarrow Mobilearrow Using Mobile Devices For Pentesting
EH-Net
May 22, 2013, 09:27:41 AM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: Go back to The Ethical Hacker Network Online Magazine Home Page
 
   Home   Help Calendar Login Register  
Pages: [1]   Go Down
  Print  
Author Topic: Using Mobile Devices For Pentesting  (Read 7718 times)
0 Members and 1 Guest are viewing this topic.
Seen
Full Member
***
Offline Offline

Posts: 134


View Profile
« on: December 19, 2011, 09:51:47 PM »

My sister just got an iPad from her work (apparently you can't teach 2nd grade without one now--when I was in grade school I think there 10 Apple IIs for the whole school!), and although I personally don't see the appeal for tablets, it got me thinking: has anyone here found a use for mobile devices in pentesting? 

There are quite a number of articles about performing a pentest on mobile applications, but besides one or two interesting projects, I couldn't really find anyone using smartphones or tablets to help perform a pentest.  This is understandable given the limited processing power, but I was just wondering does anyone here have any thoughts or personal experience on this topic?
Logged

Sec+, eCPPT
3xban
Hero Member
*****
Offline Offline

Posts: 608


View Profile WWW
« Reply #1 on: December 20, 2011, 08:42:01 AM »

A couple of the android based tablets have been hacked to run BT.  I also know someone who got it to run on their Moto Atrix.  As for the iPad, I think Apple has it locked down enough but I believe some have gotten it jailbroken to run WiFi sniffers.  Performance wise, I can't see them being an asset, I suppose you can rig one to be a RF sniffer and carry it in a small neoprene sleave with the scanner attached similar to the netbook version.  Walk around NYC grabbing cards and such.
Logged

Certs: GCWN
(@)Dewser
pseud0
Recruiters
Full Member
*
Offline Offline

Posts: 208



View Profile
« Reply #2 on: December 20, 2011, 09:04:16 AM »

For most activities involved in general pen testing a tablet or smartphone would be my last choice of platform.  Yes, some folks have done full BT installs on them but that is more for amusement than anything else.  Just not enough horsepower to do it directly from the mobile device.  That being said, I use an ipad in the field to do some quick remote access into a server I use for pen testing.  iSSH into the box to fire of nmap scans, msfcli, etc.  That's cheating as the tablet isn't really doing any of the testing, just giving me quick access to the box that is.  Some of the droid platforms can be used to do some wireless testing, but you're obviously going to be limited by antennas, injection capabilities, etc.  You're also not going to be doing much WEP or WPA cracking on the mobile, but you might be able to pass it off to another system for the actual cracking.  You can also find apps like droidsheep and others that are fun to play with, but still, more fun than functional. 
Logged

CISSP, CISM, CISA, GCIH, GREM, CEH, HMFIC, KTHXBIROFLCOPTER
chrisg
Guest
« Reply #3 on: December 20, 2011, 09:47:14 PM »

you can do it but the keyboards on the tablets make things unfun to do anything serious.
Logged
Seen
Full Member
***
Offline Offline

Posts: 134


View Profile
« Reply #4 on: December 21, 2011, 01:12:59 AM »

You can also find apps like droidsheep and others that are fun to play with, but still, more fun than functional. 

Yeah, this is kinda the feeling I got when I looked this topic online.

you can do it but the keyboards on the tablets make things unfun to do anything serious.

I HATE typing on my phone, I can call and leave a voicemail faster than I can send a text!
Logged

Sec+, eCPPT
pseud0
Recruiters
Full Member
*
Offline Offline

Posts: 208



View Profile
« Reply #5 on: December 21, 2011, 08:02:38 AM »

I bought this for myself as an early Xmas present.  Pretty happy with it so far in regards to being functional and portable.  I can sync it with my ipad or my droid phone.  Makes it a lot easier to use either one as a ssh platform into the actual testing server.

http://www.amazon.com/Verbatim-97537-Wireless-Bluetooth-Keyboard/dp/B004L9LT2E
Logged

CISSP, CISM, CISA, GCIH, GREM, CEH, HMFIC, KTHXBIROFLCOPTER
kuddus ali
Newbie
*
Offline Offline

Posts: 1


View Profile
« Reply #6 on: December 22, 2011, 10:55:20 AM »

tablets and ipad and others does not normally provide the option to use mobile to pentest but now some softwares are there which can help to use cell for this purpose
Logged

Grendel
Full Member
***
Offline Offline

Posts: 242


View Profile WWW
« Reply #7 on: December 22, 2011, 12:10:53 PM »

I did a talk at deacon about three years back on this exact topic. It was titled "hacking WITH the iPod touch."

The issues and advantages addressed in that talk are still relevant.
Logged

- Thomas Wilhelm, MSCS MSM
ISSMP CISSP SCSECA SCNA IEM

Web Site:
Author:
  • Professional Penetration Testing
  • Ninja Hacking
  • Penetration Tester's Open Source Toolkit
  • Metasploit Toolkit for Penetration Testing
  • Netcat Power Tools
Seen
Full Member
***
Offline Offline

Posts: 134


View Profile
« Reply #8 on: December 22, 2011, 01:48:40 PM »

Thanks Tom, I found it, I'll take a look at it tonight.
Logged

Sec+, eCPPT
Pages: [1]   Go Up
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.18 | SMF © 2013, Simple Machines
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.129 seconds with 23 queries.
 
Exclusive Deal

sansfire13_245x90_cw90.jpg
SANSFIRE 2013
June 15 - 22

5% Off w/ Code: EHN_5

SANS Deals 4 EH-Netters
5% OFF Any SANS Course in Any Format!
Coupon Code: EHN_5 Including SANS Rocky Mountain 2013 & SANS Boston 2013
Polls
Compared to this year, 2013 will be:
 
Recent Forum Topics
EH-Net News Feeds
Latest Additions
 
         
Free Business and Tech Magazines and eBooks

© 2013 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.