Democratic Underground Latest Greatest Lobby Journals Search Options Help Login
Google

School's Laptop Spying Software Exploitable from Anywhere

Printer-friendly format Printer-friendly format
Printer-friendly format Email this thread to a friend
Printer-friendly format Bookmark this thread
This topic is archived.
Home » Discuss » Archives » General Discussion (1/22-2007 thru 12/14/2010) Donate to DU
 
Are_grits_groceries Donating Member (1000+ posts) Send PM | Profile | Ignore Tue May-25-10 09:03 AM
Original message
School's Laptop Spying Software Exploitable from Anywhere
Absolute Manage is a remote administration program that allows sysadmins to supervise and maintain client computers over the Internet. It has been in the news since early February, when Lower Merion School District in Pennsylvania was alleged to be using it to spy on students at home via their laptop webcams.

The story took a new twist last Thursday, when Threat Level reported that researchers at Leviathan Security Group had discovered serious vulnerabilities in the program. These problems let attackers carry out a number of exploits, including installing malware or running other arbitrary code on the students' laptops. The major limitation in the reported attacks is that the bad guy needs to be on the same local network as the victim, and the program's developers, Absolute Software, says it's a largely theoretical threat.

Unfortunately, the security problems are worse than has been reported so far, and are far from theoretical. In fact, any machine with a public IP address running Absolute Manage can be taken over by attackers anywhere on the Internet. Such an attacker can command the machine to run arbitrary code, steal data, or take photographs using the computer's camera.

We have been investigating Absolute Manage for several months, hoping to gain a better understanding of the security measures it employs to protect users. We are disclosing this information now because, following the Threat Level post, we believe it's only a matter of time until real attackers discover it. Users need to be aware of the vulnerabilities and take proper measures to protect themselves.
There's much more:http://www.freedom-to-tinker.com/blog/jhalderm/schools-laptop-spying-software-exploitable-anywhere

Someone may have to be very determined to do this. Unfortunately, there are probably plenty of people with the expertise and the willingness to do just that.
Printer Friendly | Permalink |  | Top
hobbit709 Donating Member (1000+ posts) Send PM | Profile | Ignore Tue May-25-10 09:24 AM
Response to Original message
1. My, my, my! This is what I worried about from the beginning.
If a computer can be remotely accessed, then anyone can access it.
Printer Friendly | Permalink |  | Top
 
sui generis Donating Member (1000+ posts) Send PM | Profile | Ignore Tue May-25-10 09:26 AM
Response to Original message
2. also included in the software - the ability to activate your
camera without activating power or status lights. I have a panasonic robo cam inside the house - and noticed one day it had been hacked through a VPN account - running around without any status lights, but clearly tracking me in the kitchen. I guess the remote operator had no idea the camera actually moved when they changed the focus. Lesson learned: do not use cloud accounts and standard port ranges to remote monitor your equipment. A two year old can hack that.
Printer Friendly | Permalink |  | Top
 
DU AdBot (1000+ posts) Click to send private message to this author Click to view 
this author's profile Click to add 
this author to your buddy list Click to add 
this author to your Ignore list Sun May 05th 2024, 03:44 AM
Response to Original message
Advertisements [?]
 Top

Home » Discuss » Archives » General Discussion (1/22-2007 thru 12/14/2010) Donate to DU

Powered by DCForum+ Version 1.1 Copyright 1997-2002 DCScripts.com
Software has been extensively modified by the DU administrators


Important Notices: By participating on this discussion board, visitors agree to abide by the rules outlined on our Rules page. Messages posted on the Democratic Underground Discussion Forums are the opinions of the individuals who post them, and do not necessarily represent the opinions of Democratic Underground, LLC.

Home  |  Discussion Forums  |  Journals |  Store  |  Donate

About DU  |  Contact Us  |  Privacy Policy

Got a message for Democratic Underground? Click here to send us a message.

© 2001 - 2011 Democratic Underground, LLC