Jump to content


Photo

Juice-Jacking and USB condoms

Juice Jacking USB Condoms Device Charging Data Theft

  • Please log in to reply
10 replies to this topic

#1 eyecre8

eyecre8

    Mod/News Team Leader

  • Moderator
  • 108 posts
  • Google+:eyecre8
  • LocationOhio/Florida
  • Current Device(s):2 Razr's (xt912) & Asus TF700T

Posted 13 September 2013 - 08:04 AM

Please Login or Register to see this Hidden Content

 

Please Login or Register to see this Hidden Content

  31.38KB   29 downloads
You’re out and about, and your smartphone’s battery is about to die. Maybe you’re at an airport, hotel, or shopping mall....or hacker convention!  You don’t have the power cable needed to charge the device, but you do have a USB cord that can supply the needed juice. Then you spot it!!  An oasis: A free or paid charging kiosk. 
Do you hesitate before connecting your smart phone to this unknown untrusted device?? Well? ......DO YOU? 
Did you consider for a moment that it could be configured to read most of the data on your phone, and perhaps even upload malware? Hey...We all have needs and sometimes you just need to charge your phone. "Any port in a storm." as the saying goes. 
 
Several Security professionals were asked this question while research for this story was being conducted. They said they use these charging kiosks all the time (usually while on travel) but would definitely think twice after being brought aware of the malicious possibilities.
 
Granted, a charging kiosk at an airport may be less suspect than, say, a slightly sketchy-looking tower of power stationed at DefCon (the infamous hacker conference). some people will brave nearly any risk to power up their mobiles. In the three and a half days of this year’s DefCon, at least 360 attendees plugged their smartphones into the charging kiosk built by the same guys who run the infamous Wall of Sheep, a public shaming exercise at DefCon aimed at educating people about the dangers of sending email and other online communications over open wireless networks.
 
Brian Markus, president of Aires Security, said he and fellow researchers Joseph Mlodzianowski and Robert Rowley built the charging kiosk to educate attendees about the potential perils of juicing up at random power stations.
 
The Motivation behind the experiment explained:
“We’d been talking about how dangerous these charging stations could be. Most smartphones are configured to just connect and dump off data,” Markus said. “Anyone who had an inclination to could put a system inside of one of these kiosks that when someone connects their phone can suck down all of the photos and data, or write malware to the device.”
 
To make their charging station more attractive to passersby, Markus and his pals equipped it with a variety of charging cables to fit the most popular wireless devices. When no device was connected, the LCD screen fitted into the charging station displayed a blue image with the words “Free Cell Phone Charging Kiosk.”

Please Login or Register to see this Hidden Content

 

Please Login or Register to see this Hidden Content

  103.77KB   32 downloads

 

The screen switched to a red warning sign when users plugged in any devices. The warning message read:
“You should not trust public kiosks with your smart phone. Information can be retrieved or downloaded without your consent. Luckily for you, this station has taken the ethical route and your data is safe. Enjoy the free charge!”
 

Please Login or Register to see this Hidden Content

 

Please Login or Register to see this Hidden Content

  245.74KB   33 downloads
 
Markus said the comments from those who chose to juice up their phones at the kiosk were the most rewarding part of the project.
 
“One attendee claimed his phone had USB transfer off and he would be fine.  When he plugged in, it instantly went into USB transfer mode,” Markus recalls.  “He then sheepishly said,  ‘Guess that setting doesn’t work.’”
 
Another DefCon attendee remarked, “This freaked my boss out so much he sent an email across the entire company stating employees are now required to bring power cables and/or extra batteries on travel, and no longer allowed to use charging kiosks for smart devices in open public areas.”
 
The safest route for charging your device on-the-go is to use the supplied power cord that plugs into a regular electrical outlet (assuming you can find an available outlet). Battery-powered mobile charging devices also work well in a pinch and are available at many airports. If you must use a random charging kiosk, the safest option may be to completely power off the device before plugging it in.
 
Another alternative is gaining in popularity..... "USB Condoms" 
They prevent accidental data exchange when your device is plugged in to another device with a USB cable. USB Condoms achieve this by cutting off the data pins in the USB cable and allowing only the power pins to connect through. Thus, these "USB Condoms" prevent attacks like "juice jacking". 
 
Use USB-Condoms to:
  • Charge your phone on your work computer without worrying...
  • Use charging stations in public without worrying...
If you're going to run around plugging your phone into strange USB ports, at least be safe about it. ;-)
 
 
 
Via:

Please Login or Register to see this Hidden Content

Please Login or Register to see this Hidden Content

Please Login or Register to see this Hidden Content

Please Login or Register to see this Hidden Content

 

 


  • neckchop, satman80 and johnthehillbilly like this
My name is Eyecre8 and I approve this message!
Posted Image

#2 cmh714

cmh714

    Tech Service & Beyond

  • Smod
  • 3,272 posts
  • LocationSoCal
  • Current Device(s):Nexus 6

Posted 13 September 2013 - 08:19 AM

Another great article and write-up!

 

I dont remember which version of ICS had it, but on my xt912 for quite sometime when I plugged my phone into the charger it would actually ask me if I wanted MTP, Mass Transfer, Camera OR CHARGE ONLY.

 

Not sure if the charge only wouldve disabled the data pins or not, but I did like that "feature" and wish it would comeback.

 

Some other recommendations would be: disable USB debugging; Protect the sdcard so Apps have to ask for permission to read data; and disallow Unknown Sources to prevent apps from installing.

 

Convenience is the bane for Security :)


  • neckchop likes this

#3 johnthehillbilly

johnthehillbilly

    Gear jammin' S-Mod

  • Smod
  • 6,470 posts
  • Twitter:@johnhillbilly
  • Google+:http://goo.gl/ColUJ .. johnthehillbilly@gmail.com
  • LocationSomewhere between here, and there...
  • Current Device(s):unlocked RAZR HD (xt926)... RAZR (xt912)

Posted 13 September 2013 - 08:21 AM

Another great article and write-up!

I dont remember which version of ICS had it, but on my xt912 for quite sometime when I plugged my phone into the charger it would actually ask me if I wanted MTP, Mass Transfer, Camera OR CHARGE ONLY.

Not sure if the charge only wouldve disabled the data pins or not, but I did like that "feature" and wish it would comeback.

Some other recommendations would be: disable USB debugging; Protect the sdcard so Apps have to ask for permission to read data; and disallow Unknown Sources to prevent apps from installing.

Convenience is the bane for Security :)


You had the charge only option on ICS ?.... the last time I saw that on my RAZR was with GB.... :)

HD tappin' .... hillbilly style!!


Feeding my android addiction......... one phone at a time.....

jhf.png

If you are feeling generous and would like to buy me a drink.... coffee :)


#4 cmh714

cmh714

    Tech Service & Beyond

  • Smod
  • 3,272 posts
  • LocationSoCal
  • Current Device(s):Nexus 6

Posted 13 September 2013 - 08:22 AM

You had the charge only option on ICS ?.... the last time I saw that on my RAZR was with GB.... :)

HD tappin' .... hillbilly style!!

You may be right John, it may have been on GB, its been quite a while :)


  • johnthehillbilly likes this

#5 cmh714

cmh714

    Tech Service & Beyond

  • Smod
  • 3,272 posts
  • LocationSoCal
  • Current Device(s):Nexus 6

Posted 13 September 2013 - 08:25 AM

And for anyone thats not ever heard of or been to a DefCon or its bigger brother BlackHat, you should consider trying to get there once. It happens at the end of July, beginning of August every year in Las Vegas.

 

 

If you do go, you turn off EVERYTHING and NEVER connect unless you are 100% sure. No joke. I have been to many of these conferences as I do security for a living. You dont trust or use anything when there. They have previously setup ATM machines and everything to get info. Its lots of fun and scary to see how stupid we are :)



#6 cmh714

cmh714

    Tech Service & Beyond

  • Smod
  • 3,272 posts
  • LocationSoCal
  • Current Device(s):Nexus 6

Posted 13 September 2013 - 08:26 AM

This year one of the hacks they did at the Hotel was to charge everyone in the Hotel for a porn movie. Needless to say, it cause some problems for the hotel staff.



#7 livinginkaos

livinginkaos

    I don't know what I'm doing anymore.....

  • Administrator
  • 15,282 posts
  • Google+:Hangouts - livinginkaos@gmail.com
  • LocationOregon
  • Current Device(s):Samsung S8+ / Pixel XL 128gb / iPhone 7+ 256gb / iPad Pro 12.9" / Samsung Chromrbook Plus / Pixel C / Nexus 6p 128gb / Nexus 6 / Nexus 6 on Fi / Nexus 9 / Moto 360^2 / Nvidia Shield TV Pro / Nvidia Shield Tablet / HTC EVODesign on FreedomPop / Chromecast / Surface Pro 3 i7 / Samsung Tab Pro 12.2 / Lenovo Win8 Tab / Eee Slate / '13 Nexus 7

Posted 13 September 2013 - 08:32 AM

Nice Job Eye! Yeah I'm guilty of the charging station usage at International airports on my last trip. My portable power station was on the fritz so I couldn't take it. I am surely going to from here on out.

From My S4 Dev Edition


b2wvCBn.png

Sig by livinginkaos
Samsung S8+ / Pixel XL 128gb / iPhone 7+ 256gb / iPad Pro 12.9" / Samsung Chromrbook Plus / Pixel C / Nexus 6p 128gb / Nexus 6 / Nexus 6 on Fi / Nexus 9 / Moto 360^2 / Nvidia Shield TV Pro / Nvidia Shield Tablet / HTC EVODesign on FreedomPop / Chromecast / Surface Pro 3 i7 / Samsung Tab Pro 12.2 / Lenovo Win8 Tab / Eee Slate / '13 Nexus 7


#8 soocold

soocold

    OC & OCD Specialist

  • Smod
  • 8,736 posts
  • Google+:amcsocold@gmail.com
  • LocationTouching something electronic
  • Current Device(s):LG G4, Nexus 6

Posted 13 September 2013 - 10:09 AM

im glad that Ive only used my own charge base in a wall socket. ive been tempted to use one of those stations though.


pveoVTW.png

sig by jayrod

 

2760259.png

 

The Rules-Follow them.

Do you like our forum? Do you call it your second home? Help us with the upkeep


#9 livinginkaos

livinginkaos

    I don't know what I'm doing anymore.....

  • Administrator
  • 15,282 posts
  • Google+:Hangouts - livinginkaos@gmail.com
  • LocationOregon
  • Current Device(s):Samsung S8+ / Pixel XL 128gb / iPhone 7+ 256gb / iPad Pro 12.9" / Samsung Chromrbook Plus / Pixel C / Nexus 6p 128gb / Nexus 6 / Nexus 6 on Fi / Nexus 9 / Moto 360^2 / Nvidia Shield TV Pro / Nvidia Shield Tablet / HTC EVODesign on FreedomPop / Chromecast / Surface Pro 3 i7 / Samsung Tab Pro 12.2 / Lenovo Win8 Tab / Eee Slate / '13 Nexus 7

Posted 13 September 2013 - 11:34 AM

The only reason I did is I did not have my converter plug for the international plugs.  It was in my luggage because they ended up making me check my carry on.  I learned and stuck it in my pocket for the return flight......


b2wvCBn.png

Sig by livinginkaos
Samsung S8+ / Pixel XL 128gb / iPhone 7+ 256gb / iPad Pro 12.9" / Samsung Chromrbook Plus / Pixel C / Nexus 6p 128gb / Nexus 6 / Nexus 6 on Fi / Nexus 9 / Moto 360^2 / Nvidia Shield TV Pro / Nvidia Shield Tablet / HTC EVODesign on FreedomPop / Chromecast / Surface Pro 3 i7 / Samsung Tab Pro 12.2 / Lenovo Win8 Tab / Eee Slate / '13 Nexus 7


#10 Daino92

Daino92

    Member

  • Members
  • PipPip
  • 258 posts
  • Google+:chrisdaino@gmail.com
  • LocationFort Collins
  • Current Device(s):SCH-1535

Posted 14 September 2013 - 09:00 AM

Thanks for the nice article man, I'll for sure think twice now before I go and plug in willy nilly. 


  • eyecre8 likes this

#11 cmh714

cmh714

    Tech Service & Beyond

  • Smod
  • 3,272 posts
  • LocationSoCal
  • Current Device(s):Nexus 6

Posted 14 September 2013 - 09:11 AM

I just realized I have a usb condom already. A while back I bought a retractable USB to 10 different "ends" cord and it only does charging.

 

Will be adding that to the travel kit.


  • neckchop and eyecre8 like this




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users