Security research Karsten Nohl of Berlin’s SR Labs has revealed a flaw in USB devices that potentially allows hackers to evade all known security measures used by a computer. In a report by Wired, Nohl says his BadUSB exploit is “almost like a magic trick” because “you cannot tell where the virus came from.”
The exploit takes advantage of a flaw that allows a hacker to tamper with the firmware that controls the functions of USB devices such as mice, thumb drives and keyboards.
Because BadUSB resides not in the flash memory storage of USB devices, but in the firmware that controls their basic functions, the attack code can remain hidden long after the contents of the device’s memory would appear to the average user to be deleted. And the two researchers say there’s no easy fix: The kind of compromise they’re demonstrating is nearly impossible to counter without banning the sharing of USB devices or filling your port with superglue.
“These problems can’t be patched,” says Nohl, who will join Lell in presenting the research at the Black Hat security conference in Las Vegas. “We’re exploiting the very way that USB is designed.”
Nohl, along with fellow SR Labs researcher Jakob Lell, will present additional details on this attack during a presentation at the annual Black Hat hacking conference, which will be held next week in Las Vegas. The title of his presentation is “Bad USB – On Accessories that Turn Evil.”
More Stories
Multiple nation-state groups are hacking Microsoft Exchange servers
Multiple government-backed hacking groups are exploiting a recently-patched vulnerability in Microsoft Exchange email servers. (more…)
Happy Birthday Raspberry PI!! New Pricing Celebration
The Raspberry Pi is about to turn eight, having officially launched on February 29, 2012. To celebrate, the Raspberry Pi...
Microsoft Drop’s Window 10 Preview Build 15002 PreRelease
This week was as Geeky as it can get for Windows 10 Insiders. Microsoft release of Build 15002 to the...
Facebook Requiring Government PHOTO ID to unlock accounts
Well after HEARING rumors about Facebook requiring Government issued PHOTO ID verification of accounts. I'd never seen it and now...
Surviving Electmageddon: Protecting against a wave of DNS outages
This is a re-print of an excellent article posted this week regarding setting up multiple DNS addresses. To protect...
Microsoft Announces NEW BUG Bounty Program for Edge
Microsoft is updating it's EDGE bug bounty program. You want to get a chance at microsoft paying you for finding...