ShmooCon 2011: USB Autorun attacks against Linux
Sign in to YouTube
Sign in to YouTube
Sign in to YouTube
Uploaded on Feb 3, 2011
Speaker: Jon Larimer
Many people think that Linux is immune to the type of Autorun attacks that have plagued Windows systems with malware over the years. However, there have been many advances in the usability of Linux as a desktop OS - including the addition of features that can allow Autorun attacks. In this presentation, I'll explain how attackers can abuse these features to gain access to a live system by using a USB flash drive. I'll also show how USB as an exploitation platform can allow for easy bypass of protection mechanisms like ASLR and how these attacks can provide a level of access that other physical attack methods do not. The talk will conclude with steps that Linux vendors and end-users can take to protect systems from this threat to head off a wave of Linux Autorun malware.
For more information visit: http://bit.ly/shmoocon2011_information
To download the video visit: http://bit.ly/shmoocon2011_videos
-
Category
-
License
Standard YouTube License
Loading...
Loading...
Loading...
Loading...
Loading...
-
2:54
The Big Bang Theory - The Cooper-Nowitzki Theoremby TheLukasnetFeatured
348,952
-
56:02
ShmooCon 2011: URL Enlargement: Is it for You?by Christiaan008
892 views
-
43:26
ShmooCon 2011: Visual Malware Reversing: How to Stop Reading Assembly and Love the Codeby Christiaan008
7,633 views
-
50:45
Shmoocon 2012: Credit Card Fraud: The Contactless Generationby SecurityTubeCons
8,203 views
-
21:37
Shmoocon 2012: Lessons of the Kobayashi Maru: Cheating is Fundamentalby SecurityTubeCons
36,642 views
-
Linux
76,500 videos770
-
1:15:44
BlackHat EU 2011: Keynote-Schneierby Vincenzo Tilotta
12,017 views
-
40:15
Shmoocon 2012: Encryption, Passwords and Data Security: the Latest on the Law and Best Practicesby SecurityTubeCons
1,022 views
-
32:19
ShmooCon 2011: Printers Gone Wild!by Christiaan008
8,407 views
-
25:05
ShmooCon 2011: Stealing Sensitive Data from Thousands of Systems Simultaneously with OpenDLPby Christiaan008
3,795 views
-
23:24
ShmooCon 2011: Hackers for Charityby Christiaan008
1,878 views
-
2:23:45
DEFCON 13: Introduction to Lockpicking and Physical Securityby Christiaan008
5,685 views
-
47:23
ShmooCon 2011: Project Ubertooth: Building a Better Bluetooth Adapterby Christiaan008
4,013 views
-
31:19
ShmooCon 2011: Are you receiving me? Recent issues in wifi privacyby Christiaan008
1,611 views
-
50:51
ShmooCon 2011: Printer to PWND: Leveraging Multifunction Printers During Penetration Testingby Christiaan008
3,366 views
-
13:07
We need to start attacking Disc Detainer locks. Shmoocon Firetalks 2011by SchuylerTowne
10,567 views
-
53:40
ShmooCon 2011: Inside the App: All Your Data are Belong to Meby Christiaan008
2,039 views
-
40:15
Shmoocon 2012: All Your Codes Belong To Me!by SecurityTubeCons
827 views
-
19:09
ShmooCon 2011: ZigBee Security: Find, Fix, Finishby Christiaan008
2,506 views
-
16:02
WINDOWS VS. LINUX 2011 (Windows 7 VS Zorin OS 4)by tostoday
8,865 views
-
0:41
Why Linux is BETTER!by SolarisZen
273,496 views
- Loading more suggestions...
Top Comments
kyuznum1 2 years ago
This is by far the best SchmooCon talk on USB Autorun attacks I've seen this morning.
Sign in to YouTube
Sign in to YouTube
reya10276 2 years ago
blah blah blah...Sure if your Linux/Ubuntu system is not patched then sure you would be in trouble otherwise nothing to see here move on folks. Linux/Ubuntu is still way more secure than any windows version by default. So lets simmer down windows fanboys. Also Ubuntu is secure with app armor, hence is one of the main things Ubuntu emphasizes on in their advertisement of Ubuntu. Also if and when this suppose attack would happen it wont affect the actual system at the root level.
Sign in to YouTube
Sign in to YouTube
All Comments (35)
galenrivera512 1 year ago
I want this video on my GU1100 phone.
Sign in to YouTube
Sign in to YouTube
siodhe 1 year ago
The problem with that plan with regards to xlock, namely killing the xlock and then putting up a fake one with a fake login window (if I'm interpreting your correctly) is as I said: The access list has been wiped from the X server - *nothing* could access it at that point, the X server had to be killed to continue, logging out the user's session in the process. And TheMegentus mentioned that killing the screensaver would kill off the session directly, an even more direct approach.
Sign in to YouTube
Sign in to YouTube
MsPwain 1 year ago
Thanks for making Linux more secure and me a bit smarter. Good talk.
Sign in to YouTube
Sign in to YouTube
frenchpet 1 year ago
This is cool
Sign in to YouTube
Sign in to YouTube
Fredderic Unpenstein 1 year ago
Interesting talk... I am curious, though, when I was last using Debian, killing the screensaver caused the entire session to get killed, giving you a nice new login prompt, on a fresh X server. Doesn't that happen any more in modern installs?
Sign in to YouTube
Sign in to YouTube
siodhe 2 years ago
Hi :-) Many linux users don't run the user level tools (nautilus..) in the exploit, completely removing this vector. The older xlock program would wipe the access list, and so when killed would leave the X11 server unusable (obviously the modern screensavers need to be updated to the same destroy-access mentality). The TCP port mentioned in the demo in disabled by default in Xorg (the X11 server). And lastly, remember these exploits only grant user access, not root (although closer to root)
Sign in to YouTube
Sign in to YouTube