Ads by TechWords

See your link here
Receive the latest technology news and information.
Storage
Computerworld Daily News (First Look and Wrap-Up)
Computerworld Blogs Newsletter
The Weekly Top 10
Cloud Computing
View all newsletters




Privacy Policy
 

IT Risks Rise on USB Drives

Auto-run apps add to security threats

October 2, 2006 12:00 PM ET

Computerworld - Insiders stealing relatively large amounts of data on tiny USB memory sticks have already made the ubiquitous devices a potent security threat. But the emergence of flash drives capable of storing and auto-running applications straight off the device will likely make them an even greater security headache.

This danger is not going unnoticed by IT professionals.

USB thumb drives “pose a pretty big threat within the medical industry” if not properly managed, said Chris Anderson, an assistant analyst at John C. Lincoln Health Network in Phoenix. And his company has already deployed tools to protect against these new problems.

Demonstrating the potential risks, Hak.5, a security-related podcast run by self-described white-hat hackers, last month showed how a USB memory stick can be turned into a device capable of automatically installing back doors, retrieving passwords or grabbing software product codes.

“What makes it a security nightmare is that it’s a faster and automated way to do existing threats,” said Darren Kitchen, one of the hackers who hosts the Hak.5 podcasts from his home in Williamsburg, Va. “What could have been done before in four to five minutes can now be done in a few seconds,” he said.

The Hak.5 demonstration involved the use of a relatively new technology from Redwood City, Calif.-based U3 LLC that lets software execute directly from USB drives. Unlike traditional USB flash drives, U3 memory sticks are self-activating and can automatically run applications when inserted into a system by appearing to be a CD-ROM to a computer.

U3’s technology is designed to increase mobility by letting a user store his personal desktop with his programs, passwords and other data on a memory stick and then use them on any computer without worrying about whether those applications are installed. It’s among an emerging set of similar “smart” flash drives from vendors such as Migo Software Inc. in Redwood City, Calif., and Route 1 Inc. in Toronto.

But this boon to mobile end users gives malicious hackers another way to compromise systems, said John Pescatore, an analyst at Gartner Inc.

For instance, Hak.5 has already developed and made publicly available payloads that make it possible to use U3 thumb drives to automatically retrieve Windows password hashes, browser histories and AOL Instant Messenger and MSN passwords. For the moment, they only work if the user has full administrative privileges on the computer in which the USB device is inserted. But in the works is a hack that automatically escalates user privileges via a U3 drive. Another pending hack deposits code on a computer that steals information off any USB key that is subsequently inserted into the machine by e-mailing the data to another location.



Jump to comments

hak.5

Additional Resources

EFD vs. HDD - What You Need to Know
WHITE PAPER
Enterprise flash drives provide a new Tier 0 storage layer capable of delivering high I/O performance at a very low latency. Proper use of EFDs in an Oracle environment can deliver increased performance compared to fibre channel drives. Read the recommendations for identification of the best DB components for EFDs.
Gartner Research Report: Magic Quadrant for Application Delivery Controllers, 2009
WHITE PAPER
The market for products to improve the delivery of application software over networks remains dynamic and innovative. Vendors focused on solving enterprises' most-pressing application problems have become the top players.
Eight Criteria for Server Load Balancing
WHITE PAPER
Server load balancers are a simple yet highly effective means to scale an application environment while ensuring its availability. Today's solutions should also address application performance and security. Read about the top eight criteria you should consider when choosing a server load balancer and how Citrix NetScaler meets those requirements.

White Papers & Webcasts

Cache Tier Memory Efficiency with Gear6 Web Cache
Download this valuable white paper!  

Connecting to the Cloud with F5 and VMware VMotion
F5 and VMware partner to enable live application and storage migrations between datacenters and clouds, over short or long distances.  

Virtualize Microsoft Applications on VMware
Register for this live webcast now!

F5 Virtualization Guide: Seven Key Challenges You Can't Ignore
Seven Key Challenges You Can't Ignore  

Strategic ECM Webinar
Learn what new strategic business benefits can be realized through ECM!


IT Jobs

 

Partnered Content
Hitachi - Inspire the Next
Storage Economics: Understanding Tiered Storage Solutions
Storage Economics is a suite of methodologies, tools, and services that help customers identify the total cost of storage ownership and provide a tiered storage solution to reduce ongoing costs. Understand the benefits of implementing a tiered storage architecture which include improving storage capacities and easing the access demands to any single storage tier. Learn more.
Download this white paper 
Strategies for an Increasingly Cost-Conscious Data Storage World
Whatever word you use, we can all agree that the global economy continues to face challenging times. Yet, the essential challenge remains the same: IT demands continue to increase but the resources to address such challenges are being flattened or cut. However, we truly have an opportunity here to do more with less and focus on efficiency. Hitachi can help. Learn more.
Download this white paper 
Four Principles to Reduce TCO
Yes, good news! The good news is that there are proven strategic investments available today for storage infrastructure cost reduction. Smart organizations will follow the principles of Storage Economics to evaluate them not just for their technical prowess but also for how well they can support business performance and particularly efforts to economize. Learn more.
Download this white paper