Live data from Hacker News

WiFi Hides Inside a USB Cable

hackaday.com

41–50 of 159 posts

Re: WiFi Hides Inside a USB Cable

#41
post #34
post #18

Earlier quoted context omitted.

A secretly-IoT keyboard that shares your key presses and may "type" malicious stuff when you're not looking at it; the OS wouldn't be able to tell it's not you doing the typing. Not scary at all, no sir.

It can't read your keypresses (I think)

So long as it can simulate them, installing a keylogger that can read them too is a matter of a few seconds (to "type" a PowerShell script that will download and execute the desired payload).

Re: WiFi Hides Inside a USB Cable

#42
post #34

Earlier quoted context omitted.

It can't read your keypresses (I think)

It can't (unless it's the keyboard cable).

Hid usually ok with systems and hence a wireless mouse and keyboard pretended.

A windows hack may be - The “mouse” would ask to move to leftmost bottom corner then click. Type searching terms like Cmd. Then if can get hold of the windows one is in ...

Any better idea?

Re: WiFi Hides Inside a USB Cable

#43

I guess even some sort of "signed device protocol" will not work. An attacker can just create a device that guesses the device identifier (or whatever is used to create the signature). Then, the attacker device can just keep guessing until it gets it right. Chances are, some serial number or similar will be used for this, so continuous guessing is feasible. Will the solution to this, then, be to have some sort of "sm…

[deleted]

Re: WiFi Hides Inside a USB Cable

#45
What is the wifi for? the only attack I can possibly see here is pretending to be a keyboard. And you don't need wifi for that, you just need a pre programmed set of steps to set up remote control for the pc.

Re: WiFi Hides Inside a USB Cable

#48

I guess even some sort of "signed device protocol" will not work. An attacker can just create a device that guesses the device identifier (or whatever is used to create the signature). Then, the attacker device can just keep guessing until it gets it right. Chances are, some serial number or similar will be used for this, so continuous guessing is feasible. Will the solution to this, then, be to have some sort of "sm…

>Will the solution to this, then, be to have some sort of "smart card enabled device"? For example, assuming TOFU, you manually accept all device's public keys (and all devices, including cables and stuff will have one of these). Then, the computer will have to verify all actions done by those devices by sending a challenge for each action.

Even that's not enough. If you're feeling extra-evil you could tamper with the keyboard switches/traces to do whatever evil stuff you want. It's not like you can authenticate the on/off state at a switch level.

Re: WiFi Hides Inside a USB Cable

#49
post #40

About a month ago I found a similar device on aliexpress that has GPS and SIM card slot: https://www.aliexpress.com/item/1m-USB-Charging-Data-Cable-f... ?

Wow, do you know it actually works? Seems cool.

Looking at the reviews, it seems that the "GPS" is just a cell tower ID, and the microphone is very quiet.

Re: WiFi Hides Inside a USB Cable

#50
post #10
post #6

Earlier quoted context omitted.

How? I've never seen a device, certainly not a PC, that will just randomly connect to any router it sees without some sort of user input.

My understanding is that it allows an attacker connected to it via WiFi to mess with the plugged-in computer using USB (pretending to be a keyboard). See the Twitter video: https://mg.lol/blog/omg-cable/

Unless the attacker is able to view the screen somehow then this is pretty useless. Or at least no more useful than fake keyboards without WiFi.
Post reply on HN