How to use a found USB key safely

It is possible for USB drives to have firmware-embedded malware, see this BadUSB article which shows the research. There would be no way to get rid of firmware-embedded malware, formatting would have no effect on it at all. However, it's pretty new, and therefore very, very unlikely that you would run into it. It's probably something someone dropped by accident, although found devices can have deliberately installed malware on them for the unsuspecting. These can be targeted on individuals (drop it by a CFO's car door) or companies (strew them around a coffee shop or company car park) or at random (drop them on the floor of the downtown bound 2 train).

Assuming your perfect sandbox you could examine the content and reformat it with almost certain safety. That perfect sandbox doesn't really exist though, so it would make sense to boot a virtual system from read-only and save nothing from the session.


In terms of using the USB stick long term I agree with @GdD's answer, if you are truly paranoid you can not trust this stick. But unless you are a high value target it is unlikely that you will have stumbled across BadUSB.

In terms of reading securely I would:

  1. Download one of the minimal or security focused LiveCD linux distributions.
  2. Burn to CD/DVD (Not USB Stick)
  3. Unplug any hard-drives (depending on your paranoia vs effort level you could just ensure these are not mounted)
  4. Boot into the Live linux
  5. Plug in your untrusted USB and read what you like.
  6. Optional: Format the untrusted USB and hope it does not have a firmware virus.

Tags:

Usb Drive