New USB Devices Infected

Started by mikey, January 12, 2008, 08:40:26 PM

Previous topic - Next topic

0 Members and 1 Guest are viewing this topic.

mikey

It seems that folks are being infected when plugging in new devices. Be carefull with that Xmas gift, it may corrupt your sys.

Ref; http://isc.sans.org/diary.html?storyid=3787

Ref; http://isc.sans.org/diary.html?storyid=3807

Ref; http://isc.sans.org/diary.html?storyid=3817

Ref; http://www.securityfocus.com/news/11499
***
W2K/2K3/XP/2K8/Vista/W7/RHE/DEBIAN/SUSE

"Spyware/adware is NOT freeware, it costs all of us dearly." SpywareWarrior

Mikey's Stuff

Fiddler and friends...essential web diagnostic, forensic, & development tools.

"You may never need to outrun a Decepticon, but it's nice to know you can." NW's Bevo

Corrine



Take a walk through the "Security Garden" -- Where Everything is Coming up Roses!

Remember - A day without laughter is a day wasted.
May the wind sing to you and the sun rise in your heart.

mikey

My comment from another thread on the same subject;


Some have suggested turning off the 'autorun/autoplay' feature in Windows, which really is a good idea regardless of this prob. However, like your sandbox querry, I don't believe that to be satisfactory security and here is an exerpt from a MS TechNet article that explains exactly why;

QuoteMany USB controllers are actually Direct Memory Access (DMA) devices. This means they can bypass the operating system and directly read and write memory on the computer. Bypass the OS and you bypass the security controls it provides—now you have complete and unfettered access to the hardware. This renders device control implemented by the OS completely ineffective.

Ref; http://www.microsoft.com/technet/technetmag/issues/2008/01/SecurityWatch/default.aspx
***
W2K/2K3/XP/2K8/Vista/W7/RHE/DEBIAN/SUSE

"Spyware/adware is NOT freeware, it costs all of us dearly." SpywareWarrior

Mikey's Stuff

Fiddler and friends...essential web diagnostic, forensic, & development tools.

"You may never need to outrun a Decepticon, but it's nice to know you can." NW's Bevo