episode.ascii — live render
● episode

Episode 4: Bad USB.

TL;DRThe Conficker worm grounded the French Navy's Charles de Gaulle in 2009 via an infected USB drive. German researchers later revealed "Bad USB," a firmware-level exploit letting USB devices impersonate keyboards to silently install malware.

We explore how easy it is to take over a computer by plugging something into it. Jordan tells stories and interprets the nerdiness of Scott.

Transcript

Machine-generated transcript; may contain errors.

Speaker 1: And we're back. So right now, somewhere in the Eastern Mediterranean Ocean, there's a French warship called the Charles de Gaulle sailing towards Syria. The nuclear powered aircraft carrier can house 1,500 people. It is almost 900 feet long. It's the flagship of the French Navy. This is all a roundabout way of saying that it is big. On a busy day, you'd see as many as a 100 fighter jets come and go from the main deck, taking off and landing, whizzing around like ants. Now, on 01/15/2009, sometime in the early hours of the day, all over the world members of the French Navy, including those on the Charles de Gaulle, began receiving a phone call. Not an email, a phone call. Sometimes even a fax, actually, saying whatever you do, do not open your computers. So all those fighter jets whizzing around, staying in perfect sync thanks to onboard computers they use to download their flight plans, those were all grounded. The entire French Navy, which runs on this system, all at once the entire thing, the whole ant's nest on the back of the Charles de Gaulle, it ground to a halt. So why did this happen? Well, because somewhere, at some point, deep in the belly of that sprawling French naval organization, someone plugged in a USB key. And on that USB key, there was a worm called a Conficker. So this wasn't uncommon. At one point, Conficker infected anywhere from nine to 15,000,000 computers and devices, but it just happened to have infected a USB key that just happened to get plugged into a naval computer. What would it do? Who knows? But when it comes to fighter jets with missile capability, suddenly you're using facts until you've figured out what in the world is going on. So this threat of computers automatically running malicious software off of a USB drive, is this still the boogeyman lurking under the bed of world superpowers? Honestly, not so much. I mean, maybe, but computers generally no longer auto run software because of years and years of exactly this kind of thing. So why are we talking about this? Because in November 2015, two German security researchers gave a talk introducing a security vulnerability that can turn a normal USB drive into something that doesn't need to run software to take control of your computer. A vulnerability at the heart of how USB works that lets a hacker turn a USB into a surrogate capable of doing their bidding. It acts like a worm. It spreads like a worm, but it doesn't rely on the vulnerabilities that worms rely on. These researchers dubbed their discovery bad USB. And if the right people don't do something about it soon, sometime in the near future, the crew of the Charles de Gaulle will be breaking out the fax machine. My name is Jordan Blumen.

Speaker 2: And I'm Scott Winder.

Speaker 1: And we're talking about bad USB on this episode of Hacked. So when I was a kid and I would buy a computer game, that computer game came on a disc. And I would take that disc and I would put it in the computer, and the game would just start.

Speaker 2: Yeah. It's because you're younger than I am. So when I was a kid, when I bought a game, it came on a big flat piece of black plastic, which was called a disc to me. And when I put it in, it didn't auto start.

Speaker 1: What did it do? Nothing.

Speaker 2: You just clicked it in, and you had to move this lever to hold the disc in place. It was quite mechanical.

Speaker 1: So what happened between when I was playing video games and when you were playing video games?

Speaker 2: User experience design happened. People understood that people like convenience. So instead of having to put a disc in, in your case, a CD, and navigate to that CD, find the installer setup file, what they could do after Windows 95 is that you could set up a few settings on the disk, and what it would do is it would immediately execute whatever those settings told it to. So it would run the setup or installer automatically.

Speaker 1: When you buy a piece of software, you put the disk in, and everything just happens kind of on rails.

Speaker 2: Yeah. It's convenience.

Speaker 1: And why was that a terrible idea?

Speaker 2: Well, I think it everybody knows in hindsight why it was a terrible idea. You know, just by putting a misc or any form of media into your computer, having it auto execute something without your permission is an obvious vulnerability.

Speaker 1: You know,

Speaker 2: it was an obvious vulnerability when it was created, and it's an obvious vulnerability now. Windows and Microsoft have since removed that functionality from their more recent operating systems. I think Windows seven was the last one that did it.

Speaker 1: But for computer engineers to think that convenience should come at the cost of anyone being able to autorun anything that they can get someone to plug into their computer, that seems like, at best, a massive oversight and at worst instructed by, you know, a different set of motivations than what computer engineers probably normally would have, like financial motivations.

Speaker 2: Yeah. It's that's a really good point. I'm sure it was an oversight. They were probably just aiming for convenience. You know, Windows has always been a target of malicious activity, viruses, worms, etcetera. So I'm not sure why they would make that oversight.

Speaker 1: But they did.

Speaker 2: But they did.

Speaker 1: And what effect did that have?

Speaker 2: Well, it created a whole fleet of vulnerabilities. Like, you know, I stated previously that it doesn't really exist anymore since Windows seven, and that's not really the case. It'll still run things if you approve it. Those settings still work. The convenience factor is still there. It's just that it asks you a question. Right. Are you willing to open this? It's the same with if you remember the old versions of Internet Explorer. When you downloaded a file, you could be like, yes. Always open files of this type, dot exe. And then immediately, when you downloaded something you didn't know you were downloading or you didn't know what it was, if you clicked okay to that box at any time, it ran.

Speaker 1: Starting something new isn't just hard. It can be downright terrifying. You put a lot of work into a thing. You're not entirely sure it's gonna work out. You're taking a huge leap of faith. I've started a few things. Now I know I was right for believing in, you know, the idea, the product, despite all of those fears and hesitations. But boy, does it sure help when you have a partner like Shopify on your side. Shopify is the commerce platform behind millions of businesses around the world and 10% of all e commerce in The US. From household names like, well, hacked podcasts merch, to brands just getting started, you can get started with your own design studio with hundreds of ready to use templates. Shopify helps you build a beautiful online store that matches your brand style. Did I mention that that iconic purple shop pay button that's used by millions of businesses around the world? I don't know why I wouldn't. I should. It's why Shopify has the best converting checkout on the planet. It also helps boost conversions, meaning less carts, sort of getting abandoned in the parking lot, and more sales for you. It's time to turn those what ifs into sign up for your $1 per month trial at shopify.com/hacked. Go to shopify.com/hacked. One more time, that's shopify.com/hacked. It seems pretty dangerous to let people implement a rule that broad with that little, I guess, fanfare.

Speaker 2: I I think that's the nugget right there. You know, computer hacking is creative problem solving. And when you have something that's systematically happening all the time, you're creating a vulnerability because you can plan for it, factor for it. So, you know, you it's not as creative anymore as it is just a part of the toolbox. I think the biggest, earliest things was I think it was Loft, a hacker group called Loft, released something called b o two k. You're old enough that you'd probably remember it. It was essentially one of the first big malware kind of system control malware suites that any teenage kid could download or send to their friend or trick somebody or install on a computer at school, and next thing you know, they had full control of that computer.

Speaker 1: When you say full control, like a system control malware, what does that mean? What does that look like?

Speaker 2: B o two k was more of, like, a an annoyance piece of malware, but, like, you could watch somebody's webcam, open someone's CD drive, record someone's keystrokes, you know, things like that.

Speaker 1: That technology was out there. It is out there. It was proliferated probably a lot by Autorun, but that's still out there. If you can get someone to install that, those types of technologies are still out there in the world.

Speaker 2: They're I would actually say that in the last, I think, b o two k was the year 2000, hence the February. I think recent any kind of recent versions of that would be way more comprehensive. And worse than that, there's a suite of other really nasty malware that's out there that would put b o two k to shame. Like, the whole rise in trend in, cryptographic malware where it's, like, encrypting your hard drive and then pulling it hostage, forcing you to pay. Like, that the rise of those things and we'll probably do a whole episode on malware, but the rise of that style of malware, the malware for commerce, not for, like, being a pest, is changing the whole world.

Speaker 1: So is it just that we've replaced autorun with having to convince someone to click yes one time? Yes to download, yes to run?

Speaker 2: That's that's a major part of it. Yeah. You know, there's a million other things from phishing. You know, there's a variety of ways that people use things like email forging and other things to convince people to download malware. Like, I actually went home. My mother got a new computer for Christmas and a Mac, and I went home a couple weekends ago for a family thing, and she had malware on her Mac. And, like, I've been a Mac user since OSX came out since it was a UNIX based OS, and I've never had malware. So my mother got malware in, like, a three week period. So, you know, it's it's easier than you probably think, especially when you're working with numbers. So if you're looking at every Mac user in the world, statistically, you're probably gonna have a decent penetration. Hey, Jordan. Yes, sir. Do you wanna say it or say? No. I'm a say it. Fine.

Speaker 1: This episode has been brought to you by Bugcrowd. Partnership. So, Scott, why don't you tell people about our new and super supportive partner?

Speaker 2: Gladly, Jordan. Bugcrowd, they they do something awesome. You know, they provide a platform for security focused or, you know, security curious individuals to kinda legally act out these desires. They run something called bug bounty contests and they do it for some of the biggest companies in the world, you know, notably like Tesla. Or if you listen to last episode, LastPass, one of the password managers is one of their clients.

Speaker 1: Okay. So what is a bug bounty?

Speaker 2: It's essentially a reward system. So if you can find a vulnerability in, you know, the solutions or software technology that these companies offer, all the details are on their website for these contests. But if you can find a vulnerability, these companies will reward you often with money.

Speaker 1: So you get paid to hack something?

Speaker 2: Yeah. Essentially.

Speaker 1: But legally?

Speaker 2: Yes. As long as you adhere to the terms and conditions of the contest….dot. Sweet. Yeah. We, if you wanna check it out, if you wanna join me and, Jordan in this lovely financially rewarding hacking world, you can check out bugcrowd.com/hacked and, come join us as a air quotes researcher. And through this partnership with Bugcrowd, we are also declaring a challenge.

Speaker 1: What kind of challenge are we talking about here?

Speaker 2: Well, we're looking for tech companies who aren't afraid to let Bugcrowd's researchers and you, our listener base, take a swing at your security in in the best kind of way.

Speaker 1: So this is the thing we're doing now, Yeah. Hopefully.

Speaker 2: We'll see if anybody accepts the challenge.

Speaker 1: Learn more at bugcrowd.com/hacked. If, from a hacker's perspective, this is all a question of how do I get someone to run my program that does the specific, possibly unseemly thing on their computer? The the history so far can be broken up into three loose acts. There's pre auto run, there's, the reign of auto run, and then there's sort of what we're in now which is post auto run ish. The question is what's the next act?

Speaker 2: Well, you know, we opened the the show with the story about bad USB, and that's the next phase. You know, these two, I believe, they were Dutch kind of embedded system security engineers figured out a way to overwrite USB control firmware with malicious USB control firmware. Let's maybe I'll just expand on that by the confused look on your face.

Speaker 1: In my defense, I always have a confused look on my face.

Speaker 2: Every USB device has a chip in it that controls the conversation that's happening over USB. From a simple USB key to a USB keyboard to anything has a USB control chip in it. That chip also has memory, and in that memory is the firmware. These guys figured out how to take the empty space in the firmware and put a virus in it or a malware or a worm or something. And the way it works is you plug in the USB device, and then after a prescribed amount of time, the USB device will change from whatever it is, a USB key, to a keyboard, and then send a bunch of keystroke commands into the computer.

Speaker 1: What are those keystrokes hypothetically?

Speaker 2: Well, when they demoed this at a security conference, their virus or malware, their bad USB key was smart enough to figure out whether it was a Linux based operating system or a Windows based one. And if it was a Windows based one, it would run some Windows PowerShell commands, which is kind of like the black screen of of Windows, where you can do a bunch of, like, serious stuff from the command line. So it would open a PowerShell, send in a bunch of commands, install essentially a real virus on the computer or malware on the computer or a backdoor trojan, something like that, and then it would change itself back to a USB key.

Speaker 1: If that piece of malware isn't on the USB's memory, where is it getting that from? Does it have to download off the Internet? Does it or is it able to keep it in that little spare bit of memory in the firmware chip?

Speaker 2: The keystrokes and the control program for the the USB key virus is kept in that little bit of memory on the USB key. But all it's doing is sending out commands to the world saying, I am now this computer. Download me this backdoor trojan horse and install it.

Speaker 1: So to summarize what we know so far, picture a USB drive. If you're like me, it's probably in the bottom of a backpack somewhere. On that USB drive, there are two pieces of memory that you should know about. There's the memory where you store your files, and there's the second much smaller piece of memory on its own chip that holds the USB firmware, a little thing that tells the drive how to talk to the computer and the computer what kind of USB device is plugged in. That second chip, the one with the firmware, is in every USB device, not just memory sticks, a keyboard, a charge cable, whatever. So what this new vulnerability does is it makes use of the spare space in the firmware memory. If it's the firmware's job to tell the computer, hey, this is a memory drive, what bad USB does is says, okay, I know you thought I was a USB drive a second ago, but I'm actually a keyboard. And, oh, look at that. I'm typing, executing whatever commands the hacker wants as though they're sitting right at your computer.

Speaker 2: And the huge part of that is that even if you've got an antivirus system that's gonna scan the USB key, it's only looking at the storage media. So it's looking at the space where you'd put files. It's not looking at the firmware memory. So your antivirus is completely useless. And once it converts itself into a keyboard and starts sending keyboard commands, it just thinks that that's the user.

Speaker 3: Thinking about refreshing the carpet in your home? Now's the time to do it. For a limited time at The Home Depot, get 10% off installed carpet projects on trusted brands like Lifeproof, Lifeproof with PetProof Technology, Home Decorators Collection, and Traffic Master. Plus, with installation starting at just 49¢ per square foot, upgrading your space is more affordable than ever at The Home Depot. Offer valid, 06/11/2026 through 06/28/2026. Exclusions apply for licenses. See homedepot.com/ license numbers.

Speaker 1: It's pretty crazy to think about the implications once you get a a handle on it.

Speaker 2: So the thing that makes it really crazy is when they first demoed this, they plugged just what looked to be an ordinary USB key into an ordinary computer, and they could use it just like a USB key. It was a USB key. And then they just let it sit for a second. And then all of a sudden, you saw a bunch of things happen on the screen really fast without any reason. And what had happened is is that in that split second, the USB key had turned itself into a USB keyboard. So the computer saw it as a USB keyboard, not as a USB key anymore. So it had unmounted the USB key and remounted itself as a USB keyboard. Then it opened up the terminal or PowerShell for Windows and sent through a bunch of commands. And these commands could be anything. And they could even access files locally on the computer or send commands to the Internet, downloading and executing things, they really by the time you're sending actual keyboard strokes into a computer, there's really not a lot you can't do. So what they did is they had it reach out and download a few things and install some things. Some of these were, you know, remote administration malware or Trojan horses that allowed them to control a computer from other computers. Other things that they downloaded is they actually downloaded a virus, which would then replicate bad USB onto any other USB devices that came in contact with that computer. So that makes it into a worm.

Speaker 1: So even though bad USB isn't vulnerable to things like antivirus the way a worm is, it can still spread the way a worm does.

Speaker 2: Technically, the reproduction virus would be capable of being caught by an antivirus because it's actually something that would be running on the computer, but it's just a fascinating concept. I plug a physical device into a computer. It downloads and installs a virus. That virus will then infect any other USB devices connected to the computer until that virus goes away. Because really, it's infecting the control chip on the USB device. And any USB device that has these control chips, which is all USB devices, would be vulnerable at some point theoretically in the future. I think they found a virus or made a virus that was capable of attacking two control chips. And there's only, like, a small amount of these control chips because they're manufactured in such bulk quantities. But once it's on a control chip, once it's on a USB device, it can then propagate. So if you take a USB device, plug it into this computer, your USB device becomes a virus carrier. You go to another computer, you plug it in, that device becomes a virus infector, and then anybody else that plugs a USB device into that computer can get that virus. Like, it's it's a worm, but it's almost more traditionally like a real human virus. Like, it's spreading through contact, less about, you know, data connectivity, like a worm would.

Speaker 1: So any USB device is vulnerable, but are all USB firmware chips vulnerable?

Speaker 2: I believe not. The the researchers that came up with this did some subsequent testing on, more of the USB control chips, and I think they found that something like 50% of them were vulnerable to this style of attack. But the big problem that they highlighted was the fact that you don't really know what control chips in what USB device. So you you can't go out and buy something that is stated. You know, it has this USB control chip in it, so you don't have to worry about it.

Speaker 1: So it would be up to the manufacturers at this point, and it's kind of at their discretion to decide to start make using these sort of responsible practices.

Speaker 2: Yeah. Well, it's it's not even that they were irresponsible practices. It's just that this is such a new style of attack, such a new attack, and such an innovative way of attacking that I just think that over time, this will go away. They'll fix these small flaws. But right now, it's very relevant and very powerful.

Speaker 1: So if, like, a traditional virus, this is something that actually spreads physically, are we entering kind of an age when you maybe shouldn't be using someone else's charging cable?

Speaker 2: I don't know if we're there yet, but maybe in the future. Like, this is such a rare thing. It's it's more of a vulnerability for info security professionals. Like, physical proximity has always been an issue. You know, it's really hard to gain access to a computer, but there's a lot of times when computers are vulnerable and you just don't think about it. Like, how many times have you seen a computer monitor with a USB hub on the back of it? You know, USB hubs have been being added to everything for the past ten years because USB USB has become the standard norm for interfacing with your computer. So they put these things on everything. So to secure a computer down so that there's no USB ports accessible to it is probably really, really tough.

Speaker 1: It's interesting that so many of the things we talk about in the show have been around for quite a long time. So so many of the different things you can do with it have been considered and exploited and responded to. This is interesting because it's happening right now. This presentation was given just at the end of last year. There's so many unknowns. There's so many we're not totally sure what will happens.

Speaker 2: Yeah. I think it was last summer, like, late last summer that this presentation was given, and I really haven't been able to find any thorough details on how the industry has responded to it. I'm sure that major hardware manufacturers have this on their list now. At least I would hope they do.

Speaker 1: It makes sense that this would be a thing that hardware manufacturers would want to respond to moving forward. But as you said, there's still all of those monitors with the USB hub on the back. There's still all of those charging stations out there in the airports. All that stuff's already out in the world, and to expect all of those places to replace the things that they've already purchased and installed is it's a pretty tall bill.

Speaker 2: Yeah. Going going back to all of the existing peripherals and fixing them, because this is a physical problem, never gonna happen.

Speaker 1: The original researchers actually did a study in which they broke down the big firmware manufacturers into vulnerable, secure, and inconclusive categories. You can read their whole expanded analysis. Analysis it's linked to in the show description and at hackedpodcast.com. But the problem with that, however, is that USB manufacturers don't generally advertise which chip brand names they use, like, say, Intel Inside, because frankly, no one would recognize the names. And since most companies use a bunch of different chips anyway, shopping based on brands, as it currently stands, would be kinda useless. This is all why Carsten Knoll, he was the original researcher, decided not to release the code that was his proof of concept for bad USB. He didn't wanna unleash this thing on the world. But the problem with that is Someone figured it out.

Speaker 2: That quick? That quick. Once they published the information about the style of the attack and how it was happening, some of the kind of high level details, couple of people reverse engineered it, you know, such as the beauty of a large and active and interested hacking community.

Speaker 1: Is there anything they can't figure out?

Speaker 2: To be determined. The, the one thing I will say about this is it's not as severe as something like a real worm, like a worm that's spreading wildly through open exploits. But I do find it just fascinating how it acts like a human virus, like a biological virus, like it's contact to contact. It's spreading itself. And really, once you can program it to do whatever you want, you know, once it has access, The second we lost the days of autorun where you could just have something malicious on a USB key or a CD, and somebody would throw that into their computer, and it would automatically execute it. Once we once that was out of the toolbox, box, I think this is a very interesting way to replace it, especially with everything in the world being, you know, connected to the Internet now. There's not a lot that you can't do once you have shell access on a computer. So I don't think it's as severe as other major worms and exploits, but I think it's fascinating.

Speaker 1: We really appreciate anyone who still subscribed for waiting at that giant, giant, giant dead zone between this episode and the last one.

Speaker 2: I'm sorry.

Speaker 1: Especially when the last one ended with us saying we've got the next one coming out right away. We were working on a lot of stuff trying to both on hacked and some other projects that kinda just got away away from us.

Speaker 2: Well, and then there was the whole holiday season and

Speaker 1: We're not making excuses as we're making excuses, but we appreciate you for still being here.

Speaker 2: We said we love you all, and thanks for all of the passionate support and encouragement.

Speaker 1: Yeah. When you guys write, it doesn't go unnoticed. We really, really do appreciate it.

Speaker 2: Yeah. So we appreciate you all for being there, and we're hoping you'll stay around.

Speaker 1: So when we were making this episode, we actually recorded two different versions of the opening story. You obviously know which one we ended up going with, but the other one's actually pretty cool. It's a story of the CIA and spies and something called Cottonmouth. So we hope you'll stick around and listen. Otherwise, this has been another episode of Hacked. My name is Jordan Blumen.

Speaker 2: And I'm Scott Winder.

Speaker 1: Thanks for listening. The Ant division is a branch of the American government you've probably never heard of before. It stands for Advanced Network Technology. And if you have bumped into that acronym, the first time was probably sometime in 2013 during the Edward Snowden leaks. Ant is a division of the NSA, and one of the classified documents that made its way out into the world was something called the Ant catalog. Others have drawn this comparison, but the document really does read a lot like a mail order catalog, except instead of keyboard vacuums and snow globes, it's spy stuff. Not poison dart pens and shoe radios, modern spy stuff. There's the $40,000 device that emulates a cell phone tower. It's code named Candygram. There's software to install backdoors on popular smartphones, the kind you might be listening to this episode of Hacked On. There are monitor cables that let you see what's on someone's display. And then there's codename Cottonmouth. Cottonmouth is a family of USB devices that, if plugged in, give the NSA access to your computer. Doesn't matter if it's never been connected to a network, if you plug in Cottonmouth, that computer is compromised. They can see what happens on the computer. They can make the computer do things. Your computer is theirs. A set of Cottonmouth USB devices ran about a million bucks for 50 units, so a spy would have to shell out $20,000 for the privilege of a USB drive that could compromise a computer without detection. That catalog was published in 2008. Last November, 11/20/2017 German security researchers gave a talk introducing a security vulnerability that can turn a normal USB drive into something that sounds a lot like Cottonmouth. It's a vulnerability in USB that goes beyond using antivirus software, beyond not running sketchy software off the drive. It's a vulnerability that's baked into the DNA of how USB works, and not a lot of people are doing much to stop it. The researchers have named the vulnerability, quite simply, bad USB, and they're urging USB manufacturers to listen to their warning, because if they don't, pretty soon Cottonmouth is gonna be the least of our worries. My name is Jordan Blumen.

Speaker 2: And I'm Scott Winder.

Speaker 1: And we're looking at bad USB on this episode of Hacked.

Speaker 4: Visible puts the ultimate wireless hack in the palm of your hand. You get unlimited five g data and hotspot designed to keep you connected, all powered by Verizon's five gs network. Plans start at $25 a month or get the premium Visible Plus Pro plan and save $10 on your first month with promo code hack. Tap the banner to switch today. Terms apply. See visible.com for plan features and network management details.

Speaker 5: There's a new way to sweet greet. Meat wraps. Handheld, hearty, and made for life on the move. With bold chef crafted flavors, fresh ingredients, and over 40 grams of protein, they're built to satisfy without slowing you down. Try wraps today in the app or at order.sweetgreen.com, available at all participating locations. Athletic brewing company crafts award winning non alcoholic beers for those who want to be part of every round With over 185 flavor awards, they're exceptional NA beers that fit your lifestyle and any social occasion. Summer's full of good times and athletic fits right in. Go to athleticbrewing.com to have brews delivered to your door or find them at a bar, restaurant, or store near you. Near beer, athletic brewing company, fit for all times.