Interesting regarding USB devices. When US DoD systems were infected with a virus someone brought from home on a USB stick, I remember hearing there were going around filling USB ports with epoxy. There was some method behind the madness I guess. There is also a market for routers and other devices which are produced as much as possible in US (are they rolling their own capacitors I am wondering...). I saw some of th…
Just put the software in the device in ROM, a forgotten technology. No malware will survive a power cycle. It's like I read that malware could infect your "internet of things" thermostat and then hackers could remotely turn off your heat until you pay ransom. Just put the dang thermostat code in ROM. Power cycle, goodbye malware. For more critical stuff, just have it regularly power cycle itself.
Researchers crack open malware that hid for 5 years
201–210 of 232 posts
Re: Researchers crack open malware that hid for 5 years
#202Earlier quoted context omitted.
> This seems apocryphal. Its trivial to disable USB for a mass storage (or all devices) via things like group policy or other security controls. Or disable the controller. The question is - where do you stop? The controller could be re-enabled from a lower level, etc. The rabbit hole goes very deep. Sometimes it's best to just take control of the physical layer and call it a day. > Those USB ports aren't perfect boxe…
> The controller could be re-enabled from a lower level, etc In a managed environment you could do it via the BIOS trivially, which is most likely locked as well. I mean, glueing the ports is especially stupid. You can chip glue off with your fingers or a key. If you're doing physical things to the PC, you'd most likely just remove the USB header from the mb and call it a day. Pop-open the case the case, remove it, b…
> In a managed environment you could do it via the BIOS trivially, which is most likely locked as well.
The BIOS may still not be low-level enough. There is nothing preventing a buggy xhci controller, chipset, BIOS, etc, from being exploited by a rogue USB device. It would be prudent to disable USB in the BIOS AND physically disable the ports somehow.
> Pop-open the case the case, remove it, bend down the pins, or cut it and go about your business. Messing with stuff that takes 60 minutes to cure is ridiculous.
You do not need epoxy to fully cure, you only need it to reach a point where the viscosity is high enough that enough of it won't drain out of the USB port when you turn the computer on its side. This can easily be under 5 minutes, depending on the type of epoxy and you could even trivially avoid that wait time by putting a piece of tape over the epoxied port. It may also even be cheaper to implement, since you can pay someone minimum wage to fill ports with epoxy, but it takes a slightly higher skill level to do work inside of computer cases. Additionally, it's easier to visually verify that all USB ports are epoxied than it is to verify that all internal USB connectors have been disconnected. Additionally, consider that many motherboards have rear USB ports directly soldered onto the motherboard, which would take far more effort and skill to disconnect than it would to just fill the port with epoxy.
> It would take two minutes for a stoned teenager to pop-open the case and plug in his own USB connector into the header in this scenario. Less time for a determined attacker.
An attacker who has broken into the government building is not the person who this is intended to guard from. It is intended to guard from employees accidentally inserting compromised USB devices into their computers. If the attacker is opening your computer case, they have many more options than USB ports for delivering an exploit payload. Though it's also very likely that these cases are also physically locked and have case intrusion detection enabled. Not that those protections are particularly difficult to get around either. This may also even help IT avoid support phone calls from users saying "hey, how come my USB port doesn't work?" where epoxy in the ports shows some serious intent.
Additionally, in the case of a real attacker who has physically entered the building, and intends to deliver their payload by flash drive: formerly they could just waltz by some computer, pop a drive in, and walk away. Now they'd need to at the very least open the case, which at the very least makes it take slightly longer for them to deliver their payload, and is much more likely to draw suspicion.
Re: Researchers crack open malware that hid for 5 years
#203Earlier quoted context omitted.
> This seems apocryphal. I have no reason to believe the person I worked with would make it up. There would just be no point in it. > Its trivial to disable USB for a mass storage (or all devices) Except there are hundreds of different kinds of devices, and you tasked with quickly "doing something to fix the problem". Do you have time to go and dig through different types of BIOS menus or open the cases to all of the…
Why not just unplug the USB header if you want a physical solution? The idea that you're shoving glue in there is incredibly ridiculous. You can chip that off easily with your finger or a key. I seriously doubt this is a real story because it flies in the face of published STIGS and basic common sense. Nor would it stop a remotely determined attacker/idiot. That said, I could see glueing a panel to block them as a vi…
It also really is not trivial to chip off most types of even general-purpose epoxy with your finger on a flat surface, let alone a tiny USB port which your finger doesn't fit in. If the epoxy was selected with some level of care, it may be very, very time consuming, or nearly impossible to remove, even with the right tools.
No matter what, it's a helpful measure in addition to every other way you can also disable a USB port.
Re: Researchers crack open malware that hid for 5 years
#204Earlier quoted context omitted.
Just put the software in the device in ROM, a forgotten technology. No malware will survive a power cycle. It's like I read that malware could infect your "internet of things" thermostat and then hackers could remotely turn off your heat until you pay ransom. Just put the dang thermostat code in ROM. Power cycle, goodbye malware. For more critical stuff, just have it regularly power cycle itself.
Malware infection module can be stored nearby on different device infecting your target device every time you power it on, until you patch your device.
After all, if attacks can target A, B, or C, that is no excuse to not fix B.
Re: Researchers crack open malware that hid for 5 years
#205Earlier quoted context omitted.
> the DC's weren't patched As I understand it, airgapped systems are not in the habit of bringing software updates across the airgap, so unpatched everything is likely.
Its trivial to do with WSUS and off-line updates. But yeah, if its a shit run environment, it will get owned by someone eventually.
If the WSUS server were also air-gapped, then you're in the business of manually downloading each update, verifying it, and copying it to over to the air-gapped WSUS server offline.
Microsoft's Windows Update servers have also been compromised in the past. Depending on the level of security you're operating at, taking new windows updates on your air-gapped systems may require having someone decompile and review each update.
In general, being air-gapped prevents infinitely more exploits than windows updates could ever possibly cure; that is, until one of your admins uses his admin privileges to disable the USB port restrictions for 5 minutes that one time to copy that one file quickly so he can go home for the day. For this, there are epoxied USB ports.
Re: Researchers crack open malware that hid for 5 years
#206Interesting regarding USB devices. When US DoD systems were infected with a virus someone brought from home on a USB stick, I remember hearing there were going around filling USB ports with epoxy. There was some method behind the madness I guess. There is also a market for routers and other devices which are produced as much as possible in US (are they rolling their own capacitors I am wondering...). I saw some of th…
And that's why you can still buy new i7 and Xeon motherboards with PS2 keyboard connectors--because some sites don't want there to be USB ports on the computers.
Re: Researchers crack open malware that hid for 5 years
#207Earlier quoted context omitted.
Part of the reason that Windows is an approved OS is enterprise support. When you pay for hundreds of thousands of licenses for a product you can demand features. If the DoD went with Debian they would need an entire corps of developers to maintain government specific patches. Ubuntu offers enterprise support but it's from an African country and that is undesirable as you mentioned above. I've seen government systems…
SUSE is owned by Novell.
At least that is how I remember it.
Re: Researchers crack open malware that hid for 5 years
#208Earlier quoted context omitted.
Just put the software in the device in ROM, a forgotten technology. No malware will survive a power cycle. It's like I read that malware could infect your "internet of things" thermostat and then hackers could remotely turn off your heat until you pay ransom. Just put the dang thermostat code in ROM. Power cycle, goodbye malware. For more critical stuff, just have it regularly power cycle itself.
Then you can't do over the wire updates, which means no fixes after it's been manufactured and installed, which would probably increase the costs quite a bit.
In many cases that would probably be prohibitively expensive, but for a thermostat or a light switch, it should not be that difficult to do.
Re: Researchers crack open malware that hid for 5 years
#209Earlier quoted context omitted.
There's also value in being able to visually inspect it and say "Yep, that USB port's disabled" versus digging through EFI settings. Every motherboard is going to have that option in a slightly different place, but if you can put epoxy in one USB port you're pretty well set for any piece of hardware.
This scales to ${number_of_devices_you_can_see}. A hundred or more? Easier to manage remotely. You're also likely to have a very limited number of models in that case.
If you are paranoid enough or have actual reason to believe somebody would want to invade your network, epoxy is one way you can be really certain no one can hijack your network via an infected USB flash drive.
EDIT: Of course, if gluing the USB ports shut is all you do stop attackers, I am pretty much begging for trouble. And as somebody pointed out, disconnecting the USB ports from the main board, possibly disabling the pins is probably a better idea, as well as disabling the USB controller in firmware and locking the BIOS / setup, if it is part of a ... let's say comprehensive approach to securing your network.
Re: Researchers crack open malware that hid for 5 years
#210Earlier quoted context omitted.
Another way is to have a jumper that is required to enable the write cycle to the flash ROMs. That enables the manufacturer to update the ROMs before shipping, then remove the jumper. Anyone trying to compromise the device would then require physical access.
Make it a button, so the customer can apply updates, but they need to press a button to make it happen. Add another button which, using only software stored in ROM, reloads the firmware from ROM. Then you have updates, but only when the customer knows and wants it, and if they ever screw it up then they can get back to a known good state.
Update buttons ain't a good replacement for TPM hardware.