Showing posts with label USB. Show all posts
Showing posts with label USB. Show all posts

Saturday, February 2, 2013

Pen Testing & Hardware Hacking: Hacking Laptop Docking Station

http://www.darkreading.com/mobile-security/167901113/security/client-security/240147566/hacking-the-laptop-docking-station.html

Very slick idea, by NCC Group's Research Director Andy Davis.

NCC link http://www.nccgroup.com/en/our-services/security-testing-audit-compliance/

I suspect Andy Davis prefers to exploit Hardware vulnerabilities, also found this notice about USB Mac Lion exploit discovered by him http://www.securityfocus.com/archive/1/524248/30/0/threaded

It is an "Arbitrary Code Execution (bug triggered by USB device insertion)."


I think (my opinion, no hard data to support) that providing security from Hardware Hacks like this, is a lot harder than defending against more common Computer threats like Phishing, Java exploits, weak passwords, etc.

Not objectively harder, but practically harder, because providing good security form Hardware Hacks requires people with skills from both Physical Security and Computer Security.

As well as budget support from upper management, the hardest type of support to secure.

The budget support is for good vetting and retention of cleaning personnel, I have mentioned this before in relation to hardware attacks,

It is difficult to convince higher management of the Security need to pay 3-5 times more than a business is used to for custodians.

Think Social Engineering attacks, or working as part of cleaning crew, would allow easy placement of device like this.

How many companies care enough about security to pay good wages to keep good, vetted, in house Custodians vs using a Contractor provided Cleaning Crew?

Those cleaning crews tend to have high turn over, additionally, because of the high turnover, they tend to have low standards for hiring.

They need to keep hiring people that won't be paid much or be treated with much respect, so they tend to hire many people that have problems (criminal records, drug/alcohol, etc).

Even if they use in house custodians, still tends to be a low pay, low status job, with a lot of turnover, and generally low standards for hire.

Remember, Custodians or Cleaning Crews tend to have physical access to entire company, heck they are normally given keys.

It is trivially easy for someone on Cleaning Crew to swap out a hacked dock with existing one, or install hardware keyloggers.










Friday, January 18, 2013

Security & Hacking: Malware 2 Years ago USB Battery Charger Backdoor

Energizer Battery Charger Software Included Backdoor http://krebsonsecurity.com/2010/03/energizer-battery-charger-software-included-backdoor/

Energizer DUO USB battery charger software allows unauthorized remote system access http://www.kb.cert.org/vuls/id/154421

This is from 2010, so certainly not new concept, I hadn't heard of this specific hack before though, & to be honest, don't think I would have expected this, before reading Brian Kreb's article on it.

Though I was aware of the Vodafone issue that some of the Energizer Duo articles/comments mentioned http://research.pandasecurity.com/vodafone-distributes-mariposa/

To be clear, there wasn't Malware on the USB device itself, but in the software you could download from Energizer to monitor the device.

I didn't find any articles explaining how the Malware got inserted into the Energizer software, but some stories suggested it might have been in place for ~3 years.

If anyone has any more detail on this I would be interested in learning it.

Schneier also posted about it http://www.schneier.com/blog/archives/2010/03/back_door_in_ba.html