15 ms·
Usbkill – anti-forensic tool to halt computer when new USB device is connected
- raxxorrax 6y ago> In case the police or other thugs come busting in I like this wording. Disclaimer: Not a comment on current political happenings. But seriously, the use case of disallowing USB sticks on devices is unnecessary hard to configure. Just an option to disallow certain device classes would be appreciated.
- microcolonel 6y agoThis is fairly straightforward with udev, a couple lines of config should be sufficient.
- pnutjam 6y agoany directions?
- bartvk 6y agoThis guide is pretty good: http://reactivated.net/writing_udev_rules.html http://reactivated.net/writing_udev_rules.html Some ten-odd years ago, I wrote how to create udev rules to execute a command after connecting a particular USB device: https://www.vankuik.nl/2008-12-19_Linux_USB_device_handling https://www.vankuik.nl/2008-12-19_Linux_USB_device_handling
- microcolonel 6y agoI think it would end up something like SUBSYSTEM=="block", SUBSYSTEMS=="usb", OPTIONS+="ignore_device" But don't quote me on that
- daraps 6y agoI just disable all hotplugging support in my OS. Anything plugged into the machine must be manually mounted, enabled, etc. This works really great for me as it's rare that anything is attached to this machine other than the charger.
- InsomniacL 6y agohow would you authenticate the USB stick that is allowed though? Without some sort of authentication mechanism an attacked could clone the device id of an allowed device. better than nothing though! :)
- the8472 6y agoThere's the USB Authentication Protocol where devices identify themselves through digital signatures. But i don't know whether each device has a unique ID or its one cert for the whole production series.
- mschuster91 6y ago> But seriously, the use case of disallowing USB sticks on devices is unnecessary hard to configure. This will not help against hardware that exploits bugs in the USB stack of the operating system. Assuming the threat model is police or secret service seizing one's server, it is feasible that the attackers also have knowledge of the running OS (IIRC one can distinguish between Windows, Linux and xBSD by simply looking at TCP fingerprints) and thus can use a targeted exploit.
- agumonkey 6y agotypical social pattern: - nothing - hard work to make something easy to use - hard work to make something easy to control - control
- brian_herman 6y agoI thought this was https://usbkill.com/ https://usbkill.com/ I think maybe this would be more effective in anti-forensic because it actually destroys the computer?
- csunbird 6y agoGets the work done, somehow.
- zelon88 6y agoI really like this concept. That's why I've made similar projects. One to detect when USB storage devices get attached to domain workstations, and email the administrator with device and user info..... https://github.com/zelon88/Workstation_USB_Monitor https://github.com/zelon88/Workstation_USB_Monitor And one which detects USB HID devices, confirms them, and notifies the administrator..... https://github.com/zelon88/Rubber_Ducky_Defender https://github.com/zelon88/Rubber_Ducky_Defender
- blue52 6y agoAmazing work of art, bravo.
- bra4you 6y agoI saw this solved with a USB stick on a keychain and the computer shuts down when the stick is removed. Does anybody still have the link? Ah. Found it: https://tech.michaelaltfield.net/2020/01/02/buskill-laptop-kill-cord-dead-man-switch/ https://tech.michaelaltfield.net/2020/01/02/buskill-laptop-k...
- reallymental 6y ago"Tip: Additionally, you may use a cord to attach a USB key to your wrist. Then insert the key into your computer and start usbkill." This line particularly caught my eye. I wonder what's the percentage of people (I'm presuming people working in security or those who are trying to avoid detection) go to this extreme? Is is even extreme?
- berkas1 6y agoI don't think that wrist-key is an extreme (never seen it actually, but I still think this solution is a cautious one). For me an extreme measure would be to modify my motherboard in a way that I could connect RAM to my wrist and tear it away when necessary.
- nkrisc 6y agoNow that would be interesting: have your RAM strapped to your wrist and connected to your Mobo by a breakaway cable. Bonus points if they cut it when the tackle you because they thought it was a deadman switch, like mentioned in the link.
- baq 6y agonot a security expert but a commonly heard phrase is 'depends on your threat model' :)
- moritonal 6y ago"To prevent Ulbricht from encrypting or deleting files on the laptop he was using to run the site as he was arrested, two agents pretended to be quarreling lovers. When they had sufficiently distracted him, according to Joshuah Bearman of Wired, a third agent grabbed the laptop while Ulbricht was distracted by the apparent lovers' fight and handed it to agent Thomas Kiernan. Kiernan then inserted a flash drive in one of the laptop's USB ports, with software that copied key files." https://en.wikipedia.org/wiki/Ross_Ulbricht https://en.wikipedia.org/wiki/Ross_Ulbricht
- daffy 6y ago
- captainmuon 6y agoInteresting project, I'm sure this is useful for people at risk. Somewhat related, I'm wondering about the physical security of computers. There is an attack where they open your PC, take out the ram, and freeze it immediately so the bits don't decay and they can extract your encryption keys. All BIOSes have an option for cassis intrusion detection, but I've never seen a case that has the necessary cable. Has anybody here set up a chassis intrusion kill switch that erases the RAM/shuts down the PC etc. if the case is opened improperly? Can you buy anything like this on the market?
- deleted 6y ago[deleted]
- alfiedotwtf 6y agoBack in the BBS days, there were textfile describing how to wire your beige box to either turn on strong magnets or ignite termite if a case was detected. ... I don’t know of anyone actually implementing this though :)
- luckylion 6y agoSome ideas have been tested, there was an entertaining talk a few years back at DefCon: https://www.youtube.com/watch?v=-bpX8YvNg6Y https://www.youtube.com/watch?v=-bpX8YvNg6Y
- geerlingguy 6y agoI would imagine that's thermite and not termite ;) If the latter, the server would probably be okay, and it would take a very long time for the termites to damage the surrounding room enough to be a security deterrent.
- DoofusOfDeath 6y agoProbably just a debugging technique.
- 6y ago
- deleted 6y ago[deleted]
- jokoon 6y agoI dont understand. Is USB just always insecure because of hardware?
- raziel2p 6y agoYes, but that's unrelated. The idea here is that if a USB device is connected to your machine, it's an indicator that your machine is compromised. Mouse jigglers that stop your lock screen from activating are very common when confiscating machines: https://www.cru-inc.com/products/wiebetech/mouse_jiggler_mj-3/ https://www.cru-inc.com/products/wiebetech/mouse_jiggler_mj-... And of course, depending on the OS, it's possible to craft a USB stick that copies files to a remote server as soon as it's plugged in.
- daffy 6y ago> depending on the OS, it's possible to craft a USB stick that copies files to a remote server as soon as it's plugged in. Is this possible with Linux?
- michaelt 6y agoYou can get a 'USB rubber ducky' [1] which emulates both a USB memory stick and a USB keyboard, allowing you to script keystrokes for the keyboard [2] So it can do anything a newly plugged in keyboard can do. Which, if the user is already logged in, makes grabbing the user's files easy. [1] https://shop.hak5.org/collections/usb-rubber-ducky/products/usb-rubber-ducky-deluxe https://shop.hak5.org/collections/usb-rubber-ducky/products/... [2] https://github.com/hak5darren/USB-Rubber-Ducky/wiki/Payloads https://github.com/hak5darren/USB-Rubber-Ducky/wiki/Payloads
- daffy 6y agoThis will only work, I suppose, if the attacker knows beforehand a keychord that will focus a terminal.
- 6y ago
- pfundstein 6y agoIn a similar vein, there's antijiggler[1] which only locks the PC when a new device is connected. [1] http://www.codefromthe70s.org/antijiggler.aspx http://www.codefromthe70s.org/antijiggler.aspx
- raziel2p 6y agoSeems like a lot of code for what should be, on Linux anyway, a simple udev rule? echo 'RUN+=/root/usb-changed.sh' > /etc/udev/rules.d/usb-changed.rules Then just put whatever you want to be ran in /root/usb-changed.sh.
- el_oni 6y agoI attended a talk by GSK and there was part of the talk about security. They don't allow usb devices to be plugged into their analysis computers. But every year they get an intern that tries to charge their phone from the PC USB. Something like this, that doesnt halt the computer but shows a warning on screen and logs information would perhaps be a solution to their problem. Although in the case of industrial espionage maybe locking the system would be worth it...
- lozf 6y agoAt a former gig for a post-production facility we used CoSoSys EndpointProtector to restrict USB access to workstations. Works as described in your second paragraph, (logs and warning) admin can then allow approved devices remotely if necessary.
- SV_BubbleTime 6y agoI worked for a car mfg that had that on all their laptops. It was annoying and I’m 99% certain no one ever checked up on the alerts and instead was just logging in case there was an issue later.
- waldfee 6y agoIf you are paranoid about something like this happening, just use https://www.qubes-os.org/ https://www.qubes-os.org/. all usb devices are jailed in a non-networked vm by default. In general, if what you do warrants that level of paranoia, qubes will help you massively. Micah Lee held a great overview talk at HOPE 2018: https://www.youtube.com/watch?v=f4U8YbXKwog https://www.youtube.com/watch?v=f4U8YbXKwog
- kawsper 6y agoHow does that work with input devices like keyboard and mouse?
- waldfee 6y agogenerally it is advised to use ps2 input (like most laptop's integrated keyboard and touchpad). details on using usb keyboard and mouse here: https://www.qubes-os.org/doc/usb-qubes/ https://www.qubes-os.org/doc/usb-qubes/
- czechdeveloper 6y agoI don't think it solves same problem.
- numlock86 6y agoObligatory $5 wrench comment: https://xkcd.com/538/ https://xkcd.com/538/ Something like this is probably good when you - as a person - are not around when your hardware gets extracted from your place. But then again, why would it be running openly and unattended in the first place?
- ex_amazon_sde 6y agoCan we please stop endlessly repeating this? Life is much more complex than that. A small laptop, a phone or a tablet can be stolen from you while powered on and unlocked by a simple thief that has no intention, nor ability, to capture and torture you. The thief could then quickly hand the device to other people that flash it and sell it in a different country. But first they might extract any valuable data.
- numlock86 6y ago> Life is much more complex than that. > [...] a simple thief that has no intention, nor ability, to capture and torture you By your comment I assume you live in a developed country and/or are not within a regularly oppressed minority, which of course, is a nice privilege. Sadly not everyone is that lucky and torture over something simple as $1 online transactions is pretty real.
- Nasrudith 6y agoThat isn't priveledge but a matter of the threat model to protect against - stop with the irrelevant pseudomoralist privledge shaming shit. If they wanted protection against that they would recommended a gun or several mercenary bodyguards. Which would require money and connections. But the topic isn't "How to quickly kill or incapacitate three or more men with only your barehands while having legal cover".
- dividedbyzero 6y agoIn many places, law enforcement will pressure but not torture you to provide decryption keys, maybe imprison you for a while, fine you, ... But that may be preferable than them knowing about all those highly illegal nuclear doomsday space arms technology knowledge deals you've brokered, or that collection of child porn, or those detailed assassination plans, or whatever. Maybe the authorities suspect something, maybe a SWAT team will snatch your laptop, but if all evidence is in there and encrypted, you may get off with a lot less than otherwise.
- 0xdeadb00f 6y agoA hotplugd script can be used to mimic this on OpenBSD
- sn_master 6y ago"immediately terminates the connection" Reminds me of some old Firewalls that would actively poll active connections, and when one is made that violates their rules, "immediately" terminate it. Often times, an attacker can embed a lot in just a single URL in the query string (stolen passwords etc) that would be done in < 5ms, faster than the firewall can act (if not even faster than the polling interval itself), specially if there is plenty of rules and active connections and/or the machine is slow (e.g playing games). That's like choosing to not have a door on your house, because you know you can run fast and shoot the thief when they enter. Maybe its not as bad for hardware due to the inherit latencies involved, but I am always skeptic about things that use polling vs sitting in the middle at the kernel before a USB connection is allowed to happen to the OS in the first place. The default (aka the one that nobody will change) connection-polling interval for this thing is 250ms, which doesn't seem too small for me for many conceivable attack scenarios. For Mac, it runs this: os.system("killall Finder ; killall loginwindow ; halt -q") This won't prevent windows from reopening after a reboot. A possible exploit for this could be the USB pretending to be a keyboard, opening an exploit website or an app with malicious argument values, then you immediately shutdown the Mac, reboot manually and boom, the website/app opens up and the machine gets owned anyway post-reboot! Also, lack of Windows support is upsetting, considering there isn't much code change required to do so. The "melt" feature is one I really like and respect the thought they put to make it.
- bausano_michael 6y agoI think it's aimed at scenarios in which the attacker is not aware of this utility running. Otherwise they could just kill it before inserting the USB.
- sn_master 6y agoWell, for attack vectors like Mouse Jiggler (I have one, very cheap on Amazon) or polymorphic USB devices, it would work if the attack is unaware of the utility's existence. For polymorphics specifically, I checked the code, and it does indeed validate the Ids of the devices, not just their count. For others, even if the attacker is unaware of the utility, those shortcomings are still serious enough (e.g. rapid keyboard typing).
- Ericson2314 6y agoAnd now, we've come full circle to plug-and-stop-playing.
- nialv7 6y agoWhat's stopping the forensic people from just spoofing the USB device IDs?
- topspin 6y agoNothing. And that's not the problem this program is intended to solve.
- nialv7 6y agoIt is. The program tries to prevent use of unauthorized USB devices, yet it uses the easily spoofed USB device IDs to authenticate them.
- deleted 6y ago[deleted]
- topspin 6y agoIt isn't. The problem this program solves is thwarting a naive attempt to alter the state of the USB bus. The design assumes the attacker is not aware of the consequences of adding or removing devices and has no reason to employ spoofed devices or any other Ever Greater Adversary Regression techniques you can imagine.
- nialv7 6y agoAfter they got bitten but tools like this usbkill once, ID spoofing will just become the standard practice, and it will be made so easy to do they don't even need to think.
- deadbunny 6y agoHow do they get the IDs?
- nialv7 6y agoThey could just look around and see what USB devices you own. USB vendor/product IDs are not secret.
- codethief 6y agoFrom going through the discussion I'm getting the impression that the only feasible attack vector provided by USB is by emulating a keyboard like a USB Rubber Ducky. Is this really the case? For instance, if my laptop is locked (with a proper[0][1] lock screen like xscreensaver) and that lock screen is capturing all keyboard input and magic SysRq keys[2] are disabled, too, is there really no way an attacker could use a USB device to hack my laptop? Similarly, if my laptop is not locked but comes with unusual key bindings (maybe even a different keyboard layout), what are the chances of me getting hacked with a USB device? (Let's assume that the attacker manages to secretly plug in said USB device but doesn't want to access my unlocked laptop directly – maybe because we're in an open office and people are watching.) My impression had always been that USB devices are dangerous beyond simple keyboard emulation but I might be wrong. [0] https://www.jwz.org/blog/2015/04/i-told-you-so-again/ https://www.jwz.org/blog/2015/04/i-told-you-so-again/ [1] https://www.jwz.org/xscreensaver/toolkits.html https://www.jwz.org/xscreensaver/toolkits.html [2] https://en.wikipedia.org/wiki/Magic_SysRq_key https://en.wikipedia.org/wiki/Magic_SysRq_key
- busterarm 6y agoBesides keyloggers, another reason people want this is because law enforcement has USB keepalive devices that will simulate mouse movement/keypresses to keep your computer from going to sleep. They do this to make sure your computer stays on and your RAM doesn't get powered off, which will allow them to read any decrypted data in memory whether or not your data is encrypted on disk. When they raid you, they come with massive UPS devices that they plug your computers into to give them as long a window as possible to get your data.
- atum47 6y agoI've made a video about disabling the USB to prevent rubber ducky attacks a long time ago. never thought about shutting down the computer. https://youtu.be/RtRsBTGZUgc https://youtu.be/RtRsBTGZUgc
- Benmcdonald__ 6y agoHow does this work for usb typec? When I plug in my power cable will my computer shutdown?
- AnotherGoodName 6y agoAnd does it work for things that look exactly like USBC but are actually Thunderbolt? (with all its direct memory access via DMA and all of that nastiness). See the Apple combo USBC/Thunderbolt ports.
- deadbunny 6y agoIt lists the ability to whitelist devices in the article.
- lizardmancan 6y agonot as easy but more fun to ruin the usb device. if they use mousewiggling the screensaver could use other triggers/patterns to keep the box on. say 1 google search per 15 min minimum. randomly moving the mouse seems a good reason to shut down.
- gamblor956 6y agoDestroying evidence is considered a crime on it's own. Use something like this at your own legal risk, since it's usually far easier to prove obstruction than it is to prove the underlying crimes that were being investigated.
- refurb 6y agoAny relevant case law here? I mean, clearly destroying evidence (e.g. shredding documents) is one thing but I assume it’s harder to prove when it’s a byproduct of computer security? Apple phones can be wiped with 10 invalid password attempts, but the cops already know it. If it’s a piece of custom software that erases a computer after 2 attempts, can the prosecution really claim it was pure evidence destruction? I honestly don’t know, but I’m curious.
- M5x7wI3CmbEem10 6y agodoes encryption offer any benefit if you’re using a cloud syncing solution?
- stjohnswarts 6y agoEveryone should also install a hard power off on the front of their computer and always have encrypted drives. Unrecognized USB storage in my computer also is instant off. Might corrupt my files someday, but it's worth the risk.