What Are the Dangers of Using an Untrusted USB Drive?
lifehacker.com
lifehacker.com
For example, when someone searches my name, currently the #2 hit is a Gawker repost of a blog post I wrote. What's worse is that Gawker actually goes out of their way to make it seem like they spoke with me (ie, added additional "content" to my post), when in fact they didn't; all they did was provide a tl;dr[0].
I don't have a problem with news publications that seek to be secondary sources that add value (analysis, more in-depth reporting) to stories that others break, but it kills me to see publications not even bothering to do that.
[0] I can't remember if they even linked back to my post or not; I'd check, but I actually have all Gawker media sites blocked in /etc/hosts and I don't really feel like undoing that.
[0] I took a second at the Gawker "article"; they combined content with my blog post with some quotations from an interview with a (non-Gawker) publication, so it's recycling content from primary + secondary source, not just primary.
http://travisgoodspeed.blogspot.com.au/2012/07/emulating-usb...
I rarely use USB drives these days, and I don't remember the last time I used one that didn't belong to me. Probably for the best.
https://www.kernel.org/doc/Documentation/usb/authorization.t...
As far as I understand this, I think it still reads the USB descriptors (which itself has been shown to be problematic in the past), but postpone binding the drivers (thereby locking out an enourmous amount of potentially buggy code from automatically starting to work on your USB device's maliciously crafted data).
And as the USB controllers are mostly the same anyways... find a bug in a common family and PROFIT.
guestfish -a /dev/sdX
><fs> run
><fs> list-filesystems
/dev/sda1
><fs> mount /dev/sda1 /
Libguestfs runs a tiny appliance containing a separate kernel and (if your host supports it) protects that in an LXC container and with SELinux. In any case it would be extremely difficult for a malformed filesystem to exploit the guest kernel, and escape from virtualization, SELinux and LXC to attack the host.Note this doesn't help if your OS "helpfully" mounts the disk when you plug it in.
$ wc -l usb/core/*.c
21465 total
$ wc -l `find fs -name '*.c'`
1016460 total
Two orders of magnitude more. Now I'm not saying that USB descriptor parsing is free from problems, but there are an awful lot of obscure filesystem drivers in there ... Econet ADFS anyone?Another place where libguestfs can help is in parsing files from the filesystem. We provide trusted parsing libraries that run inside the VM, so parsing (say) Unix /etc configuration or Windows Registry files is much safer.
IIRC almost anything I wanted to bring for the presentation was allowed (I wasn't searched - no TSA), but USB drives were forbidden.
The disk burner on my MBP failed (weird foreign current issues), so I ended up using Dropbox and my iPhone.
The only true way? Are you sure about that?
There are other OS's besides Linux and Windows.
And there is something called rump(3).