Re: [Full-Disclosure] USB risks - working autorun example (fwd from pen-test)

Pego, Victor wrote:

I need to figure out how to autorun a file on a USB flash pen drive.

My limited understanding of how this works is that either you have to
change the default configuration of the target machine(s) so they will
autorun removable drives (that's simply a registry tweak in Windows,
but may require driver changes in other OSes??) OR you need a USB
device that "lies" about its device type.

... but there are companies who sell the pen
drives with autorun software or something, they promote it. ...

I believe that these devices work through the latter method. That is,
although they are "physically" USB pen drives, they tell the USB
interface that they are CD drives. As most modern machines autorun CDs
by default, these devices can carry autorunnable code.


Nick FitzGerald

Full-Disclosure - We believe in it.
Hosted and sponsored by Secunia -

Relevant Pages

  • USB delivered attacks - lessons learned/summary (so far)
    ... All my testing so far has been done on a Windows ... USB devices don't use autorun - well, they seem to do something with it ... drives in your machine, why assume that his USB thumbdrive is so ...
  • Re: Installation failed - and failed again...
    ... You are using USB flash/USB flash drive/USB hard disc/USB drive ... drives. ... target: 8-GB USB flash drive. ... install to a drive when it detects an iso9660 filesystem is present on ...
  • NoDriveTypeAutoRun - Disable for CD-ROM, but enable for removable drives...
    ... We are using the USBDML product and trying to enable autorun for USB ... This is because some of our USB drives use the DTE_Privacy_Launcher, ... We are struggling to get Windows XP to differentiate between CD-ROM ...
  • Re: USB Problems
    ... It's quite difficult to find a USB device which ... isn't a mass storage device in my house or I'd try other USB devices. ... (hard drives, CD/DVD or video card?) ... Maybe disable your Autorun for everything. ...
  • Re: DOS boot from USB CD-ROM drive
    ... The target can boot from a USB hard drive, floppy, or CD, so at least ... Copy all your boot and Ghost files from previous floppy and CD to ... drives have more room than your previous setup anyhow, ...