Penetration Testing mailing list archives

RE: Autorun programs from flash drive.


From: "Joe Klein" <Josephk () mischoice com>
Date: Wed, 16 Apr 2008 12:11:38 -0500

This is the functionality that U3 provide.

Also, Microsoft's StartKey program plans on providing similar capabilities
to non usb drives.

http://www.everythingusb.com/microsoft-startkey-14376.html

-joe

-----Original Message-----
From: listbounce () securityfocus com [mailto:listbounce () securityfocus com] On
Behalf Of arckeda () yahoo com
Sent: Tuesday, April 15, 2008 10:09 PM
To: pen-test () securityfocus com
Subject: Autorun programs from flash drive.

Hello, and thanks for reading this.  I am sure we are all know of the
Autorun feature in Cdroms and Dvdroms, how the program just runs out of the
box.  I am trying to figure out how to include this functionality in flash
drives.
/* I have a SD card with a USB adapter to test with. */
This would allow, say, for me to quickly insert a drive into a computer,
have it silently run something like Meterpreter or another backdoor program,
and then have remote access to the computer, assuming Windows runs it and
doesn't detect a malicious program.  I understand that Windows by default
will not run Autorun.inf by default on flash drives, except the U3s.  But I
have also heard that you can format a flash drive to look like a cdrom to
Windows.  This is about all I know.  If you have any more information, or
would know about how to go about doing this, please tell me.
Thank you again.
     -ARCKEDA

------------------------------------------------------------------------
This list is sponsored by: Cenzic

Need to secure your web apps NOW?
Cenzic finds more, "real" vulnerabilities fast.
Click to try it, buy it or download a solution FREE today!

http://www.cenzic.com/downloads
------------------------------------------------------------------------





------------------------------------------------------------------------
This list is sponsored by: Cenzic

Need to secure your web apps NOW?
Cenzic finds more, "real" vulnerabilities fast.
Click to try it, buy it or download a solution FREE today!

http://www.cenzic.com/downloads
------------------------------------------------------------------------


Current thread: