http://www.darkreading.com/mobile-security/167901113/security/client-security/240147566/hacking-the-laptop-docking-station.html
Very slick idea, by NCC Group's Research Director Andy Davis.
NCC link http://www.nccgroup.com/en/our-services/security-testing-audit-compliance/
I suspect Andy Davis prefers to exploit Hardware vulnerabilities, also found this notice about USB Mac Lion exploit discovered by him http://www.securityfocus.com/archive/1/524248/30/0/threaded
It is an "Arbitrary Code Execution (bug triggered by USB device insertion)."
I think (my opinion, no hard data to support) that providing security from Hardware Hacks like this, is a lot harder than defending against more common Computer threats like Phishing, Java exploits, weak passwords, etc.
Not objectively harder, but practically harder, because providing good security form Hardware Hacks requires people with skills from both Physical Security and Computer Security.
As well as budget support from upper management, the hardest type of support to secure.
The budget support is for good vetting and retention of cleaning personnel, I have mentioned this before in relation to hardware attacks,
It is difficult to convince higher management of the Security need to pay 3-5 times more than a business is used to for custodians.
Think Social Engineering attacks, or working as part of cleaning crew, would allow easy placement of device like this.
How many companies care enough
about security to pay good wages to keep good, vetted, in house Custodians vs using a Contractor provided Cleaning Crew?
Those cleaning crews tend to have high turn over, additionally, because of the high turnover, they tend to have low standards for hiring.
They need to keep hiring people that won't be paid much or be treated with much respect, so they tend to hire many people that have problems (criminal records, drug/alcohol, etc).
Even if they use in house custodians, still tends to be a low pay,
low status job, with a lot of turnover, and generally low standards for
hire.
Remember, Custodians or Cleaning Crews tend to have physical access to entire company, heck they are normally given keys.
It is trivially easy for someone on Cleaning Crew to swap out a hacked dock with existing one, or install hardware keyloggers.
Esports & Computer Security Blog. For SC2 tournaments see clocks immediately below. Starts with Korean time at upper left, moves west around the world till you end with PDT/PST clock for Anaheim USA. I earn a small referral fee if you click the occasional Amazon links and then purchase item. It does not affect the purchase price. For more information see "Amazon Associates" link below & left of clocks.
Showing posts with label USB. Show all posts
Showing posts with label USB. Show all posts
Saturday, February 2, 2013
Friday, January 18, 2013
Security & Hacking: Malware 2 Years ago USB Battery Charger Backdoor
Energizer Battery Charger Software Included Backdoor http://krebsonsecurity.com/2010/03/energizer-battery-charger-software-included-backdoor/
Energizer DUO USB battery charger software allows unauthorized remote system access http://www.kb.cert.org/vuls/id/154421
This is from 2010, so certainly not new concept, I hadn't heard of this specific hack before though, & to be honest, don't think I would have expected this, before reading Brian Kreb's article on it.
Though I was aware of the Vodafone issue that some of the Energizer Duo articles/comments mentioned http://research.pandasecurity.com/vodafone-distributes-mariposa/
To be clear, there wasn't Malware on the USB device itself, but in the software you could download from Energizer to monitor the device.
I didn't find any articles explaining how the Malware got inserted into the Energizer software, but some stories suggested it might have been in place for ~3 years.
If anyone has any more detail on this I would be interested in learning it.
Schneier also posted about it http://www.schneier.com/blog/archives/2010/03/back_door_in_ba.html
Energizer DUO USB battery charger software allows unauthorized remote system access http://www.kb.cert.org/vuls/id/154421
This is from 2010, so certainly not new concept, I hadn't heard of this specific hack before though, & to be honest, don't think I would have expected this, before reading Brian Kreb's article on it.
Though I was aware of the Vodafone issue that some of the Energizer Duo articles/comments mentioned http://research.pandasecurity.com/vodafone-distributes-mariposa/
To be clear, there wasn't Malware on the USB device itself, but in the software you could download from Energizer to monitor the device.
I didn't find any articles explaining how the Malware got inserted into the Energizer software, but some stories suggested it might have been in place for ~3 years.
If anyone has any more detail on this I would be interested in learning it.
Schneier also posted about it http://www.schneier.com/blog/archives/2010/03/back_door_in_ba.html
Subscribe to:
Posts (Atom)