what's the attack? the website just drones on about a cable that, as far as i can tell, could just broadcast your keypresses over wifi.
(it couldn't read user keypresses unless they use the cable to plug in their keyboard)
51–60 of 159 posts
what's the attack? the website just drones on about a cable that, as far as i can tell, could just broadcast your keypresses over wifi.
(it couldn't read user keypresses unless they use the cable to plug in their keyboard)
Huh, so all it takes is someone to break into your home when you're gone and swap a cable. Seems like privacy doesn't really exist for people who truly need it. Unless they're not using any technology.
Would a high voltage loop, for breaking components, be a good solution to an attack like this? Like, fry the electronic components to verify it's just plain metal on the insides?
The construction of this device is quite impressive, in that it fits entirely inside a USB plug The level of miniaturisation is not all that impressive, these have been around for a while: https://www.amazon.com/Edimax-EW-7811Un-150Mbps-Raspberry-Su... There's no mention of using the rest of the cable as the antenna, since in my experience the above tiny adapters have an equally tiny antenna and thus poor reception.
It says there's a microcontroller as well.
This is scary. I mean someone can just replace the cables in my house and my phones and computer would become infected. I can't even imagine the headache this does for company's cybersecurity practices. A rogue janitor replaces the usb cables on some of the employees of a company that makes $INSERT_SUPER SECRET_TECH$ and done.
>I mean someone can just replace the cables in my house and my phones and computer would become infected. Only if you leave your computer unlocked and unattended. If it's attended, obviously you'll see something's going on and pull the plug on the computer and probably investigate further. If your computer is locked (which is a good habit to have when leaving your workstation, the faked keyboard can't do.
Earlier quoted context omitted.
My understanding is that it allows an attacker connected to it via WiFi to mess with the plugged-in computer using USB (pretending to be a keyboard). See the Twitter video: https://mg.lol/blog/omg-cable/
Unless the attacker is able to view the screen somehow then this is pretty useless. Or at least no more useful than fake keyboards without WiFi.
Better than that is to just type a PowerShell script that gets all the info immediately and sends it to a server.
This is scary. I mean someone can just replace the cables in my house and my phones and computer would become infected. I can't even imagine the headache this does for company's cybersecurity practices. A rogue janitor replaces the usb cables on some of the employees of a company that makes $INSERT_SUPER SECRET_TECH$ and done.
In secure locations it's common for USB ports to be physically blocked (the ones I've seen with glue/resin).
Can someone confirm for me? This needs a nearby wifi network that is either open or has credentials too, correct? The video appeared to have it connect directly to the phone or to the network they both were on.
so... that could be useful to penetrate secure facilities, like nuclear weapons bunkers/reactors. A worker is sent a cable as a "gift" or has one substituted in by mail intercept for an actual order. Attacker waits outside in a van and controls things over wifi.