Live data from Hacker News

WiFi Hides Inside a USB Cable

hackaday.com

101–110 of 159 posts

Re: WiFi Hides Inside a USB Cable

#101
post #50

Earlier quoted context omitted.

Unless the attacker is able to view the screen somehow then this is pretty useless. Or at least no more useful than fake keyboards without WiFi.

PrintScreen/Upload screenshot to web server/Wait for command Better than that is to just type a PowerShell script that gets all the info immediately and sends it to a server.

You can do all of that without WiFi. How is an attacker with no vision of the screen any more useful than a script that can auto type a command to get remote access?

Re: WiFi Hides Inside a USB Cable

#102

Earlier quoted context omitted.

I don’t know how to reply without being too snarky. Is your position that we shouldn’t “allow” someone to build a wifi module hidden in a USB cable, because we don’t allow rape and murder? I’ll let someone else see if they can help you out. But I think you need to take a BIG step back and ask yourself this “have I solved all the problems in my own life” and if the answer is no, stop thinking so much about what other…

I think I've inadvertantly pressed some buttons, which I do apologise for - whole heartedly! The written language is a very imperfect thing to get right. I'm not trying to bait anyone in words. Ironically, I do try to "let it be" and to not be a hypocrite in my day to day life. However, we are imperfect beings, and we all make mistakes (well, at least I do!). I recognise the engineering and technical expertise of thi…

I think the point of people doing this is to prove publically that it can be done, and therefore almost certainly has already been done before by someone with nefarious intent who kept it quiet.

Re: WiFi Hides Inside a USB Cable

#103
post #31

Earlier quoted context omitted.

Perhaps, but it could start a fire. You might consider plugging into a power supply and measuring if there is any current draw.

USB type A male-to-female inline ammeters are really cheap, and accurate to 0.1W. I got one for ten bucks.

+/-20mA seems a bit coarse...with modern low-power silicon, imagining it wouldn't be too difficult to skate under that radar.

Re: WiFi Hides Inside a USB Cable

#104
post #28

Would a high voltage loop, for breaking components, be a good solution to an attack like this? Like, fry the electronic components to verify it's just plain metal on the insides?

Just do an insulation test at say 250V using a commonly available 'megger' device

Re: WiFi Hides Inside a USB Cable

#105

Earlier quoted context omitted.

While I understand how this could've been fun to 'try out', I can think of nothing but ways that this can be seriously abused. (atm attacks, corporate spying, ...) Can a device like this be used do anything positive toward humanity? Did I misunderstand something? (I'm genuinely curious!) Edited: reworded (honest) question to be less negative.

>How does a device like this do anything but affect humanity in a negative way? How is the kind of 'research' remotely legal? Here is some advice, whenever you think “there aught to be a law...” there probably shouldn’t be. Planes would be falling out of the sky and high rises would be on fire if everyone had your sense of what types of research should “be allowed”.

Perhaps I'm misunderstanding your comment but the reason planes aren't falling out of the sky and high rises aren't all on fire is because these things are so heavily regulated.

Not that I'm a fan of knee-jerk reactive lawmaking, but they struck me as odd examples.

Re: WiFi Hides Inside a USB Cable

#106
post #20
post #3

This is scary. I mean someone can just replace the cables in my house and my phones and computer would become infected. I can't even imagine the headache this does for company's cybersecurity practices. A rogue janitor replaces the usb cables on some of the employees of a company that makes $INSERT_SUPER SECRET_TECH$ and done.

In secure locations it's common for USB ports to be physically blocked (the ones I've seen with glue/resin).

I have seen in the UK solder used to physically block usb ports on laptops - this was QinetiQ (the bit that remained as civilservants).

Of course they equipped the laptop with a cd burner

Re: WiFi Hides Inside a USB Cable

#107
post #42

Earlier quoted context omitted.

It can't (unless it's the keyboard cable).

Hid usually ok with systems and hence a wireless mouse and keyboard pretended. A windows hack may be - The “mouse” would ask to move to leftmost bottom corner then click. Type searching terms like Cmd . Then if can get hold of the windows one is in ... Any better idea?

Keyboard shortcuts.

Re: WiFi Hides Inside a USB Cable

#108
post #34

Earlier quoted context omitted.

It can't read your keypresses (I think)

I took GP to be speculating about a hypothetical secretly-IoT-keyboard, not the cable being discussed. Similar thoughts are explored in the comments on TFA.

Yes. I assumed it would be straightforward after you figure out how to hide wifi inside a USB cable.

Re: WiFi Hides Inside a USB Cable

#109
post #101

Earlier quoted context omitted.

PrintScreen/Upload screenshot to web server/Wait for command Better than that is to just type a PowerShell script that gets all the info immediately and sends it to a server.

You can do all of that without WiFi. How is an attacker with no vision of the screen any more useful than a script that can auto type a command to get remote access?

It's more useful precisely because there's nothing running and no remote access on the OS. Traceless. Norton ain't catch that.

Re: WiFi Hides Inside a USB Cable

#110
post #67

Earlier quoted context omitted.

'How' is DHCP. That's one. Apparently there are least 28 more ways to use usb to attack a machine. https://www.bleepingcomputer.com/news/security/heres-a-list-...

>'How' is DHCP. Not without notice. Your computer won't connect to a wirless network automatically. So in order for this to work, the USB-device needs the same SSID and key. Then, in order to make it not suspicious (and get your data) you need to actually forward traffic to the internet. Not sure if those devices can repeat. Emulating an USB ethernet might help you, as those will connect, but without uplink it's stil…

The "cable" has WiFi, so it's probably possible to set up a hidden WiFi network around the premises of the target and have the implant connect with that. With the right type of antenna you can set up a WiFi connection to a specific device from quite a way away. Then tunnel the connection from your malicious AP and emulate ethernet on the USB side of the implant.

Or, search for open/guest networks and use those as an uplink. There's plenty of possibilities for this to work as a malicious network adaptor.

However, I think the network example is just a proof of concept and the remote connectivity is much more interesting to any real attacker.

Post reply on HN