TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

Introducing the USB Stick of Death

165 点作者 dietcokerules超过 12 年前

5 条评论

pilif超过 12 年前
I really don't agree with the severity rating. Instant admin-access by just plugging in a USB stick is exactly what malware like the ever-loved Stuxnet use(d) as a jump-start to get their other exploits and backdoors going.<p>It's like the various autorun exploits, but better because you don't need an additional privilege escalation vulnerability <i>and</i> you get to execute your attack even if autorun is turned off completely.
评论 #4683422 未加载
评论 #4684259 未加载
GFischer超过 12 年前
As a security vulnerability, it's interesting but, as they stated, low-severity.<p>If you have physical access and a local user, it's much easier to use any Linux boot CD and one of the myriad "password recovery" systems.<p>I used Petter N Hagen's <a href="http://pogostick.net/~pnh/ntpasswd/" rel="nofollow">http://pogostick.net/~pnh/ntpasswd/</a><p>back in my tech support days (several years ago).<p>The current tech support guy swears by Hiren's BootCD<p><a href="http://www.hiren.info/pages/bootcd" rel="nofollow">http://www.hiren.info/pages/bootcd</a>
评论 #4682733 未加载
评论 #4682642 未加载
评论 #4682873 未加载
评论 #4683307 未加载
评论 #4683304 未加载
wvs超过 12 年前
Coming from a *nix background, it seems odd to me that a kernel null dereference would be exploitable from userland. Or that kernel functions be directly addressable from userland.<p>Is kernel memory mapped into user processes on Windows?
bashzor超过 12 年前
I've had an usb stick of death for years now. Any system you plug it in instantly freezes. No idea how I made it, but it was certainly not the goal! And whatever I do, I can't get it to overwrite whatever data is on there :P
评论 #4682604 未加载
评论 #4683932 未加载
评论 #4682699 未加载
Evbn超过 12 年前
Was hoping for something like <a href="http://etherkiller.org/" rel="nofollow">http://etherkiller.org/</a>