A security expert has discovered a unique attack method that can be used to steal credentials from a locked computer. Rob Fuller demonstrated and explained how to exploit a USB SoC-based device to turn it into a credential-sniffer. The attack is possible because most PCs automatically install Plug-and-Play USB devices. The average time required for a successful attack is about 15 minutes. The hashed credentials collected by the network exploitation tool can later be easily brute-forced to get clear text passwords.
Source: https://thehackernews.com/2016/09/hack-windows-password.html

