Many projects are underway using a controller the size and capabilities of the Raspberry Pi Zero. Today, I want to introduce you to one being developed by Samy Kamkar , a developer who has been working for some time with small, everyday devices that can be far more dangerous than we usually assume. His latest creation is PoisonTap , software capable of turning your Raspberry Pi Zero into a lethal device for any laptop.
With this tool, as you can see in the image at the beginning of this post, you simply need to connect our unique device to any USB port on a computer for it to begin intercepting all unencrypted web traffic , including authentication cookies used to log into all kinds of private accounts. All this information will then be sent to a server that, as you're probably thinking, must be under our control.
PosionTap, a software capable of turning your Raspberry Pi Zero into the ultimate weapon.
However, we're not just talking about a system capable of stealing all kinds of accounts; it goes much further. Once the tiny Raspberry Pi Zero is connected to a computer, it installs a backdoor that allows the attacker to control the PC or laptop owner's web browser and local area network . As you can see, the results can be terrifying if you leave your computer unattended for even a moment and someone decides to use this tool.
Delving a little deeper into how PoisonTap works, it's worth noting that it functions on both Windows and macOS computers. Once connected, if the software detects a browser open with only one tab, it injects a series of HTML tags that connect to a million websites, specifically the most popular ones in Alexa. It will attempt to log in to these sites if, as is often the case, automatic login is enabled. If this happens, all credentials are saved by PoisonTap and transmitted to the attacker's server.
More information: PoisonTap