Thought it was a flash drive [video]
reddit.com
reddit.com
I mean, it's a product you can literally buy and it's impossible to adequately defend against.
https://github.com/hak5darren/USB-Rubber-Ducky/wiki/Payloads
And i'm pretty sure using this exploit for totally benign marketing purposes is a new one.
You can't really prevent that.
I don’t know that people would accept this inconvenience, though.
how would you accomplish this given that the normal situation is that you're plugging in a keyboard?
This is somewhat similar to how bluetooth keyboards are enabled on macOS (or were the last time I connected one).
All kinds of legitimate (well, this is legitimate too really, it's just weird) devices have similar behaviour, and in their cases it's what the user expects and wants.
That's exactly what's happening there, but the "keyboard" is pre-programmed to enter keys presses automatically in a way that makes a website pop up.
I wonder what it would look like to have a background program that would detect and intercept any newly connected device by default, give it a fake (VM?) environment, and log everything it tried to do to the screen while prompting to ask if you want to let it into the "real" system. Obviously this is what security professionals do manually, but I'm talking about a totally transparent and automatic version that could be left running all the time.
?
Generally though, places that I've worked at with the same restrictions, also don't let you have liquids at the desk with said stations.
I've been in plenty of machine rooms where liquids == fired/escorted from the building.
• It should allow the keyboard through—or have a timeout that defaults to "yes"—if a mouse or keyboard is not already connected.
• I should have the option to disable it.
For this case, I am assuming that the keyboard and os language are fairly compatible, at least translatable.
It doesn't stop the attack, but in my small(ish) network I can easily recognize unauthorized devices. https://github.com/zelon88/Workstation_USB_Monitor
Of course, there's always the possibility that I unlock my port and plug in some infected USB of my own volition and it's much more likely than some random person plugging something in.
But, anyway, this thing presents as a keyboard, not a storage device.
I'm in the process of creating a USB drop-test script for employee training purposes. Awareness and preparedness training has been one of my best investments of time and energy with a staggering ROI. My team recently passed my last phishing test 100%.
If the corporate network you're talking about is Windows Active Directory based then I believe that there are Group Policy settings to only allow connection of encrypted external drives. I'm not sure when this was introduced, and it might only be on Windows 10, but hopefully at this point most businesses are either already there or moving in that direction.
And with some of the crazy hardware[1] out there for retrofitting antique equipment with modern functionality; blanket encryption is not always possible either. The cited USB emulator requires that the USB stick be formatted into hundreds of minuscule FAT partitions, simulating floppy disks images and all the documentation comes in one language: Engrish. After that the machines will only load programs that follow a certain naming convention/format/ect... [1]http://www.gotekemulator.com/
So the choices for many organizations are; a) upgrade dozens of custom pieces manufacturing equipment so that they're securely networkable at astronomical cost (if it's even possible). b) Air-gap all the old scary stuff running on ancient OSs & proprietary PLC drivers from god-knows-where and only talk to them via USB/direct interfaces and worry about them when they break.
But it just completely trusts any USB device I plug into it to do whatever. I wonder how much work it would be to have it ask for the user to type a randomly-generated passcode before accepting input from a new USB device?
If you have business policies and training in place, hopefully the additional steps of removing a lock will also provide time for adequate second thoughts to percolate through those with poor judgment. Malicious actors won't be seriously deterred, but that's a different matter.
I want to say it even lets you disable or whitelist usb keyboards/mice entirely but I’m not 100% certain.
QubesOS is pretty different from other OSes though, I wish those sorts of device isolation were possible or more easily accomplished in other operating systems.
Couldn't believe we got multiple people to connect to it under the guise the device would do a cool thing.
Sometimes I feel like all this worrying about computer security makes it harder for people to share new things.
It's one thing to theorize, discuss and build something dangerous, it's another to actually use it.
See Flamethrowers.
Adults who know each other and the dangers well should be (and are) allowed to play with flamethrowers. I’m not sure I’d want to live in a place where they couldn’t.