There was another presentation at Defcon about attacking USB drivers with rogue devices. Basically, they programmed a USB-enabled microcontroller to present a malformed ID string and could use it to inject and run arbitrary code.
http://www.defcon.org/images/defcon-17/dc-17-presentations/d...
EDIT: sorry, that PDF is less informative than the talk was. He had a bunch of demonstration material that's not included here, apparently.