finds.dev← search

// the find

samyk/poisontap

★ 6,479 · JavaScript · updated Nov 2018

Exploits locked/password protected computers over USB, drops persistent WebSocket-based backdoor, exposes internal router, and siphons cookies using Raspberry Pi Zero & Node.js.

PoisonTap is Samy Kamkar's 2016 proof-of-concept that turns a $5 Raspberry Pi Zero into a USB-based attack device: plugged into a locked machine, it hijacks all outbound traffic via a DHCP/routing trick, siphons cookies for the Alexa top 1M sites, and drops a persistent WebSocket backdoor cached in the browser. It's aimed at security researchers and red teamers who want to understand USB/network trust assumptions, not at anyone looking for a turnkey exploit kit.

The core trick — telling the OS via DHCP that the entire IPv4 space is local, so a low-priority USB interface outranks the real gateway — is a genuinely clever abuse of routing table semantics rather than a software bug. The README is unusually good documentation for an offensive tool: it walks through each bypass (HttpOnly, SameSite, X-Frame-Options, 2FA, DNS pinning) with the actual mechanism, not just a claim. It also chains several independently-known weak points (iframe caching, CDN JS trust, DNS rebinding) into one persistent attack, which is a useful case study in how 'bypassed' security controls compound.

Dead project — last push was 2018, built against Raspbian/Node APIs and an Alexa top-1M list that no longer exists in that form, so it won't run as-is. It's Pi-Zero-and-specific-OS-version shell scripting (pi_startup.sh, rc.local hacks) rather than packaged software — no tests, no CI, no abstraction for other hardware. It's also a vulnerability-disclosure artifact, not a maintained tool: the defenses section is the real lasting value, the exploit code itself is mostly of historical/educational interest at this point since modern OSes and browsers have closed several of these holes (stricter cookie defaults, SRI adoption, etc.).

View on GitHub → Homepage ↗

// want more like this?

We dig through GitHub every week and send a few repos picked for what you actually care about — each with an honest take like this one.

Get finds in your inbox → Search again →