reconsidering physical security: pod slurping
From: Abe Usher (abe.usher_at_sharp-ideas.net)
Date: 06/13/05
- Previous message: Susan Bradley, CPA aka Ebitz - SBS Rocks [MVP]: "Re: New IE6 security hole"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Date: Sun, 12 Jun 2005 23:37:00 -0400 To: vuln-dev@securityfocus.com
pod slurping
------------
I've written a report that explores an idea that has been known by the
security community for decades: physical security is important to
information system security.
A year ago a report was published by the Gartner Group warning that
iPods <http://www.apple.com/ipod/> (and other multi-gigabyte portable
storage devices) pose a security risk for enterprises
<http://www.infoworld.com/article/04/07/06/HNipodsrisk_1.html>. I've
created an application (*slurp.exe*) that demonstrates this concept.
When the program is run from an iPod, it can __very__quickly__ copy
thousands of interesting files* from a PC to an iPod.
The full article and proof-of-concept application are available at:
http://www.sharp-ideas.net
Cheers,
Abe Usher, CISSP
* Office documents, *.pdf,*.xml, *.dbf, *.log, *.dat, *.txt, *.csv,
*.htm, *.url, et cetera
- Previous message: Susan Bradley, CPA aka Ebitz - SBS Rocks [MVP]: "Re: New IE6 security hole"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Relevant Pages
|