Welcome, Register for free! or Login below:
EduGeek.net RSS Feeds Register FAQ Members Social Groups User Map Calendar Search Today's Posts Mark Forums Read

Hardware

Hardware forum sponsored by
Hardware Forum Sponsored by SCL Online

For any hardware related issues, recommendations or warnings about awful equipment.

Go Back   EduGeek.net Forums > Technical > Hardware
Reply
 
LinkBack Thread Tools Search Thread
Sponsored Links
Old 13-01-2009, 12:49 PM   #1
 
flyinghaggis's Avatar
 
Join Date: Jan 2006
Posts: 303
uk
Thanks: 3
Thanked 7 Times in 7 Posts
Rep Power: 9 flyinghaggis will become famous soon enough
Default USB Memory Sticks with hidden virtual CD partitions (U3 Drives?)

We've been finding that pupils (and staff) seem to be increasingly bringing in USB memory sticks they've been given as freebies into school. Most of these seem to be formatted (I'm assuming it's done purely using software rather than custom hardware in the sticks) specifically so that they appear in windows as both a 'virtual CD' partition and a partition that contains the USB drives data.

When connecting them to a PC the USB stick autoruns and windows detects it as a virtual CD drive which launches an app (often a Menu or a promo screen) from an .exe file and them mounts the USB data partition.

What's really worrying is that despite us having autorun turned off for users and Windows GP file path restrictions in place to stop executables running from removable drives the way these sticks emulate a CD drive seems to bypass this allowing the initial menu program to run ?
????: EduGeek.net Forums http://www.edugeek.net/forums/hardware/28913-usb-memory-sticks-hidden-virtual-cd-partitions-u3-drives.html

Has anyone found a fix to stop these type of memory sticks from being used and/or autorunning when connected as they're potentially a pretty major security loophole ?

Also is there any kind of program to reformat these sticks so we can get rid of the hidden virtual CD partition? I've tried the U3 removal tool but it's not detecting the USB drive as being a U3 model ?
  Reply With Quote
Old 13-01-2009, 01:35 PM   #2
 
ajbritton's Avatar
 
Join Date: Jul 2005
Location: Wandsworth
Posts: 1,429
uk
Thanks: 9
Thanked 16 Times in 11 Posts
Rep Power: 12 ajbritton will become famous soon enough
Default

Hmmm. Never heard of that. Not sure how a normal USB drive could be formatted to appear as a CD (except of course by the inclusion of AUTORUN.INF that points to a custom icon for the partition).

Do you actually have one in your posession to test?

I am very surprised to find that GP restrictions are not effective. Perhaps students are disconnecting PCs from LAN at critical moment during logon which can affect GP processing. Are you using a blacklist or whitelist approach for restrictions? In my experience, the whitelist approach is far more reliable.
  Reply With Quote
Old 13-01-2009, 01:44 PM   #3
 
Griffo's Avatar
 
Join Date: Sep 2008
Location: Wrexham
Posts: 94
uk uk wales
Thanks: 16
Thanked 3 Times in 3 Posts
Rep Power: 2 Griffo is on a distinguished road
Default

I have had a few of them brought to me but never really looked at how it was done. There are also a few branded ones like a Liverpool Echo or LFC one that i seem to remember launches IE and goes to their website when inserted.

Not a problem for us as we simply dont allow any access to usb drives
  Reply With Quote
Old 13-01-2009, 01:51 PM   #4
 
ICT_GUY's Avatar
 
Join Date: Feb 2007
Location: Weymouth
Posts: 1,279
uk
Thanks: 236
Thanked 105 Times in 69 Posts
Rep Power: 29 ICT_GUY is a splendid one to beholdICT_GUY is a splendid one to beholdICT_GUY is a splendid one to beholdICT_GUY is a splendid one to beholdICT_GUY is a splendid one to beholdICT_GUY is a splendid one to behold
Default

I have a kingston one, it drives me mad, the U3 removal tool does not work on them either. Its so annoying I hardly ever use the stick now.
  Reply With Quote
Old 13-01-2009, 02:29 PM   #5
 
flyinghaggis's Avatar
 
Join Date: Jan 2006
Posts: 303
uk
Thanks: 3
Thanked 7 Times in 7 Posts
Rep Power: 9 flyinghaggis will become famous soon enough
Default

Quote:
Originally Posted by ajbritton View Post
Hmmm. Never heard of that. Not sure how a normal USB drive could be formatted to appear as a CD (except of course by the inclusion of AUTORUN.INF that points to a custom icon for the partition).

Do you actually have one in your posession to test?

I am very surprised to find that GP restrictions are not effective. Perhaps students are disconnecting PCs from LAN at critical moment during logon which can affect GP processing. Are you using a blacklist or whitelist approach for restrictions? In my experience, the whitelist approach is far more reliable.
Yeah, I'm amazed MS haven't blocked these sticks in windows as it's basically using a hack to fool windows into thinking the USB stick is a CD drive. Given this works as a limited user without admin rights it leaves the whole thing seriously open to being exploited! We've using a blacklist rather than whitelist which may be part of the issue? I've tried it myself using our test pupil account so it's definitely not a problem caused by pupils unplgugging network cables/etc.

Quote:
Originally Posted by Griffo View Post
I have had a few of them brought to me but never really looked at how it was done. There are also a few branded ones like a Liverpool Echo or LFC one that i seem to remember launches IE and goes to their website when inserted.

Not a problem for us as we simply dont allow any access to usb drives
Admittedly the ones I've seen so far have been innocent in what they've done but my fear was that one might get infected with a virus and/or pupils might find out how to create their own customs sticks that would allow them to run programs bypassing our security (which looks like these specifically formatted sticks do) ! It's also frustrating because after plugging in these devices they install then prompt for a reboot (because of the virtual CD drive) so it's acutally permanently altering the configuration of the PC which is a concern.

Has anyone found a way to block them yet other than blocking all removable USB drives?

Last edited by flyinghaggis; 13-01-2009 at 02:38 PM..
  Reply With Quote
Old 13-01-2009, 02:56 PM   #6
 
RabbieBurns's Avatar
 
Join Date: Apr 2008
Location: Adelaide
Posts: 1,783
australia uk scotland
Thanks: 176
Thanked 93 Times in 74 Posts
Blog Entries: 2
Rep Power: 27 RabbieBurns is a name known to allRabbieBurns is a name known to allRabbieBurns is a name known to allRabbieBurns is a name known to allRabbieBurns is a name known to allRabbieBurns is a name known to all
Default

my 16bg sandisk has this cr*p on it. It also creates a directory structure on the disk it thinks i might want. Documents. Photos etc.

If i delete them, they re-appear next time I plug it in. ANNOYING.

I even formatted the drive and it still happens. GrRR
  Reply With Quote
Old 13-01-2009, 03:05 PM   #7
 
flyinghaggis's Avatar
 
Join Date: Jan 2006
Posts: 303
uk
Thanks: 3
Thanked 7 Times in 7 Posts
Rep Power: 9 flyinghaggis will become famous soon enough
Default

They certainly make it difficult to reformat the drive (assuming it can be done) but then I guess they don't want you removing their advertising material! You can't easily do it in windows because it sees it as though it was a CD drive and only lets you format the 'other' USB partition on the drive natively.
The only way I could think to carry it out would be to use Linux (or some kind of DOS cmd prompt boot) where you could physically see the partition structure on the drive and remove it?
  Reply With Quote
Old 13-01-2009, 03:08 PM   #8
 
RabbieBurns's Avatar
 
Join Date: Apr 2008
Location: Adelaide
Posts: 1,783
australia uk scotland
Thanks: 176
Thanked 93 Times in 74 Posts
Blog Entries: 2
Rep Power: 27 RabbieBurns is a name known to allRabbieBurns is a name known to allRabbieBurns is a name known to allRabbieBurns is a name known to allRabbieBurns is a name known to allRabbieBurns is a name known to all
Default

mine appears as a usb+cd in ubuntu as well. Mine is a legitimate paid for 16gb memory stick not a freebee POS. Its annoying as H3ll.
  Reply With Quote
Old 13-01-2009, 03:23 PM   #9
 
takeware's Avatar
 
Join Date: Jan 2009
Location: Sheffield
Posts: 4
uk uk yorkshire
Thanks: 0
Thanked 0 Times in 0 Posts
Rep Power: 0 takeware is an unknown quantity at this point
Default Virtual CD

Hi

Formatting wont do it I'm afraid, neither will partitioning. U3 and some others emulate a CD in their firmware - which means as far as Windows is concerned it's pretty much a separate device.

Some of manufacturers provide tools to manipulate the vCD - can't recall whether U3 do. M-Systems (who designed the U3 system and then partnered with Sandisk to try to poularise it) used to provide such tools as a downloadable SDK. But we are going back quite a while.

Drives are so cheap now why bother with it?

HTH
  Reply With Quote
Old 13-01-2009, 03:36 PM   #10
 
flyinghaggis's Avatar
 
Join Date: Jan 2006
Posts: 303
uk
Thanks: 3
Thanked 7 Times in 7 Posts
Rep Power: 9 flyinghaggis will become famous soon enough
Default

Quote:
Originally Posted by takeware View Post
Drives are so cheap now why bother with it?
I'm not bothered about using the drives TBH. My primary concern's really what the sticks do as I don't like the idea of pupils bringing in USB drives that install virtual hardware onto a PC and appear to bypass security policies! As you say it looks as though these drives actually contain different hardware controllers (rather than just being regular sticks formatted in a special way) to handle the CD emulation so you'd need a specifically written piece of software for each hardware controller type to alter/format them

Would be nice to reformat them if we could but failing that I'd be happy to block them altogether if anyone knows a way!

Last edited by flyinghaggis; 13-01-2009 at 03:44 PM..
  Reply With Quote
Old 13-01-2009, 03:54 PM   #11
 
Geoff's Avatar
 
Join Date: Jun 2005
Location: Fylde, Lancs, UK.
Posts: 10,469
uk uk lancashire
Thanks: 55
Thanked 339 Times in 292 Posts
Blog Entries: 1
Rep Power: 89 Geoff has a brilliant futureGeoff has a brilliant futureGeoff has a brilliant futureGeoff has a brilliant futureGeoff has a brilliant futureGeoff has a brilliant futureGeoff has a brilliant futureGeoff has a brilliant futureGeoff has a brilliant futureGeoff has a brilliant futureGeoff has a brilliant futureGeoff has a brilliant future
Send a message via ICQ to Geoff Send a message via AIM to Geoff Send a message via MSN to Geoff Send a message via Yahoo to Geoff Send a message via Skype™ to Geoff
Default

You do realise your systems are vulnerable to USB switch blade hacking?

USB Switchblade - Hak5

We just disable USB here. There's so many loopholes in Windows related to it, it's not worth trying to tie it down.
  Reply With Quote
Old 13-01-2009, 03:58 PM   #12
 
takeware's Avatar
 
Join Date: Jan 2009
Location: Sheffield
Posts: 4
uk uk yorkshire
Thanks: 0
Thanked 0 Times in 0 Posts
Rep Power: 0 takeware is an unknown quantity at this point
Default vCD

It's difficult for the OS to tell the difference between a real CD drive and a good emulation in software. This may possibly be an understatement ;-)

I'm going to tread very carefully here - as I'm new here are don't want to overstep the mark - but we have software that does that (and a lot more). I'm happy to provide more details - but via private mail or only with explicit permission.
????: EduGeek.net Forums http://www.edugeek.net/forums/showthread.php?t=28913

One way you can differentiate between a resident CD and one on a USB device is that the interloper is not there at startup (obvious loophole - if it's already plugged in at startup).

A utility is possible that detects the (late) arrival of a vCD and kicks it out. I don't know how useful that would be? If enough interest is there I might be able to get something made up and available as a freeware download (once we test it). Let me know?
  Reply With Quote
Old 13-01-2009, 04:15 PM   #13
 
flyinghaggis's Avatar
 
Join Date: Jan 2006
Posts: 303
uk
Thanks: 3
Thanked 7 Times in 7 Posts
Rep Power: 9 flyinghaggis will become famous soon enough
Default

Quote:
Originally Posted by Geoff View Post
You do realise your systems are vulnerable to USB switch blade hacking?

USB Switchblade - Hak5

We just disable USB here. There's so many loopholes in Windows related to it, it's not worth trying to tie it down.
We've seen this before and it's pretty concerning TBH. USB is something I'd like to block (and think it's we'll probably ultimately be forced into in future given data protection issues and the exploits for it) but there's no way SMT will allow it at the moment without months of discussion. Even then it probably won't happen!

How'd you manage to convince SMT to allow you block all USB devices! Do you just block it on pupil PCs or for staff aswell?
  Reply With Quote
Old 13-01-2009, 04:50 PM   #14
 
Sirbendy's Avatar
 
Join Date: Nov 2005
Posts: 1,332
uk
Thanks: 1
Thanked 39 Times in 33 Posts
Rep Power: 21 Sirbendy is just really niceSirbendy is just really niceSirbendy is just really niceSirbendy is just really nice
Default

google for U3 removers...I do it to staff ones on demand, and I've removed it from my own.

Bloody annoying thing it is.
  Reply With Quote
Old 13-01-2009, 04:58 PM   #15
 
flyinghaggis's Avatar
 
Join Date: Jan 2006
Posts: 303
uk
Thanks: 3
Thanked 7 Times in 7 Posts
Rep Power: 9 flyinghaggis will become famous soon enough
Default

I actually tried the U3 removal tool on the last stick I encountered but it didn't appear to register the drive as being a U3 model so I couldn't remove the 'read-only' CD partition. I think it might be a different kind of drive though it looks like it works in a similar way.
  Reply With Quote
Reply
Similar Threads
Thread Thread Starter Forum Replies Last Post
I need a load of memory sticks Little-Miss General Chat 52 21-01-2009 12:14 PM
I need 1000 Memory Sticks (512Mb) Help! ICTNUT Hardware 12 18-07-2008 01:19 PM
Allowing USB memory sticks for non admins... Don't hit me! MrLudwig Windows 16 03-12-2007 08:08 PM
USB Memory sticks not showing in My Computer firefox_2006 Hardware 13 22-06-2007 02:45 PM
USB Memory Sticks Not Detected CHR1S Hardware 2 18-06-2007 07:59 AM


Tags
usb u3 virtual cd


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools Search Thread
Search Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT +1. The time now is 02:32 PM.
Powered by vBulletin® Version 3.8.2
Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
SEO by vBSEO 3.3.0 ©2009, Crawlability, Inc.
Copyright EduGeek.net




website uptime

© 2005 - 2009 EduGeek.net
no new posts