Penetration Testing mailing list archives

Re: Security with USB Devices


From: Terry Vernon <tvernon24 () comcast net>
Date: Tue, 26 Jul 2005 17:09:59 -0500

Well I'm not sure on this one but I would copy the autorun file from a CD that autoloads when you insert it and modify the command it gives while also making sure the properties stay the same. I'm sure that Microsoft would have enabled some sort of disabling of autoload when the screen is locked to prevent pranks and other stuff like what you're trying to do. then again my info is unfounded and based on what I can think of off the top of my head so take it with a grain of slat. Then again Microsoft Security is an oxymoron so it may work.

Terry Vernon
CTO
Sprite Technologies

NewYork User wrote:

List,
Does any one know a good program to "autorun" from USB drive on a
windows 2000 or an XP machine? I have tried the traditional
Autorun.inf but didn't have any luck. I looked up in google but
couldn't find any useful stuff. I saw some commercial programs to use
for backup etc..But its not of any use if I want to prove my point
that data can be vulnerable if use of USB drives is not restricted
either by using a program or any kind of security control. I created a
simple batch file to open up a Netcat listener. It is pretty common
for the users lock their machines and leave their desks. I'm looking
for any kind of scripts that can run a batch file automatically or can
copy the data automatically. Any ideas?

Thanks for your help.



Current thread: