Social Engineering, the USB Way

drizzle

Enlightened
Joined
Oct 23, 2003
Messages
840
Location
Seattle, WA
Wow! That's pretty scary. In fact it is really a how to for information thieves. It's not at all like the latest virus that can be analyzed and guarded against. There is no anti-human-nature software out there.
 

KevinL

Flashlight Enthusiast
Joined
Jun 10, 2004
Messages
5,866
Location
At World's End
Wow....

This would be tremendously hard to resist doing even for myself, although I would have plugged it into an off-net machine. Still, even that would have been bad enough.

It's worse if they set it up for autorun (which IS truly evil), and then the people would be screwed by just plugging it in.

But this is not so dissimilar from a problem that used to be pretty bad - just putting an virus infected floppy disk into your computer was enough to trash it. USB drives are the logical successor to floppies...
 

idleprocess

Flashaholic
Joined
Feb 29, 2004
Messages
7,197
Location
decamped
linked article said:
I immediately called my guy that wrote the Trojan and asked if anything was received at his end. Slowly but surely info was being mailed back to him. I would have loved to be on the inside of the building watching as people started plugging the USB drives in, scouring through the planted image files, then unknowingly running our piece of software.

Emphasis added. That last sentence suggests that there was an application the users ran ... either an executable (the fools!) or something designed to look like an image that used some vulnerability to run code.

I have to agree with KevinL - autorun is a downright vile thing from a security perspective ... it silently executes with permissions at least as good as the user's (perhaps greater with the right exploit).
 
Last edited:

bwaites

Flashlight Enthusiast
Joined
Nov 27, 2003
Messages
5,035
Location
Central Washington State
It would have worked even better if they had also used a "you screwed up" screen that 24 hours after they plugged in froze their computers until someone with a management password unlocked.

A big "You remember that USB drive you plugged in yesterday? Well it just shut you down. You must now contact manangement for a new password to reset your system."
That would have been VERY scary for the employee and a lesson not soon forgotten!

Bill
 

tvodrd

*Flashaholic* ,
Joined
Dec 13, 2002
Messages
4,987
Location
Hawthorne, NV
Thanks for the headsup! If I find a USB drive on the sidewalk without the owner's "contact" on it, I'm gonna STOMP it! :D

Larry
 

eluminator

Flashlight Enthusiast
Joined
Mar 7, 2002
Messages
1,750
Location
New Jersey
If someone wants to drop a nice big fast SD card around here, I wouldn't mind. I disable autorun anyway, just to protect my sanity.
 

cy

Flashaholic
Joined
Dec 20, 2003
Messages
8,186
Location
USA
pretty scary how well this would work in most places...
 
Top