Passwords stolen in a ‘Flash’
This post was published 3 years 6 months 15 days ago which may make its actuality or expire date not be valid anymore. This site is not responsible for any misunderstanding.Yet another took for the ultimate computer geek (or computer technician). Of course this tip is only for legitimate uses. How many times has someone forgot their user password, and the only answer has been to reformat (or use really hard to use hash cracking tools).
The latest episode of Hak5 has a segment where they show a USB key that takes advantage of U3 technology and weaknesses in Windows autorun and LAN Manager features. Essentially this USB key steals password hashes, LSA secrets, and creates back doors within seconds on insertion.
Easy right? Remember legitimate uses kids!