[Solved] Secure USB writables... the "new" floppy?

Talk here about security in general. Posting illegals software is prohibited. All stuffs in this forum must be considered as for "Educational purpose only".
User avatar
brokenman
Site Admin
Site Admin
Posts: 6105
Joined: 27 Dec 2010, 03:50
Distribution: Porteus v4 all desktops
Location: Brazil

Re: USB writables... the "new" floppy?

Post#16 by brokenman » 01 May 2016, 18:21

As I have stated before Porteus is not being villified.
I hope I didn't come across in the wrong light. I didn't think for a minute you were putting Porteus down. You wouldn't be using it if you didn't think it was worthy.

My point was that the majority of users booting linux from writable media will never see, nor have the need to minimize attack vectors against any such bugs. Being more cautious is obviously always going to be a better option, but for most users the need to harden up/lock down is not really there.

I'm glad you make these threads available for those that DO feel the need and don't have the expertise to harden.
I'm sure Alan Turing had to wrestle with these early constructs
He most certainly did and became one of the foremost crypt-analysts during/after the war.
Right now there is probably some moron somewhere working on the next generation of Stuxnet or whatever ready to release it into the wild to amuse himself.
I hope it IS simply some moron and not a state funded crypt-analysts.
How do i become super user?
Wear your underpants on the outside and put on a cape.

fullmoonremix

Re: USB writables... the "new" floppy?

Post#17 by fullmoonremix » 01 May 2016, 19:34

Salutations... :good:
― William Shakespeare, Hamlet
To sleep, perchance to dream
I have a "dream"... that one day everyone's system will be hardened so we can all throw the Black hat 's under the bus.
Field of Dreams - (1989)
"If you build it, he will come".
Hmmm... I guess I watched that movie too my times. :wall:
(in the background I can hear Jiminy Cricket singing the Disney theme... "When You Wish Upon A Star")

"Best Regards"... :beer:
Last edited by fullmoonremix on 02 May 2016, 11:33, edited 7 times in total.

Evan
Shogun
Shogun
Posts: 466
Joined: 11 Apr 2016, 09:00
Distribution: Distribution: *

Re: USB writables... the "new" floppy?

Post#18 by Evan » 01 May 2016, 22:06

<removed>
Last edited by Evan on 24 Jun 2016, 11:20, edited 1 time in total.

User avatar
brokenman
Site Admin
Site Admin
Posts: 6105
Joined: 27 Dec 2010, 03:50
Distribution: Porteus v4 all desktops
Location: Brazil

Re: USB writables... the "new" floppy?

Post#19 by brokenman » 02 May 2016, 01:32

You don't really need a switch to make a USB non-writable. Check out Porteus Kiosk for example. Making a drive non-writable does not protect your firmware. Security on USB drives is sub par. Search for BadUSB which was released by security researchers in a bid to force the manufacturers to pull their socks up.
How do i become super user?
Wear your underpants on the outside and put on a cape.

fullmoonremix

Re: USB writables... the "new" floppy?

Post#20 by fullmoonremix » 02 May 2016, 01:51

Salutations... :good:

The point of non-writable media is static environment. No "change" does not mean no bug. It means no morph... no hook...
no misdirection... no escalation... no false positive(s)/negative(s) or anything else but ONLY if the original boot media is sequested.

Think of it as a dual boot... remove the static boot and the bug is back in business.

This has been the case going back to the 5.25 floppy and will likely remain this way until
a manual USB switch can be virtually overridden or an optical disk can be burned "on the fly".

However... there is a class of bug which will retaliate and either brick... refuse to boot or destroy some devices (I lost some gear this way). :wall:
Unfortunately... that is counter productive because infection is the goal.

I am posting on a compromised system... the bug is contained but not eradicated.

"Best Regards"... :beer:
Last edited by fullmoonremix on 02 May 2016, 03:51, edited 11 times in total.

Evan
Shogun
Shogun
Posts: 466
Joined: 11 Apr 2016, 09:00
Distribution: Distribution: *

Re: USB writables... the "new" floppy?

Post#21 by Evan » 02 May 2016, 02:10

<removed>
Last edited by Evan on 24 Jun 2016, 11:20, edited 1 time in total.

fullmoonremix

Re: USB writables... the "new" floppy?

Post#22 by fullmoonremix » 11 May 2016, 09:45

Salutations... :)

Kanguru's badUSB solution...
https://www.kanguru.com/info/kanguru-st ... dusb.shtml

"Best Regards"... :beer:

Posted by 73.150.85.78 via http://webwarper.net
This is added while posting a message to avoid misusing the service

Post Reply