4 ms·
Similar to this is the USB Ninja, which delivers a remote payload like the Rubber Ducky. https://hackerwarehouse.com/product/usb-ninja-cable/ https://hackerwar
by wfriesen 7y ago
Similar to this is the USB Ninja, which delivers a remote payload like the Rubber Ducky.
https://hackerwarehouse.com/product/usb-ninja-cable/ https://hackerwarehouse.com/product/usb-ninja-cable/
- kweks 7y agoFor those who may be curious, how two very similar products (USBNinja and the O.MG Cable) exist, there is a bit of history. Both products are based on the concept of a HID attack: most modern OSs (MacOS, Linux, Windows, Android...) trust HID (Human Interface Devices) implicitly. This means that when you plug in a Keyboard, Mouse, Storage device or Network device, they work instantly. You don't need to install drivers or explicitly enable them. The newly attached devices work instantly - even on a locked device. The advantage here is obvious. The disadvantage is more subtle, but was exploited by the Hak5 "Rubber Ducky". By emulating a HID device (or even worse, multiple HID devices simultaneously..) - you could essentially control a computer and deploy / execute anything, as if you had full control of the device. "The Classic" PoC is the Windows "Creds" attack [1] - which unlocks locked windows machines - later turned very, very nuclear by Samy Kamkar with PoisonTap [2], which essentially exfiltrates data, exfiltrates cookies and credentials, and permanently backdoors a locked PC. The idea of moving from a dedicated device (Rubber Ducky) to an embedded device first came to surface with the BadUSB device [3]. The idea of moving it into a cable came from the NSA, a device called COTTONMOUTH [4][6], which was leaked during the NSA document dumps [5]. MG, the designer of BadUSB, built a prototype of this with today's resources. RRG, the company behind the latest iterations of Proxmark 3, ChameleonTiny, etc prototyped and built the USBNinja. Their device is built on the Arduino (Ducky) framework, as opposed to the ESP32 Framework. There is / was drama between MG (behind BadUSB) and RRG / Kevin Mitnik; MG claimed that it was his prototyped device was brought to market first by RRG. Drama aside, both products exist, both serve the same purposes, and from a hardware point of view, they're both incredible devices that we could have never imagined 10 years ago. Personally, I find the framework of the USBNinja to be slightly better in practical purposes, (Non-degraded USB-C charging and performance, non detectable wifi etc). I believe there is also a "pro" version slated for release that adds significant functionality. Source / disclaimer for all of this: I source products for https://Lab401.com https://Lab401.com - so we performed a deep dive on both products before deciding which to stock. I also had the chance to visit the factories and witness the prototyping - absolutely fascinating. It's worth underlining that when the COTTONMOUTH device came out in 2009, it had a value of over 1MUSD. 10 years later, arguably better and smaller devices are literally 0.01% the price, and you can have one in your hand. Progress is amazing. [1] https://shop.hak5.org/blogs/news/15-second-password-hack-mr-robot-style https://shop.hak5.org/blogs/news/15-second-password-hack-mr-... [2] https://samy.pl/poisontap/ https://samy.pl/poisontap/ [3] https://github.com/O-MG/DemonSeed https://github.com/O-MG/DemonSeed [4] https://arstechnica.com/information-technology/2013/12/inside-the-nsas-leaked-catalog-of-surveillance-magic/ https://arstechnica.com/information-technology/2013/12/insid... [5] https://en.wikipedia.org/wiki/NSA_ANT_catalog https://en.wikipedia.org/wiki/NSA_ANT_catalog [6] https://en.wikipedia.org/wiki/File:NSA_COTTONMOUTH-I.jpg https://en.wikipedia.org/wiki/File:NSA_COTTONMOUTH-I.jpg
- hackTP 7y agoIm not sure how you managed to get almost all of this wrong. Network adapter attacks like poisontap are not even HID. COTTONMOUTH was hardware added inside a USB cable with the type of attack not detailed. MG (twitter.com/_MG_) did not invent BadUSB. He was the first to put a HID attack inside a cable. Kevin Mitnick asked MG to build him one. Two months later, Mitnick announces that he created the same cable with the help of RRD Group. In his first announcement he even said “this took longer to ship than to make!”. His collaborators (twitter.com/vysecurity) were sorely misinformed about the internals of the cable they claimed to help build. They kept saying it was totally different hardware but it ended up being the same as MG’s. Mitnick started threatening MG for telling people that he had previously shown Mitnick the internals of his prototype. MG eventually opensourced the prototype as DemonSeed around the same time he released the OMG Cable that has much more powerful hardware. Stop shilling for crappy people. Stop shilling for an online shop that claims to do research that most obviously it never did.