• Latest
  • Trending
  • All
  • News
  • Business
  • Politics
  • Science
  • World
  • Lifestyle
  • Tech
The new USB Rubber Ducky is more dangerous than ever

The new USB Rubber Ducky is more dangerous than ever

August 16, 2022
Annie Wersching, actress on “24,” dies at age 45

Annie Wersching, actress on “24,” dies at age 45

January 29, 2023
Star Trek: Picard season 3 trailer gets the whole Next Gen gang back together

Star Trek: Picard season 3 trailer gets the whole Next Gen gang back together

January 29, 2023
Weekly Horoscope: January 30 – February 5

Weekly Horoscope: January 30 – February 5

January 29, 2023
Grad student, 23, killed by speeding Seattle police car: reports

Grad student, 23, killed by speeding Seattle police car: reports

January 29, 2023
Scorpion Unit Emerged as Memphis Pursued Get-Tough Strategy

Scorpion Unit Emerged as Memphis Pursued Get-Tough Strategy

January 29, 2023
Erdogan says Turkey may accept Finland in NATO, but not Sweden

Erdogan says Turkey may accept Finland in NATO, but not Sweden

January 29, 2023
How America Would Be Screwed If China Invades Taiwan

How America Would Be Screwed If China Invades Taiwan

January 29, 2023
Celeb Prosecutor’s Own Kidnapping Is Now a True Crime Fiasco

Celeb Prosecutor’s Own Kidnapping Is Now a True Crime Fiasco

January 29, 2023
With pestering defense and a balanced offense, the Eagles get back to the Super Bowl.

Eagles Return to the Super Bowl as the 49ers Break Down

January 29, 2023
Jennifer Lopez’s Ex Marc Anthony Marries Fourth Wife Nadia Ferreira In Lavish Miami Wedding

Jennifer Lopez’s Ex Marc Anthony Marries Fourth Wife Nadia Ferreira In Lavish Miami Wedding

January 29, 2023
With pestering defense and a balanced offense, the Eagles get back to the Super Bowl.

With pestering defense and a balanced offense, the Eagles get back to the Super Bowl.

January 29, 2023
Bryan Kohberger’s public defender represented two of the Idaho stabbing victims’ parents

Bryan Kohberger’s public defender represented two of the Idaho stabbing victims’ parents

January 29, 2023
DNYUZ
  • Home
  • News
    • U.S.
    • World
    • Politics
    • Opinion
    • Business
    • Crime
    • Education
    • Environment
    • Science
  • Entertainment
    • Culture
    • Music
    • Movie
    • Television
    • Theater
    • Gaming
    • Sports
  • Tech
    • Apps
    • Autos
    • Gear
    • Mobile
    • Startup
  • Lifestyle
    • Arts
    • Fashion
    • Food
    • Health
    • Travel
No Result
View All Result
DNYUZ
No Result
View All Result
Home News

The new USB Rubber Ducky is more dangerous than ever

August 16, 2022
in News, Tech
The new USB Rubber Ducky is more dangerous than ever
539
SHARES
1.5k
VIEWS
Share on FacebookShare on Twitter

The USB Rubber Ducky is back with a vengeance.

The much-loved hacking tool has a new incarnation, released to coincide with the Def Con hacking conference this year, and creator Darren Kitchen was on hand to explain it to The Verge. We tested out some of the new features and found that the latest edition is more dangerous than ever.

What is it?

To the human eye, the USB Rubber Ducky looks like an unremarkable USB flash drive. Plug it into a computer, though, and the machine sees it as a USB keyboard — which means it accepts keystroke commands from the device just as if a person was typing them in.

“Everything it types is trusted to the same degree as the user is trusted,” Kitchen told me, “so it takes advantage of the trust model built in, where computers have been taught to trust a human. And a computer knows that a human typically communicates with it through clicking and typing.”

The original Rubber Ducky was released over 10 years ago and became a fan favorite among hackers (it was even featured in a Mr. Robot scene). There have been a number of incremental updates since then, but the newest Rubber Ducky makes a leap forward with a set of new features that make it far more flexible and powerful than before.

What can it do?

With the right approach, the possibilities are almost endless.

Already, previous versions of the Rubber Ducky could carry out attacks like creating a fake Windows pop-up box to harvest a user’s login credentials or causing Chrome to send all saved passwords to an attacker’s webserver. But these attacks had to be carefully crafted for specific operating systems and software versions and lacked the flexibility to work across platforms.

The newest Rubber Ducky aims to overcome these limitations. It ships with a major upgrade to the DuckyScript programming language, which is used to create the commands that the Rubber Ducky will enter into a target machine. While previous versions were mostly limited to writing keystroke sequences, DuckyScript 3.0 is a feature-rich language, letting users write functions, store variables, and use logic flow controls (i.e., if this… then that).

That means, for example, the new Ducky can run a test to see if it’s plugged into a Windows or Mac machine and conditionally execute code appropriate to each one or disable itself if it has been connected to the wrong target. It also can generate pseudorandom numbers and use them to add variable delay between keystrokes for a more human effect.

Perhaps most impressively, it can steal data from a target machine by encoding it in binary format and transmitting it through the signals meant to tell a keyboard when the CapsLock or NumLock LEDs should light up. With this method, an attacker could plug it in for a few seconds, tell someone, “Sorry, I guess that USB drive is broken,” and take it back with all their passwords saved.

How much of a threat is it?

In short, it could be a big one, but the need for physical device access means most people aren’t at risk of being a target.

According to Kitchen, the new Rubber Ducky was his company’s most in-demand product at Def Con, and the 500 or so units that Hak5 brought to the conference sold out on the first day. Safe to say, many hundreds of hackers have one already, and demand will likely continue for a while.

It also comes with an online development suite, which can be used to write and compile attack payloads, then load them onto the device. And it’s easy for users of the product to connect with a broader community: a “payload hub” section of the site makes it easy for hackers to share what they’ve created, and the Hak5 Discord is also active with conversation and helpful tips.

At a price of $59.99 per unit, it’s too expensive for most people to distribute in bulk — so it’s unlikely that someone will leave a handful of them scattered in your favorite cafe unless it’s known to be a hangout place for sensitive targets. That said, if you’re planning to plug in a USB device that you found lying out in a public place, think twice about it…

Could I use it myself?

The device is fairly simple to use, but if you don’t have any experience in writing or debugging code, there are a few things that could trip you up. In testing on a Mac, for a while, I couldn’t get the Ducky to enter the F4 key to open the launchpad, but I fixed it after making it identify itself with a different Apple keyboard device ID.

From that point, I was able to write a script so that, when plugged in, the Ducky would automatically launch Chrome, open a new browser window, navigate to The Verge’s homepage, then quickly close it again — all with no input from the laptop user. Not bad for just a few hours’ testing and something that could be easily modified to do something more nefarious than browse technology news.

The post The new USB Rubber Ducky is more dangerous than ever appeared first on The Verge.

Tags: CybersecurityPolicyTech
Share216Tweet135Share

Trending Posts

Eagles trample injury-hit 49ers to reach Super Bowl

Eagles trample injury-hit 49ers to reach Super Bowl

January 29, 2023
Drones reportedly attack convoy in east Syria coming from Iraq

Drones reportedly attack convoy in east Syria coming from Iraq

January 29, 2023
Exes Olivia Wilde, Jason Sudeikis Snapped Hugging In Los Angeles After Custody Battle

Exes Olivia Wilde, Jason Sudeikis Snapped Hugging In Los Angeles After Custody Battle

January 29, 2023
Police search for man who threw Molotov cocktail at New Jersey temple

Police search for man who threw Molotov cocktail at New Jersey temple

January 29, 2023
Hilary Duff Is “Optimistic” That The ‘Lizzie McGuire’ Reboot Could Still Happen

Hilary Duff Is “Optimistic” That The ‘Lizzie McGuire’ Reboot Could Still Happen

January 29, 2023

Copyright © 2023.

Site Navigation

  • About
  • Advertise
  • Privacy & Policy
  • Contact

Follow Us

No Result
View All Result
  • Home
  • News
    • U.S.
    • World
    • Politics
    • Opinion
    • Business
    • Crime
    • Education
    • Environment
    • Science
  • Entertainment
    • Culture
    • Gaming
    • Music
    • Movie
    • Sports
    • Television
    • Theater
  • Tech
    • Apps
    • Autos
    • Gear
    • Mobile
    • Startup
  • Lifestyle
    • Arts
    • Fashion
    • Food
    • Health
    • Travel

Copyright © 2023.

We use cookies on our website to give you the most relevant experience by remembering your preferences and repeat visits. By clicking “Accept”, you consent to the use of ALL the cookies.
Cookie settingsACCEPT
Privacy & Cookies Policy

Privacy Overview

This website uses cookies to improve your experience while you navigate through the website. Out of these cookies, the cookies that are categorized as necessary are stored on your browser as they are essential for the working of basic functionalities of the website. We also use third-party cookies that help us analyze and understand how you use this website. These cookies will be stored in your browser only with your consent. You also have the option to opt-out of these cookies. But opting out of some of these cookies may have an effect on your browsing experience.
Necessary
Always Enabled
Necessary cookies are absolutely essential for the website to function properly. This category only includes cookies that ensures basic functionalities and security features of the website. These cookies do not store any personal information.
Non-necessary
Any cookies that may not be particularly necessary for the website to function and is used specifically to collect user personal data via analytics, ads, other embedded contents are termed as non-necessary cookies. It is mandatory to procure user consent prior to running these cookies on your website.
SAVE & ACCEPT