char · @char
60 followers · 841 posts · Server ioc.exchange

Updated canaryusb; Now it's possible to use a config file for your DNS canary token and the list of trusted devices; Also added some tests; And added a make install.

github.com/carvilsi/canaryusb

Get a mail notification via, Canary Tokens (DNS) when a USB device is connected on a GNU/Linux computer.
Could be useful when you leave the laptop unattended or for a server on a remote location, will not prevent to being breached, but at least you'll notice; this is the principle behind @ThinkstCanary Here we are thinking about removable media threats like or data theft.

#badusb #security #hardware

Last updated 1 year ago

Kevin Karhan :verified: · @kkarhan
1319 followers · 91237 posts · Server mstdn.social

@porkroll Because there is no rational reason they can't deploy via or whatever crutch their uses [because doesn't have any good whatsoever]...

It sounds more like and I'm convinced that it's trivial to their systems since one can configure the USB-IDs and functionality of tools like the / ...

#pwnpialoa #PwnPi #badusb #securitytheater #packagemanager #Windows #msp #sccm #pdfarranger

Last updated 1 year ago

char · @char
43 followers · 559 posts · Server ioc.exchange

I added some new features to canaryusb, the most nice it's that right now it's possible to provide a list of trusted devices, and if any of these are connected, you'll not receive a notification from

github.com/carvilsi/canaryusb

Get a mail notification via, Canary Tokens (DNS) when a USB device is connected on a GNU/Linux computer.
Could be useful when you leave the laptop unattended or for a server on a remote location, will not prevent to being breached, but at least you'll notice; this is the principle behind @ThinkstCanary. Here we are thinking about removable media threats like or data theft.

#canarytoken #badusb #security #hardware

Last updated 1 year ago

Remind me tomorrow to try get that pico to run the rubber ducky script...

I've tried so many times but it never seems to work, regardless of OS.

#RaspberryPiPico #badusb #pico

Last updated 2 years ago

LisPi · @lispi314
446 followers · 8702 posts · Server mastodon.top

@proto Interesting that there's a term for it (en.wikipedia.org/wiki/Juice_ja).

I had assumed it was just a logical analogue/extension of .

#badusb #juicejacking #usb #security #usbsecurity

Last updated 2 years ago

Lord Kusuriya ​:tower:​ · @kusuriya
-1 followers · 3041 posts · Server hackers.town

If youre concerned about juice jacking attacks there are a few ways to make power only USB cables, the lowest tech one is take a piece of tape, cover the center 2 pins on the USB-A side of the cable now its power only.
If you trust yourself with a pair of wire snips and some heat shrink you can open the cable up the white and green cables are normally data, snip them, test the cable in a computer make sure you get charge and no data, get the heat shrink on the part of the cable you opened up and reseal it. now you have a for sure data only cable.

Juice jacking while a real risk isnt the biggest one when all is said and done and easily mitigated by carrying a power only cable that is labeled clearly or a USB condom, or just using your own wallwart. The more sinister attacks honestly are the cable based ones like this cable hacker-gadgets.com/product/evi there are better made ones you can find out there too that its almost impossible to tell them apart from your normal cables and they can do all sorts of stuff. but all of this assumes someone can physically predict where you are and can do something in physical space

#badusb #juicejacking #security

Last updated 2 years ago

GeekProjects News · @news
4 followers · 3116 posts · Server geekprojects.com
IT News · @itnewsbot
3036 followers · 253996 posts · Server schleuss.online

Is Your USB-C Dock Out To Hack You? - In today’s installment of Betteridge’s law enforcement, here’s an evil USB-C dock ... - hackaday.com/2023/03/26/is-you

#usbc #dock #badusb #securityhacks #Dockingstation #peripheralshacks

Last updated 2 years ago

฿@🅂εD͓̽:parrot: · @based
29 followers · 27 posts · Server h4x0r.host

Wireless BadUSB with Flipper Zero's Inbuilt Bluetooth!

#badusb #flipper #hacking

Last updated 2 years ago

Stirling C / stirlo.space/be · @Stirlo
6 followers · 22 posts · Server aus.social

@xssfox plug in the forbidden USB

#badusb #rubberducky

Last updated 2 years ago

AlexKollar · @AlexKollar
2 followers · 18 posts · Server mastodon.lol

Yeah I got a for Christmas. It’s been hellacious fun so far messing with anything regarding a Wi-Fi signal. Right now I’m running been having a ton of run rocking the attacks. Especially in conjunction with cryptex. Linkie in my about.

#

#FlipperZero #unleashedfirmware #badusb #infosec #cybersec #cybersecurity #hacking

Last updated 2 years ago

What I've done so far with the Flipper Zero:

1. Infrared - Onboard IR can easily detect, clone, and emulate IR codes. Used this to control a few devices at home.
2. 125 kHz RFID - I've been able to detect, clone, and emulate several 125kHz RFID badges and keyfobs.
3. NFC - I can read, clone, and emulate NFC tags. I cloned one of the ones I wrote earlier that can jump on guest wifi. Emulating it works great to connect to guest wifi on my phone!
4. U2F - Works but I prefer Yubikeys. I'm also wondering if there's a way to do the U2F via NFC instead of USB, which would bring it closer to the Yubikey use case. No FIDO2 though (yet).
5. Sub-GHz - I cloned the signal from my car key to unlock my car, but it caused my car to stop trusting my key and it stopped working. I fixed it by resetting my car and key, but it's risky and might make your key stop working. Don't try it unless you're prepared for that. It could cost you your keys!
6. Bluetooth - Sync'd to the phone and Flipper app and found it a useful addition.
7. Wifi Module - Loaded Marauder and it scans and performs attacks successfully.
8. Alternate Firmware - Tried Unleashed. Works great! I'm looking to try some others to see what they offer. RogueMaster up next.

To Do:

1. iButton testing.
2. BadUSB testing.
3. RogueMaster testing.
4. Test more RFID cards.
5. Test more apps.
6. Level up the Flipper!

#FlipperZero #hardware #hardwarehacking #badusb #rfid #infrared #nfc #wifi #hacking #infosec #security #cybersecurity

Last updated 2 years ago

tuxwise · @tuxwise
24 followers · 92 posts · Server social.tchncs.de

Recommended for against on :

Why? - Block unknown USB devices from · Allow devices temporarily or permanently · Caveats: 1) Does not protect against allowed USB devices with (secretly) re-programmed firmware, or . 2) Remember to permanently allow all devices that are currently connected, during installation.

usbguard.github.io/

More recommendations: tuxwise.net/recommended-softwa

#juicejacking #killusb #plugandplay #usbguard #linux #badusb #digitalselfdefense #protection #usb #opensource

Last updated 2 years ago

tuxwise · @tuxwise
29 followers · 93 posts · Server social.tchncs.de

Recommended for against on :

Why? - Block unknown USB devices from · Allow devices temporarily or permanently · Caveats: 1) Does not protect against allowed USB devices with (secretly) re-programmed , or . 2) Remember to permanently allow all devices that are currently connected, during installation.

usbguard.github.io/

More recommendations: tuxwise.net/recommended-softwa

#firmware #juicejacking #killusb #plugandplay #usbguard #linux #badusb #digitalselfdefense #protection #usb #opensource

Last updated 2 years ago

:debian: Primit1v3 :tor: · @primit1v3
81 followers · 333 posts · Server ioc.exchange

Finished up @Spacehuhn course.

#badusb

Last updated 2 years ago

but in rare wireless networking adapter form. I’m going to solder in a green led too eventually. Will post it running shortly but it’s pretty straightforward. The fun part is breaking old stuff and putting new stuff inside of it.

#tails #xbox360 #maker #badusb #xbox

Last updated 2 years ago

Rellik · @rellik
8 followers · 21 posts · Server mstdn.party

First just recently ended, and I'm impressed that while half of them were teenagers and that they could create things like (and rick rolls). I didn't know what to expect from a hackathon, but it was amazing.

Meanwhile I just made a with my .

#hackathon #quantumcomputing #badusb #pipico

Last updated 2 years ago

lesson from on Never take a from no one. Most show I have seen in last few weeks.

#infosec #InsideMan #netflix #usb #frustrated #badusb

Last updated 2 years ago

Martin Rocket · @Rocket
38 followers · 353 posts · Server det.social

@rolltime that's this everyone talks about?

#badusb

Last updated 2 years ago

TheBuggers :mastodon: · @thebuggers
48 followers · 1123 posts · Server mastodon.online

Heute, in einer Zeit, in der weltweit mehr als 2,5 Millionen Industrieroboter im Einsatz sind, ist die Gefahr durch Angriffe mittels gefährlicher über die -Schnittstelle sehr hoch. Die Standard-USB-Speicherschnittstelle an sich bietet nur sehr begrenzte Möglichkeiten die Sicherheit zu gewährleisten. Ein USB-Gerät, das sich gemäß des USB-Standards zu erkennen gibt, erhält im Allgemeinen einen vollen Zugriff auf Teile des Host-Systems.

#usbkiller #badusb #usb #schadsoftware

Last updated 2 years ago