Black Hat USA 2014 Videos Now Online

Very interesting video (BAD USB) that was posted. Very neat attack approach, usb stick becomes a keyboard and types in some commands.

It is presented as something that might be hard to patch, but is it really? Looks like if Microsoft expanded their UAC a little bit that's all it takes. Windows detected: USB Mass Storage, USB Keyboard, Do you allow this? No. Your hardware did not install.
 
Very interesting video (BAD USB) that was posted. Very neat attack approach, usb stick becomes a keyboard and types in some commands.

It is presented as something that might be hard to patch, but is it really? Looks like if Microsoft expanded their UAC a little bit that's all it takes. Windows detected: USB Mass Storage, USB Keyboard, Do you allow this? No. Your hardware did not install.

Haw

I told you, I told all of you that's all badUSB was, it was just a USB stick programmed to execute commands via simulating keyboard and mouse input

And like I said, an easy way to protect networks from this is to have a sacrificial lamb computer you can dump files on, and then download files from it remotely

A more secure way to do that is say bios makers you can have specific ports set up to only accept input devices, and other ports only accepting data etc etc
 
Back
Top