Tags: Palm
Let the postal system deliver your evil agents
September 28th, 2003, by Rich.

I was pondering the rapidly decreasing price of handhelds and wireless hardware today, for example 802.11 enabled PDA’s, when a potential attack technique came to me.
- Take one relatively inexpensive wireless enabled handheld computer.
- Post it to a non-existent person at a company which you believe to have a wireless network
- The machine will in the mailroom for a while before being “bounced”.
- Set it to run your favourite wireless scanning program once every few hours.
- Have the machine “phone home” once it’s makes a connection, using that connection.
- You now have a machine, potentially inside the corporate firewall which you can use to tunnel your content until the battery dies - use the available time compromise a more permanent machine.
Notes:
- Using a Return-To-Sender address might get you in trouble if this turns out to be illegal in practice.
- For added bravado, why not send it to a real person - hopefully they’ll like the gift and not notice the background scanning and kindly recharge the unit, maybe even taking it to other sites.

