11 ms·
That is a really impressive piece of software. USB exfiltration of data on air gapped machines is next level. I'm in awe of their skill.
by frank_jaeger 10y ago
That is a really impressive piece of software. USB exfiltration of data on air gapped machines is next level. I'm in awe of their skill.
- jobu 10y agoAnd they had every login for the network it was found on: "The library was masquerading as a Windows password filter, which is something administrators typically use to ensure passwords match specific requirements for length and complexity. The module started every time a network or local user logged in or changed a password, and it was able to view passcodes in plaintext."
- amelius 10y agoPerhaps time to move to 2FA.
- peterwwillis 10y agoThis was a network authentication module on a domain controller. It's intercepting every low level token used to authenticate a network transaction, including encryption keys.
- mjevans 10y agoIf security has been penetrated that far you are already owned. What really scares me are things that can live in firmware; not just on mass storage drives but also in host system firmware. We've let too many dragons breed in dark places in the name of Digital Restrictions Management.
- paxcoder 10y agoCan you clarify what exactly is so impressive about this software? I read the article, and I don't see it.
- MOARDONGZPLZ 10y agoThis seems to be the crux of it: Part of what makes ProjectSauron so impressive is its ability to collect data from air-gapped computers. To do this, it uses specially prepared USB storage drives that have a virtual file system that isn't viewable by the Windows operating system. To infected computers, the removable drives appear to be approved devices, but behind the scenes are several hundred megabytes reserved for storing data that is kept on the air-gapped machines. The arrangement works even against computers in which data-loss prevention software blocks the use of unknown USB drives.
- cloudjacker 10y agoOkay first, it probably doesn't get information from air gapped computers without being plugged in, so let's quit with the voodoo right now. You guys are discounting the possibility of idiocy. Second, making partitions that windows doesn't see is trivially easy. I went out of my way to buy a 128gb flash drive nearly 10 years ago at great expense, it had a 4gb fat 32 partition which is what Windows would see. It had an 16gb Linux partition with 8gb of that being an encrypted partition I installed a bootloader that allowed it to be switched to if plugged in when any computer was starting up The other 100gb you ask? Another partition....
- IntelMiner 10y ago"making partitions that windows doesn't see is trivially easy" Are we talking "partitions Windows wont mount because they aren't FAT/NTFS" or "partitions that literally do not show up to Windows Disk Management because the disk itself is showing a different capacity. EG: A 16GB USB reporting only 8GB, regardless of the OS installed" Like one of these, only malicious https://www.neowin.net/news/fake-chinese-500-gb-external-drive-is-one-clever-paperweight-literally https://www.neowin.net/news/fake-chinese-500-gb-external-dri...
- cloudjacker 10y agoI'm not sure. I lost the flash drive, despite living in a tiny one bedroom apartment in Manhattan. Maybe a 3 letter agency took it while I was away.
- pjc50 10y agoIf your machine has a USB port, it's no longer properly isolated. Obviously that's a tremendous pain to work with, because you're limited to PS/2 keyboards and mice (etc etc), but given that there's no way of authenticating USB devices and they've already been used in various attacks, a serious airgap protocol has to ban USB ports. You could quite easily hide a USB mass storage device inside a mouse, or with a bit more work have an unmodified mouse with a spare Flash area used for data exfiltration. (Firewire is even worse, and Thunderbolt lets you onto the PCI bus)
- leni536 10y ago> You could quite easily hide a USB mass storage device inside a mouse AFAIK one could mitigate something like this by really restrictive udev rules only allowing certain usb drivers on certain usb ports (like no usb msc on the port dedicated for keyboard only).
- pjc50 10y agoYou can mitigate the exploit against standard mass storage drivers, yes, but there are other ways. It appears in this case the host was compromised (so able to override the drivers). If a userland program can get at the raw HID interface, that can also be used for exfiltration to a tailored device.
- ultramancool 10y agoThis seems trivial to me. Heck, you could practically make it full out remote exec and grab output from airgapped machines if USB keys were moved between them frequently enough. Serialize and encrypt tiny blob with command, do the same for the output and dump it back on the same USB drive or the next one plugged in, send the data out the next time it's on an internet connected machine... I don't see any challenge or skill involved here. Good post-exploitation malware is often more about doing simple things right than about doing impressive things though I suppose. Having the exploit that allows this attack to happen is the impressive part.