Author Topic: New USB Devices Infected  (Read 1666 times)

0 Members and 1 Guest are viewing this topic.

Offline mikey

  • Predator
  • Malware Experts
  • Jr. Member
  • *****
  • Posts: 81
    • VOP
New USB Devices Infected
« on: January 12, 2008, 07:40:26 PM »
It seems that folks are being infected when plugging in new devices. Be carefull with that Xmas gift, it may corrupt your sys.

Ref; http://isc.sans.org/diary.html?storyid=3787

Ref; http://isc.sans.org/diary.html?storyid=3807

Ref; http://isc.sans.org/diary.html?storyid=3817

Ref; http://www.securityfocus.com/news/11499
***
W2K/2K3/XP/2K8/Vista/W7/RHE/DEBIAN/SUSE

"Spyware/adware is NOT freeware, it costs all of us dearly." SpywareWarrior

Mikey's Stuff

Fiddler and friends...essential web diagnostic, forensic, & development tools.

"You may never need to outrun a Decepticon, but it's nice to know you can." NW's Bevo

Online Corrine

  • The Mystical Rose
  • Administrator
  • Hero Member
  • *****
  • Posts: 11541
  • "Stronger than the past, united in our goal."
    • Security Garden
Re: New USB Devices Infected
« Reply #1 on: January 14, 2008, 01:37:11 AM »
,  

Take a walk through the "Security Garden" -- Where Everything is Coming up Roses!

Remember - A day without laughter is a day wasted.
May the wind sing to you and the sun rise in your heart.

Offline mikey

  • Predator
  • Malware Experts
  • Jr. Member
  • *****
  • Posts: 81
    • VOP
Re: New USB Devices Infected
« Reply #2 on: January 14, 2008, 02:44:41 AM »
My comment from another thread on the same subject;

Some have suggested turning off the 'autorun/autoplay' feature in Windows, which really is a good idea regardless of this prob. However, like your sandbox querry, I don't believe that to be satisfactory security and here is an exerpt from a MS TechNet article that explains exactly why;

Quote
Many USB controllers are actually Direct Memory Access (DMA) devices. This means they can bypass the operating system and directly read and write memory on the computer. Bypass the OS and you bypass the security controls it provides—now you have complete and unfettered access to the hardware. This renders device control implemented by the OS completely ineffective.

Ref; http://www.microsoft.com/technet/technetmag/issues/2008/01/SecurityWatch/default.aspx
***
W2K/2K3/XP/2K8/Vista/W7/RHE/DEBIAN/SUSE

"Spyware/adware is NOT freeware, it costs all of us dearly." SpywareWarrior

Mikey's Stuff

Fiddler and friends...essential web diagnostic, forensic, & development tools.

"You may never need to outrun a Decepticon, but it's nice to know you can." NW's Bevo