Any USB Peripheral Is Now a Potential Threat

A group of Canadian hackers have identified and learned to exploit a flaw that allows them to turn any USB peripheral into a sort of hardware trojan horse. Plug-and-play USB devices follow a consistent rule, the device identifies itself to the PC. The computer, by rule, will believe that a UB device is whatever it claims to be; if a keyboard says it's a camera, the PC will register it as a camera.
This trust-by-default design makes it easy for a modified peripheral to collect or transmit data without raising any alarms. As a proof of concept, the Royal Military College of Canada's John Clark, Sylvain Leblanc and Scott Knight modified the circuitry of a keyboard, empowering it to steal data from the host hard drive and then transmit it via Morse code (using a blinking LED).
It'd be just as simple to equip these rogue USB devices with other methods of transmitting data, such as e-mail or FTP, but the researchers' primary concern was simply to show that it is possible to slip a hardware trojan past a computer's defenses. Hackers and spies could easily swap out a keyboard with a modified one, and no one, not even the PC, would be any wiser. The trojan peripheral could come in any form, including a webcam or even one of those USB coffee-cup warmers. [From: Gizmodo and Download Squad]





Whitney Houston Dead: Singer Dies at 48, Body Found in Beverly Hilton Hotel
Whitney Houston Dead: Stars React to Legend's Sudden Death
Can You Guess This Famous Face?
Tips for flying cheaper in 2012
It's Pink!
Savings Experiment: Snow Removal
The Money Man Behind Rick Santorum: Who Is Foster S. Friess?
Alleged Squatters Found With Drugs, Handgun, Grenades, Pig
There's only one thing to do when the Nürburgring is covered in snow...
Tax Reform in This Election Year: It's Not Likely














Comments
2
Subscribe to commentsbestplaceJul 4th 2010 2:34PM
Wow! I work in the immigration industry and my client data is extremely confidential! I have enough trouble with the fact that the Patriot Act allows he US government to snoop on any data that is stored on a US-based site. Now, however, it seems that the physical security of my computer systems is vital. All anyone has to do is replace your mouse or keyboard with what could be called a "stealth devce" and they can access whatever data they want.
DigiJul 5th 2010 5:31AM
If someone has physical access to your machine they can do anything. The threat with this is that it can be an ongoing threat. But this is already known and shown in concept over at thinkgeek.com . They have a USB Drive that manipulated your keyboard. Im sure you can also get keyloggers off ebay.