Week 2 Discussion 2 – Rubber Ducky

profileAK47
week2.odt

The Rubber Ducky USB Device

You've read about quite a few cyberattacks now, and you've read about vulnerabilities and exploits, but one thing the book doesn't talk much about is where attackers find exploits to use in their attacks. The TV and movie image is far too often that attackers are computer geniuses holed up in a dark room surrounded by computer monitors. While it is true that some attacks require significant technical skill, most attacks, even most that are described in the mass media as “sophisticated” or “advanced”, do not require that type of technical skill. The exploits that attackers use are readily available for free or to purchase on the internet.

 

Considering that almost anything you want to purchase can be found for sale online, this should not come as a surprise. But it is often a surprise how easily cyberattack tools can be found. For this discussion, we'll look at just one of these – a USB device known as Rubber Ducky. It is by no means the most sophisticated tool that is readily available, but it is fairly easy to understand.

 

Here's a link where you can buy a Rubber Ducky:

 

http://hakshop.myshopify.com/products/usb-rubber-ducky-deluxe (Links to an external site.)

 

Another reason for looking at this device is that it is a great illustration of a common story in cybersecurity – as new features are added, new vulnerabilities appear. And as those vulnerabilities are removed, attackers find new ones.

 

And here's that story as it relates to the Rubber Ducky:

 

Removable media have long been used to spread malware. Many of the earliest viruses were spread by floppy discs before most personal computers were connected to a network. This same method of spread continues today. For instance, back in Week 1, you read about how a classified military network was compromised through thumb drives.

 

The main way in which malware is spread from removable media was formerly through the autoplay feature. This was a wonderful convenience that Microsoft introduced into Windows so that when you bought new software, you could simply insert the disk and it would automatically begin to install. Of course, when the disk contained malware, it was also automatically installed.

 

This is actually a great example of a vulnerability that was purposefully introduced by the manufacturer. And it remained for years even though it was commonly exploited by malware.

 

But eventually Microsoft began to put limitations on the autoplay feature, but each time attackers found a way to get around the limitations. Finally, autoplay became disabled by default for all removable media. So with autoplay disabled, you may assume that if you find a thumb drive laying around, it is safe to insert it into your computer. Or, if you are in charge of security, you may feel that you no longer have to be as vigilant about stray USB devices as in the past.

 

Unfortunately, no.

 

Just as attackers found a way around every limitation in auto-play, they also have found other vulnerabilities that they can exploit to install malware from USB devices. One vulnerability is that when you plug a USB device into a computer, the computer has no idea what type of device you've just connected. So the computer asks the device, and it believes whatever the device says.

 

And computers still automatically trust certain types of devices, for instance, keyboards. If you plug a keyboard into a computer, the computer will automatically accept all input from that keyboard.

 

Which brings us back to the Rubber Ducky. It looks like a typical thumb drive, but when the computer asks what type of device it is, the Rubber Ducky tells the computer that it is a keyboard. And the Rubber Ducky can be programmed to “type” all kinds of interesting things. So when the victim plugs the Rubber Ducky into their computer, the Rubber Ducky may type a command to delete everything on the hard drive. Or to connect to a remote computer. Or to do anything that can be done from a keyboard, which is almost anything (you really don't need a mouse to run Windows, though it sure makes it easier).

 

By the way, the link is to a legitimate store. The products are often sold to cyber security professionals and used for legitimate penetration testing and other uses such as demonstration/education. But the same types of devices are available for anyone that wants to do bad things with them as well, pre-programmed and missing the cute logo.