USB security flaw
Page 1 of 1
JBeckman
VIP Member



Posts: 34968
Location: Sweden
PostPosted: Fri, 1st Aug 2014 13:47    Post subject: USB security flaw
http://www.guru3d.com/news-story/researchers-uncover-fundamental-usb-security-flawno-fix-in-sight.html

Quote:

Security researchers from SR Labs have uncovered a fundamental flaw in the way USB devices work. It affects every single USB device out there and worst yet, there's no line of defense short of prohibiting USB stick sharing or filling your USB ports with superglue. The flaw that security researchers Karsten Nohl and Jakob Lell plan to present next week at the Black Hat security conference in Las Vegas runs deeper than simply loading a USB drive with malware. Instead, it's built into the core of how the technology works.

After spending several months reverse engineering the firmware that handles the basic communications functions of USB devices, they were able to reprogram the firmware to hide malicious code. This firmware is present on every USB device within the controller chip - the component that facilitates communication between the USB device and the computer it's plugged in to. By loading malicious code on the firmware, it's essentially hidden from sight. Anti-virus scanners can't pick it up and formatting won't help, either. To prove their point, the team created a piece of malware called BadUSB that can be used to completely take over a PC, alter files invisibly and even redirect a user's Internet traffic.


Unsure if this will lead to anything, it's a interesting discovery but I imagine reverse engineering USB devices to access their firmware is pretty time consuming and acquiring the USB device itself wouldn't be that easy.
(Perhaps work environments and the like were such equipment is swapped around would be a bit more exposed?)
Back to top
Hfric




Posts: 12017

PostPosted: Sat, 2nd Aug 2014 23:11    Post subject:
in idiot : they found out USB devices first read a CHIP NAND and then the MASS ... flash the nand with a firmware that has a virus ... presto

but to do the stuff , they write
you had to have this USB device with this ROM
that is on this NAND
all the time or make it so ,
this virus in this NAND will infect other CHIP NANDS ...
like your BIOS or DVD drive or other devices that you flash to update ...

oh gee a thing that was like forever in the haker scene is now made public ... and they want credit for it Laughing



grinhurt


Back to top
Ankh




Posts: 23342
Location: Trelleborg
PostPosted: Fri, 8th Aug 2014 09:38    Post subject:
When the inventor of the USB stick dies they'll gently lower the coffin, then pull it back up, turn it the other way, then lower it again.


shitloads of new stuff in my pc. Cant keep track of it all.
Back to top
sabin1981
Mostly Cursed



Posts: 87805

PostPosted: Fri, 8th Aug 2014 13:18    Post subject:
Ankh wrote:
When the inventor of the USB stick dies they'll gently lower the coffin, then pull it back up, turn it the other way, then lower it again.


Back to top
Page 1 of 1 All times are GMT + 1 Hour
NFOHump.com Forum Index - Hardware Zone
Signature/Avatar nuking: none (can be changed in your profile)  


Display posts from previous:   

Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum


Powered by phpBB 2.0.8 © 2001, 2002 phpBB Group