Re: USB delivered attacks

From: H D Moore (sflist_at_digitaloffense.net)
Date: 06/02/04

  • Next message: Jerry Shenk: "USB delivered attacks - lessons learned/summary (so far)"
    To: pen-test@securityfocus.com
    Date: Tue, 1 Jun 2004 18:39:28 -0500
    
    

    Some friends and I looked into this a while back as a way to bypass the
    security of kiosk machines. We discovered that Windows 2000 (and possibly
    XP as well) will not execute AutoRun scripts on USB or other "removable
    storage" media types. Even though there is a registry key that can be
    changed that "enables" AutoRun, it does not work.

    "Autoplay is triggered by a Media Change Notification (MCN) message from
    the CD-ROM driver. If the Windows 2000 interface does not receive this
    message, Autoplay does not operate, regardless of the value of this"

    http://www.tburke.net/info/regentry/topics/91525.htm
    http://www.tburke.net/info/regentry/topics/30300.htm

    -HD

    On Thursday 27 May 2004 21:06, Jerry Shenk wrote:
    > I recently inserted some guy's USB drive into a machine and was a but
    > surprised when it went into an auto-run sequence. I think turning off
    > auto-run is a REALLY good idea. On a USB drive, it seems like it could


  • Next message: Jerry Shenk: "USB delivered attacks - lessons learned/summary (so far)"

    Relevant Pages

    • Re: selecting autoplay actions
      ... I can't get that to happen on the other drives at all, ... This AutoPlay setting cannot be fixed. ... "RandyB" wrote: ... >> Windows XP Troubleshooting ...
      (microsoft.public.windowsxp.general)
    • Re: Pesky Autoplay Problem
      ... Ok, Greg. ... Troubleshooting Windows XP ... > Autoplay" regfix from your site might have fixed the problem. ... >>> my drives. ...
      (microsoft.public.windowsxp.customize)
    • Re: Cheap USB device that never autoplays or asks for driver
      ... small quantities) USB device. ... something that Windows might try to autoplay, ... I have another program that uses flash drives for this, ...
      (microsoft.public.development.device.drivers)
    • =?ISO-8859-1?Q?Re=3A_Windows_7_d=E9j=E0_infect=E9?=
      ... Social engineering autoplay tricks work on early versions of Windows 7 as ... well as Vista, according to tests by security researchers. ...
      (soc.culture.quebec)
    • Re: usb autodetect
      ... Windows XP Autoplay Repairing Tutorial ... CD-ROM May Not Run Automatically in Windows XP ... Autoplay Repair Wizard 77 KB (Freeware) ...
      (microsoft.public.windowsxp.general)