Do NOT Plug This USB In! – Hak5 Rubber Ducky

preview_player
Показать описание


The Hak5 Rubber Ducky is a dangerous hacking tool that disguises itself as an unassuming USB flash drive. It delivers payloads by injecting keystrokes while appearing to its host system as a regular old keyboard.

Purchases made through some store links may provide some compensation to Linus Media Group.

FOLLOW US
---------------------------------------------------

MUSIC CREDIT
---------------------------------------------------
Intro: Laszlo - Supernova

Outro: Approaching Nirvana - Sugar High

CHAPTERS
---------------------------------------------------
0:00 Intro
1:28 What's a Ducky?
2:50 Rubber Ducky 2.0
3:50 Programming the Ducky
4:50 Command Line
5:41 Nefarious Uses
7:04 Data Extraction
7:35 Drawbacks
9:07 Should it be legal?
10:43 Conclusion
Рекомендации по теме
Комментарии
Автор

7:25 It's because the system can set (from inside) the CAPS lock and NUM lock state of keyboards. The keyboard is aware of change. So if the Ducky can be a keyboard, it also can be aware of such changes. If the script uses these state changes to transmit a message, the keyboard (here the Ducky) can read them and store the data into a file. It's genius.

Jahus
Автор

These things have been available for over a decade, I’m surprised Linus has only just made a video on this cool device.

dogbog
Автор

For additional info, Rubber Duckies are INSANELY easy to access and learn.

I built my own out of an Arduino - it’s pretty much identical in functionality to a Rubber Ducky 1.0 and it cost me maybe 6 Canadian Dollars. Granted, I use it to automate basic batch scripts to quickly troubleshoot Windows PCs for myself and some friends but anyone willing enough could definitely do some damage with it if they were so inclined.

Mantris
Автор

Hak5: it was made to automate mundane office tasks
Also Hak5: "Attack mode"

dylanjones
Автор

Finally a video on these, they've been a thing for ages!

Never plug in a random flash drive you've found or been given a lot of the times.

Skreamies
Автор

I did a project on this in college in 2014 and nearly got a failing grade because my prof said it was unrealistic. I've seem so many things that work like rubber duckies since and it's just grinds my gears every time! These things are neat but dang can they do some harm.

chicken-fried
Автор

I still use my original rubber ducky to automate all kinds of things and to demo why you don't plug in random flash drives.
Such an amazing piece of kit and the rubber ducky 2.0 is even more amazing!

BrodieFairhall
Автор

As an IT guy you could test your clients IT Security Awareness with these and load a script onto them, that automatically books the person into the next Security Seminar, so they can learn what to do the next time they find a random USB Stick

Ssch_
Автор

For testing: use vm snapshots to return to a previous state. To get the rubber ducky to work in a vm, pass trough a usb hub or pci card directly to the vm. (not the ducky device itself, that's going to cause issues)

BartDerudder
Автор

I remember learning about these many years ago in some certification classes I took when I was 14 & 16. A lot of server places will actually have their USB ports flat out disabled to prevent physical malware attacks and cables locked away behind metal from where they can be physically tampered with the prevent wire tapping even if they are already in locked facilities.

willwunsche
Автор

I always laughed at people for "acting like just plugging in a single USB stick could cause THAT much harm". I guess, I was the fool.

awakenedcrowl
Автор

I would love for LTT to do more videos on Cyber Security

carlj
Автор

Security analyst here, I've only seen one on a network once, they're pretty interesting! I hope you guys cover more cybersecurity topics

RedHeadWolf
Автор

6:00 4 months later and this has suddenly become a real story XD

carloaarnink
Автор

Hak5 brings back so many memories. I'm glad the LTT labs people found a use for their duckies, but I'm not sure I learned all that much.

SignalBoost
Автор

Wow this is scary. I am sure someone could modify a keyboard using a hub and a build in rubber ducky to make it look even less harmfull. If someone receives a USB keyboard by mail, if it looks better than their current keyboard, I am sure many wouldn't hesitate to plug it in their computer to try it.

michelyannakis
Автор

Glad that your highlighting security tools, tricks, and remediation. Keep doing videos like this. As a security professional I think tech Youtubers can play an important role in educating users

rdvn
Автор

Colton crying after opening the company to a cyber threat is very foreshadowing xD

thegift
Автор

Just now do I realize that I actually want one of these, being able to plug in a drive and have it automate a couple commands looks useful as hell

hardrivethrutown
Автор

This better be the start of a Hak5xLTT collaboration! Fly Darren and Shannon up to The Lab and let's get a few videos out of this!!

LakeVermilionDreams