Download the Tom's Hardware App from the App Store
The reference for current tech news
Yes No
Ads

Any USB Peripheral is a Potential Security Threat

by - source: Tom's Hardware US

Be careful what you stick it into.

The USB ports on a computer present a security risk. Not only are storage devices able to plug in and interface with the hardware, but also coffee cup warmers, fans, and even mini-vacuums.

A team of computer engineers from Royal Military College of Canada in Kingston, Ontario exploited a weakness in the USB plug-and-play functionality. What the team did was create a fake USB device that reported itself as something that computer already recognized.

For example, if the computer already paired itself with a USB camera, a hacker could spoof the same identity on another device.

As a proof of concept, the team designed a USB keyboard that contained a circuit that stole data from the hard drive and transmitted it by flashing an LED in a morse code-like fashion, as well as through sounds output by the sound card. While such methods are hugely inefficient and likely ineffective, it was just a proof of concept of the vulnerability.

Even though virus scanning software may check USB storage for malware, secretly planted trojans inside USB peripherals will likely be missed.

"We've shown any USB device could contain a hardware trojan," said Sylvain Leblanc, one of the engineers. "You could mount a hardware trojan attack with a USB coffee-cup warmer."

(source: New Scientist.)

Share:
29
Comments
Read more
X
Submit

Comments
Add your comment
cmcghee358 07/09/2010 1:40 PM
Hide
-20+

I guess my computer can get herpes from the USB stripper pole now? Anyone got a USB condom?

icemunk 07/09/2010 1:40 PM
Show
moricon 07/09/2010 2:28 PM
Hide
-5+

Never saw the point of USB coffee cup Warmers, my EX-Boss had one though, placed in front of his keyboard, missed one day and ended up drowning his KB!

azconnie 07/09/2010 2:46 PM
Hide
-11+

cmcghee358 :
I guess my computer can get herpes from the USB stripper pole now? Anyone got a USB condom?


Dose this count?

http://www.tomsguide.com/us/Ben-Ma [...] -7394.html

misry 07/09/2010 2:48 PM
Hide
-4+

Had a client once who actually asked about a "remote" control USB vibrator. Would have been something to brag about if she had looked like almost anyone other than the Granny in Hoodwinked. As it was she was a major reason I got out of retail.

d0gr0ck 07/09/2010 3:04 PM
Hide
-1+

In other news from the Department of Obvious: There's Porn on the Internet!

wotan31 07/09/2010 3:24 PM
Show
LORD_ORION 07/09/2010 3:40 PM
Hide
-1+

You're missing the point. Mafia types have all sorts of knock offs that they sell. It wouldn't be a strech for them to sell a fake MS Basic Opical mouse with a hardware trojan embedded. You would never know your system is comprimisd.

insider3 07/09/2010 4:07 PM
Hide
-1+

Great, next thing you know, keyboards come with firewalls and mice have built in anti-virus protection.

Marco925 07/09/2010 4:27 PM
Hide
-6+

I can only imagine what the USB humping dog will bring to my computer O_O

requiemsallure 07/09/2010 5:25 PM
Hide
-1+

why not just keep your computer away from people who like to do things like that? physical security over your things would fix this...

dark_lord69 07/09/2010 5:26 PM
Hide
--2+

Lame...

AMDnoob 07/09/2010 5:26 PM
Hide
--1+

So... should I have every USB port on my computer padlocked?

Honis 07/09/2010 5:48 PM
Hide
-0+

This is more a warning to companies. It's a proof of concept that someone can take the mass produced generic keyboards from Dell/HP/etc. embed a custom circuit and gain access to any PC where they can swap the keyboards. The next time the user logs in bang! full access to the PC.

the_krasno 07/09/2010 5:51 PM
Hide
-1+

AMDnoob :
So... should I have every USB port on my computer padlocked?



No, it means that you should be wary when using a thumb drive from an unknown brand or maker.

dman3k 07/09/2010 7:31 PM
Hide
-0+

I want that usb pole dancer!

jhansonxi 07/09/2010 7:55 PM
Hide
-2+

wotan31 :
Everything is a potential security threat when you run a swiss-cheese of an OS, like Windoze.

I've seen a USB storage device that emulates a keyboard and mouse that was designed to install malware on any system it is plugged into. If the system automatically activates any USB-connected keyboards andthe active user's account can create/edit/execute any program (including .bat, .cmd, .vbs, .sh) then it is vulnerable. On most systems it can take over in about 3 seconds. It can't easily get root on a Linux system but can install keyloggers or exploit known daemon security holes. On Windows it can respond to the security dialogs.

eklipz330 07/09/2010 10:44 PM
Hide
--1+

Quote :Be careful what you stick it into.


THAT'S WHAT SHE SAID

maestintaolius 07/10/2010 3:14 AM
Hide
-1+

jhansonxi :
I've seen a USB storage device that emulates a keyboard and mouse that was designed to install malware on any system it is plugged into. If the system automatically activates any USB-connected keyboards andthe active user's account can create/edit/execute any program (including .bat, .cmd, .vbs, .sh) then it is vulnerable. On most systems it can take over in about 3 seconds. It can't easily get root on a Linux system but can install keyloggers or exploit known daemon security holes. On Windows it can respond to the security dialogs.


Exactly, it's not that hard to hack a system if you actually get physical access, regardless of the OS. Especially if it's a device that you can convince the user they need to install additional software in order to get full use of the device.

chickenhoagie 07/10/2010 3:16 AM
Hide
--2+

i suppose this article is for people that ARENT tech savvy..

f-14 07/10/2010 6:33 AM
Hide
-0+

Honis 07/09/2010 5:48 PM Hide -1+
This is more a warning to companies. It's a proof of concept that someone can take the mass produced generic keyboards from Dell/HP/etc. embed a custom circuit and gain access to any PC where they can swap the keyboards. The next time the user logs in bang! full access to the PC.

too bad this wasn't pointed out to express scripts 2 years ago when some one took their entire user data base, then they wouldn't have to put out a 5 million dollar reward for info leading to an arrest.
thanks toms, but this is old news.

dEAne 07/10/2010 9:20 AM
Hide
-1+

Yeah that was true but at least now they expose it.

Anonymous 07/10/2010 6:09 PM
Hide
-2+

That's what happens when you contract everything to Communist China.

Josea 07/10/2010 8:05 PM
Hide
--2+

I worked on computers for a major utility until a recent layoff. Of the 100's of people I asked only 1 refused to give me their network password (so I reset it to mummy becasue the network admin gave me the network admin password and installed the tools needed to reset passwords). Soon thereafter he was promoted to wireless security admin and I got the shaft. Does anyone have a link where I can get the aforementioned keyboard?

climber 07/11/2010 12:10 PM
Hide
--1+

I situation where I can see widespread possibilities of stealing data is the notebook coolers (pads) that have active fans in the underlying heatsink surface. These fans plug into the laptop via USB cables often times. If such a company selling these kinds of notebook coolers were say to be infiltrated by a government and such trojan hardware tech installed, many thousands or tens of thousands could be at risk. A very disastrous situation if say corporations were to recommend using such notebook coolers to preserve notebook like, unbeknown-st to the corporation.

aaron686 07/12/2010 6:56 AM
Hide
--1+

My First Impression:
1)Picture of a scantily clad pole dancer.
2)"Be careful what you stick it into."
3)STD's are real people.

rotsae 07/12/2010 1:10 PM
Hide
--1+

What a minute college kids finally find out about this? Their parents must be crying when they find out where all that money is going to.

Zingam 07/12/2010 2:01 PM
Hide
--1+

It's a matter of simple logic and experience: you should never put just any kinds of sticks in your wholes!

Zingam 07/12/2010 2:02 PM
Hide
--1+

climber :
I situation where I can see widespread possibilities of stealing data is the notebook coolers (pads) that have active fans in the underlying heatsink surface. These fans plug into the laptop via USB cables often times. If such a company selling these kinds of notebook coolers were say to be infiltrated by a government and such trojan hardware tech installed, many thousands or tens of thousands could be at risk. A very disastrous situation if say corporations were to recommend using such notebook coolers to preserve notebook like, unbeknown-st to the corporation.




Funny! Wouldn't it be much easier if the government etc... wrongdoers just cooperate with Microsoft to tell them their backdoors to Windows OS?

Ads

Best offers

Newsletters


OK
Ads