Warning

 

Close
Confirm Action

Are you sure you wish to do this?

Cancel Confirm
AR15.COM
9/3/2014 8:48:33 PM EDT
One of my instructors mentioned a USB virus in class today... transmitted via the firmware of the USB drive, it can take your computer over.

Anyone heard about this? I googled it and got a lot of hooey.

Edit.. this is true, see Chokey's post below.
9/3/2014 8:54:13 PM EDT
[#1]
true









 
9/3/2014 8:57:49 PM EDT
[#2]
Just like you shouldn't put your dick is strange places, don't put strange USB devices you find lying around into your PC.
9/3/2014 9:17:48 PM EDT
[#3]
I believe there were several thousand, hundred thousand, USB drives that were manufactured in China where the master for the USB chip memory had a virus on it....thus every USB device made had the virus too.    

It was an isolated incident according to Chinese government.  But internet routers have been made with virus or malware built into them and China made a bunch of toasters with IP sniffing hardware/software to map, access, and keylog unsecured wireless networks in Russia and Europe.  Don't believe anyone in the toaster factory thought a WiFi card  would make a heating element work better.

China shipped a bunch of am/fm radios that were actually trancevers that broadcast audio from the location the radios were used..even broadcast on lesser USD frequency.  I believe I have seen a report for automated commercial bathroom air fresheners being a security concern.  Air freshener had a recording that played a voice recording to indicate the canister or batteries needed changed.....and the device could record conversations and be downloaded later.
9/3/2014 9:18:51 PM EDT
[#4]
Quote History
Quoted:
Just like you shouldn't put your dick is strange places, don't put strange USB devices you find lying around into your PC.
View Quote


What sucks is, if a student is at school and transporting schoolwork files to and from ... they'd need to plug in to the school computers.

I may look in to a cloud storage solution to avoid this!

9/3/2014 9:30:30 PM EDT
[#5]
Quote History
Quoted:


What sucks is, if a student is at school and transporting schoolwork files to and from ... they'd need to plug in to the school computers.

I may look in to a cloud storage solution to avoid this!

View Quote View All Quotes
View All Quotes
Quote History
Quoted:
Quoted:
Just like you shouldn't put your dick is strange places, don't put strange USB devices you find lying around into your PC.


What sucks is, if a student is at school and transporting schoolwork files to and from ... they'd need to plug in to the school computers.

I may look in to a cloud storage solution to avoid this!



Yep, it's all about minimising risk. USBs have issues (for example, USBs were used for the Stuxnet virus) but so does cloud storage (ask JLaw). You could use email to transfer files, but again, there's the same issue as with cloud storage.

The best thing you can really do is have good, up to date security software. Think of it like home security - if someone really wants to get in, they will. You're just trying to make your house look tougher than another.
9/3/2014 9:45:11 PM EDT
[#6]
No way I'm gonna open this....














nvm.
9/4/2014 10:29:53 AM EDT
[#7]
Quote History
Quoted:


Yep, it's all about minimising risk. USBs have issues (for example, USBs were used for the Stuxnet virus) but so does cloud storage (ask JLaw). You could use email to transfer files, but again, there's the same issue as with cloud storage.

The best thing you can really do is have good, up to date security software. Think of it like home security - if someone really wants to get in, they will. You're just trying to make your house look tougher than another.
View Quote View All Quotes
View All Quotes
Quote History
Quoted:
Quoted:
Quoted:
Just like you shouldn't put your dick is strange places, don't put strange USB devices you find lying around into your PC.


What sucks is, if a student is at school and transporting schoolwork files to and from ... they'd need to plug in to the school computers.

I may look in to a cloud storage solution to avoid this!



Yep, it's all about minimising risk. USBs have issues (for example, USBs were used for the Stuxnet virus) but so does cloud storage (ask JLaw). You could use email to transfer files, but again, there's the same issue as with cloud storage.

The best thing you can really do is have good, up to date security software. Think of it like home security - if someone really wants to get in, they will. You're just trying to make your house look tougher than another.


Yeah. I need to remind myself, despite all the security, people still rob banks.
9/4/2014 10:43:32 AM EDT
[#8]
Quote History
Quoted:
Just like you shouldn't put your dick is strange places, don't put strange USB devices you find lying around into your PC.
View Quote


Corporate HQ IT sent my office like 20 thumbdrives.  Our local IT guy then just conveniently dropped them where my coworkers could find them.  They were set up with a "phone home" type program.  18 of them were plugged into USB ports without even checking with the local IT guy first.



9/4/2014 10:49:36 AM EDT
[#9]
Anything made in China that has electronic circuitry has the potential to be carrying malware.  The Chinese are attacking us hourly and from many many attack vectors - USB firmware is just one.
9/4/2014 1:40:47 PM EDT
[#10]
Quote History
Quoted:


Corporate HQ IT sent my office like 20 thumbdrives.  Our local IT guy then just conveniently dropped them where my coworkers could find them.  They were set up with a "phone home" type program.  18 of them were plugged into USB ports without even checking with the local IT guy first.



View Quote View All Quotes
View All Quotes
Quote History
Quoted:
Quoted:
Just like you shouldn't put your dick is strange places, don't put strange USB devices you find lying around into your PC.


Corporate HQ IT sent my office like 20 thumbdrives.  Our local IT guy then just conveniently dropped them where my coworkers could find them.  They were set up with a "phone home" type program.  18 of them were plugged into USB ports without even checking with the local IT guy first.




So you failed the test?
9/4/2014 1:43:49 PM EDT
[#11]
This has been a threat for years.
9/4/2014 2:31:12 PM EDT
[#12]
It's not just limited to thumb drives.

The vulnerability is in the basic USB standard-even a keyboard can be infected.

Most likely the vector that Snowden was referring to with NSA being in everything.



Nick
9/4/2014 2:42:35 PM EDT
[#13]
Quote History
Quoted:
This has been a threat for years.
View Quote


This.. 10 years ago I worked for a company setting up hardware/networks/servers for Banks. The IT Department of one of our clients conducted a test at their branches by dropping infected USB drives out side the door of the bank to prove to the board they needed to make changes to their security policy's and configuration... Worked like a charm. People would pick them up and immediately plug it in to see what was on it.
9/4/2014 5:01:02 PM EDT
[#14]
I worked at a PC builder for a while.  We got mice in these 10x10x10 cubes.  There would be one original driver disk and 999 copies of it.  Apparently the mass duplicator was infected and every PC we sent out (well, 99.9% of them) were infected.  Yes, mouse drivers on a disk.  It was back in the day.