Arduino Tux Plant Care


Some of us need a little help keeping our green leafy friends happy. The Arduino Tux (translated) plant care system was built to make things a little easier.

The author had a broken tux toy laying around and wanted to do something fun with it. He cut a hole in the front to mount an LED matrix and connected it all to an Arduino. A couple of metal rods serve as a resistivity sensor in the plant’s dirt.

When you water the plant, tux flashes some hearts and a smiley face. As the moisture drops, tux gets less happy with the end result being a big frown.

These are the same people who brought you the Arduino Photolab.

[via Hack a Day Flickr Pool]

Black Hat 2008: NIC Based Rootkit


While Black Hat and Defcon have both concluded, we’re going to post a few more talks that we think deserve attention. [Sherri Sparks] and [Shawn Embleton] from Clear Hat presented Deeper Door, exploiting the NIC chipset. Windows machines use NDIS, the Network Driver Interface Specification, to communicate between the OS and the actual NIC. NDIS is an API that lets programmers talk to network hardware in a general fashion. Most firewalls and intrusion detection systems monitor packets at the NDIS level. The team took a novel approach to bypassing machine security by hooking directly to the network card, below the NDIS level.

The team targeted the Intel 8255x chipset because of its open documentation and availability of compatible cards like the Intel PRO/100B. They found that sending data was very easy: Write a UDP packet to a specific memory address, check to make sure the card is idle, and then tell it to send. The receive side was slightly more difficult, because you have to intercept all inbound traffic and filter out the replies you want from the legitimate packets. Even though they were writing low level chipset specific code, they said it was much easier to implement than writing an NDIS driver. While a certainly a clever way to implement a covert channel, it will only bypass an IDS or firewall on the same host and not one on the network.

[photo: Big Fat Rat]

Russia Vs Georgia, The Online Front


While we’re sure that just about everyone has heard about the conflict between Russia and Georgia, few have probably heard about the role of cyber attacks in the conflict. Shortly before Russia’s armed response, Georgian state web servers were attacked by individuals assumed to be Russian hackers. This attack almost completely obliterated Georgia’s online presence by shutting down the website for the Ministry of Defense, and the Central Government’s main site. The Russian attackers seem to be using some form of sustained DDoS to keep many Georgian sites offline. In an effort to preserve some web presence, the Georgian Government transferred [President Mikheil Saakashvili]’s site to a US hosting provider in Atlanta. The Ministry of Foreign Affairs even created a BlogSpot page after their website initially went down. While politically motivated DDoS attacks have not been rare in past months, this seems to be the first time where the attacking party can be clearly identified. This seems to be the start of a trend where the unconventional methods of cyber warfare are used to gain an advantage over the enemy.

[photo: somefool]

Possible Entrapment Scenario In Hacking Case

[Brian Salcedo] made headlines a few years ago as a hacker who attempted to break into Lowe’s corporate network. He is currently serving a nine-year prison sentence, one of the longest sentences for a computer hacking offense. Recent events surrounding a different hacking case have revealed that the buyer he worked for, [Albert “Segvec” Gonzalez], was a Secret Service informant. [Salcedo] claims that were it not for [Gonzalez]’s threats, he would not have committed the hacking offense. While the Secret Service may not have even been aware of [Gonzalez’s] activity with other hackers, [Salcedo] could make a case of entrapment by arguing that [Gonzalez] threatened him as a government agent in order to make him plant the sniffer in Lowe’s network.

Motherboard Walls

[Chris Harrison] and a friend created these motherboard walls for Carnegie Mellon professor [Scott Hudson]. According to [Harrison], he amassed over 150 pounds of motherboards, most of them off of eBay, to create this surreal project. Nearly every inch of the lab is covered with motherboards, of different lengths and varying shades of green, silver, and black. We think it’s pretty festive.

[via Neatorama]

Autonomous Helicopter Learns Autorotation


Stanford’s autonomous helicopter group has made some impressive advancements in the field of autonomous helicopter control, including inverted hovering and performing aerobatic stunts. The group uses reinforcement learning to teach its control system various maneuvers and has been very successful in doing so. One of their latest achievements was teaching the bot the emergency landing technique autorotation. Autorotation is used when a helicopter’s engine fails or is disengaged and works by changing the collective pitch to use the airflow from descent to rotate the blades. The group has more flight demonstrations on their YouTube channel.

[via BotJunkie]

Drive A Robot In Australia Over The Web


BP Australia has commissioned an online game where you get to drive robots around an obstacle course. Make no mistake, these are real robots. Actually they are modified versions of the Surveyor SRV-1 vehicles that are popular with research labs, and schools everywhere.

Go to the website, get in queue and pray for no clouds. These babies are solar powered, so you’ll have to try to get in while its day time in Australia. The entire set is built in miniature, so you feel like you’re driving a tank around a city.

[via Robots Dreams]