Found a USB in my mailbox! Plugged it into my Fedora box but, not coming up as a blk dev, instead it comes up as a Apple, Inc. Pro Keyboard [Mitsumi, A1048/US layout]( Device 018: ID 05ac:020b) and proceeds to happily type a stored string.
That's is an interesting attack vector for a cunning hacker to exploit!
USB input devices are such an obvious security flaw, no system control to block untrusted keyboard inputs. #linux #fedora #systemau
Easy way around it is to stick the flash drive into someone else's computer first.
ReplyDelete+1 on Dan's comment - there have been a few reports of USB sticks chock full of malware goodness left in people's mailboxes
ReplyDelete