Rootkit unearthed in network security software / Hidden process developer linked to Sony USB fiasco
Rootkit unearthed in network security softwarer: Via The Registe(UK)
Researchers have unearthed rootkit-like functionality in an enterprise security product.
Network security software from a Chinese developer includes processes deliberately hidden from a user and, even worse, a hidden directory, Trend Micro reports. Files in the hidden directory could exist below the radar of antivirus scanners, potentially creating a stealthy hiding place for computer viruses that their creators might seek to exploit.
Trend Micro has written to the software developers involved in what looks like a case of misguided software design, rather than anything worse. Pending a fix from software developers, Trend Micro has slapped a "hacking tool" warning on the rootkit-like component of the network security tool (called HKTL-BRUDEVIC).
It doesn't name the developers except to say they are the same firm which bundles rootkit-like software with USB storage devices featuring fingerprint authentication.
Sony got a further black eye from issues with its MicroVault USM-F fingerprint reader software last year, which emerged a little over two years after its thorough mauling for including rootkit functionality on its music CDs. The feature, designed to stop fans ripping music tracks, created a security hole exploited by a number of Trojans
Read Original Article (Via The Registe(UK) .)
Recent blog posts
- Apple patching serious SMS vulnerability on iPhone
- Enter the Advertisers - self-regulatory principles ?
- Out of business, Clear may sell customer data
- TSA asked to ensure safety of customer data after Clear closing
- Several Facts about Google and HTTPS
- China thinks twice – and its 300m internet users scent a rare victory
- Did the Sanford E-Mail Tipster or the Newspaper Break the Law?
- Supreme Court Serves Up Remote-Recording Victory
- Deep-Packet Inspection in U.S. Scrutinized Following Iran Surveillance
- ATM Vendor Halts Researcher’s Talk on Vulnerability

Delicious
Digg
Reddit
Google
Yahoo
Technorati