Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Vulnerabilities

‘BadUSB’ Code Published

Two researchers have released attack code for the ‘BadUSB’ issue first revealed at the Black Hat conference earlier this summer.

Two researchers have released attack code for the ‘BadUSB’ issue first revealed at the Black Hat conference earlier this summer.

Researchers Adam Caudill and Brandon Wilson presented on the vulnerability at Derbycon 4.0 conference last week in Louisville. Wilson and Caudill reversed-engineered USB firmware and reprogrammed it to launch various attacks. They then took the extra step of posting the attack code to GitHub.

“The belief we have is that all of this should be public,” Wired quoted Caudill as telling the audience at Derbycon last week. “It shouldn’t be held back. So we’re releasing everything we’ve got. This was largely inspired by the fact that [SR Labs] didn’t release their material. If you’re going to prove that there’s a flaw, you need to release the material so people can defend against it.”

Among the attack scenarios discussed by Caudill and Wilson are using the USB device to emulate a keyboard and issue commands on behalf of a logged-in user to exfiltrate data or install malware.

The research follows a presentation at Black Hat from researchers Jakob Lell and Karsten Nohl that first revealed the issue. At Black Hat, Nohl and Lell also noted that an attacker could boot a small virus prior to the operating system booting up, or use the device to spoof a network card and alter a computer’s DNS settings to redirect traffic.

The problem, according to the researchers, is that the USB controller chips in peripherals can be reprogrammed to spoof other devices and there’s little or no protection to prevent anyone from doing so.

Advertisement. Scroll to continue reading.

“If the only people who can do this are those with significant budgets, the manufacturers will never do anything about it,” Caudill told Wired. “You have to prove to the world that it’s practical, that anyone can do it…That puts pressure on the manufactures to fix the real issue.”

Related: USB Device Firmware Can Be Reprogrammed to Hide Sophisticated Malware

Written By

Marketing professional with a background in journalism and a focus on IT security.

Click to comment

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Discover strategies for vendor selection, integration to minimize redundancies, and maximizing ROI from your cybersecurity investments. Gain actionable insights to ensure your stack is ready for tomorrow’s challenges.

Register

Dive into critical topics such as incident response, threat intelligence, and attack surface management. Learn how to align cyber resilience plans with business objectives to reduce potential impacts and secure your organization in an ever-evolving threat landscape.

Register

People on the Move

Stephanie Crowe has been appointed head of the Australian Cyber Security Centre (ACSC).

Cloud security giant Wiz has named Fazal Merchant as President and Chief Financial Officer.

Cybersecurity and data protection company Acronis has appointed Gerald Beuchelt as CISO.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.