It has a complex codebase and firmware update methods to migrate to new USB specs. Cheap cables don't even support signing so go to town tampering with stock cables if you are so inclined.
Also an Attiny85 can fit inside just about anything.
My favorite BadUSB hello world is using the Arduino HID library to make a Digispark toggle caps lock randomly with maybe 10 lines of code. Drives people nuts.
I don't know, but I do know that back in 2013 you could get an ARM computer running linux and a webserver with wifi and 16Gb storage in a space the size of an SD card. That is still a bit too big to fit inside a USB plug without being obvious, but not by much. https://hackaday.com/2013/08/12/hacking-transcend-wifi-sd-ca...
Fitting the electronics inside the usb plug itself has been used for years in slimline usb memory sticks and in tiny readers for micro-sd too.
I expect that this has been possible for nearly 10 years, but maybe just not commercially viable for consumers for most of that.
C-to-C charger cables with Bluetooth remote activated dual payloads: https://sneaktechnology.com/product/usbninja-custom-type-c-t...
I easily modified mine to mimmic Apple Keyboard USB IDs to avoid notifications. Works great!
Cellular GPS tracking car charger: https://www.amazon.com/Charger-Locator-Professional-Listenin...
Cellular GPS tracking USB charger cable: https://www.ebay.com/itm/223990414124
I have been making, collecting, and testing toys like this for more than a decade.
It is a race to the bottom on price now.
Your best defense for USB code execution attacks is use Linux with USBGuard or QubesOS with the default USB quarantine VM.
Windows and Mac users are currently easy targets. I don't know of any good defenses there.
> Screen Crab: This covert inline screen grabber sits between HDMI devices - like a computer and monitor, or console and television - to quietly capture screenshots. Perfect for sysadmins, pentesters and anyone wanting to record what's on a screen.
> Shark Jack: This portable network attack tool is a pentesters best friend optimized for social engineering engagements and opportunistic wired network auditing. Out-of-the-box it's armed with an ultra fast nmap payload, providing quick and easy network reconnaissance.
> Key Croc: The Key Croc by Hak5 is a keylogger armed with pentest tools, remote access and payloads that trigger multi-vector attacks when chosen keywords are typed. It's the ultimate key-logging pentest implant.
They say "pentesters." What prevents a malicious actor from buying and using these tools?
I think I am missing something here.
I’m simultaneously impressed, curious and disturbed.
"But the case is locked!" Are the peripherals? Even if the case connectors are locked away behind a bird-box/knockout, if someone left one of these dangling unplugged off of the keyboard, do you think your field technician won't unlock the box and plug it right back in?
Its kind of cool to see someone I've been following for years and seeing the whole dev cycle of this product.
His exploding USB drive was pretty cool and came before this idea:
I have tried to make a cable like that in the past be the best I got was to hide the electronics in what looked like a bead. Unfortunately, this only really works with USB-B devices where users are already used to having beads on the cable which for practical purposes limits attacks to printers and older scanners.
Nowadays, with 2FA and all the big companies doing extra security check up when they see something wrong with the login patterns ... I don't see the use of keyloggers anymore.
https://panic.com/blog/the-lightning-digital-av-adapter-surp...
To exfiltrate data by WiFi, there is a neat way to get data out... Just have the esp32 connect to all unencrypted WiFi networks in turn and send the data out via a DNS tunnel.
Then the attacker can provide their own WiFi network, but it will also work with airplane WiFi, cafe WiFi, guest networks, etc.
And obviously with DNS tunnelling it works against WiFi networks that require a 'sign in' after connection, even without signing in.
Unfortunately the only real legit use for it is boring security work.
The best way to use this while avoiding big legal trouble would be to stalk a single target that would never have any idea they are being stalked and doesn’t have much resources to come after you legally. Maybe an ex-girlfriend or something.
I remember in the early days of the web getting a copy of the Anarchist Cookbook. One idea was to glue the phosphorus material from a match stick to the spinning portion of a floppy disk. Of course that was a n00b level hack.
We've come a long way since then...
Couldn't find this information. If yes, you can just switch someones cable in his bag and attack him with that. We need to be very careful in the future with our cables...
Can someone explain what this is? Is it a hardware keylogger?
Simply a Male to Female USB adaptor with the data wires not passed through.
Had an entirely different image in mind.