DeepSec 2022 Talk: Wireless Keystroke Injection As An Attack Vector During Physical Assessments – Simonovi Sergei
A lot of wireless input devices are vulnerable to keystroke injection due to the lack of security mechanisms, which makes it a perfect attack vector. During the attack, an attacker can send any text string to the victim machine acting as a remote keyboard, which can lead to quick and stealthy compromise of the system. No antivirus software shall spot the attack, as the keyboard, even remotely, is not malicious by itself and is always trusted. We asked Simonovi Sergei a few more questions about his talk. How did you come up with it? Was there something like an initial spark that set your mind on creating this talk? I came up with the idea of using a wireless keystroke injection during one unfortunate physical engagement, during which my team could not get any