Malicious Charging Cable
shop.hak5.org
shop.hak5.org
I have been watching their shows since season two and recently was granted the proud responsibility of hosting their IRC these days[1]. (which is the shameless plug)
Obviously it's built for newbies but that's part of the charm and a lot of the content gets new people interested in security and computers in general. :)
[1]: ircs://irc.hak5.org/hak5
'I had developed a small reputation from my appearances at the Ice House, and on May 6, 1969, I wrangled a meeting and auditioned in an office for Steve Allen’s two producers, Elias Davis and David Pollock. They accepted me with more ease than I expected, and when I spoke with them afterward, they commented, “There seems to be a dearth of young comedians right now.” I looked puzzled. I said, “That’s odd, I don’t think there are many at all.” Their stares made me realize my blunder. I knew the word, but I had the definition backward.'
From "Born Standing Up," an amazing memoir
https://mg.lol/blog/omg-cable/ and https://github.com/O-MG/O.MG_Cable-Firmware have more information about the cable, but is still severely lacking on technical details about the hardware and software used to communicate.
[1] https://github.com/O-MG/O.MG_Cable-Firmware/blob/master/READ...
Both products are based on the concept of a HID attack: most modern OSs (MacOS, Linux, Windows, Android...) trust HID (Human Interface Devices) implicitly. This means that when you plug in a Keyboard, Mouse, Storage device or Network device, they work instantly. You don't need to install drivers or explicitly enable them. The newly attached devices work instantly - even on a locked device.
The advantage here is obvious. The disadvantage is more subtle, but was exploited by the Hak5 "Rubber Ducky". By emulating a HID device (or even worse, multiple HID devices simultaneously..) - you could essentially control a computer and deploy / execute anything, as if you had full control of the device.
"The Classic" PoC is the Windows "Creds" attack [1] - which unlocks locked windows machines - later turned very, very nuclear by Samy Kamkar with PoisonTap [2], which essentially exfiltrates data, exfiltrates cookies and credentials, and permanently backdoors a locked PC.
The idea of moving from a dedicated device (Rubber Ducky) to an embedded device first came to surface with the BadUSB device [3].
The idea of moving it into a cable came from the NSA, a device called COTTONMOUTH [4][6], which was leaked during the NSA document dumps [5]. MG, the designer of BadUSB, built a prototype of this with today's resources.
RRG, the company behind the latest iterations of Proxmark 3, ChameleonTiny, etc prototyped and built the USBNinja. Their device is built on the Arduino (Ducky) framework, as opposed to the ESP32 Framework.
There is / was drama between MG (behind BadUSB) and RRG / Kevin Mitnik; MG claimed that it was his prototyped device was brought to market first by RRG.
Drama aside, both products exist, both serve the same purposes, and from a hardware point of view, they're both incredible devices that we could have never imagined 10 years ago.
Personally, I find the framework of the USBNinja to be slightly better in practical purposes, (Non-degraded USB-C charging and performance, non detectable wifi etc). I believe there is also a "pro" version slated for release that adds significant functionality.
Source / disclaimer for all of this: I source products for https://Lab401.com - so we performed a deep dive on both products before deciding which to stock. I also had the chance to visit the factories and witness the prototyping - absolutely fascinating.
It's worth underlining that when the COTTONMOUTH device came out in 2009, it had a value of over 1MUSD. 10 years later, arguably better and smaller devices are literally 0.01% the price, and you can have one in your hand. Progress is amazing.
[1] https://shop.hak5.org/blogs/news/15-second-password-hack-mr-...
[2] https://samy.pl/poisontap/
[3] https://github.com/O-MG/DemonSeed
[4] https://arstechnica.com/information-technology/2013/12/insid...
[5] https://en.wikipedia.org/wiki/NSA_ANT_catalog
[6] https://en.wikipedia.org/wiki/File:NSA_COTTONMOUTH-I.jpg
Network adapter attacks like poisontap are not even HID.
COTTONMOUTH was hardware added inside a USB cable with the type of attack not detailed.
MG (twitter.com/_MG_) did not invent BadUSB. He was the first to put a HID attack inside a cable.
Kevin Mitnick asked MG to build him one. Two months later, Mitnick announces that he created the same cable with the help of RRD Group. In his first announcement he even said “this took longer to ship than to make!”. His collaborators (twitter.com/vysecurity) were sorely misinformed about the internals of the cable they claimed to help build. They kept saying it was totally different hardware but it ended up being the same as MG’s. Mitnick started threatening MG for telling people that he had previously shown Mitnick the internals of his prototype. MG eventually opensourced the prototype as DemonSeed around the same time he released the OMG Cable that has much more powerful hardware.
Stop shilling for crappy people. Stop shilling for an online shop that claims to do research that most obviously it never did.
No. Sometimes it asks, sometimes it doesn't. There doesn't seem to be any pattern to it that I have been able to discern.
In sufficiently complex software, things can appear to be random (or magic), even when they are neither. — I seldom trust myself to declare something random in computer technology, just because I haven’t figured out the pattern (yet).
Well, no, but I assume it has a way of knowing if the computer I'm plugging it in to now is the same one that I plugged it in to yesterday and that I told it to trust yesterday.
The cable I'm using is the one that came with the phone, so if it was malicious that would be big news. But I just realized that I left out an important detail: my phone is not plugged directly into my computer, but is instead connected through a USB hub and an OWC Thunderbolt dock. So that muddies the waters considerably. It is not at all out of the question that one of those devices is doing something hinky, though I'll give long odds against.
> is there a chance that the trust is lost on a weird AI timer?
Extremely unlikely. This one computer is the only one my phone has ever been plugged in to (AFAIK).
> I assume you’re always using the same cable? And I also assume you don’t get the trust dialog when plugging into a wall charger directly?
Correct on both counts.
(The most depressing thing to me is that people actually pay money for devices like Alexa and Google Voice which are designed to spy on them. Who needs to become a hacker when people will voluntarily give up their privacy for a shiny thing?)
It's very weird, and the fact that the trust dialog does not display any kind of device fingerprint makes it impossible to know what is actually going on.
How often do you charge your phone? I only get those prompts when charging with a computer, not with a charger. One explanation might be that it remembers your computer for 1 week (random guess), but if you irregularly connect your phone to your computer it might seem random to you.
You're correct that if I plug the phone into my PC the phone defaults to just charging from it, and needs an explicit UI intervention to offer other features - but if I plug it into my USB keyboard it just works as a keyboard, no further UI intervention needed.
I guess it's _possible_ that I forgot having one time authorised this for the keyboard, but even if that's true it means a malevolent device just needs to guess what to impersonate to get into any phone that has even once authorised such a device, because there's no cryptographic protection - if I say "I'm a Cheap Ass Generic USB Keyboard serial # 00001" then there's no way to distinguish me from the real "Cheap Ass Generic USB Keyboard serial # 00001".
Now, maybe the situation is that phones allow some safer things and not more dangerous ones. Maybe you can pretend to be a USB keyboard or mouse, but it will refuse to offer any of the file transfer type features or networking. I don't know, but my expectation is that people who've built these cables do know and there are plenty of holes.
But anyway, suppose phones are smart enough to refuse to charge from a keyboard. These cable are remote controlled. So you plug in your phone, it charges... and then a minute later when you're distracted it gets told the charger went away... and now here's a keyboard. Attack in progress.
I reckon you could work out a procedure e.g. pretend to be power for 90 seconds, supposing experience teaches that's how long people take to forget they plugged the phone in. Then, turn the power off. Watch. An attentive user may notice, unplug their phone and try again thinking the cable may be faulty. Re-enable power when the phone vanishes. If not, after giving them say 30 seconds to notice switch to keyboard mode. Or you could just wing it. A lot of good physical penetration testers "wing it" all the time.
I think you're talking about the "this accessory is not supported by this iphone" prompt, not the "trust this computer?" or "allow this device to access your photos and videos" prompts. The first shows up if your cable can't be verified to be mfi compatible (via a special chip in the cable), and the last two only show up when connecting to a computer.
At the very least a list of specs would be greatly appreciated!
Imagine what you could do on a terminal with keyboard mouse and storage, and that's pretty much what this can do.
In theory undetectable while not activated.
> the O.MG Cable is built for covert field-use by Red Teams
Similar to how self-defense training doesn't necessarily make you a skilled fighter, but instead trains you to be more aware of your situations, and there for reduce the likelihood you will need to defend yourself.
Do they try to sell to people who they know won't check if the device has Activation Lock and then disappear when the buyer discovers it doesn't work?
I know someone who fell for this. Even though they were skeptical when they received the message, they thought there was a chance it was legit, and therefore gave them some change to recover their stolen phone. I guess they had nothing to lose, as the chance of recovering the phone was ~zero anyway.
Can't you just patch out the check with the checkra1n bootloader exploit?
I initially thought this might be used to hack into phones via the lightening or USB ports, but the security on these devices is pretty good. It seems less likely that an exploit of this value would be put into cables like this. I still worry about plugging my phone into random hotel or transport USB charge ports however... I should pick up a USB condom I guess!
Presumably it wouldn't look like data lines were present