We tested a BadUSB build that Rickroll'd people at the office

gregmcc

Honorary Master
Joined
Jun 29, 2006
Messages
25,512
Hacks any computer....that's a bit of a stretch even for mybb. It just emulates a keyboard. Try plugging it into a device that's screen locked or logged out.
 

quovadis

Honorary Master
Joined
Sep 10, 2004
Messages
11,011
Hacks any computer....that's a bit of a stretch even for mybb. It just emulates a keyboard. Try plugging it into a device that's screen locked or logged out.
Some limitation yes, but could easily be programmed to deliver its keystrokes at the opportune time. You'd also need a payload that can bypass any protections on the computer itself.
 

6spdmanual

Executive Member
Joined
Jul 3, 2015
Messages
6,189

hj007

Expert Member
Joined
Aug 30, 2006
Messages
1,866
And this is why usb is blocked on company laptops.
Well not really, its blocked to stop data getting leaked, but not a bad reason to stop malicious applications.
 

InvisibleJim

Expert Member
Joined
Mar 9, 2011
Messages
2,925
And this is why usb is blocked on company laptops.
Well not really, its blocked to stop data getting leaked, but not a bad reason to stop malicious applications.
The clever thing about about the Rubber Ducky is that most USB blocking controls are designed to block removable storage to prevent malware running automatically or data exfiltration.

Hackers be like 'Hold my beer while I emulate your USB keyboard'

Sneaky hackers are sneaky.
 

Crumbl0x

Senior Member
Joined
Mar 18, 2020
Messages
988
I was actually thinking of building something similar for testing purposes, but with an additional programmable selector, to 'type out' two or three of my common offline passwords used for decrypting my backup vault or for the login process. The YubiKey et al. would be nice for this and other features, but it's really a pity how pricey they can get for us.
 

quovadis

Honorary Master
Joined
Sep 10, 2004
Messages
11,011
And this is why usb is blocked on company laptops.
Well not really, its blocked to stop data getting leaked, but not a bad reason to stop malicious applications.
This isn't a malicious application though.
 

Acinixys

Well-Known Member
Joined
Nov 30, 2022
Messages
120
And this is why usb is blocked on company laptops.
Well not really, its blocked to stop data getting leaked, but not a bad reason to stop malicious applications.

I feel like some companies dont take this stuff seriously enough

I work for one of the big 3 retailers and my work laptop is completely unrestricted

Once I log out of the company VPN its a free for all with nothing out of bounds.
 
Top