StorageMojo




Robin Harris    




Pandora’s Flash Drive: Beware Free USB Drives

June 9th, 2006 by Robin Harris in SSD/Flash Disk, Security & Public Policy

Chilling story about a security firm’s successful infiltration of a credit union’s infrastructure using old USB flash drives. They wrote a Trojan that would collect “. . . passwords, logins and machine-specific information from the user’s computer, and then email the findings back to us,” put it on the thumb drives and scattered them around the employee parking lot.

The bottom line:

Of the 20 USB drives we planted, 15 were found by employees, and all had been plugged into company computers. The data we obtained helped us to compromise additional systems, and the best part of the whole scheme was its convenience. We never broke a sweat. Everything that needed to happen did, and in a way it was completely transparent to the users, the network, and credit union management.

Of all the social engineering efforts we have performed over the years, I always had to worry about being caught, getting detained by the police, or not getting anything of value. The USB route is really the way to go. With the exception of possibly getting caught when seeding the facility, my chances of having a problem are reduced significantly.

Business Opportunity: Software or Epoxy?”
Do I sense a product opportunity? Software that erases everything on a flash drive that doesn’t have a security certificate? Or how else could one do it?

Or you could sell epoxy glue guns to seal off the USB ports. “Secure Goo” anyone?

Leave a reply



StorageMojo RSS Feed September 2008 August 2008 July 2008 June 2008 May 2008 April 2008 March 2008 February 2008 January 2008 December 2007 November 2007 October 2007 September 2007 August 2007 July 2007 June 2007 May 2007 April 2007 March 2007 February 2007 January 2007 December 2006 November 2006 October 2006 September 2006 August 2006 July 2006 June 2006 May 2006 April 2006 March 2006 June 2005 April 2005 March 2005 February 2005 January 2005 December 2004 November 2004 October 2004 September 2004