Re: Autorun programs from flash drive.



I often avoid saying this, but:
Search the archives for detailed discussion.



On Tue, 16 Apr 2008 arckeda@xxxxxxxxx wrote:

Hello, and thanks for reading this. I am sure we are all know of the Autorun feature in Cdroms and Dvdroms, how the program just runs out of the box. I am trying to figure out how to include this functionality in flash drives.
/* I have a SD card with a USB adapter to test with. */
This would allow, say, for me to quickly insert a drive into a computer, have it silently run something like Meterpreter or another backdoor program, and then have remote access to the computer, assuming Windows runs it and doesn't detect a malicious program. I understand that Windows by default will not run Autorun.inf by default on flash drives, except the U3s. But I have also heard that you can format a flash drive to look like a cdrom to Windows. This is about all I know. If you have any more information, or would know about how to go about doing this, please tell me.
Thank you again.
-ARCKEDA

------------------------------------------------------------------------
This list is sponsored by: Cenzic

Need to secure your web apps NOW?
Cenzic finds more, "real" vulnerabilities fast.
Click to try it, buy it or download a solution FREE today!

http://www.cenzic.com/downloads
------------------------------------------------------------------------


------------------------------------------------------------------------
This list is sponsored by: Cenzic

Need to secure your web apps NOW?
Cenzic finds more, "real" vulnerabilities fast.
Click to try it, buy it or download a solution FREE today!

http://www.cenzic.com/downloads
------------------------------------------------------------------------



Relevant Pages

  • Re: web service fuzzers
    ... Need to secure your web apps NOW? ... Cenzic finds more, "real" vulnerabilities fast. ... buy it or download a solution FREE today! ...
    (Pen-Test)
  • Re: IPS Testing
    ... Need to secure your web apps NOW? ... Cenzic finds more, "real" vulnerabilities fast. ... buy it or download a solution FREE today! ...
    (Pen-Test)
  • Re: Fast UDP scan
    ... Need to secure your web apps NOW? ... Cenzic finds more, "real" vulnerabilities fast. ... buy it or download a solution FREE today! ...
    (Pen-Test)
  • RE: InfoSec certification EC/BackTrack?
    ... Need to secure your web apps NOW? ... Cenzic finds more, "real" vulnerabilities fast. ... buy it or download a solution FREE today! ...
    (Pen-Test)
  • Re: Gear
    ... Need to secure your web apps NOW? ... Cenzic finds more, "real" vulnerabilities fast. ... buy it or download a solution FREE today! ...
    (Pen-Test)