Jul 23, 2010

What is USB rubber ducky attack?

USB rubber ducky is a smart device which can emulate a keyboard or a mouse when connected to a computer and can execute a pre programmed instructions.

An example will be, opening the command prompt on windows and then flushing your DNS cache, within a flick of a second which will be absolutely difficult to notice. The dangerous part is that, it can also be used to format one of your drives in a flick of a second.

Since, we have mentioned about it on data loss blog, we could also give you an example of data loss though this new device. Consider, a modified version of rubber ducky, which also has a flash storage in it. It will take a simple command to copy all you documents on to this flash storage by emulating a keyboard and executing the copy command.

The most concerning thing about this device is, that , since the device has its own small processor, which makes itself a computer which then communicates to your computer through a usb port, it can actually work on different platforms other than windows, like Mac, Linux etc.

Here is how a USB rubber ducky looks like ?

So, be careful if see something like this next time in your office.