Security Risks of Firewire and PCMCIA DMA

Security Risks of Firewire and PCMCIA DMA

Secure Home | Search | About
 General Computer Security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
Security Risks of Firewire and PCMCIA DMA Privacy 06-06-2007
Posted by Privacy on June 6, 2007, 12:34 am
If you were  Registered and logged in, you could reply and use other advanced thread options
Does anyone know of a way to mitigate or totally eliminate the risks
of firewire and PCMCIA direct memory access on a running Windows XP
system that has the keyboard/mouse/screen locked out?

Everything I've ever read has said just live with the risk because
there's nothing you can do about it. Some have suggested just plugging
the ports with epoxy. That's not a good solution and can probably be
bypassed.

The problem seems to be that no matter how diligent you are, there's
no software solution to this. These ports have direct access to RAM,
so they can do virtually anything to your system. I'm sure there's a
solution out there, but I have yet to run accross it.


Posted by Todd H. on June 6, 2007, 1:36 am
If you were  Registered and logged in, you could reply and use other advanced thread options

> Does anyone know of a way to mitigate or totally eliminate the risks
> of firewire and PCMCIA direct memory access on a running Windows XP
> system that has the keyboard/mouse/screen locked out?
>
> Everything I've ever read has said just live with the risk because
> there's nothing you can do about it. Some have suggested just plugging
> the ports with epoxy. That's not a good solution and can probably be
> bypassed.
>
> The problem seems to be that no matter how diligent you are, there's
> no software solution to this. These ports have direct access to RAM,
> so they can do virtually anything to your system. I'm sure there's a
> solution out there, but I have yet to run accross it.

I read an article in eweek about some software based solutions out
there that seek to mitigate these issues.

I'll be damned if I can find it though.

Okay, I found something familiar. There's a mention of Safend's Port
Protector product in this article, but it's aging.
http://www.eweek.com/article2/0,1759,1840131,00.asp

I think similar other products exist, but that's about all I can tell
ya. Might be something to look into anyway.

Physical access to a machine has always been where the buck stops
though... it's just scary how quickly a machine can be infected with a
USB port open...


--
Todd H.
http://www.toddh.net/

Posted by Andrew on June 20, 2007, 3:35 am
If you were  Registered and logged in, you could reply and use other advanced thread options
> Does anyone know of a way to mitigate or totally eliminate the risks
> of firewire and PCMCIA direct memory access on a running Windows XP
> system that has the keyboard/mouse/screen locked out?

try devicelock (www.devicelock.com).


Posted by Sebastian G. on June 20, 2007, 9:22 am
If you were  Registered and logged in, you could reply and use other advanced thread options
Andrew wrote:

>> Does anyone know of a way to mitigate or totally eliminate the risks
>> of firewire and PCMCIA direct memory access on a running Windows XP
>> system that has the keyboard/mouse/screen locked out?
>
> try devicelock (www.devicelock.com).

Why should he? It's a hardware issue.

Similar ThreadsPosted
CFP: Cyber-Threats and Emerging Risks - HICSS 40 June 7, 2006, 11:30 am
Security Breaches Pandemic - Deloitte Touche 2006 Global Security Survey June 29, 2006, 12:42 am
New site dedicated to security conferences : www.security-briefings.com May 6, 2006, 11:16 am
New It Security News and Information site for security professionals August 6, 2008, 2:46 am
Excellent website for IT Security (Security+) February 8, 2008, 12:32 am
Google Closes Security Holes in Google Base Security November 21, 2005, 5:37 pm
Security IP June 10, 2005, 3:09 pm
BGP Security October 4, 2005, 1:49 pm
MSc IT Security February 28, 2006, 4:42 pm
security+ February 6, 2008, 1:03 pm

The site map in XML format XML site map

Contact Us | Privacy Policy