What are malicious USB keys and how to create a realistic one?
elie.net
elie.net
When he plugged it in, it acted as a keyboard and managed to open the browser to a MongoDB promotional page.
Needless to say he freaked out a bit. Some marketing goons (not restricted to the people at MongoDB) seem to think this kind of thing is a great promotional tool.
Now that I think of it, my wife has a similar story about her University distributing this same kind of USB/botnet thing to students.
If you have Python (and preferably a handy virtualenv so you can throw it away afterward), do `pip install rickroll`.
It will do exactly what it sounds like it should do.
MEMS microphones are tiny. It should be possible to combine data from that and a light sensor, that would make an HID based attack far less likely to be detected. The frequency profiles of keystrokes and someone pushing away an office chair should be fairly easy do discern. You'd want to make it more likely that the attack would occur after someone had left their desk. (Hopefully with the machine unlocked.)
EDIT: Another idea: The USB key uses autorun to pop up what looks like a spammy ad for a PC "cleaner" utility, or something you'd expect on a USB key conference swag item. It's actual purpose is to cover up the shell's window, or to contain the exploit itself.
Also, if you are talking about harming individual users, and you are the kind of person who would drop "killer" USB drives on a parking lot, how is that any different from just keying every car? You get no benefit, it only causes damage, it takes near zero sophistication and the end results is it costs people a bunch of money and police start an investigation for vandalism.
People will notice that some dude is walking around and keying cars. If you happen to come across a car owner, you might be in for some pretty violent payback (at least that's what I'd do with someone keying my car).
Dropping USB keys, on the other hand, won't cause any suspicion.
If anything I would say it's not worth it all, just turn it in to your nearby local law enforcement or trash it, not worth what could be the last thing you plug into your computer.
If you trust your hardware and VM hypervisor to be secure, pass the USB controller to a VM?
Or even just the USB killers that use capacitors to fry your motherboard.
Don't forget to use tinfoil gloves and hat while you eject it
There's a computer inside that SSD that reads a soft signal to decide if writing is enabled or not. More often than not its firmware is full of known bugs.
SPI is full duplex; it has a dedicated line per data direction (MISO and MOSI), however the same lines are used for commands and data. So with MOSI (master out, slave in) physically disconnected, it'd be impossible to send the command asking to read data, even though that data would be delivered on the separate MISO (master in, slave out) line.
Or sell it on eBay...
Author of this piece didn't talk about USB electrical attacks, which (IMHO) are a bit more potent and harder to spot by the untrained eye: http://www.tomshardware.com/news/usb-killer-2.0-power-surge-...
My friend accidentally jammed his headphones into the front USB socket on his PC and killed the motherboard. Of course it doesn't work on all computers, my old laptop would just shut down (which is still inconvenient), and I'm not sure what would happen to my Macbook (and don't want to find out).
Interesting. USB 2.0 spec mandates overcurrent protection on the power rail and ability to withstand continuous short circuit to ground or power on the data pins. I think 3.0 lifted the latter requirement, though.
But I never tested actual hardware for that, besides power short-circuit protection which seems to work on my machine (YMMV).
http://www.rpmsys.com/root_flyer.pdf
I can't remember what it costs, I think it was about $2k
This is a more expensive elaborate one.
http://ellisys.com/products/usbex260/index.php
Again I can't remember the cost, but I think it was about $30K or so.
Anyway in theory with a device like this you could develop a test to check a device actually only performed the functions it was supposed to, like for instance it never changed its USB descriptors from the function it was supposed to have.
Do any OSes have an option to ask the user if connection is ok before allowing it?
It also seems to me like your OS should warn and confirm when a new input source is detected.
(I.E. "USB is typing"/"USB is doing")
The reference is to the existence of /dev/tcp when using the "Bourne again" shell. Some other large shells, and gawk, have this "feature" as well.
Then I noticed he is head of something technical at Google.
We are always reading about the rigor of this company's interviews in testing candidates for practical knowledge.
I guess knowledge of important capabilities of widely/universally installed software is not something they are testing for?
I mean, I am sure there are probably hundreds of employees there who know these things. And they have some legendary programmers on the payroll. It is like a miniature Hall of Fame of computer programming.
I am not even sure what this all means, but I find it interesting to see the gaps in knowledge considering jobs with this company are so highly sought after.
And they are entrusted with protecting an enormous quantity of other people's data.
Testing for stuff like that would be worse trivia checks than the algorithm-bingo people like to complain about in Google developer interviews.
/dev/tcp/host/port
If host is a valid hostname or Internet address, and port is an integer
port number or service name, bash attempts to open the corresponding
TCP socket.
/dev/udp/host/port
If host is a valid hostname or Internet address, and port is an integer
port number or service name, bash attempts to open the corresponding
UDP socket.
It's not a feature with a large documentation footprint. I've known about it for a while, but mostly only in the context of security too. I have wondered whether the majority use of this feature is to provide hacked network shells before. It's probably a feature that never should have been added, though I understand the initial appeal.I've also used it to issue Redis and other text based protocol commands without having to have a large runtime or library.
But in both those scenarios the environment was pretty restrictive.
The feature is pretty useless because it doesn't easily get you a two-way pipe, and there are lots of easier-to-use, more reliable ways to get a two-way pipe (or a one-way pipe, even).