Author Topic: BadUSB - reason to worry?  (Read 2060 times)

0 Members and 1 Guest are viewing this topic.

Offline rowdy

  • HHKB Hapster
  • * Erudite Elder
  • Thread Starter
  • Posts: 21175
  • Location: melbourne.vic.au
  • Missed another sale.
BadUSB - reason to worry?
« on: Thu, 25 June 2015, 05:41:25 »
This has been around for a little while: https://srlabs.de/badusb/

(Search for yourself for more matches.)

Basically a USB controller on any device can be programmed to emulate a keyboard, and can, for example, send keystrokes to the host computer at a nominated time to disable antivirus, open firewall ports, and do pretty much anything else that you can do via keyboard commands.

I recently got a new USB memory stick, my first new one for many years, certainly the first one I have bought since long before BadUSB was a thing.

Now I'm worried, or perhaps a little paranoid.  The device in question is a generic made in China Target brand 16GB SUB stick.

Has anyone here suffered a BadUSB event?
"Because keyboards are accessories to PC makers, they focus on minimizing the manufacturing costs. But that’s incorrect. It’s in HHKB’s slogan, but when America’s cowboys were in the middle of a trip and their horse died, they would leave the horse there. But even if they were in the middle of a desert, they would take their saddle with them. The horse was a consumable good, but the saddle was an interface that their bodies had gotten used to. In the same vein, PCs are consumable goods, while keyboards are important interfaces." - Eiiti Wada

NEC APC-H4100E | Ducky DK9008 Shine MX blue LED red | Ducky DK9008 Shine MX blue LED green | Link 900243-08 | CM QFR MX black | KeyCool 87 white MX reds | HHKB 2 Pro | Model M 02-Mar-1993 | Model M 29-Nov-1995 | CM Trigger (broken) | CM QFS MX green | Ducky DK9087 Shine 3 TKL Yellow Edition MX black | Lexmark SSK 21-Apr-1994 | IBM SSK 13-Oct-1987 | CODE TKL MX clear | Model M 122 01-Jun-1988

Ị̸͚̯̲́ͤ̃͑̇̑ͯ̊̂͟ͅs̞͚̩͉̝̪̲͗͊ͪ̽̚̚ ̭̦͖͕̑́͌ͬͩ͟t̷̻͔̙̑͟h̹̠̼͋ͤ͋i̤̜̣̦̱̫͈͔̞ͭ͑ͥ̌̔s̬͔͎̍̈ͥͫ̐̾ͣ̔̇͘ͅ ̩̘̼͆̐̕e̞̰͓̲̺̎͐̏ͬ̓̅̾͠͝ͅv̶̰͕̱̞̥̍ͣ̄̕e͕͙͖̬̜͓͎̤̊ͭ͐͝ṇ̰͎̱̤̟̭ͫ͌̌͢͠ͅ ̳̥̦ͮ̐ͤ̎̊ͣ͡͡n̤̜̙̺̪̒͜e̶̻̦̿ͮ̂̀c̝̘̝͖̠̖͐ͨͪ̈̐͌ͩ̀e̷̥͇̋ͦs̢̡̤ͤͤͯ͜s͈̠̉̑͘a̱͕̗͖̳̥̺ͬͦͧ͆̌̑͡r̶̟̖̈͘ỷ̮̦̩͙͔ͫ̾ͬ̔ͬͮ̌?̵̘͇͔͙ͥͪ͞ͅ

Offline sethk_

  • Grand Master Wizard Pizza
  • * Esteemed Elder
  • Posts: 2710
  • Location: Pittsburgh, Pennsylvania
  • www.kbdhub.com
    • My webstore
Re: BadUSB - reason to worry?
« Reply #1 on: Thu, 25 June 2015, 05:55:42 »
I haven't personally, is there any way to check reviews for yours

Offline rowdy

  • HHKB Hapster
  • * Erudite Elder
  • Thread Starter
  • Posts: 21175
  • Location: melbourne.vic.au
  • Missed another sale.
Re: BadUSB - reason to worry?
« Reply #2 on: Thu, 25 June 2015, 06:17:50 »
I don't think so.  If the USB stick has malware in its firmware, there is nothing you can do about it.  Even formatting the USB stick doesn't affect the firmware, as I saw in a video somewhere.

Something that can inspect and reprogram the firmware on a USB controller could probably detect and remove it, but I have nothing remotely like that.
"Because keyboards are accessories to PC makers, they focus on minimizing the manufacturing costs. But that’s incorrect. It’s in HHKB’s slogan, but when America’s cowboys were in the middle of a trip and their horse died, they would leave the horse there. But even if they were in the middle of a desert, they would take their saddle with them. The horse was a consumable good, but the saddle was an interface that their bodies had gotten used to. In the same vein, PCs are consumable goods, while keyboards are important interfaces." - Eiiti Wada

NEC APC-H4100E | Ducky DK9008 Shine MX blue LED red | Ducky DK9008 Shine MX blue LED green | Link 900243-08 | CM QFR MX black | KeyCool 87 white MX reds | HHKB 2 Pro | Model M 02-Mar-1993 | Model M 29-Nov-1995 | CM Trigger (broken) | CM QFS MX green | Ducky DK9087 Shine 3 TKL Yellow Edition MX black | Lexmark SSK 21-Apr-1994 | IBM SSK 13-Oct-1987 | CODE TKL MX clear | Model M 122 01-Jun-1988

Ị̸͚̯̲́ͤ̃͑̇̑ͯ̊̂͟ͅs̞͚̩͉̝̪̲͗͊ͪ̽̚̚ ̭̦͖͕̑́͌ͬͩ͟t̷̻͔̙̑͟h̹̠̼͋ͤ͋i̤̜̣̦̱̫͈͔̞ͭ͑ͥ̌̔s̬͔͎̍̈ͥͫ̐̾ͣ̔̇͘ͅ ̩̘̼͆̐̕e̞̰͓̲̺̎͐̏ͬ̓̅̾͠͝ͅv̶̰͕̱̞̥̍ͣ̄̕e͕͙͖̬̜͓͎̤̊ͭ͐͝ṇ̰͎̱̤̟̭ͫ͌̌͢͠ͅ ̳̥̦ͮ̐ͤ̎̊ͣ͡͡n̤̜̙̺̪̒͜e̶̻̦̿ͮ̂̀c̝̘̝͖̠̖͐ͨͪ̈̐͌ͩ̀e̷̥͇̋ͦs̢̡̤ͤͤͯ͜s͈̠̉̑͘a̱͕̗͖̳̥̺ͬͦͧ͆̌̑͡r̶̟̖̈͘ỷ̮̦̩͙͔ͫ̾ͬ̔ͬͮ̌?̵̘͇͔͙ͥͪ͞ͅ

Offline fanpeople

  • Posts: 970
Re: BadUSB - reason to worry?
« Reply #3 on: Thu, 25 June 2015, 06:25:57 »
Where did you get the USB from?

It would be interesting to see stats on something like this but it would be hard to gather considering most home users wouldn't really have a centralised organisation to report to for the purpose of data collection. Most people would just assume their computer committed suicide, I know that is what I would assume.

Hey if any hacker wants my negative $20,000 they are welcome to it  :p. Don't even need BadUSB, you can have my $170 parking ticket also if you like (got that one for parking on the strip out the front of my house, that's what I get for being considerate of the bus that goes down the tight street that I live on).


Offline rowdy

  • HHKB Hapster
  • * Erudite Elder
  • Thread Starter
  • Posts: 21175
  • Location: melbourne.vic.au
  • Missed another sale.
Re: BadUSB - reason to worry?
« Reply #4 on: Thu, 25 June 2015, 15:15:39 »
Where did you get the USB from?

It would be interesting to see stats on something like this but it would be hard to gather considering most home users wouldn't really have a centralised organisation to report to for the purpose of data collection. Most people would just assume their computer committed suicide, I know that is what I would assume.

Hey if any hacker wants my negative $20,000 they are welcome to it  :p. Don't even need BadUSB, you can have my $170 parking ticket also if you like (got that one for parking on the strip out the front of my house, that's what I get for being considerate of the bus that goes down the tight street that I live on).

Target.
"Because keyboards are accessories to PC makers, they focus on minimizing the manufacturing costs. But that’s incorrect. It’s in HHKB’s slogan, but when America’s cowboys were in the middle of a trip and their horse died, they would leave the horse there. But even if they were in the middle of a desert, they would take their saddle with them. The horse was a consumable good, but the saddle was an interface that their bodies had gotten used to. In the same vein, PCs are consumable goods, while keyboards are important interfaces." - Eiiti Wada

NEC APC-H4100E | Ducky DK9008 Shine MX blue LED red | Ducky DK9008 Shine MX blue LED green | Link 900243-08 | CM QFR MX black | KeyCool 87 white MX reds | HHKB 2 Pro | Model M 02-Mar-1993 | Model M 29-Nov-1995 | CM Trigger (broken) | CM QFS MX green | Ducky DK9087 Shine 3 TKL Yellow Edition MX black | Lexmark SSK 21-Apr-1994 | IBM SSK 13-Oct-1987 | CODE TKL MX clear | Model M 122 01-Jun-1988

Ị̸͚̯̲́ͤ̃͑̇̑ͯ̊̂͟ͅs̞͚̩͉̝̪̲͗͊ͪ̽̚̚ ̭̦͖͕̑́͌ͬͩ͟t̷̻͔̙̑͟h̹̠̼͋ͤ͋i̤̜̣̦̱̫͈͔̞ͭ͑ͥ̌̔s̬͔͎̍̈ͥͫ̐̾ͣ̔̇͘ͅ ̩̘̼͆̐̕e̞̰͓̲̺̎͐̏ͬ̓̅̾͠͝ͅv̶̰͕̱̞̥̍ͣ̄̕e͕͙͖̬̜͓͎̤̊ͭ͐͝ṇ̰͎̱̤̟̭ͫ͌̌͢͠ͅ ̳̥̦ͮ̐ͤ̎̊ͣ͡͡n̤̜̙̺̪̒͜e̶̻̦̿ͮ̂̀c̝̘̝͖̠̖͐ͨͪ̈̐͌ͩ̀e̷̥͇̋ͦs̢̡̤ͤͤͯ͜s͈̠̉̑͘a̱͕̗͖̳̥̺ͬͦͧ͆̌̑͡r̶̟̖̈͘ỷ̮̦̩͙͔ͫ̾ͬ̔ͬͮ̌?̵̘͇͔͙ͥͪ͞ͅ

Offline Computer-Lab in Basement

  • The needs of the many outweigh the needs of the few.
  • * Elevated Elder
  • Posts: 3025
  • Location: NCC-1701, USS Enterprise
  • Live long and prosper
Re: BadUSB - reason to worry?
« Reply #5 on: Thu, 25 June 2015, 15:48:54 »
it's probably safe

i'd like to think Target would be opposed to identity theft that could be tied to them in any way... mainly for legal reasons...
tp thread is tp thread
Sometimes it's like he accidentally makes a thread instead of a google search.

IBM Model M SSK | IBM Model F XT | IBM Model F 122 | IBM Model M 122 | Ducky YOTD 2012 w/ blue switches | Poker II w/ Blue switches | Royal Kludge RK61 w/ Blue switches

Offline fenwick

  • Posts: 12
Re: BadUSB - reason to worry?
« Reply #6 on: Fri, 03 July 2015, 22:26:31 »
Just because an attack exists and has been demonstrated doesn't mean you need to worry about it.  Especially on hardware coming straight from the shelf at Target.

It would have to be a very complex attack for them to install something like this on thousands of drives, then somehow know when to run the keystrokes without anyone noticing applications opening and closing on their own, or seeing keyboards appearing and disappearing.

The only attacks coming from hardware out of the box that I can think of are NSA interception ops, but those are usually network hardware and are caught during shipment to someone they don't like.

Offline baldgye

  • Will Smith Disciple
  • Posts: 4780
  • Location: UK
Re: BadUSB - reason to worry?
« Reply #7 on: Sat, 04 July 2015, 03:02:05 »
If your worried about that kinda stuff why not use an old laptop (everyone has one somewhere) have it off your network and install a bunch of software on it to allow you to safely format drives etc, when you buy a new usb stick, plug it into that bad boy and format it/scan it. If nothing else would help you be less paranoid

Offline jamster

  • Posts: 1091
  • Location: Asia
Re: BadUSB - reason to worry?
« Reply #8 on: Sat, 04 July 2015, 03:42:00 »
If your worried about that kinda stuff why not use an old laptop (everyone has one somewhere) have it off your network and install a bunch of software on it to allow you to safely format drives etc, when you buy a new usb stick, plug it into that bad boy and format it/scan it. If nothing else would help you be less paranoid

Because this issue has nothing to do with malicious software installed on the USB stick, the worry is malware at the firmware level which means that it can't simply be reformatted or even detected by AV.

Offline baldgye

  • Will Smith Disciple
  • Posts: 4780
  • Location: UK
Re: BadUSB - reason to worry?
« Reply #9 on: Sat, 04 July 2015, 03:51:53 »
If your worried about that kinda stuff why not use an old laptop (everyone has one somewhere) have it off your network and install a bunch of software on it to allow you to safely format drives etc, when you buy a new usb stick, plug it into that bad boy and format it/scan it. If nothing else would help you be less paranoid

Because this issue has nothing to do with malicious software installed on the USB stick, the worry is malware at the firmware level which means that it can't simply be reformatted or even detected by AV.

But couldn't you flash the firmware with the correct software?

Offline rowdy

  • HHKB Hapster
  • * Erudite Elder
  • Thread Starter
  • Posts: 21175
  • Location: melbourne.vic.au
  • Missed another sale.
Re: BadUSB - reason to worry?
« Reply #10 on: Sat, 04 July 2015, 06:49:51 »
If your worried about that kinda stuff why not use an old laptop (everyone has one somewhere) have it off your network and install a bunch of software on it to allow you to safely format drives etc, when you buy a new usb stick, plug it into that bad boy and format it/scan it. If nothing else would help you be less paranoid

Because this issue has nothing to do with malicious software installed on the USB stick, the worry is malware at the firmware level which means that it can't simply be reformatted or even detected by AV.

But couldn't you flash the firmware with the correct software?

If you had the equipment to flash the firmware on a USB controller, which I do not.

This is a generic Chinese USB memory stick, and I have no idea where it really came from (except it was China) and where the components, including the firmware, came from.

Maybe it is part of a Chinese attempt to install malware on western PCs, but that is probably being far too paranoid.

Nevertheless BadUSB is out there, and this is the first USB memory stick I have bought for quite a few years.
"Because keyboards are accessories to PC makers, they focus on minimizing the manufacturing costs. But that’s incorrect. It’s in HHKB’s slogan, but when America’s cowboys were in the middle of a trip and their horse died, they would leave the horse there. But even if they were in the middle of a desert, they would take their saddle with them. The horse was a consumable good, but the saddle was an interface that their bodies had gotten used to. In the same vein, PCs are consumable goods, while keyboards are important interfaces." - Eiiti Wada

NEC APC-H4100E | Ducky DK9008 Shine MX blue LED red | Ducky DK9008 Shine MX blue LED green | Link 900243-08 | CM QFR MX black | KeyCool 87 white MX reds | HHKB 2 Pro | Model M 02-Mar-1993 | Model M 29-Nov-1995 | CM Trigger (broken) | CM QFS MX green | Ducky DK9087 Shine 3 TKL Yellow Edition MX black | Lexmark SSK 21-Apr-1994 | IBM SSK 13-Oct-1987 | CODE TKL MX clear | Model M 122 01-Jun-1988

Ị̸͚̯̲́ͤ̃͑̇̑ͯ̊̂͟ͅs̞͚̩͉̝̪̲͗͊ͪ̽̚̚ ̭̦͖͕̑́͌ͬͩ͟t̷̻͔̙̑͟h̹̠̼͋ͤ͋i̤̜̣̦̱̫͈͔̞ͭ͑ͥ̌̔s̬͔͎̍̈ͥͫ̐̾ͣ̔̇͘ͅ ̩̘̼͆̐̕e̞̰͓̲̺̎͐̏ͬ̓̅̾͠͝ͅv̶̰͕̱̞̥̍ͣ̄̕e͕͙͖̬̜͓͎̤̊ͭ͐͝ṇ̰͎̱̤̟̭ͫ͌̌͢͠ͅ ̳̥̦ͮ̐ͤ̎̊ͣ͡͡n̤̜̙̺̪̒͜e̶̻̦̿ͮ̂̀c̝̘̝͖̠̖͐ͨͪ̈̐͌ͩ̀e̷̥͇̋ͦs̢̡̤ͤͤͯ͜s͈̠̉̑͘a̱͕̗͖̳̥̺ͬͦͧ͆̌̑͡r̶̟̖̈͘ỷ̮̦̩͙͔ͫ̾ͬ̔ͬͮ̌?̵̘͇͔͙ͥͪ͞ͅ

Offline GL1TCH3D

  • Posts: 1117
  • Location: Quebec, Canada
  • Audiophile, tea lover and now keyboard hugger!
Re: BadUSB - reason to worry?
« Reply #11 on: Mon, 06 July 2015, 18:53:15 »
The argument that an off the shelf product from target is safe is not solid.

Not too long ago either Wal-Mart or target was selling cheaper generic Chinese tablets that came prerooted and therefore very vulnerable to data theft, loss, etc.

Offline Leslieann

  • * Elevated Elder
  • Posts: 4519
Re: BadUSB - reason to worry?
« Reply #12 on: Mon, 06 July 2015, 19:34:45 »
They also got sold a bunch of fake Sandisk sticks at one point as well.
Novelkeys NK65AE w/62g Zilents/39g springs
More
62g Zilents/lubed/Novelkeys 39g springs, HK Gaming Thick PBT caps, Netdot Gen10 magnetic cable, pic
| Filco MJ2 L.E. Vortex Case, Jailhouse Blues, heavily customized
More
Vortex case squared up/blasted finish removed/custom feet/paint/winkey blockoff plate, HID Liberator, stainless steel universal plate, 3d printed adapters, Type C, Netdot Gen10 magnetic cable, foam sound dampened, HK Gaming Thick PBT caps (o-ringed), Cherry Jailhouse Blues w/lubed/clipped Cherry light springs, 40g actuation
| GMMK TKL
More
w/ Kailh Purple Pros/lubed/Novelkeys 39g springs, HK Gaming Thick PBT caps, Netdot Gen10 Magnetic cable
| PF65 3d printed 65% w/LCD and hot swap
More
Box Jades, Interchangeable trim, mini lcd, QMK, underglow, HK Gaming Thick PBT caps, O-rings, Netdot Gen10 magnetic cable, in progress link
| Magicforce 68
More
MF68 pcb, Outemu Blues, in progress
| YMDK75 Jail Housed Gateron Blues
More
J-spacers, YMDK Thick PBT, O-rings, SIP sockets
| KBT Race S L.E.
More
Ergo Clears, custom WASD caps
| Das Pro
More
Costar model with browns
| GH60
More
Cherry Blacks, custom 3d printed case
| Logitech Illumininated | IBM Model M (x2)
Definitive Omron Guide. | 3d printed Keyboard FAQ/Discussion

Offline phosphoric

  • Posts: 229
Re: BadUSB - reason to worry?
« Reply #13 on: Mon, 06 July 2015, 20:21:59 »
If your worried about that kinda stuff why not use an old laptop (everyone has one somewhere) have it off your network and install a bunch of software on it to allow you to safely format drives etc, when you buy a new usb stick, plug it into that bad boy and format it/scan it. If nothing else would help you be less paranoid

Because this issue has nothing to do with malicious software installed on the USB stick, the worry is malware at the firmware level which means that it can't simply be reformatted or even detected by AV.

But couldn't you flash the firmware with the correct software?

If you had the equipment to flash the firmware on a USB controller, which I do not.

This is a generic Chinese USB memory stick, and I have no idea where it really came from (except it was China) and where the components, including the firmware, came from.

Maybe it is part of a Chinese attempt to install malware on western PCs, but that is probably being far too paranoid.

Nevertheless BadUSB is out there, and this is the first USB memory stick I have bought for quite a few years.

not to mention that flashing the firmware on every single usb stick that you buy/acquire is going to be a pain in the ass at some point... especially if you're digging out an old craptop just to do it
Let's get this straight. There is nothing cool about keyboards we're all lame as fk.

speak for yourself

Offline tp4tissue

  • * Destiny Supporter
  • Posts: 13568
  • Location: Official Geekhack Public Defender..
  • OmniExpert of: Rice, Top-Ramen, Ergodox, n Females
Re: BadUSB - reason to worry?
« Reply #14 on: Mon, 06 July 2015, 20:25:20 »
I'd be worried,  if I weren't so desperately poor.