I got a DigiSpark device, which is a little Arduino-based USB, and turned it into a BadUSB. Amongst my collection of other little gadgets, like wifi Deauthers and ARP spoofers, it's finda fun programming practice. Anyone else have/do these things?



Fun fact: I used to work for a medical device company that had a major vulnerability to BadUSB. Basically our DLLs, which are run as admin, are writeable by the user. An auditor was able to exploit this to get admin access to one of our machines over a year ago. The vuln is still not patched.