Welcome!

Join our community of MMO enthusiasts and game developers! By registering, you'll gain access to discussions on the latest developments in MMO server files and collaborate with like-minded individuals. Join us today and unlock the potential of MMO server development!

Join Today!

Badusb

BloopBloop
Joined
Aug 9, 2012
Messages
892
Reaction score
275
i did just read this and found it very interesting and thought lets share it.
In short: "BadUsb" is the modifying of the firmware of usb devices, what could have serious consequents.
(3 examples out of the article)
BadUSB – Turning devices evil. Once reprogrammed, benign devices can turn malicious in many ways, including:
  1. A device can emulate a keyboard and issue commands on behalf of the logged-in user, for example to exfiltrate files or install malware. Such malware, in turn, can infect the controller chips of other USB devices connected to the computer.
  2. The device can also spoof a network card and change the computer’s DNS setting to redirect traffic.
  3. A modified thumb drive or external hard disk can – when it detects that the computer is starting up – boot a small virus, which infects the computer’s operating system prior to boot



(not sure if this belongs here or in the outerworld)
 
Last edited:
Pessimistic butt@%&!
Loyal Member
Joined
Jan 18, 2008
Messages
2,057
Reaction score
487
Wouldn't a firewall detect the attempt to connect to transmit whatever information was taken (IE: keystrokes) and pop up asking you if you want to allow it to connect?
 
BloopBloop
Joined
Aug 9, 2012
Messages
892
Reaction score
275
Wouldn't a firewall detect the attempt to connect to transmit whatever information was taken (IE: keystrokes) and pop up asking you if you want to allow it to connect?

from a other article:
The presenters will demonstrate similar hacks that work against Android phones when attached to targeted computers. They say their technique will work on Web cams, keyboards, and most other types of USB-enabled devices.


  • Transforming a brand-name USB stick into a computer keyboard that opens a command window on an attached computer and enters commands that cause it to download and install malicious software. The technique can easily work around the standard user access control in Windows since the protection requires only that users click OK.

They are talking here about a similar technic for androids ,android does not have a firewall by default,however your phone must be attached to a computer to get infected. They also say that is it quite easy since you only need to press "Ok".


Wouldn't making the firmware read-only solve the problem of replacing it with malicious code?

Yes that will solve it (change it from Flash memory to ROM), however it is often used for fixing bugs/ adding new features.
 
Last edited:
BloopBloop
Joined
Aug 9, 2012
Messages
892
Reaction score
275
And where is the news in this? USB sticks are known to be very vulnerable for a long time. You can prevent it by disabling autorun and just simply not using such a stick on a windows PC

You can be infected before the bios is able to call the bootloader, in other words, you can be infected before the os is even running.
 
Back
Top