4 ms·
A student of mine was researching "vendor malware" [0] she decided to order as many random, dodgy USB devices as could be found on the internet to see what perc
by nonrandomstring 3y ago
A student of mine was researching "vendor malware" [0] she decided to
order as many random, dodgy USB devices as could be found on the
internet to see what percentage of them were loaded with horrors.
We settled on a CRU Wiebetech write blocker and a minimal sandboxed
distro (that could reboot to a clean slate in a couple of seconds)
with little more than a kernel for which we could activate and
deactivate USB modules.
Conclusions:
USB is terrifying! :)
Buying USB things in the internet is even more scary!!
[0] https://www.solent.ac.uk/degree-shows/students/helen-plews-2 https://www.solent.ac.uk/degree-shows/students/helen-plews-2
- pests 3y agoInteresting. I expected already used and returned devices but seeing hidden possible firmware and encrypted blobs was a surprise.
- epcoa 3y agoDon’t have the time to dissect the linked PDF, but it has numerous issues including methods that are imprecise, misapplied or simply wrong. It needs a pretty extensive review by an expert. The file signature listings shown on page 80 are most likely spurious (false matches). The first give away is why there would be over 2000 microcode artifacts, the next is that all of the inspected fields are bogus, including the size field (some in the GBs). In theory you could purposefully obfuscate that, but then why would you carry any tell of microcode at all. Much more likely this is just patterned data that happens to match that file magic. Anybody with experience with binwalk knows how common this is. Same goes for the mcrypt(?) headers. Blowfish 448 CBC 8-bit happens to be all 0s. Another very common false positive (matches \x00m\x02). Also look at the offsets carefully. Seems more like a match confusion. As for encrypted appearing data at all, not too surprising if someone is selling used drives and naively wiped them. But it isn’t clear that encrypted vs compressed data was identified. There’s also a fundamental misunderstanding of what a write blocker is/does repeated. "Results indicated the presence of firmware ... in the machine code of the unallocated spaces of the storage device.". Machine code of the unallocated spaces makes no sense. In general: microcode attacks are sophisticated attacks. Anybody carrying these out is unlikely to leave such an obvious smoking gun. Not saying impossible, but it would give any serious researcher pause to scrutinize their work. Also not saying you won’t get shitty crap from random sellers and should buy random junk, but I’d take this paper with a large grain of salt.
- marcusjt 3y agoExcellent (and shocking) research! Rather a shame that page with the abstract has excessively large & linespaced body text which makes it hard to actually read on mobile... that the chat feature assumes you must be a student not anyone else... and the Contact Us is buried many levels deep in the nav... hence me giving up and telling you about the above here.
- tdeck 3y agoIn case folks wondered, it looks like this study focused specifically on flash drives.
- fsflover 3y agoFortunately, my USB controller is isolated into a dedicated, disposable, hardware-virtualized virtual machine (on Qubes OS), so I can insert any USB device without a fear to be owned.