Protection from Malware on USB Sticks

Discussion in 'other anti-malware software' started by Krusty, Feb 10, 2018.

  1. RockLobster

    RockLobster Registered Member

    Joined:
    Nov 8, 2007
    Posts:
    1,812
    Yes the possibilities are scary, and obviously if it at some point tells the OS it is a also a keyboard, or perhaps a usb hub with multiple devices attatched it can behave as any or all, including sending commands to the OS to install payloads from its own storage.
     
  2. Osaban

    Osaban Registered Member

    Joined:
    Apr 11, 2005
    Posts:
    5,651
    Location:
    Milan and Seoul
    There are times that in my job I have to plug in many USB flash drives (literally hundreds over the last 12 years) and carefully check their contents, I'm not a technician but in my experience they are the most common carriers of malware.

    I do use Sandboxie for browsing safety, but for flash drives in this particular situation whereby I have to save their contents, a combination of virtualization (Shadow Defender) an updated antivirus (Avira) would be my preliminary action. Once I finish my session, I would transfer all these new files (often 2GB) from my virtualized machine to an external drive.

    Once at home the external drive would be further scanned with other tools to make sure it is clean. It goes without saying that most USB sticks were infected, although in the last 5 years they have been fairly clean probably due to the protection afforded by Windows Defender.
     
  3. RockLobster

    RockLobster Registered Member

    Joined:
    Nov 8, 2007
    Posts:
    1,812
    What we need is a way to transfer files securely between devices, specifically online to offline device and vice versa without exposing the offline device to potentially catastrophic malware carrying transfer media. I have an idea, im going to create an android app to test it.
     
  4. ronjor

    ronjor Global Moderator

    Joined:
    Jul 21, 2003
    Posts:
    179,831
    Location:
    Texas
  5. Osaban

    Osaban Registered Member

    Joined:
    Apr 11, 2005
    Posts:
    5,651
    Location:
    Milan and Seoul
  6. Krusty

    Krusty Registered Member

    Joined:
    Feb 3, 2012
    Posts:
    10,491
    Location:
    Among the gum trees
    Interesting analogy.
     
  7. Minimalist

    Minimalist Registered Member

    Joined:
    Jan 6, 2014
    Posts:
    14,909
    Location:
    Slovenia, EU
    The current state of USB data protection
    https://www.helpnetsecurity.com/2018/03/30/usb-data-protection/
     
  8. Minimalist

    Minimalist Registered Member

    Joined:
    Jan 6, 2014
    Posts:
    14,909
    Location:
    Slovenia, EU
    Journalists covering the Trump-Kim summit were given free USB fans — but security experts warn they may be trojan horses full of malware
    http://uk.businessinsider.com/usb-fans-journalists-malware-trump-kim-jong-un-summit-2018-6
     
  9. Krusty

    Krusty Registered Member

    Joined:
    Feb 3, 2012
    Posts:
    10,491
    Location:
    Among the gum trees
    The press kit from the Trump-Kim summit included a USB fan. Experts don't think it's safe
     
  10. Rasheed187

    Rasheed187 Registered Member

    Joined:
    Jul 10, 2004
    Posts:
    18,178
    Location:
    The Netherlands
  11. Minimalist

    Minimalist Registered Member

    Joined:
    Jan 6, 2014
    Posts:
    14,909
    Location:
    Slovenia, EU
    What was on a USB fan given at the Trump-Kim summit? Security experts say nothing —  but don’t plug it in.
    https://www.washingtonpost.com/tech...security-experts-say-nothing-but-dont-plug-it
     
  12. guest

    guest Guest

    USBHarpoon Is a BadUSB Attack with A Twist
    August 20, 2018
    https://www.bleepingcomputer.com/news/security/usbharpoon-is-a-badusb-attack-with-a-twist/
     
  13. guest

    guest Guest

    Schneider Electric may have shipped USB drives infested with malware
    The flash drives were "contaminated" during the manufacturing process.
    September 7, 2018
    https://www.zdnet.com/article/schneider-electric-shipped-usb-drives-infested-with-malware/
     
  14. s279

    s279 Registered Member

    Joined:
    Sep 18, 2018
    Posts:
    1
    Location:
    Australia
    Hi guys

    Long time lurker who wanted to help answer this question. There are some projects out there that are looking to mitigate these trust based attacks (as USB as a standard has implicit trust/no defined security measures).

    One is this project on github
    https://github.com/JLospinoso/beamgun

    Totally not the author, but it does seemingly work as even when I’ve plugged in non-malicious USB-Ethernet or USB HIDs it has waited for user authentication. There are also other variations of this software around.
     
  15. EASTER

    EASTER Registered Member

    Joined:
    Jul 28, 2007
    Posts:
    11,550
    Location:
    U.S.A. (South)
    Thanks for your attention to this and sharing. Might be of some use for some.
     
  16. Minimalist

    Minimalist Registered Member

    Joined:
    Jan 6, 2014
    Posts:
    14,909
    Location:
    Slovenia, EU
    USB threats from malware to miners
    https://securelist.com/usb-threats-from-malware-to-miners/
     
  17. Krusty

    Krusty Registered Member

    Joined:
    Feb 3, 2012
    Posts:
    10,491
    Location:
    Among the gum trees
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.