Home
Calendar
Certifications
Columns
Features
Forum
Resources
Vitals
Latest Additions
April 2013 Free Giveaway Sponsor - eLearnSecurity
Human Intelligence to Navigate the Security Data Deluge
February 2013 Free Giveaway Winner of SANS CyberCon Training
Interview: Bugcrowd Founders on Herding Ninjas for Crowdsourced Bug Bounties
Network Forensics: The Tree in the Forest
March 2013 Free Giveaway Sponsor - Mile2
Book Review: Violent Python
February 2013 Free Giveaway Sponsor - SANS
Holiday 2012 Free Giveaway Winner of Metasploit Pro by Rapid7
Course Review: SANS FOR408 Computer Forensic Investigations – Windows In-Depth
The Security Consulting Sugar High
Tutorial: Fun with SMB on the Command Line
Interview: Ilia Kolochenko, CEO of High-Tech Bridge
October 2012 Free Giveaway Winner of LearningGate Training
The Broken: Assessing Corporate Security in 2012 to Make a Better 2013
EH-Net Login
Welcome Guest.
Username:
Password:
Remember me
Lost Password?
No account yet?
Register
Who's Online
We have 115 guests and 1 member online
You are here:
Home
Ethical Hacking Discussions and Related Certifications
Malware
Flash drive virus
EH-Net
May 19, 2013, 05:55:51 AM
Welcome,
Guest
. Please
login
or
register
.
Did you miss your
activation email?
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
News
: Go back to The Ethical Hacker Network Online Magazine
Home Page
Home
Help
Calendar
Login
Register
EH-Net
>
Ethical Hacking Discussions and Related Certifications
>
Malware
(Moderator:
don
) >
Flash drive virus
Pages: [
1
]
2
Go Down
« previous
next »
Print
Author
Topic: Flash drive virus (Read 52212 times)
0 Members and 2 Guests are viewing this topic.
iSmith
Full Member
Offline
Posts: 157
Do or do not. There is no try. - Yoda
Flash drive virus
«
on:
January 29, 2008, 09:41:11 AM »
I once got an infected flash drive to clean. As soon as I put it in, Norton told me it had w32.sillyFDC. I tried to delete it, but the drive was locked. So i unlocked it and put it back in, and the virus disapeared right in front of my eyes. So I scanned it with Norton and it picked up 3 instances of w32.rontok@mm. But even a regularly updated Norton '07 can get confused by this old tricky virus. It names itself X.exe where X is the directory in which it resides. If you open the folder X in Windows explorer the virus moves itself, too quick to catch. I was eventually forced to delete 19 copies of it in dos prompt.
Logged
In my eyes, your operating system is as solid as swiss cheese.
Negrita
Sr. Member
Offline
Posts: 299
Re: Flash drive virus
«
Reply #1 on:
January 29, 2008, 03:20:16 PM »
Yet another example of the superiority of the CLI over the GUI.
Logged
CEH, CCSA NG/AI, NNCSS, MCP, MCSA 2003
There are 10 kinds of people, those that understand binary, and those that don't.
dannioni
Newbie
Offline
Posts: 44
Re: Flash drive virus
«
Reply #2 on:
February 04, 2008, 11:38:26 AM »
Or you could just have opened it in linux from the very beginning
Logged
pseud0
Recruiters
Full Member
Offline
Posts: 208
Re: Flash drive virus
«
Reply #3 on:
February 04, 2008, 01:08:35 PM »
Or you could have modified the source code to open a listening port for you then left the thumb drive on the table in the break room by the HR department. At least that is what my evil twin would have done.
Logged
CISSP, CISM, CISA, GCIH, GREM, CEH, HMFIC, KTHXBIROFLCOPTER
g00d_4sh
Sr. Member
Offline
Posts: 394
Re: Flash drive virus
«
Reply #4 on:
February 04, 2008, 02:55:19 PM »
I wonder how many USB drives are running around that have Hacksaw on them already. I could just see someone giving out a box of 'free' usb drives to a college or institution, and using the emailed info from their Gmail account to 'passively' gather info on the students or institution.
Interesting thought, has anyone done that for pen testing? Gone into the target area and given out 'free' thumbdrives as a 'promotion'? Besides installing backdoors and whatnot on them, just having the machines email you outside the organization info passively would be an interesting attack as well.
Logged
"Bad.. Good? I'm the guy with the gun"
BillV
Hero Member
Offline
Posts: 1892
Re: Flash drive virus
«
Reply #5 on:
February 04, 2008, 03:08:38 PM »
I heard a story in one of my classes of someone giving out CD's that had something on them, but I've not heard of anyone doing it with a flash drive.. though I'm sure it's been done.
Logged
iSmith
Full Member
Offline
Posts: 157
Do or do not. There is no try. - Yoda
Re: Flash drive virus
«
Reply #6 on:
February 04, 2008, 03:40:34 PM »
Dannioni, all of the linux distros i've used cannot modify files on a windows storage device.
Logged
In my eyes, your operating system is as solid as swiss cheese.
Negrita
Sr. Member
Offline
Posts: 299
Re: Flash drive virus
«
Reply #7 on:
February 04, 2008, 04:32:06 PM »
Quote from: iSmith on February 04, 2008, 03:40:34 PM
Dannioni, all of the linux distros i've used cannot modify files on a windows storage device.
Have you ever tried Knoppix?
Logged
CEH, CCSA NG/AI, NNCSS, MCP, MCSA 2003
There are 10 kinds of people, those that understand binary, and those that don't.
jimbob
Guest
Re: Flash drive virus
«
Reply #8 on:
February 04, 2008, 04:46:40 PM »
Quote from: iSmith on February 04, 2008, 03:40:34 PM
Dannioni, all of the linux distros i've used cannot modify files on a windows storage device.
Linux now supports read/write on NTFS. Unless you talking about a windows striped volume linux ought to be able to read and write to a regualr Windows storage device.
Jimbob
Logged
pseud0
Recruiters
Full Member
Offline
Posts: 208
Re: Flash drive virus
«
Reply #9 on:
February 04, 2008, 07:11:02 PM »
To the question earlier, yes, there are pen testing teams that have physical media drops as part of their assessment. One of the tiger teams I know used it to really screw with a bank. They dropped a dozen usb drives in the parking lot that were installed with a piece of code that would fire off when windows auto mounted. It didn't install anything, just pinged their server so they could get a count. 11 of the 12 were used in the bank, the last was used by a customer on their home system. As for CD's, that is a story from one of the original black hats. Someone loaded a trojan onto those little mini-CDs and just walked around the conference throwing them onto the tables of other participants. Dozens of people picked them up thinking they were demo disks. The next generation of this is already here, and that is infecting the media on creation. Foreign governments are pre-loading devices with trojans and just waiting to see where they'll end up. Other times you'll get people in the factories that will put the malware into memory chips without ever knowing what devices they will get built into...
http://redtape.msnbc.com/2008/01/digital-picture.html
Logged
CISSP, CISM, CISA, GCIH, GREM, CEH, HMFIC, KTHXBIROFLCOPTER
BillV
Hero Member
Offline
Posts: 1892
Re: Flash drive virus
«
Reply #10 on:
February 04, 2008, 10:02:38 PM »
Yeah, that's right. That's the story I heard about the CD's. As for the stuff that's getting put on during creation.. pretty creepy.
Logged
iSmith
Full Member
Offline
Posts: 157
Do or do not. There is no try. - Yoda
Re: Flash drive virus
«
Reply #11 on:
February 05, 2008, 09:09:03 AM »
Have you ever tried Knoppix?
[/quote]
I have tried slax, nimblex, and mandriva but i have never really been able to get my hands on knoppix.
Logged
In my eyes, your operating system is as solid as swiss cheese.
g00d_4sh
Sr. Member
Offline
Posts: 394
Re: Flash drive virus
«
Reply #12 on:
February 05, 2008, 10:15:16 AM »
Reminds me of the Maxtor hard drives that had a built in trojan that phoned home to china and sent your data to servers there. A good article on that... though it's amazing how that story became very quiet.
iSmith, knoppix is as easy to get your hands on as googling it, downloading the iso and making a cd. It's really a great program for fixing Windblows when it breaks. Lots of utilities, and like... well most Linux distro's I've ever tried, it supports reading/altering ntfs partitions. A thumbdrive with either DSL (damn small linux) or backtrack on it is a great little pocket sized tool for fixing computer... or 'fixing' computers.
Logged
"Bad.. Good? I'm the guy with the gun"
pseud0
Recruiters
Full Member
Offline
Posts: 208
Re: Flash drive virus
«
Reply #13 on:
February 05, 2008, 10:37:17 AM »
For folks moving into the security or incident response space for the first time, Knoppix, Helix, and BackTrack are an incredible resource. As for mounting the windows drive you are going to hit two issues: make sure your linux build is recognizing your usb ports, and using the right file system. Most of the live CD's will auto sense the usb ports so that shouldn't be an issue, and some of them will automount the drive if it is plugged in when you boot. If you have to mount it manually, try ntfs first and samba seconds if you can't get ntfs to work. Another thing to check, if you are trying to mount with one of the linux builds meant for forensics (especially Helix) when you do get it mounted it will be hard set as read only. It can be a bit of a pain in the hind-quarters to get it mounted as writeable.
Logged
CISSP, CISM, CISA, GCIH, GREM, CEH, HMFIC, KTHXBIROFLCOPTER
Negrita
Sr. Member
Offline
Posts: 299
Re: Flash drive virus
«
Reply #14 on:
February 05, 2008, 02:45:19 PM »
Quote from: iSmith on February 05, 2008, 09:09:03 AM
I have tried slax, nimblex, and mandriva but i have never really been able to get my hands on knoppix.
Here you go!!!
Logged
CEH, CCSA NG/AI, NNCSS, MCP, MCSA 2003
There are 10 kinds of people, those that understand binary, and those that don't.
Pages: [
1
]
2
Go Up
Print
« previous
next »
Jump to:
Please select a destination:
-----------------------------
EH-Net
-----------------------------
=> Calendar Of Events
===> ChicagoCon 2007
===> ChicagoCon 2008s
===> ChicagoCon 2008f
===> ChicagoCon 2009s
=> Ethical Hacktivism
=> News Items and General Discussion About EH-Net
===> Greetings
=> Special Events
-----------------------------
Ethical Hacking Discussions and Related Certifications
-----------------------------
=> General Certification
===> Networking
===> OS
===> Security
=> Compliance, Regulations & Standards
=> Control Systems
=> Cyber Warfare
=> Forensics
===> CCE / MCCE - (Master) Certified Computer Examiner
===> CHFI - Computer Hacking Forensic Investigator
===> EnCE - EnCase® Certified Examiner
===> GCFA - GIAC Certified Forensics Analyst
=> Hardware
=> Incident Response
===> CSIH - Computer Security Incident Handler
===> GCIH - GIAC Certified Incident Handler
=> Malware
===> Advisories
=> Mobile
=> Network Pen Testing
===> CEH - Certified Ethical Hacker
===> CPTC - Certified Penetration Testing Consultant
===> CPTE - Certified Penetration Testing Engineer
===> CSTA - Certified Security Testing Associate
===> eCPPT - eLearnSecurity Certified Professional Penetration Tester
===> ECSA - EC-Council Certified Security Analyst
===> GPEN - GIAC Certified Penetration Tester
===> OSCP - Offensive Security Certified Professional
=> Physical Security
=> Programming
=> Social Engineering
=> Web Applications
=> Wireless
===> CWNP Certs
===> GAWN - GIAC Assessing Wireless Networks
===> OSWP - Offensive Security Wireless Professional
=> Other
-----------------------------
Columns
-----------------------------
=> Editor-In-Chief
=> Andress
=> Gates
=> Haddix
=> Hadnagy
=> Heffner
=> Hoffman
=> Linn
=> RichM
=> Murray
=> J. Peltier
=> Weidman
=> Wilson
-----------------------------
Features
-----------------------------
=> /root
=> Book Reviews
=> Opinions
=> Skillz
===> Examples
===> May 06 - Star Hacks, Episode V: The Empire Hacks Back
===> July 06 - Hack Bill!
===> Sept 06 - Netcat in the Hat
===> Nov 06 - Hitch-Hackers Guide to the Galaxy
===> Dec 06 - A Christmas (Hacking) Story
===> Feb 07 - Charlottes Web Site
===> April 07 - Microsoft Office Space
===> June 07 - Serenity Hack
===> Oct 07 - Worst. Ethical. Hacker. Challenge. Ever.
===> Dec 07 - Frosty the Snow Crash
===> March 2008 - It Happened One Friday
===> Oct 2008 - Scooby Doo and the Crypto Caper
===> Dec 08 - Santa Claus Is Hacking to Town
===> Feb 2009 - Brady Bunch Boondoggle
===> July 2009 - Prison Break
===> October 2009 - SSHliders
===> December 2009 - Miracle on Thirty-Hack Street
===> December 2010 - The Nightmare Before Charlie Browns Christmas
-----------------------------
Resources
-----------------------------
=> Career Central
===> Looking For Work
===> Looking To Hire
=> Links to cool sites.
=> Mass Media
=> News from the Outside World
=> Tools
=> Tutorials
===> Tutorial Requests
Loading...
Exclusive Deal
SANSFIRE 2013
June 15 - 22
5% Off
w/ Code
:
EHN_5
SANS Deals 4 EH-Netters
5% OFF
Any
SANS Course
in Any Format!
Coupon Code:
EHN_5
Including
SANS Rocky Mountain 2013
&
SANS Boston 2013
Polls
Compared to this year, 2013 will be:
Great!
Better.
About the same.
Little worse.
FUBAR!
Recent Forum Topics
General Certification
: CPT Practical Submission
(0) by
z28power4u
OSCP - Offensive Security Certified Professional
: Class Scheduled 6/8 - Linux n00b
(5) by
MrTuxracer
Career Central
: Starter cert?
(0) by
Alert
Web Applications
: Nessus and Nikto
(4) by
Seen
Tutorials
: Need guidance
(7) by
impelse
Malware
: EICAR?
(2) by
SephStorm
Network Pen Testing
: Cracking salted MD5 hash
(4) by
n37sh@rk
CEH - Certified Ethical Hacker
: Passed my C|EH
(3) by
n37sh@rk
Mass Media
: EC-council hacked, irony at his best?
(0) by
j0rDy
Web Applications
: SQL Injection into an INSERT statement.
(6) by
eyenit0
Network Pen Testing
: Solution for sipXtapi INVITE Message CSeq Field Header Remote Overflow
(1) by
m0wgli
Web Applications
: dns
(2) by
H1t M0nk3y
Other
: BSides Boston
(0) by
3xban
Career Central
: InfoSec in Central, FL
(2) by
tturner
Web Applications
: Web vulnerability scanner
(4) by
H1t M0nk3y
EH-Net News Feeds
Latest Additions
Privacy Notice
for TDCC & All Properties
Free Business and Tech Magazines and eBooks
© 2013 The Ethical Hacker Network
Joomla!
is Free Software released under the GNU/GPL License.