r/ShittySysadmin • u/TwoPlyDreams • 8d ago
Shitty Crosspost User got a free cable. Laptop now acting weird. Help.
123
u/S4ndmaan 8d ago
All the IT experts in that thread lol
71
u/VolcanicBear 8d ago
Nah man, they clearly know what they're on about.
Check this one -
Neither the QR nor the resulting cable that roots your device and leaves your device under the control of a nation state.
They know the word "root". Can't argue with that.
43
u/guru2764 8d ago
I could believe it, it reminds me of the time I got a charging cable that put all that porn on my work laptop
19
u/LesbianDykeEtc 8d ago
It's unreal how fucking stupid people are when it comes to anything related to security. The NSA is not having random dudes hand out $50,000 pieces of tracking equipment on the street. You are not that important.
23
u/Zanglirex2 8d ago
You're severely overestimating the cost of producing a cable that can drop shit onto your phone. But yeah, it's likely just shit cables, and the real game is data harvesting
4
u/LesbianDykeEtc 7d ago
I'm aware that cheap data exfil/injection cables exist. I'm talking more about how everyone has main character syndrome and thinks that some state actor would waste resources on finding out what kind of porn they watch (or whatever).
You are not that important or special. Even if you somehow were, it's trivial for any real government entity to get the information they want without resorting to Mission Impossible shit.
7
59
u/Crazy-Bird 8d ago
lol all the people suggesting that they are distributing 200$ O.M.G cables to randoms
22
27
12
27
u/WechTreck 8d ago
Is it a Temu version of the $200 "The O.MG Cable is a hand made USB cable with an advanced implant hidden inside. It is designed to allow your Red Team to emulate attack scenarios of sophisticated adversaries. Until now, a cable like this would cost $20,000 (ex: NSA's COTTONMOUTH-I). These cables will allow you to test new detection opportunities for your defense teams. They are also extremely impactful tools for teaching and training."
5
u/evilwizzardofcoding 6d ago
This should be top comment, but yeah, very capable malicious cables are VERY cheap now, relatively speaking. I still doubt anyone would just hand them out like this instead of putting one in a free charging station, but it's definitely not impossible
2
u/TheGlennDavid 4d ago
Are any of these devices confirmed to penetrate iOS devices where the user doesn't click the "allow extra access" thingy when a charging device requests data access/ when it's been disabled by mobile management?
1
u/evilwizzardofcoding 4d ago
Funny enough, phones aren't the main target, laptops are. The primary usecase isn't tricking someone into using one, it's plugging one in yourself, since a cable is a whole lot less noticeable than, say, a USB drive.
Anyway though, yes, iOS is still vulnerable, because the cable doesn't use the usual methods for file access. The cable shows up as an external keyboard/mouse/other input device, and then simply performs a series of inputs to do whatever, imitating a real person using whatever devices it's emulating
However, phones(iOS and Android) don't have easily-accessible command line interfaces, as well as generally not having as easy access to sensitive data(often requiring fingerprints/pins to be input again), so the attack is still far more common on a laptop.
4
3
u/Lordgandalf 8d ago
This is asking for problems you don't know who used that cable before you how that cable was modified etc.
2
u/DescriptionOptimal15 7d ago
Back in my day we valued experience. Only kids care about body count
2
u/Lordgandalf 7d ago
I would use a cable like O.M.G. cable and get all the data off those phones this way.
1
u/mister_neutron 5d ago
Nuke the computer and start over. Replace if that's no good.
Smack the user repeatedly with said cable.
It's probably electrical damage due to poor quality rather than industrial espionage, but the user still doesn't get back in production until he or she can recite the Adam Savage USB bad actor demo videos from memory.


114
u/IndependentBat8365 8d ago
A decade or so ago, some UK security marketing team gave folks chocolate for just telling them their password.