HomeSecurityInvisible vulnerability in USB devices

Invisible vulnerability in USB devices

We all use USB in our digital lives. New research first reported by Wired reveals that there is a fundamental security flaw in the way the Universal Serial Bus works, and it could be exploited to take down any computer.

USB

Wired reports that security researchers Karsten Nohl and Jakob Lell were able to reverse engineer the firmware that controls the USB's basic communication functions. They then wrote a malware they called BadUSB. The malware can "install itself on a USB device and take complete control of a computer. The malware is invisible and does not modify the files on the memory stick.".

Embedded inside USB devices is a controller chip that allows the device and the computer it's connected to to send and receive information. That's where Nohl and Lell's intervention came in. That means their malware doesn't sit in flash memory, but is hidden in the firmware, making it undetectable to even the most technically savvy. Lell told Wired:

“You can give it to security researchers, they scan it, delete some or all of the files, and give it back to you saying it’s ‘clean. The hack can’t be fixed.’”

The worrying thing is that the researchers will be presenting the hack at the upcoming Black Hat security conference in Las Vegas. The researchers say the flaw can be exploited in any portable drive, mouse, keyboard, and even Android smartphones. (Theoretically, it could work on any USB device whose firmware can be reprogrammed.).

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS