USB Devices Can Crack Windows

Status
Not open for further replies.

ZOverLord

Solid State Member
Messages
16
USB Devices Can Crack Windows By Paul F. Roberts

Vulnerabilities in USB drivers for Windows could allow an attacker to take control of locked workstations using a specially programmed Universal Serial Bus device, according to an executive from SPI Dynamics, which discovered the security hole.

The buffer-overflow vulnerabilities could enable an attacker to circumvent Windows security and gain administrative access to a user's machine.

This is just the latest example of a growing danger posed by peripheral devices that use USB (Universal Serial Bus), FireWire and wireless networking connections, which are often overlooked in the search for remotely exploitable security holes, experts say.

The buffer-overflow flaw is in device drivers that Windows loads whenever USB devices are inserted into computers running Windows 32-bit operating systems, including Windows XP and Windows 2000, said Caleb Sima, chief technology officer and founder of SPI Dynamics.

SPI is still testing the hole, and hasn't informed Microsoft Corp. about the problem. The company will be demonstrating the vulnerability at this week's Black Hat Briefings hacker conference in Las Vegas, but will not release details of the security hole, Sima said.

A spokesperson for Microsoft's Security Response Center confirmed that the company has not received a vulnerability report from SPI. The company strongly encouraged any researcher to contact the MSRC if they have a vulnerability to report.

Rest Of the Story is Here:

http://testing.onlytherightanswers.com/modules.php?name=News&file=article&sid=7
 
matt2m said:
that make me wory about using my usb drive :p

For the moment I would not let folks use my USB ports, or use my USB devices on others systems, until there is more detail.
 
Thats a little overkill aint it? J/k.
Until an os comes out with a consol based set up.I read it in a magazine.Consoles never get any thing why they have to be authorized to run on the machine.While comps of to day can run crap and we would not know it this way the only way 4 a program to function is to be allowed in.I would not mind the hassle of authorising stuff like that think of it no virus scanners and firewalls.The article has it in more detail i will look 4 it then look on line 4 it.
 
Status
Not open for further replies.
Back
Top Bottom