PenTesting in the Palm of Your Hand

A portable hacking device equipped with hundreds of exploits and an automated exploitation system will go on sale in the United States in October. The wireless handheld, called Silica, is the latest product to be developed by Immunity, a Miami-based security company that sells penetration testing products and services.

An early version of Silica, which supports 802.11 (Wi-Fi) and Bluetooth wireless connections, has been fitted with more than 150 exploits from Immunity's Canvas product to allow security professionals to conduct pen tests while walking through office cubicles.


Direct Link to ImmunitySec Silica

Immunity SILICA is a hand-held penetration testing product that leverages Immunity CANVAS to provide a unique testing tool for networks. Currently it supports 802.11 (Wi-Fi) and Bluetooth wireless connections or optionally Ethernet via USB. Its slim, PDA-like profile allows the penetration tester to perform testing while appearing to perform an innocuous behavior.

Example Use Cases :

  • Tell SILICA to scan every machine on every wireless network for file shares and download anything of interest to the SILICA device. Then just put it in your suit pocket and walk through your target's office space.
  • Tell SILICA to actively penetrate any machines it can target (with any of Immunity CANVAS's exploits) and have all successfully penetrated machines connect via HTTP/DNS to an external listening post running Immunity CANVAS Professional.
  • Mail SILICA to your target's CEO, then let it turn on and hack anything it can as it's sitting on their desk.
  • Have SILICA conduct MITM attacks against people on a wireless network.
  • Use SILICA as you would CANVAS on your desktop - just smaller.

Because every penetration test is different, Immunity SILICA is highly customizable. Based on the Open Source Linux operating system and the pure Python Immunity CANVAS attack framework, if one of SILICA's built in attack profiles does not fit your needs, you can easily craft one that does.

Silica Got Slashdotted

Some interesting comments on this tool can read over Silica - Slashdot.

Post new comment

  • Allowed HTML tags: <a> <em> <strong> <cite> <code> <ul> <ol> <li> <dl> <dt> <dd> <h1> <quote> <img>
  • Lines and paragraphs break automatically.

More information about formatting options

CAPTCHA
This question is for testing whether you are a human visitor and to prevent automated spam submissions.
Image CAPTCHA
Copy the characters (respecting upper/lower case) from the image.