Wednesday, March 29, 2006

Honey Cubicle

Honey Cubicle*: A cubicle set up as an enticement to test for the latest in physical security breaches. The Honey Cubicle contains a PC with full network access not protected by any screensaver, HW or SW locking device. The Honey Cubicle is primarily a research tool meant to detect the latest physical security attack vectors and develop countermeasures to such threats. Some of the newer discovered attacks directly attributed to the Honey Cubicle include:
  1. The now famous "shoelace" attack where the attacker accidently pretends to tie shoelace near the Honey PC
  2. The "dizzy spell" attack where the attacker sits down near the PC and pretends to catch his/her breath while typing commands
  3. The very dangerous "Janitor" attack where the attacker dresses up as a cleaning lady, pretends to clean the keyboard with a duster while using the duster to secretly load Metasploit and shovel a reverse bind shell via the MS RPC DCOM exploit.
* Coined by The Sushiman.

No comments: