Privacy Tip #62 – PoisonTap Can Compromise Computer with USB Stick

Robinson+Cole Data Privacy + Security Insider
Contact

Security researcher Samy Kamkar has announced that a new hacking tool—PoisonTap—can  be loaded onto a USB stick and used to hijack the Internet connection of one’s computer.

The way it works is that if someone leaves their computer unattended, a hacker can stick the USB drive into the unattended laptop and although the individual may be accessing information through a VPN, PoisonTap takes over the Internet traffic, and continues to work even after the USB drive is removed.

According to Kamkar, when PoisonTap is introduced into a device, it masquerades as an Ethernet device and requests the IP address, even if it is locked or password protected.  Then the computer sends all of its Internet traffic though PoisonTap. It will scoop any requests to the Web and steal cookies from over 1 million web sites, which can allow the attacker to automatically log into sites without using a username or password. It can also redirect requests to the attacker’s site, which gives the attacker control over browsing.

The tip in response to this new attack?

Do not ever leave your laptop unattended (like on the train or in any other public place like a coffee shop). As we have mentioned before, review and put in place procedures that limit employees’ ability to introduce any foreign USB drives into the network, and provide employees education around the risks of USB drives, including PoisonTap.

[View source.]

DISCLAIMER: Because of the generality of this update, the information provided herein may not be applicable in all situations and should not be acted upon without specific legal advice based on particular situations.

© Robinson+Cole Data Privacy + Security Insider | Attorney Advertising

Written by:

Robinson+Cole Data Privacy + Security Insider
Contact
more
less

PUBLISH YOUR CONTENT ON JD SUPRA NOW

  • Increased visibility
  • Actionable analytics
  • Ongoing guidance

Robinson+Cole Data Privacy + Security Insider on:

Reporters on Deadline

"My best business intelligence, in one easy email…"

Your first step to building a free, personalized, morning email brief covering pertinent authors and topics on JD Supra:
*By using the service, you signify your acceptance of JD Supra's Privacy Policy.
Custom Email Digest
- hide
- hide