Kinectasploit makes hacking a game

Powered by SC Magazine
 

Merges gaming with the art of exploitation.

While Hollywood often fails to accurately portray hacking, one researcher has made the art of exploitation look more like the big screen.

Security researcher and creator of p0wnlabs, Jeff Bryner, showcased the Kinectasploit game at Defcon 20. The game is a product of the improbable melding of Microsoft's Kinect gaming motion-sensor with hacking tools such as Metasploit.

Together with the Blender 3D environment toolkit, Kinectasploit allows hackers to break wireless networks, launch web attacks and run forensics using body gestures in the style of a first person shooter.

Players are represented as an avatar within a series of three-dimensional rooms, each one housing different hacking tools which materialise from the walls in an event inspired from a scene in The Matrix.

Kinectasploit hackers choose from a cyber arsenal of 20 tools that includes Snort, Nessus, John the Ripper and Ettercap.

They navigate the game by using full body motion; leaning will move the character in a corresponding direction, pivoting at the hip turns the character, and a series of arm gestures can execute commands.

In a demonstration, Bryner hacked into a target and retrieved and forensically analysed a file from Windows machine recycle bin folders.

He began by scanning for targets and cracking a WEP key by shooting a "fireball" at an access point to select it, and then dumping packets - illustrated by balls of packets being sucked towards the player.

He then showcased the Nessus room which was depicted as a hospital where the victim machine appeared on an operating table for scanning.

The vulnerability text was splashed on the walls of the room from where an open share was targeted. An in-game intercom which guided players throughout the game declared that a pcap file was discovered. This was sent to Ettercap, depicted as a whirling "death machine".

Credentials could be packaged as a kind of suitcase that could be carried into other rooms hosting nmap, John the Ripper, Metasploit and forensics.

While the attack was ongoing, a dedicated Snort room kept watch in case players tripped intrusion detection systems.

To pass time during lengthy scans and analyses, players could walk into a Twitter room and read three-dimensional streams of social networking chatter.

Bryner told SC he was continuing to develop Kinectasploit and most recently was working to integrate a LEAP motion and MYO as alternative motion-sensor device options to the Kinect.

The program and its prerequisites are available for download on github.

Copyright © SC Magazine, Australia


Kinectasploit makes hacking a game
 
 
 
Top Stories
Photos: iTnews Benchmark Awards countdown begins
Just a few days left until entries close for 2014.
 
Australian Govt to rethink cyber security strategy
Six-year old policy to be refreshed.
 
The failure of the antivirus industry
[Blog post] Insights from AVAR 2014.
 
 
Sign up to receive iTnews email bulletins
   FOLLOW US...
Latest articles on BIT Latest Articles from BIT
More 4G from Optus in Darwin
Nov 21, 2014
Click to see where Optus has expanded coverage to the suburbs near Darwin.
Optus steps up regional 4G coverage
Nov 20, 2014
Once 700Mhz services are working, Optus claims regional users will have a "faster and more ...
This Huawei 4G phone costs $99
Nov 12, 2014
The $99 Huawei Ascend Y550, available through Vodafone, enters the budget market as one of the ...
4G smartphones: Microsoft's Lumia 830
Nov 7, 2014
Microsoft has announced its flagship Windows Phone, the Nokia Lumia 830 4G, will be available in ...
Do you direct debit customers? Read this
Oct 10, 2014
Authorities have been targeting direct debit practices with iiNet and Dodo receiving formal ...
Latest Comments
Polls
Who do you trust most to protect your private data?







   |   View results
Your bank
  38%
 
Your insurance company
  3%
 
A technology company (Google, Facebook et al)
  8%
 
Your telco, ISP or utility
  7%
 
A retailer (Coles, Woolworths et al)
  2%
 
A Federal Government agency (ATO, Centrelink etc)
  21%
 
An Australian law enforcement agency (AFP, ASIO et al)
  15%
 
A State Government agency (Health dept, etc)
  5%
TOTAL VOTES: 1067

Vote