Penetration Testing mailing list archives

Re: Autorun programs from flash drive.


From: Victor DaViking <analogviking () yahoo com>
Date: Thu, 17 Apr 2008 11:57:59 -0700 (PDT)

Hello there Arckeda,

You will probably find the following post of help: 

http://www.penetrationtests.com/blog/2007/10/12/sample-code-for-u3-sandisk-usb-autorun/

I show sample code for turning a sandisk usb w/u3 into
a sniffer that gets installed w/autorun.

Hope that helps you achieve whatever is it that you're
looking to have done. 

Use it for good!

peace,
-AV


--- arckeda () yahoo com wrote:

Hello, and thanks for reading this.  I am sure we
are all know of the Autorun feature in Cdroms and
Dvdroms, how the program just runs out of the box. 
I am trying to figure out how to include this
functionality in flash drives.
/* I have a SD card with a USB adapter to test with.
*/
This would allow, say, for me to quickly insert a
drive into a computer, have it silently run
something like Meterpreter or another backdoor
program, and then have remote access to the
computer, assuming Windows runs it and doesn't
detect a malicious program.  I understand that
Windows by default will not run Autorun.inf by
default on flash drives, except the U3s.  But I have
also heard that you can format a flash drive to look
like a cdrom to Windows.  This is about all I know. 
If you have any more information, or would know
about how to go about doing this, please tell me.
Thank you again.
     -ARCKEDA


------------------------------------------------------------------------
This list is sponsored by: Cenzic

Need to secure your web apps NOW?
Cenzic finds more, "real" vulnerabilities fast.
Click to try it, buy it or download a solution FREE
today!

http://www.cenzic.com/downloads

------------------------------------------------------------------------





      ____________________________________________________________________________________
Be a better friend, newshound, and 
know-it-all with Yahoo! Mobile.  Try it now.  http://mobile.yahoo.com/;_ylt=Ahu06i62sR8HDtDypao8Wcj9tAcJ


------------------------------------------------------------------------
This list is sponsored by: Cenzic

Need to secure your web apps NOW?
Cenzic finds more, "real" vulnerabilities fast.
Click to try it, buy it or download a solution FREE today!

http://www.cenzic.com/downloads
------------------------------------------------------------------------


Current thread: