HomeSecurityCompromising SD cards to execute malicious code

Compromising SD cards to execute malicious code

hacking-micro-sd-cards

An SD card isn't just a storage device, it also has built-in microcontrollers. That sounds good, right? But researchers say it's not.

Two hardware hackers, Bunnie and Xobs, participated in a talk about MicroSD card hacking at the Chaos Computer Congress (30C3). The researchers claim that SD cards are vulnerable to arbitrary code execution.

In a blog post, Bunnie said that SD cards have a built-in microcontroller, usually a modified 8051 or ARM CPU. The reason there is a microcontroller inside SD cards is because it is cheaper than a thorough check to ensure their operation. These microcontrollers can be used for both good and bad purposes.

On the dark side, attackers can run malicious code to perform a perfect Man in the Middle (MITM) attack, which would be difficult to detect.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS