Šta je novo?

BadUSB

  • Začetnik teme Začetnik teme kovacm
  • Datum pokretanja Datum pokretanja

kovacm

Čuven
Učlanjen(a)
28.01.2005
Poruke
8,608
Poena
870
Divno!

"napokon" se pojavio virus nalik prvobitnim racunarskim virusima (aka boot sector virusima iz doba Atarija i Amige)!

BadUSB

"A pair of researchers has discovered a flaw in the USB protocol's basic architecture that allows for malware to be programed into a device's firmware, making it nearly undetectable and impossible to patch.

To demonstrate the ubiquitous vulnerability, SR Labs security researchers Karsten Nohl and Jakob Lell created a proof-of-concept called "BadUSB" that can be installed on any universal serial bus device, including memory sticks, keyboards, smartphones and more, to take over a victim's PC, insert or change files, modify DNS settings and otherwise play havoc with host hardware, reports Wired."

...

"There's no way to get the firmware without the help of the firmware, and if you ask the infected firmware, it will just lie to you," Nohl explained.

Most troubling of all, BadUSB-corrupted devices are much harder to disinfect. Reformatting an infected USB stick, for example, will do nothing to remove the malicious programming.

...

Further, BadUSB is bidirectional. In other words, if a malware's payload is coded to do so, a thumb drive can infect a computer's USB firmware, which in turn reprograms the firmware of yet another connected USB device, spreading the code silently across any and all systems. In testing, Nohl and Lell found that basically any USB device is vulnerable to the exploit.


http://arstechnica.com/security/201...uters-badusb-exploit-makes-devices-turn-evil/

http://appleinsider.com/articles/14...n-usb-firmware-to-remain-undetected-unfixable


divota... :/
 
Nista novo, niti preterano interesantno. Ono sto ne vidim da su naglasili (pored fearmongering-a o "undetectable") je na koji se nacin malware siri od USBa do USBa i koje metode koristi da bi sa net-a pokrenuo maliciozni kod i inficirao "patient zero" USB uredjaj.
To je mnogo interesantnije, i bitnije, jer je prevencija bolja od lecenja. Mada verujem da je samo pitanje vremena kad ce AV skeneri dodati podrsku za skeniranje USB firmware-a, jer neki vec imaju podrsku za BIOS/mobo firmware skeniranje. Preduslov je naravno da ovaj tip malware-a postane rasprostranjen ITW.
Pozitivna strana ovoga je sto ce se proizvodjaci USB uredjaja (mozda) probuditi i implementirati sigurnosne provere prilikom manipulacije/update-u firmwware-a, kao sto je slucaj sa UEFI/BIOS iole novijih ploca.
 
Poslednja izmena:
Pročitao pre par dana, ništa novo i neočekivano :d
 
Nazad
Vrh Dno