Warning : USB Chip Security Breach

The Crewroom for non-FS related stuff, fun and general chat.

Moderators: Guru's, The Ministry

Post Reply
User avatar
airboatr
Red Arrows
Red Arrows
Posts: 6839
Joined: 25 Oct 2007, 07:17

Warning : USB Chip Security Breach

Post by airboatr »

Hi All.

I thought I should post this in ES instead of in the Spanner section as it may get overlooked.

The chips in USB devices have been found to have a serious flaw which expose them to malicious types who want to ruin your day.
From thumb drives to printers. - All USB devices.
For now all we can do is be careful what you plug in your PC.
The thumb drives (memory stick) have been known to be a tool to spread a virus and other malicious tools used to take control of a PC.
But now that the chips themselves have been hacked , the playing field is a much more wider and dangerous one.

I don't have a link I'll post as I think it would be better if you google it on yahoo ( ;) ) or whatever and learn about this flaw.
It's not, "chicken do little the sky is falling" thing yet ,but it's something you should be aware of, and keep yourself safe.


Joe

dodger
Concorde
Concorde
Posts: 1518
Joined: 21 Nov 2010, 23:38
Location: Devon UK

Re: Warning : USB Chip Security Breach

Post by dodger »

Hi Joe,

Thanks for the Warning, something to keep an eye on,

I will not post what i would do with these Hackers if i could catch them as i would get banned!!!

Roger.
Better to remain silent and be thought a fool than to speak out and remove all doubt.

User avatar
Tomliner
Red Arrows
Red Arrows
Posts: 5738
Joined: 02 Apr 2006, 12:00
Location: Edinburgh UK

Re: Warning : USB Chip Security Breach

Post by Tomliner »

Roger I think that you would more likely to be knighted than banned! :) EricT
Now at the age where I know I like girls but can't remember why!

User avatar
Garry Russell
The Ministry
Posts: 27180
Joined: 29 Jan 2005, 00:53
Location: On the other side of the wall

Re: Warning : USB Chip Security Breach

Post by Garry Russell »

Sir Roger the Dodger...has a nice ring to it. :)
Garry

Image

"In the world of virtual reality things are not always what they seem."

User avatar
DaveB
The Ministry
Posts: 30457
Joined: 17 Jun 2004, 20:46
Location: Pelsall, West Mids, UK
Contact:

Re: Warning : USB Chip Security Breach

Post by DaveB »

Indeed it does! :lol:

Does this flaw only apply to devices that are 'downloaded to'? I never download to a USB stick and only really use the one I have when Win7/XP/Vista aren't talking over the network (which doesn't happen often I have to say).

ATB
DaveB B)smk
ImageImage
Old sailors never die.. they just smell that way!

User avatar
TSR2
The Ministry
Posts: 16762
Joined: 17 Jun 2004, 14:32
Location: North Tyneside, UK
Contact:

Re: Warning : USB Chip Security Breach

Post by TSR2 »

The flaw is where someone makes a dodgy device, not something that's installed on a memory stick.
Ben.:tunes:

ImageImageImage

User avatar
airboatr
Red Arrows
Red Arrows
Posts: 6839
Joined: 25 Oct 2007, 07:17

Re: Warning : USB Chip Security Breach

Post by airboatr »

Hi Ben,.... Dave ;)

From what I gather the flaw is in the chip itself that communicate with a PC that identifies itself as a -Printer , or phone, or memory stick. So it's any device that is USB. ((Phones can be made to be seen as a networking device and such :-O ))

The memory Sticks do of course have more vulnerabilities because a virus can be installed onto them in the partition the software is installed that make them work.
So formatting the usable partition won't remove the virus.

OK :OT:
I learned a little about memory stick partitions not too long ago when one of my USB sticks became corrupted during a file transfer.

During the transfer the device locked up and sat idle for hours. I canceled the process and then unplugged it from the usb port - After the PC shut down.
When I plugged it back in after booting up the PC Windows said the device need to be formatted, - I chose to format.
Then a dialog box popped up telling me windows didn't recognized the file type.
A tried several times to format it, but the same message popped up.
I talked with several people I know (Microsoft certified) about it, A couple of them gave me software tools they thought might fix it, but they all told me they'd never gotten one sorted.
...But I just couldn't/wouldn't accept it wasn't fixable.
So I searched and searched the internet reading through dozens of threads where some had fixed the problem. unfortunatly, none of their solutions worked for me.
I gave up on it for a few weeks, then started looking again.
I happened across an obscure thread within the manufactures (Patriot) web site and found a tool that is a low level formatting process of the entire stick.
(Big Warning about destroying any chance of repair using the tool,) It's the process all sticks have done to them after assembly.
So I held my breath and let her rip.
Bing Bang Boom! FIXED.. :Dance:
Apparently the partitions were damaged,
...
Now of course "Rick", a 25 year certified IT Networking "bloke" I've known for a few years and have fixed a number of his cars he buys and sells , said .....
"Just throw it away and buy a new one,, GAWD! 8) ). ... Suffice to say he is a bit more reluctant to throw down a gauntlet in front of me now.. after paying up the 10 bucks I bet him .. That I could fix it... and this is the reason why I believed I could
A file recovery program did recover files off the stick before I fixed it.. and if it could do that. It had to be fixable.. It just had to be fixable!! I thought to myself. *-)
It just had to be! .. and as you know now. it was - and is.

:$
:wasntme:

:lol:

User avatar
Airspeed
The Reds & Concorde
The Reds & Concorde
Posts: 10372
Joined: 14 Sep 2011, 03:46
Location: Central Victorian Highlands, Dja Dja Wurrung Country, Australia
Contact:

Re: Warning : USB Chip Security Breach

Post by Airspeed »

Joe :welldone:
Perseverance is powerful. ;)
Thanks for the warning.
Hopefully big brand names are OK.
A young woman was killed here not long ago by a cheap USB charger, sitting in bed with her laptop. :(
Cheers, Mike.
Perspective determines interpretation.
Image

http://airspeedsflyingvisit.threadwings ... index.html

J0hn
Concorde
Concorde
Posts: 1175
Joined: 20 Jul 2008, 18:22

Re: Warning : USB Chip Security Breach

Post by J0hn »

This is something that's been known about for some time, just not been banded about in the public domain. There's no need for panic, though - just take your normal precautions and you may manage to avoid this.

It's one of the reasons that a recent purchase from China, of a 'labelled' product that turned up without said label on the side, is still sitting on the shelf in front of me, in its packaging.

This is the genuine article:

http://www.essexham.co.uk/news/realtek- ... ounds.html

I've posted about it on here before iirc.

Here's the one I ordered - it's the first one at the top of the list on the above page, so might be genuine:

http://www.amazon.co.uk/dp/B009VBUYA0/?tag=sxham-21

However, it has no Keedox brand name anywhere on the device, at all. If you look at the pic's on Amazon, it should have. An email to Keedox to ask how to confirm it was genuine has been ignored.

It's a good example of what to watch for - and is now an £11 paper weight (and not a very good one). Just use your noddle and you should be okay. Although your wallet might end up a little lighter with nought to show for it :lol:

User avatar
TSR2
The Ministry
Posts: 16762
Joined: 17 Jun 2004, 14:32
Location: North Tyneside, UK
Contact:

Re: Warning : USB Chip Security Breach

Post by TSR2 »

That's a good point John, in theory any device could be modified such that when you connect it, it gets up to no good. The last talk I heard was even a TV or BluRay player with HDMI could be compromised if someone had the desire.
Ben.:tunes:

ImageImageImage

Post Reply