ghacks Technology News

How to dump all USB files without the user knowing


USBdumper runs silently as a background process once started and copies the complete content of every connected usb device to the system without the knowledge of the user. It creates a directory with the current date and begins the background copying process. The user has no indication that his files are copied from his USB drive unless he does know that USBdumper is running on the system. (or accidentally find the directory with the copied files).

Just imagine this tool running on a public computer with no access to the task manager or a software like process explorer. You would not know that the files are copied. What could you do to protect against this program ? You could encrypt your data, if you use a tool like true crypt for example. Even if the files are copied they are useless unless the “attacker” knows your passphrase.




Tags: , ,
Categories: Operating Systems, Windows


Read Related Posts


10 Responses to “How to dump all USB files without the user knowing”

  1. tash says:

    Interesting.. Though if someone has a number of large files on their usb drive, they might notice the led on it being in use more than it should be. And the thing about truecrypt or any encryption; if someones willing to copy all your files, they can easily run a keylogger with it.. The encryption becomes useless(assuming you accessed the encrypted files.. if you don’t type your password, you’re still safe)

  2. Martin says:

    tash that is true of course. If a keylogger is running as well and the encrypted files are accessed the “hacker” will have everything he needs.

    Remember that some usb devices don’t have leds, especially those small ones that are plugged into a port on the back..

    If you want 100% security don’t use them at computers that you can’t check. Buy a second one with unimportant data only and use that one on public terminals.

  3. Chris mankey says:

    But true crypt allows you to use keyfiles, so If they have the password but not the keyfile it would be useless for them!

  4. Martin says:

    Right Chris this would work at home but not on public terminals. The keyfile would be stored on the stick as well.

  5. Quasimodo says:

    Simple lesson:
    Don’t use public computers for personal things.
    Ever.

  6. tash says:

    Quasimodo has a good point =]

  7. Chris mankey says:

    Right Chris this would work at home but not on public terminals. The keyfile would be stored on the stick as well.

    True, but you better have alot of files on the stick so they can’t figure out which one you used! Better yet, do private things in private!

  8. Ike says:

    HI
    do any of you know if there is a new version USBdumper program out there???,- the first version does not work any more once you update your antivirus program! It just delete the USBdumper.exe from your devise! If any of you know please post it here
    thank you
    Ike

  9. Akuma Kigen says:

    Welll there are similar versions here as well as some that do a whole lot more damage:

    http://www.usbhacks.com

Leave a Reply   Follow Ghacks   Subscribe To Comment Rss

© 2005-2009 Ghacks.net. All Rights Reserved. Privacy Policy - About Us