Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Threat Intelligence

2/14/2019
06:00 PM
50%
50%

From 'O.MG' to NSA, What Hardware Implants Mean for Security

A wireless device resembling an Apple USB-Lightning cable that can exploit any system via keyboard interface highlights risks associated with hardware Trojans and insecure supply chains.

During a month-long hiatus between jobs, Mike Grover challenged himself to advance a project he'd been working on for over a year: Creating a USB cable capable of compromising any computer into which it's inserted.

His latest iteration, the Offensive MG or O.MG cable, resembles an Apple-manufactured Mac USB-Lightning cable but incorporates a wireless access point into the USB connector, allowing remote access from at least 100-feet away, according to Grover. A video demonstration shows Grover taking control of a MacBook and opening up Web pages from his phone.

The cable takes advantage of a known weaknesses. To make keyboard, mice, and other input devices as easy to connect as possible, operating system makers have made computers accept the identification, through the Human Interface Device (HID) protocol, of any device plugged into a USB port. An attacker can use the weakness to create a device that acts like a keyboard to issue keystrokes, or a mouse to issue clicks.

"What the user sees, or doesn't see, depends a lot on their machine, how the cable is configured, and when the HID interface is initiated," Grover says. "A competent attacker can make this invisible to the victim."

The project is the latest demonstration of hardware Trojans — often called implants in the intelligence world — and the potential risk they pose to companies and their unwitting employees. In 2014, a team lead by Karsten Nohl created BadUSB, a set of USB peripherals that could abuse the HID protocol to compromise systems or pose as an external hard drive to control a computer's boot process.

Many of these attacks, including Grover's latest O.MG cable, aim to fool the user into inserting the compromised device into their own computers. 

"The weakest point of any company's security are the people, so any chance you have to interact with people is a good opportunity to breach their security," says John Cartrett, the red team technical lead at security services firm Trustwave.

Such a hands-off approach is one reason why Grover pursued creating such a close twin to Apple's cable, including creating his own miniature custom circuit boards. In the past, many malicious USB devices, such as Teensy and Rubber Ducky, were carried in by a red-team member to quickly infect systems or capture data by inserting the drive into the target computer. In 2013, a group of researchers from the Georgia Institute of Technology showed off a power charger for MacBooks that could compromise the systems.

Grover designed his cable to connect to a Wi-Fi hotspot and connect back through the Internet for instructions.

"The malicious cable can be both victim-deployed [and] attacker-controlled and updated while in possession of the victim," he says. "Lots, but not all, of malicious hardware tends to be intended for the attacker to deploy. [With this], the attacker does not have to risk gaining physical access to a secure location if the victim will carry it in for you."

Some security experts see the projects as a good teaching moment, but unlikely to be used very often in practice. While Cartrett admired Grover's work on the cables, he thinks it's unlikely his team would use it in their own engagements. 

"My guys go in with a small set of tools and they are initially tasked with getting a foothold," he says. "We usually don't use novelty cables like this or the chargers. We looked at some of them, but they are just too James Bond-ish." 

'Cottonmouth'-Inspired

There is a connection to intelligence work. The original idea for the wireless USB cable came from the documents leaked by Edward Snowden. Project "Cottonmouth" — as listed in the leaked Tailored Access Operations (TAO) catalog — is a USB hardware implant that provides a wireless bridge. 

Still, the decreasing costs of such custom hardware Trojans and implants, and public accessibility, could mean that they will proliferate. While Grover spent an estimated $4,000 to complete the cable, the actual cost in parts for each cable is about $30, he notes.

Companies can take steps to make sure they are harder targets of such hardware implants. Employee education can help foil some attacks, says Deral Heiland, IoT research lead at cybersecurity firm Rapid7. Workers, for example, should be taught to never insert any hardware into their computer not supplied by the company. In addition, whenever they step away from their system, they should lock it, he says.

"Lock your console, don't wait for the one minute, lock your console every time you walk away from your keyboard," Heiland advises. 

In addition, firms should pay more attention to their supply chains, making sure they are procuring hardware from reliable sources. Unfortunately, there are no sure-fire ways of detecting a hardware Trojan.  

"Supply chain security is hard," Heiland says. "If you are buying from a reliable trustworthy source, you are going to have to trust those devices."

Related Content:

 

 

Join Dark Reading LIVE for two cybersecurity summits at Interop 2019. Learn from the industry's most knowledgeable IT security experts. Check out the Interop agenda here.

Veteran technology journalist of more than 20 years. Former research engineer. Written for more than two dozen publications, including CNET News.com, Dark Reading, MIT's Technology Review, Popular Science, and Wired News. Five awards for journalism, including Best Deadline ... View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
I 'Hacked' My Accounts Using My Mobile Number: Here's What I Learned
Nicole Sette, Director in the Cyber Risk practice of Kroll, a division of Duff & Phelps,  11/19/2019
DevSecOps: The Answer to the Cloud Security Skills Gap
Lamont Orange, Chief Information Security Officer at Netskope,  11/15/2019
Attackers' Costs Increasing as Businesses Focus on Security
Robert Lemos, Contributing Writer,  11/15/2019
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Current Issue
Navigating the Deluge of Security Data
In this Tech Digest, Dark Reading shares the experiences of some top security practitioners as they navigate volumes of security data. We examine some examples of how enterprises can cull this data to find the clues they need.
Flash Poll
Rethinking Enterprise Data Defense
Rethinking Enterprise Data Defense
Frustrated with recurring intrusions and breaches, cybersecurity professionals are questioning some of the industrys conventional wisdom. Heres a look at what theyre thinking about.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2019-13157
PUBLISHED: 2019-11-22
nsGreen.dll in Naver Vaccine 2.1.4 allows remote attackers to overwrite arbitary files via directory traversal sequences in a filename within nsz archive.
CVE-2012-2079
PUBLISHED: 2019-11-22
A cross-site request forgery (CSRF) vulnerability in the Activity module 6.x-1.x for Drupal.
CVE-2019-11325
PUBLISHED: 2019-11-21
An issue was discovered in Symfony before 4.2.12 and 4.3.x before 4.3.8. The VarExport component incorrectly escapes strings, allowing some specially crafted ones to escalate to execution of arbitrary PHP code. This is related to symfony/var-exporter.
CVE-2019-18887
PUBLISHED: 2019-11-21
An issue was discovered in Symfony 2.8.0 through 2.8.50, 3.4.0 through 3.4.34, 4.2.0 through 4.2.11, and 4.3.0 through 4.3.7. The UriSigner was subject to timing attacks. This is related to symfony/http-kernel.
CVE-2019-18888
PUBLISHED: 2019-11-21
An issue was discovered in Symfony 2.8.0 through 2.8.50, 3.4.0 through 3.4.34, 4.2.0 through 4.2.11, and 4.3.0 through 4.3.7. If an application passes unvalidated user input as the file for which MIME type validation should occur, then arbitrary arguments are passed to the underlying file command. T...