Skip the navigation
News

IT Risks Rise on USB Drives

Auto-run apps add to security threats

By Jaikumar Vijayan
October 2, 2006 12:00 PM ET

Computerworld - Insiders stealing relatively large amounts of data on tiny USB memory sticks have already made the ubiquitous devices a potent security threat. But the emergence of flash drives capable of storing and auto-running applications straight off the device will likely make them an even greater security headache.

This danger is not going unnoticed by IT professionals.

USB thumb drives “pose a pretty big threat within the medical industry” if not properly managed, said Chris Anderson, an assistant analyst at John C. Lincoln Health Network in Phoenix. And his company has already deployed tools to protect against these new problems.

Demonstrating the potential risks, Hak.5, a security-related podcast run by self-described white-hat hackers, last month showed how a USB memory stick can be turned into a device capable of automatically installing back doors, retrieving passwords or grabbing software product codes.

“What makes it a security nightmare is that it’s a faster and automated way to do existing threats,” said Darren Kitchen, one of the hackers who hosts the Hak.5 podcasts from his home in Williamsburg, Va. “What could have been done before in four to five minutes can now be done in a few seconds,” he said.

The Hak.5 demonstration involved the use of a relatively new technology from Redwood City, Calif.-based U3 LLC that lets software execute directly from USB drives. Unlike traditional USB flash drives, U3 memory sticks are self-activating and can automatically run applications when inserted into a system by appearing to be a CD-ROM to a computer.

U3’s technology is designed to increase mobility by letting a user store his personal desktop with his programs, passwords and other data on a memory stick and then use them on any computer without worrying about whether those applications are installed. It’s among an emerging set of similar “smart” flash drives from vendors such as Migo Software Inc. in Redwood City, Calif., and Route 1 Inc. in Toronto.

But this boon to mobile end users gives malicious hackers another way to compromise systems, said John Pescatore, an analyst at Gartner Inc.

For instance, Hak.5 has already developed and made publicly available payloads that make it possible to use U3 thumb drives to automatically retrieve Windows password hashes, browser histories and AOL Instant Messenger and MSN passwords. For the moment, they only work if the user has full administrative privileges on the computer in which the USB device is inserted. But in the works is a hack that automatically escalates user privileges via a U3 drive. Another pending hack deposits code on a computer that steals information off any USB key that is subsequently inserted into the machine by e-mailing the data to another location.



Additional Resources
Forrester Consulting - Optimizing Users and Applications in a Mobile World
WHITE PAPER
Solving application issues over the WAN requires careful consideration. Based on their independent research, Forrester Consulting offers recommendations on how to tackle application performance issues, insufficient bandwidth and the inability to quickly restore users in a disaster.

Read now.

Security KnowledgeVault
WHITE PAPER
Security is not an option. This KnowledgeVault Series offers professional advice how to be proactive in the fight against cybercrimes and multi-layered security threats; how to adopt a holistic approach to protecting and managing data; and how to hire a qualified security assessor. Make security your Number 1 priority.

Read now.

Cut Communications Costs Once and for All
WHITE PAPER
New IP-based communications systems are being deployed by small and midsized businesses at a rapid rate. Learn how these organizations are enabling faster responsiveness, creating better customer experiences, speeding office or mobile interactions, and dramatically reducing existing communications costs.

Read now.

Storage White Papers
Datacenter Consolidation Best Practices Whitepaper
The benefits of storage consolidation are being realized by companies and seen as a way to streamline many storage-driven applications. Learn why the...
Eliminating VMware / Storage Related Performance Challenges
How to proactively monitor the performance in a Fibre Channel SAN / vSphere environment is always a concern. Understand the importance of a...
Cloud Environments Have Familiar Storage Challenges
Cloud environments have many storage challenges that are familiar to data center managers, but due to their density and abstraction, the issues become...
Eight Considerations for Evaluating Disk-Based Backup Solutions
In the past, the movement from tape- to disk-based backup has been less compelling due to the expense of storing backup data on...
ExaGrid Helps U.S. Federal Government Agencies Reduce Backup Windows and Improve Data Protection
The U.S. Government has been the largest user of tape-based backup systems since the 1970s. Most agencies have begun to deploy disk storage...
All Storage White Papers
Storage Webcasts
Understand Your Data: The Future of Backup and Archiving
Archiving and Backup are the foundation of the next generation of information governance. However, commodity data protection tools and basic archives are only...
Optimizing Networks for the Cloud
Join guest speaker, Rohit Mehra, IDC Director of Enterprise Communications Infrastructure, to explore current trends, discuss best practices for optimizing Data Center and...
Apps QuickStart Series Part 2: Designing and Deploying SQL Server on VMware vSphere
Download this webcast to learn about the design considerations for virtualizing SQL workloads, performance and scalability information and high-availability options, as well as...
Apps QuickStart Series Part 1: Designing and Deploying Exchange 2010 on VMware vSphere
Download this webcast to learn the virtual hardware design considerations for Exchange 2010, deployment using the building block approach, options for high-availability and...
Customer Spotlight: How IPC The Hospitalist Company Implemented Oracle on VMware
Have you been looking to hear about customer's experiences with the new VMware vCenter Site Recovery Manager product? View this webcast to learn...
All Storage Webcasts
Newsletter Sign-Up

Receive the latest news test, reviews and trends on your favorite technology topics

Choose a newsletter
  1. View all newsletters | Privacy Policy
IT Jobs