Re: [Full-Disclosure] Re: USB risks (continued)

From: RSnake (rsnake_at_shocking.com)
Date: 06/28/04

  • Next message: Sam: "Re: [Full-Disclosure] Re: USB risks (continued)"
    To: Chris Withers <chris@simplistix.co.uk>
    Date: Mon, 28 Jun 2004 09:03:12 -0700 (PDT)
    
    

            Of course it's not. That's just Microsoft's explination. There's no
    good reason, just a vague distinction. My only point is that it isn't a
    reliable attack vector, unlike an onboard CDROMs (the media, not the device
    must be removable). Here is how Microsoft defines it on their usbfaq page
    (sorry, the links are broken, I just cut and pasted from
    http://www.microsoft.com/whdc/device/storage/usbfaq.mspx):

    Q: What must I do to trigger Autorun on my USB storage device?
    If you need to make a USB storage device that executes Autorun, the following
    two conditions must both be true:

    . Media must be marked as removable.

    . The device can be set to either static or removable.

    We associate the "removable" nature of a device with the bus that it resides
    on. This means that a disk on an Integrated Device Electronics (IDE) or SCSI
    bus would be considered fixed, whereas a disk on a USB or IEEE 1394 bus would
    be regarded as removable by default. PnP uses a bit in the DEVICE_CAPABILITIES
    structure to determine this. For more information, see the DEVICE_CAPABILITIES
    Plug and Play Structure in the Windows DDK, located at
    http://msdn.microsoft.com/library/default.asp?url=/library/en-us/kmarch/hh/kmarch/k112_22r6.asp.

    The "removable" nature of media is a property of the device. For example, in
    the case of a CD-ROM or a ZIP drive, the medium can be removed without the
    device itself going away, but on the other hand the medium and the disk cannot
    be separated on static storage PC cards. We obtain this information by using
    the StorageDeviceProperty request. For more information, see the
    STORAGE_DEVICE_DESCRIPTOR Storage Structure in the Windows DDK, located at
    http://msdn.microsoft.com/library/en-us/storage/hh/storage/k306_00qa.asp.

    On Mon, 28 Jun 2004, Chris Withers wrote:

    | Date: Mon, 28 Jun 2004 11:59:11 +0100
    | From: Chris Withers <chris@simplistix.co.uk>
    | To: RSnake <rsnake@shocking.com>
    | Cc: Gadi Evron <ge@egotistical.reprehensible.net>,
    | Harlan Carvey <keydet89@yahoo.com>, full-disclosure@lists.netsys.com,
    | bugtraq@securityfocus.com
    | Subject: [Full-Disclosure] Re: USB risks (continued)
    |
    | RSnake wrote:
    | > writeable, but the drives aren't removeable on CDs. That of course isn't true
    | > if you have a USB drive, but I think part of the deal there is that you need to
    | > install special drivers to even read USB CD drives.
    |
    | ...that's not true ;-)
    |
    | Chris
    |
    | --
    | Simplistix - Content Management, Zope & Python Consulting
    | - http://www.simplistix.co.uk
    |
    | _______________________________________________
    | Full-Disclosure - We believe in it.
    | Charter: http://lists.netsys.com/full-disclosure-charter.html
    |

    -R

    The information in this email is confidential and may be legally
    privileged. It is intended solely for the addressee. Access to
    this email by anyone else is unauthorized. If you are not the
    intended recipient, any disclosure, copying, distribution or any
    action taken or omitted to be taken in reliance on it is
    expressly prohibited and may be unlawful.

    _______________________________________________
    Full-Disclosure - We believe in it.
    Charter: http://lists.netsys.com/full-disclosure-charter.html


  • Next message: Sam: "Re: [Full-Disclosure] Re: USB risks (continued)"

    Relevant Pages

    • Re: The Real Difference Between XP Pro and XP Media Center
      ... purchased separate disk manager sotware to try to get the external hard drive ... By the way does Vista promise better USB management? ... and XP Media Center. ... The latest one that has happened is none of my external USB hard drives ...
      (microsoft.public.windows.mediacenter)
    • Re: Reattach/redetect allways connected umass device - is it possible ?
      ... >> flash media from the USB drive. ... So in fact it is a flash card reader? ... Yes - GEOM seems to ignore media change signals from drives. ... >> So you say that the device still exists after unplugging the USB stick? ...
      (freebsd-current)
    • RE: sharing files from my removable HD to xbox360
      ... i just deicided to check my xbox and its reading the folder now. ... Added my entire USB drive to the monitored folders list. ... I'll let the developer who owns Media Sharing know about the problem you're ... reason for me to have all my songs on both drives so i dont want to have to ...
      (microsoft.public.windowsmedia.player)
    • Re: Advice on external backup of a Linux server.
      ... >> You could even swap between a few external drives so that you have a ... >> USB drive in use, one on the shelf, one in the safety deposit box, one ... DVD-R or swap the hard drive and take the ... If you leave the media near the system being backed up, ...
      (Fedora)
    • Re: Problems disconnecting usb storage device
      ... is that the USB drive cannot be ejected if either Media Center ... that it has something to do with drives and folders the media ... either by Explorer or some other app. ... apps are holding open on the USB storage device and allow you to close ...
      (microsoft.public.windowsxp.general)