USB undocumented & illegal packets

From: megan (zhongmeiyi_at_yahoo.com.sg)
Date: 06/03/03


Date: 3 Jun 2003 00:44:06 -0700

Hi,

I'm doing some research on usb tokens and i don't know much about usb
commands and need some information urgently. i've tried to search on
the internet and have come up with extremely limited info.

I've read the "attacks on and countermeasures for usb harware token
devices" and i'm looking for some examples to support some of the
things mentioned. I don't really need specific examples, vague ones
will do.

1.Is there a undocumented command that can extract information (any
kind) from the token?

2.How does sending an malformed USB packet to the token make the token
leak information? Is there an example?

thanks
Megan



Relevant Pages

  • RE: USB Tokens
    ... but if someone is able to grab your laptop the USB ... is forces smart card authentication make sure you ... Subject: USB Tokens ...
    (Focus-Microsoft)
  • Re: usb token
    ... >I've read some USB token documents and they say that the private keys never ... Think of a USB dongle as a smartcard chip with a USB interface and no ... >keys are actually released after the PIN or passwords to the tokens are ... I would expect that the token makes private keys available to its ...
    (comp.security.misc)
  • Re: USB Keys and Cisco VPN Concentrator / Cisco VPN Client ?
    ... You can run the WiKID token on any USB device. ... So you could put the Cisco VPN client and the WiKID token onto a USB ... scripts on your LAN and have them set up their tokens. ...
    (comp.dcom.sys.cisco)
  • Re: USB mass storage problem , workaround - WinCE5.0
    ... As many people in this newsgroups, I had to deal with those USB sticks ... - read the medium type (at this stage, the device type has already been ... WinCE driver side but anyway those SCSI commands are optionnal for USB ... dwErr = ScsiModeSense6; ...
    (microsoft.public.windowsce.platbuilder)
  • Re: Mixed mode WSE authentication (of internal/external clients)
    ... authenticate internal / external clients, ... These tokens will be authenticated by overriding ... > here) from your web services. ... >> external clients connecting via the internet (i.e. they will be supplying ...
    (microsoft.public.dotnet.framework.webservices.enhancements)