Image
 
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 10 guests and 2 members online
EH-Net Donations

Enter Amount:
$

Google Ads
EH-Net News Feeds
Latest Additions
Book Recommendations





 
Advertisement

You are here: Home arrow Forum arrow Ethical Hacking Discussions and Related Certificationsarrow Malwarearrow Military Bans Removable Media
Ethical Hacker Community Forums
January 09, 2009, 09:03:31 PM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: ChicagoCon 2009 - May 4 - 9. Boot Camps & an Ethical Hacking Conf. www.chicagocon.com
 
   Home   Help Calendar Login Register  
Pages: [1]   Go Down
  Print  
Author Topic: Military Bans Removable Media  (Read 2700 times)
0 Members and 1 Guest are viewing this topic.
jason
Sr. Member
****
Offline Offline

Posts: 370


Aut Viam Inveniam Aut Faciam


View Profile WWW
« on: November 20, 2008, 08:01:10 AM »

Due to the spread of the Agent.btx worm, removable media have been banned from sipr and nipr nets. While the article discussed the army specifically, it sounded like this was going to be implemented for all branches. Seems like a fairly serious situation.


http://blog.wired.com/defense/2008/11/army-bans-usb-d.html
Logged
sgt_mjc
Full Member
***
Offline Offline

Posts: 167


View Profile
« Reply #1 on: November 20, 2008, 08:33:09 AM »

It surprises me that they have not done this before. I know that the only removable media currently authorized on our classified systems for data transfer are CDs. Of course there are plenty of restrictions on how to use them for this purpose, but as far as other media goes, we are not even allowed to take a thumb drive in to the classified lab. We'll watch and see how this plays out.
Logged

Mike Conway
CompTia Security +
C|EH
jason
Sr. Member
****
Offline Offline

Posts: 370


Aut Viam Inveniam Aut Faciam


View Profile WWW
« Reply #2 on: November 20, 2008, 08:47:50 AM »

It certainly does seem to be the logical move. It surprises me that they were this lax about it to begin with.
Logged
ChrisG
EH-Net Columnist
Hero Member
*****
Offline Offline

Posts: 1049


View Profile WWW
« Reply #3 on: November 20, 2008, 10:38:53 AM »

well you are only "supposed" to use govt issued usb drives that would only touch other govt systems which "should" stop that, but we all know how well that works...
Logged

...tests i took go here...

http://carnal0wnage.blogspot.com/
RoleReversal
Hero Member
*****
Offline Offline

Posts: 508


View Profile WWW
« Reply #4 on: November 20, 2008, 10:58:14 AM »

well you are only "supposed" to use govt issued usb drives that would only touch other govt systems which "should" stop that, but we all know how well that works...
Chris beat me too it  Sad. Has anyone read how they intend to enforce this?

I'm hoping they'll be some form of edge protection to stop the functionality of USB drives if inserted, rather than 'please don't do that'. But from the mention of govt issued devices in the future I'm guessing not. Looks like an way to create scapegoats rather than address the fundamental issues.

From those in the know does the military not already have a boiler plate AUP stating 'don't connect nasty things to our network'? If so, how is this different?
Logged

A little bit of sanity:
http://www.infosanity.co.uk
ChrisG
EH-Net Columnist
Hero Member
*****
Offline Offline

Posts: 1049


View Profile WWW
« Reply #5 on: November 20, 2008, 10:59:52 AM »

ha i win!

they do have the AUP, i think this is a "dont do anything until your drive has been scanned" scenario, just to curb the spread.  least thats what the article said.
Logged

...tests i took go here...

http://carnal0wnage.blogspot.com/
jason
Sr. Member
****
Offline Offline

Posts: 370


Aut Viam Inveniam Aut Faciam


View Profile WWW
« Reply #6 on: November 20, 2008, 11:22:53 AM »

i think this is a "dont do anything until your drive has been scanned" scenario, just to curb the spread.

Which will of course be totally useless if you turn right back around and plug it into your spammy, malware-ridden, porn storage device again.
Logged
ChrisG
EH-Net Columnist
Hero Member
*****
Offline Offline

Posts: 1049


View Profile WWW
« Reply #7 on: November 20, 2008, 12:49:05 PM »

exactly
Logged

...tests i took go here...

http://carnal0wnage.blogspot.com/
sgt_mjc
Full Member
***
Offline Offline

Posts: 167


View Profile
« Reply #8 on: November 20, 2008, 12:55:30 PM »

It cracks me up, but you are right about the AUP: scan then use..... Of course we all know that only works if there is a signature for the malware and IF the end user actually does scan it. Oh well....
Logged

Mike Conway
CompTia Security +
C|EH
jason
Sr. Member
****
Offline Offline

Posts: 370


Aut Viam Inveniam Aut Faciam


View Profile WWW
« Reply #9 on: November 28, 2008, 09:22:16 PM »

Another article with slightly more detail on the specifics of the malware issue:

http://www.latimes.com/news/nationworld/iraq/complete/la-na-cyberattack28-2008nov28,0,230046.story
Logged
ChrisG
EH-Net Columnist
Hero Member
*****
Offline Offline

Posts: 1049


View Profile WWW
« Reply #10 on: November 28, 2008, 10:33:05 PM »

It cracks me up, but you are right about the AUP: scan then use..... Of course we all know that only works if there is a signature for the malware and IF the end user actually does scan it. Oh well....

what you mean all AV doesnt find custom written malware...oops.
Logged

...tests i took go here...

http://carnal0wnage.blogspot.com/
Pages: [1]   Go Up
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.7 | SMF © 2006-2007, Simple Machines LLC
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.04 seconds with 23 queries.
 
Sponsors

cwnp_moto__120x90.gif

Polls
How many security events including conferences and training do you attend a year:
 
Support EH-Net


Support EH-Net by
Buying all of your
Amazon items using
the search bar above.

cbtnuggets_logo_125.jpg
Try CBT Nuggets Free!
Recent Forum Topics
Vote For EH-Net

progenic.com
Click here to Vote!

binarica.com
Binarica Logo

Add to Technorati Favorites
technorati fave

 
         
Advertisement

© 2009 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.