Democratic Underground Latest Greatest Lobby Journals Search Options Help Login
Google

HP admits to selling infected flash-floppy drives

Printer-friendly format Printer-friendly format
Printer-friendly format Email this thread to a friend
Printer-friendly format Bookmark this thread
This topic is archived.
Home » Discuss » Latest Breaking News Donate to DU
 
OhioChick Donating Member (1000+ posts) Send PM | Profile | Ignore Mon Apr-07-08 09:28 PM
Original message
HP admits to selling infected flash-floppy drives
Source: Computer World

Hybrid devices for ProLiant servers pre-infected with worms, HP says

April 7, 2008 (Computerworld) Hewlett-Packard Co. has been selling USB-based hybrid flash-floppy drives that were pre-infected with malware, the company said last week in a security bulletin.

Dubbed the HP USB Floppy Drive Key, the device is a combination flash drive and compact floppy drive and is designed to work with various models of HP's ProLiant Server line. HP sells two versions of the drive, one with 256MB of flash capacity and the other with 1GB of storage space.

A security analyst at the SANS Institute's Internet Storm Center (ISC) suspects that the infection originated at the factory and was meant to target ProLiant servers. "I think it's naive to assume that these are not targeted attacks," said John Bambenek, who is also a researcher at the University of Illinois.

HP confirmed in an April 3 advisory that both versions of the flash-floppy drive may come with a pair of worms, although the company offered few details. It did not, for instance, say how many of the drives were infected, where in the supply chain the infections occurred or even when they were discovered.

If a compromised drive is plugged into a USB port on any machine on the network, the worms may spread "to any mapped drives on the server," HP's alert said.



Read more: http://www.computerworld.com/action/article.do?command=viewArticleBasic&articleId=9075438&intsrc=hm_list
Printer Friendly | Permalink |  | Top
hedgehog Donating Member (1000+ posts) Send PM | Profile | Ignore Mon Apr-07-08 09:33 PM
Response to Original message
1. Ooops, I thought the headline read HRC admits to selling infected flash-floppy drives
I've got to get out of GD-P more often!
Printer Friendly | Permalink |  | Top
 
JohnnyLib2 Donating Member (1000+ posts) Send PM | Profile | Ignore Mon Apr-07-08 09:38 PM
Response to Reply #1
3. Me, too! LOL

GD:P stress disorder, for sure
Printer Friendly | Permalink |  | Top
 
skooooo Donating Member (1000+ posts) Send PM | Profile | Ignore Mon Apr-07-08 09:34 PM
Response to Original message
2. I have had nothing but trouble with HP computers...

And I will never buy another one EVER. I'm considering switching to a Mac, even though they are expensive. At least they seem to work more reliably.
Printer Friendly | Permalink |  | Top
 
TheWraith Donating Member (1000+ posts) Send PM | Profile | Ignore Mon Apr-07-08 10:00 PM
Response to Reply #2
4. Buy IBM.
In my experience they're the best built and performing, at least for laptops.
Printer Friendly | Permalink |  | Top
 
MrModerate Donating Member (1000+ posts) Send PM | Profile | Ignore Tue Apr-08-08 03:21 AM
Response to Reply #4
11. Unfortunately, IBM doesn't make IBM laptops anymore
Lenova (a Chinese company) does.

Irony's a bitch.
Printer Friendly | Permalink |  | Top
 
Cessna Invesco Palin Donating Member (1000+ posts) Send PM | Profile | Ignore Tue Apr-08-08 07:16 AM
Response to Reply #11
13. Actually they're still pretty damn good.
When Lenovo bought IBM's PC line they inherited the designs. The ThinkPad T series notebooks are still as good as they ever were. Stay away from the cheaper stuff, but with T and X series ThinkPads being so cheap these days, there's really not too much point in buying one of the low-end ones.
Printer Friendly | Permalink |  | Top
 
TheWraith Donating Member (1000+ posts) Send PM | Profile | Ignore Tue Apr-08-08 11:26 AM
Response to Reply #13
14. True. Lenovo made a big deal about the fact of keeping the same design quality. nt
Printer Friendly | Permalink |  | Top
 
BearSquirrel2 Donating Member (1000+ posts) Send PM | Profile | Ignore Tue Apr-08-08 12:06 PM
Response to Reply #13
16. Beware the BIOS ...

You have NO IDEA what the Chinese are hiding in the BIOS of those computers. I wouldn't use those things for anything other then children's toys.

Printer Friendly | Permalink |  | Top
 
CatholicEdHead Donating Member (1000+ posts) Send PM | Profile | Ignore Tue Apr-08-08 12:11 PM
Response to Reply #16
18. The 3000 BIOS is just standard Phoenix BIOS
They outsource the BIOS to the usual vendors. Only the US State Department has stopped using Thinkpads because of Lenovo buying it.
Printer Friendly | Permalink |  | Top
 
CatholicEdHead Donating Member (1000+ posts) Send PM | Profile | Ignore Tue Apr-08-08 12:08 PM
Response to Reply #13
17. R- Series is also pretty good
But stay away from any 3000 or IdeaPad laptops. IBM I believe is still working with Lenovo through 2010 on the Thinkpad designs, that is why they are so good.

On the Desktop side, Thinkcentre is good, but stay away from the 3000 series desktops.
Printer Friendly | Permalink |  | Top
 
WheelWalker Donating Member (1000+ posts) Send PM | Profile | Ignore Mon Apr-07-08 10:12 PM
Response to Reply #2
5. There were no diseases when all we had was commode-odor
Printer Friendly | Permalink |  | Top
 
Cronus Protagonist Donating Member (1000+ posts) Send PM | Profile | Ignore Wed Apr-09-08 01:38 PM
Response to Reply #2
26. My new HP Media Center PC is AWESOME!
Edited on Wed Apr-09-08 01:38 PM by Cronus Protagonist
Love it. Vista too. Wonderful. I basically not only have a fast, powerful computer, I have a programmable "Tivo" as well! Fucking awesome. The entire box with Vista cost me less than $750! I could not build a better computer for anywhere near that price point. And it's stable, fast, and did I mention awesome!!

:P

2/AMD processors, 3 gigs of RAM, twin 320 Gig hard drives, media bay, tuner, Vista, all the bells and whistles :)
Printer Friendly | Permalink |  | Top
 
CRF450 Donating Member (1000+ posts) Send PM | Profile | Ignore Wed Apr-09-08 05:08 PM
Response to Reply #26
27. You mean dual core CPU?
Edited on Wed Apr-09-08 05:25 PM by CRF450
My dad has an HP that he bought last year, hasent given him any trouble at all even though it runs kinda sluggish with Vista. He updated to SP1 and it seems to help some. I have Vista on my gaming computer and it works great with SP1!

BTW, do you know if a HTPC can work with satallite tv?
Printer Friendly | Permalink |  | Top
 
jwirr Donating Member (1000+ posts) Send PM | Profile | Ignore Mon Apr-07-08 10:50 PM
Response to Original message
6. So, I have a HP printer - does this apply to me? I am barely computer
literate.
Printer Friendly | Permalink |  | Top
 
Captain Angry Donating Member (1000+ posts) Send PM | Profile | Ignore Mon Apr-07-08 11:04 PM
Response to Reply #6
8. Not even a little bit.
If you have servers from HP that cost several thousand dollars, and somebody in your network plugs in one of these keys, your server could be attacked.

These keys were shipped this way, which means the company that HP bought them from allowed the product out without due quality testing.

HP will probably cancel the contract with the company and charge them back for any attacks.

It would take a unique set of circumstances for this to affect most businesses. No "normal" home user has a Proliant server. Some people use them for small businesses, but usually it's the Googles of the world that have thousands of this box. And their network is likely secure enough to block this attack in the first place.

It's embarrassing, but not damaging.
Printer Friendly | Permalink |  | Top
 
jwirr Donating Member (1000+ posts) Send PM | Profile | Ignore Mon Apr-07-08 11:12 PM
Response to Reply #8
9. Thank you. I am 67 years old and learned to use a computer by
myself which means that I just skim the surface.
Printer Friendly | Permalink |  | Top
 
aquart Donating Member (1000+ posts) Send PM | Profile | Ignore Tue Apr-08-08 02:47 AM
Response to Reply #9
10. You're on the net? You can print? Get your email?
You are way ahead of the game.
Printer Friendly | Permalink |  | Top
 
jwirr Donating Member (1000+ posts) Send PM | Profile | Ignore Tue Apr-08-08 09:17 PM
Response to Reply #10
23. Thanks. My daughters are my backup and they get a bit frustrated.
Printer Friendly | Permalink |  | Top
 
Acadia Blue Donating Member (1000+ posts) Send PM | Profile | Ignore Tue Apr-08-08 01:03 PM
Response to Reply #9
21. Hey, you did well. I learned at a job and everyone laughed at me
because I was so green.
Printer Friendly | Permalink |  | Top
 
Amonester Donating Member (1000+ posts) Send PM | Profile | Ignore Mon Apr-07-08 11:01 PM
Response to Original message
7. a worm?
Edited on Mon Apr-07-08 11:02 PM by Amonester
made in china? (if not, from where?)

outsourcing, huh?
Printer Friendly | Permalink |  | Top
 
FormerOstrich Donating Member (1000+ posts) Send PM | Profile | Ignore Tue Apr-08-08 06:00 AM
Response to Reply #7
12. Never seems to be a shortage of
American made worms......
Printer Friendly | Permalink |  | Top
 
Acadia Blue Donating Member (1000+ posts) Send PM | Profile | Ignore Tue Apr-08-08 01:03 PM
Response to Reply #7
22. So many toxic things, like food and toys, come from Bush's banker.
Printer Friendly | Permalink |  | Top
 
BearSquirrel2 Donating Member (1000+ posts) Send PM | Profile | Ignore Tue Apr-08-08 12:05 PM
Response to Original message
15. The most obvious explanation ...

The most likely explanation is that someone brought the malware into the system accidently to the computer system that did the master image. Than the master image was replicated (along with the malware) onto all the keys.

I worked with someone who once accidentally compiled a commercial software build in debug mode. Meaning, competitors could trace through the code with all the objects, function names and variable names intact. That ... and it's slower. So, ..., stuff like that happens.



Printer Friendly | Permalink |  | Top
 
Cessna Invesco Palin Donating Member (1000+ posts) Send PM | Profile | Ignore Tue Apr-08-08 12:26 PM
Response to Reply #15
19. Exact same thing happened to my company once.
We ship a cheap USB pen drive with some of our products. The key includes our PC software, manual, and a couple of other things. Well, the master ended up with a virus (in China) and subsequently made it onto about 600 of the keys. Fortunately, we caught it before it went to customers. Unfortunately, some poor saps at our warehouse had to format and reload the 600 keys themselves from scratch.
Printer Friendly | Permalink |  | Top
 
Acadia Blue Donating Member (1000+ posts) Send PM | Profile | Ignore Tue Apr-08-08 01:02 PM
Response to Original message
20. Corporate socialists regulating themselves. LOL Theives who
know how to steal. F you HP
Printer Friendly | Permalink |  | Top
 
Codedonkey Donating Member (153 posts) Send PM | Profile | Ignore Tue Apr-08-08 09:58 PM
Response to Reply #20
24. Yeah, mistakes never happen... We should live in a perfect world...
I'm sure there are better things to criticize HP over.
Printer Friendly | Permalink |  | Top
 
B3Nut Donating Member (1000+ posts) Send PM | Profile | Ignore Wed Apr-09-08 08:50 AM
Response to Reply #24
25. Like criticizing Windows Server 2003 for still needing floppies
Edited on Wed Apr-09-08 08:50 AM by B3Nut
to install RAID drivers when installing from the CD. Supposedly you can make a new CD installer with the drivers "slipstreamed" into the install, but I've never tried that. If there's one thing that absolutely should not be anywhere near a 21st-century computer, it's a floppy drive. That, and I read somewhere that some random unnamed deity of some sort kills a kitten anytime someone uses a floppy disk, but that could just be hearsay. :D

Won't someone think of the kittens?
Printer Friendly | Permalink |  | Top
 
DU AdBot (1000+ posts) Click to send private message to this author Click to view 
this author's profile Click to add 
this author to your buddy list Click to add 
this author to your Ignore list Fri Apr 19th 2024, 12:24 AM
Response to Original message
Advertisements [?]
 Top

Home » Discuss » Latest Breaking News Donate to DU

Powered by DCForum+ Version 1.1 Copyright 1997-2002 DCScripts.com
Software has been extensively modified by the DU administrators


Important Notices: By participating on this discussion board, visitors agree to abide by the rules outlined on our Rules page. Messages posted on the Democratic Underground Discussion Forums are the opinions of the individuals who post them, and do not necessarily represent the opinions of Democratic Underground, LLC.

Home  |  Discussion Forums  |  Journals |  Store  |  Donate

About DU  |  Contact Us  |  Privacy Policy

Got a message for Democratic Underground? Click here to send us a message.

© 2001 - 2011 Democratic Underground, LLC