Reply to post: Can you still buy memory cards/USB sticks on EBAY?

Plug and PREY: Hackers reprogram USB drives to silently infect PCs

david 12 Silver badge

Can you still buy memory cards/USB sticks on EBAY?

1) All flash devices have firmware.

2) Reprogramming the firmware of flash devices is a standard operation, and little old ladies in the market stalls of Shenzhen will do it for you. The most basic purpose is to implement algorithms dealing with bad flash cells. For years, the most common malware purpose was to lie about the size and provenance of the flash device.

3) 10 Years ago it was common for usb devices to include keyboard emulators to install software. There were a couple of efforts directed towards standardising the process, which eventually died as the industry moved away from the idea because of security concerns

This clever demonstration links the two well known ideas: flash controller.reprogramming, and usb device malware.

POST COMMENT House rules

Not a member of The Register? Create a new account here.

  • Enter your comment

  • Add an icon

Anonymous cowards cannot choose their icon