SanDisk SD-ROM Bedienungsanleitung Seite 6

  • Herunterladen
  • Zu meinen Handbüchern hinzufügen
  • Drucken
  • Seite
    / 7
  • Inhaltsverzeichnis
  • LESEZEICHEN
  • Bewertet. / 5. Basierend auf Kundenbewertungen
Seitenansicht 5
U3 USB Stick (In-)Security
Q2/2007 by Martin Suess, martin.suess@csnc.ch
6
Microsoft's TweakUI also supports this setting
but only controls CD/DVD and removable
drives.
Select My Computer > AutoPlay > Types and
uncheck both entries. This will disable the
autostart feature for both CD/DVD drives and
removable drives.
Inherited from older operating systems, another
registry key to enable and disable autostart
from CD/DVD ROMs can be found here:
HKLM\System\CurrentControlSet\Services\
CDRom\AutoRun
The value can be set to 0 (autostart disabled) or
1 (autostart enabled).
Manual Prevention
If you are not sure whether or not the autostart
feature is disabled, press SHIFT while plugging
in a (U3) USB device. This disables the
autostart feature temporarily. From the security
point of view it is a little bit risky to rely on a
single button press though
Getting Rid Of U3
U3 sticks also support removing the emulated
CD ROM on the USB stick. If you use U3 sticks
personally or in your enterprise and you want to
get rid of the CD ROM part, use the removal
program of the manufacturer or U3. The
program can be found on the U3 website [1].
After the removal, you will have roughly 6MB of
additional space on your memory stick to use.
Test the technical solutions applied to make
sure they are working.
Education - Prevent Social Engineering
Along with releasing a policy and implementing
a technical solution it might be helpful to tell the
people concerned what the risks are and why
those measures have been taken. A
demonstration shows the risks and how an
incident could affect the company.
Finally…
... there is one more threat which is not subject
of this paper but shall be part of further
research: USB driver exploits. They are even
more threatening because they give access to
local system privileges and are way harder to
detect. Best solution for now: Update system
regularly or even better, disable USB
functionality on your system.
Seitenansicht 5
1 2 3 4 5 6 7

Kommentare zu diesen Handbüchern

Keine Kommentare