Skip to content

Latest commit

 

History

History
 
 

Folders and files

NameName
Last commit message
Last commit date

parent directory

..
 
 
 
 
 
 
 
 

README.md

USB

Materials for the "Introduction to USB hacking" talk.

Last iteration of the talk:

Older iterations:

Snippets for demos: here.

USB-related links: here.

Hardware

Demonstrated during the talk.

USB Kill (90$)

Rubber Ducky (45$)

Bash Bunny (100$)

LAN Turtle (55$)

ATtiny85 board (1.3$)

CJMCU BadUSB (10$)

Cactus WHID (16$)

Cactus Micro Rev2 (35$)

Teensy 3.2 (20$)

Facedancer21 (85$)

GreatFET One (110$)

Raspberry Pi Zero (5$)

Raspberry Pi Zero W (10$)

BeagleBone Black (70$)

Nexus 7 2013 (Wi-Fi) tablet (150$)

USB Armory (150$)

EC3380-AB (180$)

OpenVizsla (140$)

AirDrive Keylogger Max (100$)

Maltronics WiFi KeyLogger Internal (45$)

Agenda

This is the full agenda, each iteration of the talk may cover different parts.

Part 1: USB 101

Demos

  1. Looking at syslog (dmesg) when a new USB device is connected.
  2. Checking connected devices and their descriptors with lsusb.
  3. Sniffing and decoding USB packets with a logic analyzer.
  4. Sniffing USB via usbmon with wireshark.

Part 2: USB attack surface

  • Device -> host: electrical, firmware, kernel, logical
  • Host -> device: firmware, android, ios
  • Host -> device -> host: original BadUSB
  • Remote: USB/IP, WebUSB, USBAnywhere

Part 3: Linux USB subsystem

  • Linux USB stack
  • USB sysfs, usbfs
  • libusb, pyusb

Part 4: BadUSB

  • BadUSB: consumer-ready vs self-designed
  • BadUSB: microcontroller-based vs Facedancer vs Linux-based

Demos

Consumer-ready:

  1. Rubber Ducky.
  2. Bash Bunny.
  3. Lan Turtle.

Microcontroller-based:

  1. Teensy 3.2.
  2. ATtiny55 board.
  3. CJMCU BadUSB.
  4. Cactus WHID.

Part 5: Facedancer

  • Facedacer software overview
  • Facedancer21 and GreatFET One

Demos

  1. Emulating USB keyboard with Facedancer.
  2. USB reconnaissance with Facedancer.

Part 6: Linux USB Gadget subsystem

  • Linux USB Gadget subsystem
  • Legacy Gadget Modules
  • USB Gadget ConfigFS
  • GadgetFS
  • Raw Gadget

Demos

  1. Emulating mass storage drive through g_mass_storage.ko on Raspberry Pi Zero.
  2. Emulating keyboard with ConfigFS on Raspberry Pi Zero.
  3. Emulating keyboard through GadgetFS on Raspberry Pi Zero.
  4. Emulating keyboard through Raw Gadget on Raspberry Pi Zero.
  5. Emulating keyboard from an Android device.

Part 7: USB fuzzing

  • Fuzzing, hardware vs virtual
  • vUSBf, QEMU and usbredir
  • syzkaller, Raw Gadget and dummy_hcd.ko

Demos

  1. Fuzzing USB with Facedancer.
  2. Fuzzing USB with vUSBf.
  3. Fuzzing USB with syzkaller.
  4. Crashing a Linux machine via a bug in a USB driver.
  5. Crashing a Windows machine via a bug in a USB driver.

Part 8: USB sniffing

  • Hardware vs software sniffers
  • "Low-level" vs "high-level" sniffers
  • Beagle analyzers
  • USBProxy, USBProxy 'Nouveau'
  • OpenVizsla
  • Hardware keyloggers (AirDrive, Maltronics)

Demos

  1. Sniffing with usbmon already demoed in part 1.
  2. Sniffing with a logic analyzer already demoed in part 1.
  3. Sniffing USB with USBProxy on BeagleBone Black.
  4. Sniffing USB with USBProxy 'Nouveau' with Facedancer.
  5. Sniffing USB with OpenVizsla.
  6. Sniffing keyboard via AirDrive Keylogger.