http://kth.diva-portal.org/smash/record.jsf?pid=diva2%3A1701492&dswid=-5022 kth.sePublications [ajax-loade] Please wait ... Simple search Advanced search - Research publicationsAdvanced search - Student thesesStatistics EnglishSvenskaNorsk Jump to content Change search [ ]Search Search [ ]Only documents with full text in DiVA CiteExport * BibTex * CSL-JSON * CSV 1 * CSV 2 * CSV 3 * CSV 4 * CSV 5 * CSV all metadata * CSV all metadata version 2 * RIS * Mods * MARC-XML * ETDMS Link to record Permanent link [http://urn.kb.se/resolve?urn=urn:nbn:se:kth:diva-319693 ] [ ] [ ] Direct link [http://kth.diva-portal.org/smash/record.jsf?pid=diva2:170149] [ ] [ ] Cite Citation style [ ] [apa ] * apa * ieee * modern-language-association-8th-edition * vancouver * Other style [ ]More styles Language [ ] [en-GB ] * de-DE * en-GB * en-US * fi-FI * nn-NO * nn-NB * sv-SE * Other locale [ ]More languages Output format [ ] [html ] * html * text * asciidoc * rtf CreateClose Penetration testing wireless keyboards: Are your devices vulnerable? Tomsic, Niklas KTH, School of Electrical Engineering and Computer Science (EECS). 2022 (English)Independent thesis Advanced level (degree of Master (Two Years)), 20 credits / 30 HE creditsStudent thesisAlternative title Penetrationstest av tradlosa tangentbord : Ar dina enheter sarbara? (Swedish) Abstract [en] With an ever-increasing amount of cyberespionage and cybercrime, any potential attack vector into a computer system is worthy of investigation. One such vector could be through the wireless keyboard the user themselves use and trust. If an attacker was able to intercept the traffic between the keyboard and the computer they could spy on every keystroke that is being sent to the computer. Additionally, they could potentially inject keystrokes as if they were sitting at the computer themselves. This thesis evaluated 10 different keyboards that were purchased in common consumer electronic stores and 8 of them were found to have new substantial flaws that made it possible to reliably listen to every keystroke sent by the keyboards, as well as allow an attacker to send keystrokes to the connected computer, indirectly giving the attacker full control of the computer. It was concluded that wireless keyboards should not be used in situations where sensitive information is handled regardless of what the keyboard manufacturer claims, as it creates a potential attack vector that is otherwise nonexistent. Abstract [sv] Med en standigt okande mangd cyberspionage och cyberbrottslighet sa ar alla potentiella vagar in i ett datorsystem varda att undersoka. Ett satt att ta sig in i ett system skulle kunna vara genom det tradlosa tangentbord som anvandaren sjalv anvander och litar pa. Om en angripare hade mojligheten att fanga upp trafiken mellan tangentbordet och datorn skulle den kunna lyssna pa varenda knapptryck som skickades till datorn. Utover det sa skulle en angripare mojligen kunna skicka egna knapptryck till datorn som om den sjalv satt vid den. Den har uppsatsen har studerat och utvarderat 10 olika tangentbord som koptes i vanliga elektronikaffarer och i 8 av dem hittades nya allvarliga brister som gjorde det mojligt att bade avlyssna vad som skrevs samt att kunna skicka knapptryck till datorn som tangentbordet var kopplat till. Detta ledde indirekt till full kontroll over datorn. Slutsatsen som kunde dras var att tradlosa tangentbord inte bor anvandas i nagon situation dar kansligt innehall hanteras, oavsett vad tillverkaren av tangentbordet havdar. Detta da det oppnar upp en ny attackyta som inte finns om tradlosa tangentbord inte anvands. Place, publisher, year, edition, pages Stockholm: KTH Royal Institute of Technology , 2022. , p. xxi,143 Series TRITA-EECS-EX ; 2022:644 Keywords [en] Wireless keyboards, penetration testing, radio frequency analysis, Crazyradio, MouseJack, Enhanced ShockBurst Keywords [sv] Tradlosa tangentbord, penetrationstest, radiofrekvensanalys, Crazyradio, MouseJack, Enhanced ShockBurst National Category Computer Sciences Identifiers URN: urn:nbn:se:kth:diva-319693OAI: oai:DiVA.org:kth-319693DiVA, id: diva2:1701492 External cooperation Cparta Cyber Defense Subject / course Computer Science Educational program Master of Science - Computer Science Presentation 2022-08-05, via Zoom https://kth-se.zoom.us/j/69896857187, Isafjordsgatan 22 (Kistagangen 16), Stockholm, 13:00 (English) Supervisors Guanciale, Roberto KTH, School of Electrical Engineering and Computer Science (EECS), Computer Science. von Konow, Johan Cparta Cyber Defense. Examiners Maguire Jr., Gerald Quentin KTH, School of Electrical Engineering and Computer Science (EECS), Computer Science. Available from: 2022-10-07 Created: 2022-10-06 Last updated: 2022-10-07Bibliographically approved Open Access in DiVA fulltext(42592 kB)[info]5 downloads [ ] [ ] [ ] File information File name FULLTEXT01.pdfFile size 42592 kBChecksum SHA-512 de67ebab8d028087ac13d4881d32ce13bbfb4ffe702f12206855c63c971c8bdf587fb403b7c449df8082a5bc19a4396d219383954783a1ba7d5a9042d13c46fe Type fulltextMimetype application/pdf Search in DiVA By author/editor Tomsic, Niklas By organisation School of Electrical Engineering and Computer Science (EECS) On the subject Computer Sciences Search outside of DiVA GoogleGoogle Scholar Total: 5 downloads[info] The number of downloads is the sum of all downloads of full texts. It may include eg previous versions that are now no longer available [ajax-loade] urn-nbn Altmetric score urn-nbn Total: 427 hits CiteExport * BibTex * CSL-JSON * CSV 1 * CSV 2 * CSV 3 * CSV 4 * CSV 5 * CSV all metadata * CSV all metadata version 2 * RIS * Mods * MARC-XML * ETDMS Link to record Permanent link [http://urn.kb.se/resolve?urn=urn:nbn:se:kth:diva-319693 ] [ ] [ ] Direct link [http://kth.diva-portal.org/smash/record.jsf?pid=diva2:170149] [ ] [ ] Cite Citation style [ ] [apa ] * apa * ieee * modern-language-association-8th-edition * vancouver * Other style [ ]More styles Language [ ] [en-GB ] * de-DE * en-GB * en-US * fi-FI * nn-NO * nn-NB * sv-SE * Other locale [ ]More languages Output format [ ] [html ] * html * text * asciidoc * rtf CreateClose v. 2.37.11 | WCAG | KTH Library | DiVA support | Register in DiVA | Posting your thesis | SwePub