Click here to Skip to main content
15,887,444 members
Please Sign up or sign in to vote.
5.00/5 (2 votes)
See more:
The question is about preparing a USB stick (thumb drive) to run an application whenever it is inserted to a computer without previous preparation on the PC to which it is inserted to.
Posted

You can't, without the users express permission, not since mid-2011 anyway - MS removed it from all OS's to prevent the spread of malware.
 
Share this answer
 
Comments
Michael Haephrati 8-Mar-13 4:43am    
You are right. :) In fact I expected answers like "use autorun.inf", but this will not work since mid-2011. However, I am asking because there are undocumented ways to make it work after all. There is some kind of a trick.
OriginalGriff 8-Mar-13 5:08am    
I would not rely on them - this was changed for good reason, and there is absolutely no guarantee that these holes will not be closed either. Relying on undocumented features that expose security weaknesses is not normally a good idea in the mid to long term!

I would consider finding something else to do :laugh:
Michael Haephrati 8-Mar-13 5:12am    
You are right, as people should not rely on such tricks, which become irrelevant after a while, as security patches are released. However, this question is only for the academic discussion, as there are roomers about a very good way to make it work.
OriginalGriff 8-Mar-13 5:20am    
If you want that information, then your best route is:
1) Create a brand new sacrificial VM.
2) Make sure your AV is good quality and up-to-date.
3) Make sure your firewall is well and truly locked down.
4) Find a good proxy server
5) Cruise the hacker sites and look for / ask for the info.

But don't expect it to work for too long!
Michael Haephrati 8-Mar-13 5:23am    
I posted it here because I wanted to avoid steps 1 to 4 :)
One interesting solution would be using an HID device[^], which looks like a USB Thumb drive but in fact is recognized as a keyboard. When you attach a new keyboard to your PC, installation takes place immediately.
Here is an example: http://hakshop.myshopify.com/products/usb-rubber-ducky[^]

http://forums.hak5.org/index.php?/topic/28824-frequently-asked-questions-faq/[^]

To block malicious uses of such device, Microsoft will have to change their Plug and Play[^] behavior, which might become less automatic and less user friendly, but more secured.
 
Share this answer
 

This content, along with any associated source code and files, is licensed under The Code Project Open License (CPOL)



CodeProject, 20 Bay Street, 11th Floor Toronto, Ontario, Canada M5J 2N8 +1 (416) 849-8900