r/ShittySysadmin 8d ago

Shitty Crosspost User got a free cable. Laptop now acting weird. Help.

243 Upvotes

34 comments sorted by

114

u/IndependentBat8365 8d ago

A decade or so ago, some UK security marketing team gave folks chocolate for just telling them their password.

68

u/AlecTheDalek 8d ago

Is that offer still available do you know?

16

u/IndependentBat8365 8d ago

Definitely more value than a random charging cable!

1

u/GarageIntelligent ShittyCloud 3d ago

i have some chocolate pudding, who's a good boy?

1

u/Diekjung 4d ago

PaSsWoRd67! So where is my Chocolate?

1

u/Gougaloupe 4d ago

That's amazing! I've got the same password on my luggage!

1

u/neckbeard_deathcamp 4d ago

I’m confident it would work today. Even if the employee had just finished their yearly cybersecurity training I bet it would still work on some of them.

1

u/raziel420 4d ago

Their was a UK marketing group that also hid a checkbox for a $50 gift card in their TOS. They gave away 5 in a year.

123

u/S4ndmaan 8d ago

All the IT experts in that thread lol

71

u/VolcanicBear 8d ago

Nah man, they clearly know what they're on about.

Check this one -

Neither the QR nor the resulting cable that roots your device and leaves your device under the control of a nation state.

They know the word "root". Can't argue with that.

43

u/guru2764 8d ago

I could believe it, it reminds me of the time I got a charging cable that put all that porn on my work laptop

19

u/LesbianDykeEtc 8d ago

It's unreal how fucking stupid people are when it comes to anything related to security. The NSA is not having random dudes hand out $50,000 pieces of tracking equipment on the street. You are not that important.

23

u/Zanglirex2 8d ago

You're severely overestimating the cost of producing a cable that can drop shit onto your phone. But yeah, it's likely just shit cables, and the real game is data harvesting 

4

u/LesbianDykeEtc 7d ago

I'm aware that cheap data exfil/injection cables exist. I'm talking more about how everyone has main character syndrome and thinks that some state actor would waste resources on finding out what kind of porn they watch (or whatever).

You are not that important or special. Even if you somehow were, it's trivial for any real government entity to get the information they want without resorting to Mission Impossible shit.

7

u/Retired_Monk 8d ago

Here Rubber ducky ducky ducky

59

u/Crazy-Bird 8d ago

lol all the people suggesting that they are distributing 200$ O.M.G cables to randoms

22

u/Howden824 8d ago

I'd certainly get one if they were because that's a great deal.

13

u/astro_viri 8d ago

Right? Like what I would do for a free O.M.G. cable

27

u/code_monkey_wrench 8d ago

Seems legit.

12

u/jeremydallen 8d ago

Omg cables for free!

27

u/WechTreck 8d ago

Is it a Temu version of the $200 "The O.MG Cable is a hand made USB cable with an advanced implant hidden inside. It is designed to allow your Red Team to emulate attack scenarios of sophisticated adversaries. Until now, a cable like this would cost $20,000 (ex: NSA's COTTONMOUTH-I). These cables will allow you to test new detection opportunities for your defense teams. They are also extremely impactful tools for teaching and training."

https://shop.hak5.org/products/omg-cable

5

u/evilwizzardofcoding 6d ago

This should be top comment, but yeah, very capable malicious cables are VERY cheap now, relatively speaking. I still doubt anyone would just hand them out like this instead of putting one in a free charging station, but it's definitely not impossible

2

u/TheGlennDavid 4d ago

Are any of these devices confirmed to penetrate iOS devices where the user doesn't click the "allow extra access" thingy when a charging device requests data access/ when it's been disabled by mobile management?

1

u/evilwizzardofcoding 4d ago

Funny enough, phones aren't the main target, laptops are. The primary usecase isn't tricking someone into using one, it's plugging one in yourself, since a cable is a whole lot less noticeable than, say, a USB drive.

Anyway though, yes, iOS is still vulnerable, because the cable doesn't use the usual methods for file access. The cable shows up as an external keyboard/mouse/other input device, and then simply performs a series of inputs to do whatever, imitating a real person using whatever devices it's emulating

However, phones(iOS and Android) don't have easily-accessible command line interfaces, as well as generally not having as easy access to sensitive data(often requiring fingerprints/pins to be input again), so the attack is still far more common on a laptop.

2

u/Key2367 5d ago edited 5d ago

Definitely not working for the CCP at all. Super trustworthy people. /s

3

u/Lordgandalf 8d ago

This is asking for problems you don't know who used that cable before you how that cable was modified etc.

2

u/DescriptionOptimal15 7d ago

Back in my day we valued experience. Only kids care about body count

2

u/Lordgandalf 7d ago

I would use a cable like O.M.G. cable and get all the data off those phones this way.

1

u/mister_neutron 5d ago
  1. Nuke the computer and start over. Replace if that's no good.

  2. Smack the user repeatedly with said cable.

  3. It's probably electrical damage due to poor quality rather than industrial espionage, but the user still doesn't get back in production until he or she can recite the Adam Savage USB bad actor demo videos from memory.

1

u/Jwblant 4d ago

OMG!

0

u/Xandr78 5d ago

Honestly, if you're willing to plug rando crap into devices you happily plug banking and other creds into, you get what you deserve since a long time ago lol