Just News

Researchers Hack Laptops & Smartphones Using USB Cable
Ghen posted this item on Jan 20, 2011

Two researchers have figured out a way to attack laptops and smartphones through an innocent-looking USB cable.

cNET News, January 19, 2011: Angelos Stavrou, an assistant professor of computer science at George Mason University, and student Zhaohui Wang wrote software that changes the functionality of the USB driver so that they could launch a surreptitious attack while someone is charging a smartphone or syncing data between a smartphone and a computer. Basically, the exploit works by adding keyboard or mouse functionality to the connection so an attacker can then start typing commands or click the mouse in order to steal files, download additional malware, or do other things to take control of the computer, Stavrou told CNET in an interview. The exploit is enabled because the USB protocol can be used to connect any device to a computing platform without authentication, he said. He and his partner were scheduled to demonstrate an attack at the Black Hat DC conference today.

The exploit software they wrote identifies what operating sysetm is running on the device the USB cable is connected to. On Macintosh and Windows machines, a message pops up saying the system has detected a new human interface device, but there is no easily recognizable way to halt the process, Stavrou said. The Mac pop-up can be quickly removed by an attacker with a command sent via the smartphone so the laptop owner may not even see it, while the Windows pop-up lasts only one or two seconds in the lower left corner, making that an ineffective warning too, he said.

Linux machines offer no warning, so users will have no idea that something out of the ordinary is happening, particularly since the regular keyboard and mouse continue to function normally during an attack, Stavrou said. "The operating system should present a pop-up and ask if the user really wants to connect the device" and specify what type of device is being identified to the system, he said. The researchers wrote the exploit for Android devices only at this point. "It can be done for iPhone, but we didn't do it yet," Stavrou said. "It can work on any computing device that uses USB," and it can work between two smartphones by connecting a USB cable between then, he said. "Say your computer at home is compromised and you compromise your Android phone by connecting them," he said. "Then, whenever you connect the smartphone to another laptop or computing device I can take over that computer also, and then compromise other computers off that Android. It's a viral type of compromise using the USB cable."

The original compromise can happen by downloading the exploit from the Web or running an app that is compromised. The researchers have created exploit software to run on a computer, and an exploit to run on Android that is a modification of the Android operating system kernel. Scripts can then be written for the actual attack. Antivirus software wouldn't necessarily stop this because it can't tell that the activities of the exploit are not controlled or sanctioned by the user, Stavrou said. "It's hard to separate good behavior from bad behavior when it comes from the keyboard," he said. There's not much a person can do to protect against this at this time, according to Stavrou. The operating systems should have the capability for devices to inspect USB traffic and alert users about what exactly is happening over the connection and give them the option of refusing an action, he said.

Two researchers have figured out a way to attack laptops and smartphones through an innocent-looking USB cable.

Angelos Stavrou, an assistant professor of computer science at George Mason University, and student Zhaohui Wang wrote

software that changes the functionality of the USB driver so that they could launch a surreptitious attack while someone is

charging a smartphone or syncing data between a smartphone and a computer.

Basically, the exploit works by adding keyboard or mouse functionality to the connection so an attacker can then start typing

commands or click the mouse in order to steal files, download additional malware, or do other things to take control of the

computer, Stavrou told CNET in an interview. The exploit is enabled because the USB protocol can be used to connect any

device to a computing platform without authentication, he said.

He and his partner were scheduled to demonstrate an attack at the Black Hat DC conference today.

The exploit software they wrote identifies what operating sysetm is running on the device the USB cable is connected to. On

Macintosh and Windows machines, a message pops up saying the system has detected a new human interface device, but there is

no easily recognizable way to halt the process, Stavrou said. The Mac pop-up can be quickly removed by an attacker with a

command sent via the smartphone so the laptop owner may not even see it, while the Windows pop-up lasts only one or two

seconds in the lower left corner, making that an ineffective warning too, he said.

Linux machines offer no warning, so users will have no idea that something out of the ordinary is happening, particularly

since the regular keyboard and mouse continue to function normally during an attack, Stavrou said.

"The operating system should present a pop-up and ask if the user really wants to connect the device" and specify what type

of device is being identified to the system, he said.

The researchers wrote the exploit for Android devices only at this point. "It can be done for iPhone, but we didn't do it

yet," Stavrou said. "It can work on any computing device that uses USB," and it can work between two smartphones by

connecting a USB cable between then, he said.

"Say your computer at home is compromised and you compromise your Android phone by connecting them," he said. "Then, whenever

you connect the smartphone to another laptop or computing device I can take over that computer also, and then compromise

other computers off that Android. It's a viral type of compromise using the USB cable."

The original compromise can happen by downloading the exploit from the Web or running an app that is compromised. The

researchers have created exploit software to run on a computer, and an exploit to run on Android that is a modification of

the Android operating system kernel. Scripts can then be written for the actual attack.

Antivirus software wouldn't necessarily stop this because it can't tell that the activities of the exploit are not controlled

or sanctioned by the user, Stavrou said. "It's hard to separate good behavior from bad behavior when it comes from the

keyboard," he said.

There's not much a person can do to protect against this at this time, according to Stavrou. The operating systems should

have the capability for devices to inspect USB traffic and alert users about what exactly is happening over the connection

and give them the option of refusing an action, he said.

Comments

Saavedro commented on Jan 20, 2011

Wow... is anything safe?


lemon commented on Jan 21, 2011

awesome!


Alpha commented on Jan 21, 2011

Time to develop a usb cable with built in firewall and anti malware protection? I'll see if I can rustle something up ;-) brb!


Post a Comment

Join SpawnPoint for free to comment on this story. Have an account already? to comment.

Latest News

NA BlackShot Europe - The Sniper Update

online FPS BlackShot Europe has been updated with the new “Sniper Update”.

NA Blood Bowl: Chaos Edition

As an ultra-violent team sport inspired by the universe of Warhammer, Blood Bowl lets players recruit a team of Orcs, Elves, Humans, Vampires, Ogres, Dwarves

NA THE TESTAMENT OF SHERLOCK HOLMES

The Testament of Sherlock Holmes, the new investigation game for Xbox® 360, PlayStation® 3 and PC developed by Frogwares, unveils its release date!

NA Game of Thrones: More Battles!

Intense and tactical battles in Game of Thrones pit players against merciless opponents.

NA Anno 2070

The Anno 2070 Experience Gets Deeper

NA R.A.W. - Realms of Ancient War

R.A.W. - Realms of Ancient War will be released on Xbox LIVE®, PlayStation® Network and PC 2nd quarter of 2012.

NA Fantasy Kommander - Eukarion Wars !

They are strong, ruthless and bloodthirsty.

NA CRYSIS 3

Fight in the New York ‘Liberty Dome’, Exploit Seven Natural Wonders and Wield Advanced Alien Weaponry in the Ultimate Sandbox Shooter

NA SLEEPING DOGS

The limited edition pack will be available at all UK games retailers for consumers who pre-order the game.

NA Hard Reset: Extended Edition

Hard Reset: Extended Edition is a classically styled sci-fi first person shooter

NA Defiance

Both a television series on Syfy, and a massive online shooter for PC, the Xbox 360® video game

NA Payday The Heist

Criminal Demands Are Met In Latest Game Update

NA Confrontation

Confrontation, the new tactical role-playing game on PC

NA Greg Hastings Paintball 2

This game features more than 10 single and multiplayer game modes, each staged in all-new paintball fields based on authentic locations from around the world

NA Star Thunder

Flight simulator of the new age is coming