4 ms·
Fingerprinting has been done: https://cise.ufl.edu/~butler/pubs/sadfe11.pdf https://cise.ufl.edu/~butler/pubs/sadfe11.pdf And given you can easily reprogram th
by mshook 9y ago
Fingerprinting has been done: https://cise.ufl.edu/~butler/pubs/sadfe11.pdf https://cise.ufl.edu/~butler/pubs/sadfe11.pdf
And given you can easily reprogram thumb drives and such, it's easy to do evil stuff with them. You can plug a thumb drive with a reprogrammed firmware which will detect the OS based on IO patterns and then it can tell the OS it's also a keyboard and runs command for you.
https://srlabs.de/bites/usb-peripherals-turn/ https://srlabs.de/bites/usb-peripherals-turn/
https://srlabs.de/wp-content/uploads/2014/11/SRLabs-BadUSB-Pacsec-v2.pdf https://srlabs.de/wp-content/uploads/2014/11/SRLabs-BadUSB-P...
https://github.com/brandonlw/Psychson https://github.com/brandonlw/Psychson
https://www.computerworld.com/article/2690790/tools-for-creating-malicious-usb-thumb-drives-released.html https://www.computerworld.com/article/2690790/tools-for-crea...
From the article: "During their Derbycon demonstration, which is available on YouTube, the two researchers replicated the emulated keyboard attack, but also showed how to create a hidden partition on thumb drives to defeat forensic tools and how to bypass the password for protected partitions on some USB drives that provide such a feature."
- mschuster91 9y agoWow, the situation is even worse than I imagined - I thought fingerprinting was theoretical, not that there are actual practical examples in the wild. Jeez.