5 ms·
Introducing the USB Stick of Death
- bashzor 14y agoI've had an usb stick of death for years now. Any system you plug it in instantly freezes. No idea how I made it, but it was certainly not the goal! And whatever I do, I can't get it to overwrite whatever data is on there :P
- nodata 14y agoUnder Linux, if you get a stack trace they can fix this: they love fuzzing errors.
- chuppo 14y agoPost a stacktrace? You can take a photo for us of the kernel panic.
- bashzor 14y agoIt doesn't crash (no kernel panic), just makes the system so slow that you can't use it anymore until you pull the stick out.
- nitrogen 14y agoI've seen a feature phone do this as well, when "powered off" in charging-only mode.
- k_bx 14y agoif you dd on another usb-drive the same data -- will it stay the same? if yes -- you could post it somewhere and try to get more details etc.
- drivebyacct2 14y agoOh hey, I had one of those too. I eventually smashed it and threw it out because I tired of plugging it in and having slow down problems. (I noticed it first when I was working with the jump drive and had the system grind to a halt. Removed the drive and it immediately unfroze. further testing confirmed)
- Tobu 14y agoBoot Linux, disable automount, make a raw copy using dd, upload somewhere?
- GFischer 14y agoAs a security vulnerability, it's interesting but, as they stated, low-severity. If you have physical access and a local user, it's much easier to use any Linux boot CD and one of the myriad "password recovery" systems. I used Petter N Hagen's http://pogostick.net/~pnh/ntpasswd/ http://pogostick.net/~pnh/ntpasswd/ back in my tech support days (several years ago). The current tech support guy swears by Hiren's BootCD http://www.hiren.info/pages/bootcd http://www.hiren.info/pages/bootcd
- robk 14y agoSeverity isn't that low. If you hand out a USB stick to a friend and they run a .exe on it, you could surely trigger this exploit invisibly. It's probably not a broad vector attack, but surely would fit very well into a spearphishing scenario. Hand this to a less-than-savvy user and either auto-run via .inf (on older OSes) or dupe them into running some arbitrary binary to "unencrypt the volume" or something they wouldn't understand. Many newer USB sticks even have preloaded binaries for the supporting software (SanDisk volume utilities come to mind) - this would be a perfectly innocuous location to load this sort of attack.
- Rastafarian 14y agoBuddy, did you even read the article before commenting?? "andrewaylett: But it's not an autorun vulnerability, that wouldn't be newsworthy -- the problem is that simply mounting the filesystem exploits bugs in the filesystem driver."
- robk 14y agoUnderstood, but to fully _exploit_ the vulnerability one would need to actually execute more code than just triggering the vulnerability presumably.
- chuppo 14y agoYou appear to not understand the concepts you are attempting to participate in a discussion about. To "trigger" the vulnerability is to deliver your exploit code. This USB stick can be inserted into any Windows 7 system and, voila you have your rootkit on that machine, without any user interaction required. No running of .exe files anywhere. You could put some pictures on the usb drive for the user to look at while his system is compromised. (Rootkitted is that a word? Backdoored is.)
- pilif 14y agoI really don't agree with the severity rating. Instant admin-access by just plugging in a USB stick is exactly what malware like the ever-loved Stuxnet use(d) as a jump-start to get their other exploits and backdoors going. It's like the various autorun exploits, but better because you don't need an additional privilege escalation vulnerability and you get to execute your attack even if autorun is turned off completely.
- mistercow 14y agoYeah, the severity rating seems rather oblivious to simple social engineering. Leave a USB stick on a desk with a sticky note attached to it saying "Urgent, please review", and guess what is going to happen to that USB stick. Being able to compromise a system via a mundane and apparently benign action is never low-severity.
- Dylan16807 14y agoYou have to be running an exploit program while you play with the USB stick.
- Evbn 14y agoWas hoping for something like http://etherkiller.org/ http://etherkiller.org/
- wvs 14y agoComing from a *nix background, it seems odd to me that a kernel null dereference would be exploitable from userland. Or that kernel functions be directly addressable from userland. Is kernel memory mapped into user processes on Windows?